Sonarqube сообщает о 1000 * уязвимости зависимости - PullRequest
0 голосов
/ 14 апреля 2020

Я добавил groovy зависимость к проекту только для настройки моего входа в систему. Он создал ряд уязвимостей из нескольких jar-файлов, которые я пытаюсь удалить:

Filename: logback-ecs-encoder-0.3.0.jar 
Filename: testng-6.13.1.jar: jquery-1.7.1.min.js 
Filename: groovy-ant-2.5.9.jar 
Filename: groovy-cli-commons-2.5.9.jar 
Filename: groovy-groovysh-2.5.9.jar
Filename: groovy-console-2.5.9.jar 
Filename: groovy-docgenerator-2.5.9.jar 
Filename: groovy-groovydoc-2.5.9.jar 
Filename: groovy-cli-picocli-2.5.9.jar 
Filename: groovy-datetime-2.5.9.jar 
Filename: groovy-jmx-2.5.9.jar 
Filename: groovy-json-2.5.9.jar 
Filename: groovy-jsr223-2.5.9.jar 
Filename: groovy-macro-2.5.9.jar
Filename: groovy-nio-2.5.9.jar 
Filename: groovy-servlet-2.5.9.jar
Filename: groovy-sql-2.5.9.jar 
Filename: groovy-swing-2.5.9.jar 
Filename: groovy-templates-2.5.9.jar 
Filename: groovy-test-2.5.9.jar 
Filename: groovy-test-junit5-2.5.9.jar 
Filename: groovy-testng-2.5.9.jar 
Filename: groovy-xml-2.5.9.jar 

Используемый мной плагин groovy - 2.5.7, но по какой-то причине он кажется обновление количества пакетов до 2.5.9

+--- org.codehaus.groovy:groovy-all:2.5.7
|    +--- org.codehaus.groovy:groovy:2.5.7 -> 2.5.9
|    +--- org.codehaus.groovy:groovy-ant:2.5.7 -> 2.5.9
|    |    +--- org.codehaus.groovy:groovy:2.5.9
|    |    +--- org.apache.ant:ant:1.9.13
|    |    |    \--- org.apache.ant:ant-launcher:1.9.13
|    |    +--- org.codehaus.groovy:groovy-groovydoc:2.5.9
|    |    |    +--- org.codehaus.groovy:groovy-templates:2.5.9
|    |    |    |    +--- org.codehaus.groovy:groovy:2.5.9
|    |    |    |    \--- org.codehaus.groovy:groovy-xml:2.5.9
|    |    |    |         \--- org.codehaus.groovy:groovy:2.5.9
|    |    |    +--- org.codehaus.groovy:groovy:2.5.9
|    |    |    +--- org.codehaus.groovy:groovy-cli-picocli:2.5.9
|    |    |    |    +--- org.codehaus.groovy:groovy:2.5.9
|    |    |    |    \--- info.picocli:picocli:4.0.1
|    |    |    \--- org.codehaus.groovy:groovy-docgenerator:2.5.9
|    |    |         +--- org.codehaus.groovy:groovy-templates:2.5.9 (*)
|    |    |         +--- org.codehaus.groovy:groovy:2.5.9
|    |    |         +--- org.codehaus.groovy:groovy-cli-picocli:2.5.9 (*)
|    |    |         \--- com.thoughtworks.qdox:qdox:1.12.1
|    |    +--- org.apache.ant:ant-junit:1.9.13
|    |    |    \--- org.apache.ant:ant:1.9.13 (*)
|    |    +--- org.apache.ant:ant-launcher:1.9.13
|    |    \--- org.apache.ant:ant-antlr:1.9.13
|    +--- org.codehaus.groovy:groovy-cli-commons:2.5.7 -> 2.5.9
|    |    +--- org.codehaus.groovy:groovy:2.5.9
|    |    \--- commons-cli:commons-cli:1.4
|    +--- org.codehaus.groovy:groovy-cli-picocli:2.5.7 -> 2.5.9 (*)
|    +--- org.codehaus.groovy:groovy-console:2.5.7 -> 2.5.9
|    |    +--- org.codehaus.groovy:groovy-templates:2.5.9 (*)
|    |    +--- org.codehaus.groovy:groovy:2.5.9
|    |    +--- org.codehaus.groovy:groovy-cli-picocli:2.5.9 (*)
|    |    \--- org.codehaus.groovy:groovy-swing:2.5.9
|    |         \--- org.codehaus.groovy:groovy:2.5.9
|    +--- org.codehaus.groovy:groovy-datetime:2.5.7 -> 2.5.9
|    |    \--- org.codehaus.groovy:groovy:2.5.9
|    +--- org.codehaus.groovy:groovy-docgenerator:2.5.7 -> 2.5.9 (*)
|    +--- org.codehaus.groovy:groovy-groovydoc:2.5.7 -> 2.5.9 (*)
|    +--- org.codehaus.groovy:groovy-groovysh:2.5.7 -> 2.5.9
|    |    +--- org.codehaus.groovy:groovy:2.5.9
|    |    +--- org.codehaus.groovy:groovy-cli-picocli:2.5.9 (*)
|    |    +--- org.codehaus.groovy:groovy-console:2.5.9 (*)
|    |    \--- jline:jline:2.14.6

...