fix: prevent rogue base suppression files#7544
Merged
Conversation
aikebah
reviewed
Mar 23, 2025
core/src/main/java/org/owasp/dependencycheck/analyzer/AbstractSuppressionAnalyzer.java
Show resolved
Hide resolved
Collaborator
|
Looking once more at the code I was thinking... why are we even bothering to go through so many loopholes when the only thing we want to load in the end is the resource we expect to find. Can you see any reason to not simply apply a KISS principle and try to load 'the resource-URL we expect based on the codesource' rather than validating the resource-URLs discovered by java and only load when the resource-URL matches what we expect to find? |
Collaborator
Author
|
Thanks for the suggestion. See the updated code. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description of Change
PR #7541 showed the maintainers that it was possible for a rogue library to add a suppression file
Have test cases been added to cover the new functionality?
No, existing test cases appropriately load the suppression file. A negative test case was not added.