Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.

How to read the report | Suppressing false positives | Getting Help: github issues

 Sponsor

Project: API

org.dynamoframework:dynamo-api:4.0.0-RC2

Scan Information (show all):

Summary

Display: Showing Vulnerable Dependencies (click to show all)

DependencyVulnerability IDsPackageHighest SeverityCVE CountConfidenceEvidence Count
classgraph-4.8.146.jarpkg:maven/io.github.classgraph/classgraph@4.8.146 042
codegen-utils-5.1.0.jarcpe:2.3:a:utils_project:utils:5.1.0:*:*:*:*:*:*:*pkg:maven/com.querydsl/codegen-utils@5.1.0 0Highest37
ecj-3.26.0.jarpkg:maven/org.eclipse.jdt/ecj@3.26.0 030
jakarta.persistence-api-3.1.0.jarpkg:maven/jakarta.persistence/jakarta.persistence-api@3.1.0 040
javax.inject-1.jarpkg:maven/javax.inject/javax.inject@1 020
lombok-1.18.34.jarpkg:maven/org.projectlombok/lombok@1.18.34 036
lombok-1.18.34.jar: mavenEcjBootstrapAgent.jar 07
mysema-commons-lang-0.2.4.jarpkg:maven/com.mysema.commons/mysema-commons-lang@0.2.4 026
querydsl-apt-5.1.0-jakarta.jarpkg:maven/com.querydsl/querydsl-apt@5.1.0 020
querydsl-core-5.1.0.jarcpe:2.3:a:homepage_project:homepage:5.1.0:*:*:*:*:*:*:*pkg:maven/com.querydsl/querydsl-core@5.1.0 0Low23
querydsl-jpa-5.1.0-jakarta.jarpkg:maven/com.querydsl/querydsl-jpa@5.1.0 023
slf4j-api-2.0.16.jarpkg:maven/org.slf4j/slf4j-api@2.0.16 029

Dependencies (vulnerable)

classgraph-4.8.146.jar

Description:

The uber-fast, ultra-lightweight classpath and module scanner for JVM languages.

License:

The MIT License (MIT): http://opensource.org/licenses/MIT
File Path: /Users/tommym/.m2/repository/io/github/classgraph/classgraph/4.8.146/classgraph-4.8.146.jar
MD5: a4ed4fa2653c6540980aa06511ba3764
SHA1: 360448a09bfa5689d89cfa97fea53b3fdefa9c23
SHA256:184b8319c463656672e3480dead3bdb77d7b116d55f3a618f4f5564e8f6fa0a4
Referenced In Project/Scope: API:provided
classgraph-4.8.146.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.querydsl/querydsl-apt@5.1.0

Identifiers

codegen-utils-5.1.0.jar

Description:

Code generation and compilation for Java

License:

Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /Users/tommym/.m2/repository/com/querydsl/codegen-utils/5.1.0/codegen-utils-5.1.0.jar
MD5: 850fa8089ead3bb0a4254ad9aea16ced
SHA1: ba401554d613760617992eafb6cdba175c811e6f
SHA256:0633634e74fb716ea998d9d31c99c8dc6c24ea6e906046f2fc4707148ac58888
Referenced In Project/Scope: API:provided
codegen-utils-5.1.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.querydsl/querydsl-apt@5.1.0

Identifiers

ecj-3.26.0.jar

Description:

Eclipse Compiler for Java(TM)

License:

Eclipse Public License - v 2.0: https://www.eclipse.org/legal/epl-2.0/
File Path: /Users/tommym/.m2/repository/org/eclipse/jdt/ecj/3.26.0/ecj-3.26.0.jar
MD5: ee47966a67cd4019f1b8ccac74ba8dca
SHA1: 4837be609a3368a0f7e7cf0dc1bdbc7fe94993de
SHA256:ac0ba5876eaf7ebb47749a0d1be179c51f194b9dd0b875d1c09e1b530f5a2db5
Referenced In Project/Scope: API:provided
ecj-3.26.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.querydsl/querydsl-apt@5.1.0

Identifiers

jakarta.persistence-api-3.1.0.jar

Description:

Jakarta Persistence 3.1 API jar

License:

Eclipse Public License v. 2.0: http://www.eclipse.org/legal/epl-2.0
Eclipse Distribution License v. 1.0: http://www.eclipse.org/org/documents/edl-v10.php
File Path: /Users/tommym/.m2/repository/jakarta/persistence/jakarta.persistence-api/3.1.0/jakarta.persistence-api-3.1.0.jar
MD5: 35a1b7dfb38cf44ff795be607b0e6b5b
SHA1: 66901fa1c373c6aff65c13791cc11da72060a8d6
SHA256:475389446d35c6f46c565728b756dc508c284644ea2690644e0d8e7e339d42fd
Referenced In Project/Scope: API:provided
jakarta.persistence-api-3.1.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.dynamoframework/dynamo-api@4.0.0-RC2

Identifiers

javax.inject-1.jar

Description:

The javax.inject API

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /Users/tommym/.m2/repository/javax/inject/javax.inject/1/javax.inject-1.jar
MD5: 289075e48b909e9e74e6c915b3631d2e
SHA1: 6975da39a7040257bd51d21a231b76c915872d38
SHA256:91c77044a50c481636c32d916fd89c9118a72195390452c81065080f957de7ff
Referenced In Project/Scope: API:provided
javax.inject-1.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.querydsl/querydsl-apt@5.1.0

Identifiers

lombok-1.18.34.jar

Description:

Spice up your java: Automatic Resource Management, automatic generation of getters, setters, equals, hashCode and toString, and more!

License:

The MIT License: https://projectlombok.org/LICENSE
File Path: /Users/tommym/.m2/repository/org/projectlombok/lombok/1.18.34/lombok-1.18.34.jar
MD5: 91ce91dbfa7694bff4ddc1e51643f8b2
SHA1: ec547ef414ab1d2c040118fb9c1c265ada63af14
SHA256:c27d6b2aff56241d1b07fcbcc6b183709e6b432c80f7374eeb1d823e86d4b81a
Referenced In Project/Scope: API:compile
lombok-1.18.34.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.dynamoframework/dynamo-api@4.0.0-RC2

Identifiers

lombok-1.18.34.jar: mavenEcjBootstrapAgent.jar

File Path: /Users/tommym/.m2/repository/org/projectlombok/lombok/1.18.34/lombok-1.18.34.jar/lombok/launch/mavenEcjBootstrapAgent.jar
MD5: e5552f93605e20eb4039662ee38ee41a
SHA1: 257946794d3fbaff9023c991de99d6b7a7be8c8d
SHA256:7f93cde1d476e8d84f51213c52d70eb596fcde669fbd30fbd5a6745346fdde9d
Referenced In Project/Scope: API:compile

Identifiers

  • None

mysema-commons-lang-0.2.4.jar

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /Users/tommym/.m2/repository/com/mysema/commons/mysema-commons-lang/0.2.4/mysema-commons-lang-0.2.4.jar
MD5: c13bde1d0dae26b8ca3c56b5e4e40157
SHA1: d09c8489d54251a6c22fbce804bdd4a070557317
SHA256:dbbdd6816b33d3bead50f4d217825fcf568d50a43af881df5cdd01468c2b6efe
Referenced In Project/Scope: API:compile
mysema-commons-lang-0.2.4.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.querydsl/querydsl-jpa@5.1.0

Identifiers

querydsl-apt-5.1.0-jakarta.jar

Description:

APT based Source code generation for Querydsl

File Path: /Users/tommym/.m2/repository/com/querydsl/querydsl-apt/5.1.0/querydsl-apt-5.1.0-jakarta.jar
MD5: 75ada87133b15a7070113651dacc7499
SHA1: 3b1cbe05851840b5dc926833908747a193c097cc
SHA256:9b0e0f18205930ce1e21ab03758c46c069b92d4418956bf8468d85887cd2dfef
Referenced In Project/Scope: API:provided
querydsl-apt-5.1.0-jakarta.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.dynamoframework/dynamo-api@4.0.0-RC2

Identifiers

querydsl-core-5.1.0.jar

Description:

core module for querydsl

File Path: /Users/tommym/.m2/repository/com/querydsl/querydsl-core/5.1.0/querydsl-core-5.1.0.jar
MD5: 2c9349a570cc9b090e44a22bff6be406
SHA1: be322c3fe98de8e7c204afb8860bfabd81a3bafd
SHA256:57a3033ddbb4d928552b33443be7195bc3caba6fa85cd9a492bc874a5ef98c8e
Referenced In Project/Scope: API:compile
querydsl-core-5.1.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.querydsl/querydsl-jpa@5.1.0

Identifiers

querydsl-jpa-5.1.0-jakarta.jar

Description:

JPA support for Querydsl

File Path: /Users/tommym/.m2/repository/com/querydsl/querydsl-jpa/5.1.0/querydsl-jpa-5.1.0-jakarta.jar
MD5: 54dae173af07a330f1a80cc48b0e02f3
SHA1: f44ee79a324cf92d6821eca736b2028e69542050
SHA256:01b064b511e093ceff2a8698829354b4fb1dc08f576e405dd6dfa8ab35736ca2
Referenced In Project/Scope: API:compile
querydsl-jpa-5.1.0-jakarta.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.dynamoframework/dynamo-api@4.0.0-RC2

Identifiers

slf4j-api-2.0.16.jar

Description:

The slf4j API

License:

http://www.opensource.org/licenses/mit-license.php
File Path: /Users/tommym/.m2/repository/org/slf4j/slf4j-api/2.0.16/slf4j-api-2.0.16.jar
MD5: c8de8f5d740584cb24b5652cfba8b3c4
SHA1: 0172931663a09a1fa515567af5fbef00897d3c04
SHA256:a12578dde1ba00bd9b816d388a0b879928d00bab3c83c240f7013bf4196c579a
Referenced In Project/Scope: API:compile
slf4j-api-2.0.16.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.dynamoframework/dynamo-api@4.0.0-RC2

Identifiers



This report contains data retrieved from the National Vulnerability Database.
This report may contain data retrieved from the CISA Known Exploited Vulnerability Catalog.
This report may contain data retrieved from the Github Advisory Database (via NPM Audit API).
This report may contain data retrieved from RetireJS.
This report may contain data retrieved from the Sonatype OSS Index.