Skip to content

Commit 57d5254

Browse files
2 parents 520749e + 60a5d4f commit 57d5254

File tree

1 file changed

+63
-0
lines changed

1 file changed

+63
-0
lines changed

allow-list.xml

Lines changed: 63 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -79,4 +79,67 @@
7979
]]></notes>
8080
<cve>CVE-2020-15824</cve>
8181
</suppress>
82+
<suppress>
83+
<notes><![CDATA[
84+
This CVE only affects projects fetching p2 repo's over HTTP, but we use HTTPS.
85+
]]></notes>
86+
<cve>CVE-2021-41033</cve>
87+
</suppress>
88+
<suppress>
89+
<notes><![CDATA[
90+
We are using Reload4j, which is a secure drop-in replacement for log4j.
91+
]]></notes>
92+
<cve>CVE-2020-9493</cve>
93+
</suppress>
94+
<suppress>
95+
<notes><![CDATA[
96+
We are using Reload4j, which is a secure drop-in replacement for log4j.
97+
]]></notes>
98+
<cve>CVE-2022-23307</cve>
99+
</suppress>
100+
<suppress>
101+
<notes><![CDATA[
102+
This CVE is not about org.junit.platform.commons. It seems the check is
103+
too loose.
104+
]]></notes>
105+
<cve>CVE-2020-27225</cve>
106+
</suppress>
107+
<suppress>
108+
<notes><![CDATA[
109+
This CVE only affects projects using Xtext prior to 2.18.0.
110+
]]></notes>
111+
<cve>CVE-2019-10249</cve>
112+
</suppress>
113+
<suppress>
114+
<notes><![CDATA[
115+
Calling the method `com.google.common.io.Files.createTempDir` is a vulnerability,
116+
but we do not call it.
117+
]]></notes>
118+
<cve>CVE-2020-8908</cve>
119+
</suppress>
120+
<suppress>
121+
<notes><![CDATA[
122+
We are not creating SVG's with Batik of Apache XML Graphics.
123+
]]></notes>
124+
<cve>CVE-2022-41704</cve>
125+
</suppress>
126+
<suppress>
127+
<notes><![CDATA[
128+
We are not creating SVG's with Batik of Apache XML Graphics.
129+
]]></notes>
130+
<cve>CVE-2022-42890</cve>
131+
</suppress>
132+
<suppress>
133+
<notes><![CDATA[
134+
This CVE is not about org.eclipse.e4.emf.xpath. It seems the check is
135+
too loose.
136+
]]></notes>
137+
<cve>CVE-2022-41852</cve>
138+
</suppress>
139+
<suppress>
140+
<notes><![CDATA[
141+
This only affects milestone and RC versions, but we use a stable release.
142+
]]></notes>
143+
<cve>CVE-2020-15824</cve>
144+
</suppress>
82145
</suppressions>

0 commit comments

Comments
 (0)