Announcing OSSIndex plugins for Apache Maven: Scan your dependencies for known vulnerabilities

2018-07-25 Thread Brian Fox
You probably know Sonatype for our work in the Maven community, Nexus Repository Manager, and for hosting Central. You may not know that for the last 7 years we've also been leading the way in solutions that allow developers to innovate faster and be able to improve security, license compliance and

Re: Announcing OSSIndex plugins for Apache Maven: Scan your dependencies for known vulnerabilities

2018-07-25 Thread Mark Derricutt
On 26 Jul 2018, at 12:55, Brian Fox wrote: > Find the Maven Plugin docs here: > https://sonatype.github.io/ossindex-maven/maven-plugin/ This looks awesome! One nit pick tho - the XML plugin definition has a bad `` on the `` line. Will be interesting to see how the results compare to the OWASP d

Re: Announcing OSSIndex plugins for Apache Maven: Scan your dependencies for known vulnerabilities

2018-07-25 Thread Brian Fox
--mobile > On Jul 25, 2018, at 9:24 PM, Mark Derricutt wrote: > > On 26 Jul 2018, at 12:55, Brian Fox wrote: > > Find the Maven Plugin docs here: > https://sonatype.github.io/ossindex-maven/maven-plugin/ > > This looks awesome! One nit pick tho - the XML plugin definition has a bad > on th

Re: Announcing OSSIndex plugins for Apache Maven: Scan your dependencies for known vulnerabilities

2018-07-25 Thread Matthieu BROUILLARD
Excellent enhancement ; thank you Brian & Sonatype. > Report issues or ideas here: > https://github.com/sonatype/ossindex-maven/issues As requested I submitted my feedback as an RFE ( https://github.com/sonatype/ossindex-maven/issues/10) to report possible fixes on the vulnerabilities. Regards,