added documentation for PR #636

This commit is contained in:
Jeremy Long
2017-01-08 08:55:29 -05:00
parent 86a85db12b
commit eac47800a3

View File

@@ -12,22 +12,23 @@ Configuration
==================== ====================
The following properties can be set on the dependency-check-maven plugin. The following properties can be set on the dependency-check-maven plugin.
Property | Description | Default Value Property | Description | Default Value
---------------------|------------------------------------|------------------ ----------------------------|------------------------------------|------------------
autoUpdate | Sets whether auto-updating of the NVD CVE/CPE data is enabled. It is not recommended that this be turned to false. | true autoUpdate | Sets whether auto-updating of the NVD CVE/CPE data is enabled. It is not recommended that this be turned to false. | true
cveValidForHours | Sets the number of hours to wait before checking for new updates from the NVD. | 4 cveValidForHours | Sets the number of hours to wait before checking for new updates from the NVD. | 4
failBuildOnCVSS | Specifies if the build should be failed if a CVSS score above a specified level is identified. The default is 11 which means since the CVSS scores are 0-10, by default the build will never fail. | 11 failBuildOnCVSS | Specifies if the build should be failed if a CVSS score above a specified level is identified. The default is 11 which means since the CVSS scores are 0-10, by default the build will never fail. | 11
failOnError | Whether the build should fail if there is an error executing the dependency-check analysis | true failBuildOnAnyVulnerability | Specific that if any vulnerability is identified, the build will fail. | false
format | The report format to be generated (HTML, XML, VULN, ALL). This configuration option has no affect if using this within the Site plugin unless the externalReport is set to true. | HTML failOnError | Whether the build should fail if there is an error executing the dependency-check analysis. | true
name | The name of the report in the site | dependency-check or dependency-check:aggregate format | The report format to be generated (HTML, XML, VULN, ALL). This configuration option has no affect if using this within the Site plugin unless the externalReport is set to true. | HTML
outputDirectory | The location to write the report(s). Note, this is not used if generating the report as part of a `mvn site` build | 'target' name | The name of the report in the site. | dependency-check or dependency-check:aggregate
skip | Skips the dependency-check analysis | false outputDirectory | The location to write the report(s). Note, this is not used if generating the report as part of a `mvn site` build. | 'target'
skipTestScope | Skip analysis for artifacts with Test Scope | true skip | Skips the dependency-check analysis. | false
skipProvidedScope | Skip analysis for artifacts with Provided Scope | false skipTestScope | Skip analysis for artifacts with Test Scope. | true
skipRuntimeScope | Skip analysis for artifacts with Runtime Scope | false skipProvidedScope | Skip analysis for artifacts with Provided Scope. | false
suppressionFile | The file path to the XML suppression file \- used to suppress [false positives](../general/suppression.html) |   skipRuntimeScope | Skip analysis for artifacts with Runtime Scope. | false
hintsFile | The file path to the XML hints file \- used to resolve [false negatives](../general/hints.html) |   suppressionFile | The file path to the XML suppression file \- used to suppress [false positives](../general/suppression.html). |  
enableExperimental | Enable the [experimental analyzers](../analyzers/index.html). If not enabled the experimental analyzers (see below) will not be loaded or used. | false hintsFile | The file path to the XML hints file \- used to resolve [false negatives](../general/hints.html). |  
enableExperimental | Enable the [experimental analyzers](../analyzers/index.html). If not enabled the experimental analyzers (see below) will not be loaded or used. | false
Analyzer Configuration Analyzer Configuration
==================== ====================