Find the Best Cosmetic Hospitals

Explore trusted cosmetic hospitals and make a confident choice for your transformation.

“Invest in yourself — your confidence is always worth it.”

Explore Cosmetic Hospitals

Start your journey today — compare options in one place.

OWASP Dependency-Check — 1-Hour Quick Demo Lab

Level: Beginner / Basic DevSecOps
Duration: 60 minutes
Format: Instructor-led hands-on demo
Focus: Install → scan a real project → read findings → understand CVE/CVSS → generate reports → demonstrate a simple security gate


Lab Version

Tutorial verified for: October 2026
OWASP Dependency-Check: 13.0.0
Recommended Java runtime: Java 17 LTS
Minimum Java runtime: Java 11
Sample project: OWASP NodeGoat
Pinned sample commit: 9336e34
Primary report format: HTML
Code language: CSS (css)

Important for a 1-hour class: Dependency-Check must download vulnerability data before it can perform useful analysis. The first update can take significant time. The instructor should pre-populate the Dependency-Check data directory before the session, or provide students with a prepared lab VM/environment.


1. Learning Objectives

By the end of this 60-minute lab, students should be able to:

  • Explain what OWASP Dependency-Check does.
  • Explain why Software Composition Analysis (SCA) matters.
  • Verify a Dependency-Check installation.
  • Scan a real GitHub project.
  • Generate an HTML vulnerability report.
  • Identify the affected dependency, CVE, severity, and CVSS score.
  • Understand why a detected vulnerability still needs investigation.
  • Generate a machine-readable report.
  • Demonstrate a simple CVSS-based security gate.
  • Explain where Dependency-Check fits into CI/CD.

2. 60-Minute Agenda

TimeActivity
0–5 minSCA and Dependency-Check overview
5–12 minEnvironment and installation verification
12–18 minClone the real sample application
18–32 minRun the first Dependency-Check scan
32–43 minRead the HTML report
43–50 minCVE, CVSS, severity, evidence, and false positives
50–55 minJSON report + simple security gate
55–60 minCI/CD placement, validation, recap

3. What Is OWASP Dependency-Check?

OWASP Dependency-Check is a Software Composition Analysis tool that identifies publicly disclosed vulnerabilities in third-party software components used by an application.

A simplified workflow is:

Application source code
        ↓
Dependency manifests / packages
        ↓
OWASP Dependency-Check
        ↓
Component identification
        ↓
Known vulnerability matching
        ↓
CVE / CVSS information
        ↓
HTML / JSON / XML / SARIF reports
Code language: JavaScript (javascript)

Dependency-Check helps answer questions such as:

What third-party components are we using?
        ↓
Are known vulnerabilities associated with those components?
        ↓
How severe are the findings?
        ↓
Do the findings actually apply to our application?
        ↓
Should we upgrade, mitigate, suppress, or investigate further?
Code language: JavaScript (javascript)

Key lesson: A Dependency-Check finding is a security signal that requires analysis. It is not automatic proof that the application is exploitable.


4. Prerequisites

Student workstation

Recommended environment:

Ubuntu 22.04/24.04+ or current macOS
Java 17
Git
unzip
Internet access
OWASP Dependency-Check 13.0.0

Recommended resources:

CPU: 2+ cores
RAM: 4 GB minimum, 8 GB recommended
Disk: 3+ GB free for the lab and vulnerability data
Code language: HTTP (http)

Verify Java

java -version

Example:

openjdk version "17.x.x"
Code language: CSS (css)

Verify Git

git --version

Example:

git version 2.x.x
Code language: CSS (css)

5. Install Dependency-Check

If the instructor has already prepared Dependency-Check, students can skip directly to Installation Verification.

Linux/macOS — CLI distribution

Create a lab tools directory:

mkdir -p ~/odc-lab
cd ~/odc-lab

Download the 13.0.0 CLI distribution:

curl -LO https://github.com/dependency-check/DependencyCheck/releases/download/v13.0.0/dependency-check-13.0.0-release.zip
Code language: JavaScript (javascript)

Extract it:

unzip dependency-check-13.0.0-release.zip
Code language: CSS (css)

The executable is located under:

dependency-check/bin/

Installation Verification

Run:

./dependency-check/bin/dependency-check.sh --version

Expected result:

Dependency-Check Core version 13.0.0
Code language: CSS (css)

On Windows, use dependency-check.bat instead of dependency-check.sh.


6. Instructor Preparation — Do This Before Class

A first-time vulnerability database update can consume much of a 60-minute lab. Pre-populate the data directory.

Create a reusable data directory:

mkdir -p ~/odc-lab/odc-data
Code language: JavaScript (javascript)

If an NVD API key is available:

export NVD_API_KEY="YOUR_NVD_API_KEY"
Code language: JavaScript (javascript)

Populate/update Dependency-Check data:

~/odc-lab/dependency-check/bin/dependency-check.sh \
  --updateonly \
  --data ~/odc-lab/odc-data \
  --nvdApiKey "$NVD_API_KEY"
Code language: JavaScript (javascript)

If no API key is available, the instructor can perform the update without --nvdApiKey, but updates can be considerably slower and are more likely to encounter rate limiting.

For the live class, reuse the same data directory:

~/odc-lab/odc-data
Code language: JavaScript (javascript)

7. Clone the Real Sample Application

For this quick demo we use OWASP NodeGoat, a deliberately vulnerable application maintained for security training.

Step 1 — Clone NodeGoat

cd ~/odc-lab
git clone https://github.com/OWASP/NodeGoat.git
cd NodeGoat
Code language: PHP (php)

Step 2 — Pin the lab revision

git checkout 9336e34

Expected output is similar to:

HEAD is now at 9336e34 ...

Step 3 — Confirm dependency files

ls package.json package-lock.json
Code language: CSS (css)

Expected:

package-lock.json
package.json
Code language: CSS (css)

Why pin the commit?

Using an immutable Git commit keeps the training project stable even if the NodeGoat default branch changes later.


8. Understand the Project Before Scanning

Inspect the beginning of the dependency manifest:

head -40 package.json
Code language: CSS (css)

Optional quick dependency search:

grep -n 'marked' package.json package-lock.json | head
Code language: JavaScript (javascript)

The pinned training revision contains intentionally old dependencies. This gives Dependency-Check useful material to analyze.

We are not trying to run NodeGoat in this lab. The goal is to analyze its third-party dependencies.


9. Run the First Dependency-Check Scan

Create a report directory:

mkdir -p ~/odc-lab/reports
Code language: JavaScript (javascript)

From the NodeGoat directory, run:

~/odc-lab/dependency-check/bin/dependency-check.sh \
  --project "OWASP NodeGoat Quick Lab" \
  --scan . \
  --data ~/odc-lab/odc-data \
  --format HTML \
  --out ~/odc-lab/reports
Code language: JavaScript (javascript)

If the environment is not pre-populated and an NVD API key is available, add:

--nvdApiKey "$NVD_API_KEY"
Code language: JavaScript (javascript)

What Dependency-Check is doing

During the scan it broadly performs this sequence:

Read application files
        ↓
Identify dependencies
        ↓
Collect evidence about components
        ↓
Match components to vulnerability intelligence
        ↓
Associate possible CVEs
        ↓
Generate the report

Expected completion

The output should eventually indicate that analysis completed and that a report was written.

Do not expect an identical number of vulnerabilities every time. Vulnerability intelligence can change independently of the pinned application source code.


10. Locate the HTML Report

List the output directory:

ls -lh ~/odc-lab/reports
Code language: JavaScript (javascript)

You should see:

dependency-check-report.html
Code language: CSS (css)

Open the report

macOS

open ~/odc-lab/reports/dependency-check-report.html
Code language: JavaScript (javascript)

Linux desktop

xdg-open ~/odc-lab/reports/dependency-check-report.html
Code language: JavaScript (javascript)

If a graphical browser is not available, copy the report to a workstation with a browser.


11. Read the HTML Report

Spend several minutes examining one vulnerable dependency.

For one finding, identify these fields:

Dependency / component
        ↓
Detected version
        ↓
Evidence / identifiers
        ↓
CVE
        ↓
Severity
        ↓
CVSS score
        ↓
Vulnerability description
        ↓
References
        ↓
Affected-version information

What the fields mean

FieldMeaning
DependencyThe library or component being analyzed
VersionVersion Dependency-Check identified
CVEPublic vulnerability identifier
CVSSNumerical severity score supplied by the vulnerability source
SeverityHuman-readable severity classification
EvidenceInformation used to identify the component
CPE / identifiersComponent identity information used during matching where applicable
DescriptionSummary of the vulnerability
ReferencesVendor, advisory, NVD, patch, or other supporting links

12. CVE and CVSS — 5-Minute Explanation

CVE

CVE means Common Vulnerabilities and Exposures.

Example pattern:

CVE-YYYY-NNNNN

A CVE identifies a publicly disclosed vulnerability. It does not by itself tell you whether your application is exploitable.

CVSS

CVSS means Common Vulnerability Scoring System.

Typical interpretation:

CVSS scoreCommon severity label
0.0None
0.1–3.9Low
4.0–6.9Medium
7.0–8.9High
9.0–10.0Critical

The score helps prioritize investigation, but it must be combined with application context.


13. Detection Is Not the Same as Confirmation

Teach students this workflow:

Dependency-Check finding
        ↓
Is the dependency really present?
        ↓
Is the detected version correct?
        ↓
Does the CVE apply to that version?
        ↓
Does our application use the vulnerable functionality?
        ↓
Is the component reachable/exploitable in our deployment?
        ↓
Upgrade / mitigate / investigate / suppress with justification
Code language: JavaScript (javascript)

Useful terms

Detected vulnerability

Dependency-Check found a relationship between a component and vulnerability intelligence.

Confirmed vulnerability

Engineering/security analysis confirms that the vulnerable component/version and relevant conditions apply.

False positive

The tool associated a vulnerability with the dependency incorrectly or the identification is not applicable.

Needs investigation

The tool has provided enough evidence to justify review, but the team has not yet confirmed applicability or exploitability.

Never teach teams to suppress a finding simply because they do not want the pipeline to fail.


14. Generate a JSON Report

Machine-readable output is useful for CI/CD and security tooling.

Run:

~/odc-lab/dependency-check/bin/dependency-check.sh \
  --project "OWASP NodeGoat Quick Lab" \
  --scan . \
  --data ~/odc-lab/odc-data \
  --format JSON \
  --out ~/odc-lab/reports
Code language: JavaScript (javascript)

Check the directory:

ls -lh ~/odc-lab/reports
Code language: JavaScript (javascript)

You should now see a JSON report in addition to the HTML report.

Typical uses:

HTML  → Human review
JSON  → Automation / parsing / CI tools
XML   → Integrations
SARIF → Security/code-scanning platforms that consume SARIF
Code language: JavaScript (javascript)

15. Quick Security-Gate Demo

Dependency-Check can return a failing exit status when findings meet or exceed a configured CVSS threshold.

For a demonstration threshold of 7.0:

~/odc-lab/dependency-check/bin/dependency-check.sh \
  --project "OWASP NodeGoat Gate Demo" \
  --scan . \
  --data ~/odc-lab/odc-data \
  --format HTML \
  --out ~/odc-lab/reports \
  --failOnCVSS 7
Code language: JavaScript (javascript)

Immediately inspect the shell exit code:

echo $?
Code language: PHP (php)

Conceptually:

Scan
 ↓
Find vulnerabilities
 ↓
Evaluate CVSS scores
 ↓
Compare with threshold
 ↓
Return pass/fail status
Code language: JavaScript (javascript)

Important distinction

Report generation ≠ vulnerability remediation

Security gate ≠ vulnerability proof

Build failure ≠ application compromise

A production threshold should be set by an organization’s risk policy, not copied blindly from this training example.


16. Where Dependency-Check Fits in CI/CD

A simple pipeline placement is:

Developer
   ↓
Git push / Pull request
   ↓
CI pipeline
   ↓
Restore/install dependencies
   ↓
OWASP Dependency-Check
   ↓
Publish security report
   ↓
Security gate
   ↓
Build / Test / Deploy

Typical automation pattern:

1. Cache or centrally maintain Dependency-Check vulnerability data.
2. Scan the application during CI.
3. Save HTML/JSON/SARIF as artifacts.
4. Apply an agreed policy threshold.
5. Investigate findings.
6. Upgrade or mitigate vulnerable components.
7. Use documented suppressions only for justified false positives/not-applicable findings.
Code language: JavaScript (javascript)

17. Essential CLI Options for This Lab

OptionPurpose
--projectSets the project name shown in the report
--scanSpecifies the file/directory to analyze
--outSpecifies where reports are written
--formatSelects report format
--dataSpecifies the Dependency-Check local data directory
--nvdApiKeySupplies an NVD API key for vulnerability-data updates
--updateonlyUpdates Dependency-Check data without running a project scan
--failOnCVSSReturns a failing status when the threshold is met/exceeded
--versionDisplays the installed Dependency-Check version

For a quick lab, students do not need the full CLI option catalogue.


18. Three Student Tasks

Task 1 — Verify and Scan

Run:

~/odc-lab/dependency-check/bin/dependency-check.sh --version
Code language: JavaScript (javascript)

Then complete an HTML scan of NodeGoat.

Validation

Student can show:

Dependency-Check 13.0.0
and
dependency-check-report.html
Code language: CSS (css)

Task 2 — Investigate One Finding

Choose one dependency from the HTML report and record:

Dependency:
Version:
CVE:
CVSS:
Severity:
What evidence identified the component?
What should be investigated before calling it exploitable?

Validation

Student can explain why:

"CVE detected" does not automatically mean "application exploitable."
Code language: JavaScript (javascript)

Task 3 — Demonstrate a Gate

Run the scan with:

--failOnCVSS 7

Then inspect:

echo $?
Code language: PHP (php)

Validation

Student can explain that the exit status can be consumed by a CI system as a security gate.


19. Quick Troubleshooting

Problem — Java command not found

Cause: Java is not installed or is not on PATH.

Check:

java -version

Solution: Install a supported Java runtime. Java 17 is recommended for this lab.


Problem — dependency-check.sh permission denied

Check permissions:

ls -l ~/odc-lab/dependency-check/bin/dependency-check.sh
Code language: JavaScript (javascript)

If required:

chmod +x ~/odc-lab/dependency-check/bin/dependency-check.sh
Code language: JavaScript (javascript)

Verify:

~/odc-lab/dependency-check/bin/dependency-check.sh --version
Code language: JavaScript (javascript)

Problem — First scan is extremely slow

Likely cause: Vulnerability data is being downloaded for the first time.

Best lab solution: Pre-populate and reuse the --data directory before class.


Problem — NVD update errors or rate limiting

Likely causes:

  • No NVD API key.
  • API rate limiting.
  • Proxy/firewall restrictions.
  • Temporary network issues.

Lab solution: Use the instructor-prepared Dependency-Check data directory rather than spending class time rebuilding it.


Problem — No report appears

Confirm the requested output directory:

ls -lah ~/odc-lab/reports
Code language: JavaScript (javascript)

Then confirm the scan path exists:

pwd
ls package.json package-lock.json
Code language: CSS (css)

Problem — Many findings appear

That can be expected for a deliberately vulnerable training application.

Do not try to fix every finding during the 1-hour demo. Pick one finding and teach the investigation process.


20. Lab Validation Checklist

At the end of the session, students should be able to check:

[ ] Java works
[ ] Git works
[ ] Dependency-Check 13.0.0 is available
[ ] NodeGoat is cloned
[ ] Commit 9336e34 is checked out
[ ] Dependency-Check data is available
[ ] HTML scan completed
[ ] HTML report opened
[ ] One dependency was investigated
[ ] One CVE was identified
[ ] CVSS/severity were interpreted
[ ] JSON output was demonstrated
[ ] failOnCVSS security gate was demonstrated
[ ] CI/CD placement is understood
Code language: JavaScript (javascript)

21. Five-Minute Knowledge Check

1. What problem does Dependency-Check help solve?

Answer: It helps identify known vulnerabilities associated with third-party software components used by an application.

2. Does a reported CVE automatically prove the application is exploitable?

Answer: No. The finding must be validated in the context of the actual dependency, version, use, and deployment.

3. Why can the first Dependency-Check run take much longer?

Answer: Dependency-Check may need to download and build/update its local vulnerability data.

4. Which report is easiest for a person to review?

Answer: HTML.

5. Why generate JSON or SARIF?

Answer: They are machine-readable formats suitable for automation and security/tool integrations.

6. What does --failOnCVSS 7 demonstrate?

Answer: A CI/security gate that returns a failing status when a finding reaches the configured CVSS threshold.

7. Should suppression be used to make an uncomfortable finding disappear?

Answer: No. Suppression should be documented and justified for false positives or findings determined not to apply.


22. Key Takeaways

1. Dependency-Check is an SCA tool.

2. It analyzes application dependencies and matches them with known vulnerability intelligence.

3. A finding is the beginning of investigation—not the end.

4. CVE identifies the vulnerability; CVSS helps communicate severity.

5. HTML is useful for people; JSON/XML/SARIF are useful for automation and integrations.

6. Dependency-Check can participate in a CI/CD security gate using failOnCVSS.

7. Pre-populating the vulnerability database is essential for a smooth 1-hour classroom demo.
Code language: JavaScript (javascript)

23. Trainer Quick-Run Commands

Use these commands for the live demo after the Dependency-Check data directory has been prepared.

<em># 1. Verify Dependency-Check</em>
~/odc-lab/dependency-check/bin/dependency-check.sh --version

<em># 2. Clone and pin NodeGoat</em>
cd ~/odc-lab
git clone https://github.com/OWASP/NodeGoat.git
cd NodeGoat
git checkout 9336e34

<em># 3. HTML scan</em>
mkdir -p ~/odc-lab/reports
~/odc-lab/dependency-check/bin/dependency-check.sh \
  --project "OWASP NodeGoat Quick Lab" \
  --scan . \
  --data ~/odc-lab/odc-data \
  --format HTML \
  --out ~/odc-lab/reports

<em># 4. Inspect output</em>
ls -lh ~/odc-lab/reports

<em># 5. JSON scan</em>
~/odc-lab/dependency-check/bin/dependency-check.sh \
  --project "OWASP NodeGoat Quick Lab" \
  --scan . \
  --data ~/odc-lab/odc-data \
  --format JSON \
  --out ~/odc-lab/reports

<em># 6. Security-gate demo</em>
~/odc-lab/dependency-check/bin/dependency-check.sh \
  --project "OWASP NodeGoat Gate Demo" \
  --scan . \
  --data ~/odc-lab/odc-data \
  --format HTML \
  --out ~/odc-lab/reports \
  --failOnCVSS 7

echo $?
Code language: HTML, XML (xml)

24. Trainer Notes

For a successful one-hour delivery:

  • Prepare the Dependency-Check vulnerability data before students arrive.
  • Do not spend classroom time troubleshooting NVD downloads unless update troubleshooting is the lesson.
  • Demonstrate only one or two findings in depth.
  • Emphasize evidence and investigation rather than vulnerability counts.
  • Avoid turning the session into a complete SCA governance course.
  • Use the CVSS threshold only to explain how a gate works; do not present 7.0 as a universal production policy.
  • End by showing where the scan would run in CI/CD rather than configuring a full pipeline during the hour.

25. Official References

Use these source categories when expanding the lab:

  • OWASP Dependency-Check documentation
  • Dependency-Check official GitHub repository and releases
  • NVD API documentation
  • OWASP NodeGoat repository
  • Official CI platform documentation when implementing pipeline integration

For instructor-led delivery, verify the Dependency-Check release and upstream documentation again before reusing this lab in a future semester or training cycle.

Find Trusted Cardiac Hospitals

Compare heart hospitals by city and services — all in one place.

Explore Hospitals
I'm Rajesh Kumar, a DevOps, SRE, DevSecOps, Cloud, and Platform Engineering expert passionate about sharing practical knowledge, real-world experiences, and industry best practices. I have worked at Cotocus and regularly write about technology, travel, investing, health, product reviews, and digital marketing through my various platforms. I publish technical articles at DevOps School, travel stories at Holiday Landmark, stock market insights at Stocks Mantra, health and fitness guidance at My Medic Plus, product reviews at TrueReviewNow, and SEO and digital marketing strategies at Wizbrand.

Related Posts

OWASP Dependency-Check – Hands-On Lab Manual

OWASP Dependency-Check 13.0.0 Basic-to-Essentials Hands-On Lab Manual Audience: Beginners and engineers with basic DevOps/DevSecOps knowledgeTutorial verified/researched on: 2026-10-03OWASP Dependency-Check version: 13.0.0Minimum Java supported by Dependency-Check: Java 11Recommended lab Java runtime: Java 17…

Read More

Manufacturing automation: Is it worth investing in the field of manufacturing automation?

An investment in manufacturing automation can pay off. (Photo: Generated with the help of AI) Manufacturing automation has developed from a solution mainly associated with large factories…

Read More

How to Choose a Virtual Machine for Development and Production Workloads

Virtual machines remain a practical building block for development, testing, staging, production services, and infrastructure automation. The challenge is not simply choosing the largest instance available. It…

Read More

System Mechanic vs Advanced SystemCare for Small Teams Without an MDM

If you’re keeping a handful of Windows workstations or test machines healthy without a device-management platform, iolo’s System Mechanic is the better choice over IObit’s Advanced SystemCare…

Read More

How to Plan Infrastructure for a Community Project

Every thriving community project sits on top of infrastructure nobody notices, right up until it breaks. The forum. The server. The backups. The dull plumbing that holds…

Read More

Cloud vs Bare Metal Servers: Which Is Better for Modern Businesses?

There is always polarizing discourse in the cloud vs bare-metal server debate. Sometimes, bandwidth alone costs more than an entire fleet of servers. Is the price for…

Read More
Subscribe
Notify of
guest
0 Comments
Newest
Oldest Most Voted
0
Would love your thoughts, please comment.x
()
x