-
Notifications
You must be signed in to change notification settings - Fork 36
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Added mao's scanning actions from FINOS security scanning #382
Added mao's scanning actions from FINOS security scanning #382
Conversation
…ortant than chatvariable, test failed
any license error causes build fail
Stanford nlp scope
|
/easycla |
1 similar comment
/easycla |
this basically works now, except that there is a new critical CVE for Spring Boot and so our white source / Dependency Checks are failing. Once a new version gets published we can release. Please review + approve. |
@robmoffat - apparently spring-web-5.3.26.jar is affected by CVE-2016-1000027 , which states:
If you don't use spring-web for deserialization of untrusted data (that is, data that is manually entered), I'd suggest to add this to |
@vaibhav-db let's review. Also took out white source for future PRs |
No description provided.