Skip to content

Could not connect to Central search #5291

@MokhFn

Description

@MokhFn

Describe the bug
When using the latest version of DependencyCheck, i face an error :
[ERROR] Could not connect to Central search. Analysis failed. And the analysis keeps on trying for 7 attempts, then halts the process.

Version of dependency-check used
The problem occurs using the latest version.

Log file

Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.


   About ODC: https://jeremylong.github.io/DependencyCheck/general/internals.html
   False Positives: https://jeremylong.github.io/DependencyCheck/general/suppression.html

💖 Sponsor: https://github.com/sponsors/jeremylong


[INFO] Analysis Started
[INFO] Finished Archive Analyzer (7 seconds)
[INFO] Finished File Name Analyzer (0 seconds)
[INFO] Finished Jar Analyzer (3 seconds)
[ERROR] Could not connect to Central search. Analysis failed.
java.io.IOException: Finally failed connecting to Central search. Giving up after 7 tries.
	at org.owasp.dependencycheck.analyzer.CentralAnalyzer.fetchMavenArtifacts(CentralAnalyzer.java:364)
	at org.owasp.dependencycheck.analyzer.CentralAnalyzer.analyzeDependency(CentralAnalyzer.java:229)
	at org.owasp.dependencycheck.analyzer.AbstractAnalyzer.analyze(AbstractAnalyzer.java:131)
	at org.owasp.dependencycheck.AnalysisTask.call(AnalysisTask.java:88)
	at org.owasp.dependencycheck.AnalysisTask.call(AnalysisTask.java:37)
	at java.base/java.util.concurrent.FutureTask.run(FutureTask.java:264)
	at java.base/java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1128)
	at java.base/java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:628)
	at java.base/java.lang.Thread.run(Thread.java:829)
Caused by: java.io.IOException: Could not connect to MavenCentral (502): Bad Gateway
	at org.owasp.dependencycheck.data.central.CentralSearch.searchSha1(CentralSearch.java:231)
	at org.owasp.dependencycheck.analyzer.CentralAnalyzer.fetchMavenArtifacts(CentralAnalyzer.java:341)
	... 8 common frames omitted
[WARN] An error occurred while analyzing 'path/to/private/repo' (Central Analyzer).
[ERROR] Could not connect to Central search. Analysis failed.
java.io.IOException: Finally failed connecting to Central search. Giving up after 7 tries.
	at org.owasp.dependencycheck.analyzer.CentralAnalyzer.fetchMavenArtifacts(CentralAnalyzer.java:364)
	at org.owasp.dependencycheck.analyzer.CentralAnalyzer.analyzeDependency(CentralAnalyzer.java:229)
	at org.owasp.dependencycheck.analyzer.AbstractAnalyzer.analyze(AbstractAnalyzer.java:131)
	at org.owasp.dependencycheck.AnalysisTask.call(AnalysisTask.java:88)
	at org.owasp.dependencycheck.AnalysisTask.call(AnalysisTask.java:37)
	at java.base/java.util.concurrent.FutureTask.run(FutureTask.java:264)
	at java.base/java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1128)
	at java.base/java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:628)
	at java.base/java.lang.Thread.run(Thread.java:829)
Caused by: java.io.IOException: Could not connect to MavenCentral (504): Gateway Time-out
	at org.owasp.dependencycheck.data.central.CentralSearch.searchSha1(CentralSearch.java:231)
	at org.owasp.dependencycheck.analyzer.CentralAnalyzer.fetchMavenArtifacts(CentralAnalyzer.java:341)
	... 8 common frames omitted
[WARN] An error occurred while analyzing 'path/to/private/repo' (Central Analyzer).
[ERROR] Could not connect to Central search. Analysis failed.
java.io.IOException: Finally failed connecting to Central search. Giving up after 7 tries.
	at org.owasp.dependencycheck.analyzer.CentralAnalyzer.fetchMavenArtifacts(CentralAnalyzer.java:364)
	at org.owasp.dependencycheck.analyzer.CentralAnalyzer.analyzeDependency(CentralAnalyzer.java:229)
	at org.owasp.dependencycheck.analyzer.AbstractAnalyzer.analyze(AbstractAnalyzer.java:131)
	at org.owasp.dependencycheck.AnalysisTask.call(AnalysisTask.java:88)
	at org.owasp.dependencycheck.AnalysisTask.call(AnalysisTask.java:37)
	at java.base/java.util.concurrent.FutureTask.run(FutureTask.java:264)
	at java.base/java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1128)
	at java.base/java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:628)
	at java.base/java.lang.Thread.run(Thread.java:829)
Caused by: java.io.IOException: Could not connect to MavenCentral (504): Gateway Time-out
	at org.owasp.dependencycheck.data.central.CentralSearch.searchSha1(CentralSearch.java:231)
	at org.owasp.dependencycheck.analyzer.CentralAnalyzer.fetchMavenArtifacts(CentralAnalyzer.java:341)
	... 8 common frames omitted
[WARN] An error occurred while analyzing '/home/vsts/work/1/.m2/repository/org/scala-sbt/compiler-bridge_2.11/1.7.1/compiler-bridge_2.11-1.7.1-sources.jar' (Central Analyzer).
[INFO] Finished Central Analyzer (1144 seconds)
[INFO] Finished Assembly Analyzer (2 seconds)
[INFO] Finished PE Analyzer (0 seconds)
[INFO] Finished Dependency Merging Analyzer (0 seconds)
[INFO] Finished Version Filter Analyzer (0 seconds)
[INFO] Finished Hint Analyzer (0 seconds)
[INFO] Created CPE Index (1 seconds)
[INFO] Finished NPM CPE Analyzer (1 seconds)
[INFO] Created CPE Index (1 seconds)
[INFO] Finished CPE Analyzer (9 seconds)
[INFO] Finished False Positive Analyzer (0 seconds)
[INFO] Finished NVD CVE Analyzer (0 seconds)
[INFO] Finished RetireJS Analyzer (3 seconds)
[INFO] Finished Sonatype OSS Index Analyzer (7 seconds)
[INFO] Finished Vulnerability Suppression Analyzer (0 seconds)
[INFO] Finished Dependency Bundling Analyzer (0 seconds)
[INFO] Finished Unused Suppression Rule Analyzer (0 seconds)
[INFO] Analysis Complete (1181 seconds)
[INFO] Writing report to: /home/vsts/work/1/s/dependency-check/dependency-check-report.xml
[INFO] Writing report to: /home/vsts/work/1/s/dependency-check/dependency-check-report.html
[INFO] Writing report to: /home/vsts/work/1/s/dependency-check/dependency-check-report.json
[INFO] Writing report to: /home/vsts/work/1/s/dependency-check/dependency-check-report.csv
[INFO] Writing report to: /home/vsts/work/1/s/dependency-check/dependency-check-report.sarif
[INFO] Writing report to: /home/vsts/work/1/s/dependency-check/dependency-check-jenkins.html
[INFO] Writing report to: /home/vsts/work/1/s/dependency-check/dependency-check-junit.xml
[ERROR] Could not connect to Central search. Analysis failed.
[ERROR] Could not connect to Central search. Analysis failed.
[ERROR] Could not connect to Central search. Analysis failed.

Dependency Check completed with exit code 242.
Dependency Check reports:
[ '/home/vsts/work/1/s/dependency-check/dependency-check-jenkins.html',
  '/home/vsts/work/1/s/dependency-check/dependency-check-junit.xml',
  '/home/vsts/work/1/s/dependency-check/dependency-check-report.csv',
  '/home/vsts/work/1/s/dependency-check/dependency-check-report.html',
  '/home/vsts/work/1/s/dependency-check/dependency-check-report.json',
  '/home/vsts/work/1/s/dependency-check/dependency-check-report.sarif',
  '/home/vsts/work/1/s/dependency-check/dependency-check-report.xml' ]
Dependency Check failed with message "Dependency Check exited with an error code (exit code: 242)."
##[error]Dependency Check exited with an error code (exit code: 242).
Ending Dependency Check...

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions