This OWASP dependency check image (ngacareer/owasp-dependency-check) is based on the minimal Alpine Linux. Software Composition Analysis (SCA) tool that attempts to detect publicly disclosed vulnerabilities contained within a project's dependencies. It does this by determining if there is a Common Platform Enumeration (CPE) identifier for a given dependency.
Documentation and links to production binary releases can be found on the github pages. Additionally, more information about the architecture and ways to extend dependency-check can be found on the [wiki].
OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies. If upgrading to 6.0.0 or higher, there were breaking changes. If you get an error indicating you can't connect to the database you will need to run the purge command to remove the old database:
./gradlew dependencyCheckPurgemvn org.owasp:dependency-check-maven:6.0.0:purgedependency-check.sh --purgeHomebrew users upgrading to dependency-check 6.0.0 will need to purge their old database.
:amd64, :x86_64 - 64 bit Intel/AMD (x86_64/amd64):latest master branch usually inline with latest:6.1.5 current versioncurrent folder of project, user root, all reports storage in report folder
#pwd
#mkdir -p OWASP-Dependency-Check/data
#mkdir -p odc-reports
docker run --rm \
-e user=root \
-u $(id -u root):$(id -g root) \
--volume $(pwd):/src:z \
--volume $(pwd)/OWASP-Dependency-Check/data:/usr/share/dependency-check/data:z \
--volume $(pwd)/odc-reports:/report:z \
ngacareer/owasp-dependency-check:6.1.5 \
--scan /src \
--format "ALL" \
--project dependency-check scan: $(pwd) \
--out /
[INFO] Analysis Started
[INFO] Finished Archive Analyzer (0 seconds)
[INFO] Finished File Name Analyzer (0 seconds)
[INFO] Finished Jar Analyzer (0 seconds)
[INFO] Finished Central Analyzer (91 seconds)
[INFO] Finished Dependency Merging Analyzer (0 seconds)
[INFO] Finished Version Filter Analyzer (0 seconds)
[INFO] Finished Hint Analyzer (0 seconds)
[INFO] Created CPE Index (2 seconds)
[INFO] Finished CPE Analyzer (3 seconds)
[INFO] Finished False Positive Analyzer (0 seconds)
[INFO] Finished NVD CVE Analyzer (0 seconds)
[INFO] Finished Sonatype OSS Index Analyzer (1 seconds)
[INFO] Finished Vulnerability Suppression Analyzer (0 seconds)
[INFO] Finished Dependency Bundling Analyzer (0 seconds)
[INFO] Analysis Complete (98 seconds)
[INFO] Writing report to: /report/dependency-check-report.xml
[INFO] Writing report to: /report/dependency-check-report.html
[INFO] Writing report to: /report/dependency-check-report.json
[INFO] Writing report to: /report/dependency-check-report.csv
[INFO] Writing report to: /report/dependency-check-report.sarif
[INFO] Writing report to: /report/dependency-check-junit.xml
.........
.......
....
..
.
| PACKAGE NAME | PACKAGE VERSION | VULNERABILITIES |
|---|
Content type
Image
Digest
Size
259.9 MB
Last updated
over 5 years ago
docker pull ngacareer/owasp-dependency-check