Skip to content

Commit 99f5510

Browse files
committed
Added comment about how OWASP Dependency Check is no longer working in case someone else runs into the problem.
1 parent e6cf7a3 commit 99f5510

File tree

1 file changed

+8
-0
lines changed

1 file changed

+8
-0
lines changed

pom.xml

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -748,6 +748,14 @@
748748
<!-- Version 12.x is the latest, but 10.0.4 is the latest that we can use beccause 11.x has a breaking
749749
change that requires Java 11 or later and our mimimal JDK is Java 8.
750750
-->
751+
<-- Note: As of 2025-05-18, I (kwwall) unable to get:
752+
$ mvn -B dependency:tree
753+
to work with OpenJDK 8 even though this same version of the Dependency Check plugin worked the previous
754+
ESAPI release last November. I do not have time presently to track the reason for this down, but will
755+
try to follow up with the OWASP Depencency Check team. In the meantime, I thought I would mention it
756+
in case someone else tried it and ran into the problem. It is non-essential though, since I also use
757+
GHAS Dependabot and Snyk SCA tools to monitor unpatched vulnerabilities in ESAPI dependencies.
758+
-->
751759
<version>10.0.4</version>
752760
<configuration>
753761
<nvdApiKey>${env.NVD_API_KEY}</nvdApiKey>

0 commit comments

Comments
 (0)