Skip to content
This repository was archived by the owner on Jan 7, 2026. It is now read-only.
Merged
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
8 changes: 8 additions & 0 deletions sonarqube.advisories.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -219,6 +219,10 @@ advisories:
componentType: java-archive
componentLocation: /usr/share/sonarqube/lib/extensions/sonar-iac-plugin-1.47.0.15287.jar
scanner: grype
- timestamp: 2025-07-17T19:28:51Z
type: pending-upstream-fix
data:
note: Upstream needs to upgrade multiple instances of commons-lang3 in plugins that are used in main package. Attempts to update didn't address CVE issues

- id: CGA-jg27-23w9-m7hp
aliases:
Expand Down Expand Up @@ -303,6 +307,10 @@ advisories:
componentType: java-archive
componentLocation: /usr/share/sonarqube/elasticsearch/modules/x-pack-security/nimbus-jose-jwt-modified-8.16.3.jar
scanner: grype
- timestamp: 2025-07-17T19:25:09Z
type: pending-upstream-fix
data:
note: Upstream needs to upgrade multiple instances of nimbus-jose-jwt in plugins that are used in main package.

- id: CGA-rmgj-x5xj-3c37
aliases:
Expand Down
Loading