blob: b22c8acebd7dfbeeb86f6be35de3bc97584bd068 [file] [log] [blame]
<?xml version="1.0" encoding="UTF-8"?>
<!--
~ Licensed to the Apache Software Foundation (ASF) under one
~ or more contributor license agreements. See the NOTICE file
~ distributed with this work for additional information
~ regarding copyright ownership. The ASF licenses this file
~ to you under the Apache License, Version 2.0 (the
~ "License"); you may not use this file except in compliance
~ with the License. You may obtain a copy of the License at
~
~ http://www.apache.org/licenses/LICENSE-2.0
~
~ Unless required by applicable law or agreed to in writing,
~ software distributed under the License is distributed on an
~ "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
~ KIND, either express or implied. See the License for the
~ specific language governing permissions and limitations
~ under the License.
-->
<suppressions xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.1.xsd">
<suppress>
<notes><![CDATA[ file name: tomcat-embed-core-8.5.5.jar ]]></notes>
<sha1>d55e12a418ff99ecd723a118c2a28bb91079972d</sha1>
<cpe>cpe:/a:apache:tomcat:8.5.5</cpe>
</suppress>
<suppress>
<notes><![CDATA[ file name: tomcat-embed-websocket-8.5.5.jar ]]></notes>
<sha1>fd99cd1cd4c824abdf03466f0509f067747f0d1a</sha1>
<cpe>cpe:/a:apache:tomcat:8.5.5</cpe>
</suppress>
<suppress>
<notes><![CDATA[ file name: opensaml-1.1.jar ]]></notes>
<sha1>21ec22368b6baa211a29887e162aa4cf9a8f3c60</sha1>
<cpe>cpe:/a:internet2:opensaml:1.1</cpe>
</suppress>
<suppress>
<!-- The CPE doesn't have the upper bound set correctly -->
<notes><![CDATA[ file name: spring-web-5.3.23.jar ]]></notes>
<packageUrl regex="true">^pkg:maven/org\.springframework/spring\-web@.*$</packageUrl>
<cve>CVE-2016-1000027</cve>
</suppress>
</suppressions>