1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18 package org.owasp.dependencycheck.taskdefs;
19
20 import java.io.File;
21 import java.util.ArrayList;
22 import java.util.List;
23 import javax.annotation.concurrent.NotThreadSafe;
24
25 import org.apache.tools.ant.BuildException;
26 import org.apache.tools.ant.Project;
27 import org.apache.tools.ant.types.EnumeratedAttribute;
28 import org.apache.tools.ant.types.Reference;
29 import org.apache.tools.ant.types.Resource;
30 import org.apache.tools.ant.types.ResourceCollection;
31 import org.apache.tools.ant.types.resources.FileProvider;
32 import org.apache.tools.ant.types.resources.Resources;
33 import org.owasp.dependencycheck.Engine;
34 import org.owasp.dependencycheck.agent.DependencyCheckScanAgent;
35 import org.owasp.dependencycheck.data.nvdcve.DatabaseException;
36 import org.owasp.dependencycheck.dependency.Dependency;
37 import org.owasp.dependencycheck.dependency.Vulnerability;
38 import org.owasp.dependencycheck.exception.ExceptionCollection;
39 import org.owasp.dependencycheck.exception.ReportException;
40 import org.owasp.dependencycheck.reporting.ReportGenerator.Format;
41 import org.owasp.dependencycheck.utils.Downloader;
42 import org.owasp.dependencycheck.utils.InvalidSettingException;
43 import org.owasp.dependencycheck.utils.Settings;
44 import org.owasp.dependencycheck.utils.SeverityUtil;
45 import org.slf4j.impl.StaticLoggerBinder;
46
47
48
49
50
51
52
53 @NotThreadSafe
54 public class Check extends Update {
55
56
57
58
59 private static final String NEW_LINE = System.getProperty("line.separator", "\n").intern();
60
61
62
63
64 private Boolean rubygemsAnalyzerEnabled;
65
66
67
68 private Boolean nodeAnalyzerEnabled;
69
70
71
72 private Boolean nodeAuditAnalyzerEnabled;
73
74
75
76 private Boolean yarnAuditAnalyzerEnabled;
77
78
79
80 private Boolean pnpmAuditAnalyzerEnabled;
81
82
83
84 private Boolean nodeAuditAnalyzerUseCache;
85
86
87
88
89 private Boolean nodePackageSkipDevDependencies;
90
91
92
93 private Boolean nodeAuditSkipDevDependencies;
94
95
96
97 private Boolean retireJsAnalyzerEnabled;
98
99
100
101 private String retireJsUrl;
102
103
104
105 private String retireJsUrlUser;
106
107
108
109 private String retireJsUrlPassword;
110
111
112
113
114 private Boolean retireJsAnalyzerForceUpdate;
115
116
117
118
119 @SuppressWarnings("CanBeFinal")
120 private final List<String> retirejsFilters = new ArrayList<>();
121
122
123
124
125 private Boolean retirejsFilterNonVulnerable;
126
127
128
129 private Boolean bundleAuditAnalyzerEnabled;
130
131
132
133 private Boolean cmakeAnalyzerEnabled;
134
135
136
137 private Boolean opensslAnalyzerEnabled;
138
139
140
141 private Boolean pyPackageAnalyzerEnabled;
142
143
144
145 private Boolean pyDistributionAnalyzerEnabled;
146
147
148
149 private Boolean mixAuditAnalyzerEnabled;
150
151
152
153 private Boolean centralAnalyzerEnabled;
154
155
156
157 private Boolean centralAnalyzerUseCache;
158
159
160
161 private Boolean nexusAnalyzerEnabled;
162
163
164
165
166 private String nexusUrl;
167
168
169
170 private String nexusUser;
171
172
173
174 private String nexusPassword;
175
176
177
178 private Boolean nexusUsesProxy;
179
180
181
182
183 private Boolean golangDepEnabled;
184
185
186
187
188 private Boolean golangModEnabled;
189
190
191
192 private String pathToGo;
193
194
195
196 private Boolean dartAnalyzerEnabled;
197
198
199
200 private String pathToYarn;
201
202
203
204 private String pathToPnpm;
205
206
207
208
209 private String zipExtensions;
210
211
212
213 private String pathToCore;
214
215
216
217 private String projectName = "dependency-check";
218
219
220
221
222 private String reportOutputDirectory = ".";
223
224
225
226
227 private float junitFailOnCVSS = 0;
228
229
230
231
232
233
234
235 private float failBuildOnCVSS = 11;
236
237
238
239
240 private Boolean autoUpdate;
241
242
243
244
245 private String reportFormat = "HTML";
246
247
248
249
250 private final List<String> reportFormats = new ArrayList<>();
251
252
253
254
255 private Boolean prettyPrint = null;
256
257
258
259
260 @SuppressWarnings("CanBeFinal")
261 private final List<String> suppressionFiles = new ArrayList<>();
262
263
264
265
266 private String hintsFile;
267
268
269
270 private boolean showSummary = true;
271
272
273
274 private Boolean enableExperimental;
275
276
277
278 private Boolean enableRetired;
279
280
281
282 private Boolean jarAnalyzerEnabled;
283
284
285
286 private Boolean archiveAnalyzerEnabled;
287
288
289
290 private Boolean knownExploitedEnabled;
291
292
293
294 private String knownExploitedUrl;
295
296
297
298 private Boolean nuspecAnalyzerEnabled;
299
300
301
302 private Boolean nugetconfAnalyzerEnabled;
303
304
305
306 private Boolean libmanAnalyzerEnabled;
307
308
309
310 private Boolean composerAnalyzerEnabled;
311
312
313
314 private Boolean composerAnalyzerSkipDev;
315
316
317
318 private Boolean cpanfileAnalyzerEnabled;
319
320
321
322
323 private Boolean assemblyAnalyzerEnabled;
324
325
326
327 private Boolean msbuildAnalyzerEnabled;
328
329
330
331 private Boolean autoconfAnalyzerEnabled;
332
333
334
335 private Boolean pipAnalyzerEnabled;
336
337
338
339 private Boolean mavenInstallAnalyzerEnabled;
340
341
342
343 private Boolean pipfileAnalyzerEnabled;
344
345
346
347 private Boolean poetryAnalyzerEnabled;
348
349
350
351 private String mixAuditPath;
352
353
354
355 private String bundleAuditPath;
356
357
358
359
360 private String bundleAuditWorkingDirectory;
361
362
363
364 private Boolean cocoapodsAnalyzerEnabled;
365
366
367
368 private Boolean carthageAnalyzerEnabled;
369
370
371
372
373 private Boolean swiftPackageManagerAnalyzerEnabled;
374
375
376
377 private Boolean swiftPackageResolvedAnalyzerEnabled;
378
379
380
381
382 private Boolean ossindexAnalyzerEnabled;
383
384
385
386 private Boolean ossindexAnalyzerUseCache;
387
388
389
390 private String ossindexAnalyzerUrl;
391
392
393
394 private String ossindexAnalyzerUsername;
395
396
397
398 private String ossindexAnalyzerPassword;
399
400
401
402
403 private Boolean ossIndexAnalyzerWarnOnlyOnRemoteErrors;
404
405
406
407
408 private Boolean artifactoryAnalyzerEnabled;
409
410
411
412 private String artifactoryAnalyzerUrl;
413
414
415
416 private Boolean artifactoryAnalyzerUseProxy;
417
418
419
420 private Boolean artifactoryAnalyzerParallelAnalysis;
421
422
423
424 private String artifactoryAnalyzerUsername;
425
426
427
428 private String artifactoryAnalyzerApiToken;
429
430
431
432 private String artifactoryAnalyzerBearerToken;
433
434
435
436
437
438
439 private Resources path = null;
440
441
442
443 private Reference refId = null;
444
445
446
447
448
449
450
451 public void add(ResourceCollection rc) {
452 if (isReference()) {
453 throw new BuildException("Nested elements are not allowed when using the refId attribute.");
454 }
455 getPath().add(rc);
456 }
457
458
459
460
461
462
463
464
465 public void addConfiguredSuppressionFile(final SuppressionFile suppressionFile) {
466 suppressionFiles.add(suppressionFile.getPath());
467 }
468
469
470
471
472
473
474
475
476 public void addConfiguredReportFormat(final ReportFormat reportFormat) {
477 reportFormats.add(reportFormat.getFormat());
478 }
479
480
481
482
483
484
485
486 private synchronized Resources getPath() {
487 if (path == null) {
488 path = new Resources(getProject());
489 path.setCache(true);
490 }
491 return path;
492 }
493
494
495
496
497
498
499 public boolean isReference() {
500 return refId != null;
501 }
502
503
504
505
506
507
508
509 public synchronized void setRefId(Reference r) {
510 if (path != null) {
511 throw new BuildException("Nested elements are not allowed when using the refId attribute.");
512 }
513 refId = r;
514 }
515
516
517
518
519
520
521
522
523
524
525 @SuppressWarnings("squid:RedundantThrowsDeclarationCheck")
526 private void dealWithReferences() throws BuildException {
527 if (isReference()) {
528 final Object o = refId.getReferencedObject(getProject());
529 if (!(o instanceof ResourceCollection)) {
530 throw new BuildException("refId '" + refId.getRefId()
531 + "' does not refer to a resource collection.");
532 }
533 getPath().add((ResourceCollection) o);
534 }
535 }
536
537
538
539
540
541 public Check() {
542 super();
543
544
545 StaticLoggerBinder.getSingleton().setTask(this);
546 }
547
548
549
550
551
552
553 public String getProjectName() {
554 if (projectName == null) {
555 projectName = "";
556 }
557 return projectName;
558 }
559
560
561
562
563
564
565 public void setProjectName(String projectName) {
566 this.projectName = projectName;
567 }
568
569
570
571
572
573
574 public String getReportOutputDirectory() {
575 return reportOutputDirectory;
576 }
577
578
579
580
581
582
583 public void setReportOutputDirectory(String reportOutputDirectory) {
584 this.reportOutputDirectory = reportOutputDirectory;
585 }
586
587
588
589
590
591
592 public float getFailBuildOnCVSS() {
593 return failBuildOnCVSS;
594 }
595
596
597
598
599
600
601 public void setFailBuildOnCVSS(float failBuildOnCVSS) {
602 this.failBuildOnCVSS = failBuildOnCVSS;
603 }
604
605
606
607
608
609
610 public float getJunitFailOnCVSS() {
611 return junitFailOnCVSS;
612 }
613
614
615
616
617
618
619 public void setJunitFailOnCVSS(float junitFailOnCVSS) {
620 this.junitFailOnCVSS = junitFailOnCVSS;
621 }
622
623
624
625
626
627
628 public Boolean isAutoUpdate() {
629 return autoUpdate;
630 }
631
632
633
634
635
636
637 public void setAutoUpdate(Boolean autoUpdate) {
638 this.autoUpdate = autoUpdate;
639 }
640
641
642
643
644
645
646 public Boolean isPrettyPrint() {
647 return prettyPrint;
648 }
649
650
651
652
653
654
655 public void setPrettyPrint(boolean prettyPrint) {
656 this.prettyPrint = prettyPrint;
657 }
658
659
660
661
662
663
664 public void setReportFormat(ReportFormats reportFormat) {
665 this.reportFormat = reportFormat.getValue();
666 this.reportFormats.add(this.reportFormat);
667 }
668
669
670
671
672
673
674 public List<String> getReportFormats() {
675 if (reportFormats.isEmpty()) {
676 this.reportFormats.add(this.reportFormat);
677 }
678 return this.reportFormats;
679 }
680
681
682
683
684
685
686 public List<String> getSuppressionFiles() {
687 return suppressionFiles;
688 }
689
690
691
692
693
694
695 public void setSuppressionFile(String suppressionFile) {
696 suppressionFiles.add(suppressionFile);
697 }
698
699
700
701
702
703
704 public String getHintsFile() {
705 return hintsFile;
706 }
707
708
709
710
711
712
713 public void setHintsFile(String hintsFile) {
714 this.hintsFile = hintsFile;
715 }
716
717
718
719
720
721
722 public boolean isShowSummary() {
723 return showSummary;
724 }
725
726
727
728
729
730
731 public void setShowSummary(boolean showSummary) {
732 this.showSummary = showSummary;
733 }
734
735
736
737
738
739
740 public Boolean isEnableExperimental() {
741 return enableExperimental;
742 }
743
744
745
746
747
748
749 public void setEnableExperimental(Boolean enableExperimental) {
750 this.enableExperimental = enableExperimental;
751 }
752
753
754
755
756
757
758 public Boolean isEnableRetired() {
759 return enableRetired;
760 }
761
762
763
764
765
766
767 public void setEnableRetired(Boolean enableRetired) {
768 this.enableRetired = enableRetired;
769 }
770
771
772
773
774
775
776 public Boolean isJarAnalyzerEnabled() {
777 return jarAnalyzerEnabled;
778 }
779
780
781
782
783
784
785 public void setJarAnalyzerEnabled(Boolean jarAnalyzerEnabled) {
786 this.jarAnalyzerEnabled = jarAnalyzerEnabled;
787 }
788
789
790
791
792
793
794 public Boolean isArchiveAnalyzerEnabled() {
795 return archiveAnalyzerEnabled;
796 }
797
798
799
800
801
802
803 public void setArchiveAnalyzerEnabled(Boolean archiveAnalyzerEnabled) {
804 this.archiveAnalyzerEnabled = archiveAnalyzerEnabled;
805 }
806
807
808
809
810
811
812 public Boolean isKnownExploitedEnabled() {
813 return knownExploitedEnabled;
814 }
815
816
817
818
819
820
821 public void setKnownExploitedEnabled(Boolean knownExploitedEnabled) {
822 this.knownExploitedEnabled = knownExploitedEnabled;
823 }
824
825
826
827
828
829
830 public String getKnownExploitedUrl() {
831 return knownExploitedUrl;
832 }
833
834
835
836
837
838
839 public void setKnownExploitedUrl(String knownExploitedUrl) {
840 this.knownExploitedUrl = knownExploitedUrl;
841 }
842
843
844
845
846
847
848 public Boolean isAssemblyAnalyzerEnabled() {
849 return assemblyAnalyzerEnabled;
850 }
851
852
853
854
855
856
857 public void setAssemblyAnalyzerEnabled(Boolean assemblyAnalyzerEnabled) {
858 this.assemblyAnalyzerEnabled = assemblyAnalyzerEnabled;
859 }
860
861
862
863
864
865
866 public Boolean isMSBuildAnalyzerEnabled() {
867 return msbuildAnalyzerEnabled;
868 }
869
870
871
872
873
874
875 public void setMSBuildAnalyzerEnabled(Boolean msbuildAnalyzerEnabled) {
876 this.msbuildAnalyzerEnabled = msbuildAnalyzerEnabled;
877 }
878
879
880
881
882
883
884 public Boolean isNuspecAnalyzerEnabled() {
885 return nuspecAnalyzerEnabled;
886 }
887
888
889
890
891
892
893 public Boolean isNugetconfAnalyzerEnabled() {
894 return nugetconfAnalyzerEnabled;
895 }
896
897
898
899
900
901
902 public void setNuspecAnalyzerEnabled(Boolean nuspecAnalyzerEnabled) {
903 this.nuspecAnalyzerEnabled = nuspecAnalyzerEnabled;
904 }
905
906
907
908
909
910
911 public void setNugetconfAnalyzerEnabled(Boolean nugetconfAnalyzerEnabled) {
912 this.nugetconfAnalyzerEnabled = nugetconfAnalyzerEnabled;
913 }
914
915
916
917
918
919
920 public Boolean isLibmanAnalyzerEnabled() {
921 return libmanAnalyzerEnabled;
922 }
923
924
925
926
927
928
929 public void setLibmanAnalyzerEnabled(Boolean libmanAnalyzerEnabled) {
930 this.libmanAnalyzerEnabled = libmanAnalyzerEnabled;
931 }
932
933
934
935
936
937
938 public Boolean isComposerAnalyzerEnabled() {
939 return composerAnalyzerEnabled;
940 }
941
942
943
944
945
946
947 public void setComposerAnalyzerEnabled(Boolean composerAnalyzerEnabled) {
948 this.composerAnalyzerEnabled = composerAnalyzerEnabled;
949 }
950
951
952
953
954
955
956 public Boolean isComposerAnalyzerSkipDev() {
957 return composerAnalyzerSkipDev;
958 }
959
960
961
962
963
964
965 public void setComposerAnalyzerSkipDev(Boolean composerAnalyzerSkipDev) {
966 this.composerAnalyzerSkipDev = composerAnalyzerSkipDev;
967 }
968
969
970
971
972
973
974 public Boolean isCpanfileAnalyzerEnabled() {
975 return cpanfileAnalyzerEnabled;
976 }
977
978
979
980
981
982
983 public void setCpanfileAnalyzerEnabled(Boolean cpanfileAnalyzerEnabled) {
984 this.cpanfileAnalyzerEnabled = cpanfileAnalyzerEnabled;
985 }
986
987
988
989
990
991
992 public Boolean isAutoconfAnalyzerEnabled() {
993 return autoconfAnalyzerEnabled;
994 }
995
996
997
998
999
1000
1001 public void setAutoconfAnalyzerEnabled(Boolean autoconfAnalyzerEnabled) {
1002 this.autoconfAnalyzerEnabled = autoconfAnalyzerEnabled;
1003 }
1004
1005
1006
1007
1008
1009
1010 public Boolean isPipAnalyzerEnabled() {
1011 return pipAnalyzerEnabled;
1012 }
1013
1014
1015
1016
1017
1018
1019 public void setPipAnalyzerEnabled(Boolean pipAnalyzerEnabled) {
1020 this.pipAnalyzerEnabled = pipAnalyzerEnabled;
1021 }
1022
1023
1024
1025
1026
1027
1028 public Boolean isPipfileAnalyzerEnabled() {
1029 return pipfileAnalyzerEnabled;
1030 }
1031
1032
1033
1034
1035
1036
1037 public void setPipfileAnalyzerEnabled(Boolean pipfileAnalyzerEnabled) {
1038 this.pipfileAnalyzerEnabled = pipfileAnalyzerEnabled;
1039 }
1040
1041
1042
1043
1044
1045
1046 public Boolean isPoetryAnalyzerEnabled() {
1047 return poetryAnalyzerEnabled;
1048 }
1049
1050
1051
1052
1053
1054
1055 public void setPoetryAnalyzerEnabled(Boolean poetryAnalyzerEnabled) {
1056 this.poetryAnalyzerEnabled = poetryAnalyzerEnabled;
1057 }
1058
1059
1060
1061
1062
1063
1064 public Boolean isBundleAuditAnalyzerEnabled() {
1065 return bundleAuditAnalyzerEnabled;
1066 }
1067
1068
1069
1070
1071
1072
1073
1074 public void setBundleAuditAnalyzerEnabled(Boolean bundleAuditAnalyzerEnabled) {
1075 this.bundleAuditAnalyzerEnabled = bundleAuditAnalyzerEnabled;
1076 }
1077
1078
1079
1080
1081
1082
1083 public String getBundleAuditPath() {
1084 return bundleAuditPath;
1085 }
1086
1087
1088
1089
1090
1091
1092 public void setBundleAuditPath(String bundleAuditPath) {
1093 this.bundleAuditPath = bundleAuditPath;
1094 }
1095
1096
1097
1098
1099
1100
1101
1102
1103 public void setBundleAuditWorkingDirectory(String bundleAuditWorkingDirectory) {
1104 this.bundleAuditWorkingDirectory = bundleAuditWorkingDirectory;
1105 }
1106
1107
1108
1109
1110
1111
1112
1113
1114 public String getBundleAuditWorkingDirectory() {
1115 return bundleAuditWorkingDirectory;
1116 }
1117
1118
1119
1120
1121
1122
1123 public boolean isCocoapodsAnalyzerEnabled() {
1124 return cocoapodsAnalyzerEnabled;
1125 }
1126
1127
1128
1129
1130
1131
1132 public void setCocoapodsAnalyzerEnabled(Boolean cocoapodsAnalyzerEnabled) {
1133 this.cocoapodsAnalyzerEnabled = cocoapodsAnalyzerEnabled;
1134 }
1135
1136
1137
1138
1139
1140
1141 public boolean isCarthageAnalyzerEnabled() {
1142 return carthageAnalyzerEnabled;
1143 }
1144
1145
1146
1147
1148
1149
1150 public void setCarthageAnalyzerEnabled(Boolean carthageAnalyzerEnabled) {
1151 this.carthageAnalyzerEnabled = carthageAnalyzerEnabled;
1152 }
1153
1154
1155
1156
1157
1158
1159 public Boolean isSwiftPackageManagerAnalyzerEnabled() {
1160 return swiftPackageManagerAnalyzerEnabled;
1161 }
1162
1163
1164
1165
1166
1167
1168
1169 public void setSwiftPackageManagerAnalyzerEnabled(Boolean swiftPackageManagerAnalyzerEnabled) {
1170 this.swiftPackageManagerAnalyzerEnabled = swiftPackageManagerAnalyzerEnabled;
1171 }
1172
1173
1174
1175
1176
1177
1178 public Boolean isSwiftPackageResolvedAnalyzerEnabled() {
1179 return swiftPackageResolvedAnalyzerEnabled;
1180 }
1181
1182
1183
1184
1185
1186
1187
1188 public void setSwiftPackageResolvedAnalyzerEnabled(Boolean swiftPackageResolvedAnalyzerEnabled) {
1189 this.swiftPackageResolvedAnalyzerEnabled = swiftPackageResolvedAnalyzerEnabled;
1190 }
1191
1192
1193
1194
1195
1196
1197 public Boolean isOpensslAnalyzerEnabled() {
1198 return opensslAnalyzerEnabled;
1199 }
1200
1201
1202
1203
1204
1205
1206 public void setOpensslAnalyzerEnabled(Boolean opensslAnalyzerEnabled) {
1207 this.opensslAnalyzerEnabled = opensslAnalyzerEnabled;
1208 }
1209
1210
1211
1212
1213
1214
1215 public Boolean isNodeAnalyzerEnabled() {
1216 return nodeAnalyzerEnabled;
1217 }
1218
1219
1220
1221
1222
1223
1224 public void setNodeAnalyzerEnabled(Boolean nodeAnalyzerEnabled) {
1225 this.nodeAnalyzerEnabled = nodeAnalyzerEnabled;
1226 }
1227
1228
1229
1230
1231
1232
1233 public Boolean isNodeAuditAnalyzerEnabled() {
1234 return nodeAuditAnalyzerEnabled;
1235 }
1236
1237
1238
1239
1240
1241
1242 public void setNodeAuditAnalyzerEnabled(Boolean nodeAuditAnalyzerEnabled) {
1243 this.nodeAuditAnalyzerEnabled = nodeAuditAnalyzerEnabled;
1244 }
1245
1246
1247
1248
1249
1250
1251 public Boolean isYarnAuditAnalyzerEnabled() {
1252 return yarnAuditAnalyzerEnabled;
1253 }
1254
1255
1256
1257
1258
1259
1260 public void setYarnAuditAnalyzerEnabled(Boolean yarnAuditAnalyzerEnabled) {
1261 this.yarnAuditAnalyzerEnabled = yarnAuditAnalyzerEnabled;
1262 }
1263
1264
1265
1266
1267
1268
1269 public Boolean isPnpmAuditAnalyzerEnabled() {
1270 return pnpmAuditAnalyzerEnabled;
1271 }
1272
1273
1274
1275
1276
1277
1278 public void setPnpmAuditAnalyzerEnabled(Boolean pnpmAuditAnalyzerEnabled) {
1279 this.pnpmAuditAnalyzerEnabled = pnpmAuditAnalyzerEnabled;
1280 }
1281
1282
1283
1284
1285
1286
1287 public Boolean isNodeAuditAnalyzerUseCache() {
1288 return nodeAuditAnalyzerUseCache;
1289 }
1290
1291
1292
1293
1294
1295
1296 public void setNodeAuditAnalyzerUseCache(Boolean nodeAuditAnalyzerUseCache) {
1297 this.nodeAuditAnalyzerUseCache = nodeAuditAnalyzerUseCache;
1298 }
1299
1300
1301
1302
1303
1304
1305 public Boolean isNodePackageAnalyzerSkipDevDependencies() {
1306 return nodePackageSkipDevDependencies;
1307 }
1308
1309
1310
1311
1312
1313
1314
1315 public void setNodePackageSkipDevDependencies(Boolean nodePackageSkipDevDependencies) {
1316 this.nodePackageSkipDevDependencies = nodePackageSkipDevDependencies;
1317 }
1318
1319
1320
1321
1322
1323
1324 public Boolean isNodeAuditAnalyzerSkipDevDependencies() {
1325 return nodeAuditSkipDevDependencies;
1326 }
1327
1328
1329
1330
1331
1332
1333
1334 public void setNodeAuditSkipDevDependencies(Boolean nodeAuditSkipDevDependencies) {
1335 this.nodeAuditSkipDevDependencies = nodeAuditSkipDevDependencies;
1336 }
1337
1338
1339
1340
1341
1342
1343 public Boolean isRetireJsAnalyzerEnabled() {
1344 return retireJsAnalyzerEnabled;
1345 }
1346
1347
1348
1349
1350
1351
1352 public void setRetireJsAnalyzerEnabled(Boolean retireJsAnalyzerEnabled) {
1353 this.retireJsAnalyzerEnabled = retireJsAnalyzerEnabled;
1354 }
1355
1356
1357
1358
1359
1360
1361 public String getRetireJsUrl() {
1362 return retireJsUrl;
1363 }
1364
1365
1366
1367
1368
1369
1370 public void setRetireJsUrl(String retireJsUrl) {
1371 this.retireJsUrl = retireJsUrl;
1372 }
1373
1374
1375
1376
1377
1378
1379 public String getRetireJsUrlUser() {
1380 return retireJsUrlUser;
1381 }
1382
1383
1384
1385
1386
1387
1388 public void setRetireJsUrlUser(String retireJsUrlUser) {
1389 this.retireJsUrlUser = retireJsUrlUser;
1390 }
1391
1392
1393
1394
1395
1396
1397 public String getRetireJsUrlPassword() {
1398 return retireJsUrlPassword;
1399 }
1400
1401
1402
1403
1404
1405
1406 public void setRetireJsUrlPassword(String retireJsUrlPassword) {
1407 this.retireJsUrlPassword = retireJsUrlPassword;
1408 }
1409
1410
1411
1412
1413
1414
1415 public Boolean isRetireJsAnalyzerForceUpdate() {
1416 return retireJsAnalyzerForceUpdate;
1417 }
1418
1419
1420
1421
1422
1423
1424
1425 public void setRetireJsAnalyzerForceUpdate(Boolean retireJsAnalyzerForceUpdate) {
1426 this.retireJsAnalyzerForceUpdate = retireJsAnalyzerForceUpdate;
1427 }
1428
1429
1430
1431
1432
1433
1434 public Boolean isRetirejsFilterNonVulnerable() {
1435 return retirejsFilterNonVulnerable;
1436 }
1437
1438
1439
1440
1441
1442
1443
1444 public void setRetirejsFilterNonVulnerable(Boolean retirejsFilterNonVulnerable) {
1445 this.retirejsFilterNonVulnerable = retirejsFilterNonVulnerable;
1446 }
1447
1448
1449
1450
1451
1452
1453 public List<String> getRetirejsFilters() {
1454 return retirejsFilters;
1455 }
1456
1457
1458
1459
1460
1461
1462
1463
1464
1465 public void addConfiguredRetirejsFilter(final RetirejsFilter retirejsFilter) {
1466 retirejsFilters.add(retirejsFilter.getRegex());
1467 }
1468
1469
1470
1471
1472
1473
1474 public Boolean isRubygemsAnalyzerEnabled() {
1475 return rubygemsAnalyzerEnabled;
1476 }
1477
1478
1479
1480
1481
1482
1483 public void setRubygemsAnalyzerEnabled(Boolean rubygemsAnalyzerEnabled) {
1484 this.rubygemsAnalyzerEnabled = rubygemsAnalyzerEnabled;
1485 }
1486
1487
1488
1489
1490
1491
1492 public Boolean isPyPackageAnalyzerEnabled() {
1493 return pyPackageAnalyzerEnabled;
1494 }
1495
1496
1497
1498
1499
1500
1501 public void setPyPackageAnalyzerEnabled(Boolean pyPackageAnalyzerEnabled) {
1502 this.pyPackageAnalyzerEnabled = pyPackageAnalyzerEnabled;
1503 }
1504
1505
1506
1507
1508
1509
1510 public Boolean isPyDistributionAnalyzerEnabled() {
1511 return pyDistributionAnalyzerEnabled;
1512 }
1513
1514
1515
1516
1517
1518
1519
1520 public void setPyDistributionAnalyzerEnabled(Boolean pyDistributionAnalyzerEnabled) {
1521 this.pyDistributionAnalyzerEnabled = pyDistributionAnalyzerEnabled;
1522 }
1523
1524
1525
1526
1527
1528
1529 public Boolean getMixAuditAnalyzerEnabled() {
1530 return mixAuditAnalyzerEnabled;
1531 }
1532
1533
1534
1535
1536
1537
1538 public void setMixAuditAnalyzerEnabled(Boolean mixAuditAnalyzerEnabled) {
1539 this.mixAuditAnalyzerEnabled = mixAuditAnalyzerEnabled;
1540 }
1541
1542
1543
1544
1545
1546
1547 public Boolean isCentralAnalyzerEnabled() {
1548 return centralAnalyzerEnabled;
1549 }
1550
1551
1552
1553
1554
1555
1556 public void setCentralAnalyzerEnabled(Boolean centralAnalyzerEnabled) {
1557 this.centralAnalyzerEnabled = centralAnalyzerEnabled;
1558 }
1559
1560
1561
1562
1563
1564
1565 public Boolean isCentralAnalyzerUseCache() {
1566 return centralAnalyzerUseCache;
1567 }
1568
1569
1570
1571
1572
1573
1574 public void setCentralAnalyzerUseCache(Boolean centralAnalyzerUseCache) {
1575 this.centralAnalyzerUseCache = centralAnalyzerUseCache;
1576 }
1577
1578
1579
1580
1581
1582
1583 public Boolean isNexusAnalyzerEnabled() {
1584 return nexusAnalyzerEnabled;
1585 }
1586
1587
1588
1589
1590
1591
1592 public void setNexusAnalyzerEnabled(Boolean nexusAnalyzerEnabled) {
1593 this.nexusAnalyzerEnabled = nexusAnalyzerEnabled;
1594 }
1595
1596
1597
1598
1599
1600
1601 public Boolean isGolangDepEnabled() {
1602 return golangDepEnabled;
1603 }
1604
1605
1606
1607
1608
1609
1610 public void setGolangDepEnabled(Boolean golangDepEnabled) {
1611 this.golangDepEnabled = golangDepEnabled;
1612 }
1613
1614
1615
1616
1617
1618
1619 public Boolean isGoModDepEnabled() {
1620 return golangModEnabled;
1621 }
1622
1623
1624
1625
1626
1627
1628 public void setGolangModEnabled(Boolean golangModEnabled) {
1629 this.golangModEnabled = golangModEnabled;
1630 }
1631
1632
1633
1634
1635
1636
1637 public Boolean isDartAnalyzerEnabled() {
1638 return dartAnalyzerEnabled;
1639 }
1640
1641
1642
1643
1644
1645
1646 public void setDartAnalyzerEnabled(Boolean dartAnalyzerEnabled) {
1647 this.dartAnalyzerEnabled = dartAnalyzerEnabled;
1648 }
1649
1650
1651
1652
1653
1654
1655 public String getPathToYarn() {
1656 return pathToYarn;
1657 }
1658
1659
1660
1661
1662
1663
1664 public void setPathToYarn(String pathToYarn) {
1665 this.pathToYarn = pathToYarn;
1666 }
1667
1668
1669
1670
1671
1672
1673 public String getPathToPnpm() {
1674 return pathToPnpm;
1675 }
1676
1677
1678
1679
1680
1681
1682 public void setPathToPnpm(String pathToPnpm) {
1683 this.pathToPnpm = pathToPnpm;
1684 }
1685
1686
1687
1688
1689
1690
1691 public String getPathToGo() {
1692 return pathToGo;
1693 }
1694
1695
1696
1697
1698
1699
1700 public void setPathToGo(String pathToGo) {
1701 this.pathToGo = pathToGo;
1702 }
1703
1704
1705
1706
1707
1708
1709 public String getNexusUrl() {
1710 return nexusUrl;
1711 }
1712
1713
1714
1715
1716
1717
1718 public void setNexusUrl(String nexusUrl) {
1719 this.nexusUrl = nexusUrl;
1720 }
1721
1722
1723
1724
1725
1726
1727 public String getNexusUser() {
1728 return nexusUser;
1729 }
1730
1731
1732
1733
1734
1735
1736 public void setNexusUser(String nexusUser) {
1737 this.nexusUser = nexusUser;
1738 }
1739
1740
1741
1742
1743
1744
1745 public String getNexusPassword() {
1746 return nexusPassword;
1747 }
1748
1749
1750
1751
1752
1753
1754 public void setNexusPassword(String nexusPassword) {
1755 this.nexusPassword = nexusPassword;
1756 }
1757
1758
1759
1760
1761
1762
1763 public Boolean isNexusUsesProxy() {
1764 return nexusUsesProxy;
1765 }
1766
1767
1768
1769
1770
1771
1772 public void setNexusUsesProxy(Boolean nexusUsesProxy) {
1773 this.nexusUsesProxy = nexusUsesProxy;
1774 }
1775
1776
1777
1778
1779
1780
1781 public String getZipExtensions() {
1782 return zipExtensions;
1783 }
1784
1785
1786
1787
1788
1789
1790 public void setZipExtensions(String zipExtensions) {
1791 this.zipExtensions = zipExtensions;
1792 }
1793
1794
1795
1796
1797
1798
1799 public String getPathToDotnetCore() {
1800 return pathToCore;
1801 }
1802
1803
1804
1805
1806
1807
1808 public void setPathToDotnetCore(String pathToCore) {
1809 this.pathToCore = pathToCore;
1810 }
1811
1812
1813
1814
1815
1816
1817 public Boolean isOssindexAnalyzerEnabled() {
1818 return ossindexAnalyzerEnabled;
1819 }
1820
1821
1822
1823
1824
1825
1826 public void setOssindexAnalyzerEnabled(Boolean ossindexAnalyzerEnabled) {
1827 this.ossindexAnalyzerEnabled = ossindexAnalyzerEnabled;
1828 }
1829
1830
1831
1832
1833
1834
1835 public Boolean isOssindexAnalyzerUseCache() {
1836 return ossindexAnalyzerUseCache;
1837 }
1838
1839
1840
1841
1842
1843
1844 public void setOssindexAnalyzerUseCache(Boolean ossindexAnalyzerUseCache) {
1845 this.ossindexAnalyzerUseCache = ossindexAnalyzerUseCache;
1846 }
1847
1848
1849
1850
1851
1852
1853 public String getOssindexAnalyzerUrl() {
1854 return ossindexAnalyzerUrl;
1855 }
1856
1857
1858
1859
1860
1861
1862 public void setOssindexAnalyzerUrl(String ossindexAnalyzerUrl) {
1863 this.ossindexAnalyzerUrl = ossindexAnalyzerUrl;
1864 }
1865
1866
1867
1868
1869
1870
1871 public String getOssindexAnalyzerUsername() {
1872 return ossindexAnalyzerUsername;
1873 }
1874
1875
1876
1877
1878
1879
1880 public void setOssindexAnalyzerUsername(String ossindexAnalyzerUsername) {
1881 this.ossindexAnalyzerUsername = ossindexAnalyzerUsername;
1882 }
1883
1884
1885
1886
1887
1888
1889 public String getOssindexAnalyzerPassword() {
1890 return ossindexAnalyzerPassword;
1891 }
1892
1893
1894
1895
1896
1897
1898 public void setOssindexAnalyzerPassword(String ossindexAnalyzerPassword) {
1899 this.ossindexAnalyzerPassword = ossindexAnalyzerPassword;
1900 }
1901
1902
1903
1904
1905
1906
1907 public Boolean getOssIndexWarnOnlyOnRemoteErrors() {
1908 return ossIndexAnalyzerWarnOnlyOnRemoteErrors;
1909 }
1910
1911
1912
1913
1914
1915
1916
1917 public void setOssIndexWarnOnlyOnRemoteErrors(Boolean ossIndexWarnOnlyOnRemoteErrors) {
1918 this.ossIndexAnalyzerWarnOnlyOnRemoteErrors = ossIndexWarnOnlyOnRemoteErrors;
1919 }
1920
1921
1922
1923
1924
1925
1926 public Boolean isCmakeAnalyzerEnabled() {
1927 return cmakeAnalyzerEnabled;
1928 }
1929
1930
1931
1932
1933
1934
1935 public void setCmakeAnalyzerEnabled(Boolean cmakeAnalyzerEnabled) {
1936 this.cmakeAnalyzerEnabled = cmakeAnalyzerEnabled;
1937 }
1938
1939
1940
1941
1942
1943
1944 public Boolean getArtifactoryAnalyzerEnabled() {
1945 return artifactoryAnalyzerEnabled;
1946 }
1947
1948
1949
1950
1951
1952
1953 public void setArtifactoryAnalyzerEnabled(Boolean artifactoryAnalyzerEnabled) {
1954 this.artifactoryAnalyzerEnabled = artifactoryAnalyzerEnabled;
1955 }
1956
1957
1958
1959
1960
1961
1962 public String getArtifactoryAnalyzerUrl() {
1963 return artifactoryAnalyzerUrl;
1964 }
1965
1966
1967
1968
1969
1970
1971 public void setArtifactoryAnalyzerUrl(String artifactoryAnalyzerUrl) {
1972 this.artifactoryAnalyzerUrl = artifactoryAnalyzerUrl;
1973 }
1974
1975
1976
1977
1978
1979
1980 public Boolean getArtifactoryAnalyzerUseProxy() {
1981 return artifactoryAnalyzerUseProxy;
1982 }
1983
1984
1985
1986
1987
1988
1989
1990 public void setArtifactoryAnalyzerUseProxy(Boolean artifactoryAnalyzerUseProxy) {
1991 this.artifactoryAnalyzerUseProxy = artifactoryAnalyzerUseProxy;
1992 }
1993
1994
1995
1996
1997
1998
1999 public Boolean getArtifactoryAnalyzerParallelAnalysis() {
2000 return artifactoryAnalyzerParallelAnalysis;
2001 }
2002
2003
2004
2005
2006
2007
2008
2009 public void setArtifactoryAnalyzerParallelAnalysis(Boolean artifactoryAnalyzerParallelAnalysis) {
2010 this.artifactoryAnalyzerParallelAnalysis = artifactoryAnalyzerParallelAnalysis;
2011 }
2012
2013
2014
2015
2016
2017
2018 public String getArtifactoryAnalyzerUsername() {
2019 return artifactoryAnalyzerUsername;
2020 }
2021
2022
2023
2024
2025
2026
2027
2028 public void setArtifactoryAnalyzerUsername(String artifactoryAnalyzerUsername) {
2029 this.artifactoryAnalyzerUsername = artifactoryAnalyzerUsername;
2030 }
2031
2032
2033
2034
2035
2036
2037 public String getArtifactoryAnalyzerApiToken() {
2038 return artifactoryAnalyzerApiToken;
2039 }
2040
2041
2042
2043
2044
2045
2046
2047 public void setArtifactoryAnalyzerApiToken(String artifactoryAnalyzerApiToken) {
2048 this.artifactoryAnalyzerApiToken = artifactoryAnalyzerApiToken;
2049 }
2050
2051
2052
2053
2054
2055
2056 public String getArtifactoryAnalyzerBearerToken() {
2057 return artifactoryAnalyzerBearerToken;
2058 }
2059
2060
2061
2062
2063
2064
2065
2066 public void setArtifactoryAnalyzerBearerToken(String artifactoryAnalyzerBearerToken) {
2067 this.artifactoryAnalyzerBearerToken = artifactoryAnalyzerBearerToken;
2068 }
2069
2070
2071 @SuppressWarnings("squid:RedundantThrowsDeclarationCheck")
2072 @Override
2073 protected void executeWithContextClassloader() throws BuildException {
2074 dealWithReferences();
2075 validateConfiguration();
2076 populateSettings();
2077 try {
2078 Downloader.getInstance().configure(getSettings());
2079 } catch (InvalidSettingException e) {
2080 throw new BuildException(e);
2081 }
2082 try (Engine engine = new Engine(Check.class.getClassLoader(), getSettings())) {
2083 for (Resource resource : getPath()) {
2084 final FileProvider provider = resource.as(FileProvider.class);
2085 if (provider != null) {
2086 final File file = provider.getFile();
2087 if (file != null && file.exists()) {
2088 engine.scan(file);
2089 }
2090 }
2091 }
2092 final ExceptionCollection exceptions = callExecuteAnalysis(engine);
2093 if (exceptions == null || !exceptions.isFatal()) {
2094 for (String format : getReportFormats()) {
2095 engine.writeReports(getProjectName(), new File(reportOutputDirectory), format, exceptions);
2096 }
2097 if (this.failBuildOnCVSS <= 10) {
2098 checkForFailure(engine.getDependencies());
2099 }
2100 if (this.showSummary) {
2101 DependencyCheckScanAgent.showSummary(engine.getDependencies());
2102 }
2103 }
2104 } catch (DatabaseException ex) {
2105 final String msg = "Unable to connect to the dependency-check database; analysis has stopped";
2106 if (this.isFailOnError()) {
2107 throw new BuildException(msg, ex);
2108 }
2109 log(msg, ex, Project.MSG_ERR);
2110 } catch (ReportException ex) {
2111 final String msg = "Unable to generate the dependency-check report";
2112 if (this.isFailOnError()) {
2113 throw new BuildException(msg, ex);
2114 }
2115 log(msg, ex, Project.MSG_ERR);
2116 } finally {
2117 getSettings().cleanup();
2118 }
2119 }
2120
2121
2122
2123
2124
2125
2126
2127
2128
2129
2130
2131 @SuppressWarnings("squid:RedundantThrowsDeclarationCheck")
2132 private ExceptionCollection callExecuteAnalysis(final Engine engine) throws BuildException {
2133 ExceptionCollection exceptions = null;
2134 try {
2135 engine.analyzeDependencies();
2136 } catch (ExceptionCollection ex) {
2137 if (this.isFailOnError()) {
2138 throw new BuildException(ex);
2139 }
2140 exceptions = ex;
2141 }
2142 return exceptions;
2143 }
2144
2145
2146
2147
2148
2149
2150
2151
2152 @SuppressWarnings("squid:RedundantThrowsDeclarationCheck")
2153 private synchronized void validateConfiguration() throws BuildException {
2154 if (path == null) {
2155 throw new BuildException("No project dependencies have been defined to analyze.");
2156 }
2157 if (failBuildOnCVSS < 0 || failBuildOnCVSS > 11) {
2158 throw new BuildException("Invalid configuration, failBuildOnCVSS must be between 0 and 11.");
2159 }
2160 }
2161
2162
2163
2164
2165
2166
2167
2168
2169
2170 @SuppressWarnings("squid:RedundantThrowsDeclarationCheck")
2171 @Override
2172 protected void populateSettings() throws BuildException {
2173 super.populateSettings();
2174 getSettings().setBooleanIfNotNull(Settings.KEYS.AUTO_UPDATE, autoUpdate);
2175 getSettings().setArrayIfNotEmpty(Settings.KEYS.SUPPRESSION_FILE, suppressionFiles);
2176 getSettings().setStringIfNotEmpty(Settings.KEYS.HINTS_FILE, hintsFile);
2177 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_EXPERIMENTAL_ENABLED, enableExperimental);
2178 getSettings().setBooleanIfNotNull(Settings.KEYS.PRETTY_PRINT, prettyPrint);
2179 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_RETIRED_ENABLED, enableRetired);
2180 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_JAR_ENABLED, jarAnalyzerEnabled);
2181 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_PYTHON_DISTRIBUTION_ENABLED, pyDistributionAnalyzerEnabled);
2182 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_PYTHON_PACKAGE_ENABLED, pyPackageAnalyzerEnabled);
2183 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_RUBY_GEMSPEC_ENABLED, rubygemsAnalyzerEnabled);
2184 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_OPENSSL_ENABLED, opensslAnalyzerEnabled);
2185 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_CMAKE_ENABLED, cmakeAnalyzerEnabled);
2186
2187 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_ARTIFACTORY_ENABLED, artifactoryAnalyzerEnabled);
2188 getSettings().setStringIfNotEmpty(Settings.KEYS.ANALYZER_ARTIFACTORY_URL, artifactoryAnalyzerUrl);
2189 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_ARTIFACTORY_USES_PROXY, artifactoryAnalyzerUseProxy);
2190 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_ARTIFACTORY_PARALLEL_ANALYSIS, artifactoryAnalyzerParallelAnalysis);
2191 getSettings().setStringIfNotEmpty(Settings.KEYS.ANALYZER_ARTIFACTORY_API_USERNAME, artifactoryAnalyzerUsername);
2192 getSettings().setStringIfNotEmpty(Settings.KEYS.ANALYZER_ARTIFACTORY_API_TOKEN, artifactoryAnalyzerApiToken);
2193 getSettings().setStringIfNotEmpty(Settings.KEYS.ANALYZER_ARTIFACTORY_BEARER_TOKEN, artifactoryAnalyzerBearerToken);
2194
2195 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_SWIFT_PACKAGE_MANAGER_ENABLED, swiftPackageManagerAnalyzerEnabled);
2196 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_SWIFT_PACKAGE_RESOLVED_ENABLED, swiftPackageResolvedAnalyzerEnabled);
2197 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_COCOAPODS_ENABLED, cocoapodsAnalyzerEnabled);
2198 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_CARTHAGE_ENABLED, carthageAnalyzerEnabled);
2199 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_BUNDLE_AUDIT_ENABLED, bundleAuditAnalyzerEnabled);
2200 getSettings().setStringIfNotNull(Settings.KEYS.ANALYZER_BUNDLE_AUDIT_PATH, bundleAuditPath);
2201 getSettings().setStringIfNotNull(Settings.KEYS.ANALYZER_BUNDLE_AUDIT_WORKING_DIRECTORY, bundleAuditWorkingDirectory);
2202 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_AUTOCONF_ENABLED, autoconfAnalyzerEnabled);
2203 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_MAVEN_INSTALL_ENABLED, mavenInstallAnalyzerEnabled);
2204 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_PIP_ENABLED, pipAnalyzerEnabled);
2205 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_PIPFILE_ENABLED, pipfileAnalyzerEnabled);
2206 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_POETRY_ENABLED, poetryAnalyzerEnabled);
2207 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_COMPOSER_LOCK_ENABLED, composerAnalyzerEnabled);
2208 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_COMPOSER_LOCK_SKIP_DEV, composerAnalyzerSkipDev);
2209 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_CPANFILE_ENABLED, cpanfileAnalyzerEnabled);
2210 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_NODE_PACKAGE_ENABLED, nodeAnalyzerEnabled);
2211 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_NODE_PACKAGE_SKIPDEV, nodePackageSkipDevDependencies);
2212 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_NODE_AUDIT_ENABLED, nodeAuditAnalyzerEnabled);
2213 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_YARN_AUDIT_ENABLED, yarnAuditAnalyzerEnabled);
2214 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_PNPM_AUDIT_ENABLED, pnpmAuditAnalyzerEnabled);
2215 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_NODE_AUDIT_USE_CACHE, nodeAuditAnalyzerUseCache);
2216 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_NODE_AUDIT_SKIPDEV, nodeAuditSkipDevDependencies);
2217 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_RETIREJS_ENABLED, retireJsAnalyzerEnabled);
2218 getSettings().setStringIfNotNull(Settings.KEYS.ANALYZER_RETIREJS_REPO_JS_URL, retireJsUrl);
2219 getSettings().setStringIfNotNull(Settings.KEYS.ANALYZER_RETIREJS_REPO_JS_USER, retireJsUrlUser);
2220 getSettings().setStringIfNotNull(Settings.KEYS.ANALYZER_RETIREJS_REPO_JS_PASSWORD, retireJsUrlPassword);
2221 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_RETIREJS_FORCEUPDATE, retireJsAnalyzerForceUpdate);
2222 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_RETIREJS_FILTER_NON_VULNERABLE, retirejsFilterNonVulnerable);
2223 getSettings().setArrayIfNotEmpty(Settings.KEYS.ANALYZER_RETIREJS_FILTERS, retirejsFilters);
2224 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_GOLANG_DEP_ENABLED, golangDepEnabled);
2225 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_GOLANG_MOD_ENABLED, golangModEnabled);
2226 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_DART_ENABLED, dartAnalyzerEnabled);
2227 getSettings().setStringIfNotNull(Settings.KEYS.ANALYZER_GOLANG_PATH, pathToGo);
2228 getSettings().setStringIfNotNull(Settings.KEYS.ANALYZER_YARN_PATH, pathToYarn);
2229 getSettings().setStringIfNotNull(Settings.KEYS.ANALYZER_PNPM_PATH, pathToPnpm);
2230 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_MIX_AUDIT_ENABLED, mixAuditAnalyzerEnabled);
2231 getSettings().setStringIfNotNull(Settings.KEYS.ANALYZER_MIX_AUDIT_PATH, mixAuditPath);
2232 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_NUSPEC_ENABLED, nuspecAnalyzerEnabled);
2233 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_NUGETCONF_ENABLED, nugetconfAnalyzerEnabled);
2234 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_LIBMAN_ENABLED, libmanAnalyzerEnabled);
2235 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_CENTRAL_ENABLED, centralAnalyzerEnabled);
2236 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_CENTRAL_USE_CACHE, centralAnalyzerUseCache);
2237 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_NEXUS_ENABLED, nexusAnalyzerEnabled);
2238 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_ARCHIVE_ENABLED, archiveAnalyzerEnabled);
2239 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_KNOWN_EXPLOITED_ENABLED, knownExploitedEnabled);
2240 getSettings().setStringIfNotEmpty(Settings.KEYS.KEV_URL, knownExploitedUrl);
2241 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_ASSEMBLY_ENABLED, assemblyAnalyzerEnabled);
2242 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_MSBUILD_PROJECT_ENABLED, msbuildAnalyzerEnabled);
2243 getSettings().setStringIfNotEmpty(Settings.KEYS.ANALYZER_NEXUS_URL, nexusUrl);
2244 getSettings().setStringIfNotEmpty(Settings.KEYS.ANALYZER_NEXUS_USER, nexusUser);
2245 getSettings().setStringIfNotEmpty(Settings.KEYS.ANALYZER_NEXUS_PASSWORD, nexusPassword);
2246 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_NEXUS_USES_PROXY, nexusUsesProxy);
2247 getSettings().setStringIfNotEmpty(Settings.KEYS.ADDITIONAL_ZIP_EXTENSIONS, zipExtensions);
2248 getSettings().setStringIfNotEmpty(Settings.KEYS.ANALYZER_ASSEMBLY_DOTNET_PATH, pathToCore);
2249 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_OSSINDEX_ENABLED, ossindexAnalyzerEnabled);
2250 getSettings().setStringIfNotEmpty(Settings.KEYS.ANALYZER_OSSINDEX_URL, ossindexAnalyzerUrl);
2251 getSettings().setStringIfNotEmpty(Settings.KEYS.ANALYZER_OSSINDEX_USER, ossindexAnalyzerUsername);
2252 getSettings().setStringIfNotEmpty(Settings.KEYS.ANALYZER_OSSINDEX_PASSWORD, ossindexAnalyzerPassword);
2253 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_OSSINDEX_USE_CACHE, ossindexAnalyzerUseCache);
2254 getSettings().setBooleanIfNotNull(Settings.KEYS.ANALYZER_OSSINDEX_WARN_ONLY_ON_REMOTE_ERRORS, ossIndexAnalyzerWarnOnlyOnRemoteErrors);
2255 getSettings().setFloat(Settings.KEYS.JUNIT_FAIL_ON_CVSS, junitFailOnCVSS);
2256 }
2257
2258
2259
2260
2261
2262
2263
2264
2265
2266
2267 @SuppressWarnings("squid:RedundantThrowsDeclarationCheck")
2268 private void checkForFailure(Dependency[] dependencies) throws BuildException {
2269 final StringBuilder ids = new StringBuilder();
2270 for (Dependency d : dependencies) {
2271 boolean addName = true;
2272 for (Vulnerability v : d.getVulnerabilities()) {
2273 if ((v.getCvssV2() != null && v.getCvssV2().getCvssData().getBaseScore() >= failBuildOnCVSS)
2274 || (v.getCvssV3() != null && v.getCvssV3().getCvssData().getBaseScore() >= failBuildOnCVSS)
2275 || (v.getUnscoredSeverity() != null && SeverityUtil.estimateCvssV2(v.getUnscoredSeverity()) >= failBuildOnCVSS)
2276
2277 || (failBuildOnCVSS <= 0.0f)) {
2278 if (addName) {
2279 addName = false;
2280 ids.append(NEW_LINE).append(d.getFileName()).append(": ");
2281 ids.append(v.getName());
2282 } else {
2283 ids.append(", ").append(v.getName());
2284 }
2285 }
2286 }
2287 }
2288 if (ids.length() > 0) {
2289 final String msg;
2290 if (showSummary) {
2291 msg = String.format("%n%nDependency-Check Failure:%n"
2292 + "One or more dependencies were identified with vulnerabilities that have a CVSS score greater than or equal to '%.1f': %s%n"
2293 + "See the dependency-check report for more details.%n%n", failBuildOnCVSS, ids);
2294 } else {
2295 msg = String.format("%n%nDependency-Check Failure:%n"
2296 + "One or more dependencies were identified with vulnerabilities.%n%n"
2297 + "See the dependency-check report for more details.%n%n");
2298 }
2299 throw new BuildException(msg);
2300 }
2301 }
2302
2303
2304
2305
2306
2307 public static class ReportFormats extends EnumeratedAttribute {
2308
2309
2310
2311
2312
2313
2314 @Override
2315 public String[] getValues() {
2316 int i = 0;
2317 final Format[] formats = Format.values();
2318 final String[] values = new String[formats.length];
2319 for (Format format : formats) {
2320 values[i++] = format.name();
2321 }
2322 return values;
2323 }
2324 }
2325
2326
2327
2328
2329
2330
2331 public static class ReportFormat {
2332
2333
2334
2335
2336 private ReportFormats format;
2337
2338
2339
2340
2341
2342
2343 public String getFormat() {
2344 return this.format.getValue();
2345 }
2346
2347
2348
2349
2350
2351
2352
2353
2354 public void setFormat(final String format) {
2355 this.format = (ReportFormats) EnumeratedAttribute.getInstance(ReportFormats.class, format);
2356 }
2357 }
2358 }
2359