瀏覽代碼

adjust dependency check plugin

Armin Schrenk 1 年之前
父節點
當前提交
6929760979
共有 2 個文件被更改,包括 3 次插入1 次删除
  1. 1 1
      .github/workflows/dependency-check.yml
  2. 2 0
      pom.xml

+ 1 - 1
.github/workflows/dependency-check.yml

@@ -31,7 +31,7 @@ jobs:
       - name: Run org.owasp:dependency-check plugin
         id: dependency-check
         continue-on-error: true
-        run: mvn -B verify -Pdependency-check -DskipTests
+        run: mvn -B validate -Pdependency-check
         env:
           NVD_API_KEY: ${{ secrets.NVD_API_KEY }}
       - name: Upload report on failure

+ 2 - 0
pom.xml

@@ -460,6 +460,7 @@
 						<groupId>org.owasp</groupId>
 						<artifactId>dependency-check-maven</artifactId>
 						<configuration>
+							<nvdValidForHours>24</nvdValidForHours>
 							<failBuildOnCVSS>0</failBuildOnCVSS>
 							<skipTestScope>true</skipTestScope>
 							<detail>true</detail>
@@ -471,6 +472,7 @@
 								<goals>
 									<goal>check</goal>
 								</goals>
+								<phase>validate</phase>
 							</execution>
 						</executions>
 					</plugin>