-
Notifications
You must be signed in to change notification settings - Fork 35
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Upgrade to OWASP DependencyCheck v9.0.1 #314
Comments
Note that version 9.0.1 had stability issues. The wrapped OWASP DependencyCheck should be v9.0.2 (the latest at the time of writing this). |
Or would be contribution PRs welcome for this upgrade? |
Following up on @mims-github, I made a PR for the update (see above) that works for me locally. This works by passing an NVD API key as a direct string or as a system property. For example:
In my view however this needs a bit more work to be complete. Specifically:
Although testing with a valid NVD API key now works and completes quite fast, I changed our project's vulnerability checking that would use this to use the ODC CLI version (after doing a |
@albuch May you clarify how you welcome contributions to make that awesome plugin ready for the future? |
@albuch |
@albuch Bump on the above requests/comments ☝️. I'm sure the community would be happy to take on maintenance of this plugin - I wonder if you might be willing to help transition it to the sbt organization if you are unable to or have no interest in continued maintenance? |
Would it be possible to foresee an upgrade to OWASP DependencyCheck v9.0.1? The main driver for this is the update for the new NVD API which now requires an API key. Using the previous API will be deprecated on December 15th 2023 (see here for details).
The text was updated successfully, but these errors were encountered: