Skip to content
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
10 changes: 10 additions & 0 deletions .trivyignore
Original file line number Diff line number Diff line change
@@ -0,0 +1,10 @@
# Trivy vulnerability ignore file
# Docs: https://trivy.dev/latest/docs/configuration/filtering/#by-finding-ids
# Auto-detected by Trivy in the repo root (see trivy.yaml / .github/workflows/vulnerability-triage.yml).
# Each entry should note why it is suppressed.

# CVE-2026-41305 — PostCSS XSS via unescaped </style> in CSS stringify output.
# postcss is a build-time-only dependency here (Tailwind/Next CSS tooling); we do
# not stringify untrusted CSS ASTs at runtime, so this is not exploitable.
# @see https://github.com/vercel/next.js/issues/93234#issuecomment-4333397286
CVE-2026-41305
Loading