The GitHub Actions job "CI" on grails-core.git/build/vulnerability-scan-plugin 
has succeeded.
Run started by GitHub user jdaugherty (triggered by jdaugherty).

Head commit for run:
4d9267298c2fa66d7774c8052d4222d4ce414bae / James Daugherty 
<[email protected]>
Replace the Sonatype scan plugin with our own vulnerability scan

The scan-gradle-plugin behind ossIndexAudit is archived and its scanning has
moved into Sonatype's commercial offering. The vulnerability-scan build-logic
project now implements the scan itself.

- The vulnerabilityScan task looks the resolved runtimeClasspath and
  compileClasspath up in OSV and, when SONATYPE_GUIDE_USERNAME and
  SONATYPE_GUIDE_TOKEN are set, in Sonatype Guide through the same component
  report API the old plugin used. Each database knows of vulnerabilities the
  other does not yet; one both know of, by id or alias, is reported once.
- The credentials are read when the scan runs, and the answers of both are
  cached for an hour in the Gradle user home (vulnerabilityScan.cacheTtl), so
  repeated scans do not spend Sonatype Guide credits or hit rate limits.
- An exclusion names a vulnerability id or alias and a group:artifact instead
  of a whole group:artifact:version, so a version bump no longer orphans it,
  and each needs a reason. The exclusions of the old plugin are carried over,
  with the Spring Security and Spring Framework CVEs its whole-coordinate
  exclusions also covered, which have no open source fix on the 6.x lines
  either. The HdrHistogram and spring-webmvc entries Sonatype Guide no longer
  reports are dropped.
- The root vulnerabilityScanReport task writes a Markdown summary, which the
  workflow publishes instead of parsing the --info log. A scan whose lookup
  fails, after retries that stop when the build is cancelled, is listed in the
  summary rather than leaving it to report a clean build. The workflow no longer
  uses pull_request_target: a pull request from a fork gets no secrets, so it
  is scanned against OSV only, and the summary says so.

Report URL: https://github.com/apache/grails-core/actions/runs/37398243097

With regards,
GitHub Actions via GitBox

Reply via email to