How to stay on top of OWASP dependencycheck reports

150 Views Asked by At

We are using OWASP dependency check. It's a great tool, but it reports lots of vulnerabilities. A big proportion of them is false positives. We can suppress them using the suppression file, but with microservices, we have to do it in each repo, which is time-consuming. Is there a better way? We do not have the budget for Snyk and similar tools

2

There are 2 best solutions below

0
Lukas On

There are multiple options

  1. Share the suppression file, you can specify the remote URL in the dependency check plugins.
  2. Use Dependency Shield to streamline the flow
0
Jonathan Gruber On

you could use the free version of Snyk. If you disable PR tests you can scan a lot of projects under the 200 scans/month limit You won't have a centralized reporting but CICD scans should be effective and you can generate local reports and export in JSON