Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Request Integration team to upgrade guava
RepositoryGroupImpact AnalysisAction
policy/commoncom.fasterxml.jackson.core

False Positive - we are not using the Jackson code in the manner that exposes the vulnerability.

Request exception


policy/common

javax.jms

This is a license issue that is brought in due to inclusion of DMaap client.

Request exception
policy/commonorg.json

This is a license issue that is brought in due to inclusion of Cambria client.

Request exception
policy/commonorg.checkerframework

This is a license issue that is brought in from google.guava

There is an MIT license associated with it.

Request Integration team to upgrade guava

or

LF to override

policy/commonlog4jThere is no license for this. This is used extensively for logging and would a large effort to remove its use.Request exception
policy/commonjunitThere is no license for this. This is used for satisfying the 50% JUnit test coverage.Request exception




policy/drools-applications

policy/drools-pdp

policy/distribution


com.fasterxml.jackson.core

False Positive - flagged due to inclusion inheritance of policy/common

Request exception

policy/drools-applications

policy/drools-pdp

policy/distribution


javax.jmsThis is a license issue that is brought in due to inclusion inheritance of DMaap client.Request exception

policy/drools-applications

policy/drools-pdp

policy/distribution


org.jsonThis is a license issue that is brought in due to inclusion inheritance of Cambria client.
Request exception

policy/drools-applications

com.att.research.xacmlFalse positive - MIT license should be acceptableRequest exception or LF to override

policy/drools-pdp

policy/

drools-applications

distribution


org.checkerframeworkThis is a license issue that is brought in from google.guavaRequest Integration team to upgrade guava




policy/drools-applicationsxml-apiscom.att.research.xacmlFalse positive - Apache 2.0 MIT license should be acceptableRequest LF to select correct license
policy/drools-pdpapplicationsxml-apiscom.fasterxml.jackson.coreFalse Positive - flagged due to inclusion of policy/common

Request exception

policy/drools-pdp

javax.jmsThis is a license issue that is brought in due to inclusion of DMaap client.Request exception
positive - Apache 2.0 license should be acceptableRequest LF to select correct licensepolicy/drools-pdporg.jsonThis is a license issue that is brought in due to inclusion of Cambria client.Request exception




policy/drools-pdpdom4j

This is a security/license issue due to Drools v6.5.0.Final

Upgrading to 7.x version would not clear this issue and would result in multiple other license exceptions that are not clearable.

Request exception
policy/drools-pdpjsoup

This is a security issue due to Drools v6.5.0.Final

Upgrading to 7.x version would not clear this issue and would result in multiple other new license exceptions that are not clearable.

Request exception
policy/drools-pdpant

This is a security issue due to Drools v6.5.0.Final

Upgrading to 7.x version would clear this issue, but would result in multiple other new license exceptions that are not clearable.

Request exceptionpolicy/drools-pdporg.checkerframeworkThis is a license issue that is brought in from google.guavaRequest Integration team to upgrade guava
policy/drools-pdpjboss.jta

This is a license issue - LGPL.

JBoss has a newer set of transaction code which has the same license issue so upgrading is not possible.

This feature is unused in ONAP and is disabled.

Request exception
policy/drools-pdphibernate-core

This is a license issue - LGPL

This feature is unused in ONAP and is disabled.

Request exception
policy/drools-pdphibernate-commons-annotations

This is a license issue - LGPL

This feature is unused in ONAP and is disabled.

Request exception
policy/drools-pdpmariadbFalse positive - BSD3 license

Request LF to select correct license.

NOTE: LF requested ONAP projects to move to mariadb in Amsterdam release.

policy/drools-pdplog4jInherited from policy/commonRequest exception
policy/drools-pdpjunitInherited from policy/commonRequest exception








policy/engine

com.sword-group.bizdock.lib

Flagged due to inclusion of ONAP Portal SDKRequest exception
policy/engineorg.apache.tomcat The declared and effective license are Apache 2.0, the CLM is incorrectly reporting a problem.Request LF to select correct license.
policy/enginecom.fasterxml.jackson.core

False positive

The code is not using jackson in the manner described in the vulnerability.

There are too many lines to list here.

Request exception
policy/engineorg.springframeworkFlagged due to inclusion of ONAP Portal SDK

Request exception

policy/engine

angular.js

angular.min.js


Flagged due to inclusion of ONAP Portal SDK

Request exception

policy/engine

moment


moment

Flagged due to inclusion of ONAP Portal SDK

Request exception

policy/enginecommons-beanutilsFlagged due to inclusion of ONAP Portal SDKRequest exception




policy/distributioncom.fasterxml.jackson.core

2 separate issues:

1) Flagged due to inclusion of ONAP SDC SDK

2) Flagged due to inclusion of policy/common

Request exception
policy/distributionorg.springframeworkFlagged due to inclusion of ONAP Portal SDKRequest exception

policy/distribution

javax.jms

This is a license issue that is brought in due to inclusion of DMaap client.

Request exception
policy/distributionorg.json

This is a license issue that is brought in due to inclusion of Cambria client.

Request exception
org.springframeworkFlagged due to inheritance from policy/engine which has dependency on ONAP Portal SDKRequest exceptionpolicy/distributionorg.checkerframeworkThis is a license issue that is brought in from google.guava
policy/distributionorg.dspace.xmlui.xmlThis is a license issue that is a false positive - it is Apache 2.0Request LF to select correct license.

...