From 9b5188e7bfb0fd759d7201d018c20efd5fde8310 Mon Sep 17 00:00:00 2001 From: Armin Schrenk Date: Mon, 15 Apr 2024 15:37:13 +0200 Subject: [PATCH] cleanup cve suppression list --- suppression.xml | 42 ++++++------------------------------------ 1 file changed, 6 insertions(+), 36 deletions(-) diff --git a/suppression.xml b/suppression.xml index 6417cf9..a831953 100644 --- a/suppression.xml +++ b/suppression.xml @@ -3,8 +3,9 @@ + Incorrectly matched CPE + ]]> + org\.cryptomator:.* cpe:/a:cryptomator:cryptomator CVE-2022-25366 @@ -12,42 +13,11 @@ + Suppress false positive, because com.google.common.io.Files.getTempDir() is not used + ]]> + ^pkg:maven/com\.google\.guava/guava@.*$ CVE-2020-8908 CVE-2020-8908 - - - ^pkg:maven/org\.bouncycastle/bcutil\-jdk15on@.*$ - CVE-2023-33202 - - - - ^pkg:maven/org\.bouncycastle/bcpkix\-jdk15on@.*$ - CVE-2023-33202 - - - - ^pkg:maven/org\.bouncycastle/bcprov\-jdk15on@.*$ - CVE-2023-33202 - - - - ^pkg:maven/org\.bouncycastle/bcprov\-jdk15on@.*$ - CVE-2023-33201 -