Files
threadnet-operating/monitoring/cve
Thore Cimbal c942ce9328 cve: decide the one critical the new grafana brings with it
12.4.9 is what runs now, and its single remaining critical sits in a bundled go
dependency that grafana has to update, not us. Recording it before the scanner
reaches that image, so the count does not go to one and stay there.

Worth noting why it was not in the earlier list: the old scanner did not know
CVE-2025-41115 in grafana 12.0.0 at all. Trivy 0.74.0 found it on the first
round, on an image we were already replacing — an outdated scanner is outdated
detection, which was the argument for bumping it, now with an example.
2026-08-21 12:00:00 +00:00
..