Add OWASP suppression (#1377)

This commit is contained in:
dotasek 2023-08-01 14:03:40 -04:00 committed by GitHub
parent fd1eea71e6
commit 921ed912ff
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
2 changed files with 22 additions and 0 deletions

View File

@ -0,0 +1,17 @@
<?xml version="1.0" encoding="UTF-8"?>
<suppressions xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd">
<suppress>
<notes><![CDATA[
This suppresses CVEs related to a HAPI-FHIR parent pom that no longer exists in fhir-test-cases
]]></notes>
<packageUrl regex="true">^pkg:maven/org\.hl7\.fhir\.testcases/fhir\-test\-cases@.*$</packageUrl>
<cve>CVE-2019-12741</cve>
</suppress>
<suppress>
<notes><![CDATA[
This suppresses CVEs related to a HAPI-FHIR parent pom that no longer exists in fhir-test-cases
]]></notes>
<packageUrl regex="true">^pkg:maven/org\.hl7\.fhir\.testcases/fhir\-test\-cases@.*$</packageUrl>
<cve>CVE-2021-32053</cve>
</suppress>
</suppressions>

View File

@ -705,6 +705,11 @@
<plugin>
<groupId>org.owasp</groupId>
<artifactId>dependency-check-maven</artifactId>
<configuration>
<suppressionFiles>
<suppressionFile>owasp-suppression-file.xml</suppressionFile>
</suppressionFiles>
</configuration>
<executions>
<execution>
<goals>