dependency-check / dependency-check/DependencyCheck

Update False Positive IssueOps to support non-CVE vulnerabilities

Open
#4,105 0 comments 0 reactions 1 assignee Claimed by @jeremylong View on GitHub
enhancement
Dominant language
Java
Stars
7.7k
Forks
1.4k
Avg merge
9d 22h
Merged PRs (30d)
13

Description

As seen in https://github.com/jeremylong/DependencyCheck/issues/4099 - if the vulnerability comes from one of the non-CVE sources the suppression rule needs to use the `CWE-862: Missing Authorization` instead of the CVE element. These types of non-CVE vulns could come from NPM, OSS Index, etc.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.