diff --git a/etc/dependency-check-suppression.xml b/etc/dependency-check-suppression.xml index 93f69591..0b4c04fd 100644 --- a/etc/dependency-check-suppression.xml +++ b/etc/dependency-check-suppression.xml @@ -24,6 +24,56 @@ ^pkg:maven/io\.helidon\.integrations\.neo4j/helidon\-integrations\-neo4j@.*$ CVE-2021-34371 + + + ^pkg:maven/io\.helidon\.integrations\.neo4j/helidon\-integrations\-neo4j\-health@.*$ + CVE-2021-34371 + + + + ^pkg:maven/io\.helidon\.integrations\.neo4j/helidon\-integrations\-neo4j\-metrics@.*$ + CVE-2021-34371 + + + + + + ^pkg:maven/io\.helidon\.examples\.grpc/helidon\-examples\-grpc\-common@.*$ + cpe:/a:grpc:grpc + + + + + + ^pkg:maven/io\.helidon\.dbclient/helidon\-dbclient\-mongodb@.*$ + CVE-2021-32036 + + + + ^pkg:maven/io\.helidon\.dbclient/helidon\-dbclient\-mongodb@.*$ + CVE-2014-8180 + + + + ^pkg:maven/io\.helidon\.dbclient/helidon\-dbclient\-mongodb@.*$ + CVE-2016-6494 + - ^pkg:maven/org\.apache\.kafka/kafka\-clients@.*$ - CVE-2022-34917 + ^pkg:maven/com\.h2database/h2@.*$ + CVE-2018-14335 - - + - ^pkg:maven/org\.apache\.kafka/kafka\-clients@.*$ - CVE-2023-25194 + ^pkg:maven/com\.google\.guava/guava@.*$ + CVE-2020-8908 - - ^pkg:maven/com\.h2database/h2@.*$ - CVE-2018-14335 + ^pkg:maven/org\.graalvm\.sdk/graal\-sdk@.*$ + CVE-2023-22006 + + + + ^pkg:maven/org\.graalvm\.sdk/graal\-sdk@.*$ + CVE-2024-20932 - - ^pkg:maven/com\.google\.guava/guava@.*$ - CVE-2020-8908 + ^pkg:maven/com\.fasterxml\.jackson\.core/jackson\-databind@.*$ + CVE-2023-35116 + + + + + + ^pkg:maven/io\.netty/netty\-.*@.*$ + CVE-2023-4586 + + + + + + ^pkg:maven/org\.eclipse\.jgit/org\.eclipse\.jgit@.*$ + CVE-2023-4759 + + + + + + ^pkg:maven/io\.opentracing\.brave/brave\-opentracing@.*$ + CVE-2022-47932 + + + + ^pkg:maven/io\.opentracing\.brave/brave\-opentracing@.*$ + CVE-2022-47933 + + + ^pkg:maven/io\.opentracing\.brave/brave\-opentracing@.*$ + CVE-2022-47934 + + + + ^pkg:maven/io\.opentracing\.brave/brave\-opentracing@.*$ + CVE-2021-22929 + + + + ^pkg:maven/io\.opentracing\.brave/brave\-opentracing@.*$ + CVE-2022-30334 + + + + ^pkg:maven/io\.opentracing\.brave/brave\-opentracing@.*$ + CVE-2023-28360 + + + + + + ^pkg:maven/io\.helidon\.webserver/helidon\-webserver\-access\-log@.*$ + CVE-2022-25760 + diff --git a/etc/scripts/owasp-dependency-check.sh b/etc/scripts/owasp-dependency-check.sh old mode 100644 new mode 100755 index 60b75bbb..c8a200fa --- a/etc/scripts/owasp-dependency-check.sh +++ b/etc/scripts/owasp-dependency-check.sh @@ -1,6 +1,6 @@ #!/bin/bash -e # -# Copyright (c) 2020, 2023 Oracle and/or its affiliates. +# Copyright (c) 2020, 2024 Oracle and/or its affiliates. # # Licensed under the Apache License, Version 2.0 (the "License"); # you may not use this file except in compliance with the License. @@ -36,6 +36,7 @@ fi mvn ${MAVEN_ARGS} -Dorg.slf4j.simpleLogger.defaultLogLevel=WARN org.owasp:dependency-check-maven:aggregate \ -f ${WS_DIR}/pom.xml \ -Dtop.parent.basedir="${WS_DIR}" \ + -Dnvd-api-key=${NVD_API_KEY} \ > ${RESULT_FILE} || die "Error running the Maven command" grep -i "One or more dependencies were identified with known vulnerabilities" ${RESULT_FILE} \ diff --git a/examples/pom.xml b/examples/pom.xml index 80413a3c..ecd16446 100644 --- a/examples/pom.xml +++ b/examples/pom.xml @@ -1,7 +1,7 @@