如何使用OWASP Dependency-Check扫描系统中的指定非依赖产品?
用OWASP Dependency-Check扫描非依赖组件的可行方案
针对你想用OWASP Dependency-Check扫描JDK、数据库这类非项目正式依赖组件的需求,以下是几种可行的实现方式:
1. 命令行工具直接传入CPE参数
Dependency-Check的命令行工具支持直接指定CPE进行扫描,你只需指定一个扫描目录(空目录也可),通过--cpe参数传入目标CPE:
# Linux/macOS dependency-check.sh --scan ./empty-dummy-dir --cpe "cpe:2.3:a:eclipse:temurin:21.0.9" # Windows dependency-check.bat --scan .\empty-dummy-dir --cpe "cpe:2.3:a:eclipse:temurin:21.0.9"
扫描器会将传入的CPE当作待检查组件,匹配漏洞库生成报告。
2. Maven插件配置指定CPE
若习惯用Maven插件,可在项目pom.xml中给Dependency-Check插件添加CPE配置,让扫描时纳入该CPE:
<build> <plugins> <plugin> <groupId>org.owasp</groupId> <artifactId>dependency-check-maven</artifactId> <version>最新版本号</version> <executions> <execution> <goals> <goal>check</goal> </goals> </execution> </executions> <configuration> <cpes> <cpe>cpe:2.3:a:eclipse:temurin:21.0.9</cpe> </cpes> </configuration> </plugin> </plugins> </build>
执行mvn dependency-check:check时,插件会把配置的CPE加入扫描范围。
3. 创建Dummy Artifact
你可以创建一个极简的dummy Maven项目(或模块),在pom.xml中添加自定义依赖,再通过配置让Dependency-Check关联该依赖到目标CPE:
- 新建dummy项目,pom.xml中添加:
<dependencies> <dependency> <groupId>com.custom.dummy</groupId> <artifactId>temurin-jdk-21</artifactId> <version>21.0.9</version> <scope>provided</scope> </dependency> </dependencies>
- 编写Dependency-Check的hints文件(比如
src/main/resources/dependency-check-hints.xml),将dummy依赖映射到目标CPE:
<?xml version="1.0" encoding="UTF-8"?> <hints xmlns="https://jeremylong.github.io/DependencyCheck/dependency-hints.1.0.xsd"> <hint> <given> <groupId>com.custom.dummy</groupId> <artifactId>temurin-jdk-21</artifactId> <version>21.0.9</version> </given> <add> <cpe>cpe:2.3:a:eclipse:temurin:21.0.9</cpe> </add> </hint> </hints>
- 执行Maven扫描命令,插件会识别这个dummy依赖并关联指定CPE进行漏洞检查。
4. 直接调用扫描器JAR代码
若需自定义扫描逻辑,可直接依赖Dependency-Check的核心库,编写代码传入CPE进行扫描:
import org.owasp.dependencycheck.Engine; import org.owasp.dependencycheck.dependency.Dependency; import org.owasp.dependencycheck.exception.ExceptionCollection; public class CustomScanner { public static void main(String[] args) throws ExceptionCollection { try (Engine engine = new Engine()) { // 创建依赖对象并设置CPE Dependency dep = new Dependency(); dep.setCpe("cpe:2.3:a:eclipse:temurin:21.0.9"); dep.setName("Eclipse Temurin JDK 21.0.9"); dep.setVersion("21.0.9"); // 添加到引擎并扫描 engine.scan(dep); engine.analyzeDependencies(); // 生成报告或处理结果 engine.writeReports("./scan-report"); } } }
需在项目中引入Dependency-Check的核心依赖,版本可参考官方Maven坐标。
5. Hints File方式(你计划尝试的方案)
Hints File是最灵活的方式之一,适合扫描本地安装的组件(如JDK目录、数据库安装目录):
- 创建
dependency-check-hints.xml文件:
<?xml version="1.0" encoding="UTF-8"?> <hints xmlns="https://jeremylong.github.io/DependencyCheck/dependency-hints.1.0.xsd"> <hint> <given> <!-- 匹配JDK安装目录下的关键文件,比如rt.jar --> <filePath regex="true">.*temurin-21.0.9.*rt\.jar</filePath> </given> <add> <cpe>cpe:2.3:a:eclipse:temurin:21.0.9</cpe> </add> </hint> </hints>
- 用命令行扫描JDK安装目录并指定hints文件:
dependency-check.sh --scan /path/to/temurin-21.0.9 --hint ./dependency-check-hints.xml
扫描器会根据hints中的规则匹配目录下的文件,自动关联到指定CPE进行漏洞检查。
内容的提问来源于stack exchange,提问作者Lii
相关产品推荐
相关产品推荐

