From ab8ea6d5ca954b493efce2425e9e36538d1c7a88 Mon Sep 17 00:00:00 2001 From: Gian Miguel Del Mundo Date: Tue, 30 Sep 2025 16:11:48 +0800 Subject: [PATCH 1/4] Updated .trivyignore --- .trivyignore | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/.trivyignore b/.trivyignore index 2b11cbac..1c47553a 100644 --- a/.trivyignore +++ b/.trivyignore @@ -2,9 +2,6 @@ # See https://aquasecurity.github.io/trivy/v0.35/docs/vulnerability/examples/filter/ # for more details -# UID2-5186 -CVE-2024-8176 exp:2025-06-03 - # This is a false positive CVE # See: UID2-5492 CVE-2022-37767 @@ -15,3 +12,6 @@ CVE-2025-1686 # UID2-5864 CVE-2025-6965 exp:2025-10-01 + +# UID2-6097 +CVE-2025-59375 exp:2025-12-15 From 2fcbe83af9d330ea7af8cb7bbc06d09ea7de8029 Mon Sep 17 00:00:00 2001 From: Gian Miguel Del Mundo Date: Tue, 30 Sep 2025 17:35:45 +0800 Subject: [PATCH 2/4] Updated .trivyignore --- .trivyignore | 3 +++ 1 file changed, 3 insertions(+) diff --git a/.trivyignore b/.trivyignore index 1c47553a..13b63189 100644 --- a/.trivyignore +++ b/.trivyignore @@ -15,3 +15,6 @@ CVE-2025-6965 exp:2025-10-01 # UID2-6097 CVE-2025-59375 exp:2025-12-15 + +# UID2-6128 +CVE-2025-55163 exp:2025-11-30 From b99955ee37564153cd26ddd2a8c30a83761089ed Mon Sep 17 00:00:00 2001 From: Gian Miguel Del Mundo Date: Thu, 2 Oct 2025 15:49:08 +0800 Subject: [PATCH 3/4] Updated Eclipse Temurin image for CVE-2025-6965 --- Dockerfile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index b1f5b725..83972c87 100644 --- a/Dockerfile +++ b/Dockerfile @@ -1,5 +1,5 @@ -# sha from https://hub.docker.com/layers/amd64/eclipse-temurin/21.0.7_6-jre-alpine-3.21/images/sha256-62fa775039897e4420368514ba6c167741f6d45a0de9ff9125bee57e5aca8b75 -FROM eclipse-temurin@sha256:62fa775039897e4420368514ba6c167741f6d45a0de9ff9125bee57e5aca8b75 +# sha from https://hub.docker.com/layers/library/eclipse-temurin/21.0.8_9-jre-alpine-3.22/images/sha256-3408c45e1faee20e4e68808939a75f87efa469b927d20e12309689ead053daba +FROM eclipse-temurin@sha256:4ca7eff3ab0ef9b41f5fefa35efaeda9ed8d26e161e1192473b24b3a6c348aef WORKDIR /app EXPOSE 8089 From b68fa2acb6ea2d09795f74bd39bacb241fe0db8c Mon Sep 17 00:00:00 2001 From: Gian Miguel Del Mundo Date: Thu, 2 Oct 2025 15:51:54 +0800 Subject: [PATCH 4/4] Updated .trivyignore --- .trivyignore | 5 +---- 1 file changed, 1 insertion(+), 4 deletions(-) diff --git a/.trivyignore b/.trivyignore index 13b63189..b3a00c92 100644 --- a/.trivyignore +++ b/.trivyignore @@ -10,11 +10,8 @@ CVE-2022-37767 # See: UID2-5493 CVE-2025-1686 -# UID2-5864 -CVE-2025-6965 exp:2025-10-01 - # UID2-6097 CVE-2025-59375 exp:2025-12-15 # UID2-6128 -CVE-2025-55163 exp:2025-11-30 +CVE-2025-55163 exp:2025-10-30