Skip to content

Vulnerabilities check : Using VEX to avoid false positive ? #1664

@sbernard31

Description

@sbernard31

Using VEX could be a good way to avoid some false positive during vulnerabilities check.
But if it is used direct/transitive dependencies should be managed correctly which is generally not really done.
So maybe using maven tooling like : depcheck-maven-plugin should be used in addition.

For me details see :

(Not 100% sure this is a good move but I open this issue to keep in mind the idea)

Metadata

Metadata

Assignees

No one assigned

    Labels

    build / ciAll about Build or Continious IntegrationenhancementImprovement of existing features

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions