u/Agreeable-Price8343

Is OWASP Dependency-Check still worth running in CI?

Been using Dependency-Check for years. Starting to feel like it’s mostly noise now. CPE matching is still messy, false positives are common, and the suppression file becomes its own maintenance project.

Do you find it still useful? Or it became a legacy checkbox scanner?

reddit.com
u/Agreeable-Price8343 — 9 days ago