Make use of Maven dependencies inside DC plugin when executing a maven job

XMLWordPrintable

      Dependency Check Plugin run Dependency Check core and scan all workspace contents, including local maven repositories.

      This raise many false positive about vulnerabilities in artifacts not bundled in product but used in scope test, provided, runtime and even Maven plugins (ie Maven site using vulnerable Struts).

      Maven support is allready available in Dependency Check core and Jenkins integration in Dependency Check Plugin, this one should be able to use Jenkins/Maven integration fluently

            Assignee:
            Steve Springett
            Reporter:
            Henri Gomez
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: