Usage
Dependency-check-maven is very simple to utilize and can be used as a stand-alone plug-in or as part of the site plug-in. The plug-in requires Maven 3.1 or higher.
It is important to understand that the first time this task is executed it may take 20 minutes or more as it downloads and processes the data from the National Vulnerability Database (NVD) hosted by NIST: https://nvd.nist.gov
After the first batch download, as long as the plug-in is executed at least once every seven days the update will only take a few seconds.
The dependency-check plugin is, by default, tied to the verify
or site
phase
depending on if it is configured as a build or reporting plugin. The examples
below can be executed using mvn verify
or in the reporting example mvn site
.