Skip to content

Suppress gradleApi() transitive CVEs in rewrite-gradle-tooling-model:plugin#7752

Merged
timtebeek merged 2 commits into
mainfrom
tim/fix-gradle-tooling-cves
May 20, 2026
Merged

Suppress gradleApi() transitive CVEs in rewrite-gradle-tooling-model:plugin#7752
timtebeek merged 2 commits into
mainfrom
tim/fix-gradle-tooling-cves

Conversation

@timtebeek
Copy link
Copy Markdown
Member

@timtebeek timtebeek commented May 20, 2026

Summary

Test plan

  • CI dependencyCheckAggregate no longer reports the 7 vulnerabilities on rewrite-gradle-tooling-model:plugin

…plugin

The jline and log4j 2.17.1 jars come from gradleApi() and are provided by
the user's Gradle runtime, not shipped with our artifact. Suppress until
2026-11-01.
@timtebeek timtebeek merged commit 2ee8cfd into main May 20, 2026
@timtebeek timtebeek deleted the tim/fix-gradle-tooling-cves branch May 20, 2026 20:40
@github-project-automation github-project-automation Bot moved this from In Progress to Done in OpenRewrite May 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

Archived in project

Development

Successfully merging this pull request may close these issues.

1 participant