From 4a5bbbb903df4ef0d19a6158f664c6cef4fab8bf Mon Sep 17 00:00:00 2001 From: andyzhangx Date: Thu, 30 Oct 2025 08:15:47 +0000 Subject: [PATCH 1/2] test: fix CVE-2025-47912 error --- .github/workflows/trivy.yaml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/trivy.yaml b/.github/workflows/trivy.yaml index a0bc4ae22..7f828846a 100644 --- a/.github/workflows/trivy.yaml +++ b/.github/workflows/trivy.yaml @@ -12,7 +12,7 @@ jobs: - name: Set up Go 1.x uses: actions/setup-go@v5 with: - go-version: 1.24.6 + go-version: 1.24.9 id: go - name: Checkout code From 38bc496f7b7f2c2c5e355859333c23f67699430d Mon Sep 17 00:00:00 2001 From: andyzhangx Date: Thu, 30 Oct 2025 08:53:59 +0000 Subject: [PATCH 2/2] test: ignore azcopy CVEs --- .trivyignore | 10 ++++++++++ 1 file changed, 10 insertions(+) create mode 100644 .trivyignore diff --git a/.trivyignore b/.trivyignore new file mode 100644 index 000000000..4fb942984 --- /dev/null +++ b/.trivyignore @@ -0,0 +1,10 @@ +CVE-2025-47912 +CVE-2025-58183 +CVE-2025-58185 +CVE-2025-58186 +CVE-2025-58187 +CVE-2025-58188 +CVE-2025-58189 +CVE-2025-61723 +CVE-2025-61724 +CVE-2025-61725