dependency-check / dependency-check/DependencyCheck
Update False Positive IssueOps to support non-CVE vulnerabilities
Open
enhancement
- Dominant language
- Java
- Stars
- 7.7k
- Forks
- 1.4k
- Avg merge
- 9d 22h
- Merged PRs (30d)
- 13
Description
As seen in https://github.com/jeremylong/DependencyCheck/issues/4099 - if the vulnerability comes from one of the non-CVE sources the suppression rule needs to use the `CWE-862: Missing Authorization` instead of the CVE element. These types of non-CVE vulns could come from NPM, OSS Index, etc.
Contributor guide
Assessment
This issue has not been assessed yet.