Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 8.0.1Report Generated On : Sun, 22 Jan 2023 11:31:47 +0100Dependencies Scanned : 139 (108 unique)Vulnerable Dependencies : 3 Vulnerabilities Found : 9Vulnerabilities Suppressed : 0... NVD CVE Checked : 2023-01-22T11:23:10NVD CVE Modified : 2023-01-22T07:00:02VersionCheckOn : 2023-01-03T11:18:25kev.checked : 1674383029Summary Display:
Showing Vulnerable Dependencies (click to show all) Dependencies FlasbyUtil-1.0.15-SNAPSHOT.jarDescription:
A collection of small tools I use when writing apps. License:
BSD Licence: file://${basedir}/src/site/resources/licence.html File Path: /var/lib/jenkins/.m2/repository/org/flasby/FlasbyUtil/1.0.15-SNAPSHOT/FlasbyUtil-1.0.15-SNAPSHOT.jar
MD5: 5d0bc5ef33db075b0a83f2dd24f5a2c1
SHA1: 7ee344f32329415e0b0cdd7372329c625cd40241
SHA256: ebc7e1b9c11cb999fa517ba5fa5d42cd806fd9f71d3813fdbed09674eda26263
Referenced In Project/Scope: Christmas:compile
FlasbyUtil-1.0.15-SNAPSHOT.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/christmas@1.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name FlasbyUtil High Vendor jar package name flasby Highest Vendor Manifest artifactid FlasbyUtil Low Vendor Manifest build-jdk-spec 11 Low Vendor Manifest build-timestamp 2023/01/22 10:14 Low Vendor Manifest copyright Copyright © 2008-${current.year}, Steve Flasby Low Vendor Manifest Implementation-Vendor Steve Flasby High Vendor Manifest key value Low Vendor Manifest specification-vendor Steve Flasby Low Vendor Manifest url https://www.flasby.org/software/FlasbyUtils/1.0.15-SNAPSHOT/ Low Vendor pom artifactid FlasbyUtil Highest Vendor pom artifactid FlasbyUtil Low Vendor pom developer email steve@flasby.org Low Vendor pom developer id steve Medium Vendor pom developer name Steve Flasby Medium Vendor pom groupid org.flasby Highest Vendor pom name Flasby Utils High Vendor pom organization name Steve Flasby High Vendor pom organization url http://www.flasby.org/steve.html Medium Vendor pom parent-artifactid ParentPom Low Vendor pom url https://www.flasby.org/software/${shortname}/${project.version}/ Highest Product file name FlasbyUtil High Product jar package name flasby Highest Product Manifest artifactid FlasbyUtil Low Product Manifest build-jdk-spec 11 Low Product Manifest build-timestamp 2023/01/22 10:14 Low Product Manifest copyright Copyright © 2008-${current.year}, Steve Flasby Low Product Manifest Implementation-Title Flasby Utils High Product Manifest key value Low Product Manifest specification-title Flasby Utils Medium Product Manifest url https://www.flasby.org/software/FlasbyUtils/1.0.15-SNAPSHOT/ Low Product pom artifactid FlasbyUtil Highest Product pom developer email steve@flasby.org Low Product pom developer id steve Low Product pom developer name Steve Flasby Low Product pom groupid org.flasby Highest Product pom name Flasby Utils High Product pom organization name Steve Flasby Low Product pom organization url http://www.flasby.org/steve.html Low Product pom parent-artifactid ParentPom Medium Product pom url https://www.flasby.org/software/${shortname}/${project.version}/ Medium Version Manifest Implementation-Version 1.0.15-SNAPSHOT High Version Manifest version 1.0.15-SNAPSHOT Medium Version pom parent-version 1.0.15-SNAPSHOT Low Version pom version 1.0.15-SNAPSHOT Highest
FlasbyUtil-1.0.15-SNAPSHOT.jar: TEMPLATE.jsFile Path: /var/lib/jenkins/.m2/repository/org/flasby/FlasbyUtil/1.0.15-SNAPSHOT/FlasbyUtil-1.0.15-SNAPSHOT.jar/flasby/scripts/TEMPLATE.jsMD5: 51196d2fa7978e2ae7c2cb04eb72e8c9SHA1: cfe201c115b2a92b91ace1a8f9feaa55d92c4465SHA256: 8a303ba2ffe109d5a6bfcf2bb2319ce198bb0012946affbfcfd5c9335ce1aee7Referenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
FlasbyUtil-1.0.15-SNAPSHOT.jar: _template.jsFile Path: /var/lib/jenkins/.m2/repository/org/flasby/FlasbyUtil/1.0.15-SNAPSHOT/FlasbyUtil-1.0.15-SNAPSHOT.jar/flasby/js/_template.jsMD5: 6597839cc6772eb130ebe25962d75731SHA1: d97941de7865fa86d8d1281ab11245d6ae9b79b1SHA256: 7d973f8e5e97245630a58872261fcfd3389e1b8384513d129b83a41624bca7f9Referenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
FlasbyUtil-1.0.15-SNAPSHOT.jar: dialog.jsFile Path: /var/lib/jenkins/.m2/repository/org/flasby/FlasbyUtil/1.0.15-SNAPSHOT/FlasbyUtil-1.0.15-SNAPSHOT.jar/flasby/js/dialog.jsMD5: 274a22de5820875af1f8526d02d4cb62SHA1: 047fe2bca9da397c4ee6dc20acf07fd69273944fSHA256: 18710aae809f255417041caf1b941bba582f927be14f5daeba8fd6aed68abf44Referenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
FlasbyUtil-1.0.15-SNAPSHOT.jar: flasby.jsFile Path: /var/lib/jenkins/.m2/repository/org/flasby/FlasbyUtil/1.0.15-SNAPSHOT/FlasbyUtil-1.0.15-SNAPSHOT.jar/flasby/js/flasby.jsMD5: b1ad589533cf8c936681b8c7e562b511SHA1: 2bc24ace7456991ae3ef1c54875fd58cc1f6debcSHA256: 12849b0fedd20cb19bd80d068bf0308636b204b5c551578c10b137d61411e7d5Referenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
FlasbyUtil-1.0.15-SNAPSHOT.jar: json.jsFile Path: /var/lib/jenkins/.m2/repository/org/flasby/FlasbyUtil/1.0.15-SNAPSHOT/FlasbyUtil-1.0.15-SNAPSHOT.jar/flasby/js/json.jsMD5: 5e11dda513c0193fe81efdde5a0b6074SHA1: 08d3605850eaa7458a71093bdbe80475ae0c3472SHA256: 92bebdfac6851c5130133673fd307bfcd5dfe7f7d5b2f9d4ceaf972a09c7a413Referenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
FlasbyUtil-1.0.15-SNAPSHOT.jar: json.jsFile Path: /var/lib/jenkins/.m2/repository/org/flasby/FlasbyUtil/1.0.15-SNAPSHOT/FlasbyUtil-1.0.15-SNAPSHOT.jar/flasby/scripts/json.jsMD5: 1e7b41ac4b53e41a4bf688380a25917eSHA1: 05b17451723d57b2eabfe605596802d6a9bfda07SHA256: d89784592c6a05b46b77b4e9d5356a12ff36be1d7cb78ef1bb6a298ab6b79897Referenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
FlasbyUtil-1.0.15-SNAPSHOT.jar: message.jsFile Path: /var/lib/jenkins/.m2/repository/org/flasby/FlasbyUtil/1.0.15-SNAPSHOT/FlasbyUtil-1.0.15-SNAPSHOT.jar/flasby/js/message.jsMD5: 75cf971af9b418dea963789210b8ed47SHA1: 2fb954a7798a712b612a950be35daaede977df18SHA256: 58ccde07ee70081337194eaa2c39bba33ce3aa932ddd969814713554722fb9e2Referenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
FlasbyUtil-1.0.15-SNAPSHOT.jar: message.jsFile Path: /var/lib/jenkins/.m2/repository/org/flasby/FlasbyUtil/1.0.15-SNAPSHOT/FlasbyUtil-1.0.15-SNAPSHOT.jar/flasby/scripts/message.jsMD5: b2cb3be9fda2b4a1412f2869da705ffaSHA1: 3a1999df78996bf6cffc713c0e28cf0a921dbc05SHA256: de50bfcf7ff93ad80e5ea4bcf96cda77dd16cedd60a308833ca2cfe0fe6e9993Referenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
FlasbyUtil-1.0.15-SNAPSHOT.jar: pagebus.jsFile Path: /var/lib/jenkins/.m2/repository/org/flasby/FlasbyUtil/1.0.15-SNAPSHOT/FlasbyUtil-1.0.15-SNAPSHOT.jar/flasby/js/pagebus.jsMD5: 59a19dbdca35a97a1a258e4aa853dad4SHA1: 380b87500023d38dde823519bf695b7f60bbcf35SHA256: 577a2879133a3e99a7be04342ce987f8f23be045814559f50b1a0b94177673b4Referenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
FlasbyUtil-1.0.15-SNAPSHOT.jar: pagebus.jsFile Path: /var/lib/jenkins/.m2/repository/org/flasby/FlasbyUtil/1.0.15-SNAPSHOT/FlasbyUtil-1.0.15-SNAPSHOT.jar/flasby/scripts/pagebus.jsMD5: 8e8ecbf252dbc60d7bb9358492d676b4SHA1: 9cf8753cd2e97f675c5fcdfff3df55359c04278cSHA256: 304e252d6b5f1fda43f9c1b9449eb76894f5c6cf4c4319465748ff092e637d64Referenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
FlasbyUtil-1.0.15-SNAPSHOT.jar: search.jsFile Path: /var/lib/jenkins/.m2/repository/org/flasby/FlasbyUtil/1.0.15-SNAPSHOT/FlasbyUtil-1.0.15-SNAPSHOT.jar/flasby/js/search.jsMD5: 4f2e4a3bed2393fcd4f2b37bc092105eSHA1: 188b901a948674981a2bcfa607666c8f0c88ae09SHA256: 01e431e629df31b58b75c81bf2a4ae0d4f8569d7481320b9bcc148f67dbfe08aReferenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
FlasbyUtil-1.0.15-SNAPSHOT.jar: table.jsFile Path: /var/lib/jenkins/.m2/repository/org/flasby/FlasbyUtil/1.0.15-SNAPSHOT/FlasbyUtil-1.0.15-SNAPSHOT.jar/flasby/js/table.jsMD5: f1a2de09e89a4c635606fd2e05a74a34SHA1: 513a4c609f82335a018acf2bca4f82903ffb7f1aSHA256: b18057f4863b1de539d6bc95a51e15c165f3f32ba108dd4a8972a44a789c380eReferenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
FlasbyUtil-1.0.15-SNAPSHOT.jar: table.jsFile Path: /var/lib/jenkins/.m2/repository/org/flasby/FlasbyUtil/1.0.15-SNAPSHOT/FlasbyUtil-1.0.15-SNAPSHOT.jar/flasby/scripts/table.jsMD5: 5a6168e002b67378e349fab549cd9b08SHA1: e6fcd72fdcb940c6193b4a13a574160761195249SHA256: 68996b39e2d537c0a4d1884a4b21b7b263144f784657362959d68a21a9ab144aReferenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
HikariCP-4.0.3.jarDescription:
Ultimate JDBC Connection Pool License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/lib/jenkins/.m2/repository/com/zaxxer/HikariCP/4.0.3/HikariCP-4.0.3.jar
MD5: e725642926105cd1bbf4ad7fdff5d5a9
SHA1: 107cbdf0db6780a065f895ae9d8fbf3bb0e1c21f
SHA256: 7c024aeff1c1063576d74453513f9de6447d8e624d17f8e27f30a2e97688c6c9
Referenced In Project/Scope: Christmas:compile
HikariCP-4.0.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.7.6
Evidence Type Source Name Value Confidence Vendor file name HikariCP High Vendor jar package name pool Highest Vendor jar package name zaxxer Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://github.com/brettwooldridge Low Vendor Manifest bundle-symbolicname com.zaxxer.HikariCP Medium Vendor Manifest multi-release true Low Vendor Manifest originally-created-by Apache Maven Bundle Plugin Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid HikariCP Highest Vendor pom artifactid HikariCP Low Vendor pom developer email brett.wooldridge@gmail.com Low Vendor pom developer name Brett Wooldridge Medium Vendor pom groupid com.zaxxer Highest Vendor pom name HikariCP High Vendor pom organization name Zaxxer.com High Vendor pom organization url brettwooldridge Medium Vendor pom url brettwooldridge/HikariCP Highest Product file name HikariCP High Product jar package name 11 Highest Product jar package name pool Highest Product jar package name zaxxer Highest Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://github.com/brettwooldridge Low Product Manifest Bundle-Name HikariCP Medium Product Manifest bundle-symbolicname com.zaxxer.HikariCP Medium Product Manifest multi-release true Low Product Manifest originally-created-by Apache Maven Bundle Plugin Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid HikariCP Highest Product pom developer email brett.wooldridge@gmail.com Low Product pom developer name Brett Wooldridge Low Product pom groupid com.zaxxer Highest Product pom name HikariCP High Product pom organization name Zaxxer.com Low Product pom url brettwooldridge High Product pom url brettwooldridge/HikariCP High Version file version 4.0.3 High Version Manifest Bundle-Version 4.0.3 High Version pom version 4.0.3 Highest
antlr-2.7.7.jarDescription:
A framework for constructing recognizers, compilers,
and translators from grammatical descriptions containing
Java, C#, C++, or Python actions.
License:
BSD License: http://www.antlr.org/license.html File Path: /var/lib/jenkins/.m2/repository/antlr/antlr/2.7.7/antlr-2.7.7.jar
MD5: f8f1352c52a4c6a500b597596501fc64
SHA1: 83cd2cd674a217ade95a4bb83a8a14f351f48bd0
SHA256: 88fbda4b912596b9f56e8e12e580cc954bacfb51776ecfddd3e18fc1cf56dc4c
Referenced In Project/Scope: Christmas:compile
antlr-2.7.7.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.7.6
Evidence Type Source Name Value Confidence Vendor file name antlr High Vendor jar package name actions Highest Vendor jar package name antlr Highest Vendor jar package name antlr Low Vendor jar package name java Highest Vendor jar package name parser Highest Vendor jar package name python Highest Vendor pom artifactid antlr Highest Vendor pom artifactid antlr Low Vendor pom groupid antlr Highest Vendor pom name AntLR Parser Generator High Vendor pom url http://www.antlr.org/ Highest Product file name antlr High Product jar package name actions Highest Product jar package name antlr Highest Product jar package name java Highest Product jar package name parser Highest Product jar package name python Highest Product pom artifactid antlr Highest Product pom groupid antlr Highest Product pom name AntLR Parser Generator High Product pom url http://www.antlr.org/ Medium Version file version 2.7.7 High Version pom version 2.7.7 Highest
aspectjweaver-1.9.7.jarDescription:
The AspectJ weaver applies aspects to Java classes. It can be used as a Java agent in order to apply load-time
weaving (LTW) during class-loading and also contains the AspectJ runtime classes. License:
Eclipse Public License - v 2.0: https://www.eclipse.org/org/documents/epl-2.0/EPL-2.0.txt File Path: /var/lib/jenkins/.m2/repository/org/aspectj/aspectjweaver/1.9.7/aspectjweaver-1.9.7.jar
MD5: a4d97c5a2f94b8b5d132761a769e5eeb
SHA1: 158f5c255cd3e4408e795b79f7c3fbae9b53b7ca
SHA256: 1b448d82bd0f8a8c1842506e6c7edb95ff1a1275ce39f766e7884122b866fe5d
Referenced In Project/Scope: Christmas:compile
aspectjweaver-1.9.7.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.7.6
Evidence Type Source Name Value Confidence Vendor file name aspectjweaver High Vendor jar package name agent Highest Vendor jar package name and Highest Vendor jar package name aspectj Highest Vendor jar package name aspects Highest Vendor jar package name ltw Highest Vendor jar package name org Highest Vendor jar package name runtime Highest Vendor jar package name weaver Highest Vendor Manifest automatic-module-name org.aspectj.weaver Medium Vendor Manifest can-redefine-classes true Low Vendor manifest: org/aspectj/weaver/ Implementation-Vendor https://www.eclipse.org/aspectj/ Medium Vendor pom artifactid aspectjweaver Highest Vendor pom artifactid aspectjweaver Low Vendor pom developer email aclement@vmware.com Low Vendor pom developer email kriegaex@aspectj.dev Low Vendor pom developer id aclement Medium Vendor pom developer id kriegaex Medium Vendor pom developer name Alexander Kriegisch Medium Vendor pom developer name Andy Clement Medium Vendor pom groupid org.aspectj Highest Vendor pom name AspectJ Weaver High Vendor pom url https://www.eclipse.org/aspectj/ Highest Product file name aspectjweaver High Product jar package name agent Highest Product jar package name and Highest Product jar package name aspectj Highest Product jar package name aspects Highest Product jar package name ltw Highest Product jar package name org Highest Product jar package name runtime Highest Product jar package name weaver Highest Product Manifest automatic-module-name org.aspectj.weaver Medium Product Manifest can-redefine-classes true Low Product manifest: org/aspectj/weaver/ Implementation-Title org.aspectj.weaver Medium Product manifest: org/aspectj/weaver/ Specification-Title AspectJ Weaver Classes Medium Product pom artifactid aspectjweaver Highest Product pom developer email aclement@vmware.com Low Product pom developer email kriegaex@aspectj.dev Low Product pom developer id aclement Low Product pom developer id kriegaex Low Product pom developer name Alexander Kriegisch Low Product pom developer name Andy Clement Low Product pom groupid org.aspectj Highest Product pom name AspectJ Weaver High Product pom url https://www.eclipse.org/aspectj/ Medium Version file version 1.9.7 High Version manifest: org/aspectj/weaver/ Implementation-Version 1.9.7 Medium Version pom version 1.9.7 Highest
attoparser-2.0.5.RELEASE.jarDescription:
Powerful, fast and easy to use HTML and XML parser for Java License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/lib/jenkins/.m2/repository/org/attoparser/attoparser/2.0.5.RELEASE/attoparser-2.0.5.RELEASE.jar
MD5: 546b814a33d40124427225d6d1df8fd2
SHA1: a93ad36df9560de3a5312c1d14f69d938099fa64
SHA256: d4015d56147f696ed0a90078675bc940529f907e7b2dfc1fad754e8033da8796
Referenced In Project/Scope: Christmas:compile
attoparser-2.0.5.RELEASE.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.thymeleaf/thymeleaf@3.0.14.RELEASE
Evidence Type Source Name Value Confidence Vendor file name attoparser High Vendor jar package name attoparser Highest Vendor Manifest automatic-module-name attoparser Medium Vendor Manifest bundle-docurl http://www.attoparser.org Low Vendor Manifest bundle-symbolicname org.attoparser Medium Vendor Manifest implementation-url http://www.attoparser.org Low Vendor Manifest Implementation-Vendor The ATTOPARSER team High Vendor Manifest Implementation-Vendor-Id org.attoparser Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest specification-vendor The ATTOPARSER team Low Vendor pom artifactid attoparser Highest Vendor pom artifactid attoparser Low Vendor pom developer email daniel.fernandez AT 11thlabs DOT org Low Vendor pom developer id dfernandez Medium Vendor pom developer name Daniel Fernandez Medium Vendor pom groupid org.attoparser Highest Vendor pom name attoparser High Vendor pom organization name The ATTOPARSER team High Vendor pom organization url http://www.attoparser.org Medium Vendor pom url http://www.attoparser.org Highest Product file name attoparser High Product jar package name attoparser Highest Product Manifest automatic-module-name attoparser Medium Product Manifest bundle-docurl http://www.attoparser.org Low Product Manifest Bundle-Name attoparser Medium Product Manifest bundle-symbolicname org.attoparser Medium Product Manifest Implementation-Title attoparser High Product Manifest implementation-url http://www.attoparser.org Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest specification-title attoparser Medium Product pom artifactid attoparser Highest Product pom developer email daniel.fernandez AT 11thlabs DOT org Low Product pom developer id dfernandez Low Product pom developer name Daniel Fernandez Low Product pom groupid org.attoparser Highest Product pom name attoparser High Product pom organization name The ATTOPARSER team Low Product pom organization url http://www.attoparser.org Low Product pom url http://www.attoparser.org Medium Version Manifest Bundle-Version 2.0.5.RELEASE High Version Manifest Implementation-Version 2.0.5.RELEASE High Version pom version 2.0.5.RELEASE Highest
bootstrap-5.2.2.jarDescription:
WebJar for Bootstrap License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0 File Path: /var/lib/jenkins/.m2/repository/org/webjars/bootstrap/5.2.2/bootstrap-5.2.2.jar
MD5: 7dbf54f1fa8dfe67e72272223dce8607
SHA1: c2ede1e23d01f56e8105626a174942e1e53ad8f3
SHA256: b0b34bc4ff8b4e8b59dd6d573ac39cdfccd151cae972987d227a6e7f2994d52e
Referenced In Project/Scope: Christmas:compile
bootstrap-5.2.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/christmas@1.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name bootstrap High Vendor Manifest build-jdk-spec 1.8 Low Vendor pom artifactid bootstrap Highest Vendor pom artifactid bootstrap Low Vendor pom developer email james@jamesward.org Low Vendor pom developer id jamesward Medium Vendor pom developer name James Ward Medium Vendor pom groupid org.webjars Highest Vendor pom name Bootstrap High Vendor pom url http://webjars.org Highest Product file name bootstrap High Product Manifest build-jdk-spec 1.8 Low Product pom artifactid bootstrap Highest Product pom developer email james@jamesward.org Low Product pom developer id jamesward Low Product pom developer name James Ward Low Product pom groupid org.webjars Highest Product pom name Bootstrap High Product pom url http://webjars.org Medium Version file version 5.2.2 High Version pom version 5.2.2 Highest
bootstrap-5.2.2.jar: bootstrap.bundle.jsFile Path: /var/lib/jenkins/.m2/repository/org/webjars/bootstrap/5.2.2/bootstrap-5.2.2.jar/META-INF/resources/webjars/bootstrap/5.2.2/js/bootstrap.bundle.jsMD5: 47c7c67d7278af298f4713dbd120b1daSHA1: 02cb3545a05060b146eb5b5e7b451f4a6daeff47SHA256: 6fa15985f06cd3b67c587838206e95d4f7c3b0eadb91055a6ca054ce69586ec5Referenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
Related Dependencies bootstrap-5.2.2.jar: bootstrap.bundle.js.gz: bootstrap.bundle.jsFile Path: /var/lib/jenkins/.m2/repository/org/webjars/bootstrap/5.2.2/bootstrap-5.2.2.jar/META-INF/resources/webjars/bootstrap/5.2.2/js/bootstrap.bundle.js.gz/bootstrap.bundle.js MD5: 47c7c67d7278af298f4713dbd120b1da SHA1: 02cb3545a05060b146eb5b5e7b451f4a6daeff47 SHA256: 6fa15985f06cd3b67c587838206e95d4f7c3b0eadb91055a6ca054ce69586ec5 bootstrap-5.2.2.jar: bootstrap.bundle.min.jsFile Path: /var/lib/jenkins/.m2/repository/org/webjars/bootstrap/5.2.2/bootstrap-5.2.2.jar/META-INF/resources/webjars/bootstrap/5.2.2/js/bootstrap.bundle.min.jsMD5: d2b0d31f74e62440ea1a557f126d0c64SHA1: 5c8f6cb983397deb65673b961a8657cfd6113ad9SHA256: c4b2394a30fa0e4a23c6b308541353e20872a6fd765ed8fb70e6b402029deb00Referenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
Related Dependencies bootstrap-5.2.2.jar: bootstrap.bundle.min.js.gz: bootstrap.bundle.min.jsFile Path: /var/lib/jenkins/.m2/repository/org/webjars/bootstrap/5.2.2/bootstrap-5.2.2.jar/META-INF/resources/webjars/bootstrap/5.2.2/js/bootstrap.bundle.min.js.gz/bootstrap.bundle.min.js MD5: d2b0d31f74e62440ea1a557f126d0c64 SHA1: 5c8f6cb983397deb65673b961a8657cfd6113ad9 SHA256: c4b2394a30fa0e4a23c6b308541353e20872a6fd765ed8fb70e6b402029deb00 bootstrap-5.2.2.jar: bootstrap.esm.jsFile Path: /var/lib/jenkins/.m2/repository/org/webjars/bootstrap/5.2.2/bootstrap-5.2.2.jar/META-INF/resources/webjars/bootstrap/5.2.2/js/bootstrap.esm.jsMD5: eedcaab1ac066e4223ce97f5cd84eec2SHA1: 66b62ab383821d5f0254c3c692755b5661104ea9SHA256: 5cb607690c6e2fe4c2f84f183283a2492f6382c0059f1a42c179a02a47ba8b80Referenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
Related Dependencies bootstrap-5.2.2.jar: bootstrap.esm.js.gz: bootstrap.esm.jsFile Path: /var/lib/jenkins/.m2/repository/org/webjars/bootstrap/5.2.2/bootstrap-5.2.2.jar/META-INF/resources/webjars/bootstrap/5.2.2/js/bootstrap.esm.js.gz/bootstrap.esm.js MD5: eedcaab1ac066e4223ce97f5cd84eec2 SHA1: 66b62ab383821d5f0254c3c692755b5661104ea9 SHA256: 5cb607690c6e2fe4c2f84f183283a2492f6382c0059f1a42c179a02a47ba8b80 bootstrap-5.2.2.jar: bootstrap.esm.min.jsFile Path: /var/lib/jenkins/.m2/repository/org/webjars/bootstrap/5.2.2/bootstrap-5.2.2.jar/META-INF/resources/webjars/bootstrap/5.2.2/js/bootstrap.esm.min.jsMD5: d7c5c803cae37dcc60cab3ad25e2cba7SHA1: 253714fd757b46d343dd6f733c037af69333db9cSHA256: 24e32c5316639112a9d4d796fa21cb6bc1c8ecdd81d7a6a6358b85ae378aaf0cReferenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
Related Dependencies bootstrap-5.2.2.jar: bootstrap.esm.min.js.gz: bootstrap.esm.min.jsFile Path: /var/lib/jenkins/.m2/repository/org/webjars/bootstrap/5.2.2/bootstrap-5.2.2.jar/META-INF/resources/webjars/bootstrap/5.2.2/js/bootstrap.esm.min.js.gz/bootstrap.esm.min.js MD5: d7c5c803cae37dcc60cab3ad25e2cba7 SHA1: 253714fd757b46d343dd6f733c037af69333db9c SHA256: 24e32c5316639112a9d4d796fa21cb6bc1c8ecdd81d7a6a6358b85ae378aaf0c bootstrap-5.2.2.jar: bootstrap.jsFile Path: /var/lib/jenkins/.m2/repository/org/webjars/bootstrap/5.2.2/bootstrap-5.2.2.jar/META-INF/resources/webjars/bootstrap/5.2.2/js/bootstrap.jsMD5: 565113dc4ee4110c542c2c5e3ca0e8a5SHA1: 46f7f7b8d5b48c3e276e34fde25008f95be9f6acSHA256: 2c4265c7d6c4deff87bb159422d0d4c842f8cab5edef1a76774e7c31a7f18f62Referenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
Related Dependencies bootstrap-5.2.2.jar: bootstrap.js.gz: bootstrap.jsFile Path: /var/lib/jenkins/.m2/repository/org/webjars/bootstrap/5.2.2/bootstrap-5.2.2.jar/META-INF/resources/webjars/bootstrap/5.2.2/js/bootstrap.js.gz/bootstrap.js MD5: 565113dc4ee4110c542c2c5e3ca0e8a5 SHA1: 46f7f7b8d5b48c3e276e34fde25008f95be9f6ac SHA256: 2c4265c7d6c4deff87bb159422d0d4c842f8cab5edef1a76774e7c31a7f18f62 bootstrap-5.2.2.jar: bootstrap.min.jsFile Path: /var/lib/jenkins/.m2/repository/org/webjars/bootstrap/5.2.2/bootstrap-5.2.2.jar/META-INF/resources/webjars/bootstrap/5.2.2/js/bootstrap.min.jsMD5: c5236e5d6a5d0ff97ff8c8e5102c6c03SHA1: 6fbfdbddbe85c578de559adcc8d07cccbc16d514SHA256: 87538c4b7e488f5a49d12f98d6a04afc61d00f26a790f319569799acd434eb65Referenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
Related Dependencies bootstrap-5.2.2.jar: bootstrap.min.js.gz: bootstrap.min.jsFile Path: /var/lib/jenkins/.m2/repository/org/webjars/bootstrap/5.2.2/bootstrap-5.2.2.jar/META-INF/resources/webjars/bootstrap/5.2.2/js/bootstrap.min.js.gz/bootstrap.min.js MD5: c5236e5d6a5d0ff97ff8c8e5102c6c03 SHA1: 6fbfdbddbe85c578de559adcc8d07cccbc16d514 SHA256: 87538c4b7e488f5a49d12f98d6a04afc61d00f26a790f319569799acd434eb65 byte-buddy-1.12.20.jarDescription:
Byte Buddy is a Java library for creating Java classes at run time.
This artifact is a build of Byte Buddy with all ASM dependencies repackaged into its own name space.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/lib/jenkins/.m2/repository/net/bytebuddy/byte-buddy/1.12.20/byte-buddy-1.12.20.jar
MD5: a23f0b0ec5a590835f7bb6a10f5df42d
SHA1: 6ec3b8bccc4c988790d8cde5baad3b95609ef136
SHA256: 0a9b2795e0e2391117062f0fc7f6ae98fa3c2a7c927847ff1e01bb7cffcd9167
Referenced In Project/Scope: Christmas:compile
byte-buddy-1.12.20.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.mockito/mockito-core@4.11.0
Evidence Type Source Name Value Confidence Vendor file name byte-buddy High Vendor jar package name asm Highest Vendor jar package name build Highest Vendor jar package name bytebuddy Highest Vendor jar package name net Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-symbolicname net.bytebuddy.byte-buddy Medium Vendor Manifest multi-release true Low Vendor pom artifactid byte-buddy Highest Vendor pom artifactid byte-buddy Low Vendor pom groupid net.bytebuddy Highest Vendor pom name Byte Buddy (without dependencies) High Vendor pom parent-artifactid byte-buddy-parent Low Product file name byte-buddy High Product jar package name asm Highest Product jar package name build Highest Product jar package name bytebuddy Highest Product jar package name net Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Bundle-Name Byte Buddy (without dependencies) Medium Product Manifest bundle-symbolicname net.bytebuddy.byte-buddy Medium Product Manifest multi-release true Low Product pom artifactid byte-buddy Highest Product pom groupid net.bytebuddy Highest Product pom name Byte Buddy (without dependencies) High Product pom parent-artifactid byte-buddy-parent Medium Version file version 1.12.20 High Version Manifest Bundle-Version 1.12.20 High Version pom version 1.12.20 Highest
checker-qual-3.8.0.jarDescription:
Checker Qual is the set of annotations (qualifiers) and supporting classes
used by the Checker Framework to type check Java source code.
Please
see artifact:
org.checkerframework:checker
License:
The MIT License: http://opensource.org/licenses/MIT File Path: /var/lib/jenkins/.m2/repository/org/checkerframework/checker-qual/3.8.0/checker-qual-3.8.0.jar
MD5: b9822b33f72326c74abded69b7c717cc
SHA1: 6b83e4a33220272c3a08991498ba9dc09519f190
SHA256: c88c2e6a5fdaeb9f26fcf879264042de8a9ee9d376e2477838feaabcfa44dda6
Referenced In Project/Scope: Christmas:compile
checker-qual-3.8.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/FlasbyUtil@1.0.15-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name checker-qual High Vendor jar package name checker Highest Vendor jar package name checkerframework Highest Vendor jar package name framework Highest Vendor jar package name qual Highest Vendor Manifest automatic-module-name org.checkerframework.checker.qual Medium Vendor Manifest bundle-symbolicname checker-qual Medium Vendor Manifest implementation-url https://checkerframework.org Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid checker-qual Highest Vendor pom artifactid checker-qual Low Vendor pom developer email mernst@cs.washington.edu Low Vendor pom developer email smillst@cs.washington.edu Low Vendor pom developer email wdietl@uwaterloo.ca Low Vendor pom developer id mernst Medium Vendor pom developer id smillst Medium Vendor pom developer id wmdietl Medium Vendor pom developer name Michael Ernst Medium Vendor pom developer name Suzanne Millstein Medium Vendor pom developer name Werner M. Dietl Medium Vendor pom developer org University of Washington Medium Vendor pom developer org University of Waterloo Medium Vendor pom developer org URL http://uwaterloo.ca/ Medium Vendor pom developer org URL https://www.cs.washington.edu/ Medium Vendor pom developer org URL https://www.cs.washington.edu/research/plse/ Medium Vendor pom groupid org.checkerframework Highest Vendor pom name Checker Qual High Vendor pom url https://checkerframework.org Highest Product file name checker-qual High Product jar package name checker Highest Product jar package name checkerframework Highest Product jar package name framework Highest Product jar package name qual Highest Product Manifest automatic-module-name org.checkerframework.checker.qual Medium Product Manifest Bundle-Name checker-qual Medium Product Manifest bundle-symbolicname checker-qual Medium Product Manifest implementation-url https://checkerframework.org Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid checker-qual Highest Product pom developer email mernst@cs.washington.edu Low Product pom developer email smillst@cs.washington.edu Low Product pom developer email wdietl@uwaterloo.ca Low Product pom developer id mernst Low Product pom developer id smillst Low Product pom developer id wmdietl Low Product pom developer name Michael Ernst Low Product pom developer name Suzanne Millstein Low Product pom developer name Werner M. Dietl Low Product pom developer org University of Washington Low Product pom developer org University of Waterloo Low Product pom developer org URL http://uwaterloo.ca/ Low Product pom developer org URL https://www.cs.washington.edu/ Low Product pom developer org URL https://www.cs.washington.edu/research/plse/ Low Product pom groupid org.checkerframework Highest Product pom name Checker Qual High Product pom url https://checkerframework.org Medium Version file version 3.8.0 High Version Manifest Bundle-Version 3.8.0 High Version Manifest Implementation-Version 3.8.0 High Version pom version 3.8.0 Highest
classes.jsFile Path: /var/lib/jenkins/workspace/Christmas/src/main/resources/static/classes.jsMD5: 5626c046640360929e04b77c191c2116SHA1: 0fb1f2762e9ada9321cca36a4a1d5f7d2527d69aSHA256: f10430cea4d8dfca0439450c3795d0e0cc1f28f9cef71a2f1820253373018f4cReferenced In Project/Scope: Christmas
Evidence Type Source Name Value Confidence
classgraph-4.8.147.jarDescription:
The uber-fast, ultra-lightweight classpath and module scanner for JVM languages. License:
The MIT License (MIT): http://opensource.org/licenses/MIT File Path: /var/lib/jenkins/.m2/repository/io/github/classgraph/classgraph/4.8.147/classgraph-4.8.147.jar
MD5: 0f7dfe9428abc215c367f953aa48c9fc
SHA1: c9cc4804e9a9bfa45e62e96d0bb5cff17882e320
SHA256: c585977bc5a8ae25fedd6876224c30584fabe9c33adfb7c162d09d71231071ac
Referenced In Project/Scope: Christmas:compile
classgraph-4.8.147.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.webjars/webjars-locator-core@0.52
Evidence Type Source Name Value Confidence Vendor file name classgraph High Vendor jar package name classgraph Highest Vendor jar package name github Highest Vendor jar package name io Highest Vendor jar package name scanner Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-category Utilities Low Vendor Manifest bundle-symbolicname io.github.classgraph.classgraph Medium Vendor Manifest multi-release true Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor pom artifactid classgraph Highest Vendor pom artifactid classgraph Low Vendor pom developer email luke.hutch@gmail.com Low Vendor pom developer name Luke Hutchison Medium Vendor pom developer org ClassGraph Medium Vendor pom developer org URL https://github.com/classgraph Medium Vendor pom groupid io.github.classgraph Highest Vendor pom name ClassGraph High Vendor pom url classgraph/classgraph Highest Product file name classgraph High Product jar package name classgraph Highest Product jar package name github Highest Product jar package name io Highest Product jar package name scanner Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-category Utilities Low Product Manifest Bundle-Name ClassGraph Medium Product Manifest bundle-symbolicname io.github.classgraph.classgraph Medium Product Manifest Implementation-Title ClassGraph High Product Manifest multi-release true Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product Manifest specification-title ClassGraph Medium Product pom artifactid classgraph Highest Product pom developer email luke.hutch@gmail.com Low Product pom developer name Luke Hutchison Low Product pom developer org ClassGraph Low Product pom developer org URL https://github.com/classgraph Low Product pom groupid io.github.classgraph Highest Product pom name ClassGraph High Product pom url classgraph/classgraph High Version file version 4.8.147 High Version Manifest Bundle-Version 4.8.147 High Version Manifest Implementation-Version 4.8.147 High Version pom version 4.8.147 Highest
classmate-1.5.1.jarDescription:
Library for introspecting types with full generic information
including resolving of field and method types.
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/lib/jenkins/.m2/repository/com/fasterxml/classmate/1.5.1/classmate-1.5.1.jar
MD5: e91fcd30ba329fd1b0b6dc5321fd067c
SHA1: 3fe0bed568c62df5e89f4f174c101eab25345b6c
SHA256: aab4de3006808c09d25dd4ff4a3611cfb63c95463cfd99e73d2e1680d229a33b
Referenced In Project/Scope: Christmas:compile
classmate-1.5.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.7.6
Evidence Type Source Name Value Confidence Vendor file name classmate High Vendor jar package name classmate Highest Vendor jar package name fasterxml Highest Vendor jar package name types Highest Vendor Manifest automatic-module-name com.fasterxml.classmate Medium Vendor Manifest bundle-docurl https://github.com/FasterXML/java-classmate Low Vendor Manifest bundle-symbolicname com.fasterxml.classmate Medium Vendor Manifest implementation-build-date 2019-10-19 22:46:35+0000 Low Vendor Manifest Implementation-Vendor fasterxml.com High Vendor Manifest Implementation-Vendor-Id com.fasterxml Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest specification-vendor fasterxml.com Low Vendor pom artifactid classmate Highest Vendor pom artifactid classmate Low Vendor pom developer email blangel@ocheyedan.net Low Vendor pom developer email tatu@fasterxml.com Low Vendor pom developer id blangel Medium Vendor pom developer id tatu Medium Vendor pom developer name Brian Langel Medium Vendor pom developer name Tatu Saloranta Medium Vendor pom groupid com.fasterxml Highest Vendor pom name ClassMate High Vendor pom organization name fasterxml.com High Vendor pom organization url https://fasterxml.com Medium Vendor pom parent-artifactid oss-parent Low Vendor pom url FasterXML/java-classmate Highest Product file name classmate High Product jar package name classmate Highest Product jar package name fasterxml Highest Product jar package name filter Highest Product jar package name types Highest Product Manifest automatic-module-name com.fasterxml.classmate Medium Product Manifest bundle-docurl https://github.com/FasterXML/java-classmate Low Product Manifest Bundle-Name ClassMate Medium Product Manifest bundle-symbolicname com.fasterxml.classmate Medium Product Manifest implementation-build-date 2019-10-19 22:46:35+0000 Low Product Manifest Implementation-Title ClassMate High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest specification-title ClassMate Medium Product pom artifactid classmate Highest Product pom developer email blangel@ocheyedan.net Low Product pom developer email tatu@fasterxml.com Low Product pom developer id blangel Low Product pom developer id tatu Low Product pom developer name Brian Langel Low Product pom developer name Tatu Saloranta Low Product pom groupid com.fasterxml Highest Product pom name ClassMate High Product pom organization name fasterxml.com Low Product pom organization url https://fasterxml.com Low Product pom parent-artifactid oss-parent Medium Product pom url FasterXML/java-classmate High Version file version 1.5.1 High Version Manifest Bundle-Version 1.5.1 High Version Manifest Implementation-Version 1.5.1 High Version pom parent-version 1.5.1 Low Version pom version 1.5.1 Highest
commons-codec-1.15.jarDescription:
The Apache Commons Codec package contains simple encoder and decoders for
various formats such as Base64 and Hexadecimal. In addition to these
widely used encoders and decoders, the codec package also maintains a
collection of phonetic encoding utilities.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/lib/jenkins/.m2/repository/commons-codec/commons-codec/1.15/commons-codec-1.15.jar
MD5: 303baf002ce6d382198090aedd9d79a2
SHA1: 49d94806b6e3dc933dacbd8acb0fdbab8ebd1e5d
SHA256: b3e9f6d63a790109bf0d056611fbed1cf69055826defeb9894a71369d246ed63
Referenced In Project/Scope: Christmas:compile
commons-codec-1.15.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.1.3
Evidence Type Source Name Value Confidence Vendor file name commons-codec High Vendor jar package name apache Highest Vendor jar package name codec Highest Vendor jar package name commons Highest Vendor jar package name encoder Highest Vendor Manifest automatic-module-name org.apache.commons.codec Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-codec/ Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-codec Medium Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid commons-codec Highest Vendor pom artifactid commons-codec Low Vendor pom developer email bayard@apache.org Low Vendor pom developer email chtompki@apache.org Low Vendor pom developer email dgraham@apache.org Low Vendor pom developer email dlr@finemaltcoding.com Low Vendor pom developer email ggregory@apache.org Low Vendor pom developer email jon@collab.net Low Vendor pom developer email julius@apache.org Low Vendor pom developer email rwaldhoff@apache.org Low Vendor pom developer email sanders@totalsync.com Low Vendor pom developer email tn@apache.org Low Vendor pom developer email tobrien@apache.org Low Vendor pom developer id bayard Medium Vendor pom developer id chtompki Medium Vendor pom developer id dgraham Medium Vendor pom developer id dlr Medium Vendor pom developer id ggregory Medium Vendor pom developer id jon Medium Vendor pom developer id julius Medium Vendor pom developer id rwaldhoff Medium Vendor pom developer id sanders Medium Vendor pom developer id tn Medium Vendor pom developer id tobrien Medium Vendor pom developer name Daniel Rall Medium Vendor pom developer name David Graham Medium Vendor pom developer name Gary Gregory Medium Vendor pom developer name Henri Yandell Medium Vendor pom developer name Jon S. Stevens Medium Vendor pom developer name Julius Davies Medium Vendor pom developer name Rob Tompkins Medium Vendor pom developer name Rodney Waldhoff Medium Vendor pom developer name Scott Sanders Medium Vendor pom developer name Thomas Neidhart Medium Vendor pom developer name Tim OBrien Medium Vendor pom developer org URL http://juliusdavies.ca/ Medium Vendor pom groupid commons-codec Highest Vendor pom name Apache Commons Codec High Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom url https://commons.apache.org/proper/commons-codec/ Highest Product file name commons-codec High Product jar package name apache Highest Product jar package name codec Highest Product jar package name commons Highest Product jar package name encoder Highest Product Manifest automatic-module-name org.apache.commons.codec Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://commons.apache.org/proper/commons-codec/ Low Product Manifest Bundle-Name Apache Commons Codec Medium Product Manifest bundle-symbolicname org.apache.commons.commons-codec Medium Product Manifest Implementation-Title Apache Commons Codec High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product Manifest specification-title Apache Commons Codec Medium Product pom artifactid commons-codec Highest Product pom developer email bayard@apache.org Low Product pom developer email chtompki@apache.org Low Product pom developer email dgraham@apache.org Low Product pom developer email dlr@finemaltcoding.com Low Product pom developer email ggregory@apache.org Low Product pom developer email jon@collab.net Low Product pom developer email julius@apache.org Low Product pom developer email rwaldhoff@apache.org Low Product pom developer email sanders@totalsync.com Low Product pom developer email tn@apache.org Low Product pom developer email tobrien@apache.org Low Product pom developer id bayard Low Product pom developer id chtompki Low Product pom developer id dgraham Low Product pom developer id dlr Low Product pom developer id ggregory Low Product pom developer id jon Low Product pom developer id julius Low Product pom developer id rwaldhoff Low Product pom developer id sanders Low Product pom developer id tn Low Product pom developer id tobrien Low Product pom developer name Daniel Rall Low Product pom developer name David Graham Low Product pom developer name Gary Gregory Low Product pom developer name Henri Yandell Low Product pom developer name Jon S. Stevens Low Product pom developer name Julius Davies Low Product pom developer name Rob Tompkins Low Product pom developer name Rodney Waldhoff Low Product pom developer name Scott Sanders Low Product pom developer name Thomas Neidhart Low Product pom developer name Tim OBrien Low Product pom developer org URL http://juliusdavies.ca/ Low Product pom groupid commons-codec Highest Product pom name Apache Commons Codec High Product pom parent-artifactid commons-parent Medium Product pom parent-groupid org.apache.commons Medium Product pom url https://commons.apache.org/proper/commons-codec/ Medium Version file version 1.15 High Version Manifest Implementation-Version 1.15 High Version pom parent-version 1.15 Low Version pom version 1.15 Highest
error_prone_annotations-2.5.1.jarLicense:
Apache 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/lib/jenkins/.m2/repository/com/google/errorprone/error_prone_annotations/2.5.1/error_prone_annotations-2.5.1.jar
MD5: 2bf3239388cf5c817cd83ecb692b045f
SHA1: 562d366678b89ce5d6b6b82c1a073880341e3fba
SHA256: ff80626baaf12a09342befd4e84cba9d50662f5fcd7f7a9b3490a6b7cf87e66c
Referenced In Project/Scope: Christmas:compile
error_prone_annotations-2.5.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/FlasbyUtil@1.0.15-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name error_prone_annotations High Vendor jar package name annotations Highest Vendor jar package name errorprone Highest Vendor jar package name google Highest Vendor Manifest automatic-module-name com.google.errorprone.annotations Medium Vendor pom artifactid error_prone_annotations Highest Vendor pom artifactid error_prone_annotations Low Vendor pom groupid com.google.errorprone Highest Vendor pom name error-prone annotations High Vendor pom parent-artifactid error_prone_parent Low Product file name error_prone_annotations High Product jar package name annotations Highest Product jar package name errorprone Highest Product jar package name google Highest Product Manifest automatic-module-name com.google.errorprone.annotations Medium Product pom artifactid error_prone_annotations Highest Product pom groupid com.google.errorprone Highest Product pom name error-prone annotations High Product pom parent-artifactid error_prone_parent Medium Version file version 2.5.1 High Version pom version 2.5.1 Highest
eventbus.jsFile Path: /var/lib/jenkins/workspace/Christmas/src/main/resources/static/eventbus.jsMD5: 89a4fdfb7cc5fbf91b091d249c807849SHA1: 64ed682121b39b0847cc3da7d43ca80628b828c1SHA256: f9d0507e5f60f12f50c4839d90ac4c10b3b388eb22cfa9c1b46fe920c432dd7bReferenced In Project/Scope: Christmas
Evidence Type Source Name Value Confidence
failureaccess-1.0.1.jarDescription:
Contains
com.google.common.util.concurrent.internal.InternalFutureFailureAccess and
InternalFutures. Most users will never need to use this artifact. Its
classes is conceptually a part of Guava, but they're in this separate
artifact so that Android libraries can use them without pulling in all of
Guava (just as they can use ListenableFuture by depending on the
listenablefuture artifact).
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/lib/jenkins/.m2/repository/com/google/guava/failureaccess/1.0.1/failureaccess-1.0.1.jar
MD5: 091883993ef5bfa91da01dcc8fc52236
SHA1: 1dcf1de382a0bf95a3d8b0849546c88bac1292c9
SHA256: a171ee4c734dd2da837e4b16be9df4661afab72a41adaf31eb84dfdaf936ca26
Referenced In Project/Scope: Christmas:compile
failureaccess-1.0.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/FlasbyUtil@1.0.15-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name failureaccess High Vendor jar package name common Highest Vendor jar package name concurrent Highest Vendor jar package name google Highest Vendor jar package name util Highest Vendor Manifest bundle-docurl https://github.com/google/guava/ Low Vendor Manifest bundle-symbolicname com.google.guava.failureaccess Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor pom artifactid failureaccess Highest Vendor pom artifactid failureaccess Low Vendor pom groupid com.google.guava Highest Vendor pom name Guava InternalFutureFailureAccess and InternalFutures High Vendor pom parent-artifactid guava-parent Low Product file name failureaccess High Product jar package name common Highest Product jar package name concurrent Highest Product jar package name google Highest Product jar package name util Highest Product Manifest bundle-docurl https://github.com/google/guava/ Low Product Manifest Bundle-Name Guava InternalFutureFailureAccess and InternalFutures Medium Product Manifest bundle-symbolicname com.google.guava.failureaccess Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product pom artifactid failureaccess Highest Product pom groupid com.google.guava Highest Product pom name Guava InternalFutureFailureAccess and InternalFutures High Product pom parent-artifactid guava-parent Medium Version file version 1.0.1 High Version Manifest Bundle-Version 1.0.1 High Version pom parent-version 1.0.1 Low Version pom version 1.0.1 Highest
guava-30.1.1-jre.jarDescription:
Guava is a suite of core and expanded libraries that include
utility classes, Google's collections, I/O classes, and
much more.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/lib/jenkins/.m2/repository/com/google/guava/guava/30.1.1-jre/guava-30.1.1-jre.jar
MD5: 05374f163d0a4141db672fff9df95b12
SHA1: 87e0fd1df874ea3cbe577702fe6f17068b790fd8
SHA256: 44ce229ce26d880bf3afc362bbfcec34d7e6903d195bbb1db9f3b6e0d9834f06
Referenced In Project/Scope: Christmas:compile
guava-30.1.1-jre.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/FlasbyUtil@1.0.15-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name guava High Vendor jar package name common Highest Vendor jar package name google Highest Vendor Manifest automatic-module-name com.google.common Medium Vendor Manifest bundle-docurl https://github.com/google/guava/ Low Vendor Manifest bundle-symbolicname com.google.guava Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid guava Highest Vendor pom artifactid guava Low Vendor pom groupid com.google.guava Highest Vendor pom name Guava: Google Core Libraries for Java High Vendor pom parent-artifactid guava-parent Low Product file name guava High Product jar package name common Highest Product jar package name google Highest Product Manifest automatic-module-name com.google.common Medium Product Manifest bundle-docurl https://github.com/google/guava/ Low Product Manifest Bundle-Name Guava: Google Core Libraries for Java Medium Product Manifest bundle-symbolicname com.google.guava Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid guava Highest Product pom groupid com.google.guava Highest Product pom name Guava: Google Core Libraries for Java High Product pom parent-artifactid guava-parent Medium Version pom version 30.1.1-jre Highest
hibernate-commons-annotations-5.1.2.Final.jarDescription:
Common reflection code used in support of annotation processing License:
GNU Library General Public License v2.1 or later: http://www.opensource.org/licenses/LGPL-2.1 File Path: /var/lib/jenkins/.m2/repository/org/hibernate/common/hibernate-commons-annotations/5.1.2.Final/hibernate-commons-annotations-5.1.2.Final.jar
MD5: 2a2490b3eb8e7585a6a899d27d7ed43f
SHA1: e59ffdbc6ad09eeb33507b39ffcf287679a498c8
SHA256: 1c7ce712b2679fea0a5441eb02a04144297125b768944819be0765befb996275
Referenced In Project/Scope: Christmas:compile
hibernate-commons-annotations-5.1.2.Final.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.7.6
Evidence Type Source Name Value Confidence Vendor file name hibernate-commons-annotations High Vendor hint analyzer vendor redhat Highest Vendor jar package name annotations Highest Vendor jar package name common Highest Vendor jar package name hibernate Highest Vendor jar package name reflection Highest Vendor Manifest automatic-module-name org.hibernate.commons.annotations Medium Vendor Manifest bundle-symbolicname org.hibernate.common.hibernate-commons-annotations Medium Vendor Manifest implementation-url http://hibernate.org Low Vendor Manifest Implementation-Vendor Hibernate.org High Vendor Manifest Implementation-Vendor-Id org.hibernate Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid hibernate-commons-annotations Highest Vendor pom artifactid hibernate-commons-annotations Low Vendor pom developer id hibernate-team Medium Vendor pom developer name The Hibernate Development Team Medium Vendor pom developer org Hibernate.org Medium Vendor pom developer org URL http://hibernate.org Medium Vendor pom groupid org.hibernate.common Highest Vendor pom name Hibernate Commons Annotations High Vendor pom organization name Hibernate.org High Vendor pom organization url http://hibernate.org Medium Vendor pom url http://hibernate.org Highest Product file name hibernate-commons-annotations High Product jar package name annotations Highest Product jar package name common Highest Product jar package name hibernate Highest Product jar package name reflection Highest Product jar package name version Highest Product Manifest automatic-module-name org.hibernate.commons.annotations Medium Product Manifest Bundle-Name hibernate-commons-annotations Medium Product Manifest bundle-symbolicname org.hibernate.common.hibernate-commons-annotations Medium Product Manifest implementation-url http://hibernate.org Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid hibernate-commons-annotations Highest Product pom developer id hibernate-team Low Product pom developer name The Hibernate Development Team Low Product pom developer org Hibernate.org Low Product pom developer org URL http://hibernate.org Low Product pom groupid org.hibernate.common Highest Product pom name Hibernate Commons Annotations High Product pom organization name Hibernate.org Low Product pom organization url http://hibernate.org Low Product pom url http://hibernate.org Medium Version Manifest Bundle-Version 5.1.2.Final High Version Manifest Implementation-Version 5.1.2.Final High Version pom version 5.1.2.Final Highest
hibernate-core-5.6.14.Final.jarDescription:
Hibernate's core ORM functionality License:
GNU Library General Public License v2.1 or later: https://www.opensource.org/licenses/LGPL-2.1 File Path: /var/lib/jenkins/.m2/repository/org/hibernate/hibernate-core/5.6.14.Final/hibernate-core-5.6.14.Final.jar
MD5: ec54e7703232f55bdf9e340309ef6556
SHA1: 71e407089b71ed7c6e99385fd851c308fed7be44
SHA256: eba7f97b5e6c382b235ca263cb55dad6efd482054dc090eaf6d44bc7d9690336
Referenced In Project/Scope: Christmas:compile
hibernate-core-5.6.14.Final.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.7.6
Evidence Type Source Name Value Confidence Vendor file name hibernate-core High Vendor hint analyzer vendor redhat Highest Vendor jar package name hibernate Highest Vendor Manifest automatic-module-name org.hibernate.orm.core Medium Vendor Manifest bundle-docurl https://hibernate.org/orm/5.6 Low Vendor Manifest bundle-symbolicname org.hibernate.orm.core Medium Vendor Manifest implementation-url https://hibernate.org/orm Low Vendor Manifest Implementation-Vendor Hibernate.org High Vendor Manifest Implementation-Vendor-Id org.hibernate Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor Hibernate.org Low Vendor pom artifactid hibernate-core Highest Vendor pom artifactid hibernate-core Low Vendor pom developer id hibernate-team Medium Vendor pom developer name The Hibernate Development Team Medium Vendor pom developer org Hibernate.org Medium Vendor pom developer org URL https://hibernate.org Medium Vendor pom groupid org.hibernate Highest Vendor pom name Hibernate ORM - hibernate-core High Vendor pom organization name Hibernate.org High Vendor pom organization url https://hibernate.org Medium Vendor pom url https://hibernate.org/orm Highest Product file name hibernate-core High Product hint analyzer product orm Highest Product jar package name filter Highest Product jar package name hibernate Highest Product jar package name version Highest Product Manifest automatic-module-name org.hibernate.orm.core Medium Product Manifest bundle-docurl https://hibernate.org/orm/5.6 Low Product Manifest Bundle-Name hibernate-core Medium Product Manifest bundle-symbolicname org.hibernate.orm.core Medium Product Manifest Implementation-Title hibernate-core High Product Manifest implementation-url https://hibernate.org/orm Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title hibernate-core Medium Product pom artifactid hibernate-core Highest Product pom developer id hibernate-team Low Product pom developer name The Hibernate Development Team Low Product pom developer org Hibernate.org Low Product pom developer org URL https://hibernate.org Low Product pom groupid org.hibernate Highest Product pom name Hibernate ORM - hibernate-core High Product pom organization name Hibernate.org Low Product pom organization url https://hibernate.org Low Product pom url https://hibernate.org/orm Medium Version Manifest Bundle-Version 5.6.14.Final High Version Manifest Implementation-Version 5.6.14.Final High Version pom version 5.6.14.Final Highest
hsqldb-2.7.1.jarDescription:
HSQLDB - Lightweight 100% Java SQL Database Engine License:
HSQLDB License, a BSD open source license: http://hsqldb.org/web/hsqlLicense.html File Path: /var/lib/jenkins/.m2/repository/org/hsqldb/hsqldb/2.7.1/hsqldb-2.7.1.jar
MD5: cc960ec33d04364a280ea9eba088300e
SHA1: 9ffb617125371538a32eb9ba1cb2fa743b2c993b
SHA256: bca5532a4c58babf9fcebf20d03f086f5ba24b076c3aaf8838a16512235e53ca
Referenced In Project/Scope: Christmas:compile
hsqldb-2.7.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/christmas@1.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name hsqldb High Vendor jar package name database Highest Vendor jar package name hsqldb Highest Vendor jar package name java Highest Vendor Manifest build-vendor ft Medium Vendor Manifest bundle-symbolicname org.hsqldb.hsqldb Medium Vendor Manifest Implementation-Vendor The HSQL Development Group High Vendor Manifest originally-created-by 11.0.14.1+1 (Eclipse Adoptium) Low Vendor Manifest specification-vendor The HSQL Development Group Low Vendor pom artifactid hsqldb Highest Vendor pom artifactid hsqldb Low Vendor pom developer email blaine.simpson@admc.com Low Vendor pom developer email ft@cluedup.com Low Vendor pom developer id fredt Medium Vendor pom developer id unsaved Medium Vendor pom developer name Blaine Simpson Medium Vendor pom developer name Fred Toussi Medium Vendor pom groupid org.hsqldb Highest Vendor pom name HyperSQL Database High Vendor pom organization name The HSQL Development Group High Vendor pom organization url http://hsqldb.org Medium Vendor pom url http://hsqldb.org Highest Product file name hsqldb High Product jar package name database Highest Product jar package name hsqldb Highest Product jar package name java Highest Product Manifest Bundle-Name HSQLDB Medium Product Manifest bundle-symbolicname org.hsqldb.hsqldb Medium Product Manifest Implementation-Title Standard runtime High Product Manifest originally-created-by 11.0.14.1+1 (Eclipse Adoptium) Low Product Manifest specification-title HSQLDB Medium Product pom artifactid hsqldb Highest Product pom developer email blaine.simpson@admc.com Low Product pom developer email ft@cluedup.com Low Product pom developer id fredt Low Product pom developer id unsaved Low Product pom developer name Blaine Simpson Low Product pom developer name Fred Toussi Low Product pom groupid org.hsqldb Highest Product pom name HyperSQL Database High Product pom organization name The HSQL Development Group Low Product pom organization url http://hsqldb.org Low Product pom url http://hsqldb.org Medium Version file version 2.7.1 High Version Manifest Bundle-Version 2.7.1 High Version Manifest Implementation-Version 2.7.1 High Version pom version 2.7.1 Highest
httpclient5-5.1.3.jarDescription:
Apache HttpComponents Client File Path: /var/lib/jenkins/.m2/repository/org/apache/httpcomponents/client5/httpclient5/5.1.3/httpclient5-5.1.3.jarMD5: 757bfb86277b9b11798db8fdb351bf74SHA1: 13c984b7b881afcff3a7f0bb95878724a48a4b66SHA256: 28c759254f4e35319e078bb6ffea75676608dc12cb243b24fb3c8732522977feReferenced In Project/Scope: Christmas:compilehttpclient5-5.1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/christmas@1.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name httpclient5 High Vendor jar package name apache Highest Vendor jar package name client5 Highest Vendor Manifest automatic-module-name org.apache.httpcomponents.client5.httpclient5 Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest implementation-url https://hc.apache.org/httpcomponents-client-5.0.x/5.1.3/httpclient5/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid httpclient5 Highest Vendor pom artifactid httpclient5 Low Vendor pom groupid org.apache.httpcomponents.client5 Highest Vendor pom name Apache HttpClient High Vendor pom parent-artifactid httpclient5-parent Low Product file name httpclient5 High Product jar package name apache Highest Product jar package name client5 Highest Product jar package name hc Highest Product Manifest automatic-module-name org.apache.httpcomponents.client5.httpclient5 Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Apache HttpClient High Product Manifest implementation-url https://hc.apache.org/httpcomponents-client-5.0.x/5.1.3/httpclient5/ Low Product Manifest specification-title Apache HttpClient Medium Product pom artifactid httpclient5 Highest Product pom groupid org.apache.httpcomponents.client5 Highest Product pom name Apache HttpClient High Product pom parent-artifactid httpclient5-parent Medium Version file version 5.1.3 High Version Manifest Implementation-Version 5.1.3 High Version pom version 5.1.3 Highest
httpcore5-5.1.5.jarDescription:
Apache HttpComponents HTTP/1.1 core components File Path: /var/lib/jenkins/.m2/repository/org/apache/httpcomponents/core5/httpcore5/5.1.5/httpcore5-5.1.5.jarMD5: 934fe49160e92465763f6cc0842bb8d0SHA1: df9da3a1fa2351c4790245400ed28d78a8ddd3fcSHA256: ff6c0da485260bb6e68c2bee7e6e59c56cbf8f1bb3ac1c63b62dd002d3bb27feReferenced In Project/Scope: Christmas:compilehttpcore5-5.1.5.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.1.3
Evidence Type Source Name Value Confidence Vendor file name httpcore5 High Vendor jar package name apache Highest Vendor jar package name core5 Highest Vendor Manifest automatic-module-name org.apache.httpcomponents.core5.httpcore5 Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest implementation-url https://hc.apache.org/httpcomponents-core-5.1.x/5.1.5/httpcore5/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid httpcore5 Highest Vendor pom artifactid httpcore5 Low Vendor pom groupid org.apache.httpcomponents.core5 Highest Vendor pom name Apache HttpComponents Core HTTP/1.1 High Vendor pom parent-artifactid httpcore5-parent Low Product file name httpcore5 High Product jar package name apache Highest Product jar package name core5 Highest Product jar package name hc Highest Product Manifest automatic-module-name org.apache.httpcomponents.core5.httpcore5 Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Apache HttpComponents Core HTTP/1.1 High Product Manifest implementation-url https://hc.apache.org/httpcomponents-core-5.1.x/5.1.5/httpcore5/ Low Product Manifest specification-title Apache HttpComponents Core HTTP/1.1 Medium Product pom artifactid httpcore5 Highest Product pom groupid org.apache.httpcomponents.core5 Highest Product pom name Apache HttpComponents Core HTTP/1.1 High Product pom parent-artifactid httpcore5-parent Medium Version file version 5.1.5 High Version Manifest Implementation-Version 5.1.5 High Version pom version 5.1.5 Highest
httpcore5-h2-5.1.5.jarDescription:
Apache HttpComponents HTTP/2 Core Components File Path: /var/lib/jenkins/.m2/repository/org/apache/httpcomponents/core5/httpcore5-h2/5.1.5/httpcore5-h2-5.1.5.jarMD5: ef9b09dd9eb70dca6641f367ff46099dSHA1: 624660339afd5006d427457e6b10b10b32fd86f1SHA256: 8ef400dc6bf0f356de40b2330fa44260c831ad1215343aebdf03eb8052426257Referenced In Project/Scope: Christmas:compilehttpcore5-h2-5.1.5.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.apache.httpcomponents.client5/httpclient5@5.1.3
Evidence Type Source Name Value Confidence Vendor file name httpcore5-h2 High Vendor jar package name apache Highest Vendor jar package name core5 Highest Vendor Manifest automatic-module-name org.apache.httpcomponents.core5.httpcore5.h2 Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest implementation-url https://hc.apache.org/httpcomponents-core-5.1.x/5.1.5/httpcore5-h2/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid httpcore5-h2 Highest Vendor pom artifactid httpcore5-h2 Low Vendor pom groupid org.apache.httpcomponents.core5 Highest Vendor pom name Apache HttpComponents Core HTTP/2 High Vendor pom parent-artifactid httpcore5-parent Low Product file name httpcore5-h2 High Product jar package name apache Highest Product jar package name core5 Highest Product jar package name hc Highest Product Manifest automatic-module-name org.apache.httpcomponents.core5.httpcore5.h2 Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Apache HttpComponents Core HTTP/2 High Product Manifest implementation-url https://hc.apache.org/httpcomponents-core-5.1.x/5.1.5/httpcore5-h2/ Low Product Manifest specification-title Apache HttpComponents Core HTTP/2 Medium Product pom artifactid httpcore5-h2 Highest Product pom groupid org.apache.httpcomponents.core5 Highest Product pom name Apache HttpComponents Core HTTP/2 High Product pom parent-artifactid httpcore5-parent Medium Version file version 5.1.5 High Version Manifest Implementation-Version 5.1.5 High Version pom version 5.1.5 Highest
istack-commons-runtime-3.0.12.jarDescription:
istack common utility code License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /var/lib/jenkins/.m2/repository/com/sun/istack/istack-commons-runtime/3.0.12/istack-commons-runtime-3.0.12.jar
MD5: 1952bd76321f8580cfaa57e332a68287
SHA1: cbbe1a62b0cc6c85972e99d52aaee350153dc530
SHA256: 27d85fc134c9271d5c79d3300fc4669668f017e72409727c428f54f2417f04cd
Referenced In Project/Scope: Christmas:compile
istack-commons-runtime-3.0.12.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.7.6
Evidence Type Source Name Value Confidence Vendor file name istack-commons-runtime High Vendor jar package name com Highest Vendor jar package name istack Highest Vendor jar package name sun Highest Vendor jar (hint) package name oracle Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname com.sun.istack.commons-runtime Medium Vendor Manifest implementation-build-id 3.0.12 - 7ed1368 Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id com.sun.istack Medium Vendor Manifest multi-release true Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid istack-commons-runtime Highest Vendor pom artifactid istack-commons-runtime Low Vendor pom groupid com.sun.istack Highest Vendor pom name istack common utility code runtime High Vendor pom parent-artifactid istack-commons Low Product file name istack-commons-runtime High Product jar package name com Highest Product jar package name istack Highest Product jar package name sun Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name istack common utility code runtime Medium Product Manifest bundle-symbolicname com.sun.istack.commons-runtime Medium Product Manifest implementation-build-id 3.0.12 - 7ed1368 Low Product Manifest multi-release true Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid istack-commons-runtime Highest Product pom groupid com.sun.istack Highest Product pom name istack common utility code runtime High Product pom parent-artifactid istack-commons Medium Version file version 3.0.12 High Version Manifest Bundle-Version 3.0.12 High Version Manifest implementation-build-id 3.0.12 Low Version pom version 3.0.12 Highest
j2objc-annotations-1.3.jarDescription:
A set of annotations that provide additional information to the J2ObjC
translator to modify the result of translation.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/lib/jenkins/.m2/repository/com/google/j2objc/j2objc-annotations/1.3/j2objc-annotations-1.3.jar
MD5: 5fa4ec4ec0c5aa70af8a7d4922df1931
SHA1: ba035118bc8bac37d7eff77700720999acd9986d
SHA256: 21af30c92267bd6122c0e0b4d20cccb6641a37eaf956c6540ec471d584e64a7b
Referenced In Project/Scope: Christmas:compile
j2objc-annotations-1.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/FlasbyUtil@1.0.15-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name j2objc-annotations High Vendor jar package name annotations Highest Vendor jar package name annotations Low Vendor jar package name google Highest Vendor jar package name google Low Vendor jar package name j2objc Highest Vendor jar package name j2objc Low Vendor pom artifactid j2objc-annotations Highest Vendor pom artifactid j2objc-annotations Low Vendor pom groupid com.google.j2objc Highest Vendor pom name J2ObjC Annotations High Vendor pom url google/j2objc/ Highest Product file name j2objc-annotations High Product jar package name annotations Highest Product jar package name annotations Low Product jar package name google Highest Product jar package name j2objc Highest Product jar package name j2objc Low Product pom artifactid j2objc-annotations Highest Product pom groupid com.google.j2objc Highest Product pom name J2ObjC Annotations High Product pom url google/j2objc/ High Version file version 1.3 High Version pom version 1.3 Highest
jackson-core-2.14.1.jarDescription:
Core Jackson processing abstractions (aka Streaming API), implementation for JSON License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/lib/jenkins/.m2/repository/com/fasterxml/jackson/core/jackson-core/2.14.1/jackson-core-2.14.1.jar
MD5: f9604a5f31129cdb7db4bdec90111850
SHA1: 7a07bc535ccf0b7f6929c4d0f2ab9b294ef7c4a3
SHA256: 0114187e296b34c931c1bf9e5a84152b62bfab7d182f5623f3982dc2da35e526
Referenced In Project/Scope: Christmas:compile
jackson-core-2.14.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/christmas@1.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name jackson-core High Vendor jar package name base Highest Vendor jar package name core Highest Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor jar package name json Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor Manifest multi-release true Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-core Highest Vendor pom artifactid jackson-core Low Vendor pom groupid com.fasterxml.jackson.core Highest Vendor pom name Jackson-core High Vendor pom parent-artifactid jackson-base Low Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor pom url FasterXML/jackson-core Highest Product file name jackson-core High Product hint analyzer product java8 Highest Product hint analyzer product modules Highest Product jar package name base Highest Product jar package name core Highest Product jar package name fasterxml Highest Product jar package name filter Highest Product jar package name jackson Highest Product jar package name json Highest Product jar package name version Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low Product Manifest Bundle-Name Jackson-core Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Product Manifest Implementation-Title Jackson-core High Product Manifest multi-release true Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Jackson-core Medium Product pom artifactid jackson-core Highest Product pom groupid com.fasterxml.jackson.core Highest Product pom name Jackson-core High Product pom parent-artifactid jackson-base Medium Product pom parent-groupid com.fasterxml.jackson Medium Product pom url FasterXML/jackson-core High Version file version 2.14.1 High Version Manifest Bundle-Version 2.14.1 High Version Manifest Implementation-Version 2.14.1 High Version pom version 2.14.1 Highest
Related Dependencies jackson-annotations-2.14.1.jarFile Path: /var/lib/jenkins/.m2/repository/com/fasterxml/jackson/core/jackson-annotations/2.14.1/jackson-annotations-2.14.1.jar MD5: da4742ba6aeb24bf1bd29382fd95647b SHA1: 2a6ad504d591a7903ffdec76b5b7252819a2d162 SHA256: d255b4b863ff8ec714a8f96fa55c34621d43dbb82b82d3f57476496a4c09e1e7 pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.14.1 jackson-databind-2.14.1.jarDescription:
General data-binding functionality for Jackson: works on core streaming API License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/lib/jenkins/.m2/repository/com/fasterxml/jackson/core/jackson-databind/2.14.1/jackson-databind-2.14.1.jar
MD5: 3e3e7aab8799ccc169b10f244e6fb5b4
SHA1: 268524b9056cae1211b9f1f52560ef19347f4d17
SHA256: 423a0c806de4b3fa5eb4a28698305e3a3777c731e1bcfa1b2f3a3760c7b6e773
Referenced In Project/Scope: Christmas:compile
jackson-databind-2.14.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/christmas@1.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name jackson-databind High Vendor jar package name databind Highest Vendor jar package name fasterxml Highest Vendor jar package name jackson Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor Manifest multi-release true Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor FasterXML Low Vendor pom artifactid jackson-databind Highest Vendor pom artifactid jackson-databind Low Vendor pom groupid com.fasterxml.jackson.core Highest Vendor pom name jackson-databind High Vendor pom parent-artifactid jackson-base Low Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor pom url FasterXML/jackson Highest Product file name jackson-databind High Product hint analyzer product java8 Highest Product hint analyzer product modules Highest Product jar package name databind Highest Product jar package name fasterxml Highest Product jar package name jackson Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low Product Manifest Bundle-Name jackson-databind Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium Product Manifest Implementation-Title jackson-databind High Product Manifest multi-release true Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title jackson-databind Medium Product pom artifactid jackson-databind Highest Product pom groupid com.fasterxml.jackson.core Highest Product pom name jackson-databind High Product pom parent-artifactid jackson-base Medium Product pom parent-groupid com.fasterxml.jackson Medium Product pom url FasterXML/jackson High Version file version 2.14.1 High Version Manifest Bundle-Version 2.14.1 High Version Manifest Implementation-Version 2.14.1 High Version pom version 2.14.1 Highest
jakarta.activation-1.2.2.jarDescription:
Jakarta Activation License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /var/lib/jenkins/.m2/repository/com/sun/activation/jakarta.activation/1.2.2/jakarta.activation-1.2.2.jar
MD5: 0b8bee3bf29b9a015f8b992035581a7c
SHA1: 74548703f9851017ce2f556066659438019e7eb5
SHA256: 02156773e4ae9d048d14a56ad35d644bee9f1052a791d072df3ded3c656e6e1a
Referenced In Project/Scope: Christmas:runtime
jakarta.activation-1.2.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.7.6
Evidence Type Source Name Value Confidence Vendor file name jakarta.activation High Vendor jar package name activation Highest Vendor jar package name sun Highest Vendor jar (hint) package name oracle Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname com.sun.activation.jakarta.activation Medium Vendor Manifest extension-name jakarta.activation Medium Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id com.sun Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=9.0))" Low Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jakarta.activation Highest Vendor pom artifactid jakarta.activation Low Vendor pom groupid com.sun.activation Highest Vendor pom name Jakarta Activation High Vendor pom parent-artifactid all Low Product file name jakarta.activation High Product jar package name activation Highest Product jar package name javax Highest Product jar package name sun Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta Activation Medium Product Manifest bundle-symbolicname com.sun.activation.jakarta.activation Medium Product Manifest extension-name jakarta.activation Medium Product Manifest Implementation-Title javax.activation High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=9.0))" Low Product Manifest specification-title Jakarta Activation Specification Medium Product pom artifactid jakarta.activation Highest Product pom groupid com.sun.activation Highest Product pom name Jakarta Activation High Product pom parent-artifactid all Medium Version file version 1.2.2 High Version Manifest Bundle-Version 1.2.2 High Version Manifest Implementation-Version 1.2.2 High Version pom version 1.2.2 Highest
jakarta.activation-api-1.2.2.jarDescription:
Jakarta Activation API jar License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /var/lib/jenkins/.m2/repository/jakarta/activation/jakarta.activation-api/1.2.2/jakarta.activation-api-1.2.2.jar
MD5: 1cbb480310fa1987f9db7a3ed7118af7
SHA1: 99f53adba383cb1bf7c3862844488574b559621f
SHA256: a187a939103aef5849a7af84bd7e27be2d120c410af291437375ffe061f4f09d
Referenced In Project/Scope: Christmas:compile
jakarta.activation-api-1.2.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-test@2.7.6
Evidence Type Source Name Value Confidence Vendor file name jakarta.activation-api High Vendor jar package name activation Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.activation-api Medium Vendor Manifest extension-name jakarta.activation Medium Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id com.sun Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=9.0))" Low Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jakarta.activation-api Highest Vendor pom artifactid jakarta.activation-api Low Vendor pom groupid jakarta.activation Highest Vendor pom name Jakarta Activation API jar High Vendor pom parent-artifactid all Low Vendor pom parent-groupid com.sun.activation Medium Product file name jakarta.activation-api High Product jar package name activation Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta Activation API jar Medium Product Manifest bundle-symbolicname jakarta.activation-api Medium Product Manifest extension-name jakarta.activation Medium Product Manifest Implementation-Title jakarta.activation.jakarta.activation-api High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=9.0))" Low Product Manifest specification-title jakarta.activation.jakarta.activation-api Medium Product pom artifactid jakarta.activation-api Highest Product pom groupid jakarta.activation Highest Product pom name Jakarta Activation API jar High Product pom parent-artifactid all Medium Product pom parent-groupid com.sun.activation Medium Version file version 1.2.2 High Version Manifest Bundle-Version 1.2.2 High Version Manifest Implementation-Version 1.2.2 High Version pom version 1.2.2 Highest
jakarta.annotation-api-1.3.5.jarDescription:
Jakarta Annotations API License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html File Path: /var/lib/jenkins/.m2/repository/jakarta/annotation/jakarta.annotation-api/1.3.5/jakarta.annotation-api-1.3.5.jar
MD5: 8b165cf58df5f8c2a222f637c0a07c97
SHA1: 59eb84ee0d616332ff44aba065f3888cf002cd2d
SHA256: 85fb03fc054cdf4efca8efd9b6712bbb418e1ab98241c4539c8585bbc23e1b8a
Referenced In Project/Scope: Christmas:compile
jakarta.annotation-api-1.3.5.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-test@2.7.6
Evidence Type Source Name Value Confidence Vendor file name jakarta.annotation-api High Vendor jar package name annotation Highest Vendor Manifest automatic-module-name java.annotation Medium Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.annotation-api Medium Vendor Manifest extension-name jakarta.annotation Medium Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jakarta.annotation-api Highest Vendor pom artifactid jakarta.annotation-api Low Vendor pom developer name Linda De Michiel Medium Vendor pom developer org Oracle Corp. Medium Vendor pom groupid jakarta.annotation Highest Vendor pom name Jakarta Annotations API High Vendor pom parent-artifactid ca-parent Low Vendor pom url https://projects.eclipse.org/projects/ee4j.ca Highest Product file name jakarta.annotation-api High Product jar package name annotation Highest Product Manifest automatic-module-name java.annotation Medium Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta Annotations API Medium Product Manifest bundle-symbolicname jakarta.annotation-api Medium Product Manifest extension-name jakarta.annotation Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid jakarta.annotation-api Highest Product pom developer name Linda De Michiel Low Product pom developer org Oracle Corp. Low Product pom groupid jakarta.annotation Highest Product pom name Jakarta Annotations API High Product pom parent-artifactid ca-parent Medium Product pom url https://projects.eclipse.org/projects/ee4j.ca Medium Version file version 1.3.5 High Version Manifest Bundle-Version 1.3.5 High Version Manifest Implementation-Version 1.3.5 High Version pom version 1.3.5 Highest
jakarta.persistence-api-2.2.3.jarDescription:
Jakarta Persistence 2.2 API jar License:
Eclipse Public License v. 2.0: http://www.eclipse.org/legal/epl-2.0
Eclipse Distribution License v. 1.0: http://www.eclipse.org/org/documents/edl-v10.php File Path: /var/lib/jenkins/.m2/repository/jakarta/persistence/jakarta.persistence-api/2.2.3/jakarta.persistence-api-2.2.3.jar
MD5: e0a655f398f8e68e0afebb0f71fba4e5
SHA1: 8f6ea5daedc614f07a3654a455660145286f024e
SHA256: 0c2d73ab36ad24eeed6e0bea928e9d0ef771de8df689e23b7754d366dda27c53
Referenced In Project/Scope: Christmas:compile
jakarta.persistence-api-2.2.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.7.6
Evidence Type Source Name Value Confidence Vendor file name jakarta.persistence-api High Vendor jar package name persistence Highest Vendor Manifest automatic-module-name java.persistence Medium Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.persistence-api Medium Vendor Manifest extension-name jakarta.persistence Medium Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jakarta.persistence-api Highest Vendor pom artifactid jakarta.persistence-api Low Vendor pom developer id lukasj Medium Vendor pom developer name Lukas Jungmann Medium Vendor pom developer org Oracle, Inc. Medium Vendor pom groupid jakarta.persistence Highest Vendor pom name Jakarta Persistence API High Vendor pom parent-artifactid project Low Vendor pom parent-groupid org.eclipse.ee4j Medium Vendor pom url eclipse-ee4j/jpa-api Highest Product file name jakarta.persistence-api High Product jar package name persistence Highest Product Manifest automatic-module-name java.persistence Medium Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta Persistence API jar Medium Product Manifest bundle-symbolicname jakarta.persistence-api Medium Product Manifest extension-name jakarta.persistence Medium Product pom artifactid jakarta.persistence-api Highest Product pom developer id lukasj Low Product pom developer name Lukas Jungmann Low Product pom developer org Oracle, Inc. Low Product pom groupid jakarta.persistence Highest Product pom name Jakarta Persistence API High Product pom parent-artifactid project Medium Product pom parent-groupid org.eclipse.ee4j Medium Product pom url eclipse-ee4j/jpa-api High Version file version 2.2.3 High Version Manifest Bundle-Version 2.2.3 High Version Manifest Implementation-Version 2.2.3 High Version pom parent-version 2.2.3 Low Version pom version 2.2.3 Highest
jakarta.transaction-api-1.3.3.jarDescription:
Jakarta Transactions License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html File Path: /var/lib/jenkins/.m2/repository/jakarta/transaction/jakarta.transaction-api/1.3.3/jakarta.transaction-api-1.3.3.jar
MD5: cc45726045cc9a0728f803f9db4c90c4
SHA1: c4179d48720a1e87202115fbed6089bdc4195405
SHA256: 0b02a194dd04ee2e192dc9da9579e10955dd6e8ac707adfc91d92f119b0e67ab
Referenced In Project/Scope: Christmas:compile
jakarta.transaction-api-1.3.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.7.6
Evidence Type Source Name Value Confidence Vendor file name jakarta.transaction-api High Vendor jar package name javax Highest Vendor jar package name transaction Highest Vendor Manifest automatic-module-name java.transaction Medium Vendor Manifest bundle-docurl https://github.com/eclipse-ee4j Low Vendor Manifest bundle-symbolicname jakarta.transaction-api Medium Vendor Manifest extension-name javax.transaction Medium Vendor Manifest Implementation-Vendor EE4J Community High Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor Manifest specification-vendor Oracle Corporation Low Vendor pom artifactid jakarta.transaction-api Highest Vendor pom artifactid jakarta.transaction-api Low Vendor pom developer id stephen_felts Medium Vendor pom developer name Stephen Felts Medium Vendor pom developer org Oracle, Inc. Medium Vendor pom groupid jakarta.transaction Highest Vendor pom name ${extension.name} API High Vendor pom organization name EE4J Community High Vendor pom organization url eclipse-ee4j Medium Vendor pom parent-artifactid project Low Vendor pom parent-groupid org.eclipse.ee4j Medium Vendor pom url https://projects.eclipse.org/projects/ee4j.jta Highest Product file name jakarta.transaction-api High Product jar package name javax Highest Product jar package name transaction Highest Product Manifest automatic-module-name java.transaction Medium Product Manifest bundle-docurl https://github.com/eclipse-ee4j Low Product Manifest Bundle-Name javax.transaction API Medium Product Manifest bundle-symbolicname jakarta.transaction-api Medium Product Manifest extension-name javax.transaction Medium Product pom artifactid jakarta.transaction-api Highest Product pom developer id stephen_felts Low Product pom developer name Stephen Felts Low Product pom developer org Oracle, Inc. Low Product pom groupid jakarta.transaction Highest Product pom name ${extension.name} API High Product pom organization name EE4J Community Low Product pom parent-artifactid project Medium Product pom parent-groupid org.eclipse.ee4j Medium Product pom url eclipse-ee4j High Product pom url https://projects.eclipse.org/projects/ee4j.jta Medium Version file version 1.3.3 High Version Manifest Bundle-Version 1.3.3 High Version Manifest Implementation-Version 1.3.3 High Version pom parent-version 1.3.3 Low Version pom version 1.3.3 Highest
jakarta.xml.bind-api-2.3.3.jarDescription:
Jakarta XML Binding API 2.3 Design Specification License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /var/lib/jenkins/.m2/repository/jakarta/xml/bind/jakarta.xml.bind-api/2.3.3/jakarta.xml.bind-api-2.3.3.jar
MD5: 61286918ca0192e9f87d1358aef718dd
SHA1: 48e3b9cfc10752fba3521d6511f4165bea951801
SHA256: c04539f472e9a6dd0c7685ea82d677282269ab8e7baca2e14500e381e0c6cec5
Referenced In Project/Scope: Christmas:compile
jakarta.xml.bind-api-2.3.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-test@2.7.6
Evidence Type Source Name Value Confidence Vendor file name jakarta.xml.bind-api High Vendor jar package name bind Highest Vendor jar package name xml Highest Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.xml.bind-api Medium Vendor Manifest extension-name jakarta.xml.bind Medium Vendor Manifest implementation-build-id 2.3.3-RELEASE-fd06b2b Low Vendor Manifest multi-release true Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom artifactid jakarta.xml.bind-api Highest Vendor pom artifactid jakarta.xml.bind-api Low Vendor pom groupid jakarta.xml.bind Highest Vendor pom name Jakarta XML Binding API High Vendor pom parent-artifactid jakarta.xml.bind-api-parent Low Product file name jakarta.xml.bind-api High Product jar package name bind Highest Product jar package name xml Highest Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name Jakarta XML Binding API Medium Product Manifest bundle-symbolicname jakarta.xml.bind-api Medium Product Manifest extension-name jakarta.xml.bind Medium Product Manifest implementation-build-id 2.3.3-RELEASE-fd06b2b Low Product Manifest multi-release true Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid jakarta.xml.bind-api Highest Product pom groupid jakarta.xml.bind Highest Product pom name Jakarta XML Binding API High Product pom parent-artifactid jakarta.xml.bind-api-parent Medium Version file version 2.3.3 High Version Manifest Bundle-Version 2.3.3 High Version Manifest Implementation-Version 2.3.3 High Version pom version 2.3.3 Highest
jandex-2.4.2.Final.jarDescription:
Parent POM for JBoss projects. Provides default project build configuration. License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/lib/jenkins/.m2/repository/org/jboss/jandex/2.4.2.Final/jandex-2.4.2.Final.jar
MD5: 489f7a97d2ed7ae34ea56d01b3566d57
SHA1: 1e1c385990b258ff1a24c801e84aebbacf70eb39
SHA256: 3f2ce55c7d71e744581488dc5105806aa8084c08e6e916a019bab8f8698994f0
Referenced In Project/Scope: Christmas:compile
jandex-2.4.2.Final.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.7.6
Evidence Type Source Name Value Confidence Vendor file name jandex High Vendor hint analyzer vendor redhat Highest Vendor jar package name indexer Highest Vendor jar package name jandex Highest Vendor jar package name jboss Highest Vendor Manifest automatic-module-name org.jboss.jandex Medium Vendor Manifest build-timestamp ÄŒt, 6 Led 2022 17:31:47 +0100 Low Vendor Manifest bundle-docurl http://www.jboss.org Low Vendor Manifest bundle-symbolicname org.jboss.jandex Medium Vendor Manifest implementation-url http://www.jboss.org/jandex Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest Implementation-Vendor-Id org.jboss Medium Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor JBoss by Red Hat Low Vendor pom artifactid jandex Highest Vendor pom artifactid jandex Low Vendor pom groupid org.jboss Highest Vendor pom name Java Annotation Indexer High Vendor pom parent-artifactid jboss-parent Low Product file name jandex High Product jar package name indexer Highest Product jar package name jandex Highest Product jar package name jboss Highest Product Manifest automatic-module-name org.jboss.jandex Medium Product Manifest build-timestamp ÄŒt, 6 Led 2022 17:31:47 +0100 Low Product Manifest bundle-docurl http://www.jboss.org Low Product Manifest Bundle-Name Java Annotation Indexer Medium Product Manifest bundle-symbolicname org.jboss.jandex Medium Product Manifest Implementation-Title Java Annotation Indexer High Product Manifest implementation-url http://www.jboss.org/jandex Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest specification-title Java Annotation Indexer Medium Product pom artifactid jandex Highest Product pom groupid org.jboss Highest Product pom name Java Annotation Indexer High Product pom parent-artifactid jboss-parent Medium Version Manifest Bundle-Version 2.4.2.Final High Version Manifest Implementation-Version 2.4.2.Final High Version pom parent-version 2.4.2.Final Low Version pom version 2.4.2.Final Highest
javassist-3.20.0-GA.jarDescription:
Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation
simple. It is a class library for editing bytecodes in Java.
License:
MPL 1.1: http://www.mozilla.org/MPL/MPL-1.1.html
LGPL 2.1: http://www.gnu.org/licenses/lgpl-2.1.html
Apache License 2.0: http://www.apache.org/licenses/ File Path: /var/lib/jenkins/.m2/repository/org/javassist/javassist/3.20.0-GA/javassist-3.20.0-GA.jar
MD5: a89dd7907d76e061ec2c07e762a74256
SHA1: a9cbcdfb7e9f86fbc74d3afae65f2248bfbf82a0
SHA256: d7691062fb779c2381640c8f72acba2c23873b01c243866d41c15dc4c8848ea2
Referenced In Project/Scope: Christmas:compile
javassist-3.20.0-GA.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.thymeleaf/thymeleaf@3.0.14.RELEASE
Evidence Type Source Name Value Confidence Vendor file name javassist High Vendor jar package name bytecode Highest Vendor jar package name javassist Highest Vendor Manifest bundle-symbolicname javassist Medium Vendor Manifest specification-vendor Shigeru Chiba, www.javassist.org Low Vendor pom artifactid javassist Highest Vendor pom artifactid javassist Low Vendor pom developer email adinn@redhat.com Low Vendor pom developer email chiba@javassist.org Low Vendor pom developer email kabir.khan@jboss.com Low Vendor pom developer email smarlow@redhat.com Low Vendor pom developer id adinn Medium Vendor pom developer id chiba Medium Vendor pom developer id kabir.khan@jboss.com Medium Vendor pom developer id scottmarlow Medium Vendor pom developer name Andrew Dinn Medium Vendor pom developer name Kabir Khan Medium Vendor pom developer name Scott Marlow Medium Vendor pom developer name Shigeru Chiba Medium Vendor pom developer org JBoss Medium Vendor pom developer org The Javassist Project Medium Vendor pom developer org URL http://www.javassist.org/ Medium Vendor pom developer org URL http://www.jboss.org/ Medium Vendor pom groupid org.javassist Highest Vendor pom name Javassist High Vendor pom organization name Shigeru Chiba, www.javassist.org High Vendor pom url http://www.javassist.org/ Highest Product file name javassist High Product jar package name bytecode Highest Product jar package name javassist Highest Product Manifest Bundle-Name Javassist Medium Product Manifest bundle-symbolicname javassist Medium Product Manifest specification-title Javassist Medium Product pom artifactid javassist Highest Product pom developer email adinn@redhat.com Low Product pom developer email chiba@javassist.org Low Product pom developer email kabir.khan@jboss.com Low Product pom developer email smarlow@redhat.com Low Product pom developer id adinn Low Product pom developer id chiba Low Product pom developer id kabir.khan@jboss.com Low Product pom developer id scottmarlow Low Product pom developer name Andrew Dinn Low Product pom developer name Kabir Khan Low Product pom developer name Scott Marlow Low Product pom developer name Shigeru Chiba Low Product pom developer org JBoss Low Product pom developer org The Javassist Project Low Product pom developer org URL http://www.javassist.org/ Low Product pom developer org URL http://www.jboss.org/ Low Product pom groupid org.javassist Highest Product pom name Javassist High Product pom organization name Shigeru Chiba, www.javassist.org Low Product pom url http://www.javassist.org/ Medium Version Manifest specification-version 3.20.0-GA High Version pom version 3.20.0-GA Highest
javax.activation-api-1.2.0.jarDescription:
JavaBeans Activation Framework API jar License:
https://github.com/javaee/activation/blob/master/LICENSE.txt File Path: /var/lib/jenkins/.m2/repository/javax/activation/javax.activation-api/1.2.0/javax.activation-api-1.2.0.jar
MD5: 5e50e56bcf4a3ef3bc758f69f7643c3b
SHA1: 85262acf3ca9816f9537ca47d5adeabaead7cb16
SHA256: 43fdef0b5b6ceb31b0424b208b930c74ab58fac2ceeb7b3f6fd3aeb8b5ca4393
Referenced In Project/Scope: Christmas:compile
javax.activation-api-1.2.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/javax.xml.bind/jaxb-api@2.3.1
Evidence Type Source Name Value Confidence Vendor file name javax.activation-api High Vendor jar package name activation Highest Vendor jar package name javax Highest Vendor Manifest automatic-module-name java.activation Medium Vendor Manifest bundle-docurl http://www.oracle.com Low Vendor Manifest bundle-symbolicname javax.activation-api Medium Vendor Manifest extension-name javax.activation Medium Vendor Manifest Implementation-Vendor Oracle High Vendor Manifest Implementation-Vendor-Id com.sun Medium Vendor Manifest originally-created-by 1.8.0_141 (Oracle Corporation) Low Vendor Manifest specification-vendor Oracle Low Vendor Manifest (hint) Implementation-Vendor sun High Vendor Manifest (hint) specification-vendor sun Low Vendor pom artifactid javax.activation-api Highest Vendor pom artifactid javax.activation-api Low Vendor pom groupid javax.activation Highest Vendor pom name JavaBeans Activation Framework API jar High Vendor pom parent-artifactid all Low Vendor pom parent-groupid com.sun.activation Medium Product file name javax.activation-api High Product jar package name activation Highest Product jar package name javax Highest Product Manifest automatic-module-name java.activation Medium Product Manifest bundle-docurl http://www.oracle.com Low Product Manifest Bundle-Name JavaBeans Activation Framework API jar Medium Product Manifest bundle-symbolicname javax.activation-api Medium Product Manifest extension-name javax.activation Medium Product Manifest Implementation-Title javax.activation.javax.activation-api High Product Manifest originally-created-by 1.8.0_141 (Oracle Corporation) Low Product Manifest specification-title javax.activation.javax.activation-api Medium Product pom artifactid javax.activation-api Highest Product pom groupid javax.activation Highest Product pom name JavaBeans Activation Framework API jar High Product pom parent-artifactid all Medium Product pom parent-groupid com.sun.activation Medium Version file version 1.2.0 High Version Manifest Bundle-Version 1.2.0 High Version Manifest Implementation-Version 1.2.0 High Version pom version 1.2.0 Highest
javax.jms-api-2.0.1.jarDescription:
Java(TM) Message Service Specification License:
CDDL + GPLv2 with classpath exception: https://glassfish.java.net/nonav/public/CDDL+GPL_1_1.html File Path: /var/lib/jenkins/.m2/repository/javax/jms/javax.jms-api/2.0.1/javax.jms-api-2.0.1.jar
MD5: d69d2e02910e97b2478c0105e9b2caab
SHA1: 5faaa3864ff6025ce69809b60d65bda3e358610c
SHA256: aa4a16fac46d949b17b32091036e4d1e3c812ef3b4bd184ec838efffb53ba4f8
Referenced In Project/Scope: Christmas:compile
javax.jms-api-2.0.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/christmas@1.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name javax.jms-api High Vendor jar package name javax Highest Vendor jar package name jms Highest Vendor Manifest bundle-symbolicname javax.jms-api Medium Vendor Manifest extension-name javax.jms Medium Vendor Manifest Implementation-Vendor-Id org.glassfish.mq Medium Vendor Manifest specification-vendor Oracle Corporation Low Vendor pom artifactid javax.jms-api Highest Vendor pom artifactid javax.jms-api Low Vendor pom developer org Oracle Corporation Medium Vendor pom groupid javax.jms Highest Vendor pom name JMS API High Vendor pom parent-artifactid jvnet-parent Low Vendor pom parent-groupid net.java Medium Vendor pom url http://java.net/projects/jms-spec/pages/Home Highest Product file name javax.jms-api High Product jar package name javax Highest Product jar package name jms Highest Product jar package name message Highest Product Manifest Bundle-Name JMS API Medium Product Manifest bundle-symbolicname javax.jms-api Medium Product Manifest extension-name javax.jms Medium Product pom artifactid javax.jms-api Highest Product pom developer org Oracle Corporation Low Product pom groupid javax.jms Highest Product pom name JMS API High Product pom parent-artifactid jvnet-parent Medium Product pom parent-groupid net.java Medium Product pom url http://java.net/projects/jms-spec/pages/Home Medium Version file version 2.0.1 High Version Manifest Bundle-Version 2.0.1 High Version Manifest Implementation-Version 2.0.1 High Version pom parent-version 2.0.1 Low Version pom version 2.0.1 Highest
javax.persistence-api-2.2.jarDescription:
Java(TM) Persistence API License:
Eclipse Public License v1.0: http://www.eclipse.org/legal/epl-v10.html
Eclipse Distribution License v. 1.0: http://www.eclipse.org/org/documents/edl-v10.php File Path: /var/lib/jenkins/.m2/repository/javax/persistence/javax.persistence-api/2.2/javax.persistence-api-2.2.jar
MD5: e6520b3435f5b6d58eee415b5542abf8
SHA1: 25665ac8c0b62f50e6488173233239120fc52c96
SHA256: 5578b71b37999a5eaed3fea0d14aa61c60c6ec6328256f2b63472f336318baf4
Referenced In Project/Scope: Christmas:compile
javax.persistence-api-2.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/christmas@1.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name javax.persistence-api High Vendor jar package name javax Highest Vendor jar package name persistence Highest Vendor Manifest automatic-module-name java.persistence Medium Vendor Manifest bundle-symbolicname javax.persistence-api Medium Vendor Manifest extension-name javax.persistence Medium Vendor Manifest Implementation-Vendor-Id com.oracle Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor Oracle Corporation Low Vendor pom artifactid javax.persistence-api Highest Vendor pom artifactid javax.persistence-api Low Vendor pom groupid javax.persistence Highest Vendor pom parent-artifactid jvnet-parent Low Vendor pom parent-groupid net.java Medium Vendor pom url javaee/jpa-spec Highest Product file name javax.persistence-api High Product jar package name javax Highest Product jar package name persistence Highest Product jar package name version Highest Product Manifest automatic-module-name java.persistence Medium Product Manifest Bundle-Name Java(TM) Persistence API jar Medium Product Manifest bundle-symbolicname javax.persistence-api Medium Product Manifest extension-name javax.persistence Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid javax.persistence-api Highest Product pom groupid javax.persistence Highest Product pom parent-artifactid jvnet-parent Medium Product pom parent-groupid net.java Medium Product pom url javaee/jpa-spec High Version file version 2.2 High Version Manifest Bundle-Version 2.2 High Version Manifest Implementation-Version 2.2 High Version pom parent-version 2.2 Low Version pom version 2.2 Highest
jaxb-api-2.3.1.jarDescription:
JAXB (JSR 222) API License:
https://oss.oracle.com/licenses/CDDL+GPL-1.1, https://oss.oracle.com/licenses/CDDL+GPL-1.1 File Path: /var/lib/jenkins/.m2/repository/javax/xml/bind/jaxb-api/2.3.1/jaxb-api-2.3.1.jar
MD5: bcf270d320f645ad19f5edb60091e87f
SHA1: 8531ad5ac454cc2deb9d4d32c40c4d7451939b5d
SHA256: 88b955a0df57880a26a74708bc34f74dcaf8ebf4e78843a28b50eae945732b06
Referenced In Project/Scope: Christmas:compile
jaxb-api-2.3.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/christmas@1.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name jaxb-api High Vendor jar package name bind Highest Vendor jar package name javax Highest Vendor jar package name jaxb Highest Vendor jar package name xml Highest Vendor Manifest bundle-docurl http://www.oracle.com/ Low Vendor Manifest bundle-symbolicname jaxb-api Medium Vendor Manifest extension-name javax.xml.bind Medium Vendor Manifest implementation-build-id UNKNOWN-7de2ca118a0cfc4a373872915aef59148dff5f93, 2018-09-12T06:28:43-0700 Low Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor Manifest multi-release true Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version>=1.8))" Low Vendor Manifest specification-vendor Oracle Corporation Low Vendor pom artifactid jaxb-api Highest Vendor pom artifactid jaxb-api Low Vendor pom groupid javax.xml.bind Highest Vendor pom parent-artifactid jaxb-api-parent Low Product file name jaxb-api High Product jar package name bind Highest Product jar package name javax Highest Product jar package name jaxb Highest Product jar package name xml Highest Product Manifest bundle-docurl http://www.oracle.com/ Low Product Manifest Bundle-Name jaxb-api Medium Product Manifest bundle-symbolicname jaxb-api Medium Product Manifest extension-name javax.xml.bind Medium Product Manifest implementation-build-id UNKNOWN-7de2ca118a0cfc4a373872915aef59148dff5f93, 2018-09-12T06:28:43-0700 Low Product Manifest multi-release true Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version>=1.8))" Low Product Manifest specification-title jaxb-api Medium Product pom artifactid jaxb-api Highest Product pom groupid javax.xml.bind Highest Product pom parent-artifactid jaxb-api-parent Medium Version file version 2.3.1 High Version Manifest Bundle-Version 2.3.1 High Version pom version 2.3.1 Highest
jaxb-runtime-2.3.7.jarDescription:
JAXB (JSR 222) Reference Implementation License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /var/lib/jenkins/.m2/repository/org/glassfish/jaxb/jaxb-runtime/2.3.7/jaxb-runtime-2.3.7.jar
MD5: 4fb00614ad222cfdfc2204ceae827fb5
SHA1: ebcde6a44159eb9e3db721dfe6b45f26e6272341
SHA256: c048d9edde5d5d67bca4f66921ef1315b8e20b1a978b757d54cea0ea5ce1c907
Referenced In Project/Scope: Christmas:compile
jaxb-runtime-2.3.7.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.7.6
Evidence Type Source Name Value Confidence Vendor file name jaxb-runtime High Vendor jar package name bind Highest Vendor jar package name com Highest Vendor jar package name sun Highest Vendor jar package name xml Highest Vendor jar (hint) package name oracle Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname org.glassfish.jaxb.runtime Medium Vendor Manifest git-revision cb2da3e Low Vendor Manifest implementation-build-id 2.3.7 - cb2da3e Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id org.glassfish.jaxb Medium Vendor Manifest multi-release true Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid jaxb-runtime Highest Vendor pom artifactid jaxb-runtime Low Vendor pom groupid org.glassfish.jaxb Highest Vendor pom name JAXB Runtime High Vendor pom parent-artifactid jaxb-runtime-parent Low Vendor pom parent-groupid com.sun.xml.bind.mvn Medium Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest Product file name jaxb-runtime High Product jar package name bind Highest Product jar package name com Highest Product jar package name sun Highest Product jar package name xml Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest Bundle-Name JAXB Runtime Medium Product Manifest bundle-symbolicname org.glassfish.jaxb.runtime Medium Product Manifest git-revision cb2da3e Low Product Manifest implementation-build-id 2.3.7 - cb2da3e Low Product Manifest Implementation-Title Jakarta XML Binding Implementation High Product Manifest multi-release true Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Jakarta XML Binding Medium Product pom artifactid jaxb-runtime Highest Product pom groupid org.glassfish.jaxb Highest Product pom name JAXB Runtime High Product pom parent-artifactid jaxb-runtime-parent Medium Product pom parent-groupid com.sun.xml.bind.mvn Medium Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium Version file version 2.3.7 High Version Manifest build-id 2.3.7 Medium Version Manifest Bundle-Version 2.3.7 High Version Manifest implementation-build-id 2.3.7 Low Version Manifest Implementation-Version 2.3.7 High Version Manifest major-version 2.3.7 Medium Version pom version 2.3.7 Highest
jbcrypt-0.4.jarDescription:
OpenBSD-style Blowfish password hashing for Java License:
ISC: https://opensource.org/licenses/isc-license File Path: /var/lib/jenkins/.m2/repository/org/mindrot/jbcrypt/0.4/jbcrypt-0.4.jar
MD5: d2b39d874e0d512f85386a72b0083682
SHA1: af7e61017f73abb18ac4e036954f9f28c6366c07
SHA256: e183f6f59404fc1e12073cfea4ace7ea103c900463cd21fb609a7c617ecdf624
Referenced In Project/Scope: Christmas:compile
jbcrypt-0.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/FlasbyUtil@1.0.15-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name jbcrypt High Vendor jar package name jbcrypt Highest Vendor jar package name jbcrypt Low Vendor jar package name mindrot Highest Vendor jar package name mindrot Low Vendor pom artifactid jbcrypt Highest Vendor pom artifactid jbcrypt Low Vendor pom developer email djm@mindrot.org Low Vendor pom developer name Damien Miller Medium Vendor pom developer org Mindrot.org Medium Vendor pom developer org URL http://www.mindrot.org Medium Vendor pom groupid org.mindrot Highest Vendor pom name jBCrypt High Vendor pom url djmdjm/jBCrypt Highest Product file name jbcrypt High Product jar package name bcrypt Low Product jar package name jbcrypt Highest Product jar package name jbcrypt Low Product jar package name mindrot Highest Product pom artifactid jbcrypt Highest Product pom developer email djm@mindrot.org Low Product pom developer name Damien Miller Low Product pom developer org Mindrot.org Low Product pom developer org URL http://www.mindrot.org Low Product pom groupid org.mindrot Highest Product pom name jBCrypt High Product pom url djmdjm/jBCrypt High Version file version 0.4 High Version pom version 0.4 Highest
jboss-logging-3.4.3.Final.jarDescription:
The JBoss Logging Framework License:
Apache License, version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/lib/jenkins/.m2/repository/org/jboss/logging/jboss-logging/3.4.3.Final/jboss-logging-3.4.3.Final.jar
MD5: b298d4b79e591843c1eb1458ea79f070
SHA1: c4bd7e12a745c0e7f6cf98c45cdcdf482fd827ea
SHA256: 0b324cca4d550060e51e70cc0045a6cce62f264278ec1f5082aafeb670fcac49
Referenced In Project/Scope: Christmas:compile
jboss-logging-3.4.3.Final.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.7.6
Evidence Type Source Name Value Confidence Vendor file name jboss-logging High Vendor hint analyzer vendor redhat Highest Vendor jar package name jboss Highest Vendor jar package name logging Highest Vendor Manifest automatic-module-name org.jboss.logging Medium Vendor Manifest build-jdk-spec 11 Low Vendor Manifest bundle-docurl http://www.jboss.org Low Vendor Manifest bundle-symbolicname org.jboss.logging.jboss-logging Medium Vendor Manifest implementation-url http://www.jboss.org Low Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest os-arch amd64 Low Vendor Manifest os-name Linux Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor JBoss by Red Hat Low Vendor pom artifactid jboss-logging Highest Vendor pom artifactid jboss-logging Low Vendor pom groupid org.jboss.logging Highest Vendor pom name JBoss Logging 3 High Vendor pom parent-artifactid jboss-parent Low Vendor pom parent-groupid org.jboss Medium Vendor pom url http://www.jboss.org Highest Product file name jboss-logging High Product jar package name jboss Highest Product jar package name logging Highest Product Manifest automatic-module-name org.jboss.logging Medium Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl http://www.jboss.org Low Product Manifest Bundle-Name JBoss Logging 3 Medium Product Manifest bundle-symbolicname org.jboss.logging.jboss-logging Medium Product Manifest Implementation-Title JBoss Logging 3 High Product Manifest implementation-url http://www.jboss.org Low Product Manifest os-arch amd64 Low Product Manifest os-name Linux Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title JBoss Logging 3 Medium Product pom artifactid jboss-logging Highest Product pom groupid org.jboss.logging Highest Product pom name JBoss Logging 3 High Product pom parent-artifactid jboss-parent Medium Product pom parent-groupid org.jboss Medium Product pom url http://www.jboss.org Medium Version Manifest Bundle-Version 3.4.3.Final High Version Manifest Implementation-Version 3.4.3.Final High Version pom parent-version 3.4.3.Final Low Version pom version 3.4.3.Final Highest
jquery-3.6.1.jarDescription:
WebJar for jQuery License:
MIT License: https://github.com/jquery/jquery/blob/master/MIT-LICENSE.txt File Path: /var/lib/jenkins/.m2/repository/org/webjars/jquery/3.6.1/jquery-3.6.1.jar
MD5: da81e8f13bfc953d51a79fc035efe721
SHA1: d08df6250157cd2db3d9b01b11b76e9b7225083a
SHA256: da2381fbee4799631ba44d1f4d6487b886b22450c7fc85842c5fdfa03429b817
Referenced In Project/Scope: Christmas:compile
jquery-3.6.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/christmas@1.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name jquery High Vendor pom artifactid jquery Highest Vendor pom artifactid jquery Low Vendor pom developer email james@jamesward.org Low Vendor pom developer id jamesward Medium Vendor pom developer name James Ward Medium Vendor pom groupid org.webjars Highest Vendor pom name jquery High Vendor pom url http://webjars.org Highest Product file name jquery High Product pom artifactid jquery Highest Product pom developer email james@jamesward.org Low Product pom developer id jamesward Low Product pom developer name James Ward Low Product pom groupid org.webjars Highest Product pom name jquery High Product pom url http://webjars.org Medium Version file version 3.6.1 High Version pom version 3.6.1 Highest
jquery-3.6.1.jar: jquery.jsFile Path: /var/lib/jenkins/.m2/repository/org/webjars/jquery/3.6.1/jquery-3.6.1.jar/META-INF/resources/webjars/jquery/3.6.1/jquery.jsMD5: 7e26506326a182c4175e54acda7ef15eSHA1: 01ee1a965e756292430031c46f258d6e2d3a961dSHA256: df3941e6cdaec28533ad72b7053ec05f7172be88ecada345c42736bc2ffba4d2Referenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
jquery-3.6.1.jar: jquery.min.jsFile Path: /var/lib/jenkins/.m2/repository/org/webjars/jquery/3.6.1/jquery-3.6.1.jar/META-INF/resources/webjars/jquery/3.6.1/jquery.min.jsMD5: 00727d1d5d9c90f7de826f1a4a9cc632SHA1: ea61688671d0c3044f2c5b2f2c4af0a6620ac6c2SHA256: a3cf00c109d907e543bc4f6dbc85eb31068f94515251347e9e57509b52ee3d74Referenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
jquery-3.6.1.jar: jquery.slim.jsFile Path: /var/lib/jenkins/.m2/repository/org/webjars/jquery/3.6.1/jquery-3.6.1.jar/META-INF/resources/webjars/jquery/3.6.1/jquery.slim.jsMD5: 047263837daa9552f4cf919d22be3b3dSHA1: 78b5bad67fe75cce3842287ffd497b1f8e3ad89cSHA256: b579beb1ad6ecec6c59db5edf0626ab208b64f0fa6e012c60e87fa7943e36ed9Referenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
jquery-3.6.1.jar: jquery.slim.min.jsFile Path: /var/lib/jenkins/.m2/repository/org/webjars/jquery/3.6.1/jquery-3.6.1.jar/META-INF/resources/webjars/jquery/3.6.1/jquery.slim.min.jsMD5: 6bb2d76bc531993f8368cef389e88b04SHA1: 50504dd95e37488eb9871bee661c588f84e04c9cSHA256: c3c0af845b3b88735552d9d23f460a120d34a7d221d77ae52fdcc6aaf2dd78f0Referenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
jquery-3.6.1.jar: webjars-requirejs.jsFile Path: /var/lib/jenkins/.m2/repository/org/webjars/jquery/3.6.1/jquery-3.6.1.jar/META-INF/resources/webjars/jquery/3.6.1/webjars-requirejs.jsMD5: 30e1a7f167b667001f50e32ea87bf7b5SHA1: d18dc733350ad3549af2df096599e824c10f777eSHA256: daca7b23bc4d8302a8961373b92b78d36d5c85d730fc14130e29d55d976aa420Referenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
jsr305-3.0.2.jarDescription:
JSR305 Annotations for Findbugs License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/lib/jenkins/.m2/repository/com/google/code/findbugs/jsr305/3.0.2/jsr305-3.0.2.jar
MD5: dd83accb899363c32b07d7a1b2e4ce40
SHA1: 25ea2e8b0c338a877313bd4672d3fe056ea78f0d
SHA256: 766ad2a0783f2687962c8ad74ceecc38a28b9f72a2d085ee438b7813e928d0c7
Referenced In Project/Scope: Christmas:compile
jsr305-3.0.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/FlasbyUtil@1.0.15-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name jsr305 High Vendor Manifest bundle-symbolicname org.jsr-305 Medium Vendor pom artifactid jsr305 Highest Vendor pom artifactid jsr305 Low Vendor pom groupid com.google.code.findbugs Highest Vendor pom name FindBugs-jsr305 High Vendor pom url http://findbugs.sourceforge.net/ Highest Product file name jsr305 High Product Manifest Bundle-Name FindBugs-jsr305 Medium Product Manifest bundle-symbolicname org.jsr-305 Medium Product pom artifactid jsr305 Highest Product pom groupid com.google.code.findbugs Highest Product pom name FindBugs-jsr305 High Product pom url http://findbugs.sourceforge.net/ Medium Version file version 3.0.2 High Version Manifest Bundle-Version 3.0.2 High Version pom version 3.0.2 Highest
jul-to-slf4j-1.7.36.jarDescription:
JUL to SLF4J bridge File Path: /var/lib/jenkins/.m2/repository/org/slf4j/jul-to-slf4j/1.7.36/jul-to-slf4j-1.7.36.jarMD5: 2a3fe73e6cafe8f102facaf2dd65353fSHA1: ed46d81cef9c412a88caef405b58f93a678ff2caSHA256: 9e641fb142c5f0b0623d6222c09ea87523a41bf6bed48ac79940724010b989deReferenced In Project/Scope: Christmas:compilejul-to-slf4j-1.7.36.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-log4j2@2.7.6
Evidence Type Source Name Value Confidence Vendor file name jul-to-slf4j High Vendor jar package name bridge Highest Vendor jar package name slf4j Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname jul.to.slf4j Medium Vendor pom artifactid jul-to-slf4j Highest Vendor pom artifactid jul-to-slf4j Low Vendor pom groupid org.slf4j Highest Vendor pom name JUL to SLF4J bridge High Vendor pom parent-artifactid slf4j-parent Low Vendor pom url http://www.slf4j.org Highest Product file name jul-to-slf4j High Product jar package name bridge Highest Product jar package name slf4j Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Bundle-Name jul-to-slf4j Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname jul.to.slf4j Medium Product pom artifactid jul-to-slf4j Highest Product pom groupid org.slf4j Highest Product pom name JUL to SLF4J bridge High Product pom parent-artifactid slf4j-parent Medium Product pom url http://www.slf4j.org Medium Version file version 1.7.36 High Version Manifest Bundle-Version 1.7.36 High Version Manifest Implementation-Version 1.7.36 High Version pom version 1.7.36 Highest
listenablefuture-9999.0-empty-to-avoid-conflict-with-guava.jarDescription:
An empty artifact that Guava depends on to signal that it is providing
ListenableFuture -- but is also available in a second "version" that
contains com.google.common.util.concurrent.ListenableFuture class, without
any other Guava classes. The idea is:
- If users want only ListenableFuture, they depend on listenablefuture-1.0.
- If users want all of Guava, they depend on guava, which, as of Guava
27.0, depends on
listenablefuture-9999.0-empty-to-avoid-conflict-with-guava. The 9999.0-...
version number is enough for some build systems (notably, Gradle) to select
that empty artifact over the "real" listenablefuture-1.0 -- avoiding a
conflict with the copy of ListenableFuture in guava itself. If users are
using an older version of Guava or a build system other than Gradle, they
may see class conflicts. If so, they can solve them by manually excluding
the listenablefuture artifact or manually forcing their build systems to
use 9999.0-....
File Path: /var/lib/jenkins/.m2/repository/com/google/guava/listenablefuture/9999.0-empty-to-avoid-conflict-with-guava/listenablefuture-9999.0-empty-to-avoid-conflict-with-guava.jarMD5: d094c22570d65e132c19cea5d352e381SHA1: b421526c5f297295adef1c886e5246c39d4ac629SHA256: b372a037d4230aa57fbeffdef30fd6123f9c0c2db85d0aced00c91b974f33f99Referenced In Project/Scope: Christmas:compilelistenablefuture-9999.0-empty-to-avoid-conflict-with-guava.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/FlasbyUtil@1.0.15-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name listenablefuture High Vendor pom artifactid listenablefuture Highest Vendor pom artifactid listenablefuture Low Vendor pom groupid com.google.guava Highest Vendor pom name Guava ListenableFuture only High Vendor pom parent-artifactid guava-parent Low Product file name listenablefuture High Product pom artifactid listenablefuture Highest Product pom groupid com.google.guava Highest Product pom name Guava ListenableFuture only High Product pom parent-artifactid guava-parent Medium Version pom parent-version 9999.0-empty-to-avoid-conflict-with-guava Low Version pom version 9999.0-empty-to-avoid-conflict-with-guava Highest
log4j-core-2.17.2.jarDescription:
The Apache Log4j Implementation License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/lib/jenkins/.m2/repository/org/apache/logging/log4j/log4j-core/2.17.2/log4j-core-2.17.2.jar
MD5: b35d06ffd3ea52e5ba9efe455108745c
SHA1: fa43ba4467f5300b16d1e0742934149bfc5ac564
SHA256: 5adb34ff4197cd16a8d24f63035856a933cb59562a6888dde86e9450fcfef646
Referenced In Project/Scope: Christmas:compile
log4j-core-2.17.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/FlasbyUtil@1.0.15-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name log4j-core High Vendor jar package name apache Highest Vendor jar package name core Highest Vendor jar package name log4j Highest Vendor jar package name logging Highest Vendor jar package name org Highest Vendor Manifest automatic-module-name org.apache.logging.log4j.core Medium Vendor Manifest bundle-docurl https://www.apache.org/ Low Vendor Manifest bundle-symbolicname org.apache.logging.log4j.core Medium Vendor Manifest implementation-url https://logging.apache.org/log4j/2.x/log4j-core/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.logging.log4j Medium Vendor Manifest log4jreleasekey B3D8E1BA Low Vendor Manifest log4jreleasemanager Ralph Goers Low Vendor Manifest log4jsigningusername rgoers@apache.org Medium Vendor Manifest multi-release true Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid log4j-core Highest Vendor pom artifactid log4j-core Low Vendor pom groupid org.apache.logging.log4j Highest Vendor pom name Apache Log4j Core High Vendor pom parent-artifactid log4j Low Product file name log4j-core High Product jar package name apache Highest Product jar package name core Highest Product jar package name log4j Highest Product jar package name logging Highest Product jar package name org Highest Product Manifest automatic-module-name org.apache.logging.log4j.core Medium Product Manifest bundle-docurl https://www.apache.org/ Low Product Manifest Bundle-Name Apache Log4j Core Medium Product Manifest bundle-symbolicname org.apache.logging.log4j.core Medium Product Manifest Implementation-Title Apache Log4j Core High Product Manifest implementation-url https://logging.apache.org/log4j/2.x/log4j-core/ Low Product Manifest log4jreleasekey B3D8E1BA Low Product Manifest log4jreleasemanager Ralph Goers Low Product Manifest log4jsigningusername rgoers@apache.org Medium Product Manifest multi-release true Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Apache Log4j Core Medium Product pom artifactid log4j-core Highest Product pom groupid org.apache.logging.log4j Highest Product pom name Apache Log4j Core High Product pom parent-artifactid log4j Medium Version file version 2.17.2 High Version Manifest Bundle-Version 2.17.2 High Version Manifest Implementation-Version 2.17.2 High Version Manifest log4jreleaseversion 2.17.2 Medium Version pom version 2.17.2 Highest
Related Dependencies log4j-api-2.17.2.jarFile Path: /var/lib/jenkins/.m2/repository/org/apache/logging/log4j/log4j-api/2.17.2/log4j-api-2.17.2.jar MD5: 0c39d90e7819c92c111e447bdf786a90 SHA1: f42d6afa111b4dec5d2aea0fe2197240749a4ea6 SHA256: 09351b5a03828f369cdcff76f4ed39e6a6fc20f24f046935d0b28ef5152f8ce4 pkg:maven/org.apache.logging.log4j/log4j-api@2.17.2 log4j-jul-2.17.2.jarFile Path: /var/lib/jenkins/.m2/repository/org/apache/logging/log4j/log4j-jul/2.17.2/log4j-jul-2.17.2.jar MD5: 233c257087bd9f421278bfeeb4a3b323 SHA1: 6a479ffc13d5f0ca3df8117ed57419fc5d06de7f SHA256: cec8d204efa87dfc759faf43d6affde1d18fa25b7c6d98ea5ef0737a56ff195c pkg:maven/org.apache.logging.log4j/log4j-jul@2.17.2 log4j-slf4j-impl-2.17.2.jarDescription:
The Apache Log4j SLF4J API binding to Log4j 2 Core License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/lib/jenkins/.m2/repository/org/apache/logging/log4j/log4j-slf4j-impl/2.17.2/log4j-slf4j-impl-2.17.2.jar
MD5: fe52fcd1f4027ab9a12bed89acdbf109
SHA1: 0183f7c95fc981f3e97d008b363341343508848e
SHA256: 77912d47190a5d25d583728e048496a92a2cb32308b71d3439931d7719996637
Referenced In Project/Scope: Christmas:compile
log4j-slf4j-impl-2.17.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-log4j2@2.7.6
Evidence Type Source Name Value Confidence Vendor file name log4j-slf4j-impl High Vendor jar package name apache Highest Vendor jar package name impl Highest Vendor jar package name logging Highest Vendor jar package name slf4j Highest Vendor Manifest automatic-module-name org.apache.logging.log4j.slf4j Medium Vendor Manifest bundle-docurl https://www.apache.org/ Low Vendor Manifest bundle-symbolicname org.apache.logging.log4j.slf4j-impl Medium Vendor Manifest implementation-url https://logging.apache.org/log4j/2.x/log4j-slf4j-impl/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.logging.log4j Medium Vendor Manifest log4jreleasekey B3D8E1BA Low Vendor Manifest log4jreleasemanager Ralph Goers Low Vendor Manifest log4jsigningusername rgoers@apache.org Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid log4j-slf4j-impl Highest Vendor pom artifactid log4j-slf4j-impl Low Vendor pom groupid org.apache.logging.log4j Highest Vendor pom name Apache Log4j SLF4J Binding High Vendor pom parent-artifactid log4j Low Product file name log4j-slf4j-impl High Product jar package name apache Highest Product jar package name impl Highest Product jar package name logging Highest Product jar package name slf4j Highest Product Manifest automatic-module-name org.apache.logging.log4j.slf4j Medium Product Manifest bundle-docurl https://www.apache.org/ Low Product Manifest Bundle-Name Apache Log4j SLF4J Binding Medium Product Manifest bundle-symbolicname org.apache.logging.log4j.slf4j-impl Medium Product Manifest Implementation-Title Apache Log4j SLF4J Binding High Product Manifest implementation-url https://logging.apache.org/log4j/2.x/log4j-slf4j-impl/ Low Product Manifest log4jreleasekey B3D8E1BA Low Product Manifest log4jreleasemanager Ralph Goers Low Product Manifest log4jsigningusername rgoers@apache.org Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Apache Log4j SLF4J Binding Medium Product pom artifactid log4j-slf4j-impl Highest Product pom groupid org.apache.logging.log4j Highest Product pom name Apache Log4j SLF4J Binding High Product pom parent-artifactid log4j Medium Version file version 2.17.2 High Version Manifest Bundle-Version 2.17.2 High Version Manifest Implementation-Version 2.17.2 High Version Manifest log4jreleaseversion 2.17.2 Medium Version pom version 2.17.2 Highest
log4j-to-slf4j-2.17.2.jarDescription:
The Apache Log4j binding between Log4j 2 API and SLF4J. License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/lib/jenkins/.m2/repository/org/apache/logging/log4j/log4j-to-slf4j/2.17.2/log4j-to-slf4j-2.17.2.jar
MD5: 14b27a4266c6d71c949cb4591ee463cc
SHA1: 17dd0fae2747d9a28c67bc9534108823d2376b46
SHA256: 9bcfa5273527b950d79739d11e8f8080cfc881908fa2a946b4e891c0293094de
Referenced In Project/Scope: Christmas:compile
log4j-to-slf4j-2.17.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-test@2.7.6
Evidence Type Source Name Value Confidence Vendor file name log4j-to-slf4j High Vendor jar package name apache Highest Vendor jar package name logging Highest Vendor jar package name slf4j Highest Vendor Manifest automatic-module-name org.apache.logging.slf4j Medium Vendor Manifest bundle-docurl https://www.apache.org/ Low Vendor Manifest bundle-symbolicname org.apache.logging.log4j.to-slf4j Medium Vendor Manifest implementation-url https://logging.apache.org/log4j/2.x/log4j-to-slf4j/ Low Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.logging.log4j Medium Vendor Manifest log4jreleasekey B3D8E1BA Low Vendor Manifest log4jreleasemanager Ralph Goers Low Vendor Manifest log4jsigningusername rgoers@apache.org Medium Vendor Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.apache.logging.log4j.spi.Provider" Low Vendor Manifest require-capability osgi.extender;filter:="(osgi.extender=osgi.serviceloader.registrar)",osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid log4j-to-slf4j Highest Vendor pom artifactid log4j-to-slf4j Low Vendor pom groupid org.apache.logging.log4j Highest Vendor pom name Apache Log4j to SLF4J Adapter High Vendor pom parent-artifactid log4j Low Product file name log4j-to-slf4j High Product jar package name apache Highest Product jar package name logging Highest Product jar package name slf4j Highest Product Manifest automatic-module-name org.apache.logging.slf4j Medium Product Manifest bundle-docurl https://www.apache.org/ Low Product Manifest Bundle-Name Apache Log4j to SLF4J Adapter Medium Product Manifest bundle-symbolicname org.apache.logging.log4j.to-slf4j Medium Product Manifest Implementation-Title Apache Log4j to SLF4J Adapter High Product Manifest implementation-url https://logging.apache.org/log4j/2.x/log4j-to-slf4j/ Low Product Manifest log4jreleasekey B3D8E1BA Low Product Manifest log4jreleasemanager Ralph Goers Low Product Manifest log4jsigningusername rgoers@apache.org Medium Product Manifest provide-capability osgi.serviceloader;osgi.serviceloader="org.apache.logging.log4j.spi.Provider" Low Product Manifest require-capability osgi.extender;filter:="(osgi.extender=osgi.serviceloader.registrar)",osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Apache Log4j to SLF4J Adapter Medium Product pom artifactid log4j-to-slf4j Highest Product pom groupid org.apache.logging.log4j Highest Product pom name Apache Log4j to SLF4J Adapter High Product pom parent-artifactid log4j Medium Version file version 2.17.2 High Version Manifest Bundle-Version 2.17.2 High Version Manifest Implementation-Version 2.17.2 High Version Manifest log4jreleaseversion 2.17.2 Medium Version pom version 2.17.2 Highest
logback-core-1.2.11.jarDescription:
logback-core module License:
http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html File Path: /var/lib/jenkins/.m2/repository/ch/qos/logback/logback-core/1.2.11/logback-core-1.2.11.jar
MD5: 115da115b5e66ef64e774ec35af1fb1a
SHA1: a01230df5ca5c34540cdaa3ad5efb012f1f1f792
SHA256: 6ce1e9397be8298a2e99029f55f955c6fa3cef255171c554d0b9c201cffd0159
Referenced In Project/Scope: Christmas:compile
logback-core-1.2.11.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-test@2.7.6
Evidence Type Source Name Value Confidence Vendor file name logback-core High Vendor jar package name ch Highest Vendor jar package name core Highest Vendor jar package name logback Highest Vendor jar package name qos Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-docurl http://www.qos.ch Low Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low Vendor Manifest bundle-symbolicname ch.qos.logback.core Medium Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.4 Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor pom artifactid logback-core Highest Vendor pom artifactid logback-core Low Vendor pom groupid ch.qos.logback Highest Vendor pom name Logback Core Module High Vendor pom parent-artifactid logback-parent Low Product file name logback-core High Product jar package name ch Highest Product jar package name core Highest Product jar package name logback Highest Product jar package name qos Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-docurl http://www.qos.ch Low Product Manifest Bundle-Name Logback Core Module Medium Product Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low Product Manifest bundle-symbolicname ch.qos.logback.core Medium Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.4 Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product pom artifactid logback-core Highest Product pom groupid ch.qos.logback Highest Product pom name Logback Core Module High Product pom parent-artifactid logback-parent Medium Version file version 1.2.11 High Version Manifest Bundle-Version 1.2.11 High Version pom version 1.2.11 Highest
Related Dependencies logback-classic-1.2.11.jarFile Path: /var/lib/jenkins/.m2/repository/ch/qos/logback/logback-classic/1.2.11/logback-classic-1.2.11.jar MD5: e13679004cc76ad5792f275f04884fab SHA1: 4741689214e9d1e8408b206506cbe76d1c6a7d60 SHA256: 4d8e899621a3006c2f66e19feab002b11e6cfc5cb1854fc41f01532c00deb2aa pkg:maven/ch.qos.logback/logback-classic@1.2.11 lombok-1.18.24.jarDescription:
Spice up your java: Automatic Resource Management, automatic generation of getters, setters, equals, hashCode and toString, and more! License:
The MIT License: https://projectlombok.org/LICENSE File Path: /var/lib/jenkins/.m2/repository/org/projectlombok/lombok/1.18.24/lombok-1.18.24.jar
MD5: a1651eaa9c999c61131d32feab16fcde
SHA1: 13a394eed5c4f9efb2a6d956e2086f1d81e857d9
SHA256: d3584bc2db03f059f984fb0a9c119aac1fa0da578a448e69fc3f68b36584c749
Referenced In Project/Scope: Christmas:compile
lombok-1.18.24.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/christmas@1.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name lombok High Vendor jar package name java Highest Vendor jar package name lombok Highest Vendor jar package name tostring Highest Vendor Manifest automatic-module-name lombok Medium Vendor Manifest can-redefine-classes true Low Vendor pom artifactid lombok Highest Vendor pom artifactid lombok Low Vendor pom developer email reinier@projectlombok.org Low Vendor pom developer email roel@projectlombok.org Low Vendor pom developer id rspilker Medium Vendor pom developer id rzwitserloot Medium Vendor pom developer name Reinier Zwitserloot Medium Vendor pom developer name Roel Spilker Medium Vendor pom groupid org.projectlombok Highest Vendor pom name Project Lombok High Vendor pom url https://projectlombok.org Highest Product file name lombok High Product jar package name java Highest Product jar package name lombok Highest Product jar package name tostring Highest Product Manifest automatic-module-name lombok Medium Product Manifest can-redefine-classes true Low Product pom artifactid lombok Highest Product pom developer email reinier@projectlombok.org Low Product pom developer email roel@projectlombok.org Low Product pom developer id rspilker Low Product pom developer id rzwitserloot Low Product pom developer name Reinier Zwitserloot Low Product pom developer name Roel Spilker Low Product pom groupid org.projectlombok Highest Product pom name Project Lombok High Product pom url https://projectlombok.org Medium Version file version 1.18.24 High Version Manifest lombok-version 1.18.24 Medium Version pom version 1.18.24 Highest
lombok-1.18.24.jar: mavenEcjBootstrapAgent.jarFile Path: /var/lib/jenkins/.m2/repository/org/projectlombok/lombok/1.18.24/lombok-1.18.24.jar/lombok/launch/mavenEcjBootstrapAgent.jarMD5: 7196a24381121bf3a7c93dcdd5575fffSHA1: 3cfed1579d718ac3dcf78bceba9ed668eb025beeSHA256: d034830e1d8615a9d0e4afdaee693687c6e61e041cc905608bba60efb04744d6Referenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence Vendor file name mavenEcjBootstrapAgent High Vendor jar package name launch Low Vendor jar package name lombok Low Vendor Manifest can-redefine-classes true Low Product file name mavenEcjBootstrapAgent High Product jar package name launch Low Product Manifest can-redefine-classes true Low
main.jsFile Path: /var/lib/jenkins/workspace/Christmas/src/main/resources/static/main.jsMD5: ea10f7f98b5fb4925128701ee9b7afd6SHA1: 93cdefce2a19b993d1ad4f11a3e0826ad47b19ebSHA256: 16f59b31645cfa91b7cb90440f8d1f82af2ea8119c6f34768e39e3ef8eeed62dReferenced In Project/Scope: Christmas
Evidence Type Source Name Value Confidence
ognl-3.1.26.jarDescription:
OGNL - Object Graph Navigation Library License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/lib/jenkins/.m2/repository/ognl/ognl/3.1.26/ognl-3.1.26.jar
MD5: c309667d632d808b2627f66a33aa05c7
SHA1: 922d3d922b8aa40146d842114c184c8b403d2f4f
SHA256: 807277276d4b9d5231139ad50885995ba1a6631498e6c1cf61e6e156d15872f5
Referenced In Project/Scope: Christmas:compile
ognl-3.1.26.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.thymeleaf/thymeleaf@3.0.14.RELEASE
Evidence Type Source Name Value Confidence Vendor file name ognl High Vendor jar package name ognl Highest Vendor Manifest automatic-module-name ognl Medium Vendor pom artifactid ognl Highest Vendor pom artifactid ognl Low Vendor pom developer email lukaszlenart@apache.org Low Vendor pom developer id lukaszlenart Medium Vendor pom groupid ognl Highest Vendor pom name OGNL - Object Graph Navigation Library High Vendor pom organization name OpenSymphony High Vendor pom organization url http://www.opensymphony.com Medium Vendor pom url http://ognl.org Highest Product file name ognl High Product jar package name ognl Highest Product Manifest automatic-module-name ognl Medium Product pom artifactid ognl Highest Product pom developer email lukaszlenart@apache.org Low Product pom developer id lukaszlenart Low Product pom groupid ognl Highest Product pom name OGNL - Object Graph Navigation Library High Product pom organization name OpenSymphony Low Product pom organization url http://www.opensymphony.com Low Product pom url http://ognl.org Medium Version file version 3.1.26 High Version pom version 3.1.26 Highest
sender.jsFile Path: /var/lib/jenkins/workspace/Christmas/src/main/resources/static/sender.jsMD5: 6fcf27cc8e76d167c0a9d5f1dbc8f535SHA1: 89b7cbff03fd53daeb4fe26d699308f5ee78bafdSHA256: 33571e77d790df3b68e05bc5fa40027bfd746d4ef5fc2110e8b93d240d63cd61Referenced In Project/Scope: Christmas
Evidence Type Source Name Value Confidence
servlet-api-2.5.jarFile Path: /var/lib/jenkins/.m2/repository/javax/servlet/servlet-api/2.5/servlet-api-2.5.jarMD5: 69ca51af4e9a67a1027a7f95b52c3e8fSHA1: 5959582d97d8b61f4d154ca9e495aafd16726e34SHA256: c658ea360a70faeeadb66fb3c90a702e4142a0ab7768f9ae9828678e0d9ad4dcReferenced In Project/Scope: Christmas:providedservlet-api-2.5.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/christmas@1.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name servlet-api High Vendor jar package name javax Highest Vendor jar package name servlet Highest Vendor Manifest extension-name servlet-api Medium Vendor Manifest Implementation-Vendor Sun Microsystems Inc High Vendor Manifest specification-vendor Sun Microsystems Inc Low Vendor pom artifactid servlet-api Highest Vendor pom artifactid servlet-api Low Vendor pom groupid javax.servlet Highest Product file name servlet-api High Product jar package name javax Highest Product jar package name servlet Highest Product Manifest extension-name servlet-api Medium Product Manifest Implementation-Title High Product Manifest specification-title A component of the Glassfish Application Server Medium Product pom artifactid servlet-api Highest Product pom groupid javax.servlet Highest Version file version 2.5 High Version Manifest Implementation-Version 2.5 High Version pom version 2.5 Highest
slf4j-api-1.7.36.jarDescription:
The slf4j API File Path: /var/lib/jenkins/.m2/repository/org/slf4j/slf4j-api/1.7.36/slf4j-api-1.7.36.jarMD5: 872da51f5de7f3923da4de871d57fd85SHA1: 6c62681a2f655b49963a5983b8b0950a6120ae14SHA256: d3ef575e3e4979678dc01bf1dcce51021493b4d11fb7f1be8ad982877c16a1c0Referenced In Project/Scope: Christmas:compileslf4j-api-1.7.36.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.webjars/webjars-locator-core@0.52
Evidence Type Source Name Value Confidence Vendor file name slf4j-api High Vendor jar package name slf4j Highest Vendor Manifest automatic-module-name org.slf4j Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest bundle-symbolicname slf4j.api Medium Vendor pom artifactid slf4j-api Highest Vendor pom artifactid slf4j-api Low Vendor pom groupid org.slf4j Highest Vendor pom name SLF4J API Module High Vendor pom parent-artifactid slf4j-parent Low Vendor pom url http://www.slf4j.org Highest Product file name slf4j-api High Product jar package name slf4j Highest Product Manifest automatic-module-name org.slf4j Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest Bundle-Name slf4j-api Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest bundle-symbolicname slf4j.api Medium Product Manifest Implementation-Title slf4j-api High Product pom artifactid slf4j-api Highest Product pom groupid org.slf4j Highest Product pom name SLF4J API Module High Product pom parent-artifactid slf4j-parent Medium Product pom url http://www.slf4j.org Medium Version file version 1.7.36 High Version Manifest Bundle-Version 1.7.36 High Version Manifest Implementation-Version 1.7.36 High Version pom version 1.7.36 Highest
snakeyaml-1.30.jarDescription:
YAML 1.1 parser and emitter for Java License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/lib/jenkins/.m2/repository/org/yaml/snakeyaml/1.30/snakeyaml-1.30.jar
MD5: ba063b8ef3a8bfd591a1b56451166b14
SHA1: 8fde7fe2586328ac3c68db92045e1c8759125000
SHA256: f43a4e40a946b8cdfd0321bc1c9a839bc3f119c57e4ca84fb87c367f51c8b2b3
Referenced In Project/Scope: Christmas:compile
snakeyaml-1.30.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-test@2.7.6
Evidence Type Source Name Value Confidence Vendor file name snakeyaml High Vendor jar package name emitter Highest Vendor jar package name parser Highest Vendor jar package name snakeyaml Highest Vendor jar package name yaml Highest Vendor Manifest automatic-module-name org.yaml.snakeyaml Medium Vendor Manifest bundle-symbolicname org.yaml.snakeyaml Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor pom artifactid snakeyaml Highest Vendor pom artifactid snakeyaml Low Vendor pom developer email alexander.maslov@gmail.com Low Vendor pom developer email jordanangold@gmail.com Low Vendor pom developer email public.somov@gmail.com Low Vendor pom developer id asomov Medium Vendor pom developer id Jordan Medium Vendor pom developer id maslovalex Medium Vendor pom developer name Alexander Maslov Medium Vendor pom developer name Andrey Somov Medium Vendor pom developer name Jordan Angold Medium Vendor pom groupid org.yaml Highest Vendor pom name SnakeYAML High Vendor pom url https://bitbucket.org/snakeyaml/snakeyaml Highest Product file name snakeyaml High Product jar package name emitter Highest Product jar package name parser Highest Product jar package name snakeyaml Highest Product jar package name yaml Highest Product Manifest automatic-module-name org.yaml.snakeyaml Medium Product Manifest Bundle-Name SnakeYAML Medium Product Manifest bundle-symbolicname org.yaml.snakeyaml Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product pom artifactid snakeyaml Highest Product pom developer email alexander.maslov@gmail.com Low Product pom developer email jordanangold@gmail.com Low Product pom developer email public.somov@gmail.com Low Product pom developer id asomov Low Product pom developer id Jordan Low Product pom developer id maslovalex Low Product pom developer name Alexander Maslov Low Product pom developer name Andrey Somov Low Product pom developer name Jordan Angold Low Product pom groupid org.yaml Highest Product pom name SnakeYAML High Product pom url https://bitbucket.org/snakeyaml/snakeyaml Medium Version file version 1.30 High Version pom version 1.30 Highest
CVE-2022-1471 suppress
SnakeYaml's Constructor() class does not restrict types which can be instantiated during deserialization. Deserializing yaml content provided by an attacker can lead to remote code execution. We recommend using SnakeYaml's SafeConsturctor when parsing untrusted content to restrict deserialization. CWE-502 Deserialization of Untrusted Data
CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions:
CVE-2022-25857 suppress
The package org.yaml:snakeyaml from 0 and before 1.31 are vulnerable to Denial of Service (DoS) due missing to nested depth limitation for collections. CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
CVSSv3:
Base Score: HIGH (7.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions:
CVE-2022-38749 suppress
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. CWE-787 Out-of-bounds Write
CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions:
CVE-2022-38751 suppress
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. CWE-787 Out-of-bounds Write
CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions:
CVE-2022-38752 suppress
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack-overflow. CWE-787 Out-of-bounds Write
CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions:
CVE-2022-41854 suppress
Those using Snakeyaml to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stack overflow. This effect may support a denial of service attack. CWE-787 Out-of-bounds Write
CVSSv3:
Base Score: MEDIUM (6.5) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions:
CVE-2022-38750 suppress
Using snakeYAML to parse untrusted YAML files may be vulnerable to Denial of Service attacks (DOS). If the parser is running on user supplied input, an attacker may supply content that causes the parser to crash by stackoverflow. CWE-787 Out-of-bounds Write
CVSSv3:
Base Score: MEDIUM (5.5) Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H References:
Vulnerable Software & Versions:
sockjs-client-1.5.1.jarDescription:
WebJar for SockJS-client License:
MIT: https://github.com/sockjs/sockjs-client/blob/master/LICENSE-MIT-SockJS File Path: /var/lib/jenkins/.m2/repository/org/webjars/sockjs-client/1.5.1/sockjs-client-1.5.1.jar
MD5: edd0e340bcf632004107ec6b0b1b4e27
SHA1: 69151ceb2e4ada6f6cbc002c255d1158fe581b52
SHA256: cb143f106d633d90510fe1fab728fb09279a60febae9362c66742f0074338e74
Referenced In Project/Scope: Christmas:compile
sockjs-client-1.5.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/christmas@1.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name sockjs-client High Vendor pom artifactid sockjs-client Highest Vendor pom artifactid sockjs-client Low Vendor pom developer email james@jamesward.com Low Vendor pom developer id jamesward Medium Vendor pom developer name James Ward Medium Vendor pom groupid org.webjars Highest Vendor pom name SockJS-client High Vendor pom url http://webjars.org Highest Product file name sockjs-client High Product pom artifactid sockjs-client Highest Product pom developer email james@jamesward.com Low Product pom developer id jamesward Low Product pom developer name James Ward Low Product pom groupid org.webjars Highest Product pom name SockJS-client High Product pom url http://webjars.org Medium Version file version 1.5.1 High Version pom version 1.5.1 Highest
sockjs-client-1.5.1.jar: sockjs.jsFile Path: /var/lib/jenkins/.m2/repository/org/webjars/sockjs-client/1.5.1/sockjs-client-1.5.1.jar/META-INF/resources/webjars/sockjs-client/1.5.1/sockjs.jsMD5: 8d166109b67bd097dba8d116a1dce299SHA1: 09da497c9d04ff15e099e86a419ec9913a4c8effSHA256: 8c427b7518b99bb36e1dddb0455a9165dc2e8668e320f592f8e2e2cb8b23c3d6Referenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
sockjs-client-1.5.1.jar: sockjs.min.jsFile Path: /var/lib/jenkins/.m2/repository/org/webjars/sockjs-client/1.5.1/sockjs-client-1.5.1.jar/META-INF/resources/webjars/sockjs-client/1.5.1/sockjs.min.jsMD5: 22f39595b8791b2c6cf0684832ad2a70SHA1: f60e1b0d28484537bbcc349010bddf849b217352SHA256: 02a803b1fda49903c0c9b060605dece184de2065731b10fb3d3b8e1890674bdcReferenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
spring-beans-5.3.23.jarDescription:
Spring Beans License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /var/lib/jenkins/.m2/repository/org/springframework/spring-beans/5.3.23/spring-beans-5.3.23.jar
MD5: 54a6169c8887dac4c3a5e2e3975d838c
SHA1: 3bdefbf6042ed742cbe16f27d2d14cca9096a606
SHA256: 99e2ec12fd419db7facf0424b2c601a4155eba85aac5f75050baa55e18eb6c80
Referenced In Project/Scope: Christmas:compile
spring-beans-5.3.23.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/christmas@1.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name spring-beans High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name beans Highest Vendor jar package name springframework Highest Vendor Manifest automatic-module-name spring.beans Medium Vendor pom artifactid spring-beans Highest Vendor pom artifactid spring-beans Low Vendor pom developer email jhoeller@pivotal.io Low Vendor pom developer id jhoeller Medium Vendor pom developer name Juergen Hoeller Medium Vendor pom groupid org.springframework Highest Vendor pom name Spring Beans High Vendor pom organization name Spring IO High Vendor pom organization url https://spring.io/projects/spring-framework Medium Vendor pom url spring-projects/spring-framework Highest Product file name spring-beans High Product hint analyzer product springsource_spring_framework Highest Product jar package name beans Highest Product jar package name springframework Highest Product Manifest automatic-module-name spring.beans Medium Product Manifest Implementation-Title spring-beans High Product pom artifactid spring-beans Highest Product pom developer email jhoeller@pivotal.io Low Product pom developer id jhoeller Low Product pom developer name Juergen Hoeller Low Product pom groupid org.springframework Highest Product pom name Spring Beans High Product pom organization name Spring IO Low Product pom organization url https://spring.io/projects/spring-framework Low Product pom url spring-projects/spring-framework High Version file version 5.3.23 High Version Manifest Implementation-Version 5.3.23 High Version pom version 5.3.23 Highest
spring-boot-2.7.7.jarDescription:
Spring Boot License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /var/lib/jenkins/.m2/repository/org/springframework/boot/spring-boot/2.7.7/spring-boot-2.7.7.jar
MD5: 75e5a70f351a7b64d9e7af866bfe75a9
SHA1: 1fa59eb2fce0363bdf152d7660b784257bfac99b
SHA256: 57cb88b88ff9b8b75fa65f1d85a209065e75fe1e28e4403c165633f16579dfb7
Referenced In Project/Scope: Christmas:compile
spring-boot-2.7.7.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-test@2.7.6
Evidence Type Source Name Value Confidence Vendor file name spring-boot High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name boot Highest Vendor jar package name springframework Highest Vendor Manifest automatic-module-name spring.boot Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor pom artifactid spring-boot Highest Vendor pom artifactid spring-boot Low Vendor pom developer email info@pivotal.io Low Vendor pom developer name Pivotal Medium Vendor pom developer org Pivotal Software, Inc. Medium Vendor pom developer org URL https://www.spring.io Medium Vendor pom groupid org.springframework.boot Highest Vendor pom name spring-boot High Vendor pom organization name Pivotal Software, Inc. High Vendor pom organization url https://spring.io Medium Vendor pom url https://spring.io/projects/spring-boot Highest Product file name spring-boot High Product jar package name boot Highest Product jar package name springframework Highest Product Manifest automatic-module-name spring.boot Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Spring Boot High Product pom artifactid spring-boot Highest Product pom developer email info@pivotal.io Low Product pom developer name Pivotal Low Product pom developer org Pivotal Software, Inc. Low Product pom developer org URL https://www.spring.io Low Product pom groupid org.springframework.boot Highest Product pom name spring-boot High Product pom organization name Pivotal Software, Inc. Low Product pom organization url https://spring.io Low Product pom url https://spring.io/projects/spring-boot Medium Version file version 2.7.7 High Version Manifest Implementation-Version 2.7.7 High Version pom version 2.7.7 Highest
Related Dependencies spring-boot-autoconfigure-2.7.7.jarFile Path: /var/lib/jenkins/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/2.7.7/spring-boot-autoconfigure-2.7.7.jar MD5: 55a80bb4f1e0d4ba0b04e782804626c9 SHA1: 8da88afca89ce4b1ab5762e6ca35e1bad196ad47 SHA256: c8852e2a539cbecaaf34373983b977ab8b718f348af9e50c4d017ed5c13d890e pkg:maven/org.springframework.boot/spring-boot-autoconfigure@2.7.7 spring-boot-starter-2.7.7.jarFile Path: /var/lib/jenkins/.m2/repository/org/springframework/boot/spring-boot-starter/2.7.7/spring-boot-starter-2.7.7.jar MD5: 40c5ea52807490cadf26fcf79ceb319d SHA1: dd06582c2b6b911bdf1be4f3a40e7b63a5ae75d7 SHA256: d45015e0c98aad624ee7d9f8f2e392bb751aad2108b772fb768f247d31b0b51c pkg:maven/org.springframework.boot/spring-boot-starter@2.7.7 spring-boot-starter-aop-2.7.7.jarFile Path: /var/lib/jenkins/.m2/repository/org/springframework/boot/spring-boot-starter-aop/2.7.7/spring-boot-starter-aop-2.7.7.jar MD5: 6433008c1e9c96f778dc31d3be1152de SHA1: 68062ada4148e4914a3b96046030fbcd5e0a62fa SHA256: f35acf4484fda17574efa829e4e1484c334634bf6134e962a80f5eb546d0c08a pkg:maven/org.springframework.boot/spring-boot-starter-aop@2.7.7 spring-boot-starter-jdbc-2.7.7.jarFile Path: /var/lib/jenkins/.m2/repository/org/springframework/boot/spring-boot-starter-jdbc/2.7.7/spring-boot-starter-jdbc-2.7.7.jar MD5: 3182d259a80cd895bbeff07849122fd1 SHA1: 404134263ab70e1f41ecc2d0bbf6446f9afc3e02 SHA256: 891ba7bfaca8904b9e9a8335609e083b3e85201881a8040d6953f0e9a5c21002 pkg:maven/org.springframework.boot/spring-boot-starter-jdbc@2.7.7 spring-boot-starter-logging-2.7.7.jarFile Path: /var/lib/jenkins/.m2/repository/org/springframework/boot/spring-boot-starter-logging/2.7.7/spring-boot-starter-logging-2.7.7.jar MD5: 7df1b0d64c104ed2e5b1f9708237637c SHA1: 0c71bdb4e93d75b535fef277606868d1d6934c35 SHA256: 31c7e0d1e6843d0a9b869552ac34abab98f8240ff0f22b569642f5ec15abc7b5 pkg:maven/org.springframework.boot/spring-boot-starter-logging@2.7.7 spring-boot-starter-log4j2-2.7.6.jarDescription:
Starter for using Log4j2 for logging. An alternative to spring-boot-starter-logging License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /var/lib/jenkins/.m2/repository/org/springframework/boot/spring-boot-starter-log4j2/2.7.6/spring-boot-starter-log4j2-2.7.6.jar
MD5: 448dc58245ff11ee84ec69eb89de4dcd
SHA1: 2672839bc1aaa8ef292dea2eb40a34abc5d5ada3
SHA256: e514c4b4c22d76e48a2ed15f5d1f4139f6469514fc8b41ffb10376751ac2ec48
Referenced In Project/Scope: Christmas:compile
spring-boot-starter-log4j2-2.7.6.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/christmas@1.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name spring-boot-starter-log4j2 High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor Manifest automatic-module-name spring.boot.starter.log4j2 Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest spring-boot-jar-type dependencies-starter Low Vendor pom artifactid spring-boot-starter-log4j2 Highest Vendor pom artifactid spring-boot-starter-log4j2 Low Vendor pom developer email info@pivotal.io Low Vendor pom developer name Pivotal Medium Vendor pom developer org Pivotal Software, Inc. Medium Vendor pom developer org URL https://www.spring.io Medium Vendor pom groupid org.springframework.boot Highest Vendor pom name spring-boot-starter-log4j2 High Vendor pom organization name Pivotal Software, Inc. High Vendor pom organization url https://spring.io Medium Vendor pom url https://spring.io/projects/spring-boot Highest Product file name spring-boot-starter-log4j2 High Product Manifest automatic-module-name spring.boot.starter.log4j2 Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Starter for using Log4j2 for logging. An alternative to spring-boot-starter-logging High Product Manifest spring-boot-jar-type dependencies-starter Low Product pom artifactid spring-boot-starter-log4j2 Highest Product pom developer email info@pivotal.io Low Product pom developer name Pivotal Low Product pom developer org Pivotal Software, Inc. Low Product pom developer org URL https://www.spring.io Low Product pom groupid org.springframework.boot Highest Product pom name spring-boot-starter-log4j2 High Product pom organization name Pivotal Software, Inc. Low Product pom organization url https://spring.io Low Product pom url https://spring.io/projects/spring-boot Medium Version file version 2.7.6 High Version Manifest Implementation-Version 2.7.6 High Version pom version 2.7.6 Highest
Related Dependencies spring-boot-configuration-processor-2.7.6.jarFile Path: /var/lib/jenkins/.m2/repository/org/springframework/boot/spring-boot-configuration-processor/2.7.6/spring-boot-configuration-processor-2.7.6.jar MD5: f817359626b4b52c92b8279096a20ee1 SHA1: ef52bd1c96c4b04f3fe6c72a6108a3bea24f966f SHA256: d7216861cb25fc130b175f1e605dbff5c0c38d62b3c98376da690e556433b41a pkg:maven/org.springframework.boot/spring-boot-configuration-processor@2.7.6 spring-boot-starter-data-jpa-2.7.6.jarFile Path: /var/lib/jenkins/.m2/repository/org/springframework/boot/spring-boot-starter-data-jpa/2.7.6/spring-boot-starter-data-jpa-2.7.6.jar MD5: 06473f8d5d05bdd2fcbcf036bba58ea2 SHA1: 7eef599012347f2fb7f84ba71eba10caf094dfb5 SHA256: 35df3afd2f2043bc4b8e9b24b621b9e0d9b0d9c291217b5f38e9f50b654c339c pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.7.6 spring-core-5.3.24.jarDescription:
Spring Core License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /var/lib/jenkins/.m2/repository/org/springframework/spring-core/5.3.24/spring-core-5.3.24.jar
MD5: c5a7205d5d58105713aa9f033ae01dd9
SHA1: d095c329f30baf2b6d44eccbd2352d7a2f840c72
SHA256: 7d513957395e6a354b80e714b31a52b765dd6c771b50a26419d277a06d13ea68
Referenced In Project/Scope: Christmas:compile
spring-core-5.3.24.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework/spring-messaging@5.3.24
Evidence Type Source Name Value Confidence Vendor file name spring-core High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name core Highest Vendor jar package name io Highest Vendor jar package name springframework Highest Vendor Manifest automatic-module-name spring.core Medium Vendor pom artifactid spring-core Highest Vendor pom artifactid spring-core Low Vendor pom developer email jhoeller@pivotal.io Low Vendor pom developer id jhoeller Medium Vendor pom developer name Juergen Hoeller Medium Vendor pom groupid org.springframework Highest Vendor pom name Spring Core High Vendor pom organization name Spring IO High Vendor pom organization url https://spring.io/projects/spring-framework Medium Vendor pom url spring-projects/spring-framework Highest Product file name spring-core High Product hint analyzer product springsource_spring_framework Highest Product jar package name core Highest Product jar package name io Highest Product jar package name springframework Highest Product Manifest automatic-module-name spring.core Medium Product Manifest Implementation-Title spring-core High Product pom artifactid spring-core Highest Product pom developer email jhoeller@pivotal.io Low Product pom developer id jhoeller Low Product pom developer name Juergen Hoeller Low Product pom groupid org.springframework Highest Product pom name Spring Core High Product pom organization name Spring IO Low Product pom organization url https://spring.io/projects/spring-framework Low Product pom url spring-projects/spring-framework High Version file version 5.3.24 High Version Manifest Implementation-Version 5.3.24 High Version pom version 5.3.24 Highest
Related Dependencies spring-aop-5.3.24.jarFile Path: /var/lib/jenkins/.m2/repository/org/springframework/spring-aop/5.3.24/spring-aop-5.3.24.jar MD5: 8aea1f70ed68bd24db1d3f3a051e51f6 SHA1: efd01bc1048a2e1b6a7442fbd78170bc02c342b7 SHA256: 8258621a15613b3a651a8305ddb488848ad502f6b147bc69eed553bb9ebf3426 pkg:maven/org.springframework/spring-aop@5.3.24 spring-aspects-5.3.24.jarFile Path: /var/lib/jenkins/.m2/repository/org/springframework/spring-aspects/5.3.24/spring-aspects-5.3.24.jar MD5: de9073f281de50de6c46901d8a6a7aa3 SHA1: e97d36c3e516d3dd0579437428b6e26902da0c88 SHA256: 20a5bb77c3a3010a1e721e65e4047b3b1e5d466217f0736276d0357df54ba307 pkg:maven/org.springframework/spring-aspects@5.3.24 spring-context-5.3.24.jarFile Path: /var/lib/jenkins/.m2/repository/org/springframework/spring-context/5.3.24/spring-context-5.3.24.jar MD5: 719f09fce0cc0526f28a1854d55a9d78 SHA1: e48634d7b8f40d4d0fe978830be0247bfc2ff2cd SHA256: 7e7bdee594a9fc17ccc46c9c584c793a2e1e3de4a819ba007e155a7e0769795e pkg:maven/org.springframework/spring-context@5.3.24 spring-expression-5.3.24.jarFile Path: /var/lib/jenkins/.m2/repository/org/springframework/spring-expression/5.3.24/spring-expression-5.3.24.jar MD5: b4a867204a73ba1450c463bc0a45d9b8 SHA1: ae7410418e7b4bd27a01e3fb1c2fed35b2bc1e84 SHA256: 05b0117e9bfb269a1803f08020787591930a8c79ec0363e5081a1df8ebe26c7b pkg:maven/org.springframework/spring-expression@5.3.24 spring-jcl-5.3.24.jarFile Path: /var/lib/jenkins/.m2/repository/org/springframework/spring-jcl/5.3.24/spring-jcl-5.3.24.jar MD5: bfc7ee2676eb0c5c68dd2141575cdfc7 SHA1: 2b30878663ceed2af07238dc54e92e5bf001438d SHA256: a62d125552e7c8d438145ea31af6b027be244e631fea5ebb3c62f60147afd7ae pkg:maven/org.springframework/spring-jcl@5.3.24 spring-jdbc-5.3.24.jarFile Path: /var/lib/jenkins/.m2/repository/org/springframework/spring-jdbc/5.3.24/spring-jdbc-5.3.24.jar MD5: cff9c2b9ee30dce700fc5ad52724c492 SHA1: 909c19ab470a59b9fd23177d26b8e880733b15d4 SHA256: 418c4b2cf04f0654ffd96e5c85822e0fa6f42dd7e3d44cf2598565bc79f7c12d pkg:maven/org.springframework/spring-jdbc@5.3.24 spring-messaging-5.3.24.jarFile Path: /var/lib/jenkins/.m2/repository/org/springframework/spring-messaging/5.3.24/spring-messaging-5.3.24.jar MD5: c3329c6ce4a58d7808b951f1c55e249f SHA1: 62577a956a4fa4f5d6a2d6ee645ad65295a8bd7a SHA256: bcfd745f5d621694daf9bf73f849b4d9d9301f3c0b030533930cdedd02067054 pkg:maven/org.springframework/spring-messaging@5.3.24 spring-orm-5.3.24.jarFile Path: /var/lib/jenkins/.m2/repository/org/springframework/spring-orm/5.3.24/spring-orm-5.3.24.jar MD5: 75360e3f424e084c31c6f646f86c7107 SHA1: 256e029c2d8200294fe7fb5352ca2d1d7310dcad SHA256: 9d79ae55b957fe085e5775c0c75e5d250d7c7fec8cb49b2b0346b70a456d1914 pkg:maven/org.springframework/spring-orm@5.3.24 spring-tx-5.3.24.jarFile Path: /var/lib/jenkins/.m2/repository/org/springframework/spring-tx/5.3.24/spring-tx-5.3.24.jar MD5: dbcef239a0c4e1155274a101d409ea56 SHA1: 175a2157fce17669af6d4db1d094cb4baaa5c8fd SHA256: 8b8cc5c5235b1836c2e5b75b7e1739cbfb5d0a023096fada95367875fba3b808 pkg:maven/org.springframework/spring-tx@5.3.24 spring-websocket-5.3.24.jarFile Path: /var/lib/jenkins/.m2/repository/org/springframework/spring-websocket/5.3.24/spring-websocket-5.3.24.jar MD5: 1a9fd7e54acf65f600be2264289fc3d1 SHA1: b2a19786ab58f6e31316bd06c7e6da28c2770c87 SHA256: f65844caee8888c5cbe81365abc7d51c7777b8a4bc1aca960038843c260f947d pkg:maven/org.springframework/spring-websocket@5.3.24 spring-data-commons-2.7.6.jarFile Path: /var/lib/jenkins/.m2/repository/org/springframework/data/spring-data-commons/2.7.6/spring-data-commons-2.7.6.jarMD5: f17351668836c0395932bb5539abf9cfSHA1: e3d15a8f4d5ef0d2323569445c66903d0188cb68SHA256: 8903f08719c8a220fbbb502ebad23c7f5694ad382493e3ce0e7fcf6bedaccae1Referenced In Project/Scope: Christmas:compilespring-data-commons-2.7.6.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.7.6
Evidence Type Source Name Value Confidence Vendor file name spring-data-commons High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name core Highest Vendor jar package name data Highest Vendor jar package name springframework Highest Vendor Manifest automatic-module-name spring.data.commons Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor pom artifactid spring-data-commons Highest Vendor pom artifactid spring-data-commons Low Vendor pom groupid org.springframework.data Highest Vendor pom name Spring Data Core High Vendor pom parent-artifactid spring-data-parent Low Vendor pom parent-groupid org.springframework.data.build Medium Product file name spring-data-commons High Product jar package name core Highest Product jar package name data Highest Product jar package name springframework Highest Product Manifest automatic-module-name spring.data.commons Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Spring Data Core High Product pom artifactid spring-data-commons Highest Product pom groupid org.springframework.data Highest Product pom name Spring Data Core High Product pom parent-artifactid spring-data-parent Medium Product pom parent-groupid org.springframework.data.build Medium Version file version 2.7.6 High Version Manifest Implementation-Version 2.7.6 High Version pom version 2.7.6 Highest
spring-data-jpa-2.7.6.jarDescription:
Spring Data module for JPA repositories. File Path: /var/lib/jenkins/.m2/repository/org/springframework/data/spring-data-jpa/2.7.6/spring-data-jpa-2.7.6.jarMD5: f5a576a6fe2ddde2b2db47e9b437695dSHA1: 8d0414f5cca5e31509943cd5f97cacdddd7c7384SHA256: 40b5de0a77874250ef906a0cd5ab2607e9e8412c12b6c6df4c2a4c0f6814e2dbReferenced In Project/Scope: Christmas:compilespring-data-jpa-2.7.6.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.7.6
Evidence Type Source Name Value Confidence Vendor file name spring-data-jpa High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name data Highest Vendor jar package name jpa Highest Vendor jar package name springframework Highest Vendor Manifest automatic-module-name spring.data.jpa Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor pom artifactid spring-data-jpa Highest Vendor pom artifactid spring-data-jpa Low Vendor pom groupid org.springframework.data Highest Vendor pom name Spring Data JPA High Vendor pom parent-artifactid spring-data-parent Low Vendor pom parent-groupid org.springframework.data.build Medium Vendor pom url https://spring.io/projects/spring-data-jpa Highest Product file name spring-data-jpa High Product jar package name data Highest Product jar package name jpa Highest Product jar package name springframework Highest Product Manifest automatic-module-name spring.data.jpa Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Spring Data JPA High Product pom artifactid spring-data-jpa Highest Product pom groupid org.springframework.data Highest Product pom name Spring Data JPA High Product pom parent-artifactid spring-data-parent Medium Product pom parent-groupid org.springframework.data.build Medium Product pom url https://spring.io/projects/spring-data-jpa Medium Version file version 2.7.6 High Version Manifest Implementation-Version 2.7.6 High Version pom version 2.7.6 Highest
spring-security-core-5.8.1.jarDescription:
Spring Security License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /var/lib/jenkins/.m2/repository/org/springframework/security/spring-security-core/5.8.1/spring-security-core-5.8.1.jar
MD5: b1af5947486710449a8936a387e90d98
SHA1: ad8f871b5f9e04802bdc4063a5b6e88943536903
SHA256: abb00c8201744977aa7d36ebfbf8c7fbe9b9a4eea51b742e00053fce4ffad723
Referenced In Project/Scope: Christmas:compile
spring-security-core-5.8.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.security/spring-security-web@5.8.1
Evidence Type Source Name Value Confidence Vendor file name spring-security-core High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name core Highest Vendor jar package name security Highest Vendor jar package name springframework Highest Vendor Manifest automatic-module-name spring.security.core Medium Vendor pom artifactid spring-security-core Highest Vendor pom artifactid spring-security-core Low Vendor pom developer email info@pivotal.io Low Vendor pom developer name Pivotal Medium Vendor pom developer org Pivotal Software, Inc. Medium Vendor pom developer org URL https://www.spring.io Medium Vendor pom groupid org.springframework.security Highest Vendor pom name spring-security-core High Vendor pom organization name Pivotal Software, Inc. High Vendor pom organization url https://spring.io Medium Vendor pom url https://spring.io/projects/spring-security Highest Product file name spring-security-core High Product jar package name core Highest Product jar package name security Highest Product jar package name springframework Highest Product Manifest automatic-module-name spring.security.core Medium Product Manifest Implementation-Title spring-security-core High Product pom artifactid spring-security-core Highest Product pom developer email info@pivotal.io Low Product pom developer name Pivotal Low Product pom developer org Pivotal Software, Inc. Low Product pom developer org URL https://www.spring.io Low Product pom groupid org.springframework.security Highest Product pom name spring-security-core High Product pom organization name Pivotal Software, Inc. Low Product pom organization url https://spring.io Low Product pom url https://spring.io/projects/spring-security Medium Version file version 5.8.1 High Version Manifest Implementation-Version 5.8.1 High Version pom version 5.8.1 Highest
Related Dependencies spring-security-config-5.8.1.jarFile Path: /var/lib/jenkins/.m2/repository/org/springframework/security/spring-security-config/5.8.1/spring-security-config-5.8.1.jar MD5: c759d011b35fe299724f0cf3d00a6fec SHA1: 16c758781dcc3811837ebe64573155b5cac0b8e6 SHA256: 3656eaaf5855e1663f4dcaabba10e35b02fa3c9a49b351031bc8576af9c043f2 pkg:maven/org.springframework.security/spring-security-config@5.8.1 spring-security-messaging-5.8.1.jarFile Path: /var/lib/jenkins/.m2/repository/org/springframework/security/spring-security-messaging/5.8.1/spring-security-messaging-5.8.1.jar MD5: 88b4fe9a51bff329bca2a878466a0085 SHA1: 68a38dc45da6191ab1811e46998a58d703e5f831 SHA256: 3ba7e6a1e60e6bcfbdee4688b4760784a9079ca0cff77a513a92e9b92e2edee2 pkg:maven/org.springframework.security/spring-security-messaging@5.8.1 spring-security-crypto-5.8.1.jarDescription:
Spring Security License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /var/lib/jenkins/.m2/repository/org/springframework/security/spring-security-crypto/5.8.1/spring-security-crypto-5.8.1.jar
MD5: 19b5a2033316a9e9d993c8d9fb64e232
SHA1: b6aef84bd8761e87a78a0f2f05d42fcb03a0414f
SHA256: 3889dd2150c58fd778657aee2ebdfb3bf791dc4dcfa5d50a28e40ec17c4e2caa
Referenced In Project/Scope: Christmas:compile
spring-security-crypto-5.8.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.security/spring-security-web@5.8.1
Evidence Type Source Name Value Confidence Vendor file name spring-security-crypto High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name crypto Highest Vendor jar package name security Highest Vendor jar package name springframework Highest Vendor Manifest automatic-module-name spring.security.crypto Medium Vendor pom artifactid spring-security-crypto Highest Vendor pom artifactid spring-security-crypto Low Vendor pom developer email info@pivotal.io Low Vendor pom developer name Pivotal Medium Vendor pom developer org Pivotal Software, Inc. Medium Vendor pom developer org URL https://www.spring.io Medium Vendor pom groupid org.springframework.security Highest Vendor pom name spring-security-crypto High Vendor pom organization name Pivotal Software, Inc. High Vendor pom organization url https://spring.io Medium Vendor pom url https://spring.io/projects/spring-security Highest Product file name spring-security-crypto High Product jar package name crypto Highest Product jar package name security Highest Product jar package name springframework Highest Product Manifest automatic-module-name spring.security.crypto Medium Product Manifest Implementation-Title spring-security-crypto High Product pom artifactid spring-security-crypto Highest Product pom developer email info@pivotal.io Low Product pom developer name Pivotal Low Product pom developer org Pivotal Software, Inc. Low Product pom developer org URL https://www.spring.io Low Product pom groupid org.springframework.security Highest Product pom name spring-security-crypto High Product pom organization name Pivotal Software, Inc. Low Product pom organization url https://spring.io Low Product pom url https://spring.io/projects/spring-security Medium Version file version 5.8.1 High Version Manifest Implementation-Version 5.8.1 High Version pom version 5.8.1 Highest
CVE-2020-5408 (OSSINDEX) suppress
Spring Security versions 5.3.x prior to 5.3.2, 5.2.x prior to 5.2.4, 5.1.x prior to 5.1.10, 5.0.x prior to 5.0.16 and 4.2.x prior to 4.2.16 use a fixed null initialization vector with CBC Mode in the implementation of the queryable text encryptor. A malicious user with access to the data that has been encrypted using such an encryptor may be able to derive the unencrypted values using a dictionary attack.
Sonatype's research suggests that this CVE's details differ from those defined at NVD. See https://ossindex.sonatype.org/vulnerability/CVE-2020-5408 for details CWE-330 Use of Insufficiently Random Values
CVSSv2:
Base Score: MEDIUM (6.5) Vector: /AV:N/AC:L/Au:/C:H/I:N/A:N References:
Vulnerable Software & Versions (OSSINDEX):
cpe:2.3:a:org.springframework.security:spring-security-crypto:5.8.1:*:*:*:*:*:*:* spring-security-web-5.8.1.jarDescription:
Spring Security License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /var/lib/jenkins/.m2/repository/org/springframework/security/spring-security-web/5.8.1/spring-security-web-5.8.1.jar
MD5: d9ab5cae64a994c335428e77679e663b
SHA1: 6b81ef79b7f07f2a75d937f932d62c28f0d747de
SHA256: a89bfbf5deff2bbeb33e32a69dd00cb7a31b039f69b802ef33ecb9b71d403ebf
Referenced In Project/Scope: Christmas:compile
spring-security-web-5.8.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/christmas@1.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name spring-security-web High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name security Highest Vendor jar package name springframework Highest Vendor jar package name web Highest Vendor Manifest automatic-module-name spring.security.web Medium Vendor pom artifactid spring-security-web Highest Vendor pom artifactid spring-security-web Low Vendor pom developer email info@pivotal.io Low Vendor pom developer name Pivotal Medium Vendor pom developer org Pivotal Software, Inc. Medium Vendor pom developer org URL https://www.spring.io Medium Vendor pom groupid org.springframework.security Highest Vendor pom name spring-security-web High Vendor pom organization name Pivotal Software, Inc. High Vendor pom organization url https://spring.io Medium Vendor pom url https://spring.io/projects/spring-security Highest Product file name spring-security-web High Product jar package name security Highest Product jar package name springframework Highest Product jar package name web Highest Product Manifest automatic-module-name spring.security.web Medium Product Manifest Implementation-Title spring-security-web High Product pom artifactid spring-security-web Highest Product pom developer email info@pivotal.io Low Product pom developer name Pivotal Low Product pom developer org Pivotal Software, Inc. Low Product pom developer org URL https://www.spring.io Low Product pom groupid org.springframework.security Highest Product pom name spring-security-web High Product pom organization name Pivotal Software, Inc. Low Product pom organization url https://spring.io Low Product pom url https://spring.io/projects/spring-security Medium Version file version 5.8.1 High Version Manifest Implementation-Version 5.8.1 High Version pom version 5.8.1 Highest
spring-web-5.3.24.jarDescription:
Spring Web License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /var/lib/jenkins/.m2/repository/org/springframework/spring-web/5.3.24/spring-web-5.3.24.jar
MD5: 63eaf250c49b69e02280549b7b73918f
SHA1: d89bbcaabb1ff247a089875cbc4211bfe96c9a59
SHA256: d7e9b62ae99354b84e42c0a61efd70e384c6cecd9354408b9c1a3002fed3d5fc
Referenced In Project/Scope: Christmas:compile
spring-web-5.3.24.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework/spring-websocket@5.3.24
Evidence Type Source Name Value Confidence Vendor file name spring-web High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name springframework Highest Vendor jar package name web Highest Vendor Manifest automatic-module-name spring.web Medium Vendor pom artifactid spring-web Highest Vendor pom artifactid spring-web Low Vendor pom developer email jhoeller@pivotal.io Low Vendor pom developer id jhoeller Medium Vendor pom developer name Juergen Hoeller Medium Vendor pom groupid org.springframework Highest Vendor pom name Spring Web High Vendor pom organization name Spring IO High Vendor pom organization url https://spring.io/projects/spring-framework Medium Vendor pom url spring-projects/spring-framework Highest Product file name spring-web High Product hint analyzer product springsource_spring_framework Highest Product jar package name springframework Highest Product jar package name web Highest Product Manifest automatic-module-name spring.web Medium Product Manifest Implementation-Title spring-web High Product pom artifactid spring-web Highest Product pom developer email jhoeller@pivotal.io Low Product pom developer id jhoeller Low Product pom developer name Juergen Hoeller Low Product pom groupid org.springframework Highest Product pom name Spring Web High Product pom organization name Spring IO Low Product pom organization url https://spring.io/projects/spring-framework Low Product pom url spring-projects/spring-framework High Version file version 5.3.24 High Version Manifest Implementation-Version 5.3.24 High Version pom version 5.3.24 Highest
CVE-2016-1000027 suppress
Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentication may be required. NOTE: the vendor's position is that untrusted data is not an intended use case. The product's behavior will not be changed because some users rely on deserialization of trusted data. CWE-502 Deserialization of Untrusted Data
CVSSv2:
Base Score: HIGH (7.5) Vector: /AV:N/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
Base Score: CRITICAL (9.8) Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions:
spring-webmvc-5.3.24.jarDescription:
Spring Web MVC License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /var/lib/jenkins/.m2/repository/org/springframework/spring-webmvc/5.3.24/spring-webmvc-5.3.24.jar
MD5: 63b2d6f23ce512122f601e082c84b998
SHA1: 33d2187c2bf1cb2c222bd1cc18b618736babcf3d
SHA256: 913d82ea870b257a052ed9b88e8d76d2af5d680c7f52264fbbfc6aae86b4e72d
Referenced In Project/Scope: Christmas:compile
spring-webmvc-5.3.24.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/christmas@1.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name spring-webmvc High Vendor hint analyzer vendor pivotal software Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name mvc Highest Vendor jar package name springframework Highest Vendor jar package name web Highest Vendor Manifest automatic-module-name spring.webmvc Medium Vendor pom artifactid spring-webmvc Highest Vendor pom artifactid spring-webmvc Low Vendor pom developer email jhoeller@pivotal.io Low Vendor pom developer id jhoeller Medium Vendor pom developer name Juergen Hoeller Medium Vendor pom groupid org.springframework Highest Vendor pom name Spring Web MVC High Vendor pom organization name Spring IO High Vendor pom organization url https://spring.io/projects/spring-framework Medium Vendor pom url spring-projects/spring-framework Highest Product file name spring-webmvc High Product hint analyzer product springsource_spring_framework Highest Product jar package name mvc Highest Product jar package name springframework Highest Product jar package name web Highest Product Manifest automatic-module-name spring.webmvc Medium Product Manifest Implementation-Title spring-webmvc High Product pom artifactid spring-webmvc Highest Product pom developer email jhoeller@pivotal.io Low Product pom developer id jhoeller Low Product pom developer name Juergen Hoeller Low Product pom groupid org.springframework Highest Product pom name Spring Web MVC High Product pom organization name Spring IO Low Product pom organization url https://spring.io/projects/spring-framework Low Product pom url spring-projects/spring-framework High Version file version 5.3.24 High Version Manifest Implementation-Version 5.3.24 High Version pom version 5.3.24 Highest
status.jsFile Path: /var/lib/jenkins/workspace/Christmas/src/main/resources/static/status.jsMD5: c3e02e78339a2a0ae37ca662eef4b66eSHA1: 80ae4922de35efcc3464f8a1e383d96954677264SHA256: 19279a8e7970844e5ce9f6c0e36504f6613e89a8bf72bc9303d670b38659d3caReferenced In Project/Scope: Christmas
Evidence Type Source Name Value Confidence
stomp-websocket-2.3.4.jarDescription:
WebJar for stomp-websocket License:
Apache License 2.0: https://github.com/jmesnil/stomp-websocket/blob/master/LICENSE.txt File Path: /var/lib/jenkins/.m2/repository/org/webjars/stomp-websocket/2.3.4/stomp-websocket-2.3.4.jar
MD5: 6e0289546dca193c17cccf60785ba52d
SHA1: 3ad3cfafb03f4fb4c94c1e4287c17f2713ae5bf5
SHA256: 3ccc3a8b3cc7ecbb073da62c88888452bda80a0fc576025b09c1ae26388ae74c
Referenced In Project/Scope: Christmas:compile
stomp-websocket-2.3.4.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/christmas@1.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name stomp-websocket High Vendor pom artifactid stomp-websocket Highest Vendor pom artifactid stomp-websocket Low Vendor pom developer email james@jamesward.com Low Vendor pom developer id jamesward Medium Vendor pom developer name James Ward Medium Vendor pom groupid org.webjars Highest Vendor pom name stomp-websocket High Vendor pom url http://webjars.org Highest Product file name stomp-websocket High Product pom artifactid stomp-websocket Highest Product pom developer email james@jamesward.com Low Product pom developer id jamesward Low Product pom developer name James Ward Low Product pom groupid org.webjars Highest Product pom name stomp-websocket High Product pom url http://webjars.org Medium Version file version 2.3.4 High Version pom version 2.3.4 Highest
stomp-websocket-2.3.4.jar: stomp.jsFile Path: /var/lib/jenkins/.m2/repository/org/webjars/stomp-websocket/2.3.4/stomp-websocket-2.3.4.jar/META-INF/resources/webjars/stomp-websocket/2.3.4/stomp.jsMD5: 808dec911f89464647fda5335c3861deSHA1: 6e0d813034b8301058b4d52930803963ea35778dSHA256: 5512d05690bd60f8a12388a01866db106a7f42559866f0b0d44f117373e8dfa5Referenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
stomp-websocket-2.3.4.jar: stomp.min.jsFile Path: /var/lib/jenkins/.m2/repository/org/webjars/stomp-websocket/2.3.4/stomp-websocket-2.3.4.jar/META-INF/resources/webjars/stomp-websocket/2.3.4/stomp.min.jsMD5: 408353c4a57ed88b804323b0ccf9aa66SHA1: aaec0bfdfb8ebb6306e543ea50201082af1f9b88SHA256: 2f8855dc95d620e84c905253e22ba28771a48bbf82ef8448465f8b4ca6b3ff26Referenced In Project/Scope: Christmas:compile
Evidence Type Source Name Value Confidence
thymeleaf-3.0.14.RELEASE.jarDescription:
Modern server-side Java template engine for both web and standalone environments License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/lib/jenkins/.m2/repository/org/thymeleaf/thymeleaf/3.0.14.RELEASE/thymeleaf-3.0.14.RELEASE.jar
MD5: a8c7b9ae46eb161d763e26761b84db60
SHA1: 05ec84717bf76bcbcc133f9f19bab754f97b92f8
SHA256: 30871e0ce3177a984c273878440188aa55fb28aa1742e148136ce2fe04017053
Referenced In Project/Scope: Christmas:compile
thymeleaf-3.0.14.RELEASE.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/christmas@1.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name thymeleaf High Vendor jar package name engine Highest Vendor jar package name thymeleaf Highest Vendor Manifest automatic-module-name thymeleaf Medium Vendor Manifest build-jdk-spec 11 Low Vendor Manifest Implementation-Vendor The THYMELEAF team High Vendor Manifest specification-vendor The THYMELEAF team Low Vendor pom artifactid thymeleaf Highest Vendor pom artifactid thymeleaf Low Vendor pom developer email daniel.fernandez AT 11thlabs DOT org Low Vendor pom developer email emanuelrabina AT gmail DOT com Low Vendor pom developer email jmiguelsamper AT users DOT sourceforge DOT net Low Vendor pom developer id danielfernandez Medium Vendor pom developer id jmiguelsamper Medium Vendor pom developer id ultraq Medium Vendor pom developer name Daniel Fernandez Medium Vendor pom developer name Emanuel Rabina Medium Vendor pom developer name Jose Miguel Samper Medium Vendor pom groupid org.thymeleaf Highest Vendor pom name thymeleaf High Vendor pom organization name The THYMELEAF team High Vendor pom organization url http://www.thymeleaf.org Medium Vendor pom url http://www.thymeleaf.org Highest Product file name thymeleaf High Product jar package name engine Highest Product jar package name thymeleaf Highest Product Manifest automatic-module-name thymeleaf Medium Product Manifest build-jdk-spec 11 Low Product Manifest Implementation-Title thymeleaf High Product Manifest specification-title thymeleaf Medium Product pom artifactid thymeleaf Highest Product pom developer email daniel.fernandez AT 11thlabs DOT org Low Product pom developer email emanuelrabina AT gmail DOT com Low Product pom developer email jmiguelsamper AT users DOT sourceforge DOT net Low Product pom developer id danielfernandez Low Product pom developer id jmiguelsamper Low Product pom developer id ultraq Low Product pom developer name Daniel Fernandez Low Product pom developer name Emanuel Rabina Low Product pom developer name Jose Miguel Samper Low Product pom groupid org.thymeleaf Highest Product pom name thymeleaf High Product pom organization name The THYMELEAF team Low Product pom organization url http://www.thymeleaf.org Low Product pom url http://www.thymeleaf.org Medium Version Manifest Implementation-Version 3.0.14.RELEASE High Version pom version 3.0.14.RELEASE Highest
Related Dependencies thymeleaf-spring5-3.0.14.RELEASE.jarFile Path: /var/lib/jenkins/.m2/repository/org/thymeleaf/thymeleaf-spring5/3.0.14.RELEASE/thymeleaf-spring5-3.0.14.RELEASE.jar MD5: d14bef61c611c367a9dce63f2194c667 SHA1: 0a0588f30a1e7dcadfc5c260ef6c6078ef377384 SHA256: 5620bcbc326cd6fc4ae7935a6c46a7b87ef8d61de76bc852ca49f1648b6eb4bc pkg:maven/org.thymeleaf/thymeleaf-spring5@3.0.14.RELEASE thymeleaf-extras-java8time-3.0.4.RELEASE.jarDescription:
Modern server-side Java template engine for both web and standalone environments License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/lib/jenkins/.m2/repository/org/thymeleaf/extras/thymeleaf-extras-java8time/3.0.4.RELEASE/thymeleaf-extras-java8time-3.0.4.RELEASE.jar
MD5: 01420fcda7481663f967836c440f9bc5
SHA1: 36e7175ddce36c486fff4578b5af7bb32f54f5df
SHA256: c07690c764329afd148a4134980d636911390a3fda45f6c6ae46517e4b4444d3
Referenced In Project/Scope: Christmas:compile
thymeleaf-extras-java8time-3.0.4.RELEASE.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/christmas@1.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name thymeleaf-extras-java8time High Vendor jar package name extras Highest Vendor jar package name java8time Highest Vendor jar package name thymeleaf Highest Vendor Manifest automatic-module-name thymeleaf.extras.java8time Medium Vendor Manifest implementation-url http://www.thymeleaf.org Low Vendor Manifest Implementation-Vendor The THYMELEAF team High Vendor Manifest Implementation-Vendor-Id org.thymeleaf.extras Medium Vendor Manifest specification-vendor The THYMELEAF team Low Vendor pom artifactid thymeleaf-extras-java8time Highest Vendor pom artifactid thymeleaf-extras-java8time Low Vendor pom developer email daniel.fernandez AT 11thlabs DOT org Low Vendor pom developer email emanuelrabina AT gmail DOT com Low Vendor pom developer email jmiguelsamper AT users DOT sourceforge DOT net Low Vendor pom developer id danielfernandez Medium Vendor pom developer id jmiguelsamper Medium Vendor pom developer id ultraq Medium Vendor pom developer name Daniel Fernandez Medium Vendor pom developer name Emanuel Rabina Medium Vendor pom developer name Jose Miguel Samper Medium Vendor pom groupid org.thymeleaf.extras Highest Vendor pom name thymeleaf-extras-java8time High Vendor pom organization name The THYMELEAF team High Vendor pom organization url http://www.thymeleaf.org Medium Vendor pom url http://www.thymeleaf.org Highest Product file name thymeleaf-extras-java8time High Product jar package name extras Highest Product jar package name java8time Highest Product jar package name thymeleaf Highest Product Manifest automatic-module-name thymeleaf.extras.java8time Medium Product Manifest Implementation-Title thymeleaf-extras-java8time High Product Manifest implementation-url http://www.thymeleaf.org Low Product Manifest specification-title thymeleaf-extras-java8time Medium Product pom artifactid thymeleaf-extras-java8time Highest Product pom developer email daniel.fernandez AT 11thlabs DOT org Low Product pom developer email emanuelrabina AT gmail DOT com Low Product pom developer email jmiguelsamper AT users DOT sourceforge DOT net Low Product pom developer id danielfernandez Low Product pom developer id jmiguelsamper Low Product pom developer id ultraq Low Product pom developer name Daniel Fernandez Low Product pom developer name Emanuel Rabina Low Product pom developer name Jose Miguel Samper Low Product pom groupid org.thymeleaf.extras Highest Product pom name thymeleaf-extras-java8time High Product pom organization name The THYMELEAF team Low Product pom organization url http://www.thymeleaf.org Low Product pom url http://www.thymeleaf.org Medium Version Manifest Implementation-Version 3.0.4.RELEASE High Version pom version 3.0.4.RELEASE Highest
thymeleaf-extras-springsecurity5-3.0.4.RELEASE.jarDescription:
Modern server-side Java template engine for both web and standalone environments License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/lib/jenkins/.m2/repository/org/thymeleaf/extras/thymeleaf-extras-springsecurity5/3.0.4.RELEASE/thymeleaf-extras-springsecurity5-3.0.4.RELEASE.jar
MD5: 83c28331b1c3cb5b4a6d3fc2ecad2f39
SHA1: 88bb10bf73ce285208dd848e8eb17f897ebb02d4
SHA256: 774c93e2256dbebdfd7039fac72af016b485321870d4a6efe9dfcb01d1acf9aa
Referenced In Project/Scope: Christmas:compile
thymeleaf-extras-springsecurity5-3.0.4.RELEASE.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/christmas@1.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name thymeleaf-extras-springsecurity5 High Vendor jar package name extras Highest Vendor jar package name springsecurity5 Highest Vendor jar package name thymeleaf Highest Vendor Manifest automatic-module-name thymeleaf.extras.springsecurity5 Medium Vendor Manifest implementation-url http://www.thymeleaf.org Low Vendor Manifest Implementation-Vendor The THYMELEAF team High Vendor Manifest Implementation-Vendor-Id org.thymeleaf.extras Medium Vendor Manifest specification-vendor The THYMELEAF team Low Vendor pom artifactid thymeleaf-extras-springsecurity5 Highest Vendor pom artifactid thymeleaf-extras-springsecurity5 Low Vendor pom developer email daniel.fernandez AT 11thlabs DOT org Low Vendor pom developer email emanuelrabina AT gmail DOT com Low Vendor pom developer email jmiguelsamper AT users DOT sourceforge DOT net Low Vendor pom developer id danielfernandez Medium Vendor pom developer id jmiguelsamper Medium Vendor pom developer id ultraq Medium Vendor pom developer name Daniel Fernandez Medium Vendor pom developer name Emanuel Rabina Medium Vendor pom developer name Jose Miguel Samper Medium Vendor pom groupid org.thymeleaf.extras Highest Vendor pom name thymeleaf-extras-springsecurity5 High Vendor pom organization name The THYMELEAF team High Vendor pom organization url http://www.thymeleaf.org Medium Vendor pom url http://www.thymeleaf.org Highest Product file name thymeleaf-extras-springsecurity5 High Product jar package name extras Highest Product jar package name springsecurity5 Highest Product jar package name thymeleaf Highest Product Manifest automatic-module-name thymeleaf.extras.springsecurity5 Medium Product Manifest Implementation-Title thymeleaf-extras-springsecurity5 High Product Manifest implementation-url http://www.thymeleaf.org Low Product Manifest specification-title thymeleaf-extras-springsecurity5 Medium Product pom artifactid thymeleaf-extras-springsecurity5 Highest Product pom developer email daniel.fernandez AT 11thlabs DOT org Low Product pom developer email emanuelrabina AT gmail DOT com Low Product pom developer email jmiguelsamper AT users DOT sourceforge DOT net Low Product pom developer id danielfernandez Low Product pom developer id jmiguelsamper Low Product pom developer id ultraq Low Product pom developer name Daniel Fernandez Low Product pom developer name Emanuel Rabina Low Product pom developer name Jose Miguel Samper Low Product pom groupid org.thymeleaf.extras Highest Product pom name thymeleaf-extras-springsecurity5 High Product pom organization name The THYMELEAF team Low Product pom organization url http://www.thymeleaf.org Low Product pom url http://www.thymeleaf.org Medium Version Manifest Implementation-Version 3.0.4.RELEASE High Version pom version 3.0.4.RELEASE Highest
tomcat-annotations-api-9.0.70.jarDescription:
Annotations Package License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/lib/jenkins/.m2/repository/org/apache/tomcat/tomcat-annotations-api/9.0.70/tomcat-annotations-api-9.0.70.jar
MD5: 065c09cad9e3abe47b7ad9fb713891f5
SHA1: 1edfc99d53345c39db23166b4e1c4c0438eb0e14
SHA256: 8a97174b89d4ec76b58189bd04d390dede64955eb094f5247cd3425e44a06266
Referenced In Project/Scope: Christmas:compile
tomcat-annotations-api-9.0.70.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.apache.tomcat.embed/tomcat-embed-core@9.0.70
Evidence Type Source Name Value Confidence Vendor file name tomcat-annotations-api High Vendor Manifest bundle-symbolicname org.apache.tomcat-annotations-api Medium Vendor Manifest provide-capability osgi.contract;osgi.contract=JavaAnnotation;version:List="1.3,1.2,1.1,1";uses:="javax.annotation,javax.annotation.security,javax.annotation.sql" Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor manifest: javax/annotation/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/annotation/security/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/annotation/sql/ Implementation-Vendor Apache Software Foundation Medium Vendor pom artifactid tomcat-annotations-api Highest Vendor pom artifactid tomcat-annotations-api Low Vendor pom groupid org.apache.tomcat Highest Vendor pom url https://tomcat.apache.org/ Highest Product file name tomcat-annotations-api High Product jar package name annotation Highest Product jar package name javax Highest Product jar package name security Highest Product jar package name sql Highest Product Manifest Bundle-Name tomcat-annotations-api Medium Product Manifest bundle-symbolicname org.apache.tomcat-annotations-api Medium Product Manifest provide-capability osgi.contract;osgi.contract=JavaAnnotation;version:List="1.3,1.2,1.1,1";uses:="javax.annotation,javax.annotation.security,javax.annotation.sql" Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product manifest: javax/annotation/ Implementation-Title javax.annotation Medium Product manifest: javax/annotation/ Specification-Title Common Annotations Medium Product manifest: javax/annotation/security/ Implementation-Title javax.annotation Medium Product manifest: javax/annotation/security/ Specification-Title Common Annotations Medium Product manifest: javax/annotation/sql/ Implementation-Title javax.annotation Medium Product manifest: javax/annotation/sql/ Specification-Title Common Annotations Medium Product pom artifactid tomcat-annotations-api Highest Product pom groupid org.apache.tomcat Highest Product pom url https://tomcat.apache.org/ Medium Version file version 9.0.70 High Version Manifest Bundle-Version 9.0.70 High Version pom version 9.0.70 Highest
tomcat-embed-core-9.0.70.jarDescription:
Core Tomcat implementation License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/lib/jenkins/.m2/repository/org/apache/tomcat/embed/tomcat-embed-core/9.0.70/tomcat-embed-core-9.0.70.jar
MD5: 14029f7d29f7c3c9af9a6b86afcc8a56
SHA1: 517f236dc4e45ecec94d8bf1c7037f952ad1e316
SHA256: 7ee65d82f60a69a5634dffef9fcbbb1a573b8dae3f4a418656336f8bc99334fc
Referenced In Project/Scope: Christmas:compile
tomcat-embed-core-9.0.70.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/christmas@1.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name tomcat-embed-core High Vendor jar package name apache Highest Vendor jar package name core Highest Vendor jar package name tomcat Highest Vendor Manifest bundle-symbolicname org.apache.tomcat-embed-core Medium Vendor Manifest Implementation-Vendor Apache Software Foundation High Vendor Manifest provide-capability osgi.contract;osgi.contract=JavaJASPIC;version:List="1.1,1";uses:="javax.security.auth.message,javax.security.auth.message.callback,javax.security.auth.message.config,javax.security.auth.message.module",osgi.contract;osgi.contract=JavaServlet;version:List="4.0,3.1,3,2.5";uses:="javax.servlet,javax.servlet.annotation,javax.servlet.descriptor,javax.servlet.http,javax.servlet.resources" Low Vendor Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.processor)(version>=1.0.0)(!(version>=2.0.0)))",osgi.serviceloader;filter:="(osgi.serviceloader=org.apache.juli.logging.Log)";osgi.serviceloader="org.apache.juli.logging.Log",osgi.contract;osgi.contract=JavaAnnotation;filter:="(&(osgi.contract=JavaAnnotation)(version=1.3.0))",osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest specification-vendor Apache Software Foundation Low Vendor manifest: javax/security/auth/message/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/security/auth/message/callback/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/security/auth/message/config/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/security/auth/message/module/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/servlet/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/servlet/annotation/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/servlet/descriptor/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/servlet/http/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/servlet/resources/ Implementation-Vendor Apache Software Foundation Medium Vendor pom artifactid tomcat-embed-core Highest Vendor pom artifactid tomcat-embed-core Low Vendor pom groupid org.apache.tomcat.embed Highest Vendor pom url https://tomcat.apache.org/ Highest Product file name tomcat-embed-core High Product jar package name annotation Highest Product jar package name apache Highest Product jar package name auth Highest Product jar package name core Highest Product jar package name descriptor Highest Product jar package name filter Highest Product jar package name http Highest Product jar package name java Highest Product jar package name javax Highest Product jar package name juli Highest Product jar package name logging Highest Product jar package name message Highest Product jar package name processor Highest Product jar package name security Highest Product jar package name servlet Highest Product jar package name servlets Highest Product jar package name tomcat Highest Product Manifest Bundle-Name tomcat-embed-core Medium Product Manifest bundle-symbolicname org.apache.tomcat-embed-core Medium Product Manifest Implementation-Title Apache Tomcat High Product Manifest provide-capability osgi.contract;osgi.contract=JavaJASPIC;version:List="1.1,1";uses:="javax.security.auth.message,javax.security.auth.message.callback,javax.security.auth.message.config,javax.security.auth.message.module",osgi.contract;osgi.contract=JavaServlet;version:List="4.0,3.1,3,2.5";uses:="javax.servlet,javax.servlet.annotation,javax.servlet.descriptor,javax.servlet.http,javax.servlet.resources" Low Product Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.processor)(version>=1.0.0)(!(version>=2.0.0)))",osgi.serviceloader;filter:="(osgi.serviceloader=org.apache.juli.logging.Log)";osgi.serviceloader="org.apache.juli.logging.Log",osgi.contract;osgi.contract=JavaAnnotation;filter:="(&(osgi.contract=JavaAnnotation)(version=1.3.0))",osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Apache Tomcat Medium Product manifest: javax/security/auth/message/ Implementation-Title javax.security.auth.message Medium Product manifest: javax/security/auth/message/ Specification-Title Java Authentication SPI for Containers Medium Product manifest: javax/security/auth/message/callback/ Implementation-Title javax.security.auth.message Medium Product manifest: javax/security/auth/message/callback/ Specification-Title Java Authentication SPI for Containers Medium Product manifest: javax/security/auth/message/config/ Implementation-Title javax.security.auth.message Medium Product manifest: javax/security/auth/message/config/ Specification-Title Java Authentication SPI for Containers Medium Product manifest: javax/security/auth/message/module/ Implementation-Title javax.security.auth.message Medium Product manifest: javax/security/auth/message/module/ Specification-Title Java Authentication SPI for Containers Medium Product manifest: javax/servlet/ Implementation-Title javax.servlet Medium Product manifest: javax/servlet/ Specification-Title Java API for Servlets Medium Product manifest: javax/servlet/annotation/ Implementation-Title javax.servlet Medium Product manifest: javax/servlet/annotation/ Specification-Title Java API for Servlets Medium Product manifest: javax/servlet/descriptor/ Implementation-Title javax.servlet Medium Product manifest: javax/servlet/descriptor/ Specification-Title Java API for Servlets Medium Product manifest: javax/servlet/http/ Implementation-Title javax.servlet Medium Product manifest: javax/servlet/http/ Specification-Title Java API for Servlets Medium Product manifest: javax/servlet/resources/ Implementation-Title javax.servlet Medium Product manifest: javax/servlet/resources/ Specification-Title Java API for Servlets Medium Product pom artifactid tomcat-embed-core Highest Product pom groupid org.apache.tomcat.embed Highest Product pom url https://tomcat.apache.org/ Medium Version file version 9.0.70 High Version Manifest Bundle-Version 9.0.70 High Version Manifest Implementation-Version 9.0.70 High Version pom version 9.0.70 Highest
Related Dependencies tomcat-embed-websocket-9.0.70.jarFile Path: /var/lib/jenkins/.m2/repository/org/apache/tomcat/embed/tomcat-embed-websocket/9.0.70/tomcat-embed-websocket-9.0.70.jar MD5: 8fe5883c98f31b2d7cecaa329d430fda SHA1: 3dbd48222828d4123b74abb3664eb84c388e9832 SHA256: e2dfda01e5b17d320e6e0acb5f02c9663ee85aa5175e3961b43057b1e7441071 pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@9.0.70 txw2-2.3.7.jarDescription:
TXW is a library that allows you to write XML documents.
File Path: /var/lib/jenkins/.m2/repository/org/glassfish/jaxb/txw2/2.3.7/txw2-2.3.7.jarMD5: d7d7c63bc636c072394334c85cb6d49fSHA1: 55cddcac1945150e09b09b0f89d86799652eee82SHA256: 4a52d7c42a7e6270c8d72554eb994059f53d69c2545fb2daa02c6e9bfbda8b22Referenced In Project/Scope: Christmas:compiletxw2-2.3.7.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-data-jpa@2.7.6
Evidence Type Source Name Value Confidence Vendor file name txw2 High Vendor jar package name sun Highest Vendor jar package name txw Highest Vendor jar package name txw2 Highest Vendor jar package name xml Highest Vendor jar (hint) package name oracle Highest Vendor Manifest git-revision cb2da3e Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor Manifest Implementation-Vendor-Id org.eclipse Medium Vendor pom artifactid txw2 Highest Vendor pom artifactid txw2 Low Vendor pom groupid org.glassfish.jaxb Highest Vendor pom name TXW2 Runtime High Vendor pom parent-artifactid jaxb-txw-parent Low Vendor pom parent-groupid com.sun.xml.bind.mvn Medium Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest Product file name txw2 High Product jar package name sun Highest Product jar package name txw Highest Product jar package name txw2 Highest Product jar package name xml Highest Product Manifest git-revision cb2da3e Low Product Manifest Implementation-Title Jakarta XML Binding Implementation High Product Manifest specification-title Jakarta XML Binding Medium Product pom artifactid txw2 Highest Product pom groupid org.glassfish.jaxb Highest Product pom name TXW2 Runtime High Product pom parent-artifactid jaxb-txw-parent Medium Product pom parent-groupid com.sun.xml.bind.mvn Medium Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium Version file version 2.3.7 High Version Manifest build-id 2.3.7 Medium Version Manifest Implementation-Version 2.3.7 High Version Manifest major-version 2.3.7 Medium Version pom version 2.3.7 Highest
unbescape-1.1.6.RELEASE.jarDescription:
Advanced yet easy-to-use escape/unescape library for Java License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /var/lib/jenkins/.m2/repository/org/unbescape/unbescape/1.1.6.RELEASE/unbescape-1.1.6.RELEASE.jar
MD5: d95ed94e1624e307a1958ee105ccbf39
SHA1: 7b90360afb2b860e09e8347112800d12c12b2a13
SHA256: 597cf87d5b1a4f385b9d1cec974b7b483abb3ee85fc5b3f8b62af8e4bec95c2c
Referenced In Project/Scope: Christmas:compile
unbescape-1.1.6.RELEASE.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.thymeleaf/thymeleaf@3.0.14.RELEASE
Evidence Type Source Name Value Confidence Vendor file name unbescape High Vendor jar package name java Highest Vendor jar package name unbescape Highest Vendor Manifest automatic-module-name unbescape Medium Vendor Manifest bundle-docurl http://www.unbescape.org Low Vendor Manifest bundle-symbolicname org.unbescape Medium Vendor Manifest implementation-url http://www.unbescape.org Low Vendor Manifest Implementation-Vendor The UNBESCAPE team High Vendor Manifest Implementation-Vendor-Id org.unbescape Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest specification-vendor The UNBESCAPE team Low Vendor pom artifactid unbescape Highest Vendor pom artifactid unbescape Low Vendor pom developer email daniel.fernandez AT 11thlabs DOT org Low Vendor pom developer id danielfernandez Medium Vendor pom developer name Daniel Fernandez Medium Vendor pom groupid org.unbescape Highest Vendor pom name unbescape High Vendor pom organization name The UNBESCAPE team High Vendor pom organization url http://www.unbescape.org Medium Vendor pom url http://www.unbescape.org Highest Product file name unbescape High Product jar package name java Highest Product jar package name unbescape Highest Product Manifest automatic-module-name unbescape Medium Product Manifest bundle-docurl http://www.unbescape.org Low Product Manifest Bundle-Name unbescape Medium Product Manifest bundle-symbolicname org.unbescape Medium Product Manifest Implementation-Title unbescape High Product Manifest implementation-url http://www.unbescape.org Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest specification-title unbescape Medium Product pom artifactid unbescape Highest Product pom developer email daniel.fernandez AT 11thlabs DOT org Low Product pom developer id danielfernandez Low Product pom developer name Daniel Fernandez Low Product pom groupid org.unbescape Highest Product pom name unbescape High Product pom organization name The UNBESCAPE team Low Product pom organization url http://www.unbescape.org Low Product pom url http://www.unbescape.org Medium Version Manifest Bundle-Version 1.1.6.RELEASE High Version Manifest Implementation-Version 1.1.6.RELEASE High Version pom version 1.1.6.RELEASE Highest
webjars-locator-core-0.52.jarDescription:
WebJar Locator Core functionality License:
MIT: https://github.com/webjars/webjars-locator-core/blob/master/LICENSE.md File Path: /var/lib/jenkins/.m2/repository/org/webjars/webjars-locator-core/0.52/webjars-locator-core-0.52.jar
MD5: 3d59bac81b958e289ac3c84eb8a644c6
SHA1: f219134c6b8d4aebfea70f135b2f80dc2794253f
SHA256: 67c83f3678411a7085a0d1e1ad3d82d0adb23376579b3f127b8c6b433d2a6d4f
Referenced In Project/Scope: Christmas:compile
webjars-locator-core-0.52.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/christmas@1.0-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name webjars-locator-core High Vendor jar package name webjars Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor pom artifactid webjars-locator-core Highest Vendor pom artifactid webjars-locator-core Low Vendor pom developer email james@jamesward.org Low Vendor pom developer id jamesward Medium Vendor pom developer name James Ward Medium Vendor pom groupid org.webjars Highest Vendor pom name webjars-locator-core High Vendor pom url http://webjars.org Highest Product file name webjars-locator-core High Product jar package name webjars Highest Product Manifest build-jdk-spec 1.8 Low Product pom artifactid webjars-locator-core Highest Product pom developer email james@jamesward.org Low Product pom developer id jamesward Low Product pom developer name James Ward Low Product pom groupid org.webjars Highest Product pom name webjars-locator-core High Product pom url http://webjars.org Medium Version file version 0.52 High Version pom version 0.52 Highest
zxcvbn-1.7.0.jarDescription:
This is a java port of zxcvbn, which is a JavaScript password strength generator. License:
MIT License: http://www.opensource.org/licenses/mit-license.php File Path: /var/lib/jenkins/.m2/repository/com/nulab-inc/zxcvbn/1.7.0/zxcvbn-1.7.0.jar
MD5: 7d5add15d8148460335adca8409a3d07
SHA1: d452b43bbdd959c5b98216af02881b7a348fa2de
SHA256: 9531c91e91fae6e664d6e9708274b1be46008841bf50d4b6b1614fbb9b130de5
Referenced In Project/Scope: Christmas:compile
zxcvbn-1.7.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.flasby/FlasbyUtil@1.0.15-SNAPSHOT
Evidence Type Source Name Value Confidence Vendor file name zxcvbn High Vendor jar package name strength Highest Vendor jar package name zxcvbn Highest Vendor Manifest multi-release true Low Vendor pom artifactid zxcvbn Highest Vendor pom artifactid zxcvbn Low Vendor pom developer email yuichi.watanabe@nulab-inc.com Low Vendor pom developer id vvatanabe Medium Vendor pom developer name Yuichi Watanabe Medium Vendor pom groupid com.nulab-inc Highest Vendor pom name zxcvbn4j High Vendor pom url nulab/zxcvbn4j Highest Product file name zxcvbn High Product jar package name strength Highest Product jar package name zxcvbn Highest Product Manifest Implementation-Title zxcvbn High Product Manifest multi-release true Low Product pom artifactid zxcvbn Highest Product pom developer email yuichi.watanabe@nulab-inc.com Low Product pom developer id vvatanabe Low Product pom developer name Yuichi Watanabe Low Product pom groupid com.nulab-inc Highest Product pom name zxcvbn4j High Product pom url nulab/zxcvbn4j High Version file version 1.7.0 High Version Manifest Implementation-Version 1.7.0 High Version pom version 1.7.0 Highest