开始我搜项目哪里写了nvdcve,但没找着。
[root@sandbox eagle]# grep -rn "nvdcve" ./
然后在StackOverflow上搜到这个,发现应该找dependency-check,找到后改成了最新的版本6.0.3。
nist have renamed this file to 1.1 in their next update:
check this changelog
New file's link is:
https://nvd.nist.gov/feeds/json/cve/1.1/nvdcve-1.1-modified.meta
and This file was being used by Owasp-dependecy-check-gradle in our case, so we updated that to 6.0.1 version: https://jeremylong.github.io/DependencyCheck/dependency-check-gradle/index.html
详见:https://stackoverflow.com/questions/63949763/error-retrieving-https-nvd-nist-gov-feeds-json-cve-1-0-nvdcve-1-0-modified-met