diff --git a/.mvn/maven.config b/.mvn/maven.config new file mode 100644 index 00000000000..e69de29bb2d diff --git a/NOTICE.txt b/NOTICE.txt index 2a7d5099f7f..941b2d25d2a 100644 --- a/NOTICE.txt +++ b/NOTICE.txt @@ -1,6 +1,6 @@ dependency-check -Copyright (c) 2012-2025 OWASP Dependency-Check Contributors. All Rights Reserved. +Copyright (c) 2012-2026 OWASP Dependency-Check Contributors. All Rights Reserved. The licenses for the software listed below can be found in the META-INF/licenses/[dependency name]. diff --git a/README.md b/README.md index 44461acef28..219cd60d22c 100644 --- a/README.md +++ b/README.md @@ -373,7 +373,7 @@ Dependency-Check makes use of several other open source libraries. Please see th This product uses the NVD API but is not endorsed or certified by the NVD. -Copyright (c) 2012-2025 Jeremy Long. All Rights Reserved. +Copyright (c) 2012-2026 OWASP Dependency-Check Contributors. All Rights Reserved. [wiki]: https://github.com/dependency-check/DependencyCheck/wiki [notices]: https://github.com/dependency-check/DependencyCheck/blob/main/NOTICE.txt diff --git a/ant/NOTICE.txt b/ant/NOTICE.txt index 01bb3831dfa..a878d0fa559 100644 --- a/ant/NOTICE.txt +++ b/ant/NOTICE.txt @@ -1,6 +1,6 @@ OWASP dependency-check -Copyright (c) 2012-2015 Jeremy Long. All Rights Reserved. +Copyright (c) 2012-2026 OWASP Dependency-Check Contributors. All Rights Reserved. The licenses for the software listed below can be found in the META-INF/licenses/[dependency name]. diff --git a/ant/README.md b/ant/README.md index 3338cd1f12d..0868f2ce133 100644 --- a/ant/README.md +++ b/ant/README.md @@ -12,7 +12,7 @@ Documentation and links to production binary releases can be found on the [githu Copyright & License ------------------- -Dependency-Check is Copyright (c) 2012-2014 Jeremy Long. All Rights Reserved. +Dependency-Check is Copyright (c) 2012-2026 OWASP Dependency-Check Contributors. All Rights Reserved. Permission to modify and redistribute is granted under the terms of the Apache 2.0 license. See the [LICENSE.txt](https://github.com/dependency-check/DependencyCheck/blob/main/LICENSE.txt) file for the full license. diff --git a/ant/src/site/site.xml b/ant/src/site/site.xml index 3e61201cc30..a18f9d20f5b 100644 --- a/ant/src/site/site.xml +++ b/ant/src/site/site.xml @@ -1,4 +1,4 @@ - + - OWASP dependency-check-ant @@ -30,7 +30,6 @@ Copyright (c) 2013 Jeremy Long. All Rights Reserved. - - + \ No newline at end of file diff --git a/archetype/src/site/site.xml b/archetype/src/site/site.xml index d6def9453dd..91c1e68666b 100644 --- a/archetype/src/site/site.xml +++ b/archetype/src/site/site.xml @@ -1,4 +1,4 @@ - + - OWASP dependency-check-plugin @@ -29,7 +29,6 @@ Copyright (c) 2017 Jeremy Long. All Rights Reserved. - - + \ No newline at end of file diff --git a/cli/NOTICE.txt b/cli/NOTICE.txt index fde74278a1c..ef87742ed29 100644 --- a/cli/NOTICE.txt +++ b/cli/NOTICE.txt @@ -1,6 +1,6 @@ dependency-check-cli -Copyright (c) 2013 Jeremy Long. All Rights Reserved. +Copyright (c) 2012-2026 OWASP Dependency-Check Contributors. All Rights Reserved. The licenses for the software listed below can be found in the licenses. diff --git a/cli/README.md b/cli/README.md index 7ab25b589d9..38bdf713d58 100644 --- a/cli/README.md +++ b/cli/README.md @@ -11,7 +11,7 @@ Documentation and links to production binary releases can be found on the [githu Copyright & License ------------ -Dependency-Check is Copyright (c) 2012-2014 Jeremy Long. All Rights Reserved. +Dependency-Check is Copyright (c) 2012-2026 OWASP Dependency-Check Contributors. All Rights Reserved. Permission to modify and redistribute is granted under the terms of the Apache 2.0 license. See the [LICENSE.txt](https://github.com/dependency-check/DependencyCheck/blob/main/cli/LICENSE.txt) file for the full license. diff --git a/cli/src/main/assembly/license.txt b/cli/src/main/assembly/license.txt index 34408aac429..1e6ddbb6b27 100644 --- a/cli/src/main/assembly/license.txt +++ b/cli/src/main/assembly/license.txt @@ -1,5 +1,5 @@ -Copyright (c) 2012-2013 Jeremy Long. All rights reserved. +Copyright (c) 2012-2026 OWASP Dependency-Check Contributors. All rights reserved. Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. diff --git a/cli/src/site/site.xml b/cli/src/site/site.xml index 184ffed4d8b..66963233da5 100644 --- a/cli/src/site/site.xml +++ b/cli/src/site/site.xml @@ -1,4 +1,4 @@ - + - OWASP dependency-check-cli @@ -30,7 +30,6 @@ Copyright (c) 2013 Jeremy Long. All Rights Reserved. - - + \ No newline at end of file diff --git a/core/NOTICE.txt b/core/NOTICE.txt index 6638101b332..941b2d25d2a 100644 --- a/core/NOTICE.txt +++ b/core/NOTICE.txt @@ -1,6 +1,6 @@ dependency-check -Copyright (c) 2012-2013 Jeremy Long. All Rights Reserved. +Copyright (c) 2012-2026 OWASP Dependency-Check Contributors. All Rights Reserved. The licenses for the software listed below can be found in the META-INF/licenses/[dependency name]. diff --git a/core/README.md b/core/README.md index 1b6c759cb08..7e99ba3f284 100644 --- a/core/README.md +++ b/core/README.md @@ -6,7 +6,7 @@ Dependency-Check-Core is the main engine used by all of the other modules to do Copyright & License ------------ -Dependency-Check is Copyright (c) 2012-2014 Jeremy Long. All Rights Reserved. +Dependency-Check is Copyright (c) 2012-2026 OWASP Dependency-Check Contributors. All Rights Reserved. Permission to modify and redistribute is granted under the terms of the Apache 2.0 license. See the [LICENSE.txt](https://raw.githubusercontent.com/dependency-check/DependencyCheck/main/LICENSE.txt) file for the full license. diff --git a/core/src/site/site.xml b/core/src/site/site.xml index 42daf544182..871f890e03a 100644 --- a/core/src/site/site.xml +++ b/core/src/site/site.xml @@ -1,4 +1,4 @@ - + - OWASP dependency-check-core @@ -26,10 +26,9 @@ Copyright (c) 2012 Jeremy Long. All Rights Reserved. - - + + - - + \ No newline at end of file diff --git a/maven/NOTICE.txt b/maven/NOTICE.txt index c7d118655e0..f0ffde4afb6 100644 --- a/maven/NOTICE.txt +++ b/maven/NOTICE.txt @@ -1,6 +1,6 @@ dependency-check-maven -Copyright (c) 2013 Jeremy Long. All Rights Reserved. +Copyright (c) 2013-2026 OWASP Dependency-Check Contributors. All Rights Reserved. The licenses for the software listed below can be found in the META-INF/licenses/[dependency name]. diff --git a/maven/README.md b/maven/README.md index 78e6c9705a8..570ce2030a4 100644 --- a/maven/README.md +++ b/maven/README.md @@ -8,7 +8,7 @@ Documentation and links to production binary releases can be found on the [githu Copyright & License ------------------- -Dependency-Check is Copyright (c) 2012-2014 Jeremy Long. All Rights Reserved. +Dependency-Check is Copyright (c) 2012-2026 OWASP Dependency-Check Contributors. All Rights Reserved. Permission to modify and redistribute is granted under the terms of the Apache 2.0 license. See the [LICENSE.txt](https://github.com/dependency-check/DependencyCheck/blob/main/LICENSE.txt) file for the full license. diff --git a/maven/pom.xml b/maven/pom.xml index 8409530ee12..3c7720be2cd 100644 --- a/maven/pom.xml +++ b/maven/pom.xml @@ -30,7 +30,6 @@ Copyright (c) 2013 Jeremy Long. All Rights Reserved. 3.8.1 - 3.16.0 ${java.home} @@ -149,7 +148,7 @@ Copyright (c) 2013 Jeremy Long. All Rights Reserved. org.apache.maven.plugins maven-plugin-plugin - ${version.maven-plugin-plugin} + 3.16.0 dependency-check @@ -168,6 +167,14 @@ Copyright (c) 2013 Jeremy Long. All Rights Reserved. + + org.apache.maven.plugins + maven-site-plugin + + + true + + @@ -267,7 +274,18 @@ Copyright (c) 2013 Jeremy Long. All Rights Reserved. org.apache.maven.plugins maven-plugin-report-plugin - ${version.maven-plugin-plugin} + 3.16.0 + + + org.apache.maven.plugins + maven-project-info-reports-plugin + 3.9.0 + + + + + + diff --git a/maven/src/site/markdown/configuration.md b/maven/src/site/markdown/configuration.md index ba04d4f9696..7c016c6af72 100644 --- a/maven/src/site/markdown/configuration.md +++ b/maven/src/site/markdown/configuration.md @@ -126,15 +126,15 @@ RetireJS Configuration If using the [experimental](../analyzers/index.html) RetireJS Analyzer the following configuration options are available to control the included JS files -###Example -
-    <retirejs>
-        <filters>
-            <filter>Copyright\(c\) Jeremy Long</filter>
-        </filters>
-        <filterNonVulnerable>true</filterNonVulnerable>
-    </retirejs>
-
+### Example +```xml + + + Copyright\(c\) Jeremy Long + + true + +``` | Property | Description | Default Value | |---------------------|-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------| diff --git a/maven/src/site/site.xml b/maven/src/site/site.xml index 72997dae05b..8a17403a97f 100644 --- a/maven/src/site/site.xml +++ b/maven/src/site/site.xml @@ -16,8 +16,8 @@ limitations under the License. Copyright (c) 2013 Jeremy Long. All Rights Reserved. --> - OWASP dependency-check-maven @@ -31,7 +31,6 @@ Copyright (c) 2013 Jeremy Long. All Rights Reserved.
- - + diff --git a/pom.xml b/pom.xml index ad9a322722d..f70b3e2bea9 100644 --- a/pom.xml +++ b/pom.xml @@ -117,15 +117,6 @@ Copyright (c) 2012 - Jeremy Long UTF-8 UTF-8 - - 3.6.0 - 9.3 - 3.11.0 - 3.12.0 - 3.9.0 - 0.8.15 - 4.10.4.0 - 2.0.19 1.5.34 @@ -182,7 +173,7 @@ Copyright (c) 2012 - Jeremy Long org.jacoco jacoco-maven-plugin - ${jacoco-maven-plugin.version} + 0.8.15 org.apache.maven.plugins @@ -202,7 +193,7 @@ Copyright (c) 2012 - Jeremy Long org.apache.maven.plugins maven-dependency-plugin - ${maven-dependency-plugin.version} + 3.11.0 org.apache.maven.plugins @@ -217,7 +208,7 @@ Copyright (c) 2012 - Jeremy Long org.apache.maven.plugins maven-deploy-plugin - 3.1.4 + 3.2.0 org.apache.maven.plugins @@ -232,7 +223,7 @@ Copyright (c) 2012 - Jeremy Long org.apache.maven.plugins maven-install-plugin - 3.1.4 + 3.2.0 org.apache.maven.plugins @@ -272,7 +263,7 @@ Copyright (c) 2012 - Jeremy Long org.apache.maven.plugins maven-surefire-plugin - 3.5.6 + 3.6.0 org.apache.maven.plugins @@ -287,7 +278,7 @@ Copyright (c) 2012 - Jeremy Long org.apache.maven.plugins maven-javadoc-plugin - ${maven-javadoc-plugin.version} + 3.12.0 - 2.5 - - - org.apache.maven.plugins - maven-checkstyle-plugin - ${maven-checkstyle-plugin.version} - - false - false - **/HelpMojo.java - ${odc.config}/checkstyle-checks.xml - ${odc.config}/checkstyle-header.txt - ${odc.config}/checkstyle-suppressions.xml - checkstyle.suppressions.file - - - - org.apache.maven.plugins - maven-project-info-reports-plugin - ${maven-project-info-reports-plugin.version} - - - - summary - issue-management - modules - team - scm - ci-management - licenses - - - - - - org.apache.maven.plugins - maven-surefire-report-plugin - 3.5.6 - - - - report-only - failsafe-report-only - - - - - - org.jacoco - jacoco-maven-plugin - ${jacoco-maven-plugin.version} - - - ${project.basedir}/target/jacoco.exec - - - - - - report - - - - - - com.github.spotbugs - spotbugs-maven-plugin - ${spotbugs.maven.plugin.version} - - ${odc.config}/spotbugs_excludes.xml - - - - org.codehaus.mojo - taglist-maven-plugin - 3.2.2 - - - - - Todo Work - - - todo - ignoreCase - - - FIXME - exact - - - - - - - - - org.codehaus.mojo - versions-maven-plugin - - - - dependency-updates-report - plugin-updates-report - - - - - - diff --git a/src/main/config/version-rules.xml b/src/main/config/version-rules.xml deleted file mode 100644 index 178736484ff..00000000000 --- a/src/main/config/version-rules.xml +++ /dev/null @@ -1,7 +0,0 @@ - - - .*[-_\.](alpha|Alpha|ALPHA|b|beta|Beta|BETA|rc|RC|M|EA)[-_\.]?[0-9]* - - \ No newline at end of file diff --git a/src/site/markdown/dependency-check-jenkins/index.md b/src/site/markdown/dependency-check-jenkins/index.md index 65de5a4a4e4..2a5bdd462ac 100644 --- a/src/site/markdown/dependency-check-jenkins/index.md +++ b/src/site/markdown/dependency-check-jenkins/index.md @@ -13,7 +13,7 @@ Note, not all of the features in the HTML report produced by dependency-check, w Copyright & License ------------------- -Dependency-Check is Copyright (c) 2012-2014 Jeremy Long. All Rights Reserved. +Dependency-Check is Copyright (c) 2012-2026 OWASP Dependency-Check Contributors. All Rights Reserved. Dependency-Check Jenkins Plugin is Copyright (c) 2013-2014 Steve Springett. All Rights Reserved. diff --git a/src/site/markdown/related.md b/src/site/markdown/related.md index 1c572775f4e..18ef5f78afd 100644 --- a/src/site/markdown/related.md +++ b/src/site/markdown/related.md @@ -8,23 +8,27 @@ Related FOSS Projects ------------------------ * [The Victims Project](https://github.com/victims) * [Ruby Bundler-Audit](https://github.com/rubysec/bundler-audit) -* [Retire.js](http://bekk.github.io/retire.js/) -* [NPM Public Advisories](https://www.npmjs.com/advisories) +* [Retire.js](https://retirejs.github.io/retire.js/) +* [Trivy](https://trivy.dev/) +* [OSV-Scanner](https://google.github.io/osv-scanner/) Vulnerability Sources ------------------------ -The following are sources of vulnerability information. Dependency-check only uses information in the [National Vulnerability +The following are sources of vulnerability information. Dependency-check primarily uses information in the [National Vulnerability Database (NVD)](https://nvd.nist.gov/). The other sources listed below contain vulnerability information that may not be included in the NVD. -* [vFeed](http://www.toolswatch.org/vfeed) -* [Sonatype Guide OSS Index](https://www.sonatype.com/products/sonatype-guide/oss-index-users) +* [vFeed](https://vfeed.io/) +* [OSV](https://osv.dev/) +* [GitHub Advisory Database](https://github.com/advisories) +* [Sonatype Guide OSS Index](https://guide.sonatype.com/) (commercial beyond a free use tier) Related Commercial Products ------------------------ The below list is merely informational. It is not a complete list, nor do the authors of dependency-check endorse any of the products listed below. -* [SRC:CLR](https://srcclr.com/) -* [Sonatype Nexus Intelligence](https://www.sonatype.com/nexus-intelligence) and [Sonatype Nexus Lifecycle](https://www.sonatype.com/nexus-lifecycle) -* [Palamida](http://www.palamida.com/products/enterpriseedition.html) -* [Black Duck](https://www.blackducksoftware.com/products/black-duck-suite/code-center) +* [Aqua Security](https://www.aquasec.com/products/software-supply-chain-security/) +* [Black Duck](https://www.blackduck.com/software-composition-analysis-tools/black-duck-sca.html) +* [Revenera SCA](https://www.revenera.com/software-composition-analysis/products/flexnet-code-insight) +* [Sonatype Intelligence](https://www.sonatype.com/products/intelligence) and [Sonatype Lifecycle](https://www.sonatype.com/products/open-source-security-dependency-management) +* [Snyk](https://snyk.io/product/open-source-security-management/) diff --git a/src/site/site.xml b/src/site/site.xml index d66aa222f05..31257571c16 100644 --- a/src/site/site.xml +++ b/src/site/site.xml @@ -1,4 +1,4 @@ - + - org.apache.maven.skins @@ -33,10 +33,6 @@ Copyright (c) 2013 Jeremy Long. All Rights Reserved. right gray - - ctxt - true - @@ -144,7 +140,6 @@ Copyright (c) 2013 Jeremy Long. All Rights Reserved. - - + diff --git a/utils/src/site/site.xml b/utils/src/site/site.xml index c47ca30b5bb..febf52669e2 100644 --- a/utils/src/site/site.xml +++ b/utils/src/site/site.xml @@ -1,6 +1,6 @@ - + - + - OWASP dependency-check-utils - OWASP dependency-check-utils - ./images/dc-utils.svg + OWASP dependency-check-utils - - - + + + + - \ No newline at end of file + \ No newline at end of file