New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Rajeswari|Nandha] Add OWASP dependency check and fix the vulnerabilities #52
Conversation
Any updates on that? |
Ah, I see (#41) that this project isn't maintained at this moment :( |
@RobWin Thank you! Should we expect a new release soon? :) |
Just informing about failed build after this PR merge: https://travis-ci.org/RobWin/assertj-swagger/builds/487351732?utm_source=github_status&utm_medium=notification |
Whould you like to handle the issues?
|
Sure, Slava!
We will look into it in sometime :)
…On Fri 1 Feb, 2019, 4:19 PM Robert Winkler ***@***.*** wrote:
Whould you like to handle the issues?
One or more dependencies were identified with known vulnerabilities:
json-patch-1.6.jar: ids:(com.github.fge:json-patch:1.6, cpe:/a:json-patch_project:json-patch:1.6) : CVE-2018-14632
jackson-databind-2.9.5.jar: ids:(com.fasterxml.jackson.core:jackson-databind:2.9.5, cpe:/a:fasterxml:jackson:2.9.5, cpe:/a:fasterxml:jackson-databind:2.9.5) : CVE-2018-1000873, CVE-2018-14719, CVE-2018-14720, CVE-2018-14721, CVE-2018-19360, CVE-2018-19361, CVE-2018-19362
guava-20.0.jar: ids:(com.google.guava:guava:20.0, cpe:/a:google:guava:20.0) : CVE-2018-10237
slf4j-ext-1.6.3.jar: ids:(cpe:/a:slf4j:slf4j-ext:1.6.3, org.slf4j:slf4j-ext:1.6.3) : CVE-2018-8088
See the dependency-check report for more details.
:dependencyCheckAnalyze FAILED
FAILURE: Build failed with an exception.
* What went wrong:
Execution failed for task ':dependencyCheckAnalyze'.
>
Dependency-Analyze Failure:
One or more dependencies were identified with vulnerabilities that have a CVSS score greater then '5.0': CVE-2018-14719, CVE-2018-14720, CVE-2018-14721, CVE-2018-19360, CVE-2018-19361, CVE-2018-19362, CVE-2018-8088, CVE-2018-1000873
See the dependency-check report for more details.
—
You are receiving this because you authored the thread.
Reply to this email directly, view it on GitHub
<#52 (comment)>,
or mute the thread
<https://github.com/notifications/unsubscribe-auth/AK1uzkZrrjqkqFZMx4XDjaMofkiDDY0qks5vJBuvgaJpZM4WzjpT>
.
|
If no one working on this, I can handle it or find someone else who will handle. Please, let me know if my help is required. |
I am working on that - you can expect a PR soon! |
We have used assertj-swagger in our project and we also have OWASP dependency checker for analysing vulnerabilities. The dependency checker complained about 2 dependencies of assertj-swagger -> commons-collections and jackson-databind (a dependency of swagger-compat-spec-parser).
This PR adds dependency check analyser to the build and also fixes the existing vulnerabilities by upgrading them to the closest version that has the fix.