Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.

How to read the report | Suppressing false positives | Getting Help: github issues

Project: Executable Java Parent

me.chrissw-r1:java-exe-parent:3.0.34

Scan Information (show all):

Summary

Summary of Vulnerable Dependencies (click to show all)

DependencyVulnerability IDsPackageHighest SeverityCVE CountConfidenceEvidence Count
annotations-26.0.2-1.jarpkg:maven/org.jetbrains/annotations@26.0.2-1 026
java-parent-test-3.0.34.jarpkg:maven/me.chrissw-r1/java-parent-test@3.0.34 027
jcip-annotations-1.0-1.jarpkg:maven/com.github.stephenc.jcip/jcip-annotations@1.0-1 025
jsr305-3.0.2.jarpkg:maven/com.google.code.findbugs/jsr305@3.0.2 017
lombok-1.18.42.jarpkg:maven/org.projectlombok/lombok@1.18.42 036
lombok-1.18.42.jar: mavenEcjBootstrapAgent.jar 07
proguard-annotations-7.8.2.jarpkg:maven/com.guardsquare/proguard-annotations@7.8.2 026
slf4j-api-2.0.17.jarpkg:maven/org.slf4j/slf4j-api@2.0.17 029
spotbugs-annotations-4.9.8.jarpkg:maven/com.github.spotbugs/spotbugs-annotations@4.9.8 053

Dependencies (vulnerable)

annotations-26.0.2-1.jar

Description:

A set of annotations used for code inspection support and code documentation.

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/jetbrains/annotations/26.0.2-1/annotations-26.0.2-1.jar
MD5: ef0e782af9ee48fac1156485366d7cc9
SHA1: c7ce3cdeda3d18909368dfe5977332dfad326c6d
SHA256:2037be378980d3ba9333e97955f3b2cde392aa124d04ca73ce2eee6657199297
Referenced In Projects/Scopes:
  • Executable Java Parent:provided
  • Executable Java Test:provided

annotations-26.0.2-1.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/me.chrissw-r1/java-exe-parent@3.0.34
  • pkg:maven/me.chrissw-r1/java-exe-parent-test@3.0.34

Identifiers

java-parent-test-3.0.34.jar

Description:

		Test for Java Parent
	

License:

Apache License (ASL), Version 2.0 (Apache-2.0): https://raw.githubusercontent.com/spdx/license-list-data/main/text/Apache-2.0.txt
File Path: /home/runner/work/general-parent/general-parent/target/checkout/build-parent/java-parent/java-parent-test/target/java-parent-test-3.0.34.jar
MD5: 2c2413f7b20dd1fe91ad9b0e47e4a13b
SHA1: b27cb467f009d46716cfb8dd46a4848767feeed5
SHA256:223fac0e9db71613b524ba9bc5fb193fd8af89f8c21797b59780791b6a9982a0
Referenced In Project/Scope: Executable Java Test:compile
java-parent-test-3.0.34.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/me.chrissw-r1/java-exe-parent-test@3.0.34

Identifiers

jcip-annotations-1.0-1.jar

Description:

    A clean room implementation of the JCIP Annotations based entirely on the specification provided by the javadocs.
  

License:

Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/github/stephenc/jcip/jcip-annotations/1.0-1/jcip-annotations-1.0-1.jar
MD5: d62dbfa8789378457ada685e2f614846
SHA1: ef31541dd28ae2cefdd17c7ebf352d93e9058c63
SHA256:4fccff8382aafc589962c4edb262f6aa595e34f1e11e61057d1c6a96e8fc7323
Referenced In Projects/Scopes:
  • Executable Java Parent:provided
  • Executable Java Test:provided

jcip-annotations-1.0-1.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/me.chrissw-r1/java-exe-parent-test@3.0.34
  • pkg:maven/me.chrissw-r1/java-exe-parent@3.0.34

Identifiers

jsr305-3.0.2.jar

Description:

JSR305 Annotations for Findbugs

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/google/code/findbugs/jsr305/3.0.2/jsr305-3.0.2.jar
MD5: dd83accb899363c32b07d7a1b2e4ce40
SHA1: 25ea2e8b0c338a877313bd4672d3fe056ea78f0d
SHA256:766ad2a0783f2687962c8ad74ceecc38a28b9f72a2d085ee438b7813e928d0c7
Referenced In Projects/Scopes:
  • Executable Java Parent:provided
  • Executable Java Test:provided

jsr305-3.0.2.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/com.github.spotbugs/spotbugs-annotations@4.9.8
  • pkg:maven/com.github.spotbugs/spotbugs-annotations@4.9.8

Identifiers

lombok-1.18.42.jar

Description:

Spice up your java: Automatic Resource Management, automatic generation of getters, setters, equals, hashCode and toString, and more!

License:

The MIT License: https://projectlombok.org/LICENSE
File Path: /home/runner/.m2/repository/org/projectlombok/lombok/1.18.42/lombok-1.18.42.jar
MD5: f29149836e0187fb9fd95d82dc718d36
SHA1: 8365263844ebb62398e0dc33057ba10ba472d3b8
SHA256:3488a4e9994c26596baaceebee58cad36a50e3bdaec5be72b5834d3c3b560306
Referenced In Projects/Scopes:
  • Executable Java Parent:provided
  • Executable Java Test:provided

lombok-1.18.42.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/me.chrissw-r1/java-exe-parent@3.0.34
  • pkg:maven/me.chrissw-r1/java-exe-parent-test@3.0.34

Identifiers

lombok-1.18.42.jar: mavenEcjBootstrapAgent.jar

File Path: /home/runner/.m2/repository/org/projectlombok/lombok/1.18.42/lombok-1.18.42.jar/lombok/launch/mavenEcjBootstrapAgent.jar
MD5: 885d5d6be90a5dcd4b82cdf741e3f31a
SHA1: e1f7f1779f40157fd0b984c1bc32a0cb45cae66e
SHA256:74a80a6ee84e5c6fe497dfcc46a46dbe30578525e747eb531e918ee0750c8da9
Referenced In Projects/Scopes:

  • Executable Java Parent:provided
  • Executable Java Test:provided

Identifiers

  • None

proguard-annotations-7.8.2.jar

Description:

Java annotations to configure ProGuard, the free shrinker, optimizer, obfuscator, and preverifier for Java bytecode

License:

GNU General Public License, Version 2: https://www.gnu.org/licenses/gpl-2.0.txt
File Path: /home/runner/.m2/repository/com/guardsquare/proguard-annotations/7.8.2/proguard-annotations-7.8.2.jar
MD5: d14549b6031f5a0560f15034bfcd5927
SHA1: 938db20b9393793410777f51d7745b74fc7d39d7
SHA256:b5764e56e338468ebd94b7f8e6cbc65a94b3f997cc42d9429143aad8a5498220
Referenced In Projects/Scopes:
  • Executable Java Parent:provided
  • Executable Java Test:provided

proguard-annotations-7.8.2.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/me.chrissw-r1/java-exe-parent@3.0.34
  • pkg:maven/me.chrissw-r1/java-exe-parent-test@3.0.34

Identifiers

slf4j-api-2.0.17.jar

Description:

The slf4j API

License:

https://opensource.org/license/mit
File Path: /home/runner/.m2/repository/org/slf4j/slf4j-api/2.0.17/slf4j-api-2.0.17.jar
MD5: b6480d114a23683498ac3f746f959d2f
SHA1: d9e58ac9c7779ba3bf8142aff6c830617a7fe60f
SHA256:7b751d952061954d5abfed7181c1f645d336091b679891591d63329c622eb832
Referenced In Projects/Scopes:
  • Executable Java Test:compile
  • Executable Java Parent:compile

slf4j-api-2.0.17.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/me.chrissw-r1/java-exe-parent@3.0.34
  • pkg:maven/me.chrissw-r1/java-exe-parent-test@3.0.34

Identifiers

spotbugs-annotations-4.9.8.jar

Description:

Annotations the SpotBugs tool supports

License:

GNU LESSER GENERAL PUBLIC LICENSE, Version 2.1: https://www.gnu.org/licenses/old-licenses/lgpl-2.1.en.html
File Path: /home/runner/.m2/repository/com/github/spotbugs/spotbugs-annotations/4.9.8/spotbugs-annotations-4.9.8.jar
MD5: d4c2e7bd090be697ad409a4e75684a94
SHA1: ca4a2783a6123e67124fd7feb4caccd2e2ac9a73
SHA256:6f69d6fe9c55a54dcb30e87d8fa2d5f52246af50d7a3445246d9539ef221be1c
Referenced In Projects/Scopes:
  • Executable Java Parent:provided
  • Executable Java Test:provided

spotbugs-annotations-4.9.8.jar is in the transitive dependency tree of the listed items.Included by:
  • pkg:maven/me.chrissw-r1/java-exe-parent@3.0.34
  • pkg:maven/me.chrissw-r1/java-exe-parent-test@3.0.34

Identifiers



This report contains data retrieved from the National Vulnerability Database.
This report may contain data retrieved from the CISA Known Exploited Vulnerability Catalog.
This report may contain data retrieved from the Github Advisory Database (via NPM Audit API).
This report may contain data retrieved from RetireJS.
This report may contain data retrieved from the Sonatype OSS Index.