Skip to content

acm19/dependency-resolution

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Dependency Resolution

Demostrates how under specific dependency setup both Snyk and Maven Dependency Plugin fail to report the dependencies that will be part of the final WAR file.

Explanation

This library is a multi-module project dependency-resolution, composed by 2 modules:

  • resolution-error: contains the final WAR project where the dependency is added to the final artefact but not detected by Snyk or Maven Dependency Plugin.
  • trasitive-dependency: it's necessary to transitively include the dependency so that it's ignored but others but not the Maven WAR plugin.

Steps to Reproduce

  1. Got to the root of the project and run:
mvn clean install
  1. Run Snyk, it will report no vulnerability (even though a vulnerable version of snakeyaml-1.30.jar is included in the final Jar).
snyk test --file=resolution-error/pom.xml
  1. Run Maven Dependency plugin to check the runtime dependencies and filter for the expected dependency, it's not present:
mvn dependency:tree -Dscope=runtime -pl resolution-error | grep snakeyaml
  1. List the dependencies included in the final WAR and filter by the expected dependency, it's present:
ls resolution-error/target/resolution-error-1.0-SNAPSHOT/WEB-INF/lib/ | grep snakeyaml

About

No description, website, or topics provided.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published