Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.

How to read the report | Suppressing false positives | Getting Help: github issues

Project: coveralls-maven-plugin

com.github.hazendaz.maven:coveralls-maven-plugin:5.1.0

Scan Information (show all):

Summary

Summary of Vulnerable Dependencies (click to show all)

Dependency Vulnerability IDs Package Highest Severity CVE Count Confidence Evidence Count
JavaEWAH-1.2.3.jar pkg:maven/com.googlecode.javaewah/JavaEWAH@1.2.3   0 35
aopalliance-1.0.jar pkg:maven/aopalliance/aopalliance@1.0   0 20
asm-9.9.1.jar pkg:maven/org.ow2.asm/asm@9.9.1   0 54
checker-qual-4.1.0.jar pkg:maven/org.checkerframework/checker-qual@4.1.0   0 44
commons-codec-1.22.0.jar pkg:maven/commons-codec/commons-codec@1.22.0   0 121
commons-io-2.22.0.jar cpe:2.3:a:apache:commons_io:2.22.0:*:*:*:*:*:*:* pkg:maven/commons-io/commons-io@2.22.0   0 Highest 127
commons-lang3-3.20.0.jar cpe:2.3:a:apache:commons_lang:3.20.0:*:*:*:*:*:*:* pkg:maven/org.apache.commons/commons-lang3@3.20.0   0 Highest 145
error_prone_annotations-2.49.0.jar pkg:maven/com.google.errorprone/error_prone_annotations@2.49.0   0 29
failureaccess-1.0.3.jar pkg:maven/com.google.guava/failureaccess@1.0.3   0 32
guava-33.6.0-jre.jar cpe:2.3:a:google:guava:33.6.0:*:*:*:*:*:*:* pkg:maven/com.google.guava/guava@33.6.0-jre   0 Highest 25
guice-5.1.0-classes.jar pkg:maven/com.google.inject/guice@5.1.0   0 32
j2objc-annotations-3.1.jar pkg:maven/com.google.j2objc/j2objc-annotations@3.1   0 33
jackson-annotations-2.21.jar cpe:2.3:a:fasterxml:jackson-core:2.21:*:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-modules-java8:2.21:*:*:*:*:*:*:*
pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.21   0 Highest 36
jackson-core-2.21.3.jar cpe:2.3:a:fasterxml:jackson-core:2.21.3:*:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-modules-java8:2.21.3:*:*:*:*:*:*:*
pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.3   0 Highest 47
jackson-databind-2.21.3.jar cpe:2.3:a:fasterxml:jackson-core:2.21.3:*:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-databind:2.21.3:*:*:*:*:*:*:*
cpe:2.3:a:fasterxml:jackson-modules-java8:2.21.3:*:*:*:*:*:*:*
pkg:maven/com.fasterxml.jackson.core/jackson-databind@2.21.3   0 Highest 41
javax.inject-1.jar pkg:maven/javax.inject/javax.inject@1   0 20
jspecify-1.0.0.jar pkg:maven/org.jspecify/jspecify@1.0.0   0 32
jsr305-3.0.2.jar pkg:maven/com.google.code.findbugs/jsr305@3.0.2   0 17
lombok-1.18.46.jar: mavenEcjBootstrapAgent.jar   0 7
lombok-1.18.46.jar pkg:maven/org.projectlombok/lombok@1.18.46   0 36
maven-artifact-3.9.16.jar pkg:maven/org.apache.maven/maven-artifact@3.9.16   0 26
maven-builder-support-3.9.16.jar pkg:maven/org.apache.maven/maven-builder-support@3.9.16   0 24
maven-core-3.9.16.jar cpe:2.3:a:apache:maven:3.9.16:*:*:*:*:*:*:* pkg:maven/org.apache.maven/maven-core@3.9.16   0 Highest 24
maven-model-3.9.16.jar pkg:maven/org.apache.maven/maven-model@3.9.16   0 26
maven-model-builder-3.9.16.jar pkg:maven/org.apache.maven/maven-model-builder@3.9.16   0 32
maven-plugin-annotations-3.15.2.jar pkg:maven/org.apache.maven.plugin-tools/maven-plugin-annotations@3.15.2   0 26
maven-plugin-api-3.9.16.jar pkg:maven/org.apache.maven/maven-plugin-api@3.9.16   0 26
maven-repository-metadata-3.9.16.jar pkg:maven/org.apache.maven/maven-repository-metadata@3.9.16   0 26
maven-resolver-api-1.9.27.jar pkg:maven/org.apache.maven.resolver/maven-resolver-api@1.9.27   0 34
maven-resolver-impl-1.9.27.jar pkg:maven/org.apache.maven.resolver/maven-resolver-impl@1.9.27   0 32
maven-resolver-named-locks-1.9.27.jar pkg:maven/org.apache.maven.resolver/maven-resolver-named-locks@1.9.27   0 33
maven-resolver-provider-3.9.16.jar pkg:maven/org.apache.maven/maven-resolver-provider@3.9.16   0 26
maven-resolver-spi-1.9.27.jar pkg:maven/org.apache.maven.resolver/maven-resolver-spi@1.9.27   0 32
maven-resolver-util-1.9.27.jar pkg:maven/org.apache.maven.resolver/maven-resolver-util@1.9.27   0 36
maven-settings-3.9.16.jar pkg:maven/org.apache.maven/maven-settings@3.9.16   0 26
maven-settings-builder-3.9.16.jar pkg:maven/org.apache.maven/maven-settings-builder@3.9.16   0 26
maven-shared-utils-3.4.2.jar cpe:2.3:a:apache:maven_shared_utils:3.4.2:*:*:*:*:*:*:*
cpe:2.3:a:utils_project:utils:3.4.2:*:*:*:*:*:*:*
pkg:maven/org.apache.maven.shared/maven-shared-utils@3.4.2   0 Highest 29
modernizer-maven-annotations-3.4.0.jar pkg:maven/org.gaul/modernizer-maven-annotations@3.4.0   0 19
org.eclipse.jgit-6.10.1.202505221210-r.jar cpe:2.3:a:eclipse:jgit:6.10.1:202505221210:*:*:*:*:*:* pkg:maven/org.eclipse.jgit/org.eclipse.jgit@6.10.1.202505221210-r MEDIUM 1 Highest 55
org.eclipse.sisu.inject-1.0.0.jar pkg:maven/org.eclipse.sisu/org.eclipse.sisu.inject@1.0.0   0 37
org.eclipse.sisu.plexus-1.0.0.jar pkg:maven/org.eclipse.sisu/org.eclipse.sisu.plexus@1.0.0   0 32
plexus-cipher-2.0.jar pkg:maven/org.codehaus.plexus/plexus-cipher@2.0   0 20
plexus-classworlds-2.11.0.jar pkg:maven/org.codehaus.plexus/plexus-classworlds@2.11.0   0 37
plexus-component-annotations-2.2.0.jar pkg:maven/org.codehaus.plexus/plexus-component-annotations@2.2.0   0 23
plexus-interpolation-1.29.jar pkg:maven/org.codehaus.plexus/plexus-interpolation@1.29   0 34
plexus-sec-dispatcher-2.0.jar cpe:2.3:a:sec_project:sec:2.0:*:*:*:*:*:*:* pkg:maven/org.codehaus.plexus/plexus-sec-dispatcher@2.0   0 Highest 20
plexus-utils-4.0.3.jar cpe:2.3:a:codehaus-plexus:plexus-utils:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:utils_project:utils:4.0.3:*:*:*:*:*:*:*
pkg:maven/org.codehaus.plexus/plexus-utils@4.0.3   0 Highest 35
plexus-xml-3.0.2.jar pkg:maven/org.codehaus.plexus/plexus-xml@3.0.2   0 29
slf4j-api-2.0.18.jar pkg:maven/org.slf4j/slf4j-api@2.0.18   0 29
spotbugs-annotations-4.9.8.jar pkg:maven/com.github.spotbugs/spotbugs-annotations@4.9.8   0 53

Dependencies (vulnerable)

JavaEWAH-1.2.3.jar

Description:

The bit array data structure is implemented in Java as the BitSet class. Unfortunately, this fails to scale without compression.
  JavaEWAH is a word-aligned compressed variant of the Java bitset class. It uses a 64-bit run-length encoding (RLE) compression scheme.
  The goal of word-aligned compression is not to achieve the best compression, but rather to improve query processing time. Hence, we try to save CPU cycles, maybe at the expense of storage. However, the EWAH scheme we implemented is always more efficient storage-wise than an uncompressed bitmap (implemented in Java as the BitSet class). Unlike some alternatives, javaewah does not rely on a patented scheme. 

License:

Apache 2: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Jeremy\.m2\repository\com\googlecode\javaewah\JavaEWAH\1.2.3\JavaEWAH-1.2.3.jar
MD5: 8fdeda28c1fb10e67b3d79f86bef5e61
SHA1: 13a27c856e0c8808cee9a64032c58eee11c3adc9
SHA256:d65226949713c4c61a784f41c51167e7b0316f93764398ebba9e4336b3d954c2
Referenced In Project/Scope: coveralls-maven-plugin:compile
JavaEWAH-1.2.3.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.eclipse.jgit/org.eclipse.jgit@6.10.1.202505221210-r

Identifiers

  • pkg:maven/com.googlecode.javaewah/JavaEWAH@1.2.3   (Confidence:High)

aopalliance-1.0.jar

Description:

AOP Alliance

License:

Public Domain
File Path: C:\Users\Jeremy\.m2\repository\aopalliance\aopalliance\1.0\aopalliance-1.0.jar
MD5: 04177054e180d09e3998808efa0401c7
SHA1: 0235ba8b489512805ac13a8f9ea77a1ca5ebe3e8
SHA256:0addec670fedcd3f113c5c8091d783280d23f75e3acb841b61a9cdb079376a08
Referenced In Project/Scope: coveralls-maven-plugin:provided
aopalliance-1.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.maven/maven-core@3.9.16

Identifiers

  • pkg:maven/aopalliance/aopalliance@1.0   (Confidence:High)

asm-9.9.1.jar

Description:

ASM, a very small and fast Java bytecode manipulation framework

License:

BSD-3-Clause: https://asm.ow2.io/license.html
File Path: C:\Users\Jeremy\.m2\repository\org\ow2\asm\asm\9.9.1\asm-9.9.1.jar
MD5: 1888ad1f49038441bb2d12aa6dffe396
SHA1: 2ceea6ab43bcae1979b2a6d85fc0ca429877e5ab
SHA256:6f3828a215c920059a5efa2fb55c233d6c54ec5cadca99ce1b1bdd10077c7ddd
Referenced In Project/Scope: coveralls-maven-plugin:provided
asm-9.9.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.maven/maven-core@3.9.16

Identifiers

  • pkg:maven/org.ow2.asm/asm@9.9.1   (Confidence:High)

checker-qual-4.1.0.jar

Description:

checker-qual contains annotations (type qualifiers) that a programmerwrites to specify Java code for type-checking by the Checker Framework.

License:

The MIT License: https://opensource.org/licenses/MIT
File Path: C:\Users\Jeremy\.m2\repository\org\checkerframework\checker-qual\4.1.0\checker-qual-4.1.0.jar
MD5: 915efc242a44466cf82281e2229aaeb9
SHA1: 127f572d0f7e9dfb205bc4667dc361056e536c88
SHA256:a7e08a5400f6e1d97818ed01a8624473fee90b0ded941a44d190f1210c081790
Referenced In Project/Scope: coveralls-maven-plugin:compile
checker-qual-4.1.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.hazendaz.maven/coveralls-maven-plugin@5.1.0

Identifiers

  • pkg:maven/org.checkerframework/checker-qual@4.1.0   (Confidence:High)

commons-codec-1.22.0.jar

Description:

     The Apache Commons Codec component contains encoders and decoders for
     formats such as Base16, Base32, Base64, digest, and Hexadecimal. In addition to these
     widely used encoders and decoders, the codec package also maintains a
     collection of phonetic encoding utilities.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Jeremy\.m2\repository\commons-codec\commons-codec\1.22.0\commons-codec-1.22.0.jar
MD5: f14b9146cd553f4e8c5c3f5c9e2be611
SHA1: 6b3eb4beb7058c2a638f5f17bcb388649fd339dd
SHA256:d164fe79f262c32d9b18a0b5b2d317d1c27653d5e98fd2b998c24bf901c72ce4
Referenced In Project/Scope: coveralls-maven-plugin:compile
commons-codec-1.22.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.hazendaz.maven/coveralls-maven-plugin@5.1.0

Identifiers

  • pkg:maven/commons-codec/commons-codec@1.22.0   (Confidence:High)

commons-io-2.22.0.jar

Description:

The Apache Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Jeremy\.m2\repository\commons-io\commons-io\2.22.0\commons-io-2.22.0.jar
MD5: f91d54bd47c42456b4a5ae62eed85565
SHA1: 5b1e18bc0ad651ed878029d83f88d9c8189fd51e
SHA256:2b9a7b1f726fb86216dbd2c8321eabe0221dbd5b1be81c18e1cb53811b104758
Referenced In Project/Scope: coveralls-maven-plugin:compile
commons-io-2.22.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.hazendaz.maven/coveralls-maven-plugin@5.1.0

Identifiers

commons-lang3-3.20.0.jar

Description:

  Apache Commons Lang, a package of Java utility classes for the
  classes that are in java.lang's hierarchy, or are considered to be so
  standard as to justify existence in java.lang.

  The code is tested using the latest revision of the JDK for supported
  LTS releases: 8, 11, 17, 21 and 25 currently.
  See https://github.com/apache/commons-lang/blob/master/.github/workflows/maven.yml
  
  Please ensure your build environment is up-to-date and kindly report any build issues.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Jeremy\.m2\repository\org\apache\commons\commons-lang3\3.20.0\commons-lang3-3.20.0.jar
MD5: 4b29562ded527aa074e1d44f8646dac5
SHA1: 65897b3e5731220962e659e001904af3c3cbeba9
SHA256:69e5c9fa35da7a51a5fd2099dfe56a2d8d32cf233e2f6d770e796146440263f4
Referenced In Project/Scope: coveralls-maven-plugin:compile
commons-lang3-3.20.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.hazendaz.maven/coveralls-maven-plugin@5.1.0

Identifiers

error_prone_annotations-2.49.0.jar

Description:

Error Prone is a static analysis tool for Java that catches common programming mistakes at compile-time.

License:

Apache 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Jeremy\.m2\repository\com\google\errorprone\error_prone_annotations\2.49.0\error_prone_annotations-2.49.0.jar
MD5: f15f20dc5df752e2c0f8e37f7cdd9b1d
SHA1: 8b42a2e3865f6e0576da3fad51dbb96732ff0f14
SHA256:3b1003e51b8ae56fdbd7c71073e81d1683b97e6c4dff5a9151164d59b769d13c
Referenced In Project/Scope: coveralls-maven-plugin:provided
error_prone_annotations-2.49.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.hazendaz.maven/coveralls-maven-plugin@5.1.0

Identifiers

  • pkg:maven/com.google.errorprone/error_prone_annotations@2.49.0   (Confidence:High)

failureaccess-1.0.3.jar

Description:

    Contains
    com.google.common.util.concurrent.internal.InternalFutureFailureAccess and
    InternalFutures. Most users will never need to use this artifact. Its
    classes are conceptually a part of Guava, but they're in this separate
    artifact so that Android libraries can use them without pulling in all of
    Guava (just as they can use ListenableFuture by depending on the
    listenablefuture artifact).
  

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Jeremy\.m2\repository\com\google\guava\failureaccess\1.0.3\failureaccess-1.0.3.jar
MD5: 29a782e90f6b37218b18bb880d2a8f4a
SHA1: aeaffd00d57023a2c947393ed251f0354f0985fc
SHA256:cbfc3906b19b8f55dd7cfd6dfe0aa4532e834250d7f080bd8d211a3e246b59cb
Referenced In Project/Scope: coveralls-maven-plugin:provided
failureaccess-1.0.3.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.maven/maven-core@3.9.16

Identifiers

  • pkg:maven/com.google.guava/failureaccess@1.0.3   (Confidence:High)

guava-33.6.0-jre.jar

Description:

    Guava is a suite of core and expanded libraries that include
    utility classes, Google's collections, I/O classes, and
    much more.
  

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Jeremy\.m2\repository\com\google\guava\guava\33.6.0-jre\guava-33.6.0-jre.jar
MD5: 34a4f258ed23d2e876a6e4666bb3b1c5
SHA1: c376b13067cc99a5774403530953f7b05a91e218
SHA256:dc573e1fca4fd5454f4a5fd3d7da2df03002876a4175bafc14a95980dd7713b3
Referenced In Project/Scope: coveralls-maven-plugin:provided
guava-33.6.0-jre.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.maven/maven-core@3.9.16

Identifiers

guice-5.1.0-classes.jar

Description:

Guice is a lightweight dependency injection framework for Java 6 and above

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Jeremy\.m2\repository\com\google\inject\guice\5.1.0\guice-5.1.0-classes.jar
MD5: d4d4d9bf878b98862116e8ccc0a5c34e
SHA1: e7ba4c25bec3761840f67c73f166c0d509d01d1d
SHA256:142ad4475e19524d2fe3ac995b3f7cbc962fc726f2edb9dbdccc61feab9b2bf9
Referenced In Project/Scope: coveralls-maven-plugin:provided
guice-5.1.0-classes.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.maven/maven-core@3.9.16

Identifiers

  • pkg:maven/com.google.inject/guice@5.1.0   (Confidence:Highest)

j2objc-annotations-3.1.jar

Description:

    A set of annotations that provide additional information to the J2ObjC
    translator to modify the result of translation.
  

License:

Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Jeremy\.m2\repository\com\google\j2objc\j2objc-annotations\3.1\j2objc-annotations-3.1.jar
MD5: abe8bd3abff622b9a8b15c3a737aa741
SHA1: a892ca9507839bbdb900d64310ac98256cab992f
SHA256:84d3a150518485f8140ea99b8a985656749629f6433c92b80c75b36aba3b099b
Referenced In Project/Scope: coveralls-maven-plugin:provided
j2objc-annotations-3.1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.hazendaz.maven/coveralls-maven-plugin@5.1.0

Identifiers

  • pkg:maven/com.google.j2objc/j2objc-annotations@3.1   (Confidence:High)

jackson-annotations-2.21.jar

Description:

Core annotations used for value types, used by Jackson data binding package.
  

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Jeremy\.m2\repository\com\fasterxml\jackson\core\jackson-annotations\2.21\jackson-annotations-2.21.jar
MD5: e0d0c3e7300954f73e43c67d933aaea4
SHA1: b1bc1868bf02dc0bd6c7836257a036a331005309
SHA256:53ca085f4a150f703f49e1aabd935bd03b43e1ea3d55d135438292af22cef56b
Referenced In Project/Scope: coveralls-maven-plugin:compile
jackson-annotations-2.21.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.hazendaz.maven/coveralls-maven-plugin@5.1.0

Identifiers

  • pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.21   (Confidence:High)
  • cpe:2.3:a:fasterxml:jackson-core:2.21:*:*:*:*:*:*:*   (Confidence:Highest)   
  • cpe:2.3:a:fasterxml:jackson-modules-java8:2.21:*:*:*:*:*:*:*   (Confidence:Low)   

jackson-core-2.21.3.jar

Description:

Core Jackson processing abstractions (aka Streaming API), implementation for JSON

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Jeremy\.m2\repository\com\fasterxml\jackson\core\jackson-core\2.21.3\jackson-core-2.21.3.jar
MD5: 513c4f2160300c336a02bb13592d0d98
SHA1: 3358e9345dd0f2537c47bee152c0377df6c81ad5
SHA256:baf8b739e9d9b93bcdb33f25046bfdb8dbd74c97de2a8698539fbe0c7eeac0bb
Referenced In Project/Scope: coveralls-maven-plugin:compile
jackson-core-2.21.3.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.hazendaz.maven/coveralls-maven-plugin@5.1.0

Identifiers

  • pkg:maven/com.fasterxml.jackson.core/jackson-core@2.21.3   (Confidence:High)
  • cpe:2.3:a:fasterxml:jackson-core:2.21.3:*:*:*:*:*:*:*   (Confidence:Highest)   
  • cpe:2.3:a:fasterxml:jackson-modules-java8:2.21.3:*:*:*:*:*:*:*   (Confidence:Low)   

jackson-databind-2.21.3.jar

Description:

General data-binding functionality for Jackson: works on core streaming API

License:

The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Jeremy\.m2\repository\com\fasterxml\jackson\core\jackson-databind\2.21.3\jackson-databind-2.21.3.jar
MD5: 0ae595293418fd4dd9c4527d4abc5610
SHA1: aa7ccec161c275f3e6332666ab758916f3120714
SHA256:f397563d8e67630c10cab8c2334ca0e55af832fa3ebde160a379c2c96d43bf25
Referenced In Project/Scope: coveralls-maven-plugin:compile
jackson-databind-2.21.3.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.hazendaz.maven/coveralls-maven-plugin@5.1.0

Identifiers

javax.inject-1.jar

Description:

The javax.inject API

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Jeremy\.m2\repository\javax\inject\javax.inject\1\javax.inject-1.jar
MD5: 289075e48b909e9e74e6c915b3631d2e
SHA1: 6975da39a7040257bd51d21a231b76c915872d38
SHA256:91c77044a50c481636c32d916fd89c9118a72195390452c81065080f957de7ff
Referenced In Project/Scope: coveralls-maven-plugin:provided
javax.inject-1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.maven/maven-core@3.9.16

Identifiers

  • pkg:maven/javax.inject/javax.inject@1   (Confidence:High)

jspecify-1.0.0.jar

Description:

An artifact of well-named and well-specified annotations to power static analysis checks

License:

The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Jeremy\.m2\repository\org\jspecify\jspecify\1.0.0\jspecify-1.0.0.jar
MD5: 9133aba420d0ca3b001dbb6ae9992cf6
SHA1: 7425a601c1c7ec76645a78d22b8c6a627edee507
SHA256:1fad6e6be7557781e4d33729d49ae1cdc8fdda6fe477bb0cc68ce351eafdfbab
Referenced In Project/Scope: coveralls-maven-plugin:provided
jspecify-1.0.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.junit.jupiter/junit-jupiter-api@6.1.0

Identifiers

  • pkg:maven/org.jspecify/jspecify@1.0.0   (Confidence:High)

jsr305-3.0.2.jar

Description:

JSR305 Annotations for Findbugs

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Jeremy\.m2\repository\com\google\code\findbugs\jsr305\3.0.2\jsr305-3.0.2.jar
MD5: dd83accb899363c32b07d7a1b2e4ce40
SHA1: 25ea2e8b0c338a877313bd4672d3fe056ea78f0d
SHA256:766ad2a0783f2687962c8ad74ceecc38a28b9f72a2d085ee438b7813e928d0c7
Referenced In Project/Scope: coveralls-maven-plugin:provided
jsr305-3.0.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.spotbugs/spotbugs-annotations@4.9.8

Identifiers

  • pkg:maven/com.google.code.findbugs/jsr305@3.0.2   (Confidence:High)

lombok-1.18.46.jar: mavenEcjBootstrapAgent.jar

File Path: C:\Users\Jeremy\.m2\repository\org\projectlombok\lombok\1.18.46\lombok-1.18.46.jar\lombok\launch\mavenEcjBootstrapAgent.jar
MD5: 8b80305e4846088e139701372844e637
SHA1: 4b03ce7b33d535b42e4a84e106c3647760eb8769
SHA256:639da94437813649eac5af6d8154d736355f27199fc8aaeda85904fce947ee4f
Referenced In Project/Scope: coveralls-maven-plugin:provided

Identifiers

  • None

lombok-1.18.46.jar

Description:

Spice up your java: Automatic Resource Management, automatic generation of getters, setters, equals, hashCode and toString, and more!

License:

The MIT License: https://projectlombok.org/LICENSE
File Path: C:\Users\Jeremy\.m2\repository\org\projectlombok\lombok\1.18.46\lombok-1.18.46.jar
MD5: e02f419a66b86c594ffcafc862778723
SHA1: a5cfe99fdf320e84955ef653f2ce1bf789d11385
SHA256:01f7b1a015e33e2b62d5f5f37053306357ab1415fd181fcba7794f5d198c1126
Referenced In Project/Scope: coveralls-maven-plugin:provided
lombok-1.18.46.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.hazendaz.maven/coveralls-maven-plugin@5.1.0

Identifiers

  • pkg:maven/org.projectlombok/lombok@1.18.46   (Confidence:High)

maven-artifact-3.9.16.jar

File Path: C:\Users\Jeremy\.m2\repository\org\apache\maven\maven-artifact\3.9.16\maven-artifact-3.9.16.jar
MD5: 6005ab2198a19a41cd3cf59618f9abc1
SHA1: 1176c6579a8a68508c3479ef72d514e71c98ddca
SHA256:54cc1c1ef932e3d4a903352111b42b4d3c3ed8e7a1d0de73b625309d9c3ad3e8
Referenced In Project/Scope: coveralls-maven-plugin:provided
maven-artifact-3.9.16.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.maven/maven-core@3.9.16

Identifiers

  • pkg:maven/org.apache.maven/maven-artifact@3.9.16   (Confidence:High)

maven-builder-support-3.9.16.jar

Description:

Support for descriptor builders (model, setting, toolchains)

File Path: C:\Users\Jeremy\.m2\repository\org\apache\maven\maven-builder-support\3.9.16\maven-builder-support-3.9.16.jar
MD5: 63d5dfe8e9a09ac68ad382ee8af116ab
SHA1: d23ad247143e3b0fb6de5b61c56d46bba6513f9b
SHA256:02972384eae3495801565fd27abb84cfd75a8e6d2cbb1ae0c556752ebc2b1cde
Referenced In Project/Scope: coveralls-maven-plugin:provided
maven-builder-support-3.9.16.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.maven/maven-core@3.9.16

Identifiers

  • pkg:maven/org.apache.maven/maven-builder-support@3.9.16   (Confidence:High)

maven-core-3.9.16.jar

Description:

Maven Core classes.

File Path: C:\Users\Jeremy\.m2\repository\org\apache\maven\maven-core\3.9.16\maven-core-3.9.16.jar
MD5: 045855e32be6ef1727118a7dcb9af9fe
SHA1: 1f2b4176f1395310a9bce323919189cec51f7115
SHA256:5d45c72e3dbfab8b68d15ad4f12777b7d9b5fe4d4adc99c3bd51fb9641fab009
Referenced In Project/Scope: coveralls-maven-plugin:provided
maven-core-3.9.16.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.hazendaz.maven/coveralls-maven-plugin@5.1.0

Identifiers

maven-model-3.9.16.jar

Description:

Model for Maven POM (Project Object Model)

File Path: C:\Users\Jeremy\.m2\repository\org\apache\maven\maven-model\3.9.16\maven-model-3.9.16.jar
MD5: 15ea34610d5c8d1944fc4ba317c6b4cd
SHA1: 6f93dbc874ef321b0c3734dee41a6d17e18ceebd
SHA256:f59d86a507c241bf17bbf050050d1b8b9c0d34d5010a7e2386c3cab7c83b93de
Referenced In Project/Scope: coveralls-maven-plugin:provided
maven-model-3.9.16.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.hazendaz.maven/coveralls-maven-plugin@5.1.0

Identifiers

  • pkg:maven/org.apache.maven/maven-model@3.9.16   (Confidence:High)

maven-model-builder-3.9.16.jar

Description:

The effective model builder, with inheritance, profile activation, interpolation, ...

File Path: C:\Users\Jeremy\.m2\repository\org\apache\maven\maven-model-builder\3.9.16\maven-model-builder-3.9.16.jar
MD5: 114db488c69246d1b371b4c203801b3a
SHA1: eb7a9ca8cc2d61d7c6430dd2ee16f71628b2046d
SHA256:002be86d1f53b36f559a0786034a17598d71087f1935f205a1f9e51d4dd124b3
Referenced In Project/Scope: coveralls-maven-plugin:provided
maven-model-builder-3.9.16.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.maven/maven-core@3.9.16

Identifiers

  • pkg:maven/org.apache.maven/maven-model-builder@3.9.16   (Confidence:High)

maven-plugin-annotations-3.15.2.jar

Description:

Java annotations to use in Mojos

File Path: C:\Users\Jeremy\.m2\repository\org\apache\maven\plugin-tools\maven-plugin-annotations\3.15.2\maven-plugin-annotations-3.15.2.jar
MD5: 6b86f30960ce2f9eac20c6657db588a2
SHA1: dfc79f3b5b0c3afd01f55b8b01310f457568d2a4
SHA256:979d3cf8f4ac804cc27d2f8a6db07f2149d58ccd59bb3d589cc46bb9a44c0b4b
Referenced In Project/Scope: coveralls-maven-plugin:compile
maven-plugin-annotations-3.15.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.hazendaz.maven/coveralls-maven-plugin@5.1.0

Identifiers

  • pkg:maven/org.apache.maven.plugin-tools/maven-plugin-annotations@3.15.2   (Confidence:High)

maven-plugin-api-3.9.16.jar

Description:

The API for plugins - Mojos - development.

File Path: C:\Users\Jeremy\.m2\repository\org\apache\maven\maven-plugin-api\3.9.16\maven-plugin-api-3.9.16.jar
MD5: bcb853f9daa463ff30dcf96d96bcbb06
SHA1: 4509ebc6c30856368a5786859342eef9b43ab27a
SHA256:37cb5e483e23327cf4ba18f920b45e000d20eec0428a086a5c1bd6bbdecf088c
Referenced In Project/Scope: coveralls-maven-plugin:provided
maven-plugin-api-3.9.16.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.hazendaz.maven/coveralls-maven-plugin@5.1.0

Identifiers

  • pkg:maven/org.apache.maven/maven-plugin-api@3.9.16   (Confidence:High)

maven-repository-metadata-3.9.16.jar

Description:

Per-directory local and remote repository metadata.

File Path: C:\Users\Jeremy\.m2\repository\org\apache\maven\maven-repository-metadata\3.9.16\maven-repository-metadata-3.9.16.jar
MD5: df9e6c18b95541ac7585f7d213d459af
SHA1: d2013b76825de9d844d5894e17fb4a894e8e8ae1
SHA256:bc3dd413b89a16b695f35a5d0496b58ea2787c30b7b6062c130d24d6d764720f
Referenced In Project/Scope: coveralls-maven-plugin:provided
maven-repository-metadata-3.9.16.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.maven/maven-core@3.9.16

Identifiers

  • pkg:maven/org.apache.maven/maven-repository-metadata@3.9.16   (Confidence:High)

maven-resolver-api-1.9.27.jar

Description:

The application programming interface for the repository system.

License:

"Apache-2.0";link="https://www.apache.org/licenses/LICENSE-2.0.txt"
File Path: C:\Users\Jeremy\.m2\repository\org\apache\maven\resolver\maven-resolver-api\1.9.27\maven-resolver-api-1.9.27.jar
MD5: c7bd6f04c52f098ba934742bb204cb5e
SHA1: 2fe7e86e3c193121789470507cf4fadd5bd7ad59
SHA256:a895d222283666a7320ddc76615e2e93a41fabd93ce9a6bf9ddee39272bb87b4
Referenced In Project/Scope: coveralls-maven-plugin:provided
maven-resolver-api-1.9.27.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.maven/maven-core@3.9.16

Identifiers

  • pkg:maven/org.apache.maven.resolver/maven-resolver-api@1.9.27   (Confidence:High)

maven-resolver-impl-1.9.27.jar

Description:

An implementation of the repository system.

License:

"Apache-2.0";link="https://www.apache.org/licenses/LICENSE-2.0.txt"
File Path: C:\Users\Jeremy\.m2\repository\org\apache\maven\resolver\maven-resolver-impl\1.9.27\maven-resolver-impl-1.9.27.jar
MD5: 37de3b6f62504d03fb281c533de98d4a
SHA1: 876fc89223d9572cade60a1b8158846724548d07
SHA256:295d48ea2a8bb3aef51888967f105fb6251997d111f13c32d28919fd9b1c951e
Referenced In Project/Scope: coveralls-maven-plugin:provided
maven-resolver-impl-1.9.27.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.maven/maven-core@3.9.16

Identifiers

  • pkg:maven/org.apache.maven.resolver/maven-resolver-impl@1.9.27   (Confidence:High)

maven-resolver-named-locks-1.9.27.jar

Description:

A synchronization utility implementation using Named locks.

License:

"Apache-2.0";link="https://www.apache.org/licenses/LICENSE-2.0.txt"
File Path: C:\Users\Jeremy\.m2\repository\org\apache\maven\resolver\maven-resolver-named-locks\1.9.27\maven-resolver-named-locks-1.9.27.jar
MD5: 7bbb9ba859aa1ac04280422f0520b9eb
SHA1: 72c89ad87be374309a7308ee144949360ed482e8
SHA256:b39ecd4da98fdac5068e6f5d16910a71f4e4d48e95e17d107f6603e18f2b3fdf
Referenced In Project/Scope: coveralls-maven-plugin:provided
maven-resolver-named-locks-1.9.27.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.maven/maven-core@3.9.16

Identifiers

  • pkg:maven/org.apache.maven.resolver/maven-resolver-named-locks@1.9.27   (Confidence:High)

maven-resolver-provider-3.9.16.jar

Description:

Extensions to Maven Resolver for utilizing Maven POM and repository metadata.

File Path: C:\Users\Jeremy\.m2\repository\org\apache\maven\maven-resolver-provider\3.9.16\maven-resolver-provider-3.9.16.jar
MD5: 476c028745a99d6492386f7e6d7d4471
SHA1: 92faacf3d46fe4b971689b4839b0d9aaf438ce48
SHA256:72a2d6aad3708e2c708b659b292ae9587a4d170ec88f48466290318730221118
Referenced In Project/Scope: coveralls-maven-plugin:provided
maven-resolver-provider-3.9.16.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.maven/maven-core@3.9.16

Identifiers

  • pkg:maven/org.apache.maven/maven-resolver-provider@3.9.16   (Confidence:High)

maven-resolver-spi-1.9.27.jar

Description:

The service provider interface for repository system implementations and repository connectors.

License:

"Apache-2.0";link="https://www.apache.org/licenses/LICENSE-2.0.txt"
File Path: C:\Users\Jeremy\.m2\repository\org\apache\maven\resolver\maven-resolver-spi\1.9.27\maven-resolver-spi-1.9.27.jar
MD5: ef88eaf44762342c8322924955e3c333
SHA1: fb64e47acdc73f938b4d5b6464ef7a6351f983d5
SHA256:1cab02f45bc58d5f4d8e084eaf032f13ea1a5fc9021d8bd74f8360ebb6593e5a
Referenced In Project/Scope: coveralls-maven-plugin:provided
maven-resolver-spi-1.9.27.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.maven/maven-core@3.9.16

Identifiers

  • pkg:maven/org.apache.maven.resolver/maven-resolver-spi@1.9.27   (Confidence:High)

maven-resolver-util-1.9.27.jar

Description:

A collection of utility classes to ease usage of the repository system.

License:

"Apache-2.0";link="https://www.apache.org/licenses/LICENSE-2.0.txt"
File Path: C:\Users\Jeremy\.m2\repository\org\apache\maven\resolver\maven-resolver-util\1.9.27\maven-resolver-util-1.9.27.jar
MD5: 0d792ab540b382fc240c3529d5b6e88e
SHA1: 7ee4446af6aab27475765ec9c9dc1fb2b082af2b
SHA256:74a12548f0d6aad13c728666288c1e81201c24bd05bb4e4ec8c1558517b379a7
Referenced In Project/Scope: coveralls-maven-plugin:provided
maven-resolver-util-1.9.27.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.maven/maven-core@3.9.16

Identifiers

  • pkg:maven/org.apache.maven.resolver/maven-resolver-util@1.9.27   (Confidence:High)

maven-settings-3.9.16.jar

Description:

Maven Settings model.

File Path: C:\Users\Jeremy\.m2\repository\org\apache\maven\maven-settings\3.9.16\maven-settings-3.9.16.jar
MD5: 46ffb3627f87c3b798829a41960f9fe9
SHA1: ab466fe1cb5b80d1b5e6f6b5ba3f87dfc56f75b6
SHA256:322ae5b23f4b7b6ce7896bd33a793143dbbbbcc16c4475e2d7eebbd8f755da92
Referenced In Project/Scope: coveralls-maven-plugin:provided
maven-settings-3.9.16.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.hazendaz.maven/coveralls-maven-plugin@5.1.0

Identifiers

  • pkg:maven/org.apache.maven/maven-settings@3.9.16   (Confidence:High)

maven-settings-builder-3.9.16.jar

Description:

The effective settings builder, with inheritance and password decryption.

File Path: C:\Users\Jeremy\.m2\repository\org\apache\maven\maven-settings-builder\3.9.16\maven-settings-builder-3.9.16.jar
MD5: bd711f14681dc719b1ca8c883912014b
SHA1: 31321459aee3dd0a12d72a9fb71bfac31b0fb529
SHA256:226f1cbb0b4d414eff773fb151a8977837c98073e14d5963794e6cf464e6adbb
Referenced In Project/Scope: coveralls-maven-plugin:provided
maven-settings-builder-3.9.16.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.maven/maven-core@3.9.16

Identifiers

  • pkg:maven/org.apache.maven/maven-settings-builder@3.9.16   (Confidence:High)

maven-shared-utils-3.4.2.jar

Description:

Shared utilities for use by Maven core and plugins

File Path: C:\Users\Jeremy\.m2\repository\org\apache\maven\shared\maven-shared-utils\3.4.2\maven-shared-utils-3.4.2.jar
MD5: 53a038f77a81cb5816ad2b1c7daa8711
SHA1: bfa28296272a5915b08de9f11f34a94b0a818fd0
SHA256:b613357e1bad4dfc1dead801691c9460f9585fe7c6b466bc25186212d7d18487
Referenced In Project/Scope: coveralls-maven-plugin:provided
maven-shared-utils-3.4.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.maven/maven-core@3.9.16

Identifiers

modernizer-maven-annotations-3.4.0.jar

File Path: C:\Users\Jeremy\.m2\repository\org\gaul\modernizer-maven-annotations\3.4.0\modernizer-maven-annotations-3.4.0.jar
MD5: f46f4c747b5ab932252fea7d0733cc04
SHA1: 9deb15aa2a3a725be971c8bbb4b560d0d096fca9
SHA256:c3ca20a7ccb295f528642532fc7644b4e822a45746fe8bf1683227ca1d0ddfa9
Referenced In Project/Scope: coveralls-maven-plugin:provided
modernizer-maven-annotations-3.4.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.hazendaz.maven/coveralls-maven-plugin@5.1.0

Identifiers

  • pkg:maven/org.gaul/modernizer-maven-annotations@3.4.0   (Confidence:High)

org.eclipse.jgit-6.10.1.202505221210-r.jar

Description:

    Repository access and algorithms
  

File Path: C:\Users\Jeremy\.m2\repository\org\eclipse\jgit\org.eclipse.jgit\6.10.1.202505221210-r\org.eclipse.jgit-6.10.1.202505221210-r.jar
MD5: 9ed41b6326929cddee8317087cc74367
SHA1: f2b9b9ff8e591a7ce5dca87631cbd5c45d7bdf53
SHA256:8f0135ca45d00c4da8e7ba2e96d44e1ade452bf279d79ca4eb54921e8f27952c
Referenced In Project/Scope: coveralls-maven-plugin:compile
org.eclipse.jgit-6.10.1.202505221210-r.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.hazendaz.maven/coveralls-maven-plugin@5.1.0

Identifiers

CVE-2025-4949  

In Eclipse JGit versions 7.2.0.202503040940-r and older, the ManifestParser class used by the repo command and the AmazonS3 class used to implement the experimental amazons3 git transport protocol allowing to store git pack files in an Amazon S3 bucket, are vulnerable to XML External Entity (XXE) attacks when parsing XML files. This vulnerability can lead to information disclosure, denial of service, and other security issues.
CWE-611 Improper Restriction of XML External Entity Reference, CWE-827 Improper Control of Document Type Definition

CVSSv4:
  • Base Score: MEDIUM (6.8)
  • Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:D/RE:L/U:Green
CVSSv3:
  • Base Score: MEDIUM (5.3)
  • Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H/E:P/RC:R/MAV:A

References:

Vulnerable Software & Versions: (show all)

org.eclipse.sisu.inject-1.0.0.jar

Description:

JSR330-based container; supports classpath scanning, auto-binding, and dynamic auto-wiring

License:

Eclipse Public License, Version 2.0;link="https://www.eclipse.org/legal/epl-v20.html"
File Path: C:\Users\Jeremy\.m2\repository\org\eclipse\sisu\org.eclipse.sisu.inject\1.0.0\org.eclipse.sisu.inject-1.0.0.jar
MD5: 9d66e7450d82f2070a1422de1ebd4c81
SHA1: d9c2d6ff4b461ab9492edb1cd9d8239cfb41f4ca
SHA256:3ab8d7bfe68f3b6ec95c1a0a47e628edbc9d76e90634cb0a0ba121fbb11b8e42
Referenced In Project/Scope: coveralls-maven-plugin:provided
org.eclipse.sisu.inject-1.0.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.maven/maven-core@3.9.16

Identifiers

  • pkg:maven/org.eclipse.sisu/org.eclipse.sisu.inject@1.0.0   (Confidence:High)

org.eclipse.sisu.plexus-1.0.0.jar

Description:

Plexus-JSR330 adapter; adds Plexus support to the Sisu-Inject container

License:

Eclipse Public License, Version 2.0;link="https://www.eclipse.org/legal/epl-v20.html"
File Path: C:\Users\Jeremy\.m2\repository\org\eclipse\sisu\org.eclipse.sisu.plexus\1.0.0\org.eclipse.sisu.plexus-1.0.0.jar
MD5: fb07aece41f034fea46b022e2756cd7c
SHA1: 873767e95597c9e31749123a408bd4949c29a46c
SHA256:865b5300034fc08c790215d7d97f141914c932191bef9338a7dcef589f7536e9
Referenced In Project/Scope: coveralls-maven-plugin:provided
org.eclipse.sisu.plexus-1.0.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.maven/maven-core@3.9.16

Identifiers

  • pkg:maven/org.eclipse.sisu/org.eclipse.sisu.plexus@1.0.0   (Confidence:High)

plexus-cipher-2.0.jar

File Path: C:\Users\Jeremy\.m2\repository\org\codehaus\plexus\plexus-cipher\2.0\plexus-cipher-2.0.jar
MD5: 55d612839faf248cbe3e273969c002c2
SHA1: 425ea8e534716b4bff1ea90f39bd76be951d651b
SHA256:9a7f1b5c5a9effd61eadfd8731452a2f76a8e79111fac391ef75ea801bea203a
Referenced In Project/Scope: coveralls-maven-plugin:provided
plexus-cipher-2.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.maven/maven-core@3.9.16

Identifiers

  • pkg:maven/org.codehaus.plexus/plexus-cipher@2.0   (Confidence:High)

plexus-classworlds-2.11.0.jar

Description:

A class loader framework

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Jeremy\.m2\repository\org\codehaus\plexus\plexus-classworlds\2.11.0\plexus-classworlds-2.11.0.jar
MD5: 54d5f4e0835c5e53f08a494f08d2a75d
SHA1: 6586ba9f3137d7ac7b9789f1fcf7c4e192482905
SHA256:8971f135490070bc5fde7413fcc8db7c997fda4bebfb5c31185900d66edcbbb2
Referenced In Project/Scope: coveralls-maven-plugin:provided
plexus-classworlds-2.11.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.maven/maven-core@3.9.16

Identifiers

  • pkg:maven/org.codehaus.plexus/plexus-classworlds@2.11.0   (Confidence:High)

plexus-component-annotations-2.2.0.jar

Description:

Plexus Component Java Annotations, to describe plexus components properties in java sources with
    standard annotations instead of javadoc annotations.

File Path: C:\Users\Jeremy\.m2\repository\org\codehaus\plexus\plexus-component-annotations\2.2.0\plexus-component-annotations-2.2.0.jar
MD5: a2397189a5ce25e7d2d44effa9f5176c
SHA1: a506f84636ea7ae370d04167dd155c103e616f68
SHA256:50edb93c73786e62822b4fe1336e22880fdf147191373cf5c911370e16748fcf
Referenced In Project/Scope: coveralls-maven-plugin:provided
plexus-component-annotations-2.2.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.maven/maven-core@3.9.16

Identifiers

  • pkg:maven/org.codehaus.plexus/plexus-component-annotations@2.2.0   (Confidence:High)

plexus-interpolation-1.29.jar

Description:

The Plexus project provides a full software stack for creating and executing software projects.

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Jeremy\.m2\repository\org\codehaus\plexus\plexus-interpolation\1.29\plexus-interpolation-1.29.jar
MD5: b1489e6968b874cecfe24cadb62b77db
SHA1: 5dd1b1fbaca263ad5baa169fbd8e804c789c9db5
SHA256:088d444dbcedfb384630d8686697ece3c401d6f33c8f8b3aa7259ea1c6996878
Referenced In Project/Scope: coveralls-maven-plugin:provided
plexus-interpolation-1.29.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.maven/maven-core@3.9.16

Identifiers

  • pkg:maven/org.codehaus.plexus/plexus-interpolation@1.29   (Confidence:High)

plexus-sec-dispatcher-2.0.jar

File Path: C:\Users\Jeremy\.m2\repository\org\codehaus\plexus\plexus-sec-dispatcher\2.0\plexus-sec-dispatcher-2.0.jar
MD5: e68635a721630177ac70173e441336b6
SHA1: f89c5080614ffd0764e49861895dbedde1b47237
SHA256:873139960c4c780176dda580b003a2c4bf82188bdce5bb99234e224ef7acfceb
Referenced In Project/Scope: coveralls-maven-plugin:provided
plexus-sec-dispatcher-2.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.apache.maven/maven-core@3.9.16

Identifiers

plexus-utils-4.0.3.jar

Description:

A collection of various utility classes to ease working with strings, files, command lines and
    more.

License:

Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: C:\Users\Jeremy\.m2\repository\org\codehaus\plexus\plexus-utils\4.0.3\plexus-utils-4.0.3.jar
MD5: a8848eea66d01d0279b26871dbc2cf1b
SHA1: c097bf60a8a7aaf37dfb8f2c933a21e784035976
SHA256:421ff6ed146c53a9d4eaade8f629b52b12af7187101f1bd06c2c64e904019f3c
Referenced In Project/Scope: coveralls-maven-plugin:compile
plexus-utils-4.0.3.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.hazendaz.maven/coveralls-maven-plugin@5.1.0

Identifiers

plexus-xml-3.0.2.jar

Description:

A collection of various utility classes to ease working with XML in Maven 3.

File Path: C:\Users\Jeremy\.m2\repository\org\codehaus\plexus\plexus-xml\3.0.2\plexus-xml-3.0.2.jar
MD5: e2feab7a114ac4a144632670734db7e4
SHA1: 70c207ae478a5011a14dcefe56f4bbda16e3bc87
SHA256:6a49fe0c49a06b5bcd6073ff16580fcb0dd87c50295e97a9fa9f95619b69921c
Referenced In Project/Scope: coveralls-maven-plugin:compile
plexus-xml-3.0.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.hazendaz.maven/coveralls-maven-plugin@5.1.0

Identifiers

  • pkg:maven/org.codehaus.plexus/plexus-xml@3.0.2   (Confidence:High)

slf4j-api-2.0.18.jar

Description:

The slf4j API

License:

https://opensource.org/license/mit
File Path: C:\Users\Jeremy\.m2\repository\org\slf4j\slf4j-api\2.0.18\slf4j-api-2.0.18.jar
MD5: fe2837bd49bfb76657419002fed20ca9
SHA1: 78a9e7a37cd6360e0b818e86341b24123d28d4df
SHA256:44508fd1576500688c790b190acdd16fec4f8c79a3e0b900afd70503cf055f55
Referenced In Project/Scope: coveralls-maven-plugin:compile
slf4j-api-2.0.18.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.eclipse.jgit/org.eclipse.jgit@6.10.1.202505221210-r

Identifiers

  • pkg:maven/org.slf4j/slf4j-api@2.0.18   (Confidence:High)

spotbugs-annotations-4.9.8.jar

Description:

Annotations the SpotBugs tool supports

License:

GNU LESSER GENERAL PUBLIC LICENSE, Version 2.1: https://www.gnu.org/licenses/old-licenses/lgpl-2.1.en.html
File Path: C:\Users\Jeremy\.m2\repository\com\github\spotbugs\spotbugs-annotations\4.9.8\spotbugs-annotations-4.9.8.jar
MD5: d4c2e7bd090be697ad409a4e75684a94
SHA1: ca4a2783a6123e67124fd7feb4caccd2e2ac9a73
SHA256:6f69d6fe9c55a54dcb30e87d8fa2d5f52246af50d7a3445246d9539ef221be1c
Referenced In Project/Scope: coveralls-maven-plugin:provided
spotbugs-annotations-4.9.8.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.github.hazendaz.maven/coveralls-maven-plugin@5.1.0

Identifiers

  • pkg:maven/com.github.spotbugs/spotbugs-annotations@4.9.8   (Confidence:High)


This report contains data retrieved from the National Vulnerability Database.
This report may contain data retrieved from the CISA Known Exploited Vulnerability Catalog.
This report may contain data retrieved from the Github Advisory Database (via NPM Audit API).
This report may contain data retrieved from RetireJS.
This report may contain data retrieved from the Sonatype Guide OSS Index API.