From 3313e5a6be3046b3d449d405bf6aec907788f8b8 Mon Sep 17 00:00:00 2001 From: Kovid Goyal Date: Fri, 3 Jul 2026 08:58:07 +0530 Subject: [PATCH] Ignore inapplicable CVE --- .github/workflows/ci.py | 1 + 1 file changed, 1 insertion(+) diff --git a/.github/workflows/ci.py b/.github/workflows/ci.py index ab791df15..39b458d2c 100644 --- a/.github/workflows/ci.py +++ b/.github/workflows/ci.py @@ -236,6 +236,7 @@ IGNORED_DEPENDENCY_CVES = [ 'CVE-2026-7210', # DoS in unused XML parser 'CVE-2026-3276', # DoS in unicodedata.normalize() 'CVE-2026-7774', # tarfile.data_filter path traversal bypass + 'CVE-2026-12003', # bug in release builds irrelevant to us # github.com/nwaples/rardecode/v2 'CVE-2025-11579', # rardecode is version 2.2.1, not vulnerable 'CVE-2026-2673', # openssl fix not released