feat: CVE suppression for Tobago 5
further dependencies, but only used at build time
issue: TOBAGO-2084
diff --git a/other/checkstyle-rules/src/main/resources/tobago/dependency-check-suppression-for-tobago-5.x.xml b/other/checkstyle-rules/src/main/resources/tobago/dependency-check-suppression-for-tobago-5.x.xml
index 2acf5b9..148e747 100644
--- a/other/checkstyle-rules/src/main/resources/tobago/dependency-check-suppression-for-tobago-5.x.xml
+++ b/other/checkstyle-rules/src/main/resources/tobago/dependency-check-suppression-for-tobago-5.x.xml
@@ -3,6 +3,11 @@
xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
xsi:schemaLocation="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd">
<suppress>
+ <notes><![CDATA[ file name: jdom2-2.0.6.jar ]]></notes>
+ <packageUrl regex="true">^pkg:maven/org\.jdom/jdom2@.*$</packageUrl>
+ <cve>CVE-2021-33813</cve>
+ </suppress>
+ <suppress>
<notes><![CDATA[ file name: path-parse:1.0.6 ]]></notes>
<packageUrl regex="true">^pkg:npm/path\-parse@.*$</packageUrl>
<cve>CVE-2021-23343</cve>