Skip to content

Commit 5cdcd59

Browse files
authored
Suppress false positive OWASP violation (#1705)
1 parent 01f7d32 commit 5cdcd59

File tree

2 files changed

+14
-0
lines changed

2 files changed

+14
-0
lines changed

buildSrc/src/main/kotlin/otel.java-conventions.gradle.kts

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -192,6 +192,7 @@ afterEvaluate {
192192

193193
dependencyCheck {
194194
scanConfigurations = mutableListOf("runtimeClasspath")
195+
suppressionFile = "buildscripts/dependency-check-suppressions.xml"
195196
failBuildOnCVSS = 7.0f // fail on high or critical CVE
196197
nvd.apiKey = System.getenv("NVD_API_KEY")
197198
nvd.delay = 3500 // until next dependency check release (https://github.com/jeremylong/DependencyCheck/pull/6333)
Lines changed: 13 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,13 @@
1+
<?xml version="1.0" encoding="UTF-8"?>
2+
<suppressions xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd">
3+
<suppress>
4+
<!-- this package is misidentified by OWASP as an Android app named "Wire" -->
5+
<packageUrl regex="true">^pkg:maven/com\.squareup\.wire/wire-runtime-jvm@.*$</packageUrl>
6+
<cpe>cpe:/a:wire:wire</cpe>
7+
</suppress>
8+
<suppress>
9+
<!-- this package is misidentified by OWASP as Prometheus server -->
10+
<packageUrl regex="true">^pkg:maven/io\.opentelemetry/opentelemetry-exporter-prometheus@.*$</packageUrl>
11+
<cpe>cpe:/a:prometheus:prometheus</cpe>
12+
</suppress>
13+
</suppressions>

0 commit comments

Comments
 (0)