Skip to content
Snippets Groups Projects

Dependency updates to eliminate vulnerabilities discovered by dependency-check

Merged bhill6@wisc.edu requested to merge dependency_updates into main

Eliminated all CRITICAL and HIGH except for CVE-2016-1000027 (which more or less forbids the use of Spring since 2016 -- it's moderately controversial.

@road

Merge request reports

Loading
Loading

Activity

Filter activity
  • Approvals
  • Assignees & reviewers
  • Comments (from bots)
  • Comments (from users)
  • Commits & branches
  • Edits
  • Labels
  • Lock status
  • Mentions
  • Merge request status
  • Tracking
  • dependency-check-report.html latest dependency check report after updates.

  • added 1 commit

    Compare with previous version

  • added 1 commit

    • 79eec30f - Removing log4j dependencies from test and substituting logback as the slf4j...

    Compare with previous version

  • added 1 commit

    Compare with previous version

  • added 1 commit

    • 00866503 - another fix for CWE-93 issue in sample code raised by SAST

    Compare with previous version

  • Lyle Hanson
  • Lyle Hanson
  • added 1 commit

    • 8db88ca0 - reorganized gitlab-ci for scanning

    Compare with previous version

  • bhill6@wisc.edu resolved all threads

    resolved all threads

  • Interesting. It seems that adding the Security/SAST-IaC.latest.gitlab-ci.yml scans caused it to scan the dependency-check-report.html files and treat them like code (triggering a slew of new CRITICALS).

    Since we don't really need the maven OWASP scans with the gitlab ones available, I'm going to remove that from the pom file to avoid this stranger error that it caused.

  • added 1 commit

    • 9e8b8594 - removing maven-dependency-check plugin to avoid false positives from gitlab scans

    Compare with previous version

  • Lyle Hanson
  • Lyle Hanson
  • added 1 commit

    Compare with previous version

  • added 1 commit

    • 0b83cff8 - removed unused cvs-suppressions file

    Compare with previous version

  • Lyle Hanson
  • Loading
  • Loading
  • Loading
  • Loading
  • Loading
  • Loading
  • Loading
  • Loading
  • Loading
  • Loading
  • Please register or sign in to reply
    Loading