Skip to content

Conversation

@chadlwilson
Copy link
Collaborator

@chadlwilson chadlwilson commented Jan 26, 2026

Description of Change

A new CVE in a generic named CPE is leading to a lot of FPs

Consolidate to a negative-lookahead suppression.

The library is released as

Vulnerability is categorised against the first two package types: GHSA-fccg-7w3p-w66f so this should be good enough, to also stop the CPE matching against "validator"s in all manner of other package types. The executable jar should match against the jar if indeed a PURL can be inferred for it (if not, a hint can be added)

Related issues

Have test cases been added to cover the new functionality?

N/A

…cker

Signed-off-by: Chad Wilson <29788154+chadlwilson@users.noreply.github.com>
@chadlwilson chadlwilson added maven changes to the maven plugin nvd FP Report labels Jan 26, 2026
@jeremylong jeremylong merged commit c84e196 into dependency-check:generatedSuppressions Jan 27, 2026
1 check passed
@jeremylong jeremylong added this to the 12.2.1 milestone Jan 27, 2026
@chadlwilson chadlwilson deleted the consolidate-vnu-suppression branch January 27, 2026 13:38
@chadlwilson chadlwilson removed this from the 12.2.1 milestone Jan 27, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

FP Report maven changes to the maven plugin nvd

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants