Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 3.0.1
Report Generated On : Nov 10, 2017 at 01:47:52 -06:00
Dependencies Scanned : 27 (19 unique)
Vulnerable Dependencies : 0
Vulnerabilities Found : 0
Vulnerabilities Suppressed : 0
...
NVD CVE 2002 : 02/11/2017 02:24:55
NVD CVE 2003 : 20/10/2017 02:19:00
NVD CVE 2004 : 19/10/2017 02:32:36
NVD CVE 2005 : 26/10/2017 02:18:51
NVD CVE 2006 : 29/10/2017 02:08:58
NVD CVE 2007 : 19/10/2017 02:27:06
NVD CVE 2008 : 04/11/2017 02:20:47
NVD CVE 2009 : 02/11/2017 02:22:39
NVD CVE 2010 : 27/10/2017 02:17:29
NVD CVE 2011 : 02/11/2017 02:19:33
NVD CVE 2012 : 04/11/2017 02:17:51
NVD CVE 2013 : 04/11/2017 02:15:11
NVD CVE 2014 : 07/11/2017 02:09:00
NVD CVE 2015 : 07/11/2017 02:05:55
NVD CVE 2016 : 06/11/2017 02:06:34
NVD CVE 2017 : 07/11/2017 02:03:01
NVD CVE Checked : 09/11/2017 23:07:32
NVD CVE Modified : 09/11/2017 19:00:59
VersionCheckOn : 1510118772719
Display:
Showing Vulnerable Dependencies (click to show all)
Dependencies
jsr305-1.3.9.jar
Description: JSR305 Annotations for Findbugs
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /Users/swindle/.m2/repository/com/google/code/findbugs/jsr305/1.3.9/jsr305-1.3.9.jar
MD5: 1d5a772e400b04bb67a7ef4a0e0996d8
SHA1: 40719ea6961c0cb6afaeb6a921eaa1f6afd4cfdf
Referenced In Project/Scope:
maven-code-quality-pom:compile
Evidence
Type Source Name Value Confidence
Vendor file name jsr305 High
Vendor pom groupid com.google.code.findbugs Highest
Vendor pom url http://findbugs.sourceforge.net/ Highest
Vendor jar package name javax Low
Vendor central groupid com.google.code.findbugs Highest
Vendor pom groupid google.code.findbugs Highest
Vendor pom description JSR305 Annotations for Findbugs Medium
Vendor pom name FindBugs-jsr305 High
Vendor pom artifactid jsr305 Low
Vendor jar package name annotation Low
Product pom artifactid jsr305 Highest
Product pom url http://findbugs.sourceforge.net/ Medium
Product file name jsr305 High
Product central artifactid jsr305 Highest
Product pom groupid google.code.findbugs Low
Product pom description JSR305 Annotations for Findbugs Medium
Product pom name FindBugs-jsr305 High
Product jar package name annotation Low
Version pom version 1.3.9 Highest
Version file version 1.3.9 Highest
Version central version 1.3.9 Highest
error_prone_annotations-2.0.18.jar
File Path: /Users/swindle/.m2/repository/com/google/errorprone/error_prone_annotations/2.0.18/error_prone_annotations-2.0.18.jar
MD5: 98051758c08c9b7111b3268655069432
SHA1: 5f65affce1684999e2f4024983835efc3504012e
Referenced In Project/Scope:
maven-code-quality-pom:compile
Evidence
Type Source Name Value Confidence
Vendor jar package name google Low
Vendor pom groupid google.errorprone Highest
Vendor jar package name annotations Low
Vendor jar package name errorprone Low
Vendor central groupid com.google.errorprone Highest
Vendor file name error_prone_annotations High
Vendor pom parent-groupid com.google.errorprone Medium
Vendor pom parent-artifactid error_prone_parent Low
Vendor pom artifactid error_prone_annotations Low
Vendor pom groupid com.google.errorprone Highest
Vendor pom name error-prone annotations High
Product jar package name annotations Low
Product jar package name errorprone Low
Product pom parent-groupid com.google.errorprone Low
Product pom parent-artifactid error_prone_parent Medium
Product pom artifactid error_prone_annotations Highest
Product file name error_prone_annotations High
Product pom groupid google.errorprone Low
Product pom name error-prone annotations High
Product central artifactid error_prone_annotations Highest
Version pom version 2.0.18 Highest
Version central version 2.0.18 Highest
Version file version 2.0.18 Highest
javac-shaded-9-dev-r4023-3.jar
Description: A repackaged and shaded copy of javac
License:
GNU General Public License, version 2, with the Classpath Exception: http://openjdk.java.net/legal/gplv2+ce.html
File Path: /Users/swindle/.m2/repository/com/google/errorprone/javac-shaded/9-dev-r4023-3/javac-shaded-9-dev-r4023-3.jar
MD5: 4271f3d058b287d1c15172b00a844783
SHA1: 72b688efd290280a0afde5f9892b0fde6f362d1d
Referenced In Project/Scope:
maven-code-quality-pom:compile
Evidence
Type Source Name Value Confidence
Vendor file name javac-shaded-9-dev-r4023-3 High
Vendor pom description A repackaged and shaded copy of javac Medium
Vendor pom url google/error-prone-javac Highest
Vendor pom groupid google.errorprone Highest
Vendor central groupid com.google.errorprone Highest
Vendor pom artifactid javac-shaded Low
Vendor pom name Error Prone shaded javac High
Vendor jar package name openjdk Low
Vendor jar package name javac Low
Vendor pom groupid com.google.errorprone Highest
Vendor jar package name tools Low
Product file name javac-shaded-9-dev-r4023-3 High
Product pom description A repackaged and shaded copy of javac Medium
Product central artifactid javac-shaded Highest
Product pom url google/error-prone-javac High
Product pom name Error Prone shaded javac High
Product pom artifactid javac-shaded Highest
Product jar package name javac Low
Product pom groupid google.errorprone Low
Product jar package name tools Low
Version pom version 9-dev-r4023-3 Highest
Version central version 9-dev-r4023-3 Highest
google-java-format-1.5.jar
Description:
A Java source code formatter that follows Google Java Style.
File Path: /Users/swindle/.m2/repository/com/google/googlejavaformat/google-java-format/1.5/google-java-format-1.5.jar
MD5: 2d528c036c15a9bad7c48012bbba678b
SHA1: fba7f130d29061d2d2ea384b4880c10cae92ef73
Referenced In Project/Scope:
maven-code-quality-pom:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-artifactid google-java-format-parent Low
Vendor pom groupid google.googlejavaformat Highest
Vendor pom parent-groupid com.google.googlejavaformat Medium
Vendor pom description
A Java source code formatter that follows Google Java Style.
Medium
Vendor central groupid com.google.googlejavaformat Highest
Vendor Manifest Implementation-Vendor Google Inc. High
Vendor Manifest implementation-url https://github.com/google/google-java-format/google-java-format Low
Vendor pom name Google Java Format High
Vendor pom groupid com.google.googlejavaformat Highest
Vendor file name google-java-format High
Vendor pom artifactid google-java-format Low
Vendor Manifest Implementation-Vendor-Id com.google.googlejavaformat Medium
Product Manifest implementation-url https://github.com/google/google-java-format/google-java-format Low
Product pom groupid google.googlejavaformat Low
Product pom name Google Java Format High
Product Manifest Implementation-Title Google Java Format High
Product file name google-java-format High
Product pom description
A Java source code formatter that follows Google Java Style.
Medium
Product pom artifactid google-java-format Highest
Product central artifactid google-java-format Highest
Product pom parent-groupid com.google.googlejavaformat Low
Product pom parent-artifactid google-java-format-parent Medium
Version central version 1.5 Highest
Version pom version 1.5 Highest
Version file version 1.5 Highest
Version Manifest Implementation-Version 1.5 High
guava-22.0.jar
Description:
Guava is a suite of core and expanded libraries that include
utility classes, google's collections, io classes, and much
much more.
Guava has only one code dependency - javax.annotation,
per the JSR-305 spec.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /Users/swindle/.m2/repository/com/google/guava/guava/22.0/guava-22.0.jar
MD5: 5ba5b28f59ed2d96534ece0a72802db6
SHA1: 3564ef3803de51fb0530a8377ec6100b33b0d073
Referenced In Project/Scope:
maven-code-quality-pom:compile
Evidence
Type Source Name Value Confidence
Vendor pom description Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more. Guava has only one code dependency - javax.annotation, per the JSR-305 spec. Low
Vendor pom artifactid guava Low
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low
Vendor pom name Guava: Google Core Libraries for Java High
Vendor Manifest bundle-symbolicname com.google.guava Medium
Vendor pom parent-artifactid guava-parent Low
Vendor central groupid com.google.guava Highest
Vendor pom groupid com.google.guava Highest
Vendor manifest Bundle-Description Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more. Guava has only one code dependency - javax.annotation, per the JSR-305 spec. Low
Vendor pom parent-groupid com.google.guava Medium
Vendor Manifest bundle-docurl https://github.com/google/guava/ Low
Vendor file name guava High
Vendor pom groupid google.guava Highest
Product pom description Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more. Guava has only one code dependency - javax.annotation, per the JSR-305 spec. Low
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low
Product pom name Guava: Google Core Libraries for Java High
Product Manifest bundle-symbolicname com.google.guava Medium
Product pom groupid google.guava Low
Product central artifactid guava Highest
Product pom artifactid guava Highest
Product Manifest Bundle-Name Guava: Google Core Libraries for Java Medium
Product manifest Bundle-Description Guava is a suite of core and expanded libraries that include utility classes, google's collections, io classes, and much much more. Guava has only one code dependency - javax.annotation, per the JSR-305 spec. Low
Product pom parent-artifactid guava-parent Medium
Product Manifest bundle-docurl https://github.com/google/guava/ Low
Product file name guava High
Product pom parent-groupid com.google.guava Low
Version central version 22.0 Highest
Version pom version 22.0 Highest
Version file version 22.0 Highest
j2objc-annotations-1.1.jar
Description:
A set of annotations that provide additional information to the J2ObjC
translator to modify the result of translation.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /Users/swindle/.m2/repository/com/google/j2objc/j2objc-annotations/1.1/j2objc-annotations-1.1.jar
MD5: 49ae3204bb0bb9b2ac77062641f4a6d7
SHA1: ed28ded51a8b1c6b112568def5f4b455e6809019
Referenced In Project/Scope:
maven-code-quality-pom:compile
Evidence
Type Source Name Value Confidence
Vendor jar package name google Low
Vendor jar package name j2objc Low
Vendor pom groupid google.j2objc Highest
Vendor jar package name annotations Low
Vendor pom artifactid j2objc-annotations Low
Vendor pom groupid com.google.j2objc Highest
Vendor pom name J2ObjC Annotations High
Vendor central groupid com.google.j2objc Highest
Vendor pom url google/j2objc/ Highest
Vendor file name j2objc-annotations High
Vendor pom description A set of annotations that provide additional information to the J2ObjC translator to modify the result of translation. Low
Product jar package name j2objc Low
Product pom groupid google.j2objc Low
Product jar package name annotations Low
Product pom artifactid j2objc-annotations Highest
Product pom name J2ObjC Annotations High
Product file name j2objc-annotations High
Product pom description A set of annotations that provide additional information to the J2ObjC translator to modify the result of translation. Low
Product central artifactid j2objc-annotations Highest
Product pom url google/j2objc/ High
Version pom version 1.1 Highest
Version central version 1.1 Highest
Version file version 1.1 Highest
commons-logging-1.2.jar
Description: Apache Commons Logging is a thin adapter allowing configurable bridging to other,
well known logging systems.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /Users/swindle/.m2/repository/commons-logging/commons-logging/1.2/commons-logging-1.2.jar
MD5: 040b4b4d8eac886f6b4a2a3bd2f31b00
SHA1: 4bfc12adfe4842bf07b657f0369c4cb522955686
Referenced In Project/Scope:
maven-code-quality-pom:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom name Apache Commons Logging High
Vendor pom artifactid commons-logging Low
Vendor pom url http://commons.apache.org/proper/commons-logging/ Highest
Vendor file name commons-logging High
Vendor pom description Apache Commons Logging is a thin adapter allowing configurable bridging to other, well known logging systems. Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor central groupid commons-logging Highest
Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-logging/ Low
Vendor pom groupid commons-logging Highest
Vendor Manifest bundle-symbolicname org.apache.commons.logging Medium
Vendor Manifest implementation-build tags/LOGGING_1_2_RC2@r1608092; 2014-07-05 20:11:44+0200 Low
Vendor pom parent-artifactid commons-parent Low
Vendor manifest Bundle-Description Apache Commons Logging is a thin adapter allowing configurable bridging to other, well known logging systems. Low
Product pom parent-groupid org.apache.commons Low
Product pom name Apache Commons Logging High
Product pom groupid commons-logging Low
Product central artifactid commons-logging Highest
Product file name commons-logging High
Product pom description Apache Commons Logging is a thin adapter allowing configurable bridging to other, well known logging systems. Low
Product Manifest Implementation-Title Apache Commons Logging High
Product Manifest Bundle-Name Apache Commons Logging Medium
Product Manifest bundle-docurl http://commons.apache.org/proper/commons-logging/ Low
Product pom parent-artifactid commons-parent Medium
Product pom artifactid commons-logging Highest
Product pom url http://commons.apache.org/proper/commons-logging/ Medium
Product Manifest specification-title Apache Commons Logging Medium
Product Manifest bundle-symbolicname org.apache.commons.logging Medium
Product Manifest implementation-build tags/LOGGING_1_2_RC2@r1608092; 2014-07-05 20:11:44+0200 Low
Product manifest Bundle-Description Apache Commons Logging is a thin adapter allowing configurable bridging to other, well known logging systems. Low
Version file version 1.2 Highest
Version Manifest Implementation-Version 1.2 High
Version central version 1.2 Highest
Version pom version 1.2 Highest
log4j-core-2.9.1.jar
Description: The Apache Log4j Implementation
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /Users/swindle/.m2/repository/org/apache/logging/log4j/log4j-core/2.9.1/log4j-core-2.9.1.jar
MD5: 942f429eacb8015e18d8f59996cfbee6
SHA1: c041978c686866ee8534f538c6220238db3bb6be
Referenced In Project/Scope:
maven-code-quality-pom:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest Implementation-Vendor-Id org.apache Medium
Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Vendor pom groupid org.apache.logging.log4j Highest
Vendor pom description The Apache Log4j Implementation Medium
Vendor pom groupid apache.logging.log4j Highest
Vendor Manifest log4jreleasemanager Ralph Goers Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom parent-groupid org.apache.logging.log4j Medium
Vendor pom name Apache Log4j Core High
Vendor Manifest implementation-url https://logging.apache.org/log4j/2.x/log4j-core/ Low
Vendor pom parent-artifactid log4j Low
Vendor manifest Bundle-Description The Apache Log4j Implementation Medium
Vendor Manifest bundle-docurl https://www.apache.org/ Low
Vendor central groupid org.apache.logging.log4j Highest
Vendor file name log4j-core High
Vendor pom artifactid log4j-core Low
Vendor Manifest bundle-symbolicname org.apache.logging.log4j.core Medium
Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low
Product Manifest specification-title Apache Log4j Core Medium
Product pom description The Apache Log4j Implementation Medium
Product pom artifactid log4j-core Highest
Product Manifest log4jreleasemanager Ralph Goers Low
Product Manifest Implementation-Title Apache Log4j Core High
Product pom parent-groupid org.apache.logging.log4j Low
Product Manifest Bundle-Name Apache Log4j Core Medium
Product pom parent-artifactid log4j Medium
Product pom name Apache Log4j Core High
Product Manifest implementation-url https://logging.apache.org/log4j/2.x/log4j-core/ Low
Product central artifactid log4j-core Highest
Product manifest Bundle-Description The Apache Log4j Implementation Medium
Product Manifest bundle-docurl https://www.apache.org/ Low
Product pom groupid apache.logging.log4j Low
Product file name log4j-core High
Product Manifest bundle-symbolicname org.apache.logging.log4j.core Medium
Version central version 2.9.1 Highest
Version pom version 2.9.1 Highest
Version file version 2.9.1 Highest
Version Manifest Implementation-Version 2.9.1 High
Related Dependencies
log4j-api-2.9.1.jar
File Path: /Users/swindle/.m2/repository/org/apache/logging/log4j/log4j-api/2.9.1/log4j-api-2.9.1.jar
SHA1: 7a2999229464e7a324aa503c0a52ec0f05efe7bd
MD5: 20f0b4e1a16bd2030f0acc2b277cb16f
maven: org.apache.logging.log4j:log4j-api:2.9.1 ✓
maven-fluido-skin-1.6.jar
Description: The Apache Maven Fluido Skin is an Apache Maven site skin
built on top of Twitter's bootstrap.
File Path: /Users/swindle/.m2/repository/org/apache/maven/skins/maven-fluido-skin/1.6/maven-fluido-skin-1.6.jar
MD5: 0dc414c10b79fd21b5c67de8fd661ece
SHA1: 5fb8d418df82bc072cdb360dda6bff97db149fb0
Referenced In Project/Scope:
maven-code-quality-pom:compile
Evidence
Type Source Name Value Confidence
Vendor Manifest implementation-url https://maven.apache.org/skins/maven-fluido-skin/ Low
Vendor pom artifactid maven-fluido-skin Low
Vendor pom description The Apache Maven Fluido Skin is an Apache Maven site skin
built on top of Twitter's bootstrap. Medium
Vendor pom name Apache Maven Fluido Skin High
Vendor central groupid org.apache.maven.skins Highest
Vendor file name maven-fluido-skin High
Vendor pom parent-groupid org.apache.maven.skins Medium
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom groupid apache.maven.skins Highest
Vendor pom groupid org.apache.maven.skins Highest
Vendor pom parent-artifactid maven-skins Low
Vendor Manifest Implementation-Vendor-Id org.apache.maven.skins Medium
Product Manifest implementation-url https://maven.apache.org/skins/maven-fluido-skin/ Low
Product pom parent-artifactid maven-skins Medium
Product central artifactid maven-fluido-skin Highest
Product pom artifactid maven-fluido-skin Highest
Product Manifest specification-title Apache Maven Fluido Skin Medium
Product pom description The Apache Maven Fluido Skin is an Apache Maven site skin
built on top of Twitter's bootstrap. Medium
Product pom groupid apache.maven.skins Low
Product pom name Apache Maven Fluido Skin High
Product pom parent-groupid org.apache.maven.skins Low
Product file name maven-fluido-skin High
Product Manifest Implementation-Title Apache Maven Fluido Skin High
Version pom version 1.6 Highest
Version Manifest Implementation-Version 1.6 High
Version central version 1.6 Highest
Version file version 1.6 Highest
common-java5-2.19.1.jar
File Path: /Users/swindle/.m2/repository/org/apache/maven/surefire/common-java5/2.19.1/common-java5-2.19.1.jar
MD5: 0fafcaf5a2fe151e0430dd9f5347acc6
SHA1: e691579ae810d8608c7a2f37b8223c44a2aa18c3
Referenced In Project/Scope:
maven-code-quality-pom:runtime
Evidence
Type Source Name Value Confidence
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom groupid org.apache.maven.surefire Highest
Vendor file name common-java5 High
Vendor jar package name apache Low
Vendor jar package name maven Low
Vendor Manifest Implementation-Vendor-Id org.apache.maven.surefire Medium
Vendor jar package name surefire Low
Vendor central groupid org.apache.maven.surefire Highest
Product Manifest Implementation-Title Shared Java 5 Provider Base High
Product file name common-java5 High
Product jar package name report Low
Product pom artifactid common-java5 Highest
Product jar package name maven Low
Product jar package name surefire Low
Product central artifactid common-java5 Highest
Product Manifest specification-title Shared Java 5 Provider Base Medium
Version central version 2.19.1 Highest
Version file version 2.19.1 Highest
Version pom version 2.19.1 Highest
Version Manifest Implementation-Version 2.19.1 High
surefire-api-2.19.1.jar
File Path: /Users/swindle/.m2/repository/org/apache/maven/surefire/surefire-api/2.19.1/surefire-api-2.19.1.jar
MD5: 325899c60a638cc1ac49374ccb2ac605
SHA1: bc116d32abb2302e6a21d158bd4b7cccd87d578e
Referenced In Project/Scope:
maven-code-quality-pom:runtime
Evidence
Type Source Name Value Confidence
Vendor file name surefire-api High
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor pom groupid org.apache.maven.surefire Highest
Vendor jar package name apache Low
Vendor jar package name maven Low
Vendor Manifest Implementation-Vendor-Id org.apache.maven.surefire Medium
Vendor jar package name surefire Low
Vendor central groupid org.apache.maven.surefire Highest
Product pom artifactid surefire-api Highest
Product file name surefire-api High
Product Manifest specification-title SureFire API Medium
Product jar package name maven Low
Product Manifest Implementation-Title SureFire API High
Product jar package name surefire Low
Product central artifactid surefire-api Highest
Version central version 2.19.1 Highest
Version file version 2.19.1 Highest
Version pom version 2.19.1 Highest
Version Manifest Implementation-Version 2.19.1 High
animal-sniffer-annotations-1.14.jar
File Path: /Users/swindle/.m2/repository/org/codehaus/mojo/animal-sniffer-annotations/1.14/animal-sniffer-annotations-1.14.jar
MD5: 9d42e46845c874f1710a9f6a741f6c14
SHA1: 775b7e22fb10026eed3f86e8dc556dfafe35f2d5
Referenced In Project/Scope:
maven-code-quality-pom:compile
Evidence
Type Source Name Value Confidence
Vendor jar package name codehaus Low
Vendor central groupid org.codehaus.mojo Highest
Vendor pom groupid codehaus.mojo Highest
Vendor pom artifactid animal-sniffer-annotations Low
Vendor jar package name mojo Low
Vendor file name animal-sniffer-annotations High
Vendor jar package name animal_sniffer Low
Vendor pom parent-artifactid animal-sniffer-parent Low
Vendor pom name Animal Sniffer Annotations High
Vendor pom groupid org.codehaus.mojo Highest
Vendor pom parent-groupid org.codehaus.mojo Medium
Product pom parent-groupid org.codehaus.mojo Low
Product pom parent-artifactid animal-sniffer-parent Medium
Product jar package name mojo Low
Product pom artifactid animal-sniffer-annotations Highest
Product file name animal-sniffer-annotations High
Product pom groupid codehaus.mojo Low
Product jar package name animal_sniffer Low
Product pom name Animal Sniffer Annotations High
Product central artifactid animal-sniffer-annotations Highest
Product jar package name ignorejrerequirement Low
Version pom version 1.14 Highest
Version central version 1.14 Highest
Version file version 1.14 Highest
junit-platform-surefire-provider-1.0.1.jar
Description: Module "junit-platform-surefire-provider" of JUnit 5.
License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /Users/swindle/.m2/repository/org/junit/platform/junit-platform-surefire-provider/1.0.1/junit-platform-surefire-provider-1.0.1.jar
MD5: 68d7cfaee15223b5482cee7d0d0fc6e9
SHA1: fdf646385f0ee9e3348761bbfef75bc6d8ce3818
Referenced In Project/Scope:
maven-code-quality-pom:compile
Evidence
Type Source Name Value Confidence
Vendor pom groupid org.junit.platform Highest
Vendor Manifest automatic-module-name org.junit.platform.surefire.provider Medium
Vendor Manifest Implementation-Vendor junit.org High
Vendor pom artifactid junit-platform-surefire-provider Low
Vendor central groupid org.junit.platform Highest
Vendor pom groupid junit.platform Highest
Vendor pom url http://junit.org/junit5/ Highest
Vendor Manifest build-date 2017-10-03 Low
Vendor Manifest build-time 14:27:00.381+0200 Low
Vendor pom name org.junit.platform:junit-platform-surefire-provider High
Vendor Manifest specification-vendor junit.org Low
Vendor file name junit-platform-surefire-provider High
Vendor pom description Module "junit-platform-surefire-provider" of JUnit 5. Medium
Product Manifest automatic-module-name org.junit.platform.surefire.provider Medium
Product Manifest Implementation-Title junit-platform-surefire-provider High
Product central artifactid junit-platform-surefire-provider Highest
Product Manifest build-date 2017-10-03 Low
Product Manifest build-time 14:27:00.381+0200 Low
Product pom name org.junit.platform:junit-platform-surefire-provider High
Product pom artifactid junit-platform-surefire-provider Highest
Product pom groupid junit.platform Low
Product file name junit-platform-surefire-provider High
Product Manifest specification-title junit-platform-surefire-provider Medium
Product pom description Module "junit-platform-surefire-provider" of JUnit 5. Medium
Product pom url http://junit.org/junit5/ Medium
Version file version 1.0.1 Highest
Version Manifest Implementation-Version 1.0.1 High
Version pom version 1.0.1 Highest
Version central version 1.0.1 Highest
spring-boot-autoconfigure-1.5.4.RELEASE.jar
Description: Spring Boot AutoConfigure
File Path: /Users/swindle/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/1.5.4.RELEASE/spring-boot-autoconfigure-1.5.4.RELEASE.jar
MD5: 03bc3a0621cf24d122079d650a9c0eb2
SHA1: 5591fa7358d950f374532c7d92dccf113ebfa1bb
Referenced In Project/Scope:
maven-code-quality-pom:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-artifactid spring-boot-parent Low
Vendor central groupid org.springframework.boot Highest
Vendor pom url http://projects.spring.io/spring-boot/ Highest
Vendor pom groupid org.springframework.boot Highest
Vendor file name spring-boot-autoconfigure High
Vendor pom description Spring Boot AutoConfigure Medium
Vendor pom groupid springframework.boot Highest
Vendor pom organization name Pivotal Software, Inc. High
Vendor Manifest Implementation-Vendor Pivotal Software, Inc. High
Vendor Manifest Implementation-Vendor-Id org.springframework.boot Medium
Vendor pom name Spring Boot AutoConfigure High
Vendor Manifest implementation-url http://projects.spring.io/spring-boot/ Low
Vendor pom artifactid spring-boot-autoconfigure Low
Vendor Manifest specification-vendor Pivotal Software, Inc. Low
Vendor pom organization url http://www.spring.io Medium
Product Manifest specification-title Spring Boot AutoConfigure Medium
Product pom artifactid spring-boot-autoconfigure Highest
Product file name spring-boot-autoconfigure High
Product pom description Spring Boot AutoConfigure Medium
Product Manifest Implementation-Title Spring Boot AutoConfigure High
Product central artifactid spring-boot-autoconfigure Highest
Product pom parent-artifactid spring-boot-parent Medium
Product pom parent-groupid org.springframework.boot Low
Product pom organization name Pivotal Software, Inc. Low
Product pom name Spring Boot AutoConfigure High
Product Manifest implementation-url http://projects.spring.io/spring-boot/ Low
Product pom url http://projects.spring.io/spring-boot/ Medium
Product pom organization url http://www.spring.io Low
Product pom groupid springframework.boot Low
Version central version 1.5.4.RELEASE Highest
Version pom version 1.5.4.RELEASE Highest
Version Manifest Implementation-Version 1.5.4.RELEASE High
spring-boot-1.5.4.RELEASE.jar
Description: Spring Boot
File Path: /Users/swindle/.m2/repository/org/springframework/boot/spring-boot/1.5.4.RELEASE/spring-boot-1.5.4.RELEASE.jar
MD5: 1720a2ed8b2f62d318c0bb9a9d19e5bf
SHA1: 0cf51bb0751c1362a417eb59824d27d2907780d2
Referenced In Project/Scope:
maven-code-quality-pom:compile
Evidence
Type Source Name Value Confidence
Vendor pom parent-artifactid spring-boot-parent Low
Vendor central groupid org.springframework.boot Highest
Vendor pom url http://projects.spring.io/spring-boot/ Highest
Vendor pom groupid org.springframework.boot Highest
Vendor pom groupid springframework.boot Highest
Vendor pom organization name Pivotal Software, Inc. High
Vendor pom name Spring Boot High
Vendor Manifest Implementation-Vendor Pivotal Software, Inc. High
Vendor Manifest Implementation-Vendor-Id org.springframework.boot Medium
Vendor Manifest implementation-url http://projects.spring.io/spring-boot/ Low
Vendor pom description Spring Boot Medium
Vendor pom artifactid spring-boot Low
Vendor Manifest specification-vendor Pivotal Software, Inc. Low
Vendor file name spring-boot High
Vendor pom organization url http://www.spring.io Medium
Product pom artifactid spring-boot Highest
Product pom name Spring Boot High
Product pom parent-artifactid spring-boot-parent Medium
Product pom parent-groupid org.springframework.boot Low
Product pom organization name Pivotal Software, Inc. Low
Product Manifest Implementation-Title Spring Boot High
Product Manifest implementation-url http://projects.spring.io/spring-boot/ Low
Product pom url http://projects.spring.io/spring-boot/ Medium
Product pom organization url http://www.spring.io Low
Product pom description Spring Boot Medium
Product pom groupid springframework.boot Low
Product Manifest specification-title Spring Boot Medium
Product central artifactid spring-boot Highest
Product file name spring-boot High
Version central version 1.5.4.RELEASE Highest
Version pom version 1.5.4.RELEASE Highest
Version Manifest Implementation-Version 1.5.4.RELEASE High
spring-core-4.3.12.RELEASE.jar
Description: Spring Core
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0
File Path: /Users/swindle/.m2/repository/org/springframework/spring-core/4.3.12.RELEASE/spring-core-4.3.12.RELEASE.jar
MD5: 01ab7f742861c65f7339acba6333326c
SHA1: 4cebc69478c6d350dbd5af28e3db7d5694f416e3
Referenced In Project/Scope:
maven-code-quality-pom:compile
Evidence
Type Source Name Value Confidence
Vendor pom description Spring Core Medium
Vendor file name spring-core High
Vendor pom url spring-projects/spring-framework Highest
Vendor hint analyzer vendor vmware High
Vendor hint analyzer vendor pivotal software High
Vendor pom organization url http://projects.spring.io/spring-framework Medium
Vendor pom name Spring Core High
Vendor pom organization name Spring IO High
Vendor hint analyzer vendor SpringSource High
Vendor pom groupid org.springframework Highest
Vendor pom groupid springframework Highest
Vendor central groupid org.springframework Highest
Vendor pom artifactid spring-core Low
Product Manifest Implementation-Title spring-core High
Product pom description Spring Core Medium
Product pom organization name Spring IO Low
Product file name spring-core High
Product pom organization url http://projects.spring.io/spring-framework Low
Product pom name Spring Core High
Product central artifactid spring-core Highest
Product pom groupid springframework Low
Product pom artifactid spring-core Highest
Product pom url spring-projects/spring-framework High
Product hint analyzer product springsource_spring_framework High
Version central version 4.3.12.RELEASE Highest
Version pom version 4.3.12.RELEASE Highest
Version Manifest Implementation-Version 4.3.12.RELEASE High
Related Dependencies
spring-beans-4.3.12.RELEASE.jar
File Path: /Users/swindle/.m2/repository/org/springframework/spring-beans/4.3.12.RELEASE/spring-beans-4.3.12.RELEASE.jar
SHA1: 0547dd432d47d0f01d9ccbedc4b705f9f7c1240a
MD5: 016d6b84ad5520b96b0d73ced6b729be
maven: org.springframework:spring-beans:4.3.12.RELEASE ✓
spring-aop-4.3.12.RELEASE.jar
File Path: /Users/swindle/.m2/repository/org/springframework/spring-aop/4.3.12.RELEASE/spring-aop-4.3.12.RELEASE.jar
SHA1: b3fef085902993c2ef874c45c7bfd79296d5a5a4
MD5: 43f27fd377b41bd4c1d59fb17bdc3a4d
maven: org.springframework:spring-aop:4.3.12.RELEASE ✓
spring-context-4.3.12.RELEASE.jar
File Path: /Users/swindle/.m2/repository/org/springframework/spring-context/4.3.12.RELEASE/spring-context-4.3.12.RELEASE.jar
SHA1: 5e6d26f36636f36b7efec1d6a0c5991284fbd95b
MD5: e403d653908491418191f2c12c77a6b6
maven: org.springframework:spring-context:4.3.12.RELEASE ✓
spring-expression-4.3.12.RELEASE.jar
File Path: /Users/swindle/.m2/repository/org/springframework/spring-expression/4.3.12.RELEASE/spring-expression-4.3.12.RELEASE.jar
SHA1: 790f69f6ad7f9da8d4a92c603ad7244c398c8309
MD5: 406bc89c8e55275190cc04e65fabc05d
maven: org.springframework:spring-expression:4.3.12.RELEASE ✓
maven: org.springframework:spring-core:4.3.12.RELEASE ✓
Confidence :Highest
cpe: cpe:/a:pivotal:spring_framework:4.3.12
Confidence :Low
suppress
cpe: cpe:/a:pivotal_software:spring_framework:4.3.12
Confidence :Low
suppress
cpe: cpe:/a:vmware:springsource_spring_framework:4.3.12
Confidence :Low
suppress
cpe: cpe:/a:springsource:spring_framework:4.3.12
Confidence :Low
suppress
common-java5-2.19.1.jar/META-INF/maven/org.apache.maven.shared/maven-shared-utils/pom.xml
Description: Shared utils without any further dependencies
File Path: /Users/swindle/.m2/repository/org/apache/maven/surefire/common-java5/2.19.1/common-java5-2.19.1.jar/META-INF/maven/org.apache.maven.shared/maven-shared-utils/pom.xml
MD5: b5476e14234893cf9246bfbc1f904059
SHA1: 9acaa2395b74fd34eef0cefc5cc162c20e4473f3
Evidence
Type Source Name Value Confidence
Vendor pom artifactid maven-shared-utils Low
Vendor pom description Shared utils without any further dependencies Medium
Vendor pom groupid apache.maven.shared Highest
Vendor pom name Apache Maven Shared Utils High
Vendor pom parent-groupid org.apache.maven.shared Medium
Vendor pom parent-artifactid maven-shared-components Low
Product pom parent-groupid org.apache.maven.shared Low
Product pom artifactid maven-shared-utils Highest
Product pom description Shared utils without any further dependencies Medium
Product pom name Apache Maven Shared Utils High
Product pom groupid apache.maven.shared Low
Product pom parent-artifactid maven-shared-components Medium
Version pom parent-version 0.9 Low
Version pom version 0.9 Highest
Related Dependencies
surefire-api-2.19.1.jar/META-INF/maven/org.apache.maven.shared/maven-shared-utils/pom.xml
File Path: /Users/swindle/.m2/repository/org/apache/maven/surefire/surefire-api/2.19.1/surefire-api-2.19.1.jar/META-INF/maven/org.apache.maven.shared/maven-shared-utils/pom.xml
SHA1: 9acaa2395b74fd34eef0cefc5cc162c20e4473f3
MD5: b5476e14234893cf9246bfbc1f904059
maven: org.apache.maven.shared:maven-shared-utils:0.9
Confidence :High
common-java5-2.19.1.jar/META-INF/maven/commons-io/commons-io/pom.xml
Description:
The Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
File Path: /Users/swindle/.m2/repository/org/apache/maven/surefire/common-java5/2.19.1/common-java5-2.19.1.jar/META-INF/maven/commons-io/commons-io/pom.xml
MD5: 8dcc8cd4255c1f23e7f58780a943cefb
SHA1: 1ef24807b2eaf9d51b5587710878146d630cc855
Evidence
Type Source Name Value Confidence
Vendor pom description
The Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more. Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom groupid commons-io Highest
Vendor pom url http://commons.apache.org/io/ Highest
Vendor pom name Commons IO High
Vendor pom artifactid commons-io Low
Vendor pom parent-artifactid commons-parent Low
Product pom url http://commons.apache.org/io/ Medium
Product pom groupid commons-io Low
Product pom description
The Commons IO library contains utility classes, stream implementations, file filters, file comparators, endian transformation classes, and much more. Low
Product pom parent-groupid org.apache.commons Low
Product pom parent-artifactid commons-parent Medium
Product pom name Commons IO High
Product pom artifactid commons-io Highest
Version pom version 2.2 Highest
Version pom parent-version 2.2 Low
Related Dependencies
surefire-api-2.19.1.jar/META-INF/maven/commons-io/commons-io/pom.xml
File Path: /Users/swindle/.m2/repository/org/apache/maven/surefire/surefire-api/2.19.1/surefire-api-2.19.1.jar/META-INF/maven/commons-io/commons-io/pom.xml
SHA1: 1ef24807b2eaf9d51b5587710878146d630cc855
MD5: 8dcc8cd4255c1f23e7f58780a943cefb
maven: commons-io:commons-io:2.2
Confidence :High
common-java5-2.19.1.jar/META-INF/maven/org.apache.maven.surefire/surefire-api/pom.xml
Description: API used in Surefire and Failsafe MOJO, Booter, Common and test framework providers.
File Path: /Users/swindle/.m2/repository/org/apache/maven/surefire/common-java5/2.19.1/common-java5-2.19.1.jar/META-INF/maven/org.apache.maven.surefire/surefire-api/pom.xml
MD5: 20a834dfa5637f6ea89819827d3cdc00
SHA1: 69d5d7186223eb6a503aab6f51b093cd0b40b025
Evidence
Type Source Name Value Confidence
Vendor pom parent-groupid org.apache.maven.surefire Medium
Vendor pom artifactid surefire-api Low
Vendor pom description API used in Surefire and Failsafe MOJO, Booter, Common and test framework providers. Medium
Vendor pom groupid apache.maven.surefire Highest
Vendor pom parent-artifactid surefire Low
Vendor pom name SureFire API High
Product pom artifactid surefire-api Highest
Product pom description API used in Surefire and Failsafe MOJO, Booter, Common and test framework providers. Medium
Product pom parent-artifactid surefire Medium
Product pom groupid apache.maven.surefire Low
Product pom name SureFire API High
Product pom parent-groupid org.apache.maven.surefire Low
Version pom version 2.19.1 Highest
Related Dependencies
surefire-api-2.19.1.jar/META-INF/maven/org.apache.maven.surefire/surefire-api/pom.xml
File Path: /Users/swindle/.m2/repository/org/apache/maven/surefire/surefire-api/2.19.1/surefire-api-2.19.1.jar/META-INF/maven/org.apache.maven.surefire/surefire-api/pom.xml
SHA1: 69d5d7186223eb6a503aab6f51b093cd0b40b025
MD5: 20a834dfa5637f6ea89819827d3cdc00
cpe: cpe:/a:apache:apache_test:2.19.1
Confidence :Low
suppress
maven: org.apache.maven.surefire:surefire-api:2.19.1
Confidence :High