Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
1242 commits
Select commit Hold shift + click to select a range
fd48db4
build(deps): bump com.google.guava:guava from 33.4.6-jre to 33.4.7-jr…
dependabot[bot] Apr 9, 2025
9640164
feat: #7510 Display a dedicated message when receiving an HTTP 403 (#…
aikebah Apr 9, 2025
a6ad37e
build(deps): bump org.apache.commons:commons-text from 1.13.0 to 1.13…
dependabot[bot] Apr 11, 2025
cf5fd44
fix: remove duplicate dependency declaration
nhumblot Apr 11, 2025
044af60
fix: #7591 tell the stage goal has to be used
nhumblot Apr 11, 2025
1353adf
fix: #7591 tell the stage goal has to be used (#7594)
nhumblot Apr 12, 2025
00e5be0
fix: remove duplicate dependency declaration (#7593)
aikebah Apr 13, 2025
956cecc
chore: remove the unused URLConnectionFactory (#7595)
aikebah Apr 14, 2025
9c66722
build(deps): bump commons-io:commons-io from 2.18.0 to 2.19.0 (#7597)
dependabot[bot] Apr 14, 2025
3b501ad
chore: Add a serialVersionUID to serializable classes that don't have…
aikebah Apr 14, 2025
3529fbe
build(deps): bump com.google.guava:guava from 33.4.7-jre to 33.4.8-jr…
dependabot[bot] Apr 15, 2025
0ea4fc3
build(deps): bump actions/setup-node from 4.3.0 to 4.4.0 (#7599)
dependabot[bot] Apr 15, 2025
f653a81
feat: #7610 add a reference to NVD mirroring in getting started docum…
nhumblot Apr 19, 2025
c9392b4
build(deps): bump org.apache.maven.shared:file-management from 3.1.0 …
dependabot[bot] Apr 19, 2025
e3da14c
build(deps): bump org.apache.commons:commons-collections4
dependabot[bot] Apr 23, 2025
273d075
build(deps): bump org.apache.commons:commons-collections4 from 4.4 to…
aikebah Apr 24, 2025
718a08a
build(deps): bump jackson.version from 2.18.3 to 2.19.0
dependabot[bot] Apr 25, 2025
e79ebfc
build(deps): bump org.apache.httpcomponents.client5:httpclient5
dependabot[bot] Apr 25, 2025
333c896
build(deps): bump org.apache.httpcomponents.client5:httpclient5 from …
aikebah Apr 26, 2025
3ac1522
build(deps): bump jackson.version from 2.18.3 to 2.19.0 (#7616)
aikebah Apr 26, 2025
db0bda7
build(deps): bump org.codehaus.gmavenplus:gmavenplus-plugin
dependabot[bot] Apr 29, 2025
142420a
chore: add publish suppressions workflow (#7620)
jeremylong Apr 29, 2025
f821b99
chore: fix publish suppressions workflow (#7621)
jeremylong Apr 29, 2025
6436692
chore: fix publish suppressions workflow (#7622)
jeremylong Apr 29, 2025
e7fb7dc
Migrate tests to JUnit5 (parent)
strangelookingnerd Apr 29, 2025
07f8061
Migrate tests to JUnit5 (ant)
strangelookingnerd Apr 29, 2025
b4a8eaf
Migrate tests to JUnit5 (archetype)
strangelookingnerd Apr 29, 2025
2408e96
Migrate tests to JUnit5 (cli)
strangelookingnerd Apr 29, 2025
0312530
Migrate tests to JUnit5 (core)
strangelookingnerd Apr 29, 2025
6c56761
Migrate tests to JUnit5 (maven)
strangelookingnerd Apr 29, 2025
2463f9c
Migrate tests to JUnit5 (utils)
strangelookingnerd Apr 29, 2025
fea5a73
Migrate tests to JUnit5 (fixes)
strangelookingnerd Apr 29, 2025
b2ad7b3
build(deps): bump org.jsoup:jsoup from 1.19.1 to 1.20.1
dependabot[bot] Apr 30, 2025
c96e318
Migrate tests to JUnit5 (fixes)
strangelookingnerd Apr 29, 2025
fc0d37e
build(deps): bump org.jsoup:jsoup from 1.19.1 to 1.20.1 (#7624)
aikebah Apr 30, 2025
ecc6def
build(deps): bump org.codehaus.gmavenplus:gmavenplus-plugin from 4.1.…
aikebah Apr 30, 2025
df8ff76
Merge branch 'main' into migrate_to_junit5
strangelookingnerd Apr 30, 2025
945208d
Migrate tests to JUnit5 (assertThrows)
strangelookingnerd Apr 30, 2025
dc79635
Apply suggestions from code review
strangelookingnerd Apr 30, 2025
5659da9
test: Migrate tests to JUnit5 (#7623)
aikebah Apr 30, 2025
e462a23
build(deps): bump org.semver4j:semver4j from 5.6.0 to 5.7.0 (#7626)
dependabot[bot] May 2, 2025
a487391
fix: Resolve various WCAG accessibility / css issues in the HTML repo…
aikebah May 5, 2025
06cce45
build(deps-dev): bump io.netty:netty-codec-http
dependabot[bot] May 7, 2025
c20ecfd
build(deps): bump golang from 1.24.2-alpine to 1.24.3-alpine (#7636)
dependabot[bot] May 7, 2025
37f296b
build(deps-dev): bump io.netty:netty-codec-http from 4.2.0.Final to 4…
aikebah May 7, 2025
82bd063
feat: Allow configuring OSS Index user/pw directly (#7640)
marcelstoer May 14, 2025
89c4ca9
build(deps): bump mockito.version from 5.17.0 to 5.18.0
dependabot[bot] May 21, 2025
f99a590
build(deps): bump mockito.version from 5.17.0 to 5.18.0 (#7648)
aikebah May 21, 2025
aa0ae51
fix(cli): Patch generated Windows shell script for JAVACMD installs w…
chadlwilson May 22, 2025
0357b52
docs: Fix vulnz links (#7647)
chadlwilson May 23, 2025
5346f80
build(deps): bump org.apache.httpcomponents.client5:httpclient5 from …
dependabot[bot] May 24, 2025
3ab1cbb
fix: update CPE pattern to remove FP (#7684)
jeremylong May 27, 2025
8e74247
build(deps): bump org.postgresql:postgresql from 42.7.5 to 42.7.6 (#7…
dependabot[bot] May 29, 2025
dce88bb
docs: Make `Vulnerability Sources` in `Related Work` clearer (#7691)
JackPGreen May 31, 2025
991397c
refactor: improve logs and add exception stack trace for YarnAuditAna…
nhumblot May 31, 2025
4ff0e58
fix: Simplify PHP framework suppression for Composer (#7693)
sigv May 31, 2025
c479c3c
build(deps): bump junit.version from 5.12.2 to 5.13.0
dependabot[bot] Jun 2, 2025
2b72dd1
build(deps): bump org.apache.maven.plugins:maven-clean-plugin
dependabot[bot] Jun 2, 2025
011d4ad
fix(fp): fixes nuget FP on Redis (#7702)
jeremylong Jun 2, 2025
f76eb34
build(deps): bump org.apache.maven.plugins:maven-clean-plugin from 3.…
aikebah Jun 2, 2025
e49d28d
build(deps): bump junit.version from 5.12.2 to 5.13.0 (#7696)
aikebah Jun 2, 2025
0e0cd58
fix: remove vulnerable transitive dependency - beanutils (#7705)
jeremylong Jun 4, 2025
6296163
fix(fp): remove iicu4j FP
jeremylong Jun 4, 2025
f551343
fix(fp): remove iicu4j FP (#7707)
nhumblot Jun 5, 2025
116fdab
build(deps): bump golang from 1.24.3-alpine to 1.24.4-alpine
dependabot[bot] Jun 6, 2025
4cde0d7
build(deps-dev): bump io.netty:netty-codec-http
dependabot[bot] Jun 6, 2025
a6abd65
build(deps): bump golang from 1.24.3-alpine to 1.24.4-alpine (#7710)
nhumblot Jun 6, 2025
9c1312a
Merge branch 'main' into dependabot/maven/io.netty-netty-codec-http-4…
nhumblot Jun 6, 2025
ce126c7
build(deps-dev): bump io.netty:netty-codec-http from 4.2.1.Final to 4…
nhumblot Jun 6, 2025
624c3ca
docs: release 12.1.2
jeremylong Jun 7, 2025
4744206
build: prepare release v12.1.2
jeremylong Jun 7, 2025
7f9b258
build: prepare for next development iteration
jeremylong Jun 7, 2025
cc18626
build: Release 12.1.2 (#7714)
jeremylong Jun 7, 2025
7fdad34
build(deps): bump org.semver4j:semver4j from 5.7.0 to 5.7.1
dependabot[bot] Jun 9, 2025
a58584f
build(deps): bump junit.version from 5.13.0 to 5.13.1 (#7719)
dependabot[bot] Jun 9, 2025
2b548f8
build(deps): bump org.semver4j:semver4j from 5.7.0 to 5.7.1 (#7718)
nhumblot Jun 10, 2025
f9e6b79
fix: correct regex matches introduced in 12.1.2 (#7726)
jeremylong Jun 10, 2025
84d3436
docs: release 12.1.3
jeremylong Jun 10, 2025
dfd437e
build: prepare release v12.1.3
jeremylong Jun 10, 2025
720bc1c
build: prepare for next development iteration
jeremylong Jun 10, 2025
ffa9e5f
build: release 12.1.3 (#7729)
jeremylong Jun 10, 2025
3544e91
build(deps): bump org.postgresql:postgresql from 42.7.6 to 42.7.7 (#7…
dependabot[bot] Jun 12, 2025
36aa3ff
fix(fp): resolves several false positives related to CVE-2021-41033 (…
jeremylong Jun 12, 2025
37cdb97
build(deps): bump jackson.version from 2.19.0 to 2.19.1 (#7743)
dependabot[bot] Jun 16, 2025
0a4931b
build(deps): bump org.jsoup:jsoup from 1.20.1 to 1.21.1
dependabot[bot] Jun 24, 2025
b1cd3a2
build(deps): bump org.semver4j:semver4j from 5.7.1 to 5.8.0
dependabot[bot] Jun 24, 2025
3bad345
build(deps): bump junit.version from 5.13.1 to 5.13.2
dependabot[bot] Jun 25, 2025
1a5202e
docs: fix minor typos in false positive issue template (#7763)
samumbach Jun 26, 2025
a7cc092
chore: add marcelstoer to the FP approvers list (#7771)
marcelstoer Jun 26, 2025
7cdf6c1
build: remove weekly coverity scan (#7770)
jeremylong Jun 26, 2025
f993c15
build(deps): bump junit.version from 5.13.1 to 5.13.2 (#7767)
aikebah Jun 26, 2025
9510fce
build(deps): bump org.semver4j:semver4j from 5.7.1 to 5.8.0 (#7765)
aikebah Jun 26, 2025
b0af16b
build(deps): bump org.jsoup:jsoup from 1.20.1 to 1.21.1 (#7764)
aikebah Jun 26, 2025
b43f73b
build(deps): bump com.github.spotbugs:spotbugs-maven-plugin from 4.9.…
dependabot[bot] Jun 27, 2025
5fa111d
docs: copyright year (#7773)
jeremylong Jun 27, 2025
0734bb4
build(deps): bump com.github.spotbugs:spotbugs-maven-plugin
dependabot[bot] Jun 30, 2025
829a68b
build(deps): bump com.github.spotbugs:spotbugs-maven-plugin from 4.9.…
nhumblot Jun 30, 2025
2675754
build(deps): bump org.apache.maven.plugins:maven-invoker-plugin from …
dependabot[bot] Jul 2, 2025
4caa786
build(deps): bump org.apache.maven.plugins:maven-gpg-plugin from 3.2.…
dependabot[bot] Jul 3, 2025
2bf4e0d
build(deps): bump org.apache.maven.plugins:maven-enforcer-plugin from…
dependabot[bot] Jul 5, 2025
ebe6f0d
fix: Add null checking when parsing the license json in AbstractNpmAn…
floverfelt Jul 6, 2025
9195c3f
build(deps): bump junit.version from 5.13.2 to 5.13.3
dependabot[bot] Jul 7, 2025
9187ca9
build(deps): bump org.codehaus.gmavenplus:gmavenplus-plugin
dependabot[bot] Jul 7, 2025
121b386
build(deps): bump org.codehaus.gmavenplus:gmavenplus-plugin from 4.2.…
nhumblot Jul 7, 2025
49eda89
build(deps): bump junit.version from 5.13.2 to 5.13.3 (#7789)
nhumblot Jul 7, 2025
a43fa47
docs: update development pre-reqs
jeremylong Jul 7, 2025
df3ee13
docs: update development pre-reqs (#7792)
nhumblot Jul 8, 2025
4c7c115
build(deps): bump golang from 1.24.4-alpine to 1.24.5-alpine (#7797)
dependabot[bot] Jul 9, 2025
907f3f7
build(deps): bump org.apache.commons:commons-lang3 from 3.17.0 to 3.1…
dependabot[bot] Jul 10, 2025
5d81c4c
build(deps): bump commons-validator:commons-validator from 1.9.0 to 1…
dependabot[bot] Jul 11, 2025
29967c3
build: utilize central publishing (#7810)
jeremylong Jul 13, 2025
9724fd4
build: use correct environment variables for publishing (#7812)
jeremylong Jul 13, 2025
8ac68cc
build: remove unused code coverage (#7813)
jeremylong Jul 13, 2025
1b97f1d
build(deps-dev): bump io.netty:netty-codec-http
dependabot[bot] Jul 15, 2025
1eb12fa
build(deps-dev): bump io.netty:netty-codec-http from 4.2.2.Final to 4…
nhumblot Jul 15, 2025
e134044
build(deps): bump org.apache.maven.plugins:maven-enforcer-plugin from…
dependabot[bot] Jul 16, 2025
e257e82
docs: request FP reporters use the latest version of ODC. (#7820)
jeremylong Jul 17, 2025
8d692e4
feat: Migration to Alpine 3.22 (#7822)
julienhuon Jul 18, 2025
dd52a68
build(deps): bump jackson.version from 2.19.1 to 2.19.2
dependabot[bot] Jul 21, 2025
0c0bc0a
build(deps): bump commons-io:commons-io from 2.19.0 to 2.20.0 (#7826)
dependabot[bot] Jul 21, 2025
41a0ae4
build(deps): bump junit.version from 5.13.3 to 5.13.4
dependabot[bot] Jul 22, 2025
dcfb75c
build(deps): bump junit.version from 5.13.3 to 5.13.4 (#7830)
nhumblot Jul 24, 2025
745c804
build(deps): bump jackson.version from 2.19.1 to 2.19.2 (#7825)
nhumblot Jul 24, 2025
5793eba
build(deps): bump org.apache.commons:commons-text from 1.13.1 to 1.14.0
dependabot[bot] Jul 25, 2025
9fd451b
build(deps): bump commons-codec:commons-codec from 1.18.0 to 1.19.0
dependabot[bot] Jul 25, 2025
79066ad
build(deps): bump org.apache.commons:commons-text from 1.13.1 to 1.14…
aikebah Jul 27, 2025
326eb6b
build(deps): bump commons-codec:commons-codec from 1.18.0 to 1.19.0 (…
aikebah Jul 27, 2025
a9f313a
fix: classloading problem with fat jars (#7786)
Thomas-Bergmann Jul 4, 2025
7f92ad9
Improve Artifactory handler log message
marcelstoer Jul 29, 2025
4c33e0a
build(deps): bump org.apache.commons:commons-compress
dependabot[bot] Jul 30, 2025
8bd8caf
feat: Improve Artifactory handler log message (#7838)
aikebah Jul 30, 2025
f23ff91
fix: class loading problem with fat jars (#7786) (#7787)
aikebah Jul 30, 2025
b9383c1
build(deps): bump org.apache.commons:commons-compress from 1.27.1 to …
aikebah Jul 30, 2025
e16e851
fix: Return unsorted vulnerabilities in new HashSet, avoiding CoMod
Jul 31, 2025
db8dd16
build(deps): bump actions/download-artifact from 4 to 5
dependabot[bot] Aug 6, 2025
de5c4d2
build(deps): bump actions/download-artifact from 4 to 5 (#7856)
nhumblot Aug 6, 2025
8c47e4d
Merge branch 'main' into NpmCoModExc
nhumblot Aug 6, 2025
4333171
fix: Return unsorted vulnerabilities in new HashSet, avoiding CoMod (…
nhumblot Aug 6, 2025
b7d8867
docs: Document poetry-based analysis behaviour in Python analyzer (#7…
sdruskat Aug 6, 2025
6b033f6
build(deps): bump golang from 1.24.5-alpine to 1.24.6-alpine (#7858)
dependabot[bot] Aug 8, 2025
3483ace
build(deps): bump com.github.spotbugs:spotbugs-annotations from 4.9.3…
dependabot[bot] Aug 11, 2025
01cf58a
build(deps): bump actions/checkout from 4 to 5 (#7861)
dependabot[bot] Aug 13, 2025
9716927
build(deps): bump amannn/action-semantic-pull-request from 5.5.3 to 6…
dependabot[bot] Aug 14, 2025
3ec985d
build(deps-dev): bump io.netty:netty-codec-http from 4.2.3.Final to 4…
dependabot[bot] Aug 15, 2025
1fd50d5
build(deps): bump org.apache.maven.plugins:maven-javadoc-plugin
dependabot[bot] Aug 18, 2025
87015a3
build(deps): bump org.apache.maven.plugins:maven-javadoc-plugin from …
nhumblot Aug 18, 2025
9123eaf
build(deps): bump golang from 1.24.6-alpine to 1.25.0-alpine (#7865)
dependabot[bot] Aug 18, 2025
2957400
build(deps): bump mockito.version from 5.18.0 to 5.19.0 (#7874)
dependabot[bot] Aug 19, 2025
f55001a
build(deps): bump actions/setup-java from 4 to 5 (#7883)
dependabot[bot] Aug 22, 2025
15c9491
docs: Clarify format of exclude patterns (#7879)
kwin Aug 22, 2025
b7702a6
build(deps): bump com.github.spotbugs:spotbugs-maven-plugin from 4.9.…
dependabot[bot] Aug 24, 2025
577cf94
build(deps): bump amannn/action-semantic-pull-request from 6.0.1 to 6…
dependabot[bot] Aug 25, 2025
2dd7324
fix: npe when processing cve with empty configuration (#7888)
timnieder Aug 25, 2025
840b13a
fix: correctly utilize CVSSv4 from ossindex (#7899)
jeremylong Aug 31, 2025
f3de851
fix: add CVSSv4 to suppressed entries in JSON report (#7900)
jeremylong Sep 2, 2025
d926861
build(deps): bump org.jsoup:jsoup from 1.21.1 to 1.21.2 (#7885)
dependabot[bot] Sep 3, 2025
1a111d2
build(deps): bump jackson.version from 2.19.2 to 2.20.0 (#7907)
dependabot[bot] Sep 7, 2025
4a6901f
build(deps): bump golang from 1.25.0-alpine to 1.25.1-alpine (#7914)
dependabot[bot] Sep 15, 2025
fc289ea
build(deps): bump actions/github-script from 7.0.1 to 8.0.0 (#7909)
dependabot[bot] Sep 16, 2025
812793d
fix: Update to support OSS Index Authentication Requirements (#7920)
framayo Sep 20, 2025
8ddda01
build(deps): bump actions/setup-node from 4.4.0 to 5.0.0 (#7910)
dependabot[bot] Sep 20, 2025
baf281b
build(deps): bump actions/setup-dotnet from 4.3.1 to 5.0.0 (#7908)
dependabot[bot] Sep 20, 2025
1d15a2d
docs: update changelog for release 12.1.4
jeremylong Sep 20, 2025
dcfcc10
build: prepare release v12.1.4
jeremylong Sep 20, 2025
3220b96
build: prepare for next development iteration
jeremylong Sep 20, 2025
af34748
build: release 12.1.4 (#7931)
jeremylong Sep 20, 2025
045e428
chore: revert failed release
jeremylong Sep 20, 2025
ed80987
chore: revert failed release (#7932)
jeremylong Sep 20, 2025
d5198d5
chore: bump project to 12.1.5
jeremylong Sep 20, 2025
71e0fd8
build: prepare release v12.1.5
jeremylong Sep 20, 2025
4434197
build: prepare for next development iteration
jeremylong Sep 20, 2025
ebee56e
build: release 12.1.5 (#7933)
jeremylong Sep 20, 2025
36543b5
fix: Correct CVSSv4 parsing for low precision OSSIndex values (#7935)
chadlwilson Sep 21, 2025
dd04cd1
chore: fix version typo in security policy (#7936)
chadlwilson Sep 22, 2025
a74b3c7
build(deps): bump commons-cli:commons-cli from 1.9.0 to 1.10.0
dependabot[bot] Aug 4, 2025
9cbfb35
build(deps): bump org.jetbrains:annotations from 26.0.2 to 26.0.2-1 (…
dependabot[bot] Sep 22, 2025
1e7a598
build(deps): bump com.github.spotbugs:spotbugs-annotations
dependabot[bot] Sep 23, 2025
b3aa3f2
build: replace deprecated jlink argument (#7953)
chadlwilson Sep 23, 2025
6008202
test: Fix AssemblyAnalyzerTest to be robust to Grok availability (#7950)
chadlwilson Sep 23, 2025
4af07cc
docs: Implement #7808 to make changelog links clickable (#7945)
chadlwilson Sep 23, 2025
c44ba32
fix(fp): Fix false positives for Redis Server against NPM/JS client l…
chadlwilson Sep 23, 2025
34a1235
docs: Fix legacy GitHub links within docs and CHANGELOG (#7944)
chadlwilson Sep 23, 2025
93422d2
chore: Allow passing ossIndex credentials during false positive ops w…
chadlwilson Sep 23, 2025
22ecc0b
fix: Disable OSS Index if its credentials are missing (#7963)
nMoncho Sep 24, 2025
93b0d1b
build(deps): bump netty-codec-http from 5.2.4-final to 5.2.5-final (#…
jeremylong Sep 24, 2025
c7e992c
docs: release 12.1.6
jeremylong Sep 24, 2025
0a9592c
build: prepare release v12.1.6
jeremylong Sep 24, 2025
e96e843
build: prepare for next development iteration
jeremylong Sep 24, 2025
e1071ec
build: release 12.1.6 (#7966)
jeremylong Sep 24, 2025
c108644
build(deps): bump commons-cli:commons-cli from 1.9.0 to 1.10.0 (#7851)
jeremylong Sep 24, 2025
966aca1
build(deps): bump org.apache.maven.plugins:maven-failsafe-plugin
dependabot[bot] Sep 25, 2025
c23b953
build(deps): bump com.github.spotbugs:spotbugs-annotations from 4.9.4…
jeremylong Sep 25, 2025
1e3a83b
fix(fp): Fix broad Python regex to suppress packages ending in `-pyth…
chadlwilson Sep 26, 2025
a98db25
fix: Clean up Apache Lucene logging via SLF4j redirect (#7979)
chadlwilson Sep 26, 2025
eaa76f9
fix: improve OSS Index Error Reporting (#7977)
jeremylong Sep 27, 2025
3bff5af
fix: Update NVD CPE search URLs to match new search interface (#7970)
chadlwilson Sep 27, 2025
9341f02
build: Build amd64 and arm64 multi-platform Docker image (#7952)
chadlwilson Sep 27, 2025
fc28be0
build(deps): bump org.apache.httpcomponents.core5:httpcore5 from 5.3.…
dependabot[bot] Sep 29, 2025
d1843ac
fix: Correct Archive Analyzer behaviour on certain tgz archives (#7986)
chadlwilson Sep 30, 2025
d48d7ba
fix: remove sponsorship link (#7990)
jeremylong Sep 30, 2025
eefb8d7
build(deps): bump org.apache.commons:commons-lang3 from 3.18.0 to 3.1…
dependabot[bot] Oct 1, 2025
46042fd
build(deps): bump org.apache.maven.plugins:maven-surefire-plugin from…
dependabot[bot] Oct 2, 2025
c566904
fix: disable central analyzer after failures (#7993)
jeremylong Oct 2, 2025
5fa401f
docs: Clarify Nexus Analyzer requirements and usage (#8000)
chadlwilson Oct 3, 2025
de46625
docs: Documentation artifactory settings fix (#7999)
evgeniiworkst Oct 3, 2025
ae97b08
feat: Suppress JVM warnings from Lucene within CLI (#8003)
chadlwilson Oct 6, 2025
edd1491
fix(fp): Fix more common false positives for popular PHP/composer fra…
chadlwilson Oct 6, 2025
ea3500d
build(deps): bump org.postgresql:postgresql from 42.7.7 to 42.7.8
dependabot[bot] Oct 7, 2025
fcc7c8a
build: Replace Maven Enforcer byte code rule with extra-enforcer-rule…
chadlwilson Oct 7, 2025
1d629a5
Merge branch 'main' into dependabot/maven/org.postgresql-postgresql-4…
nhumblot Oct 7, 2025
d7b2a01
build(deps): bump org.postgresql:postgresql from 42.7.7 to 42.7.8 (#8…
nhumblot Oct 7, 2025
18da5fb
Merge branch 'main' into dependabot/maven/org.apache.maven.plugins-ma…
nhumblot Oct 7, 2025
5a41209
build(deps): bump org.apache.maven.plugins:maven-failsafe-plugin from…
nhumblot Oct 7, 2025
96e2efa
build(deps): bump golang from 1.25.1-alpine to 1.25.2-alpine (#8013)
dependabot[bot] Oct 8, 2025
f682929
build(deps): bump org.apache.maven.plugins:maven-javadoc-plugin from …
dependabot[bot] Oct 9, 2025
f8f4877
build(deps): bump github/codeql-action from 3 to 4 (#8010)
dependabot[bot] Oct 9, 2025
7c700bd
fix(fp): Consolidate false positive suppression for false positives o…
chadlwilson Oct 9, 2025
c1e4143
build(deps): bump pnpm/action-setup from 4.1.0 to 4.2.0 (#8015)
dependabot[bot] Oct 10, 2025
f613de3
build(deps): bump junit.version from 5.13.4 to 5.14.0 (#8011)
dependabot[bot] Oct 10, 2025
c7e3ee8
build(deps): bump org.apache.maven.plugins:maven-surefire-report-plug…
dependabot[bot] Oct 10, 2025
e32fbaf
build(deps): bump com.google.guava:guava from 33.4.8-jre to 33.5.0-jr…
dependabot[bot] Oct 10, 2025
98fa933
build(deps): bump org.apache.maven.plugins:maven-dependency-plugin fr…
dependabot[bot] Oct 10, 2025
c93bb05
build(deps): bump microsoft/sarif-actions from v0.1 to 0.2 (#8025)
jeremylong Oct 10, 2025
004b585
docs: add scarf to gh-pages (#8027)
jeremylong Oct 11, 2025
11ab774
docs: add scarf to readme.md (#8028)
jeremylong Oct 11, 2025
6865cd3
docs: improve slack notification documentation (#8026)
jeremylong Oct 11, 2025
a7fe54c
build(deps): bump azul/zulu-openjdk-alpine from 21 to 25 (#7928)
dependabot[bot] Oct 12, 2025
d94bc17
docs: release 12.1.7
jeremylong Oct 12, 2025
1cfa37d
build: prepare release v12.1.7
jeremylong Oct 12, 2025
a311d70
build: prepare for next development iteration
jeremylong Oct 12, 2025
986afb0
build: release 12.1.7 (#8030)
jeremylong Oct 12, 2025
8ceb175
docs: Improve Gradle docs wrt experimental analyzers, use of Central …
chadlwilson Oct 13, 2025
5ac1edb
build(deps): bump org.jacoco:jacoco-maven-plugin from 0.8.13 to 0.8.1…
dependabot[bot] Oct 13, 2025
fd8371c
build(deps): bump org.apache.maven.plugins:maven-compiler-plugin from…
dependabot[bot] Oct 13, 2025
52eefb7
build(deps): bump org.apache.maven.plugins:maven-artifact-plugin from…
dependabot[bot] Oct 13, 2025
a8e00c8
build: fix flaky central test (#8039)
jeremylong Oct 13, 2025
c4696c0
docs: add note about central analyzer for gradle (#8038)
jeremylong Oct 13, 2025
8230ba2
fix: improve VulnerableSoftware comparison (#8031)
jeremylong Oct 13, 2025
a06ba2e
docs: release 12.1.8
jeremylong Oct 13, 2025
2d29a0b
build: prepare release v12.1.8
jeremylong Oct 13, 2025
ddc019d
build: prepare for next development iteration
jeremylong Oct 13, 2025
3239948
build: release 12.1.8 (#8041)
jeremylong Oct 13, 2025
d410a44
build(deps): bump org.codehaus.mojo:versions-maven-plugin
dependabot[bot] Oct 14, 2025
a997466
build(deps): bump org.apache.maven.plugins:maven-enforcer-plugin
dependabot[bot] Oct 14, 2025
6889767
build(deps): bump golang from 1.25.2-alpine to 1.25.3-alpine
dependabot[bot] Oct 14, 2025
bdfbb5c
build(deps): bump golang from 1.25.2-alpine to 1.25.3-alpine (#8045)
nhumblot Oct 14, 2025
f0d97a1
Merge branch 'main' into dependabot/maven/org.apache.maven.plugins-ma…
nhumblot Oct 14, 2025
397d1c7
build(deps): bump org.apache.maven.plugins:maven-enforcer-plugin from…
nhumblot Oct 14, 2025
431e687
Merge branch 'main' into dependabot/maven/org.codehaus.mojo-versions-…
nhumblot Oct 14, 2025
67d9ff9
build(deps): bump org.codehaus.mojo:versions-maven-plugin from 2.18.0…
nhumblot Oct 14, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
3 changes: 3 additions & 0 deletions .github/ISSUE_TEMPLATE/bug_report.md
Original file line number Diff line number Diff line change
Expand Up @@ -7,6 +7,9 @@ assignees: ''

---

**Precondition**
- [ ] I checked the issues list for existing open or closed reports of the same problem.

**Describe the bug**
A clear and concise description of what the bug is.

Expand Down
20 changes: 15 additions & 5 deletions .github/ISSUE_TEMPLATE/false-positive-report.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,28 +6,38 @@ body:
- type: markdown
attributes:
value: |
False Positive identified.
**Ensure you are using the latest version of dependency-check.**

**Automation is used to process most false positives reports**; failure to follow these guidelines will delay the process:

- Only enter a **single (1) Package URL**.
- Only enter a **single (1) CPE or CVE**.
- If filing a CPE report you do not need to add the CVEs. Note that **most reports should be for incorrectly matched CPEs**.

If reporting false positives for multiple PURL and/or CPE please file multiple reports.

Thank you for filing a false positive report!
- type: input
id: purl
attributes:
label: Package URl
description: The identified package URL as identified in the HTML Report.
description: Please enter the single identified package URL as identified in the HTML Report. Only a **single PURL** can be specified, if you are reporting more then one - please open two issues using this template.
placeholder: ex. pkg:maven/org.apache.logging.log4j/log4j-slf4j-impl@2.12.1
validations:
required: true
- type: input
id: cpe
attributes:
label: CPE
description: The Common Platform enumeration (CPE) as identified in the HTML Report. Please put backtic characters around the CPE to ensure it displays correctly.
description: Please enter the single Common Platform enumeration (CPE) as identified in the HTML Report. Only a **single CPE** can be specified. **Please put backtick characters around the CPE to ensure it displays correctly**.
placeholder: ex. `cpe:2.3:a:apache:log4j:2.12.1:*:*:*:*:*:*:*`
validations:
required: true
- type: input
id: cve
attributes:
label: CVE
description: The vulnerability name as identified in the HTML Report. This is optional and may not be needed as most FP reports are due to an incorrect CPE.
description: The vulnerability name as identified in the HTML Report. If specifying a CPE this is not necessary; if entered please enter only a **single CVE**; if multiple CVE should be suppressed please enter multiple FP reports. This is optional and may not be needed as most FP reports are due to an incorrect CPE.
placeholder: ex. CVE-2021-44228
validations:
required: false
Expand Down Expand Up @@ -58,4 +68,4 @@ body:
label: Description
description: Additional information regarding the false positive report.
validations:
required: false
required: false
12 changes: 6 additions & 6 deletions .github/contributing.md
Original file line number Diff line number Diff line change
Expand Up @@ -3,8 +3,8 @@
## Reporting Bugs

- Ensure you're running the latest version of dependency-check.
- Ensure the bug has not [already been reported](https://github.com/jeremylong/DependencyCheck/issues).
- If you're unable to find an open issue addressing the problem, please [submit a new issue](https://github.com/jeremylong/DependencyCheck/issues/new/choose).
- Ensure the bug has not [already been reported](https://github.com/dependency-check/DependencyCheck/issues).
- If you're unable to find an open issue addressing the problem, please [submit a new issue](https://github.com/dependency-check/DependencyCheck/issues/new/choose).
- Please fill out the appropriate section of the bug report template provided.
- Delete any sections not needed in the template.

Expand All @@ -14,13 +14,13 @@

## Asking Questions

- Your question may be answered by taking a look at the [documentation](https://jeremylong.github.io/DependencyCheck/).
- Search both the [open and closed issues issues in GitHub](https://github.com/jeremylong/DependencyCheck/issues/)
- If you still have a question ask a [new question](https://github.com/jeremylong/DependencyCheck/issues/new?assignees=&labels=question&template=ask-a-question.md&title=)
- Your question may be answered by taking a look at the [documentation](https://dependency-check.github.io/DependencyCheck/).
- Search both the [open and closed issues issues in GitHub](https://github.com/dependency-check/DependencyCheck/issues/)
- If you still have a question ask a [new question](https://github.com/dependency-check/DependencyCheck/issues/new?assignees=&labels=question&template=ask-a-question.md&title=)

## Enhancement Requests

- Suggest changes by [submitting a new issue](https://github.com/jeremylong/DependencyCheck/issues/new?assignees=&labels=enhancement&template=feature_request.md&title=) and begin coding.
- Suggest changes by [submitting a new issue](https://github.com/dependency-check/DependencyCheck/issues/new?assignees=&labels=enhancement&template=feature_request.md&title=) and begin coding.

## Contributing Code

Expand Down
8 changes: 1 addition & 7 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -11,10 +11,4 @@ updates:
- package-ecosystem: "docker"
directory: "/"
schedule:
interval: "daily"
ignore:
# stay .net 3.1
- dependency-name: "mcr.microsoft.com/dotnet/runtime"
versions:
- "5.x"
- "6.x"
interval: "daily"
27 changes: 0 additions & 27 deletions .github/lock.yml

This file was deleted.

14 changes: 11 additions & 3 deletions .github/pull_request_template.md
Original file line number Diff line number Diff line change
@@ -1,8 +1,16 @@
## Fixes Issue #

## Description of Change

*Please add a description of the proposed change*
<!--
Please add a description of the proposed change
-->

## Related issues

<!--
e.g
- fixes #xxxx
- relates to #xxxx
-->

## Have test cases been added to cover the new functionality?

Expand Down
94 changes: 54 additions & 40 deletions .github/workflows/build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -20,66 +20,68 @@ jobs:
- name: Install gpg secret key
id: install-gpg-key
run: |
cat <(echo -e "${{ secrets.OSSRH_GPG_SECRET_KEY }}") | gpg --batch --import
cat <(echo -e "${{ secrets.GPG_PRIVATE_KEY }}") | gpg --batch --import
gpg --list-secret-keys --keyid-format LONG
- uses: actions/checkout@v3
- uses: actions/checkout@v5
- name: Check Maven Cache
id: maven-cache
uses: actions/cache@v3
uses: actions/cache@v4
with:
path: ~/.m2/repository
key: ${{ runner.os }}-maven-${{ hashFiles('**/pom.xml') }}
restore-keys: |
${{ runner.os }}-maven-
- name: Check Local Maven Cache
id: maven-it-cache
uses: actions/cache@v3
uses: actions/cache@v4
with:
path: maven/target/local-repo
key: mvn-it-repo
- name: Check ODC Data Cache
id: odc-data-cache
uses: actions/cache@v3
uses: actions/cache@v4
with:
path: core/target/data
key: odc-data
- uses: actions/setup-dotnet@v3.0.3
- uses: actions/setup-dotnet@v5.0.0
with:
dotnet-version: '6.0.x'
- name: Set up JDK 1.8
id: jdk-8
uses: actions/setup-java@v3
dotnet-version: '8.0.x'
- name: Set up JDK 11
id: jdk-11
uses: actions/setup-java@v5
with:
java-version: 8
java-version: 11
distribution: 'zulu'
server-id: ossrh
server-username: ${{ secrets.OSSRH_USERNAME }}
server-password: ${{ secrets.OSSRH_TOKEN }}
- uses: pnpm/action-setup@v2.2.4
server-id: central
server-username: ${{ secrets.CENTRAL_USER }}
server-password: ${{ secrets.CENTRAL_PASSWORD }}
- uses: pnpm/action-setup@41ff72655975bd51cab0327fa583b6e92b6d3061 # v4.2.0
with:
version: 6.0.2
- name: Build Snapshot with Maven
id: build-snapshot
env:
MAVEN_USERNAME: ${{ secrets.OSSRH_USERNAME }}
MAVEN_PASSWORD: ${{ secrets.OSSRH_TOKEN }}
run: mvn -s settings.xml -Prelease clean package verify source:jar javadoc:jar gpg:sign deploy -DreleaseTesting --no-transfer-progress --batch-mode -Dgpg.passphrase=${{ secrets.OSSRH_GPG_SECRET_KEY_PASSWORD }}
MAVEN_USERNAME: ${{ secrets.CENTRAL_USER }}
MAVEN_PASSWORD: ${{ secrets.CENTRAL_PASSWORD }}
MAVEN_GPG_PASSPHRASE: ${{ secrets.GPG_PRIVATE_KEY_PASSWORD }}
NVD_API_KEY: ${{ secrets.NVD_API_KEY }}
run: mvn -V -s settings.xml -Prelease clean package verify source:jar javadoc:jar gpg:sign deploy -DreleaseTesting --no-transfer-progress --batch-mode
- name: SARIF Multitool
uses: microsoft/sarif-actions@v0.1
uses: microsoft/sarif-actions@v0.2
with:
# Command to be sent to SARIF Multitool
command: 'validate core/target/test-reports/Report.sarif'
- name: Archive IT test logs
id: archive-logs
if: always()
uses: actions/upload-artifact@v3
uses: actions/upload-artifact@v4
with:
name: it-test-logs
retention-days: 7
path: maven/target/it/**/build.log
- name: Archive code coverage results
id: archive-coverage
uses: actions/upload-artifact@v3
uses: actions/upload-artifact@v4
with:
name: code-coverage-report
retention-days: 7
Expand All @@ -88,7 +90,7 @@ jobs:
**/target/jacoco-results/**/*.html
- name: Archive Snapshot
id: archive-snapshot
uses: actions/upload-artifact@v3
uses: actions/upload-artifact@v4
with:
name: archive-snapshot
retention-days: 7
Expand All @@ -99,20 +101,20 @@ jobs:
ant/target/*.zip
cli/target/*.zip

publish_coverage:
name: publish code coverage reports
runs-on: ubuntu-latest
needs: build
steps:
- name: Download coverage reports
uses: actions/download-artifact@v3
with:
name: code-coverage-report
- name: Run codacy-coverage-reporter
uses: codacy/codacy-coverage-reporter-action@master
with:
project-token: ${{ secrets.CODACY_PROJECT_TOKEN }}
coverage-reports: utils/target/jacoco-results/jacoco.xml,core/target/jacoco-results/jacoco.xml,maven/target/jacoco-results/jacoco.xml,ant/target/jacoco-results/jacoco.xml,cli/target/jacoco-results/jacoco.xml
# publish_coverage:
# name: publish code coverage reports
# runs-on: ubuntu-latest
# needs: build
# steps:
# - name: Download coverage reports
# uses: actions/download-artifact@v5
# with:
# name: code-coverage-report
# - name: Run codacy-coverage-reporter
# uses: codacy/codacy-coverage-reporter-action@master
# with:
# project-token: ${{ secrets.CODACY_PROJECT_TOKEN }}
# coverage-reports: utils/target/jacoco-results/jacoco.xml,core/target/jacoco-results/jacoco.xml,maven/target/jacoco-results/jacoco.xml,ant/target/jacoco-results/jacoco.xml,cli/target/jacoco-results/jacoco.xml

docker:
permissions:
Expand All @@ -126,22 +128,34 @@ jobs:
DOCKER_TOKEN: ${{ secrets.DOCKER_TOKEN }}
steps:
- name: Checkout code
uses: actions/checkout@v3
uses: actions/checkout@v5
- name: Check Maven Cache
id: maven-cache
uses: actions/cache@v3
uses: actions/cache@v4
with:
path: ~/.m2/repository
key: ${{ runner.os }}-maven-${{ hashFiles('**/pom.xml') }}
restore-keys: |
${{ runner.os }}-maven-
- name: Download release build
uses: actions/download-artifact@v3
uses: actions/download-artifact@v5
with:
name: archive-snapshot
- name: Set up Docker
uses: docker/setup-docker-action@v4
with:
daemon-config: |
{
"debug": true,
"features": {
"containerd-snapshotter": true
}
}
- name: Set up Docker Buildx
uses: docker/setup-buildx-action@v3
- name: Build Docker Image
run: ./build-docker.sh
- name: build scan target
run: mvn -s settings.xml package -DskipTests=true --no-transfer-progress --batch-mode
run: mvn -V -s settings.xml package -DskipTests=true --no-transfer-progress --batch-mode
- name: Test Docker Image
run: ./test-docker.sh
6 changes: 3 additions & 3 deletions .github/workflows/codeql-analysis.yml
Original file line number Diff line number Diff line change
Expand Up @@ -33,11 +33,11 @@ jobs:

steps:
- name: Checkout repository
uses: actions/checkout@v3
uses: actions/checkout@v5

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v2
uses: github/codeql-action/init@v4
with:
languages: ${{ matrix.language }}
# If you wish to specify custom queries, you can do so here or in a config file.
Expand All @@ -61,4 +61,4 @@ jobs:
mvn -s settings.xml clean package -DskipTests=true --no-transfer-progress --batch-mode

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v2
uses: github/codeql-action/analyze@v4
37 changes: 0 additions & 37 deletions .github/workflows/coverity.yml

This file was deleted.

Loading