Skip to content

Conversation

@astubbs
Copy link
Contributor

@astubbs astubbs commented Jul 9, 2022

Description...

Checklist

  • Documentation (if applicable)
  • Changelog

- CVE-2020-8908: Files::createTempDir local information disclosure vulnerability #4011
- Only used transitively from tests, and is a deprecated function
- google/guava#4011
@astubbs astubbs requested a review from rkolesnev July 9, 2022 08:10
astubbs added 5 commits July 9, 2022 09:10
New issues with WireMocks dep on Jetty BOM ~v9
…that

Especially given we also use dependabot. If anyone is concerned to that level, they can use the plugin in their end user applications.
@astubbs astubbs changed the title build: Exclude Guava 31.1 from OSSIndex sec scan - CVE-2020-8908 WONT_FIX build: Exclude Guava 31.1 from OSSIndex sec scan - because Guava marked CVE-2020-8908 as WONT_FIX Jul 11, 2022
@astubbs astubbs changed the title build: Exclude Guava 31.1 from OSSIndex sec scan - because Guava marked CVE-2020-8908 as WONT_FIX build: OSS Index scan change to warn only and exclude Guava CVE-2020-8908 as it's WONT_FIX Jul 11, 2022
@astubbs astubbs marked this pull request as ready for review July 11, 2022 10:45
@astubbs astubbs merged commit 8198ccf into confluentinc:master Jul 11, 2022
@astubbs astubbs deleted the exclude-guava-oss-index branch July 11, 2022 10:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant