Skip to content

Commit cd8332c

Browse files
committed
Suppress false positives in dependency track report
1 parent 979c34c commit cd8332c

File tree

1 file changed

+16
-1
lines changed

1 file changed

+16
-1
lines changed

dependency-check-supress.xml

Lines changed: 16 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,19 @@
11
<?xml version="1.0" encoding="UTF-8"?>
22
<suppressions xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd">
3-
3+
<suppress>
4+
<notes><![CDATA[
5+
file name: icu4j-75.1.jar
6+
This is a known false positive related to the CVE data
7+
]]></notes>
8+
<packageUrl regex="true">^pkg:maven/com\.ibm\.icu/icu4j@.*$</packageUrl>
9+
<cve>CVE-2025-5222</cve>
10+
</suppress>
11+
<suppress>
12+
<notes><![CDATA[
13+
file name: spdx-java-model-2_X-1.0.1.jar
14+
Reference https://github.com/dependency-check/DependencyCheck/issues/8051
15+
]]></notes>
16+
<packageUrl regex="true">^pkg:maven/org\.spdx/spdx-java-model-2_X@.*$</packageUrl>
17+
<cpe>cpe:/a:x.org:x.org</cpe>
18+
</suppress>
419
</suppressions>

0 commit comments

Comments
 (0)