You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何使用OWASP Dependency-Check扫描系统中的指定非依赖产品?

用OWASP Dependency-Check扫描非依赖组件的可行方案

针对你想用OWASP Dependency-Check扫描JDK、数据库这类非项目正式依赖组件的需求,以下是几种可行的实现方式:

1. 命令行工具直接传入CPE参数

Dependency-Check的命令行工具支持直接指定CPE进行扫描,你只需指定一个扫描目录(空目录也可),通过--cpe参数传入目标CPE:

# Linux/macOS
dependency-check.sh --scan ./empty-dummy-dir --cpe "cpe:2.3:a:eclipse:temurin:21.0.9"

# Windows
dependency-check.bat --scan .\empty-dummy-dir --cpe "cpe:2.3:a:eclipse:temurin:21.0.9"

扫描器会将传入的CPE当作待检查组件,匹配漏洞库生成报告。

2. Maven插件配置指定CPE

若习惯用Maven插件,可在项目pom.xml中给Dependency-Check插件添加CPE配置,让扫描时纳入该CPE:

<build>
    <plugins>
        <plugin>
            <groupId>org.owasp</groupId>
            <artifactId>dependency-check-maven</artifactId>
            <version>最新版本号</version>
            <executions>
                <execution>
                    <goals>
                        <goal>check</goal>
                    </goals>
                </execution>
            </executions>
            <configuration>
                <cpes>
                    <cpe>cpe:2.3:a:eclipse:temurin:21.0.9</cpe>
                </cpes>
            </configuration>
        </plugin>
    </plugins>
</build>

执行mvn dependency-check:check时,插件会把配置的CPE加入扫描范围。

3. 创建Dummy Artifact

你可以创建一个极简的dummy Maven项目(或模块),在pom.xml中添加自定义依赖,再通过配置让Dependency-Check关联该依赖到目标CPE:

  1. 新建dummy项目,pom.xml中添加:
<dependencies>
    <dependency>
        <groupId>com.custom.dummy</groupId>
        <artifactId>temurin-jdk-21</artifactId>
        <version>21.0.9</version>
        <scope>provided</scope>
    </dependency>
</dependencies>
  1. 编写Dependency-Check的hints文件(比如src/main/resources/dependency-check-hints.xml),将dummy依赖映射到目标CPE:
<?xml version="1.0" encoding="UTF-8"?>
<hints xmlns="https://jeremylong.github.io/DependencyCheck/dependency-hints.1.0.xsd">
    <hint>
        <given>
            <groupId>com.custom.dummy</groupId>
            <artifactId>temurin-jdk-21</artifactId>
            <version>21.0.9</version>
        </given>
        <add>
            <cpe>cpe:2.3:a:eclipse:temurin:21.0.9</cpe>
        </add>
    </hint>
</hints>
  1. 执行Maven扫描命令,插件会识别这个dummy依赖并关联指定CPE进行漏洞检查。

4. 直接调用扫描器JAR代码

若需自定义扫描逻辑,可直接依赖Dependency-Check的核心库,编写代码传入CPE进行扫描:

import org.owasp.dependencycheck.Engine;
import org.owasp.dependencycheck.dependency.Dependency;
import org.owasp.dependencycheck.exception.ExceptionCollection;

public class CustomScanner {
    public static void main(String[] args) throws ExceptionCollection {
        try (Engine engine = new Engine()) {
            // 创建依赖对象并设置CPE
            Dependency dep = new Dependency();
            dep.setCpe("cpe:2.3:a:eclipse:temurin:21.0.9");
            dep.setName("Eclipse Temurin JDK 21.0.9");
            dep.setVersion("21.0.9");
            
            // 添加到引擎并扫描
            engine.scan(dep);
            engine.analyzeDependencies();
            
            // 生成报告或处理结果
            engine.writeReports("./scan-report");
        }
    }
}

需在项目中引入Dependency-Check的核心依赖,版本可参考官方Maven坐标。

5. Hints File方式(你计划尝试的方案)

Hints File是最灵活的方式之一,适合扫描本地安装的组件(如JDK目录、数据库安装目录):

  1. 创建dependency-check-hints.xml文件:
<?xml version="1.0" encoding="UTF-8"?>
<hints xmlns="https://jeremylong.github.io/DependencyCheck/dependency-hints.1.0.xsd">
    <hint>
        <given>
            <!-- 匹配JDK安装目录下的关键文件,比如rt.jar -->
            <filePath regex="true">.*temurin-21.0.9.*rt\.jar</filePath>
        </given>
        <add>
            <cpe>cpe:2.3:a:eclipse:temurin:21.0.9</cpe>
        </add>
    </hint>
</hints>
  1. 用命令行扫描JDK安装目录并指定hints文件:
dependency-check.sh --scan /path/to/temurin-21.0.9 --hint ./dependency-check-hints.xml

扫描器会根据hints中的规则匹配目录下的文件,自动关联到指定CPE进行漏洞检查。

内容的提问来源于stack exchange,提问作者Lii

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.02 01:02:29