Skip to content

Commit 042d56c

Browse files
committed
adjust dependency check plugin
1 parent f7ed1f6 commit 042d56c

File tree

2 files changed

+3
-1
lines changed

2 files changed

+3
-1
lines changed

.github/workflows/dependency-check.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ jobs:
3434
- name: Run org.owasp:dependency-check plugin
3535
id: dependency-check
3636
continue-on-error: true
37-
run: mvn -B verify -Pdependency-check -DskipTests
37+
run: mvn -B validate -Pdependency-check
3838
env:
3939
NVD_API_KEY: ${{ secrets.NVD_API_KEY }}
4040
- name: Upload report on failure

pom.xml

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -211,6 +211,7 @@
211211
<artifactId>dependency-check-maven</artifactId>
212212
<version>${dependency-check.version}</version>
213213
<configuration>
214+
<nvdValidForHours>24</nvdValidForHours>
214215
<failBuildOnCVSS>0</failBuildOnCVSS>
215216
<skipTestScope>true</skipTestScope>
216217
<detail>true</detail>
@@ -222,6 +223,7 @@
222223
<goals>
223224
<goal>check</goal>
224225
</goals>
226+
<phase>validate</phase>
225227
</execution>
226228
</executions>
227229
</plugin>

0 commit comments

Comments
 (0)