apache / apache/pulsar

[Security] Owasp dependency check: check if suppressing of vulnerabilities is still reasonable

Open
#17,068 1 comment 0 reactions 0 assignees View on GitHub
Stale
Dominant language
Java
Stars
15.3k
Forks
3.8k
Avg merge
1d 14h
Merged PRs (30d)
160

Description

### Search before asking

- [X] I searched in the [issues](https://github.com/apache/pulsar/issues) and found nothing similar.

### Motivation

Since https://github.com/apache/pulsar/pull/10855 we are doing dependency scans for vulnerabilities on regular basis. That is really great!

Over time, more and more vulnerabilities are suppressed.
This may
- not be necessary anymore if it's about suppressing false positive (since number of false positive are reduced with every new version of check tool)
- may hide some open vulnerabilities even if there is a solution available now

org.apache.pulsar:pulsar-server-distribution:2.11.0-SNAPSHOT:
**Vulnerabilities Suppressed: 23**

org.apache.pulsar:pulsar-offloader-distribution:2.11.0-SNAPSHOT:
**Vulnerabilities Suppressed: 4**

### Solution

**before every release:**
check for each suppressed vulnerability if it's still reasonable/necessary to suppress it
otherwise we are possibly releasing with security flaws which could easily being solved

**before:** update check tool to latest version (which typical solves some false positive)
7.11+, the check today uses see 7.10 https://github.com/jeremylong/DependencyCheck/releases

### Alternatives

### Anything else?

_No response_

### Are you willing to submit a PR?

- [ ] I'm willing to submit a PR!

Contributor guide

Open the contributing guide

Research direction

Locate the OWASP Dependency-Check configuration and suppression entries for pulsar-server-distribution and pulsar-offloader-distribution; the issue does not name their files. Compare the current check tool with version 7.11+ and reassess the 23 and 4 suppressed vulnerabilities before a release. Done means unnecessary suppressions are removed and remaining ones are justified.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
build-system, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.