dependency-check / dependency-check-gradle

The dependency-check gradle plugin is a Software Composition Analysis (SCA) tool that allows projects to monitor dependent libraries for known, published vulnerabilities.

Home Page:http://jeremylong.github.io/DependencyCheck/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Kotlin 2.0 and test groups problem

BrunoJAzevedo opened this issue · comments

Hello,

I'm using this plugin for the first time on an Android App and I noticed something

When using Kotlin version 2.0 and skipTestGroups=false I have the following error:

Cannot change dependencies of dependency configuration ':debugAndroidTestCompileClasspath' after it has been included in dependency resolution. Use 'defaultDependencies' instead of 'beforeResolve' to specify default dependencies for a configuration.

I've been able to "fix" this either changing Kotlin version to 1.9.24 or still use Kotlin 2.0 but skipping the test groups skipTestGroups=true

Currently I'm using version 9.2.0 of the dependency check.

Is there something that I should be doing different on how to use Kotlin 2.0 and not skipping the tests groups?

Thank you in advance!

Hi @jeremylong !

We also face issues with Gradle 8.5 / Kotlin 2.0.0 that can be "fixed" by downgrading to 1.9.24.

In our case we get false positives for quite old CVEs or CVEs that don't affect us.
Are there any known limitations / bugs using dependency-check with Kotlin 2.0.0?

Thanks!