Skip to content

Commit

Permalink
Merge pull request #133 from yetanalytics/clojure-nvd-suppression
Browse files Browse the repository at this point in the history
CVE-2017-20189 is false positive for most libs with clojure name
  • Loading branch information
kelvinqian00 authored Jan 31, 2024
2 parents c0b776c + d12b21f commit 9fe286b
Showing 1 changed file with 9 additions and 1 deletion.
10 changes: 9 additions & 1 deletion .nvd/suppression.xml
Original file line number Diff line number Diff line change
@@ -1,4 +1,12 @@
<?xml version="1.0" encoding="UTF-8"?>
<suppressions xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd">
<!-- No suppressions needed at the moment -->
<suppress>
<notes><![CDATA[
all packages except for org.clojure/clojure
]]></notes>
<packageUrl regex="true">^pkg:maven\/(?!org\.clojure\/clojure).*$</packageUrl>
<cpe>cpe:/a:clojure:clojure</cpe>
<cve>CVE-2017-20189</cve>
</suppress>
</suppressions>

0 comments on commit 9fe286b

Please sign in to comment.