From 36f32850a103b7ce929c4a9e345d8eda0bbd461e Mon Sep 17 00:00:00 2001 From: John Leacox Date: Mon, 29 Jan 2018 09:24:50 -0600 Subject: [PATCH] Add dependency-check plugin (#80) --- dependency-check-suppressions.xml | 19 ++++++++++++++ pom.xml | 41 ++++++++++++++++++++++++++++++- 2 files changed, 59 insertions(+), 1 deletion(-) create mode 100644 dependency-check-suppressions.xml diff --git a/dependency-check-suppressions.xml b/dependency-check-suppressions.xml new file mode 100644 index 00000000..2a1b4bce --- /dev/null +++ b/dependency-check-suppressions.xml @@ -0,0 +1,19 @@ + + + + + + ^com\.github\.spullara\.mustache\.java:compiler:.*$ + CVE-2015-8862 + + + + + ^org\.tukaani:xz:.*$ + CVE-2015-4035 + + diff --git a/pom.xml b/pom.xml index 967aa39d..2ec1dedf 100644 --- a/pom.xml +++ b/pom.xml @@ -87,7 +87,7 @@ http://cerner.github.io/beadledom/${project.version} 1.8 - 2.11.7 + 2.11.12 2.11 1.17.4 2.9.2 @@ -462,6 +462,11 @@ stagemonitor-web ${stagemonitor.version} + + org.tukaani + xz + 1.8 + @@ -476,12 +481,30 @@ 2.12.0 test + + org.scala-lang + scalap + ${scala.version} + test + + + org.scala-lang + scala-compiler + ${scala.version} + test + org.scala-lang scala-library ${scala.version} test + + org.scala-lang + scala-reflect + ${scala.version} + test + org.scalacheck scalacheck_${scala.binary.version} @@ -656,6 +679,22 @@ + + org.owasp + dependency-check-maven + 3.1.0 + + true + dependency-check-suppressions.xml + + + + + aggregate + + + + com.github.spotbugs spotbugs-maven-plugin