diff --git a/.trivyignore b/.trivyignore new file mode 100644 index 00000000..98b52072 --- /dev/null +++ b/.trivyignore @@ -0,0 +1,4 @@ +# libexpat integer overflow — no fix available in Debian repos yet +# https://avd.aquasec.com/nvd/cve-2026-25210 +# Review: remove this entry once a patched libexpat1 is published +CVE-2026-25210