Founder and project lead for dependency-check.
- Oak Hill, VA
- https://infosec.exchange/@ctxt
- @ctxt
Highlights
- Pro
Block or Report
Block or report jeremylong
Report abuse
Contact GitHub support about this user’s behavior. Learn more about reporting abuse.
Report abusePinned
-
DependencyCheck Public
OWASP dependency-check is a software composition analysis utility that detects publicly disclosed vulnerabilities in application dependencies.
-
The dependency-check gradle plugin allows projects to monitor dependent libraries for known, published vulnerabilities.
-
1,596 contributions in the last year
Less
More
Contribution activity
February 2023
Created 1 repository
Created a pull request in Homebrew/homebrew-core that received 1 comment
dependency-check 8.1.0
Have you followed the guidelines for contributing? Have you ensured that your commits follow the commit style guide? Have you checked that the…
+5
−3
•
1
comment
Opened 20 other pull requests in 4 repositories
jeremylong/DependencyCheck
1
open
8
merged
- feat: Support msbuild Directory.build.props
- fix: do not throw error if pyproject.toml is in node_modules
- chore: Release 8.1.0
- fix(fp): False Positives on GitPython
- fix: correctly return update status in KnownExploitedDataSource
- fix: resolve false negative on yii2
- fix: bad version string interpolation
- fix: ensure pyproject.toml has lock
- fix: improve error messages for AssemblyAnalyzer
jeremylong/vuln-tools
9
merged
- chore: add changelog
- chore: documentation, cleanup, fixes, etc.
- feat(vulnz): add parameters for cve search
- feat(nvd-lib): add version start and version end
- feat(nvd-lib): add virtual match string parameter
- chore(nvd-lib): correct build sourceSets
- feat(nvd-lib): support noRejected
- fix: LocalDateTime -> ZonedDateTime
- feat: Add GitHub Security Advisories
owasp-change/owasp-change.github.io
1
merged
dependency-check/dependency-check-gradle
1
merged
Reviewed 20 pull requests in 2 repositories
jeremylong/DependencyCheck
19 pull requests
- build(deps): bump jsonschema2pojo-maven-plugin from 1.2.0 to 1.2.1
- build(deps): bump jsoup from 1.15.3 to 1.15.4
- feat: Support msbuild Directory.build.props
- fix: Node package dependencies ending up as related dependency of the wrong version of the package
- fix: Prefer pom.properties G/A/V over pom.xml G/A/V to resolve GAV interpolation issues
- build(deps): bump semver4j from 4.2.0 to 4.2.1
- build(deps): bump jsonschema2pojo-maven-plugin from 1.1.3 to 1.2.0
- build(deps): bump postgresql from 42.5.3 to 42.5.4
- build(deps): bump maven-javadoc-plugin from 3.4.1 to 3.5.0
- build(deps): bump maven-invoker-plugin from 3.4.0 to 3.5.0
- build(deps): bump amannn/action-semantic-pull-request from 5.0.2 to 5.1.0
- fix(FP): Fp suppressions too hard for our automation
- build(deps): bump maven-deploy-plugin from 3.0.0 to 3.1.0
- build(deps): bump semver4j from 4.1.1 to 4.2.0
- build(deps): bump maven-artifact-plugin from 3.3.0 to 3.4.0
- build(deps): bump postgresql from 42.5.2 to 42.5.3
- fix: bad version string interpolation
- build(deps): bump postgresql from 42.5.1 to 42.5.2
- build(deps): bump maven-enforcer-plugin from 3.1.0 to 3.2.1






