Files
MoviePilot/.trivyignore.yaml

86 lines
3.2 KiB
YAML

vulnerabilities:
- id: CVE-2026-84445
paths:
- usr/bin/rclone
purls:
- pkg:golang/google.golang.org/grpc@v1.84.0-dev.0.20260723093437-b6eac429d7b6
expired_at: 2026-10-09
statement: The pinned rclone image d6f5448594ecefefcf09cfeaf85cb7a21a866328032576ce2c1813e7b59c66dc has no google.golang.org/grpc/xds functions in either its amd64 or arm64 Go function table. GHSA-2v4p-qf9q-27wj requires xds.NewGRPCServer, so the affected interceptor is not linked. Reassess this exception when upgrading rclone or before expiry; see docs/development-setup.md.
- id: GHSA-6v7p-g79w-8964
paths:
- Python
purls:
- pkg:pypi/msgpack@1.1.2
expired_at: 2026-11-20
statement: The finding belongs to the base image's system pip and is not imported by MoviePilot.
- id: CVE-2025-47273
paths:
- Python
purls:
- pkg:pypi/setuptools@70.3.0
expired_at: 2026-11-20
statement: The finding belongs to the base image's system pip and is not used for dependency installation.
- id: CVE-2026-33818
paths:
- usr/bin/rclone
purls:
- pkg:golang/stdlib@v1.26.5
expired_at: 2026-11-20
statement: The official rclone binary has no patched release for this embedded Go runtime yet.
- id: CVE-2026-39821
paths:
- usr/bin/rclone
purls:
- pkg:golang/stdlib@v1.26.5
expired_at: 2026-11-20
statement: The official rclone binary has no patched release for this embedded Go runtime yet.
- id: CVE-2026-46600
paths:
- usr/bin/rclone
purls:
- pkg:golang/stdlib@v1.26.5
expired_at: 2026-11-20
statement: The official rclone binary has no patched release for this embedded Go runtime yet.
- id: CVE-2026-56853
paths:
- usr/bin/rclone
purls:
- pkg:golang/stdlib@v1.26.5
expired_at: 2026-11-20
statement: The official rclone binary has no patched release for this embedded Go runtime yet.
- id: CVE-2026-56854
paths:
- usr/bin/rclone
purls:
- pkg:golang/golang.org/x/crypto@v0.54.0
expired_at: 2026-11-20
statement: The pinned stable rclone image has no release with the upstream x/crypto v0.55.0 fix yet; its SFTP callbacks do not set source-address permissions, so the affected path is not reachable. Reassess when this exception expires.
- id: CVE-2026-56858
paths:
- usr/bin/rclone
purls:
- pkg:golang/stdlib@v1.26.5
expired_at: 2026-11-20
statement: The official rclone binary has no patched release for this embedded Go runtime yet.
- id: CVE-2026-56859
paths:
- usr/bin/rclone
purls:
- pkg:golang/stdlib@v1.26.5
expired_at: 2026-11-20
statement: The official rclone binary has no patched release for this embedded Go runtime yet.
- id: CVE-2026-56860
paths:
- usr/bin/rclone
purls:
- pkg:golang/stdlib@v1.26.5
expired_at: 2026-11-20
statement: The official rclone binary has no patched release for this embedded Go runtime yet.
- id: CVE-2026-56862
paths:
- usr/bin/rclone
purls:
- pkg:golang/stdlib@v1.26.5
expired_at: 2026-11-20
statement: The official rclone binary has no patched release for this embedded Go runtime yet.