Title: Improve detection of CVE-affected components · Issue #38 · scijava/pom-scijava-base · GitHub
Open Graph Title: Improve detection of CVE-affected components · Issue #38 · scijava/pom-scijava-base
X Title: Improve detection of CVE-affected components · Issue #38 · scijava/pom-scijava-base
Description: As discussed in this Zulip thread, we can do more to check for CVEs impacting dependencies in SciJava-based projects: Any build extending pom-scijava-base (either directly or indirectly via pom-scijava) should have an easily accessible b...
Open Graph Description: As discussed in this Zulip thread, we can do more to check for CVEs impacting dependencies in SciJava-based projects: Any build extending pom-scijava-base (either directly or indirectly via pom-sci...
X Description: As discussed in this Zulip thread, we can do more to check for CVEs impacting dependencies in SciJava-based projects: Any build extending pom-scijava-base (either directly or indirectly via pom-sci...
Opengraph URL: https://github.com/scijava/pom-scijava-base/issues/38
X: @github
Domain: patch-diff.githubusercontent.com
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"Improve detection of CVE-affected components","articleBody":"As discussed in [this Zulip thread](https://imagesc.zulipchat.com/#narrow/channel/327237-SciJava/topic/Security.20and.20CVEs.20in.20Old.20Native.20Libraries/with/535708343), we can do more to check for CVEs impacting dependencies in SciJava-based projects:\n1. Any build extending pom-scijava-base (either directly or indirectly via pom-scijava) should have an easily accessible build mode (goal, profile, whatever) for running the `dependency-check-maven-plugin` from `org.owasp` to check its dependency tree for security issues.\n2. Any BOM extend pom-scijava-base (notably pom-scijava, but not necessarily limited to that) should be able to invoke the `dependency-check-maven-plugin` as well on all managed components, not just active dependencies.\n3. Trickier are managed JAR components that wrap native code. It might be limitedly possible to catch them with the `dependency-check-maven-plugin` by ensuring all the scanning modes are enabled:\n ```xml\n \u003cconfiguration\u003e\n \u003cassemblyAnalyzerEnabled\u003etrue\u003c/assemblyAnalyzerEnabled\u003e\n \u003carchiveAnalyzerEnabled\u003etrue\u003c/archiveAnalyzerEnabled\u003e\n \u003cjarAnalyzerEnabled\u003etrue\u003c/jarAnalyzerEnabled\u003e\n \u003c/configuration\u003e\n ```\n but it's imperfect at best.\n\nWe do already use Dependabot on GitHub with both pom-scijava-base and pom-scijava, but it has not reported much of anything in recent years, so I wonder how effective those scans actually are.","author":{"url":"https://github.com/ctrueden","@type":"Person","name":"ctrueden"},"datePublished":"2025-08-22T15:59:11.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":0},"url":"https://github.com/38/pom-scijava-base/issues/38"}
| route-pattern | /_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format) |
| route-controller | voltron_issues_fragments |
| route-action | issue_layout |
| fetch-nonce | v2:88c01424-6031-eb78-1611-4d65c21fc833 |
| current-catalog-service-hash | 81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114 |
| request-id | B728:6CA27:1EE12F:295C59:6970298F |
| html-safe-nonce | c7d28582d22d995e6e15c0eac1d6ae5dccc05dda29fa7169cf009d2a33fd8386 |
| visitor-payload | eyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJCNzI4OjZDQTI3OjFFRTEyRjoyOTVDNTk6Njk3MDI5OEYiLCJ2aXNpdG9yX2lkIjoiODEwMzQ5ODY0MDkxMjI5NjMzNiIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9 |
| visitor-hmac | 01d229af7f7a6324d852b86e81b959373e24b65eeb380fb0512ca49b1f4a3262 |
| hovercard-subject-tag | issue:3345939878 |
| github-keyboard-shortcuts | repository,issues,copilot |
| google-site-verification | Apib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I |
| octolytics-url | https://collector.github.com/github/collect |
| analytics-location | / |
| fb:app_id | 1401488693436528 |
| apple-itunes-app | app-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/scijava/pom-scijava-base/38/issue_layout |
| twitter:image | https://opengraph.githubassets.com/9b19c2a6882fcfb1ba22840dc7a5c94b28ca3907c98974ab912170424e646a57/scijava/pom-scijava-base/issues/38 |
| twitter:card | summary_large_image |
| og:image | https://opengraph.githubassets.com/9b19c2a6882fcfb1ba22840dc7a5c94b28ca3907c98974ab912170424e646a57/scijava/pom-scijava-base/issues/38 |
| og:image:alt | As discussed in this Zulip thread, we can do more to check for CVEs impacting dependencies in SciJava-based projects: Any build extending pom-scijava-base (either directly or indirectly via pom-sci... |
| og:image:width | 1200 |
| og:image:height | 600 |
| og:site_name | GitHub |
| og:type | object |
| og:author:username | ctrueden |
| hostname | github.com |
| expected-hostname | github.com |
| None | 01fa379f5de85ef8e791d09724e69709ce9eb9595278316e0a921312dc88e0bc |
| turbo-cache-control | no-preview |
| go-import | github.com/scijava/pom-scijava-base git https://github.com/scijava/pom-scijava-base.git |
| octolytics-dimension-user_id | 1262770 |
| octolytics-dimension-user_login | scijava |
| octolytics-dimension-repository_id | 72131582 |
| octolytics-dimension-repository_nwo | scijava/pom-scijava-base |
| octolytics-dimension-repository_public | true |
| octolytics-dimension-repository_is_fork | false |
| octolytics-dimension-repository_network_root_id | 72131582 |
| octolytics-dimension-repository_network_root_nwo | scijava/pom-scijava-base |
| turbo-body-classes | logged-out env-production page-responsive |
| disable-turbo | false |
| browser-stats-url | https://api.github.com/_private/browser/stats |
| browser-errors-url | https://api.github.com/_private/browser/errors |
| release | dda91974c069382b0dfa47b2da7e28bd061c8331 |
| ui-target | full |
| theme-color | #1e2327 |
| color-scheme | light dark |
Links:
Viewport: width=device-width