Skip to content

fix(fp): Consolidate/update icu4j suppressions for false positives#8062

Merged
jeremylong merged 1 commit intodependency-check:mainfrom
chadlwilson:update-icu4j-suppressions
Oct 18, 2025
Merged

fix(fp): Consolidate/update icu4j suppressions for false positives#8062
jeremylong merged 1 commit intodependency-check:mainfrom
chadlwilson:update-icu4j-suppressions

Conversation

@chadlwilson
Copy link
Copy Markdown
Collaborator

@chadlwilson chadlwilson commented Oct 17, 2025

Description of Change

  • Update the list of suppressed icu4j CVEs for java due to lack of support for the target sw ecosystem.
  • Sorted it so it can be compared easily with the search
  • Consolidate into single suppression across multiple java packages for ease of maintenance

Reconciled with the NVD and checked all are C/C++.

Related issues

Have test cases been added to cover the new functionality?

N/A

@boring-cyborg boring-cyborg Bot added the core changes to core label Oct 17, 2025
Copy link
Copy Markdown
Collaborator

@jeremylong jeremylong left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@jeremylong jeremylong merged commit a574ca6 into dependency-check:main Oct 18, 2025
6 checks passed
@jeremylong jeremylong added this to the 12.1.9 milestone Oct 18, 2025
@chadlwilson chadlwilson deleted the update-icu4j-suppressions branch October 18, 2025 11:59
@github-actions github-actions Bot locked as resolved and limited conversation to collaborators Nov 18, 2025
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

core changes to core

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants