Skip to content

ZOOKEEPER-5087: Suppress false positive OpenTelemetry CVE-s in OWASP dependency check - #2453

Merged
anmolnar merged 1 commit into
apache:masterfrom
PDavid:ZOOKEEPER-5087
Sep 15, 2026
Merged

anmolnar merged 1 commit into
apache:masterfrom
PDavid:ZOOKEEPER-5087

Conversation

@PDavid

@PDavid PDavid commented Sep 3, 2026

Copy link
Copy Markdown
Contributor

All of these CVE-s are false positives as they are not affecting the Java library.

…dependency check

All of these CVE-s are false positives as they are not affecting the Java library.
@PDavid PDavid self-assigned this Sep 3, 2026
@PDavid

PDavid commented Sep 3, 2026

Copy link
Copy Markdown
Contributor Author

After these changes mvn clean package -DskipTests dependency-check:check was successful for me.

@PDavid
PDavid requested a review from anmolnar September 10, 2026 08:51

@anmolnar anmolnar left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm.

@anmolnar

Copy link
Copy Markdown
Contributor

Thanks. Which branches are affected?

@PDavid

PDavid commented Sep 14, 2026

Copy link
Copy Markdown
Contributor Author

Thanks. Which branches are affected?

I checked the latest runs under https://ci-hadoop.apache.org/view/ZooKeeper/job/zookeeper-multi-branch-owasp/ for each active branch and only master branch seems to be affected by this - or at least OWASP dependency check only reports these for master.

@anmolnar
anmolnar merged commit 33770c4 into apache:master Sep 15, 2026
17 checks passed
@anmolnar

Copy link
Copy Markdown
Contributor

Merged to master.

@PDavid
PDavid deleted the ZOOKEEPER-5087 branch September 16, 2026 08:47
@PDavid

PDavid commented Sep 16, 2026

Copy link
Copy Markdown
Contributor Author

Many thanks! 👍

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants