[GitHub] [zookeeper] nkalmar commented on pull request #1817: ZOOKEEPER-4469: Suppress OWASP false positives related to Netty TCNative

2022-02-14 Thread GitBox
nkalmar commented on pull request #1817: URL: https://github.com/apache/zookeeper/pull/1817#issuecomment-1038874390 One of the devs at owasp clarified to me that this was only fixed for netty:netty artifact, and he also opened a new issue to fix it in other artifacts as well. So this is wh

[GitHub] [zookeeper] nkalmar commented on pull request #1817: ZOOKEEPER-4469: Suppress OWASP false positives related to Netty TCNative

2022-02-11 Thread GitBox
nkalmar commented on pull request #1817: URL: https://github.com/apache/zookeeper/pull/1817#issuecomment-1036178351 That's a bummer, I double checked, this is a closed item in 6.5.2 milestone (one up from last item): https://github.com/jeremylong/DependencyCheck/milestone/38?closed=1 --

[GitHub] [zookeeper] nkalmar commented on pull request #1817: ZOOKEEPER-4469: Suppress OWASP false positives related to Netty TCNative

2022-02-11 Thread GitBox
nkalmar commented on pull request #1817: URL: https://github.com/apache/zookeeper/pull/1817#issuecomment-1036152946 Can we update owasp to latest 6.5.3? Will it cause any issues? -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitH

[GitHub] [zookeeper] nkalmar commented on pull request #1817: ZOOKEEPER-4469: Suppress OWASP false positives related to Netty TCNative

2022-02-11 Thread GitBox
nkalmar commented on pull request #1817: URL: https://github.com/apache/zookeeper/pull/1817#issuecomment-1036150036 Yes, looks like it: https://www.giters.com/jeremylong/DependencyCheck/issues/3867 -- This is an automated message from the Apache Git Service. To respond to the message, p