Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.

How to read the report | Suppressing false positives | Getting Help: github issues

 Sponsor

Project: java-random

com.namics.oss:java-random:1.3.0

Scan Information (show all):

Summary

Display: Showing Vulnerable Dependencies (click to show all)

DependencyVulnerability IDsPackageHighest SeverityCVE CountConfidenceEvidence Count
commons-lang-2.6.jarpkg:maven/commons-lang/commons-lang@2.6 0122
gentyref-1.2.0.jarpkg:maven/com.googlecode.gentyref/gentyref@1.2.0 024
javassist-3.28.0-GA.jarpkg:maven/org.javassist/javassist@3.28.0-GA 056
joda-time-2.10.10.jarpkg:maven/joda-time/joda-time@2.10.10 047
jsr305-3.0.2.jarpkg:maven/com.google.code.findbugs/jsr305@3.0.2 017
reflections-0.10.2.jarpkg:maven/org.reflections/reflections@0.10.2 025
slf4j-api-1.7.32.jarpkg:maven/org.slf4j/slf4j-api@1.7.32 027

Dependencies (vulnerable)

commons-lang-2.6.jar

Description:

        Commons Lang, a package of Java utility classes for the
        classes that are in java.lang's hierarchy, or are considered to be so
        standard as to justify existence in java.lang.
    

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/commons-lang/commons-lang/2.6/commons-lang-2.6.jar
MD5: 4d5c1693079575b362edf41500630bbd
SHA1: 0ce1edb914c94ebc388f086c6827e8bdeec71ac2
SHA256:50f11b09f877c294d56f24463f47d28f929cf5044f648661c0f0cfbae9a2f49c
Referenced In Project/Scope: java-random:compile
commons-lang-2.6.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.namics.oss/java-random@1.3.0

Identifiers

gentyref-1.2.0.jar

Description:

Generic type reflection library

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/googlecode/gentyref/gentyref/1.2.0/gentyref-1.2.0.jar
MD5: e907b55db6feacd0ba989f72dea8d7e3
SHA1: 8d776d0a52d707fa29c7449ddd4d102ac7002d6c
SHA256:383672c11afc3f3d69e3c7d630983c0e6c0d643ca2b0e42db8e1c146406239aa
Referenced In Project/Scope: java-random:compile
gentyref-1.2.0.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.namics.oss/java-random@1.3.0

Identifiers

javassist-3.28.0-GA.jar

Description:

  	Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation
    simple.  It is a class library for editing bytecodes in Java.
  

License:

MPL 1.1: http://www.mozilla.org/MPL/MPL-1.1.html
LGPL 2.1: http://www.gnu.org/licenses/lgpl-2.1.html
Apache License 2.0: http://www.apache.org/licenses/
File Path: /home/runner/.m2/repository/org/javassist/javassist/3.28.0-GA/javassist-3.28.0-GA.jar
MD5: 1a2dd8c76321cef26cc2669fe70a2557
SHA1: 9a958811a88381bb159cc2f5ed79c34a45c4af7a
SHA256:57d0a9e9286f82f4eaa851125186997f811befce0e2060ff0a15a77f5a9dd9a7
Referenced In Project/Scope: java-random:compile
javassist-3.28.0-GA.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.reflections/reflections@0.10.2

Identifiers

joda-time-2.10.10.jar

Description:

Date and time library to replace JDK date handling

License:

Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/joda-time/joda-time/2.10.10/joda-time-2.10.10.jar
MD5: c2a46de8a73ec7b60011429561ae72e3
SHA1: 29e8126e31f41e5c12b9fe3a7eb02e704c47d70b
SHA256:dd8e7c92185a678d1b7b933f31209b6203c8ffa91e9880475a1be0346b9617e3
Referenced In Project/Scope: java-random:compile
joda-time-2.10.10.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.namics.oss/java-random@1.3.0

Identifiers

jsr305-3.0.2.jar

Description:

JSR305 Annotations for Findbugs

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/google/code/findbugs/jsr305/3.0.2/jsr305-3.0.2.jar
MD5: dd83accb899363c32b07d7a1b2e4ce40
SHA1: 25ea2e8b0c338a877313bd4672d3fe056ea78f0d
SHA256:766ad2a0783f2687962c8ad74ceecc38a28b9f72a2d085ee438b7813e928d0c7
Referenced In Project/Scope: java-random:compile
jsr305-3.0.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/org.reflections/reflections@0.10.2

Identifiers

reflections-0.10.2.jar

Description:

Reflections - Java runtime metadata analysis

License:

WTFPL: http://www.wtfpl.net/
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/reflections/reflections/0.10.2/reflections-0.10.2.jar
MD5: 1d0070839d825f57fe6f4d8e2a82989b
SHA1: b638d7ca0e0fe0146b60a0e7ba232ad852a73b31
SHA256:938a2d08fe54050d7610b944d8ddc3a09355710d9e6be0aac838dbc04e9a2825
Referenced In Project/Scope: java-random:compile
reflections-0.10.2.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.namics.oss/java-random@1.3.0

Identifiers

slf4j-api-1.7.32.jar

Description:

The slf4j API

File Path: /home/runner/.m2/repository/org/slf4j/slf4j-api/1.7.32/slf4j-api-1.7.32.jar
MD5: fbcf58513bc25b80f075d812aad3e3cf
SHA1: cdcff33940d9f2de763bc41ea05a0be5941176c3
SHA256:3624f8474c1af46d75f98bc097d7864a323c81b3808aa43689a6e1c601c027be
Referenced In Project/Scope: java-random:compile
slf4j-api-1.7.32.jar is in the transitive dependency tree of the listed items.Included by: pkg:maven/com.namics.oss/java-random@1.3.0

Identifiers



This report contains data retrieved from the National Vulnerability Database.
This report may contain data retrieved from the CISA Known Exploited Vulnerability Catalog.
This report may contain data retrieved from the Github Advisory Database (via NPM Audit API).
This report may contain data retrieved from RetireJS.
This report may contain data retrieved from the Sonatype OSS Index.