Skip to content

feat: allow downloader TLS configuration via Java system properties - #8825

Open
chadlwilson wants to merge 2 commits into
dependency-check:mainfrom
chadlwilson:patch-1
Open

chadlwilson wants to merge 2 commits into
dependency-check:mainfrom
chadlwilson:patch-1

Conversation

@chadlwilson

Copy link
Copy Markdown
Collaborator

Description of Change

Extends use of standard Java system properties to the TLs configuration behind pooled connections, not solely proxy or http client-level settings settings, etc.

Related issues

Have test cases been added to cover the new functionality?

no - standard Apache Client functionality.

@boring-cyborg boring-cyborg Bot added the utils changes to utils label Oct 1, 2026
@chadlwilson
chadlwilson requested a lite review from Copilot October 1, 2026 12:21

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

A missing semicolon prevents Downloader.java from compiling.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Updates Downloader so pooled HTTP connections honor Java TLS system properties, including mTLS configuration.

Changes:

  • Enables system properties on the pooled connection manager.
  • Shares the configured manager with HTTP clients.
  • Compilation is blocked by a missing semicolon after build().
File Description
utils/​src/​main/​java/​org/​owasp/​dependencycheck/​utils/​Downloader.java Configures pooled connections from Java system properties.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread utils/src/main/java/org/owasp/dependencycheck/utils/Downloader.java Outdated

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

No unresolved blocking issues were identified.

Review effort: Lite
Findings: None

Resolved since last review (1)

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

utils changes to utils

Projects

None yet

Development

Successfully merging this pull request may close these issues.

mTLS support for nvdDataFeed, retireJsUrl, kevURL

2 participants