Skip to content

Commit d99a725

Browse files
committed
Merge remote-tracking branch 'upstream/master' into sync-upstream-master
2 parents 23903bf + 20cbf3d commit d99a725

6 files changed

Lines changed: 65 additions & 32 deletions

File tree

‎.github/workflows/codeql-analysis.yml‎

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -27,14 +27,14 @@ jobs:
2727

2828
steps:
2929
- name: Checkout repository
30-
uses: actions/checkout@v6
30+
uses: actions/checkout@v7
3131
# Get full history for spotless ratchetFrom
3232
with:
3333
fetch-depth: 0
3434

3535
# Initializes the CodeQL tools for scanning.
3636
- name: Initialize CodeQL
37-
uses: github/codeql-action/init@v4
37+
uses: github/codeql-action/init@v4.37.9
3838
with:
3939
languages: ${{ matrix.language }}
4040
queries: security-extended, security-experimental, security-and-quality
@@ -43,7 +43,7 @@ jobs:
4343
run: mvn -DskipTests=true install
4444

4545
- name: Perform CodeQL Analysis
46-
uses: github/codeql-action/analyze@v4
46+
uses: github/codeql-action/analyze@v4.37.9
4747

4848
- name: Upload Output
4949
uses: actions/upload-artifact@v7

‎.github/workflows/maven.yaml‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -8,11 +8,11 @@ jobs:
88
runs-on: ubuntu-latest
99

1010
steps:
11-
- uses: actions/checkout@v6
11+
- uses: actions/checkout@v7
1212
with:
1313
fetch-depth: 0
1414
- name: Set up JDK 17
15-
uses: actions/setup-java@v5
15+
uses: actions/setup-java@v6
1616
with:
1717
java-version: 17
1818
distribution: zulu

‎pom.xml‎

Lines changed: 20 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -636,7 +636,7 @@
636636
<dependency>
637637
<groupId>commons-codec</groupId>
638638
<artifactId>commons-codec</artifactId>
639-
<version>1.22.0</version>
639+
<version>1.22.1</version>
640640
</dependency>
641641

642642
<!-- mvn dependency:analyze says this is an unused declared dependency, but its wrong. Get this runtime error if it's not included: Caused by: org.springframework.beans.factory.CannotLoadBeanClassException: Cannot find class [org.apache.commons.dbcp.BasicDataSource] for bean with name 'dataSource' defined in class path resource [context.xml]; nested exception is java.lang.ClassNotFoundException: org.apache.commons.dbcp.BasicDataSource -->
@@ -663,13 +663,14 @@
663663
<dependency>
664664
<groupId>org.slf4j</groupId>
665665
<artifactId>slf4j-reload4j</artifactId>
666-
<version>2.0.17</version>
666+
<version>2.0.19</version>
667667
</dependency>
668668

669+
<!-- NOTE: Do NOT upgrade this library until the Apache team fixes issue: https://issues.apache.org/jira/browse/DIRAPI-433 -->
669670
<dependency>
670671
<groupId>org.apache.directory.api</groupId>
671672
<artifactId>api-ldap-model</artifactId>
672-
<version>${version.apache.api-ldap}</version>
673+
<version>2.1.7</version>
673674
</dependency>
674675

675676
<dependency>
@@ -777,13 +778,13 @@
777778
<dependency>
778779
<groupId>org.apache.httpcomponents.client5</groupId>
779780
<artifactId>httpclient5</artifactId>
780-
<version>5.6.1</version>
781+
<version>5.6.4</version>
781782
</dependency>
782783

783784
<dependency>
784785
<groupId>org.apache.httpcomponents.core5</groupId>
785786
<artifactId>httpcore5</artifactId>
786-
<version>5.4.2</version>
787+
<version>5.4.3</version>
787788
</dependency>
788789

789790
<dependency>
@@ -866,7 +867,7 @@
866867
<dependency>
867868
<groupId>com.fasterxml.jackson.core</groupId>
868869
<artifactId>jackson-databind</artifactId>
869-
<version>2.21.3</version>
870+
<version>2.22.2</version>
870871
</dependency>
871872
</dependencies>
872873

@@ -902,7 +903,7 @@
902903
<plugin>
903904
<groupId>org.apache.maven.plugins</groupId>
904905
<artifactId>maven-dependency-plugin</artifactId>
905-
<version>3.10.0</version>
906+
<version>3.11.0</version>
906907
<configuration>
907908
<usedDependencies>
908909
<dependency>com.sun.jersey:jersey-servlet</dependency>
@@ -936,7 +937,7 @@
936937
<plugin>
937938
<groupId>org.apache.maven.plugins</groupId>
938939
<artifactId>maven-compiler-plugin</artifactId>
939-
<version>3.15.0</version>
940+
<version>3.16.0</version>
940941
<configuration>
941942
<fork>true</fork>
942943
<meminitial>1000m</meminitial>
@@ -954,7 +955,7 @@
954955
<plugin>
955956
<groupId>org.apache.maven.plugins</groupId>
956957
<artifactId>maven-enforcer-plugin</artifactId>
957-
<version>3.6.2</version>
958+
<version>3.6.3</version>
958959
<dependencies>
959960
<dependency>
960961
<groupId>org.codehaus.mojo</groupId>
@@ -999,7 +1000,7 @@
9991000
<plugin>
10001001
<groupId>org.apache.maven.plugins</groupId>
10011002
<artifactId>maven-help-plugin</artifactId>
1002-
<version>3.5.1</version>
1003+
<version>3.5.2</version>
10031004
</plugin>
10041005

10051006
<plugin>
@@ -1036,7 +1037,7 @@
10361037
<!-- Note: This uses the maven-fluido-skin version specified next. The skin is referenced in src/site/site.xml. -->
10371038
<groupId>org.apache.maven.plugins</groupId>
10381039
<artifactId>maven-site-plugin</artifactId>
1039-
<version>3.21.0</version>
1040+
<version>3.22.0</version>
10401041
<dependencies>
10411042
<!-- Explicitly declare these dependencies so the versions plugin and library bots will flag available updates. The fluido-skin plugin is referenced in src/site/site.xml using the same fluido version property. -->
10421043
<dependency>
@@ -1050,7 +1051,7 @@
10501051
<plugin>
10511052
<groupId>org.apache.maven.plugins</groupId>
10521053
<artifactId>maven-surefire-plugin</artifactId>
1053-
<version>3.5.5</version>
1054+
<version>3.6.0</version>
10541055
</plugin>
10551056

10561057
<plugin>
@@ -1065,7 +1066,7 @@
10651066
<plugin>
10661067
<groupId>org.codehaus.cargo</groupId>
10671068
<artifactId>cargo-maven3-plugin</artifactId>
1068-
<version>1.10.27</version>
1069+
<version>1.10.28</version>
10691070
</plugin>
10701071

10711072
<plugin>
@@ -1116,7 +1117,7 @@
11161117
<plugin>
11171118
<groupId>com.diffplug.spotless</groupId>
11181119
<artifactId>spotless-maven-plugin</artifactId>
1119-
<version>3.4.0</version>
1120+
<version>3.10.2</version>
11201121
<configuration>
11211122
<!-- optional: limit format enforcement to just the files changed by this feature branch -->
11221123
<ratchetFrom>origin/master</ratchetFrom>
@@ -1255,19 +1256,19 @@
12551256
</tomcat.jvmargs.debug>
12561257
<log.directory>${project.build.directory}/log</log.directory>
12571258

1258-
<version.apache.api-ldap>2.1.7</version.apache.api-ldap>
1259+
<version.apache.api-ldap>2.1.8</version.apache.api-ldap>
12591260
<version.apacheds>2.0.0.AM27</version.apacheds>
12601261
<version.fluido>2.1.0</version.fluido>
12611262
<!-- hibernate is up to rev 6+. But 4.0.0. causes this error: symbol: org.hibernate.classic.Session not found -->
12621263
<version.hibernate>3.6.10.Final</version.hibernate>
1263-
<version.spotbugs.maven>4.9.8.3</version.spotbugs.maven>
1264-
<version.spotbugs>4.9.8</version.spotbugs>
1264+
<version.spotbugs.maven>4.10.4.1</version.spotbugs.maven>
1265+
<version.spotbugs>4.10.4</version.spotbugs>
12651266
<!-- Spring 6.x requires Java 17 -->
12661267
<version.springframework>5.3.39</version.springframework>
12671268
<!-- Tomcat 10 moves from Java EE to Jakarta EE, moving packages javax.* to jakarta.* - code changes likely required to address this change. -->
12681269
<tomcat.major.version>9</tomcat.major.version>
1269-
<version.tomcat>9.0.115</version.tomcat>
1270-
<tomcat.url>https://archive.apache.org/dist/tomcat/tomcat-${tomcat.major.version}/v${version.tomcat}/bin/apache-tomcat-${version.tomcat}.zip</tomcat.url>
1270+
<version.tomcat>9.0.120</version.tomcat>
1271+
<tomcat.url>https://downloads.apache.org/tomcat/tomcat-${tomcat.major.version}/v${version.tomcat}/bin/apache-tomcat-${version.tomcat}.zip</tomcat.url>
12711272
</properties>
12721273

12731274
</project>

‎scripts/runCognium.sh‎

Lines changed: 14 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,14 @@
1+
#!/usr/bin/env bash
2+
3+
# Install: npm install -g cognium
4+
# Check for install/updates at https://github.com/cogniumhq/cognium
5+
6+
source scripts/requireCommand.sh
7+
8+
requireCommand cognium
9+
10+
benchmark_version=$(scripts/getBenchmarkVersion.sh 2>/dev/null | grep -E '^[0-9]+\.[0-9]')
11+
cognium_version=$(cognium --version | grep -oE '[0-9]+\.[0-9]+\.[0-9]+')
12+
result_file="results/Benchmark_$benchmark_version-cognium-v$cognium_version.sarif"
13+
14+
cognium scan src/main/java --format sarif --category security --output "$result_file"

‎scripts/runOpenTaint.sh‎

Lines changed: 21 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,21 @@
1+
#!/usr/bin/env bash
2+
3+
# Check for install/updates at https://github.com/seqra/opentaint
4+
5+
source scripts/requireCommand.sh
6+
7+
requireCommand docker
8+
9+
docker pull ghcr.io/seqra/opentaint
10+
11+
benchmark_version=$(scripts/getBenchmarkVersion.sh 2>/dev/null | tail -1)
12+
opentaint_version=$(docker run --rm ghcr.io/seqra/opentaint opentaint --version | awk '{print $NF}')
13+
result_file="/project/results/Benchmark_$benchmark_version-OpenTaint-$opentaint_version.sarif"
14+
15+
docker run --rm -v $(pwd):/project \
16+
ghcr.io/seqra/opentaint:latest \
17+
opentaint scan \
18+
--severity error \
19+
--severity warning \
20+
--severity note \
21+
--output "$result_file" /project

‎scripts/runSonarQube.sh‎

Lines changed: 5 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -13,11 +13,6 @@ requireCommand curl
1313
requireCommand docker
1414
requireCommand jq
1515

16-
if ! command -v "sonar-report" &> /dev/null; then
17-
echo "sonar-report is required. Please install it via https://github.com/soprasteria/sonar-report and then try again."
18-
exit 1
19-
fi
20-
2116
# Check for install/updates at https://github.com/SonarSource/sonarqube
2217

2318
container_name="sonarqube-benchmark"
@@ -69,11 +64,12 @@ echo "Starting scan... (might take some time!)"
6964
container_ip=$(docker inspect "$container_name" | jq -r '.[0].NetworkSettings.Networks.bridge.IPAddress' )
7065
sonar_docker_host="http://$container_ip:$sonar_internal_port"
7166

72-
docker run --env SONAR_SCANNER_OPTS=-Xmx4g --rm -v ~/.m2:/root/.m2 -v "$(pwd)":"$(pwd)" -w "$(pwd)" sonarsource/sonar-scanner-cli \
67+
docker run --env SONAR_SCANNER_OPTS=-Xmx4g --rm -v ~/.m2:/root/.m2 -v "$(pwd)":/benchmark -w "/benchmark" sonarsource/sonar-scanner-cli \
68+
-Dsonar.projectBaseDir="/benchmark" \
7369
-Dsonar.java.binaries="target" \
7470
-Dsonar.projectKey="$sonar_project" \
7571
-Dsonar.host.url="$sonar_docker_host" \
76-
-Dsonar.login="$sonar_token" \
72+
-Dsonar.token="$sonar_token" \
7773
-Dsonar.sources="src" \
7874
-Dsonar.exclusions="results/**,scorecard/**,scripts/**,tools/**,VMs/**,**/*.js"
7975

@@ -87,8 +83,9 @@ done
8783
echo ""
8884
echo "Generating report..."
8985

86+
mvn compile
9087
mvn exec:java -Dexec.mainClass="org.owasp.benchmark.report.sonarqube.SonarReport"
9188

9289
echo "Shutting down SonarQube..."
9390

94-
#docker stop "$container_name"
91+
docker stop "$container_name"

0 commit comments

Comments
 (0)