Support dev dependencies in pom.xml #7346
Closed
metametadata
started this conversation in
Ideas
Replies: 2 comments 3 replies
-
Do you mean |
Beta Was this translation helpful? Give feedback.
3 replies
-
Created #7384 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Description
Vuln scanning of
pom.xml
should be able to scan dev dependencies too.E.g.
--include-dev-deps
existing flag can be used to specify such behaviour.Currently it's stated in https://aquasecurity.github.io/trivy/v0.54/docs/coverage/language/java/ that
pom.xml
dev deps will be excluded.Target
Filesystem
Scanner
Vulnerability
Beta Was this translation helpful? Give feedback.
All reactions