-
Notifications
You must be signed in to change notification settings - Fork 9
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Client as used by dependency-check-maven fails with NullPointerException #35
Comments
Seems like response changed and does not contain [
{
"description":"",
"reference":"https://ossindex.sonatype.org/component/pkg:maven/commons-lang/commons-lang@2.1?utm_source=dependency-check&utm_medium=integration&utm_content=7.1.0",
"vulnerabilities":[
],
"sonatypeOssiScore":0.0
}
] |
I tested that specific component and I did get a response with [
{
"coordinates": "pkg:maven/commons-lang/commons-lang@2.1",
"description": "",
"reference": "https://ossindex.sonatype.org/component/pkg:maven/commons-lang/commons-lang@2.1?utm_source=insomnia&utm_medium=integration&utm_content=2022.3.0",
"vulnerabilities": [],
"sonatypeOssiScore": 0.0
}
] |
Looks like now it depends if you provide credentials or not: jeremylong/DependencyCheck#4535 (comment) |
I didn't provide any credentials. Here's a curl --request POST \
--url https://ossindex.sonatype.org/api/v3/component-report \
--header 'Accept: application/vnd.ossindex.component-report.v1+json' \
--header 'Content-Type: application/vnd.ossindex.component-report-request.v1+json' \
--data '{
"coordinates":[
"pkg:maven/commons-lang/commons-lang@2.1"
]
}
' |
It's fixed now: jeremylong/DependencyCheck#4535 (comment) |
This problem no longer manifests. |
Thanks for letting us know. We have been chasing down a variety of edge cases causing problems, so I am glad one of them resolved your issue. Sorry for the inconvenience. |
There are many reports of suddenly failing builds using org.owasp:dependency-check-maven -plugin. That plugin uses this library to make requests to OSS Index.
Most reports seem to go along the lines of:
jeremylong/DependencyCheck#4538
The text was updated successfully, but these errors were encountered: