Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Conversation

chadlwilson
Copy link
Collaborator

@chadlwilson chadlwilson commented Oct 17, 2025

Description of Change

  • Update the list of suppressed icu4j CVEs for java due to lack of support for the target sw ecosystem.
  • Sorted it so it can be compared easily with the search
  • Consolidate into single suppression across multiple java packages for ease of maintenance

Reconciled with the NVD and checked all are C/C++.

Related issues

Have test cases been added to cover the new functionality?

N/A

Signed-off-by: Chad Wilson <29788154+chadlwilson@users.noreply.github.com>
@boring-cyborg boring-cyborg bot added the core changes to core label Oct 17, 2025
Copy link
Collaborator

@jeremylong jeremylong left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@jeremylong jeremylong merged commit a574ca6 into dependency-check:main Oct 18, 2025
10 checks passed
@jeremylong jeremylong added this to the 12.1.9 milestone Oct 18, 2025
@chadlwilson chadlwilson deleted the update-icu4j-suppressions branch October 18, 2025 11:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

core changes to core

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants

Morty Proxy This is a proxified and sanitized view of the page, visit original site.