|
95 | 95 | <packageUrl regex="true">^pkg:maven/org\.zalando/spring\-boot\-etcd@.*$</packageUrl> |
96 | 96 | <cpe>cpe:/a:etcd:etcd</cpe> |
97 | 97 | </suppress> |
98 | | - <suppress base="true"> |
99 | | - <notes><![CDATA[ |
100 | | - FP per #3678 |
101 | | - ]]></notes> |
102 | | - <packageUrl regex="true">^pkg:maven/com\.salesforce\.servicelibs/reactive\-grpc.*$</packageUrl> |
103 | | - <cpe>cpe:/a:grpc:grpc</cpe> |
104 | | - </suppress> |
105 | 98 | <suppress base="true"> |
106 | 99 | <notes><![CDATA[ |
107 | 100 | FP per #3685 |
|
236 | 229 | <packageUrl regex="true">^pkg:maven/io\.helidon\.microprofile\.server/helidon\-microprofile\-server@.*$</packageUrl> |
237 | 230 | <cpe>cpe:/a:oracle:http_server</cpe> |
238 | 231 | </suppress> |
239 | | - <suppress base="true"> |
240 | | - <notes><![CDATA[ |
241 | | - FP per #3015 & #3016 |
242 | | - ]]></notes> |
243 | | - <packageUrl regex="true">^pkg:maven/co\.elastic\.apm/apm\-.*$</packageUrl> |
244 | | - <cpe>cpe:/a:grpc:grpc</cpe> |
245 | | - <cpe>cpe:/a:apache:httpclient</cpe> |
246 | | - </suppress> |
247 | 232 | <suppress base="true"> |
248 | 233 | <notes><![CDATA[ |
249 | 234 | FP per #3005 |
|
272 | 257 | <packageUrl regex="true">^pkg:maven/.*vertx-pg-client@.*$</packageUrl> |
273 | 258 | <cpe>cpe:/a:postgresql:postgresql</cpe> |
274 | 259 | </suppress> |
275 | | - <suppress base="true"> |
276 | | - <notes><![CDATA[ |
277 | | - FP per #3002 CPE is for GRPC core |
278 | | - ]]></notes> |
279 | | - <packageUrl regex="true">^pkg:maven/io\.opencensus/opencensus\-contrib\-grpc\-metrics@.*$</packageUrl> |
280 | | - <cpe>cpe:/a:grpc:grpc</cpe> |
281 | | - </suppress> |
282 | | - <suppress base="true"> |
283 | | - <notes><![CDATA[ |
284 | | - FP per #3002 and #5890 - CVE are for GRPC C/ruby/python etc. Suppressing individual CVEs because ODC cannot understand the target SW |
285 | | - field. NVD search to review in future (not that some are marked incorrectly as affecting all languages) |
286 | | - --> https://nvd.nist.gov/vuln/search#/nvd/home?sortOrder=1&sortDirection=1&cpeFilterMode=applicability&cpeName=cpe:2.3:a:grpc:grpc:*:*:*:*:*:*:*:*&resultType=records |
287 | | - ]]></notes> |
288 | | - <packageUrl regex="true">^pkg:maven/io\.grpc/grpc\-.*$</packageUrl> |
289 | | - <cve>CVE-2017-7860</cve> |
290 | | - <cve>CVE-2017-7861</cve> |
291 | | - <cve>CVE-2017-8359</cve> |
292 | | - <cve>CVE-2017-9431</cve> |
293 | | - <cve>CVE-2020-7768</cve> |
294 | | - <cve>CVE-2023-1428</cve> |
295 | | - <cve>CVE-2023-32731</cve> |
296 | | - <cve>CVE-2023-32732</cve> |
297 | | - <cve>CVE-2023-33953</cve> |
298 | | - <cve>CVE-2023-4785</cve> |
299 | | - <cve>CVE-2024-11407</cve> |
300 | | - <cve>CVE-2024-7246</cve> |
301 | | - </suppress> |
302 | | - <suppress base="true"> |
303 | | - <notes><![CDATA[ |
304 | | - FP per #3002, CPE is for GRPC core |
305 | | - ]]></notes> |
306 | | - <packageUrl regex="true">^pkg:maven/com\.google\.api\.grpc/grpc\-google\-common\-protos@.*$</packageUrl> |
307 | | - <cpe>cpe:/a:grpc:grpc</cpe> |
308 | | - </suppress> |
309 | | - <suppress base="true"> |
310 | | - <notes><![CDATA[ |
311 | | - FP per #3002, CPE is for GRPC core |
312 | | - ]]></notes> |
313 | | - <packageUrl regex="true">^pkg:maven/com\.lightstep\.tracer/.*$</packageUrl> |
314 | | - <cpe>cpe:/a:grpc:grpc</cpe> |
315 | | - </suppress> |
316 | 260 | <suppress base="true"> |
317 | 261 | <notes><![CDATA[ |
318 | 262 | FP per #3001 |
|
2908 | 2852 | <gav regex="true">^com\.typesafe\.akka:akka-persistence-cassandra:.*$</gav> |
2909 | 2853 | <cpe>cpe:/a:akka:akka</cpe> |
2910 | 2854 | </suppress> |
2911 | | - <suppress base="true"> |
2912 | | - <notes><![CDATA[ |
2913 | | - Fp per #2995 |
2914 | | - ]]></notes> |
2915 | | - <packageUrl regex="true">^pkg:maven/io\.opencensus/opencensus\-contrib\-grpc\-util@.*$</packageUrl> |
2916 | | - <cpe>cpe:/a:grpc:grpc</cpe> |
2917 | | - </suppress> |
2918 | | - <suppress base="true"> |
2919 | | - <notes><![CDATA[ |
2920 | | - False positive per issue #1259 and #2991 |
2921 | | - ]]></notes> |
2922 | | - <gav regex="true">^com\.google\.api\.grpc:proto-.*$</gav> |
2923 | | - <cpe>cpe:/a:grpc:grpc</cpe> |
2924 | | - </suppress> |
2925 | 2855 | <suppress base="true"> |
2926 | 2856 | <notes><![CDATA[ |
2927 | 2857 | FP per issue #942 |
|
5012 | 4942 | <packageUrl regex="true">^pkg:maven/com\.google\.flatbuffers/flatbuffers-java@.*$</packageUrl> |
5013 | 4943 | <cpe regex="true">cpe:/a:flat(_project)?:flat.*</cpe> |
5014 | 4944 | </suppress> |
5015 | | - <suppress base="true"> |
5016 | | - <notes><![CDATA[ |
5017 | | - FP per issues #5321, #5322, #5323, #5324 |
5018 | | - ]]></notes> |
5019 | | - <packageUrl regex="true">^pkg:maven/me\.dinowernli/java\-grpc\-prometheus@.*$</packageUrl> |
5020 | | - <cpe>cpe:/a:grpc:grpc</cpe> |
5021 | | - <cpe>cpe:/a:prometheus:prometheus</cpe> |
5022 | | - </suppress> |
5023 | 4945 | <suppress base="true"> |
5024 | 4946 | <notes><![CDATA[ |
5025 | 4947 | FP per issue #5370 |
|
0 commit comments