lhotari opened a new pull request, #21281: URL: https://github.com/apache/pulsar/pull/21281
### Motivation OWASP dependency check report ([example](https://github.com/apache/pulsar/actions/runs/6345669507/job/17238038834)) has some CVEs that can be suppressed. ### Modifications - add 2 suppressions - CVE-2023-37475 is a false positive - CVE-2023-4586 is about Netty hostname verification and that is already covered in Pulsar code base with https://github.com/apache/pulsar/pull/15824 changes. ### Documentation <!-- DO NOT REMOVE THIS SECTION. CHECK THE PROPER BOX ONLY. --> - [ ] `doc` <!-- Your PR contains doc changes. --> - [ ] `doc-required` <!-- Your PR changes impact docs and you will update later --> - [x] `doc-not-needed` <!-- Your PR changes do not impact docs --> - [ ] `doc-complete` <!-- Docs have been already added --> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
