Skip to content

Commit 452cfed

Browse files
author
Mark Reeves
committed
Update version of dependency-check-maven and change default config to use an (undefined) proxy instead of a DB mirror. This is a more reliable way of ensuring the database is up to date.
1 parent f73a9b7 commit 452cfed

File tree

1 file changed

+7
-15
lines changed

1 file changed

+7
-15
lines changed

qa-parent/pom.xml

Lines changed: 7 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -19,18 +19,17 @@
1919
<findbugs.skip>${wc.qa.skip}</findbugs.skip>
2020
<pmd.skip>${wc.qa.skip}</pmd.skip>
2121
<badges.skip>${wc.qa.skip}</badges.skip>
22+
2223
<javadoc.excluded.packages />
2324
<checkstyle.excludes />
2425

2526
<!--
2627
OWASP dependency vulnerability scanner.
2728
-->
28-
<bt.owasp.dependency-check.version>3.3.2</bt.owasp.dependency-check.version>
29-
<bt.owasp.dependency-check.enable>false</bt.owasp.dependency-check.enable>
30-
<!-- properties to allow for mirroring of CVE definitions -->
31-
<bt.owasp.dependency-check.cve.mirror>https://nvd.nist.gov/feeds/xml/cve</bt.owasp.dependency-check.cve.mirror>
32-
<bt.owasp.dependency-check.cve.12.path>1.2</bt.owasp.dependency-check.cve.12.path>
33-
<bt.owasp.dependency-check.cve.20.path>2.0</bt.owasp.dependency-check.cve.20.path>
29+
<bt.owasp.dependency-check.version>4.0.1</bt.owasp.dependency-check.version>
30+
<bt.owasp.dependency-check.skip>false</bt.owasp.dependency-check.skip>
31+
<!-- allow for proxy settings -->
32+
<bt.owasp.dependency-check.proxy></bt.owasp.dependency-check.proxy>
3433
<!-- Non java analysers are off by default because, well this is a Maven builder! -->
3534
<!-- nodejs nsp requires nsp on the path at scan time -->
3635
<bt.owasp.dependency-check.enableNsp>false</bt.owasp.dependency-check.enableNsp>
@@ -60,10 +59,7 @@
6059
<version>${bt.owasp.dependency-check.version}</version>
6160
<configuration>
6261
<failBuildOnAnyVulnerability>true</failBuildOnAnyVulnerability>
63-
<cveUrl12Modified>${bt.owasp.dependency-check.cve.mirror}/${bt.owasp.dependency-check.cve.12.path}/nvdcve-Modified.xml.gz</cveUrl12Modified>
64-
<cveUrl20Modified>${bt.owasp.dependency-check.cve.mirror}/${bt.owasp.dependency-check.cve.20.path}/nvdcve-2.0-Modified.xml.gz</cveUrl20Modified>
65-
<cveUrl12Base>${bt.owasp.dependency-check.cve.mirror}/${bt.owasp.dependency-check.cve.12.path}/nvdcve-%d.xml.gz</cveUrl12Base>
66-
<cveUrl20Base>${bt.owasp.dependency-check.cve.mirror}/${bt.owasp.dependency-check.cve.20.path}/nvdcve-2.0-%d.xml.gz</cveUrl20Base>
62+
<mavenSettingsProxyId>${bt.owasp.dependency-check.proxy}</mavenSettingsProxyId>
6763
<retireJsAnalyzerEnabled>${bt.owasp.dependency-check.enableRetireJs}</retireJsAnalyzerEnabled><!-- see https://github.com/jeremylong/DependencyCheck/issues/1467 before turning this on -->
6864
<nspAnalyzerEnabled>${bt.owasp.dependency-check.enableNsp}</nspAnalyzerEnabled>
6965
<nuspecAnalyzerEnabled>${bt.owasp.dependency-check.enableNuspec}</nuspecAnalyzerEnabled>
@@ -207,7 +203,7 @@
207203
<groupId>org.owasp</groupId>
208204
<artifactId>dependency-check-maven</artifactId>
209205
<configuration>
210-
<skip>${bt.owasp.dependency-check.enable}</skip>
206+
<skip>${bt.owasp.dependency-check.skip}</skip>
211207
</configuration>
212208
<executions>
213209
<execution>
@@ -382,10 +378,6 @@
382378
<configuration>
383379
<skip>false</skip>
384380
<failOnError>false</failOnError>
385-
<cveUrl12Modified>${bt.owasp.dependency-check.cve.mirror}/${bt.owasp.dependency-check.cve.12.path}/nvdcve-Modified.xml.gz</cveUrl12Modified>
386-
<cveUrl20Modified>${bt.owasp.dependency-check.cve.mirror}/${bt.owasp.dependency-check.cve.20.path}/nvdcve-2.0-Modified.xml.gz</cveUrl20Modified>
387-
<cveUrl12Base>${bt.owasp.dependency-check.cve.mirror}/${bt.owasp.dependency-check.cve.12.path}/nvdcve-%d.xml.gz</cveUrl12Base>
388-
<cveUrl20Base>${bt.owasp.dependency-check.cve.mirror}/${bt.owasp.dependency-check.cve.20.path}/nvdcve-2.0-%d.xml.gz</cveUrl20Base>
389381
<retireJsAnalyzerEnabled>${bt.owasp.dependency-check.enableRetireJs}</retireJsAnalyzerEnabled><!-- see https://github.com/jeremylong/DependencyCheck/issues/1467 before turning this on -->
390382
<nspAnalyzerEnabled>${bt.owasp.dependency-check.enableNsp}</nspAnalyzerEnabled>
391383
<nuspecAnalyzerEnabled>${bt.owasp.dependency-check.enableNuspec}</nuspecAnalyzerEnabled>

0 commit comments

Comments
 (0)