Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FP]: CVE-2023-45142 detector-resources-support-0.32.0 #7248

Closed
rochish-suresh opened this issue Dec 13, 2024 · 3 comments
Closed

[FP]: CVE-2023-45142 detector-resources-support-0.32.0 #7248

rochish-suresh opened this issue Dec 13, 2024 · 3 comments
Labels
duplicate FP Report maven changes to the maven plugin

Comments

@rochish-suresh
Copy link

Package URl

pkg:maven/com.google.cloud.opentelemetry/detector-resources-support@0.32.0

CPE

cpe:2.3:a:opentelemetry:opentelemetry:0.32.0:::::::*

CVE

CVE-2023-45142

ODC Integration

{"label"=>"Gradle Plugin"}

ODC Version

11.1.1

Description

No response

Copy link
Contributor

Maven Coordinates

<dependency>
   <groupId>com.google.cloud.opentelemetry</groupId>
   <artifactId>detector-resources-support</artifactId>
   <version>0.32.0</version>
</dependency>

Suppression rule:

<suppress base="true">
   <notes><![CDATA[
   FP per issue #7248
   ]]></notes>
   <packageUrl regex="true">^pkg:maven/com\.google\.cloud\.opentelemetry/detector-resources-support@.*$</packageUrl>
   <cpe>cpe:/a:opentelemetry:opentelemetry</cpe>
</suppress>

Link to test results: https://github.com/jeremylong/DependencyCheck/actions/runs/12311985342

@github-actions github-actions bot added the maven changes to the maven plugin label Dec 13, 2024
@chadlwilson
Copy link
Contributor

You don't need to create an item for every single CVE if the library and CPE are the same.

Please also include a description so people know why you think it is a false positive.

@aikebah
Copy link
Collaborator

aikebah commented Dec 17, 2024

Duplicate of #7247

@aikebah aikebah marked this as a duplicate of #7247 Dec 17, 2024
@aikebah aikebah closed this as not planned Won't fix, can't repro, duplicate, stale Dec 17, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
duplicate FP Report maven changes to the maven plugin
Projects
None yet
Development

No branches or pull requests

3 participants