Skip to content

Commit cb0b903

Browse files
committed
Avoid noise from non-prod libraries
1 parent 6a781e3 commit cb0b903

File tree

2 files changed

+1
-11
lines changed

2 files changed

+1
-11
lines changed

build-config/dependency-check-suppressions.xml

-9
Original file line numberDiff line numberDiff line change
@@ -1,15 +1,6 @@
11
<?xml version="1.0" encoding="UTF-8"?>
22
<suppressions xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd">
33

4-
<suppress>
5-
<notes><![CDATA[
6-
Recce doesn't use the H2 console so is not affected by these apparent vulnerabilities.
7-
]]></notes>
8-
<packageUrl regex="true">^pkg:maven/com\.h2database/h2@.*$</packageUrl>
9-
<cve>CVE-2018-14335</cve>
10-
<cve>CVE-2022-45868</cve>
11-
</suppress>
12-
134
<suppress>
145
<notes><![CDATA[
156
This is a false positive "noise" CVE: https://github.com/FasterXML/jackson-databind/issues/3972

build.gradle.kts

+1-2
Original file line numberDiff line numberDiff line change
@@ -167,8 +167,7 @@ dependencies {
167167
dependencyCheck {
168168
failBuildOnCVSS = 1f
169169
suppressionFile = "build-config/dependency-check-suppressions.xml"
170-
scanConfigurations = listOf("runtimeClasspath", "testRuntimeClasspath")
171-
skipTestGroups = false
170+
scanConfigurations = listOf("runtimeClasspath")
172171
analyzers.assemblyEnabled = false // Unneeded, and creates warning noise
173172
}
174173

0 commit comments

Comments
 (0)