Skip to content

Commit 7c700bd

Browse files
authored
fix(fp): Consolidate false positive suppression for false positives on Redis client libs (#8017)
Signed-off-by: Chad Wilson <[email protected]>
1 parent f8f4877 commit 7c700bd

File tree

1 file changed

+5
-31
lines changed

1 file changed

+5
-31
lines changed

core/src/main/resources/dependencycheck-base-suppression.xml

Lines changed: 5 additions & 31 deletions
Original file line numberDiff line numberDiff line change
@@ -6350,24 +6350,12 @@
63506350
<!-- end generated suppressions added to main in 8.4.0 -->
63516351
<suppress base="true">
63526352
<notes><![CDATA[
6353-
FP per #4321
6353+
FP per #4321, #7444, #7740, 8016
6354+
Redis client packages within various languages are not the same as the redis server
6355+
NOTE: the additional colon in the CPE is required to not match on prefix with cpe:/a:redis:redis.js etc
63546356
]]></notes>
6355-
<packageUrl regex="true">^pkg:(pypi/redis|generic/Microsoft\.Extensions\.Caching\.StackExchangeRedis|generic/HealthChecks\.Redis)@.*$</packageUrl>
6356-
<cve>CVE-2021-32626</cve>
6357-
<cve>CVE-2021-32627</cve>
6358-
<cve>CVE-2021-32628</cve>
6359-
<cve>CVE-2021-32675</cve>
6360-
<cve>CVE-2021-32687</cve>
6361-
<cve>CVE-2021-32762</cve>
6362-
<cve>CVE-2021-41099</cve>
6363-
<cve>CVE-2022-24735</cve>
6364-
<cve>CVE-2022-24834</cve>
6365-
<cve>CVE-2021-31294</cve>
6366-
<cve>CVE-2021-32672</cve>
6367-
<cve>CVE-2022-24736</cve>
6368-
<cve>CVE-2022-36021</cve>
6369-
<cve>CVE-2023-25155</cve>
6370-
<cve>CVE-2023-28856</cve>
6357+
<packageUrl regex="true">^pkg:(pypi|nuget|generic|npm|composer)/.*[rR]edis.*@.*$</packageUrl>
6358+
<cpe>cpe:/a:redis:redis:</cpe>
63716359
</suppress>
63726360
<!-- generated suppression 8.4.0 up to 9.1.0 -->
63736361
<suppress base="true">
@@ -7085,20 +7073,6 @@
70857073
<packageUrl regex="true">^pkg:nuget/IronPython@.*$</packageUrl>
70867074
<cpe>cpe:/a:python:python</cpe>
70877075
</suppress>
7088-
<suppress base="true">
7089-
<notes><![CDATA[
7090-
FP per issue #7444
7091-
]]></notes>
7092-
<packageUrl regex="true">^pkg:nuget/.+\.Redis\..*$</packageUrl>
7093-
<cpe>cpe:2.3:a:redis:redis</cpe>
7094-
</suppress>
7095-
<suppress base="true">
7096-
<notes><![CDATA[
7097-
FP per issue #7740
7098-
]]></notes>
7099-
<packageUrl regex="true">^pkg:npm/.*redis.*@.*$</packageUrl>
7100-
<cpe>cpe:2.3:a:redis:redis</cpe>
7101-
</suppress>
71027076
<suppress base="true">
71037077
<notes><![CDATA[
71047078
FP per issue #7664

0 commit comments

Comments
 (0)