OWASP Dependency Check Config Lint

OWASP dependency check setup lint for pom.xml, Gradle, suppression XML and CI files: plugin versions below the 12.1.0 mandatory upgrade, expired suppressions, hardcoded NVD API keys, failBuildOnCVSS 11. Runs entirely in your browser — nothing is uploaded.

Same engine as the VS Code extension, byte for byte.

Get the full version $29

Scans every build, suppression and CI file in the workspace at once, exports a dated audit report and runs the same check in CI with a team key.

One payment, one licence key for this tool. The key is shown right after payment.

Snyk Team starts at $25 a month (snyk.io/plans, checked 2026-10-01); this lint is $29 once and keeps the free scanner you already run.

Buy the full version — $29
Get the steps by email
We send the link and three steps to a first result now, then a real example and what the full version adds over the next week, and one email if a rule behind this tool changes. No newsletter.
ENDEJAESPT

Find a tool

· ReadyStack

Worked example

Real numbers from this tool, line by line.

OWASP Dependency Check Config Lint

OWASP dependency check: six setup findings in a sample pom.xml, and the dates behind them

Six findings — three errors and three warnings — came back when OWASP Dependency Check Config Lint read the sample pom.xml of a Java billing API, the Maven build a team lead in a US or EU payments shop inherits. None of them is a CVE. All of them decide whether the CVE scan still works.

The scanner is fine. The setup is dated.

OWASP Dependency-Check is free and widely used in Maven and Gradle builds. Its configuration has broken on fixed dates, and the README on GitHub lists them:

What the lint found, line by line

The sample pom.xml pins dependency-check-maven through a property, dependency-check.version, set to 8.4.3. The lint resolves the property and reports on the version line.

Broken lineFix
dependency-check 8.4.313.0.0 (12.1.0+ mandatory)
nvdApiKey 3f9c2a71-... (literal)${env.NVD_API_KEY}
cveUrlModified .../1.1/ feeddelete; NVD API since 9.0.0
failBuildOnCVSS 11failBuildOnCVSS 7
ossindexAnalyzerEnabled true, no tokenossIndexServerId + token
nexusAnalyzerEnabled truefalse (removal in 13.0.0)

failBuildOnCVSS 11 is the default, and since CVSS stops at 10.0 the build can never fail on a CVE. The OSS Index line looks switched on, but with no token the analyzer is turned off for you.

Suppressions expire on a date

A suppression file can carry an until date:

<suppress until="2026-09-15Z">
  <cve>CVE-2020-36518</cve>
</suppress>

On that day the suppression stops applying and the CVE is reported again. The lint compares every until with today: past dates are errors, dates within 30 days are warnings. Run on 2026-10-01, the sample suppression file gives one error (2026-09-15) and one warning (2026-10-20). Run on 2026-11-01, both are errors.

What a chatbot gets wrong

Ask a chatbot for a dependency-check-maven block and you often get an older version number and the cveUrlModified setting, because most examples online predate 9.0.0. The docs do not point at your line.

The ten rules

ODC001 version below 12.1.0 · ODC002 legacy NVD feed setting · ODC003 hardcoded NVD API key or OSS Index password · ODC004 no NVD API key · ODC005 failBuildOnCVSS above 10 · ODC006 suppression until date · ODC007 OSS Index on without a token · ODC008 legacy OSS Index credentials · ODC009 Java 8 runtime · ODC010 Nexus v2 analyzer.

Free and full

Linting the open file is free, with every finding and fix line. The full version scans every build, suppression and CI file in the workspace, exports a dated audit report and runs the same check in CI with a team key. For comparison, Snyk Team starts at $25 a month on its plans page, checked 2026-10-01, and replaces the scanner instead of checking it.

15 seconds — what it actually does

Questions people ask

What does OWASP Dependency Check Config Lint do?

It reads the files that run OWASP dependency check — pom.xml, build.gradle, dependency-check-suppression.xml and CI workflow YAML — and flags setup breaks on their exact line: plugin versions below the 12.1.0 mandatory upgrade, retired NVD feed settings, hardcoded NVD API keys, failBuildOnCVSS 11, expired suppression until dates, OSS Index without a token, Java 8 runners and Nexus v2. Each finding carries the replacement line and a dated source.

Who is OWASP Dependency Check Config Lint for?

Java and JVM team leads, build engineers and AppSec owners who run OWASP dependency check in Maven, Gradle or a CI pipeline, and anyone who inherited a pom.xml with a dependency-check-maven block nobody has touched since 2023. It also fits auditors who must show the scan was current and able to fail the build on a given date.

Why not just ask a chatbot or read the Dependency-Check docs?

The breaking points are dated: 9.0.0 moved to the NVD API on 2023-11-22, 11.0.0 needs Java 11, issue #7463 made 12.1.0 mandatory on 2025-02-24, and OSS Index tokens became required in September 2025. A chatbot often answers from older docs, and reading the docs does not tell you which line in your own pom.xml is affected. This lint checks each line against those dates.

What is free and what does the full version add?

Free: lint the open file and see every finding with its fix line, with no key and no limit. The full version, $29 once, scans every build, suppression and CI file in the workspace at once, exports a dated audit report, and runs the same check in CI with a team key, so a clean result can be shown to an auditor.

What does the alternative cost?

Snyk Team starts at $25 a month per the snyk.io plans page checked on 2026-10-01, and it replaces your scanner rather than checking it. This lint costs $29 once and keeps the free OWASP Dependency-Check scanner you already run. It only checks that the scan can still update its NVD data, keeps its suppressions current and can fail the build.

Ask about this tool

One question, answered by the person who built it. Your email only if you want the answer sent.