Skip to content

Commit e7a8dc7

Browse files
committed
add CVE suppressions for the lateset spring version (this CVE has not been fixed yet)
1 parent 99ac9ad commit e7a8dc7

File tree

2 files changed

+5
-2
lines changed

2 files changed

+5
-2
lines changed

cve-suppressions.xml

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,7 @@
11
<?xml version="1.0" encoding="UTF-8"?>
22
<suppressions xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.1.xsd">
3-
3+
<suppress>
4+
<filePath regex="true">spring-.*-5\.3\.23\.jar</filePath>
5+
<cve>CVE-2016-1000027</cve>
6+
</suppress>
47
</suppressions>

pom.xml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -63,7 +63,7 @@
6363
<maven.compiler.target>11</maven.compiler.target>
6464
<spring.version>5.3.23</spring.version>
6565
<postgresql.version>42.5.0</postgresql.version>
66-
<dependency-check-maven.version>6.3.1</dependency-check-maven.version>
66+
<dependency-check-maven.version>7.2.1</dependency-check-maven.version>
6767
</properties>
6868

6969
<dependencies>

0 commit comments

Comments
 (0)