jenkinsci / dependency-check-plugin
Jenkins plugin for OWASP Dependency-Check. Inspects project components for known vulnerabilities (e.g. CVEs).
☆134Updated this week
Alternatives and similar repositories for dependency-check-plugin:
Users that are interested in dependency-check-plugin are comparing it to the libraries listed below
- A simple Java command-line utility to mirror the CVE JSON data from NIST.☆207Updated 2 years ago
- Integrates Dependency-Check reports into SonarQube☆631Updated this week
- Integrates OWASP Zed Attack Proxy reports into SonarQube☆70Updated last year
- Creates CycloneDX Software Bill of Materials (SBOM) from Maven projects☆310Updated this week
- This plugin adds an ability to perform automatic code scan by Checkmarx server and shows results summary and trend in Jenkins interface.☆42Updated this week
- Maven plugin that integrates with a Dependency Track server to submit dependency manifests and optionally fail execution when vulnerable …☆68Updated 2 months ago
- SpotBugs plugin for SonarQube☆359Updated last week
- A cli that can be used to query various online vulnerability sources such as the NVD or GHSA. The CLI and docker images can be used to mi…☆139Updated 2 weeks ago
- Checkmarx Scan and Result Orchestration☆91Updated last week
- CycloneDX SBOM Model and Utils for Creating and Validating BOMs☆86Updated this week
- Allows Jenkins admins to control what in-process scripts can be run by users☆68Updated last week
- SonarQube Licensecheck Plugin☆163Updated this week
- Test and monitor your projects for vulnerabilities with Maven. This plugin is officially maintained by Snyk.☆79Updated 6 months ago
- CycloneDX CLI tool for SBOM analysis, merging, diffs and format conversions.☆337Updated 3 months ago
- Evaluation Framework for Dependency Analysis (EFDA)☆43Updated 2 years ago
- A rule for the Maven enforcer plugin to check for vulnerable artifacts within a project.☆40Updated 4 years ago
- An opinionated scaffolding framework that jumpstarts Java projects with an API-first design, secure defaults, and minimal dependencies☆62Updated this week
- Code Smells plugin for SonarQube and companion Java library☆49Updated 7 years ago
- ThreadFix is a software vulnerability management platform. This GitHub site is far out of date. Please go to www.threadfix.it for up-to-d…☆339Updated 2 years ago
- Java Agent which mitigates deserialisation attacks by making certain classes unserializable☆189Updated 8 years ago
- Container Security Verification Standard☆58Updated 5 years ago
- Integrates Xanitizer results into SonarQube☆21Updated 3 years ago
- SonarQube Scanner for Jenkins☆182Updated this week
- Build Breaker Plugin for SonarQube☆93Updated 3 years ago
- SonarQube Scanner for Maven☆150Updated this week
- Common Java library used by many SonarScanners☆113Updated 2 weeks ago
- ZAP Java API☆47Updated last month
- Simple command-line client to the Anchore Engine service☆114Updated 7 months ago
- ☆60Updated this week
- Command line tool to migrate MySQL database of SonarQube 6.7-7.8 to non-MySQL☆39Updated 3 years ago