Skip to content

Commit

Permalink
chore: add OWASP suppression for CVE-2023-35116 (false positive as per
Browse files Browse the repository at this point in the history
  • Loading branch information
deki committed Jun 29, 2023
1 parent 31858ae commit fb9b2cb
Show file tree
Hide file tree
Showing 7 changed files with 45 additions and 0 deletions.
3 changes: 3 additions & 0 deletions aws-serverless-java-container-core/pom.xml
Expand Up @@ -169,6 +169,9 @@
<version>${dependencyCheck.version}</version>
<configuration>
<skipProvidedScope>true</skipProvidedScope>
<suppressionFiles>
<suppressionFile>${project.basedir}/../owasp-suppression.xml</suppressionFile>
</suppressionFiles>
<failBuildOnCVSS>7</failBuildOnCVSS>
<failOnError>false</failOnError>
</configuration>
Expand Down
3 changes: 3 additions & 0 deletions aws-serverless-java-container-jersey/pom.xml
Expand Up @@ -192,6 +192,9 @@
<version>${dependencyCheck.version}</version>
<configuration>
<skipProvidedScope>true</skipProvidedScope>
<suppressionFiles>
<suppressionFile>${project.basedir}/../owasp-suppression.xml</suppressionFile>
</suppressionFiles>
<failBuildOnCVSS>7</failBuildOnCVSS>
<failOnError>false</failOnError>
</configuration>
Expand Down
3 changes: 3 additions & 0 deletions aws-serverless-java-container-spark/pom.xml
Expand Up @@ -114,6 +114,9 @@
<version>${dependencyCheck.version}</version>
<configuration>
<skipProvidedScope>true</skipProvidedScope>
<suppressionFiles>
<suppressionFile>${project.basedir}/../owasp-suppression.xml</suppressionFile>
</suppressionFiles>
<failBuildOnCVSS>7</failBuildOnCVSS>
<failOnError>false</failOnError>
</configuration>
Expand Down
3 changes: 3 additions & 0 deletions aws-serverless-java-container-spring/pom.xml
Expand Up @@ -235,6 +235,9 @@
<version>${dependencyCheck.version}</version>
<configuration>
<skipProvidedScope>true</skipProvidedScope>
<suppressionFiles>
<suppressionFile>${project.basedir}/../owasp-suppression.xml</suppressionFile>
</suppressionFiles>
<failBuildOnCVSS>7</failBuildOnCVSS>
<failOnError>false</failOnError>
</configuration>
Expand Down
3 changes: 3 additions & 0 deletions aws-serverless-java-container-springboot3/pom.xml
Expand Up @@ -265,6 +265,9 @@
<version>${dependencyCheck.version}</version>
<configuration>
<skipProvidedScope>true</skipProvidedScope>
<suppressionFiles>
<suppressionFile>${project.basedir}/../owasp-suppression.xml</suppressionFile>
</suppressionFiles>
<failBuildOnCVSS>7</failBuildOnCVSS>
<failOnError>false</failOnError>
</configuration>
Expand Down
3 changes: 3 additions & 0 deletions aws-serverless-java-container-struts/pom.xml
Expand Up @@ -182,6 +182,9 @@
<version>${dependencyCheck.version}</version>
<configuration>
<skipProvidedScope>true</skipProvidedScope>
<suppressionFiles>
<suppressionFile>${project.basedir}/../owasp-suppression.xml</suppressionFile>
</suppressionFiles>
<failBuildOnCVSS>7</failBuildOnCVSS>
<failOnError>false</failOnError>
</configuration>
Expand Down
27 changes: 27 additions & 0 deletions owasp-suppression.xml
@@ -0,0 +1,27 @@
<?xml version="1.0" encoding="UTF-8"?>
<!--
~ Licensed to the Apache Software Foundation (ASF) under one
~ or more contributor license agreements. See the NOTICE file
~ distributed with this work for additional information
~ regarding copyright ownership. The ASF licenses this file
~ to you under the Apache License, Version 2.0 (the
~ "License"); you may not use this file except in compliance
~ with the License. You may obtain a copy of the License at
~
~ http://www.apache.org/licenses/LICENSE-2.0
~
~ Unless required by applicable law or agreed to in writing,
~ software distributed under the License is distributed on an
~ "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
~ KIND, either express or implied. See the License for the
~ specific language governing permissions and limitations
~ under the License.
-->
<suppressions xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd">

<suppress>
<notes><![CDATA[False positive as per https://github.com/FasterXML/jackson-databind/issues/3972]]></notes>
<packageUrl regex="true">^pkg:maven/com.fasterxml.jackson.core/jackson-databind@.*$</packageUrl>
<cve>CVE-2023-35116</cve>
</suppress>
</suppressions>

0 comments on commit fb9b2cb

Please sign in to comment.