Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Improved Report Testing #7

Open
wants to merge 20 commits into
base: main
Choose a base branch
from
Open

Improved Report Testing #7

wants to merge 20 commits into from

Conversation

rottebds
Copy link
Contributor

@rottebds rottebds commented Dec 6, 2021

No description provided.

@github-actions
Copy link

github-actions bot commented Feb 9, 2022

❌ Found dependencies violating policy!

Policies Violated Dependency License(s) Vulnerabilities Short Term Recommended Upgrade Long Term Recommended Upgrade
Review Status (BLOCKER)
Med Risk Vuln (CRITICAL)
Spring Framework 5.3.10 Apache License 2.0 ❌   BDSA-2021-3236 (MEDIUM: CVSS 4.3)
❌   BDSA-2022-0011 (MEDIUM: CVSS 4.3)
5.3.15 (0 known vulnerabilities) 5.3.15 (0 known vulnerabilities)
Review Status (BLOCKER)
Med Risk Vuln (CRITICAL)
Spring Framework 5.3.10 Apache License 2.0 ❌   BDSA-2021-3236 (MEDIUM: CVSS 4.3)
❌   BDSA-2022-0011 (MEDIUM: CVSS 4.3)
5.3.15 (0 known vulnerabilities) 5.3.15 (0 known vulnerabilities)
Review Status (BLOCKER) Apache Commons Compress 1.20 Apache License 2.0 BDSA-2021-2076 (LOW: CVSS 3.7)
BDSA-2021-2078 (LOW: CVSS 3.7)
BDSA-2021-2073 (LOW: CVSS 3.7)
BDSA-2021-2075 (LOW: CVSS 3.7)
1.21.0.redhat-00001 (0 known vulnerabilities) 1.21.0.redhat-00001 (0 known vulnerabilities)
Review Status (BLOCKER) Guava: Google Core Libraries for Java v23.3 Apache License 2.0 BDSA-2018-1358 (LOW: CVSS 3.7)
BDSA-2020-3736 (LOW: CVSS 1.7)
v23.6 (2 known vulnerabilities) 31.0.1-jre (0 known vulnerabilities)
Review Status (BLOCKER)
Med Risk Vuln (CRITICAL)
Logback 1.2.6 GNU Lesser General Public License v2.1 only
Eclipse Public License 1.0
❌   BDSA-2021-3818 (MEDIUM: CVSS 5.1)
BDSA-2021-3401 (LOW: CVSS 3)
1.2.10 (0 known vulnerabilities) 1.2.10 (0 known vulnerabilities)
Review Status (BLOCKER)
Med Risk Vuln (CRITICAL)
Spring TestContext Framework 5.3.10 Apache License 2.0 ❌   CVE-2021-22060 (MEDIUM: CVSS 4)
❌   CVE-2021-22096 (MEDIUM: CVSS 4)
5.3.15 (0 known vulnerabilities) 5.3.15 (0 known vulnerabilities)
Review Status (BLOCKER)
Med Risk Vuln (CRITICAL)
Spring Framework 5.3.10 Apache License 2.0 ❌   BDSA-2021-3236 (MEDIUM: CVSS 4.3)
❌   BDSA-2022-0011 (MEDIUM: CVSS 4.3)
5.3.15 (0 known vulnerabilities) 5.3.15 (0 known vulnerabilities)
Review Status (BLOCKER)
Med Risk Vuln (CRITICAL)
Spring Framework 5.3.10 Apache License 2.0 ❌   BDSA-2021-3236 (MEDIUM: CVSS 4.3)
❌   BDSA-2022-0011 (MEDIUM: CVSS 4.3)
5.3.15 (0 known vulnerabilities) 5.3.15 (0 known vulnerabilities)
Review Status (BLOCKER)
Med Risk Vuln (CRITICAL)
Spring Framework 5.3.10 Apache License 2.0 ❌   BDSA-2021-3236 (MEDIUM: CVSS 4.3)
❌   BDSA-2022-0011 (MEDIUM: CVSS 4.3)
5.3.15 (0 known vulnerabilities) 5.3.15 (0 known vulnerabilities)
Review Status (BLOCKER)
Med Risk Vuln (CRITICAL)
Logback 1.2.6 GNU Lesser General Public License v2.1 only
Eclipse Public License 1.0
❌   BDSA-2021-3818 (MEDIUM: CVSS 5.1)
BDSA-2021-3401 (LOW: CVSS 3)
1.2.10 (0 known vulnerabilities) 1.2.10 (0 known vulnerabilities)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant