diff --git a/pom.xml b/pom.xml index 9a155d1a1df0..0d804441be0d 100644 --- a/pom.xml +++ b/pom.xml @@ -1389,7 +1389,6 @@ - @@ -1450,6 +1449,35 @@ + + dependency-check + + + dependency-check + + + + + + org.owasp + dependency-check-maven + 9.0.9 + + nvd + ./sca-overrides/owasp-suppressions.xml + + + + + aggregate + + + + + + + + + + + + ^pkg:maven/org\.glassfish\.expressly/expressly@.*$ + cpe:/a:eclipse:glassfish + + + + ^pkg:maven/org\.wildfly\.security\.jakarta/jakarta\-client\-resteasy@.*$ + cpe:/a:redhat:resteasy + + + + ^pkg:maven/org\.jboss/jboss\-iiop\-client@.*$ + cpe:/a:redhat:jboss-ejb-client + + + + ^pkg:maven/org\.wildfly/mvc\-krazo\-subsystem@.*$ + cpe:/a:redhat:wildfly + + + + ^pkg:maven/org\.wildfly/mvc\-krazo\-galleon\-shared@.*$ + cpe:/a:redhat:wildfly + + + + ^pkg:maven/org\.wildfly\.extras\.batavia/transformer\-api@.*$ + cpe:/a:redhat:wildfly + + + + ^pkg:maven/org\.wildfly\.security/wildfly\-elytron\-audit@.*$ + cpe:/a:linux_audit_project:linux_audit + + + + ^pkg:maven/org\.wildfly\.core/wildfly\-.*@.*$ + cpe:/a:redhat:wildfly + + + + ^pkg:maven/org\.wildfly\.plugins/wildfly\-plugin\-core@.*$ + cpe:/a:redhat:wildfly + cpe:/a:redhat:wildfly_core + + + + ^pkg:maven/org\.wildfly\.galleon\-plugins/transformer@.*$ + cpe:/a:redhat:wildfly + + + + ^pkg:maven/org\.wildfly\.deployment/wildfly\-ee\-9\-deployment\-transformer@.*$ + cpe:/a:redhat:wildfly + + + + ^pkg:maven/org\.wildfly\.galleon\-plugins/wildfly\-galleon\-plugins@.*$ + cpe:/a:redhat:wildfly + + + + + + + + + + + ^pkg:maven/org\.apache\.directory\.server/apacheds\-.*@.*$ + CVE-2010-1151 + + + + ^pkg:maven/org\.apache\.mina/mina\-core@.*$ + CVE-2021-41973 + + + + ^pkg:maven/io\.grpc/grpc\-api@.*$ + CVE-2023-44487 + + + + ^pkg:maven/com\.h2database/h2@.*$ + + CVE-2018-14335 + + + + ^pkg:maven/com\.fasterxml\.jackson\.core/jackson\-databind@.*$ + + CVE-2023-35116 + + + + ^pkg:maven/org\.glassfish\.soteria/jakarta\.security\.enterprise@.*$ + CVE-2020-1732 + + + + ^pkg:maven/org\.jgroups\.aws/jgroups\-aws@.*$ + CVE-2016-2141 + + + + ^pkg:maven/org\.apache\.commons/commons\-compress@.*$ + CVE-2024-25710 + CVE-2024-26308 + + + + ^pkg:maven/io\.opentelemetry\.proto/opentelemetry\-proto@.*$ + CVE-2023-43810 + CVE-2023-45142 + CVE-2023-47108 + + + + ^pkg:maven/org\.jboss\.resteasy\.spring/resteasy\-spring@.*$ + CVE-2016-9606 + CVE-2014-3490 + CVE-2020-1695 + CVE-2020-10688 + CVE-2023-0482 + CVE-2020-25633 + CVE-2021-20289 + + + + ^pkg:maven/org\.jboss\.resteasy/resteasy\-tracing\-api@.*$ + CVE-2016-9606 + CVE-2020-10688 + CVE-2023-0482 + CVE-2020-25633 + CVE-2021-20289 + CVE-2011-5245 + CVE-2012-0818 + + + + ^pkg:maven/io\.undertow/undertow\-core@.*$ + CVE-2016-6311 + + + + ^pkg:maven/org\.jboss\.resteasy\.spring/resteasy\-spring@.*$ + CVE-2021-20293 + + + + ^pkg:maven/org\.jboss\.resteasy/resteasy\-tracing\-api@.*$ + CVE-2021-20293 + + + + ^pkg:maven/org\.jboss\.resteasy\.spring/resteasy\-spring@.*$ + CVE-2018-1051 + +