From 3feccefee8508020972617ca6afdf196878b176e Mon Sep 17 00:00:00 2001 From: Jeremy Long Date: Fri, 3 May 2013 20:23:42 -0400 Subject: [PATCH] improved pom analysis Former-commit-id: 8da3f802dbf2c3d8cd63d07a1a0a5d984074f007 --- .../java/org/owasp/dependencycheck/analyzer/JarAnalyzer.java | 2 ++ 1 file changed, 2 insertions(+) diff --git a/src/main/java/org/owasp/dependencycheck/analyzer/JarAnalyzer.java b/src/main/java/org/owasp/dependencycheck/analyzer/JarAnalyzer.java index 4a0f92336..1f5f017d2 100644 --- a/src/main/java/org/owasp/dependencycheck/analyzer/JarAnalyzer.java +++ b/src/main/java/org/owasp/dependencycheck/analyzer/JarAnalyzer.java @@ -294,6 +294,7 @@ public class JarAnalyzer extends AbstractAnalyzer implements Analyzer { if (artifactid != null) { foundSomething = true; dependency.getProductEvidence().addEvidence("pom", "artifactid", artifactid, Evidence.Confidence.HIGH); + dependency.getVendorEvidence().addEvidence("pom", "artifactid", artifactid, Evidence.Confidence.LOW); } //version final String version = interpolateString(pom.getVersion(), pomProperties); @@ -313,6 +314,7 @@ public class JarAnalyzer extends AbstractAnalyzer implements Analyzer { if (pomName != null) { foundSomething = true; dependency.getProductEvidence().addEvidence("pom", "name", pomName, Evidence.Confidence.HIGH); + dependency.getVendorEvidence().addEvidence("pom", "name", pomName, Evidence.Confidence.HIGH); } //Description