Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.

How to read the report | Suppressing false positives | Getting Help: google group | github issues

Project: maven-code-quality-pom

Scan Information (show all):

Display: Showing Vulnerable Dependencies (click to show all)

Dependency CPE GAV Highest Severity CVE Count CPE Confidence Evidence Count
jsr305-1.3.9.jar com.google.code.findbugs:jsr305:1.3.9    0 21
error_prone_annotations-2.0.18.jar com.google.errorprone:error_prone_annotations:2.0.18    0 23
javac-shaded-9-dev-r4023-3.jar com.google.errorprone:javac-shaded:9-dev-r4023-3    0 22
google-java-format-1.5.jar com.google.googlejavaformat:google-java-format:1.5    0 26
guava-22.0.jar com.google.guava:guava:22.0    0 29
j2objc-annotations-1.1.jar com.google.j2objc:j2objc-annotations:1.1    0 23
commons-logging-1.2.jar commons-logging:commons-logging:1.2    0 36
log4j-core-2.9.1.jar cpe:/a:apache:log4j:2.9.1 org.apache.logging.log4j:log4j-core:2.9.1    0 Low 39
maven-fluido-skin-1.6.jar org.apache.maven.skins:maven-fluido-skin:1.6    0 28
common-java5-2.19.1.jar org.apache.maven.surefire:common-java5:2.19.1    0 21
surefire-api-2.19.1.jar org.apache.maven.surefire:surefire-api:2.19.1    0 20
animal-sniffer-annotations-1.14.jar org.codehaus.mojo:animal-sniffer-annotations:1.14    0 24
junit-platform-surefire-provider-1.0.1.jar org.junit.platform:junit-platform-surefire-provider:1.0.1    0 29
spring-boot-autoconfigure-1.5.4.RELEASE.jar org.springframework.boot:spring-boot-autoconfigure:1.5.4.RELEASE    0 32
spring-boot-1.5.4.RELEASE.jar org.springframework.boot:spring-boot:1.5.4.RELEASE    0 32
spring-core-4.3.12.RELEASE.jar cpe:/a:pivotal:spring_framework:4.3.12
cpe:/a:pivotal_software:spring_framework:4.3.12
cpe:/a:vmware:springsource_spring_framework:4.3.12
cpe:/a:springsource:spring_framework:4.3.12
org.springframework:spring-core:4.3.12.RELEASE    0 Low 27
common-java5-2.19.1.jar/META-INF/maven/org.apache.maven.shared/maven-shared-utils/pom.xml org.apache.maven.shared:maven-shared-utils:0.9   0 14
common-java5-2.19.1.jar/META-INF/maven/commons-io/commons-io/pom.xml commons-io:commons-io:2.2   0 16
common-java5-2.19.1.jar/META-INF/maven/org.apache.maven.surefire/surefire-api/pom.xml cpe:/a:apache:apache_test:2.19.1 org.apache.maven.surefire:surefire-api:2.19.1   0 Low 13

Dependencies

jsr305-1.3.9.jar

Description: JSR305 Annotations for Findbugs

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /Users/swindle/.m2/repository/com/google/code/findbugs/jsr305/1.3.9/jsr305-1.3.9.jar
MD5: 1d5a772e400b04bb67a7ef4a0e0996d8
SHA1: 40719ea6961c0cb6afaeb6a921eaa1f6afd4cfdf
Referenced In Project/Scope: maven-code-quality-pom:compile

Identifiers

error_prone_annotations-2.0.18.jar

File Path: /Users/swindle/.m2/repository/com/google/errorprone/error_prone_annotations/2.0.18/error_prone_annotations-2.0.18.jar
MD5: 98051758c08c9b7111b3268655069432
SHA1: 5f65affce1684999e2f4024983835efc3504012e
Referenced In Project/Scope: maven-code-quality-pom:compile

Identifiers

javac-shaded-9-dev-r4023-3.jar

Description: A repackaged and shaded copy of javac

License:

GNU General Public License, version 2, with the Classpath Exception: http://openjdk.java.net/legal/gplv2+ce.html
File Path: /Users/swindle/.m2/repository/com/google/errorprone/javac-shaded/9-dev-r4023-3/javac-shaded-9-dev-r4023-3.jar
MD5: 4271f3d058b287d1c15172b00a844783
SHA1: 72b688efd290280a0afde5f9892b0fde6f362d1d
Referenced In Project/Scope: maven-code-quality-pom:compile

Identifiers

google-java-format-1.5.jar

Description:  A Java source code formatter that follows Google Java Style.

File Path: /Users/swindle/.m2/repository/com/google/googlejavaformat/google-java-format/1.5/google-java-format-1.5.jar
MD5: 2d528c036c15a9bad7c48012bbba678b
SHA1: fba7f130d29061d2d2ea384b4880c10cae92ef73
Referenced In Project/Scope: maven-code-quality-pom:compile

Identifiers

guava-22.0.jar

Description:  Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more. Guava has only one code dependency - javax.annotation, per the JSR-305 spec.

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /Users/swindle/.m2/repository/com/google/guava/guava/22.0/guava-22.0.jar
MD5: 5ba5b28f59ed2d96534ece0a72802db6
SHA1: 3564ef3803de51fb0530a8377ec6100b33b0d073
Referenced In Project/Scope: maven-code-quality-pom:compile

Identifiers

j2objc-annotations-1.1.jar

Description:  A set of annotations that provide additional information to the J2ObjC translator to modify the result of translation.

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /Users/swindle/.m2/repository/com/google/j2objc/j2objc-annotations/1.1/j2objc-annotations-1.1.jar
MD5: 49ae3204bb0bb9b2ac77062641f4a6d7
SHA1: ed28ded51a8b1c6b112568def5f4b455e6809019
Referenced In Project/Scope: maven-code-quality-pom:compile

Identifiers

commons-logging-1.2.jar

Description: Apache Commons Logging is a thin adapter allowing configurable bridging to other, well known logging systems.

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /Users/swindle/.m2/repository/commons-logging/commons-logging/1.2/commons-logging-1.2.jar
MD5: 040b4b4d8eac886f6b4a2a3bd2f31b00
SHA1: 4bfc12adfe4842bf07b657f0369c4cb522955686
Referenced In Project/Scope: maven-code-quality-pom:compile

Identifiers

log4j-core-2.9.1.jar

Description: The Apache Log4j Implementation

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /Users/swindle/.m2/repository/org/apache/logging/log4j/log4j-core/2.9.1/log4j-core-2.9.1.jar
MD5: 942f429eacb8015e18d8f59996cfbee6
SHA1: c041978c686866ee8534f538c6220238db3bb6be
Referenced In Project/Scope: maven-code-quality-pom:compile

Identifiers

maven-fluido-skin-1.6.jar

Description: The Apache Maven Fluido Skin is an Apache Maven site skin built on top of Twitter's bootstrap.

File Path: /Users/swindle/.m2/repository/org/apache/maven/skins/maven-fluido-skin/1.6/maven-fluido-skin-1.6.jar
MD5: 0dc414c10b79fd21b5c67de8fd661ece
SHA1: 5fb8d418df82bc072cdb360dda6bff97db149fb0
Referenced In Project/Scope: maven-code-quality-pom:compile

Identifiers

common-java5-2.19.1.jar

File Path: /Users/swindle/.m2/repository/org/apache/maven/surefire/common-java5/2.19.1/common-java5-2.19.1.jar
MD5: 0fafcaf5a2fe151e0430dd9f5347acc6
SHA1: e691579ae810d8608c7a2f37b8223c44a2aa18c3
Referenced In Project/Scope: maven-code-quality-pom:runtime

Identifiers

surefire-api-2.19.1.jar

File Path: /Users/swindle/.m2/repository/org/apache/maven/surefire/surefire-api/2.19.1/surefire-api-2.19.1.jar
MD5: 325899c60a638cc1ac49374ccb2ac605
SHA1: bc116d32abb2302e6a21d158bd4b7cccd87d578e
Referenced In Project/Scope: maven-code-quality-pom:runtime

Identifiers

animal-sniffer-annotations-1.14.jar

File Path: /Users/swindle/.m2/repository/org/codehaus/mojo/animal-sniffer-annotations/1.14/animal-sniffer-annotations-1.14.jar
MD5: 9d42e46845c874f1710a9f6a741f6c14
SHA1: 775b7e22fb10026eed3f86e8dc556dfafe35f2d5
Referenced In Project/Scope: maven-code-quality-pom:compile

Identifiers

junit-platform-surefire-provider-1.0.1.jar

Description: Module "junit-platform-surefire-provider" of JUnit 5.

License:

The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /Users/swindle/.m2/repository/org/junit/platform/junit-platform-surefire-provider/1.0.1/junit-platform-surefire-provider-1.0.1.jar
MD5: 68d7cfaee15223b5482cee7d0d0fc6e9
SHA1: fdf646385f0ee9e3348761bbfef75bc6d8ce3818
Referenced In Project/Scope: maven-code-quality-pom:compile

Identifiers

spring-boot-autoconfigure-1.5.4.RELEASE.jar

Description: Spring Boot AutoConfigure

File Path: /Users/swindle/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/1.5.4.RELEASE/spring-boot-autoconfigure-1.5.4.RELEASE.jar
MD5: 03bc3a0621cf24d122079d650a9c0eb2
SHA1: 5591fa7358d950f374532c7d92dccf113ebfa1bb
Referenced In Project/Scope: maven-code-quality-pom:compile

Identifiers

spring-boot-1.5.4.RELEASE.jar

Description: Spring Boot

File Path: /Users/swindle/.m2/repository/org/springframework/boot/spring-boot/1.5.4.RELEASE/spring-boot-1.5.4.RELEASE.jar
MD5: 1720a2ed8b2f62d318c0bb9a9d19e5bf
SHA1: 0cf51bb0751c1362a417eb59824d27d2907780d2
Referenced In Project/Scope: maven-code-quality-pom:compile

Identifiers

spring-core-4.3.12.RELEASE.jar

Description: Spring Core

License:

Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0
File Path: /Users/swindle/.m2/repository/org/springframework/spring-core/4.3.12.RELEASE/spring-core-4.3.12.RELEASE.jar
MD5: 01ab7f742861c65f7339acba6333326c
SHA1: 4cebc69478c6d350dbd5af28e3db7d5694f416e3
Referenced In Project/Scope: maven-code-quality-pom:compile

Identifiers

  • maven: org.springframework:spring-core:4.3.12.RELEASE    Confidence:Highest
  • cpe: cpe:/a:pivotal:spring_framework:4.3.12   Confidence:Low   
  • cpe: cpe:/a:pivotal_software:spring_framework:4.3.12   Confidence:Low   
  • cpe: cpe:/a:vmware:springsource_spring_framework:4.3.12   Confidence:Low   
  • cpe: cpe:/a:springsource:spring_framework:4.3.12   Confidence:Low   

common-java5-2.19.1.jar/META-INF/maven/org.apache.maven.shared/maven-shared-utils/pom.xml

Description: Shared utils without any further dependencies

File Path: /Users/swindle/.m2/repository/org/apache/maven/surefire/common-java5/2.19.1/common-java5-2.19.1.jar/META-INF/maven/org.apache.maven.shared/maven-shared-utils/pom.xml
MD5: b5476e14234893cf9246bfbc1f904059
SHA1: 9acaa2395b74fd34eef0cefc5cc162c20e4473f3

Identifiers

  • maven: org.apache.maven.shared:maven-shared-utils:0.9   Confidence:High

common-java5-2.19.1.jar/META-INF/maven/commons-io/commons-io/pom.xml

Description:  The Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more.

File Path: /Users/swindle/.m2/repository/org/apache/maven/surefire/common-java5/2.19.1/common-java5-2.19.1.jar/META-INF/maven/commons-io/commons-io/pom.xml
MD5: 8dcc8cd4255c1f23e7f58780a943cefb
SHA1: 1ef24807b2eaf9d51b5587710878146d630cc855

Identifiers

  • maven: commons-io:commons-io:2.2   Confidence:High

common-java5-2.19.1.jar/META-INF/maven/org.apache.maven.surefire/surefire-api/pom.xml

Description: API used in Surefire and Failsafe MOJO, Booter, Common and test framework providers.

File Path: /Users/swindle/.m2/repository/org/apache/maven/surefire/common-java5/2.19.1/common-java5-2.19.1.jar/META-INF/maven/org.apache.maven.surefire/surefire-api/pom.xml
MD5: 20a834dfa5637f6ea89819827d3cdc00
SHA1: 69d5d7186223eb6a503aab6f51b093cd0b40b025

Identifiers

  • cpe: cpe:/a:apache:apache_test:2.19.1   Confidence:Low   
  • maven: org.apache.maven.surefire:surefire-api:2.19.1   Confidence:High


This report contains data retrieved from the National Vulnerability Database.
This report may contain data retrieved from the Node Security Platform.