summaryrefslogtreecommitdiffhomepage
path: root/android/e2e/e2e-suppression.xml
diff options
context:
space:
mode:
authorAlbin <albin@mullvad.net>2022-11-23 17:54:09 +0100
committerAlbin <albin@mullvad.net>2023-01-10 15:32:27 +0100
commitbf287ad5153bb3687afb03370cdea1014b3cef75 (patch)
tree38fb21e35c8108f973853a03fe20273f5dc4c7e7 /android/e2e/e2e-suppression.xml
parent14c536c8cf902894188a72c65301659b7cd8256b (diff)
downloadmullvadvpn-bf287ad5153bb3687afb03370cdea1014b3cef75.tar.xz
mullvadvpn-bf287ad5153bb3687afb03370cdea1014b3cef75.zip
Move :e2e project to :test:e2e
Also changes source directory from "java" to "kotlin" which is supported since upgrading the project from AGP 3.x to 7.x.
Diffstat (limited to 'android/e2e/e2e-suppression.xml')
-rw-r--r--android/e2e/e2e-suppression.xml95
1 files changed, 0 insertions, 95 deletions
diff --git a/android/e2e/e2e-suppression.xml b/android/e2e/e2e-suppression.xml
deleted file mode 100644
index 2b57bc13e8..0000000000
--- a/android/e2e/e2e-suppression.xml
+++ /dev/null
@@ -1,95 +0,0 @@
-<?xml version="1.0" encoding="UTF-8"?>
-<suppressions xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd">
- <!--
- CVEs in the e2e project are deemed less severe than CVEs in the main projects as CVEs in the e2e
- project doesn't affect release or debug versions of the app.
- -->
- <suppress until="2023-05-01Z">
- <notes><![CDATA[
- This CVE is tracked externally and is therefore suppressed in the automatic audit checks.
- ]]></notes>
- <packageUrl regex="true">^pkg:maven/com\.google\.protobuf/protobuf\-java@.*$</packageUrl>
- <cve>CVE-2022-3171</cve>
- <cve>CVE-2022-3509</cve>
- <cve>CVE-2022-3510</cve>
- <cve>CVE-2021-22569</cve>
- </suppress>
- <suppress until="2023-05-01Z">
- <notes><![CDATA[
- These CVEs affects the Apache Commons Net's FTP client that this app doesn't use.
- https://www.openwall.com/lists/oss-security/2022/12/03/1
-
- File names:
- - commons-beanutils-1.9.4.jar
- - commons-collections-3.2.2.jar
- - commons-digester-2.1.jar
- - commons-logging-1.2.jar
- - commons-validator-1.7.jar
- ]]></notes>
- <packageUrl regex="true">^pkg:maven/commons\-.*/commons\-.*@.*$</packageUrl>
- <cve>CVE-2021-37533</cve>
- </suppress>
- <suppress until="2023-05-01Z">
- <notes><![CDATA[
- This CVE is tracked externally and is therefore suppressed in the automatic audit checks.
- https://nvd.nist.gov/vuln/detail/CVE-2021-29425
-
- File name: commons-io-2.4.jar
- ]]></notes>
- <packageUrl regex="true">^pkg:maven/commons\-io/commons\-io@.*$</packageUrl>
- <cve>CVE-2021-29425</cve>
- </suppress>
- <suppress until="2023-05-01Z">
- <notes><![CDATA[
- These CVEs are tracked externally and is therefore suppressed in the automatic audit checks.
- ]]></notes>
- <packageUrl regex="true">^pkg:maven/io\.netty/netty\-.*@.*$</packageUrl>
- <cve>CVE-2021-37136</cve>
- <cve>CVE-2021-37137</cve>
- <cve>CVE-2021-43797</cve>
- <cve>CVE-2021-21295</cve>
- <cve>CVE-2021-21409</cve>
- <cve>CVE-2021-21290</cve>
- <cve>CVE-2022-24823</cve>
- <cve>CVE-2022-41881</cve>
- <cve>CVE-2022-41915</cve>
- </suppress>
- <suppress until="2023-05-01Z">
- <notes><![CDATA[
- This CVE is tracked externally and is therefore suppressed in the automatic audit checks.
- https://nvd.nist.gov/vuln/detail/CVE-2022-25647
-
- File name: gson-2.8.6.jar
- ]]></notes>
- <packageUrl regex="true">^pkg:maven/com\.google\.code\.gson/gson@.*$</packageUrl>
- <cve>CVE-2022-25647</cve>
- </suppress>
- <suppress until="2023-05-01Z">
- <notes><![CDATA[
- This CVE only affect Multiplatform Gradle Projects, which this project is not.
- https://nvd.nist.gov/vuln/detail/CVE-2022-24329
- ]]></notes>
- <packageUrl regex="true">^pkg:maven/org\.jetbrains\.kotlin/kotlin\-stdlib.*@.*$</packageUrl>
- <cve>CVE-2022-24329</cve>
- </suppress>
- <suppress until="2023-06-01Z">
- <notes><![CDATA[
- This CVE is limited to processing of screenshots, which this app doesn't use.
- https://nvd.nist.gov/vuln/detail/CVE-2021-4277
-
- File name: legacy-support-core-utils-1.0.0.aar
- ]]></notes>
- <packageUrl regex="true">^pkg:maven/androidx\.legacy/legacy\-support\-core\-utils@.*$</packageUrl>
- <cve>CVE-2021-4277</cve>
- </suppress>
- <suppress until="2023-06-01Z">
- <notes><![CDATA[
- This CVE is limited to processing of screenshots, which this app doesn't use.
- https://nvd.nist.gov/vuln/detail/CVE-2021-4277
-
- File name: common-30.3.1.jar
- ]]></notes>
- <packageUrl regex="true">^pkg:maven/com\.android\.tools/common@.*$</packageUrl>
- <cve>CVE-2021-4277</cve>
- </suppress>
-</suppressions>