Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.

How to read the report | Suppressing false positives | Getting Help: github issues

 Sponsor

Project: com.github.pmonks/asf-cat 2.0.116

Scan Information (show all):

Summary

Display: Showing Vulnerable Dependencies (click to show all)

DependencyVulnerability IDsPackageHighest SeverityCVE CountConfidenceEvidence Count
clj-base62-0.1.1.jarpkg:maven/miikka/clj-base62@0.1.1 012
clj-spdx-1.0.126.jarpkg:maven/com.github.pmonks/clj-spdx@1.0.126 020
clj-xml-validation-1.0.2.jarpkg:maven/clj-xml-validation/clj-xml-validation@1.0.2 012
clojure-1.11.1.jarpkg:maven/org.clojure/clojure@1.11.1 021
commons-beanutils-1.9.4.jarcpe:2.3:a:apache:commons_beanutils:1.9.4:*:*:*:*:*:*:*pkg:maven/commons-beanutils/commons-beanutils@1.9.4 0Highest167
commons-collections-3.2.2.jarcpe:2.3:a:apache:commons_collections:3.2.2:*:*:*:*:*:*:*pkg:maven/commons-collections/commons-collections@3.2.2 0Highest83
commons-digester-2.1.jarpkg:maven/commons-digester/commons-digester@2.1 097
commons-lang3-3.5.jarpkg:maven/org.apache.commons/commons-lang3@3.5 0138
commons-logging-1.3.0.jarpkg:maven/commons-logging/commons-logging@1.3.0 0128
commons-validator-1.8.0.jarpkg:maven/commons-validator/commons-validator@1.8.0 0129
core.specs.alpha-0.2.62.jarcpe:2.3:a:alex_project:alex:0.2.62:*:*:*:*:*:*:*pkg:maven/org.clojure/core.specs.alpha@0.2.62 0Low17
data.xml-0.2.0-alpha8.jarpkg:maven/org.clojure/data.xml@0.2.0-alpha8 028
gson-2.8.9.jarcpe:2.3:a:google:gson:2.8.9:*:*:*:*:*:*:*pkg:maven/com.google.code.gson/gson@2.8.9 0Highest28
hato-0.9.0.jarpkg:maven/hato/hato@0.9.0 017
instaparse-1.4.12.jarpkg:maven/instaparse/instaparse@1.4.12 017
java-spdx-library-1.1.10.jarpkg:maven/org.spdx/java-spdx-library@1.1.10 036
jsoup-1.15.3.jarcpe:2.3:a:jsoup:jsoup:1.15.3:*:*:*:*:*:*:*pkg:maven/org.jsoup/jsoup@1.15.3 0Highest39
jsr305-3.0.2.jarpkg:maven/com.google.code.findbugs/jsr305@3.0.2 016
lice-comb-2.0.240.jarpkg:maven/com.github.pmonks/lice-comb@2.0.240 020
medley-1.7.0.jarpkg:maven/dev.weavejester/medley@1.7.0 015
rencg-1.0.34.jarpkg:maven/com.github.pmonks/rencg@1.0.34 020
slf4j-api-2.0.9.jarpkg:maven/org.slf4j/slf4j-api@2.0.9 028
spec.alpha-0.3.218.jarpkg:maven/org.clojure/spec.alpha@0.3.218 026
tools.logging-1.2.4.jarcpe:2.3:a:alex_project:alex:1.2.4:*:*:*:*:*:*:*pkg:maven/org.clojure/tools.logging@1.2.4 0Low15
xml-in-0.1.1.jarpkg:maven/tolitius/xml-in@0.1.1 012

Dependencies (vulnerable)

clj-base62-0.1.1.jar

Description:

Base62 encoding and decoding for Clojure

File Path: /home/runner/.m2/repository/miikka/clj-base62/0.1.1/clj-base62-0.1.1.jar
MD5: 4d1ff2cba176169428c21fb9ddab0528
SHA1: e983866be496ce97fc442c07561be31cf1d95ecd
SHA256:b835393a3ef4d3f45574824f42d1fcc7980378971b484cd1994d70cbb0d54862

Identifiers

clj-spdx-1.0.126.jar

Description:

Clojure wrapper around spdx/Spdx-Java-Library.

License:

Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/com/github/pmonks/clj-spdx/1.0.126/clj-spdx-1.0.126.jar
MD5: 65201a17402214c8e3e84a9b15df914a
SHA1: b1ea26cc9d31ebdd877b1b25c6193075a9f31f01
SHA256:2432c7285aad096932d89e434690de065de4fe586a48efdb4aec4ecba8dc9094

Identifiers

clj-xml-validation-1.0.2.jar

Description:

Simple XML Schema validation library for Clojure

License:

Eclipse Public License: http://www.eclipse.org/legal/epl-v10.html
File Path: /home/runner/.m2/repository/clj-xml-validation/clj-xml-validation/1.0.2/clj-xml-validation-1.0.2.jar
MD5: ab69483eecdcab00c0eaa011b056c351
SHA1: be28bbe42941f00acfa073e986fa7b386a7c4f2d
SHA256:e4210b7290f38bf90ce0dfb6c4398b74f54c7636baef37598c05e2852b59bf43

Identifiers

clojure-1.11.1.jar

Description:

Clojure core environment and runtime library.

License:

Eclipse Public License 1.0: http://opensource.org/licenses/eclipse-1.0.php
File Path: /home/runner/.m2/repository/org/clojure/clojure/1.11.1/clojure-1.11.1.jar
MD5: 88321e4272aa5e10d2b803f47944e27c
SHA1: 2896bc72c90da8125026c0e61df0470a084f9ec3
SHA256:2381b6e9423ab465151455944903d13a56243d6006b9194afc1bf4f8710cb4de

Identifiers

commons-beanutils-1.9.4.jar

Description:

Apache Commons BeanUtils provides an easy-to-use but flexible wrapper around reflection and introspection.

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/commons-beanutils/commons-beanutils/1.9.4/commons-beanutils-1.9.4.jar
MD5: 07dc532ee316fe1f2f0323e9bd2f8df4
SHA1: d52b9abcd97f38c81342bb7e7ae1eee9b73cba51
SHA256:7d938c81789028045c08c065e94be75fc280527620d5bd62b519d5838532368a

Identifiers

commons-collections-3.2.2.jar

Description:

Types that extend and augment the Java Collections Framework.

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/commons-collections/commons-collections/3.2.2/commons-collections-3.2.2.jar
MD5: f54a8510f834a1a57166970bfc982e94
SHA1: 8ad72fe39fa8c91eaaf12aadb21e0c3661fe26d5
SHA256:eeeae917917144a68a741d4c0dff66aa5c5c5fd85593ff217bced3fc8ca783b8

Identifiers

commons-digester-2.1.jar

Description:

    The Digester package lets you configure an XML to Java object mapping module
    which triggers certain actions called rules whenever a particular 
    pattern of nested XML elements is recognized.
  

License:

http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/commons-digester/commons-digester/2.1/commons-digester-2.1.jar
MD5: 528445033f22da28f5047b6abcd1c7c9
SHA1: 73a8001e7a54a255eef0f03521ec1805dc738ca0
SHA256:e0b2b980a84fc6533c5ce291f1917b32c507f62bcad64198fff44368c2196a3d

Identifiers

commons-lang3-3.5.jar

Description:

  Apache Commons Lang, a package of Java utility classes for the
  classes that are in java.lang's hierarchy, or are considered to be so
  standard as to justify existence in java.lang.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/apache/commons/commons-lang3/3.5/commons-lang3-3.5.jar
MD5: 780b5a8b72eebe6d0dbff1c11b5658fa
SHA1: 6c6c702c89bfff3cd9e80b04d668c5e190d588c6
SHA256:8ac96fc686512d777fca85e144f196cd7cfe0c0aec23127229497d1a38ff651c

Identifiers

commons-logging-1.3.0.jar

Description:

Apache Commons Logging is a thin adapter allowing configurable bridging to other,
    well known logging systems.

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/commons-logging/commons-logging/1.3.0/commons-logging-1.3.0.jar
MD5: 522cc4b1f42b7db1554474cb989adfb2
SHA1: f5e064b541f5c5fbc5e4fb49c4e8cd4eabb3afd6
SHA256:66d3c980470b99b0c511dad3dfc0ae7b265ec1fb144e96bc0253a8a175fd34d9

Identifiers

commons-validator-1.8.0.jar

Description:

    Apache Commons Validator provides the building blocks for both client side validation and server side data validation.
    It may be used standalone or with a framework like Struts.
  

License:

https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/commons-validator/commons-validator/1.8.0/commons-validator-1.8.0.jar
MD5: 28fac5309e05b1ce9d83285a8500cad2
SHA1: 49bb9f45e0aa3c8b2261394c76675fba6f20d2e4
SHA256:1292e4bd956936461a6096b094400f5c2a946267c2e20324512ac7532c0c6eb3

Identifiers

core.specs.alpha-0.2.62.jar

Description:

Specs for clojure.core

License:

Eclipse Public License 1.0: http://opensource.org/licenses/eclipse-1.0.php
File Path: /home/runner/.m2/repository/org/clojure/core.specs.alpha/0.2.62/core.specs.alpha-0.2.62.jar
MD5: b1e37e6e8efdade6b7c2a4dd17c0d437
SHA1: a2a7ea21a695561924bc8506f3feb5d8c8f894d5
SHA256:06eea8c070bbe45c158567e443439681bc8c46e9123414f81bfa32ba42d6cbc8

Identifiers

data.xml-0.2.0-alpha8.jar

Description:

Functions to parse XML into lazy sequences and lazy trees and emit these as text

File Path: /home/runner/.m2/repository/org/clojure/data.xml/0.2.0-alpha8/data.xml-0.2.0-alpha8.jar
MD5: ecf740cd730cad5fdbaf16e401027290
SHA1: c3dd8907b0a63a67082bc3091e304d9e1676d4b0
SHA256:b5b10c4f6df654c36c610f2b218cd8f52af3b2677ef9ffb5a3f901ab9fbb3a95

Identifiers

gson-2.8.9.jar

Description:

Gson JSON library

License:

Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/google/code/gson/gson/2.8.9/gson-2.8.9.jar
MD5: e67627f67e03301092dc7de0a2d7cef8
SHA1: 8a432c1d6825781e21a02db2e2c33c5fde2833b9
SHA256:d3999291855de495c94c743761b8ab5176cfeabe281a5ab0d8e8d45326fd703e

Identifiers

hato-0.9.0.jar

Description:

An HTTP client for Clojure, wrapping JDK 11's HttpClient.

License:

The MIT License: http://opensource.org/licenses/mit-license.php
File Path: /home/runner/.m2/repository/hato/hato/0.9.0/hato-0.9.0.jar
MD5: 3439dcca378712fa26e9927acf1f7bc8
SHA1: d47dec2b0e8fb631d95e89864df4abc1fdcd7bc3
SHA256:5e798c88abc14aaf3f6664dfdc2677b2d5ad366d000df8714adbba0dfcd00c9b

Identifiers

instaparse-1.4.12.jar

Description:

Instaparse: No grammar left behind

License:

Eclipse Public License: http://www.eclipse.org/legal/epl-v10.html
File Path: /home/runner/.m2/repository/instaparse/instaparse/1.4.12/instaparse-1.4.12.jar
MD5: ef15595aeb81ea2592a624a4c8fb30a9
SHA1: fdb360826edec1cc2c13c6c8a5397f115bdcf952
SHA256:139f78bff278f1b2d9804d785911d23451e5bcb042580ecadec4400ceb55decd

Identifiers

java-spdx-library-1.1.10.jar

Description:

Java library which implements the Java object model for SPDX and provides useful helper functions.

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/spdx/java-spdx-library/1.1.10/java-spdx-library-1.1.10.jar
MD5: 9bf5e91b0e94b6bdf21291d8d73ab2b7
SHA1: 0dc9e7af93007c88b98388209d231be2f838cb45
SHA256:ef116816a4d221933d34d9f113fd47f6780bca2b0c826545081d742f4e7178fb

Identifiers

jsoup-1.15.3.jar

Description:

jsoup is a Java library for working with real-world HTML. It provides a very convenient API for fetching URLs and extracting and manipulating data, using the best of HTML5 DOM methods and CSS selectors. jsoup implements the WHATWG HTML5 specification, and parses HTML to the same DOM as modern browsers do.

License:

The MIT License: https://jsoup.org/license
File Path: /home/runner/.m2/repository/org/jsoup/jsoup/1.15.3/jsoup-1.15.3.jar
MD5: 4f16c3b17b8c1b0173b1ed9f99f2c27c
SHA1: f6e1d8a8819f854b681c8eaa57fd59a42329e10c
SHA256:e20a5e78b1372f2a4e620832db4442d5077e5cbde280b24c666a3770844999bc

Identifiers

jsr305-3.0.2.jar

Description:

JSR305 Annotations for Findbugs

License:

The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/google/code/findbugs/jsr305/3.0.2/jsr305-3.0.2.jar
MD5: dd83accb899363c32b07d7a1b2e4ce40
SHA1: 25ea2e8b0c338a877313bd4672d3fe056ea78f0d
SHA256:766ad2a0783f2687962c8ad74ceecc38a28b9f72a2d085ee438b7813e928d0c7

Identifiers

lice-comb-2.0.240.jar

Description:

A Clojure library for software license detection.

License:

Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/com/github/pmonks/lice-comb/2.0.240/lice-comb-2.0.240.jar
MD5: 68abf2b19efb8053c7be928e3ba1b74f
SHA1: d724cc604a30fa4e7bfcf1fb8ce6b213329bc15b
SHA256:5508f92eda3846ae61bd483b4d03932d3abf34dfe803310fdb39de4749de9f56

Identifiers

medley-1.7.0.jar

Description:

A lightweight library of useful, mostly pure functions

License:

Eclipse Public License: http://www.eclipse.org/legal/epl-v10.html
File Path: /home/runner/.m2/repository/dev/weavejester/medley/1.7.0/medley-1.7.0.jar
MD5: 249ee290d7e2251e43d8e0ffe5eada0d
SHA1: 5f2d2bec8700ba4fceceb5445afc4024e05c87d0
SHA256:4e620275b5f0f0811262bc0d245f7f2532acb5256848300866a5f5e6f621775a

Identifiers

rencg-1.0.34.jar

Description:

A micro-library for Clojure that provides first class support for named-capturing groups in regular expressions.

License:

Apache-2.0: http://www.apache.org/licenses/LICENSE-2.0.html
File Path: /home/runner/.m2/repository/com/github/pmonks/rencg/1.0.34/rencg-1.0.34.jar
MD5: 5d0dd6a9dd68c9307e0acf0a54e380e7
SHA1: 68cef55ad7c6cc3ac4149b3ac05ab15ccfd65755
SHA256:542310b5862368809b238b3d15c9b04eb21d1b44c79750beee14de11bb48a5f6

Identifiers

slf4j-api-2.0.9.jar

Description:

The slf4j API

License:

http://www.opensource.org/licenses/mit-license.php
File Path: /home/runner/.m2/repository/org/slf4j/slf4j-api/2.0.9/slf4j-api-2.0.9.jar
MD5: 45630e54b0f0ac2b3c80462515ad8fda
SHA1: 7cf2726fdcfbc8610f9a71fb3ed639871f315340
SHA256:0818930dc8d7debb403204611691da58e49d42c50b6ffcfdce02dadb7c3c2b6c

Identifiers

spec.alpha-0.3.218.jar

Description:

Specification of data and functions

License:

Eclipse Public License 1.0: http://opensource.org/licenses/eclipse-1.0.php
File Path: /home/runner/.m2/repository/org/clojure/spec.alpha/0.3.218/spec.alpha-0.3.218.jar
MD5: ecdbb58e7a95163c1369ef9fa054013d
SHA1: a7dad492f8d6cf657d82dcd6b31bda0899f1ac0e
SHA256:67ec898eb55c66a957a55279dd85d1376bb994bd87668b2b0de1eb3b97e8aae0

Identifiers

tools.logging-1.2.4.jar

File Path: /home/runner/.m2/repository/org/clojure/tools.logging/1.2.4/tools.logging-1.2.4.jar
MD5: 0c96fb5aa6fc3a19e3a8fd9456968780
SHA1: 3a85764aa30c434a5b0375a2ee72924aa040fa66
SHA256:46fe0a3cd0234980be7fed8e437b1de107beaea4953194be8f71ba3b048f1929

Identifiers

xml-in-0.1.1.jar

Description:

your friendly XML navigator

License:

Eclipse Public License: http://www.eclipse.org/legal/epl-v10.html
File Path: /home/runner/.m2/repository/tolitius/xml-in/0.1.1/xml-in-0.1.1.jar
MD5: 754502ef9d8c1574d6d893b22f6101dc
SHA1: 0a68865842a0fa7484bca3a7be33f182d8213a97
SHA256:43ab632812fe03b86b1a154723d809bb393e11a0ff0e6677167f14ece40f5543

Identifiers



This report contains data retrieved from the National Vulnerability Database.
This report may contain data retrieved from the CISA Known Exploited Vulnerability Catalog.
This report may contain data retrieved from the Github Advisory Database (via NPM Audit API).
This report may contain data retrieved from RetireJS.
This report may contain data retrieved from the Sonatype OSS Index.