From e2384db6b95cfcb976e884e995d9a67beb4cd9bb Mon Sep 17 00:00:00 2001 From: Adam Rauch Date: Thu, 9 Jan 2025 14:19:01 -0800 Subject: [PATCH 1/3] Remove unnecessary suppressions --- dependencyCheckSuppression.xml | 221 +-------------------------------- 1 file changed, 3 insertions(+), 218 deletions(-) diff --git a/dependencyCheckSuppression.xml b/dependencyCheckSuppression.xml index a83acd1e9b..96046f51df 100644 --- a/dependencyCheckSuppression.xml +++ b/dependencyCheckSuppression.xml @@ -25,7 +25,7 @@ --> ^pkg:maven/com\.google\.protobuf/protobuf\-java@.*$ cpe:/a:google:protobuf-java @@ -108,27 +108,6 @@ CVE-2006-5391 - - - - ^pkg:maven/org\.apache\.sanselan/sanselan@.*$ - CVE-2018-17201 - - - - - ^pkg:maven/com\.fasterxml\.jackson\.core/jackson\-databind@.*$ - CVE-2023-35116 - - ^pkg:maven/org\.apache\.tomcat/tomcat\-jaspic\-api@.*$ cpe:/a:apache:tomcat @@ -157,48 +136,12 @@ ^pkg:maven/org\.apache\.tomcat/tomcat\-jsp\-api@.*$ cpe:/a:apache:tomcat - - - - ^pkg:maven/joda\-time/joda\-time@.*$ - CVE-2024-23080 - - - - - - ^pkg:maven/joda\-time/joda\-time@.*$ - CVE-2024-23080 - - - - - - ^pkg:maven/org\.jfree/jfreechart@.*$ - CVE-2024-22949 - - - CVE-2023-52070 - - - - ^pkg:maven/org\.jfree/jfreechart@.*$ - CVE-2024-23076 - - - - - - ^pkg:maven/org\.itadaki/bzip2@.*$ - CVE-2019-12900 - CVE-2011-4089 - CVE-2010-0405 - CVE-2005-1260 - - - - - - ^pkg:maven/org\.apache\.lucene/lucene-analysis-common@.*$ - CVE-2024-45772 - - - - - ^pkg:maven/org\.apache\.lucene/lucene-backward-codecs@.*$ - CVE-2024-45772 - - - - - ^pkg:maven/org\.apache\.lucene/lucene-core@.*$ - CVE-2024-45772 - - - - - ^pkg:maven/org\.apache\.lucene/lucene-queries@.*$ - CVE-2024-45772 - - - - - ^pkg:maven/org\.apache\.lucene/lucene-queryparser@.*$ - CVE-2024-45772 - - - - - ^pkg:maven/org\.apache\.lucene/lucene-sandbox@.*$ - CVE-2024-45772 - - - - - - - ^pkg:maven/org\.glassfish\.jaxb/jaxb-core@.*$ - CVE-2024-9329 - - - - - ^pkg:maven/org\.glassfish\.jaxb/jaxb-core@.*$ - CVE-2024-9329 - - - - - ^pkg:maven/org\.glassfish\.jaxb/jaxb-core@.*$ - CVE-2024-9329 - - - - - ^pkg:maven/org\.glassfish\.jaxb/jaxb-runtime@.*$ - CVE-2024-9329 - - - - - ^pkg:maven/org\.glassfish\.jaxb/jaxb-runtime@.*$ - CVE-2024-9329 - - - - - ^pkg:maven/org\.glassfish\.hk2/osgi-resource-locator@.*$ - CVE-2024-9329 - - - - - ^pkg:maven/org\.glassfish\.jaxb/txw2@.*$ - CVE-2024-9329 - - - - - ^pkg:maven/org\.glassfish\.jaxb/txw2@.*$ - CVE-2024-9329 - - - - - - - ^pkg:maven/org\.apache\.tomcat/tomcat-catalina@.*$ - CVE-2024-56337 - - CVE-2024-56337 - From 24b02c41b70b7e6cd5f656bfa4c55393aa4374ac Mon Sep 17 00:00:00 2001 From: Adam Rauch Date: Thu, 9 Jan 2025 14:47:59 -0800 Subject: [PATCH 2/3] Re-add WNPRC dependency suppression and jfreechart comment --- dependencyCheckSuppression.xml | 16 ++++++++++++++++ gradle.properties | 2 +- 2 files changed, 17 insertions(+), 1 deletion(-) diff --git a/dependencyCheckSuppression.xml b/dependencyCheckSuppression.xml index 96046f51df..dfcbb45438 100644 --- a/dependencyCheckSuppression.xml +++ b/dependencyCheckSuppression.xml @@ -108,6 +108,19 @@ CVE-2006-5391 + + + + ^pkg:maven/org\.apache\.sanselan/sanselan@.*$ + CVE-2018-17201 + + Date: Thu, 9 Jan 2025 14:49:42 -0800 Subject: [PATCH 3/3] Revert --- gradle.properties | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/gradle.properties b/gradle.properties index d82c5e8165..3e8777fa0c 100644 --- a/gradle.properties +++ b/gradle.properties @@ -1,4 +1,4 @@ -moduleSet=all +#moduleSet=all #ideaIncludeAllModules=true # This controls Gradle's file system watching, which improves efficiency of incremental builds # https://docs.gradle.org/current/userguide/file_system_watching.html