Skip to content

Commit 6a4272c

Browse files
Suppress bad CPE match for Spring AI 2.x
1 parent efd7e47 commit 6a4272c

1 file changed

Lines changed: 28 additions & 0 deletions

File tree

dependencyCheckSuppression.xml

Lines changed: 28 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -194,4 +194,32 @@
194194
<packageUrl regex="true">^pkg:maven/org\.mozilla/rhino@.*$</packageUrl>
195195
<vulnerabilityName>CVE-2025-66453</vulnerabilityName>
196196
</suppress>
197+
198+
<!-- Lots of false positives for Spring AI 2.0 due to bad matches-->
199+
<suppress>
200+
<notes><![CDATA[
201+
file name: spring-ai-autoconfigure-mcp-server-common-2.0.0-M2.jar
202+
]]></notes>
203+
<packageUrl regex="true">^pkg:maven/org\.springframework\.ai/spring-ai-autoconfigure-mcp-server-common@.*$</packageUrl>
204+
<cpe>cpe:/a:vmware:server</cpe>
205+
<cpe>cpe:/a:vmware:vmware_server</cpe>
206+
</suppress>
207+
208+
<suppress>
209+
<notes><![CDATA[
210+
file name: spring-ai-autoconfigure-mcp-server-webmvc-2.0.0-M2.jar
211+
]]></notes>
212+
<packageUrl regex="true">^pkg:maven/org\.springframework\.ai/spring-ai-autoconfigure-mcp-server-webmvc@.*$</packageUrl>
213+
<cpe>cpe:/a:vmware:server</cpe>
214+
<cpe>cpe:/a:vmware:vmware_server</cpe>
215+
</suppress>
216+
217+
<suppress>
218+
<notes><![CDATA[
219+
file name: spring-ai-starter-mcp-server-webmvc-2.0.0-M2.jar
220+
]]></notes>
221+
<packageUrl regex="true">^pkg:maven/org\.springframework\.ai/spring-ai-starter-mcp-server-webmvc@.*$</packageUrl>
222+
<cpe>cpe:/a:vmware:server</cpe>
223+
<cpe>cpe:/a:vmware:vmware_server</cpe>
224+
</suppress>
197225
</suppressions>

0 commit comments

Comments
 (0)