Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 12.1.6Report Generated On : Thu, 5 Feb 2026 19:37:54 +0100Dependencies Scanned : 137 (94 unique)Vulnerable Dependencies : 4 Vulnerabilities Found : 5Vulnerabilities Suppressed : 0 ... NVD API Last Checked : 2026-02-05T19:01:03+01NVD API Last Modified : 2026-02-05T18:00:51ZSummary Summary of Vulnerable Dependencies (click to show all)
HikariCP-6.3.3.jarDescription:
Ultimate JDBC Connection Pool License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/com/zaxxer/HikariCP/6.3.3/HikariCP-6.3.3.jar
MD5: a5c7bb14f24a598a87118c9f73641466
SHA1: 7c5aec1e47a97ff40977e0193018865304ea9585
SHA256: 709f378c05756280939ce50fc1b1f1a53bb8e1899dc1b249f21f12703640b48b
Referenced In Project/Scope: fides-tool-ui-desktop:compile
HikariCP-6.3.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name HikariCP High Vendor jar package name hikari Highest Vendor jar package name pool Highest Vendor jar package name zaxxer Highest Vendor Manifest automatic-module-name com.zaxxer.hikari Medium Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://github.com/brettwooldridge Low Vendor Manifest bundle-symbolicname com.zaxxer.HikariCP Medium Vendor pom artifactid HikariCP Highest Vendor pom artifactid HikariCP Low Vendor pom developer email brett.wooldridge@gmail.com Low Vendor pom developer name Brett Wooldridge Medium Vendor pom groupid com.zaxxer Highest Vendor pom name HikariCP High Vendor pom organization name Zaxxer.com High Vendor pom organization url brettwooldridge Medium Vendor pom url brettwooldridge/HikariCP Highest Product file name HikariCP High Product jar package name hikari Highest Product jar package name pool Highest Product jar package name zaxxer Highest Product Manifest automatic-module-name com.zaxxer.hikari Medium Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://github.com/brettwooldridge Low Product Manifest Bundle-Name HikariCP Medium Product Manifest bundle-symbolicname com.zaxxer.HikariCP Medium Product pom artifactid HikariCP Highest Product pom developer email brett.wooldridge@gmail.com Low Product pom developer name Brett Wooldridge Low Product pom groupid com.zaxxer Highest Product pom name HikariCP High Product pom organization name Zaxxer.com Low Product pom url brettwooldridge High Product pom url brettwooldridge/HikariCP High Version file version 6.3.3 High Version Manifest Bundle-Version 6.3.3 High Version pom version 6.3.3 Highest
SparseBitSet-1.3.jarDescription:
An efficient sparse bitset implementation for Java License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/com/zaxxer/SparseBitSet/1.3/SparseBitSet-1.3.jar
MD5: fbe27bb4c05e8719b7fff5aa71a57364
SHA1: 533eac055afe3d5f614ea95e333afd6c2bde8f26
SHA256: f76b85adb0c00721ae267b7cfde4da7f71d3121cc2160c9fc00c0c89f8c53c8a
Referenced In Project/Scope: fides-tool-ui-desktop:compile
SparseBitSet-1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name SparseBitSet High Vendor jar package name sparsebitset Highest Vendor jar package name zaxxer Highest Vendor Manifest automatic-module-name com.zaxxer.sparsebitset Medium Vendor Manifest build-jdk-spec 11 Low Vendor pom artifactid SparseBitSet Highest Vendor pom artifactid SparseBitSet Low Vendor pom developer email brett.wooldridge@gmail.com Low Vendor pom developer name Brett Wooldridge Medium Vendor pom groupid com.zaxxer Highest Vendor pom name SparseBitSet High Vendor pom organization name Zaxxer.com High Vendor pom organization url brettwooldridge/SparseBitSet Medium Vendor pom url brettwooldridge/SparseBitSet Highest Product file name SparseBitSet High Product jar package name sparsebitset Highest Product jar package name zaxxer Highest Product Manifest automatic-module-name com.zaxxer.sparsebitset Medium Product Manifest build-jdk-spec 11 Low Product pom artifactid SparseBitSet Highest Product pom developer email brett.wooldridge@gmail.com Low Product pom developer name Brett Wooldridge Low Product pom groupid com.zaxxer Highest Product pom name SparseBitSet High Product pom organization name Zaxxer.com Low Product pom url brettwooldridge/SparseBitSet High Version file version 1.3 High Version pom version 1.3 Highest
angus-activation-2.0.2.jarDescription:
Implementation License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /var/jenkins_home/.m2/repository/org/eclipse/angus/angus-activation/2.0.2/angus-activation-2.0.2.jar
MD5: 42bba74155dc773eca277ee7a16f74be
SHA1: 41f1e0ddd157c856926ed149ab837d110955a9fc
SHA256: 6dd3bcffc22bce83b07376a0e2e094e4964a3195d4118fb43e380ef35436cc1e
Referenced In Project/Scope: fides-tool-ui-desktop:runtime
angus-activation-2.0.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name angus-activation High Vendor jar package name activation Highest Vendor jar package name angus Highest Vendor jar package name eclipse Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname angus-activation Medium Vendor Manifest extension-name org.eclipse.angus Medium Vendor Manifest implementation-build-id 2.0.2-RELEASE-c08e320 Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MailcapRegistryProvider",osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MimeTypeRegistryProvider" Low Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid angus-activation Highest Vendor pom artifactid angus-activation Low Vendor pom groupid org.eclipse.angus Highest Vendor pom name Angus Activation Registries High Vendor pom parent-artifactid angus-activation-project Low Product file name angus-activation High Product jar package name activation Highest Product jar package name angus Highest Product jar package name eclipse Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Angus Activation Registries Medium Product Manifest bundle-symbolicname angus-activation Medium Product Manifest extension-name org.eclipse.angus Medium Product Manifest implementation-build-id 2.0.2-RELEASE-c08e320 Low Product Manifest Implementation-Title Angus Activation Registries High Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MailcapRegistryProvider",osgi.serviceloader;osgi.serviceloader="jakarta.activation.spi.MimeTypeRegistryProvider" Low Product Manifest specification-title Jakarta Activation Specification Medium Product pom artifactid angus-activation Highest Product pom groupid org.eclipse.angus Highest Product pom name Angus Activation Registries High Product pom parent-artifactid angus-activation-project Medium Version file version 2.0.2 High Version Manifest Bundle-Version 2.0.2 High Version pom version 2.0.2 Highest
ant-1.10.14.jarFile Path: /var/jenkins_home/.m2/repository/org/apache/ant/ant/1.10.14/ant-1.10.14.jarMD5: 263e00d844d0e4efa54440ec5ed6362aSHA1: 1edce9bbfa60dfd51f010879c78f4421dafae7a7SHA256: 4cbbd9243de4c1042d61d9a15db4c43c90ff93b16d78b39481da1c956c8e9671Referenced In Project/Scope: fides-tool-ui-desktop:providedant-1.10.14.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.apache.ant/ant-jsch@1.10.14
Evidence Type Source Name Value Confidence Vendor file name ant High Vendor jar package name ant Highest Vendor jar package name apache Highest Vendor manifest: org/apache/tools/ant/ Implementation-Vendor Apache Software Foundation Medium Vendor pom artifactid ant Highest Vendor pom artifactid ant Low Vendor pom groupid org.apache.ant Highest Vendor pom name Apache Ant Core High Vendor pom parent-artifactid ant-parent Low Vendor pom url https://ant.apache.org/ Highest Product file name ant High Product jar package name ant Highest Product jar package name apache Highest Product jar package name tools Highest Product manifest: org/apache/tools/ant/ Implementation-Title org.apache.tools.ant Medium Product manifest: org/apache/tools/ant/ Specification-Title Apache Ant Medium Product pom artifactid ant Highest Product pom groupid org.apache.ant Highest Product pom name Apache Ant Core High Product pom parent-artifactid ant-parent Medium Product pom url https://ant.apache.org/ Medium Version file version 1.10.14 High Version manifest: org/apache/tools/ant/ Implementation-Version 1.10.14 Medium Version pom version 1.10.14 Highest
Related Dependencies ant-jsch-1.10.14.jarFile Path: /var/jenkins_home/.m2/repository/org/apache/ant/ant-jsch/1.10.14/ant-jsch-1.10.14.jar MD5: 152ab4736656c9e0d634396f3f398ded SHA1: 19889add3381479dc1068eff23cfdfcea77a219d SHA256: 48a6ec154df2cf6a151452d4fa59062ae745ac8d325778ba357b2eb820d6b558 pkg:maven/org.apache.ant/ant-jsch@1.10.14 ant-launcher-1.10.14.jarFile Path: /var/jenkins_home/.m2/repository/org/apache/ant/ant-launcher/1.10.14/ant-launcher-1.10.14.jar MD5: 0e6c71b2f05383e1fb891e99f5267663 SHA1: 8d2268288496b0541a2640f2ee07fe3de1a02301 SHA256: f0909725a7a24e393888f3fbb558347abf506ce2f7ebc581ff26331b94d951a5 pkg:maven/org.apache.ant/ant-launcher@1.10.14 antlr4-runtime-4.13.0.jarDescription:
The ANTLR 4 Runtime License:
https://www.antlr.org/license.html File Path: /var/jenkins_home/.m2/repository/org/antlr/antlr4-runtime/4.13.0/antlr4-runtime-4.13.0.jar
MD5: bff95723c494b332b14575d713a65df4
SHA1: 5a02e48521624faaf5ff4d99afc88b01686af655
SHA256: bd7f7b5d07bc0b047f10915b32ca4bb1de9e57d8049098882e4453c88c076a5d
Referenced In Project/Scope: fides-tool-ui-desktop:compile
antlr4-runtime-4.13.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name antlr4-runtime High Vendor jar package name antlr Highest Vendor jar package name runtime Highest Vendor Manifest automatic-module-name org.antlr.antlr4.runtime Medium Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://www.antlr.org/ Low Vendor Manifest bundle-symbolicname org.antlr.antlr4-runtime Medium Vendor Manifest Implementation-Vendor ANTLR High Vendor pom artifactid antlr4-runtime Highest Vendor pom artifactid antlr4-runtime Low Vendor pom groupid org.antlr Highest Vendor pom name ANTLR 4 Runtime High Vendor pom parent-artifactid antlr4-master Low Product file name antlr4-runtime High Product jar package name antlr Highest Product jar package name runtime Highest Product Manifest automatic-module-name org.antlr.antlr4.runtime Medium Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://www.antlr.org/ Low Product Manifest Bundle-Name ANTLR 4 Runtime Medium Product Manifest bundle-symbolicname org.antlr.antlr4-runtime Medium Product Manifest Implementation-Title ANTLR 4 Runtime High Product pom artifactid antlr4-runtime Highest Product pom groupid org.antlr Highest Product pom name ANTLR 4 Runtime High Product pom parent-artifactid antlr4-master Medium Version file version 4.13.0 High Version Manifest Bundle-Version 4.13.0 High Version Manifest Implementation-Version 4.13.0 High Version pom version 4.13.0 Highest
aspectjweaver-1.9.24.jarDescription:
The AspectJ weaver applies aspects to Java classes. It can be used as a Java agent in order to apply load-time
weaving (LTW) during class-loading and also contains the AspectJ runtime classes. License:
Eclipse Public License - v 2.0: https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt File Path: /var/jenkins_home/.m2/repository/org/aspectj/aspectjweaver/1.9.24/aspectjweaver-1.9.24.jar
MD5: d95bb9406a5351d45a02145777b9a241
SHA1: 9b5aeb0cea9f958b9c57fb80e62996e95a3e9379
SHA256: 75e4227fb7dc5f97c3d4689cd1c2439f4db0bd18cea2fa242c4656cd93c599aa
Referenced In Project/Scope: fides-tool-ui-desktop:compile
aspectjweaver-1.9.24.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name aspectjweaver High Vendor jar package name agent Highest Vendor jar package name and Highest Vendor jar package name aspectj Highest Vendor jar package name aspects Highest Vendor jar package name ltw Highest Vendor jar package name org Highest Vendor jar package name runtime Highest Vendor jar package name weaver Highest Vendor Manifest automatic-module-name org.aspectj.weaver Medium Vendor Manifest can-redefine-classes true Low Vendor manifest: org/aspectj/weaver/ Implementation-Vendor https://www.eclipse.org/aspectj/ Medium Vendor pom artifactid aspectjweaver Highest Vendor pom artifactid aspectjweaver Low Vendor pom developer email aclement@vmware.com Low Vendor pom developer email kriegaex@aspectj.dev Low Vendor pom developer id aclement Medium Vendor pom developer id kriegaex Medium Vendor pom developer name Alexander Kriegisch Medium Vendor pom developer name Andy Clement Medium Vendor pom groupid org.aspectj Highest Vendor pom name AspectJ Weaver High Vendor pom url https://www.eclipse.org/aspectj/ Highest Product file name aspectjweaver High Product jar package name agent Highest Product jar package name and Highest Product jar package name aspectj Highest Product jar package name aspects Highest Product jar package name ltw Highest Product jar package name org Highest Product jar package name runtime Highest Product jar package name weaver Highest Product Manifest automatic-module-name org.aspectj.weaver Medium Product Manifest can-redefine-classes true Low Product manifest: org/aspectj/weaver/ Implementation-Title org.aspectj.weaver Medium Product manifest: org/aspectj/weaver/ Specification-Title AspectJ Weaver Classes Medium Product pom artifactid aspectjweaver Highest Product pom developer email aclement@vmware.com Low Product pom developer email kriegaex@aspectj.dev Low Product pom developer id aclement Low Product pom developer id kriegaex Low Product pom developer name Alexander Kriegisch Low Product pom developer name Andy Clement Low Product pom groupid org.aspectj Highest Product pom name AspectJ Weaver High Product pom url https://www.eclipse.org/aspectj/ Medium Version file version 1.9.24 High Version manifest: org/aspectj/weaver/ Implementation-Version 1.9.24 Medium Version pom version 1.9.24 Highest
batik-css-1.18.jarDescription:
Batik CSS engine File Path: /var/jenkins_home/.m2/repository/org/apache/xmlgraphics/batik-css/1.18/batik-css-1.18.jarMD5: 3c84f96ad95b3f2ff868f4fca2e599e5SHA1: 639787c5503d058420eddc663f06ea8e05cc712dSHA256: 3d62a9b1f492fea44b36e9947367ee22501009da262d818df5a33b1808b1e09fReferenced In Project/Scope: fides-tool-ui-desktop:compilebatik-css-1.18.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.satodev/std-commons-desktop@7.0
Evidence Type Source Name Value Confidence Vendor file name batik-css High Vendor jar package name apache Highest Vendor jar package name batik Highest Vendor jar package name css Highest Vendor jar package name engine Highest Vendor Manifest automatic-module-name org.apache.xmlgraphics.batik.css Medium Vendor pom artifactid batik-css Highest Vendor pom artifactid batik-css Low Vendor pom groupid org.apache.xmlgraphics Highest Vendor pom name : High Vendor pom parent-artifactid batik Low Product file name batik-css High Product jar package name apache Highest Product jar package name batik Highest Product jar package name css Highest Product jar package name engine Highest Product Manifest automatic-module-name org.apache.xmlgraphics.batik.css Medium Product pom artifactid batik-css Highest Product pom groupid org.apache.xmlgraphics Highest Product pom name : High Product pom parent-artifactid batik Medium Version file version 1.18 High Version pom version 1.18 Highest
Related Dependencies batik-anim-1.18.jarFile Path: /var/jenkins_home/.m2/repository/org/apache/xmlgraphics/batik-anim/1.18/batik-anim-1.18.jar MD5: f46ce4aa85aca0e125f055671cfdea8c SHA1: fb3be1a0c47bfb4c7a03e24527349b42af0f3067 SHA256: d4acb70131ebe795831ab25c210ca4961e022bc80715b20dd5bd1577c6a550ae pkg:maven/org.apache.xmlgraphics/batik-anim@1.18 batik-awt-util-1.18.jarFile Path: /var/jenkins_home/.m2/repository/org/apache/xmlgraphics/batik-awt-util/1.18/batik-awt-util-1.18.jar MD5: 67a7b464183aa9c90d0a11838900d3f2 SHA1: 5797344c42a27f9ec6608f5994acb11737c86de2 SHA256: 807b9d54e6a1e828772a309d75ef51fe2dd6881d74c8a4d39b2fb7e4e1aaf6be pkg:maven/org.apache.xmlgraphics/batik-awt-util@1.18 batik-bridge-1.18.jarFile Path: /var/jenkins_home/.m2/repository/org/apache/xmlgraphics/batik-bridge/1.18/batik-bridge-1.18.jar MD5: 22bdbb532ad73feeea36bdbfc4888145 SHA1: ad14bf6d21013c8b165581511c8b2fbaaff32c1a SHA256: 733eee0123bc7295994d00fd63e28ed764f73f223ecc58095eebb2e83e6f4a50 pkg:maven/org.apache.xmlgraphics/batik-bridge@1.18 batik-constants-1.18.jarFile Path: /var/jenkins_home/.m2/repository/org/apache/xmlgraphics/batik-constants/1.18/batik-constants-1.18.jar MD5: 32e83165183034f4a15e16c16020bc53 SHA1: 377a0e5aea2a44295c472c0960f4fa9f09412a77 SHA256: ba0d6990bd15cc6dc5c30320abd9dea7d201e79404bab15c482edbc22f958358 pkg:maven/org.apache.xmlgraphics/batik-constants@1.18 batik-dom-1.18.jarFile Path: /var/jenkins_home/.m2/repository/org/apache/xmlgraphics/batik-dom/1.18/batik-dom-1.18.jar MD5: a3361ea4bc2641ffb2272ab745c1351a SHA1: 7a6dca47bb9e93c40b7bcb3d615624db00c73abc SHA256: 15c017bb3d34226d6f34f4f63df60c2ea9f80a819e6abbda1b49335d5981d983 pkg:maven/org.apache.xmlgraphics/batik-dom@1.18 batik-ext-1.18.jarFile Path: /var/jenkins_home/.m2/repository/org/apache/xmlgraphics/batik-ext/1.18/batik-ext-1.18.jar MD5: d2c472469d0c887833bfd39d68716510 SHA1: b4966ca56f24f89276e5aef06d3138e778314f7a SHA256: f7b1b415fd0e4e2a0c438b156395c4036e032b4e91d508fd5b216744f3629d0a pkg:maven/org.apache.xmlgraphics/batik-ext@1.18 batik-gvt-1.18.jarFile Path: /var/jenkins_home/.m2/repository/org/apache/xmlgraphics/batik-gvt/1.18/batik-gvt-1.18.jar MD5: 5bbbf65cf384fc4a68579278ecedadcd SHA1: eca7fe784c9272ed75c9fd72ac5b5e7da0681877 SHA256: 293f4ac23666b4ae41244d4c29f059cac306db4a85b293aa28c38214721900d3 pkg:maven/org.apache.xmlgraphics/batik-gvt@1.18 batik-parser-1.18.jarFile Path: /var/jenkins_home/.m2/repository/org/apache/xmlgraphics/batik-parser/1.18/batik-parser-1.18.jar MD5: 949357768df34b802c04c79b5e0602e8 SHA1: f931747352a96203bca03a19124e1004ad5c54fd SHA256: c100962d660a0a415d4c2a2bba7bb02c6c62adb30aac706cd185cdf9ed70a72c pkg:maven/org.apache.xmlgraphics/batik-parser@1.18 batik-script-1.18.jarFile Path: /var/jenkins_home/.m2/repository/org/apache/xmlgraphics/batik-script/1.18/batik-script-1.18.jar MD5: 636d2a2bf1d109c0c292814ae1789dd8 SHA1: 34479b161e0bce23d5e44403c5bda738c08ebf80 SHA256: 89b6c20cc7fe5b41e9cf88fe94d4de3d787cde2d562567b5dba1558c279d5039 pkg:maven/org.apache.xmlgraphics/batik-script@1.18 batik-shared-resources-1.18.jarFile Path: /var/jenkins_home/.m2/repository/org/apache/xmlgraphics/batik-shared-resources/1.18/batik-shared-resources-1.18.jar MD5: f53367b7a736414310d7104c9d194ee4 SHA1: 0d64a5ea72a2e34dfa030158d0688e5187001242 SHA256: 48f4753472d6e6805a124307984d063574acb539f88ada923f1fa757a441665e pkg:maven/org.apache.xmlgraphics/batik-shared-resources@1.18 batik-svg-dom-1.18.jarFile Path: /var/jenkins_home/.m2/repository/org/apache/xmlgraphics/batik-svg-dom/1.18/batik-svg-dom-1.18.jar MD5: 37ff371ade0f8c8b72ea3586d8e8c20a SHA1: 950d8ada7403373d2fa24c71166d6764306f23ca SHA256: deb9c652da0b66dd61b1d323bfca3c7034dbcad855a5e435e607eddd8aace1cd pkg:maven/org.apache.xmlgraphics/batik-svg-dom@1.18 batik-svggen-1.18.jarFile Path: /var/jenkins_home/.m2/repository/org/apache/xmlgraphics/batik-svggen/1.18/batik-svggen-1.18.jar MD5: 95230011e33bd0491da1ebe51778338e SHA1: 1d907524c217a45e97eeb529580c95aea49d92d8 SHA256: 3f181a74bcd01e6688d988080d63ec88eadf8e4a51d8b4c5aa3d1952eb4203b3 pkg:maven/org.apache.xmlgraphics/batik-svggen@1.18 batik-transcoder-1.18.jarFile Path: /var/jenkins_home/.m2/repository/org/apache/xmlgraphics/batik-transcoder/1.18/batik-transcoder-1.18.jar MD5: 4403d0eb03ab193d13ad6ad3df39e0b9 SHA1: 7c3ea9d4e9b7b8d8f1ebc51dc766dbd25649d62e SHA256: 75e8f0c02afc66ca509fc59fcda7fc9de713f01cf8c60c2e4c8c257b58f85c5a pkg:maven/org.apache.xmlgraphics/batik-transcoder@1.18 batik-util-1.18.jarFile Path: /var/jenkins_home/.m2/repository/org/apache/xmlgraphics/batik-util/1.18/batik-util-1.18.jar MD5: 59e6888a94e79ed78a55ae2ea50bc868 SHA1: 1b5126413569b45fa5e35eae936e1acd4abcd5dd SHA256: 0c7e4fdd80be8ba31202eaaf0ebe85ec2cd51f9cb1f21b602d17035aaa84851c pkg:maven/org.apache.xmlgraphics/batik-util@1.18 batik-xml-1.18.jarFile Path: /var/jenkins_home/.m2/repository/org/apache/xmlgraphics/batik-xml/1.18/batik-xml-1.18.jar MD5: 24e74f09875ba65da969f22fcb532c11 SHA1: 36dea570b200621e19150c8fdf21a9a426ef0d22 SHA256: 3ece795300ad2762f9bcd4e8338657f3aac6ed7d51ff71d050bc4f350ff8653f pkg:maven/org.apache.xmlgraphics/batik-xml@1.18 batik-i18n-1.18.jarDescription:
Batik i18n library File Path: /var/jenkins_home/.m2/repository/org/apache/xmlgraphics/batik-i18n/1.18/batik-i18n-1.18.jarMD5: 32c60445f4efa48aa8f93c144f2668d7SHA1: 816b3f791b95cc0a0cec616028a869ecc790dd4dSHA256: cc4a2a50380a6e6295f59ef6468d351e6771e3adf68c12d79c6007e4b1cb25ccReferenced In Project/Scope: fides-tool-ui-desktop:compilebatik-i18n-1.18.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.satodev/std-commons-desktop@7.0
Evidence Type Source Name Value Confidence Vendor file name batik-i18n High Vendor jar package name apache Highest Vendor jar package name batik Highest Vendor jar package name i18n Highest Vendor Manifest automatic-module-name org.apache.xmlgraphics.batik.i18n Medium Vendor pom artifactid batik-i18n Highest Vendor pom artifactid batik-i18n Low Vendor pom groupid org.apache.xmlgraphics Highest Vendor pom name : High Vendor pom parent-artifactid batik Low Product file name batik-i18n High Product jar package name apache Highest Product jar package name batik Highest Product jar package name i18n Highest Product Manifest automatic-module-name org.apache.xmlgraphics.batik.i18n Medium Product pom artifactid batik-i18n Highest Product pom groupid org.apache.xmlgraphics Highest Product pom name : High Product pom parent-artifactid batik Medium Version file version 1.18 High Version pom version 1.18 Highest
byte-buddy-1.17.7.jarDescription:
Byte Buddy is a Java library for creating Java classes at run time.
This artifact is a build of Byte Buddy with all ASM dependencies repackaged into its own name space.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/net/bytebuddy/byte-buddy/1.17.7/byte-buddy-1.17.7.jar
MD5: 209b2faed508ed6804df6982f8fd2c16
SHA1: 3856bfab61beb23e099a0d6629f2ba8de4b98ace
SHA256: 3575dcb8a98faf943d3c1595c47a16047c4fce8a83ebbb26262f1a2f67546357
Referenced In Project/Scope: fides-tool-ui-desktop:runtime
byte-buddy-1.17.7.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name byte-buddy High Vendor jar package name asm Highest Vendor jar package name build Highest Vendor jar package name bytebuddy Highest Vendor jar package name net Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-symbolicname net.bytebuddy.byte-buddy Medium Vendor Manifest multi-release true Low Vendor pom artifactid byte-buddy Highest Vendor pom artifactid byte-buddy Low Vendor pom groupid net.bytebuddy Highest Vendor pom name Byte Buddy (without dependencies) High Vendor pom parent-artifactid byte-buddy-parent Low Product file name byte-buddy High Product jar package name asm Highest Product jar package name build Highest Product jar package name bytebuddy Highest Product jar package name net Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Bundle-Name Byte Buddy (without dependencies) Medium Product Manifest bundle-symbolicname net.bytebuddy.byte-buddy Medium Product Manifest multi-release true Low Product pom artifactid byte-buddy Highest Product pom groupid net.bytebuddy Highest Product pom name Byte Buddy (without dependencies) High Product pom parent-artifactid byte-buddy-parent Medium Version file version 1.17.7 High Version Manifest Bundle-Version 1.17.7 High Version pom version 1.17.7 Highest
cache-api-1.1.1.jarLicense:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/javax/cache/cache-api/1.1.1/cache-api-1.1.1.jar
MD5: dfdac9358e140e61c574abb1ada84dc9
SHA1: c56fb980eb5208bfee29a9a5b9d951aba076bd91
SHA256: 9f34e007edfa82a7b2a2e1b969477dcf5099ce7f4f926fb54ce7e27c4a0cd54b
Referenced In Project/Scope: fides-tool-ui-desktop:compile
cache-api-1.1.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name cache-api High Vendor jar package name cache Highest Vendor jar package name javax Highest Vendor jar package name spi Highest Vendor Manifest bundle-symbolicname javax.cache.api Medium Vendor pom artifactid cache-api Highest Vendor pom artifactid cache-api Low Vendor pom groupid javax.cache Highest Vendor pom name JSR107 API and SPI High Vendor pom url jsr107/jsr107spec Highest Product file name cache-api High Product jar package name cache Highest Product jar package name javax Highest Product jar package name spi Highest Product Manifest Bundle-Name JSR107 API and SPI Medium Product Manifest bundle-symbolicname javax.cache.api Medium Product pom artifactid cache-api Highest Product pom groupid javax.cache Highest Product pom name JSR107 API and SPI High Product pom url jsr107/jsr107spec High Version file version 1.1.1 High Version Manifest Bundle-Version 1.1.1 High Version pom version 1.1.1 Highest
classmate-1.7.0.jarDescription:
Library for introspecting types with full generic information
including resolving of field and method types.
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/com/fasterxml/classmate/1.7.0/classmate-1.7.0.jar
MD5: 3b8f14fe92feb865a8205aa63c5ed769
SHA1: 0e98374da1f2143ac8e6e0a95036994bb19137a3
SHA256: cb868f231c5cceb89d795ea00e6e1b7a93b8f4ac1ce1d8be76dde322dff4a046
Referenced In Project/Scope: fides-tool-ui-desktop:runtime
classmate-1.7.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name classmate High Vendor jar package name classmate Highest Vendor jar package name fasterxml Highest Vendor jar package name types Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/java-classmate Low Vendor Manifest bundle-symbolicname com.fasterxml.classmate Medium Vendor Manifest Implementation-Vendor fasterxml.com High Vendor Manifest Implementation-Vendor-Id com.fasterxml Medium Vendor Manifest specification-vendor fasterxml.com Low Vendor pom artifactid classmate Highest Vendor pom artifactid classmate Low Vendor pom developer email blangel@ocheyedan.net Low Vendor pom developer email tatu@fasterxml.com Low Vendor pom developer id blangel Medium Vendor pom developer id tatu Medium Vendor pom developer name Brian Langel Medium Vendor pom developer name Tatu Saloranta Medium Vendor pom groupid com.fasterxml Highest Vendor pom name ClassMate High Vendor pom organization name fasterxml.com High Vendor pom organization url https://fasterxml.com Medium Vendor pom parent-artifactid oss-parent Low Vendor pom url FasterXML/java-classmate Highest Product file name classmate High Product jar package name classmate Highest Product jar package name fasterxml Highest Product jar package name types Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/java-classmate Low Product Manifest Bundle-Name ClassMate Medium Product Manifest bundle-symbolicname com.fasterxml.classmate Medium Product Manifest Implementation-Title ClassMate High Product Manifest specification-title ClassMate Medium Product pom artifactid classmate Highest Product pom developer email blangel@ocheyedan.net Low Product pom developer email tatu@fasterxml.com Low Product pom developer id blangel Low Product pom developer id tatu Low Product pom developer name Brian Langel Low Product pom developer name Tatu Saloranta Low Product pom groupid com.fasterxml Highest Product pom name ClassMate High Product pom organization name fasterxml.com Low Product pom organization url https://fasterxml.com Low Product pom parent-artifactid oss-parent Medium Product pom url FasterXML/java-classmate High Version file version 1.7.0 High Version Manifest Bundle-Version 1.7.0 High Version Manifest Implementation-Version 1.7.0 High Version pom parent-version 1.7.0 Low Version pom version 1.7.0 Highest
commons-codec-1.18.0.jarDescription:
The Apache Commons Codec component contains encoders and decoders for
formats such as Base16, Base32, Base64, digest, and Hexadecimal. In addition to these
widely used encoders and decoders, the codec package also maintains a
collection of phonetic encoding utilities.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/commons-codec/commons-codec/1.18.0/commons-codec-1.18.0.jar
MD5: 2abf189633424b9292fd57a3192c0ed5
SHA1: ee45d1cf6ec2cc2b809ff04b4dc7aec858e0df8f
SHA256: ba005f304cef92a3dede24a38ad5ac9b8afccf0d8f75839d6c1338634cf7f6e4
Referenced In Project/Scope: fides-tool-ui-desktop:compile
commons-codec-1.18.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name commons-codec High Vendor jar package name apache Highest Vendor jar package name codec Highest Vendor jar package name commons Highest Vendor jar package name digest Highest Vendor Manifest automatic-module-name org.apache.commons.codec Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-codec/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-codec Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest multi-release true Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-codec Highest Vendor pom artifactid commons-codec Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email chtompki@apache.org Low Vendor pom developer email dgraham@apache.org Low Vendor pom developer email dlr@finemaltcoding.com Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email jon@collab.net Low Vendor pom developer email julius@apache.org Low Vendor pom developer email mattsicker@apache.org Low Vendor pom developer email rwaldhoff@apache.org Low Vendor pom developer email sanders@totalsync.com Low Vendor pom developer email tn@apache.org Low Vendor pom developer email tobrien@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id chtompki Medium Vendor pom developer id dgraham Medium Vendor pom developer id dlr Medium Vendor pom developer id ggregory Medium Vendor pom developer id jon Medium Vendor pom developer id julius Medium Vendor pom developer id mattsicker Medium Vendor pom developer id rwaldhoff Medium Vendor pom developer id sanders Medium Vendor pom developer id tn Medium Vendor pom developer id tobrien Medium Vendor pom developer name Daniel Rall Medium Vendor pom developer name David Graham Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name Jon S. Stevens Medium Vendor pom developer name Julius Davies Medium Vendor pom developer name Matt Sicker Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Rodney Waldhoff Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer name Thomas Neidhart Medium Vendor pom developer name Tim OBrien Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL http://juliusdavies.ca/ Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid commons-codec Highest Vendor pom name Apache Commons Codec High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url https://commons.apache.org/proper/commons-codec/ Highest Product file name commons-codec High Product jar package name apache Highest Product jar package name codec Highest Product jar package name commons Highest Product jar package name digest Highest Product Manifest automatic-module-name org.apache.commons.codec Medium Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-codec/ Low Product Manifest Bundle-Name Apache Commons Codec Medium Product Manifest bundle-symbolicname org.apache.commons.commons-codec Medium Product Manifest Implementation-Title Apache Commons Codec High Product Manifest multi-release true Low Product Manifest specification-title Apache Commons Codec Medium Product pom artifactid commons-codec Highest Product pom developer email bayard@apache.org Low Product pom developer email chtompki@apache.org Low Product pom developer email dgraham@apache.org Low Product pom developer email dlr@finemaltcoding.com Low Product pom developer email ggregory at apache.org Low Product pom developer email jon@collab.net Low Product pom developer email julius@apache.org Low Product pom developer email mattsicker@apache.org Low Product pom developer email rwaldhoff@apache.org Low Product pom developer email sanders@totalsync.com Low Product pom developer email tn@apache.org Low Product pom developer email tobrien@apache.org Low Product pom developer id bayard Low Product pom developer id chtompki Low Product pom developer id dgraham Low Product pom developer id dlr Low Product pom developer id ggregory Low Product pom developer id jon Low Product pom developer id julius Low Product pom developer id mattsicker Low Product pom developer id rwaldhoff Low Product pom developer id sanders Low Product pom developer id tn Low Product pom developer id tobrien Low Product pom developer name Daniel Rall Low Product pom developer name David Graham Low Product pom developer name Gary Gregory Low Product pom developer name Henri Yandell Low Product pom developer name Jon S. Stevens Low Product pom developer name Julius Davies Low Product pom developer name Matt Sicker Low Product pom developer name Rob Tompkins Low Product pom developer name Rodney Waldhoff Low Product pom developer name Scott Sanders Low Product pom developer name Thomas Neidhart Low Product pom developer name Tim OBrien Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL http://juliusdavies.ca/ Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid commons-codec Highest Product pom name Apache Commons Codec High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url https://commons.apache.org/proper/commons-codec/ Medium Version file version 1.18.0 High Version Manifest Bundle-Version 1.18.0 High Version Manifest Implementation-Version 1.18.0 High Version pom parent-version 1.18.0 Low Version pom version 1.18.0 Highest
commons-collections4-4.4.jarDescription:
The Apache Commons Collections package contains types that extend and augment the Java Collections Framework. License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/org/apache/commons/commons-collections4/4.4/commons-collections4-4.4.jar
MD5: 4a37023740719b391f10030362c86be6
SHA1: 62ebe7544cb7164d87e0637a2a6a2bdc981395e8
SHA256: 1df8b9430b5c8ed143d7815e403e33ef5371b2400aadbe9bda0883762e0846d1
Referenced In Project/Scope: fides-tool-ui-desktop:compile
commons-collections4-4.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name commons-collections4 High Vendor jar package name apache Highest Vendor jar package name collections4 Highest Vendor jar package name commons Highest Vendor Manifest automatic-module-name org.apache.commons.collections4 Medium Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-collections/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-collections4 Medium Vendor Manifest implementation-url https://commons.apache.org/proper/commons-collections/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.commons Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-collections4 Highest Vendor pom artifactid commons-collections4 Low Vendor pom developer id adriannistor Medium Vendor pom developer id amamment Medium Vendor pom developer id bayard Medium Vendor pom developer id chtompki Medium Vendor pom developer id craigmcc Medium Vendor pom developer id dlaha Medium Vendor pom developer id geirm Medium Vendor pom developer id ggregory Medium Vendor pom developer id jcarman Medium Vendor pom developer id luc Medium Vendor pom developer id matth Medium Vendor pom developer id mbenson Medium Vendor pom developer id morgand Medium Vendor pom developer id rdonkin Medium Vendor pom developer id rwaldhoff Medium Vendor pom developer id scolebourne Medium Vendor pom developer id tn Medium Vendor pom developer name Adrian Nistor Medium Vendor pom developer name Arun M. Thomas Medium Vendor pom developer name Craig McClanahan Medium Vendor pom developer name Dipanjan Laha Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Geir Magnusson Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name James Carman Medium Vendor pom developer name Luc Maisonobe Medium Vendor pom developer name Matt Benson Medium Vendor pom developer name Matthew Hawthorne Medium Vendor pom developer name Morgan Delagrange Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Rodney Waldhoff Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom developer name Thomas Neidhart Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons Collections High Vendor pom parent-artifactid commons-parent Low Vendor pom url https://commons.apache.org/proper/commons-collections/ Highest Product file name commons-collections4 High Product jar package name apache Highest Product jar package name collections4 Highest Product jar package name commons Highest Product Manifest automatic-module-name org.apache.commons.collections4 Medium Product Manifest bundle-docurl https://commons.apache.org/proper/commons-collections/ Low Product Manifest Bundle-Name Apache Commons Collections Medium Product Manifest bundle-symbolicname org.apache.commons.commons-collections4 Medium Product Manifest Implementation-Title Apache Commons Collections High Product Manifest implementation-url https://commons.apache.org/proper/commons-collections/ Low Product Manifest specification-title Apache Commons Collections Medium Product pom artifactid commons-collections4 Highest Product pom developer id adriannistor Low Product pom developer id amamment Low Product pom developer id bayard Low Product pom developer id chtompki Low Product pom developer id craigmcc Low Product pom developer id dlaha Low Product pom developer id geirm Low Product pom developer id ggregory Low Product pom developer id jcarman Low Product pom developer id luc Low Product pom developer id matth Low Product pom developer id mbenson Low Product pom developer id morgand Low Product pom developer id rdonkin Low Product pom developer id rwaldhoff Low Product pom developer id scolebourne Low Product pom developer id tn Low Product pom developer name Adrian Nistor Low Product pom developer name Arun M. Thomas Low Product pom developer name Craig McClanahan Low Product pom developer name Dipanjan Laha Low Product pom developer name Gary Gregory Low Product pom developer name Geir Magnusson Low Product pom developer name Henri Yandell Low Product pom developer name James Carman Low Product pom developer name Luc Maisonobe Low Product pom developer name Matt Benson Low Product pom developer name Matthew Hawthorne Low Product pom developer name Morgan Delagrange Low Product pom developer name Rob Tompkins Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Rodney Waldhoff Low Product pom developer name Stephen Colebourne Low Product pom developer name Thomas Neidhart Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons Collections High Product pom parent-artifactid commons-parent Medium Product pom url https://commons.apache.org/proper/commons-collections/ Medium Version file version 4.4 High Version Manifest Implementation-Version 4.4 High Version pom parent-version 4.4 Low Version pom version 4.4 Highest
commons-compress-1.27.1.jarDescription:
Apache Commons Compress defines an API for working with
compression and archive formats. These include bzip2, gzip, pack200,
LZMA, XZ, Snappy, traditional Unix Compress, DEFLATE, DEFLATE64, LZ4,
Brotli, Zstandard and ar, cpio, jar, tar, zip, dump, 7z, arj.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/org/apache/commons/commons-compress/1.27.1/commons-compress-1.27.1.jar
MD5: 1db4bd87b0082044c6e7a6af0b977a3e
SHA1: a19151084758e2fbb6b41eddaa88e7b8ff4e6599
SHA256: 293d80f54b536b74095dcd7ea3cf0a29bbfc3402519281332495f4420d370d16
Referenced In Project/Scope: fides-tool-ui-desktop:compile
commons-compress-1.27.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name commons-compress High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name compress Highest Vendor Manifest automatic-module-name org.apache.commons.compress Medium Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-compress/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-compress Medium Vendor Manifest extension-name org.apache.commons.compress Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest multi-release true Low Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-compress Highest Vendor pom artifactid commons-compress Low Vendor pom developer email bodewig at apache.org Low Vendor pom developer email chtompki at apache.org Low Vendor pom developer email damjan at apache.org Low Vendor pom developer email ebourg at apache.org Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email grobmeier at apache.org Low Vendor pom developer email julius at apache.org Low Vendor pom developer email peterlee at apache.org Low Vendor pom developer email sebb at apache.org Low Vendor pom developer email tcurdt at apache.org Low Vendor pom developer id bodewig Medium Vendor pom developer id chtompki Medium Vendor pom developer id damjan Medium Vendor pom developer id ebourg Medium Vendor pom developer id ggregory Medium Vendor pom developer id grobmeier Medium Vendor pom developer id julius Medium Vendor pom developer id peterlee Medium Vendor pom developer id sebb Medium Vendor pom developer id tcurdt Medium Vendor pom developer name Christian Grobmeier Medium Vendor pom developer name Damjan Jovanovic Medium Vendor pom developer name Emmanuel Bourg Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Julius Davies Medium Vendor pom developer name Peter Alfred Lee Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Sebastian Bazley Medium Vendor pom developer name Stefan Bodewig Medium Vendor pom developer name Torsten Curdt Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons Compress High Vendor pom parent-artifactid commons-parent Low Vendor pom url https://commons.apache.org/proper/commons-compress/ Highest Product file name commons-compress High Product jar package name 9 Highest Product jar package name apache Highest Product jar package name commons Highest Product jar package name compress Highest Product Manifest automatic-module-name org.apache.commons.compress Medium Product Manifest build-jdk-spec 17 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-compress/ Low Product Manifest Bundle-Name Apache Commons Compress Medium Product Manifest bundle-symbolicname org.apache.commons.commons-compress Medium Product Manifest extension-name org.apache.commons.compress Medium Product Manifest Implementation-Title Apache Commons Compress High Product Manifest multi-release true Low Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low Product Manifest specification-title Apache Commons Compress Medium Product pom artifactid commons-compress Highest Product pom developer email bodewig at apache.org Low Product pom developer email chtompki at apache.org Low Product pom developer email damjan at apache.org Low Product pom developer email ebourg at apache.org Low Product pom developer email ggregory at apache.org Low Product pom developer email grobmeier at apache.org Low Product pom developer email julius at apache.org Low Product pom developer email peterlee at apache.org Low Product pom developer email sebb at apache.org Low Product pom developer email tcurdt at apache.org Low Product pom developer id bodewig Low Product pom developer id chtompki Low Product pom developer id damjan Low Product pom developer id ebourg Low Product pom developer id ggregory Low Product pom developer id grobmeier Low Product pom developer id julius Low Product pom developer id peterlee Low Product pom developer id sebb Low Product pom developer id tcurdt Low Product pom developer name Christian Grobmeier Low Product pom developer name Damjan Jovanovic Low Product pom developer name Emmanuel Bourg Low Product pom developer name Gary Gregory Low Product pom developer name Julius Davies Low Product pom developer name Peter Alfred Lee Low Product pom developer name Rob Tompkins Low Product pom developer name Sebastian Bazley Low Product pom developer name Stefan Bodewig Low Product pom developer name Torsten Curdt Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons Compress High Product pom parent-artifactid commons-parent Medium Product pom url https://commons.apache.org/proper/commons-compress/ Medium Version file version 1.27.1 High Version Manifest Bundle-Version 1.27.1 High Version Manifest Implementation-Version 1.27.1 High Version pom parent-version 1.27.1 Low Version pom version 1.27.1 Highest
commons-io-2.18.0.jarDescription:
The Apache Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/commons-io/commons-io/2.18.0/commons-io-2.18.0.jar
MD5: 8cce74ccf461cd6502ae04c908eca917
SHA1: 44084ef756763795b31c578403dd028ff4a22950
SHA256: f3ca0f8d63c40e23a56d54101c60d5edee136b42d84bfb85bc7963093109cf8b
Referenced In Project/Scope: fides-tool-ui-desktop:compile
commons-io-2.18.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name commons-io High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name file Highest Vendor jar package name io Highest Vendor Manifest automatic-module-name org.apache.commons.io Medium Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-io/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-io Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest multi-release true Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-io Highest Vendor pom artifactid commons-io Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email dion@apache.org Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email jeremias@apache.org Low Vendor pom developer email jochen.wiedmann@gmail.com Low Vendor pom developer email krosenvold@apache.org Low Vendor pom developer email martinc@apache.org Low Vendor pom developer email matth@apache.org Low Vendor pom developer email nicolaken@apache.org Low Vendor pom developer email roxspring@apache.org Low Vendor pom developer email sanders@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id dion Medium Vendor pom developer id ggregory Medium Vendor pom developer id jeremias Medium Vendor pom developer id jochen Medium Vendor pom developer id jukka Medium Vendor pom developer id krosenvold Medium Vendor pom developer id martinc Medium Vendor pom developer id matth Medium Vendor pom developer id niallp Medium Vendor pom developer id nicolaken Medium Vendor pom developer id roxspring Medium Vendor pom developer id sanders Medium Vendor pom developer id scolebourne Medium Vendor pom developer name dIon Gillard Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name Jeremias Maerki Medium Vendor pom developer name Jochen Wiedmann Medium Vendor pom developer name Jukka Zitting Medium Vendor pom developer name Kristian Rosenvold Medium Vendor pom developer name Martin Cooper Medium Vendor pom developer name Matthew Hawthorne Medium Vendor pom developer name Niall Pemberton Medium Vendor pom developer name Nicola Ken Barozzi Medium Vendor pom developer name Rob Oxspring Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid commons-io Highest Vendor pom name Apache Commons IO High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url https://commons.apache.org/proper/commons-io/ Highest Product file name commons-io High Product jar package name apache Highest Product jar package name commons Highest Product jar package name file Highest Product jar package name io Highest Product Manifest automatic-module-name org.apache.commons.io Medium Product Manifest build-jdk-spec 17 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-io/ Low Product Manifest Bundle-Name Apache Commons IO Medium Product Manifest bundle-symbolicname org.apache.commons.commons-io Medium Product Manifest Implementation-Title Apache Commons IO High Product Manifest multi-release true Low Product Manifest specification-title Apache Commons IO Medium Product pom artifactid commons-io Highest Product pom developer email bayard@apache.org Low Product pom developer email dion@apache.org Low Product pom developer email ggregory at apache.org Low Product pom developer email jeremias@apache.org Low Product pom developer email jochen.wiedmann@gmail.com Low Product pom developer email krosenvold@apache.org Low Product pom developer email martinc@apache.org Low Product pom developer email matth@apache.org Low Product pom developer email nicolaken@apache.org Low Product pom developer email roxspring@apache.org Low Product pom developer email sanders@apache.org Low Product pom developer id bayard Low Product pom developer id dion Low Product pom developer id ggregory Low Product pom developer id jeremias Low Product pom developer id jochen Low Product pom developer id jukka Low Product pom developer id krosenvold Low Product pom developer id martinc Low Product pom developer id matth Low Product pom developer id niallp Low Product pom developer id nicolaken Low Product pom developer id roxspring Low Product pom developer id sanders Low Product pom developer id scolebourne Low Product pom developer name dIon Gillard Low Product pom developer name Gary Gregory Low Product pom developer name Henri Yandell Low Product pom developer name Jeremias Maerki Low Product pom developer name Jochen Wiedmann Low Product pom developer name Jukka Zitting Low Product pom developer name Kristian Rosenvold Low Product pom developer name Martin Cooper Low Product pom developer name Matthew Hawthorne Low Product pom developer name Niall Pemberton Low Product pom developer name Nicola Ken Barozzi Low Product pom developer name Rob Oxspring Low Product pom developer name Scott Sanders Low Product pom developer name Stephen Colebourne Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid commons-io Highest Product pom name Apache Commons IO High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url https://commons.apache.org/proper/commons-io/ Medium Version file version 2.18.0 High Version Manifest Bundle-Version 2.18.0 High Version Manifest Implementation-Version 2.18.0 High Version pom parent-version 2.18.0 Low Version pom version 2.18.0 Highest
commons-lang3-3.17.0.jarDescription:
Apache Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
The code is tested using the latest revision of the JDK for supported
LTS releases: 8, 11, 17 and 21 currently.
See https://github.com/apache/commons-lang/blob/master/.github/workflows/maven.yml
Please ensure your build environment is up-to-date and kindly report any build issues.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/org/apache/commons/commons-lang3/3.17.0/commons-lang3-3.17.0.jar
MD5: 7730df72b7fdff4a3a32d89a314f826a
SHA1: b17d2136f0460dcc0d2016ceefca8723bdf4ee70
SHA256: 6ee731df5c8e5a2976a1ca023b6bb320ea8d3539fbe64c8a1d5cb765127c33b4
Referenced In Project/Scope: fides-tool-ui-desktop:compile
commons-lang3-3.17.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name commons-lang3 High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name lang3 Highest Vendor Manifest automatic-module-name org.apache.commons.lang3 Medium Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-lang/ Low Vendor Manifest bundle-symbolicname org.apache.commons.lang3 Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest multi-release true Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-lang3 Highest Vendor pom artifactid commons-lang3 Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email britter@apache.org Low Vendor pom developer email chtompki@apache.org Low Vendor pom developer email djones@apache.org Low Vendor pom developer email dlr@finemaltcoding.com Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email jcarman@apache.org Low Vendor pom developer email joerg.schaible@gmx.de Low Vendor pom developer email lguibert@apache.org Low Vendor pom developer email oheger@apache.org Low Vendor pom developer email pbenedict@apache.org Low Vendor pom developer email rdonkin@apache.org Low Vendor pom developer email scolebourne@joda.org Low Vendor pom developer email stevencaswell@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id britter Medium Vendor pom developer id chtompki Medium Vendor pom developer id djones Medium Vendor pom developer id dlr Medium Vendor pom developer id fredrik Medium Vendor pom developer id ggregory Medium Vendor pom developer id jcarman Medium Vendor pom developer id joehni Medium Vendor pom developer id lguibert Medium Vendor pom developer id mbenson Medium Vendor pom developer id niallp Medium Vendor pom developer id oheger Medium Vendor pom developer id pbenedict Medium Vendor pom developer id rdonkin Medium Vendor pom developer id scaswell Medium Vendor pom developer id scolebourne Medium Vendor pom developer name Benedikt Ritter Medium Vendor pom developer name Daniel Rall Medium Vendor pom developer name Duncan Jones Medium Vendor pom developer name Fredrik Westermarck Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name James Carman Medium Vendor pom developer name Joerg Schaible Medium Vendor pom developer name Loic Guibert Medium Vendor pom developer name Matt Benson Medium Vendor pom developer name Niall Pemberton Medium Vendor pom developer name Oliver Heger Medium Vendor pom developer name Paul Benedict Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Stephen Colebourne Medium Vendor pom developer name Steven Caswell Medium Vendor pom developer org Carman Consulting, Inc. Medium Vendor pom developer org CollabNet, Inc. Medium Vendor pom developer org SITA ATS Ltd Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons Lang High Vendor pom parent-artifactid commons-parent Low Vendor pom url https://commons.apache.org/proper/commons-lang/ Highest Product file name commons-lang3 High Product jar package name apache Highest Product jar package name commons Highest Product jar package name lang3 Highest Product Manifest automatic-module-name org.apache.commons.lang3 Medium Product Manifest build-jdk-spec 17 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-lang/ Low Product Manifest Bundle-Name Apache Commons Lang Medium Product Manifest bundle-symbolicname org.apache.commons.lang3 Medium Product Manifest Implementation-Title Apache Commons Lang High Product Manifest multi-release true Low Product Manifest specification-title Apache Commons Lang Medium Product pom artifactid commons-lang3 Highest Product pom developer email bayard@apache.org Low Product pom developer email britter@apache.org Low Product pom developer email chtompki@apache.org Low Product pom developer email djones@apache.org Low Product pom developer email dlr@finemaltcoding.com Low Product pom developer email ggregory at apache.org Low Product pom developer email jcarman@apache.org Low Product pom developer email joerg.schaible@gmx.de Low Product pom developer email lguibert@apache.org Low Product pom developer email oheger@apache.org Low Product pom developer email pbenedict@apache.org Low Product pom developer email rdonkin@apache.org Low Product pom developer email scolebourne@joda.org Low Product pom developer email stevencaswell@apache.org Low Product pom developer id bayard Low Product pom developer id britter Low Product pom developer id chtompki Low Product pom developer id djones Low Product pom developer id dlr Low Product pom developer id fredrik Low Product pom developer id ggregory Low Product pom developer id jcarman Low Product pom developer id joehni Low Product pom developer id lguibert Low Product pom developer id mbenson Low Product pom developer id niallp Low Product pom developer id oheger Low Product pom developer id pbenedict Low Product pom developer id rdonkin Low Product pom developer id scaswell Low Product pom developer id scolebourne Low Product pom developer name Benedikt Ritter Low Product pom developer name Daniel Rall Low Product pom developer name Duncan Jones Low Product pom developer name Fredrik Westermarck Low Product pom developer name Gary Gregory Low Product pom developer name Henri Yandell Low Product pom developer name James Carman Low Product pom developer name Joerg Schaible Low Product pom developer name Loic Guibert Low Product pom developer name Matt Benson Low Product pom developer name Niall Pemberton Low Product pom developer name Oliver Heger Low Product pom developer name Paul Benedict Low Product pom developer name Rob Tompkins Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Stephen Colebourne Low Product pom developer name Steven Caswell Low Product pom developer org Carman Consulting, Inc. Low Product pom developer org CollabNet, Inc. Low Product pom developer org SITA ATS Ltd Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons Lang High Product pom parent-artifactid commons-parent Medium Product pom url https://commons.apache.org/proper/commons-lang/ Medium Version file version 3.17.0 High Version Manifest Bundle-Version 3.17.0 High Version Manifest Implementation-Version 3.17.0 High Version pom parent-version 3.17.0 Low Version pom version 3.17.0 Highest
CVE-2025-48924 suppress
Uncontrolled Recursion vulnerability in Apache Commons Lang.
This issue affects Apache Commons Lang: Starting with commons-lang:commons-lang 2.0 to 2.6, and, from org.apache.commons:commons-lang3 3.0 before 3.18.0.
The methods ClassUtils.getClass(...) can throw StackOverflowError on very long inputs. Because an Error is usually not handled by applications and libraries, a
StackOverflowError could cause an application to stop.
Users are recommended to upgrade to version 3.18.0, which fixes the issue. CWE-674 Uncontrolled Recursion
CVSSv3:
Base Score: MEDIUM (5.3) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:3.9/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
commons-logging-1.0.4.jarDescription:
Commons Logging is a thin adapter allowing configurable bridging to other,
well known logging systems. License:
The Apache Software License, Version 2.0: /LICENSE.txt File Path: /var/jenkins_home/.m2/repository/commons-logging/commons-logging/1.0.4/commons-logging-1.0.4.jar
MD5: 8a507817b28077e0478add944c64586a
SHA1: f029a2aefe2b3e1517573c580f948caac31b1056
SHA256: e94af49749384c11f5aa50e8d0f5fe679be771295b52030338d32843c980351e
Referenced In Project/Scope: fides-tool-ui-desktop:compile
commons-logging-1.0.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.satodev/std-commons-desktop@7.0
Evidence Type Source Name Value Confidence Vendor file name commons-logging High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name logging Highest Vendor Manifest extension-name org.apache.commons.logging Medium Vendor Manifest Implementation-Vendor Apache Software Foundation High Vendor Manifest specification-vendor Apache Software Foundation Low Vendor pom artifactid commons-logging Highest Vendor pom artifactid commons-logging Low Vendor pom developer email baliuka@apache.org Low Vendor pom developer email costin at apache dot org Low Vendor pom developer email craigmcc at apache org Low Vendor pom developer email donaldp at apache dot org Low Vendor pom developer email morgand at apache dot org Low Vendor pom developer email rdonkin at apache dot org Low Vendor pom developer email rsitze at apache dot org Low Vendor pom developer email rwaldhoff at apache org Low Vendor pom developer email sanders at apache dot org Low Vendor pom developer id baliuka Medium Vendor pom developer id costin Medium Vendor pom developer id craigmcc Medium Vendor pom developer id donaldp Medium Vendor pom developer id morgand Medium Vendor pom developer id rdonkin Medium Vendor pom developer id rsitze Medium Vendor pom developer id rwaldhoff Medium Vendor pom developer id sanders Medium Vendor pom developer name Costin Manolache Medium Vendor pom developer name Craig McClanahan Medium Vendor pom developer name Juozas Baliuka Medium Vendor pom developer name Morgan Delagrange Medium Vendor pom developer name Peter Donald Medium Vendor pom developer name Richard Sitze Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Rodney Waldhoff Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer org Apache Medium Vendor pom developer org Apache Software Foundation Medium Vendor pom groupid commons-logging Highest Vendor pom name Logging High Vendor pom organization name The Apache Software Foundation High Vendor pom organization url http://jakarta.apache.org Medium Vendor pom url http://jakarta.apache.org/commons/logging/ Highest Product file name commons-logging High Product jar package name apache Highest Product jar package name commons Highest Product jar package name logging Highest Product Manifest extension-name org.apache.commons.logging Medium Product pom artifactid commons-logging Highest Product pom developer email baliuka@apache.org Low Product pom developer email costin at apache dot org Low Product pom developer email craigmcc at apache org Low Product pom developer email donaldp at apache dot org Low Product pom developer email morgand at apache dot org Low Product pom developer email rdonkin at apache dot org Low Product pom developer email rsitze at apache dot org Low Product pom developer email rwaldhoff at apache org Low Product pom developer email sanders at apache dot org Low Product pom developer id baliuka Low Product pom developer id costin Low Product pom developer id craigmcc Low Product pom developer id donaldp Low Product pom developer id morgand Low Product pom developer id rdonkin Low Product pom developer id rsitze Low Product pom developer id rwaldhoff Low Product pom developer id sanders Low Product pom developer name Costin Manolache Low Product pom developer name Craig McClanahan Low Product pom developer name Juozas Baliuka Low Product pom developer name Morgan Delagrange Low Product pom developer name Peter Donald Low Product pom developer name Richard Sitze Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Rodney Waldhoff Low Product pom developer name Scott Sanders Low Product pom developer org Apache Low Product pom developer org Apache Software Foundation Low Product pom groupid commons-logging Highest Product pom name Logging High Product pom organization name The Apache Software Foundation Low Product pom organization url http://jakarta.apache.org Low Product pom url http://jakarta.apache.org/commons/logging/ Medium Version file version 1.0.4 High Version Manifest Implementation-Version 1.0.4 High Version pom version 1.0.4 Highest
commons-math3-3.6.1.jarDescription:
The Apache Commons Math project is a library of lightweight, self-contained mathematics and statistics components addressing the most common practical problems not immediately available in the Java programming language or commons-lang. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/org/apache/commons/commons-math3/3.6.1/commons-math3-3.6.1.jar
MD5: 5b730d97e4e6368069de1983937c508e
SHA1: e4ba98f1d4b3c80ec46392f25e094a6a2e58fcbf
SHA256: 1e56d7b058d28b65abd256b8458e3885b674c1d588fa43cd7d1cbb9c7ef2b308
Referenced In Project/Scope: fides-tool-ui-desktop:compile
commons-math3-3.6.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name commons-math3 High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name math3 Highest Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-math/ Low Vendor Manifest bundle-symbolicname org.apache.commons.math3 Medium Vendor Manifest implementation-build 16abfe5de688cc52fb0396e0609cb33044b15653; 2016-03-17 13:30:43-0400 Low Vendor Manifest implementation-url http://commons.apache.org/proper/commons-math/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-math3 Highest Vendor pom artifactid commons-math3 Low Vendor pom developer email achou at apache dot org Low Vendor pom developer email billbarker at apache dot org Low Vendor pom developer email brentworden at apache dot org Low Vendor pom developer email celestin at apache dot org Low Vendor pom developer email dimpbx at apache dot org Low Vendor pom developer email erans at apache dot org Low Vendor pom developer email evanward at apache dot org Low Vendor pom developer email gregs at apache dot org Low Vendor pom developer email j3322ptm at yahoo dot de Low Vendor pom developer email luc at apache dot org Low Vendor pom developer email mdiggory at apache dot org Low Vendor pom developer email mikl at apache dot org Low Vendor pom developer email oertl at apache dot org Low Vendor pom developer email rdonkin at apache dot org Low Vendor pom developer email tn at apache dot org Low Vendor pom developer email tobrien at apache dot org Low Vendor pom developer id achou Medium Vendor pom developer id billbarker Medium Vendor pom developer id brentworden Medium Vendor pom developer id celestin Medium Vendor pom developer id dimpbx Medium Vendor pom developer id erans Medium Vendor pom developer id evanward Medium Vendor pom developer id gregs Medium Vendor pom developer id luc Medium Vendor pom developer id mdiggory Medium Vendor pom developer id mikl Medium Vendor pom developer id oertl Medium Vendor pom developer id pietsch Medium Vendor pom developer id rdonkin Medium Vendor pom developer id tn Medium Vendor pom developer id tobrien Medium Vendor pom developer name Albert Davidson Chou Medium Vendor pom developer name Bill Barker Medium Vendor pom developer name Brent Worden Medium Vendor pom developer name Dimitri Pourbaix Medium Vendor pom developer name Evan Ward Medium Vendor pom developer name Gilles Sadowski Medium Vendor pom developer name Greg Sterijevski Medium Vendor pom developer name J. Pietschmann Medium Vendor pom developer name Luc Maisonobe Medium Vendor pom developer name Mark Diggory Medium Vendor pom developer name Mikkel Meyer Andersen Medium Vendor pom developer name Otmar Ertl Medium Vendor pom developer name Robert Burrell Donkin Medium Vendor pom developer name Sébastien Brisard Medium Vendor pom developer name Thomas Neidhart Medium Vendor pom developer name Tim O'Brien Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons Math High Vendor pom parent-artifactid commons-parent Low Vendor pom url http://commons.apache.org/proper/commons-math/ Highest Product file name commons-math3 High Product jar package name apache Highest Product jar package name commons Highest Product jar package name math3 Highest Product Manifest bundle-docurl http://commons.apache.org/proper/commons-math/ Low Product Manifest Bundle-Name Apache Commons Math Medium Product Manifest bundle-symbolicname org.apache.commons.math3 Medium Product Manifest implementation-build 16abfe5de688cc52fb0396e0609cb33044b15653; 2016-03-17 13:30:43-0400 Low Product Manifest Implementation-Title Apache Commons Math High Product Manifest implementation-url http://commons.apache.org/proper/commons-math/ Low Product Manifest specification-title Apache Commons Math Medium Product pom artifactid commons-math3 Highest Product pom developer email achou at apache dot org Low Product pom developer email billbarker at apache dot org Low Product pom developer email brentworden at apache dot org Low Product pom developer email celestin at apache dot org Low Product pom developer email dimpbx at apache dot org Low Product pom developer email erans at apache dot org Low Product pom developer email evanward at apache dot org Low Product pom developer email gregs at apache dot org Low Product pom developer email j3322ptm at yahoo dot de Low Product pom developer email luc at apache dot org Low Product pom developer email mdiggory at apache dot org Low Product pom developer email mikl at apache dot org Low Product pom developer email oertl at apache dot org Low Product pom developer email rdonkin at apache dot org Low Product pom developer email tn at apache dot org Low Product pom developer email tobrien at apache dot org Low Product pom developer id achou Low Product pom developer id billbarker Low Product pom developer id brentworden Low Product pom developer id celestin Low Product pom developer id dimpbx Low Product pom developer id erans Low Product pom developer id evanward Low Product pom developer id gregs Low Product pom developer id luc Low Product pom developer id mdiggory Low Product pom developer id mikl Low Product pom developer id oertl Low Product pom developer id pietsch Low Product pom developer id rdonkin Low Product pom developer id tn Low Product pom developer id tobrien Low Product pom developer name Albert Davidson Chou Low Product pom developer name Bill Barker Low Product pom developer name Brent Worden Low Product pom developer name Dimitri Pourbaix Low Product pom developer name Evan Ward Low Product pom developer name Gilles Sadowski Low Product pom developer name Greg Sterijevski Low Product pom developer name J. Pietschmann Low Product pom developer name Luc Maisonobe Low Product pom developer name Mark Diggory Low Product pom developer name Mikkel Meyer Andersen Low Product pom developer name Otmar Ertl Low Product pom developer name Robert Burrell Donkin Low Product pom developer name Sébastien Brisard Low Product pom developer name Thomas Neidhart Low Product pom developer name Tim O'Brien Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons Math High Product pom parent-artifactid commons-parent Medium Product pom url http://commons.apache.org/proper/commons-math/ Medium Version file version 3.6.1 High Version Manifest Bundle-Version 3.6.1 High Version Manifest Implementation-Version 3.6.1 High Version pom parent-version 3.6.1 Low Version pom version 3.6.1 Highest
commons-text-1.13.0.jarDescription:
Apache Commons Text is a set of utility functions and reusable components for the purpose of processing
and manipulating text that should be of use in a Java environment.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/org/apache/commons/commons-text/1.13.0/commons-text-1.13.0.jar
MD5: 4b4766452c04316e3ef6ffe3490d6b10
SHA1: ba2ed5521c491cabf7ecdb57f77922561c2e8958
SHA256: 1e323a501127df78ed0987f345d69d65d0ea7fa3d4fb5b3f84aaeba3a8b20f38
Referenced In Project/Scope: fides-tool-ui-desktop:compile
commons-text-1.13.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name commons-text High Vendor jar package name apache Highest Vendor jar package name commons Highest Vendor jar package name text Highest Vendor Manifest automatic-module-name org.apache.commons.text Medium Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-text Low Vendor Manifest bundle-symbolicname org.apache.commons.text Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest multi-release true Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-text Highest Vendor pom artifactid commons-text Low Vendor pom developer email britter@apache.org Low Vendor pom developer email chtompki@apache.org Low Vendor pom developer email djones@apache.org Low Vendor pom developer email ggregory at apache.org Low Vendor pom developer email kinow@apache.org Low Vendor pom developer id britter Medium Vendor pom developer id chtompki Medium Vendor pom developer id djones Medium Vendor pom developer id ggregory Medium Vendor pom developer id kinow Medium Vendor pom developer name Benedikt Ritter Medium Vendor pom developer name Bruno P. Kinoshita Medium Vendor pom developer name Duncan Jones Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer org The Apache Software Foundation Medium Vendor pom developer org URL https://www.apache.org/ Medium Vendor pom groupid org.apache.commons Highest Vendor pom name Apache Commons Text High Vendor pom parent-artifactid commons-parent Low Vendor pom url https://commons.apache.org/proper/commons-text Highest Product file name commons-text High Product jar package name apache Highest Product jar package name commons Highest Product jar package name text Highest Product Manifest automatic-module-name org.apache.commons.text Medium Product Manifest build-jdk-spec 17 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-text Low Product Manifest Bundle-Name Apache Commons Text Medium Product Manifest bundle-symbolicname org.apache.commons.text Medium Product Manifest Implementation-Title Apache Commons Text High Product Manifest multi-release true Low Product Manifest specification-title Apache Commons Text Medium Product pom artifactid commons-text Highest Product pom developer email britter@apache.org Low Product pom developer email chtompki@apache.org Low Product pom developer email djones@apache.org Low Product pom developer email ggregory at apache.org Low Product pom developer email kinow@apache.org Low Product pom developer id britter Low Product pom developer id chtompki Low Product pom developer id djones Low Product pom developer id ggregory Low Product pom developer id kinow Low Product pom developer name Benedikt Ritter Low Product pom developer name Bruno P. Kinoshita Low Product pom developer name Duncan Jones Low Product pom developer name Gary Gregory Low Product pom developer name Rob Tompkins Low Product pom developer org The Apache Software Foundation Low Product pom developer org URL https://www.apache.org/ Low Product pom groupid org.apache.commons Highest Product pom name Apache Commons Text High Product pom parent-artifactid commons-parent Medium Product pom url https://commons.apache.org/proper/commons-text Medium Version file version 1.13.0 High Version Manifest Bundle-Version 1.13.0 High Version Manifest Implementation-Version 1.13.0 High Version pom parent-version 1.13.0 Low Version pom version 1.13.0 Highest
curvesapi-1.08.jarDescription:
Implementation of various mathematical curves that define themselves over a set of control points. The API is written in Java. The curves supported are: Bezier, B-Spline, Cardinal Spline, Catmull-Rom Spline, Lagrange, Natural Cubic Spline, and NURBS. License:
BSD License: http://opensource.org/licenses/BSD-3-Clause File Path: /var/jenkins_home/.m2/repository/com/github/virtuald/curvesapi/1.08/curvesapi-1.08.jar
MD5: fc3aed90346691e7c79da06bb6606beb
SHA1: 3d3d36568154059825089b289dcfca481fe44e2c
SHA256: ad95b08b8bbf9d7d17e5e00814898fa23324f32bc5b62f1a37801e6a56ce0079
Referenced In Project/Scope: fides-tool-ui-desktop:compile
curvesapi-1.08.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name curvesapi High Vendor Manifest automatic-module-name com.github.virtuald.curvesapi Medium Vendor pom artifactid curvesapi Highest Vendor pom artifactid curvesapi Low Vendor pom developer id stormdollar Medium Vendor pom developer id virtuald Medium Vendor pom developer name Dustin Spicuzza Medium Vendor pom developer name stormdollar Medium Vendor pom groupid com.github.virtuald Highest Vendor pom name curvesapi High Vendor pom url virtuald/curvesapi Highest Product file name curvesapi High Product Manifest automatic-module-name com.github.virtuald.curvesapi Medium Product pom artifactid curvesapi Highest Product pom developer id stormdollar Low Product pom developer id virtuald Low Product pom developer name Dustin Spicuzza Low Product pom developer name stormdollar Low Product pom groupid com.github.virtuald Highest Product pom name curvesapi High Product pom url virtuald/curvesapi High Version file version 1.08 High Version pom version 1.08 Highest
ehcache-3.10.9.jar (shaded: org.ehcache.modules:ehcache-107:3.10.9)Description:
The JSR-107 compatibility module of Ehcache 3 License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/org/ehcache/ehcache/3.10.9/ehcache-3.10.9.jar/META-INF/maven/org.ehcache.modules/ehcache-107/pom.xml
MD5: 3e9d99c512303ef275b02e8ce9cb2c7d
SHA1: e35d5eab1f56cb5080d6af1a3c63a8d6518dcaf4
SHA256: 3b4cc7a9e5779cc0dfb60833252928cabf6086e5503489da8247f85a8d62d1fd
Referenced In Project/Scope: fides-tool-ui-desktop:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid ehcache-107 Low Vendor pom developer email tc-oss@softwareag.com Low Vendor pom developer name Terracotta Engineers Medium Vendor pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Medium Vendor pom developer org URL http://ehcache.org Medium Vendor pom groupid org.ehcache.modules Highest Vendor pom name Ehcache 3 JSR-107 module High Vendor pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. High Vendor pom organization url http://terracotta.org Medium Vendor pom url http://ehcache.org Highest Product pom artifactid ehcache-107 Highest Product pom developer email tc-oss@softwareag.com Low Product pom developer name Terracotta Engineers Low Product pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low Product pom developer org URL http://ehcache.org Low Product pom groupid org.ehcache.modules Highest Product pom name Ehcache 3 JSR-107 module High Product pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low Product pom organization url http://terracotta.org Low Product pom url http://ehcache.org Medium Version pom version 3.10.9 Highest
ehcache-3.10.9.jar (shaded: org.ehcache.modules:ehcache-api:3.10.9)Description:
The API module of Ehcache 3 License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/org/ehcache/ehcache/3.10.9/ehcache-3.10.9.jar/META-INF/maven/org.ehcache.modules/ehcache-api/pom.xml
MD5: 601fa12cf135e831aacd37ae34712e9a
SHA1: 8361b135d76240bed3aaec811ba342d158087f2f
SHA256: ea857512c008c0d555c378b8e1cfce272405e9fb60888e9e57424262ca657734
Referenced In Project/Scope: fides-tool-ui-desktop:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid ehcache-api Low Vendor pom developer email tc-oss@softwareag.com Low Vendor pom developer name Terracotta Engineers Medium Vendor pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Medium Vendor pom developer org URL http://ehcache.org Medium Vendor pom groupid org.ehcache.modules Highest Vendor pom name Ehcache 3 API module High Vendor pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. High Vendor pom organization url http://terracotta.org Medium Vendor pom url http://ehcache.org Highest Product pom artifactid ehcache-api Highest Product pom developer email tc-oss@softwareag.com Low Product pom developer name Terracotta Engineers Low Product pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low Product pom developer org URL http://ehcache.org Low Product pom groupid org.ehcache.modules Highest Product pom name Ehcache 3 API module High Product pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low Product pom organization url http://terracotta.org Low Product pom url http://ehcache.org Medium Version pom version 3.10.9 Highest
ehcache-3.10.9.jar (shaded: org.ehcache.modules:ehcache-core:3.10.9)Description:
The Core module of Ehcache 3 License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/org/ehcache/ehcache/3.10.9/ehcache-3.10.9.jar/META-INF/maven/org.ehcache.modules/ehcache-core/pom.xml
MD5: 061a4bd861a4d29f9b786b47d9635014
SHA1: bdce3f9d0f6a27316414bbc8022581863d6fd241
SHA256: 93fdb9ca82a212876a6680d49793cedcde06c0f107207f1c4ae83b3b2491cf7c
Referenced In Project/Scope: fides-tool-ui-desktop:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid ehcache-core Low Vendor pom developer email tc-oss@softwareag.com Low Vendor pom developer name Terracotta Engineers Medium Vendor pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Medium Vendor pom developer org URL http://ehcache.org Medium Vendor pom groupid org.ehcache.modules Highest Vendor pom name Ehcache 3 Core module High Vendor pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. High Vendor pom organization url http://terracotta.org Medium Vendor pom url http://ehcache.org Highest Product pom artifactid ehcache-core Highest Product pom developer email tc-oss@softwareag.com Low Product pom developer name Terracotta Engineers Low Product pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low Product pom developer org URL http://ehcache.org Low Product pom groupid org.ehcache.modules Highest Product pom name Ehcache 3 Core module High Product pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low Product pom organization url http://terracotta.org Low Product pom url http://ehcache.org Medium Version pom version 3.10.9 Highest
ehcache-3.10.9.jar (shaded: org.ehcache.modules:ehcache-impl:3.10.9)Description:
The implementation module of Ehcache 3 License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/org/ehcache/ehcache/3.10.9/ehcache-3.10.9.jar/META-INF/maven/org.ehcache.modules/ehcache-impl/pom.xml
MD5: 4d9767d55ea8d32afd6ce5197047f1c8
SHA1: 7ab36b6dda8a1d57a35fb9e5b6731e8446bf0a80
SHA256: fad7aceb8e91d1e3cf6b984826cf1364a3f3d41bc1f8f59a6bb26fbd5fd47bb4
Referenced In Project/Scope: fides-tool-ui-desktop:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid ehcache-impl Low Vendor pom developer email tc-oss@softwareag.com Low Vendor pom developer name Terracotta Engineers Medium Vendor pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Medium Vendor pom developer org URL http://ehcache.org Medium Vendor pom groupid org.ehcache.modules Highest Vendor pom name Ehcache 3 Implementation module High Vendor pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. High Vendor pom organization url http://terracotta.org Medium Vendor pom url http://ehcache.org Highest Product pom artifactid ehcache-impl Highest Product pom developer email tc-oss@softwareag.com Low Product pom developer name Terracotta Engineers Low Product pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low Product pom developer org URL http://ehcache.org Low Product pom groupid org.ehcache.modules Highest Product pom name Ehcache 3 Implementation module High Product pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low Product pom organization url http://terracotta.org Low Product pom url http://ehcache.org Medium Version pom version 3.10.9 Highest
ehcache-3.10.9.jar (shaded: org.ehcache.modules:ehcache-xml-spi:3.10.9)Description:
This module contains the XML parsing SPI for Ehcache 3. This allows Ehcache extension services to provide XML configuration capabilities. License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/org/ehcache/ehcache/3.10.9/ehcache-3.10.9.jar/META-INF/maven/org.ehcache.modules/ehcache-xml-spi/pom.xml
MD5: 0fdc12d35c3b82110a6601869615698e
SHA1: b3988d89ef1edd03ce1b304db18375c03551c6ef
SHA256: e122fb7b9c7ad560a34da6df49db182035b3c7709927922ea0b771c02624e4de
Referenced In Project/Scope: fides-tool-ui-desktop:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid ehcache-xml-spi Low Vendor pom developer email tc-oss@softwareag.com Low Vendor pom developer name Terracotta Engineers Medium Vendor pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Medium Vendor pom developer org URL http://ehcache.org Medium Vendor pom groupid org.ehcache.modules Highest Vendor pom name Ehcache 3 XML Parsing SPI Module High Vendor pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. High Vendor pom organization url http://terracotta.org Medium Vendor pom url http://ehcache.org Highest Product pom artifactid ehcache-xml-spi Highest Product pom developer email tc-oss@softwareag.com Low Product pom developer name Terracotta Engineers Low Product pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low Product pom developer org URL http://ehcache.org Low Product pom groupid org.ehcache.modules Highest Product pom name Ehcache 3 XML Parsing SPI Module High Product pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low Product pom organization url http://terracotta.org Low Product pom url http://ehcache.org Medium Version pom version 3.10.9 Highest
ehcache-3.10.9.jar (shaded: org.ehcache.modules:ehcache-xml:3.10.9)Description:
The module containing all XML parsing logic Ehcache 3 License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/org/ehcache/ehcache/3.10.9/ehcache-3.10.9.jar/META-INF/maven/org.ehcache.modules/ehcache-xml/pom.xml
MD5: 18b7941044501bb7413d4d1b253e2dd7
SHA1: faf12f5ef9f9a4c667850c9d68f4e6c952272744
SHA256: 541eba0603acd33677be138dfb5b41a4818704e4d6921bbe2da1c312584bc3b0
Referenced In Project/Scope: fides-tool-ui-desktop:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid ehcache-xml Low Vendor pom developer email tc-oss@softwareag.com Low Vendor pom developer name Terracotta Engineers Medium Vendor pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Medium Vendor pom developer org URL http://ehcache.org Medium Vendor pom groupid org.ehcache.modules Highest Vendor pom name Ehcache 3 XML Parsing module High Vendor pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. High Vendor pom organization url http://terracotta.org Medium Vendor pom url http://ehcache.org Highest Product pom artifactid ehcache-xml Highest Product pom developer email tc-oss@softwareag.com Low Product pom developer name Terracotta Engineers Low Product pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low Product pom developer org URL http://ehcache.org Low Product pom groupid org.ehcache.modules Highest Product pom name Ehcache 3 XML Parsing module High Product pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low Product pom organization url http://terracotta.org Low Product pom url http://ehcache.org Medium Version pom version 3.10.9 Highest
ehcache-3.10.9.jar (shaded: org.ehcache:sizeof:0.4.3)Description:
SizeOf engine, extracted from Ehcache License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/org/ehcache/ehcache/3.10.9/ehcache-3.10.9.jar/META-INF/maven/org.ehcache/sizeof/pom.xml
MD5: c0ad3baef0ef03d4ca849743f1f26b70
SHA1: 8589b7bd18f4b3e12cd222a44bdcbbada5363da8
SHA256: 9c03a981dbff96ff6b7d74dffb5e8a9a46bb66e06ba98d18f6b8ff4472bd0709
Referenced In Project/Scope: fides-tool-ui-desktop:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid sizeof Low Vendor pom groupid org.ehcache Highest Vendor pom name Ehcache SizeOf Engine High Vendor pom organization name Terracotta High Vendor pom organization url http://terracotta.org Medium Vendor pom url ehcache/sizeof Highest Product pom artifactid sizeof Highest Product pom groupid org.ehcache Highest Product pom name Ehcache SizeOf Engine High Product pom organization name Terracotta Low Product pom organization url http://terracotta.org Low Product pom url ehcache/sizeof High Version pom version 0.4.3 Highest
ehcache-3.10.9.jar (shaded: org.terracotta:fast-restartable-store:1.6.10)File Path: /var/jenkins_home/.m2/repository/org/ehcache/ehcache/3.10.9/ehcache-3.10.9.jar/META-INF/maven/org.terracotta/fast-restartable-store/pom.xmlMD5: 8f0f230c65db7e3c578e8869e7187a82SHA1: 7dc4a86d5fe3f0531c10df047271076d738ebe4aSHA256: 7cbeb173bc14daac42de34f30e317f36e37043b2beb04c77a3518c1d90380415Referenced In Project/Scope: fides-tool-ui-desktop:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid fast-restartable-store Low Vendor pom groupid org.terracotta Highest Vendor pom name fast-restartable-store High Vendor pom parent-artifactid terracotta-parent Low Product pom artifactid fast-restartable-store Highest Product pom groupid org.terracotta Highest Product pom name fast-restartable-store High Product pom parent-artifactid terracotta-parent Medium Version pom parent-version 1.6.10 Low Version pom version 1.6.10 Highest
ehcache-3.10.9.jar (shaded: org.terracotta:offheap-store:2.5.5)Description:
A library that offers data structures allocated off the java heap. License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/org/ehcache/ehcache/3.10.9/ehcache-3.10.9.jar/META-INF/maven/org.terracotta/offheap-store/pom.xml
MD5: f7bf911658d136d41dd38ec3111608e8
SHA1: 3363fddddcf6fe228d4bd684d79f7ffd1c9876df
SHA256: 2739a6e286415e85e05a9fa2f74428b7a8cbc6dd5c8325f0f03655cefedde1b2
Referenced In Project/Scope: fides-tool-ui-desktop:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid offheap-store Low Vendor pom developer email chris.dennis@terracottatech.com Low Vendor pom developer name Chris Dennis Medium Vendor pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Medium Vendor pom developer org URL https://terracotta.org Medium Vendor pom groupid org.terracotta Highest Vendor pom name Terracotta Off-Heap Store High Vendor pom parent-artifactid terracotta-parent Low Vendor pom url Terracotta-OSS/offheap-store/ Highest Product pom artifactid offheap-store Highest Product pom developer email chris.dennis@terracottatech.com Low Product pom developer name Chris Dennis Low Product pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low Product pom developer org URL https://terracotta.org Low Product pom groupid org.terracotta Highest Product pom name Terracotta Off-Heap Store High Product pom parent-artifactid terracotta-parent Medium Product pom url Terracotta-OSS/offheap-store/ High Version pom parent-version 2.5.5 Low Version pom version 2.5.5 Highest
ehcache-3.10.9.jar (shaded: org.terracotta:statistics:2.1.2)Description:
A statistics framework used inside Ehcache and the Terracotta products License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/org/ehcache/ehcache/3.10.9/ehcache-3.10.9.jar/META-INF/maven/org.terracotta/statistics/pom.xml
MD5: 9df3f5a18142de19c1c7f379885a4391
SHA1: 305a0214578ebf1c14e8d78adce1a5af028c8132
SHA256: 25c36806fdcd2ab5e4c1c1c5625bc4f966c10a4a93ab3dd321aa82b3f9e43081
Referenced In Project/Scope: fides-tool-ui-desktop:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid statistics Low Vendor pom developer email chris.dennis@terracottatech.com Low Vendor pom developer email Chris.Schanck@terracottatech.com Low Vendor pom developer email ludovic.orban@terracottatech.com Low Vendor pom developer name Chris Dennis Medium Vendor pom developer name Chris Schanck Medium Vendor pom developer name Ludovic Orban Medium Vendor pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Medium Vendor pom developer org URL https://terracotta.org Medium Vendor pom groupid org.terracotta Highest Vendor pom name Terracotta Statistics High Vendor pom url Terracotta-OSS/statistics Highest Product pom artifactid statistics Highest Product pom developer email chris.dennis@terracottatech.com Low Product pom developer email Chris.Schanck@terracottatech.com Low Product pom developer email ludovic.orban@terracottatech.com Low Product pom developer name Chris Dennis Low Product pom developer name Chris Schanck Low Product pom developer name Ludovic Orban Low Product pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low Product pom developer org URL https://terracotta.org Low Product pom groupid org.terracotta Highest Product pom name Terracotta Statistics High Product pom url Terracotta-OSS/statistics High Version pom version 2.1.2 Highest
ehcache-3.10.9.jar (shaded: org.terracotta:terracotta-utilities-tools:0.0.17)Description:
Utility classes/methods for common Java tasks License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/org/ehcache/ehcache/3.10.9/ehcache-3.10.9.jar/META-INF/maven/org.terracotta/terracotta-utilities-tools/pom.xml
MD5: 16fb5cf823dc55ddcebbe66a600fc55d
SHA1: 895abb2757ea0e257a12f700247fe7e4432bf9c4
SHA256: 0f4b9612a048634f484856cd6e3341e5bcc912eb8f0ec3d5bba5bedf76c8ca87
Referenced In Project/Scope: fides-tool-ui-desktop:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid terracotta-utilities-tools Low Vendor pom developer email clifford.johnson@softwareag.com Low Vendor pom developer name Clifford W Johnson Medium Vendor pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Medium Vendor pom developer org URL https://terracotta.org Medium Vendor pom groupid org.terracotta Highest Vendor pom name Terracotta Utilities Tools High Vendor pom parent-artifactid terracotta-utilities-parent Low Vendor pom url Terracotta-OSS/terracotta-utilities/ Highest Product pom artifactid terracotta-utilities-tools Highest Product pom developer email clifford.johnson@softwareag.com Low Product pom developer name Clifford W Johnson Low Product pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low Product pom developer org URL https://terracotta.org Low Product pom groupid org.terracotta Highest Product pom name Terracotta Utilities Tools High Product pom parent-artifactid terracotta-utilities-parent Medium Product pom url Terracotta-OSS/terracotta-utilities/ High Version pom version 0.0.17 Highest
ehcache-3.10.9.jarDescription:
End-user ehcache3 jar artifact License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/org/ehcache/ehcache/3.10.9/ehcache-3.10.9.jar
MD5: 916b64a3f93df9e99c08231fd666c522
SHA1: 19c98036524575bff4bb040ecac9cf547cc175cc
SHA256: f22d97693b02b5b95169799340c009862f4935082130b630bb64780dbafaf718
Referenced In Project/Scope: fides-tool-ui-desktop:compile
ehcache-3.10.9.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name ehcache High Vendor jar package name ehcache Highest Vendor jar package name org Highest Vendor jar package name terracotta Highest Vendor Manifest bundle-docurl http://ehcache.org Low Vendor Manifest bundle-symbolicname org.ehcache Medium Vendor Manifest implementation-revision 6cb5a50d73a9f33c574a754559bc963e64cfd151 Low Vendor Manifest Implementation-Vendor-Id org.ehcache Medium Vendor Manifest provide-capability osgi.service;objectClass:List="javax.cache.spi.CachingProvider";uses:="javax.cache.spi",osgi.service;objectClass:List="org.ehcache.core.spi.service.ServiceFactory";uses:="org.ehcache.core.spi.service",osgi.service;objectClass:List="org.ehcache.xml.CacheManagerServiceConfigurationParser";uses:="org.ehcache.xml",osgi.service;objectClass:List="org.ehcache.xml.CacheServiceConfigurationParser";uses:="org.ehcache.xml" Low Vendor Manifest service-component OSGI-INF/*.xml Low Vendor pom artifactid ehcache Highest Vendor pom artifactid ehcache Low Vendor pom developer email tc-oss@softwareag.com Low Vendor pom developer name Terracotta Engineers Medium Vendor pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Medium Vendor pom developer org URL http://ehcache.org Medium Vendor pom groupid org.ehcache Highest Vendor pom name Ehcache High Vendor pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. High Vendor pom organization url http://terracotta.org Medium Vendor pom url http://ehcache.org Highest Product file name ehcache High Product jar package name cache Highest Product jar package name cachemanagerserviceconfigurationparser Highest Product jar package name cacheserviceconfigurationparser Highest Product jar package name core Highest Product jar package name ehcache Highest Product jar package name org Highest Product jar package name osgi Highest Product jar package name service Highest Product jar package name spi Highest Product jar package name terracotta Highest Product jar package name xml Highest Product Manifest bundle-docurl http://ehcache.org Low Product Manifest Bundle-Name Ehcache 3 Medium Product Manifest bundle-symbolicname org.ehcache Medium Product Manifest implementation-revision 6cb5a50d73a9f33c574a754559bc963e64cfd151 Low Product Manifest Implementation-Title ehcache High Product Manifest provide-capability osgi.service;objectClass:List="javax.cache.spi.CachingProvider";uses:="javax.cache.spi",osgi.service;objectClass:List="org.ehcache.core.spi.service.ServiceFactory";uses:="org.ehcache.core.spi.service",osgi.service;objectClass:List="org.ehcache.xml.CacheManagerServiceConfigurationParser";uses:="org.ehcache.xml",osgi.service;objectClass:List="org.ehcache.xml.CacheServiceConfigurationParser";uses:="org.ehcache.xml" Low Product Manifest service-component OSGI-INF/*.xml Low Product pom artifactid ehcache Highest Product pom developer email tc-oss@softwareag.com Low Product pom developer name Terracotta Engineers Low Product pom developer org Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low Product pom developer org URL http://ehcache.org Low Product pom groupid org.ehcache Highest Product pom name Ehcache High Product pom organization name Terracotta Inc., a wholly-owned subsidiary of Software AG USA, Inc. Low Product pom organization url http://terracotta.org Low Product pom url http://ehcache.org Medium Version file version 3.10.9 High Version Manifest Bundle-Version 3.10.9 High Version Manifest Implementation-Version 3.10.9 High Version pom version 3.10.9 Highest
ehcache-3.10.9.jar: sizeof-agent.jarFile Path: /var/jenkins_home/.m2/repository/org/ehcache/ehcache/3.10.9/ehcache-3.10.9.jar/org/ehcache/sizeof/impl/sizeof-agent.jarMD5: 532dbbf741bfb7f531938786bc0bb970SHA1: 4e5d8c485b09104825c0d8ec635f775ab522be06SHA256: 60e093acb08d3bc30235ef15941380195cbb85b1ec8b4afd672249f9c530e356Referenced In Project/Scope: fides-tool-ui-desktop:compile
Evidence Type Source Name Value Confidence Vendor file name sizeof-agent High Vendor jar package name ehcache Low Vendor jar package name impl Low Vendor jar package name sizeof Low Product file name sizeof-agent High Product jar package name impl Low Product jar package name sizeof Low Product jar package name sizeofagent Low
exp4j-0.4.8.jarDescription:
A simple mathematical expression evaluator for java. License:
Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0 File Path: /var/jenkins_home/.m2/repository/net/objecthunter/exp4j/0.4.8/exp4j-0.4.8.jar
MD5: 5c554588bdf3319842a4fa66136c0119
SHA1: cf1cfc0f958077d86ac7452c7e36d944689b2ec4
SHA256: 271f7824ee8a3468257bc0613afdabb67597af8389317643fa806b983b7ecb27
Referenced In Project/Scope: fides-tool-ui-desktop:compile
exp4j-0.4.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name exp4j High Vendor jar package name exp4j Highest Vendor jar package name exp4j Low Vendor jar package name expression Highest Vendor jar package name net Highest Vendor jar package name net Low Vendor jar package name objecthunter Highest Vendor jar package name objecthunter Low Vendor pom artifactid exp4j Highest Vendor pom artifactid exp4j Low Vendor pom developer email frank.asseg@objecthunter.net Low Vendor pom developer id fas Medium Vendor pom developer name frank Medium Vendor pom developer org URL http://www.objecthunter.net Medium Vendor pom groupid net.objecthunter Highest Vendor pom name exp4j High Vendor pom url http://www.objecthunter.net/exp4j Highest Product file name exp4j High Product jar package name exp4j Highest Product jar package name exp4j Low Product jar package name expression Highest Product jar package name net Highest Product jar package name objecthunter Highest Product jar package name objecthunter Low Product pom artifactid exp4j Highest Product pom developer email frank.asseg@objecthunter.net Low Product pom developer id fas Low Product pom developer name frank Low Product pom developer org URL http://www.objecthunter.net Low Product pom groupid net.objecthunter Highest Product pom name exp4j High Product pom url http://www.objecthunter.net/exp4j Medium Version file version 0.4.8 High Version pom version 0.4.8 Highest
fides-tool-api-1.0.jarFile Path: /var/jenkins_home/workspace/Fides_Multi_desktop-production/Fides/fides-tool-api/target/fides-tool-api-1.0.jarMD5: eb9c2a9db56b43312f1a5915842ce76dSHA1: 45e018e3c4c72efea1a96c78fefb5e11b79017e3SHA256: 4da7663264d20ec91db9954c823a5e223d73b9165c7c1753bca5878d7916b762Referenced In Project/Scope: fides-tool-ui-desktop:compilefides-tool-api-1.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui-desktop@1.5.6
Evidence Type Source Name Value Confidence Vendor file name fides-tool-api High Vendor jar package name api Highest Vendor jar package name eu Highest Vendor jar package name fides Highest Vendor jar package name imdr Highest Vendor Manifest Implementation-Vendor-Id eu.imdr Medium Vendor pom artifactid fides-tool-api Highest Vendor pom artifactid fides-tool-api Low Vendor pom groupid eu.imdr Highest Vendor pom parent-artifactid fides-tool-parent Low Product file name fides-tool-api High Product jar package name api Highest Product jar package name eu Highest Product jar package name fides Highest Product jar package name imdr Highest Product Manifest Implementation-Title fides-tool-api High Product pom artifactid fides-tool-api Highest Product pom groupid eu.imdr Highest Product pom parent-artifactid fides-tool-parent Medium Version file version 1.0 High Version Manifest Implementation-Version 1.0 High Version pom version 1.0 Highest
fides-tool-common-1.0.jarFile Path: /var/jenkins_home/workspace/Fides_Multi_desktop-production/Fides/fides-tool-common/target/fides-tool-common-1.0.jarMD5: 69f6a6f3bafd07d1fe6427b23876111aSHA1: 943a63351cf2cb5d67deaa587eb6ec6fb149ef3eSHA256: 3d3ae4e8c38641ff9202cd78a21de53eee5cee63d72839cc29b09568cbcc3effReferenced In Project/Scope: fides-tool-ui-desktop:compilefides-tool-common-1.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name fides-tool-common High Vendor jar package name eu Highest Vendor jar package name fides Highest Vendor jar package name imdr Highest Vendor Manifest Implementation-Vendor-Id eu.imdr Medium Vendor pom artifactid fides-tool-common Highest Vendor pom artifactid fides-tool-common Low Vendor pom groupid eu.imdr Highest Vendor pom parent-artifactid fides-tool-parent Low Product file name fides-tool-common High Product jar package name eu Highest Product jar package name fides Highest Product jar package name imdr Highest Product Manifest Implementation-Title fides-tool-common High Product pom artifactid fides-tool-common Highest Product pom groupid eu.imdr Highest Product pom parent-artifactid fides-tool-parent Medium Version file version 1.0 High Version Manifest Implementation-Version 1.0 High Version pom version 1.0 Highest
fides-tool-engine-1.0.jarFile Path: /var/jenkins_home/workspace/Fides_Multi_desktop-production/Fides/fides-tool-engine/target/fides-tool-engine-1.0.jarMD5: d239deee1887075e873b41e5ddb679b9SHA1: 30ead189b9aac2b20399e46e4824c8a7921b67b7SHA256: f9c5288a6518c8a8418bf7fd23738ab39301fe5c111f47d4144eb0b7b6c38103Referenced In Project/Scope: fides-tool-ui-desktop:compilefides-tool-engine-1.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name fides-tool-engine High Vendor jar package name engine Highest Vendor jar package name eu Highest Vendor jar package name fides Highest Vendor jar package name imdr Highest Vendor Manifest Implementation-Vendor-Id eu.imdr Medium Vendor pom artifactid fides-tool-engine Highest Vendor pom artifactid fides-tool-engine Low Vendor pom groupid eu.imdr Highest Vendor pom parent-artifactid fides-tool-parent Low Product file name fides-tool-engine High Product jar package name engine Highest Product jar package name eu Highest Product jar package name fides Highest Product jar package name imdr Highest Product Manifest Implementation-Title fides-tool-engine High Product pom artifactid fides-tool-engine Highest Product pom groupid eu.imdr Highest Product pom parent-artifactid fides-tool-parent Medium Version file version 1.0 High Version Manifest Implementation-Version 1.0 High Version pom version 1.0 Highest
fides-tool-persistence-1.0.jarFile Path: /var/jenkins_home/workspace/Fides_Multi_desktop-production/Fides/fides-tool-persistence/target/fides-tool-persistence-1.0.jarMD5: 96e06b053b7cfdfa0ceb1918827b88fdSHA1: f22aa04d09f244bb6d2e24ab59a7b51a879597d5SHA256: dc3d7899cb3331897457d5d4724fbf1b5a78c10d06f4562e28912621dee77ee1Referenced In Project/Scope: fides-tool-ui-desktop:compilefides-tool-persistence-1.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name fides-tool-persistence High Vendor jar package name eu Highest Vendor jar package name fides Highest Vendor jar package name imdr Highest Vendor jar package name persistence Highest Vendor Manifest Implementation-Vendor-Id eu.imdr Medium Vendor pom artifactid fides-tool-persistence Highest Vendor pom artifactid fides-tool-persistence Low Vendor pom groupid eu.imdr Highest Vendor pom parent-artifactid fides-tool-parent Low Product file name fides-tool-persistence High Product jar package name eu Highest Product jar package name fides Highest Product jar package name imdr Highest Product jar package name persistence Highest Product Manifest Implementation-Title fides-tool-persistence High Product pom artifactid fides-tool-persistence Highest Product pom groupid eu.imdr Highest Product pom parent-artifactid fides-tool-parent Medium Version file version 1.0 High Version Manifest Implementation-Version 1.0 High Version pom version 1.0 Highest
fides-tool-ui-1.5.6.jarFile Path: /var/jenkins_home/workspace/Fides_Multi_desktop-production/Fides/fides-tool-ui/target/fides-tool-ui-1.5.6.jarMD5: bbfef51573d7df480415b9b0da5e6496SHA1: 1a1a69861e0b091e88c6134d882fb325d88fb494SHA256: ebdb333ad80b653be88bae669d49a05db31166d11963792610f0568adb584388Referenced In Project/Scope: fides-tool-ui-desktop:compilefides-tool-ui-1.5.6.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui-desktop@1.5.6
Evidence Type Source Name Value Confidence Vendor file name fides-tool-ui High Vendor jar package name eu Highest Vendor jar package name fides Highest Vendor jar package name imdr Highest Vendor jar package name ui Highest Vendor Manifest Implementation-Vendor-Id eu.imdr Medium Vendor pom artifactid fides-tool-ui Highest Vendor pom artifactid fides-tool-ui Low Vendor pom groupid eu.imdr Highest Vendor pom parent-artifactid fides-tool-parent Low Product file name fides-tool-ui High Product jar package name eu Highest Product jar package name fides Highest Product jar package name imdr Highest Product jar package name ui Highest Product Manifest Implementation-Title fides-tool-ui High Product pom artifactid fides-tool-ui Highest Product pom groupid eu.imdr Highest Product pom parent-artifactid fides-tool-parent Medium Version file version 1.5.6 High Version Manifest Implementation-Version 1.5.6 High Version pom parent-version 1.5.6 Low Version pom version 1.5.6 Highest
flatlaf-3.5.jarDescription:
Flat Look and Feel License:
The Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/com/formdev/flatlaf/3.5/flatlaf-3.5.jar
MD5: f37660c8d78199e83434430e4aad59aa
SHA1: 5ba0ba8ca4a1942bfff4a2771565f125c07a56a6
SHA256: 0ead65f732e0934c6674e040deeb5e4c05fd932604a51bb1bf066d8909679769
Referenced In Project/Scope: fides-tool-ui-desktop:compile
flatlaf-3.5.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.satodev/std-commons-desktop@7.0
Evidence Type Source Name Value Confidence Vendor file name flatlaf High Vendor jar package name com Highest Vendor jar package name flatlaf Highest Vendor jar package name formdev Highest Vendor Manifest implementation-copyright Copyright (C) 2019-2024 FormDev Software GmbH. All rights reserved. Low Vendor Manifest Implementation-Vendor FormDev Software GmbH High Vendor Manifest multi-release true Low Vendor pom artifactid flatlaf Highest Vendor pom artifactid flatlaf Low Vendor pom developer name Karl Tauber Medium Vendor pom developer org FormDev Software GmbH Medium Vendor pom developer org URL https://www.formdev.com/ Medium Vendor pom groupid com.formdev Highest Vendor pom name FlatLaf High Vendor pom url JFormDesigner/FlatLaf Highest Product file name flatlaf High Product jar package name com Highest Product jar package name flatlaf Highest Product jar package name formdev Highest Product Manifest implementation-copyright Copyright (C) 2019-2024 FormDev Software GmbH. All rights reserved. Low Product Manifest multi-release true Low Product pom artifactid flatlaf Highest Product pom developer name Karl Tauber Low Product pom developer org FormDev Software GmbH Low Product pom developer org URL https://www.formdev.com/ Low Product pom groupid com.formdev Highest Product pom name FlatLaf High Product pom url JFormDesigner/FlatLaf High Version file version 3.5 High Version Manifest Implementation-Version 3.5 High Version pom version 3.5 Highest
flatlaf-3.5.jar: flatlaf-windows-arm64.dllFile Path: /var/jenkins_home/.m2/repository/com/formdev/flatlaf/3.5/flatlaf-3.5.jar/com/formdev/flatlaf/natives/flatlaf-windows-arm64.dllMD5: 9adc1896f6c8ee163fc6fd4189fd84c7SHA1: 092c692c71b82a8aa955abcae683e71394b8091bSHA256: 7c3073c6fe96be83eeddc2380e73cd3c591d44810c1249ed2cd51c50836f2a07Referenced In Project/Scope: fides-tool-ui-desktop:compile
Evidence Type Source Name Value Confidence Vendor file name flatlaf-windows-arm64 High Product file name flatlaf-windows-arm64 High Version file name flatlaf-windows-arm64 Medium Version file version 64 Medium
flatlaf-3.5.jar: flatlaf-windows-x86.dllFile Path: /var/jenkins_home/.m2/repository/com/formdev/flatlaf/3.5/flatlaf-3.5.jar/com/formdev/flatlaf/natives/flatlaf-windows-x86.dllMD5: e2356ea2ea840926c817709dc577979dSHA1: ba74d19365968acd9eef79f57590b64480ac83eaSHA256: a5415cd32df7aeff6f9b39fb08767ba47d75f4c93d8cf409e6ea95e87530c4d3Referenced In Project/Scope: fides-tool-ui-desktop:compile
Evidence Type Source Name Value Confidence Vendor file name flatlaf-windows-x86 High Product file name flatlaf-windows-x86 High Version file name flatlaf-windows-x86 Medium Version file version 86 Medium
flatlaf-3.5.jar: flatlaf-windows-x86_64.dllFile Path: /var/jenkins_home/.m2/repository/com/formdev/flatlaf/3.5/flatlaf-3.5.jar/com/formdev/flatlaf/natives/flatlaf-windows-x86_64.dllMD5: b785b258aec2821d114cad48eb6992dcSHA1: c7d147ff7c92a2a72fbe63aca888a424b4684d52SHA256: 1056954c89c770358d8871f6d69e16bce5fc76f19e8d145a2388f7badd7cdff3Referenced In Project/Scope: fides-tool-ui-desktop:compile
Evidence Type Source Name Value Confidence Vendor file name flatlaf-windows-x86_64 High Product file name flatlaf-windows-x86_64 High
h2-2.4.240.jarDescription:
H2 Database Engine License:
MPL 2.0: https://www.mozilla.org/en-US/MPL/2.0/
EPL 1.0: https://opensource.org/licenses/eclipse-1.0.php File Path: /var/jenkins_home/.m2/repository/com/h2database/h2/2.4.240/h2-2.4.240.jar
MD5: fb14a47b07dfd4381a608d3adb89dc25
SHA1: 686180ad33981ad943fdc0ab381e619b2c2fdfe5
SHA256: 29b70e427cc1c40cdc376283adbb0cc62853073797bb5fe5761f81fe73d57ce0
Referenced In Project/Scope: fides-tool-ui-desktop:runtime
h2-2.4.240.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui-desktop@1.5.6
Evidence Type Source Name Value Confidence Vendor file name h2 High Vendor jar package name database Highest Vendor jar package name engine Highest Vendor jar package name h2 Highest Vendor Manifest automatic-module-name com.h2database Medium Vendor Manifest bundle-category jdbc Low Vendor Manifest bundle-symbolicname com.h2database Medium Vendor Manifest implementation-url https://h2database.com Low Vendor Manifest multi-release true Low Vendor Manifest provide-capability osgi.service;objectClass:List=org.osgi.service.jdbc.DataSourceFactory Low Vendor pom artifactid h2 Highest Vendor pom artifactid h2 Low Vendor pom developer email thomas.tom.mueller at gmail dot com Low Vendor pom developer id thomas.tom.mueller Medium Vendor pom developer name Thomas Mueller Medium Vendor pom groupid com.h2database Highest Vendor pom name H2 Database Engine High Vendor pom url https://h2database.com Highest Product file name h2 High Product jar package name database Highest Product jar package name engine Highest Product jar package name h2 Highest Product jar package name jdbc Highest Product jar package name org Highest Product jar package name service Highest Product Manifest automatic-module-name com.h2database Medium Product Manifest bundle-category jdbc Low Product Manifest Bundle-Name H2 Database Engine Medium Product Manifest bundle-symbolicname com.h2database Medium Product Manifest Implementation-Title H2 Database Engine High Product Manifest implementation-url https://h2database.com Low Product Manifest multi-release true Low Product Manifest provide-capability osgi.service;objectClass:List=org.osgi.service.jdbc.DataSourceFactory Low Product pom artifactid h2 Highest Product pom developer email thomas.tom.mueller at gmail dot com Low Product pom developer id thomas.tom.mueller Low Product pom developer name Thomas Mueller Low Product pom groupid com.h2database Highest Product pom name H2 Database Engine High Product pom url https://h2database.com Medium Version file version 2.4.240 High Version Manifest Bundle-Version 2.4.240 High Version Manifest Implementation-Version 2.4.240 High Version pom version 2.4.240 Highest
CVE-2018-14335 (OSSINDEX) suppress
h2database - Improper Link Resolution Before File Access CWE-59 Improper Link Resolution Before File Access ('Link Following')
CVSSv3:
Base Score: MEDIUM (6.0) Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:com.h2database:h2:2.4.240:*:*:*:*:*:*:* h2-2.4.240.jar: data.zip: table.jsFile Path: /var/jenkins_home/.m2/repository/com/h2database/h2/2.4.240/h2-2.4.240.jar/org/h2/util/data.zip/org/h2/server/web/res/table.jsMD5: ca07fc6140e278428c7704453d30bed5SHA1: 8044d5d7aecfa0cd1cbb897af398492ac5c8af7eSHA256: 968e1c570a30b2383db9fc67150ac924df171fe587c44996bdd08f2f14b7a017Referenced In Project/Scope: fides-tool-ui-desktop:runtime
Evidence Type Source Name Value Confidence
h2-2.4.240.jar: data.zip: tree.jsFile Path: /var/jenkins_home/.m2/repository/com/h2database/h2/2.4.240/h2-2.4.240.jar/org/h2/util/data.zip/org/h2/server/web/res/tree.jsMD5: c2620dfa674439d78be770a2588a3e56SHA1: 0c6bc6d3eb88131d071938de4e5514e1f182e1f9SHA256: 9f933afa133f72bd51e7904e54792418ed1595e35005e48b72af1f7fbccd8963Referenced In Project/Scope: fides-tool-ui-desktop:runtime
Evidence Type Source Name Value Confidence
hibernate-commons-annotations-7.0.3.Final.jarDescription:
Common reflection code used in support of annotation processing License:
Apache License Version 2.0: https://opensource.org/licenses/Apache-2.0 File Path: /var/jenkins_home/.m2/repository/org/hibernate/common/hibernate-commons-annotations/7.0.3.Final/hibernate-commons-annotations-7.0.3.Final.jar
MD5: 6698f99235fe6d36c42caaf2e6b52797
SHA1: e183c4be8bb41d12e9f19b374e00c34a0a85f439
SHA256: 0db2fd57d5e43688ac6ed5cdf36deaf05d84340dcc24c2dd2a2114de38e5175d
Referenced In Project/Scope: fides-tool-ui-desktop:runtime
hibernate-commons-annotations-7.0.3.Final.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name hibernate-commons-annotations High Vendor hint analyzer vendor redhat Highest Vendor jar package name annotations Highest Vendor jar package name common Highest Vendor jar package name hibernate Highest Vendor jar package name reflection Highest Vendor Manifest implementation-url http://hibernate.org Low Vendor Manifest Implementation-Vendor Hibernate.org High Vendor Manifest Implementation-Vendor-Id org.hibernate Medium Vendor pom artifactid hibernate-commons-annotations Highest Vendor pom artifactid hibernate-commons-annotations Low Vendor pom developer id hibernate-team Medium Vendor pom developer name The Hibernate Development Team Medium Vendor pom developer org Hibernate.org Medium Vendor pom developer org URL http://hibernate.org Medium Vendor pom groupid org.hibernate.common Highest Vendor pom name Hibernate Commons Annotations High Vendor pom organization name Hibernate.org High Vendor pom organization url http://hibernate.org Medium Vendor pom url http://hibernate.org Highest Product file name hibernate-commons-annotations High Product jar package name annotations Highest Product jar package name common Highest Product jar package name hibernate Highest Product jar package name reflection Highest Product Manifest implementation-url http://hibernate.org Low Product pom artifactid hibernate-commons-annotations Highest Product pom developer id hibernate-team Low Product pom developer name The Hibernate Development Team Low Product pom developer org Hibernate.org Low Product pom developer org URL http://hibernate.org Low Product pom groupid org.hibernate.common Highest Product pom name Hibernate Commons Annotations High Product pom organization name Hibernate.org Low Product pom organization url http://hibernate.org Low Product pom url http://hibernate.org Medium Version Manifest Implementation-Version 7.0.3.Final High Version pom version 7.0.3.Final Highest
hibernate-core-6.6.29.Final.jarDescription:
Hibernate's core ORM functionality License:
GNU Library General Public License v2.1 or later: https://www.opensource.org/licenses/LGPL-2.1 File Path: /var/jenkins_home/.m2/repository/org/hibernate/orm/hibernate-core/6.6.29.Final/hibernate-core-6.6.29.Final.jar
MD5: 803edf8cbb9c6e5dd1b856fb08969c87
SHA1: d12db68bb867e2fe6e68740b3fba3d1d633f77ff
SHA256: a769334ed1b477afc7f3c1ec4f368d1dcd9f6535ab272a8560037e4f163a0a1f
Referenced In Project/Scope: fides-tool-ui-desktop:compile
hibernate-core-6.6.29.Final.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name hibernate-core High Vendor hint analyzer vendor redhat Highest Vendor jar package name hibernate Highest Vendor Manifest automatic-module-name org.hibernate.orm.core Medium Vendor Manifest bundle-docurl https://www.hibernate.org/orm/6.6 Low Vendor Manifest bundle-symbolicname org.hibernate.orm.core Medium Vendor Manifest implementation-url https://hibernate.org/orm Low Vendor Manifest Implementation-Vendor Hibernate.org High Vendor Manifest Implementation-Vendor-Id org.hibernate Medium Vendor Manifest specification-vendor Hibernate.org Low Vendor pom artifactid hibernate-core Highest Vendor pom artifactid hibernate-core Low Vendor pom developer id hibernate-team Medium Vendor pom developer name The Hibernate Development Team Medium Vendor pom developer org Hibernate.org Medium Vendor pom developer org URL https://hibernate.org Medium Vendor pom groupid org.hibernate.orm Highest Vendor pom name Hibernate ORM - hibernate-core High Vendor pom organization name Hibernate.org High Vendor pom organization url https://hibernate.org Medium Vendor pom url https://hibernate.org/orm Highest Product file name hibernate-core High Product jar package name hibernate Highest Product Manifest automatic-module-name org.hibernate.orm.core Medium Product Manifest bundle-docurl https://www.hibernate.org/orm/6.6 Low Product Manifest Bundle-Name hibernate-core Medium Product Manifest bundle-symbolicname org.hibernate.orm.core Medium Product Manifest Implementation-Title hibernate-core High Product Manifest implementation-url https://hibernate.org/orm Low Product Manifest specification-title hibernate-core Medium Product pom artifactid hibernate-core Highest Product pom developer id hibernate-team Low Product pom developer name The Hibernate Development Team Low Product pom developer org Hibernate.org Low Product pom developer org URL https://hibernate.org Low Product pom groupid org.hibernate.orm Highest Product pom name Hibernate ORM - hibernate-core High Product pom organization name Hibernate.org Low Product pom organization url https://hibernate.org Low Product pom url https://hibernate.org/orm Medium Version Manifest Bundle-Version 6.6.29.Final High Version Manifest Implementation-Version 6.6.29.Final High Version pom version 6.6.29.Final Highest
hibernate-jcache-6.6.13.Final.jarDescription:
Integration for javax.cache into Hibernate as a second-level caching service License:
GNU Library General Public License v2.1 or later: https://www.opensource.org/licenses/LGPL-2.1 File Path: /var/jenkins_home/.m2/repository/org/hibernate/orm/hibernate-jcache/6.6.13.Final/hibernate-jcache-6.6.13.Final.jar
MD5: ecfe70696fa3ae18476f0b55209455e4
SHA1: 555049af043f6cdec0f4f2f637a5a41f49b738a0
SHA256: 48fbaf23cb96d8d6ef3317087ca472943cb6042761d7baae1f2a96dddc87c704
Referenced In Project/Scope: fides-tool-ui-desktop:compile
hibernate-jcache-6.6.13.Final.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name hibernate-jcache High Vendor hint analyzer vendor redhat Highest Vendor jar package name cache Highest Vendor jar package name hibernate Highest Vendor jar package name jcache Highest Vendor Manifest automatic-module-name org.hibernate.orm.jcache Medium Vendor Manifest bundle-docurl https://www.hibernate.org/orm/6.6 Low Vendor Manifest bundle-symbolicname org.hibernate.orm.jcache Medium Vendor Manifest implementation-url https://hibernate.org/orm Low Vendor Manifest Implementation-Vendor Hibernate.org High Vendor Manifest Implementation-Vendor-Id org.hibernate Medium Vendor Manifest specification-vendor Hibernate.org Low Vendor pom artifactid hibernate-jcache Highest Vendor pom artifactid hibernate-jcache Low Vendor pom developer id hibernate-team Medium Vendor pom developer name The Hibernate Development Team Medium Vendor pom developer org Hibernate.org Medium Vendor pom developer org URL https://hibernate.org Medium Vendor pom groupid org.hibernate.orm Highest Vendor pom name Hibernate ORM - hibernate-jcache High Vendor pom organization name Hibernate.org High Vendor pom organization url https://hibernate.org Medium Vendor pom url https://hibernate.org/orm Highest Product file name hibernate-jcache High Product jar package name cache Highest Product jar package name hibernate Highest Product jar package name jcache Highest Product Manifest automatic-module-name org.hibernate.orm.jcache Medium Product Manifest bundle-docurl https://www.hibernate.org/orm/6.6 Low Product Manifest Bundle-Name hibernate-jcache Medium Product Manifest bundle-symbolicname org.hibernate.orm.jcache Medium Product Manifest Implementation-Title hibernate-jcache High Product Manifest implementation-url https://hibernate.org/orm Low Product Manifest specification-title hibernate-jcache Medium Product pom artifactid hibernate-jcache Highest Product pom developer id hibernate-team Low Product pom developer name The Hibernate Development Team Low Product pom developer org Hibernate.org Low Product pom developer org URL https://hibernate.org Low Product pom groupid org.hibernate.orm Highest Product pom name Hibernate ORM - hibernate-jcache High Product pom organization name Hibernate.org Low Product pom organization url https://hibernate.org Low Product pom url https://hibernate.org/orm Medium Version Manifest Bundle-Version 6.6.13.Final High Version Manifest Implementation-Version 6.6.13.Final High Version pom version 6.6.13.Final Highest
istack-commons-runtime-4.1.2.jarDescription:
istack common utility code License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /var/jenkins_home/.m2/repository/com/sun/istack/istack-commons-runtime/4.1.2/istack-commons-runtime-4.1.2.jar
MD5: 535154ef647af2a52478c4debec93659
SHA1: 18ec117c85f3ba0ac65409136afa8e42bc74e739
SHA256: 7fd6792361f4dd00f8c56af4a20cecc0066deea4a8f3dec38348af23fc2296ee
Referenced In Project/Scope: fides-tool-ui-desktop:runtime
istack-commons-runtime-4.1.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name istack-commons-runtime High Vendor jar package name istack Highest Vendor jar package name sun Highest Vendor jar (hint) package name oracle Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname com.sun.istack.commons-runtime Medium Vendor Manifest implementation-build-id 4.1.2 - 343a28e Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id com.sun.istack Medium Vendor pom artifactid istack-commons-runtime Highest Vendor pom artifactid istack-commons-runtime Low Vendor pom groupid com.sun.istack Highest Vendor pom name istack common utility code runtime High Vendor pom parent-artifactid istack-commons Low Product file name istack-commons-runtime High Product jar package name istack Highest Product jar package name sun Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name istack common utility code runtime Medium Product Manifest bundle-symbolicname com.sun.istack.commons-runtime Medium Product Manifest implementation-build-id 4.1.2 - 343a28e Low Product pom artifactid istack-commons-runtime Highest Product pom groupid com.sun.istack Highest Product pom name istack common utility code runtime High Product pom parent-artifactid istack-commons Medium Version file version 4.1.2 High Version Manifest Bundle-Version 4.1.2 High Version Manifest implementation-build-id 4.1.2 Low Version pom version 4.1.2 Highest
jackson-core-2.19.2.jarDescription:
Core Jackson processing abstractions (aka Streaming API), implementation for JSON License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.19.2/jackson-core-2.19.2.jar
MD5: b3843578b0753a9a685eea819dea3ab7
SHA1: 50f3b4bd59b9ff51a0ed493e7b5abaf5c39709bf
SHA256: aa77eaf29293a868c47372194f7c5287d77d9370b04ea25d3fffc1e4904b5880
Referenced In Project/Scope: fides-tool-ui-desktop:compile
jackson-core-2.19.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-json@3.5.6
Evidence Type Source Name Value Confidence Vendor file name jackson-core High Vendor jar package name base Highest Vendor jar package name com Highest Vendor jar package name core Highest Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor jar package name json Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor Manifest multi-release true Low Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-core Highest Vendor pom artifactid jackson-core Low Vendor pom groupid com.fasterxml.jackson.core Highest Vendor pom name Jackson-core High Vendor pom parent-artifactid jackson-base Low Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor pom url FasterXML/jackson-core Highest Product file name jackson-core High Product hint analyzer product java8 Highest Product hint analyzer product modules Highest Product jar package name base Highest Product jar package name com Highest Product jar package name core Highest Product jar package name fasterxml Highest Product jar package name jackson Highest Product jar package name json Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low Product Manifest Bundle-Name Jackson-core Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Product Manifest Implementation-Title Jackson-core High Product Manifest multi-release true Low Product Manifest specification-title Jackson-core Medium Product pom artifactid jackson-core Highest Product pom groupid com.fasterxml.jackson.core Highest Product pom name Jackson-core High Product pom parent-artifactid jackson-base Medium Product pom parent-groupid com.fasterxml.jackson Medium Product pom url FasterXML/jackson-core High Version file version 2.19.2 High Version Manifest Bundle-Version 2.19.2 High Version Manifest Implementation-Version 2.19.2 High Version pom version 2.19.2 Highest
Related Dependencies jackson-annotations-2.19.2.jarFile Path: /var/jenkins_home/.m2/repository/com/fasterxml/jackson/core/jackson-annotations/2.19.2/jackson-annotations-2.19.2.jar MD5: 99b71c4cebb9dae38ae925ac7ab0574f SHA1: 0c5381f11988ae3d424b197a26087d86067b6d7d SHA256: e516743a316dcf83c572ffc9cb6e8c5e8c134880c8c5155b02f7b34e9c5dc3cf pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.19.2 jackson-datatype-jdk8-2.19.2.jarFile Path: /var/jenkins_home/.m2/repository/com/fasterxml/jackson/datatype/jackson-datatype-jdk8/2.19.2/jackson-datatype-jdk8-2.19.2.jar MD5: 284d3188bc0c31d0bddf63ce34b4eace SHA1: a720d3946c3a1ab04b780f3b3163d62eee6948a0 SHA256: 6055fef10756e8bd1b0e8807aa1d881338c63ca95d59271e1da4922b9a17581e pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jdk8@2.19.2 jackson-datatype-jsr310-2.19.2.jarFile Path: /var/jenkins_home/.m2/repository/com/fasterxml/jackson/datatype/jackson-datatype-jsr310/2.19.2/jackson-datatype-jsr310-2.19.2.jar MD5: d7696f657f85fa3664f2a5fbd91febc2 SHA1: 72e73f048b36d9df82aef146bf8b2ae63b2e28e2 SHA256: 9709f43e0fa5625633ee66db6c078fb1e8c7ca02092696ba95ea785dbf0fa6a1 pkg:maven/com.fasterxml.jackson.datatype/jackson-datatype-jsr310@2.19.2 jackson-module-parameter-names-2.19.2.jarFile Path: /var/jenkins_home/.m2/repository/com/fasterxml/jackson/module/jackson-module-parameter-names/2.19.2/jackson-module-parameter-names-2.19.2.jar MD5: 001bf7f1db8b0d32fcf74a358e054f7b SHA1: 3c4ce467c11364c72ec4967c570fd5a2d1be1d0b SHA256: 5cafef98759b40a418631e91257930a5e30abc162d9a690c1e365dbbdacdfecb pkg:maven/com.fasterxml.jackson.module/jackson-module-parameter-names@2.19.2 jackson-databind-2.19.2.jarDescription:
General data-binding functionality for Jackson: works on core streaming API License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.19.2/jackson-databind-2.19.2.jar
MD5: 856506e1d49091e89599a3ef34990597
SHA1: 46509399d28f57ca32c6bb4b0d4e10e8f062051e
SHA256: 0a1bd4e9b0d670e632d40ee8c625ad376233502f03c2f5889baea95d025b47a7
Referenced In Project/Scope: fides-tool-ui-desktop:compile
jackson-databind-2.19.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-json@3.5.6
Evidence Type Source Name Value Confidence Vendor file name jackson-databind High Vendor jar package name databind Highest Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor Manifest multi-release true Low Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-databind Highest Vendor pom artifactid jackson-databind Low Vendor pom groupid com.fasterxml.jackson.core Highest Vendor pom name jackson-databind High Vendor pom parent-artifactid jackson-base Low Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor pom url FasterXML/jackson Highest Product file name jackson-databind High Product hint analyzer product java8 Highest Product hint analyzer product modules Highest Product jar package name databind Highest Product jar package name fasterxml Highest Product jar package name jackson Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low Product Manifest Bundle-Name jackson-databind Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium Product Manifest Implementation-Title jackson-databind High Product Manifest multi-release true Low Product Manifest specification-title jackson-databind Medium Product pom artifactid jackson-databind Highest Product pom groupid com.fasterxml.jackson.core Highest Product pom name jackson-databind High Product pom parent-artifactid jackson-base Medium Product pom parent-groupid com.fasterxml.jackson Medium Product pom url FasterXML/jackson High Version file version 2.19.2 High Version Manifest Bundle-Version 2.19.2 High Version Manifest Implementation-Version 2.19.2 High Version pom version 2.19.2 Highest
jakarta.activation-api-2.1.4.jarDescription:
Specification License:
EDL 1.0: http://www.eclipse.org/org/documents/edl-v10.php File Path: /var/jenkins_home/.m2/repository/jakarta/activation/jakarta.activation-api/2.1.4/jakarta.activation-api-2.1.4.jar
MD5: bc1602eee7bc61a0b86f14bbbb0cc794
SHA1: 9e5c2a0d75dde71a0bedc4dbdbe47b78a5dc50f8
SHA256: c9db52100ce6c8aac95cc39075f95720d2e561b11f8051b81c121ad4effd7004
Referenced In Project/Scope: fides-tool-ui-desktop:runtime
jakarta.activation-api-2.1.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name jakarta.activation-api High Vendor jar package name activation Highest Vendor jar package name jakarta Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.activation-api Medium Vendor Manifest extension-name jakarta.activation Medium Vendor Manifest implementation-build-id 3dad341 Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jakarta.activation-api Highest Vendor pom artifactid jakarta.activation-api Low Vendor pom developer email bill.shannon@oracle.com Low Vendor pom developer id shannon Medium Vendor pom developer name Bill Shannon Medium Vendor pom developer org Oracle Medium Vendor pom groupid jakarta.activation Highest Vendor pom name Jakarta Activation API High Vendor pom parent-artifactid project Low Vendor pom parent-groupid org.eclipse.ee4j Medium Vendor pom url jakartaee/jaf-api Highest Vendor pom (hint) developer org sun Medium Product file name jakarta.activation-api High Product jar package name activation Highest Product jar package name jakarta Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta Activation API Medium Product Manifest bundle-symbolicname jakarta.activation-api Medium Product Manifest extension-name jakarta.activation Medium Product Manifest implementation-build-id 3dad341 Low Product Manifest Implementation-Title Jakarta Activation API High Product Manifest specification-title Jakarta Activation Specification Medium Product pom artifactid jakarta.activation-api Highest Product pom developer email bill.shannon@oracle.com Low Product pom developer id shannon Low Product pom developer name Bill Shannon Low Product pom developer org Oracle Low Product pom groupid jakarta.activation Highest Product pom name Jakarta Activation API High Product pom parent-artifactid project Medium Product pom parent-groupid org.eclipse.ee4j Medium Product pom url jakartaee/jaf-api High Version file version 2.1.4 High Version Manifest Bundle-Version 2.1.4 High Version pom parent-version 2.1.4 Low Version pom version 2.1.4 Highest
jakarta.annotation-api-2.1.1.jarDescription:
Jakarta Annotations API License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html File Path: /var/jenkins_home/.m2/repository/jakarta/annotation/jakarta.annotation-api/2.1.1/jakarta.annotation-api-2.1.1.jar
MD5: 5dac2f68e8288d0add4dc92cb161711d
SHA1: 48b9bda22b091b1f48b13af03fe36db3be6e1ae3
SHA256: 5f65fdaf424eee2b55e1d882ba9bb376be93fb09b37b808be6e22e8851c909fe
Referenced In Project/Scope: fides-tool-ui-desktop:compile
jakarta.annotation-api-2.1.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name jakarta.annotation-api High Vendor jar package name annotation Highest Vendor jar package name jakarta Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.annotation-api Medium Vendor Manifest extension-name jakarta.annotation Medium Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jakarta.annotation-api Highest Vendor pom artifactid jakarta.annotation-api Low Vendor pom developer name Dmitry Kornilov Medium Vendor pom developer name Linda De Michiel Medium Vendor pom developer org Oracle Corp. Medium Vendor pom groupid jakarta.annotation Highest Vendor pom name Jakarta Annotations API High Vendor pom parent-artifactid project Low Vendor pom parent-groupid org.eclipse.ee4j Medium Vendor pom url https://projects.eclipse.org/projects/ee4j.ca Highest Product file name jakarta.annotation-api High Product jar package name annotation Highest Product jar package name jakarta Highest Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta Annotations API Medium Product Manifest bundle-symbolicname jakarta.annotation-api Medium Product Manifest extension-name jakarta.annotation Medium Product pom artifactid jakarta.annotation-api Highest Product pom developer name Dmitry Kornilov Low Product pom developer name Linda De Michiel Low Product pom developer org Oracle Corp. Low Product pom groupid jakarta.annotation Highest Product pom name Jakarta Annotations API High Product pom parent-artifactid project Medium Product pom parent-groupid org.eclipse.ee4j Medium Product pom url https://projects.eclipse.org/projects/ee4j.ca Medium Version file version 2.1.1 High Version Manifest Bundle-Version 2.1.1 High Version Manifest Implementation-Version 2.1.1 High Version pom parent-version 2.1.1 Low Version pom version 2.1.1 Highest
jakarta.inject-api-2.0.1.jarDescription:
Jakarta Dependency Injection License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/jakarta/inject/jakarta.inject-api/2.0.1/jakarta.inject-api-2.0.1.jar
MD5: 72003bf6efcc8455d414bbd7da86c11c
SHA1: 4c28afe1991a941d7702fe1362c365f0a8641d1e
SHA256: f7dc98062fccf14126abb751b64fab12c312566e8cbdc8483598bffcea93af7c
Referenced In Project/Scope: fides-tool-ui-desktop:runtime
jakarta.inject-api-2.0.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name jakarta.inject-api High Vendor jar package name inject Highest Vendor jar package name jakarta Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.inject.jakarta.inject-api Medium Vendor pom artifactid jakarta.inject-api Highest Vendor pom artifactid jakarta.inject-api Low Vendor pom developer email asd[at]redhat[dot]com Low Vendor pom developer email manovotn[at]redhat[dot]com Low Vendor pom developer email mkouba[at]redhat[dot]com Low Vendor pom developer email tremes[at]redhat[dot]com Low Vendor pom developer id asabotdu Medium Vendor pom developer id manovotn Medium Vendor pom developer id mkouba Medium Vendor pom developer id tremes Medium Vendor pom developer name Antoine Sabot-Durand Medium Vendor pom developer name Martin Kouba Medium Vendor pom developer name Matej Novotny Medium Vendor pom developer name Tomas Remes Medium Vendor pom developer org Red Hat Inc. Medium Vendor pom groupid jakarta.inject Highest Vendor pom name Jakarta Dependency Injection High Vendor pom parent-artifactid project Low Vendor pom parent-groupid org.eclipse.ee4j Medium Vendor pom url eclipse-ee4j/injection-api Highest Product file name jakarta.inject-api High Product jar package name inject Highest Product jar package name jakarta Highest Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta Dependency Injection Medium Product Manifest bundle-symbolicname jakarta.inject.jakarta.inject-api Medium Product pom artifactid jakarta.inject-api Highest Product pom developer email asd[at]redhat[dot]com Low Product pom developer email manovotn[at]redhat[dot]com Low Product pom developer email mkouba[at]redhat[dot]com Low Product pom developer email tremes[at]redhat[dot]com Low Product pom developer id asabotdu Low Product pom developer id manovotn Low Product pom developer id mkouba Low Product pom developer id tremes Low Product pom developer name Antoine Sabot-Durand Low Product pom developer name Martin Kouba Low Product pom developer name Matej Novotny Low Product pom developer name Tomas Remes Low Product pom developer org Red Hat Inc. Low Product pom groupid jakarta.inject Highest Product pom name Jakarta Dependency Injection High Product pom parent-artifactid project Medium Product pom parent-groupid org.eclipse.ee4j Medium Product pom url eclipse-ee4j/injection-api High Version file version 2.0.1 High Version Manifest Bundle-Version 2.0.1 High Version pom parent-version 2.0.1 Low Version pom version 2.0.1 Highest
jakarta.persistence-api-3.1.0.jarDescription:
Jakarta Persistence 3.1 API jar License:
Eclipse Public License v. 2.0: http://www.eclipse.org/legal/epl-2.0
Eclipse Distribution License v. 1.0: http://www.eclipse.org/org/documents/edl-v10.php File Path: /var/jenkins_home/.m2/repository/jakarta/persistence/jakarta.persistence-api/3.1.0/jakarta.persistence-api-3.1.0.jar
MD5: 35a1b7dfb38cf44ff795be607b0e6b5b
SHA1: 66901fa1c373c6aff65c13791cc11da72060a8d6
SHA256: 475389446d35c6f46c565728b756dc508c284644ea2690644e0d8e7e339d42fd
Referenced In Project/Scope: fides-tool-ui-desktop:compile
jakarta.persistence-api-3.1.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name jakarta.persistence-api High Vendor jar package name jakarta Highest Vendor jar package name persistence Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.persistence-api Medium Vendor Manifest extension-name jakarta.persistence Medium Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jakarta.persistence-api Highest Vendor pom artifactid jakarta.persistence-api Low Vendor pom developer id lukasj Medium Vendor pom developer name Lukas Jungmann Medium Vendor pom developer org Oracle, Inc. Medium Vendor pom groupid jakarta.persistence Highest Vendor pom name Jakarta Persistence API High Vendor pom parent-artifactid project Low Vendor pom parent-groupid org.eclipse.ee4j Medium Vendor pom url eclipse-ee4j/jpa-api Highest Product file name jakarta.persistence-api High Product jar package name jakarta Highest Product jar package name persistence Highest Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta Persistence API jar Medium Product Manifest bundle-symbolicname jakarta.persistence-api Medium Product Manifest extension-name jakarta.persistence Medium Product pom artifactid jakarta.persistence-api Highest Product pom developer id lukasj Low Product pom developer name Lukas Jungmann Low Product pom developer org Oracle, Inc. Low Product pom groupid jakarta.persistence Highest Product pom name Jakarta Persistence API High Product pom parent-artifactid project Medium Product pom parent-groupid org.eclipse.ee4j Medium Product pom url eclipse-ee4j/jpa-api High Version file version 3.1.0 High Version Manifest Bundle-Version 3.1.0 High Version Manifest Implementation-Version 3.1.0 High Version pom parent-version 3.1.0 Low Version pom version 3.1.0 Highest
jakarta.transaction-api-2.0.1.jarDescription:
Jakarta Transactions License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html File Path: /var/jenkins_home/.m2/repository/jakarta/transaction/jakarta.transaction-api/2.0.1/jakarta.transaction-api-2.0.1.jar
MD5: 5315974a3935e342b40849478e1c9966
SHA1: 51a520e3fae406abb84e2e1148e6746ce3f80a1a
SHA256: 50c0a7c760c13ae6c042acf182b28f0047413db95b4636fb8879bcffab5ba875
Referenced In Project/Scope: fides-tool-ui-desktop:compile
jakarta.transaction-api-2.0.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name jakarta.transaction-api High Vendor jar package name jakarta Highest Vendor jar package name transaction Highest Vendor Manifest automatic-module-name jakarta.transaction Medium Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://github.com/eclipse-ee4j Low Vendor Manifest bundle-symbolicname jakarta.transaction-api Medium Vendor Manifest extension-name jakarta.transaction Medium Vendor Manifest Implementation-Vendor EE4J Community High Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor Manifest specification-vendor Oracle Corporation Low Vendor pom artifactid jakarta.transaction-api Highest Vendor pom artifactid jakarta.transaction-api Low Vendor pom developer id stephen_felts Medium Vendor pom developer name Stephen Felts Medium Vendor pom developer org Oracle, Inc. Medium Vendor pom groupid jakarta.transaction Highest Vendor pom name API High Vendor pom name ${extension.name} API High Vendor pom organization name EE4J Community High Vendor pom organization url eclipse-ee4j Medium Vendor pom parent-artifactid project Low Vendor pom parent-groupid org.eclipse.ee4j Medium Vendor pom url https://projects.eclipse.org/projects/ee4j.jta Highest Product file name jakarta.transaction-api High Product jar package name jakarta Highest Product jar package name transaction Highest Product Manifest automatic-module-name jakarta.transaction Medium Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://github.com/eclipse-ee4j Low Product Manifest Bundle-Name jakarta.transaction API Medium Product Manifest bundle-symbolicname jakarta.transaction-api Medium Product Manifest extension-name jakarta.transaction Medium Product pom artifactid jakarta.transaction-api Highest Product pom developer id stephen_felts Low Product pom developer name Stephen Felts Low Product pom developer org Oracle, Inc. Low Product pom groupid jakarta.transaction Highest Product pom name API High Product pom name ${extension.name} API High Product pom organization name EE4J Community Low Product pom parent-artifactid project Medium Product pom parent-groupid org.eclipse.ee4j Medium Product pom url eclipse-ee4j High Product pom url https://projects.eclipse.org/projects/ee4j.jta Medium Version file version 2.0.1 High Version Manifest Bundle-Version 2.0.1 High Version Manifest Implementation-Version 2.0.1 High Version pom parent-version 2.0.1 Low Version pom version 2.0.1 Highest
jakarta.xml.bind-api-4.0.2.jarDescription:
Jakarta XML Binding API 4.0 Design Specification License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /var/jenkins_home/.m2/repository/jakarta/xml/bind/jakarta.xml.bind-api/4.0.2/jakarta.xml.bind-api-4.0.2.jar
MD5: 0c8f9991081def819435c3ff36e4d93f
SHA1: 6cd5a999b834b63238005b7144136379dc36cad2
SHA256: 0d6bcfe47763e85047acf7c398336dc84ff85ebcad0a7cb6f3b9d3e981245406
Referenced In Project/Scope: fides-tool-ui-desktop:runtime
jakarta.xml.bind-api-4.0.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name jakarta.xml.bind-api High Vendor jar package name bind Highest Vendor jar package name jakarta Highest Vendor jar package name xml Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.xml.bind-api Medium Vendor Manifest extension-name jakarta.xml.bind Medium Vendor Manifest implementation-build-id ca43d8b Low Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jakarta.xml.bind-api Highest Vendor pom artifactid jakarta.xml.bind-api Low Vendor pom groupid jakarta.xml.bind Highest Vendor pom name Jakarta XML Binding API High Vendor pom parent-artifactid jakarta.xml.bind-api-parent Low Product file name jakarta.xml.bind-api High Product jar package name bind Highest Product jar package name jakarta Highest Product jar package name xml Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta XML Binding API Medium Product Manifest bundle-symbolicname jakarta.xml.bind-api Medium Product Manifest extension-name jakarta.xml.bind Medium Product Manifest implementation-build-id ca43d8b Low Product pom artifactid jakarta.xml.bind-api Highest Product pom groupid jakarta.xml.bind Highest Product pom name Jakarta XML Binding API High Product pom parent-artifactid jakarta.xml.bind-api-parent Medium Version file version 4.0.2 High Version Manifest Bundle-Version 4.0.2 High Version Manifest Implementation-Version 4.0.2 High Version pom version 4.0.2 Highest
jandex-3.2.0.jarDescription:
SmallRye Build Parent POM License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/io/smallrye/jandex/3.2.0/jandex-3.2.0.jar
MD5: 703254a1bd4c37efeebdc0a283c65565
SHA1: f17ad860f62a08487b9edabde608f8ac55c62fa7
SHA256: 6da3e9ce8d0c0a433f3e7ce610a3c66accb00c71fee67aa0ff3e5a841395ac15
Referenced In Project/Scope: fides-tool-ui-desktop:runtime
jandex-3.2.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name jandex High Vendor jar package name jandex Highest Vendor jar package name jboss Highest Vendor Manifest automatic-module-name org.jboss.jandex Medium Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-symbolicname io.smallrye.jandex Medium Vendor Manifest multi-release true Low Vendor pom artifactid jandex Highest Vendor pom artifactid jandex Low Vendor pom groupid io.smallrye Highest Vendor pom name Jandex: Core High Vendor pom parent-artifactid jandex-parent Low Product file name jandex High Product jar package name jandex Highest Product jar package name jboss Highest Product Manifest automatic-module-name org.jboss.jandex Medium Product Manifest build-jdk-spec 17 Low Product Manifest Bundle-Name Jandex: Core Medium Product Manifest bundle-symbolicname io.smallrye.jandex Medium Product Manifest multi-release true Low Product pom artifactid jandex Highest Product pom groupid io.smallrye Highest Product pom name Jandex: Core High Product pom parent-artifactid jandex-parent Medium Version file version 3.2.0 High Version Manifest Bundle-Version 3.2.0 High Version pom version 3.2.0 Highest
jaxb-core-4.0.5.jarDescription:
JAXB Core module. Contains sources required by XJC, JXC and Runtime modules. License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /var/jenkins_home/.m2/repository/org/glassfish/jaxb/jaxb-core/4.0.5/jaxb-core-4.0.5.jar
MD5: ab09aef6bebd4438b0a02707881801e4
SHA1: 007b4b11ea5542eea4ad55e1080b23be436795b3
SHA256: ad3fd9bf00de3eda9859f70b6cfb011e2fe9904804e16a2665092888ece0fdca
Referenced In Project/Scope: fides-tool-ui-desktop:runtime
jaxb-core-4.0.5.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name jaxb-core High Vendor jar package name core Highest Vendor jar package name glassfish Highest Vendor jar package name jaxb Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname org.glassfish.jaxb.core Medium Vendor Manifest git-revision cb19596 Low Vendor Manifest implementation-build-id 4.0.5 - cb19596 Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id org.glassfish.jaxb Medium Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jaxb-core Highest Vendor pom artifactid jaxb-core Low Vendor pom groupid org.glassfish.jaxb Highest Vendor pom name JAXB Core High Vendor pom parent-artifactid jaxb-parent Low Vendor pom parent-groupid com.sun.xml.bind.mvn Medium Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest Product file name jaxb-core High Product jar package name core Highest Product jar package name glassfish Highest Product jar package name jaxb Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name JAXB Core Medium Product Manifest bundle-symbolicname org.glassfish.jaxb.core Medium Product Manifest git-revision cb19596 Low Product Manifest implementation-build-id 4.0.5 - cb19596 Low Product Manifest Implementation-Title Eclipse Implementation of JAXB High Product Manifest specification-title Jakarta XML Binding Medium Product pom artifactid jaxb-core Highest Product pom groupid org.glassfish.jaxb Highest Product pom name JAXB Core High Product pom parent-artifactid jaxb-parent Medium Product pom parent-groupid com.sun.xml.bind.mvn Medium Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium Version file version 4.0.5 High Version Manifest build-version 4.0.5 Medium Version Manifest Bundle-Version 4.0.5 High Version Manifest implementation-build-id 4.0.5 Low Version pom version 4.0.5 Highest
jaxb-runtime-4.0.5.jarDescription:
JAXB (JSR 222) Reference Implementation License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /var/jenkins_home/.m2/repository/org/glassfish/jaxb/jaxb-runtime/4.0.5/jaxb-runtime-4.0.5.jar
MD5: c7384f1f95b8a8e15291485ff9dbe4f3
SHA1: ca84c2a7169b5293e232b9d00d1e4e36d4c3914a
SHA256: 485d8940e76373a7f300815ea5504bf5b726c234425ad30971019d133124cca4
Referenced In Project/Scope: fides-tool-ui-desktop:runtime
jaxb-runtime-4.0.5.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name jaxb-runtime High Vendor jar package name glassfish Highest Vendor jar package name jaxb Highest Vendor jar package name runtime Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname org.glassfish.jaxb.runtime Medium Vendor Manifest git-revision cb19596 Low Vendor Manifest implementation-build-id 4.0.5 - cb19596 Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id org.glassfish.jaxb Medium Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.xml.bind.JAXBContextFactory" Low Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jaxb-runtime Highest Vendor pom artifactid jaxb-runtime Low Vendor pom groupid org.glassfish.jaxb Highest Vendor pom name JAXB Runtime High Vendor pom parent-artifactid jaxb-runtime-parent Low Vendor pom parent-groupid com.sun.xml.bind.mvn Medium Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest Product file name jaxb-runtime High Product jar package name glassfish Highest Product jar package name jaxb Highest Product jar package name runtime Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name JAXB Runtime Medium Product Manifest bundle-symbolicname org.glassfish.jaxb.runtime Medium Product Manifest git-revision cb19596 Low Product Manifest implementation-build-id 4.0.5 - cb19596 Low Product Manifest Implementation-Title Eclipse Implementation of JAXB High Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="jakarta.xml.bind.JAXBContextFactory" Low Product Manifest specification-title Jakarta XML Binding Medium Product pom artifactid jaxb-runtime Highest Product pom groupid org.glassfish.jaxb Highest Product pom name JAXB Runtime High Product pom parent-artifactid jaxb-runtime-parent Medium Product pom parent-groupid com.sun.xml.bind.mvn Medium Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium Version file version 4.0.5 High Version Manifest build-version 4.0.5 Medium Version Manifest Bundle-Version 4.0.5 High Version Manifest implementation-build-id 4.0.5 Low Version pom version 4.0.5 Highest
jboss-logging-3.6.1.Final.jarDescription:
The JBoss Logging Framework License:
Apache License 2.0: https://repository.jboss.org/licenses/apache-2.0.txt File Path: /var/jenkins_home/.m2/repository/org/jboss/logging/jboss-logging/3.6.1.Final/jboss-logging-3.6.1.Final.jar
MD5: acab989faf62db02c092448e95614fab
SHA1: 886afbb445b4016a37c8960a7aef6ebd769ce7e5
SHA256: 5e08a4b092dc85b337f0910a740571d8720cfa565fabd880a8caf94a657ca416
Referenced In Project/Scope: fides-tool-ui-desktop:runtime
jboss-logging-3.6.1.Final.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name jboss-logging High Vendor hint analyzer vendor redhat Highest Vendor jar package name jboss Highest Vendor jar package name logging Highest Vendor Manifest automatic-module-name org.jboss.logging Medium Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl http://www.jboss.org Low Vendor Manifest bundle-symbolicname org.jboss.logging.jboss-logging Medium Vendor Manifest implementation-url http://www.jboss.org Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest originally-created-by Apache Maven Bundle Plugin Low Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor JBoss by Red Hat Low Vendor pom artifactid jboss-logging Highest Vendor pom artifactid jboss-logging Low Vendor pom groupid org.jboss.logging Highest Vendor pom name JBoss Logging 3 High Vendor pom parent-artifactid logging-parent Low Vendor pom url http://www.jboss.org Highest Product file name jboss-logging High Product jar package name jboss Highest Product jar package name logging Highest Product Manifest automatic-module-name org.jboss.logging Medium Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl http://www.jboss.org Low Product Manifest Bundle-Name JBoss Logging 3 Medium Product Manifest bundle-symbolicname org.jboss.logging.jboss-logging Medium Product Manifest Implementation-Title JBoss Logging 3 High Product Manifest implementation-url http://www.jboss.org Low Product Manifest originally-created-by Apache Maven Bundle Plugin Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title JBoss Logging 3 Medium Product pom artifactid jboss-logging Highest Product pom groupid org.jboss.logging Highest Product pom name JBoss Logging 3 High Product pom parent-artifactid logging-parent Medium Product pom url http://www.jboss.org Medium Version Manifest Bundle-Version 3.6.1.Final High Version Manifest Implementation-Version 3.6.1.Final High Version pom parent-version 3.6.1.Final Low Version pom version 3.6.1.Final Highest
jsch-0.1.55.jarDescription:
JSch is a pure Java implementation of SSH2 License:
Revised BSD: http://www.jcraft.com/jsch/LICENSE.txt File Path: /var/jenkins_home/.m2/repository/com/jcraft/jsch/0.1.55/jsch-0.1.55.jar
MD5: c395ada0fc012d66f11bd30246f6c84d
SHA1: bbd40e5aa7aa3cfad5db34965456cee738a42a50
SHA256: d492b15a6d2ea3f1cc39c422c953c40c12289073dbe8360d98c0f6f9ec74fc44
Referenced In Project/Scope: fides-tool-ui-desktop:provided
jsch-0.1.55.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.apache.ant/ant-jsch@1.10.14
Evidence Type Source Name Value Confidence Vendor file name jsch High Vendor jar package name jcraft Highest Vendor jar package name jcraft Low Vendor jar package name jsch Highest Vendor jar package name jsch Low Vendor pom artifactid jsch Highest Vendor pom artifactid jsch Low Vendor pom developer email ymnk at jcraft D0t com Low Vendor pom developer id ymnk Medium Vendor pom developer name Atsuhiko Yamanaka Medium Vendor pom developer org JCraft,Inc. Medium Vendor pom developer org URL http://www.jcraft.com/ Medium Vendor pom groupid com.jcraft Highest Vendor pom name JSch High Vendor pom organization name JCraft,Inc. High Vendor pom organization url http://www.jcraft.com/ Medium Vendor pom url http://www.jcraft.com/jsch/ Highest Product file name jsch High Product jar package name jcraft Highest Product jar package name jsch Highest Product jar package name jsch Low Product pom artifactid jsch Highest Product pom developer email ymnk at jcraft D0t com Low Product pom developer id ymnk Low Product pom developer name Atsuhiko Yamanaka Low Product pom developer org JCraft,Inc. Low Product pom developer org URL http://www.jcraft.com/ Low Product pom groupid com.jcraft Highest Product pom name JSch High Product pom organization name JCraft,Inc. Low Product pom organization url http://www.jcraft.com/ Low Product pom url http://www.jcraft.com/jsch/ Medium Version file version 0.1.55 High Version pom version 0.1.55 Highest
jsch-0.2.17.jarDescription:
JSch is a pure Java implementation of SSH2 License:
Revised BSD: https://github.com/mwiede/jsch/blob/master/LICENSE.txt
Revised BSD: https://github.com/mwiede/jsch/blob/master/LICENSE.JZlib.txt
ISC: https://github.com/mwiede/jsch/blob/master/LICENSE.jBCrypt.txt File Path: /var/jenkins_home/.m2/repository/com/github/mwiede/jsch/0.2.17/jsch-0.2.17.jar
MD5: cab01731fd7e65e13cb509869a3df7fb
SHA1: 1572f8ac4023895c2232160fddd4bfdd8c8e214d
SHA256: 744667315fcaaa1b00d2ef177fb2660036a9733f6ccd93a5c87ce800fde6b832
Referenced In Project/Scope: fides-tool-ui-desktop:provided
jsch-0.2.17.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui-desktop@1.5.6
Evidence Type Source Name Value Confidence Vendor file name jsch High Vendor jar package name com Highest Vendor jar package name jcraft Highest Vendor jar package name jsch Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-symbolicname com.github.mwiede.jsch Medium Vendor Manifest multi-release true Low Vendor pom artifactid jsch Highest Vendor pom artifactid jsch Low Vendor pom developer email mwiede@gmx.de Low Vendor pom developer email ymnk at jcraft D0t com Low Vendor pom developer id mwiede Medium Vendor pom developer id norrisjeremy Medium Vendor pom developer id ymnk Medium Vendor pom developer name Atsuhiko Yamanaka Medium Vendor pom developer name Jeremy Norris Medium Vendor pom developer name Matthias Wiedemann Medium Vendor pom developer org Community Medium Vendor pom developer org JCraft,Inc. Medium Vendor pom developer org URL http://www.jcraft.com/ Medium Vendor pom developer org URL https://github.com/mwiede Medium Vendor pom developer org URL https://github.com/norrisjeremy Medium Vendor pom groupid com.github.mwiede Highest Vendor pom name JSch High Vendor pom url mwiede/jsch Highest Product file name jsch High Product jar package name com Highest Product jar package name jcraft Highest Product jar package name jsch Highest Product Manifest build-jdk-spec 21 Low Product Manifest Bundle-Name JSch Medium Product Manifest bundle-symbolicname com.github.mwiede.jsch Medium Product Manifest Implementation-Title JSch High Product Manifest multi-release true Low Product Manifest specification-title JSch Medium Product pom artifactid jsch Highest Product pom developer email mwiede@gmx.de Low Product pom developer email ymnk at jcraft D0t com Low Product pom developer id mwiede Low Product pom developer id norrisjeremy Low Product pom developer id ymnk Low Product pom developer name Atsuhiko Yamanaka Low Product pom developer name Jeremy Norris Low Product pom developer name Matthias Wiedemann Low Product pom developer org Community Low Product pom developer org JCraft,Inc. Low Product pom developer org URL http://www.jcraft.com/ Low Product pom developer org URL https://github.com/mwiede Low Product pom developer org URL https://github.com/norrisjeremy Low Product pom groupid com.github.mwiede Highest Product pom name JSch High Product pom url mwiede/jsch High Version file version 0.2.17 High Version Manifest Bundle-Version 0.2.17 High Version Manifest Implementation-Version 0.2.17 High Version pom version 0.2.17 Highest
jul-to-slf4j-2.0.17.jarDescription:
JUL to SLF4J bridge License:
https://opensource.org/license/mit File Path: /var/jenkins_home/.m2/repository/org/slf4j/jul-to-slf4j/2.0.17/jul-to-slf4j-2.0.17.jar
MD5: a42936c56611e4794c42908fb3d3a647
SHA1: 524cb6ccc2b68a57604750e1ab8b13b5a786a6aa
SHA256: a7afcd23b9cfd1475e55c94f943b808c5922035e7e2c2a5c65a487a4106bc538
Referenced In Project/Scope: fides-tool-ui-desktop:compile
jul-to-slf4j-2.0.17.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name jul-to-slf4j High Vendor jar package name bridge Highest Vendor jar package name slf4j Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl http://www.slf4j.org Low Vendor Manifest bundle-symbolicname jul.to.slf4j Medium Vendor Manifest multi-release true Low Vendor pom artifactid jul-to-slf4j Highest Vendor pom artifactid jul-to-slf4j Low Vendor pom groupid org.slf4j Highest Vendor pom name JUL to SLF4J bridge High Vendor pom parent-artifactid slf4j-parent Low Vendor pom url http://www.slf4j.org Highest Product file name jul-to-slf4j High Product jar package name bridge Highest Product jar package name slf4j Highest Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl http://www.slf4j.org Low Product Manifest Bundle-Name JUL to SLF4J bridge Medium Product Manifest bundle-symbolicname jul.to.slf4j Medium Product Manifest Implementation-Title jul-to-slf4j High Product Manifest multi-release true Low Product pom artifactid jul-to-slf4j Highest Product pom groupid org.slf4j Highest Product pom name JUL to SLF4J bridge High Product pom parent-artifactid slf4j-parent Medium Product pom url http://www.slf4j.org Medium Version file version 2.0.17 High Version Manifest Bundle-Version 2.0.17 High Version Manifest Implementation-Version 2.0.17 High Version pom version 2.0.17 Highest
log4j-api-2.24.3.jarDescription:
The logging API of the Log4j project.
Library and application code can log through this API.
It contains a simple built-in implementation (`SimpleLogger`) for trivial use cases.
Production applications are recommended to use Log4j API in combination with a fully-fledged implementation, such as Log4j Core. License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/org/apache/logging/log4j/log4j-api/2.24.3/log4j-api-2.24.3.jar
MD5: d89516699543c5c21be87ee1760695f3
SHA1: b02c125db8b6d295adf72ae6e71af5d83bce2370
SHA256: 5b4a0a0cd0e751ded431c162442bdbdd53328d1f8bb2bae5fc1bbeee0f66d80f
Referenced In Project/Scope: fides-tool-ui-desktop:compile
log4j-api-2.24.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name log4j-api High Vendor jar package name apache Highest Vendor jar package name log4j Highest Vendor jar package name logging Highest Vendor jar package name org Highest Vendor jar package name simple Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-activationpolicy lazy Low Vendor Manifest bundle-symbolicname org.apache.logging.log4j.api Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest multi-release true Low Vendor Manifest provide-capability osgi.service;objectClass:List="org.apache.logging.log4j.util.PropertySource";effective:=active,osgi.serviceloader;osgi.serviceloader="org.apache.logging.log4j.util.PropertySource";register:="org.apache.logging.log4j.util.EnvironmentPropertySource",osgi.serviceloader;osgi.serviceloader="org.apache.logging.log4j.util.PropertySource";register:="org.apache.logging.log4j.util.SystemPropertiesPropertySource" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid log4j-api Highest Vendor pom artifactid log4j-api Low Vendor pom groupid org.apache.logging.log4j Highest Vendor pom name Apache Log4j API High Vendor pom parent-artifactid log4j Low Product file name log4j-api High Product jar package name apache Highest Product jar package name log4j Highest Product jar package name logging Highest Product jar package name org Highest Product jar package name simple Highest Product jar package name util Highest Product Manifest build-jdk-spec 17 Low Product Manifest bundle-activationpolicy lazy Low Product Manifest Bundle-Name Apache Log4j API Medium Product Manifest bundle-symbolicname org.apache.logging.log4j.api Medium Product Manifest Implementation-Title Apache Log4j API High Product Manifest multi-release true Low Product Manifest provide-capability osgi.service;objectClass:List="org.apache.logging.log4j.util.PropertySource";effective:=active,osgi.serviceloader;osgi.serviceloader="org.apache.logging.log4j.util.PropertySource";register:="org.apache.logging.log4j.util.EnvironmentPropertySource",osgi.serviceloader;osgi.serviceloader="org.apache.logging.log4j.util.PropertySource";register:="org.apache.logging.log4j.util.SystemPropertiesPropertySource" Low Product Manifest specification-title Apache Log4j API Medium Product pom artifactid log4j-api Highest Product pom groupid org.apache.logging.log4j Highest Product pom name Apache Log4j API High Product pom parent-artifactid log4j Medium Version file version 2.24.3 High Version Manifest Bundle-Version 2.24.3 High Version Manifest Implementation-Version 2.24.3 High Version pom version 2.24.3 Highest
CVE-2025-68161 suppress
The Socket Appender in Apache Log4j Core versions 2.0-beta9 through 2.25.2 does not perform TLS hostname verification of the peer certificate, even when the verifyHostName https://logging.apache.org/log4j/2.x/manual/appenders/network.html#SslConfiguration-attr-verifyHostName configuration attribute or the log4j2.sslVerifyHostName https://logging.apache.org/log4j/2.x/manual/systemproperties.html#log4j2.sslVerifyHostName system property is set to true.
This issue may allow a man-in-the-middle attacker to intercept or redirect log traffic under the following conditions:
* The attacker is able to intercept or redirect network traffic between the client and the log receiver.
* The attacker can present a server certificate issued by a certification authority trusted by the Socket Appender’s configured trust store (or by the default Java trust store if no custom trust store is configured).
Users are advised to upgrade to Apache Log4j Core version 2.25.3, which addresses this issue.
As an alternative mitigation, the Socket Appender may be configured to use a private or restricted trust root to limit the set of trusted certificates. CWE-295 Improper Certificate Validation, CWE-297 Improper Validation of Certificate with Host Mismatch
CVSSv4:
Base Score: MEDIUM (6.3) Vector: CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X CVSSv3:
Base Score: MEDIUM (4.8) Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N/E:2.2/RC:R/MAV:A References:
Vulnerable Software & Versions: (show all )
log4j-to-slf4j-2.24.3.jarDescription:
Forwards the Log4j API calls to SLF4J.
(Refer to the `log4j-slf4j[2]-impl` artifacts for forwarding SLF4J to the Log4j API.) License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/org/apache/logging/log4j/log4j-to-slf4j/2.24.3/log4j-to-slf4j-2.24.3.jar
MD5: 1f4b63f9c41f2f5179aa10b35d76e805
SHA1: da1143e2a2531ee1c2d90baa98eb50a28a39d5a7
SHA256: c7f2b0c612a4eb05b1587d1c880eb4cf5f4f53850676a8ede8da2b8fabb4f73f
Referenced In Project/Scope: fides-tool-ui-desktop:compile
log4j-to-slf4j-2.24.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name log4j-to-slf4j High Vendor jar package name apache Highest Vendor jar package name logging Highest Vendor jar package name slf4j Highest Vendor Manifest build-jdk-spec 17 Low Vendor Manifest bundle-activationpolicy lazy Low Vendor Manifest bundle-symbolicname org.apache.logging.log4j.to.slf4j Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest multi-release false Low Vendor Manifest provide-capability osgi.service;objectClass:List="org.apache.logging.log4j.spi.Provider";effective:=active,osgi.serviceloader;osgi.serviceloader="org.apache.logging.log4j.spi.Provider";register:="org.apache.logging.slf4j.SLF4JProvider" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid log4j-to-slf4j Highest Vendor pom artifactid log4j-to-slf4j Low Vendor pom groupid org.apache.logging.log4j Highest Vendor pom name Log4j API to SLF4J Adapter High Vendor pom parent-artifactid log4j Low Product file name log4j-to-slf4j High Product jar package name apache Highest Product jar package name logging Highest Product jar package name slf4j Highest Product jar package name slf4jprovider Highest Product Manifest build-jdk-spec 17 Low Product Manifest bundle-activationpolicy lazy Low Product Manifest Bundle-Name Log4j API to SLF4J Adapter Medium Product Manifest bundle-symbolicname org.apache.logging.log4j.to.slf4j Medium Product Manifest Implementation-Title Log4j API to SLF4J Adapter High Product Manifest multi-release false Low Product Manifest provide-capability osgi.service;objectClass:List="org.apache.logging.log4j.spi.Provider";effective:=active,osgi.serviceloader;osgi.serviceloader="org.apache.logging.log4j.spi.Provider";register:="org.apache.logging.slf4j.SLF4JProvider" Low Product Manifest specification-title Log4j API to SLF4J Adapter Medium Product pom artifactid log4j-to-slf4j Highest Product pom groupid org.apache.logging.log4j Highest Product pom name Log4j API to SLF4J Adapter High Product pom parent-artifactid log4j Medium Version file version 2.24.3 High Version Manifest Bundle-Version 2.24.3 High Version Manifest Implementation-Version 2.24.3 High Version pom version 2.24.3 Highest
logback-classic-1.5.18.jarDescription:
logback-classic module License:
http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html File Path: /var/jenkins_home/.m2/repository/ch/qos/logback/logback-classic/1.5.18/logback-classic-1.5.18.jar
MD5: 05bd5f5d61a7efe5d5ae362df43377b5
SHA1: fc371f3fc97a639de2d67947cffb7518ec5e3d40
SHA256: 3e1533d0321f8815eef46750aee0111b41554f9a4644c3c4d2d404744b09f60f
Referenced In Project/Scope: fides-tool-ui-desktop:compile
logback-classic-1.5.18.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name logback-classic High Vendor jar package name ch Highest Vendor jar package name classic Highest Vendor jar package name logback Highest Vendor jar package name qos Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl http://www.qos.ch Low Vendor Manifest bundle-symbolicname ch.qos.logback.classic Medium Vendor Manifest Implementation-Vendor QOS.ch High Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low Vendor Manifest provide-capability osgi.service;objectClass:List="jakarta.servlet.ServletContainerInitializer";effective:=active,osgi.service;objectClass:List="org.slf4j.spi.SLF4JServiceProvider";effective:=active,osgi.serviceloader;osgi.serviceloader="jakarta.servlet.ServletContainerInitializer";register:="ch.qos.logback.classic.servlet.LogbackServletContainerInitializer",osgi.serviceloader;osgi.serviceloader="org.slf4j.spi.SLF4JServiceProvider";register:="ch.qos.logback.classic.spi.LogbackServiceProvider" Low Vendor Manifest specification-vendor QOS.ch Low Vendor pom artifactid logback-classic Highest Vendor pom artifactid logback-classic Low Vendor pom groupid ch.qos.logback Highest Vendor pom name Logback Classic Module High Vendor pom parent-artifactid logback-parent Low Product file name logback-classic High Product jar package name ch Highest Product jar package name classic Highest Product jar package name logback Highest Product jar package name qos Highest Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl http://www.qos.ch Low Product Manifest Bundle-Name Logback Classic Module Medium Product Manifest bundle-symbolicname ch.qos.logback.classic Medium Product Manifest Implementation-Title Logback Classic Module High Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low Product Manifest provide-capability osgi.service;objectClass:List="jakarta.servlet.ServletContainerInitializer";effective:=active,osgi.service;objectClass:List="org.slf4j.spi.SLF4JServiceProvider";effective:=active,osgi.serviceloader;osgi.serviceloader="jakarta.servlet.ServletContainerInitializer";register:="ch.qos.logback.classic.servlet.LogbackServletContainerInitializer",osgi.serviceloader;osgi.serviceloader="org.slf4j.spi.SLF4JServiceProvider";register:="ch.qos.logback.classic.spi.LogbackServiceProvider" Low Product Manifest specification-title Logback Classic Module Medium Product pom artifactid logback-classic Highest Product pom groupid ch.qos.logback Highest Product pom name Logback Classic Module High Product pom parent-artifactid logback-parent Medium Version file version 1.5.18 High Version Manifest Bundle-Version 1.5.18 High Version Manifest Implementation-Version 1.5.18 High Version pom version 1.5.18 Highest
logback-core-1.5.18.jarDescription:
logback-core module License:
http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html File Path: /var/jenkins_home/.m2/repository/ch/qos/logback/logback-core/1.5.18/logback-core-1.5.18.jar
MD5: 10bcea83842beead15f072799b9c923d
SHA1: 6c0375624f6f36b4e089e2488ba21334a11ef13f
SHA256: 85139e7b57b464f8e5e36326dd81317648bed199ccc4f98cd42585f8d7571027
Referenced In Project/Scope: fides-tool-ui-desktop:compile
logback-core-1.5.18.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name logback-core High Vendor jar package name ch Highest Vendor jar package name core Highest Vendor jar package name logback Highest Vendor jar package name qos Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl http://www.qos.ch Low Vendor Manifest bundle-symbolicname ch.qos.logback.core Medium Vendor Manifest Implementation-Vendor QOS.ch High Vendor Manifest multi-release true Low Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low Vendor Manifest specification-vendor QOS.ch Low Vendor pom artifactid logback-core Highest Vendor pom artifactid logback-core Low Vendor pom groupid ch.qos.logback Highest Vendor pom name Logback Core Module High Vendor pom parent-artifactid logback-parent Low Product file name logback-core High Product jar package name 21 Highest Product jar package name ch Highest Product jar package name core Highest Product jar package name logback Highest Product jar package name qos Highest Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl http://www.qos.ch Low Product Manifest Bundle-Name Logback Core Module Medium Product Manifest bundle-symbolicname ch.qos.logback.core Medium Product Manifest Implementation-Title Logback Core Module High Product Manifest multi-release true Low Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low Product Manifest specification-title Logback Core Module Medium Product pom artifactid logback-core Highest Product pom groupid ch.qos.logback Highest Product pom name Logback Core Module High Product pom parent-artifactid logback-parent Medium Version file version 1.5.18 High Version Manifest Bundle-Version 1.5.18 High Version Manifest Implementation-Version 1.5.18 High Version pom version 1.5.18 Highest
CVE-2025-11226 (OSSINDEX) suppress
ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.18 in Java applications, allows an attacker to execute arbitrary code by compromising an existing logback configuration file or by injecting an environment variable before program execution.
A successful attack requires the presence of Janino library and Spring Framework to be present on the user's class path. In addition, the attacker must have write access to a
configuration file. Alternatively, the attacker could inject a malicious
environment variable pointing to a malicious configuration file. In both
cases, the attack requires existing privilege. CWE-20 Improper Input Validation
CVSSv4:
Base Score: HIGH (7.300000190734863) Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:ch.qos.logback:logback-core:1.5.18:*:*:*:*:*:*:* CVE-2026-1225 (OSSINDEX) suppress
ACE vulnerability in configuration file processing by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attacker to instantiate classes already present on the class path by compromising an existing logback configuration file.
The instantiation of a potentially malicious Java class requires that said class is present on the user's class-path. In addition, the attacker must have write access to a
configuration file. However, after successful instantiation, the instance is very likely to be discarded with no further ado. CWE-20 Improper Input Validation
CVSSv4:
Base Score: LOW (1.7999999523162842) Vector: CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:N/V:X/RE:X/U:X References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:ch.qos.logback:logback-core:1.5.18:*:*:*:*:*:*:* lombok-1.18.32.jarDescription:
Spice up your java: Automatic Resource Management, automatic generation of getters, setters, equals, hashCode and toString, and more! License:
The MIT License: https://projectlombok.org/LICENSE File Path: /var/jenkins_home/.m2/repository/org/projectlombok/lombok/1.18.32/lombok-1.18.32.jar
MD5: 56e9be7b9a26802ac0c784ad824f3a29
SHA1: 17d46b3e205515e1e8efd3ee4d57ce8018914163
SHA256: 97574674e2a25f567a313736ace00df8787d443de316407d57fc877d9f19a65d
Referenced In Project/Scope: fides-tool-ui-desktop:provided
lombok-1.18.32.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui-desktop@1.5.6
Evidence Type Source Name Value Confidence Vendor file name lombok High Vendor jar package name java Highest Vendor jar package name lombok Highest Vendor jar package name tostring Highest Vendor Manifest automatic-module-name lombok Medium Vendor Manifest can-redefine-classes true Low Vendor pom artifactid lombok Highest Vendor pom artifactid lombok Low Vendor pom developer email reinier@projectlombok.org Low Vendor pom developer email roel@projectlombok.org Low Vendor pom developer id rspilker Medium Vendor pom developer id rzwitserloot Medium Vendor pom developer name Reinier Zwitserloot Medium Vendor pom developer name Roel Spilker Medium Vendor pom groupid org.projectlombok Highest Vendor pom name Project Lombok High Vendor pom url https://projectlombok.org Highest Product file name lombok High Product jar package name java Highest Product jar package name lombok Highest Product jar package name tostring Highest Product Manifest automatic-module-name lombok Medium Product Manifest can-redefine-classes true Low Product pom artifactid lombok Highest Product pom developer email reinier@projectlombok.org Low Product pom developer email roel@projectlombok.org Low Product pom developer id rspilker Low Product pom developer id rzwitserloot Low Product pom developer name Reinier Zwitserloot Low Product pom developer name Roel Spilker Low Product pom groupid org.projectlombok Highest Product pom name Project Lombok High Product pom url https://projectlombok.org Medium Version file version 1.18.32 High Version Manifest lombok-version 1.18.32 Medium Version pom version 1.18.32 Highest
lombok-1.18.32.jar: mavenEcjBootstrapAgent.jarFile Path: /var/jenkins_home/.m2/repository/org/projectlombok/lombok/1.18.32/lombok-1.18.32.jar/lombok/launch/mavenEcjBootstrapAgent.jarMD5: 81090c80616485973f6cd4a19d72bbdbSHA1: ed1e7c8794dea7c7f7050098d56b2751b9f91288SHA256: e97851350e56f4d1b02356ef61276886831e3a5e33a914ea95e878e2a46df69eReferenced In Project/Scope: fides-tool-ui-desktop:provided
Evidence Type Source Name Value Confidence Vendor file name mavenEcjBootstrapAgent High Vendor jar package name launch Low Vendor jar package name lombok Low Vendor Manifest can-redefine-classes true Low Product file name mavenEcjBootstrapAgent High Product jar package name launch Low Product Manifest can-redefine-classes true Low
micrometer-commons-1.15.4.jarDescription:
Module containing common code License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/io/micrometer/micrometer-commons/1.15.4/micrometer-commons-1.15.4.jar
MD5: dce057f497778156adf8d890d4f6ee35
SHA1: f73f10deeee5700b15c2f0f41ae79e2689b39613
SHA256: d9971273957d7cd695887cbc680772b75844bfcf3fa7017189171683798b9181
Referenced In Project/Scope: fides-tool-ui-desktop:compile
micrometer-commons-1.15.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-devtools@3.5.6
Evidence Type Source Name Value Confidence Vendor file name micrometer-commons High Vendor jar package name common Highest Vendor jar package name io Highest Vendor jar package name micrometer Highest Vendor Manifest automatic-module-name micrometer.commons Medium Vendor Manifest branch HEAD Low Vendor Manifest build-date 2025-09-08_07:35:41 Low Vendor Manifest build-date-utc 2025-09-08T07:35:41.482770380Z Low Vendor Manifest build-host a79b0d2a8a5b Low Vendor Manifest build-job deploy Low Vendor Manifest build-number 55789 Low Vendor Manifest build-timezone Etc/UTC Low Vendor Manifest build-url https://circleci.com/gh/micrometer-metrics/micrometer/55789 Low Vendor Manifest built-os Linux Low Vendor Manifest built-status release Low Vendor Manifest bundle-symbolicname micrometer-commons Medium Vendor Manifest change 68c4d22 Low Vendor Manifest full-change 68c4d2210b97d90bf82cda6402f327cc87e667d2 Low Vendor Manifest module-email tludwig@vmware.com Low Vendor Manifest module-origin micrometer-metrics/micrometer.git Low Vendor Manifest module-owner tludwig@vmware.com Low Vendor Manifest module-source /micrometer-commons Low Vendor pom artifactid micrometer-commons Highest Vendor pom artifactid micrometer-commons Low Vendor pom developer email tludwig@vmware.com Low Vendor pom developer id shakuzen Medium Vendor pom developer name Tommy Ludwig Medium Vendor pom groupid io.micrometer Highest Vendor pom name micrometer-commons High Vendor pom url micrometer-metrics/micrometer Highest Product file name micrometer-commons High Product jar package name common Highest Product jar package name io Highest Product jar package name micrometer Highest Product Manifest automatic-module-name micrometer.commons Medium Product Manifest branch HEAD Low Product Manifest build-date 2025-09-08_07:35:41 Low Product Manifest build-date-utc 2025-09-08T07:35:41.482770380Z Low Product Manifest build-host a79b0d2a8a5b Low Product Manifest build-job deploy Low Product Manifest build-number 55789 Low Product Manifest build-timezone Etc/UTC Low Product Manifest build-url https://circleci.com/gh/micrometer-metrics/micrometer/55789 Low Product Manifest built-os Linux Low Product Manifest built-status release Low Product Manifest Bundle-Name micrometer-commons Medium Product Manifest bundle-symbolicname micrometer-commons Medium Product Manifest change 68c4d22 Low Product Manifest full-change 68c4d2210b97d90bf82cda6402f327cc87e667d2 Low Product Manifest Implementation-Title io.micrometer#micrometer-commons;1.15.4 High Product Manifest module-email tludwig@vmware.com Low Product Manifest module-origin micrometer-metrics/micrometer.git Low Product Manifest module-owner tludwig@vmware.com Low Product Manifest module-source /micrometer-commons Low Product pom artifactid micrometer-commons Highest Product pom developer email tludwig@vmware.com Low Product pom developer id shakuzen Low Product pom developer name Tommy Ludwig Low Product pom groupid io.micrometer Highest Product pom name micrometer-commons High Product pom url micrometer-metrics/micrometer High Version file version 1.15.4 High Version Manifest Bundle-Version 1.15.4 High Version Manifest Implementation-Version 1.15.4 High Version pom version 1.15.4 Highest
Related Dependencies micrometer-observation-1.15.4.jarFile Path: /var/jenkins_home/.m2/repository/io/micrometer/micrometer-observation/1.15.4/micrometer-observation-1.15.4.jar MD5: e30ed38fdfcbd599dd3137eb3f654547 SHA1: 8cd0aed0ff098a7937f2f8f81705840f2d60a432 SHA256: 49693a239af0219384fd41f6cf5e48639e097c5da0f628433e1f9b7bf3120d1b pkg:maven/io.micrometer/micrometer-observation@1.15.4 nimbus-jose-jwt-10.0.2.jar (shaded: com.github.stephenc.jcip:jcip-annotations:1.0-1)Description:
A clean room implementation of the JCIP Annotations based entirely on the specification provided by the javadocs.
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/com/nimbusds/nimbus-jose-jwt/10.0.2/nimbus-jose-jwt-10.0.2.jar/META-INF/maven/com.github.stephenc.jcip/jcip-annotations/pom.xml
MD5: 11f9647450c14ff9b341c68782ef071a
SHA1: bdccebfbbbdd66fe56dcdf3bdee7b97a853cccc5
SHA256: 68c2a5aa6e8f345743093e52b5b9e0190ba4d5a5215c0a59b4d7d33647208cbb
Referenced In Project/Scope: fides-tool-ui-desktop:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid jcip-annotations Low Vendor pom developer id stephenc Medium Vendor pom developer name Stephen Connolly Medium Vendor pom groupid com.github.stephenc.jcip Highest Vendor pom name JCIP Annotations under Apache License High Vendor pom url http://stephenc.github.com/jcip-annotations Highest Product pom artifactid jcip-annotations Highest Product pom developer id stephenc Low Product pom developer name Stephen Connolly Low Product pom groupid com.github.stephenc.jcip Highest Product pom name JCIP Annotations under Apache License High Product pom url http://stephenc.github.com/jcip-annotations Medium Version pom version 1.0-1 Highest
nimbus-jose-jwt-10.0.2.jar (shaded: com.google.code.gson:gson:2.12.1)License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/com/nimbusds/nimbus-jose-jwt/10.0.2/nimbus-jose-jwt-10.0.2.jar/META-INF/maven/com.google.code.gson/gson/pom.xml
MD5: 54205b633e8a676f5bb25c188631c854
SHA1: d2c3993ff96e5da39a57e5e0b695eda560949b57
SHA256: 0b5735ec85f45282f1e2c769779800427b150a8163f405093a9280b71cab1978
Referenced In Project/Scope: fides-tool-ui-desktop:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid gson Low Vendor pom groupid com.google.code.gson Highest Vendor pom name Gson High Vendor pom parent-artifactid gson-parent Low Product pom artifactid gson Highest Product pom groupid com.google.code.gson Highest Product pom name Gson High Product pom parent-artifactid gson-parent Medium Version pom version 2.12.1 Highest
nimbus-jose-jwt-10.0.2.jarDescription:
Java library for Javascript Object Signing and Encryption (JOSE) and
JSON Web Tokens (JWT)
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/com/nimbusds/nimbus-jose-jwt/10.0.2/nimbus-jose-jwt-10.0.2.jar
MD5: 98ebb498f6bbcee1049de8a64ff7c52c
SHA1: 93347ea9247ae09e095575e10f9cae79c195fbb8
SHA256: 960b978a6cd6cbc3319648adc73959789f6742a2bf1e8dd0c843dbc91624218a
Referenced In Project/Scope: fides-tool-ui-desktop:compile
nimbus-jose-jwt-10.0.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name nimbus-jose-jwt High Vendor jar package name jose Highest Vendor jar package name jwt Highest Vendor jar package name nimbusds Highest Vendor Manifest automatic-module-name com.nimbusds.jose.jwt Medium Vendor Manifest build-date ${timestamp} Low Vendor Manifest build-jdk-spec 17 Low Vendor Manifest build-number ${buildNumber} Low Vendor Manifest build-tag 10.0.2 Low Vendor Manifest bundle-docurl https://connect2id.com Low Vendor Manifest bundle-symbolicname com.nimbusds.nimbus-jose-jwt Medium Vendor Manifest Implementation-Vendor Connect2id Ltd. High Vendor Manifest specification-vendor Connect2id Ltd. Low Vendor pom artifactid nimbus-jose-jwt Highest Vendor pom artifactid nimbus-jose-jwt Low Vendor pom developer email vladimir@dzhuvinov.com Low Vendor pom developer id vdzhuvinov Medium Vendor pom developer name Vladimir Dzhuvinov Medium Vendor pom groupid com.nimbusds Highest Vendor pom name Nimbus JOSE+JWT High Vendor pom organization name Connect2id Ltd. High Vendor pom organization url https://connect2id.com Medium Vendor pom url https://bitbucket.org/connect2id/nimbus-jose-jwt Highest Product file name nimbus-jose-jwt High Product jar package name jose Highest Product jar package name jwt Highest Product jar package name nimbusds Highest Product Manifest automatic-module-name com.nimbusds.jose.jwt Medium Product Manifest build-date ${timestamp} Low Product Manifest build-jdk-spec 17 Low Product Manifest build-number ${buildNumber} Low Product Manifest build-tag 10.0.2 Low Product Manifest bundle-docurl https://connect2id.com Low Product Manifest Bundle-Name Nimbus JOSE+JWT Medium Product Manifest bundle-symbolicname com.nimbusds.nimbus-jose-jwt Medium Product Manifest Implementation-Title Nimbus JOSE+JWT High Product Manifest specification-title Nimbus JOSE+JWT Medium Product pom artifactid nimbus-jose-jwt Highest Product pom developer email vladimir@dzhuvinov.com Low Product pom developer id vdzhuvinov Low Product pom developer name Vladimir Dzhuvinov Low Product pom groupid com.nimbusds Highest Product pom name Nimbus JOSE+JWT High Product pom organization name Connect2id Ltd. Low Product pom organization url https://connect2id.com Low Product pom url https://bitbucket.org/connect2id/nimbus-jose-jwt Medium Version file version 10.0.2 High Version Manifest build-tag 10.0.2 Low Version Manifest Bundle-Version 10.0.2 High Version Manifest Implementation-Version 10.0.2 High Version pom version 10.0.2 Highest
poi-5.4.1.jarDescription:
Apache POI - Java API To Access Microsoft Format Files License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/org/apache/poi/poi/5.4.1/poi-5.4.1.jar
MD5: d238d8ad583b76119b85c793fc36e0e7
SHA1: e4c74c59e13f62d8edd215756d14ce55566c6efe
SHA256: da5abf42da4604c5a7bca38956af6e9d6f196d9b6d4cb7eabee4f480b580d505
Referenced In Project/Scope: fides-tool-ui-desktop:compile
poi-5.4.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name poi High Vendor jar package name apache Highest Vendor jar package name common Highest Vendor jar package name format Highest Vendor jar package name poi Highest Vendor Manifest automatic-module-name org.apache.poi.poi Medium Vendor Manifest Implementation-Vendor org.apache.poi High Vendor Manifest Implementation-Vendor-Id The Apache Software Foundation Medium Vendor Manifest multi-release true Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid poi Highest Vendor pom artifactid poi Low Vendor pom groupid org.apache.poi Highest Vendor pom name Apache POI - Common High Vendor pom organization name Apache Software Foundation High Vendor pom organization url https://www.apache.org/ Medium Vendor pom url https://poi.apache.org/ Highest Product file name poi High Product jar package name apache Highest Product jar package name common Highest Product jar package name format Highest Product jar package name poi Highest Product Manifest automatic-module-name org.apache.poi.poi Medium Product Manifest Implementation-Title Apache POI High Product Manifest multi-release true Low Product Manifest specification-title Apache POI Medium Product pom artifactid poi Highest Product pom groupid org.apache.poi Highest Product pom name Apache POI - Common High Product pom organization name Apache Software Foundation Low Product pom organization url https://www.apache.org/ Low Product pom url https://poi.apache.org/ Medium Version file version 5.4.1 High Version Manifest Implementation-Version 5.4.1 High Version pom version 5.4.1 Highest
Related Dependencies poi-ooxml-5.4.1.jarFile Path: /var/jenkins_home/.m2/repository/org/apache/poi/poi-ooxml/5.4.1/poi-ooxml-5.4.1.jar MD5: 739aff194051285e0e727e7c95ccbebd SHA1: 508ed3e7fcc775738415870d0bc6d27196317fe3 SHA256: fd200c9e6f74d704160a97e9d52041995ed87439454530001edd920688f19f53 pkg:maven/org.apache.poi/poi-ooxml@5.4.1 poi-ooxml-lite-5.4.1.jarFile Path: /var/jenkins_home/.m2/repository/org/apache/poi/poi-ooxml-lite/5.4.1/poi-ooxml-lite-5.4.1.jar MD5: 03d8127d15807b3892dd46cae45ce731 SHA1: 0ed2246f88254ba40fc2e7999c8f8e4e9031208a SHA256: dc590461efdfcd4f27e2a892737979ab5e30b4132a7adfc7c9e56447b71a45b0 pkg:maven/org.apache.poi/poi-ooxml-lite@5.4.1 slf4j-api-2.0.17.jarDescription:
The slf4j API License:
https://opensource.org/license/mit File Path: /var/jenkins_home/.m2/repository/org/slf4j/slf4j-api/2.0.17/slf4j-api-2.0.17.jar
MD5: b6480d114a23683498ac3f746f959d2f
SHA1: d9e58ac9c7779ba3bf8142aff6c830617a7fe60f
SHA256: 7b751d952061954d5abfed7181c1f645d336091b679891591d63329c622eb832
Referenced In Project/Scope: fides-tool-ui-desktop:compile
slf4j-api-2.0.17.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name slf4j-api High Vendor jar package name slf4j Highest Vendor Manifest build-jdk-spec 21 Low Vendor Manifest bundle-docurl http://www.slf4j.org Low Vendor Manifest bundle-symbolicname slf4j.api Medium Vendor Manifest multi-release true Low Vendor pom artifactid slf4j-api Highest Vendor pom artifactid slf4j-api Low Vendor pom groupid org.slf4j Highest Vendor pom name SLF4J API Module High Vendor pom parent-artifactid slf4j-parent Low Vendor pom url http://www.slf4j.org Highest Product file name slf4j-api High Product jar package name slf4j Highest Product Manifest build-jdk-spec 21 Low Product Manifest bundle-docurl http://www.slf4j.org Low Product Manifest Bundle-Name SLF4J API Module Medium Product Manifest bundle-symbolicname slf4j.api Medium Product Manifest Implementation-Title slf4j-api High Product Manifest multi-release true Low Product pom artifactid slf4j-api Highest Product pom groupid org.slf4j Highest Product pom name SLF4J API Module High Product pom parent-artifactid slf4j-parent Medium Product pom url http://www.slf4j.org Medium Version file version 2.0.17 High Version Manifest Bundle-Version 2.0.17 High Version Manifest Implementation-Version 2.0.17 High Version pom version 2.0.17 Highest
snakeyaml-2.4.jarDescription:
YAML 1.1 parser and emitter for Java License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/org/yaml/snakeyaml/2.4/snakeyaml-2.4.jar
MD5: 29410ee3a987e3bff7b847933c591972
SHA1: e0666b825b796f85521f02360e77f4c92c5a7a07
SHA256: ef779af5d29a9dde8cc70ce0341f5c6f7735e23edff9685ceaa9d35359b7bb7f
Referenced In Project/Scope: fides-tool-ui-desktop:compile
snakeyaml-2.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name snakeyaml High Vendor jar package name emitter Highest Vendor jar package name org Highest Vendor jar package name parser Highest Vendor jar package name snakeyaml Highest Vendor jar package name yaml Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-symbolicname org.yaml.snakeyaml Medium Vendor Manifest multi-release true Low Vendor pom artifactid snakeyaml Highest Vendor pom artifactid snakeyaml Low Vendor pom developer email alexander.maslov@gmail.com Low Vendor pom developer email public.somov@gmail.com Low Vendor pom developer id asomov Medium Vendor pom developer id maslovalex Medium Vendor pom developer name Alexander Maslov Medium Vendor pom developer name Andrey Somov Medium Vendor pom groupid org.yaml Highest Vendor pom name SnakeYAML High Vendor pom url https://bitbucket.org/snakeyaml/snakeyaml Highest Product file name snakeyaml High Product jar package name emitter Highest Product jar package name org Highest Product jar package name parser Highest Product jar package name snakeyaml Highest Product jar package name yaml Highest Product Manifest build-jdk-spec 11 Low Product Manifest Bundle-Name SnakeYAML Medium Product Manifest bundle-symbolicname org.yaml.snakeyaml Medium Product Manifest multi-release true Low Product pom artifactid snakeyaml Highest Product pom developer email alexander.maslov@gmail.com Low Product pom developer email public.somov@gmail.com Low Product pom developer id asomov Low Product pom developer id maslovalex Low Product pom developer name Alexander Maslov Low Product pom developer name Andrey Somov Low Product pom groupid org.yaml Highest Product pom name SnakeYAML High Product pom url https://bitbucket.org/snakeyaml/snakeyaml Medium Version file version 2.4 High Version pom version 2.4 Highest
spring-boot-3.5.6.jarDescription:
Spring Boot License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /var/jenkins_home/.m2/repository/org/springframework/boot/spring-boot/3.5.6/spring-boot-3.5.6.jar
MD5: 231014f73d50a9f27d683152e13676c9
SHA1: a02f486ab700dad1f81e54cb37651d92a3f9d700
SHA256: 4e66f6f3152e148c028977c33ab12c91ae381701b5d9d9951882a84f05ff5fea
Referenced In Project/Scope: fides-tool-ui-desktop:compile
spring-boot-3.5.6.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-devtools@3.5.6
Evidence Type Source Name Value Confidence Vendor file name spring-boot High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name boot Highest Vendor jar package name springframework Highest Vendor Manifest automatic-module-name spring.boot Medium Vendor Manifest build-jdk-spec 17 Low Vendor pom artifactid spring-boot Highest Vendor pom artifactid spring-boot Low Vendor pom developer email ask@spring.io Low Vendor pom developer name Spring Medium Vendor pom developer org VMware, Inc. Medium Vendor pom developer org URL https://www.spring.io Medium Vendor pom groupid org.springframework.boot Highest Vendor pom name spring-boot High Vendor pom organization name VMware, Inc. High Vendor pom organization url https://spring.io Medium Vendor pom url https://spring.io/projects/spring-boot Highest Product file name spring-boot High Product jar package name boot Highest Product jar package name springframework Highest Product Manifest automatic-module-name spring.boot Medium Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Spring Boot High Product pom artifactid spring-boot Highest Product pom developer email ask@spring.io Low Product pom developer name Spring Low Product pom developer org VMware, Inc. Low Product pom developer org URL https://www.spring.io Low Product pom groupid org.springframework.boot Highest Product pom name spring-boot High Product pom organization name VMware, Inc. Low Product pom organization url https://spring.io Low Product pom url https://spring.io/projects/spring-boot Medium Version file version 3.5.6 High Version Manifest Implementation-Version 3.5.6 High Version pom version 3.5.6 Highest
Related Dependencies spring-boot-autoconfigure-3.5.6.jarFile Path: /var/jenkins_home/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/3.5.6/spring-boot-autoconfigure-3.5.6.jar MD5: cd644e2db8b76d02439b979924344524 SHA1: 6b8fc2519774de4e82b0dbb5651093ce2ca20836 SHA256: 1f8284cefaffb3018d803e4c9cf065eaa88dc3e09a9aa2abea8e876981b1be7a pkg:maven/org.springframework.boot/spring-boot-autoconfigure@3.5.6 spring-boot-starter-3.5.6.jarFile Path: /var/jenkins_home/.m2/repository/org/springframework/boot/spring-boot-starter/3.5.6/spring-boot-starter-3.5.6.jar MD5: 499b44457693418562472af01d12fe79 SHA1: 2a2de314809a7c4c9b7303063c1313e03fe31ad3 SHA256: 7485ac46795f7e2c87252b285dfa0b9364a2b32f24a0aa20ebaee2a88b03b29b pkg:maven/org.springframework.boot/spring-boot-starter@3.5.6 spring-boot-starter-aop-3.5.6.jarFile Path: /var/jenkins_home/.m2/repository/org/springframework/boot/spring-boot-starter-aop/3.5.6/spring-boot-starter-aop-3.5.6.jar MD5: 4d5823ac34be609d65b5bc90b185c3a3 SHA1: a4892435751062086f3b204bb6dacc963f65f138 SHA256: 68d3031dce20f6f8815b027fa5da786bb0e5978d1092bbefec8646ec51037245 pkg:maven/org.springframework.boot/spring-boot-starter-aop@3.5.6 spring-boot-starter-data-jpa-3.5.6.jarFile Path: /var/jenkins_home/.m2/repository/org/springframework/boot/spring-boot-starter-data-jpa/3.5.6/spring-boot-starter-data-jpa-3.5.6.jar MD5: c2072d8743ebe42720a3c9903ba8c13c SHA1: ec77fd4b025ff3401e80be68a8a3dfbe45c7dcfa SHA256: 94f8fcbecfff5e79ae14c1e8bbb3028e00989ff766b3c528d6c5523f13e27701 pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@3.5.6 spring-boot-starter-jdbc-3.5.6.jarFile Path: /var/jenkins_home/.m2/repository/org/springframework/boot/spring-boot-starter-jdbc/3.5.6/spring-boot-starter-jdbc-3.5.6.jar MD5: bd0bb871efd8ccc22273d72b388edee5 SHA1: 812d2dc9a662d9ab640bea01b383e82d881fc586 SHA256: e89e116ca817ad1b2a3b42ce51a79fda0b37b746288416185098668b2c7ba4eb pkg:maven/org.springframework.boot/spring-boot-starter-jdbc@3.5.6 spring-boot-starter-json-3.5.6.jarFile Path: /var/jenkins_home/.m2/repository/org/springframework/boot/spring-boot-starter-json/3.5.6/spring-boot-starter-json-3.5.6.jar MD5: 38a24931a27e2b3eb83e8c011dc92c2d SHA1: 62143e29dbac1e72759da7dd85fb8f85a3d582f7 SHA256: 018087e3534c5a814c80a27d8557683ed936a95939fe4a3e18072d4a5efacf28 pkg:maven/org.springframework.boot/spring-boot-starter-json@3.5.6 spring-boot-starter-logging-3.5.6.jarFile Path: /var/jenkins_home/.m2/repository/org/springframework/boot/spring-boot-starter-logging/3.5.6/spring-boot-starter-logging-3.5.6.jar MD5: 605762761130e359dc3c60b6e32ec759 SHA1: 61717f15cb53d2a0cce6428b29adbdc2ed5f2f25 SHA256: e6892def352e56ae612274b768cf29ebae71810433560b12c2177aaaa8362080 pkg:maven/org.springframework.boot/spring-boot-starter-logging@3.5.6 spring-boot-starter-security-3.5.6.jarFile Path: /var/jenkins_home/.m2/repository/org/springframework/boot/spring-boot-starter-security/3.5.6/spring-boot-starter-security-3.5.6.jar MD5: 2d259382210e2c5fa4cdb83667501cce SHA1: 000f784752820b4e59f1e144e6d208d04fa27da9 SHA256: 105eefcdfe4583031391ddc28166e5d090e56fcf6125db58537e440a8df89a83 pkg:maven/org.springframework.boot/spring-boot-starter-security@3.5.6 spring-boot-devtools-3.5.6.jarDescription:
Spring Boot Developer Tools License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /var/jenkins_home/.m2/repository/org/springframework/boot/spring-boot-devtools/3.5.6/spring-boot-devtools-3.5.6.jar
MD5: 91809d84940c512d788c46fe490672ce
SHA1: cef8469fb0f018e4180f9244ffb8e6076621987e
SHA256: eb65e5a51da7110f3bdfd708fb6ea36d847c3637b69c1ac70298e1aca87797ff
Referenced In Project/Scope: fides-tool-ui-desktop:compile
spring-boot-devtools-3.5.6.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui-desktop@1.5.6
Evidence Type Source Name Value Confidence Vendor file name spring-boot-devtools High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name boot Highest Vendor jar package name devtools Highest Vendor jar package name springframework Highest Vendor Manifest automatic-module-name spring.boot.devtools Medium Vendor Manifest build-jdk-spec 17 Low Vendor pom artifactid spring-boot-devtools Highest Vendor pom artifactid spring-boot-devtools Low Vendor pom developer email ask@spring.io Low Vendor pom developer name Spring Medium Vendor pom developer org VMware, Inc. Medium Vendor pom developer org URL https://www.spring.io Medium Vendor pom groupid org.springframework.boot Highest Vendor pom name spring-boot-devtools High Vendor pom organization name VMware, Inc. High Vendor pom organization url https://spring.io Medium Vendor pom url https://spring.io/projects/spring-boot Highest Product file name spring-boot-devtools High Product jar package name boot Highest Product jar package name devtools Highest Product jar package name springframework Highest Product Manifest automatic-module-name spring.boot.devtools Medium Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Spring Boot Developer Tools High Product pom artifactid spring-boot-devtools Highest Product pom developer email ask@spring.io Low Product pom developer name Spring Low Product pom developer org VMware, Inc. Low Product pom developer org URL https://www.spring.io Low Product pom groupid org.springframework.boot Highest Product pom name spring-boot-devtools High Product pom organization name VMware, Inc. Low Product pom organization url https://spring.io Low Product pom url https://spring.io/projects/spring-boot Medium Version file version 3.5.6 High Version Manifest Implementation-Version 3.5.6 High Version pom version 3.5.6 Highest
spring-boot-devtools-3.5.6.jar: livereload.jsFile Path: /var/jenkins_home/.m2/repository/org/springframework/boot/spring-boot-devtools/3.5.6/spring-boot-devtools-3.5.6.jar/org/springframework/boot/devtools/livereload/livereload.jsMD5: cd0ec67ecbb16eb5808ac021d139b500SHA1: 4720deaad842bc4e96d26d54f3e9d9f62b6f5b3eSHA256: 22f51f2ab40406e5b31468e3fea7dd413014f7ccbe780d9e2171d27904c6ccdfReferenced In Project/Scope: fides-tool-ui-desktop:compile
Evidence Type Source Name Value Confidence
spring-core-6.2.11.jarDescription:
Spring Core License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /var/jenkins_home/.m2/repository/org/springframework/spring-core/6.2.11/spring-core-6.2.11.jar
MD5: 51868fd20036bc3bb237bf06c327dd22
SHA1: 0f4860eb6ea92abb8ae6c5e82e2e7efc395cef8d
SHA256: a1de6ff2d88c05442468360b89f881b77ff7a393b8cd5b1d5758756b2e247f8a
Referenced In Project/Scope: fides-tool-ui-desktop:compile
spring-core-6.2.11.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name spring-core High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name core Highest Vendor jar package name io Highest Vendor jar package name org Highest Vendor jar package name springframework Highest Vendor Manifest automatic-module-name spring.core Medium Vendor Manifest multi-release true Low Vendor pom artifactid spring-core Highest Vendor pom artifactid spring-core Low Vendor pom developer email juergen.hoeller@broadcom.com Low Vendor pom developer id jhoeller Medium Vendor pom developer name Juergen Hoeller Medium Vendor pom groupid org.springframework Highest Vendor pom name Spring Core High Vendor pom organization name Spring IO High Vendor pom organization url https://spring.io/projects/spring-framework Medium Vendor pom url spring-projects/spring-framework Highest Product file name spring-core High Product hint analyzer product springsource_spring_framework Highest Product jar package name core Highest Product jar package name io Highest Product jar package name org Highest Product jar package name springframework Highest Product Manifest automatic-module-name spring.core Medium Product Manifest Implementation-Title spring-core High Product Manifest multi-release true Low Product pom artifactid spring-core Highest Product pom developer email juergen.hoeller@broadcom.com Low Product pom developer id jhoeller Low Product pom developer name Juergen Hoeller Low Product pom groupid org.springframework Highest Product pom name Spring Core High Product pom organization name Spring IO Low Product pom organization url https://spring.io/projects/spring-framework Low Product pom url spring-projects/spring-framework High Version file version 6.2.11 High Version Manifest Implementation-Version 6.2.11 High Version pom version 6.2.11 Highest
Related Dependencies spring-aop-6.2.11.jarFile Path: /var/jenkins_home/.m2/repository/org/springframework/spring-aop/6.2.11/spring-aop-6.2.11.jar MD5: b427d46b0276ea4d43601f7c145788c9 SHA1: 1e970383810700506d646c2fa8943725f123f000 SHA256: 91e6cd420cd601a34dc41fc33364cfe77d40b6281ee472a0b72d43791f06a1dd pkg:maven/org.springframework/spring-aop@6.2.11 spring-aspects-6.2.11.jarFile Path: /var/jenkins_home/.m2/repository/org/springframework/spring-aspects/6.2.11/spring-aspects-6.2.11.jar MD5: 4bc60cc0c416a758597885bd448c64f4 SHA1: e02d582f1595b101c7fa53778e91ddb71d62974e SHA256: 15face570cbba18703234a42f63ebd9e4c05bcb8389c4fab754c4aedb7e48c92 pkg:maven/org.springframework/spring-aspects@6.2.11 spring-beans-6.2.11.jarFile Path: /var/jenkins_home/.m2/repository/org/springframework/spring-beans/6.2.11/spring-beans-6.2.11.jar MD5: e3c01be35c60920a3ab12c21baa41a7c SHA1: 8d92eb837b70094d7316f6a07770eefd360bc53c SHA256: f9ba5dedee94947b11d930209ff1a12bbe9e28b1b4f73c5baeba2fb3fe32d08e pkg:maven/org.springframework/spring-beans@6.2.11 spring-context-6.2.11.jarFile Path: /var/jenkins_home/.m2/repository/org/springframework/spring-context/6.2.11/spring-context-6.2.11.jar MD5: 29653a26355b3f42611823e903b890f6 SHA1: bbfb4d55385b2b65ecaf04937d209cf467eaba2f SHA256: a2c732fce8b24ead7caf4a21a157167bce991048638805cf1277a5ed6a568057 pkg:maven/org.springframework/spring-context@6.2.11 spring-expression-6.2.11.jarFile Path: /var/jenkins_home/.m2/repository/org/springframework/spring-expression/6.2.11/spring-expression-6.2.11.jar MD5: fa635dc6c35b44c562243b6197c36a1f SHA1: 7190c1c69576516efef1a061d956dccf17cb0b86 SHA256: 0fd8753b1ad861019ab1e1cedbba82c1354bab0313f0c8509799edd3fc98bbb3 pkg:maven/org.springframework/spring-expression@6.2.11 spring-jcl-6.2.11.jarFile Path: /var/jenkins_home/.m2/repository/org/springframework/spring-jcl/6.2.11/spring-jcl-6.2.11.jar MD5: ceca93e5e49f5246dcd15f246fdb14bb SHA1: 819fc7e968ac07d4b042be7cfb8d99c267142ac7 SHA256: a5d92923b658637c62c481dc44eab029afc1b816b10d8d0fda5ed63715f3cf85 pkg:maven/org.springframework/spring-jcl@6.2.11 spring-jdbc-6.2.11.jarFile Path: /var/jenkins_home/.m2/repository/org/springframework/spring-jdbc/6.2.11/spring-jdbc-6.2.11.jar MD5: af2cef13597c5eb0a22e1f718136e50a SHA1: 8aadfc8bed1630563c65bb5628e2175ecd508998 SHA256: 01e63e0bb60859ba64279998fd1619b4ad8fad0f127cc84271c7652e00ee6a98 pkg:maven/org.springframework/spring-jdbc@6.2.11 spring-orm-6.2.11.jarFile Path: /var/jenkins_home/.m2/repository/org/springframework/spring-orm/6.2.11/spring-orm-6.2.11.jar MD5: 102e113c4e69aa42cbebd7e7c1fe2ef6 SHA1: d14df2d6ecddd2984ef5590d73c5178d7df25c11 SHA256: e3c865f95f56875824dac07820f9a0589ef56509843fdc96585826097dd1f654 pkg:maven/org.springframework/spring-orm@6.2.11 spring-tx-6.2.11.jarFile Path: /var/jenkins_home/.m2/repository/org/springframework/spring-tx/6.2.11/spring-tx-6.2.11.jar MD5: 46b1e227c1981f909a42e3fde38c8fec SHA1: f2b8bef65f6682019002c12a628886637e596261 SHA256: dd7eb3514a51c91e565a4ca1e7b170f7513b4da56d6f7821ac84cb32dc4fbb16 pkg:maven/org.springframework/spring-tx@6.2.11 spring-data-commons-3.5.4.jarDescription:
Core Spring concepts underpinning every Spring Data module. File Path: /var/jenkins_home/.m2/repository/org/springframework/data/spring-data-commons/3.5.4/spring-data-commons-3.5.4.jarMD5: aaa31b985d10f0d128d2400237d8166cSHA1: b61f6528cb8b39b471775a4b27f0437f6646f1e6SHA256: 03295fe2e3c60931d46153136b4d8008d9d2e0bd8c7a058ddbfbc5e96779ca0cReferenced In Project/Scope: fides-tool-ui-desktop:compilespring-data-commons-3.5.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name spring-data-commons High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name core Highest Vendor jar package name data Highest Vendor jar package name springframework Highest Vendor Manifest automatic-module-name spring.data.commons Medium Vendor Manifest build-jdk-spec 17 Low Vendor pom artifactid spring-data-commons Highest Vendor pom artifactid spring-data-commons Low Vendor pom groupid org.springframework.data Highest Vendor pom name Spring Data Core High Vendor pom parent-artifactid spring-data-parent Low Vendor pom parent-groupid org.springframework.data.build Medium Vendor pom url https://spring.io/projects/spring-data Highest Product file name spring-data-commons High Product jar package name core Highest Product jar package name data Highest Product jar package name springframework Highest Product Manifest automatic-module-name spring.data.commons Medium Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Spring Data Core High Product pom artifactid spring-data-commons Highest Product pom groupid org.springframework.data Highest Product pom name Spring Data Core High Product pom parent-artifactid spring-data-parent Medium Product pom parent-groupid org.springframework.data.build Medium Product pom url https://spring.io/projects/spring-data Medium Version file version 3.5.4 High Version Manifest Implementation-Version 3.5.4 High Version pom version 3.5.4 Highest
spring-data-jpa-3.5.4.jarDescription:
Spring Data module for JPA repositories. File Path: /var/jenkins_home/.m2/repository/org/springframework/data/spring-data-jpa/3.5.4/spring-data-jpa-3.5.4.jarMD5: 4b07aa3463690622494ca3f5fbc15d2eSHA1: abd37141d1bd52283aac0d962d6efa1d4d72424bSHA256: acb41799f540043275c60713b72445e9bf5b4a58faf2ce5716ca9dc993d5b2e3Referenced In Project/Scope: fides-tool-ui-desktop:compilespring-data-jpa-3.5.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name spring-data-jpa High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name data Highest Vendor jar package name jpa Highest Vendor jar package name springframework Highest Vendor Manifest automatic-module-name spring.data.jpa Medium Vendor Manifest build-jdk-spec 17 Low Vendor pom artifactid spring-data-jpa Highest Vendor pom artifactid spring-data-jpa Low Vendor pom groupid org.springframework.data Highest Vendor pom name Spring Data JPA High Vendor pom parent-artifactid spring-data-jpa-parent Low Vendor pom url https://projects.spring.io/spring-data-jpa Highest Product file name spring-data-jpa High Product jar package name data Highest Product jar package name jpa Highest Product jar package name springframework Highest Product Manifest automatic-module-name spring.data.jpa Medium Product Manifest build-jdk-spec 17 Low Product Manifest Implementation-Title Spring Data JPA High Product pom artifactid spring-data-jpa Highest Product pom groupid org.springframework.data Highest Product pom name Spring Data JPA High Product pom parent-artifactid spring-data-jpa-parent Medium Product pom url https://projects.spring.io/spring-data-jpa Medium Version file version 3.5.4 High Version Manifest Implementation-Version 3.5.4 High Version pom version 3.5.4 Highest
spring-security-core-6.5.5.jarDescription:
Spring Security License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /var/jenkins_home/.m2/repository/org/springframework/security/spring-security-core/6.5.5/spring-security-core-6.5.5.jar
MD5: 66783411d2afa0d62a095029e0c646b8
SHA1: b4010d71d6b53cae574ba3d5c15629ed782f3318
SHA256: 22e02475fb304e52fa0f1185d12785fd7aa2fe907aa60b0d77b27f9c455da29e
Referenced In Project/Scope: fides-tool-ui-desktop:compile
spring-security-core-6.5.5.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-security@3.5.6
Evidence Type Source Name Value Confidence Vendor file name spring-security-core High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name core Highest Vendor jar package name security Highest Vendor jar package name springframework Highest Vendor Manifest automatic-module-name spring.security.core Medium Vendor pom artifactid spring-security-core Highest Vendor pom artifactid spring-security-core Low Vendor pom developer email info@pivotal.io Low Vendor pom developer name Pivotal Medium Vendor pom developer org Pivotal Software, Inc. Medium Vendor pom developer org URL https://www.spring.io Medium Vendor pom groupid org.springframework.security Highest Vendor pom name spring-security-core High Vendor pom organization name Pivotal Software, Inc. High Vendor pom organization url https://spring.io Medium Vendor pom url https://spring.io/projects/spring-security Highest Product file name spring-security-core High Product jar package name core Highest Product jar package name security Highest Product jar package name springframework Highest Product Manifest automatic-module-name spring.security.core Medium Product Manifest Implementation-Title spring-security-core High Product pom artifactid spring-security-core Highest Product pom developer email info@pivotal.io Low Product pom developer name Pivotal Low Product pom developer org Pivotal Software, Inc. Low Product pom developer org URL https://www.spring.io Low Product pom groupid org.springframework.security Highest Product pom name spring-security-core High Product pom organization name Pivotal Software, Inc. Low Product pom organization url https://spring.io Low Product pom url https://spring.io/projects/spring-security Medium Version file version 6.5.5 High Version Manifest Implementation-Version 6.5.5 High Version pom version 6.5.5 Highest
Related Dependencies spring-security-config-6.5.5.jarFile Path: /var/jenkins_home/.m2/repository/org/springframework/security/spring-security-config/6.5.5/spring-security-config-6.5.5.jar MD5: 938dbac0af2a497953e8b0e20b5d3e60 SHA1: e647f8334d2d4578f7b553e705a409017ac37be1 SHA256: d884887c4d1106624e9724db199d8abdf4c3b94678359d5d6eac12f69b0daea2 pkg:maven/org.springframework.security/spring-security-config@6.5.5 spring-security-crypto-6.5.5.jarFile Path: /var/jenkins_home/.m2/repository/org/springframework/security/spring-security-crypto/6.5.5/spring-security-crypto-6.5.5.jar MD5: ad3821c4c1701b40d2e2e0282e9dcfa6 SHA1: 83f9ebdd4706d23d697a7012aa946b64b54476f6 SHA256: c969250ffcebcbfa18586ec2161e4f106d4cd1125f11a9b2e819f96e2aeff1c1 pkg:maven/org.springframework.security/spring-security-crypto@6.5.5 std-commons-desktop-7.0.jarFile Path: /var/jenkins_home/workspace/Fides_Multi_desktop-production/Std-Commons/std-commons-desktop/target/std-commons-desktop-7.0.jarMD5: 48f2f7a6c279213f1391c6b5c6c07839SHA1: d61a56b64750dd4cd4fdf4e98baa0bfdac543b6aSHA256: 4f02f19a4cb6238708a93bc5c6926c9ce199ec2ac7480e6848d15be2c64c64edReferenced In Project/Scope: fides-tool-ui-desktop:compilestd-commons-desktop-7.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui-desktop@1.5.6
Evidence Type Source Name Value Confidence Vendor file name std-commons-desktop High Vendor jar package name desktop Highest Vendor jar package name satodev Highest Vendor Manifest build-jdk-spec 17 Low Vendor pom artifactid std-commons-desktop Highest Vendor pom artifactid std-commons-desktop Low Vendor pom groupid com.satodev Highest Vendor pom parent-artifactid std-commons Low Product file name std-commons-desktop High Product jar package name desktop Highest Product jar package name satodev Highest Product Manifest build-jdk-spec 17 Low Product pom artifactid std-commons-desktop Highest Product pom groupid com.satodev Highest Product pom parent-artifactid std-commons Medium Version file version 7.0 High Version pom version 7.0 Highest
std-commons-oneui-7.0.jarFile Path: /var/jenkins_home/workspace/Fides_Multi_desktop-production/Std-Commons/std-commons-oneui/target/std-commons-oneui-7.0.jarMD5: 11e4696275092f443dc2fc109c981883SHA1: 27dc6204c597368349b22774178e1b11ae562f03SHA256: 33643d62ff435c49d65c236d8e54b95ef772e2c57ae54c8dea6bae1bdd1b4f41Referenced In Project/Scope: fides-tool-ui-desktop:compilestd-commons-oneui-7.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name std-commons-oneui High Vendor jar package name oneui Highest Vendor jar package name satodev Highest Vendor Manifest build-jdk-spec 17 Low Vendor pom artifactid std-commons-oneui Highest Vendor pom artifactid std-commons-oneui Low Vendor pom groupid com.satodev Highest Vendor pom parent-artifactid std-commons Low Product file name std-commons-oneui High Product jar package name oneui Highest Product jar package name satodev Highest Product Manifest build-jdk-spec 17 Low Product pom artifactid std-commons-oneui Highest Product pom groupid com.satodev Highest Product pom parent-artifactid std-commons Medium Version file version 7.0 High Version pom version 7.0 Highest
std-commons-spring-7.0.jarFile Path: /var/jenkins_home/workspace/Fides_Multi_desktop-production/Std-Commons/std-commons-spring/target/std-commons-spring-7.0.jarMD5: d1cb6610b8d7561ef7e0ea5d88d95f64SHA1: 796c93d41aa43c0a8b25a4890b1564a830569893SHA256: 14ae98de7846410435ac0ce752dad2eb1b201636fbcbd6213349088b31829ff7Referenced In Project/Scope: fides-tool-ui-desktop:compilestd-commons-spring-7.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name std-commons-spring High Vendor jar package name satodev Highest Vendor jar package name spring Highest Vendor Manifest build-jdk-spec 17 Low Vendor pom artifactid std-commons-spring Highest Vendor pom artifactid std-commons-spring Low Vendor pom groupid com.satodev Highest Vendor pom parent-artifactid std-commons Low Product file name std-commons-spring High Product jar package name satodev Highest Product jar package name spring Highest Product Manifest build-jdk-spec 17 Low Product pom artifactid std-commons-spring Highest Product pom groupid com.satodev Highest Product pom parent-artifactid std-commons Medium Version file version 7.0 High Version pom version 7.0 Highest
std-commons-utils-7.0.jarFile Path: /var/jenkins_home/workspace/Fides_Multi_desktop-production/Std-Commons/std-commons-utils/target/std-commons-utils-7.0.jarMD5: e146037ba8235b86acbbd6c1f2fb8122SHA1: dc7786e5ebedff59339ec1c553f94a9529e2246dSHA256: afecd995649f6c4265d83ef4a0f007ff0fe399dd8cc4c9c92643f4cfc92651f0Referenced In Project/Scope: fides-tool-ui-desktop:compilestd-commons-utils-7.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name std-commons-utils High Vendor jar package name satodev Highest Vendor jar package name utils Highest Vendor Manifest build-jdk-spec 17 Low Vendor pom artifactid std-commons-utils Highest Vendor pom artifactid std-commons-utils Low Vendor pom groupid com.satodev Highest Vendor pom parent-artifactid std-commons Low Product file name std-commons-utils High Product jar package name satodev Highest Product jar package name utils Highest Product Manifest build-jdk-spec 17 Low Product pom artifactid std-commons-utils Highest Product pom groupid com.satodev Highest Product pom parent-artifactid std-commons Medium Version file version 7.0 High Version pom version 7.0 Highest
txw2-4.0.5.jarDescription:
TXW is a library that allows you to write XML documents.
File Path: /var/jenkins_home/.m2/repository/org/glassfish/jaxb/txw2/4.0.5/txw2-4.0.5.jarMD5: 2f5aa7dbd5e326562cff6ce720a1485aSHA1: f36a4ef12120a9bb06d766d6a0e54b144fd7ed98SHA256: 917355bc451481f30d043b24d123110517966af34383901773882810dca480e5Referenced In Project/Scope: fides-tool-ui-desktop:runtimetxw2-4.0.5.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-api@1.0
Evidence Type Source Name Value Confidence Vendor file name txw2 High Vendor jar package name sun Highest Vendor jar package name txw Highest Vendor jar package name txw2 Highest Vendor jar package name xml Highest Vendor jar (hint) package name oracle Highest Vendor Manifest git-revision cb19596 Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id org.eclipse Medium Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid txw2 Highest Vendor pom artifactid txw2 Low Vendor pom groupid org.glassfish.jaxb Highest Vendor pom name TXW2 Runtime High Vendor pom parent-artifactid jaxb-txw-parent Low Vendor pom parent-groupid com.sun.xml.bind.mvn Medium Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest Product file name txw2 High Product jar package name sun Highest Product jar package name txw Highest Product jar package name txw2 Highest Product jar package name xml Highest Product Manifest git-revision cb19596 Low Product Manifest Implementation-Title Eclipse Implementation of JAXB High Product Manifest specification-title Jakarta XML Binding Medium Product pom artifactid txw2 Highest Product pom groupid org.glassfish.jaxb Highest Product pom name TXW2 Runtime High Product pom parent-artifactid jaxb-txw-parent Medium Product pom parent-groupid com.sun.xml.bind.mvn Medium Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium Version file version 4.0.5 High Version Manifest build-version 4.0.5 Medium Version pom version 4.0.5 Highest
validation-api-2.0.1.Final.jarDescription:
Bean Validation API
License:
Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/javax/validation/validation-api/2.0.1.Final/validation-api-2.0.1.Final.jar
MD5: 5d02c034034a7a16725ceff787e191d6
SHA1: cb855558e6271b1b32e716d24cb85c7f583ce09e
SHA256: 9873b46df1833c9ee8f5bc1ff6853375115dadd8897bcb5a0dffb5848835ee6c
Referenced In Project/Scope: fides-tool-ui-desktop:compile
validation-api-2.0.1.Final.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name validation-api High Vendor jar package name javax Highest Vendor jar package name validation Highest Vendor Manifest automatic-module-name java.validation Medium Vendor Manifest bundle-symbolicname javax.validation.api Medium Vendor pom artifactid validation-api Highest Vendor pom artifactid validation-api Low Vendor pom developer email emmanuel@hibernate.org Low Vendor pom developer email guillaume.smet@hibernate.org Low Vendor pom developer email gunnar@hibernate.org Low Vendor pom developer email hferents@redhat.com Low Vendor pom developer id emmanuelbernard Medium Vendor pom developer id epbernard Medium Vendor pom developer id guillaume.smet Medium Vendor pom developer id gunnar.morling Medium Vendor pom developer id hardy.ferentschik Medium Vendor pom developer name Emmanuel Bernard Medium Vendor pom developer name Guillaume Smet Medium Vendor pom developer name Gunnar Morling Medium Vendor pom developer name Hardy Ferentschik Medium Vendor pom developer org Red Hat, Inc. Medium Vendor pom groupid javax.validation Highest Vendor pom name Bean Validation API High Vendor pom url http://beanvalidation.org Highest Product file name validation-api High Product jar package name javax Highest Product jar package name validation Highest Product Manifest automatic-module-name java.validation Medium Product Manifest Bundle-Name Bean Validation API Medium Product Manifest bundle-symbolicname javax.validation.api Medium Product pom artifactid validation-api Highest Product pom developer email emmanuel@hibernate.org Low Product pom developer email guillaume.smet@hibernate.org Low Product pom developer email gunnar@hibernate.org Low Product pom developer email hferents@redhat.com Low Product pom developer id emmanuelbernard Low Product pom developer id epbernard Low Product pom developer id guillaume.smet Low Product pom developer id gunnar.morling Low Product pom developer id hardy.ferentschik Low Product pom developer name Emmanuel Bernard Low Product pom developer name Guillaume Smet Low Product pom developer name Gunnar Morling Low Product pom developer name Hardy Ferentschik Low Product pom developer org Red Hat, Inc. Low Product pom groupid javax.validation Highest Product pom name Bean Validation API High Product pom url http://beanvalidation.org Medium Version Manifest Bundle-Version 2.0.1.Final High Version pom version 2.0.1.Final Highest
xml-apis-ext-1.3.04.jarDescription:
xml-commons provides an Apache-hosted set of DOM, SAX, and
JAXP interfaces for use in other xml-based projects. Our hope is that we
can standardize on both a common version and packaging scheme for these
critical XML standards interfaces to make the lives of both our developers
and users easier. The External Components portion of xml-commons contains
interfaces that are defined by external standards organizations. For DOM,
that's the W3C; for SAX it's David Megginson and sax.sourceforge.net; for
JAXP it's Sun. File Path: /var/jenkins_home/.m2/repository/xml-apis/xml-apis-ext/1.3.04/xml-apis-ext-1.3.04.jarMD5: bcb07d3b8d2397db7a3013b6465d347bSHA1: 41a8b86b358e87f3f13cf46069721719105aff66SHA256: d0b4887dc34d57de49074a58affad439a013d0baffa1a8034f8ef2a5ea191646Referenced In Project/Scope: fides-tool-ui-desktop:compilexml-apis-ext-1.3.04.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.satodev/std-commons-desktop@7.0
Evidence Type Source Name Value Confidence Vendor file name xml-apis-ext High Vendor jar package name dom Highest Vendor jar package name w3c Highest Vendor manifest: org/w3c/css/sac/ Implementation-Vendor World Wide Web Consortium Medium Vendor manifest: org/w3c/dom/smil/ Implementation-Vendor World Wide Web Consortium Medium Vendor manifest: org/w3c/dom/svg/ Implementation-Vendor World Wide Web Consortium Medium Vendor pom artifactid xml-apis-ext Highest Vendor pom artifactid xml-apis-ext Low Vendor pom groupid xml-apis Highest Vendor pom name XML Commons External Components XML APIs Extensions High Vendor pom parent-artifactid apache Low Vendor pom parent-groupid org.apache Medium Vendor pom url http://xml.apache.org/commons/components/external/ Highest Product file name xml-apis-ext High Product jar package name css Highest Product jar package name dom Highest Product jar package name sac Highest Product jar package name smil Highest Product jar package name svg Highest Product jar package name w3c Highest Product manifest: org/w3c/css/sac/ Implementation-Title org.w3c.css.sac Medium Product manifest: org/w3c/css/sac/ Specification-Title Simple API for CSS Medium Product manifest: org/w3c/dom/smil/ Implementation-Title org.w3c.dom.smil Medium Product manifest: org/w3c/dom/smil/ Specification-Title Document Object Model (DOM) for Synchronized Multimedia Integration Language (SMIL) Medium Product manifest: org/w3c/dom/svg/ Implementation-Title org.w3c.dom.svg Medium Product manifest: org/w3c/dom/svg/ Specification-Title Document Object Model (DOM) for Scalable Vector Graphics (SVG) Medium Product pom artifactid xml-apis-ext Highest Product pom groupid xml-apis Highest Product pom name XML Commons External Components XML APIs Extensions High Product pom parent-artifactid apache Medium Product pom parent-groupid org.apache Medium Product pom url http://xml.apache.org/commons/components/external/ Medium Version file version 1.3.04 High Version pom parent-version 1.3.04 Low Version pom version 1.3.04 Highest
xmlbeans-5.3.0.jarDescription:
XmlBeans main jar License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/org/apache/xmlbeans/xmlbeans/5.3.0/xmlbeans-5.3.0.jar
MD5: 8d5b1d80cafc2d3feae8526ce1f45cb0
SHA1: f93c3ba820d7240b7fec4ec5bc35e7223cc6fc1f
SHA256: 6cc69da3b4d35b83c5e477cd4daba204e44109833e34af2b9a8a2c8788289917
Referenced In Project/Scope: fides-tool-ui-desktop:compile
xmlbeans-5.3.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/eu.imdr/fides-tool-ui@1.5.6
Evidence Type Source Name Value Confidence Vendor file name xmlbeans High Vendor jar package name apache Highest Vendor jar package name org Highest Vendor jar package name xmlbeans Highest Vendor Manifest multi-release true Low Vendor manifest: org/apache/xmlbeans/ Implementation-Vendor org.apache.xmlbeans Medium Vendor pom artifactid xmlbeans Highest Vendor pom artifactid xmlbeans Low Vendor pom developer email user@poi.apache.org Low Vendor pom developer id poi Medium Vendor pom developer name POI Team Medium Vendor pom developer org Apache POI Medium Vendor pom groupid org.apache.xmlbeans Highest Vendor pom name XmlBeans High Vendor pom organization name XmlBeans High Vendor pom organization url https://xmlbeans.apache.org/ Medium Vendor pom url https://xmlbeans.apache.org/ Highest Product file name xmlbeans High Product jar package name apache Highest Product jar package name org Highest Product jar package name xmlbeans Highest Product Manifest multi-release true Low Product manifest: org/apache/xmlbeans/ Implementation-Title Apache XmlBeans Medium Product manifest: org/apache/xmlbeans/ Specification-Title Apache XmlBeans Medium Product pom artifactid xmlbeans Highest Product pom developer email user@poi.apache.org Low Product pom developer id poi Low Product pom developer name POI Team Low Product pom developer org Apache POI Low Product pom groupid org.apache.xmlbeans Highest Product pom name XmlBeans High Product pom organization name XmlBeans Low Product pom organization url https://xmlbeans.apache.org/ Low Product pom url https://xmlbeans.apache.org/ Medium Version file version 5.3.0 High Version manifest: org/apache/xmlbeans/ Implementation-Version 5.3.0 Medium Version pom version 5.3.0 Highest
xmlgraphics-commons-2.10.jarDescription:
Apache XML Graphics Commons is a library that consists of several reusable
components used by Apache Batik and Apache FOP. Many of these components
can easily be used separately outside the domains of SVG and XSL-FO.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/jenkins_home/.m2/repository/org/apache/xmlgraphics/xmlgraphics-commons/2.10/xmlgraphics-commons-2.10.jar
MD5: 92c1ad0e6513acfe797a48baa108a8f3
SHA1: ee7fce93d437d489a323addd1f63f0587b5c4a97
SHA256: 857af2d06d002ce217532504244ea8ee831aeb094feb0a47b2697f19496711ea
Referenced In Project/Scope: fides-tool-ui-desktop:compile
xmlgraphics-commons-2.10.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.satodev/std-commons-desktop@7.0
Evidence Type Source Name Value Confidence Vendor file name xmlgraphics-commons High Vendor jar package name apache Highest Vendor jar package name xmlgraphics Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation (http://xmlgraphics.apache.org/) High Vendor pom artifactid xmlgraphics-commons Highest Vendor pom artifactid xmlgraphics-commons Low Vendor pom groupid org.apache.xmlgraphics Highest Vendor pom name Apache XML Graphics Commons High Vendor pom organization name Apache Software Foundation High Vendor pom organization url http://www.apache.org/ Medium Vendor pom parent-artifactid apache Low Vendor pom parent-groupid org.apache Medium Vendor pom url http://xmlgraphics.apache.org/commons/ Highest Product file name xmlgraphics-commons High Product jar package name apache Highest Product jar package name xmlgraphics Highest Product Manifest Implementation-Title Apache XML Graphics Commons High Product pom artifactid xmlgraphics-commons Highest Product pom groupid org.apache.xmlgraphics Highest Product pom name Apache XML Graphics Commons High Product pom organization name Apache Software Foundation Low Product pom organization url http://www.apache.org/ Low Product pom parent-artifactid apache Medium Product pom parent-groupid org.apache Medium Product pom url http://xmlgraphics.apache.org/commons/ Medium Version file version 2.10 High Version Manifest Implementation-Version 2.10 High Version pom parent-version 2.10 Low Version pom version 2.10 Highest