eclipse-tractusx / sig-infra

Apache License 2.0
2 stars 2 forks source link

Aplication not passing VeraCode Rules due to Spring #249

Closed Bailonis closed 1 year ago

Bailonis commented 1 year ago

Hi there!

We are having some issues with the VeraCode platform, the problem is that our scans are not passing the rules, this because it has some vulnerabilities above medium, but all of this came from spring, is there any way to resolve this? Our application is demand-capacity-mgmt-backend

image

Thanks in advance

Siegfriedk commented 1 year ago

Hi @Bailonis ,

you actually need to upgrade your spring boot.

Pls get in touch with security @the-tatanka

Bailonis commented 1 year ago

@the-tatanka we are using spring-boot-starter-parent version 2.7.8. Which version do you recommend?

Bailonis commented 1 year ago

I'm also receiving this message on my build whenever I try to do a veracode scan:

image

scherersebastian commented 1 year ago

I will look into it today

scherersebastian commented 1 year ago

we need to takle a few things... I will create a PR and set you as reviewer.

scherersebastian commented 1 year ago

https://github.com/eclipse-tractusx/demand-capacity-mgmt/pull/14