diff --git a/src/main/java/org/owasp/dependencycheck/App.java b/src/main/java/org/owasp/dependencycheck/App.java index d60623dec..e48f4e7a0 100644 --- a/src/main/java/org/owasp/dependencycheck/App.java +++ b/src/main/java/org/owasp/dependencycheck/App.java @@ -1,7 +1,7 @@ /* - ** This file is part of Dependency-Check. + * This file is part of Dependency-Check. * - ** Dependency-Check is free software: you can redistribute it and/or modify it + * Dependency-Check is free software: you can redistribute it and/or modify it * under the terms of the GNU General Public License as published by the Free * Software Foundation, either version 3 of the License, or (at your option) any * later version. diff --git a/src/main/java/org/owasp/dependencycheck/analyzer/DependencyBundlingAnalyzer.java b/src/main/java/org/owasp/dependencycheck/analyzer/DependencyBundlingAnalyzer.java index 37cdc3503..469f147bb 100644 --- a/src/main/java/org/owasp/dependencycheck/analyzer/DependencyBundlingAnalyzer.java +++ b/src/main/java/org/owasp/dependencycheck/analyzer/DependencyBundlingAnalyzer.java @@ -161,19 +161,19 @@ public class DependencyBundlingAnalyzer extends AbstractAnalyzer implements Anal * @return a string representing the base path. */ private String getBaseRepoPath(final String path) { - int pos = path.indexOf("repository") + 10; - if (pos<0) { + int pos = path.indexOf("repository" + File.separator) + 11; + if (pos < 0) { return path; } int tmp = path.indexOf(File.separator, pos); - if (tmp<=0) { + if (tmp <= 0) { return path; } - if (tmp>0) { + if (tmp > 0) { pos = tmp + 1; } tmp = path.indexOf(File.separator, pos); - if (tmp>0) { + if (tmp > 0) { pos = tmp + 1; } return path.substring(0, pos); diff --git a/src/main/java/org/owasp/dependencycheck/analyzer/JarAnalyzer.java b/src/main/java/org/owasp/dependencycheck/analyzer/JarAnalyzer.java index daf0296bf..a53c5bc10 100644 --- a/src/main/java/org/owasp/dependencycheck/analyzer/JarAnalyzer.java +++ b/src/main/java/org/owasp/dependencycheck/analyzer/JarAnalyzer.java @@ -376,9 +376,7 @@ public class JarAnalyzer extends AbstractAnalyzer implements Analyzer { JarFile jar = null; try { jar = new JarFile(dependency.getActualFilePath()); - final java.util.Enumeration en = jar.entries(); - final HashMap level0 = new HashMap(); final HashMap level1 = new HashMap(); final HashMap level2 = new HashMap(); @@ -438,7 +436,6 @@ public class JarAnalyzer extends AbstractAnalyzer implements Analyzer { } final EvidenceCollection vendor = dependency.getVendorEvidence(); final EvidenceCollection product = dependency.getProductEvidence(); - for (String s : level0.keySet()) { if (!"org".equals(s) && !"com".equals(s)) { vendor.addWeighting(s);