Skip to content

Commit 499afe7

Browse files
github-actions[bot]devin-ai-integration[bot]davidkonigsberg
authored
fix(fai): ignore CVE-2025-60876 for fai-reindexing container (no upstream fix) (#6178)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: Devin AI <158243242+devin-ai-integration[bot]@users.noreply.github.com> Co-authored-by: David Konigsberg <72822263+davidkonigsberg@users.noreply.github.com>
1 parent b2c6025 commit 499afe7

File tree

1 file changed

+5
-1
lines changed

1 file changed

+5
-1
lines changed

.github/workflows/dependabot-alerts-to-prs.yml

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -607,4 +607,8 @@ jobs:
607607
container_name: fai-reindexing
608608
github_token: ${{ secrets.GITHUB_TOKEN }}
609609
slack_token: ${{ secrets.DEVIN_AI_PR_BOT_SLACK_TOKEN }}
610-
ignored_cves: ""
610+
# CVE-2025-60876: BusyBox wget HTTP request smuggling vulnerability
611+
# No upstream fix available in Alpine Linux (busybox 1.37.0-r30)
612+
# Risk accepted: fai-reindexing container does not use wget functionality
613+
ignored_cves: |
614+
CVE-2025-60876

0 commit comments

Comments
 (0)