| Age | Commit message (Collapse) | Author | Files | Lines | |
|---|---|---|---|---|---|
| 2025-02-04 | Remove OWASP dependency check plugin | Albin | 1 | -59/+0 | |
| The OWASP DependencyCheck plugin has been replaced with `osv-scanner` which covers our use-case. | |||||
| 2025-02-03 | Bump dates of depependency check suppressions | Jonatan Rhodin | 1 | -1/+1 | |
| 2025-01-07 | Extend CVE suppression | David Göransson | 1 | -1/+1 | |
| 2024-12-17 | Extend expiry date | David Göransson | 1 | -4/+4 | |
| 2024-11-01 | Push suppression of CVE-2022-24329 | Albin | 1 | -1/+1 | |
| 2024-10-04 | Suppress CVE-2024-47554 | Albin | 1 | -0/+7 | |
| 2024-09-23 | Suppress CVE-2024-7254 | Jonatan Rhodin | 1 | -0/+9 | |
| 2024-09-17 | Remove old false-postive CVE suppression | David Göransson | 1 | -8/+0 | |
| 2024-09-17 | Extend CVE suppression for ksp false-positive | David Göransson | 1 | -1/+1 | |
| 2024-06-27 | Suppress false-postive CVE | David Göransson | 1 | -0/+7 | |
| 2024-06-07 | Suppress gRPC CVEs | Albin | 1 | -0/+16 | |
| These CVEs are a combination of a false-positive and CVEs not affecting our app. | |||||
| 2024-06-07 | Remove outdated suppression for CVE-2023-3635 | Albin | 1 | -10/+0 | |
| 2024-06-07 | Push suppression of CVE-2018-1000840 | Albin | 1 | -1/+1 | |
| Pushing the suppression a few months so that we can revisit it after bumping to K2. | |||||
| 2024-05-06 | Push suppression date for CVE-2022-24329 | Albin | 1 | -1/+1 | |
| Reasons: * Not affecting our project. * Transitive dependency that require update in upstream dependencies. | |||||
| 2024-05-06 | Remove outdated suppression rules | Albin | 1 | -42/+0 | |
| 2024-04-15 | Suppress Joda-Time CVE-2024-23080 | Albin | 1 | -0/+9 | |
| 2024-03-12 | Suppress false-positive CVE-2014-9152 | Albin | 1 | -0/+8 | |
| 2023-12-14 | Add compose destinations navigation dependency | David Göransson | 1 | -0/+9 | |
| 2023-12-06 | Update CVE suppression | David Göransson | 1 | -1/+1 | |
| 2023-11-06 | Push suppression date for unfixed non-critical CVEs | Albin | 1 | -3/+3 | |
| 2023-09-14 | Push suppression date for CVE-2023-2976 | Albin | 1 | -1/+1 | |
| Pushing the suppression date since not much new information is available and no upstream release has been made of the affected library (espresso). | |||||
| 2023-07-27 | Suppress CVE-2023-3635 | Albin | 1 | -0/+10 | |
| 2023-06-07 | Update gradle dependency suppressions | Albin | 1 | -69/+7 | |
| 2023-05-19 | Bump kotlin and agp | Albin | 1 | -0/+8 | |
| 2023-05-03 | Push suppression review date | Albin | 1 | -7/+7 | |
| New review date: 2023-06-01 | |||||
| 2023-01-10 | Suppress CVE-2021-4277 | Albin | 1 | -0/+20 | |
| 2022-12-16 | Update compose to 1.3.2 | Albin | 1 | -11/+0 | |
| This fixes the following transitive CVEs in Compose: - CVE-2022-3171 - CVE-2022-3510 However, the mentioned CVEs are still present via the espresso-contrib dependency. | |||||
| 2022-12-13 | Set CVE suppression expiration to 2023-05-01 | Albin | 1 | -8/+8 | |
| 2022-12-13 | Suppress CVE-2022-3510 | Albin | 1 | -0/+1 | |
| 2022-12-08 | Suppress test framework CVEs | Albin | 1 | -0/+40 | |
| CVEs: - CVE-2020-8908 - CVE-2021-37714 - CVE-2022-36033 | |||||
| 2022-12-08 | Update suppression of CVE-2022-3171 | Albin | 1 | -1/+14 | |
| 2022-12-08 | Update suppression of CVE-2021-22569 | Albin | 1 | -3/+5 | |
| 2022-12-08 | Remove suppression of CVE-2022-24329 | Albin | 1 | -6/+0 | |
| This CVE has been fixed upstream. | |||||
| 2022-12-08 | Suppress CVE-2021-37533 | Albin | 1 | -0/+15 | |
| This CVE affects the Apache Commons Net's FTP client that this app doesn't use. https://www.openwall.com/lists/oss-security/2022/12/03/1 File names: - commons-beanutils-1.9.4.jar - commons-collections-3.2.2.jar - commons-digester-2.1.jar - commons-logging-1.2.jar - commons-validator-1.7.jar | |||||
| 2022-10-07 | Suppress CVE-2022-3171 from automatic audit checks | Albin | 1 | -0/+7 | |
| This suppression only affects the Android app. The CVE will instead be tracked externally and will likely be mitigated by either updating affected dependencies or by identifying that it doesn't affect the app. | |||||
| 2022-06-15 | Suppress false positive CVE-2021-22569 | Albin | 1 | -0/+8 | |
| 2022-03-09 | Suppress false positive Android CVE | Albin | 1 | -0/+9 | |
| The CVE (CVE-2022-24329) only affects "Multiplatform Gradle Projects" according to the CVE description, which this is not, and therefore it's considered a false positive. | |||||
