See <https://ci-builds.apache.org/job/Struts/job/Struts-examples-dependency-check/108/display/redirect?page=changes>
Changes: [github] Bump org.apache.maven.plugins:maven-failsafe-plugin from 3.2.2 to 3.2.3 [github] Bump org.springframework:spring-web from 6.1.1 to 6.1.2 [github] Update struts.xml - Timer Interceptor is DEPRECATED [github] Bump io.quarkus:quarkus-universe-bom from 3.6.1 to 3.6.4 [github] Bump log4j2.version from 2.22.0 to 2.22.1 [github] Bump org.slf4j:slf4j-simple from 2.0.9 to 2.0.10 [github] Update .asf.yaml [Lukasz Lenart] Avoids scanning all the classes from all the packages [Lukasz Lenart] Simplifies scanning to the base package ------------------------------------------ [...truncated 11.58 KB...] [INFO] Preparable Interface [war] [INFO] Struts 2 Quarkus [jar] [INFO] REST to Action Mapper Example Application [war] [INFO] REST Plugin based application with AngularJS [war] [INFO] Struts2 with Basic Shiro Security Integration [war] [INFO] Struts2 with Spring Integration [war] [INFO] Custom TextProvider [war] [INFO] Struts Tiles Example [war] [INFO] Struts 2 Themes [war] [INFO] Struts 2 Themes Override [war] [INFO] Type Conversion [war] [INFO] Unit Testing [war] [INFO] Unknown handler [war] [INFO] Using Struts 2 Tags [war] [INFO] validation-messages [war] [INFO] Wildcard Method Selection [war] [INFO] Wildcard RegEx pattern matching [war] [INFO] JasperReports Tutorial [war] [INFO] [INFO] -----------------< org.apache.struts:struts-examples >------------------ [INFO] Building Struts 2 Examples 1.1.0 [1/47] [INFO] --------------------------------[ pom ]--------------------------------- [INFO] [INFO] --- dependency-check-maven:7.2.1:check (default) @ struts-examples --- [INFO] Checking for updates [INFO] NVD CVE requires several updates; this could take a couple of minutes. [INFO] Download Started for NVD CVE - 2002 [INFO] Download Complete for NVD CVE - 2002 (703 ms) [INFO] Processing Started for NVD CVE - 2002 WARNING: An illegal reflective access operation has occurred WARNING: Illegal reflective access by com.fasterxml.jackson.module.afterburner.util.MyClassLoader (file:/home/jenkins/.m2/repository/com/fasterxml/jackson/module/jackson-module-afterburner/2.13.4/jackson-module-afterburner-2.13.4.jar) to method java.lang.ClassLoader.findLoadedClass(java.lang.String) WARNING: Please consider reporting this to the maintainers of com.fasterxml.jackson.module.afterburner.util.MyClassLoader WARNING: Use --illegal-access=warn to enable warnings of further illegal reflective access operations WARNING: All illegal access operations will be denied in a future release [INFO] Download Started for NVD CVE - 2003 [INFO] Download Complete for NVD CVE - 2003 (568 ms) [INFO] Processing Started for NVD CVE - 2003 [INFO] Download Started for NVD CVE - 2004 [INFO] Processing Complete for NVD CVE - 2003 (4031 ms) [INFO] Download Complete for NVD CVE - 2004 (630 ms) [INFO] Processing Started for NVD CVE - 2004 [INFO] Download Started for NVD CVE - 2005 [INFO] Download Complete for NVD CVE - 2005 (663 ms) [INFO] Processing Started for NVD CVE - 2005 [INFO] Processing Complete for NVD CVE - 2002 (14564 ms) [INFO] Processing Complete for NVD CVE - 2004 (7858 ms) [INFO] Download Started for NVD CVE - 2006 [INFO] Download Complete for NVD CVE - 2006 (743 ms) [INFO] Processing Started for NVD CVE - 2006 [INFO] Download Started for NVD CVE - 2007 [INFO] Download Complete for NVD CVE - 2007 (748 ms) [INFO] Processing Started for NVD CVE - 2007 [INFO] Processing Complete for NVD CVE - 2005 (12215 ms) [INFO] Download Started for NVD CVE - 2008 [INFO] Download Complete for NVD CVE - 2008 (718 ms) [INFO] Processing Started for NVD CVE - 2008 [INFO] Download Started for NVD CVE - 2009 [INFO] Download Complete for NVD CVE - 2009 (714 ms) [INFO] Processing Started for NVD CVE - 2009 [INFO] Processing Complete for NVD CVE - 2006 (17849 ms) [INFO] Download Started for NVD CVE - 2010 [INFO] Download Complete for NVD CVE - 2010 (683 ms) [INFO] Processing Started for NVD CVE - 2010 [INFO] Processing Complete for NVD CVE - 2007 (15650 ms) [INFO] Download Started for NVD CVE - 2011 [INFO] Download Complete for NVD CVE - 2011 (702 ms) [INFO] Processing Started for NVD CVE - 2011 [INFO] Download Started for NVD CVE - 2012 [INFO] Download Complete for NVD CVE - 2012 (680 ms) [INFO] Processing Started for NVD CVE - 2012 [INFO] Processing Complete for NVD CVE - 2008 (19088 ms) [INFO] Download Started for NVD CVE - 2013 [INFO] Download Complete for NVD CVE - 2013 (751 ms) [INFO] Processing Started for NVD CVE - 2013 [INFO] Processing Complete for NVD CVE - 2009 (18876 ms) [INFO] Download Started for NVD CVE - 2014 [INFO] Download Complete for NVD CVE - 2014 (805 ms) [INFO] Processing Started for NVD CVE - 2014 [INFO] Download Started for NVD CVE - 2015 [INFO] Download Complete for NVD CVE - 2015 (704 ms) [INFO] Processing Complete for NVD CVE - 2010 (23689 ms) [INFO] Processing Started for NVD CVE - 2015 [INFO] Download Started for NVD CVE - 2016 [INFO] Download Complete for NVD CVE - 2016 (722 ms) [INFO] Processing Started for NVD CVE - 2016 [INFO] Processing Complete for NVD CVE - 2011 (26424 ms) [INFO] Download Started for NVD CVE - 2017 [INFO] Download Complete for NVD CVE - 2017 (852 ms) [INFO] Processing Started for NVD CVE - 2017 [INFO] Download Started for NVD CVE - 2018 [INFO] Download Complete for NVD CVE - 2018 (777 ms) [INFO] Processing Started for NVD CVE - 2018 [INFO] Download Started for NVD CVE - 2019 [INFO] Download Complete for NVD CVE - 2019 (769 ms) [INFO] Processing Started for NVD CVE - 2019 [INFO] Processing Complete for NVD CVE - 2012 (33840 ms) [INFO] Download Started for NVD CVE - 2020 [INFO] Download Complete for NVD CVE - 2020 (785 ms) [INFO] Processing Started for NVD CVE - 2020 [INFO] Processing Complete for NVD CVE - 2014 (30341 ms) [INFO] Processing Complete for NVD CVE - 2015 (25918 ms) [INFO] Processing Complete for NVD CVE - 2013 (35638 ms) [INFO] Download Started for NVD CVE - 2021 [INFO] Download Complete for NVD CVE - 2021 (829 ms) [INFO] Processing Started for NVD CVE - 2021 [INFO] Processing Complete for NVD CVE - 2016 (26282 ms) [INFO] Download Started for NVD CVE - 2022 [INFO] Download Complete for NVD CVE - 2022 (840 ms) [INFO] Processing Started for NVD CVE - 2022 [INFO] Download Started for NVD CVE - 2023 [INFO] Download Complete for NVD CVE - 2023 (849 ms) [INFO] Processing Started for NVD CVE - 2023 [INFO] Processing Complete for NVD CVE - 2017 (31841 ms) [INFO] Processing Complete for NVD CVE - 2018 (27850 ms) [INFO] Processing Complete for NVD CVE - 2019 (28688 ms) [INFO] Processing Complete for NVD CVE - 2020 (33423 ms) [INFO] Processing Complete for NVD CVE - 2021 (35118 ms) [INFO] Processing Complete for NVD CVE - 2022 (36660 ms) [INFO] Processing Complete for NVD CVE - 2023 (33379 ms) [INFO] Download Started for NVD CVE - Modified [INFO] Download Complete for NVD CVE - Modified (522 ms) [INFO] Processing Started for NVD CVE - Modified [INFO] Processing Complete for NVD CVE - Modified (2189 ms) [INFO] Begin database maintenance [INFO] Updated the CPE ecosystem on 132473 NVD records [INFO] End database maintenance (25779 ms) [INFO] Begin database defrag [INFO] End database defrag (10157 ms) [INFO] Check for updates complete (181583 ms) [INFO] Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report. About ODC: https://jeremylong.github.io/DependencyCheck/general/internals.html False Positives: https://jeremylong.github.io/DependencyCheck/general/suppression.html 💖 Sponsor: https://github.com/sponsors/jeremylong [INFO] Analysis Started [INFO] Finished Archive Analyzer (0 seconds) [INFO] Finished File Name Analyzer (0 seconds) [INFO] Finished Jar Analyzer (0 seconds) [INFO] Finished Dependency Merging Analyzer (0 seconds) [INFO] Finished Version Filter Analyzer (0 seconds) [INFO] Finished Hint Analyzer (0 seconds) [INFO] Created CPE Index (3 seconds) [INFO] Finished CPE Analyzer (4 seconds) [INFO] Finished False Positive Analyzer (0 seconds) [INFO] Finished NVD CVE Analyzer (0 seconds) [INFO] Finished RetireJS Analyzer (0 seconds) [INFO] Finished Sonatype OSS Index Analyzer (0 seconds) [INFO] Finished Vulnerability Suppression Analyzer (0 seconds) [INFO] Finished Dependency Bundling Analyzer (0 seconds) [INFO] Analysis Complete (6 seconds) [INFO] Writing report to: <https://ci-builds.apache.org/job/Struts/job/Struts-examples-dependency-check/ws/target/dependency-check-report.html> [WARNING] One or more dependencies were identified with known vulnerabilities in Struts 2 Examples: commons-fileupload-1.5.jar (pkg:maven/commons-fileupload/[email protected], cpe:2.3:a:apache:commons_fileupload:1.5:*:*:*:*:*:*:*, cpe:2.3:a:apache:commons_net:1.5:*:*:*:*:*:*:*) : CVE-2021-37533 commons-io-2.13.0.jar (pkg:maven/commons-io/[email protected], cpe:2.3:a:apache:commons_io:2.13.0:*:*:*:*:*:*:*, cpe:2.3:a:apache:commons_net:2.13.0:*:*:*:*:*:*:*) : CVE-2021-37533 commons-text-1.10.0.jar (pkg:maven/org.apache.commons/[email protected], cpe:2.3:a:apache:commons_net:1.10.0:*:*:*:*:*:*:*, cpe:2.3:a:apache:commons_text:1.10.0:*:*:*:*:*:*:*) : CVE-2021-37533 See the dependency-check report for more details. [INFO] [INFO] -----------------< org.apache.struts:action-chaining >------------------ [INFO] Building Action chaining 1.1.0 [2/47] [INFO] --------------------------------[ war ]--------------------------------- [INFO] [INFO] --- maven-resources-plugin:2.6:resources (default-resources) @ action-chaining --- [INFO] Using 'UTF-8' encoding to copy filtered resources. [INFO] Copying 1 resource [INFO] [INFO] --- maven-compiler-plugin:3.1:compile (default-compile) @ action-chaining --- [INFO] Changes detected - recompiling the module! [INFO] Compiling 2 source files to <https://ci-builds.apache.org/job/Struts/job/Struts-examples-dependency-check/ws/action-chaining/target/classes> [INFO] ------------------------------------------------------------------------ [INFO] Reactor Summary: [INFO] [INFO] Struts 2 Examples 1.1.0 ............................ SUCCESS [03:13 min] [INFO] Action chaining .................................... FAILURE [ 0.655 s] [INFO] Annotations with Convention Plugin ................. SKIPPED [INFO] Basic Struts2 Example .............................. SKIPPED [INFO] Bean Validation .................................... SKIPPED [INFO] Struts 2 Blank Webapp .............................. SKIPPED [INFO] Coding Struts 2 Action ............................. SKIPPED [INFO] Control Tags ....................................... SKIPPED [INFO] CRUD Example ....................................... SKIPPED [INFO] Debugging Struts ................................... SKIPPED [INFO] Dynamic Url ........................................ SKIPPED [INFO] Exception handling ................................. SKIPPED [INFO] Exclude Parameters ................................. SKIPPED [INFO] Expression Cache ................................... SKIPPED [INFO] File upload ........................................ SKIPPED [INFO] Form Processing .................................... SKIPPED [INFO] Form Tags .......................................... SKIPPED [INFO] Form validation .................................... SKIPPED [INFO] XML based form validation .......................... SKIPPED [INFO] Hello World Struts 2 Example Application ........... SKIPPED [INFO] Http Session ....................................... SKIPPED [INFO] Struts 2 Interceptors .............................. SKIPPED [INFO] jfreechart ......................................... SKIPPED [INFO] JSON produce/consume ............................... SKIPPED [INFO] Customized JSON produce ............................ SKIPPED [INFO] Struts 2 Mail Reader Webapp ........................ SKIPPED [INFO] Message resource ................................... SKIPPED [INFO] Message Store ...................................... SKIPPED [INFO] Portlet Webapp ..................................... SKIPPED [INFO] Preparable Interface ............................... SKIPPED [INFO] Struts 2 Quarkus ................................... SKIPPED [INFO] REST to Action Mapper Example Application .......... SKIPPED [INFO] REST Plugin based application with AngularJS ....... SKIPPED [INFO] Struts2 with Basic Shiro Security Integration ...... SKIPPED [INFO] Struts2 with Spring Integration .................... SKIPPED [INFO] Custom TextProvider ................................ SKIPPED [INFO] Struts Tiles Example ............................... SKIPPED [INFO] Struts 2 Themes .................................... SKIPPED [INFO] Struts 2 Themes Override ........................... SKIPPED [INFO] Type Conversion .................................... SKIPPED [INFO] Unit Testing ....................................... SKIPPED [INFO] Unknown handler .................................... SKIPPED [INFO] Using Struts 2 Tags ................................ SKIPPED [INFO] validation-messages ................................ SKIPPED [INFO] Wildcard Method Selection .......................... SKIPPED [INFO] Wildcard RegEx pattern matching .................... SKIPPED [INFO] JasperReports Tutorial 1.1.0 ....................... SKIPPED [INFO] ------------------------------------------------------------------------ [INFO] BUILD FAILURE [INFO] ------------------------------------------------------------------------ [INFO] Total time: 03:18 min [INFO] Finished at: 2024-01-01T22:02:29Z [INFO] ------------------------------------------------------------------------ [ERROR] Failed to execute goal org.apache.maven.plugins:maven-compiler-plugin:3.1:compile (default-compile) on project action-chaining: Fatal error compiling: error: invalid target release: 17 -> [Help 1] [ERROR] [ERROR] To see the full stack trace of the errors, re-run Maven with the -e switch. [ERROR] Re-run Maven using the -X switch to enable full debug logging. [ERROR] [ERROR] For more information about the errors and possible solutions, please read the following articles: [ERROR] [Help 1] http://cwiki.apache.org/confluence/display/MAVEN/MojoExecutionException [ERROR] [ERROR] After correcting the problems, you can resume the build with the command [ERROR] mvn <goals> -rf :action-chaining Build step 'Execute shell' marked build as failure ERROR: No tool found matching MAVEN_3_LATEST__HOME
