diff --git a/.github/workflows/dependencyCheck.yml b/.github/workflows/dependencyCheck.yml deleted file mode 100644 index 13ac9b21..00000000 --- a/.github/workflows/dependencyCheck.yml +++ /dev/null @@ -1,30 +0,0 @@ -name: OWASP Dependency Check - -on: [push] - -jobs: - build: - - runs-on: ubuntu-latest - - steps: - - uses: actions/checkout@v3 - with: - fetch-depth: 0 - - name: Get Fetch Tags - run: git -c protocol.version=2 fetch --tags --progress --no-recurse-submodules origin - if: "!contains(github.ref, 'refs/tags')" - - name: Set up JDK 11 - uses: actions/setup-java@v3 - with: - java-version: '11' - distribution: 'zulu' - - name: Grant execute permission for gradlew - run: chmod +x gradlew - - name: Build with Gradle - run: ./gradlew dependencyCheckAggregate -Porg.gradle.dependency.verification.console=verbose --dependency-verification lenient - - uses: actions/upload-artifact@v3 - if: failure() - with: - name: dependency-check-reports - path: build/reports/dependency-check-report* diff --git a/README.md b/README.md index 3d44ee31..6cec4879 100644 --- a/README.md +++ b/README.md @@ -72,12 +72,6 @@ Update dependency verification metadata and export any new keys. git add gradle/verification-metadata.xml git add gradle/verification-keyring.keys -## Owasp Dependency check - -Check OWASP scan for dependencies - - ./gradlew dependencyCheckAggregate -Porg.gradle.dependency.verification.console=verbose --dependency-verification lenient - ## Install Locally Install to local path rd-cli-tool/build/install/rd/bin/rd diff --git a/build.gradle b/build.gradle index cd9b1dc4..788281b7 100644 --- a/build.gradle +++ b/build.gradle @@ -16,7 +16,6 @@ plugins { id 'base' - alias(libs.plugins.owasp) alias(libs.plugins.axion) alias(libs.plugins.nexusPublish) } @@ -24,15 +23,9 @@ import java.util.regex.Matcher import pl.allegro.tech.build.axion.release.domain.VersionConfig import pl.allegro.tech.build.axion.release.infrastructure.di.VersionResolutionContext -apply plugin: 'org.owasp.dependencycheck' ext.githubUrl = "https://github.com/rundeck/rundeck-cli" ext.changelogFile = file("CHANGELOG.md") -dependencyCheck { - suppressionFile='cve-suppress.xml' - format='ALL' - failBuildOnCVSS=8 -} subprojects{ apply plugin: "java-library" diff --git a/gradle/libs.versions.toml b/gradle/libs.versions.toml index 746823a3..c2b22594 100644 --- a/gradle/libs.versions.toml +++ b/gradle/libs.versions.toml @@ -13,7 +13,6 @@ shadow = "7.1.2" ospackage = "9.1.1" buildInfo = "0.9" buildConfig = "3.1.0" -owasp = "7.1.0.1" jacksonDatabind = "2.18.1" picocli = "4.6.3" snakeYaml = "2.0" @@ -66,4 +65,3 @@ shadow = { id = "com.github.johnrengelman.shadow", version.ref = "shadow" } ospackage = { id = "nebula.ospackage", version.ref = "ospackage" } buildInfo = { id = "org.dvaske.gradle.git-build-info", version.ref = "buildInfo" } buildConfig = { id = 'com.github.gmazzo.buildconfig', version.ref = "buildConfig" } -owasp = { id = "org.owasp.dependencycheck", version.ref = "owasp" }