dependency-check-core is the engine and reporting tool used to identify and report if there are any known, publicly disclosed vulnerabilities in the scanned project's dependencies. The engine extracts meta-data from the dependencies and uses this to do fuzzy key-word matching against the Common Platfrom Enumeration (CPE), if any CPE identifiers are found the associated Common Vulnerability and Exposure (CVE) entries are added to the generated report.

LicenseApache 2.0
Tagsowaspdependencies
DateJun 07, 2025
Filespom (30 KB)  jar (1.0 MB)  View All
RepositoriesCentral
Ranking#18069 in MvnRepository (See Top Artifacts)
Used By26 artifacts
VulnerabilitiesVulnerabilities from dependencies:
CVE-2025-48924
CVE-2025-11226
CVE-2024-12801
View 1 more ...

Note: There is a new version for this artifact

New Version12.1.9

Scope:
Scope:
Format:
Scope:
Scope:
Scope:
Scope:
Scope:
Scope:

Compile Dependencies (42)

Category/License Group / ArtifactVersionUpdates
Logging
BSD 3-clause
com.esotericsoftware » minlog 1.3.1
JSON Lib
Apache 2.0
com.fasterxml.jackson.core » jackson-databind 2.19.03.0.2
JSON Lib
Apache 2.0
com.fasterxml.jackson.core » jackson-core 2.19.03.0.2
Annotation Lib
Apache 2.0
com.fasterxml.jackson.core » jackson-annotations 2.19.02.20
YAML
Apache 2.0
com.fasterxml.jackson.dataformat » jackson-dataformat-yaml 2.19.03.0.2
Date/Time
Apache 2.0
com.fasterxml.jackson.datatype » jackson-datatype-jsr310 2.19.03.0.0-rc2

Apache 2.0
com.fasterxml.jackson.module » jackson-module-blackbird 2.19.03.0.2

MIT
com.github.package-url » packageurl-java 1.5.0
Core Utils
Apache 2.0
com.google.guava » guava 33.4.8-jre33.5.0-jre
Embedded SQL DB
EPL 1.0MPL 2.0
com.h2database » h2 2.3.2322.4.240

Apache 2.0
com.h3xstream.retirejs » retirejs-core 3.0.4

Apache 2.0
com.hankcs » aho-corasick-double-array-trie 1.2.3
TOML
MIT
com.moandjiezana.toml » toml4j 0.7.20.7.3
JSON Lib
Apache 2.0
com.vaadin.external.google » android-json 0.0.20131108.vaadin1
I/O
Apache 2.0
commons-io » commons-io 2.19.02.21.0
Validation
Apache 2.0
commons-validator » commons-validator 1.9.01.10.0

Apache 2.0
io.github.jeremylong » open-vulnerability-clients 7.3.29.0.2
Date/Time
Apache 2.0
joda-time » joda-time 2.14.0

Apache 2.0
org.anarres.jdiagnostics » jdiagnostics 1.0.7
Cache Impl
Apache 2.0
org.apache.commons » commons-jcs3-core 3.2.1
Collections
Apache 2.0
org.apache.commons » commons-collections4 4.5.0
Compression
Apache 2.0
org.apache.commons » commons-compress 1.27.11.28.0
Core Utils
Apache 2.0
org.apache.commons » commons-lang31 vulnerability 3.17.03.20.0
String Utils
Apache 2.0
org.apache.commons » commons-text 1.13.11.14.0
JDBC Pool
Apache 2.0
org.apache.commons » commons-dbcp2 2.13.0
HTTP Clients
Apache 2.0
org.apache.httpcomponents.client5 » httpclient5 5.55.5.1
HTTP Clients
Apache 2.0
org.apache.httpcomponents.core5 » httpcore5 5.3.45.3.6
Full-Text Indexing
Apache 2.0
org.apache.lucene » lucene-core 9.12.010.3.1

Apache 2.0
org.apache.lucene » lucene-analysis-common 9.12.010.3.1

Apache 2.0
org.apache.lucene » lucene-queryparser 9.12.010.3.1
Template Engine
Apache 2.0
org.apache.velocity » velocity-engine-core 2.4.1

EPL 2.0
org.eclipse.packager » packager-rpm 0.21.0
JSON Lib
EPL 2.0
org.glassfish » jakarta.json 2.0.1
HTML Parser
MIT
org.jsoup » jsoup 1.20.11.21.2

Apache 2.0
org.owasp » dependency-check-utils 12.1.212.1.9
Semantic Versioning
MIT
org.semver4j » semver4j 5.7.06.0.0
Logging
MIT
org.slf4j » slf4j-api 1.7.362.0.17

Apache 2.0
org.sonatype.goodies » package-url-java 1.2.0

Apache 2.0
org.sonatype.ossindex » ossindex-service-client 1.8.2

Apache 2.0
org.sonatype.ossindex » ossindex-service-api 1.8.2

CPAL 1.0
org.whitesource » pecoff4j 0.0.2.1

Apache 2.0
us.springett » cpe-parser 3.0.03.0.1

Runtime Dependencies (1)

Category/License Group / ArtifactVersionUpdates

Apache 2.0
io.github.jeremylong » jcs3-slf4j 1.0.5

Licenses

LicenseURL
The Apache Software License, Version 2.0 http://www.apache.org/licenses/LICENSE-2.0.txt

Developers

NameEmailDev IdRolesOrganization
Jeremy Longjeremy.long<at>owasp.orgarchitect, developerOWASP
Steve SpringettSteve.Springett<at>owasp.orgdeveloperOWASP
Will StranathanWill.Stranathan<at>owasp.orgdeveloperOWASP
Dale Visserdvisser<at>ida.orgdeveloperInstitute for Defense Analyses