From 26f8d937dd4b0bff2b52a1e31464d819b1c0a267 Mon Sep 17 00:00:00 2001 From: Joe DiPol Date: Tue, 8 Oct 2024 12:35:40 -0700 Subject: [PATCH 1/3] 3.x: Suppress GlassFish false positives (#9339) * Upgrade dependency check plugin * Suppress glassfish false positive --- etc/dependency-check-suppression.xml | 15 +++++++++++++++ pom.xml | 2 +- 2 files changed, 16 insertions(+), 1 deletion(-) diff --git a/etc/dependency-check-suppression.xml b/etc/dependency-check-suppression.xml index 771312c2cb0..4e5518a3ad8 100644 --- a/etc/dependency-check-suppression.xml +++ b/etc/dependency-check-suppression.xml @@ -2,6 +2,21 @@ + + + + ^pkg:maven/org\.glassfish.*/(jakarta\.el|jakarta\.json|jaxb-core|jaxb-runtime|osgi-resource-locator|txw2)@.*$ + CVE-2024-9329 + +