dependencyCheckSuppressions.xml 2.1 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455
  1. <?xml version="1.0" encoding="UTF-8"?>
  2. <suppressions xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd">
  3. <!-- You can add <suppress>...</suppress> entries in here. -->
  4. <!-- Ignore CVE-2020-8908: Used by exoplayer, but vulnerable code (createTempDir)
  5. is not used. -->
  6. <suppress>
  7. <notes><![CDATA[
  8. file name: guava-27.1-android.jar
  9. ]]></notes>
  10. <packageUrl regex="true">^pkg:maven/com\.google\.guava/guava@.*$</packageUrl>
  11. <cve>CVE-2020-8908</cve>
  12. </suppress>
  13. <!-- Ignore CVE-2021-29425: Vulnerable code (FileNameUtils.normalize) not used. -->
  14. <suppress>
  15. <notes><![CDATA[
  16. file name: commons-io-2.6.jar
  17. ]]></notes>
  18. <packageUrl regex="true">^pkg:maven/commons\-io/commons\-io@.*$</packageUrl>
  19. <cve>CVE-2021-29425</cve>
  20. </suppress>
  21. <!-- Ignore CVE-2018-20200: It requires hooking into the running application, CVE is disputed.
  22. https://github.com/square/okhttp/issues/4967 -->
  23. <suppress>
  24. <notes><![CDATA[
  25. file name: okhttp-3.12.0.jar
  26. ]]></notes>
  27. <packageUrl regex="true">^pkg:maven/com\.squareup\.okhttp3/okhttp@.*$</packageUrl>
  28. <cve>CVE-2018-20200</cve>
  29. </suppress>
  30. <!-- Ignore wrong matches. -->
  31. <suppress>
  32. <packageUrl regex="true">^pkg:maven/org\.saltyrtc/saltyrtc\-task\-webrtc@.*$</packageUrl>
  33. <cpe>cpe:/a:webrtc_project:webrtc</cpe>
  34. </suppress>
  35. <suppress>
  36. <packageUrl regex="true">^pkg:maven/org\.saltyrtc/saltyrtc\-task\-webrtc@.*$</packageUrl>
  37. <cpe>cpe:/a:tasks:tasks</cpe>
  38. </suppress>
  39. <suppress>
  40. <packageUrl regex="true">^pkg:maven/com\.huawei\.hmf/tasks@.*$</packageUrl>
  41. <cpe>cpe:/a:tasks:tasks</cpe>
  42. </suppress>
  43. <suppress>
  44. <packageUrl regex="true">^pkg:maven/org\.jetbrains\.kotlin/kotlin\-stdlib@.*$</packageUrl>
  45. <cpe>cpe:/a:jetbrains:kotlin</cpe>
  46. </suppress>
  47. <suppress>
  48. <packageUrl regex="true">^pkg:maven/org\.jetbrains\.kotlin/kotlin\-stdlib\-common@.*$</packageUrl>
  49. <cpe>cpe:/a:jetbrains:kotlin</cpe>
  50. </suppress>
  51. </suppressions>