dependency-check-suppressions.xml 855 B

12345678910111213141516
  1. <?xml version="1.0" encoding="UTF-8"?>
  2. <suppressions xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd">
  3. <suppress>
  4. <!-- this suppresses opentelemetry instrumentation modules and artifacts which get misidentified
  5. as real dependencies like dubbo and prometheus -->
  6. <packageUrl regex="true">^pkg:maven/io\.opentelemetry[./].*</packageUrl>
  7. <vulnerabilityName regex="true">^CVE-.*</vulnerabilityName>
  8. </suppress>
  9. <suppress>
  10. <!-- detected CVEs are for otel go and python -->
  11. <packageUrl regex="true">^pkg:maven/com\.google\.cloud\.opentelemetry/detector-resources-support@.*</packageUrl>
  12. <vulnerabilityName>CVE-2023-43810</vulnerabilityName>
  13. <vulnerabilityName>CVE-2023-45142</vulnerabilityName>
  14. <vulnerabilityName>CVE-2023-47108</vulnerabilityName>
  15. </suppress>
  16. </suppressions>