<?xml version="1.0" encoding="UTF-8"?>
<project xmlns="http://maven.apache.org/POM/4.0.0"
         xsi:schemaLocation="http://maven.apache.org/POM/4.0.0 http://maven.apache.org/maven-v4_0_0.xsd">
  <description>Open source platform for continuous inspection of code quality</description>




    <!-- see http://repo1.maven.org/maven2/org/sonarsource/dotnet/sonar-csharp-plugin/ -->
    <!-- Do not forget to exclude any new transitive dependencies -->
    <!-- see http://repo1.maven.org/maven2/org/sonarsource/java/sonar-java-plugin/ -->
    <!-- Do not forget to exclude any new transitive dependencies -->
    <!-- see http://repo1.maven.org/maven2/org/sonarsource/javascript/sonar-javascript-plugin/ -->
    <!-- Do not forget to exclude any new transitive dependencies -->
    <!-- see http://repo1.maven.org/maven2/org/sonarsource/php/sonar-php-plugin/ -->
    <!-- Do not forget to exclude any new transitive dependencies -->
    <!-- see http://repo1.maven.org/maven2/org/sonarsource/python/sonar-python-plugin/ -->
    <!-- Do not forget to exclude any new transitive dependencies -->
    <!-- see http://repo1.maven.org/maven2/org/sonarsource/flex/sonar-flex-plugin/ -->
    <!-- Do not forget to exclude any new transitive dependencies -->
    <!-- see http://repo1.maven.org/maven2/org/sonarsource/xml/sonar-xml-plugin/ -->
    <!-- Do not forget to exclude any new transitive dependencies -->
    <!-- see https://repo1.maven.org/maven2/org/sonarsource/typescript/sonar-typescript-plugin/ -->
    <!-- see http://repo1.maven.org/maven2/org/sonarsource/scm/git/sonar-scm-git-plugin/ -->
    <!-- see http://repo1.maven.org/maven2/org/sonarsource/scm/svn/sonar-scm-svn-plugin/ -->

    <!-- Be aware that Log4j is used by Elasticsearch client -->




    <argLine>-Xmx512m -Djava.awt.headless=true</argLine>

    <!-- used for deployment to SonarSource Artifactory -->
    <!-- Release: enable publication to Bintray -->


      <!-- Plugins ordered by shortname (assembly, antrun ...) -->
              <!-- Workaround for http://jira.codehaus.org/browse/MASSEMBLY-422 -->
              <!-- 420(dec) = 644(oct) -->
              <!-- 493(dec) = 755(oct) -->
          <!-- not thread safe -->
          Detection of conflicts in classpath.
          Command line is: mvn org.basepom.maven:duplicate-finder-maven-plugin:check
          See https://github.com/basepom/duplicate-finder-maven-plugin

                  <message>Build reproducibility : always define plugin versions</message>
                  <message>No SNAPSHOT versions allowed for dependencies</message>
                  <message>To build this project JDK ${jdk.min.version} (or upper) is required. Please install it.
                  <!-- See SONAR-2512 -->
                  <message>commons-beanutils:commons-beanutils should be used instead</message>
                  <message>Definition of new repositories is not allowed in order to deploy to central repository.
      Choosing a random timezone when executing tests allows to detect
      early the tests that are coupled with local environment.
                String[] timezones = new String[] {"GMT-9", "UTC", "GMT+9"};
                String testTimezone = timezones[new java.util.Random().nextInt(timezones.length)];
                project.getProperties().setProperty("testTimezone", testTimezone);
                logger.info("Timezone used for tests: " + testTimezone);
            <!-- keep system temp directory clean -->
            See profile 'randomize-environment'

      <!-- SonarQube modules -->
            Provided at runtime by sonar-plugin-api.
            Do not use transitive version 4.1 but the current version.
          no need for transitive dependencies as only the JAR file
          is needed for the zip bundle
          no need for transitive dependencies as only the JAR file
          is needed for the zip bundle
          no need for transitive dependencies as only the JAR file
          is needed for the zip bundle
          no need for transitive dependencies as only the JAR file
          is needed for the zip bundle
          no need for transitive dependencies as only the JAR file
          is needed for the zip bundle
          no need for transitive dependencies as only the JAR file
          is needed for the zip bundle
          no need for transitive dependencies as only the JAR file
          is needed for the zip bundle
          no need for transitive dependencies as only the JAR file
          is needed for the zip bundle
        <!-- animal-sniffer doesn't work with 2.6.1 -->
             This version is compatible with Oracle 11g and 12c :
            <!-- provided by Java 1.7 -->
          <!-- see SONAR-879 -->
          <!--  removing commons lang 2.1 and xerces-->

      <!-- tomcat -->

      <!-- Using scope=provided to exclude from all transitive dependencies -->


      <name>SonarQube users mailing list</name>



      <name>GNU LGPL 3</name>

  <!-- Developers information should not be removed as it's
  required for deployment -->

      <name>Fabrice Bellingard</name>
      <name>Dinesh Bolkensteyn</name>
      <name>David Gageot</name>
      <name>Eric Hartmann</name>
      <name>Freddy Mallet</name>
      <name>Evgeny Mandrikov</name>
      <name>Julien Henry</name>
      <name>Jean-Baptiste Lievremont</name>
      <name>Julien Lancelot</name>
      <name>Olivier Gaudin</name>
      <name>Simon Brandhof</name>
      <name>Sebastien Lesaint</name>
      <name>Stas Vilchik</name>
      <name>Teryk Bellahsene</name>



      check if maven dependencies have vulnerabilities listed in CVE
      Standalone command: mvn org.owasp:dependency-check-maven:check
      See http://jeremylong.github.io/DependencyCheck

      <!-- integration tests -->
