This is an automated email from the ASF dual-hosted git repository.

lukaszlenart pushed a commit to branch WW-5735-jasperreports-provided
in repository https://gitbox.apache.org/repos/asf/struts.git

commit b680d3c9e4611784a2716c82cd536645af9b46c4
Author: Lukasz Lenart <[email protected]>
AuthorDate: Sat Sep 12 15:39:11 2026 +0200

    WW-5735 build: drop the OWASP suppression for the no longer shipped 
jasperreports jar
    
    The dependency-check profile skips provided scope, so with jasperreports
    declared provided the jar is no longer scanned and the CVE-2025-10492
    suppression has nothing left to match.
    
    Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
---
 src/etc/project-suppression.xml | 8 --------
 1 file changed, 8 deletions(-)

diff --git a/src/etc/project-suppression.xml b/src/etc/project-suppression.xml
index 718b3a7cb..587e8ace0 100644
--- a/src/etc/project-suppression.xml
+++ b/src/etc/project-suppression.xml
@@ -18,14 +18,6 @@
   under the License.
 -->
 <suppressions 
xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd";>
-    <suppress>
-        <notes><![CDATA[
-    file name: jasperreports-*.jar
-    
https://community.jaspersoft.com/knowledgebase/faq/update-details-about-the-java-vulnerability-r4897/
-    One way to prevent such an attack would be to make sure the parent Java 
application runs on Java 17 or later, where this type of attack is blocked by 
some changes made to the Java platform itself.
-    ]]></notes>
-        <cve>CVE-2025-10492</cve>
-    </suppress>
     <suppress>
         <notes><![CDATA[false positive due to naming to close to apache tiles
         cpe:2.3:a:apache:tiles:*:*:*:*:*:*:*:* versions from (including) 
2.0]]></notes>

Reply via email to