Skip to content

Commit

Permalink
trivy
Browse files Browse the repository at this point in the history
  • Loading branch information
southeo committed Mar 21, 2024
1 parent 512e531 commit eafa2de
Show file tree
Hide file tree
Showing 2 changed files with 7 additions and 1 deletion.
7 changes: 6 additions & 1 deletion .github/workflows/.trivyignore
Original file line number Diff line number Diff line change
@@ -1,4 +1,9 @@
# Date: Feb 19, 2024
# Issue: Libexpat, parsing large tokens can trigger a denial of service
# Solution: Update docker image
CVE-2023-52425
CVE-2023-52425

# Date: March 21, 2024
# Issue: Vulnerability in spring-web
# Solution: Spring boot needs to update its version of spring
CVE-2024-22259
1 change: 1 addition & 0 deletions pom.xml
Original file line number Diff line number Diff line change
Expand Up @@ -27,6 +27,7 @@
</sonar.coverage.jacoco.xmlReportPaths>
<sonar.host.url>https://sonarcloud.io</sonar.host.url>
<sonar.organization>dissco</sonar.organization>
<spring-security.version>6.2.3</spring-security.version> <!-- 21/03/24: CVE-2024-22257-->
<version.victools>4.28.0</version.victools>
</properties>

Expand Down

0 comments on commit eafa2de

Please sign in to comment.