Skip to end of metadata
Go to start of metadata

You are viewing an old version of this content. View the current version.

Compare with Current View Version History

« Previous Version 7 Next »

NOTE: This page is copy of /wiki/spaces/SV/pages/16094118 report

The tables contain the recommended package version upgrades for outdated direct dependencies with Critical or Severe vulnerabilities identified by NexusIQ. These packages must be upgraded by M2/M3 or a request for a waiver must be requested from SECCOM and the TSC.

  • Priority 1 recommendations have at least one Critical vulnerability.
  • Priority 2 recommendations contain at least one Severe vulnerability, and no Critical vulnerabilities.
  • There are four status values:
    • OPEN - required upgrade identified
    • IN PROGRESS - project working on the upgrade
    • COMPLETE - package has been upgraded to the recommended version
    • WAIVER - project granted a waiver for the upgrade because of technical or resource constraints

When the upgrade of the package is complete change the status in the table to COMPLETE.

If a waiver is granted, change the status to WAIVER.

When the status of all direct dependency replacements is COMPLETE or WAIVER , the Jira ticket should be closed.

so-adapters-so-etsi-sol003-adapter

Status

Priority

Component name and version

Recommended version

Threat level

Project’s assessment

COMPLETE

1com.fasterxml.jackson.core : jackson-databind : 2.11.32.14.1

This is indirect dependency coming from the o-parent. 


The version 2.14.2 is updated and available in Master branch   

IN PROGRESS

1org.yaml : snakeyaml : 1.261.33

This needs further analysis and is being checked in detail. We have a resource crunch at the moment.

so-libs

Status

Priority

Component name and version

Recommended version

Threat level

Project’s assessment

COMPLETE

1com.fasterxml.jackson.core : jackson-databind : 2.11.12.14.1

This is indirect dependency coming from the o-parent. 

 
The version 
2.14.2 is updated and available in Master branch 

so

Status

Priority

Component name and version

Recommended version

Threat level

Project’s assessment

COMPLETE

1com.fasterxml.jackson.core : jackson-databind : 2.11.32.14.1


This is indirect dependency coming from the o-parent.


The version 2.14.2 is updated and available in Master branch   

COMPLETE

1com.fasterxml.jackson.core : jackson-databind : 2.9.82.14.1
Same as above

IN PROGRESS

1com.google.protobuf : protobuf-java : 3.10.04.0.0-rc-2

This needs further analysis and is being checked in detail. We have a resource crunch at the moment.

IN PROGRESS

1com.h2database : h2 : 1.4.2000.16.4

We dont use this code in the production and is only built for testing code.

IN PROGRESS

1org.apache.tomcat : tomcat-catalina : 9.0.459.0.37.1

This needs further analysis and We are facing resource issue at the moment, request a waiver.

COMPLETE

1org.json : json : 2014010720220924


The change would bring in a major testing to be performed across the projects and we have a resource crunch. 


The version 2.14.2 is updated and available in Master branch   

COMPLETE

1org.json : json : 2016021220220924

The change would bring in a major testing to be performed across the projects and we have a resource crunch. 


The version 2.14.2 is updated and available in Master branch   

IN PROGRESS

1org.springframework : spring-web : 5.2.14.RELEASE6.0.2

The change would bring in a major testing to be performed across the projects and we have a resource crunch

IN PROGRESS

1

org.springframework.data : spring-data-rest-hal-browser : 3.3.9.RELEASE

3.3.9.RELEASE

This needs further analysis and We are facing resource issue at the moment, request a waiver.

IN PROGRESS

1org.springframework.security : spring-security-web : 5.4.63.0.11-oss


This needs further analysis and We are facing resource issue at the moment, request a waiver.

IN PROGRESS

1org.yaml : snakeyaml : 1.261.33


This needs further analysis and We are facing resource issue at the moment, request a waiver.

IN PROGRESS

2org.glassfish.jersey.core : jersey-common : 2.22.1

Indirect dependency,

IN PROGRESS

2org.glassfish.jersey.core : jersey-common : 2.30.1

Indirect dependency.

IN PROGRESS

2org.springframework : spring-webmvc : 5.2.12.RELEASE6.0.2

This needs further analysis and We are facing resource issue at the moment, request a waiver.

so-so-admin-cockpit

Status

Priority

Component name and version

Recommended version

Threat level

Project’s assessment

COMPLETE

1com.fasterxml.jackson.core : jackson-databind : 2.11.12.14.1

This is indirect dependency coming from the o-parent. The change would bring in a major testing to be performed across the projects and we have a resource crunch


The version 2.14.2 is updated and available in Master branch   

so-so-etsi-nfvo

Status

Priority

Component name and version

Recommended version

Threat level

Project’s assessment

COMPLETE1com.fasterxml.jackson.core : jackson-databind : 2.11.12.14.1

This is indirect dependency coming from the o-parent. The change would bring in a major testing to be performed across the projects and we have a resource crunch.


The version 2.14.2 is updated and available in Master branch   

IN PROGRESS

1org.yaml : snakeyaml : 1.261.33

This needs further analysis and is being checked in detail. We have a resource crunch at the moment.

  • No labels