On 20/05/2021 16.15, Mark Thomas wrote:
I like it.
Looks like Tomcat has managed to trigger a false positive in
CharsetCache.java.
You can exclude files and contexts if you click on 'scan settings...'
and edit it. There will later on be a per-occurrence action to ignore or
mark as intended/false-positive that the scanner will remember.
thouogh, remember the scanner only rescans every 12 hours, so it'll be a
while before your changes show up. I might change that to something shorter.
Might want to consider a way to handle such cases depending on how
frequent they are.
Mark
---------------------------------------------------------------------
To unsubscribe, e-mail: diversity-unsubscr...@apache.org
For additional commands, e-mail: diversity-h...@apache.org
---------------------------------------------------------------------
To unsubscribe, e-mail: diversity-unsubscr...@apache.org
For additional commands, e-mail: diversity-h...@apache.org