Original DevCenter security card
io.moderne.devcenter.SecurityOriginalStarter
This is the same set of recipes as the original DevCenter security card.
Recipe source
GitHub, Issue Tracker, Maven Central
This recipe is composed of more than one recipe. If you want to customize the set of recipes this is composed of, you can find and copy the GitHub source for the recipe from the link above.
This recipe is available under the Moderne Source Available License.
Definition
- Recipe List
- Yaml Recipe List
- Find secrets
- Remediate OWASP A01:2021 Broken access control
- Remediate OWASP A02:2021 Cryptographic failures
- Remediate OWASP A03:2021 Injection
- Remediate OWASP A06:2021 Vulnerable and outdated components
- Remediate OWASP A08:2021 Software and data integrity failures
- Regular Expression Denial of Service (ReDOS)
- Zip slip
- Use secure temporary file creation
- Report as security issues
---
type: specs.openrewrite.org/v1beta/recipe
name: io.moderne.devcenter.SecurityOriginalStarter
displayName: Original DevCenter security card
description: |
This is the same set of recipes as the original DevCenter security card.
recipeList:
- org.openrewrite.java.security.secrets.FindSecrets
- org.openrewrite.java.security.OwaspA01
- org.openrewrite.java.security.OwaspA02
- org.openrewrite.java.security.OwaspA03
- org.openrewrite.java.security.OwaspA06
- org.openrewrite.java.security.OwaspA08
- org.openrewrite.java.security.RegularExpressionDenialOfService
- org.openrewrite.java.security.ZipSlip
- org.openrewrite.java.security.SecureTempFileCreation
- io.moderne.devcenter.ReportAsSecurityIssues
Usage
This recipe has no required configuration options. It can be activated by adding a dependency on io.moderne.recipe:rewrite-devcenter
in your build file or by running a shell command (in which case no build changes are needed):
- Gradle
- Gradle init script
- Maven POM
- Maven Command Line
- Moderne CLI
- Add the following to your
build.gradle
file:
plugins {
id("org.openrewrite.rewrite") version("latest.release")
}
rewrite {
activeRecipe("io.moderne.devcenter.SecurityOriginalStarter")
setExportDatatables(true)
}
repositories {
mavenCentral()
}
dependencies {
rewrite("io.moderne.recipe:rewrite-devcenter:1.4.2")
}
- Run
gradle rewriteRun
to run the recipe.
- Create a file named
init.gradle
in the root of your project.
initscript {
repositories {
maven { url "https://plugins.gradle.org/m2" }
}
dependencies { classpath("org.openrewrite:plugin:7.9.0") }
}
rootProject {
plugins.apply(org.openrewrite.gradle.RewritePlugin)
dependencies {
rewrite("io.moderne.recipe:rewrite-devcenter:1.4.2")
}
rewrite {
activeRecipe("io.moderne.devcenter.SecurityOriginalStarter")
setExportDatatables(true)
}
afterEvaluate {
if (repositories.isEmpty()) {
repositories {
mavenCentral()
}
}
}
}
- Run the recipe.
gradle --init-script init.gradle rewriteRun
- Add the following to your
pom.xml
file:
<project>
<build>
<plugins>
<plugin>
<groupId>org.openrewrite.maven</groupId>
<artifactId>rewrite-maven-plugin</artifactId>
<version>6.12.0</version>
<configuration>
<exportDatatables>true</exportDatatables>
<activeRecipes>
<recipe>io.moderne.devcenter.SecurityOriginalStarter</recipe>
</activeRecipes>
</configuration>
<dependencies>
<dependency>
<groupId>io.moderne.recipe</groupId>
<artifactId>rewrite-devcenter</artifactId>
<version>1.4.2</version>
</dependency>
</dependencies>
</plugin>
</plugins>
</build>
</project>
- Run
mvn rewrite:run
to run the recipe.
You will need to have Maven installed on your machine before you can run the following command.
mvn -U org.openrewrite.maven:rewrite-maven-plugin:run -Drewrite.recipeArtifactCoordinates=io.moderne.recipe:rewrite-devcenter:RELEASE -Drewrite.activeRecipes=io.moderne.devcenter.SecurityOriginalStarter -Drewrite.exportDatatables=true
You will need to have configured the Moderne CLI on your machine before you can run the following command.
mod run . --recipe SecurityOriginalStarter
If the recipe is not available locally, then you can install it using:
mod config recipes jar install io.moderne.recipe:rewrite-devcenter:1.4.2
See how this recipe works across multiple open-source repositories
Run this recipe on OSS repos at scale with the Moderne SaaS.

The community edition of the Moderne platform enables you to easily run recipes across thousands of open-source repositories.
Please contact Moderne for more information about safely running the recipes on your own codebase in a private SaaS.
Data Tables
- SourcesFileResults
- SourcesFileErrors
- RecipeRunStats
- MethodCalls
- MavenMetadataFailures
- VulnerabilityReport
- SecurityIssues
Source files that had results
org.openrewrite.table.SourcesFileResults
Source files that were modified by the recipe run.
Column Name | Description |
---|---|
Source path before the run | The source path of the file before the run. null when a source file was created during the run. |
Source path after the run | A recipe may modify the source path. This is the path after the run. null when a source file was deleted during the run. |
Parent of the recipe that made changes | In a hierarchical recipe, the parent of the recipe that made a change. Empty if this is the root of a hierarchy or if the recipe is not hierarchical at all. |
Recipe that made changes | The specific recipe that made a change. |
Estimated time saving | An estimated effort that a developer to fix manually instead of using this recipe, in unit of seconds. |
Cycle | The recipe cycle in which the change was made. |
Source files that errored on a recipe
org.openrewrite.table.SourcesFileErrors
The details of all errors produced by a recipe run.
Column Name | Description |
---|---|
Source path | The file that failed to parse. |
Recipe that made changes | The specific recipe that made a change. |
Stack trace | The stack trace of the failure. |
Recipe performance
org.openrewrite.table.RecipeRunStats
Statistics used in analyzing the performance of recipes.
Column Name | Description |
---|---|
The recipe | The recipe whose stats are being measured both individually and cumulatively. |
Source file count | The number of source files the recipe ran over. |
Source file changed count | The number of source files which were changed in the recipe run. Includes files created, deleted, and edited. |
Cumulative scanning time (ns) | The total time spent across the scanning phase of this recipe. |
99th percentile scanning time (ns) | 99 out of 100 scans completed in this amount of time. |
Max scanning time (ns) | The max time scanning any one source file. |
Cumulative edit time (ns) | The total time spent across the editing phase of this recipe. |
99th percentile edit time (ns) | 99 out of 100 edits completed in this amount of time. |
Max edit time (ns) | The max time editing any one source file. |
Method calls
org.openrewrite.java.table.MethodCalls
The text of matching method invocations.
Column Name | Description |
---|---|
Source file | The source file that the method call occurred in. |
Method call | The text of the method call. |
Class name | The class name of the method call. |
Method name | The method name of the method call. |
Argument types | The argument types of the method call. |
Maven metadata failures
org.openrewrite.maven.table.MavenMetadataFailures
Attempts to resolve maven metadata that failed.
Column Name | Description |
---|---|
Group id | The groupId of the artifact for which the metadata download failed. |
Artifact id | The artifactId of the artifact for which the metadata download failed. |
Version | The version of the artifact for which the metadata download failed. |
Maven repository | The URL of the Maven repository that the metadata download failed on. |
Snapshots | Does the repository support snapshots. |
Releases | Does the repository support releases. |
Failure | The reason the metadata download failed. |
Vulnerability report
org.openrewrite.java.dependencies.table.VulnerabilityReport
A vulnerability report that includes detailed information about the affected artifact and the corresponding CVEs.
Column Name | Description |
---|---|
Project | The name of the project / module taking the dependency. Relevant in repositories with multiple modules. |
CVE | The CVE number. |
Group | The first part of a dependency coordinate com.google.guava:guava:VERSION . |
Artifact | The second part of a dependency coordinate com.google.guava:guava:VERSION . |
Version | The resolved version. |
Fixed in version | The minimum version that is no longer vulnerable. |
Last affected version | The last version which was vulnerable. |
Version within delta | The difference between the version in use and the fixed version is within the configured maximum version delta. The recipe attempted to upgrade the version in use to a fixed version. |
Summary | The summary of the CVE. |
Base score | The calculated base score. |
Depth | Zero for direct dependencies. |
CWEs | Common Weakness Enumeration (CWE) identifiers; semicolon separated. |
Security issues
io.moderne.devcenter.table.SecurityIssues
Security issues in the repository.
Column Name | Description |
---|---|
Ordinal | The ordinal position of this issue relative to other issues. |
Issue name | The name of the security issue. |
Contributors
Jonathan Schnéider, Jonathan Leitschuh, Jonathan Schneider, Patrick, Knut Wannheden, Sam Snyder, Tim te Beek, Bryce Tompkins, Jonathan Leitschuh, Kun Li, Kyle Scully, Scott Jungling, Simon Verhoeven