From fc5f9dc44dde37851e835815d4b215b1a6f70a27 Mon Sep 17 00:00:00 2001 From: Joe DiPol Date: Wed, 10 Jul 2024 10:51:59 -0700 Subject: [PATCH] 1.x: upgrade owasp dependency check to 10.0.2 (#8953) * Upgrade OCI SDK to 2.73.0 * upgrade owasp dependency check plugin to 10.0.2 * Supress false positive for brave --- dependencies/pom.xml | 2 +- etc/dependency-check-suppression.xml | 47 ++++++++++++++++++++++++++++ pom.xml | 4 +-- 3 files changed, 50 insertions(+), 3 deletions(-) diff --git a/dependencies/pom.xml b/dependencies/pom.xml index d8a452ab0fc..99792edf35e 100644 --- a/dependencies/pom.xml +++ b/dependencies/pom.xml @@ -88,7 +88,7 @@ 8.0.29 5.9.3.Final 4.1.108.Final - 2.66.0 + 2.73.0 19.3.0.0 0.32.0 0.2.1 diff --git a/etc/dependency-check-suppression.xml b/etc/dependency-check-suppression.xml index 89a76de519c..105b2674449 100644 --- a/etc/dependency-check-suppression.xml +++ b/etc/dependency-check-suppression.xml @@ -292,5 +292,52 @@ CVE-2023-4759 + + + + ^pkg:maven/io\.opentracing\.brave/brave\-opentracing@.*$ + CVE-2022-47932 + + + + ^pkg:maven/io\.opentracing\.brave/brave\-opentracing@.*$ + CVE-2022-47933 + + + + ^pkg:maven/io\.opentracing\.brave/brave\-opentracing@.*$ + CVE-2022-47934 + + + + ^pkg:maven/io\.opentracing\.brave/brave\-opentracing@.*$ + CVE-2021-22929 + + + + ^pkg:maven/io\.opentracing\.brave/brave\-opentracing@.*$ + CVE-2022-30334 + + + + ^pkg:maven/io\.opentracing\.brave/brave\-opentracing@.*$ + CVE-2023-28360 + + + diff --git a/pom.xml b/pom.xml index bfd42273ad0..406f5e7f12d 100644 --- a/pom.xml +++ b/pom.xml @@ -112,7 +112,7 @@ 3.1.12 1.0.3 2.19.1 - 9.1.0 + 10.0.2 1.1 2.3 1.4 @@ -524,7 +524,7 @@ ${dependency-check.skip} true - false + 0 false