[ 
https://issues.apache.org/jira/browse/EAGLE-1102?focusedWorklogId=323273&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-323273
 ]

ASF GitHub Bot logged work on EAGLE-1102:
-----------------------------------------

                Author: ASF GitHub Bot
            Created on: 04/Oct/19 08:28
            Start Date: 04/Oct/19 08:28
    Worklog Time Spent: 10m 
      Work Description: grainier commented on pull request #1005: [EAGLE-1102] 
Integrate CVE maven plugin
URL: https://github.com/apache/eagle/pull/1005
 
 
   <!--
   {% comment %}
   Licensed to the Apache Software Foundation (ASF) under one or more
   contributor license agreements.  See the NOTICE file distributed with
   this work for additional information regarding copyright ownership.
   The ASF licenses this file to you under the Apache License, Version 2.0
   (the "License"); you may not use this file except in compliance with
   the License.  You may obtain a copy of the License at
   
   http://www.apache.org/licenses/LICENSE-2.0
   
   Unless required by applicable law or agreed to in writing, software
   distributed under the License is distributed on an "AS IS" BASIS,
   WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
   See the License for the specific language governing permissions and
   limitations under the License.
   {% endcomment %}
   -->
   
   ## Purpose
   Purpose of this pull request is to integrate the CVE maven plugin for eagle 
to check security vulnerabilities in dependencies during build time. This will 
help to detect publicly disclosed vulnerabilities contained within eagle's 
dependencies (and the dependencies of all child modules).
   
   ## Usage
   
   This plugin configuration is attached to the `mvn verify` phase. Therefore, 
this will run automatically when we perform a `mvn clean verify`. Once the 
`mvn` process is completed, the plugin will create a 
`dependency-check-report.html` report in `target/` dir with the detect 
vulnerabilities.
   
   In case if you need to skip this plugin, use `owasp.check.skip=true` 
property (i.e `mvn clean verify -Dowasp.check.skip=true`). 
   
   ## Remarks
   - Fixes https://issues.apache.org/jira/browse/EAGLE-1102
   - https://issues.apache.org/jira/browse/EAGLE-1100
   - https://github.com/jeremylong/DependencyCheck
   - 
https://jeremylong.github.io/DependencyCheck/dependency-check-maven/aggregate-mojo.html
   - https://jeremylong.github.io/DependencyCheck/general/suppression.html
   ---
   
   Be sure to do all of the following to help us incorporate your contribution
   quickly and easily:
   
    - [x] Make sure the PR title is formatted like:
      `[EAGLE-<Jira issue #>] Description of pull request`
    - [x] Make sure tests pass via `mvn clean verify`. (Even better, enable
          Travis-CI on your fork and ensure the whole test matrix passes).
    - [x] Replace `<Jira issue #>` in the title with the actual Jira issue
          number, if there is one.
    - [ ] If this contribution is large, please file an Apache
          [Individual Contributor License 
Agreement](https://www.apache.org/licenses/icla.txt).
   
   ---
 
----------------------------------------------------------------
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
 
For queries about this service, please contact Infrastructure at:
us...@infra.apache.org


Issue Time Tracking
-------------------

            Worklog Id:     (was: 323273)
    Remaining Estimate: 0h
            Time Spent: 10m

> Integrate CVE maven plugin
> --------------------------
>
>                 Key: EAGLE-1102
>                 URL: https://issues.apache.org/jira/browse/EAGLE-1102
>             Project: Eagle
>          Issue Type: Sub-task
>    Affects Versions: v0.5.0
>            Reporter: Grainier Perera
>            Assignee: Grainier Perera
>            Priority: Critical
>              Labels: security
>          Time Spent: 10m
>  Remaining Estimate: 0h
>
> Integrate the CVE maven plugin [1] for eagle to check security during build 
> time. This will help to detect publicly disclosed vulnerabilities contained 
> within eagle's dependencies.
> [1] https://github.com/jeremylong/DependencyCheck



--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Reply via email to