diff --git a/build.gradle b/build.gradle index 6c4825fb21..e4acd92973 100644 --- a/build.gradle +++ b/build.gradle @@ -304,7 +304,7 @@ allprojects { force "org.bouncycastle:bcprov-jdk18on:${bouncycastleVersion}" // force consistency in docker and connectors and saml force "org.bouncycastle:bcpkix-jdk18on:${bouncycastleVersion}" - // force consistency with netty jar files for docker and UserReg-WS + // docker dependency: force to mitigate CVEs in 4.1.46 force "io.netty:netty-resolver:${nettyVersion}" force "io.netty:netty-resolver-dns:${nettyVersion}" force "io.netty:netty-handler:${nettyVersion}" diff --git a/dependencyCheckSuppression.xml b/dependencyCheckSuppression.xml index dfcbb45438..3f5d0b287c 100644 --- a/dependencyCheckSuppression.xml +++ b/dependencyCheckSuppression.xml @@ -121,20 +121,6 @@ CVE-2018-17201 - - - - ^pkg:maven/org\.graalvm\.shadowed/icu4j@.*$ - cpe:/a:icu-project:international_components_for_unicode - cpe:/a:unicode:international_components_for_unicode - cpe:/a:unicode:unicode - -