From ae621d60a8dfe30c050a457121149c45570a1c92 Mon Sep 17 00:00:00 2001 From: Adam Rauch Date: Fri, 1 Aug 2025 14:19:44 -0700 Subject: [PATCH 1/2] Remove unnecessary OWASP suppressions --- dependencyCheckSuppression.xml | 135 --------------------------------- 1 file changed, 135 deletions(-) diff --git a/dependencyCheckSuppression.xml b/dependencyCheckSuppression.xml index 423ec9f23d..74b44e0a75 100644 --- a/dependencyCheckSuppression.xml +++ b/dependencyCheckSuppression.xml @@ -19,29 +19,6 @@ CVE-2021-39491 - - - - ^pkg:maven/com\.google\.protobuf/protobuf\-java@.*$ - cpe:/a:google:protobuf-java - CVE-2022-3509 - CVE-2021-22569 - - - - - ^pkg:maven/com\.google\.protobuf/protobuf\-java@.*$ - cpe:/a:google:protobuf-java - CVE-2024-7254 - - CVE-2006-5391 - - - - ^pkg:maven/org\.apache\.sanselan/sanselan@.*$ - CVE-2018-17201 - - - - - - ^pkg:maven/org\.apache\.tomcat/tomcat\-jaspic\-api@.*$ - cpe:/a:apache:tomcat - - - - - ^pkg:maven/org\.apache\.tomcat/tomcat\-jsp\-api@.*$ - cpe:/a:apache:tomcat - - @@ -152,72 +96,6 @@ CVE-2023-52070 - - - - ^pkg:maven/org\.apache\.tomcat/tomcat-catalina@.*$ - CVE-2024-56337 - - - - - - ^pkg:maven/org\.labkey\.api/labkey-client-api@.*$ - CVE-2019-3911 - - - - ^pkg:maven/org\.labkey\.api/labkey-client-api@.*$ - CVE-2019-3912 - - - - ^pkg:maven/org\.labkey\.api/labkey-client-api@.*$ - CVE-2019-3913 - - - - - - ^pkg:maven/io\.github\.x-stream/mxparser@.*$ - cpe:/a:xstream:xstream - - - - - - ^pkg:maven/org\.itadaki/bzip2@.*$ - CVE-2019-12900 - - - - ^pkg:maven/org\.itadaki/bzip2@.*$ - CVE-2010-0405 - - - - ^pkg:maven/org\.itadaki/bzip2@.*$ - CVE-2005-1260 - - ^pkg:maven/commons-lang/commons-lang@.*$ CVE-2025-48924 - - - - - ^pkg:maven/com\.google\.code\.gson/gson@.*$ - CVE-2025-53864 - From e1d0f5f034fa1643674044284e7e87ee5ef13b9b Mon Sep 17 00:00:00 2001 From: Adam Rauch Date: Fri, 1 Aug 2025 14:42:59 -0700 Subject: [PATCH 2/2] Add back a couple OWASP suppressions that didn't show up locally --- dependencyCheckSuppression.xml | 26 ++++++++++++++++++++++++++ 1 file changed, 26 insertions(+) diff --git a/dependencyCheckSuppression.xml b/dependencyCheckSuppression.xml index 74b44e0a75..4c69d33d30 100644 --- a/dependencyCheckSuppression.xml +++ b/dependencyCheckSuppression.xml @@ -85,6 +85,19 @@ CVE-2006-5391 + + + + ^pkg:maven/org\.apache\.sanselan/sanselan@.*$ + CVE-2018-17201 + + @@ -113,4 +126,17 @@ ^pkg:maven/commons-lang/commons-lang@.*$ CVE-2025-48924 + + + + + ^pkg:maven/com\.google\.code\.gson/gson@.*$ + CVE-2025-53864 +