-
Task
-
Resolution: Done
-
Major
-
None
-
None
-
-
Empty show more show less
-
Empty show more show less
-
2
- implement suppressions (false-positives), likely through plugin configuration in parent POMs
- provide a default suppressionFile in build-resources module
- also configure a project-specific location, so that projects can add more suppressions, without requiring parent pom re-release
- let's not bind the check goal to any phase yet
- for local run: mvn dependency-check:check, typically mostly relevant in webapps
- for CI runs: add a separate pipeline step to magnoliaPacksPipeline I believe, invoking the mvn command above
- add a report configuration for site-generation, using the aggregate goal on module parent (nice to have)
- estimate load on CI from vulnerability database updates
Initial research goal (fulfilled): estimate initial effort to discard false positives such as the one mentioned on the CVE scans research log.
=> suppressions may not be that hard, and upon second look amount of false-positives seems manageable.
Acceptance criteria
- clones
-
BUILD-373 Implement OWASP Dependency Check for selected webapps
- Closed