Git Product home page Git Product logo

fortify-ssc-parser-owasp-dependency-check's People

Contributors

github-actions[bot] avatar rsenden avatar

Stargazers

 avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar

fortify-ssc-parser-owasp-dependency-check's Issues

Support for version 6.x.x

Hello,

is the plugin (v1.4.1) supporting version 6 of the OWASP dep. checker ?
We're not sure which engine version is meant?

image

Upload of DC Results to SSC from Jenkins

Hello,

I am planning to automate the usage of Dependency Check and its results to Fortify SSC portal since it will be one stop for both code analysis and software composition analysis. Currently, I can upload results of DC manually in SSC however I would like to know how I can automate it through a plugin from Jenkins. I tried to upload DC results file through "Fortify Assessment" step and didn't work out as it will explicitly look for FPR's

Additionally, during manual upload also, we have to enable the "Third Party Results" and how can we automate all these to upload DC result into SSC?

Thanks

Add README.md

Add a README.md file with:

  • A generic description of the purpose of this project
  • Where to download releases and beta versions
  • (How to build from source)?
  • How to install/use (and/or just refer to SSC documentation)

Gradle deprecation warning

The following warning is shown when running ./gradlew distThirdParty --warning-mode=all:

> Task :generateLicenseReport
The runtime configuration has been deprecated for resolution. This will fail with an error in Gradle 7.0. Please resolve the runtimeClasspath configuration instead. Consult the upgrading guide for further information: https://docs.gradle.org/6.8.3/userguide/upgrading_version_5.html#dependencies_should_no_longer_be_declared_using_the_compile_and_runtime_configurations

This is caused by this issue: jk1/Gradle-License-Report#161 (comment)

Once this has been fixed in the plugin, the plugin version should be updated in our build.gradle.

Note that this applies to all parser plugins in the fortify-ps organization: https://github.com/fortify-ps?q=fortify-ssc-parser

Unable to upload OWASP DC Results

Hi,

Shown with an error "Exception: An unexpected error occurred during scan processing: com.fortify.manager.exception.FMDALException: Unable to execute batch." while uploading JSON file regenerated by OWASP DC latest version i.e. 6.0.1

Thanks,
Mani

Reparsing

Hello @rsenden,

we have a quation about the parser and upload mechanismn.
If an application uses a vul. jar file and this information is found by OWASP scanner & uploaded to an SSC AppVersion.

What will happen if the jar is replaced by a newer version without a finding. So we're uploading an empty OWASP report to SCC AppVersion.

Our assumption would be that the finding is marked as removed (or physically deleted) in SSC. Is this right ?

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.