Skip to content

Commit

Permalink
Supress prometheus false positives (#9315)
Browse files Browse the repository at this point in the history
  • Loading branch information
barchetta authored Oct 2, 2024
1 parent 5a6ecd1 commit 3a851b3
Showing 1 changed file with 18 additions and 0 deletions.
18 changes: 18 additions & 0 deletions etc/dependency-check-suppression.xml
Original file line number Diff line number Diff line change
Expand Up @@ -174,4 +174,22 @@
<cpe>cpe:/a:mysql:mysql</cpe>
</suppress>

<!-- False Positive.
This is against an old version of prometheusa (not prometheus metrics nor micrometer)
-->
<suppress>
<notes><![CDATA[
file name: micrometer-registry-prometheus-simpleclient-1.13.4.jar
]]></notes>
<packageUrl regex="true">^pkg:maven/io\.micrometer/micrometer-registry-prometheus-simpleclient@.*$</packageUrl>
<cve>CVE-2019-3826</cve>
</suppress>
<suppress>
<notes><![CDATA[
file name: prometheus-metrics-core-1.2.1.jar
]]></notes>
<packageUrl regex="true">^pkg:maven/io\.prometheus/prometheus-metrics-(.*)@.*$</packageUrl>
<cve>CVE-2019-3826</cve>
</suppress>

</suppressions>

0 comments on commit 3a851b3

Please sign in to comment.