You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Dependency-Check插件离线模式(mvn -o)运行问题求助

Dependency-Check Maven插件离线模式兼容解决方案

核心问题

Dependency-Check插件默认强制校验Maven在线状态,即便已同步所有本地资源,该硬编码检查仍会阻断离线执行。以下是可行的解决方法:


1. 跳过插件的在线模式检查

在插件配置中添加<skipOnlineCheck>true</skipOnlineCheck>参数,直接绕过插件自身的在线校验逻辑。同时配置本地数据存储和依赖镜像地址,确保插件完全使用本地资源:

<plugin>
    <groupId>org.owasp</groupId>
    <artifactId>dependency-check-maven</artifactId>
    <version>替换为你的插件版本</version>
    <configuration>
        <!-- 关键:跳过在线模式检查 -->
        <skipOnlineCheck>true</skipOnlineCheck>
        <!-- 指定本地NVD数据存储目录(需先在联网环境同步数据) -->
        <dataDirectory>${project.basedir}/.dependency-check-data</dataDirectory>
        <!-- 延长本地NVD数据有效期,避免触发自动在线更新 -->
        <cveValidForHours>720</cveValidForHours>
        <!-- 指向本地依赖仓库镜像 -->
        <mirrorList>file:///path/to/your/local/maven/repo</mirrorList>
    </configuration>
</plugin>

2. 预同步本地NVD数据

在联网环境下执行一次完整的插件扫描,让插件下载并存储最新的NVD漏洞数据到上述dataDirectory目录:

mvn dependency-check:check

之后将该目录同步到离线环境的机器上,确保离线扫描时插件能直接读取本地数据,无需联网更新。

3. 替代mvn -o的离线配置(可选)

如果直接使用mvn -o仍有问题,可以通过修改Maven settings.xml强制所有请求指向本地仓库,无需依赖-o参数:

<settings>
    <mirrors>
        <mirror>
            <id>local-repo-mirror</id>
            <mirrorOf>*</mirrorOf>
            <url>file:///path/to/your/local/maven/repo</url>
        </mirror>
    </mirrors>
    <profiles>
        <profile>
            <id>local-only</id>
            <activation>
                <activeByDefault>true</activeByDefault>
            </activation>
            <repositories>
                <repository>
                    <id>central</id>
                    <url>file:///path/to/your/local/maven/repo</url>
                    <releases><enabled>true</enabled></releases>
                    <snapshots><enabled>false</enabled></snapshots>
                </repository>
            </repositories>
            <pluginRepositories>
                <pluginRepository>
                    <id>central</id>
                    <url>file:///path/to/your/local/maven/repo</url>
                    <releases><enabled>true</enabled></releases>
                    <snapshots><enabled>false</enabled></snapshots>
                </pluginRepository>
            </pluginRepositories>
        </profile>
    </profiles>
</settings>

此时执行mvn dependency-check:check就会完全使用本地资源,同时插件已跳过在线检查,可正常运行。

注意事项

  • 确保使用6.0版本及以上的Dependency-Check插件,旧版本没有skipOnlineCheck参数。
  • 本地仓库必须包含项目所有依赖、插件自身依赖,以及预同步的NVD数据。
  • 定期在联网环境更新NVD数据并同步到离线环境,保证漏洞扫描的准确性。

内容的提问来源于stack exchange,提问作者badr dahmane

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.14 00:19:59