bash
<plugin>
<groupId>org.owasp</groupId>
<artifactId>dependency-check-maven</artifactId>
<version>10.0.3</version>
<configuration>
<!-- 设置 CVSS 分数阈值,超过此值构建失败 -->
<failBuildOnCVSS>1000</failBuildOnCVSS>
<!-- 自动更新漏洞数据库 -->
<autoUpdate>false</autoUpdate>
<!-- 配置 NVD API Key -->
<nvdApiKey>02577e78-8a54-4bdb-a1dd-78a917814183</nvdApiKey>
<!-- 关闭 Sonatype OSS Index 分析器(避免凭证错误) -->
<ossindexAnalyzerEnabled>false</ossindexAnalyzerEnabled>
</configuration>
<executions>
<execution>
<goals>
<goal>aggregate</goal>
</goals>
</execution>
</executions>
</plugin>
检测示例
