jenkinsci / cucumber-reports-plugin

Jenkins plugin to generate cucumber-jvm reports
https://plugins.jenkins.io/cucumber-reports/
GNU Lesser General Public License v2.1
210 stars 232 forks source link

Security Violations and Operational Risks #441

Closed dietmarpradler closed 1 year ago

dietmarpradler commented 1 year ago

Hello, we are using the Jenkins plugin cucumber-reports provided by you in version 5.7.5. Through a security scan with JFrog-XRAY we have encountered security vulnerabilities and operational risks. The current security policy of our company prohibits the use of plugins with vulnerabilities. I ask to fix the vulnerabilities and operational risks in this plugin. Thank you very much for your support.

Best regards Dietmar Pradler

Maven_net.masterthought.jenkins_cucumber-reports_version-5.7.5_v001113_2023-07-26.zip Jenkins Environment.txt

damianszczepanik commented 1 year ago

For the security issues follow https://www.jenkins.io/security/