NVD API Key for eclipse-tractusx projects improving dependency check possibilities
Summary
OWASP Dependency Check takes very long without api key. Can we request an api key for the organziation or the project? https://nvd.nist.gov/general/news/API-Key-Announcement
Steps to reproduce
Open eclipse-tractusx/traceability-foss project and execute the action: https://github.com/eclipse-tractusx/traceability-foss/actions/runs/8353452321/job/22865193054
What is the current bug behavior?
The action runs sometimes longer than 2 hours.
What is the expected correct behavior?
The action runs within a normal time frame. Provide an api key to be able to have normal runs.
Relevant logs and/or screenshots
Please see logs of action: https://github.com/eclipse-tractusx/traceability-foss/actions/runs/8353452321/job/22865193054
Priority
-
Urgent -
High -
Medium -
Low
Severity
-
Blocker -
Major -
Normal -
Low
Impact
(What is the impact of this issue? Is it blocking a release? Are there any time constraints?, for example: "We have a release tomorrow") Cost of github actions