| Actually, you didn't explain they were false positives. You said they were Spring's issue, not Cloudbees. You deflected and said it wasn't your problem. You're using Spring 2.5 or at least the time this issue was written, that's what you are using. It's clearly out of date. Rather than attacking the requestor, could you address the request? Is there an ETA for updating these libraries or Spring version? Could you maybe administer this ticket, relate it to another, possibly blocked issue to upgrade Spring? Or just address the open concern that the underlying framework is dated and if there's an ETA to do somethign about it? If you're not concerned about it - why aren't you concerned? I get you're probably tired of people asking for silly requests with little research. Apologies if this is the case, I did, at the time of writing my comment look into the maven file and libraries despite not being a developer. Heck, maybe our scanner is "trash" as you're accusing. I don't own it. I just want the problems to go away so the auditors are happy. Any help or explanation of that to make my life and possibly others better would be tremendously helpful. Thanks! |