-
Notifications
You must be signed in to change notification settings - Fork 48
#1143: Added CPE methods to UrlUpdater #1198
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
#1143: Added CPE methods to UrlUpdater #1198
Conversation
…t/103-add-methods-to-url-updater-2 # Conflicts: # url-updater/src/main/java/com/devonfw/tools/ide/url/tool/helm/HelmUrlUpdater.java
hohwille
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@leonrohne27 thanks for this PR. This is a good enhancement and preparation for #1143
Please note that your CPE configuration is incomplete and many other URL Updaters still use the default (getTool()) even though this is not correct.
I guess you will realise that on your way, and can then override these new methods in other URL updates in future PRs.
BTW: I did a constructive review and directly edited AbstractUrlUpdater to improve the JavaDoc.
IMHO ready for merge.
…thub.com/leonrohne27/IDEasy into implement/103-add-methods-to-url-updater
url-updater/src/main/java/com/devonfw/tools/ide/url/tool/sonar/SonarUrlUpdater.java
Outdated
Show resolved
Hide resolved
hohwille
left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@leonrohne27 thanks for your rework. Great progress 👍
Most CPEs seems to match - e.g. for pip see https://nvd.nist.gov/vuln/detail/CVE-2023-5752#vulnConfigurationsArea or for python see https://nvd.nist.gov/vuln/detail/CVE-2024-9287#vulnConfigurationsArea or for terraform see https://nvd.nist.gov/products/cpe/search/results?namingFormat=2.3&orderBy=2.3&keyword=cpe%3A2.3%3Aa%3Ahashicorp%3Aterraform&status=FINAL%2CDEPRECATED - just to show some cross-checks I did.
I also found some incorrect CPEs to update.
url-updater/src/main/java/com/devonfw/tools/ide/url/tool/mvn/Mvn4UrlUpdater.java
Outdated
Show resolved
Hide resolved
url-updater/src/main/java/com/devonfw/tools/ide/url/tool/kotlinc/KotlincUrlUpdater.java
Outdated
Show resolved
Hide resolved
url-updater/src/main/java/com/devonfw/tools/ide/url/tool/quarkus/QuarkusUrlUpdater.java
Outdated
Show resolved
Hide resolved
url-updater/src/main/java/com/devonfw/tools/ide/url/updater/AbstractUrlUpdater.java
Show resolved
Hide resolved
…stractUrlUpdater.java Co-authored-by: Jörg Hohwiller <[email protected]>
…us/QuarkusUrlUpdater.java Co-authored-by: Jörg Hohwiller <[email protected]>
…nc/KotlincUrlUpdater.java Co-authored-by: Jörg Hohwiller <[email protected]>
…vn4UrlUpdater.java Co-authored-by: Jörg Hohwiller <[email protected]>
…thub.com/leonrohne27/IDEasy into implement/103-add-methods-to-url-updater
Part of #1143
Implements: