hughpearse opened a new pull request, #4162: URL: https://github.com/apache/calcite/pull/4162
Automated scans are failing of the repo blocking corporate process for library approval due to CVE vulnerability findings. Very minor change to site gemfile required to pass the scans. Scanning tool is Trivy, and issue does not appear in owasp dependency-check. Scan of https://github.com/apache/calcite* on *Jan 17, 2025 Repo Tag Scanned: [calcite-1](https://issues.apache.org/jira/browse/CALCITE-1).38.0 Vulnerabilities -- HIGH | rexml | 3.2.5 | >= 3.3.9 | https://github.com/advisories/GHSA-2rxp-v6pw-ch6m | https://avd.aquasec.com/nvd/cve-2024-49761 HIGH | webrick | 1.7.0 | >= 1.8.2 | https://github.com/advisories/GHSA-6f62-3596-g6w7 | https://avd.aquasec.com/nvd/cve-2024-47220 MEDIUM | nokogiri | 1.14.3 | 1.15.6, 1.16.2 | https://github.com/advisories/GHSA-vcc3-rw6f-jv97 | https://github.com/advisories/GHSA-vcc3-rw6f-jv97 MEDIUM | nokogiri | 1.14.3 | ~> 1.15.6, >= 1.16.2 | https://github.com/advisories/GHSA-xc9x-jj77-9p9j | https://github.com/advisories/GHSA-xc9x-jj77-9p9j MEDIUM | rexml | 3.2.5 | >= 3.2.7 | https://github.com/advisories/GHSA-vg3r-rm7w-2xgh | https://avd.aquasec.com/nvd/cve-2024-35176 MEDIUM | rexml | 3.2.5 | >= 3.3.2 | https://github.com/advisories/GHSA-4xqq-m2hx-25v8 | https://avd.aquasec.com/nvd/cve-2024-39908 MEDIUM | rexml | 3.2.5 | >= 3.3.3 | https://github.com/advisories/GHSA-r55c-59qm-vjw6 | https://avd.aquasec.com/nvd/cve-2024-41123 MEDIUM | rexml | 3.2.5 | >= 3.3.3 | https://github.com/advisories/GHSA-5866-49gr-22v4 | https://avd.aquasec.com/nvd/cve-2024-41946 MEDIUM | rexml | 3.2.5 | >= 3.3.6 | https://github.com/advisories/GHSA-vmwr-mc7x-5vc3 | https://avd.aquasec.com/nvd/cve-2024-43398 Solution is to update the site Gemfile See following Jira ticket [CALCITE-6794](https://issues.apache.org/jira/browse/CALCITE-6794) Related to [PR#4159](https://github.com/apache/calcite/pull/4159) -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
