1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18 package org.owasp.dependencycheck;
19
20 import edu.umd.cs.findbugs.annotations.SuppressFBWarnings;
21 import org.apache.commons.cli.CommandLine;
22 import org.apache.commons.cli.CommandLineParser;
23 import org.apache.commons.cli.DefaultParser;
24 import org.apache.commons.cli.Option;
25 import org.apache.commons.cli.OptionGroup;
26 import org.apache.commons.cli.Options;
27 import org.apache.commons.cli.ParseException;
28 import org.apache.commons.cli.help.HelpFormatter;
29 import org.apache.commons.cli.help.TextHelpAppendable;
30 import org.owasp.dependencycheck.reporting.ReportGenerator.Format;
31 import org.owasp.dependencycheck.utils.InvalidSettingException;
32 import org.owasp.dependencycheck.utils.Settings;
33 import org.slf4j.Logger;
34 import org.slf4j.LoggerFactory;
35
36 import java.io.File;
37 import java.io.FileNotFoundException;
38 import java.io.IOException;
39 import java.io.UncheckedIOException;
40 import java.util.Comparator;
41
42
43
44
45
46
47
48 @SuppressWarnings("squid:S2068")
49 public final class CliParser {
50
51
52
53
54 private static final Logger LOGGER = LoggerFactory.getLogger(CliParser.class);
55
56
57
58 private CommandLine line;
59
60
61
62 private boolean isValid = true;
63
64
65
66 private final Settings settings;
67
68
69
70 private static final String SUPPORTED_FORMATS = "HTML, XML, CSV, JSON, JUNIT, SARIF, JENKINS, GITLAB or ALL";
71
72 private static final String HELP_MSG = String.format(
73 "Dependency-Check can be used to identify if there are any known CVE vulnerabilities in libraries " +
74 "utilized by an application. Dependency-Check will automatically update required data from the " +
75 "Internet, such as the CVE and CPE data files from nvd.nist.gov.%n"
76 );
77
78
79
80
81
82
83 public CliParser(Settings settings) {
84 this.settings = settings;
85 }
86
87
88
89
90
91
92
93
94
95 public void parse(String... args) throws FileNotFoundException, ParseException {
96 line = parseArgs(args);
97
98 if (line != null) {
99 validateArgs();
100 }
101 }
102
103
104
105
106
107
108
109
110 private CommandLine parseArgs(String... args) throws ParseException {
111 final CommandLineParser parser = new DefaultParser();
112 final Options options = createCommandLineOptions();
113 return parser.parse(options, args);
114 }
115
116
117
118
119
120
121
122
123
124 private void validateArgs() throws FileNotFoundException, ParseException {
125 if (isUpdateOnly() || isRunScan()) {
126
127 String value = line.getOptionValue(ARGUMENT.NVD_API_VALID_FOR_HOURS);
128 if (value != null) {
129 try {
130 final int i = Integer.parseInt(value);
131 if (i < 0) {
132 throw new ParseException("Invalid Setting: nvdValidForHours must be a number greater than or equal to 0.");
133 }
134 } catch (NumberFormatException ex) {
135 throw new ParseException("Invalid Setting: nvdValidForHours must be a number greater than or equal to 0.");
136 }
137 }
138 value = line.getOptionValue(ARGUMENT.NVD_API_MAX_RETRY_COUNT);
139 if (value != null) {
140 try {
141 final int i = Integer.parseInt(value);
142 if (i <= 0) {
143 throw new ParseException("Invalid Setting: nvdMaxRetryCount must be a number greater than 0.");
144 }
145 } catch (NumberFormatException ex) {
146 throw new ParseException("Invalid Setting: nvdMaxRetryCount must be a number greater than 0.");
147 }
148 }
149 value = line.getOptionValue(ARGUMENT.NVD_API_DELAY);
150 if (value != null) {
151 try {
152 final int i = Integer.parseInt(value);
153 if (i < 0) {
154 throw new ParseException("Invalid Setting: nvdApiDelay must be a number greater than or equal to 0.");
155 }
156 } catch (NumberFormatException ex) {
157 throw new ParseException("Invalid Setting: nvdApiDelay must be a number greater than or equal to 0.");
158 }
159 }
160 value = line.getOptionValue(ARGUMENT.NVD_API_RESULTS_PER_PAGE);
161 if (value != null) {
162 try {
163 final int i = Integer.parseInt(value);
164 if (i <= 0 || i > 2000) {
165 throw new ParseException("Invalid Setting: nvdApiResultsPerPage must be a number in the range [1, 2000].");
166 }
167 } catch (NumberFormatException ex) {
168 throw new ParseException("Invalid Setting: nvdApiResultsPerPage must be a number in the range [1, 2000].");
169 }
170 }
171 }
172 if (isRunScan()) {
173 validatePathExists(getScanFiles(), ARGUMENT.SCAN);
174 validatePathExists(getReportDirectory(), ARGUMENT.OUT);
175 final String pathToCore = getStringArgument(ARGUMENT.PATH_TO_CORE);
176 if (pathToCore != null) {
177 validatePathExists(pathToCore, ARGUMENT.PATH_TO_CORE);
178 }
179 if (line.hasOption(ARGUMENT.OUTPUT_FORMAT)) {
180 for (String validating : getReportFormat()) {
181 if (!isValidFormat(validating)
182 && !isValidFilePath(validating, "format")) {
183 final String msg = String.format("An invalid 'format' of '%s' was specified. "
184 + "Supported output formats are %s, and custom template files.",
185 validating, SUPPORTED_FORMATS);
186 throw new ParseException(msg);
187 }
188 }
189 }
190 if (line.hasOption(ARGUMENT.SYM_LINK_DEPTH)) {
191 try {
192 final int i = Integer.parseInt(line.getOptionValue(ARGUMENT.SYM_LINK_DEPTH));
193 if (i < 0) {
194 throw new ParseException("Symbolic Link Depth (symLink) must be greater than zero.");
195 }
196 } catch (NumberFormatException ex) {
197 throw new ParseException("Symbolic Link Depth (symLink) is not a number.");
198 }
199 }
200 }
201 }
202
203
204
205
206
207
208
209
210 private boolean isValidFormat(String format) {
211 try {
212 Format.valueOf(format);
213 return true;
214 } catch (IllegalArgumentException ex) {
215 return false;
216 }
217 }
218
219
220
221
222
223
224
225
226 private boolean isValidFilePath(String path, @SuppressWarnings("SameParameterValue") String argumentName) {
227 try {
228 validatePathExists(path, argumentName);
229 return true;
230 } catch (FileNotFoundException ex) {
231 return false;
232 }
233 }
234
235
236
237
238
239
240
241
242
243
244
245 private void validatePathExists(String[] paths, @SuppressWarnings("SameParameterValue") String optType) throws FileNotFoundException {
246 for (String path : paths) {
247 validatePathExists(path, optType);
248 }
249 }
250
251
252
253
254
255
256
257
258
259
260
261 private void validatePathExists(String path, String argumentName) throws FileNotFoundException {
262 if (path == null) {
263 isValid = false;
264 final String msg = String.format("Invalid '%s' argument: null", argumentName);
265 throw new FileNotFoundException(msg);
266 } else if (!path.contains("*") && !path.contains("?")) {
267 File f = new File(path);
268 final String[] formats = this.getReportFormat();
269 if ("o".equalsIgnoreCase(argumentName.substring(0, 1)) && formats.length == 1 && !"ALL".equalsIgnoreCase(formats[0])) {
270 final String checkPath = path.toLowerCase();
271 if (checkPath.endsWith(".html") || checkPath.endsWith(".xml") || checkPath.endsWith(".htm")
272 || checkPath.endsWith(".csv") || checkPath.endsWith(".json")) {
273 if (f.getParentFile() == null) {
274 f = new File(".", path);
275 }
276 if (!f.getParentFile().isDirectory()) {
277 isValid = false;
278 final String msg = String.format("Invalid '%s' argument: '%s' - directory path does not exist", argumentName, path);
279 throw new FileNotFoundException(msg);
280 }
281 }
282 } else if ("o".equalsIgnoreCase(argumentName.substring(0, 1)) && !f.isDirectory()) {
283 if (f.getParentFile() != null && f.getParentFile().isDirectory() && !f.mkdir()) {
284 isValid = false;
285 final String msg = String.format("Invalid '%s' argument: '%s' - unable to create the output directory", argumentName, path);
286 throw new FileNotFoundException(msg);
287 }
288 if (!f.isDirectory()) {
289 isValid = false;
290 final String msg = String.format("Invalid '%s' argument: '%s' - path does not exist", argumentName, path);
291 throw new FileNotFoundException(msg);
292 }
293 } else if (!f.exists()) {
294 isValid = false;
295 final String msg = String.format("Invalid '%s' argument: '%s' - path does not exist", argumentName, path);
296 throw new FileNotFoundException(msg);
297 }
298
299
300
301
302 } else if ((path.endsWith("/*") && !path.endsWith("**/*")) || (path.endsWith("\\*") && path.endsWith("**\\*"))) {
303 LOGGER.warn("Possibly incorrect path '{}' from argument '{}' because it ends with a slash star; "
304 + "dependency-check uses ant-style paths", path, argumentName);
305 }
306 }
307
308
309
310
311
312
313
314 private Options createCommandLineOptions() {
315 final Options options = new Options();
316 addStandardOptions(options);
317 addAdvancedOptions(options);
318 addDeprecatedOptions(options);
319 return options;
320 }
321
322
323
324
325
326
327 private void addStandardOptions(final Options options) {
328
329 options.addOptionGroup(newOptionGroup(newOptionWithArg(ARGUMENT.SCAN_SHORT, ARGUMENT.SCAN, "path",
330 "The path to scan - this option can be specified multiple times. Ant style paths are supported (e.g. 'path/**/*.jar'); "
331 + "if using Ant style paths it is highly recommended to quote the argument value.")))
332 .addOptionGroup(newOptionGroup(newOptionWithArg(ARGUMENT.EXCLUDE, "pattern", "Specify an exclusion pattern. This option "
333 + "can be specified multiple times and it accepts Ant style exclusions.")))
334 .addOption(newOptionWithArg(ARGUMENT.PROJECT, "name", "The name of the project being scanned."))
335 .addOption(newOptionWithArg(ARGUMENT.OUT_SHORT, ARGUMENT.OUT, "path",
336 "The folder to write reports to. This defaults to the current directory. It is possible to set this to a specific "
337 + "file name if the format argument is not set to ALL."))
338 .addOption(newOptionWithArg(ARGUMENT.OUTPUT_FORMAT_SHORT, ARGUMENT.OUTPUT_FORMAT, "format",
339 "The report format (" + SUPPORTED_FORMATS + "). The default is HTML. Multiple format parameters can be specified."))
340 .addOption(newOption(ARGUMENT.PRETTY_PRINT, "When specified the JSON and XML report formats will be pretty printed."))
341 .addOption(newOption(ARGUMENT.VERSION_SHORT, ARGUMENT.VERSION, "Print the version information."))
342 .addOption(newOption(ARGUMENT.HELP_SHORT, ARGUMENT.HELP, "Print this message."))
343 .addOption(newOption(ARGUMENT.ADVANCED_HELP, "Print the advanced help message."))
344 .addOption(newOption(ARGUMENT.DISABLE_AUTO_UPDATE_SHORT, ARGUMENT.DISABLE_AUTO_UPDATE,
345 "Disables the automatic updating of the NVD-CVE, hosted-suppressions and RetireJS data."))
346 .addOption(newOptionWithArg(ARGUMENT.VERBOSE_LOG_SHORT, ARGUMENT.VERBOSE_LOG, "file",
347 "The file path to write verbose logging information."))
348 .addOptionGroup(newOptionGroup(newOptionWithArg(ARGUMENT.SUPPRESSION_FILES, "file",
349 "The file path to the suppression XML file. This can be specified more then once to utilize multiple suppression files")))
350 .addOption(newOption(ARGUMENT.DISABLE_VERSION_CHECK, "Disables the dependency-check version check"))
351 .addOption(newOption(ARGUMENT.EXPERIMENTAL, "Enables the experimental analyzers."))
352 .addOption(newOptionWithArg(ARGUMENT.NVD_API_KEY, "apiKey", "The API Key to access the NVD API."))
353 .addOption(newOptionWithArg(ARGUMENT.FAIL_ON_CVSS, "score",
354 "Specifies if the build should be failed if a CVSS score above a specified level is identified. The default is 11; "
355 + "since the CVSS scores are 0-10, by default the build will never fail."))
356 .addOption(newOptionWithArg(ARGUMENT.FAIL_JUNIT_ON_CVSS, "score",
357 "Specifies the CVSS score that is considered a failure when generating the junit report. The default is 0."));
358 }
359
360
361
362
363
364
365
366
367 private void addAdvancedOptions(final Options options) {
368 options
369 .addOption(newOption(ARGUMENT.UPDATE_ONLY,
370 "Only update the local NVD data cache; no scan will be executed."))
371 .addOption(newOptionWithArg(ARGUMENT.NVD_API_DELAY, "milliseconds",
372 "Time in milliseconds to wait between downloading from the NVD."))
373 .addOption(newOptionWithArg(ARGUMENT.NVD_API_RESULTS_PER_PAGE, "count",
374 "The number records for a single page from NVD API (must be <=2000)."))
375 .addOption(newOptionWithArg(ARGUMENT.NVD_API_ENDPOINT, "endpoint",
376 "The NVD API Endpoint - setting this is rare."))
377 .addOption(newOptionWithArg(ARGUMENT.NVD_API_DATAFEED_URL, "url",
378 "The URL to the NVD API Datafeed."))
379 .addOption(newOptionWithArg(ARGUMENT.NVD_API_DATAFEED_USER, "user",
380 "Credentials for basic authentication to the NVD API Datafeed."))
381 .addOption(newOptionWithArg(ARGUMENT.NVD_API_DATAFEED_PASSWORD, "password",
382 "Credentials for basic authentication to the NVD API Datafeed."))
383 .addOption(newOptionWithArg(ARGUMENT.NVD_API_DATAFEED_BEARER_TOKEN, "token",
384 "Credentials for bearer authentication to the NVD API Datafeed."))
385 .addOption(newOptionWithArg(ARGUMENT.SUPPRESSION_FILE_USER, "user",
386 "Credentials for basic authentication to web-hosted suppression files."))
387 .addOption(newOptionWithArg(ARGUMENT.SUPPRESSION_FILE_PASSWORD, "password",
388 "Credentials for basic authentication to web-hosted suppression files."))
389 .addOption(newOptionWithArg(ARGUMENT.SUPPRESSION_FILE_BEARER_TOKEN, "token",
390 "Credentials for bearer authentication to web-hosted suppression files."))
391 .addOption(newOptionWithArg(ARGUMENT.NVD_API_MAX_RETRY_COUNT, "count",
392 "The maximum number of retry requests for a single call to the NVD API."))
393 .addOption(newOptionWithArg(ARGUMENT.NVD_API_VALID_FOR_HOURS, "hours",
394 "The number of hours to wait before checking for new updates from the NVD."))
395 .addOption(newOptionWithArg(ARGUMENT.PROXY_PORT, "port",
396 "The proxy port to use when downloading resources."))
397 .addOption(newOptionWithArg(ARGUMENT.PROXY_SERVER, "server",
398 "The proxy server to use when downloading resources."))
399 .addOption(newOptionWithArg(ARGUMENT.PROXY_USERNAME, "user",
400 "The proxy username to use when downloading resources."))
401 .addOption(newOptionWithArg(ARGUMENT.PROXY_PASSWORD, "pass",
402 "The proxy password to use when downloading resources."))
403 .addOption(newOptionWithArg(ARGUMENT.NON_PROXY_HOSTS, "list",
404 "The proxy exclusion list: hostnames (or patterns) for which proxy should not be used. "
405 + "Use pipe, comma or colon as list separator."))
406 .addOption(newOptionWithArg(ARGUMENT.CONNECTION_TIMEOUT_SHORT, ARGUMENT.CONNECTION_TIMEOUT, "timeout",
407 "The connection timeout (in milliseconds) to use when downloading resources."))
408 .addOption(newOptionWithArg(ARGUMENT.CONNECTION_READ_TIMEOUT, "timeout",
409 "The read timeout (in milliseconds) to use when downloading resources."))
410 .addOption(newOptionWithArg(ARGUMENT.CONNECTION_STRING, "connStr",
411 "The connection string to the database."))
412 .addOption(newOptionWithArg(ARGUMENT.DB_NAME, "user",
413 "The username used to connect to the database."))
414 .addOption(newOptionWithArg(ARGUMENT.DATA_DIRECTORY_SHORT, ARGUMENT.DATA_DIRECTORY, "path",
415 "The location of the H2 Database file. This option should generally not be set."))
416 .addOption(newOptionWithArg(ARGUMENT.DB_PASSWORD, "password",
417 "The password for connecting to the database."))
418 .addOption(newOptionWithArg(ARGUMENT.DB_DRIVER, "driver",
419 "The database driver name."))
420 .addOption(newOptionWithArg(ARGUMENT.DB_DRIVER_PATH, "path",
421 "The path to the database driver; note, this does not need to be set unless the JAR is "
422 + "outside of the classpath."))
423 .addOption(newOptionWithArg(ARGUMENT.SYM_LINK_DEPTH, "depth",
424 "Sets how deep nested symbolic links will be followed; 0 indicates symbolic links will not be followed."))
425 .addOption(newOptionWithArg(ARGUMENT.PATH_TO_BUNDLE_AUDIT, "path",
426 "The path to bundle-audit for Gem bundle analysis."))
427 .addOption(newOptionWithArg(ARGUMENT.PATH_TO_BUNDLE_AUDIT_WORKING_DIRECTORY, "path",
428 "The path to working directory that the bundle-audit command should be executed from when "
429 + "doing Gem bundle analysis."))
430 .addOption(newOptionWithArg(ARGUMENT.CENTRAL_URL, "url",
431 "Alternative URL for Maven Central Search. If not set the public Sonatype Maven Central will be used."))
432 .addOption(newOptionWithArg(ARGUMENT.CENTRAL_USERNAME, "username",
433 "Credentials for basic auth towards the --centralUrl."))
434 .addOption(newOptionWithArg(ARGUMENT.CENTRAL_PASSWORD, "password",
435 "Credentials for basic auth towards the --centralUrl"))
436 .addOption(newOptionWithArg(ARGUMENT.CENTRAL_BEARER_TOKEN, "token",
437 "Token for bearer auth towards the --centralUrl"))
438 .addOption(newOptionWithArg(ARGUMENT.OSSINDEX_CACHE_VALID_FOR_HOURS, "hours",
439 "The number of hours to wait before checking for new updates on individual packages/components from Sonatype OSS Index. The default is 24 hours."))
440 .addOption(newOptionWithArg(ARGUMENT.OSSINDEX_URL, "url",
441 "Alternative base URL for the OSS Index API. If not set the public Sonatype OSS Index API on Sonatype Guide will be used."))
442 .addOption(newOptionWithArg(ARGUMENT.OSSINDEX_USERNAME, "username",
443 "(deprecated) Sets the OSS Index API username for use with legacy OSS Index API tokens. " +
444 "Username is not required after migration to using Sonatype Guide personal access token as password."))
445 .addOption(newOptionWithArg(ARGUMENT.OSSINDEX_PASSWORD, "password", "Sets the Sonatype Guide personal " +
446 "access token or (deprecated) legacy OSS Index API token to authenticate with."))
447 .addOption(newOptionWithArg(ARGUMENT.OSSINDEX_WARN_ONLY_ON_REMOTE_ERRORS, "true/false",
448 "Whether a Sonatype OSS Index remote error should result in a warning only or a failure."))
449 .addOption(newOption(ARGUMENT.RETIRE_JS_FORCEUPDATE, "Force the RetireJS Analyzer to update "
450 + "even if autoupdate is disabled"))
451 .addOption(newOptionWithArg(ARGUMENT.RETIREJS_URL, "url",
452 "The Retire JS Repository URL"))
453 .addOption(newOptionWithArg(ARGUMENT.RETIREJS_URL_USER, "username",
454 "Credentials for basic auth towards the Retire JS Repository URL"))
455 .addOption(newOptionWithArg(ARGUMENT.RETIREJS_URL_PASSWORD, "password",
456 "Credentials for basic auth towards the Retire JS Repository URL"))
457 .addOption(newOptionWithArg(ARGUMENT.RETIREJS_URL_BEARER_TOKEN, "token",
458 "Token for bearer auth towards the Retire JS Repository URL"))
459 .addOption(newOption(ARGUMENT.RETIRE_JS_FILTER_NON_VULNERABLE, "Specifies that the Retire JS "
460 + "Analyzer should filter out non-vulnerable JS files from the report."))
461 .addOption(newOptionWithArg(ARGUMENT.ARTIFACTORY_PARALLEL_ANALYSIS, "true/false",
462 "Whether the Artifactory Analyzer should use parallel analysis."))
463 .addOption(newOptionWithArg(ARGUMENT.ARTIFACTORY_USES_PROXY, "true/false",
464 "Whether the Artifactory Analyzer should use the proxy."))
465 .addOption(newOptionWithArg(ARGUMENT.ARTIFACTORY_USERNAME, "username",
466 "The Artifactory username for authentication."))
467 .addOption(newOptionWithArg(ARGUMENT.ARTIFACTORY_API_TOKEN, "token",
468 "The Artifactory API token."))
469 .addOption(newOptionWithArg(ARGUMENT.ARTIFACTORY_BEARER_TOKEN, "token",
470 "The Artifactory bearer token."))
471 .addOption(newOptionWithArg(ARGUMENT.ARTIFACTORY_URL, "url",
472 "The Artifactory URL."))
473 .addOption(newOptionWithArg(ARGUMENT.PATH_TO_GO, "path",
474 "The path to the `go` executable."))
475 .addOption(newOptionWithArg(ARGUMENT.PATH_TO_YARN, "path",
476 "The path to the `yarn` executable."))
477 .addOption(newOptionWithArg(ARGUMENT.PATH_TO_PNPM, "path",
478 "The path to the `pnpm` executable."))
479 .addOption(newOptionWithArg(ARGUMENT.RETIRE_JS_FILTERS, "pattern",
480 "Specify Retire JS content filter used to exclude files from analysis based on their content; "
481 + "most commonly used to exclude based on your applications own copyright line. This "
482 + "option can be specified multiple times."))
483 .addOption(newOptionWithArg(ARGUMENT.NEXUS_URL, "url",
484 "Sets the Nexus Repository v3 API base URL (example https://domain.enterprise/nexus/). If not "
485 + "set the Nexus Analyzer will be disabled."))
486 .addOption(newOptionWithArg(ARGUMENT.NEXUS_USERNAME, "username",
487 "The username to authenticate to the Nexus Server's REST API Endpoint. If not set the Nexus "
488 + "Analyzer will use an unauthenticated connection."))
489 .addOption(newOptionWithArg(ARGUMENT.NEXUS_PASSWORD, "password",
490 "The password to authenticate to the Nexus Server's REST API Endpoint. If not set the Nexus "
491 + "Analyzer will use an unauthenticated connection."))
492
493 .addOption(newOptionWithArg(ARGUMENT.NEXUS_USES_PROXY, "true/false",
494 "Whether or not the configured proxy should be used when connecting to Nexus."))
495 .addOption(newOptionWithArg(ARGUMENT.ADDITIONAL_ZIP_EXTENSIONS, "extensions",
496 "A comma separated list of additional extensions to be scanned as ZIP files (ZIP, EAR, WAR "
497 + "are already treated as zip files)"))
498 .addOption(newOptionWithArg(ARGUMENT.PROP_SHORT, ARGUMENT.PROP, "file", "A property file to load."))
499 .addOption(newOptionWithArg(ARGUMENT.PATH_TO_CORE, "path", "The path to dotnet core."))
500 .addOption(newOptionWithArg(ARGUMENT.HINTS_FILE, "file", "The file path to the hints XML file."))
501 .addOption(newOption(ARGUMENT.RETIRED, "Enables the retired analyzers."))
502 .addOption(newOption(ARGUMENT.DISABLE_MSBUILD, "Disable the MS Build Analyzer."))
503 .addOption(newOption(ARGUMENT.DISABLE_JAR, "Disable the Jar Analyzer."))
504 .addOption(newOption(ARGUMENT.DISABLE_ARCHIVE, "Disable the Archive Analyzer."))
505 .addOption(newOption(ARGUMENT.DISABLE_KEV, "Disable the Known Exploited Vulnerability Analyzer."))
506 .addOption(newOptionWithArg(ARGUMENT.KEV_URL, "url", "The url to the CISA Known Exploited Vulnerabilities JSON data feed"))
507 .addOption(newOptionWithArg(ARGUMENT.KEV_USER, "user", "The user for basic authentication towards the CISA Known Exploited "
508 + "Vulnerabilities JSON data feed"))
509 .addOption(newOptionWithArg(ARGUMENT.KEV_PASSWORD, "password", "The password for basic authentication towards the CISA Known "
510 + "Exploited Vulnerabilities JSON data feed"))
511 .addOption(newOptionWithArg(ARGUMENT.KEV_BEARER_TOKEN, "token", "The token for bearer authentication towards the CISA Known "
512 + "Exploited Vulnerabilities JSON data feed"))
513 .addOption(newOption(ARGUMENT.DISABLE_ASSEMBLY, "Disable the .NET Assembly Analyzer."))
514 .addOption(newOption(ARGUMENT.DISABLE_PY_DIST, "Disable the Python Distribution Analyzer."))
515 .addOption(newOption(ARGUMENT.DISABLE_CMAKE, "Disable the Cmake Analyzer."))
516 .addOption(newOption(ARGUMENT.DISABLE_PY_PKG, "Disable the Python Package Analyzer."))
517 .addOption(newOption(ARGUMENT.DISABLE_MIX_AUDIT, "Disable the Elixir mix_audit Analyzer."))
518 .addOption(newOption(ARGUMENT.DISABLE_RUBYGEMS, "Disable the Ruby Gemspec Analyzer."))
519 .addOption(newOption(ARGUMENT.DISABLE_BUNDLE_AUDIT, "Disable the Ruby Bundler-Audit Analyzer."))
520 .addOption(newOption(ARGUMENT.DISABLE_FILENAME, "Disable the File Name Analyzer."))
521 .addOption(newOption(ARGUMENT.DISABLE_AUTOCONF, "Disable the Autoconf Analyzer."))
522 .addOption(newOption(ARGUMENT.DISABLE_MAVEN_INSTALL, "Disable the Maven install Analyzer."))
523 .addOption(newOption(ARGUMENT.DISABLE_PE, "Disable the PE Analyzer."))
524 .addOption(newOption(ARGUMENT.DISABLE_PIP, "Disable the pip Analyzer."))
525 .addOption(newOption(ARGUMENT.DISABLE_PIPFILE, "Disable the Pipfile Analyzer."))
526 .addOption(newOption(ARGUMENT.DISABLE_COMPOSER, "Disable the PHP Composer Analyzer."))
527 .addOption(newOption(ARGUMENT.COMPOSER_LOCK_SKIP_DEV, "Configures the PHP Composer Analyzer to skip packages-dev"))
528 .addOption(newOption(ARGUMENT.DISABLE_CPAN, "Disable the Perl CPAN file Analyzer."))
529 .addOption(newOption(ARGUMENT.DISABLE_POETRY, "Disable the Poetry Analyzer."))
530 .addOption(newOption(ARGUMENT.DISABLE_GOLANG_MOD, "Disable the Golang Mod Analyzer."))
531 .addOption(newOption(ARGUMENT.DISABLE_DART, "Disable the Dart Analyzer."))
532 .addOption(newOption(ARGUMENT.DISABLE_OPENSSL, "Disable the OpenSSL Analyzer."))
533 .addOption(newOption(ARGUMENT.DISABLE_NUSPEC, "Disable the Nuspec Analyzer."))
534 .addOption(newOption(ARGUMENT.DISABLE_NUGETCONF, "Disable the Nuget packages.config Analyzer."))
535 .addOption(newOption(ARGUMENT.DISABLE_CENTRAL, "Disable the Central Analyzer. If this analyzer "
536 + "is disabled it is likely you also want to disable the Nexus Analyzer."))
537 .addOption(newOption(ARGUMENT.DISABLE_CENTRAL_CACHE, "Disallow the Central Analyzer from caching results"))
538 .addOption(newOption(ARGUMENT.DISABLE_OSSINDEX, "Disable the Sonatype OSS Index Analyzer."))
539 .addOption(newOption(ARGUMENT.DISABLE_OSSINDEX_CACHE, "Disallow the OSS Index Analyzer from caching results"))
540 .addOption(newOption(ARGUMENT.DISABLE_COCOAPODS, "Disable the CocoaPods Analyzer."))
541 .addOption(newOption(ARGUMENT.DISABLE_CARTHAGE, "Disable the Carthage Analyzer."))
542 .addOption(newOption(ARGUMENT.DISABLE_SWIFT, "Disable the swift package Analyzer."))
543 .addOption(newOption(ARGUMENT.DISABLE_SWIFT_RESOLVED, "Disable the swift package resolved Analyzer."))
544 .addOption(newOption(ARGUMENT.DISABLE_GO_DEP, "Disable the Golang Package Analyzer."))
545 .addOption(newOption(ARGUMENT.DISABLE_NODE_JS, "Disable the Node Package Analyzer."))
546 .addOption(newOption(ARGUMENT.NODE_PACKAGE_SKIP_DEV_DEPENDENCIES, "Configures the Node Package Analyzer to skip devDependencies"))
547 .addOption(newOption(ARGUMENT.DISABLE_NODE_AUDIT, "Disable the Node Audit Analyzer."))
548 .addOption(newOption(ARGUMENT.DISABLE_PNPM_AUDIT, "Disable the Pnpm Audit Analyzer."))
549 .addOption(newOption(ARGUMENT.DISABLE_YARN_AUDIT, "Disable the Yarn Audit Analyzer."))
550 .addOption(newOption(ARGUMENT.DISABLE_NODE_AUDIT_CACHE, "Disallow the Node Audit Analyzer from caching results"))
551 .addOption(newOption(ARGUMENT.DISABLE_NODE_AUDIT_SKIPDEV, "Configures the Node Audit Analyzer to skip devDependencies"))
552 .addOption(newOption(ARGUMENT.DISABLE_RETIRE_JS, "Disable the RetireJS Analyzer."))
553 .addOption(newOption(ARGUMENT.ENABLE_NEXUS, "Enable the Nexus Analyzer."))
554 .addOption(newOption(ARGUMENT.ARTIFACTORY_ENABLED, "Whether the Artifactory Analyzer should be enabled."))
555 .addOption(newOption(ARGUMENT.PURGE_NVD, "Purges the local NVD data cache"))
556 .addOption(newOption(ARGUMENT.DISABLE_HOSTED_SUPPRESSIONS, "Disable retrieval of the hosted suppressions from the configured URL."))
557 .addOption(newOption(ARGUMENT.HOSTED_SUPPRESSIONS_FORCEUPDATE, "Force the hosted suppressions file to update even"
558 + " if autoupdate is disabled"))
559 .addOption(newOptionWithArg(ARGUMENT.HOSTED_SUPPRESSIONS_VALID_FOR_HOURS, "hours",
560 "The number of hours to wait before checking for new updates of the the hosted suppressions file."))
561 .addOption(newOptionWithArg(ARGUMENT.HOSTED_SUPPRESSIONS_URL, "url",
562 "The URL for a mirrored hosted suppressions file"))
563 .addOption(newOptionWithArg(ARGUMENT.HOSTED_SUPPRESSIONS_USER, "user",
564 "The user for basic auth to a mirrored hosted suppressions file"))
565 .addOption(newOptionWithArg(ARGUMENT.HOSTED_SUPPRESSIONS_PASSWORD, "password",
566 "The password for basic auth to a mirrored hosted suppressions file"))
567 .addOption(newOptionWithArg(ARGUMENT.HOSTED_SUPPRESSIONS_BEARER_TOKEN, "token",
568 "The token for bearer auth to a mirrored hosted suppressions file"));
569
570 }
571
572
573
574
575
576
577
578
579
580 private void addDeprecatedOptions(final Options options) {
581
582 options.addOption(newOption("debug",
583 "Used to enable java debugging of the cli via dependency-check.sh."));
584 }
585
586
587
588
589
590
591 public boolean isGetVersion() {
592 return (line != null) && line.hasOption(ARGUMENT.VERSION);
593 }
594
595
596
597
598
599
600 public boolean isGetHelp() {
601 return (line != null) && line.hasOption(ARGUMENT.HELP);
602 }
603
604
605
606
607
608
609 public boolean isRunScan() {
610 return (line != null) && isValid && line.hasOption(ARGUMENT.SCAN);
611 }
612
613
614
615
616
617
618
619 public int getSymLinkDepth() {
620 int value = 0;
621 try {
622 value = Integer.parseInt(line.getOptionValue(ARGUMENT.SYM_LINK_DEPTH, "0"));
623 if (value < 0) {
624 value = 0;
625 }
626 } catch (NumberFormatException ex) {
627 LOGGER.debug("Symbolic link was not a number");
628 }
629 return value;
630 }
631
632
633
634
635
636
637
638
639
640
641
642
643
644
645 public boolean isDisabled(String disableFlag, String setting) {
646 if (line == null || !line.hasOption(disableFlag)) {
647 try {
648 return !settings.getBoolean(setting);
649 } catch (InvalidSettingException ise) {
650 LOGGER.warn("Invalid property setting '{}' defaulting to false", setting);
651 return false;
652 }
653 } else {
654 return true;
655 }
656 }
657
658
659
660
661
662
663
664 public boolean isNodeAuditDisabled() {
665 return isDisabled(ARGUMENT.DISABLE_NODE_AUDIT, Settings.KEYS.ANALYZER_NODE_AUDIT_ENABLED);
666 }
667
668
669
670
671
672
673
674 public boolean isYarnAuditDisabled() {
675 return isDisabled(ARGUMENT.DISABLE_YARN_AUDIT, Settings.KEYS.ANALYZER_YARN_AUDIT_ENABLED);
676 }
677
678
679
680
681
682
683
684 public boolean isPnpmAuditDisabled() {
685 return isDisabled(ARGUMENT.DISABLE_PNPM_AUDIT, Settings.KEYS.ANALYZER_PNPM_AUDIT_ENABLED);
686 }
687
688
689
690
691
692
693
694
695 public boolean isNexusUsesProxy() {
696
697
698 if (line == null || !line.hasOption(ARGUMENT.NEXUS_USES_PROXY)) {
699 try {
700 return settings.getBoolean(Settings.KEYS.ANALYZER_NEXUS_USES_PROXY);
701 } catch (InvalidSettingException ise) {
702 return true;
703 }
704 } else {
705 return Boolean.parseBoolean(line.getOptionValue(ARGUMENT.NEXUS_USES_PROXY));
706 }
707 }
708
709
710
711
712
713
714
715 @SuppressFBWarnings(justification = "Accepting that this is a bad practice - used a Boolean as we needed three states",
716 value = {"NP_BOOLEAN_RETURN_NULL"})
717 public Boolean getBooleanArgument(String argument) {
718 if (line != null && line.hasOption(argument)) {
719 final String value = line.getOptionValue(argument);
720 if (value != null) {
721 return Boolean.parseBoolean(value);
722 }
723 }
724 return null;
725 }
726
727
728
729
730
731
732
733 public String getStringArgument(String option) {
734 return getStringArgument(option, null);
735 }
736
737
738
739
740
741
742
743
744 public String getStringArgument(String option, String key) {
745 if (line != null && line.hasOption(option)) {
746 if (key != null && (option.toLowerCase().endsWith("password")
747 || option.toLowerCase().endsWith("pass"))) {
748 LOGGER.warn("{} used on the command line, consider moving the password "
749 + "to a properties file using the key `{}` and using the "
750 + "--propertyfile argument instead", option, key);
751 }
752 return line.getOptionValue(option);
753 }
754 return null;
755 }
756
757
758
759
760
761
762
763 public String[] getStringArguments(String option) {
764 if (line != null && line.hasOption(option)) {
765 return line.getOptionValues(option);
766 }
767 return null;
768 }
769
770
771
772
773
774
775
776 public File getFileArgument(String option) {
777 final String path = line.getOptionValue(option);
778 if (path != null) {
779 return new File(path);
780 }
781 return null;
782 }
783
784
785
786
787 void printHelp(Appendable appendable) {
788 TextHelpAppendable helpAppendable = new TextHelpAppendable(appendable);
789 helpAppendable.setMaxWidth(100);
790 HelpFormatter formatter = HelpFormatter.builder()
791 .setShowSince(false)
792 .setComparator(Comparator.comparing(Option::getKey, String::compareToIgnoreCase))
793 .setHelpAppendable(helpAppendable)
794 .get();
795
796 final Options options = new Options();
797 addStandardOptions(options);
798 if (line != null && line.hasOption(ARGUMENT.ADVANCED_HELP)) {
799 addAdvancedOptions(options);
800 }
801
802 try {
803 formatter.printHelp("dependency-check", HELP_MSG, formatter.sort(options), "", true);
804 } catch (IOException e) {
805 throw new UncheckedIOException(e);
806 }
807 }
808
809
810
811
812
813
814
815 public String[] getScanFiles() {
816 return line.getOptionValues(ARGUMENT.SCAN);
817 }
818
819
820
821
822
823
824
825 public String[] getExcludeList() {
826 return line.getOptionValues(ARGUMENT.EXCLUDE);
827 }
828
829
830
831
832
833
834
835 public String[] getRetireJsFilters() {
836 return line.getOptionValues(ARGUMENT.RETIRE_JS_FILTERS);
837 }
838
839
840
841
842
843
844
845
846 @SuppressFBWarnings(justification = "Accepting that this is a bad practice - but made more sense in this use case",
847 value = {"NP_BOOLEAN_RETURN_NULL"})
848 public Boolean isRetireJsFilterNonVulnerable() {
849 return line != null && line.hasOption(ARGUMENT.RETIRE_JS_FILTER_NON_VULNERABLE) ? true : null;
850 }
851
852
853
854
855
856
857
858 public String getReportDirectory() {
859 return line.getOptionValue(ARGUMENT.OUT, ".");
860 }
861
862
863
864
865
866
867
868 public String[] getReportFormat() {
869 if (line.hasOption(ARGUMENT.OUTPUT_FORMAT)) {
870 return line.getOptionValues(ARGUMENT.OUTPUT_FORMAT);
871 }
872 return new String[]{"HTML"};
873 }
874
875
876
877
878
879
880 public String getProjectName() {
881 String name = line.getOptionValue(ARGUMENT.PROJECT);
882 if (name == null) {
883 name = "";
884 }
885 return name;
886 }
887
888
889
890
891
892
893
894 public void printVersionInfo() {
895 final String version = String.format("%s version %s",
896 settings.getString(Settings.KEYS.APPLICATION_NAME, "dependency-check"),
897 settings.getString(Settings.KEYS.APPLICATION_VERSION, "Unknown"));
898 System.out.println(version);
899 }
900
901
902
903
904
905
906
907 public boolean isUpdateOnly() {
908 return line != null && line.hasOption(ARGUMENT.UPDATE_ONLY);
909 }
910
911
912
913
914
915
916
917 public boolean isPurge() {
918 return line != null && line.hasOption(ARGUMENT.PURGE_NVD);
919 }
920
921
922
923
924
925
926
927 public String getDatabaseDriverName() {
928 return line.getOptionValue(ARGUMENT.DB_DRIVER);
929 }
930
931
932
933
934
935
936
937 public Integer getIntegerValue(String argument) {
938 final String v = line.getOptionValue(argument);
939 if (v != null) {
940 return Integer.parseInt(v);
941 }
942 return null;
943 }
944
945
946
947
948
949
950
951
952
953 @SuppressFBWarnings(justification = "Accepting that this is a bad practice - but made more sense in this use case",
954 value = {"NP_BOOLEAN_RETURN_NULL"})
955 public Boolean hasOption(String option) {
956 return (line != null && line.hasOption(option)) ? true : null;
957 }
958
959
960
961
962
963
964
965 public float getFailOnCVSS() {
966 if (line.hasOption(ARGUMENT.FAIL_ON_CVSS)) {
967 final String value = line.getOptionValue(ARGUMENT.FAIL_ON_CVSS);
968 try {
969 return Float.parseFloat(value);
970 } catch (NumberFormatException nfe) {
971 return 11;
972 }
973 } else {
974 return 11;
975 }
976 }
977
978
979
980
981
982
983
984
985 public float getFloatArgument(String option, float defaultValue) {
986 if (line.hasOption(option)) {
987 final String value = line.getOptionValue(option);
988 try {
989 return Integer.parseInt(value);
990 } catch (NumberFormatException nfe) {
991 return defaultValue;
992 }
993 } else {
994 return defaultValue;
995 }
996 }
997
998
999
1000
1001
1002
1003
1004
1005 private Option newOption(String name, String description) {
1006 return Option.builder().longOpt(name).desc(description).get();
1007 }
1008
1009
1010
1011
1012
1013
1014
1015
1016
1017 private Option newOption(String shortName, String name, String description) {
1018 return Option.builder(shortName).longOpt(name).desc(description).get();
1019 }
1020
1021
1022
1023
1024
1025
1026
1027
1028
1029 private Option newOptionWithArg(String name, String arg, String description) {
1030 return Option.builder().longOpt(name).argName(arg).hasArg().desc(description).get();
1031 }
1032
1033
1034
1035
1036
1037
1038
1039
1040
1041
1042 private Option newOptionWithArg(String shortName, String name, String arg, String description) {
1043 return Option.builder(shortName).longOpt(name).argName(arg).hasArg().desc(description).get();
1044 }
1045
1046
1047
1048
1049
1050
1051
1052
1053 private OptionGroup newOptionGroup(Option option) {
1054 final OptionGroup group = new OptionGroup();
1055 group.addOption(option);
1056 return group;
1057 }
1058
1059
1060
1061
1062
1063 public static class ARGUMENT {
1064
1065
1066
1067
1068 public static final String SCAN = "scan";
1069
1070
1071
1072 public static final String SCAN_SHORT = "s";
1073
1074
1075
1076
1077 public static final String DISABLE_AUTO_UPDATE = "noupdate";
1078
1079
1080
1081
1082 public static final String DISABLE_VERSION_CHECK = "disableVersionCheck";
1083
1084
1085
1086
1087 public static final String DISABLE_AUTO_UPDATE_SHORT = "n";
1088
1089
1090
1091
1092 public static final String UPDATE_ONLY = "updateonly";
1093
1094
1095
1096
1097 public static final String PURGE_NVD = "purge";
1098
1099
1100
1101
1102 public static final String OUT = "out";
1103
1104
1105
1106
1107 public static final String OUT_SHORT = "o";
1108
1109
1110
1111
1112 public static final String OUTPUT_FORMAT = "format";
1113
1114
1115
1116
1117 public static final String OUTPUT_FORMAT_SHORT = "f";
1118
1119
1120
1121
1122 public static final String PROJECT = "project";
1123
1124
1125
1126 public static final String HELP = "help";
1127
1128
1129
1130 public static final String ADVANCED_HELP = "advancedHelp";
1131
1132
1133
1134 public static final String HELP_SHORT = "h";
1135
1136
1137
1138 public static final String VERSION_SHORT = "v";
1139
1140
1141
1142 public static final String VERSION = "version";
1143
1144
1145
1146 public static final String PROXY_PORT = "proxyport";
1147
1148
1149
1150 public static final String PROXY_SERVER = "proxyserver";
1151
1152
1153
1154 public static final String PROXY_USERNAME = "proxyuser";
1155
1156
1157
1158 public static final String PROXY_PASSWORD = "proxypass";
1159
1160
1161
1162 public static final String NON_PROXY_HOSTS = "nonProxyHosts";
1163
1164
1165
1166 public static final String CONNECTION_TIMEOUT_SHORT = "c";
1167
1168
1169
1170 public static final String CONNECTION_TIMEOUT = "connectiontimeout";
1171
1172
1173
1174 public static final String CONNECTION_READ_TIMEOUT = "readtimeout";
1175
1176
1177
1178
1179 public static final String PROP_SHORT = "P";
1180
1181
1182
1183
1184 public static final String PROP = "propertyfile";
1185
1186
1187
1188 public static final String DATA_DIRECTORY = "data";
1189
1190
1191
1192 public static final String NVD_API_ENDPOINT = "nvdApiEndpoint";
1193
1194
1195
1196 public static final String NVD_API_KEY = "nvdApiKey";
1197
1198
1199
1200
1201 public static final String NVD_API_MAX_RETRY_COUNT = "nvdMaxRetryCount";
1202
1203
1204
1205
1206 public static final String NVD_API_VALID_FOR_HOURS = "nvdValidForHours";
1207
1208
1209
1210 public static final String NVD_API_DATAFEED_URL = "nvdDatafeed";
1211
1212
1213
1214 public static final String NVD_API_DATAFEED_USER = "nvdUser";
1215
1216
1217
1218 public static final String NVD_API_DATAFEED_PASSWORD = "nvdPassword";
1219
1220
1221
1222 public static final String NVD_API_DATAFEED_BEARER_TOKEN = "nvdBearerToken";
1223
1224
1225
1226 public static final String SUPPRESSION_FILE_USER = "suppressionUser";
1227
1228
1229
1230 public static final String SUPPRESSION_FILE_PASSWORD = "suppressionPassword";
1231
1232
1233
1234 public static final String SUPPRESSION_FILE_BEARER_TOKEN = "suppressionBearerToken";
1235
1236
1237
1238 public static final String NVD_API_DELAY = "nvdApiDelay";
1239
1240
1241
1242 public static final String NVD_API_RESULTS_PER_PAGE = "nvdApiResultsPerPage";
1243
1244
1245
1246
1247 public static final String DATA_DIRECTORY_SHORT = "d";
1248
1249
1250
1251 public static final String VERBOSE_LOG = "log";
1252
1253
1254
1255
1256 public static final String VERBOSE_LOG_SHORT = "l";
1257
1258
1259
1260
1261 public static final String SYM_LINK_DEPTH = "symLink";
1262
1263
1264
1265
1266 public static final String SUPPRESSION_FILES = "suppression";
1267
1268
1269
1270 public static final String HINTS_FILE = "hints";
1271
1272
1273
1274 public static final String DISABLE_JAR = "disableJar";
1275
1276
1277
1278 public static final String DISABLE_MSBUILD = "disableMSBuild";
1279
1280
1281
1282 public static final String DISABLE_ARCHIVE = "disableArchive";
1283
1284
1285
1286 public static final String DISABLE_KEV = "disableKnownExploited";
1287
1288
1289
1290 public static final String KEV_URL = "kevURL";
1291
1292
1293
1294 public static final String KEV_USER = "kevUser";
1295
1296
1297
1298 public static final String KEV_PASSWORD = "kevPassword";
1299
1300
1301
1302 public static final String KEV_BEARER_TOKEN = "kevBearerToken";
1303
1304
1305
1306 public static final String DISABLE_PY_DIST = "disablePyDist";
1307
1308
1309
1310 public static final String DISABLE_PY_PKG = "disablePyPkg";
1311
1312
1313
1314 public static final String DISABLE_MIX_AUDIT = "disableMixAudit";
1315
1316
1317
1318 public static final String DISABLE_GO_DEP = "disableGolangDep";
1319
1320
1321
1322 public static final String DISABLE_COMPOSER = "disableComposer";
1323
1324
1325
1326 public static final String COMPOSER_LOCK_SKIP_DEV = "composerSkipDev";
1327
1328
1329
1330 public static final String DISABLE_CPAN = "disableCpan";
1331
1332
1333
1334 public static final String DISABLE_GOLANG_MOD = "disableGolangMod";
1335
1336
1337
1338 public static final String DISABLE_DART = "disableDart";
1339
1340
1341
1342 public static final String PATH_TO_GO = "go";
1343
1344
1345
1346 public static final String PATH_TO_YARN = "yarn";
1347
1348
1349
1350 public static final String PATH_TO_PNPM = "pnpm";
1351
1352
1353
1354 public static final String DISABLE_RUBYGEMS = "disableRubygems";
1355
1356
1357
1358 public static final String DISABLE_AUTOCONF = "disableAutoconf";
1359
1360
1361
1362 public static final String DISABLE_MAVEN_INSTALL = "disableMavenInstall";
1363
1364
1365
1366 public static final String DISABLE_PIP = "disablePip";
1367
1368
1369
1370 public static final String DISABLE_PIPFILE = "disablePipfile";
1371
1372
1373
1374 public static final String DISABLE_POETRY = "disablePoetry";
1375
1376
1377
1378 public static final String DISABLE_CMAKE = "disableCmake";
1379
1380
1381
1382 public static final String DISABLE_COCOAPODS = "disableCocoapodsAnalyzer";
1383
1384
1385
1386 public static final String DISABLE_CARTHAGE = "disableCarthageAnalyzer";
1387
1388
1389
1390 public static final String DISABLE_SWIFT = "disableSwiftPackageManagerAnalyzer";
1391
1392
1393
1394 public static final String DISABLE_SWIFT_RESOLVED = "disableSwiftPackageResolvedAnalyzer";
1395
1396
1397
1398 public static final String DISABLE_ASSEMBLY = "disableAssembly";
1399
1400
1401
1402 public static final String DISABLE_PE = "disablePE";
1403
1404
1405
1406 public static final String DISABLE_BUNDLE_AUDIT = "disableBundleAudit";
1407
1408
1409
1410 public static final String DISABLE_FILENAME = "disableFileName";
1411
1412
1413
1414 public static final String DISABLE_NUSPEC = "disableNuspec";
1415
1416
1417
1418 public static final String DISABLE_NUGETCONF = "disableNugetconf";
1419
1420
1421
1422 public static final String DISABLE_CENTRAL = "disableCentral";
1423
1424
1425
1426 public static final String DISABLE_CENTRAL_CACHE = "disableCentralCache";
1427
1428
1429
1430 public static final String CENTRAL_URL = "centralUrl";
1431
1432
1433
1434 public static final String CENTRAL_USERNAME = "centralUsername";
1435
1436
1437
1438 public static final String CENTRAL_PASSWORD = "centralPassword";
1439
1440
1441
1442 public static final String CENTRAL_BEARER_TOKEN = "centralBearerToken";
1443
1444
1445
1446 public static final String ENABLE_NEXUS = "enableNexus";
1447
1448
1449
1450 public static final String DISABLE_OSSINDEX = "disableOssIndex";
1451
1452
1453
1454
1455 public static final String DISABLE_OSSINDEX_CACHE = "disableOssIndexCache";
1456
1457
1458
1459 public static final String OSSINDEX_CACHE_VALID_FOR_HOURS = "ossIndexCacheValidForHours";
1460
1461
1462
1463 public static final String OSSINDEX_URL = "ossIndexUrl";
1464
1465
1466
1467 public static final String OSSINDEX_USERNAME = "ossIndexUsername";
1468
1469
1470
1471 public static final String OSSINDEX_PASSWORD = "ossIndexPassword";
1472
1473
1474
1475 public static final String OSSINDEX_WARN_ONLY_ON_REMOTE_ERRORS = "ossIndexRemoteErrorWarnOnly";
1476
1477
1478
1479 public static final String DISABLE_OPENSSL = "disableOpenSSL";
1480
1481
1482
1483 public static final String DISABLE_NODE_JS = "disableNodeJS";
1484
1485
1486
1487 public static final String NODE_PACKAGE_SKIP_DEV_DEPENDENCIES = "nodePackageSkipDevDependencies";
1488
1489
1490
1491 public static final String DISABLE_NODE_AUDIT = "disableNodeAudit";
1492
1493
1494
1495 public static final String DISABLE_YARN_AUDIT = "disableYarnAudit";
1496
1497
1498
1499 public static final String DISABLE_PNPM_AUDIT = "disablePnpmAudit";
1500
1501
1502
1503 public static final String DISABLE_NODE_AUDIT_CACHE = "disableNodeAuditCache";
1504
1505
1506
1507 public static final String DISABLE_NODE_AUDIT_SKIPDEV = "nodeAuditSkipDevDependencies";
1508
1509
1510
1511 public static final String DISABLE_RETIRE_JS = "disableRetireJs";
1512
1513
1514
1515
1516 public static final String RETIRE_JS_FORCEUPDATE = "retireJsForceUpdate";
1517
1518
1519
1520 public static final String RETIREJS_URL = "retireJsUrl";
1521
1522
1523
1524 public static final String RETIREJS_URL_USER = "retireJsUrlUser";
1525
1526
1527
1528 public static final String RETIREJS_URL_PASSWORD = "retireJsUrlPass";
1529
1530
1531
1532 public static final String RETIREJS_URL_BEARER_TOKEN = "retireJsUrlBearerToken";
1533
1534
1535
1536 public static final String NEXUS_URL = "nexus";
1537
1538
1539
1540 public static final String NEXUS_USERNAME = "nexusUser";
1541
1542
1543
1544 public static final String NEXUS_PASSWORD = "nexusPass";
1545
1546
1547
1548
1549 public static final String NEXUS_USES_PROXY = "nexusUsesProxy";
1550
1551
1552
1553 public static final String CONNECTION_STRING = "connectionString";
1554
1555
1556
1557 public static final String DB_NAME = "dbUser";
1558
1559
1560
1561 public static final String DB_PASSWORD = "dbPassword";
1562
1563
1564
1565 public static final String DB_DRIVER = "dbDriverName";
1566
1567
1568
1569
1570 public static final String DB_DRIVER_PATH = "dbDriverPath";
1571
1572
1573
1574 public static final String PATH_TO_CORE = "dotnet";
1575
1576
1577
1578 public static final String ADDITIONAL_ZIP_EXTENSIONS = "zipExtensions";
1579
1580
1581
1582 public static final String EXCLUDE = "exclude";
1583
1584
1585
1586
1587 public static final String PATH_TO_BUNDLE_AUDIT = "bundleAudit";
1588
1589
1590
1591
1592
1593
1594 public static final String PATH_TO_BUNDLE_AUDIT_WORKING_DIRECTORY = "bundleAuditWorkingDirectory";
1595
1596
1597
1598
1599 public static final String PATH_TO_MIX_AUDIT = "mixAudit";
1600
1601
1602
1603 public static final String EXPERIMENTAL = "enableExperimental";
1604
1605
1606
1607 public static final String RETIRED = "enableRetired";
1608
1609
1610
1611 public static final String RETIRE_JS_FILTERS = "retireJsFilter";
1612
1613
1614
1615 public static final String RETIRE_JS_FILTER_NON_VULNERABLE = "retireJsFilterNonVulnerable";
1616
1617
1618
1619
1620 public static final String ARTIFACTORY_ENABLED = "enableArtifactory";
1621
1622
1623
1624
1625 public static final String ARTIFACTORY_URL = "artifactoryUrl";
1626
1627
1628
1629 public static final String ARTIFACTORY_USERNAME = "artifactoryUsername";
1630
1631
1632
1633 public static final String ARTIFACTORY_API_TOKEN = "artifactoryApiToken";
1634
1635
1636
1637 public static final String ARTIFACTORY_BEARER_TOKEN = "artifactoryBearerToken";
1638
1639
1640
1641
1642 public static final String ARTIFACTORY_USES_PROXY = "artifactoryUseProxy";
1643
1644
1645
1646
1647 public static final String ARTIFACTORY_PARALLEL_ANALYSIS = "artifactoryParallelAnalysis";
1648
1649
1650
1651
1652 public static final String FAIL_ON_CVSS = "failOnCVSS";
1653
1654
1655
1656
1657 public static final String PRETTY_PRINT = "prettyPrint";
1658
1659
1660
1661
1662 public static final String FAIL_JUNIT_ON_CVSS = "junitFailOnCVSS";
1663
1664
1665
1666
1667 public static final String DISABLE_HOSTED_SUPPRESSIONS = "disableHostedSuppressions";
1668
1669
1670
1671
1672 public static final String HOSTED_SUPPRESSIONS_VALID_FOR_HOURS = "hostedSuppressionsValidForHours";
1673
1674
1675
1676
1677 public static final String HOSTED_SUPPRESSIONS_FORCEUPDATE = "hostedSuppressionsForceUpdate";
1678
1679
1680
1681
1682 public static final String HOSTED_SUPPRESSIONS_URL = "hostedSuppressionsUrl";
1683
1684
1685
1686 public static final String HOSTED_SUPPRESSIONS_USER = "hostedSuppressionsUser";
1687
1688
1689
1690 public static final String HOSTED_SUPPRESSIONS_PASSWORD = "hostedSuppressionsPassword";
1691
1692
1693
1694 public static final String HOSTED_SUPPRESSIONS_BEARER_TOKEN = "hostedSuppressionsBearerToken";
1695 }
1696 }