Skip to content
This repository was archived by the owner on Sep 27, 2025. It is now read-only.

Commit c0b2c0b

Browse files
authored
fix(FP): Several FPs not suitable for our automation (#5504)
1 parent 3be9c17 commit c0b2c0b

File tree

2 files changed

+208
-1
lines changed

2 files changed

+208
-1
lines changed

core/src/main/java/org/owasp/dependencycheck/analyzer/JarAnalyzer.java

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -159,7 +159,8 @@ public class JarAnalyzer extends AbstractFileTypeAnalyzer {
159159
"tstamp",
160160
"dstamp",
161161
"eclipse-sourcereferences",
162-
"kotlin-version");
162+
"kotlin-version",
163+
"require-capability");
163164
/**
164165
* Deprecated Jar manifest attribute, that is, nonetheless, useful for
165166
* analysis.

core/src/main/resources/dependencycheck-base-suppression.xml

Lines changed: 206 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -6180,4 +6180,210 @@
61806180
<packageUrl regex="true">^(?!pkg:maven/org.eclipse.platform).+$</packageUrl>
61816181
<cpe>cpe:/a:eclipse:eclipse_ide</cpe>
61826182
</suppress>
6183+
<suppress base="true">
6184+
<notes><![CDATA[
6185+
suppress various improper matches to the CPE that belongs only to pkg:maven/org.json/json
6186+
FP per #5502
6187+
]]></notes>
6188+
<packageUrl regex="true">^(?!pkg:maven/org\.json/json@).+$</packageUrl>
6189+
<cpe>cpe:/a:json-java_project:json-java</cpe>
6190+
</suppress>
6191+
<suppress base="true">
6192+
<notes><![CDATA[
6193+
suppress various improper matches to the CPE that belongs only to pkg:npm/flat
6194+
FP per #5454
6195+
]]></notes>
6196+
<packageUrl regex="true">^(?!pkg:npm/flat@).+$</packageUrl>
6197+
<cpe>cpe:/a:flat_project:flat</cpe>
6198+
</suppress>
6199+
<suppress base="true">
6200+
<notes><![CDATA[
6201+
FP per issue #5489, make sure to include all apacha calcite-avatica modules
6202+
]]></notes>
6203+
<packageUrl regex="true">^pkg:maven/org\.apache\.calcite\.avatica/.*$</packageUrl>
6204+
<cpe>cpe:/a:apache:calcite:</cpe>
6205+
</suppress>
6206+
<suppress base="true">
6207+
<notes><![CDATA[
6208+
FP per issue #5381, apollo_project:apollo is a PHP project unrelated to apollographql
6209+
]]></notes>
6210+
<packageUrl regex="true">^pkg:maven/com\.apollographql\.apollo/.*$</packageUrl>
6211+
<cpe>cpe:/a:apollo_project:apollo</cpe>
6212+
</suppress>
6213+
<!-- generated suppressions added to main in 8.1.1 -->
6214+
<suppress base="true">
6215+
<notes><![CDATA[
6216+
FP per issue #5333
6217+
]]></notes>
6218+
<packageUrl regex="true">^pkg:maven/com\.graphql-java-kickstart/graphql-kickstart-spring-support@.*$</packageUrl>
6219+
<cpe>cpe:/a:graphql-java_project:graphql-java</cpe>
6220+
</suppress>
6221+
<suppress base="true">
6222+
<notes><![CDATA[
6223+
FP per issue #5336
6224+
]]></notes>
6225+
<packageUrl regex="true">^pkg:maven/org\.openrewrite\.recipe/rewrite-jhipster@.*$</packageUrl>
6226+
<cpe>cpe:/a:jhipster:jhipster</cpe>
6227+
</suppress>
6228+
<suppress base="true">
6229+
<notes><![CDATA[
6230+
FP per issue #5361
6231+
]]></notes>
6232+
<packageUrl regex="true">^pkg:maven/jakarta\.resource/jakarta\.resource-api@.*$</packageUrl>
6233+
<cpe>cpe:/a:payara:payara</cpe>
6234+
</suppress>
6235+
<suppress base="true">
6236+
<notes><![CDATA[
6237+
FP per issue #5373
6238+
]]></notes>
6239+
<packageUrl regex="true">^pkg:maven/org\.locationtech\.spatial4j/spatial4j@.*$</packageUrl>
6240+
<cpe>cpe:/a:voyager_project:voyager</cpe>
6241+
</suppress>
6242+
<suppress base="true">
6243+
<notes><![CDATA[
6244+
FP per issue #5372
6245+
]]></notes>
6246+
<packageUrl regex="true">^pkg:maven/org\.locationtech\.spatial4j/spatial4j@.*$</packageUrl>
6247+
<cpe>cpe:/a:smiley_project:smiley</cpe>
6248+
</suppress>
6249+
<suppress base="true">
6250+
<notes><![CDATA[
6251+
FP per issue #5380
6252+
]]></notes>
6253+
<packageUrl regex="true">^pkg:maven/dev\.ludovic\.netlib/lapack@.*$</packageUrl>
6254+
<cpe>cpe:/a:lapack_project:lapack</cpe>
6255+
</suppress>
6256+
<suppress base="true">
6257+
<notes><![CDATA[
6258+
FP per issue #5375
6259+
]]></notes>
6260+
<packageUrl regex="true">^pkg:maven/org\.eclipse\.microprofile\.jwt/microprofile-jwt-auth-api@.*$</packageUrl>
6261+
<cpe>cpe:/a:payara:payara</cpe>
6262+
</suppress>
6263+
<suppress base="true">
6264+
<notes><![CDATA[
6265+
FP per issue #5368
6266+
]]></notes>
6267+
<packageUrl regex="true">^pkg:maven/org\.apache\.hadoop\.thirdparty/hadoop-shaded-protobuf_3_7@.*$</packageUrl>
6268+
<cpe>cpe:/a:apache:hadoop</cpe>
6269+
</suppress>
6270+
<suppress base="true">
6271+
<notes><![CDATA[
6272+
FP per issue #5325
6273+
]]></notes>
6274+
<packageUrl regex="true">^pkg:maven/com\.enterprisedt/edtFTPj@.*$</packageUrl>
6275+
<cpe>cpe:/a:ftp_project:ftp</cpe>
6276+
</suppress>
6277+
<suppress base="true">
6278+
<notes><![CDATA[
6279+
FP per issue #5436
6280+
]]></notes>
6281+
<packageUrl regex="true">^pkg:maven/org\.codehaus\.woodstox/stax2-api@.*$</packageUrl>
6282+
<cpe>cpe:/a:fasterxml:woodstox</cpe>
6283+
</suppress>
6284+
<suppress base="true">
6285+
<notes><![CDATA[
6286+
FP per issue #5459
6287+
]]></notes>
6288+
<packageUrl regex="true">^pkg:maven/com\.oracle\.database\.nls/orai18n@.*$</packageUrl>
6289+
<cpe>cpe:/a:oracle:database</cpe>
6290+
</suppress>
6291+
<suppress base="true">
6292+
<notes><![CDATA[
6293+
FP per issue #5460
6294+
]]></notes>
6295+
<packageUrl regex="true">^pkg:maven/com\.oracle\.database\.nls/orai18n@.*$</packageUrl>
6296+
<cpe>cpe:/a:oracle:oracle_database</cpe>
6297+
</suppress>
6298+
<suppress base="true">
6299+
<notes><![CDATA[
6300+
FP per issue #5501
6301+
]]></notes>
6302+
<packageUrl regex="true">^pkg:maven/org\.jsonschema2pojo/jsonschema2pojo-jdk-annotation@.*$</packageUrl>
6303+
<cpe>cpe:/a:json-schema_project:json-schema</cpe>
6304+
</suppress>
6305+
<suppress base="true">
6306+
<notes><![CDATA[
6307+
FP per issue #5500
6308+
]]></notes>
6309+
<packageUrl regex="true">^pkg:maven/org\.apache\.iceberg/iceberg-orc@.*$</packageUrl>
6310+
<cpe>cpe:/a:apache:orc</cpe>
6311+
</suppress>
6312+
<suppress base="true">
6313+
<notes><![CDATA[
6314+
FP per issue #5499
6315+
]]></notes>
6316+
<packageUrl regex="true">^pkg:maven/org\.apache\.iceberg/iceberg-flink-1\.15@.*$</packageUrl>
6317+
<cpe>cpe:/a:apache:flink</cpe>
6318+
</suppress>
6319+
<suppress base="true">
6320+
<notes><![CDATA[
6321+
FP per issue #5498
6322+
]]></notes>
6323+
<packageUrl regex="true">^pkg:maven/com\.googlecode\.javaewah/JavaEWAH@.*$</packageUrl>
6324+
<cpe>cpe:/a:google:google_search</cpe>
6325+
</suppress>
6326+
<suppress base="true">
6327+
<notes><![CDATA[
6328+
FP per issue #5497
6329+
]]></notes>
6330+
<packageUrl regex="true">^pkg:maven/com\.google\.cloud/grpc-gcp@.*$</packageUrl>
6331+
<cpe>cpe:/a:grpc:grpc</cpe>
6332+
</suppress>
6333+
<suppress base="true">
6334+
<notes><![CDATA[
6335+
FP per issue #5496
6336+
]]></notes>
6337+
<packageUrl regex="true">^pkg:maven/org\.apache\.flink/flink-s3-fs-hadoop@.*$</packageUrl>
6338+
<cpe>cpe:/a:apache:hadoop</cpe>
6339+
</suppress>
6340+
<suppress base="true">
6341+
<notes><![CDATA[
6342+
FP per issue #5492
6343+
]]></notes>
6344+
<packageUrl regex="true">^pkg:maven/com\.microsoft\.azure/azure-cosmosdb-direct@.*$</packageUrl>
6345+
<cpe>cpe:/a:microsoft:platform_sdk</cpe>
6346+
</suppress>
6347+
<suppress base="true">
6348+
<notes><![CDATA[
6349+
FP per issue #5491
6350+
]]></notes>
6351+
<packageUrl regex="true">^pkg:maven/com\.microsoft\.azure/azure-cosmosdb@.*$</packageUrl>
6352+
<cpe>cpe:/a:www-sql_project:www-sql</cpe>
6353+
</suppress>
6354+
<suppress base="true">
6355+
<notes><![CDATA[
6356+
FP per issue #5490
6357+
]]></notes>
6358+
<packageUrl regex="true">^pkg:maven/com\.microsoft\.azure/azure-cosmosdb@.*$</packageUrl>
6359+
<cpe>cpe:/a:async_project:async</cpe>
6360+
</suppress>
6361+
<suppress base="true">
6362+
<notes><![CDATA[
6363+
FP per issue #5471
6364+
]]></notes>
6365+
<packageUrl regex="true">^pkg:maven/org\.apache\.spark/spark-token-provider-kafka-0-10_2\.12@.*$</packageUrl>
6366+
<cpe>cpe:/a:apache:kafka</cpe>
6367+
</suppress>
6368+
<suppress base="true">
6369+
<notes><![CDATA[
6370+
FP per issue #5462
6371+
]]></notes>
6372+
<packageUrl regex="true">^pkg:maven/org\.apache\.ws\.commons\.axiom/axiom-impl@.*$</packageUrl>
6373+
<cpe>cpe:/a:web_project:web</cpe>
6374+
</suppress>
6375+
<suppress base="true">
6376+
<notes><![CDATA[
6377+
FP per issue #5461
6378+
]]></notes>
6379+
<packageUrl regex="true">^pkg:maven/com\.github\.luben/zstd-jni@.*$</packageUrl>
6380+
<cpe>cpe:/a:freebsd:freebsd</cpe>
6381+
</suppress>
6382+
<suppress base="true">
6383+
<notes><![CDATA[
6384+
FP per issue #5506
6385+
]]></notes>
6386+
<packageUrl regex="true">^pkg:maven/io\.kamon/kamon-prometheus_2\.13@.*$</packageUrl>
6387+
<cpe>cpe:/a:prometheus:prometheus</cpe>
6388+
</suppress>
61836389
</suppressions>

0 commit comments

Comments
 (0)