Skip to content

build: scan only what the library ships with OWASP - #8

Merged
ahincho merged 1 commit into
mainfrom
build/owasp-library-scope
Sep 30, 2026
Merged

ahincho merged 1 commit into
mainfrom
build/owasp-library-scope

Conversation

@ahincho

@ahincho ahincho commented Sep 30, 2026

Copy link
Copy Markdown
Owner

Qué cambia

El análisis de OWASP recorría todas las configuraciones de Gradle, y fallaba por vulnerabilidades de Checkstyle y de PIT (commons-beanutils, commons-lang3, plexus-utils, httpclient5 y httpcore5) que no viajan con la librería. Ahora analiza lo mismo que el toolchain de Nova (ADR-044): compileClasspath y runtimeClasspath.

Con esto vuelve a pasar el check de OWASP, que hoy falla en cualquier PR de este repositorio, incluido el #7. En nova-java-01-api-standard se aplica el mismo cambio en su propio PR.

Cómo se probó

./gradlew help configura sin errores. El check de OWASP de este PR confirma el resultado en el CI.

@ahincho ahincho self-assigned this Sep 30, 2026
@ahincho
ahincho merged commit b0acfe3 into main Sep 30, 2026
7 checks passed
@ahincho
ahincho deleted the build/owasp-library-scope branch September 30, 2026 23:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant