[MNG-6487] Adding CVE Checks via OWASP
- Dominant language
- Java
- Stars
- 5.3k
- Forks
- 3.1k
- Avg merge
- 20h 40m
- Merged PRs (30d)
- 275
Description
**[Karl Heinz Marbaise](https://issues.apache.org/jira/secure/ViewProfile.jspa?name=khmarbaise)** opened **[MNG-6487](https://issues.apache.org/jira/browse/MNG-6487?redirect=false)** and commented
`mvn compile org.sonatype.ossindex.maven:ossindex-maven-plugin:audit`
Result on all modules is a CVSS-score threshold: 0.0
In contrast: IIRC the owasp dependency plugin gave several false positives.
We should consider to add this to the maven-parent to get early notifications on known CVEs.
---
**Issue Links:**
- [MPOM-210](https://issues.apache.org/jira/browse/MPOM-210) Adding CVE Checks via OWASP
(_**"is blocked by"**_)
**Remote Links:**
- [GitHub Pull Request #858
](https://github.com/apache/maven/pull/858)
0 votes, 6 watchers
Contributor guide
Assessment
This issue has not been assessed yet.