From dev-return-70201-archive-asf-public=cust-asf.ponee.io@struts.apache.org Tue Feb 5 09:30:26 2019 Return-Path: X-Original-To: archive-asf-public@cust-asf.ponee.io Delivered-To: archive-asf-public@cust-asf.ponee.io Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by mx-eu-01.ponee.io (Postfix) with SMTP id 9E6B1180608 for ; Tue, 5 Feb 2019 10:30:24 +0100 (CET) Received: (qmail 35024 invoked by uid 500); 5 Feb 2019 09:30:23 -0000 Mailing-List: contact dev-help@struts.apache.org; run by ezmlm Precedence: bulk List-Unsubscribe: List-Help: List-Post: List-Id: "Struts Developers List" Reply-To: "Struts Developers List" Delivered-To: mailing list dev@struts.apache.org Received: (qmail 35008 invoked by uid 99); 5 Feb 2019 09:30:22 -0000 Received: from mail-relay.apache.org (HELO mailrelay2-lw-us.apache.org) (207.244.88.137) by apache.org (qpsmtpd/0.29) with ESMTP; Tue, 05 Feb 2019 09:30:22 +0000 Received: from jenkins02.apache.org (jenkins02.apache.org [195.201.213.130]) by mailrelay2-lw-us.apache.org (ASF Mail Server at mailrelay2-lw-us.apache.org) with ESMTP id 02BEA3DB4 for ; Tue, 5 Feb 2019 09:30:22 +0000 (UTC) Received: from jenkins02.apache.org (localhost.localdomain [127.0.0.1]) by jenkins02.apache.org (ASF Mail Server at jenkins02.apache.org) with ESMTP id 1D85F33E001E for ; Tue, 5 Feb 2019 09:30:20 +0000 (UTC) Date: Tue, 5 Feb 2019 09:30:19 +0000 (UTC) From: Apache Jenkins Server To: dev@struts.apache.org Message-ID: <506119846.8540.1549359020142.JavaMail.jenkins@jenkins02> In-Reply-To: <396721601.8312.1549232911107.JavaMail.jenkins@jenkins02> References: <396721601.8312.1549232911107.JavaMail.jenkins@jenkins02> Subject: Build failed in Jenkins: Struts-master-JDK8-dependency-check #141 MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: quoted-printable X-Instance-Identity: MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAkqVKZPv7YyHBB3FvWfV7XQehwe/Ga3aadzSNknt8g382X3uN8A3SOQ+Ixq9HxS+ZlN6XR4TECySmSRy2JN5Rx8svxAD0TjtSF9LuU98dD+LniNDP7Lq6gvRFuJhbMHoS0nuTizDZLsK4X8TW5MyV9w+jFbdoZfRE5O/Mse0fkOeL5uoIS/3Vvu/W+x9QSjDkB7CaU56bPFlQjqqJBl3Cn9r34CkXQZYnLb/NjW4vcpw0+TgMUAPTIVEr5BTPZRshz19g7huwg3zANT5HBIZnzV4hsVY9w4JHkceFdKi/ibNnjPjsFs9pm0HSGJ/RDxjIvSTYT02eH4+m1RAYaj2E9QIDAQAB X-Jenkins-Job: Struts-master-JDK8-dependency-check X-Jenkins-Result: FAILURE See Changes: [github] Switch to Java 8 [github] Update Jenkinsfile [github] Update .travis.yml [lukaszlenart] Adds a link to JavaDocs [yasserzamani] upgrade to ASM 7 [amashchenko] WW-4991 Not existing property in listValueKey throws exceptio= n ------------------------------------------ [...truncated 912.91 KB...] [INFO] Exclude: src/main/webapp/**/*.svg [INFO] Exclude: src/main/webapp/**/*.txt [INFO] Exclude: src/main/resources/**/sitegraph-usage.txt [INFO] Exclude: src/main/resources/**/docs-urls.txt [INFO] Exclude: src/etc/header.txt [INFO] Exclude: src/main/resources/static/css/**/*.css [INFO] Exclude: src/main/resources/static/js/**/*.js [INFO] Exclude: src/main/resources/docs.cfg [INFO] Exclude: src/main/webapp/fonts/**/* [INFO] 5 resources included (use -debug for more details) [INFO] Rat check: Summary over all files. Unapproved: 0, unknown: 0, genera= ted: 0, approved: 4 licenses. [INFO]=20 [INFO] --- maven-jar-plugin:3.1.0:jar (default-jar) @ struts2-portlet-tiles= -plugin --- [INFO] Building jar: [INFO]=20 [INFO] >>> maven-source-plugin:3.0.1:jar (attach-sources) > generate-source= s @ struts2-portlet-tiles-plugin >>> [INFO]=20 [INFO] --- maven-enforcer-plugin:1.4.1:enforce (enforce-maven-version) @ st= ruts2-portlet-tiles-plugin --- [INFO]=20 [INFO] <<< maven-source-plugin:3.0.1:jar (attach-sources) < generate-source= s @ struts2-portlet-tiles-plugin <<< [INFO]=20 [INFO]=20 [INFO] --- maven-source-plugin:3.0.1:jar (attach-sources) @ struts2-portlet= -tiles-plugin --- [INFO] Building jar: [INFO]=20 [INFO] --- maven-site-plugin:3.7.1:attach-descriptor (attach-descriptor) @ = struts2-portlet-tiles-plugin --- [INFO] Skipping because packaging 'jar' is not pom. [INFO]=20 [INFO] --- dependency-check-maven:4.0.2:check (default) @ struts2-portlet-t= iles-plugin --- [INFO] Central analyzer disabled [INFO] Checking for updates [INFO] Skipping NVD check since last check was within 4 hours. [INFO] Skipping RetireJS update since last update was within 24 hours. [INFO] Check for updates complete (7 ms) [INFO] Analysis Started [INFO] Finished Archive Analyzer (0 seconds) [INFO] Finished File Name Analyzer (0 seconds) [INFO] Finished Jar Analyzer (0 seconds) [INFO] Finished Dependency Merging Analyzer (0 seconds) [INFO] Finished Version Filter Analyzer (0 seconds) [INFO] Finished Hint Analyzer (0 seconds) [INFO] Created CPE Index (0 seconds) [INFO] Skipping CPE Analysis for npm [INFO] Finished CPE Analyzer (0 seconds) [INFO] Finished False Positive Analyzer (0 seconds) [INFO] Finished NVD CVE Analyzer (0 seconds) [INFO] Finished Vulnerability Suppression Analyzer (0 seconds) [INFO] Finished Dependency Bundling Analyzer (0 seconds) [INFO] Analysis Complete (1 seconds) [WARNING]=20 One or more dependencies were identified with known vulnerabilities in Stru= ts 2 Portlet Tiles Plugin: tiles-ognl-3.0.8.jar (cpe:/a:ognl_project:ognl:3.0.8, cpe:/a:apache:tiles:3= .0.8, org.apache.tiles:tiles-ognl:3.0.8) : CVE-2016-3093 See the dependency-check report for more details. [INFO]=20 [INFO] -------------< org.apache.struts:struts2-sitegraph-plugin >---------= ---- [INFO] Building DEPRECATED: Struts 2 Sitegraph Plugin 2.6-SNAPSHOT [31= /36] [INFO] --------------------------------[ jar ]-----------------------------= ---- [INFO]=20 [INFO] --- maven-enforcer-plugin:1.4.1:enforce (enforce-maven-version) @ st= ruts2-sitegraph-plugin --- [INFO]=20 [INFO] --- maven-remote-resources-plugin:1.5:process (process-resource-bund= les) @ struts2-sitegraph-plugin --- [INFO]=20 [INFO] --- maven-resources-plugin:3.1.0:resources (default-resources) @ str= uts2-sitegraph-plugin --- [INFO] Using 'UTF-8' encoding to copy filtered resources. [INFO] Copying 3 resources [INFO] Copying 3 resources [INFO]=20 [INFO] --- maven-compiler-plugin:3.7.0:compile (default-compile) @ struts2-= sitegraph-plugin --- [INFO] Changes detected - recompiling the module! [INFO] Compiling 18 source files to [INFO] : uses unchecked or unsafe ope= rations. [INFO] : Recompile = with -Xlint:unchecked for details. [INFO]=20 [INFO] --- maven-bundle-plugin:3.5.0:manifest (bundle-manifest) @ struts2-s= itegraph-plugin --- [INFO]=20 [INFO] --- maven-resources-plugin:3.1.0:testResources (default-testResource= s) @ struts2-sitegraph-plugin --- [INFO] Using 'UTF-8' encoding to copy filtered resources. [INFO] Copying 6 resources [INFO] Copying 3 resources [INFO]=20 [INFO] --- maven-compiler-plugin:3.7.0:testCompile (default-testCompile) @ = struts2-sitegraph-plugin --- [INFO] Changes detected - recompiling the module! [INFO] Compiling 1 source file to [INFO]=20 [INFO] --- maven-surefire-plugin:2.22.1:test (default-test) @ struts2-siteg= raph-plugin --- [INFO]=20 [INFO] ------------------------------------------------------- [INFO] T E S T S [INFO] ------------------------------------------------------- [INFO] Running org.apache.struts2.sitegraph.SiteGraphTest ERROR StatusLogger Log4j2 could not find a logging implementation. Please a= dd log4j-core to the classpath. Using SimpleLogger to log to the console... [INFO] Tests run: 1, Failures: 0, Errors: 0, Skipped: 0, Time elapsed: 0.74= 1 s - in org.apache.struts2.sitegraph.SiteGraphTest [INFO]=20 [INFO] Results: [INFO]=20 [INFO] Tests run: 1, Failures: 0, Errors: 0, Skipped: 0 [INFO]=20 [INFO]=20 [INFO] --- apache-rat-plugin:0.12:check (default) @ struts2-sitegraph-plugi= n --- [INFO] Added 1 additional default licenses. [INFO] Added 1 custom approved licenses. [INFO] Will parse SCM ignores for exclusions... [INFO] Finished adding exclusions from SCM ignore files. [INFO] 61 implicit excludes (use -debug for more details). [INFO] Exclude: Jenkinsfile [INFO] Exclude: src/main/groovy/Jenkinsfile.gdsl [INFO] Exclude: src/main/resources/org/apache/struts2/static/domTT.js [INFO] Exclude: src/site/resources/tags/**/*.html [INFO] Exclude: src/main/resources/*LICENSE.txt [INFO] Exclude: src/test/resources/**/*.txt [INFO] Exclude: src/main/webapp/**/*.css [INFO] Exclude: src/main/webapp/**/*.map [INFO] Exclude: src/main/webapp/**/*.js [INFO] Exclude: src/main/webapp/**/*.svg [INFO] Exclude: src/main/webapp/**/*.txt [INFO] Exclude: src/main/resources/**/sitegraph-usage.txt [INFO] Exclude: src/main/resources/**/docs-urls.txt [INFO] Exclude: src/etc/header.txt [INFO] Exclude: src/main/resources/static/css/**/*.css [INFO] Exclude: src/main/resources/static/js/**/*.js [INFO] Exclude: src/main/resources/docs.cfg [INFO] Exclude: src/main/webapp/fonts/**/* [INFO] 27 resources included (use -debug for more details) [INFO] Rat check: Summary over all files. Unapproved: 0, unknown: 0, genera= ted: 0, approved: 26 licenses. [INFO]=20 [INFO] --- maven-jar-plugin:3.1.0:jar (default-jar) @ struts2-sitegraph-plu= gin --- [INFO] Building jar: [INFO]=20 [INFO] >>> maven-source-plugin:3.0.1:jar (attach-sources) > generate-source= s @ struts2-sitegraph-plugin >>> [INFO]=20 [INFO] --- maven-enforcer-plugin:1.4.1:enforce (enforce-maven-version) @ st= ruts2-sitegraph-plugin --- [INFO]=20 [INFO] <<< maven-source-plugin:3.0.1:jar (attach-sources) < generate-source= s @ struts2-sitegraph-plugin <<< [INFO]=20 [INFO]=20 [INFO] --- maven-source-plugin:3.0.1:jar (attach-sources) @ struts2-sitegra= ph-plugin --- [INFO] Building jar: [INFO]=20 [INFO] --- maven-site-plugin:3.7.1:attach-descriptor (attach-descriptor) @ = struts2-sitegraph-plugin --- [INFO] Skipping because packaging 'jar' is not pom. [INFO]=20 [INFO] --- dependency-check-maven:4.0.2:check (default) @ struts2-sitegraph= -plugin --- [INFO] Central analyzer disabled [INFO] Checking for updates [INFO] Skipping NVD check since last check was within 4 hours. [INFO] Skipping RetireJS update since last update was within 24 hours. [INFO] Check for updates complete (7 ms) [INFO] Analysis Started [INFO] Finished Archive Analyzer (0 seconds) [INFO] Finished File Name Analyzer (0 seconds) [INFO] Finished Jar Analyzer (0 seconds) [INFO] Finished Dependency Merging Analyzer (0 seconds) [INFO] Finished Version Filter Analyzer (0 seconds) [INFO] Finished Hint Analyzer (0 seconds) [INFO] Created CPE Index (0 seconds) [INFO] Skipping CPE Analysis for npm [INFO] Finished CPE Analyzer (0 seconds) [INFO] Finished False Positive Analyzer (0 seconds) [INFO] Finished NVD CVE Analyzer (0 seconds) [INFO] Finished Vulnerability Suppression Analyzer (0 seconds) [INFO] Finished Dependency Bundling Analyzer (0 seconds) [INFO] Analysis Complete (1 seconds) [WARNING]=20 One or more dependencies were identified with known vulnerabilities in DEPR= ECATED: Struts 2 Sitegraph Plugin: org.mortbay.jetty-5.1.4.jar (jetty:org.mortbay.jetty:5.1.4, cpe:/a:mortbay_= jetty:jetty:5.1.4, cpe:/a:mortbay:jetty:5.1.4, cpe:/a:jetty:jetty:5.1.4) : = CVE-2011-4461, CVE-2009-1524, CVE-2009-1523, CVE-2005-3747, CVE-2007-5615 jasper-compiler-5.5.12.jar (cpe:/a:apache:tomcat:5.5.12, cpe:/a:apache_soft= ware_foundation:tomcat:5.5.12, cpe:/a:jasper_project:jasper:5.5.12, tomcat:= jasper-compiler:5.5.12) : CVE-2007-6286, CVE-2009-3548, CVE-2010-1157, CVE-= 2014-0096, CVE-2009-0033, CVE-2014-0099, CVE-2008-4308, CVE-2008-5519, CVE-= 2009-2693, CVE-2017-6056, CVE-2012-5568, CVE-2012-5887, CVE-2012-5885, CVE-= 2011-2526, CVE-2012-5886, CVE-2008-2370, CVE-2013-6357, CVE-2006-3835, CVE-= 2011-2204, CVE-2007-5342, CVE-2008-1947, CVE-2007-0450, CVE-2011-3190, CVE-= 2008-5515, CVE-2007-1858, CVE-2016-6325, CVE-2008-1232, CVE-2014-0119, CVE-= 2010-2227, CVE-2011-5063, CVE-2011-5062, CVE-2014-0075, CVE-2008-0128, CVE-= 2011-1184, CVE-2011-5064, CVE-2010-3718, CVE-2007-5333, CVE-2006-7195, CVE-= 2013-4590, CVE-2006-7196, CVE-2016-5425, CVE-2009-2901, CVE-2009-2902, CVE-= 2009-0783, CVE-2009-0781, CVE-2007-3385, CVE-2007-2450, CVE-2007-3382, CVE-= 2007-3386, CVE-2009-0580, CVE-2012-0022, CVE-2007-2449, CVE-2013-4322, CVE-= 2011-0013, CVE-2013-4444, CVE-2013-4286, CVE-2013-2185 jasper-runtime-5.5.12.jar (tomcat:jasper-runtime:5.5.12, cpe:/a:apache:tomc= at:5.5.12, cpe:/a:apache_software_foundation:tomcat:5.5.12, cpe:/a:jasper_p= roject:jasper:5.5.12) : CVE-2007-6286, CVE-2009-3548, CVE-2010-1157, CVE-20= 14-0096, CVE-2009-0033, CVE-2014-0099, CVE-2008-4308, CVE-2008-5519, CVE-20= 09-2693, CVE-2017-6056, CVE-2012-5568, CVE-2012-5887, CVE-2012-5885, CVE-20= 11-2526, CVE-2012-5886, CVE-2008-2370, CVE-2013-6357, CVE-2006-3835, CVE-20= 11-2204, CVE-2007-5342, CVE-2008-1947, CVE-2007-0450, CVE-2011-3190, CVE-20= 08-5515, CVE-2007-1858, CVE-2016-6325, CVE-2008-1232, CVE-2014-0119, CVE-20= 10-2227, CVE-2011-5063, CVE-2011-5062, CVE-2014-0075, CVE-2008-0128, CVE-20= 11-1184, CVE-2011-5064, CVE-2010-3718, CVE-2007-5333, CVE-2006-7195, CVE-20= 13-4590, CVE-2006-7196, CVE-2016-5425, CVE-2009-2901, CVE-2009-2902, CVE-20= 09-0783, CVE-2009-0781, CVE-2007-3385, CVE-2007-2450, CVE-2007-3382, CVE-20= 07-3386, CVE-2009-0580, CVE-2012-0022, CVE-2007-2449, CVE-2013-4322, CVE-20= 11-0013, CVE-2013-4444, CVE-2013-4286, CVE-2013-2185 See the dependency-check report for more details. [INFO] --------------------------------------------------------------------= ---- [INFO] Reactor Summary for Struts 2 2.6-SNAPSHOT: [INFO]=20 [INFO] Struts 2 Bill of Materials ......................... SUCCESS [ 1.31= 1 s] [INFO] Struts 2 ........................................... SUCCESS [03:30 = min] [INFO] Struts 2 Core ...................................... SUCCESS [01:29 = min] [INFO] Struts 2 Plugins ................................... SUCCESS [ 2.30= 7 s] [INFO] Struts 2 Configuration Browser Plugin .............. SUCCESS [ 2.66= 3 s] [INFO] Struts 2 Sitemesh Plugin ........................... SUCCESS [ 3.12= 3 s] [INFO] Struts 2 Tiles Plugin .............................. SUCCESS [ 4.47= 5 s] [INFO] Struts 2 DWR Plugin ................................ SUCCESS [ 2.62= 3 s] [INFO] Struts 2 Spring Plugin ............................. SUCCESS [ 4.57= 8 s] [INFO] Struts 2 Convention Plugin ......................... SUCCESS [ 9.64= 2 s] [INFO] Struts 2 JUnit Plugin .............................. SUCCESS [ 7.37= 5 s] [INFO] Struts 2 JSON Plugin ............................... SUCCESS [ 8.10= 8 s] [INFO] Struts 2 Bean Validation Plugin .................... SUCCESS [ 4.79= 9 s] [INFO] Struts 2 Async Plugin .............................. SUCCESS [ 3.71= 7 s] [INFO] Struts 2 Webapps ................................... SUCCESS [ 2.95= 2 s] [INFO] Struts 2 Showcase Webapp ........................... SUCCESS [ 50.39= 1 s] [INFO] Struts 2 REST Plugin ............................... SUCCESS [ 5.65= 8 s] [INFO] Struts 2 Rest Showcase Webapp ...................... SUCCESS [ 3.06= 4 s] [INFO] Struts 2 CDI Plugin ................................ SUCCESS [ 4.24= 3 s] [INFO] DEPRECATED: Struts 2 Embedded JSP Plugin ........... SUCCESS [ 8.84= 6 s] [INFO] Struts 2 GXP Plugin ................................ SUCCESS [ 2.71= 5 s] [INFO] Struts 2 Jasper Reports Plugin ..................... SUCCESS [ 6.38= 6 s] [INFO] Struts 2 Java Templates Plugin ..................... SUCCESS [ 3.84= 3 s] [INFO] Struts 2 JFreeChart Plugin ......................... SUCCESS [ 5.19= 1 s] [INFO] Struts 2 OSGi Plugin ............................... SUCCESS [ 4.48= 1 s] [INFO] Struts 2 OVal Plugin ............................... SUCCESS [ 5.51= 9 s] [INFO] Struts 2 Pell Multipart Plugin ..................... SUCCESS [ 3.34= 5 s] [INFO] Struts 2 Plexus Plugin ............................. SUCCESS [ 2.62= 1 s] [INFO] Struts 2 Portlet Plugin ............................ SUCCESS [ 7.88= 6 s] [INFO] Struts 2 Portlet Tiles Plugin ...................... SUCCESS [ 2.89= 1 s] [INFO] DEPRECATED: Struts 2 Sitegraph Plugin .............. FAILURE [ 6.75= 7 s] [INFO] Struts 2 TestNG Plugin ............................. SKIPPED [INFO] Struts 2 OSGi Bundles .............................. SKIPPED [INFO] Struts 2 OSGi Admin Bundle ......................... SKIPPED [INFO] Struts 2 OSGi Demo Bundle .......................... SKIPPED [INFO] Struts 2 Assembly .................................. SKIPPED [INFO] --------------------------------------------------------------------= ---- [INFO] BUILD FAILURE [INFO] --------------------------------------------------------------------= ---- [INFO] Total time: 08:03 min [INFO] Finished at: 2019-02-05T09:30:18Z [INFO] --------------------------------------------------------------------= ---- [ERROR] Failed to execute goal org.owasp:dependency-check-maven:4.0.2:check= (default) on project struts2-sitegraph-plugin:=20 [ERROR]=20 [ERROR] One or more dependencies were identified with vulnerabilities that = have a CVSS score greater than or equal to '7.0':=20 [ERROR]=20 [ERROR] jasper-compiler-5.5.12.jar: CVE-2009-3548, CVE-2011-3190, CVE-2016-= 6325, CVE-2016-5425, CVE-2013-2185 [ERROR] jasper-runtime-5.5.12.jar: CVE-2009-3548, CVE-2011-3190, CVE-2016-6= 325, CVE-2016-5425, CVE-2013-2185 [ERROR]=20 [ERROR] See the dependency-check report for more details. [ERROR]=20 [ERROR]=20 [ERROR] -> [Help 1] [ERROR]=20 [ERROR] To see the full stack trace of the errors, re-run Maven with the -e= switch. [ERROR] Re-run Maven using the -X switch to enable full debug logging. [ERROR]=20 [ERROR] For more information about the errors and possible solutions, pleas= e read the following articles: [ERROR] [Help 1] http://cwiki.apache.org/confluence/display/MAVEN/MojoFailu= reException [ERROR]=20 [ERROR] After correcting the problems, you can resume the build with the co= mmand [ERROR] mvn -rf :struts2-sitegraph-plugin Build step 'Execute shell' marked build as failure [locks-and-latches] Releasing all the locks [locks-and-latches] All the locks released Setting MAVEN_3_LATEST__HOME=3D/home/jenkins/tools/maven/latest3/ --------------------------------------------------------------------- To unsubscribe, e-mail: dev-unsubscribe@struts.apache.org For additional commands, e-mail: dev-help@struts.apache.org