From ba15af63de596c48fe69d387ae39d123cebc7087 Mon Sep 17 00:00:00 2001 From: nwithan8 Date: Fri, 29 Sep 2023 11:20:48 -0600 Subject: [PATCH] - Bump DependencyCheck, skip known CVE in plugin --- dependency-check-suppressions.xml | 7 ++++++- pom.xml | 8 ++++++-- 2 files changed, 12 insertions(+), 3 deletions(-) diff --git a/dependency-check-suppressions.xml b/dependency-check-suppressions.xml index 86f0d6eeb..576299f08 100644 --- a/dependency-check-suppressions.xml +++ b/dependency-check-suppressions.xml @@ -3,11 +3,16 @@ CVE-2022-3171 CVE-2022-3509 CVE-2022-3510 CVE-2023-2976 + + CVE-2023-4759 diff --git a/pom.xml b/pom.xml index 47a93738b..fc7b1eec4 100644 --- a/pom.xml +++ b/pom.xml @@ -83,6 +83,12 @@ 1.18.26 provided + + org.eclipse.jgit + org.eclipse.jgit + 6.7.0.202309050840-r + test + @@ -334,8 +340,6 @@ dependency-check-suppressions.xml 7 7 - false - true