4.0.0
org.owasp
dependency-check-parent
1.4.6-SNAPSHOT
pom
dependency-check-core
dependency-check-cli
dependency-check-ant
dependency-check-maven
dependency-check-utils
dependency-check-plugin
Dependency-Check
https://github.com/jeremylong/DependencyCheck.git
dependency-check is a utility that identifies project dependencies and checks if there are any known, publicly disclosed vulnerabilities. This tool can be part of the solution to the OWASP Top 10 2013: A9 - Using Components with Known Vulnerabilities.
2012
OWASP
http://www.owasp.org
Jeremy Long
jeremy.long@owasp.org
OWASP
https://www.owasp.org/
architect
developer
Steve Springett
Steve.Springett@owasp.org
OWASP
https://www.owasp.org/
developer
Will Stranathan
Will.Stranathan@owasp.org
OWASP
https://www.owasp.org/
developer
Dale Visser
dvisser@ida.org
Institute for Defense Analyses
https://www.ida.org/
developer
Hugo Costa
OWASP
https://www.owasp.org/
logo design
scm:git:git@github.com:jeremylong/DependencyCheck.git
https://github.com/jeremylong/DependencyCheck
scm:git:git@github.com:jeremylong/DependencyCheck.git
HEAD
github
https://github.com/jeremylong/DependencyCheck/issues
travis-ci
https://travis-ci.org/jeremylong/DependencyCheck
Dependency Check
dependency-check+subscribe@googlegroups.com
dependency-check+unsubscribe@googlegroups.com
dependency-check@googlegroups.com
https://groups.google.com/forum/?fromgroups#!forum/dependency-check
The Apache Software License, Version 2.0
http://www.apache.org/licenses/LICENSE-2.0.txt
UTF-8
UTF-8
github
4.7.2
1.9.8
1.7.23
1.1.9
3.0
2.17
2.7
3.6
ossrh
https://oss.sonatype.org/content/repositories/snapshots
ossrh
https://oss.sonatype.org/service/local/staging/deploy/maven2/
gh-pages
gh-pages
${project.build.directory}/site/${project.version}
3.1
org.codehaus.mojo
appassembler-maven-plugin
1.10
org.codehaus.mojo
cobertura-maven-plugin
2.7
org.apache.maven.plugins
maven-assembly-plugin
3.0.0
org.apache.maven.plugins
maven-clean-plugin
3.0.0
org.apache.maven.plugins
maven-compiler-plugin
3.6.1
org.apache.maven.plugins
maven-dependency-plugin
3.0.0
org.apache.maven.plugins
maven-enforcer-plugin
1.4.1
org.apache.maven.plugins
maven-deploy-plugin
2.8.2
org.apache.maven.plugins
maven-failsafe-plugin
2.19.1
org.apache.maven.plugins
maven-gpg-plugin
1.6
org.apache.maven.plugins
maven-install-plugin
2.5.2
org.apache.maven.plugins
maven-jar-plugin
3.0.2
org.apache.maven.plugins
maven-release-plugin
2.5.3
org.apache.maven.plugins
maven-resources-plugin
3.0.2
org.apache.maven.plugins
maven-site-plugin
3.6
org.apache.maven.plugins
maven-surefire-plugin
2.19.1
org.apache.maven.plugins
maven-antrun-plugin
1.8
org.apache.maven.plugins
maven-source-plugin
3.0.1
org.apache.maven.plugins
maven-javadoc-plugin
2.10.4
org.apache.maven.plugins
maven-compiler-plugin
-Xlint
true
1.7
1.7
org.apache.maven.plugins
maven-jar-plugin
true
**/checkstyle*
org.apache.maven.plugins
maven-failsafe-plugin
temp.directory
${project.build.directory}/temp
**/*IntegrationTest.java
integration-test
verify
org.apache.maven.plugins
maven-release-plugin
release
org.apache.maven.plugins
maven-resources-plugin
site-filtering-hack
pre-site
copy-resources
false
${project.build.directory}/site/
src/main/site-resources/
true
UTF-8
org.apache.maven.plugins
maven-site-plugin
org.apache.maven.doxia
doxia-module-markdown
1.7
true
false
org.apache.maven.plugins
maven-antrun-plugin
1.8
copy-xsd
compile
run
release
false
org.apache.maven.plugins
maven-enforcer-plugin
1.4.1
enforce-java
enforce
1.7.0
org.codehaus.mojo
animal-sniffer-maven-plugin
1.15
signature-check
verify
check
org.codehaus.mojo.signature
java16
1.1
org.apache.maven.plugins
maven-source-plugin
attach-sources
jar-no-fork
org.apache.maven.plugins
maven-javadoc-plugin
attach-javadocs
jar
org.apache.maven.plugins
maven-gpg-plugin
sign-artifacts
verify
sign
org.apache.maven.plugins
maven-dependency-plugin
2.10
org.apache.maven.plugins
maven-javadoc-plugin
2.10.4
false
Copyright© 2012-15 Jeremy Long. All Rights Reserved.
default
javadoc
org.apache.maven.plugins
maven-jxr-plugin
2.5
org.apache.maven.plugins
maven-project-info-reports-plugin
2.9
cim
summary
mailing-list
issue-tracking
modules
project-team
scm
license
org.apache.maven.plugins
maven-surefire-report-plugin
2.19.1
report-only
org.codehaus.mojo
cobertura-maven-plugin
${reporting.cobertura-plugin.version}
cobertura
org.codehaus.mojo
findbugs-maven-plugin
3.0.4
org.codehaus.mojo
taglist-maven-plugin
2.4
Todo Work
todo
ignoreCase
FIXME
exact
org.codehaus.mojo
versions-maven-plugin
2.3
dependency-updates-report
plugin-updates-report
joda-time
joda-time
1.6
com.google.code.findbugs
annotations
3.0.1u2
com.h2database
h2
1.3.176
commons-cli
commons-cli
1.3.1
commons-io
commons-io
2.5
org.apache.commons
commons-lang3
3.3.2
com.sun.mail
mailapi
1.5.6
ch.qos.logback
logback-core
${logback.version}
ch.qos.logback
logback-classic
${logback.version}
junit
junit
4.12
test
org.apache.commons
commons-compress
1.13
org.apache.ant
ant
${apache.ant.version}
org.apache.ant
ant-testutil
${apache.ant.version}
org.apache.lucene
lucene-analyzers-common
${apache.lucene.version}
org.apache.lucene
lucene-core
${apache.lucene.version}
org.apache.lucene
lucene-queryparser
${apache.lucene.version}
org.apache.lucene
lucene-test-framework
${apache.lucene.version}
org.apache.maven
maven-core
${maven.api.version}
org.apache.maven
maven-plugin-api
${maven.api.version}
org.apache.maven
maven-settings
${maven.api.version}
org.apache.maven.plugin-testing
maven-plugin-testing-harness
3.3.0
org.apache.maven.plugin-tools
maven-plugin-annotations
3.5
org.apache.maven.reporting
maven-reporting-api
3.0
commons-collections
commons-collections
3.2.2
org.apache.velocity
velocity
1.7
org.sonatype.plexus
plexus-sec-dispatcher
1.4
org.apache.maven.shared
maven-dependency-tree
2.2
org.glassfish
javax.json
1.0.4
org.hamcrest
hamcrest-core
1.3
test
org.jmockit
jmockit
1.26
test
org.jsoup
jsoup
1.10.2
org.slf4j
slf4j-api
${slf4j.version}
org.slf4j
slf4j-simple
${slf4j.version}
junit
junit
test
org.hamcrest
hamcrest-core
test
com.google.code.findbugs
annotations
provided