引入插件依赖:
<plugin>
<groupId>org.owasp</groupId>
<artifactId>dependency-check-maven</artifactId>
<version>7.0.4</version>
<configuration>
<autoUpdate>false</autoUpdate>
<dataDirectory>D:\ProgramFiles\dependency-check\data</dataDirectory>
<versionCheckEnabled>false</versionCheckEnabled>
<retireJsForceUpdate>false</retireJsForceUpdate>
<ossindexAnalyzerUseCache>true</ossindexAnalyzerUseCache>
<skipRuntimeScope>true</skipRuntimeScope>
<skipProvidedScope>true</skipProvidedScope>
<skipSystemScope>true</skipSystemScope>
<skipTestScope>true</skipTestScope>
</configuration>
<executions>
<execution>
<goals>
<goal>check</goal>
</goals>
</execution>
</executions>
</plugin>
报错:
改autoUpdate参数
<autoUpdate>false</autoUpdate>
或者手动初始化数据库:
mvn org.owasp:dependency-check-maven:7.0.4:initialize
或使用 update-only 更新数据库:
mvn org.owasp:dependency-check-maven:7.0.4:update-only
数据初始化或更新成功:
执行命令开始扫描:
mvn dependency-check:check
扫描结束:
target文件目录下获取扫描结果: