Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ci chore: vulnerability scan is failing after 6h #125

Closed
lread opened this issue Jul 1, 2024 · 3 comments
Closed

ci chore: vulnerability scan is failing after 6h #125

lread opened this issue Jul 1, 2024 · 3 comments

Comments

@lread
Copy link
Collaborator

lread commented Jul 1, 2024

No description provided.

@lread
Copy link
Collaborator Author

lread commented Jul 1, 2024

There are several issues about this over at DependencyCheck, for example: jeremylong/DependencyCheck#6760. If I understand it, the NIST data feeds are not working very well these days. I'll try a couple of things here:

  1. Bump DependencyCheck to v10. I don't know if this will help, but a current local test with v10 is doing better than the local test I tried yesterday with the current transitive dep of v9.0.8.
  2. Change the database caching strategy. The NIST data feeds recently changed to support downloading database updates instead of the entire database. Our current caching strategy is 1d, so I don't think we take advantage of this.

@damu9618
Copy link

damu9618 commented Jul 1, 2024

@lread Thanks for the input, However I have jeremylong/DependencyCheck#6760 this issue post upgrade to depdendencycheck v10

@lread
Copy link
Collaborator Author

lread commented Jul 1, 2024

Thanks, @damu9618. I noticed that. I'm not clear on the root cause yet. Is it not that the NIST data feeds are misbehaving these days? I was guessing that bumping to DependencyCheck latest (v10) would not hurt my situation, but I could be wrong.

@lread lread closed this as completed in 707d19b Jul 2, 2024
lread added a commit that referenced this issue Jul 2, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants