Skip to content

Commit

Permalink
Suppress CVE-2023-35116 as it is a false-positive per issue jeremylon…
Browse files Browse the repository at this point in the history
  • Loading branch information
turing85 committed Aug 28, 2023
1 parent 7d49ba1 commit d2f37a8
Show file tree
Hide file tree
Showing 2 changed files with 8 additions and 2 deletions.
3 changes: 1 addition & 2 deletions pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -115,8 +115,6 @@
<version>${quarkus.platform.version}</version>
<configuration>
<skip>${quarkus-maven-plugin.skip}</skip>
<!-- TODO: Remove when https://github.com/quarkusio/quarkus/pull/34454 is available -->
<skipOriginalJarRename>true</skipOriginalJarRename>
</configuration>
<executions>
<execution>
Expand Down Expand Up @@ -147,6 +145,7 @@
<failBuildOnCVSS>0</failBuildOnCVSS>
<formats>${dependency-check-maven.formats}</formats>
<skip>${dependency-check-maven.skip}</skip>
<suppressionFile>src/test/resources/owasp-dependency-check.xml</suppressionFile>
</configuration>
<executions>
<execution>
Expand Down
7 changes: 7 additions & 0 deletions src/test/resources/owasp-dependency-check.xml
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
<?xml version="1.0" encoding="UTF-8"?>
<suppressions xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd">
<suppress>
<notes>False-Positive per issue https://github.com/jeremylong/DependencyCheck/issues/5779</notes>
<cve>CVE-2023-35116</cve>
</suppress>
</suppressions>

0 comments on commit d2f37a8

Please sign in to comment.