apache / apache/maven

[MNG-6487] Adding CVE Checks via OWASP

Open
#7,384 2 comments 0 reactions 0 assignees View on GitHub
enhancement priority:minor
Dominant language
Java
Stars
5.3k
Forks
3.1k
Avg merge
20h 40m
Merged PRs (30d)
275

Description

**[Karl Heinz Marbaise](https://issues.apache.org/jira/secure/ViewProfile.jspa?name=khmarbaise)** opened **[MNG-6487](https://issues.apache.org/jira/browse/MNG-6487?redirect=false)** and commented

`mvn compile org.sonatype.ossindex.maven:ossindex-maven-plugin:audit`

Result on all modules is a CVSS-score threshold: 0.0

In contrast: IIRC the owasp dependency plugin gave several false positives.

We should consider to add this to the maven-parent to get early notifications on known CVEs.

---

**Issue Links:**
- [MPOM-210](https://issues.apache.org/jira/browse/MPOM-210) Adding CVE Checks via OWASP
(_**"is blocked by"**_)

**Remote Links:**
- [GitHub Pull Request #858
](https://github.com/apache/maven/pull/858)

0 votes, 6 watchers

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.