Giter VIP home page Giter VIP logo

Comments (4)

stevespringett avatar stevespringett commented on August 18, 2024 1

The issue should be resolved now.

from dependency-check-sonar-plugin.

stevespringett avatar stevespringett commented on August 18, 2024

The SonarQube plugin does not scan. It requires the XML output from a Dependency-Check implementation (CLI, Maven, Jenkins, etc). In the SQ configuration, you specify the path to the XML file. Refer to the readme and examples.

from dependency-check-sonar-plugin.

RenePingen avatar RenePingen commented on August 18, 2024

HI steve,

Maybe I phrased the issue a bit unclear. I am aware of how the plugin works. the latest version of the owasp command line scanner on nodejs project returns an xml file which contains the following code:
"

moment:2.11.2
C:\agent_work\14\s\server\package.json?moment
"
The filepath part of the XML contains a '?' character, which causes the sonarqube import plugin to fail with the stacktrace as pointed above.

Btw i managed to workaround the issue by reverting to an older version of the OWASP dependency scanner command line tool.
Nonetheless, I think it should be relatively easy to fix.

Kind regards,

RenΓ©

from dependency-check-sonar-plugin.

stevespringett avatar stevespringett commented on August 18, 2024

Ah, thanks for the clarification.

from dependency-check-sonar-plugin.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    πŸ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. πŸ“ŠπŸ“ˆπŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❀️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.