Add CVE-2026-6385, CVE-2026-30997 and CVE-2026-6192 to .trivyignore.
All three are marked "vulnerable / postponed" in both bookworm and
trixie by the Debian Security Tracker with no upstream fix yet, so
the Trivy container scan will keep re-raising them on every run.
None of the vulnerable code paths are reachable in Bambuddy:
* CVE-2026-6385 (ffmpeg DVD subtitle heap OOB write) — ffmpeg here
only ingests printer-camera RTSP and MJPEG/H.264/H.265 streams,
never DVD/VOB files with subtitle tracks.
* CVE-2026-30997 (ffmpeg AV1 decoder OOB read → DoS) — Bambu
printer cameras emit H.264/H.265/MJPEG, not AV1.
* CVE-2026-6192 (openjpeg JPEG 2000 integer overflow) —
libopenjp2-7 is pulled in transitively by ffmpeg but Bambuddy
never decodes JPEG 2000 files.
Not caused by the recent bookworm → trixie runtime image switch;
both releases carry the same "postponed" status. Rationale captured
inline next to each CVE for future auditors.