This is an automated email from the ASF dual-hosted git repository. lukaszlenart pushed a commit to branch WW-5735-jasperreports-provided in repository https://gitbox.apache.org/repos/asf/struts.git
commit b680d3c9e4611784a2716c82cd536645af9b46c4 Author: Lukasz Lenart <[email protected]> AuthorDate: Sat Sep 12 15:39:11 2026 +0200 WW-5735 build: drop the OWASP suppression for the no longer shipped jasperreports jar The dependency-check profile skips provided scope, so with jasperreports declared provided the jar is no longer scanned and the CVE-2025-10492 suppression has nothing left to match. Co-Authored-By: Claude Opus 5 (1M context) <[email protected]> --- src/etc/project-suppression.xml | 8 -------- 1 file changed, 8 deletions(-) diff --git a/src/etc/project-suppression.xml b/src/etc/project-suppression.xml index 718b3a7cb..587e8ace0 100644 --- a/src/etc/project-suppression.xml +++ b/src/etc/project-suppression.xml @@ -18,14 +18,6 @@ under the License. --> <suppressions xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd"> - <suppress> - <notes><![CDATA[ - file name: jasperreports-*.jar - https://community.jaspersoft.com/knowledgebase/faq/update-details-about-the-java-vulnerability-r4897/ - One way to prevent such an attack would be to make sure the parent Java application runs on Java 17 or later, where this type of attack is blocked by some changes made to the Java platform itself. - ]]></notes> - <cve>CVE-2025-10492</cve> - </suppress> <suppress> <notes><![CDATA[false positive due to naming to close to apache tiles cpe:2.3:a:apache:tiles:*:*:*:*:*:*:*:* versions from (including) 2.0]]></notes>
