Skip to content

Conversation

chadlwilson
Copy link
Collaborator

@chadlwilson chadlwilson commented Oct 17, 2025

Description of Change

Updates the list of suppressions for GRPC java for newer C++/native vulns after review. See #5890 (comment), however at this time I didn't realise we already had a CVE-by-CVE suppression list. I suppose we chose to do so since grpc is such a big/popular library.

Can review the CVEs at NVD.

Related issues

Have test cases been added to cover the new functionality?

N/A

@boring-cyborg boring-cyborg bot added the core changes to core label Oct 17, 2025
@chadlwilson
Copy link
Collaborator Author

Tests need a re-run (our flaky friend Comparison method violates its general contract!).

@jeremylong jeremylong merged commit cca70e0 into dependency-check:main Oct 18, 2025
14 of 16 checks passed
@jeremylong jeremylong added this to the 12.1.9 milestone Oct 18, 2025
@chadlwilson chadlwilson deleted the fix-grpc-java-fps branch October 18, 2025 11:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

core changes to core

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[FP]: CVE-2023-33953 - grpc-context-1.56.1.jar

2 participants