[jira] [Commented] (EAGLE-1102) Integrate CVE maven plugin

2019-10-05 Thread Grainier Perera (Jira)


[ 
https://issues.apache.org/jira/browse/EAGLE-1102?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16945247#comment-16945247
 ] 

Grainier Perera commented on EAGLE-1102:


Please find the 
[dependency-check-report.html|https://issues.apache.org/jira/secure/attachment/12982206/dependency-check-report.html]
 attached in parent Jira issue;

> Integrate CVE maven plugin
> --
>
> Key: EAGLE-1102
> URL: https://issues.apache.org/jira/browse/EAGLE-1102
> Project: Eagle
>  Issue Type: Sub-task
>Affects Versions: v0.5.0
>Reporter: Grainier Perera
>Assignee: Grainier Perera
>Priority: Critical
>  Labels: security
>  Time Spent: 0.5h
>  Remaining Estimate: 0h
>
> Integrate the CVE maven plugin [1] for eagle to check security during build 
> time. This will help to detect publicly disclosed vulnerabilities contained 
> within eagle's dependencies.
> [1] https://github.com/jeremylong/DependencyCheck



--
This message was sent by Atlassian Jira
(v8.3.4#803005)


[jira] [Commented] (EAGLE-1102) Integrate CVE maven plugin

2019-10-04 Thread Grainier Perera (Jira)


[ 
https://issues.apache.org/jira/browse/EAGLE-1102?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=16944321#comment-16944321
 ] 

Grainier Perera commented on EAGLE-1102:


[~haoch], [~jhsenjaliya],

I sent this PR [1] to fix the same; Please review and merge.

[1] [https://github.com/apache/eagle/pull/1005]

Thanks

> Integrate CVE maven plugin
> --
>
> Key: EAGLE-1102
> URL: https://issues.apache.org/jira/browse/EAGLE-1102
> Project: Eagle
>  Issue Type: Sub-task
>Affects Versions: v0.5.0
>Reporter: Grainier Perera
>Assignee: Grainier Perera
>Priority: Critical
>  Labels: security
>  Time Spent: 10m
>  Remaining Estimate: 0h
>
> Integrate the CVE maven plugin [1] for eagle to check security during build 
> time. This will help to detect publicly disclosed vulnerabilities contained 
> within eagle's dependencies.
> [1] https://github.com/jeremylong/DependencyCheck



--
This message was sent by Atlassian Jira
(v8.3.4#803005)