hughpearse opened a new pull request, #4162:
URL: https://github.com/apache/calcite/pull/4162

   Automated scans are failing of the repo blocking corporate process for 
library approval due to CVE vulnerability findings. Very minor change to site 
gemfile required to pass the scans.
   
   Scanning tool is Trivy, and issue does not appear in owasp dependency-check.
   
   Scan of https://github.com/apache/calcite* on *Jan 17, 2025
   Repo Tag Scanned: 
[calcite-1](https://issues.apache.org/jira/browse/CALCITE-1).38.0
   Vulnerabilities --
   HIGH | rexml | 3.2.5 | >= 3.3.9 | 
https://github.com/advisories/GHSA-2rxp-v6pw-ch6m | 
https://avd.aquasec.com/nvd/cve-2024-49761
   HIGH | webrick | 1.7.0 | >= 1.8.2 | 
https://github.com/advisories/GHSA-6f62-3596-g6w7 | 
https://avd.aquasec.com/nvd/cve-2024-47220
   MEDIUM | nokogiri | 1.14.3 | 1.15.6, 1.16.2 | 
https://github.com/advisories/GHSA-vcc3-rw6f-jv97 | 
https://github.com/advisories/GHSA-vcc3-rw6f-jv97
   MEDIUM | nokogiri | 1.14.3 | ~> 1.15.6, >= 1.16.2 | 
https://github.com/advisories/GHSA-xc9x-jj77-9p9j | 
https://github.com/advisories/GHSA-xc9x-jj77-9p9j
   MEDIUM | rexml | 3.2.5 | >= 3.2.7 | 
https://github.com/advisories/GHSA-vg3r-rm7w-2xgh | 
https://avd.aquasec.com/nvd/cve-2024-35176
   MEDIUM | rexml | 3.2.5 | >= 3.3.2 | 
https://github.com/advisories/GHSA-4xqq-m2hx-25v8 | 
https://avd.aquasec.com/nvd/cve-2024-39908
   MEDIUM | rexml | 3.2.5 | >= 3.3.3 | 
https://github.com/advisories/GHSA-r55c-59qm-vjw6 | 
https://avd.aquasec.com/nvd/cve-2024-41123
   MEDIUM | rexml | 3.2.5 | >= 3.3.3 | 
https://github.com/advisories/GHSA-5866-49gr-22v4 | 
https://avd.aquasec.com/nvd/cve-2024-41946
   MEDIUM | rexml | 3.2.5 | >= 3.3.6 | 
https://github.com/advisories/GHSA-vmwr-mc7x-5vc3 | 
https://avd.aquasec.com/nvd/cve-2024-43398
   
   Solution is to update the site Gemfile
   
   See following Jira ticket
   [CALCITE-6794](https://issues.apache.org/jira/browse/CALCITE-6794)
   
   Related to [PR#4159](https://github.com/apache/calcite/pull/4159)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to