You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
before every release:
check for each suppressed vulnerability if it's still reasonable/necessary to suppress it
otherwise we are possibly releasing with security flaws which could easily being solved
hpvd
changed the title
Owasp dependency check: check if suppressing of Vulnerabilities is still reasonable
Owasp dependency check: check if suppressing of vulnerabilities is still reasonable
Aug 11, 2022
hpvd
changed the title
Owasp dependency check: check if suppressing of vulnerabilities is still reasonable
[security] Owasp dependency check: check if suppressing of vulnerabilities is still reasonable
Oct 28, 2023
hpvd
changed the title
[security] Owasp dependency check: check if suppressing of vulnerabilities is still reasonable
[Security] Owasp dependency check: check if suppressing of vulnerabilities is still reasonable
Oct 28, 2023
Search before asking
Motivation
Since #10855 we are doing dependency scans for vulnerabilities on regular basis. That is really great!
Over time, more and more vulnerabilities are suppressed.
This may
org.apache.pulsar:pulsar-server-distribution:2.11.0-SNAPSHOT:
Vulnerabilities Suppressed: 23
org.apache.pulsar:pulsar-offloader-distribution:2.11.0-SNAPSHOT:
Vulnerabilities Suppressed: 4
Solution
before every release:
check for each suppressed vulnerability if it's still reasonable/necessary to suppress it
otherwise we are possibly releasing with security flaws which could easily being solved
before: update check tool to latest version (which typical solves some false positive)
7.11+, the check today uses see 7.10 https://github.com/jeremylong/DependencyCheck/releases
Alternatives
Anything else?
No response
Are you willing to submit a PR?
The text was updated successfully, but these errors were encountered: