exasol/release-droid

Dependency check fails

kaklakariada opened this issue · 0 comments

See https://github.com/exasol/release-droid/actions/runs/4867637136/jobs/8680388598

Error:  Failed to execute goal org.sonatype.ossindex.maven:ossindex-maven-plugin:3.2.0:audit (default-cli) on project release-droid: Detected 1 vulnerable components:
Error:    com.google.guava:guava:jar:30.1.1-jre:compile; https://ossindex.sonatype.org/component/pkg:maven/com.google.guava/guava@30.1.1-jre?utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.1
Error:      * [CVE-2020-8908] CWE-379: Creation of Temporary File in Directory with Incorrect Permissions (6.2); https://ossindex.sonatype.org/vulnerability/CVE-2020-8908?component-type=maven&component-name=com.google.guava%2Fguava&utm_source=ossindex-client&utm_medium=integration&utm_content=1.8.1