Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[FP]: Multiple False positives found in dependency check scan #7383

Closed
NamineniVaishnavi opened this issue Feb 10, 2025 · 3 comments
Closed

Comments

@NamineniVaishnavi
Copy link

Package URl

jre-8u431-linux-x64.rpm: jfr.jar

CPE

cpe:2.3:a:oracle:jrockit:1.8.0.431

CVE

CVE-2009-1006

ODC Integration

None

ODC Version

7.1.0

Description

False Positives ticket.docx
Multiple false positives vulnerabilities were identified while running dependency checker scan. I have mentioned only one CVE in the ticket. Since there are numerous CVE's filing multiple reports is time consuming, so I have attached a document with all the CVE's and the justification for them being False positive. Please consider the same.

Copy link
Contributor

Error parsing package url: jre-8u431-linux-x64.rpm: jfr.jar.

Error: Error: Invalid purl: missing required "pkg" scheme component

Please correct the package URL - consider copying the package url from the HTML report.

Copy link
Contributor

Failed to automatically evaluate the false positive. See: https://github.com/jeremylong/DependencyCheck/actions/runs/13234611865

@aikebah
Copy link
Collaborator

aikebah commented Feb 12, 2025

ODC 7.1.0 is outdated as indicated on #7384 I cannot reproduce the FPs with an up-to-date CLI

@aikebah aikebah closed this as not planned Won't fix, can't repro, duplicate, stale Feb 12, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants