Scanning reveals devil's number vulnerability

Docker-compose deployment
SonarQube server version is 10.4 Enterprise Edition
Sonar Scanner version 7.0.1.4817
Scan a vulnerability alert with a devil’s number through SonarQube, but if the code structure doesn’t look like a devil’s number, is it a false alarm


Hi,

Thanks for this report. Since 10.4 is EOL, can you upgrade to a current version and see if this is still replicable?

Your upgrade path is:

10.4 → 2025.1.1-> 2025.2 (last step optional)

You may find these resources helpful:

If you have questions about upgrading, feel free to open a new thread for that here.

 
Thx,
Ann