hughpearse opened a new pull request, #4159: URL: https://github.com/apache/calcite/pull/4159
<html> <body> <!--StartFragment--><p style="margin: 0px; padding: 0px; color: rgb(23, 43, 77); font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Oxygen, Ubuntu, "Fira Sans", "Droid Sans", "Helvetica Neue", sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;">Automated scans are failing of the repo blocking corporate process for library approval due to CVE vulnerability findings. Very minor change to site gemfile required to pass the scans.</p><p style="margin: 10px 0px 0px; padding: 0px; color: rgb(23, 43, 77); font-family: -apple-system, BlinkMacSystemFo nt, "Segoe UI", Roboto, Oxygen, Ubuntu, "Fira Sans", "Droid Sans", "Helvetica Neue", sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;">Scanning tool is Trivy, and issue does not appear in owasp dependency-check.</p><p style="margin: 10px 0px 0px; padding: 0px; color: rgb(23, 43, 77); font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Oxygen, Ubuntu, "Fira Sans", "Droid Sans", "Helvetica Neue", sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; fo nt-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"> </p><ul style="margin: 10px 0px 0px; color: rgb(23, 43, 77); font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Oxygen, Ubuntu, "Fira Sans", "Droid Sans", "Helvetica Neue", sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;"><li>Scan of <b><a href="https://github.com/apache/calcite*" class="external-link" target="_blank" rel="nofollow noopener" title="Follow link" style="color: rgb(0, 82, 204); text-decoration: var(--aui-link-decoration); cursor: pointer;">https://github.com/apache/calcite*</a> on *Jan 17, 2025</b><br>Repo Tag Scanned:<span> </span><b>calcite-1.38.0</b></li></ul><div class="table-wrap" style="margin: 0px; padding: 0px; color: rgb(23, 43, 77); font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Oxygen, Ubuntu, "Fira Sans", "Droid Sans", "Helvetica Neue", sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: i nitial; text-decoration-style: initial; text-decoration-color: initial;"> Vulnerabilities -- HIGH | rexml | 3.2.5 | >= 3.3.9 | CVE-2024-49761 | https://avd.aquasec.com/nvd/cve-2024-49761 HIGH | webrick | 1.7.0 | >= 1.8.2 | CVE-2024-47220 | https://avd.aquasec.com/nvd/cve-2024-47220 MEDIUM | nokogiri | 1.14.3 | 1.15.6, 1.16.2 | GHSA-vcc3-rw6f-jv97 | https://github.com/advisories/GHSA-vcc3-rw6f-jv97 MEDIUM | nokogiri | 1.14.3 | ~> 1.15.6, >= 1.16.2 | GHSA-xc9x-jj77-9p9j | https://github.com/advisories/GHSA-xc9x-jj77-9p9j MEDIUM | rexml | 3.2.5 | >= 3.2.7 | CVE-2024-35176 | https://avd.aquasec.com/nvd/cve-2024-35176 MEDIUM | rexml | 3.2.5 | >= 3.3.2 | CVE-2024-39908 | https://avd.aquasec.com/nvd/cve-2024-39908 MEDIUM | rexml | 3.2.5 | >= 3.3.3 | CVE-2024-41123 | https://avd.aquasec.com/nvd/cve-2024-41123 MEDIUM | rexml | 3.2.5 | >= 3.3.3 | CVE-2024-41946 | https://avd.aquasec.com/nvd/cve-2024-41946 MEDIUM | rexml | 3.2.5 | >= 3.3.6 | CVE-2024-43398 | https://avd.aquasec.com/nvd/cve-2024-43398 </div><p style="margin: 10px 0px 0px; padding: 0px; color: rgb(23, 43, 77); font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, Oxygen, Ubuntu, "Fira Sans", "Droid Sans", "Helvetica Neue", sans-serif; font-size: 14px; font-style: normal; font-variant-ligatures: normal; font-variant-caps: normal; font-weight: 400; letter-spacing: normal; orphans: 2; text-align: start; text-indent: 0px; text-transform: none; widows: 2; word-spacing: 0px; -webkit-text-stroke-width: 0px; white-space: normal; background-color: rgb(255, 255, 255); text-decoration-thickness: initial; text-decoration-style: initial; text-decoration-color: initial;">Solution is to update the site Gemfile</p><!--EndFragment--> </body> </html> See following Jira ticket [CALCITE-6794](https://issues.apache.org/jira/browse/CALCITE-6794) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
