Highlights
- Pro
Block or Report
Block or report jeremylong
Contact GitHub support about this user’s behavior. Learn more about reporting abuse.
Report abusePinned
-
DependencyCheck Public
OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.
-
The dependency-check gradle plugin allows projects to monitor dependent libraries for known, published vulnerabilities.
-
lein-dependency-check Public
Forked from livingsocial/lein-dependency-check
A leiningen plugin for detecting vulnerable project dependencies
Clojure
-
sbt-dependency-check Public
Forked from albuch/sbt-dependency-check
SBT Plugin for OWASP DependencyCheck. Monitor your dependencies and report if there are any publicly known vulnerabilities (e.g. CVEs).
Scala
-
Integrates Dependency-Check reports into SonarQube
-
Jenkins plugin for OWASP Dependency-Check. Inspects project components for known vulnerabilities (e.g. CVEs).
1,464 contributions in the last year
Contribution activity
September 2022
Created 2 repositories
Created a pull request in jeremylong/DependencyCheck that received 2 comments
Opened 19 other pull requests in 4 repositories
jeremylong/DependencyCheck
1
open
14
merged
- Update Gradle Documentation
- Release 7.2.1
- Fix Logging Issue
- fix copy/paste error in workflow
- Correct login name in approval workflow
- debugging workflow...
- additional logging
- actions - additional logging
- workflow - add additional logging
- IssueOps Approvals: debugging and possible fix
- Remove === in workflow
- fix url in issue ops for FP
- Fix syntax error in FP approval ops
- fix issue ops for FP
- Update false positive issue ops
Homebrew/homebrew-core
2
closed
Mattraks/delete-workflow-runs
1
merged
pingcap/ossinsight
1
merged
Reviewed 13 pull requests in 1 repository
jeremylong/DependencyCheck
13 pull requests
- Add links to Gradle Plugin page in various docs
- Bump maven-jar-plugin from 3.2.2 to 3.3.0
- Adjusted mime4j pattern
- Bump versions-maven-plugin from 2.11.0 to 2.12.0
- Bump spotbugs-maven-plugin from 4.7.1.1 to 4.7.2.0
- Bump actions/github-script from 5.1.1 to 6.2.0
- Fix syntax of false-positive-approvals.yml
- CLI,completion: add --disableMavenInstall
- Allow custom report templates via CLI
- Fix false-positive CPE matches for spring-boot libraries
- Checking for null value from MSBuild xpath method before accessing it
- Fixing file separator bug for unit test on windows machines
- Add a PinnedMavenInstallAnalyzer
Created an issue in jeremylong/DependencyCheck that received 5 comments
[FP]: easyuploads reported as vaadin
Package URl
pkg:maven/org.vaadin.addon/easyuploads@8.0.1
CPE
cpe:2.3:a:vaadin:vaadin:8.0.1:*:*:*:*:*:*:*
CVE
No response
ODC Integration
{"label"=>…






