Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
347 commits
Select commit Hold shift + click to select a range
cf5eac2
Bump org.apache.httpcomponents.core5:httpcore5 from 5.2.4 to 5.3.1
dependabot[bot] Nov 27, 2024
af7e369
Bump org.apache.httpcomponents.client5:httpclient5 from 5.3.1 to 5.4.1
dependabot[bot] Nov 27, 2024
74db851
Bump org.apache.maven.plugins:maven-site-plugin
dependabot[bot] Nov 27, 2024
896a028
Bump org.apache.maven.plugins:maven-dependency-plugin
dependabot[bot] Nov 27, 2024
efbb62e
Bump co.leantechniques:maven-buildtime-extension from 3.0.3 to 3.0.5
dependabot[bot] Nov 27, 2024
a5a2e09
Bump com.github.spotbugs:spotbugs from 4.8.4 to 4.8.6
dependabot[bot] Nov 27, 2024
bf6454d
Bump org.apache.maven.plugins:maven-pmd-plugin from 3.21.2 to 3.26.0
dependabot[bot] Nov 27, 2024
027c98b
Merge pull request #250 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Nov 27, 2024
4251a1d
Merge pull request #251 from OWASP-Benchmark/dependabot/maven/org.cod…
davewichers Nov 27, 2024
1793d07
Merge pull request #253 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Nov 27, 2024
729c0f5
Merge pull request #254 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Nov 27, 2024
482b01b
Merge pull request #255 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Nov 27, 2024
0d0b196
Merge pull request #256 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Nov 27, 2024
51454ff
Merge pull request #257 from OWASP-Benchmark/dependabot/maven/co.lean…
davewichers Nov 27, 2024
8423261
Merge pull request #258 from OWASP-Benchmark/dependabot/maven/com.git…
davewichers Nov 27, 2024
2036e23
Merge pull request #259 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Nov 27, 2024
3201b91
Bump org.apache.maven.plugins:maven-help-plugin from 3.4.0 to 3.5.1
dependabot[bot] Nov 28, 2024
b90ab4c
Bump org.hsqldb:hsqldb from 2.7.2 to 2.7.4
dependabot[bot] Nov 28, 2024
1fd790d
Merge pull request #261 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Nov 29, 2024
4b4ce2b
Merge pull request #262 from OWASP-Benchmark/dependabot/maven/org.hsq…
davewichers Nov 29, 2024
70a0838
Due to ESAPI 2.6.0.0 upgrade, have to drop esapi logging properties file
davewichers Nov 29, 2024
4f81617
Upgrade to latest version of Tomcat 9.
davewichers Nov 29, 2024
78eb964
Upgrade a few dependencies/plugins.
davewichers Nov 29, 2024
a214551
Update CodeQL tool scripts to work with latest version (2.19.4). Old …
davewichers Dec 6, 2024
4ceda54
Upgrade 1 plugin and upgrade googleJavaFormat setting for
Dec 16, 2024
dbb943b
Upgrade a few plugins. Add missing ESAPI property due to previous ESAPI
davewichers Jan 7, 2025
2ca55cd
Revert maven-site-plugin to 3.x release, upgrade spotless, and fluido
davewichers Jan 8, 2025
2c69ee0
Bump org.apache.httpcomponents.core5:httpcore5 from 5.3.1 to 5.3.2
dependabot[bot] Jan 10, 2025
910341c
Merge pull request #278 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Jan 10, 2025
9cd4eba
Bump com.diffplug.spotless:spotless-maven-plugin from 2.44.1 to 2.44.2
dependabot[bot] Jan 15, 2025
c439bd4
Merge pull request #279 from OWASP-Benchmark/dependabot/maven/com.dif…
davewichers Jan 15, 2025
2354a91
SonarQube requires 12 characters passwords now
Leyart Jan 16, 2025
6b3633e
Bump com.github.spotbugs:spotbugs from 4.8.6 to 4.9.0
dependabot[bot] Jan 16, 2025
c57e4e2
Merge pull request #282 from OWASP-Benchmark/dependabot/maven/com.git…
davewichers Jan 16, 2025
a3e11b7
Merge pull request #280 from Leyart/sonarPassword
davewichers Jan 17, 2025
b25801a
Create a 2nd Contrast CodeSec script for scanning source code, and move
Jan 20, 2025
00931b7
Add version of runBearer script that works on Windows.
davewichers Jan 23, 2025
f190e05
Fix runContrastCodeSec_OnSource.sh script. Add Snyk version to runSnyk
Jan 24, 2025
08240ce
Bump commons-codec:commons-codec from 1.17.2 to 1.18.0
dependabot[bot] Jan 28, 2025
d45ed05
Bump org.apache.httpcomponents.core5:httpcore5 from 5.3.2 to 5.3.3
dependabot[bot] Jan 28, 2025
4fb517b
replace custom sonarqube generation with sonar-report plus some minor…
darkspirit510 Jan 28, 2025
fc4931a
Merge pull request #283 from OWASP-Benchmark/dependabot/maven/commons…
davewichers Jan 28, 2025
22b9ded
Merge pull request #284 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Jan 28, 2025
fdfe560
Merge pull request #286 from darkspirit510/sonar-report-new
davewichers Jan 28, 2025
29f0763
Bump org.apache.httpcomponents.client5:httpclient5 from 5.4.1 to 5.4.2
dependabot[bot] Feb 3, 2025
4a591ee
Bump org.codehaus.cargo:cargo-maven3-plugin from 1.10.16 to 1.10.17
dependabot[bot] Feb 3, 2025
e734ee1
Merge pull request #287 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Feb 3, 2025
5f98cd3
Merge pull request #288 from OWASP-Benchmark/dependabot/maven/org.cod…
davewichers Feb 3, 2025
4e91806
Bump com.github.spotbugs:spotbugs from 4.9.0 to 4.9.1
dependabot[bot] Feb 10, 2025
32933c4
SonarQube report as Java class
darkspirit510 Feb 15, 2025
ff84eb4
Merge pull request #289 from OWASP-Benchmark/dependabot/maven/com.git…
davewichers Feb 18, 2025
53d3cc6
Bump com.github.spotbugs:spotbugs-maven-plugin from 4.8.6.6 to 4.9.1.0
dependabot[bot] Feb 18, 2025
e4ab03e
Merge pull request #291 from OWASP-Benchmark/dependabot/maven/com.git…
davewichers Feb 18, 2025
994bca8
Bump org.apache.maven.plugins:maven-clean-plugin from 3.4.0 to 3.4.1
dependabot[bot] Feb 19, 2025
f183cd3
Merge pull request #292 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Feb 19, 2025
0f2fff0
Bump org.apache.maven.plugins:maven-compiler-plugin
dependabot[bot] Feb 21, 2025
5e1ffee
Bump com.diffplug.spotless:spotless-maven-plugin from 2.44.2 to 2.44.3
dependabot[bot] Feb 21, 2025
2d636c9
Merge pull request #293 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Feb 21, 2025
6237f53
Merge pull request #294 from OWASP-Benchmark/dependabot/maven/com.dif…
davewichers Feb 21, 2025
f119cb3
Bump org.slf4j:slf4j-reload4j from 2.0.16 to 2.0.17
dependabot[bot] Feb 26, 2025
e0e8a33
Merge pull request #295 from OWASP-Benchmark/dependabot/maven/org.slf…
davewichers Feb 26, 2025
3a0386a
Bump org.apache.maven.plugins:maven-deploy-plugin from 3.1.3 to 3.1.4
dependabot[bot] Feb 27, 2025
64de60d
Bump org.apache.maven.plugins:maven-project-info-reports-plugin
dependabot[bot] Feb 27, 2025
c8a1fb8
Merge pull request #296 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Feb 27, 2025
f9d1761
Merge pull request #297 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Feb 27, 2025
eac9230
Bump org.apache.maven.plugins:maven-install-plugin from 3.1.3 to 3.1.4
dependabot[bot] Feb 28, 2025
6cbf3ac
Merge pull request #298 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Feb 28, 2025
283e0e6
spotless
darkspirit510 Mar 2, 2025
0096876
Bump com.github.spotbugs:spotbugs from 4.9.1 to 4.9.2
dependabot[bot] Mar 3, 2025
bdd3ee3
Merge pull request #300 from OWASP-Benchmark/dependabot/maven/com.git…
davewichers Mar 3, 2025
cb70ea0
Bump com.github.spotbugs:spotbugs-maven-plugin from 4.9.1.0 to 4.9.2.0
dependabot[bot] Mar 4, 2025
908ae94
Bump org.codehaus.cargo:cargo-maven3-plugin from 1.10.17 to 1.10.18
dependabot[bot] Mar 4, 2025
eda7fac
Merge pull request #301 from OWASP-Benchmark/dependabot/maven/com.git…
davewichers Mar 5, 2025
d99d962
Merge pull request #302 from OWASP-Benchmark/dependabot/maven/org.cod…
davewichers Mar 5, 2025
81e4e20
Bump org.apache.maven.skins:maven-fluido-skin from 2.0.1 to 2.1.0
dependabot[bot] Mar 13, 2025
cf1f0c3
Merge pull request #304 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Mar 14, 2025
a73bc43
Bump com.github.spotbugs:spotbugs-maven-plugin from 4.9.2.0 to 4.9.3.0
dependabot[bot] Mar 17, 2025
4f3b458
Merge pull request #305 from OWASP-Benchmark/dependabot/maven/com.git…
davewichers Mar 19, 2025
94c8510
Bump com.github.spotbugs:spotbugs from 4.9.2 to 4.9.3
dependabot[bot] Mar 19, 2025
958f09d
Bump org.apache.httpcomponents.core5:httpcore5 from 5.3.3 to 5.3.4
dependabot[bot] Mar 20, 2025
eb63c90
Merge pull request #307 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Mar 20, 2025
245b363
Merge pull request #306 from OWASP-Benchmark/dependabot/maven/com.git…
davewichers Mar 20, 2025
a23230b
Bump org.apache.httpcomponents.client5:httpclient5 from 5.4.2 to 5.4.3
dependabot[bot] Mar 27, 2025
bb30092
Merge pull request #309 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Mar 27, 2025
2fad50d
Bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.2 to 3.5.3
dependabot[bot] Mar 31, 2025
83b97c5
Merge pull request #310 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Mar 31, 2025
e8af2b1
Merge pull request #299 from darkspirit510/report-as-java-class
davewichers Mar 31, 2025
f79a6bd
Bump org.codehaus.mojo:extra-enforcer-rules from 1.9.0 to 1.10.0
dependabot[bot] Apr 1, 2025
7cb8188
Bump com.fasterxml.jackson.core:jackson-databind from 2.17.2 to 2.18.3
dependabot[bot] Apr 1, 2025
ff025b4
Merge pull request #311 from OWASP-Benchmark/dependabot/maven/org.cod…
davewichers Apr 1, 2025
62ebf48
Merge pull request #312 from OWASP-Benchmark/dependabot/maven/com.fas…
davewichers Apr 1, 2025
5f5bcdd
Bump com.diffplug.spotless:spotless-maven-plugin from 2.44.3 to 2.44.4
dependabot[bot] Apr 8, 2025
446b40c
Merge pull request #313 from OWASP-Benchmark/dependabot/maven/com.dif…
davewichers Apr 8, 2025
af75ca3
Bump org.codehaus.cargo:cargo-maven3-plugin from 1.10.18 to 1.10.19
dependabot[bot] Apr 9, 2025
c5dc499
Merge pull request #314 from OWASP-Benchmark/dependabot/maven/org.cod…
davewichers Apr 9, 2025
b2e5b14
Bump commons-io:commons-io from 2.18.0 to 2.19.0
dependabot[bot] Apr 14, 2025
d40f68e
Merge pull request #315 from OWASP-Benchmark/dependabot/maven/commons…
davewichers Apr 14, 2025
5837a4e
Bump com.h3xstream.findsecbugs:findsecbugs-plugin from 1.13.0 to 1.14.0
dependabot[bot] Apr 21, 2025
958b5bb
Merge pull request #318 from OWASP-Benchmark/dependabot/maven/com.h3x…
davewichers Apr 21, 2025
90b5f0f
Bump org.apache.httpcomponents.client5:httpclient5 from 5.4.3 to 5.4.4
dependabot[bot] Apr 25, 2025
66ad756
Bump com.fasterxml.jackson.core:jackson-databind from 2.18.3 to 2.19.0
dependabot[bot] Apr 25, 2025
251004d
Merge pull request #319 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Apr 25, 2025
ca30e67
Merge pull request #320 from OWASP-Benchmark/dependabot/maven/com.fas…
davewichers Apr 25, 2025
6912889
Bump org.owasp.esapi:esapi from 2.6.0.0 to 2.6.1.0
dependabot[bot] May 19, 2025
476fab1
Merge pull request #322 from OWASP-Benchmark/dependabot/maven/org.owa…
davewichers May 19, 2025
aaed9e4
Update CodeQL scripts to use newer/stronger set of Java rules that
davewichers May 21, 2025
8128b5b
Bump org.apache.httpcomponents.client5:httpclient5 from 5.4.4 to 5.5
dependabot[bot] May 23, 2025
072598b
Merge pull request #323 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers May 23, 2025
3527c5a
Bump com.diffplug.spotless:spotless-maven-plugin from 2.44.4 to 2.44.5
dependabot[bot] May 28, 2025
7dc9145
Merge pull request #324 from OWASP-Benchmark/dependabot/maven/com.dif…
davewichers May 28, 2025
e8e17df
Move results files back into results directly that were accidentally
May 29, 2025
a0e756d
Bump org.apache.maven.plugins:maven-clean-plugin from 3.4.1 to 3.5.0
dependabot[bot] Jun 2, 2025
a3be45b
Merge pull request #325 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Jun 2, 2025
53457c6
Bump org.owasp.esapi:esapi from 2.6.1.0 to 2.6.2.0
dependabot[bot] Jun 3, 2025
7021305
Merge pull request #326 from OWASP-Benchmark/dependabot/maven/org.owa…
davewichers Jun 3, 2025
92532b7
Bump org.codehaus.cargo:cargo-maven3-plugin from 1.10.19 to 1.10.20
dependabot[bot] Jun 9, 2025
fe53c83
Merge pull request #327 from OWASP-Benchmark/dependabot/maven/org.cod…
davewichers Jun 9, 2025
ff352d6
Bump com.fasterxml.jackson.core:jackson-databind from 2.19.0 to 2.19.1
dependabot[bot] Jun 16, 2025
f39357b
Merge pull request #329 from OWASP-Benchmark/dependabot/maven/com.fas…
davewichers Jun 17, 2025
365facc
Bump com.github.spotbugs:spotbugs-maven-plugin from 4.9.3.0 to 4.9.3.1
dependabot[bot] Jun 25, 2025
5427a0b
Merge pull request #330 from OWASP-Benchmark/dependabot/maven/com.git…
davewichers Jun 25, 2025
6cb57d2
Bump org.apache.maven.plugins:maven-pmd-plugin from 3.26.0 to 3.27.0
dependabot[bot] Jun 26, 2025
fb37f15
Merge pull request #331 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Jun 26, 2025
109e3ed
Bump com.github.spotbugs:spotbugs-maven-plugin from 4.9.3.1 to 4.9.3.2
dependabot[bot] Jun 27, 2025
99d7530
Merge pull request #332 from OWASP-Benchmark/dependabot/maven/com.git…
davewichers Jun 27, 2025
eae3c16
Bump org.owasp.esapi:esapi from 2.6.2.0 to 2.7.0.0
dependabot[bot] Jun 30, 2025
6be8ea9
Merge pull request #333 from OWASP-Benchmark/dependabot/maven/org.owa…
davewichers Jun 30, 2025
520e8d1
Bump org.apache.maven.plugins:maven-enforcer-plugin from 3.5.0 to 3.6.0
dependabot[bot] Jul 2, 2025
a8bd437
Merge pull request #334 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Jul 2, 2025
5aa8320
Bump com.diffplug.spotless:spotless-maven-plugin from 2.44.5 to 2.45.0
dependabot[bot] Jul 8, 2025
d706e9c
Merge pull request #335 from OWASP-Benchmark/dependabot/maven/com.dif…
davewichers Jul 8, 2025
b79b28f
Bump org.apache.maven.plugins:maven-enforcer-plugin from 3.6.0 to 3.6.1
dependabot[bot] Jul 16, 2025
ecbd3a2
Bump commons-io:commons-io from 2.19.0 to 2.20.0
dependabot[bot] Jul 21, 2025
e1dcc84
Bump com.fasterxml.jackson.core:jackson-databind from 2.19.1 to 2.19.2
dependabot[bot] Jul 21, 2025
d9348d6
Bump com.diffplug.spotless:spotless-maven-plugin from 2.45.0 to 2.46.1
dependabot[bot] Jul 22, 2025
d087c0c
Bump commons-codec:commons-codec from 1.18.0 to 1.19.0
dependabot[bot] Jul 23, 2025
2df9e37
Merge pull request #336 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Jul 24, 2025
8b46536
Merge pull request #339 from OWASP-Benchmark/dependabot/maven/commons…
davewichers Jul 24, 2025
baf2a74
Merge pull request #340 from OWASP-Benchmark/dependabot/maven/com.fas…
davewichers Jul 24, 2025
91df53e
Merge pull request #341 from OWASP-Benchmark/dependabot/maven/com.dif…
davewichers Jul 24, 2025
e2734b2
Merge pull request #342 from OWASP-Benchmark/dependabot/maven/commons…
davewichers Jul 24, 2025
a8a92a3
Bump com.github.spotbugs:spotbugs from 4.9.3 to 4.9.4
dependabot[bot] Aug 11, 2025
fb9e3c7
Bump org.codehaus.cargo:cargo-maven3-plugin from 1.10.20 to 1.10.21
dependabot[bot] Aug 11, 2025
87aad45
Bump actions/checkout from 4 to 5
dependabot[bot] Aug 12, 2025
bc16ff9
Merge pull request #347 from OWASP-Benchmark/dependabot/maven/com.git…
davewichers Aug 17, 2025
177d79d
Merge pull request #348 from OWASP-Benchmark/dependabot/maven/org.cod…
davewichers Aug 17, 2025
eb87c89
Merge pull request #349 from OWASP-Benchmark/dependabot/github_action…
davewichers Aug 17, 2025
9b45fb6
Bump actions/setup-java from 4 to 5
dependabot[bot] Aug 21, 2025
0303430
Merge pull request #351 from OWASP-Benchmark/dependabot/github_action…
davewichers Aug 21, 2025
21b66e6
Bump com.github.spotbugs:spotbugs-maven-plugin from 4.9.3.2 to 4.9.4.0
dependabot[bot] Aug 22, 2025
79bb497
Merge pull request #352 from OWASP-Benchmark/dependabot/maven/com.git…
davewichers Aug 22, 2025
fc267b1
Bump com.fasterxml.jackson.core:jackson-databind from 2.19.2 to 2.20.0
dependabot[bot] Aug 29, 2025
9a0a151
Merge pull request #353 from OWASP-Benchmark/dependabot/maven/com.fas…
davewichers Aug 29, 2025
16cea00
Bump org.apache.httpcomponents.core5:httpcore5 from 5.3.4 to 5.3.5
dependabot[bot] Sep 1, 2025
0b3ad0d
Merge pull request #354 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Sep 2, 2025
638cefe
Bump com.github.spotbugs:spotbugs-maven-plugin from 4.9.4.0 to 4.9.4.1
dependabot[bot] Sep 3, 2025
458f168
Merge pull request #355 from OWASP-Benchmark/dependabot/maven/com.git…
davewichers Sep 3, 2025
20b5b54
Bump org.codehaus.mojo:versions-maven-plugin from 2.18.0 to 2.19.0
dependabot[bot] Sep 5, 2025
2944f55
Merge pull request #356 from OWASP-Benchmark/dependabot/maven/org.cod…
davewichers Sep 5, 2025
18aed35
Bump com.github.spotbugs:spotbugs-maven-plugin from 4.9.4.1 to 4.9.4.2
dependabot[bot] Sep 8, 2025
e0c6487
Merge pull request #357 from OWASP-Benchmark/dependabot/maven/com.git…
davewichers Sep 8, 2025
bececc2
Bump com.github.spotbugs:spotbugs from 4.9.4 to 4.9.5
dependabot[bot] Sep 15, 2025
2664051
Bump org.codehaus.cargo:cargo-maven3-plugin from 1.10.21 to 1.10.22
dependabot[bot] Sep 15, 2025
cb8a418
Bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.3 to 3.5.4
dependabot[bot] Sep 15, 2025
995308f
Merge pull request #359 from OWASP-Benchmark/dependabot/maven/com.git…
davewichers Sep 15, 2025
44d817c
Merge pull request #360 from OWASP-Benchmark/dependabot/maven/org.cod…
davewichers Sep 15, 2025
5a1e8ae
Merge pull request #361 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Sep 15, 2025
2ba0781
Bump com.github.spotbugs:spotbugs-maven-plugin from 4.9.4.2 to 4.9.5.0
dependabot[bot] Sep 16, 2025
ccbe389
Merge pull request #362 from OWASP-Benchmark/dependabot/maven/com.git…
davewichers Sep 16, 2025
2e430b2
Bump com.github.spotbugs:spotbugs from 4.9.5 to 4.9.6
dependabot[bot] Sep 17, 2025
cfdcf07
Merge pull request #363 from OWASP-Benchmark/dependabot/maven/com.git…
davewichers Sep 17, 2025
74b5649
Bump com.github.spotbugs:spotbugs-maven-plugin from 4.9.5.0 to 4.9.6.0
dependabot[bot] Sep 18, 2025
9011af6
Merge pull request #364 from OWASP-Benchmark/dependabot/maven/com.git…
davewichers Sep 18, 2025
c9304de
Bump org.codehaus.mojo:versions-maven-plugin from 2.19.0 to 2.19.1
dependabot[bot] Sep 22, 2025
37b4f5d
Bump org.apache.maven.plugins:maven-compiler-plugin
dependabot[bot] Sep 22, 2025
d676548
Bump org.apache.httpcomponents.core5:httpcore5 from 5.3.5 to 5.3.6
dependabot[bot] Sep 22, 2025
5da8522
Merge pull request #365 from OWASP-Benchmark/dependabot/maven/org.cod…
davewichers Sep 22, 2025
f6257a3
Merge pull request #366 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Sep 22, 2025
8e67df1
Merge pull request #367 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Sep 22, 2025
846a7c7
Upgrade Tomcat 9 to latest version.
Sep 25, 2025
5bd80cf
Bump org.apache.httpcomponents.client5:httpclient5 from 5.5 to 5.5.1
dependabot[bot] Sep 29, 2025
01bfc49
Merge pull request #369 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Sep 29, 2025
96aee66
Bump org.apache.maven.plugins:maven-enforcer-plugin from 3.6.1 to 3.6.2
dependabot[bot] Oct 3, 2025
946daf2
Bump org.apache.maven.plugins:maven-dependency-plugin
dependabot[bot] Oct 3, 2025
dffaae9
Bump org.codehaus.mojo:extra-enforcer-rules from 1.10.0 to 1.11.0
dependabot[bot] Oct 6, 2025
9d31db3
Merge pull request #370 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Oct 6, 2025
61fc67e
Merge pull request #371 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Oct 6, 2025
6240c5e
Merge pull request #372 from OWASP-Benchmark/dependabot/maven/org.cod…
davewichers Oct 6, 2025
28a9ea3
Bump github/codeql-action from 3 to 4
dependabot[bot] Oct 8, 2025
8f01d79
Merge pull request #373 from OWASP-Benchmark/dependabot/github_action…
davewichers Oct 8, 2025
b259a1f
Bump org.apache.maven.plugins:maven-pmd-plugin from 3.27.0 to 3.28.0
dependabot[bot] Oct 13, 2025
eacbd3c
Bump org.codehaus.cargo:cargo-maven3-plugin from 1.10.22 to 1.10.23
dependabot[bot] Oct 13, 2025
fb26969
Merge pull request #374 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Oct 14, 2025
60e72a2
Merge pull request #375 from OWASP-Benchmark/dependabot/maven/org.cod…
davewichers Oct 14, 2025
e4b59d5
Bump com.github.spotbugs:spotbugs from 4.9.6 to 4.9.7
dependabot[bot] Oct 15, 2025
b917e08
Merge pull request #376 from OWASP-Benchmark/dependabot/maven/com.git…
davewichers Oct 15, 2025
3f099cc
Bump com.github.spotbugs:spotbugs-maven-plugin from 4.9.6.0 to 4.9.7.0
dependabot[bot] Oct 15, 2025
0e1dc67
Merge pull request #377 from OWASP-Benchmark/dependabot/maven/com.git…
davewichers Oct 15, 2025
8b17201
Bump org.codehaus.cargo:cargo-maven3-plugin from 1.10.23 to 1.10.24
dependabot[bot] Oct 16, 2025
7ae3cbd
Merge pull request #379 from OWASP-Benchmark/dependabot/maven/org.cod…
davewichers Oct 16, 2025
65a0531
Bump com.github.spotbugs:spotbugs from 4.9.7 to 4.9.8
dependabot[bot] Oct 20, 2025
6eef016
Bump com.github.spotbugs:spotbugs-maven-plugin from 4.9.7.0 to 4.9.8.1
dependabot[bot] Oct 20, 2025
03f0fa3
Merge pull request #380 from OWASP-Benchmark/dependabot/maven/com.git…
davewichers Oct 20, 2025
7e418db
Merge branch 'master' into dependabot/maven/com.github.spotbugs-spotb…
davewichers Oct 20, 2025
2397772
Merge pull request #381 from OWASP-Benchmark/dependabot/maven/com.git…
davewichers Oct 20, 2025
7255141
Bump org.apache.maven.plugins:maven-antrun-plugin from 3.1.0 to 3.2.0
dependabot[bot] Oct 21, 2025
8a24961
Merge pull request #382 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Oct 21, 2025
25d3b02
Bump org.apache.maven.plugins:maven-war-plugin from 3.4.0 to 3.5.0
dependabot[bot] Oct 27, 2025
68b0dd9
Bump actions/upload-artifact from 4 to 5
dependabot[bot] Oct 27, 2025
ce8bc00
Merge pull request #383 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Oct 27, 2025
6693123
Merge pull request #384 from OWASP-Benchmark/dependabot/github_action…
davewichers Oct 27, 2025
096d215
Bump com.fasterxml.jackson.core:jackson-databind from 2.20.0 to 2.20.1
dependabot[bot] Oct 31, 2025
2565f29
Merge pull request #385 from OWASP-Benchmark/dependabot/maven/com.fas…
davewichers Oct 31, 2025
1244735
Fix runBearer.sh script so docker now works in the tighter/more const…
Oct 31, 2025
2665e65
Minor tweaks to runCodeQL.sh and README.
davewichers Nov 1, 2025
63e07ad
Bump commons-codec:commons-codec from 1.19.0 to 1.20.0
dependabot[bot] Nov 6, 2025
314b2af
Bump commons-io:commons-io from 2.20.0 to 2.21.0
dependabot[bot] Nov 10, 2025
5f60686
Bump org.apache.maven.plugins:maven-release-plugin from 3.1.1 to 3.2.0
dependabot[bot] Nov 10, 2025
0320c5d
Bump org.codehaus.cargo:cargo-maven3-plugin from 1.10.24 to 1.10.25
dependabot[bot] Nov 10, 2025
c3063e1
Merge pull request #386 from OWASP-Benchmark/dependabot/maven/commons…
davewichers Nov 17, 2025
4a09861
Merge pull request #388 from OWASP-Benchmark/dependabot/maven/commons…
davewichers Nov 17, 2025
1a010c8
Merge pull request #389 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Nov 17, 2025
c2f1c12
Merge pull request #390 from OWASP-Benchmark/dependabot/maven/org.cod…
davewichers Nov 17, 2025
2cf91fa
Upgrade spotless dependency and maven workflow since spotless now
davewichers Nov 19, 2025
b74c1df
Update Dockerfile to use java 17
Nov 21, 2025
f0de687
Bump actions/checkout from 5 to 6
dependabot[bot] Nov 21, 2025
1253554
Merge pull request #394 from roksui/vm
davewichers Nov 21, 2025
4fb9a3c
Merge pull request #395 from OWASP-Benchmark/dependabot/github_action…
davewichers Nov 21, 2025
17f30c8
Minor enhancements to some tool scripts.
davewichers Nov 21, 2025
ec7def2
Bump com.github.spotbugs:spotbugs-maven-plugin from 4.9.8.1 to 4.9.8.2
dependabot[bot] Nov 24, 2025
d3f1e08
Bump org.codehaus.mojo:versions-maven-plugin from 2.19.1 to 2.20.0
dependabot[bot] Nov 24, 2025
c2f4f46
Merge pull request #396 from OWASP-Benchmark/dependabot/maven/com.git…
davewichers Nov 24, 2025
4d7dfa9
Merge pull request #397 from OWASP-Benchmark/dependabot/maven/org.cod…
davewichers Nov 24, 2025
633afab
Bump org.codehaus.mojo:versions-maven-plugin from 2.20.0 to 2.20.1
dependabot[bot] Nov 25, 2025
2bdd0c4
Merge pull request #398 from OWASP-Benchmark/dependabot/maven/org.cod…
davewichers Nov 25, 2025
cbcb9ea
Bump org.apache.maven.plugins:maven-resources-plugin from 3.3.1 to 3.4.0
dependabot[bot] Dec 2, 2025
b50ec2a
Bump org.apache.maven.plugins:maven-assembly-plugin from 3.7.1 to 3.8.0
dependabot[bot] Dec 2, 2025
e70b8da
Bump org.apache.maven.plugins:maven-war-plugin from 3.5.0 to 3.5.1
dependabot[bot] Dec 2, 2025
ed937c0
Bump org.apache.maven.plugins:maven-release-plugin from 3.2.0 to 3.3.0
dependabot[bot] Dec 4, 2025
685692c
Merge pull request #399 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Dec 4, 2025
2be9e9e
Merge pull request #400 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Dec 4, 2025
938b2a2
Merge pull request #401 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Dec 4, 2025
4943dbb
Merge pull request #402 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Dec 4, 2025
02fb88d
Bump org.apache.maven.plugins:maven-release-plugin from 3.3.0 to 3.3.1
dependabot[bot] Dec 15, 2025
21e104c
Bump org.apache.httpcomponents.core5:httpcore5 from 5.3.6 to 5.4
dependabot[bot] Dec 15, 2025
0d0d1be
Bump actions/upload-artifact from 5 to 6
dependabot[bot] Dec 15, 2025
b0b465b
Merge pull request #405 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Dec 15, 2025
13c9863
Merge pull request #406 from OWASP-Benchmark/dependabot/maven/org.apa…
davewichers Dec 15, 2025
f139ec1
Merge pull request #407 from OWASP-Benchmark/dependabot/github_action…
davewichers Dec 15, 2025
5ed20d1
Upgrade Tomcat version.
Dec 15, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
18 changes: 18 additions & 0 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
# To get started with Dependabot version updates, you'll need to specify which
# package ecosystems to update and where the package manifests are located.
# Please see the documentation for all configuration options:
# https://docs.github.com/code-security/dependabot/dependabot-version-updates/configuration-options-for-the-dependabot.yml-file

version: 2
updates:
- package-ecosystem: "github-actions"
directory: "/"
schedule:
interval: "daily"
- package-ecosystem: "maven"
directory: "/"
schedule:
interval: "daily"
open-pull-requests-limit: 10
labels:
- dependencies
26 changes: 16 additions & 10 deletions .github/workflows/codeql-analysis.yml
Original file line number Diff line number Diff line change
@@ -1,13 +1,15 @@
name: "CodeQL"

env:
CODEQL_EXTRACTOR_JAVA_RUN_ANNOTATION_PROCESSORS: true

on:
push:
branches: [ master ]
pull_request:
# The branches below must be a subset of the branches above
branches: [ master ]
schedule:
- cron: '32 14 * * 0'
workflow_dispatch:

jobs:
analyze:
Expand All @@ -17,31 +19,35 @@ jobs:
actions: read
contents: read
security-events: write

strategy:
fail-fast: false
matrix:
language: [ 'java', 'javascript' ]

steps:
- name: Checkout repository
uses: actions/checkout@v2
uses: actions/checkout@v6
# Get full history for spotless ratchetFrom
with:
fetch-depth: 0

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v1
uses: github/codeql-action/init@v4
with:
languages: ${{ matrix.language }}
# queries: ./path/to/local/query, your-org/your-repo/queries@main

#- name: Autobuild
# uses: github/codeql-action/autobuild@v1
queries: security-extended, security-experimental, security-and-quality

- name: Build with Maven
run: mvn -DskipTests=true install

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v1
uses: github/codeql-action/analyze@v4

- name: Upload Output
uses: actions/upload-artifact@v6
with:
name: ${{ matrix.language }} SARIF
path: ${{ runner.workspace }}/results/*.sarif

15 changes: 8 additions & 7 deletions .github/workflows/maven.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -8,15 +8,16 @@ jobs:
runs-on: ubuntu-latest

steps:
- uses: actions/checkout@v2
- uses: actions/checkout@v6
with:
fetch-depth: 0
- name: Set up JDK 1.8
uses: actions/setup-java@v1
- name: Set up JDK 17
uses: actions/setup-java@v5
with:
java-version: 1.8
- name: Run spotless check
java-version: 17
distribution: zulu
- name: Run Spotless check
run: mvn spotless:check
- name: Run unit tests
run: mvn test
- name: Create WAR
run: mvn package

7 changes: 5 additions & 2 deletions .gitignore
Original file line number Diff line number Diff line change
@@ -1,17 +1,20 @@
.DS_Store
.dccache
.java-version
.classpath
.project
.settings/
.idea/
*.iml
.scannerwork/

data/out.csv
owasp-benchmark/
reports/
scripts/SonarQubeCredentials.sh
src.zip
src/main/resources/benchmark.properties
target/
testfiles/
tools/Contrast/contrast.jar
tools/Contrast/contrast.yaml
tools/Contrast/working/

2 changes: 1 addition & 1 deletion .mvn/extensions.xml
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@
<extension>
<groupId>co.leantechniques</groupId>
<artifactId>maven-buildtime-extension</artifactId>
<version>3.0.3</version>
<version>3.0.5</version>
</extension>
</extensions>

8 changes: 8 additions & 0 deletions .mvn/jvm.config
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
--add-exports jdk.compiler/com.sun.tools.javac.tree=ALL-UNNAMED
--add-opens java.base/java.lang=ALL-UNNAMED

--add-exports=jdk.compiler/com.sun.tools.javac.api=ALL-UNNAMED
--add-exports=jdk.compiler/com.sun.tools.javac.code=ALL-UNNAMED
--add-exports=jdk.compiler/com.sun.tools.javac.file=ALL-UNNAMED
--add-exports=jdk.compiler/com.sun.tools.javac.parser=ALL-UNNAMED
--add-exports=jdk.compiler/com.sun.tools.javac.util=ALL-UNNAMED
3 changes: 2 additions & 1 deletion DevStyleXml.prefs
Original file line number Diff line number Diff line change
Expand Up @@ -2,4 +2,5 @@ eclipse.preferences.version=1
indentationChar=space
indentationSize=4
lineWidth=999
formatCommentJoinLines=false
formatCommentJoinLines=true

12 changes: 9 additions & 3 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,12 @@
# OWASP Benchmark
The OWASP Benchmark Project is a Java test suite designed to verify the speed and accuracy of vulnerability detection tools. It is a fully runnable open source web application that can be analyzed by any type of Application Security Testing (AST) tool, including SAST, DAST (like <a href="https://owasp.org/www-project-zap">OWASP ZAP</a>), and IAST tools. The intent is that all the vulnerabilities deliberately included in and scored by the Benchmark are actually exploitable so its a fair test for any kind of application vulnerability detection tool. The Benchmark also includes scorecard generators for numerous open source and commercial AST tools, and the set of supported tools is growing all the time.
# OWASP Benchmark for Java
The OWASP Benchmark Project is a Java test suite designed to verify the speed and accuracy of vulnerability detection tools. It is a fully runnable open source web application that can be analyzed by any type of Application Security Testing (AST) tool, including SAST, DAST (like <a href="https://www.zaproxy.org/">ZAP</a>), and IAST tools. The intent is that all the vulnerabilities deliberately included in and scored by the Benchmark are actually exploitable so it's a fair test for any kind of application vulnerability detection tool.

The Benchmark project also includes scorecard generators for numerous open source and commercial AST tools, and the set of supported tools is growing all the time. This scoring capability is implemented in the BenchmarkUtils project, which is at: https://github.com/OWASP/BenchmarkUtils.

The project documentation is all on the OWASP site at the <a href="https://owasp.org/www-project-benchmark">OWASP Benchmark</a> project pages. Please refer to that site for all the project details.

The current latest release is v1.2. Note that all the releases that are available here: https://github.com/OWASP/Benchmark/releases are historical. The latest release is always available live by simply cloning or pulling the head of this repository (i.e., git pull).
The current latest release is v1.2. Note that all the releases that are available here: https://github.com/OWASP/BenchmarkJava/releases, are historical. The latest release is always available live by simply cloning or pulling the head of this repository (i.e., git pull).

Running Benchmark Itself:
* runBenchmark.sh - run the Benchmark Web Application (accessible via local machine only)
* runRemoteAccessibleBenchmark.sh - like the above but allows port 8443 to be accessible outside the machine Benchmark is running on.
23 changes: 20 additions & 3 deletions VMs/Dockerfile
Original file line number Diff line number Diff line change
@@ -1,12 +1,12 @@
# This dockerfile builds a container that pulls down and runs the latest version of Benchmark
# This dockerfile builds a container that pulls down and runs the latest version of BenchmarkJava
FROM ubuntu:latest
MAINTAINER "Dave Wichers [email protected]"

RUN apt-get update
RUN DEBIAN_FRONTEND="noninteractive" apt-get -y install tzdata
RUN apt-get install -q -y \
openjdk-8-jre-headless \
openjdk-8-jdk \
openjdk-17-jre-headless \
openjdk-17-jdk \
git \
maven \
wget \
Expand All @@ -15,7 +15,19 @@ RUN apt-get install -q -y \

RUN mkdir /owasp
WORKDIR /owasp

# Download, build, install Benchmark Utilities required by crawler and scorecard generation
RUN git clone https://github.com/OWASP-Benchmark/BenchmarkUtils.git
WORKDIR /owasp/BenchmarkUtils
RUN mvn install

# Download, build BenchmarkJava
WORKDIR /owasp
RUN git clone https://github.com/OWASP-Benchmark/BenchmarkJava

# Workaround for security fix for CVE-2022-24765
RUN git config --global --add safe.directory /owasp/BenchmarkJava

WORKDIR /owasp/BenchmarkJava
RUN mvn clean package cargo:install

Expand All @@ -25,3 +37,8 @@ RUN echo bench:bench | chpasswd
RUN chown -R bench /owasp/
ENV PATH /owasp/BenchmarkJava:$PATH

# start up Benchmark once, for 60 seconds, then kill it, so the additional dependencies required to run it are downloaded/cached in the image as well.
# exit 0 is required to return a 'success' code, otherwise the timeout returns a failure code, causing the Docker build to fail.
WORKDIR /owasp/BenchmarkJava
RUN timeout 60 ./runBenchmark.sh; exit 0

6 changes: 3 additions & 3 deletions VMs/buildDockerImage.sh
Original file line number Diff line number Diff line change
@@ -1,13 +1,13 @@
# Pull in latest version of ubuntu
# Pull in latest version of ubuntu. This builds an image using the OS native to this platform.
docker pull ubuntu:latest
# Remove any ubuntu:<none> image if it was left behind by a new version of ubunto:latest being pulled
# Remove any ubuntu:<none> image if it was left behind by a new version of ubuntu:latest being pulled
i=$(docker images | grep "ubuntu" | grep "<none" | awk '{print $3}')
if [ "$i" ]
then
docker rmi $i
fi

# Since Docker doesn't auto delete anything, just like for the Ubunto update, delete any existing benchmark:latest image before building a new one
# Since Docker doesn't auto delete anything, just like for the Ubuntu update, delete any existing benchmark:latest image before building a new one
docker image rm benchmark:latest
docker build -t benchmark .

1 change: 0 additions & 1 deletion createScorecards.bat
Original file line number Diff line number Diff line change
@@ -1,4 +1,3 @@
# source "scripts/verifyBenchmarkPluginAvailable.sh" - Don't have .bat version of this (yet)
#mvn -Djava.awt.headless=true org.owasp:benchmarkutils-maven-plugin:create-scorecard -DconfigFile=config/score_v1.3config.yaml
call mvn -Djava.awt.headless=true org.owasp:benchmarkutils-maven-plugin:create-scorecard

3 changes: 1 addition & 2 deletions createScorecards.sh
Original file line number Diff line number Diff line change
@@ -1,4 +1,3 @@
source "scripts/verifyBenchmarkPluginAvailable.sh"
#mvn -Djava.awt.headless=true org.owasp:benchmarkutils-maven-plugin:create-scorecard -DconfigFile=config/score_v1.3config.yaml
mvn -Djava.awt.headless=true org.owasp:benchmarkutils-maven-plugin:create-scorecard
MAVEN_OPTS="-Xmx8G" mvn -Djava.awt.headless=true org.owasp:benchmarkutils-maven-plugin:create-scorecard

Loading