Return-Path: X-Original-To: archive-asf-public-internal@cust-asf2.ponee.io Delivered-To: archive-asf-public-internal@cust-asf2.ponee.io Received: from cust-asf.ponee.io (cust-asf.ponee.io [163.172.22.183]) by cust-asf2.ponee.io (Postfix) with ESMTP id EA542200D1E for ; Wed, 18 Oct 2017 17:57:49 +0200 (CEST) Received: by cust-asf.ponee.io (Postfix) id E8D51160BEB; Wed, 18 Oct 2017 15:57:49 +0000 (UTC) Delivered-To: archive-asf-public@cust-asf.ponee.io Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by cust-asf.ponee.io (Postfix) with SMTP id 426AB160BEA for ; Wed, 18 Oct 2017 17:57:49 +0200 (CEST) Received: (qmail 78618 invoked by uid 500); 18 Oct 2017 15:57:48 -0000 Mailing-List: contact builds-help@apache.org; run by ezmlm Precedence: bulk List-Help: List-Unsubscribe: List-Post: List-Id: Reply-To: builds@apache.org Delivered-To: mailing list builds@apache.org Received: (qmail 78607 invoked by uid 99); 18 Oct 2017 15:57:48 -0000 Received: from pnap-us-west-generic-nat.apache.org (HELO spamd2-us-west.apache.org) (209.188.14.142) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 18 Oct 2017 15:57:48 +0000 Received: from localhost (localhost [127.0.0.1]) by spamd2-us-west.apache.org (ASF Mail Server at spamd2-us-west.apache.org) with ESMTP id 744CA1A02E5 for ; Wed, 18 Oct 2017 15:57:47 +0000 (UTC) X-Virus-Scanned: Debian amavisd-new at spamd2-us-west.apache.org X-Spam-Flag: NO X-Spam-Score: 0.979 X-Spam-Level: X-Spam-Status: No, score=0.979 tagged_above=-999 required=6.31 tests=[KAM_LAZY_DOMAIN_SECURITY=1, RCVD_IN_DNSWL_NONE=-0.0001, RCVD_IN_MSPIKE_H3=-0.01, RCVD_IN_MSPIKE_WL=-0.01, RP_MATCHES_RCVD=-0.001] autolearn=disabled Received: from mx1-lw-us.apache.org ([10.40.0.8]) by localhost (spamd2-us-west.apache.org [10.40.0.9]) (amavisd-new, port 10024) with ESMTP id zL0-RaC1MXQG for ; Wed, 18 Oct 2017 15:57:46 +0000 (UTC) Received: from mailout02.t-online.de (mailout02.t-online.de [194.25.134.17]) by mx1-lw-us.apache.org (ASF Mail Server at mx1-lw-us.apache.org) with ESMTPS id A43E75F5F7 for ; Wed, 18 Oct 2017 15:57:45 +0000 (UTC) Received: from fwd06.aul.t-online.de (fwd06.aul.t-online.de [172.20.26.150]) by mailout02.t-online.de (Postfix) with SMTP id D65E041A5329 for ; Wed, 18 Oct 2017 17:57:44 +0200 (CEST) Received: from [192.168.2.108] (r9Swg-ZVwhD++YSCzQWBXMzVVAhjtlY-26fLb5IFD0K3FI0fzzPueDNCnlcCaOKw0r@[217.231.137.2]) by fwd06.t-online.de with (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384 encrypted) esmtp id 1e4qj1-2jbsJc0; Wed, 18 Oct 2017 17:57:43 +0200 Subject: Re: OWAS Dependency Check To: builds@apache.org References: <861aaa00-934f-bddd-3334-7ce5e308ba47@t-online.de> From: Tilman Hausherr Message-ID: <31f3b282-4b01-28d4-9aa9-513ded82cebe@t-online.de> Date: Wed, 18 Oct 2017 17:57:41 +0200 User-Agent: Mozilla/5.0 (Windows NT 10.0; WOW64; rv:52.0) Gecko/20100101 Thunderbird/52.4.0 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 8bit Content-Language: en-US X-ID: r9Swg-ZVwhD++YSCzQWBXMzVVAhjtlY-26fLb5IFD0K3FI0fzzPueDNCnlcCaOKw0r X-TOI-MSGID: 8d33f7af-b770-4e36-85ca-a0cc375fdbbd archived-at: Wed, 18 Oct 2017 15:57:50 -0000 Am 18.10.2017 um 15:32 schrieb Lukasz Lenart: > 2017-10-13 17:46 GMT+02:00 Tilman Hausherr : >> We use it for PDFBox in all builds as a maven plugin. The current version >> 2.1.1 is over-sensitive compared to 2.1.0. The developer told me that this >> will be fixed in 3.0. > Do you fail a build when the plugin finds something? Yes:                                             org.owasp dependency-check-maven                         2.1.0                         true                                                                                                                                                 check                                                                                                         Tilman