That's where we have it. It slows down the build, but it has caught a few CVE's that we have been able to correct, so probably worth it.
________________________________ From: Shawn McKinney <[email protected]> Sent: Monday, August 6, 2018 10:37:50 AM To: Apache Directory Developers List Subject: Re: OWASP Dependency-Check > On Aug 6, 2018, at 8:20 AM, Smith, Shawn Eion <[email protected]> wrote: > > We have it in the Scimple pom if you're looking for an example to play with. > Thanks, that is very helpful. I wondering if this should be part of the project pom. WDYT?
