Skip to content

OWASP Dependency Checker #60

@jonathanaustin

Description

@jonathanaustin

The OWASP dependency check adds a lot of time to the build and is brittle due to updates always being provided. Many projects disable the checker.

Possible improvements:-

  • Make the OWASP checker run in its own maven profile so it can be run as a seperate process.
  • Increase the check update interval to prevent too many downloads.
  • Report errors and not fail by default

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions