This is an automated email from the ASF dual-hosted git repository.

lukaszlenart pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/struts.git


The following commit(s) were added to refs/heads/main by this push:
     new a99a06bc6 WW-5735 build(jasperreports7): declare jasperreports as 
provided (#1926)
a99a06bc6 is described below

commit a99a06bc6acc2de121bddfcc15068ab7a429e636
Author: Lukasz Lenart <[email protected]>
AuthorDate: Sat Sep 12 18:31:13 2026 +0200

    WW-5735 build(jasperreports7): declare jasperreports as provided (#1926)
    
    * WW-5735 build(jasperreports7): declare jasperreports as provided
    
    The plugin declared net.sf.jasperreports:jasperreports at compile scope,
    so the assembly's runtime dependency set shipped jasperreports-7.0.7.jar
    in struts-*-lib.zip and struts-*-all.zip since 7.1.0, and every Maven
    consumer of the plugin pulled it transitively. JasperReports is LGPL,
    which may not be included in an Apache product; the 6.x plugin has
    always declared the same dependency as provided for this reason.
    
    Applications add net.sf.jasperreports:jasperreports (and
    jasperreports-pdf for PDF output) themselves, as with the 6.x plugin.
    
    Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
    
    * WW-5735 build: drop the OWASP suppression for the no longer shipped 
jasperreports jar
    
    The dependency-check profile skips provided scope, so with jasperreports
    declared provided the jar is no longer scanned and the CVE-2025-10492
    suppression has nothing left to match.
    
    Co-Authored-By: Claude Opus 5 (1M context) <[email protected]>
    
    ---------
    
    Co-authored-by: Claude Opus 5 (1M context) <[email protected]>
---
 plugins/jasperreports7/pom.xml  | 1 +
 src/etc/project-suppression.xml | 8 --------
 2 files changed, 1 insertion(+), 8 deletions(-)

diff --git a/plugins/jasperreports7/pom.xml b/plugins/jasperreports7/pom.xml
index 00017e256..a15849384 100644
--- a/plugins/jasperreports7/pom.xml
+++ b/plugins/jasperreports7/pom.xml
@@ -42,6 +42,7 @@
             <groupId>net.sf.jasperreports</groupId>
             <artifactId>jasperreports</artifactId>
             <version>${jasperreports7.version}</version>
+            <scope>provided</scope>
             <exclusions>
                 <!-- not necessary to compile and it force dependency 
convergence issues -->
                 <exclusion>
diff --git a/src/etc/project-suppression.xml b/src/etc/project-suppression.xml
index 718b3a7cb..587e8ace0 100644
--- a/src/etc/project-suppression.xml
+++ b/src/etc/project-suppression.xml
@@ -18,14 +18,6 @@
   under the License.
 -->
 <suppressions 
xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd";>
-    <suppress>
-        <notes><![CDATA[
-    file name: jasperreports-*.jar
-    
https://community.jaspersoft.com/knowledgebase/faq/update-details-about-the-java-vulnerability-r4897/
-    One way to prevent such an attack would be to make sure the parent Java 
application runs on Java 17 or later, where this type of attack is blocked by 
some changes made to the Java platform itself.
-    ]]></notes>
-        <cve>CVE-2025-10492</cve>
-    </suppress>
     <suppress>
         <notes><![CDATA[false positive due to naming to close to apache tiles
         cpe:2.3:a:apache:tiles:*:*:*:*:*:*:*:* versions from (including) 
2.0]]></notes>

Reply via email to