dependency check plugin results for OWASP benchmark

15 views
Skip to first unread message

Arbi Sookazian

unread,
Jul 28, 2017, 2:32:30 PM7/28/17
to Dependency Check
Hi,


Have there been any results reported on the dependency check maven plugin tool in terms of this benchmarking?  If yes, where can we view them?

Also, at one point I had found a list of vulnerability database which was more extensive than the list here: https://danielmiessler.com/study/vulnerability-database-resources/#gs.NHURN4g

Is it possible that the dependency check maven plugin will potentially miss some if they are not in the NVD?

Thanks.

Jeremy Long

unread,
Jul 28, 2017, 11:35:37 PM7/28/17
to Arbi Sookazian, Dependency Check
First, to my knowledge there are no benchmark tests for Software Composition Analysis tools. Might be something to talk to that project about.

Regarding vulnerability sources, currently dependency-check only uses the NVD. Most other vulnerability data sources are commercial and require licensing.

--Jeremy

--
You received this message because you are subscribed to the Google Groups "Dependency Check" group.
To unsubscribe from this group and stop receiving emails from it, send an email to dependency-check+unsubscribe@googlegroups.com.
For more options, visit https://groups.google.com/d/optout.

Reply all
Reply to author
Forward
0 new messages