Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

RepositoryGroupImpact AnalysisAction
policy/commoncom.fasterxml.jackson.core

False Positive - we are not using the Jackson code in the manner that exposes the vulnerability.

Request exception or false positive


policy/commonjavax.servlet False Positive - the license is CCDL-1.1Request exception

policy/common

javax.jms

This is a license issue that is brought in due to inclusion of DMaap client.

Request exception
policy/commonorg.json

This is a license issue that is brought in due to inclusion of Cambria client.

Request exception
policy/drools-applicationscom.fasterxml.jackson.core

False Positive - flagged due to inclusion of policy/drools-pdp

Request exception

policy/drools-applications

javax.jmsFalse Positive - flagged This is a license issue that is brought in due to inclusion of Dmaap DMaap client.Request exception
policy/drools-applicationsorg.jsonFalse Positive - flagged This is a license issue that is brought in due to inclusion of Dmaap cambria Cambria client.
Request exception
policy/drools-applicationscom.att.research.xacmlFalse positive - MIT license should be acceptableRequest exception
policy/drools-applicationsxacml-apisFalse positive - Apache 2.0 license should be acceptableRequest exception












policy/engine

com.sword-group.bizdock.lib

Flagged due to inclusion of ONAP Portal SDK
policy/engineorg.apache.tomcat The declared and effective license are Apache 2.0, the CLM is incorrectly reporting a problem.False Positive
policy/enginecom.fasterxml.jackson.core

False positive

The code is not using jackson in the manner described in the vulnerability.

There are too many lines to list here.

Request exception
policy/engineorg.springframeworkFlagged due to inclusion of ONAP Portal SDK

Request exception

policy/engine

angular.js

angular.min.js


Flagged due to inclusion of ONAP Portal SDK

Request exception

policy/engine

moment


moment

Flagged due to inclusion of ONAP Portal SDK

Request exception

policy/enginecommons-beanutilsFlagged due to inclusion of ONAP Portal SDKRequest exception

...