From ef0ef207bea51c5484658d4816711188b3fe0a69 Mon Sep 17 00:00:00 2001 From: labkey-susanh Date: Wed, 22 Apr 2026 07:49:54 -0700 Subject: [PATCH 1/2] Suppress CVE for PDFbox that does not affect us --- dependencyCheckSuppression.xml | 25 +++++++++++++------------ gradle.properties | 2 +- 2 files changed, 14 insertions(+), 13 deletions(-) diff --git a/dependencyCheckSuppression.xml b/dependencyCheckSuppression.xml index d610e97a2b..6e0de95a90 100644 --- a/dependencyCheckSuppression.xml +++ b/dependencyCheckSuppression.xml @@ -229,31 +229,31 @@ --> + file name: pdfbox-3.0.7.jar + ]]> ^pkg:maven/org\.apache\.pdfbox/pdfbox@.*$ - CVE-2026-23907 + CVE-2026-33929 + file name: pdfbox-debugger-3.0.7.jar + ]]> ^pkg:maven/org\.apache\.pdfbox/pdfbox-debugger@.*$ - CVE-2026-23907 + CVE-2026-33929 + file name: pdfbox-io-3.0.7.jar + ]]> ^pkg:maven/org\.apache\.pdfbox/pdfbox-io@.*$ - CVE-2026-23907 + CVE-2026-33929 + file name: pdfbox-tools-3.0.7.jar + ]]> ^pkg:maven/org\.apache\.pdfbox/pdfbox-tools@.*$ - CVE-2026-23907 + CVE-2026-33929 + ^pkg:maven/org\.apache\.pdfbox/pdfbox@.*$ + CVE-2026-23907 + + + + ^pkg:maven/org\.apache\.pdfbox/pdfbox-debugger@.*$ + CVE-2026-23907 + + + + ^pkg:maven/org\.apache\.pdfbox/pdfbox-io@.*$ + CVE-2026-23907 + + + + ^pkg:maven/org\.apache\.pdfbox/pdfbox-tools@.*$ + CVE-2026-23907 + + + ^pkg:maven/org\.apache\.pdfbox/pdfbox@.*$