Commit Graph
4 Commits
Author SHA1 Message Date
maziggy 5303673582 chore(security): suppress three Debian-postponed CVEs in Trivy scans
Add CVE-2026-6385, CVE-2026-30997 and CVE-2026-6192 to .trivyignore.
  All three are marked "vulnerable / postponed" in both bookworm and
  trixie by the Debian Security Tracker with no upstream fix yet, so
  the Trivy container scan will keep re-raising them on every run.

  None of the vulnerable code paths are reachable in Bambuddy:

    * CVE-2026-6385 (ffmpeg DVD subtitle heap OOB write) — ffmpeg here
      only ingests printer-camera RTSP and MJPEG/H.264/H.265 streams,
      never DVD/VOB files with subtitle tracks.
    * CVE-2026-30997 (ffmpeg AV1 decoder OOB read → DoS) — Bambu
      printer cameras emit H.264/H.265/MJPEG, not AV1.
    * CVE-2026-6192 (openjpeg JPEG 2000 integer overflow) —
      libopenjp2-7 is pulled in transitively by ffmpeg but Bambuddy
      never decodes JPEG 2000 files.

  Not caused by the recent bookworm → trixie runtime image switch;
  both releases carry the same "postponed" status. Rationale captured
  inline next to each CVE for future auditors.
2026-04-19 11:52:33 +02:00
maziggy 105ed7b50a Updated .trivyignore 2026-03-16 13:38:17 +01:00
maziggy c928be1e36 Updated CI 2026-02-27 14:53:45 +01:00
maziggy 01cb23ee85 Add .trivyignore to suppress Dockerfile USER directive finding (DS-0002)
Bambuddy runs as a single-host Docker container where root is needed
for device access and FFmpeg. Trivy picks up the file automatically.
2026-02-06 13:05:35 +01:00