Skip to content

Instantly share code, notes, and snippets.

@SvenLie
Created September 14, 2022 09:37
Show Gist options
  • Save SvenLie/94f6e98447bcd2d79c90cd4a9e0553d7 to your computer and use it in GitHub Desktop.
Save SvenLie/94f6e98447bcd2d79c90cd4a9e0553d7 to your computer and use it in GitHub Desktop.
$ /usr/share/dependency-check/bin/dependency-check.sh --data ".dependency-check" --out ".dependency-check" --suppression ".dependency-check/suppressions.xml" --scan "./" --project "$CI_PROJECT_TITLE" --format ALL --enableExperimental --disableYarnAudit
[INFO] Checking for updates
[INFO] NVD CVE requires several updates; this could take a couple of minutes.
[INFO] Download Started for NVD CVE - 2002
[INFO] Download Complete for NVD CVE - 2002 (1459 ms)
[INFO] Processing Started for NVD CVE - 2002
[INFO] Download Started for NVD CVE - 2003
[INFO] Download Complete for NVD CVE - 2003 (1038 ms)
[INFO] Processing Started for NVD CVE - 2003
[INFO] Processing Complete for NVD CVE - 2002 (5053 ms)
[INFO] Processing Complete for NVD CVE - 2003 (1126 ms)
[INFO] Download Started for NVD CVE - 2004
[INFO] Download Complete for NVD CVE - 2004 (1129 ms)
[INFO] Processing Started for NVD CVE - 2004
[INFO] Processing Complete for NVD CVE - 2004 (1979 ms)
[INFO] Download Started for NVD CVE - 2005
[INFO] Download Complete for NVD CVE - 2005 (1454 ms)
[INFO] Processing Started for NVD CVE - 2005
[INFO] Processing Complete for NVD CVE - 2005 (2901 ms)
[INFO] Download Started for NVD CVE - 2006
[INFO] Download Complete for NVD CVE - 2006 (1677 ms)
[INFO] Processing Started for NVD CVE - 2006
[INFO] Download Started for NVD CVE - 2007
[INFO] Processing Complete for NVD CVE - 2006 (4195 ms)
[INFO] Download Complete for NVD CVE - 2007 (1688 ms)
[INFO] Processing Started for NVD CVE - 2007
[INFO] Processing Complete for NVD CVE - 2007 (3178 ms)
[INFO] Download Started for NVD CVE - 2008
[INFO] Download Complete for NVD CVE - 2008 (1672 ms)
[INFO] Processing Started for NVD CVE - 2008
[INFO] Download Started for NVD CVE - 2009
[INFO] Processing Complete for NVD CVE - 2008 (4110 ms)
[INFO] Download Complete for NVD CVE - 2009 (1683 ms)
[INFO] Processing Started for NVD CVE - 2009
[INFO] Processing Complete for NVD CVE - 2009 (3952 ms)
[INFO] Download Started for NVD CVE - 2010
[INFO] Download Complete for NVD CVE - 2010 (1596 ms)
[INFO] Processing Started for NVD CVE - 2010
[INFO] Download Started for NVD CVE - 2011
[INFO] Processing Complete for NVD CVE - 2010 (4615 ms)
[INFO] Download Complete for NVD CVE - 2011 (1640 ms)
[INFO] Processing Started for NVD CVE - 2011
[INFO] Download Started for NVD CVE - 2012
[INFO] Processing Complete for NVD CVE - 2011 (4801 ms)
[INFO] Download Complete for NVD CVE - 2012 (1977 ms)
[INFO] Processing Started for NVD CVE - 2012
[INFO] Download Started for NVD CVE - 2013
[INFO] Download Complete for NVD CVE - 2013 (1913 ms)
[INFO] Processing Started for NVD CVE - 2013
[INFO] Processing Complete for NVD CVE - 2012 (6468 ms)
[INFO] Download Started for NVD CVE - 2014
[INFO] Processing Complete for NVD CVE - 2013 (5879 ms)
[INFO] Download Complete for NVD CVE - 2014 (1931 ms)
[INFO] Processing Started for NVD CVE - 2014
[INFO] Download Started for NVD CVE - 2015
[INFO] Processing Complete for NVD CVE - 2014 (4709 ms)
[INFO] Download Complete for NVD CVE - 2015 (1790 ms)
[INFO] Processing Started for NVD CVE - 2015
[INFO] Processing Complete for NVD CVE - 2015 (3689 ms)
[INFO] Download Started for NVD CVE - 2016
[INFO] Download Complete for NVD CVE - 2016 (2036 ms)
[INFO] Processing Started for NVD CVE - 2016
[INFO] Download Started for NVD CVE - 2017
[INFO] Processing Complete for NVD CVE - 2016 (4132 ms)
[INFO] Download Complete for NVD CVE - 2017 (2429 ms)
[INFO] Processing Started for NVD CVE - 2017
[INFO] Download Started for NVD CVE - 2018
[INFO] Processing Complete for NVD CVE - 2017 (4930 ms)
[INFO] Download Complete for NVD CVE - 2018 (2549 ms)
[INFO] Processing Started for NVD CVE - 2018
[INFO] Download Started for NVD CVE - 2019
[INFO] Processing Complete for NVD CVE - 2018 (5130 ms)
[INFO] Download Complete for NVD CVE - 2019 (2773 ms)
[INFO] Processing Started for NVD CVE - 2019
[INFO] Download Started for NVD CVE - 2020
[INFO] Processing Complete for NVD CVE - 2019 (4645 ms)
[INFO] Download Complete for NVD CVE - 2020 (2878 ms)
[INFO] Processing Started for NVD CVE - 2020
[INFO] Download Started for NVD CVE - 2021
[INFO] Processing Complete for NVD CVE - 2020 (5505 ms)
[INFO] Download Complete for NVD CVE - 2021 (2993 ms)
[INFO] Processing Started for NVD CVE - 2021
[INFO] Download Started for NVD CVE - 2022
[INFO] Processing Complete for NVD CVE - 2021 (5991 ms)
[INFO] Download Complete for NVD CVE - 2022 (2113 ms)
[INFO] Processing Started for NVD CVE - 2022
[INFO] Processing Complete for NVD CVE - 2022 (3959 ms)
[INFO] Download Started for NVD CVE - Modified
[INFO] Download Complete for NVD CVE - Modified (1018 ms)
[INFO] Processing Started for NVD CVE - Modified
[INFO] Processing Complete for NVD CVE - Modified (918 ms)
[INFO] Begin database maintenance
[INFO] Updated the CPE ecosystem on 128204 NVD records
[INFO] Removed the CPE ecosystem on 3564 NVD records
[INFO] Cleaned up 1 orphaned NVD records
[INFO] End database maintenance (12096 ms)
[INFO] Begin database defrag
[INFO] End database defrag (3577 ms)
[INFO] Check for updates complete (151176 ms)
[INFO]
Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
About ODC: https://jeremylong.github.io/DependencyCheck/general/internals.html
False Positives: https://jeremylong.github.io/DependencyCheck/general/suppression.html
💖 Sponsor: https://github.com/sponsors/jeremylong
[INFO] Analysis Started
[WARN] Exception extracting archive 'GDS_Zip_1234987654322.zip'.
[WARN] Exception extracting archive 'GDS_Zip_1234987654323.zip'.
[WARN] Exception extracting archive 'GDS_Zip_1234987654321.zip'.
[INFO] Finished Archive Analyzer (1 seconds)
[INFO] Finished File Name Analyzer (0 seconds)
[INFO] Finished Jar Analyzer (0 seconds)
[INFO] Finished Central Analyzer (0 seconds)
[INFO] Finished Assembly Analyzer (0 seconds)
[INFO] Finished Python Distribution Analyzer (0 seconds)
[INFO] Finished Python Package Analyzer (0 seconds)
[WARN] Analyzing `/builds/dpdhl-fipp/partnerportal/package-lock.json` - however, the node_modules directory does not exist. Please run `npm install` prior to running dependency-check
[INFO] Finished Node.js Package Analyzer (0 seconds)
[INFO] Finished Composer.lock analyzer (0 seconds)
[INFO] Finished PE Analyzer (0 seconds)
[INFO] Finished Dependency Merging Analyzer (0 seconds)
[INFO] Finished Version Filter Analyzer (0 seconds)
[INFO] Finished Hint Analyzer (0 seconds)
[INFO] Created CPE Index (0 seconds)
[INFO] Suppression is expired for rule: SuppressionRule{until=2022-03-08T00:00:00Z,filePath=PropertyType{value=.*/sbin/generic/tika-app.jar(.*)?, regex=true, caseSensitive=false},vulnerabilityName={PropertyType{value=.*, regex=true, caseSensitive=false},}}
[INFO] Finished NPM CPE Analyzer (1 seconds)
[INFO] Created CPE Index (1 seconds)
[INFO] Finished CPE Analyzer (2 seconds)
[INFO] Finished False Positive Analyzer (0 seconds)
[INFO] Finished NVD CVE Analyzer (0 seconds)
[INFO] Finished Node Audit Analyzer (0 seconds)
00:00 INFO: Vulnerability found: jquery-ui below 1.13.0
00:00 INFO: Vulnerability found: jquery-ui below 1.13.0
00:00 INFO: Vulnerability found: jquery-ui below 1.13.0
00:00 INFO: Vulnerability found: jquery-ui below 1.13.2
[INFO] Finished RetireJS Analyzer (0 seconds)
[INFO] Finished Sonatype OSS Index Analyzer (4 seconds)
[INFO] Finished Vulnerability Suppression Analyzer (0 seconds)
[INFO] Finished Dependency Bundling Analyzer (0 seconds)
[INFO] Analysis Complete (13 seconds)
[INFO] Writing report to: /builds/dpdhl-fipp/partnerportal/.dependency-check/dependency-check-report.xml
[INFO] Writing report to: /builds/dpdhl-fipp/partnerportal/.dependency-check/dependency-check-report.html
[INFO] Writing report to: /builds/dpdhl-fipp/partnerportal/.dependency-check/dependency-check-report.json
[INFO] Writing report to: /builds/dpdhl-fipp/partnerportal/.dependency-check/dependency-check-report.csv
[INFO] Writing report to: /builds/dpdhl-fipp/partnerportal/.dependency-check/dependency-check-report.sarif
[INFO] Writing report to: /builds/dpdhl-fipp/partnerportal/.dependency-check/dependency-check-junit.xml
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment