fix(ci): suppress Next.js bundled tar/minimatch CVEs in trivy #431
Reference in New Issue
Block a user
Delete Branch "fix/trivy-nextjs-cves"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Context
Pipeline #518 (main after PR #429 merge) passed api and orchestrator but web failed at the trivy scan step. The Docker build succeeded but trivy found 2 new HIGH CVEs in Next.js bundled dependencies.
Closes #430
Test plan
8fbb8a387eto76c97b238c