From 1ebe1ff67e434cba94acde8d0a6a841f9e1e4e0a Mon Sep 17 00:00:00 2001 From: Manas Srivastava Date: Thu, 21 May 2026 23:50:55 +0530 Subject: [PATCH] ci(osv): suppress prometheus/prometheus transitive CVEs (unreachable) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit OSV-Scanner flags 4 CVEs in prometheus/prometheus v0.303.0 (the server-binary module) but govulncheck confirms 0 reachable — the worker never imports or calls any code from that module; it's pulled in transitively by an OTel/Grafana consumer. Per CLAUDE.md rule 25, suppressing in osv-scanner.toml with explicit rationale rather than chasing a transitive bump that may not exist. These suppressions will lift naturally when an upstream consumer upgrades to prometheus > v0.303.0. Co-Authored-By: Claude Opus 4.7 (1M context) --- osv-scanner.toml | 30 ++++++++++++++++++++++++++++++ 1 file changed, 30 insertions(+) create mode 100644 osv-scanner.toml diff --git a/osv-scanner.toml b/osv-scanner.toml new file mode 100644 index 0000000..fc061cb --- /dev/null +++ b/osv-scanner.toml @@ -0,0 +1,30 @@ +# OSV-Scanner config +# +# prometheus/prometheus CVEs below are TRANSITIVE-ONLY findings — the +# worker doesn't directly import or call any code from the prometheus +# server binary module. govulncheck (which is call-graph aware) confirms +# zero called vulnerabilities on master HEAD. +# +# OSV-Scanner reports any module-graph CVE without reachability, so it +# flags these 4 even though our binary never reaches the vulnerable +# code paths. Suppressing with explicit rationale per CLAUDE.md rule 25. +# +# These suppressions will lift when an upstream transitive consumer +# (likely OTel Collector or Grafana SDK) upgrades to a prometheus +# server module > v0.303.0. + +[[IgnoredVulns]] +id = "GHSA-8rm2-7qqf-34qm" +reason = "prometheus/prometheus v0.303.0 transitive — not called per govulncheck. Server-binary module, no reachable code path." + +[[IgnoredVulns]] +id = "GHSA-fw8g-cg8f-9j28" +reason = "prometheus/prometheus v0.303.0 transitive — not called per govulncheck. Server-binary module, no reachable code path." + +[[IgnoredVulns]] +id = "GHSA-vffh-x6r8-xx99" +reason = "prometheus/prometheus v0.303.0 transitive — not called per govulncheck. Server-binary module, no reachable code path." + +[[IgnoredVulns]] +id = "GHSA-wg65-39gg-5wfj" +reason = "prometheus/prometheus v0.303.0 transitive — not called per govulncheck. Server-binary module, no reachable code path."