Skip to content

Commit 9502964

Browse files
committed
fix: Avoid FPs for Symfony Contracts as framework
Symfony Contracts are being matched as Symphony framework. However, they are different projects with independent versioning schemes. For example, CVE-2022-23601 for Symfony is resolved in versions 5.3.15, 5.4.4 and 6.0.4. However, Contracts project's latest version is v3.5.2.
1 parent 27dcba2 commit 9502964

File tree

1 file changed

+7
-0
lines changed

1 file changed

+7
-0
lines changed

core/src/main/resources/dependencycheck-base-suppression.xml

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -390,6 +390,13 @@
390390
<packageUrl regex="true">^pkg:composer/symfony/polyfill-.*$</packageUrl>
391391
<cpe>cpe:/a:sensiolabs:symfony</cpe>
392392
</suppress>
393+
<suppress base="true">
394+
<notes><![CDATA[
395+
FP per #7545
396+
]]></notes>
397+
<packageUrl regex="true">^pkg:composer/symfony/.*-contracts@.*$</packageUrl>
398+
<cpe>cpe:/a:sensiolabs:symfony</cpe>
399+
</suppress>
393400
<suppress base="true">
394401
<notes><![CDATA[
395402
FP per #2957

0 commit comments

Comments
 (0)