Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Skip dependency-check on extensions-contrib modules and suppress false-positive gRPC CVEs #15026

Conversation

tejaswini-imply
Copy link
Member

@tejaswini-imply tejaswini-imply commented Sep 22, 2023

With this PR contrib extensions are being excluded from dependency CVE checks so that the release process would go smoothly. Instead, those CVEs in contrib extensions can be fixed on an ad-hoc basis when someone reports them.

Discussion thread - https://lists.apache.org/thread/hmoc68fg3gmwjz110tf3s5sxrmnr34jk

Suppress false-positive gRPC CVEs:
CVE-2023-4785, CVE-2023-33953 aren't applicable to gRPC Java.

@abhishekagarwal87 abhishekagarwal87 merged commit 48b6d2a into apache:master Sep 25, 2023
@LakshSingla LakshSingla added this to the 28.0 milestone Oct 12, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants