Skip to content

Update dependency-check to v12 - #18399

Closed
amaechler wants to merge 1 commit into
apache:masterfrom
amaechler:dependency-check-12
Closed

Update dependency-check to v12#18399
amaechler wants to merge 1 commit into
apache:masterfrom
amaechler:dependency-check-12

Conversation

@amaechler

Copy link
Copy Markdown
Contributor

Description

This PR updates dependency-check to v12. If we get an NVD API key added to this project (as GH secret), it should become quite quick.


This PR has:

  • been self-reviewed.

@FrankChen021

Copy link
Copy Markdown
Member

@amaechler are you still working on this?

@amaechler

Copy link
Copy Markdown
Contributor Author

No, I haven't. I believe we need ASF Infra or a similar service to add the GH secret for us, which we can do by requesting a new NVD API key here. That should be everything remaining for this PR, but I haven't had time to discuss it anywhere yet.

@FrankChen021

Copy link
Copy Markdown
Member

I think we need to merge this one because current CVE check fails, see #18456
switching to the API is the recommended way to get the CVE list.

for the GH secret, I can edit the repo to add one.

image

But not sure if this the correct way to ada a new one because I didn't see any secrets here(all of our GHA do no use secret? I don't know) @gianm do you know it?

@FrankChen021

Copy link
Copy Markdown
Member

@amaechler I merged your branch to #18456, and an API key has been configured. Let's see if the CI runs correctly.

@amaechler

amaechler commented Jun 12, 2026

Copy link
Copy Markdown
Contributor Author

Closing this as dependency-check-maven was upgraded to v12 on master in the meantime (#18620 to 12.1.0, #18898 to 12.2.0), and the NVD API key is now wired into the security_vulnerabilities cron job via the NVD_API_KEY GitHub Actions secret.

@amaechler amaechler closed this Jun 12, 2026
@amaechler
amaechler deleted the dependency-check-12 branch June 12, 2026 17:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants