Skip to content

[FP]: Eclipse jetty toolchain libs should also be excluded from eclipse:jetty cpe #6812

@lread

Description

@lread

Package URl

pkg:maven/org.eclipse.jetty.toolchain/jetty-jakarta-websocket-api@2.0.0

CPE

cpe:2.3:a:eclipse:jetty:2.0.0:*:*:*:*:*:*:*

CVE

No response

ODC Integration

None

ODC Version

10.0.2

Description

I listed a specific package URI and cpe because this is what I understand the issue form to require, but I think we should instead tweak an existing suppression.

In #6799, the eclipse jetty tool chain libs were excluded from cpe:/a:jetty:jetty, but I think they also need to be excluded from cpe:/a:eclipse:jetty.

And with that, hopefully, the game of whack-a-mole will be complete!

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions