|
19 | 19 | <findbugs.skip>${wc.qa.skip}</findbugs.skip> |
20 | 20 | <pmd.skip>${wc.qa.skip}</pmd.skip> |
21 | 21 | <badges.skip>${wc.qa.skip}</badges.skip> |
| 22 | + |
22 | 23 | <javadoc.excluded.packages /> |
23 | 24 | <checkstyle.excludes /> |
24 | 25 |
|
25 | 26 | <!-- |
26 | 27 | OWASP dependency vulnerability scanner. |
27 | 28 | --> |
28 | | - <bt.owasp.dependency-check.version>3.3.2</bt.owasp.dependency-check.version> |
29 | | - <bt.owasp.dependency-check.enable>false</bt.owasp.dependency-check.enable> |
30 | | - <!-- properties to allow for mirroring of CVE definitions --> |
31 | | - <bt.owasp.dependency-check.cve.mirror>https://nvd.nist.gov/feeds/xml/cve</bt.owasp.dependency-check.cve.mirror> |
32 | | - <bt.owasp.dependency-check.cve.12.path>1.2</bt.owasp.dependency-check.cve.12.path> |
33 | | - <bt.owasp.dependency-check.cve.20.path>2.0</bt.owasp.dependency-check.cve.20.path> |
| 29 | + <bt.owasp.dependency-check.version>4.0.1</bt.owasp.dependency-check.version> |
| 30 | + <bt.owasp.dependency-check.skip>false</bt.owasp.dependency-check.skip> |
| 31 | + <!-- allow for proxy settings --> |
| 32 | + <bt.owasp.dependency-check.proxy></bt.owasp.dependency-check.proxy> |
34 | 33 | <!-- Non java analysers are off by default because, well this is a Maven builder! --> |
35 | 34 | <!-- nodejs nsp requires nsp on the path at scan time --> |
36 | 35 | <bt.owasp.dependency-check.enableNsp>false</bt.owasp.dependency-check.enableNsp> |
|
60 | 59 | <version>${bt.owasp.dependency-check.version}</version> |
61 | 60 | <configuration> |
62 | 61 | <failBuildOnAnyVulnerability>true</failBuildOnAnyVulnerability> |
63 | | - <cveUrl12Modified>${bt.owasp.dependency-check.cve.mirror}/${bt.owasp.dependency-check.cve.12.path}/nvdcve-Modified.xml.gz</cveUrl12Modified> |
64 | | - <cveUrl20Modified>${bt.owasp.dependency-check.cve.mirror}/${bt.owasp.dependency-check.cve.20.path}/nvdcve-2.0-Modified.xml.gz</cveUrl20Modified> |
65 | | - <cveUrl12Base>${bt.owasp.dependency-check.cve.mirror}/${bt.owasp.dependency-check.cve.12.path}/nvdcve-%d.xml.gz</cveUrl12Base> |
66 | | - <cveUrl20Base>${bt.owasp.dependency-check.cve.mirror}/${bt.owasp.dependency-check.cve.20.path}/nvdcve-2.0-%d.xml.gz</cveUrl20Base> |
| 62 | + <mavenSettingsProxyId>${bt.owasp.dependency-check.proxy}</mavenSettingsProxyId> |
67 | 63 | <retireJsAnalyzerEnabled>${bt.owasp.dependency-check.enableRetireJs}</retireJsAnalyzerEnabled><!-- see https://github.com/jeremylong/DependencyCheck/issues/1467 before turning this on --> |
68 | 64 | <nspAnalyzerEnabled>${bt.owasp.dependency-check.enableNsp}</nspAnalyzerEnabled> |
69 | 65 | <nuspecAnalyzerEnabled>${bt.owasp.dependency-check.enableNuspec}</nuspecAnalyzerEnabled> |
|
207 | 203 | <groupId>org.owasp</groupId> |
208 | 204 | <artifactId>dependency-check-maven</artifactId> |
209 | 205 | <configuration> |
210 | | - <skip>${bt.owasp.dependency-check.enable}</skip> |
| 206 | + <skip>${bt.owasp.dependency-check.skip}</skip> |
211 | 207 | </configuration> |
212 | 208 | <executions> |
213 | 209 | <execution> |
|
382 | 378 | <configuration> |
383 | 379 | <skip>false</skip> |
384 | 380 | <failOnError>false</failOnError> |
385 | | - <cveUrl12Modified>${bt.owasp.dependency-check.cve.mirror}/${bt.owasp.dependency-check.cve.12.path}/nvdcve-Modified.xml.gz</cveUrl12Modified> |
386 | | - <cveUrl20Modified>${bt.owasp.dependency-check.cve.mirror}/${bt.owasp.dependency-check.cve.20.path}/nvdcve-2.0-Modified.xml.gz</cveUrl20Modified> |
387 | | - <cveUrl12Base>${bt.owasp.dependency-check.cve.mirror}/${bt.owasp.dependency-check.cve.12.path}/nvdcve-%d.xml.gz</cveUrl12Base> |
388 | | - <cveUrl20Base>${bt.owasp.dependency-check.cve.mirror}/${bt.owasp.dependency-check.cve.20.path}/nvdcve-2.0-%d.xml.gz</cveUrl20Base> |
389 | 381 | <retireJsAnalyzerEnabled>${bt.owasp.dependency-check.enableRetireJs}</retireJsAnalyzerEnabled><!-- see https://github.com/jeremylong/DependencyCheck/issues/1467 before turning this on --> |
390 | 382 | <nspAnalyzerEnabled>${bt.owasp.dependency-check.enableNsp}</nspAnalyzerEnabled> |
391 | 383 | <nuspecAnalyzerEnabled>${bt.owasp.dependency-check.enableNuspec}</nuspecAnalyzerEnabled> |
|
0 commit comments