Skip to content

Annotate new snyk sigstore entry#233

Merged
JonJagger merged 2 commits into
mainfrom
annotate-new-snyk-sigstore-entry
May 14, 2026
Merged

Annotate new snyk sigstore entry#233
JonJagger merged 2 commits into
mainfrom
annotate-new-snyk-sigstore-entry

Conversation

@JonJagger
Copy link
Copy Markdown
Member

No description provided.

JonJagger and others added 2 commits May 14, 2026 14:20
…nted ones

SNYK-GOLANG-GITHUBCOMSIGSTORETIMESTAMPAUTHORITYV2PKGVERIFICATION-16134930
(CVSS 6.7) is not exploitable: the affected cosign binary runs in the runner
service image, not in user code sandbox containers.

Also adds runner-vulns.txt entries for CVE-2026-33814 (golang.org/x/net/http2)
and SNYK-16316406 (aws-sdk-go-v2 CloudWatch Logs), which were already in .snyk
and Kosli annotations but had no corresponding documentation.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
…maintenance

Replaces docs/runner-vulns.txt with docs/vulns/, one file per CVE or Snyk ID.
Also consolidates .snyk.example and snyk-crib-sheet.txt into the same directory.

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
@JonJagger JonJagger merged commit d776fb0 into main May 14, 2026
24 checks passed
@JonJagger JonJagger deleted the annotate-new-snyk-sigstore-entry branch May 14, 2026 14:00
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant