4.0.0 org.owasp dependency-check-parent 1.3.0 dependency-check-core jar Dependency-Check Core dependency-check-core is the engine and reporting tool used to identify and report if there are any known, publicly disclosed vulnerabilities in the scanned project's dependencies. The engine extracts meta-data from the dependencies and uses this to do fuzzy key-word matching against the Common Platfrom Enumeration (CPE), if any CPE identifiers are found the associated Common Vulnerability and Exposure (CVE) entries are added to the generated report. github-pages-site Deployment through GitHub's site deployment plugin ${basedir}/../target/site/${project.version}/dependency-check-core src/main/resources **/*.properties **/schema/*.xsd true ${basedir}/.. META-INF LICENSE.txt NOTICE.txt src/main/resources **/*.properties **/*.gif **/*.js **/schema/**/*.xsd **/schema/**/*.xml **/schema/**/*.bat **/schema/**/*.sh false src/test/resources **/*.properties true ${basedir}/../src/test/resources false ${basedir}/src/test/resources **/mysql-connector-java-5.1.27-bin.jar false org.apache.maven.plugins maven-dependency-plugin generate-resources copy-dependencies ${project.build.directory}/test-classes test org.apache.maven.plugins maven-jar-plugin jar package jar test-jar package test-jar org.codehaus.mojo cobertura-maven-plugin .*\$KEYS\.class .*\$Element\.class .*\$KEYS\.class .*\$Element\.class 85 85 false 85 85 85 85 .*\$.* 0 0 org.owasp.dependencycheck.data.cpe.Fields 0 0 org.owasp.dependencycheck.App 0 0 clean org.apache.maven.plugins maven-surefire-plugin data.directory ${project.build.directory}/data temp.directory ${project.build.directory}/temp **/*IntegrationTest.java **/*MySQLTest.java org.apache.maven.plugins maven-failsafe-plugin data.directory ${project.build.directory}/data temp.directory ${project.build.directory}/temp org.apache.maven.plugins maven-compiler-plugin -Xlint:unchecked org.apache.maven.plugins maven-project-info-reports-plugin ${reporting.project-info-reports-plugin.version} summary license help org.apache.maven.plugins maven-javadoc-plugin ${reporting.javadoc-plugin.version} false Copyright© 2012-15 Jeremy Long. All Rights Reserved. default javadoc org.codehaus.mojo versions-maven-plugin ${reporting.versions-plugin.version} dependency-updates-report plugin-updates-report org.apache.maven.plugins maven-jxr-plugin ${reporting.jxr-plugin.version} org.codehaus.mojo cobertura-maven-plugin ${reporting.cobertura-plugin.version} org.apache.maven.plugins maven-surefire-report-plugin ${reporting.surefire-report-plugin.version} report-only integration-tests report-only failsafe-report-only org.codehaus.mojo taglist-maven-plugin ${reporting.taglist-plugin.version} Todo Work todo ignoreCase FIXME exact org.apache.maven.plugins maven-checkstyle-plugin ${reporting.checkstyle-plugin.version} false false ${basedir}/../src/main/config/checkstyle-checks.xml ${basedir}/../src/main/config/checkstyle-header.txt ${basedir}/../src/main/config/checkstyle-suppressions.xml checkstyle.suppressions.file org.apache.maven.plugins maven-pmd-plugin ${reporting.pmd-plugin.version} 1.6 true utf-8 **/generated/*.java ../src/main/config/dcrules.xml /rulesets/java/basic.xml /rulesets/java/imports.xml /rulesets/java/unusedcode.xml org.codehaus.mojo findbugs-maven-plugin ${reporting.findbugs-plugin.version} com.google.code.findbugs annotations true org.slf4j slf4j-api ch.qos.logback logback-core test ch.qos.logback logback-classic test org.slf4j slf4j-ext compile org.owasp dependency-check-utils ${project.parent.version} org.apache.lucene lucene-test-framework test org.jmockit jmockit test org.apache.commons commons-compress commons-io commons-io commons-lang commons-lang org.apache.lucene lucene-core org.apache.lucene lucene-analyzers-common org.apache.lucene lucene-queryparser org.apache.velocity velocity com.h2database h2 org.jsoup jsoup jar com.sun.mail mailapi org.apache.maven.scm maven-scm-provider-cvsexe 1.8.1 test true org.springframework spring-webmvc 2.5.5 test true org.springframework.security spring-security-web 3.0.0.RELEASE test true com.hazelcast hazelcast 2.5 test true net.sf.ehcache ehcache-core 2.2.0 test true org.apache.struts struts2-core 2.1.2 test true org.mortbay.jetty jetty 6.1.0 test true org.apache.axis2 axis2-spring 1.4.1 test true org.apache.axis2 axis2-adb 1.4.1 test true org.apache.geronimo.daytrader daytrader-ear 2.1.7 ear test true org.glassfish.main.admingui war 4.0 war test true org.dojotoolkit dojo-war 1.3.0 war test true org.apache.openjpa openjpa 2.0.1 test true com.google.inject guice 3.0 test true org.springframework.retry spring-retry 1.1.0.RELEASE test true uk.ltd.getahead dwr 1.1.1 test true MySQL-IntegrationTest mysql org.apache.maven.plugins maven-surefire-plugin 2.18.1 true org.apache.maven.plugins maven-failsafe-plugin 2.18.1 data.driver_path ${basedir}/${driver_path} data.driver_name ${driver_name} data.connection_string ${connection_string} **/*MySQLTest.java integration-test verify False Positive Tests allTests org.apache.xmlgraphics batik-util 1.7 test true com.thoughtworks.xstream xstream 1.4.2 test true org.apache.ws.security wss4j 1.5.7 test true com.ganyo gcm-server 1.0.2 test true org.python jython-standalone 2.7-b1 test true org.jruby jruby-complete 1.7.4 test true org.jruby jruby 1.6.3 test true org.glassfish.jersey.core jersey-client 2.12 test true com.sun.jersey jersey-client 1.11.1 test true com.sun.faces jsf-impl 2.2.8-02 test true com.google.inject guice 3.0 test true org.opensaml xmltooling 1.4.1 test true org.springframework spring-webmvc 3.2.12.RELEASE test true com.google.code.gson gson 2.3.1 test true com.google.gerrit gerrit-extension-api 2.11 test true com.google.apis google-api-services-sqladmin v1beta4-rev5-1.20.0 test true com.google.gwt.google-apis gwt-gears 1.2.1 test true org.mozilla rhino 1.7.6 test true com.microsoft.windowsazure microsoft-azure-api-media 0.5.0 test true com.microsoft.windowsazure microsoft-azure-api-management-sql 0.5.0 test true com.microsoft.bingads microsoft.bingads 9.3.4 test true