Re: AW: Re: OWASP Dependency Checking?

2018-12-13 Thread César Hernández Mendoza
gt; http://twitter.com/jlouismonteiro > > >> http://www.tomitribe.com > > >> > > >> > > >> On Thu, Dec 13, 2018 at 10:10 AM Richard Zowalla > > > >> wrote: > > >> > > >>> Hey, > > >>> >

Re: AW: Re: OWASP Dependency Checking?

2018-12-13 Thread Daniel Cunha
luable contribution > >> -- > >> Jean-Louis Monteiro > >> http://twitter.com/jlouismonteiro > >> http://www.tomitribe.com > >> > >> > >> On Thu, Dec 13, 2018 at 10:10 AM Richard Zowalla > >> wrote: > >> > >>>

Re: OWASP Dependency Checking?

2018-12-13 Thread Jean-Louis Monteiro
disclosed > dependency vulnerabilities in the Maven build process (e.g. via a profile). > > I was thinking about introducing OWASP dependency checking (see > https://www.owasp.org/index.php/OWASP_Dependency_Check) in the TomEE > project, so we are aware of security risks introduced by (t

OWASP Dependency Checking?

2018-12-13 Thread Richard Zowalla
Hey, any objectives against automatic checking of known, publicly disclosed dependency vulnerabilities in the Maven build process (e.g. via a profile). I was thinking about introducing OWASP dependency checking (see https://www.owasp.org/index.php/OWASP_Dependency_Check) in the TomEE