VulnerableCode
An advisor that uses a VulnerableCode instance to determine vulnerabilities in dependencies.
Description
An AdviceProvider implementation that obtains security vulnerability information from a
VulnerableCode instance.
For the list of data sources see here.
Configuration
Example
Use the following syntax to configure this plugin globally as part of config.yml:
ort:
advisor:
advisors:
VulnerableCode:
options:
serverUrl: "https://public.vulnerablecode.io/api/"
readTimeout: <OPTIONAL_LONG>
apiVersion: V3
secrets:
apiKey: <OPTIONAL_SECRET>
Options
serverUrl
The base URL of the VulnerableCode REST API. By default, the public VulnerableCode instance is used. The implementation will take care of normalizing the API URL to contain the "/api/" part.
apiKey
The optional API key to use.
readTimeout
The read timeout for the server connection in seconds. Defaults to whatever is the HTTP client's default value.
apiVersion
Possible values:
V1, V3
The VulnerableCode API version to use.