# Intentionally empty of CVE entries.
#
# This file must exist: the Docker workflow's Trivy step passes
# `trivyignores: .trivyignore`, and trivy-action fails hard with
# "cannot find ignorefile '.trivyignore'" when it is missing.
#
# The only recurring source of HIGH findings in the image is the bundled
# static Docker CLI (/usr/local/bin/docker), whose binary bakes in the Go
# stdlib — a stale Docker release therefore carries stale-toolchain CVEs.
# DOCKER_CLI_VERSION 29.8.0 ships go1.26.8 and scans clean on both
# linux/amd64 and linux/arm64, so nothing needs suppressing today.
#
# When a new Go stdlib advisory lands, prefer bumping DOCKER_CLI_VERSION in
# the Dockerfile to a static release built with the fixed toolchain. Only add
# an entry here when no such release exists yet, and say why the CVE is not
# reachable through fakecloud's usage (it shells out to the CLI purely for
# container lifecycle: run/exec/cp/rm; fakecloud's own binary is Rust).
