diff --git a/dependency-check-core/src/test/resources/dependencycheck.properties b/dependency-check-core/src/test/resources/dependencycheck.properties index fdaed3919..83b5430ca 100644 --- a/dependency-check-core/src/test/resources/dependencycheck.properties +++ b/dependency-check-core/src/test/resources/dependencycheck.properties @@ -16,9 +16,7 @@ engine.version.url=http://jeremylong.github.io/DependencyCheck/current.txt # will not be used. The data.directory will be resolved and if the connection string # below contains a %s then the data.directory will replace the %s. data.directory=[JAR]/data -# if the filename has a %s it will be replaced with the current expected version. For file -# based databases the below filename will be added to the data directory above and then -# if the connection string has a %s it will be replaced by the directory/filename path. +#if the filename has a %s it will be replaced with the current expected version data.file_name=dc.h2.db data.version=3.0 data.connection_string=jdbc:h2:file:%s;FILE_LOCK=SERIALIZED;AUTOCOMMIT=ON; @@ -39,19 +37,15 @@ data.password=DC-Pass1337! data.driver_name=org.h2.Driver data.driver_path= -# the path to the cpe xml file -#cpe.url=http://static.nvd.nist.gov/feeds/xml/cpe/dictionary/official-cpe-dictionary_v2.2.xml.gz -cpe.url=http://static.nvd.nist.gov/feeds/xml/cpe/dictionary/official-cpe-dictionary_v2.3.xml.gz -# the path to the cpe meta data file. -cpe.meta.url=http://static.nvd.nist.gov/feeds/xml/cpe/dictionary/official-cpe-dictionary_v2.2.meta - # the number of days that the modified nvd cve data holds data for. We don't need # to update the other files if we are within this timespan. Per NIST this file # holds 8 days of updates, we are using 7 just to be safe. cve.url.modified.validfordays=7 - -# the path to the modified nvd cve xml file. +# the number of hours to wait before checking if updates are available from the NVD. +cve.check.validforhours=0 +#first year to pull data from the URLs below cve.startyear=2014 +# the path to the modified nvd cve xml file. cve.url-1.2.modified=https://nvd.nist.gov/download/nvdcve-Modified.xml.gz #cve.url-1.2.modified=http://nvd.nist.gov/download/nvdcve-modified.xml cve.url-2.0.modified=https://nvd.nist.gov/feeds/xml/cve/nvdcve-2.0-Modified.xml.gz @@ -62,6 +56,14 @@ cve.url-2.0.base=https://nvd.nist.gov/feeds/xml/cve/nvdcve-2.0-%d.xml.gz #cve.url-2.0.base=http://static.nvd.nist.gov/feeds/xml/cve/nvdcve-2.0-%d.xml cpe.validfordays=30 +cpe.url=http://static.nvd.nist.gov/feeds/xml/cpe/dictionary/official-cpe-dictionary_v2.3.xml.gz + +# file type analyzer settings: +analyzer.archive.enabled=true +analyzer.jar.enabled=true +analyzer.nuspec.enabled=true +analyzer.assembly.enabled=true +analyzer.composer.lock.enabled=true # the URL for searching Nexus for SHA-1 hashes and whether it's enabled analyzer.nexus.enabled=true @@ -74,5 +76,27 @@ analyzer.nexus.proxy=true analyzer.central.enabled=true analyzer.central.url=http://search.maven.org/solrsearch/select +# the number of nested archives that will be searched. +archive.scan.depth=3 + # use HEAD (default) or GET as HTTP request method for query timestamp downloader.quick.query.timestamp=true + + +analyzer.jar.enabled=true +analyzer.archive.enabled=true +analyzer.node.package.enabled=true +analyzer.composer.lock.enabled=true +analyzer.python.distribution.enabled=true +analyzer.python.package.enabled=true +analyzer.ruby.gemspec.enabled=true +analyzer.autoconf.enabled=true +analyzer.cmake.enabled=true +analyzer.assembly.enabled=true +analyzer.nuspec.enabled=true +analyzer.openssl.enabled=true +analyzer.central.enabled=true +analyzer.nexus.enabled=false +#whether the nexus analyzer uses the proxy +analyzer.nexus.proxy=true +