mirror of
https://github.com/ysoftdevs/DependencyCheck.git
synced 2026-03-26 02:51:27 +01:00
patch for issue #229 to remove bundle vendor from the evidence
Former-commit-id: a5a24422d5edfb23d3ea4d4c617044051d454860
This commit is contained in:
@@ -116,6 +116,7 @@ public class JarAnalyzer extends AbstractFileTypeAnalyzer {
|
|||||||
"tool",
|
"tool",
|
||||||
"bundle-manifestversion",
|
"bundle-manifestversion",
|
||||||
"bundlemanifestversion",
|
"bundlemanifestversion",
|
||||||
|
"bundle-vendor",
|
||||||
"include-resource",
|
"include-resource",
|
||||||
"embed-dependency",
|
"embed-dependency",
|
||||||
"ipojo-components",
|
"ipojo-components",
|
||||||
@@ -689,10 +690,11 @@ public class JarAnalyzer extends AbstractFileTypeAnalyzer {
|
|||||||
foundSomething = true;
|
foundSomething = true;
|
||||||
productEvidence.addEvidence(source, key, value, Confidence.MEDIUM);
|
productEvidence.addEvidence(source, key, value, Confidence.MEDIUM);
|
||||||
addMatchingValues(classInformation, value, productEvidence);
|
addMatchingValues(classInformation, value, productEvidence);
|
||||||
} else if (key.equalsIgnoreCase(BUNDLE_VENDOR)) {
|
// //the following caused false positives.
|
||||||
foundSomething = true;
|
// } else if (key.equalsIgnoreCase(BUNDLE_VENDOR)) {
|
||||||
vendorEvidence.addEvidence(source, key, value, Confidence.HIGH);
|
// foundSomething = true;
|
||||||
addMatchingValues(classInformation, value, vendorEvidence);
|
// vendorEvidence.addEvidence(source, key, value, Confidence.HIGH);
|
||||||
|
// addMatchingValues(classInformation, value, vendorEvidence);
|
||||||
} else if (key.equalsIgnoreCase(BUNDLE_VERSION)) {
|
} else if (key.equalsIgnoreCase(BUNDLE_VERSION)) {
|
||||||
foundSomething = true;
|
foundSomething = true;
|
||||||
versionEvidence.addEvidence(source, key, value, Confidence.HIGH);
|
versionEvidence.addEvidence(source, key, value, Confidence.HIGH);
|
||||||
|
|||||||
Reference in New Issue
Block a user