ofbiz-notifications mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From "Jacques Le Roux (JIRA)" <j...@apache.org>
Subject [jira] [Commented] (OFBIZ-7930) Load the OWASP dependency checker Gradle plugin efficiently
Date Sun, 04 Sep 2016 12:55:20 GMT

    [ https://issues.apache.org/jira/browse/OFBIZ-7930?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=15462884#comment-15462884
] 

Jacques Le Roux commented on OFBIZ-7930:
----------------------------------------

This was my own initiative I started to use OWASP-DC around end of 2013. I committed related
stuff end of 2015 and then created the related page in wiki. So far nobody disagreed, so I
take that as a lazy consensus. If there was a better free tool I'd use it. You might start
a discussion on the dev ML if you think it's worth it.

> Load the OWASP dependency checker Gradle plugin efficiently
> -----------------------------------------------------------
>
>                 Key: OFBIZ-7930
>                 URL: https://issues.apache.org/jira/browse/OFBIZ-7930
>             Project: OFBiz
>          Issue Type: Sub-task
>          Components: framework
>    Affects Versions: Trunk
>            Reporter: Jacques Le Roux
>            Assignee: Jacques Le Roux
>            Priority: Minor
>             Fix For: Upcoming Branch
>
>
> As I warned at https://cwiki.apache.org/confluence/display/OFBIZ/About+OWASP+Dependency+Check
it's currently difficult to separate the OFBiz jars from other jars in the .gradle\caches
contains which may contain jars unrelated to OFBiz. Notably Eclipse jars if you use the Gradle
Eclipse task and more if you use Gradle for other reasons than OFBiz.
> I did not find yet a way to avoid to have all external jars in .gradle\caches and I wonder
if it's even possible. What I would like to have is the external jars mandatory for OFBiz
to work in an isolated place. For instance a sub folder of the main Gradle build folder. I
picked $buildDir/externalJars.



--
This message was sent by Atlassian JIRA
(v6.3.4#6332)

Mime
View raw message