-
-
Notifications
You must be signed in to change notification settings - Fork 1.3k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[FP]: spring-boot-jarmode-tools incorrectly identified as vmware:tools #6725
Comments
Maven Coordinates <dependency>
<groupId>org.springframework.boot</groupId>
<artifactId>spring-boot-jarmode-tools</artifactId>
<version>3.3.0</version>
</dependency> Suppression rule: <suppress base="true">
<notes><![CDATA[
FP per issue #6725
]]></notes>
<packageUrl regex="true">^pkg:maven/org\.springframework\.boot/spring-boot-jarmode-tools@.*$</packageUrl>
<cpe>cpe:/a:vmware:tools</cpe>
</suppress> Link to test results: https://github.com/jeremylong/DependencyCheck/actions/runs/9514606574 |
approved |
Suppress rule has been added to the |
@aikebah Using dependency-check 10.0.4 |
@rpaasche Resolutions by the bot are immediately available as a suppression in the hosted suppressions file (assuming that you run your scans with internet connectivity it should become active as soon as the currently cached hostedSuppressions file expires - 2hrs after its latest retrieval in the default setup) Check you scan report to see whether it properly identifies your jar as the maven package ( |
I see the problem now:
Will investigate this. Thank you. |
Package URl
pkg:maven/org.springframework.boot/[email protected]
CPE
cpe:2.3:a:vmware:tools:3.3.0:*:*:*:*:*:*:*
CVE
No response
ODC Integration
{"label"=>"Maven Plugin"}
ODC Version
9.2.0
Description
No response
The text was updated successfully, but these errors were encountered: