使用 SpotBugs Maven 插件
本章介绍如何将 SpotBugs 集成到 Maven 项目中。
将 spotbugs-maven-plugin 添加到你的 pom.xml 中
将 <plugin> 按如下方式添加到你的 pom.xml 中:
<plugin>
<groupId>com.github.spotbugs</groupId>
<artifactId>spotbugs-maven-plugin</artifactId>
<version>4.8.5.0</version>
<dependencies>
<!-- overwrite dependency on spotbugs if you want to specify the version of spotbugs -->
<dependency>
<groupId>com.github.spotbugs</groupId>
<artifactId>spotbugs</artifactId>
<version>4.8.5</version>
</dependency>
</dependencies>
</plugin>将 Find Security Bugs 集成到 spotbugs-maven-plugin
是否在为 SpotBugs 寻找更多的安全检测规则?我们建议你了解 Find Security Bugs,这是一个用于 Java Web 和 Android 应用安全审计的 SpotBugs 插件。它可以检测 138 种不同的漏洞类型,包括 SQL/HQL 注入、命令注入、XPath 注入以及加密方面的弱点。
要将 Find Security Bugs 集成到 SpotBugs 插件中,你可以按如下方式配置你的 pom.xml:
[...]
<build>
<plugins>
[...]
<plugin>
<groupId>com.github.spotbugs</groupId>
<artifactId>spotbugs-maven-plugin</artifactId>
<version>4.8.5.0</version>
<configuration>
<includeFilterFile>spotbugs-security-include.xml</includeFilterFile>
<excludeFilterFile>spotbugs-security-exclude.xml</excludeFilterFile>
<plugins>
<plugin>
<groupId>com.h3xstream.findsecbugs</groupId>
<artifactId>findsecbugs-plugin</artifactId>
<version>1.12.0</version>
</plugin>
</plugins>
</configuration>
</plugin>
</plugins>
</build><plugins> 选项定义了要处理的 PluginArtifact 集合。请通过添加其 groupId、artifactId、version 来指定 “Find Security Bugs”。
<includeFilterFile> 和 <excludeFilterFile> 分别用于指定包含和排除缺陷报告的过滤器文件(详见过滤器文件])。可选地,你可以通过添加如下文件,将检查范围限定在安全类别:
spotbugs-security-include.xml
<FindBugsFilter>
<Match>
<Bug category="SECURITY"/>
</Match>
</FindBugsFilter>spotbugs-security-exclude.xml
<FindBugsFilter>
</FindBugsFilter>spotbugs-maven-plugin 的目标
spotbugs goal
spotbugs goal 使用 SpotBugs 分析目标项目。详情请参阅 maven 站点中的 spotbugs goal 说明。
check goal
check goal 执行与 spotbugs goal 类似的分析,并在发现任何缺陷时使构建失败。详情请参阅 maven 站点中的 check goal 说明。
gui goal
gui goal 启动 SpotBugs 图形界面以查看分析结果。详情请参阅 maven 站点中的 gui goal 说明。
help goal
help goal 显示此 Maven 插件的用法。
评论
登录后参与评论
KnowForge