(DC 12.1.6) Exception reading archive - (Archive Analyzer): Extra subfield lenght exceeds remaining bytes in extra: 21064 > 37
envgap__dependency-check__DependencyCheck-7985
01 / FAILURE SIGNATURE
As reported upstream
[ERROR] Exception reading archive 'project.tgz'.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
fc28be081e5434019b35f5796a3a153a85bdf627- Manifest
pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
dependency-check/DependencyCheck #7985 · read the original issue
**Precondition** - [x] I checked the issues list for existing open or closed reports of the same problem. **Version of dependency-check used** The problem occurs using version 12.1.6 on Linux CLI. **Describe the bug** The console logs report the following: `[INFO] Analysis Started [ERROR] Exception reading archive 'project.tgz'. [WARN] An error occurred while analyzing '/home/pipelineuser/project.tgz' (Archive Analyzer): Extra subfield lenght exceeds remaining bytes in extra: 21064 > 37 [INFO] Finished Archive Analyzer (1 seconds)` **Other observations** We see that DC 12.1.6 uses apache commons - commons-compress-1.28.0.jar There is a bug report in Apache Compress with regards similar errors: [GZip IOException: Extra subfield lenght exceeds remaining bytes in extra field](https://issues.apache.org/jira/browse/COMPRESS-705) In which the report mentions _"Extra subfield lenght exceeds remaining bytes in extra: 21064 > 37"._ Given the wording in both cases, suggests it's a dependency problem _( commons-compress-1.28.0 )_. The ticket marks it resolved at compress 1.29.0 We have previously used DC 12.1.3 and don't recall seeing this archive issue with that and it uses commons-compress-1.27.1.jar.
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]