Uploaded image for project: 'Jenkins'
  1. Jenkins
  2. JENKINS-57203

OWASP Dependency-Check Plugin is unable to read results from the Node Security Project (NspAnalyzer)

XMLWordPrintable

      Hello,

      I have configured OWASP Dependency Check Plugin for security scan but I am getting following error in console output :

       

      [DependencyCheck] Scanning: /var/lib/jenkins/workspace/XXXXXXXXXXXXXXX
      [DependencyCheck] Analyzing Dependencies
      [DependencyCheck] One or more exceptions were thrown while executing Dependency-Check
      [DependencyCheck] Exception Caught: org.owasp.dependencycheck.analyzer.exception.AnalysisException
      [DependencyCheck] Cause: api.nodesecurity.io
      [DependencyCheck] Message: Failed to read results from the Node Security Project (NspAnalyzer); the analyzer is being disabled and may result in false negatives.
      [DependencyCheck] org.owasp.dependencycheck.analyzer.exception.AnalysisException: Failed to read results from the Node Security Project (NspAnalyzer); the analyzer is being disabled and may result in false negatives.
      [DependencyCheck] at org.owasp.dependencycheck.analyzer.NspAnalyzer.analyzeDependency(NspAnalyzer.java:222)
      [DependencyCheck] at org.owasp.dependencycheck.analyzer.AbstractAnalyzer.analyze(AbstractAnalyzer.java:136)
      [DependencyCheck] at org.owasp.dependencycheck.AnalysisTask.call(AnalysisTask.java:88)
      [DependencyCheck] at org.owasp.dependencycheck.AnalysisTask.call(AnalysisTask.java:37)
      [DependencyCheck] at java.util.concurrent.FutureTask.run(FutureTask.java:266)
      [DependencyCheck] at java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1149)
      [DependencyCheck] at java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:624)
      [DependencyCheck] at java.lang.Thread.run(Thread.java:748)
      [DependencyCheck] Caused by: java.net.UnknownHostException: api.nodesecurity.io
      [DependencyCheck] at java.net.AbstractPlainSocketImpl.connect(AbstractPlainSocketImpl.java:184)
      [DependencyCheck] at java.net.SocksSocketImpl.connect(SocksSocketImpl.java:392)
      [DependencyCheck] at java.net.Socket.connect(Socket.java:589)
      [DependencyCheck] at sun.net.NetworkClient.doConnect(NetworkClient.java:175)
      [DependencyCheck] at sun.net.www.http.HttpClient.openServer(HttpClient.java:463)
      [DependencyCheck] at sun.net.www.http.HttpClient.openServer(HttpClient.java:558)
      [DependencyCheck] at sun.net.www.protocol.https.HttpsClient.<init>(HttpsClient.java:264)
      [DependencyCheck] at sun.net.www.protocol.https.HttpsClient.New(HttpsClient.java:367)
      [DependencyCheck] at sun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.getNewHttpClient(AbstractDelegateHttpsURLConnection.java:191)
      [DependencyCheck] at sun.net.www.protocol.http.HttpURLConnection.plainConnect0(HttpURLConnection.java:1156)
      [DependencyCheck] at sun.net.www.protocol.http.HttpURLConnection.plainConnect(HttpURLConnection.java:1050)
      [DependencyCheck] at sun.net.www.protocol.https.AbstractDelegateHttpsURLConnection.connect(AbstractDelegateHttpsURLConnection.java:177)
      [DependencyCheck] at sun.net.www.protocol.https.HttpsURLConnectionImpl.connect(HttpsURLConnectionImpl.java:162)
      [DependencyCheck] at org.owasp.dependencycheck.data.nsp.NspSearch.submitPackage(NspSearch.java:114)
      [DependencyCheck] at org.owasp.dependencycheck.analyzer.NspAnalyzer.analyzeDependency(NspAnalyzer.java:179)
      [DependencyCheck] ... 7 more
      [DependencyCheck]

            Unassigned Unassigned
            anujgupta Anuj Gupta
            Votes:
            0 Vote for this issue
            Watchers:
            2 Start watching this issue

              Created:
              Updated:
              Resolved: