Uploaded image for project: 'camunda BPM'
  1. camunda BPM
  2. CAM-14396

Include Swagger UI package-lock.json in vulnerability scan

    • Icon: Task Task
    • Resolution: Unresolved
    • Icon: L3 - Default L3 - Default
    • None
    • None
    • run
    • None

      Acceptance Criteria (Required on creation):

      Hints (optional):

        This is the controller panel for Smart Panels app

            [CAM-14396] Include Swagger UI package-lock.json in vulnerability scan

            Implementation notes:

            Thorben Lindhauer added a comment - Implementation notes: The OWASP plugin defines a scanSet configuration property for where it looks for sources to scan: https://jeremylong.github.io/DependencyCheck/dependency-check-maven/configuration.html With the change, it still picks up Maven dependencies declared in the pom file. I tested that with an old Spring version.

            Reopening, because swagger ui is still not respected in the Scan performed by the github action.

            Thorben Lindhauer added a comment - Reopening, because swagger ui is still not respected in the Scan performed by the github action.

            This ticket was migrated to github: https://github.com/camunda/camunda-bpm-platform/issues/2699. Please use this link for any future references and continue any discussion there.

            Thorben Lindhauer added a comment - This ticket was migrated to github: https://github.com/camunda/camunda-bpm-platform/issues/2699 . Please use this link for any future references and continue any discussion there.

              thorben.lindhauer Thorben Lindhauer
              thorben.lindhauer Thorben Lindhauer
              Thorben Lindhauer Thorben Lindhauer
              Tassilo Weidner Tassilo Weidner
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

                Created:
                Updated: