Skip to content

chore(security): suppress unfixable GO-2026-5932 openpgp notice - #256

Merged
charlesgreen merged 1 commit into
mainfrom
chore/trivy-ignore-openpgp
Sep 10, 2026
Merged

charlesgreen merged 1 commit into
mainfrom
chore/trivy-ignore-openpgp

Conversation

@charlesgreen

Copy link
Copy Markdown
Contributor

Summary

The 6 currently-open code-scanning alerts (Trivy, GO-2026-5932) all say the same thing: golang.org/x/crypto/openpgp is an unmaintained package. This repo never imports openpgp — x/crypto is only present transitively via grpc/otel — and the advisory has no fixed version, so no dependency bump can resolve it.

Worse, per-alert dismissal doesn't hold up over time: bumping x/crypto's version (as #255 just did) makes Trivy mark the old alert "fixed" and immediately raise a brand-new alert number for the new version. The dismissal-approval requests filed against the previous alert numbers (#254–258, #280) are already orphaned — those alerts are gone, replaced same-day by #305/310/313/316/319/322.

This adds a .trivyignore entry for GO-2026-5932, which suppresses it at the scanner level so it survives future version bumps instead of resetting every time.

Verification

  • trivy fs --scanners vuln . locally: 6 GO-2026-5932 findings without .trivyignore, 0 with it.
  • The 6 currently-open alerts should auto-transition to fixed on the next scan after this merges (GitHub marks a previously-reported finding as fixed when a new SARIF upload for the same category no longer contains it) — no manual dismissal or org approval needed.

Trivy flags golang.org/x/crypto/openpgp as unmaintained on every scan,
regardless of x/crypto's version, because the advisory has no fixed
version (it's a "don't use this package" notice, not a vulnerable
version range). This repo never imports openpgp (grep -rn openpgp
--include=*.go . returns nothing) -- x/crypto is only present
transitively via grpc/otel.

Per-alert dismissal doesn't hold: bumping x/crypto's version (as in
#255) makes Trivy mark the old alert "fixed" and immediately open a
new one for the new version, so the previously-filed dismissal
requests (#254-258, #280) are already orphaned against alerts that no
longer exist (#305/310/313/316/319/322 replaced them within the same
day). A .trivyignore entry is scanner-level and survives version
bumps; the currently-open alerts should auto-resolve to "fixed" once
this lands, since Trivy will stop reporting the finding.

Verified locally: `trivy fs --scanners vuln .` reports 6 GO-2026-5932
findings without this file, 0 with it.
@charlesgreen
charlesgreen merged commit a74c21f into main Sep 10, 2026
10 checks passed
@charlesgreen
charlesgreen deleted the chore/trivy-ignore-openpgp branch September 10, 2026 09:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant