The GitHub Actions job "CI" on grails-core.git/build/vulnerability-scan-plugin has succeeded. Run started by GitHub user jdaugherty (triggered by jdaugherty).
Head commit for run: 4d9267298c2fa66d7774c8052d4222d4ce414bae / James Daugherty <[email protected]> Replace the Sonatype scan plugin with our own vulnerability scan The scan-gradle-plugin behind ossIndexAudit is archived and its scanning has moved into Sonatype's commercial offering. The vulnerability-scan build-logic project now implements the scan itself. - The vulnerabilityScan task looks the resolved runtimeClasspath and compileClasspath up in OSV and, when SONATYPE_GUIDE_USERNAME and SONATYPE_GUIDE_TOKEN are set, in Sonatype Guide through the same component report API the old plugin used. Each database knows of vulnerabilities the other does not yet; one both know of, by id or alias, is reported once. - The credentials are read when the scan runs, and the answers of both are cached for an hour in the Gradle user home (vulnerabilityScan.cacheTtl), so repeated scans do not spend Sonatype Guide credits or hit rate limits. - An exclusion names a vulnerability id or alias and a group:artifact instead of a whole group:artifact:version, so a version bump no longer orphans it, and each needs a reason. The exclusions of the old plugin are carried over, with the Spring Security and Spring Framework CVEs its whole-coordinate exclusions also covered, which have no open source fix on the 6.x lines either. The HdrHistogram and spring-webmvc entries Sonatype Guide no longer reports are dropped. - The root vulnerabilityScanReport task writes a Markdown summary, which the workflow publishes instead of parsing the --info log. A scan whose lookup fails, after retries that stop when the build is cancelled, is listed in the summary rather than leaving it to report a clean build. The workflow no longer uses pull_request_target: a pull request from a fork gets no secrets, so it is scanned against OSV only, and the summary says so. Report URL: https://github.com/apache/grails-core/actions/runs/37398243097 With regards, GitHub Actions via GitBox
