File tree Expand file tree Collapse file tree 2 files changed +14
-0
lines changed Expand file tree Collapse file tree 2 files changed +14
-0
lines changed Original file line number Diff line number Diff line change @@ -192,6 +192,7 @@ afterEvaluate {
192
192
193
193
dependencyCheck {
194
194
scanConfigurations = mutableListOf (" runtimeClasspath" )
195
+ suppressionFile = " buildscripts/dependency-check-suppressions.xml"
195
196
failBuildOnCVSS = 7.0f // fail on high or critical CVE
196
197
nvd.apiKey = System .getenv(" NVD_API_KEY" )
197
198
nvd.delay = 3500 // until next dependency check release (https://github.com/jeremylong/DependencyCheck/pull/6333)
Original file line number Diff line number Diff line change
1
+ <?xml version =" 1.0" encoding =" UTF-8" ?>
2
+ <suppressions xmlns =" https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd" >
3
+ <suppress >
4
+ <!-- this package is misidentified by OWASP as an Android app named "Wire" -->
5
+ <packageUrl regex =" true" >^pkg:maven/com\.squareup\.wire/wire-runtime-jvm@.*$</packageUrl >
6
+ <cpe >cpe:/a:wire:wire</cpe >
7
+ </suppress >
8
+ <suppress >
9
+ <!-- this package is misidentified by OWASP as Prometheus server -->
10
+ <packageUrl regex =" true" >^pkg:maven/io\.opentelemetry/opentelemetry-exporter-prometheus@.*$</packageUrl >
11
+ <cpe >cpe:/a:prometheus:prometheus</cpe >
12
+ </suppress >
13
+ </suppressions >
You can’t perform that action at this time.
0 commit comments