mirror of
https://github.com/ysoftdevs/DependencyCheck.git
synced 2026-01-14 15:53:36 +01:00
339 lines
15 KiB
XML
339 lines
15 KiB
XML
<!--
|
||
This file is part of Dependency-Check.
|
||
|
||
Licensed under the Apache License, Version 2.0 (the "License");
|
||
you may not use this file except in compliance with the License.
|
||
You may obtain a copy of the License at
|
||
|
||
http://www.apache.org/licenses/LICENSE-2.0
|
||
|
||
Unless required by applicable law or agreed to in writing, software
|
||
distributed under the License is distributed on an "AS IS" BASIS,
|
||
WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
||
See the License for the specific language governing permissions and
|
||
limitations under the License.
|
||
|
||
Copyright (c) 2012 - Jeremy Long. All Rights Reserved.
|
||
-->
|
||
<project xmlns="http://maven.apache.org/POM/4.0.0" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/xsd/maven-4.0.0.xsd">
|
||
<modelVersion>4.0.0</modelVersion>
|
||
<parent>
|
||
<groupId>org.owasp</groupId>
|
||
<artifactId>dependency-check-parent</artifactId>
|
||
<version>1.3.1-SNAPSHOT</version>
|
||
</parent>
|
||
|
||
<artifactId>dependency-check-cli</artifactId>
|
||
<packaging>jar</packaging>
|
||
|
||
<name>Dependency-Check Command Line</name>
|
||
<description>dependency-check-cli is an command line tool that uses dependency-check-core to detect publicly disclosed vulnerabilities associated with the scanned project dependencies. The tool will generate a report listing the dependency, any identified Common Platform Enumeration (CPE) identifiers, and the associated Common Vulnerability and Exposure (CVE) entries.</description>
|
||
<!-- begin copy from http://minds.coremedia.com/2012/09/11/problem-solved-deploy-multi-module-maven-project-site-as-github-pages/ -->
|
||
<distributionManagement>
|
||
<site>
|
||
<id>github-pages-site</id>
|
||
<name>Deployment through GitHub's site deployment plugin</name>
|
||
<url>${basedir}/../target/site/${project.version}/dependency-check-cli</url>
|
||
</site>
|
||
</distributionManagement>
|
||
<!-- end copy -->
|
||
<build>
|
||
<finalName>dependency-check-${project.version}</finalName>
|
||
<resources>
|
||
<resource>
|
||
<directory>src/main/resources</directory>
|
||
<includes>
|
||
<include>**/*.properties</include>
|
||
<include>logback.xml</include>
|
||
</includes>
|
||
<filtering>true</filtering>
|
||
</resource>
|
||
<resource>
|
||
<directory>${basedir}</directory>
|
||
<targetPath>META-INF</targetPath>
|
||
<includes>
|
||
<include>LICENSE.txt</include>
|
||
<include>NOTICE.txt</include>
|
||
</includes>
|
||
</resource>
|
||
</resources>
|
||
<plugins>
|
||
<plugin>
|
||
<groupId>org.apache.maven.plugins</groupId>
|
||
<artifactId>maven-jar-plugin</artifactId>
|
||
<configuration>
|
||
<archive>
|
||
<manifest>
|
||
<mainClass>org.owasp.dependencycheck.App</mainClass>
|
||
</manifest>
|
||
</archive>
|
||
</configuration>
|
||
</plugin>
|
||
<plugin>
|
||
<groupId>org.codehaus.mojo</groupId>
|
||
<artifactId>cobertura-maven-plugin</artifactId>
|
||
<configuration>
|
||
<!--instrumentation>
|
||
<ignoreTrivial>true</ignoreTrivial>
|
||
</instrumentation-->
|
||
<check>
|
||
<branchRate>85</branchRate>
|
||
<lineRate>85</lineRate>
|
||
<haltOnFailure>false</haltOnFailure>
|
||
<totalBranchRate>85</totalBranchRate>
|
||
<totalLineRate>85</totalLineRate>
|
||
<packageLineRate>85</packageLineRate>
|
||
<packageBranchRate>85</packageBranchRate>
|
||
<regexes>
|
||
<regex>
|
||
<pattern>.*\$.*</pattern>
|
||
<branchRate>0</branchRate>
|
||
<lineRate>0</lineRate>
|
||
</regex>
|
||
<regex>
|
||
<pattern>org.owasp.dependencycheck.App</pattern>
|
||
<branchRate>0</branchRate>
|
||
<lineRate>0</lineRate>
|
||
</regex>
|
||
</regexes>
|
||
</check>
|
||
</configuration>
|
||
<executions>
|
||
<execution>
|
||
<goals>
|
||
<goal>clean</goal>
|
||
</goals>
|
||
</execution>
|
||
</executions>
|
||
</plugin>
|
||
<plugin>
|
||
<groupId>org.apache.maven.plugins</groupId>
|
||
<artifactId>maven-surefire-plugin</artifactId>
|
||
<configuration>
|
||
<systemProperties>
|
||
<property>
|
||
<name>cpe</name>
|
||
<value>data/cpe</value>
|
||
<workingDirectory>target</workingDirectory>
|
||
</property>
|
||
<property>
|
||
<name>cve</name>
|
||
<value>data/cpe</value>
|
||
<workingDirectory>target</workingDirectory>
|
||
</property>
|
||
</systemProperties>
|
||
</configuration>
|
||
</plugin>
|
||
<plugin>
|
||
<groupId>org.apache.maven.plugins</groupId>
|
||
<artifactId>maven-compiler-plugin</artifactId>
|
||
</plugin>
|
||
<plugin>
|
||
<groupId>org.codehaus.mojo</groupId>
|
||
<artifactId>appassembler-maven-plugin</artifactId>
|
||
<configuration>
|
||
<programs>
|
||
<program>
|
||
<mainClass>org.owasp.dependencycheck.App</mainClass>
|
||
<id>dependency-check</id>
|
||
</program>
|
||
</programs>
|
||
<assembleDirectory>${project.build.directory}/release</assembleDirectory>
|
||
<licenseHeaderFile>${basedir}/src/main/assembly/license.txt</licenseHeaderFile>
|
||
<binFileExtensions>
|
||
<unix>.sh</unix>
|
||
</binFileExtensions>
|
||
</configuration>
|
||
<executions>
|
||
<execution>
|
||
<id>assemble</id>
|
||
<goals>
|
||
<goal>assemble</goal>
|
||
</goals>
|
||
</execution>
|
||
</executions>
|
||
</plugin>
|
||
<plugin>
|
||
<groupId>org.apache.maven.plugins</groupId>
|
||
<artifactId>maven-assembly-plugin</artifactId>
|
||
<configuration>
|
||
<attach>false</attach> <!-- don't install/deploy this archive -->
|
||
</configuration>
|
||
<executions>
|
||
<execution>
|
||
<id>create-distribution</id>
|
||
<phase>package</phase>
|
||
<goals>
|
||
<goal>single</goal>
|
||
</goals>
|
||
<configuration>
|
||
<descriptors>
|
||
<descriptor>src/main/assembly/release.xml</descriptor>
|
||
</descriptors>
|
||
</configuration>
|
||
</execution>
|
||
</executions>
|
||
</plugin>
|
||
</plugins>
|
||
</build>
|
||
<reporting>
|
||
<plugins>
|
||
<plugin>
|
||
<groupId>org.apache.maven.plugins</groupId>
|
||
<artifactId>maven-project-info-reports-plugin</artifactId>
|
||
<version>${reporting.project-info-reports-plugin.version}</version>
|
||
<reportSets>
|
||
<reportSet>
|
||
<reports>
|
||
<report>summary</report>
|
||
<report>license</report>
|
||
<report>help</report>
|
||
</reports>
|
||
</reportSet>
|
||
</reportSets>
|
||
</plugin>
|
||
<plugin>
|
||
<groupId>org.apache.maven.plugins</groupId>
|
||
<artifactId>maven-javadoc-plugin</artifactId>
|
||
<version>${reporting.javadoc-plugin.version}</version>
|
||
<configuration>
|
||
<failOnError>false</failOnError>
|
||
<bottom>Copyright<EFBFBD> 2012-15 Jeremy Long. All Rights Reserved.</bottom>
|
||
</configuration>
|
||
<reportSets>
|
||
<reportSet>
|
||
<id>default</id>
|
||
<reports>
|
||
<report>javadoc</report>
|
||
</reports>
|
||
</reportSet>
|
||
</reportSets>
|
||
</plugin>
|
||
<plugin>
|
||
<groupId>org.codehaus.mojo</groupId>
|
||
<artifactId>versions-maven-plugin</artifactId>
|
||
<version>${reporting.versions-plugin.version}</version>
|
||
<reportSets>
|
||
<reportSet>
|
||
<reports>
|
||
<report>dependency-updates-report</report>
|
||
<report>plugin-updates-report</report>
|
||
</reports>
|
||
</reportSet>
|
||
</reportSets>
|
||
</plugin>
|
||
<plugin>
|
||
<groupId>org.apache.maven.plugins</groupId>
|
||
<artifactId>maven-jxr-plugin</artifactId>
|
||
<version>${reporting.jxr-plugin.version}</version>
|
||
</plugin>
|
||
<plugin>
|
||
<groupId>org.codehaus.mojo</groupId>
|
||
<artifactId>cobertura-maven-plugin</artifactId>
|
||
<version>${reporting.cobertura-plugin.version}</version>
|
||
</plugin>
|
||
<plugin>
|
||
<groupId>org.apache.maven.plugins</groupId>
|
||
<artifactId>maven-surefire-report-plugin</artifactId>
|
||
<version>${reporting.surefire-report-plugin.version}</version>
|
||
<reportSets>
|
||
<reportSet>
|
||
<reports>
|
||
<report>report-only</report>
|
||
</reports>
|
||
</reportSet>
|
||
</reportSets>
|
||
</plugin>
|
||
<plugin>
|
||
<groupId>org.codehaus.mojo</groupId>
|
||
<artifactId>taglist-maven-plugin</artifactId>
|
||
<version>${reporting.taglist-plugin.version}</version>
|
||
<configuration>
|
||
<tagListOptions>
|
||
<tagClasses>
|
||
<tagClass>
|
||
<displayName>Todo Work</displayName>
|
||
<tags>
|
||
<tag>
|
||
<matchString>todo</matchString>
|
||
<matchType>ignoreCase</matchType>
|
||
</tag>
|
||
<tag>
|
||
<matchString>FIXME</matchString>
|
||
<matchType>exact</matchType>
|
||
</tag>
|
||
</tags>
|
||
</tagClass>
|
||
</tagClasses>
|
||
</tagListOptions>
|
||
</configuration>
|
||
</plugin>
|
||
<plugin>
|
||
<groupId>org.apache.maven.plugins</groupId>
|
||
<artifactId>maven-checkstyle-plugin</artifactId>
|
||
<version>${reporting.checkstyle-plugin.version}</version>
|
||
<configuration>
|
||
<enableRulesSummary>false</enableRulesSummary>
|
||
<enableFilesSummary>false</enableFilesSummary>
|
||
<configLocation>${basedir}/../src/main/config/checkstyle-checks.xml</configLocation>
|
||
<headerLocation>${basedir}/../src/main/config/checkstyle-header.txt</headerLocation>
|
||
<suppressionsLocation>${basedir}/../src/main/config/checkstyle-suppressions.xml</suppressionsLocation>
|
||
<suppressionsFileExpression>checkstyle.suppressions.file</suppressionsFileExpression>
|
||
</configuration>
|
||
</plugin>
|
||
<plugin>
|
||
<groupId>org.apache.maven.plugins</groupId>
|
||
<artifactId>maven-pmd-plugin</artifactId>
|
||
<version>${reporting.pmd-plugin.version}</version>
|
||
<configuration>
|
||
<targetJdk>1.6</targetJdk>
|
||
<linkXref>true</linkXref>
|
||
<sourceEncoding>utf-8</sourceEncoding>
|
||
<excludes>
|
||
<exclude>**/generated/*.java</exclude>
|
||
</excludes>
|
||
<rulesets>
|
||
<ruleset>../src/main/config/dcrules.xml</ruleset>
|
||
<ruleset>/rulesets/java/basic.xml</ruleset>
|
||
<ruleset>/rulesets/java/imports.xml</ruleset>
|
||
<ruleset>/rulesets/java/unusedcode.xml</ruleset>
|
||
</rulesets>
|
||
</configuration>
|
||
</plugin>
|
||
<plugin>
|
||
<groupId>org.codehaus.mojo</groupId>
|
||
<artifactId>findbugs-maven-plugin</artifactId>
|
||
<version>${reporting.findbugs-plugin.version}</version>
|
||
</plugin>
|
||
</plugins>
|
||
</reporting>
|
||
<dependencies>
|
||
<dependency>
|
||
<groupId>commons-cli</groupId>
|
||
<artifactId>commons-cli</artifactId>
|
||
</dependency>
|
||
<dependency>
|
||
<groupId>org.owasp</groupId>
|
||
<artifactId>dependency-check-core</artifactId>
|
||
<version>${project.parent.version}</version>
|
||
</dependency>
|
||
<dependency>
|
||
<groupId>org.owasp</groupId>
|
||
<artifactId>dependency-check-utils</artifactId>
|
||
<version>${project.parent.version}</version>
|
||
</dependency>
|
||
<dependency>
|
||
<groupId>org.slf4j</groupId>
|
||
<artifactId>slf4j-api</artifactId>
|
||
</dependency>
|
||
<dependency>
|
||
<groupId>ch.qos.logback</groupId>
|
||
<artifactId>logback-core</artifactId>
|
||
</dependency>
|
||
<dependency>
|
||
<groupId>ch.qos.logback</groupId>
|
||
<artifactId>logback-classic</artifactId>
|
||
</dependency>
|
||
</dependencies>
|
||
</project>
|