Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 12.2.0
Report Generated On : Mon, 19 Jan 2026 20:54:41 GMT
Dependencies Scanned : 60 (33 unique)
Vulnerable Dependencies : 0
Vulnerabilities Found : 0
Vulnerabilities Suppressed : 0
...
NVD API Last Checked : 2026-01-19T20:29:50Z
NVD API Last Modified : 2026-01-19T20:15:49Z
Summary
Summary of Vulnerable Dependencies (click to show all)
caffeine-3.2.3.jar
Description:
A high performance caching library
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/github/ben-manes/caffeine/caffeine/3.2.3/caffeine-3.2.3.jar
MD5: 0258f45d43968523cc11beeb01b240f2
SHA1: c097f0f6d21a0e6db88ea55836e26419b30dfe19
SHA256: ca70c90a5d1ce1511880ce9c93d4ad22108f61111d3daf91eb52762b571bd179
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
caffeine-3.2.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-spring-security7@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name caffeine High
Vendor jar package name cache Highest
Vendor jar package name caffeine Highest
Vendor jar package name github Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-symbolicname com.github.ben-manes.caffeine Medium
Vendor pom artifactid caffeine Highest
Vendor pom artifactid caffeine Low
Vendor pom developer email ben.manes@gmail.com Low
Vendor pom developer id ben-manes Medium
Vendor pom developer name Ben Manes Medium
Vendor pom groupid com.github.ben-manes.caffeine Highest
Vendor pom name Caffeine cache High
Vendor pom url ben-manes/caffeine Highest
Product file name caffeine High
Product jar package name cache Highest
Product jar package name caffeine Highest
Product jar package name github Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Bundle-Name com.github.ben-manes.caffeine Medium
Product Manifest bundle-symbolicname com.github.ben-manes.caffeine Medium
Product Manifest Implementation-Title A high performance caching library High
Product pom artifactid caffeine Highest
Product pom developer email ben.manes@gmail.com Low
Product pom developer id ben-manes Low
Product pom developer name Ben Manes Low
Product pom groupid com.github.ben-manes.caffeine Highest
Product pom name Caffeine cache High
Product pom url ben-manes/caffeine High
Version file version 3.2.3 High
Version Manifest Bundle-Version 3.2.3 High
Version Manifest Implementation-Version 3.2.3 High
Version pom version 3.2.3 Highest
pkg:maven/com.github.ben-manes.caffeine/caffeine@3.2.3
(Confidence :High)
checker-qual-3.53.0.jar
Description:
checker-qual contains annotations (type qualifiers) that a programmerwrites to specify Java code for type-checking by the Checker Framework.
License:
The MIT License: http://opensource.org/licenses/MIT
File Path: /home/runner/.m2/repository/org/checkerframework/checker-qual/3.53.0/checker-qual-3.53.0.jar
MD5: d1ee2a3366a19a8fff01208da2adb48e
SHA1: af1105964a03d7ed8aaf8ea2cb6ec0da7ec6c7a6
SHA256: 7ca002815d92fad79e966b375c2ee7b2b4bf953024bc9a5d5e0c59df13ff5af8
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
checker-qual-3.53.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.hazendaz.jmockit/jmockit@2.1.0
Evidence
Type Source Name Value Confidence
Vendor file name checker-qual High
Vendor jar package name checker Highest
Vendor jar package name checkerframework Highest
Vendor jar package name framework Highest
Vendor jar package name qual Highest
Vendor Manifest bundle-symbolicname checker-qual Medium
Vendor Manifest implementation-url https://checkerframework.org Low
Vendor pom artifactid checker-qual Highest
Vendor pom artifactid checker-qual Low
Vendor pom developer email mernst@cs.washington.edu Low
Vendor pom developer email smillst@cs.washington.edu Low
Vendor pom developer id mernst Medium
Vendor pom developer id smillst Medium
Vendor pom developer name Michael Ernst Medium
Vendor pom developer name Suzanne Millstein Medium
Vendor pom developer org University of Washington Medium
Vendor pom developer org URL https://www.cs.washington.edu/ Medium
Vendor pom groupid org.checkerframework Highest
Vendor pom name Checker Qual High
Vendor pom url https://checkerframework.org/ Highest
Product file name checker-qual High
Product jar package name checker Highest
Product jar package name checkerframework Highest
Product jar package name framework Highest
Product jar package name qual Highest
Product Manifest Bundle-Name checker-qual Medium
Product Manifest bundle-symbolicname checker-qual Medium
Product Manifest implementation-url https://checkerframework.org Low
Product pom artifactid checker-qual Highest
Product pom developer email mernst@cs.washington.edu Low
Product pom developer email smillst@cs.washington.edu Low
Product pom developer id mernst Low
Product pom developer id smillst Low
Product pom developer name Michael Ernst Low
Product pom developer name Suzanne Millstein Low
Product pom developer org University of Washington Low
Product pom developer org URL https://www.cs.washington.edu/ Low
Product pom groupid org.checkerframework Highest
Product pom name Checker Qual High
Product pom url https://checkerframework.org/ Medium
Version file version 3.53.0 High
Version Manifest Bundle-Version 3.53.0 High
Version Manifest Implementation-Version 3.53.0 High
Version pom version 3.53.0 Highest
pkg:maven/org.checkerframework/checker-qual@3.53.0
(Confidence :High)
com.github.waffle:waffle-jna-jakarta:3.6.0-SNAPSHOT
Description:
WAFFLE JNA Jakarta Pakage implementation
License:
MIT https://raw.github.com/Waffle/waffle/master/LICENSE
File Path: /home/runner/work/waffle/waffle/Source/JNA/waffle-jna-jakarta/pom.xml
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4
com.github.waffle:waffle-jna-jakarta:3.6.0-SNAPSHOT is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-spring-boot-autoconfigure4@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name pom High
Vendor project artifactid waffle-jna-jakarta Low
Vendor project groupid com.github.waffle Highest
Product file name pom High
Product project artifactid waffle-jna-jakarta Highest
Product project groupid com.github.waffle Low
pkg:maven/com.github.waffle/waffle-jna-jakarta@3.6.0-SNAPSHOT
(Confidence :Highest)
com.github.waffle:waffle-spring-security7:3.6.0-SNAPSHOT
Description:
Spring Security 7 integration for WAFFLE
License:
MIT https://raw.github.com/Waffle/waffle/master/LICENSE
File Path: /home/runner/work/waffle/waffle/Source/JNA/waffle-spring-security7/pom.xml
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4
com.github.waffle:waffle-spring-security7:3.6.0-SNAPSHOT is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-spring-boot-autoconfigure4@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name pom High
Vendor project artifactid waffle-spring-security7 Low
Vendor project groupid com.github.waffle Highest
Product file name pom High
Product project artifactid waffle-spring-security7 Highest
Product project groupid com.github.waffle Low
pkg:maven/com.github.waffle/waffle-spring-security7@3.6.0-SNAPSHOT
(Confidence :Highest)
commons-logging-1.3.5.jar
Description:
Apache Commons Logging is a thin adapter allowing configurable bridging to other,
well-known logging systems.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/commons-logging/commons-logging/1.3.5/commons-logging-1.3.5.jar
MD5: 9ca067b073153c86c2da350c0f2cdf70
SHA1: a3fcc5d3c29b2b03433aa2d2f2d2c1b1638924a1
SHA256: 6d7a744e4027649fbb50895df9497d109f98c766a637062fe8d2eabbb3140ba4
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
commons-logging-1.3.5.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-spring-boot-autoconfigure4@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name commons-logging High
Vendor jar package name apache Highest
Vendor jar package name commons Highest
Vendor jar package name logging Highest
Vendor Manifest automatic-module-name org.apache.commons.logging Medium
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-logging/ Low
Vendor Manifest bundle-symbolicname org.apache.commons.commons-logging Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid commons-logging Highest
Vendor pom artifactid commons-logging Low
Vendor pom developer email baliuka@apache.org Low
Vendor pom developer email costin@apache.org Low
Vendor pom developer email craigmcc@apache.org Low
Vendor pom developer email dennisl@apache.org Low
Vendor pom developer email donaldp@apache.org Low
Vendor pom developer email ggregory at apache.org Low
Vendor pom developer email morgand@apache.org Low
Vendor pom developer email rdonkin@apache.org Low
Vendor pom developer email rsitze@apache.org Low
Vendor pom developer email rwaldhoff@apache.org Low
Vendor pom developer email sanders@apache.org Low
Vendor pom developer email skitching@apache.org Low
Vendor pom developer email tn@apache.org Low
Vendor pom developer id baliuka Medium
Vendor pom developer id bstansberry Medium
Vendor pom developer id costin Medium
Vendor pom developer id craigmcc Medium
Vendor pom developer id dennisl Medium
Vendor pom developer id donaldp Medium
Vendor pom developer id ggregory Medium
Vendor pom developer id morgand Medium
Vendor pom developer id rdonkin Medium
Vendor pom developer id rsitze Medium
Vendor pom developer id rwaldhoff Medium
Vendor pom developer id sanders Medium
Vendor pom developer id skitching Medium
Vendor pom developer id tn Medium
Vendor pom developer name Brian Stansberry Medium
Vendor pom developer name Costin Manolache Medium
Vendor pom developer name Craig McClanahan Medium
Vendor pom developer name Dennis Lundberg Medium
Vendor pom developer name Gary Gregory Medium
Vendor pom developer name Juozas Baliuka Medium
Vendor pom developer name Morgan Delagrange Medium
Vendor pom developer name Peter Donald Medium
Vendor pom developer name Richard Sitze Medium
Vendor pom developer name Robert Burrell Donkin Medium
Vendor pom developer name Rodney Waldhoff Medium
Vendor pom developer name Scott Sanders Medium
Vendor pom developer name Simon Kitching Medium
Vendor pom developer name Thomas Neidhart Medium
Vendor pom developer org Apache Medium
Vendor pom developer org The Apache Software Foundation Medium
Vendor pom developer org URL https://www.apache.org/ Medium
Vendor pom groupid commons-logging Highest
Vendor pom name Apache Commons Logging High
Vendor pom parent-artifactid commons-parent Low
Vendor pom parent-groupid org.apache.commons Medium
Vendor pom url https://commons.apache.org/proper/commons-logging/ Highest
Product file name commons-logging High
Product jar package name apache Highest
Product jar package name commons Highest
Product jar package name logging Highest
Product Manifest automatic-module-name org.apache.commons.logging Medium
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl https://commons.apache.org/proper/commons-logging/ Low
Product Manifest Bundle-Name Apache Commons Logging Medium
Product Manifest bundle-symbolicname org.apache.commons.commons-logging Medium
Product Manifest Implementation-Title Apache Commons Logging High
Product Manifest multi-release true Low
Product Manifest specification-title Apache Commons Logging Medium
Product pom artifactid commons-logging Highest
Product pom developer email baliuka@apache.org Low
Product pom developer email costin@apache.org Low
Product pom developer email craigmcc@apache.org Low
Product pom developer email dennisl@apache.org Low
Product pom developer email donaldp@apache.org Low
Product pom developer email ggregory at apache.org Low
Product pom developer email morgand@apache.org Low
Product pom developer email rdonkin@apache.org Low
Product pom developer email rsitze@apache.org Low
Product pom developer email rwaldhoff@apache.org Low
Product pom developer email sanders@apache.org Low
Product pom developer email skitching@apache.org Low
Product pom developer email tn@apache.org Low
Product pom developer id baliuka Low
Product pom developer id bstansberry Low
Product pom developer id costin Low
Product pom developer id craigmcc Low
Product pom developer id dennisl Low
Product pom developer id donaldp Low
Product pom developer id ggregory Low
Product pom developer id morgand Low
Product pom developer id rdonkin Low
Product pom developer id rsitze Low
Product pom developer id rwaldhoff Low
Product pom developer id sanders Low
Product pom developer id skitching Low
Product pom developer id tn Low
Product pom developer name Brian Stansberry Low
Product pom developer name Costin Manolache Low
Product pom developer name Craig McClanahan Low
Product pom developer name Dennis Lundberg Low
Product pom developer name Gary Gregory Low
Product pom developer name Juozas Baliuka Low
Product pom developer name Morgan Delagrange Low
Product pom developer name Peter Donald Low
Product pom developer name Richard Sitze Low
Product pom developer name Robert Burrell Donkin Low
Product pom developer name Rodney Waldhoff Low
Product pom developer name Scott Sanders Low
Product pom developer name Simon Kitching Low
Product pom developer name Thomas Neidhart Low
Product pom developer org Apache Low
Product pom developer org The Apache Software Foundation Low
Product pom developer org URL https://www.apache.org/ Low
Product pom groupid commons-logging Highest
Product pom name Apache Commons Logging High
Product pom parent-artifactid commons-parent Medium
Product pom parent-groupid org.apache.commons Medium
Product pom url https://commons.apache.org/proper/commons-logging/ Medium
Version file version 1.3.5 High
Version Manifest Bundle-Version 1.3.5 High
Version Manifest Implementation-Version 1.3.5 High
Version pom parent-version 1.3.5 Low
Version pom version 1.3.5 Highest
pkg:maven/commons-logging/commons-logging@1.3.5
(Confidence :High)
error_prone_annotations-2.46.0.jar
Description:
Error Prone is a static analysis tool for Java that catches common programming mistakes at compile-time.
License:
Apache 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/google/errorprone/error_prone_annotations/2.46.0/error_prone_annotations-2.46.0.jar
MD5: d0dabea249c067d21d7eb997fbdf5c99
SHA1: 4ecb5d2392c38c46e6cb65e1bf60be708d97005d
SHA256: b67be81ff4b956401146e14eaf1526bc435a9480f2546e91eb45b796631a8a99
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:provided
error_prone_annotations-2.46.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-spring-boot-autoconfigure4@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name error_prone_annotations High
Vendor jar package name annotations Highest
Vendor jar package name errorprone Highest
Vendor jar package name google Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl https://errorprone.info/error_prone_annotations Low
Vendor Manifest bundle-symbolicname com.google.errorprone.annotations Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid error_prone_annotations Highest
Vendor pom artifactid error_prone_annotations Low
Vendor pom groupid com.google.errorprone Highest
Vendor pom name error-prone annotations High
Vendor pom parent-artifactid error_prone_parent Low
Product file name error_prone_annotations High
Product jar package name annotations Highest
Product jar package name errorprone Highest
Product jar package name google Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl https://errorprone.info/error_prone_annotations Low
Product Manifest Bundle-Name error-prone annotations Medium
Product Manifest bundle-symbolicname com.google.errorprone.annotations Medium
Product Manifest multi-release true Low
Product pom artifactid error_prone_annotations Highest
Product pom groupid com.google.errorprone Highest
Product pom name error-prone annotations High
Product pom parent-artifactid error_prone_parent Medium
Version file version 2.46.0 High
Version Manifest Bundle-Version 2.46.0 High
Version pom version 2.46.0 Highest
pkg:maven/com.google.errorprone/error_prone_annotations@2.46.0
(Confidence :High)
j2objc-annotations-3.1.jar
Description:
A set of annotations that provide additional information to the J2ObjC
translator to modify the result of translation.
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/google/j2objc/j2objc-annotations/3.1/j2objc-annotations-3.1.jar
MD5: abe8bd3abff622b9a8b15c3a737aa741
SHA1: a892ca9507839bbdb900d64310ac98256cab992f
SHA256: 84d3a150518485f8140ea99b8a985656749629f6433c92b80c75b36aba3b099b
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:provided
j2objc-annotations-3.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-spring-boot-autoconfigure4@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name j2objc-annotations High
Vendor jar package name annotations Highest
Vendor jar package name google Highest
Vendor jar package name j2objc Highest
Vendor Manifest build-jdk-spec 22 Low
Vendor Manifest multi-release true Low
Vendor pom artifactid j2objc-annotations Highest
Vendor pom artifactid j2objc-annotations Low
Vendor pom developer email tball@google.com Low
Vendor pom developer id tomball Medium
Vendor pom developer name Tom Ball Medium
Vendor pom developer org Google Medium
Vendor pom developer org URL https://www.google.com Medium
Vendor pom groupid com.google.j2objc Highest
Vendor pom name J2ObjC Annotations High
Vendor pom url google/j2objc/ Highest
Product file name j2objc-annotations High
Product jar package name annotations Highest
Product jar package name google Highest
Product jar package name j2objc Highest
Product Manifest build-jdk-spec 22 Low
Product Manifest multi-release true Low
Product pom artifactid j2objc-annotations Highest
Product pom developer email tball@google.com Low
Product pom developer id tomball Low
Product pom developer name Tom Ball Low
Product pom developer org Google Low
Product pom developer org URL https://www.google.com Low
Product pom groupid com.google.j2objc Highest
Product pom name J2ObjC Annotations High
Product pom url google/j2objc/ High
Version file version 3.1 High
Version pom version 3.1 Highest
pkg:maven/com.google.j2objc/j2objc-annotations@3.1
(Confidence :High)
jackson-annotations-2.20.jar
Description:
Core annotations used for value types, used by Jackson data binding package.
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/fasterxml/jackson/core/jackson-annotations/2.20/jackson-annotations-2.20.jar
MD5: b901def3c20752817f27130e4b8d6640
SHA1: 6a5e7291ea3f2b590a7ce400adb7b3aea4d7e12c
SHA256: 959a2ffb2d591436f51f183c6a521fc89347912f711bf0cae008cdf045d95319
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
jackson-annotations-2.20.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-web@4.0.1
Evidence
Type Source Name Value Confidence
Vendor file name jackson-annotations High
Vendor jar package name fasterxml Highest
Vendor jar package name jackson Highest
Vendor Manifest build-jdk-spec 1.8 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-annotations Highest
Vendor pom artifactid jackson-annotations Low
Vendor pom groupid com.fasterxml.jackson.core Highest
Vendor pom name Jackson-annotations High
Vendor pom parent-artifactid jackson-parent Low
Vendor pom parent-groupid com.fasterxml.jackson Medium
Vendor pom url FasterXML/jackson Highest
Product file name jackson-annotations High
Product hint analyzer product java8 Highest
Product hint analyzer product modules Highest
Product jar package name fasterxml Highest
Product jar package name jackson Highest
Product Manifest build-jdk-spec 1.8 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Product Manifest Bundle-Name Jackson-annotations Medium
Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium
Product Manifest Implementation-Title Jackson-annotations High
Product Manifest specification-title Jackson-annotations Medium
Product pom artifactid jackson-annotations Highest
Product pom groupid com.fasterxml.jackson.core Highest
Product pom name Jackson-annotations High
Product pom parent-artifactid jackson-parent Medium
Product pom parent-groupid com.fasterxml.jackson Medium
Product pom url FasterXML/jackson High
Version file version 2.20 High
Version Manifest Implementation-Version 2.20 High
Version pom version 2.20 Highest
pkg:maven/com.fasterxml.jackson.core/jackson-annotations@2.20
(Confidence :High)
cpe:2.3:a:fasterxml:jackson-modules-java8:2.20:*:*:*:*:*:*:*
(Confidence :Low)
suppress
jackson-core-3.0.3.jar
Description:
Core Jackson processing abstractions (aka Streaming API), implementation for JSON
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/tools/jackson/core/jackson-core/3.0.3/jackson-core-3.0.3.jar
MD5: 5abfa2ee36fa2833fe40521f851dc08a
SHA1: d208ec73d6a17667a0462cfc3237076a087bc936
SHA256: 4149bb2b3bbffb5339089174e26f454081e6a01a104d24b22f78a16b948799eb
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
jackson-core-3.0.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-web@4.0.1
Evidence
Type Source Name Value Confidence
Vendor file name jackson-core High
Vendor jar package name base Highest
Vendor jar package name core Highest
Vendor jar package name jackson Highest
Vendor jar package name json Highest
Vendor jar package name tools Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Vendor Manifest bundle-symbolicname tools.jackson.core.jackson-core Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id tools.jackson.core Medium
Vendor Manifest multi-release true Low
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-core Highest
Vendor pom artifactid jackson-core Low
Vendor pom developer email tatu@fasterxml.com Low
Vendor pom developer id cowtowncoder Medium
Vendor pom developer name Tatu Saloranta Medium
Vendor pom groupid tools.jackson.core Highest
Vendor pom name Jackson-core High
Vendor pom parent-artifactid jackson-base Low
Vendor pom parent-groupid tools.jackson Medium
Vendor pom url FasterXML/jackson-core Highest
Product file name jackson-core High
Product jar package name 17 Highest
Product jar package name base Highest
Product jar package name core Highest
Product jar package name jackson Highest
Product jar package name json Highest
Product jar package name tools Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low
Product Manifest Bundle-Name Jackson-core Medium
Product Manifest bundle-symbolicname tools.jackson.core.jackson-core Medium
Product Manifest Implementation-Title Jackson-core High
Product Manifest multi-release true Low
Product Manifest specification-title Jackson-core Medium
Product pom artifactid jackson-core Highest
Product pom developer email tatu@fasterxml.com Low
Product pom developer id cowtowncoder Low
Product pom developer name Tatu Saloranta Low
Product pom groupid tools.jackson.core Highest
Product pom name Jackson-core High
Product pom parent-artifactid jackson-base Medium
Product pom parent-groupid tools.jackson Medium
Product pom url FasterXML/jackson-core High
Version file version 3.0.3 High
Version Manifest Bundle-Version 3.0.3 High
Version Manifest Implementation-Version 3.0.3 High
Version pom version 3.0.3 Highest
pkg:maven/tools.jackson.core/jackson-core@3.0.3
(Confidence :High)
jackson-databind-3.0.3.jar
Description:
General data-binding functionality for Jackson: works on core streaming API
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/tools/jackson/core/jackson-databind/3.0.3/jackson-databind-3.0.3.jar
MD5: 445adbd3b97c9638f393d8e3787ba293
SHA1: c024f05711e311341d4338cbb7905696e20921f8
SHA256: dfbb79130910decf063125c1e693a39c5ec8fb8b478d7f39671901d47ce7f6a2
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
jackson-databind-3.0.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-web@4.0.1
Evidence
Type Source Name Value Confidence
Vendor file name jackson-databind High
Vendor jar package name databind Highest
Vendor jar package name jackson Highest
Vendor jar package name tools Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Vendor Manifest bundle-symbolicname tools.jackson.core.jackson-databind Medium
Vendor Manifest Implementation-Vendor FasterXML High
Vendor Manifest Implementation-Vendor-Id tools.jackson.core Medium
Vendor Manifest specification-vendor FasterXML Low
Vendor pom artifactid jackson-databind Highest
Vendor pom artifactid jackson-databind Low
Vendor pom groupid tools.jackson.core Highest
Vendor pom name jackson-databind High
Vendor pom parent-artifactid jackson-base Low
Vendor pom parent-groupid tools.jackson Medium
Vendor pom url FasterXML/jackson Highest
Product file name jackson-databind High
Product jar package name databind Highest
Product jar package name jackson Highest
Product jar package name tools Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-docurl https://github.com/FasterXML/jackson Low
Product Manifest Bundle-Name jackson-databind Medium
Product Manifest bundle-symbolicname tools.jackson.core.jackson-databind Medium
Product Manifest Implementation-Title jackson-databind High
Product Manifest specification-title jackson-databind Medium
Product pom artifactid jackson-databind Highest
Product pom groupid tools.jackson.core Highest
Product pom name jackson-databind High
Product pom parent-artifactid jackson-base Medium
Product pom parent-groupid tools.jackson Medium
Product pom url FasterXML/jackson High
Version file version 3.0.3 High
Version Manifest Bundle-Version 3.0.3 High
Version Manifest Implementation-Version 3.0.3 High
Version pom version 3.0.3 Highest
jakarta.annotation-api-3.0.0.jar
Description:
Jakarta Annotations API
License:
EPL 2.0: https://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html
File Path: /home/runner/.m2/repository/jakarta/annotation/jakarta.annotation-api/3.0.0/jakarta.annotation-api-3.0.0.jar
MD5: 7faffaab962918da4cf5ddfd76609dd2
SHA1: 54f928fadec906a99d558536756d171917b9d936
SHA256: b01f55552284cfb149411e64eabca75e942d26d2e1786b32914250e4330afaa2
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
jakarta.annotation-api-3.0.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-security@4.0.1
Evidence
Type Source Name Value Confidence
Vendor file name jakarta.annotation-api High
Vendor jar package name annotation Highest
Vendor jar package name jakarta Highest
Vendor Manifest build-jdk-spec 18 Low
Vendor Manifest bundle-docurl https://www.eclipse.org Low
Vendor Manifest bundle-symbolicname jakarta.annotation-api Medium
Vendor Manifest extension-name jakarta.annotation Medium
Vendor Manifest Implementation-Vendor Eclipse Foundation High
Vendor Manifest Implementation-Vendor-Id org.glassfish Medium
Vendor Manifest specification-vendor Eclipse Foundation Low
Vendor pom artifactid jakarta.annotation-api Highest
Vendor pom artifactid jakarta.annotation-api Low
Vendor pom developer name Dmitry Kornilov Medium
Vendor pom developer name Linda De Michiel Medium
Vendor pom developer org Oracle Corp. Medium
Vendor pom groupid jakarta.annotation Highest
Vendor pom name Jakarta Annotations API High
Vendor pom parent-artifactid project Low
Vendor pom parent-groupid org.eclipse.ee4j Medium
Vendor pom url https://projects.eclipse.org/projects/ee4j.ca Highest
Product file name jakarta.annotation-api High
Product jar package name annotation Highest
Product jar package name jakarta Highest
Product Manifest build-jdk-spec 18 Low
Product Manifest bundle-docurl https://www.eclipse.org Low
Product Manifest Bundle-Name Jakarta Annotations API Medium
Product Manifest bundle-symbolicname jakarta.annotation-api Medium
Product Manifest extension-name jakarta.annotation Medium
Product pom artifactid jakarta.annotation-api Highest
Product pom developer name Dmitry Kornilov Low
Product pom developer name Linda De Michiel Low
Product pom developer org Oracle Corp. Low
Product pom groupid jakarta.annotation Highest
Product pom name Jakarta Annotations API High
Product pom parent-artifactid project Medium
Product pom parent-groupid org.eclipse.ee4j Medium
Product pom url https://projects.eclipse.org/projects/ee4j.ca Medium
Version file version 3.0.0 High
Version Manifest Bundle-Version 3.0.0 High
Version Manifest Implementation-Version 3.0.0 High
Version pom parent-version 3.0.0 Low
Version pom version 3.0.0 Highest
pkg:maven/jakarta.annotation/jakarta.annotation-api@3.0.0
(Confidence :High)
cpe:2.3:a:oracle:projects:3.0.0:*:*:*:*:*:*:*
(Confidence :Low)
suppress
jna-5.18.1.jar
Description:
Java Native Access
License:
LGPL-2.1-or-later: https://www.gnu.org/licenses/old-licenses/lgpl-2.1
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/net/java/dev/jna/jna/5.18.1/jna-5.18.1.jar
MD5: cb531ec131e1c68c045b5d45fe5b9878
SHA1: b27ba04287cc4abe769642fe8318d39fc89bf937
SHA256: 260c4b1e22b1db9e110ee441c4f13ce115f841fa48c41d78750986214b395557
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
jna-5.18.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-spring-security7@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name jna High
Vendor jar package name jna Highest
Vendor jar package name native Highest
Vendor jar package name sun Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest automatic-module-name com.sun.jna Medium
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-category jni Low
Vendor Manifest bundle-nativecode com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win32, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win32, com/sun/jna/win32-aarch64/jnidispatch.dll; processor=aarch64;osname=win32, com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win, com/sun/jna/win32-aarch64/jnidispatch.dll; processor=aarch64;osname=win, com/sun/jna/w32ce-arm/jnidispatch.dll; processor=arm;osname=wince, com/sun/jna/sunos-x86/libjnidispatch.so; processor=x86;osname=sunos, com/sun/jna/sunos-x86-64/libjnidispatch.so; processor=x86-64;osname=sunos, com/sun/jna/sunos-sparc/libjnidispatch.so; processor=sparc;osname=sunos, com/sun/jna/sunos-sparcv9/libjnidispatch.so; processor=sparcv9;osname=sunos, com/sun/jna/aix-ppc/libjnidispatch.a; processor=ppc;osname=aix, com/sun/jna/aix-ppc64/libjnidispatch.a; processor=ppc64;osname=aix, com/sun/jna/linux-ppc/libjnidispatch.so; processor=ppc;osname=linux, com/sun/jna/linux-ppc64/libjnidispatch.so; processor=ppc64;osname=linux, com/sun/jna/linux-ppc64le/libjnidispatch.so; processor=ppc64le;osname=linux, com/sun/jna/linux-x86/libjnidispatch.so; processor=x86;osname=linux, com/sun/jna/linux-x86-64/libjnidispatch.so; processor=x86-64;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm_le;osname=linux, com/sun/jna/linux-armel/libjnidispatch.so; processor=armel;osname=linux, com/sun/jna/linux-aarch64/libjnidispatch.so; processor=aarch64;osname=linux, com/sun/jna/linux-ia64/libjnidispatch.so; processor=ia64;osname=linux, com/sun/jna/linux-sparcv9/libjnidispatch.so; processor=sparcv9;osname=linux, com/sun/jna/linux-mips64el/libjnidispatch.so; processor=mips64el;osname=linux, com/sun/jna/linux-s390x/libjnidispatch.so; processor=S390x;osname=linux, com/sun/jna/linux-loongarch64/libjnidispatch.so; processor=loongarch64;osname=linux, com/sun/jna/linux-riscv64/libjnidispatch.so; processor=riscv64;osname=linux, com/sun/jna/dragonflybsd-x86-64/libjnidispatch.so; processor=x86-64;osname=dragonflybsd, com/sun/jna/freebsd-x86/libjnidispatch.so; processor=x86;osname=freebsd, com/sun/jna/freebsd-x86-64/libjnidispatch.so; processor=x86-64;osname=freebsd, com/sun/jna/freebsd-aarch64/libjnidispatch.so; processor=aarch64;osname=freebsd, com/sun/jna/freebsd-ppc64le/libjnidispatch.so; processor=ppc64le;osname=freebsd, com/sun/jna/freebsd-ppc64/libjnidispatch.so; processor=ppc64;osname=freebsd, com/sun/jna/openbsd-x86/libjnidispatch.so; processor=x86;osname=openbsd, com/sun/jna/openbsd-x86-64/libjnidispatch.so; processor=x86-64;osname=openbsd, com/sun/jna/darwin-ppc/libjnidispatch.jnilib; osname=macosx;processor=ppc, com/sun/jna/darwin-ppc64/libjnidispatch.jnilib; osname=macosx;processor=ppc64, com/sun/jna/darwin-x86/libjnidispatch.jnilib; osname=macosx;processor=x86, com/sun/jna/darwin-x86-64/libjnidispatch.jnilib; osname=macosx;processor=x86-64, com/sun/jna/darwin-aarch64/libjnidispatch.jnilib; osname=macosx;processor=aarch64 Low
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low
Vendor Manifest bundle-symbolicname com.sun.jna Medium
Vendor Manifest Implementation-Vendor JNA Development Team High
Vendor Manifest specification-vendor JNA Development Team Low
Vendor pom artifactid jna Highest
Vendor pom artifactid jna Low
Vendor pom developer email mblaesing@doppel-helix.eu Low
Vendor pom developer id twall Medium
Vendor pom developer name Matthias Bläsing Medium
Vendor pom developer name Timothy Wall Medium
Vendor pom groupid net.java.dev.jna Highest
Vendor pom name Java Native Access High
Vendor pom url java-native-access/jna Highest
Product file name jna High
Product jar package name jna Highest
Product jar package name library Highest
Product jar package name native Highest
Product jar package name sun Highest
Product jar package name win32 Highest
Product Manifest automatic-module-name com.sun.jna Medium
Product Manifest bundle-activationpolicy lazy Low
Product Manifest bundle-category jni Low
Product Manifest Bundle-Name jna Medium
Product Manifest bundle-nativecode com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win32, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win32, com/sun/jna/win32-aarch64/jnidispatch.dll; processor=aarch64;osname=win32, com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win, com/sun/jna/win32-aarch64/jnidispatch.dll; processor=aarch64;osname=win, com/sun/jna/w32ce-arm/jnidispatch.dll; processor=arm;osname=wince, com/sun/jna/sunos-x86/libjnidispatch.so; processor=x86;osname=sunos, com/sun/jna/sunos-x86-64/libjnidispatch.so; processor=x86-64;osname=sunos, com/sun/jna/sunos-sparc/libjnidispatch.so; processor=sparc;osname=sunos, com/sun/jna/sunos-sparcv9/libjnidispatch.so; processor=sparcv9;osname=sunos, com/sun/jna/aix-ppc/libjnidispatch.a; processor=ppc;osname=aix, com/sun/jna/aix-ppc64/libjnidispatch.a; processor=ppc64;osname=aix, com/sun/jna/linux-ppc/libjnidispatch.so; processor=ppc;osname=linux, com/sun/jna/linux-ppc64/libjnidispatch.so; processor=ppc64;osname=linux, com/sun/jna/linux-ppc64le/libjnidispatch.so; processor=ppc64le;osname=linux, com/sun/jna/linux-x86/libjnidispatch.so; processor=x86;osname=linux, com/sun/jna/linux-x86-64/libjnidispatch.so; processor=x86-64;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm_le;osname=linux, com/sun/jna/linux-armel/libjnidispatch.so; processor=armel;osname=linux, com/sun/jna/linux-aarch64/libjnidispatch.so; processor=aarch64;osname=linux, com/sun/jna/linux-ia64/libjnidispatch.so; processor=ia64;osname=linux, com/sun/jna/linux-sparcv9/libjnidispatch.so; processor=sparcv9;osname=linux, com/sun/jna/linux-mips64el/libjnidispatch.so; processor=mips64el;osname=linux, com/sun/jna/linux-s390x/libjnidispatch.so; processor=S390x;osname=linux, com/sun/jna/linux-loongarch64/libjnidispatch.so; processor=loongarch64;osname=linux, com/sun/jna/linux-riscv64/libjnidispatch.so; processor=riscv64;osname=linux, com/sun/jna/dragonflybsd-x86-64/libjnidispatch.so; processor=x86-64;osname=dragonflybsd, com/sun/jna/freebsd-x86/libjnidispatch.so; processor=x86;osname=freebsd, com/sun/jna/freebsd-x86-64/libjnidispatch.so; processor=x86-64;osname=freebsd, com/sun/jna/freebsd-aarch64/libjnidispatch.so; processor=aarch64;osname=freebsd, com/sun/jna/freebsd-ppc64le/libjnidispatch.so; processor=ppc64le;osname=freebsd, com/sun/jna/freebsd-ppc64/libjnidispatch.so; processor=ppc64;osname=freebsd, com/sun/jna/openbsd-x86/libjnidispatch.so; processor=x86;osname=openbsd, com/sun/jna/openbsd-x86-64/libjnidispatch.so; processor=x86-64;osname=openbsd, com/sun/jna/darwin-ppc/libjnidispatch.jnilib; osname=macosx;processor=ppc, com/sun/jna/darwin-ppc64/libjnidispatch.jnilib; osname=macosx;processor=ppc64, com/sun/jna/darwin-x86/libjnidispatch.jnilib; osname=macosx;processor=x86, com/sun/jna/darwin-x86-64/libjnidispatch.jnilib; osname=macosx;processor=x86-64, com/sun/jna/darwin-aarch64/libjnidispatch.jnilib; osname=macosx;processor=aarch64 Low
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low
Product Manifest bundle-symbolicname com.sun.jna Medium
Product Manifest Implementation-Title com.sun.jna High
Product Manifest specification-title Java Native Access (JNA) Medium
Product pom artifactid jna Highest
Product pom developer email mblaesing@doppel-helix.eu Low
Product pom developer id twall Low
Product pom developer name Matthias Bläsing Low
Product pom developer name Timothy Wall Low
Product pom groupid net.java.dev.jna Highest
Product pom name Java Native Access High
Product pom url java-native-access/jna High
Version file version 5.18.1 High
Version Manifest Bundle-Version 5.18.1 High
Version pom version 5.18.1 Highest
pkg:maven/net.java.dev.jna/jna@5.18.1
(Confidence :High)
cpe:2.3:a:oracle:java_se:5.18.1:*:*:*:*:*:*:*
(Confidence :Low)
suppress
jna-5.18.1.jar: jnidispatch.dll
File Path: /home/runner/.m2/repository/net/java/dev/jna/jna/5.18.1/jna-5.18.1.jar/com/sun/jna/win32-aarch64/jnidispatch.dll
MD5: 302945a811fd8e21bcdd5226c73b6f74
SHA1: 6b05e299ff2b3eb3b7b7aeac44263f715693607c
SHA256: b8f98be314234cf12b5b46c29652f70c0f6abb93ae19b63d3fe2692062aa699d
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
Evidence
Type Source Name Value Confidence
Vendor file name jnidispatch High
Product file name jnidispatch High
jna-5.18.1.jar: jnidispatch.dll
File Path: /home/runner/.m2/repository/net/java/dev/jna/jna/5.18.1/jna-5.18.1.jar/com/sun/jna/win32-x86-64/jnidispatch.dll
MD5: 2d2475f1f026dd54e9f3e787ae4f81da
SHA1: 27ff882ac271db547aee520b38e3ba9aa91e136c
SHA256: 5a7ff949f6d93d86491eb5b26b1cfc60051168a60622650224b89995ac420023
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
Evidence
Type Source Name Value Confidence
Vendor file name jnidispatch High
Product file name jnidispatch High
jna-5.18.1.jar: jnidispatch.dll
File Path: /home/runner/.m2/repository/net/java/dev/jna/jna/5.18.1/jna-5.18.1.jar/com/sun/jna/win32-x86/jnidispatch.dll
MD5: 0caa1ef75a807f9dde05084fa2219a5c
SHA1: 2f5e1cd82cde192905c7510ce99037b67d980640
SHA256: 752d597cee7e95cb517327146bf42f124c0d6c0bc48b3ecc3b1b3b0531a52f44
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
Evidence
Type Source Name Value Confidence
Vendor file name jnidispatch High
Product file name jnidispatch High
jna-platform-5.18.1.jar
Description:
Java Native Access Platform
License:
LGPL-2.1-or-later: https://www.gnu.org/licenses/old-licenses/lgpl-2.1
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/net/java/dev/jna/jna-platform/5.18.1/jna-platform-5.18.1.jar
MD5: a7af00779ec98bfe22dfb07b1532830d
SHA1: dd817f391efc492041c9ae91127527c13750a789
SHA256: ad14c1b1ec4f43d396231219dfa635ebf828f738eac9f890ea1bc07795892d9a
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
jna-platform-5.18.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-spring-security7@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name jna-platform High
Vendor jar package name jna Highest
Vendor jar package name platform Highest
Vendor jar package name sun Highest
Vendor jar (hint) package name oracle Highest
Vendor Manifest automatic-module-name com.sun.jna.platform Medium
Vendor Manifest bundle-category jni Low
Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.4 Low
Vendor Manifest bundle-symbolicname com.sun.jna.platform Medium
Vendor Manifest Implementation-Vendor JNA Development Team High
Vendor Manifest specification-vendor JNA Development Team Low
Vendor pom artifactid jna-platform Highest
Vendor pom artifactid jna-platform Low
Vendor pom developer email mblaesing@doppel-helix.eu Low
Vendor pom developer id twall Medium
Vendor pom developer name Matthias Bläsing Medium
Vendor pom developer name Timothy Wall Medium
Vendor pom groupid net.java.dev.jna Highest
Vendor pom name Java Native Access Platform High
Vendor pom url java-native-access/jna Highest
Product file name jna-platform High
Product jar package name jna Highest
Product jar package name platform Highest
Product jar package name sun Highest
Product Manifest automatic-module-name com.sun.jna.platform Medium
Product Manifest bundle-category jni Low
Product Manifest Bundle-Name jna-platform Medium
Product Manifest bundle-requiredexecutionenvironment J2SE-1.4 Low
Product Manifest bundle-symbolicname com.sun.jna.platform Medium
Product Manifest Implementation-Title com.sun.jna High
Product Manifest specification-title Java Native Access (JNA) Medium
Product pom artifactid jna-platform Highest
Product pom developer email mblaesing@doppel-helix.eu Low
Product pom developer id twall Low
Product pom developer name Matthias Bläsing Low
Product pom developer name Timothy Wall Low
Product pom groupid net.java.dev.jna Highest
Product pom name Java Native Access Platform High
Product pom url java-native-access/jna High
Version file version 5.18.1 High
Version Manifest Bundle-Version 5.18.1 High
Version pom version 5.18.1 Highest
pkg:maven/net.java.dev.jna/jna-platform@5.18.1
(Confidence :High)
jspecify-1.0.0.jar
Description:
An artifact of well-named and well-specified annotations to power static analysis checks
License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/jspecify/jspecify/1.0.0/jspecify-1.0.0.jar
MD5: 9133aba420d0ca3b001dbb6ae9992cf6
SHA1: 7425a601c1c7ec76645a78d22b8c6a627edee507
SHA256: 1fad6e6be7557781e4d33729d49ae1cdc8fdda6fe477bb0cc68ce351eafdfbab
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
jspecify-1.0.0.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.junit.jupiter/junit-jupiter-engine@6.0.1
Evidence
Type Source Name Value Confidence
Vendor file name jspecify High
Vendor jar package name annotations Highest
Vendor jar package name jspecify Highest
Vendor Manifest bundle-docurl https://jspecify.dev/docs/start-here Low
Vendor Manifest bundle-symbolicname org.jspecify.jspecify Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid jspecify Highest
Vendor pom artifactid jspecify Low
Vendor pom developer email kevinb9n@gmail.com Low
Vendor pom developer id kevinb9n Medium
Vendor pom developer name Kevin Bourrillion Medium
Vendor pom groupid org.jspecify Highest
Vendor pom name JSpecify annotations High
Vendor pom url http://jspecify.org/ Highest
Product file name jspecify High
Product jar package name annotations Highest
Product jar package name jspecify Highest
Product Manifest bundle-docurl https://jspecify.dev/docs/start-here Low
Product Manifest Bundle-Name JSpecify annotations Medium
Product Manifest bundle-symbolicname org.jspecify.jspecify Medium
Product Manifest multi-release true Low
Product pom artifactid jspecify Highest
Product pom developer email kevinb9n@gmail.com Low
Product pom developer id kevinb9n Low
Product pom developer name Kevin Bourrillion Low
Product pom groupid org.jspecify Highest
Product pom name JSpecify annotations High
Product pom url http://jspecify.org/ Medium
Version file version 1.0.0 High
Version Manifest Bundle-Version 1.0.0 High
Version Manifest Implementation-Version 1.0.0 High
Version pom version 1.0.0 Highest
pkg:maven/org.jspecify/jspecify@1.0.0
(Confidence :High)
jsr305-3.0.2.jar
Description:
JSR305 Annotations for Findbugs
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/com/google/code/findbugs/jsr305/3.0.2/jsr305-3.0.2.jar
MD5: dd83accb899363c32b07d7a1b2e4ce40
SHA1: 25ea2e8b0c338a877313bd4672d3fe056ea78f0d
SHA256: 766ad2a0783f2687962c8ad74ceecc38a28b9f72a2d085ee438b7813e928d0c7
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:provided
jsr305-3.0.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.spotbugs/spotbugs-annotations@4.9.8
Evidence
Type Source Name Value Confidence
Vendor file name jsr305 High
Vendor Manifest bundle-symbolicname org.jsr-305 Medium
Vendor pom artifactid jsr305 Highest
Vendor pom artifactid jsr305 Low
Vendor pom groupid com.google.code.findbugs Highest
Vendor pom name FindBugs-jsr305 High
Vendor pom url http://findbugs.sourceforge.net/ Highest
Product file name jsr305 High
Product Manifest Bundle-Name FindBugs-jsr305 Medium
Product Manifest bundle-symbolicname org.jsr-305 Medium
Product pom artifactid jsr305 Highest
Product pom groupid com.google.code.findbugs Highest
Product pom name FindBugs-jsr305 High
Product pom url http://findbugs.sourceforge.net/ Medium
Version file version 3.0.2 High
Version Manifest Bundle-Version 3.0.2 High
Version pom version 3.0.2 Highest
pkg:maven/com.google.code.findbugs/jsr305@3.0.2
(Confidence :High)
jul-to-slf4j-2.0.17.jar
Description:
JUL to SLF4J bridge
License:
https://opensource.org/license/mit
File Path: /home/runner/.m2/repository/org/slf4j/jul-to-slf4j/2.0.17/jul-to-slf4j-2.0.17.jar
MD5: a42936c56611e4794c42908fb3d3a647
SHA1: 524cb6ccc2b68a57604750e1ab8b13b5a786a6aa
SHA256: a7afcd23b9cfd1475e55c94f943b808c5922035e7e2c2a5c65a487a4106bc538
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
jul-to-slf4j-2.0.17.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-security@4.0.1
Evidence
Type Source Name Value Confidence
Vendor file name jul-to-slf4j High
Vendor jar package name bridge Highest
Vendor jar package name slf4j Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.slf4j.org Low
Vendor Manifest bundle-symbolicname jul.to.slf4j Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid jul-to-slf4j Highest
Vendor pom artifactid jul-to-slf4j Low
Vendor pom groupid org.slf4j Highest
Vendor pom name JUL to SLF4J bridge High
Vendor pom parent-artifactid slf4j-parent Low
Vendor pom url http://www.slf4j.org Highest
Product file name jul-to-slf4j High
Product jar package name bridge Highest
Product jar package name slf4j Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.slf4j.org Low
Product Manifest Bundle-Name JUL to SLF4J bridge Medium
Product Manifest bundle-symbolicname jul.to.slf4j Medium
Product Manifest Implementation-Title jul-to-slf4j High
Product Manifest multi-release true Low
Product pom artifactid jul-to-slf4j Highest
Product pom groupid org.slf4j Highest
Product pom name JUL to SLF4J bridge High
Product pom parent-artifactid slf4j-parent Medium
Product pom url http://www.slf4j.org Medium
Version file version 2.0.17 High
Version Manifest Bundle-Version 2.0.17 High
Version Manifest Implementation-Version 2.0.17 High
Version pom version 2.0.17 Highest
pkg:maven/org.slf4j/jul-to-slf4j@2.0.17
(Confidence :High)
log4j-api-2.25.3.jar
Description:
The logging API of the Log4j project.
Library and application code can log through this API.
It contains a simple built-in implementation (`SimpleLogger`) for trivial use cases.
Production applications are recommended to use Log4j API in combination with a fully-fledged implementation, such as Log4j Core.
License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/apache/logging/log4j/log4j-api/2.25.3/log4j-api-2.25.3.jar
MD5: 7061652b4274beeaa657ec908e83f491
SHA1: fb385330d89c2d61058ef649403f214633569205
SHA256: e886682920fa0fb9d6eb6395dcb4de088443f8646c89c5e5846e168e327f406f
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
log4j-api-2.25.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-security@4.0.1
Evidence
Type Source Name Value Confidence
Vendor file name log4j-api High
Vendor jar package name apache Highest
Vendor jar package name log4j Highest
Vendor jar package name logging Highest
Vendor jar package name org Highest
Vendor jar package name simple Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-symbolicname org.apache.logging.log4j.api Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest multi-release true Low
Vendor Manifest provide-capability osgi.service;objectClass:List="org.apache.logging.log4j.util.PropertySource";effective:=active,osgi.serviceloader;osgi.serviceloader="org.apache.logging.log4j.util.PropertySource";register:="org.apache.logging.log4j.util.EnvironmentPropertySource",osgi.serviceloader;osgi.serviceloader="org.apache.logging.log4j.util.PropertySource";register:="org.apache.logging.log4j.util.SystemPropertiesPropertySource" Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid log4j-api Highest
Vendor pom artifactid log4j-api Low
Vendor pom groupid org.apache.logging.log4j Highest
Vendor pom name Apache Log4j API High
Vendor pom parent-artifactid log4j Low
Vendor pom url https://logging.apache.org/log4j/2.x/ Highest
Product file name log4j-api High
Product jar package name apache Highest
Product jar package name log4j Highest
Product jar package name logging Highest
Product jar package name org Highest
Product jar package name simple Highest
Product jar package name util Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest Bundle-Name Apache Log4j API Medium
Product Manifest bundle-symbolicname org.apache.logging.log4j.api Medium
Product Manifest Implementation-Title Apache Log4j API High
Product Manifest multi-release true Low
Product Manifest provide-capability osgi.service;objectClass:List="org.apache.logging.log4j.util.PropertySource";effective:=active,osgi.serviceloader;osgi.serviceloader="org.apache.logging.log4j.util.PropertySource";register:="org.apache.logging.log4j.util.EnvironmentPropertySource",osgi.serviceloader;osgi.serviceloader="org.apache.logging.log4j.util.PropertySource";register:="org.apache.logging.log4j.util.SystemPropertiesPropertySource" Low
Product Manifest specification-title Apache Log4j API Medium
Product pom artifactid log4j-api Highest
Product pom groupid org.apache.logging.log4j Highest
Product pom name Apache Log4j API High
Product pom parent-artifactid log4j Medium
Product pom url https://logging.apache.org/log4j/2.x/ Medium
Version file version 2.25.3 High
Version Manifest Bundle-Version 2.25.3 High
Version Manifest Implementation-Version 2.25.3 High
Version pom version 2.25.3 Highest
log4j-to-slf4j-2.25.3.jar
Description:
Forwards the Log4j API calls to SLF4J.
(Refer to the `log4j-slf4j[2]-impl` artifacts for forwarding SLF4J to the Log4j API.)
License:
Apache-2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/apache/logging/log4j/log4j-to-slf4j/2.25.3/log4j-to-slf4j-2.25.3.jar
MD5: f515a81b64474e5faf389ab8611e123a
SHA1: 30adfb40cca243ec88cf7ec1fddb411ab55faa4f
SHA256: 90a09280390c54a28ac1514ded7c5293f3fe62f4448bf371b4e2415272e67a3d
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
log4j-to-slf4j-2.25.3.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-security@4.0.1
Evidence
Type Source Name Value Confidence
Vendor file name log4j-to-slf4j High
Vendor jar package name apache Highest
Vendor jar package name logging Highest
Vendor jar package name slf4j Highest
Vendor Manifest build-jdk-spec 17 Low
Vendor Manifest bundle-activationpolicy lazy Low
Vendor Manifest bundle-symbolicname org.apache.logging.log4j.to.slf4j Medium
Vendor Manifest Implementation-Vendor The Apache Software Foundation High
Vendor Manifest multi-release false Low
Vendor Manifest provide-capability osgi.service;objectClass:List="org.apache.logging.log4j.spi.Provider";effective:=active,osgi.serviceloader;osgi.serviceloader="org.apache.logging.log4j.spi.Provider";register:="org.apache.logging.slf4j.SLF4JProvider" Low
Vendor Manifest specification-vendor The Apache Software Foundation Low
Vendor pom artifactid log4j-to-slf4j Highest
Vendor pom artifactid log4j-to-slf4j Low
Vendor pom groupid org.apache.logging.log4j Highest
Vendor pom name Log4j API to SLF4J Adapter High
Vendor pom parent-artifactid log4j Low
Vendor pom url https://logging.apache.org/log4j/2.x/ Highest
Product file name log4j-to-slf4j High
Product jar package name apache Highest
Product jar package name logging Highest
Product jar package name slf4j Highest
Product jar package name slf4jprovider Highest
Product Manifest build-jdk-spec 17 Low
Product Manifest bundle-activationpolicy lazy Low
Product Manifest Bundle-Name Log4j API to SLF4J Adapter Medium
Product Manifest bundle-symbolicname org.apache.logging.log4j.to.slf4j Medium
Product Manifest Implementation-Title Log4j API to SLF4J Adapter High
Product Manifest multi-release false Low
Product Manifest provide-capability osgi.service;objectClass:List="org.apache.logging.log4j.spi.Provider";effective:=active,osgi.serviceloader;osgi.serviceloader="org.apache.logging.log4j.spi.Provider";register:="org.apache.logging.slf4j.SLF4JProvider" Low
Product Manifest specification-title Log4j API to SLF4J Adapter Medium
Product pom artifactid log4j-to-slf4j Highest
Product pom groupid org.apache.logging.log4j Highest
Product pom name Log4j API to SLF4J Adapter High
Product pom parent-artifactid log4j Medium
Product pom url https://logging.apache.org/log4j/2.x/ Medium
Version file version 2.25.3 High
Version Manifest Bundle-Version 2.25.3 High
Version Manifest Implementation-Version 2.25.3 High
Version pom version 2.25.3 Highest
pkg:maven/org.apache.logging.log4j/log4j-to-slf4j@2.25.3
(Confidence :High)
logback-core-1.5.22.jar
Description:
logback-core module
License:
http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html
File Path: /home/runner/.m2/repository/ch/qos/logback/logback-core/1.5.22/logback-core-1.5.22.jar
MD5: a001d8dfa6910cbeb38fa7714778a046
SHA1: 7c3ee4420b36bd499fa4f9f18a81d54a64fe0218
SHA256: 7561b7a525364612966ff3823f8c62a81a3262742d455301f479273ef55570b8
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
logback-core-1.5.22.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-security@4.0.1
Evidence
Type Source Name Value Confidence
Vendor file name logback-core High
Vendor jar package name ch Highest
Vendor jar package name core Highest
Vendor jar package name logback Highest
Vendor jar package name qos Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.qos.ch Low
Vendor Manifest bundle-symbolicname ch.qos.logback.core Medium
Vendor Manifest Implementation-Vendor QOS.ch High
Vendor Manifest multi-release true Low
Vendor Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low
Vendor Manifest specification-vendor QOS.ch Low
Vendor pom artifactid logback-core Highest
Vendor pom artifactid logback-core Low
Vendor pom groupid ch.qos.logback Highest
Vendor pom name Logback Core Module High
Vendor pom parent-artifactid logback-parent Low
Product file name logback-core High
Product jar package name 21 Highest
Product jar package name ch Highest
Product jar package name core Highest
Product jar package name logback Highest
Product jar package name qos Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.qos.ch Low
Product Manifest Bundle-Name Logback Core Module Medium
Product Manifest bundle-symbolicname ch.qos.logback.core Medium
Product Manifest Implementation-Title Logback Core Module High
Product Manifest multi-release true Low
Product Manifest originally-created-by Apache Maven Bundle Plugin 5.1.9 Low
Product Manifest specification-title Logback Core Module Medium
Product pom artifactid logback-core Highest
Product pom groupid ch.qos.logback Highest
Product pom name Logback Core Module High
Product pom parent-artifactid logback-parent Medium
Version file version 1.5.22 High
Version Manifest Bundle-Version 1.5.22 High
Version Manifest Implementation-Version 1.5.22 High
Version pom version 1.5.22 Highest
Related Dependencies
logback-classic-1.5.22.jar
File Path: /home/runner/.m2/repository/ch/qos/logback/logback-classic/1.5.22/logback-classic-1.5.22.jar
MD5: eeb5c0f0a24fd772111fab1dd559038d
SHA1: b5212de704deea1a38a41a2bf8de274e7c9cd653
SHA256: 875f31c4b4dc49808e503490701a21cee3e7279800d9c76601da82685342e54b
pkg:maven/ch.qos.logback/logback-classic@1.5.22
micrometer-commons-1.16.1.jar
Description:
Module containing common code
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/io/micrometer/micrometer-commons/1.16.1/micrometer-commons-1.16.1.jar
MD5: 23e0b713e3ed971c92eea68f8074d72d
SHA1: 1b14b7052dd88e35625b3f5505f9bb8a9b0fedb8
SHA256: 6c668165cb7204dcc48ff67a30e276c71304b92f3ed746ecaf98b1ea6b672fbb
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
micrometer-commons-1.16.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-spring-security7@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name micrometer-commons High
Vendor jar package name common Highest
Vendor jar package name io Highest
Vendor jar package name micrometer Highest
Vendor Manifest automatic-module-name micrometer.commons Medium
Vendor Manifest branch HEAD Low
Vendor Manifest build-date 2025-12-08_20:33:14 Low
Vendor Manifest build-date-utc 2025-12-08T20:33:14.227668117Z Low
Vendor Manifest build-host b8894f464959 Low
Vendor Manifest build-job deploy Low
Vendor Manifest build-number 59905 Low
Vendor Manifest build-timezone Etc/UTC Low
Vendor Manifest build-url https://circleci.com/gh/micrometer-metrics/micrometer/59905 Low
Vendor Manifest built-os Linux Low
Vendor Manifest built-status release Low
Vendor Manifest bundle-symbolicname micrometer-commons Medium
Vendor Manifest change 0550e76 Low
Vendor Manifest full-change 0550e769cb9b4f15cff86c1e503fce8ae03ef84f Low
Vendor Manifest module-email tludwig@vmware.com Low
Vendor Manifest module-origin micrometer-metrics/micrometer.git Low
Vendor Manifest module-owner tludwig@vmware.com Low
Vendor Manifest module-source /micrometer-commons Low
Vendor pom artifactid micrometer-commons Highest
Vendor pom artifactid micrometer-commons Low
Vendor pom developer email tludwig@vmware.com Low
Vendor pom developer id shakuzen Medium
Vendor pom developer name Tommy Ludwig Medium
Vendor pom groupid io.micrometer Highest
Vendor pom name micrometer-commons High
Vendor pom url micrometer-metrics/micrometer Highest
Product file name micrometer-commons High
Product jar package name common Highest
Product jar package name io Highest
Product jar package name micrometer Highest
Product Manifest automatic-module-name micrometer.commons Medium
Product Manifest branch HEAD Low
Product Manifest build-date 2025-12-08_20:33:14 Low
Product Manifest build-date-utc 2025-12-08T20:33:14.227668117Z Low
Product Manifest build-host b8894f464959 Low
Product Manifest build-job deploy Low
Product Manifest build-number 59905 Low
Product Manifest build-timezone Etc/UTC Low
Product Manifest build-url https://circleci.com/gh/micrometer-metrics/micrometer/59905 Low
Product Manifest built-os Linux Low
Product Manifest built-status release Low
Product Manifest Bundle-Name micrometer-commons Medium
Product Manifest bundle-symbolicname micrometer-commons Medium
Product Manifest change 0550e76 Low
Product Manifest full-change 0550e769cb9b4f15cff86c1e503fce8ae03ef84f Low
Product Manifest Implementation-Title io.micrometer#micrometer-commons;1.16.1 High
Product Manifest module-email tludwig@vmware.com Low
Product Manifest module-origin micrometer-metrics/micrometer.git Low
Product Manifest module-owner tludwig@vmware.com Low
Product Manifest module-source /micrometer-commons Low
Product pom artifactid micrometer-commons Highest
Product pom developer email tludwig@vmware.com Low
Product pom developer id shakuzen Low
Product pom developer name Tommy Ludwig Low
Product pom groupid io.micrometer Highest
Product pom name micrometer-commons High
Product pom url micrometer-metrics/micrometer High
Version file version 1.16.1 High
Version Manifest Bundle-Version 1.16.1 High
Version Manifest Implementation-Version 1.16.1 High
Version pom version 1.16.1 Highest
pkg:maven/io.micrometer/micrometer-commons@1.16.1
(Confidence :High)
micrometer-observation-1.16.1.jar
Description:
Module containing Observation related code
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/io/micrometer/micrometer-observation/1.16.1/micrometer-observation-1.16.1.jar
MD5: 924c696548bc1f9402233ef74b4a591f
SHA1: 659a6aa16a5e541de071ef7ba6cb7ef35d59ce2a
SHA256: 2511718a303d086fd5fd0befc65db87e456894e1d9cdeef4f9c4eaf28b428bc0
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
micrometer-observation-1.16.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-spring-security7@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name micrometer-observation High
Vendor jar package name io Highest
Vendor jar package name micrometer Highest
Vendor jar package name observation Highest
Vendor Manifest automatic-module-name micrometer.observation Medium
Vendor Manifest branch HEAD Low
Vendor Manifest build-date 2025-12-08_20:33:14 Low
Vendor Manifest build-date-utc 2025-12-08T20:33:14.662922809Z Low
Vendor Manifest build-host b8894f464959 Low
Vendor Manifest build-job deploy Low
Vendor Manifest build-number 59905 Low
Vendor Manifest build-timezone Etc/UTC Low
Vendor Manifest build-url https://circleci.com/gh/micrometer-metrics/micrometer/59905 Low
Vendor Manifest built-os Linux Low
Vendor Manifest built-status release Low
Vendor Manifest bundle-symbolicname micrometer-observation Medium
Vendor Manifest change 0550e76 Low
Vendor Manifest full-change 0550e769cb9b4f15cff86c1e503fce8ae03ef84f Low
Vendor Manifest module-email tludwig@vmware.com Low
Vendor Manifest module-origin micrometer-metrics/micrometer.git Low
Vendor Manifest module-owner tludwig@vmware.com Low
Vendor Manifest module-source /micrometer-observation Low
Vendor pom artifactid micrometer-observation Highest
Vendor pom artifactid micrometer-observation Low
Vendor pom developer email tludwig@vmware.com Low
Vendor pom developer id shakuzen Medium
Vendor pom developer name Tommy Ludwig Medium
Vendor pom groupid io.micrometer Highest
Vendor pom name micrometer-observation High
Vendor pom url micrometer-metrics/micrometer Highest
Product file name micrometer-observation High
Product jar package name io Highest
Product jar package name micrometer Highest
Product jar package name observation Highest
Product Manifest automatic-module-name micrometer.observation Medium
Product Manifest branch HEAD Low
Product Manifest build-date 2025-12-08_20:33:14 Low
Product Manifest build-date-utc 2025-12-08T20:33:14.662922809Z Low
Product Manifest build-host b8894f464959 Low
Product Manifest build-job deploy Low
Product Manifest build-number 59905 Low
Product Manifest build-timezone Etc/UTC Low
Product Manifest build-url https://circleci.com/gh/micrometer-metrics/micrometer/59905 Low
Product Manifest built-os Linux Low
Product Manifest built-status release Low
Product Manifest Bundle-Name micrometer-observation Medium
Product Manifest bundle-symbolicname micrometer-observation Medium
Product Manifest change 0550e76 Low
Product Manifest full-change 0550e769cb9b4f15cff86c1e503fce8ae03ef84f Low
Product Manifest Implementation-Title io.micrometer#micrometer-observation;1.16.1 High
Product Manifest module-email tludwig@vmware.com Low
Product Manifest module-origin micrometer-metrics/micrometer.git Low
Product Manifest module-owner tludwig@vmware.com Low
Product Manifest module-source /micrometer-observation Low
Product pom artifactid micrometer-observation Highest
Product pom developer email tludwig@vmware.com Low
Product pom developer id shakuzen Low
Product pom developer name Tommy Ludwig Low
Product pom groupid io.micrometer Highest
Product pom name micrometer-observation High
Product pom url micrometer-metrics/micrometer High
Version file version 1.16.1 High
Version Manifest Bundle-Version 1.16.1 High
Version Manifest Implementation-Version 1.16.1 High
Version pom version 1.16.1 Highest
pkg:maven/io.micrometer/micrometer-observation@1.16.1
(Confidence :High)
slf4j-api-2.0.17.jar
Description:
The slf4j API
License:
https://opensource.org/license/mit
File Path: /home/runner/.m2/repository/org/slf4j/slf4j-api/2.0.17/slf4j-api-2.0.17.jar
MD5: b6480d114a23683498ac3f746f959d2f
SHA1: d9e58ac9c7779ba3bf8142aff6c830617a7fe60f
SHA256: 7b751d952061954d5abfed7181c1f645d336091b679891591d63329c622eb832
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
slf4j-api-2.0.17.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.slf4j/slf4j-simple@2.0.17
Evidence
Type Source Name Value Confidence
Vendor file name slf4j-api High
Vendor jar package name slf4j Highest
Vendor Manifest build-jdk-spec 21 Low
Vendor Manifest bundle-docurl http://www.slf4j.org Low
Vendor Manifest bundle-symbolicname slf4j.api Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid slf4j-api Highest
Vendor pom artifactid slf4j-api Low
Vendor pom groupid org.slf4j Highest
Vendor pom name SLF4J API Module High
Vendor pom parent-artifactid slf4j-parent Low
Vendor pom url http://www.slf4j.org Highest
Product file name slf4j-api High
Product jar package name slf4j Highest
Product Manifest build-jdk-spec 21 Low
Product Manifest bundle-docurl http://www.slf4j.org Low
Product Manifest Bundle-Name SLF4J API Module Medium
Product Manifest bundle-symbolicname slf4j.api Medium
Product Manifest Implementation-Title slf4j-api High
Product Manifest multi-release true Low
Product pom artifactid slf4j-api Highest
Product pom groupid org.slf4j Highest
Product pom name SLF4J API Module High
Product pom parent-artifactid slf4j-parent Medium
Product pom url http://www.slf4j.org Medium
Version file version 2.0.17 High
Version Manifest Bundle-Version 2.0.17 High
Version Manifest Implementation-Version 2.0.17 High
Version pom version 2.0.17 Highest
pkg:maven/org.slf4j/slf4j-api@2.0.17
(Confidence :High)
snakeyaml-2.5.jar
Description:
YAML 1.1 parser and emitter for Java
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/yaml/snakeyaml/2.5/snakeyaml-2.5.jar
MD5: 8d3b7581db5c7620db55183f33a4f2ad
SHA1: 2d53ddec134280cb384c1e35d094e5f71c1f2316
SHA256: e6682acf1ace77508ef13649cbf4f8d09d2cf5457bdb61d25ffb6ac0233d78dd
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
snakeyaml-2.5.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-security@4.0.1
Evidence
Type Source Name Value Confidence
Vendor file name snakeyaml High
Vendor jar package name emitter Highest
Vendor jar package name org Highest
Vendor jar package name parser Highest
Vendor jar package name snakeyaml Highest
Vendor jar package name yaml Highest
Vendor Manifest build-jdk-spec 11 Low
Vendor Manifest bundle-symbolicname org.yaml.snakeyaml Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid snakeyaml Highest
Vendor pom artifactid snakeyaml Low
Vendor pom developer email alexander.maslov@gmail.com Low
Vendor pom developer email public.somov@gmail.com Low
Vendor pom developer id asomov Medium
Vendor pom developer id maslovalex Medium
Vendor pom developer name Alexander Maslov Medium
Vendor pom developer name Andrey Somov Medium
Vendor pom groupid org.yaml Highest
Vendor pom name SnakeYAML High
Vendor pom url https://bitbucket.org/snakeyaml/snakeyaml Highest
Product file name snakeyaml High
Product jar package name emitter Highest
Product jar package name org Highest
Product jar package name parser Highest
Product jar package name snakeyaml Highest
Product jar package name yaml Highest
Product Manifest build-jdk-spec 11 Low
Product Manifest Bundle-Name SnakeYAML Medium
Product Manifest bundle-symbolicname org.yaml.snakeyaml Medium
Product Manifest multi-release true Low
Product pom artifactid snakeyaml Highest
Product pom developer email alexander.maslov@gmail.com Low
Product pom developer email public.somov@gmail.com Low
Product pom developer id asomov Low
Product pom developer id maslovalex Low
Product pom developer name Alexander Maslov Low
Product pom developer name Andrey Somov Low
Product pom groupid org.yaml Highest
Product pom name SnakeYAML High
Product pom url https://bitbucket.org/snakeyaml/snakeyaml Medium
Version file version 2.5 High
Version pom version 2.5 Highest
spotbugs-annotations-4.9.8.jar
Description:
Annotations the SpotBugs tool supports
License:
GNU LESSER GENERAL PUBLIC LICENSE, Version 2.1: https://www.gnu.org/licenses/old-licenses/lgpl-2.1.en.html
File Path: /home/runner/.m2/repository/com/github/spotbugs/spotbugs-annotations/4.9.8/spotbugs-annotations-4.9.8.jar
MD5: d4c2e7bd090be697ad409a4e75684a94
SHA1: ca4a2783a6123e67124fd7feb4caccd2e2ac9a73
SHA256: 6f69d6fe9c55a54dcb30e87d8fa2d5f52246af50d7a3445246d9539ef221be1c
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:provided
spotbugs-annotations-4.9.8.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-spring-boot-autoconfigure4@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name spotbugs-annotations High
Vendor Manifest automatic-module-name com.github.spotbugs.annotations Medium
Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.8 Low
Vendor Manifest bundle-symbolicname spotbugs-annotations Medium
Vendor pom artifactid spotbugs-annotations Highest
Vendor pom artifactid spotbugs-annotations Low
Vendor pom developer email andreas.sewe@codetrails.com Low
Vendor pom developer email dbrosius@mebigfatguy.com Low
Vendor pom developer email loskutov@gmx.de Low
Vendor pom developer email skypencil@gmail.com Low
Vendor pom developer id henrik242 Medium
Vendor pom developer id iloveeclipse Medium
Vendor pom developer id jsotuyod Medium
Vendor pom developer id KengoTODA Medium
Vendor pom developer id mebigfatguy Medium
Vendor pom developer id sewe Medium
Vendor pom developer id ThrawnCA Medium
Vendor pom developer name Andreas Sewe Medium
Vendor pom developer name Andrey Loskutov Medium
Vendor pom developer name Dave Brosius Medium
Vendor pom developer name Juan Martín Sotuyo Dodero Medium
Vendor pom developer name Kengo TODA Medium
Vendor pom groupid com.github.spotbugs Highest
Vendor pom name SpotBugs Annotations High
Vendor pom url https://spotbugs.github.io/ Highest
Product file name spotbugs-annotations High
Product Manifest automatic-module-name com.github.spotbugs.annotations Medium
Product Manifest Bundle-Name spotbugs-annotations Medium
Product Manifest bundle-requiredexecutionenvironment JavaSE-1.8 Low
Product Manifest bundle-symbolicname spotbugs-annotations Medium
Product pom artifactid spotbugs-annotations Highest
Product pom developer email andreas.sewe@codetrails.com Low
Product pom developer email dbrosius@mebigfatguy.com Low
Product pom developer email loskutov@gmx.de Low
Product pom developer email skypencil@gmail.com Low
Product pom developer id henrik242 Low
Product pom developer id iloveeclipse Low
Product pom developer id jsotuyod Low
Product pom developer id KengoTODA Low
Product pom developer id mebigfatguy Low
Product pom developer id sewe Low
Product pom developer id ThrawnCA Low
Product pom developer name Andreas Sewe Low
Product pom developer name Andrey Loskutov Low
Product pom developer name Dave Brosius Low
Product pom developer name Juan Martín Sotuyo Dodero Low
Product pom developer name Kengo TODA Low
Product pom groupid com.github.spotbugs Highest
Product pom name SpotBugs Annotations High
Product pom url https://spotbugs.github.io/ Medium
Version file version 4.9.8 High
Version Manifest Bundle-Version 4.9.8 High
Version pom version 4.9.8 Highest
pkg:maven/com.github.spotbugs/spotbugs-annotations@4.9.8
(Confidence :High)
spring-boot-web-server-4.0.1.jar
Description:
Spring Boot Web Server
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-web-server/4.0.1/spring-boot-web-server-4.0.1.jar
MD5: 578257dba79ab073bc230a59b50c593b
SHA1: 659ce5f51c2bb7161db2811150a555a121dabd68
SHA256: f0a538e1f2d2f9cef43feb9b04b12fac4e5872d740db2eb56e362446bc4fe98c
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
spring-boot-web-server-4.0.1.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-web@4.0.1
Evidence
Type Source Name Value Confidence
Vendor file name spring-boot-web-server High
Vendor hint analyzer vendor pivotal software Highest
Vendor hint analyzer vendor SpringSource Highest
Vendor hint analyzer vendor vmware Highest
Vendor jar package name boot Highest
Vendor jar package name server Highest
Vendor jar package name springframework Highest
Vendor jar package name web Highest
Vendor Manifest automatic-module-name spring.boot.web.server Medium
Vendor Manifest build-jdk-spec 17 Low
Vendor pom artifactid spring-boot-web-server Highest
Vendor pom artifactid spring-boot-web-server Low
Vendor pom developer email ask@spring.io Low
Vendor pom developer name Spring Medium
Vendor pom developer org VMware, Inc. Medium
Vendor pom developer org URL https://www.spring.io Medium
Vendor pom groupid org.springframework.boot Highest
Vendor pom name spring-boot-web-server High
Vendor pom organization name VMware, Inc. High
Vendor pom organization url https://spring.io Medium
Vendor pom url https://spring.io/projects/spring-boot Highest
Product file name spring-boot-web-server High
Product jar package name boot Highest
Product jar package name server Highest
Product jar package name springframework Highest
Product jar package name web Highest
Product Manifest automatic-module-name spring.boot.web.server Medium
Product Manifest build-jdk-spec 17 Low
Product Manifest Implementation-Title Spring Boot Web Server High
Product pom artifactid spring-boot-web-server Highest
Product pom developer email ask@spring.io Low
Product pom developer name Spring Low
Product pom developer org VMware, Inc. Low
Product pom developer org URL https://www.spring.io Low
Product pom groupid org.springframework.boot Highest
Product pom name spring-boot-web-server High
Product pom organization name VMware, Inc. Low
Product pom organization url https://spring.io Low
Product pom url https://spring.io/projects/spring-boot Medium
Version file version 4.0.1 High
Version Manifest Implementation-Version 4.0.1 High
Version pom version 4.0.1 Highest
Related Dependencies
spring-boot-4.0.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot/4.0.1/spring-boot-4.0.1.jar
MD5: 99728e08dfce163bc9e0963bdfddbdd6
SHA1: 2c20ae598c14dd78d3098aafc8a799afbdf8e69a
SHA256: 947b648ec6ddea77dfaba41cccfb4fd7b0823b7d1c43c7f3b357c1880e0ec460
pkg:maven/org.springframework.boot/spring-boot@4.0.1
spring-boot-autoconfigure-4.0.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-autoconfigure/4.0.1/spring-boot-autoconfigure-4.0.1.jar
MD5: d58228904fbdd6fc68657c4cd5d40b17
SHA1: 808c34d74bbad5802bac8ce687424da4da93bb08
SHA256: 5598ce8521086b5b662770b7411fc90233f393257d2e4f388d189e0ed8891272
pkg:maven/org.springframework.boot/spring-boot-autoconfigure@4.0.1
spring-boot-configuration-processor-4.0.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-configuration-processor/4.0.1/spring-boot-configuration-processor-4.0.1.jar
MD5: 054fc382d32d3d1597a77707cfca339a
SHA1: a6d77ad038728f5497b218458a0c99c50a19b605
SHA256: 31bcdb2394ee78a75e45d896628df77c971ca92a4aa4f1dfd091a8ed802b1103
pkg:maven/org.springframework.boot/spring-boot-configuration-processor@4.0.1
spring-boot-http-converter-4.0.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-http-converter/4.0.1/spring-boot-http-converter-4.0.1.jar
MD5: 8f9ed7914ecd4222df3a53fd54e10c1f
SHA1: ff2953160f2bffc4c888067300f9bf367ae55f26
SHA256: 60b958ec12489f2a97fed379449d077232dfa5ca24315baa04b944885df940a2
pkg:maven/org.springframework.boot/spring-boot-http-converter@4.0.1
spring-boot-jackson-4.0.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-jackson/4.0.1/spring-boot-jackson-4.0.1.jar
MD5: f9fcbb137dda4821f3aa0a706380cff7
SHA1: 245c1e71474e903bb06b6fffc018c4b2d98738c4
SHA256: 4c419c426cbcb92fa8fdbf813c20a88ba950ecc78d9dfc80c515d99fdad7b5b1
pkg:maven/org.springframework.boot/spring-boot-jackson@4.0.1
spring-boot-security-4.0.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-security/4.0.1/spring-boot-security-4.0.1.jar
MD5: 4ceb04e4e6330c75fb866591765080eb
SHA1: 9e406a65f41f9b4d94a7373aa3743c8178f9a226
SHA256: d51ed600f438e41765897fdd878c81e5136ba1ec1cd75ce72173552a569d9120
pkg:maven/org.springframework.boot/spring-boot-security@4.0.1
spring-boot-servlet-4.0.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-servlet/4.0.1/spring-boot-servlet-4.0.1.jar
MD5: 341994af8142ec3fa8b25fadb0c24dba
SHA1: 3dcddba717a9deb204925f41f8e596bba07f417f
SHA256: 8274a8dfdb1e1ea1d0664977a059c9a421d7cd7a6671d400304e0164c11b03db
pkg:maven/org.springframework.boot/spring-boot-servlet@4.0.1
spring-boot-starter-4.0.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-starter/4.0.1/spring-boot-starter-4.0.1.jar
MD5: 46d7d44713a78c635525bfb5c392bb2e
SHA1: 775e306503c1170ba472a33a47a6549a15e7015f
SHA256: 1d03d6d448c87e3fe02ee089ed3e3511370c63bd93eeae6528011cccfaaec626
pkg:maven/org.springframework.boot/spring-boot-starter@4.0.1
spring-boot-starter-jackson-4.0.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-starter-jackson/4.0.1/spring-boot-starter-jackson-4.0.1.jar
MD5: 56d7bb6223e7c3d2cd4dbdb02fb8dd1b
SHA1: 89aa1cd99f32ed00f1fd9d5c22e019e7cb9fa262
SHA256: b3842926cf8fd6f72416d03da84e9f232a279f2bf7729fbb3c2e9c8d353a31bb
pkg:maven/org.springframework.boot/spring-boot-starter-jackson@4.0.1
spring-boot-starter-logging-4.0.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-starter-logging/4.0.1/spring-boot-starter-logging-4.0.1.jar
MD5: e4aef35a2c73cb6de0a32245476b7673
SHA1: 95b39c11a1a69a48ababef38c9a415f25fead87b
SHA256: dc804995968d927818235a87ac38de1f335fed84b7f57c4b5cb3edc9f5a948c0
pkg:maven/org.springframework.boot/spring-boot-starter-logging@4.0.1
spring-boot-starter-security-4.0.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-starter-security/4.0.1/spring-boot-starter-security-4.0.1.jar
MD5: b213dff05f27ce6ba062325ec96d2760
SHA1: 9b5f936ee3c7d75f288ebbc14548c3dda4cd5f73
SHA256: 5b6533344a8fd868339ba5a70732258f781ebf15a4e6ae99103ee52282af7c1a
pkg:maven/org.springframework.boot/spring-boot-starter-security@4.0.1
spring-boot-starter-tomcat-4.0.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-starter-tomcat/4.0.1/spring-boot-starter-tomcat-4.0.1.jar
MD5: 9ae72a2227fc4ca06ed4c4f684498a4f
SHA1: ebf0883b5ef313119a35f74bfdcc55a816bf85a7
SHA256: fd439e7a52f66b9cfd11e7227250017bd3a198a4ddc87970bb815786c7290a12
pkg:maven/org.springframework.boot/spring-boot-starter-tomcat@4.0.1
spring-boot-starter-tomcat-runtime-4.0.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-starter-tomcat-runtime/4.0.1/spring-boot-starter-tomcat-runtime-4.0.1.jar
MD5: 554727caeb03e5ab14cd7b40a7e0eae1
SHA1: ce0f7d5cb75fbfcdbc839d0aeee62ce38f8ee58c
SHA256: 029a4b3e6f2d2db29359b7743027fcf8b1e0a87cef17cf0644560f6da831c771
pkg:maven/org.springframework.boot/spring-boot-starter-tomcat-runtime@4.0.1
spring-boot-starter-web-4.0.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-starter-web/4.0.1/spring-boot-starter-web-4.0.1.jar
MD5: 705a435981e12480899f8c7738929a64
SHA1: 5d686bdc4417486872aa7e1fa305bcf4fec7076b
SHA256: b739dd12fcad2bcbb59872c417f58684dd86b1d9f65929e0586bbf2614b895c6
pkg:maven/org.springframework.boot/spring-boot-starter-web@4.0.1
spring-boot-tomcat-4.0.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-tomcat/4.0.1/spring-boot-tomcat-4.0.1.jar
MD5: 3d82d0c2259ad0c3c7ff393f0c9131c1
SHA1: 4e89e61bfb085a95d1541f1f9ca2d705f31b6197
SHA256: c3d3e8b2a26204ac44cc3e6b6ce8b2dea489092e76ff1e3f16298febdc74459c
pkg:maven/org.springframework.boot/spring-boot-tomcat@4.0.1
spring-boot-webmvc-4.0.1.jar
File Path: /home/runner/.m2/repository/org/springframework/boot/spring-boot-webmvc/4.0.1/spring-boot-webmvc-4.0.1.jar
MD5: a20d7f64dbe04e73543908f90e10e588
SHA1: 4635bb0220cba3d95ab0b0883b5b1460f59bb31d
SHA256: ba13b693fa1a8f18e519e22ea2cfc3522bf7e3d7fc796f67a01e8da01868b6c3
pkg:maven/org.springframework.boot/spring-boot-webmvc@4.0.1
spring-core-7.0.2.jar
Description:
Spring Core
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0
File Path: /home/runner/.m2/repository/org/springframework/spring-core/7.0.2/spring-core-7.0.2.jar
MD5: 15551a52baa8a51cba039e2a87e138c7
SHA1: 92b5608685a6212fe2ce3565bc1bf660505560c7
SHA256: 4d0ceaa52d33483b2442cada981bba8a8b0227b969bdabfffc5b128e1e02f9bc
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
spring-core-7.0.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-spring-security7@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name spring-core High
Vendor hint analyzer vendor pivotal software Highest
Vendor hint analyzer vendor SpringSource Highest
Vendor hint analyzer vendor vmware Highest
Vendor jar package name core Highest
Vendor jar package name io Highest
Vendor jar package name org Highest
Vendor jar package name springframework Highest
Vendor Manifest automatic-module-name spring.core Medium
Vendor Manifest multi-release true Low
Vendor pom artifactid spring-core Highest
Vendor pom artifactid spring-core Low
Vendor pom developer email juergen.hoeller@broadcom.com Low
Vendor pom developer id jhoeller Medium
Vendor pom developer name Juergen Hoeller Medium
Vendor pom groupid org.springframework Highest
Vendor pom name Spring Core High
Vendor pom organization name Spring IO High
Vendor pom organization url https://spring.io/projects/spring-framework Medium
Vendor pom url spring-projects/spring-framework Highest
Product file name spring-core High
Product hint analyzer product springsource_spring_framework Highest
Product jar package name core Highest
Product jar package name io Highest
Product jar package name org Highest
Product jar package name springframework Highest
Product Manifest automatic-module-name spring.core Medium
Product Manifest Implementation-Title spring-core High
Product Manifest multi-release true Low
Product pom artifactid spring-core Highest
Product pom developer email juergen.hoeller@broadcom.com Low
Product pom developer id jhoeller Low
Product pom developer name Juergen Hoeller Low
Product pom groupid org.springframework Highest
Product pom name Spring Core High
Product pom organization name Spring IO Low
Product pom organization url https://spring.io/projects/spring-framework Low
Product pom url spring-projects/spring-framework High
Version file version 7.0.2 High
Version Manifest Implementation-Version 7.0.2 High
Version pom version 7.0.2 Highest
Related Dependencies
spring-aop-7.0.2.jar
File Path: /home/runner/.m2/repository/org/springframework/spring-aop/7.0.2/spring-aop-7.0.2.jar
MD5: e0f1c76ae304e1d6348a7a1db2a4ba9e
SHA1: 25b824571d184e9d47606a62dd787bcf7c55e88e
SHA256: bd763e6019222129aea5ac0c1261a90af3ee904e1c4b87a570175366d2f10325
pkg:maven/org.springframework/spring-aop@7.0.2
spring-beans-7.0.2.jar
File Path: /home/runner/.m2/repository/org/springframework/spring-beans/7.0.2/spring-beans-7.0.2.jar
MD5: 091b6bb7aa41f79cce76ea3cada85988
SHA1: 224739ac1b1bd96e866fb436cbcc46a7457a64a2
SHA256: 7ce3218b5a2172900ea9f9d791acf2cfaedcdbffcb4ef39f981daeed18411781
pkg:maven/org.springframework/spring-beans@7.0.2
spring-context-7.0.2.jar
File Path: /home/runner/.m2/repository/org/springframework/spring-context/7.0.2/spring-context-7.0.2.jar
MD5: eb7657a182946507706eb317b9321054
SHA1: 531fbbabf0d9ff80bc506121acfd29dcb1531bf9
SHA256: cff8ff2039db2c4e13a0abf03aece6fdb2e5384ac0613446d55f4227b27d06fc
pkg:maven/org.springframework/spring-context@7.0.2
spring-expression-7.0.2.jar
File Path: /home/runner/.m2/repository/org/springframework/spring-expression/7.0.2/spring-expression-7.0.2.jar
MD5: 41497d8d9f3899e500b38c165d7d7695
SHA1: 692338c5c7eaeeeba4f0919b54216c1bf9fbee04
SHA256: 2e1596cfc15322329c655805c2dd01a3f2a1d1145f8f91cac2d4b0f7de284f4a
pkg:maven/org.springframework/spring-expression@7.0.2
spring-web-7.0.2.jar
File Path: /home/runner/.m2/repository/org/springframework/spring-web/7.0.2/spring-web-7.0.2.jar
MD5: 656e35517710f8c028196b79cecbb96a
SHA1: fc1f3eec8e102b896b06c0082bf4d08486e091d3
SHA256: 49767bf0effe8d4ebaaf16453ff1bffc4478f7328a687313811e56d5140feca5
pkg:maven/org.springframework/spring-web@7.0.2
spring-webmvc-7.0.2.jar
File Path: /home/runner/.m2/repository/org/springframework/spring-webmvc/7.0.2/spring-webmvc-7.0.2.jar
MD5: 776da4bbb0b1a5be8ed08f536f96348c
SHA1: ed0b3b7724e8cb4b47976eda5e862b3dd1ed871b
SHA256: 32e6b1e3381b6caca190a159d5859bc334bba7fef84b126b513e1487e7783b41
pkg:maven/org.springframework/spring-webmvc@7.0.2
spring-security-core-7.0.2.jar
Description:
Spring Security
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0
File Path: /home/runner/.m2/repository/org/springframework/security/spring-security-core/7.0.2/spring-security-core-7.0.2.jar
MD5: 9fbe37f425d92d5ef1503dc887ffbb80
SHA1: 40317c3763917b061b912bd381bf8016e38eebde
SHA256: 771adf6de0e761c9a5f3ed4e506822ad13a8a1de699799df5fe9a34824748bc3
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
spring-security-core-7.0.2.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/com.github.waffle/waffle-spring-security7@3.6.0-SNAPSHOT
Evidence
Type Source Name Value Confidence
Vendor file name spring-security-core High
Vendor hint analyzer vendor pivotal software Highest
Vendor hint analyzer vendor SpringSource Highest
Vendor hint analyzer vendor vmware Highest
Vendor jar package name core Highest
Vendor jar package name security Highest
Vendor jar package name springframework Highest
Vendor Manifest automatic-module-name spring.security.core Medium
Vendor pom artifactid spring-security-core Highest
Vendor pom artifactid spring-security-core Low
Vendor pom developer email info@pivotal.io Low
Vendor pom developer name Pivotal Medium
Vendor pom developer org Pivotal Software, Inc. Medium
Vendor pom developer org URL https://www.spring.io Medium
Vendor pom groupid org.springframework.security Highest
Vendor pom name spring-security-core High
Vendor pom organization name Pivotal Software, Inc. High
Vendor pom organization url https://spring.io Medium
Vendor pom url https://spring.io/projects/spring-security Highest
Product file name spring-security-core High
Product jar package name core Highest
Product jar package name security Highest
Product jar package name springframework Highest
Product Manifest automatic-module-name spring.security.core Medium
Product Manifest Implementation-Title spring-security-core High
Product pom artifactid spring-security-core Highest
Product pom developer email info@pivotal.io Low
Product pom developer name Pivotal Low
Product pom developer org Pivotal Software, Inc. Low
Product pom developer org URL https://www.spring.io Low
Product pom groupid org.springframework.security Highest
Product pom name spring-security-core High
Product pom organization name Pivotal Software, Inc. Low
Product pom organization url https://spring.io Low
Product pom url https://spring.io/projects/spring-security Medium
Version file version 7.0.2 High
Version Manifest Implementation-Version 7.0.2 High
Version pom version 7.0.2 Highest
Related Dependencies
spring-security-config-7.0.2.jar
File Path: /home/runner/.m2/repository/org/springframework/security/spring-security-config/7.0.2/spring-security-config-7.0.2.jar
MD5: 9f924bf7498fe14ee0d655e151775df1
SHA1: d15ffd7762c07248e43ee153e27362e89ff8c6b4
SHA256: 84f0532af906e60d3a9eddc596152a7f0cc522b2ba665a9d909782851fb2b4f9
pkg:maven/org.springframework.security/spring-security-config@7.0.2
spring-security-crypto-7.0.2.jar
File Path: /home/runner/.m2/repository/org/springframework/security/spring-security-crypto/7.0.2/spring-security-crypto-7.0.2.jar
MD5: 39f1efd59135d39ab606f4a8ee9bb9f7
SHA1: 8cec3433f111e21d6349a9788a1efcf547b8db03
SHA256: ad909c728a4a293981742e31e9f0e4c72d5800595632f402f831c5f7c737c43d
pkg:maven/org.springframework.security/spring-security-crypto@7.0.2
spring-security-web-7.0.2.jar
File Path: /home/runner/.m2/repository/org/springframework/security/spring-security-web/7.0.2/spring-security-web-7.0.2.jar
MD5: d71ac1888336260436f5767ccd1afc80
SHA1: 8d55b2164a866d932031b77ce21fed35a4a3bfe0
SHA256: 564bb85e5c2d0606de83670b2d4257d6c9e43ea518e2e820a1c19f19ef562535
pkg:maven/org.springframework.security/spring-security-web@7.0.2
spring-security-web-7.0.2.jar: spring-security-webauthn.js
File Path: /home/runner/.m2/repository/org/springframework/security/spring-security-web/7.0.2/spring-security-web-7.0.2.jar/org/springframework/security/spring-security-webauthn.js
MD5: d8d90d854a23d021c2e758b3eebce213
SHA1: 7814ccd3adc2388f52b2658bf5fc30b457949ab6
SHA256: 044a2b8d7e995bff815565678631a2d3a5cc0aa96ef8ac35cfacb579307f77a9
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
Evidence
Type Source Name Value Confidence
tomcat-embed-core-11.0.15.jar
Description:
Core Tomcat implementation
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/apache/tomcat/embed/tomcat-embed-core/11.0.15/tomcat-embed-core-11.0.15.jar
MD5: 69aad964e5a07592e5173a00793a5cfa
SHA1: aa20506537e3efa61afd6b57d79f9da6a55f37ae
SHA256: 25299ce44012a34775b4e1f5237a3d6ec8af52ace658e540d4dd61ee38064ba0
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
tomcat-embed-core-11.0.15.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-web@4.0.1
Evidence
Type Source Name Value Confidence
Vendor file name tomcat-embed-core High
Vendor jar package name apache Highest
Vendor jar package name core Highest
Vendor jar package name tomcat Highest
Vendor Manifest bundle-symbolicname org.apache.tomcat-embed-core Medium
Vendor Manifest Implementation-Vendor Apache Software Foundation High
Vendor Manifest provide-capability osgi.contract;osgi.contract=JakartaAuthentication;version:Version="3.1";uses:="jakarta.security.auth.message,jakarta.security.auth.message.callback,jakarta.security.auth.message.config,jakarta.security.auth.message.module",osgi.contract;osgi.contract=JakartaServlet;version:Version="6.1";uses:="jakarta.servlet,jakarta.servlet.annotation,jakarta.servlet.descriptor,jakarta.servlet.http,jakarta.servlet.resources" Low
Vendor Manifest specification-vendor Apache Software Foundation Low
Vendor manifest: jakarta/security/auth/message/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: jakarta/security/auth/message/callback/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: jakarta/security/auth/message/config/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: jakarta/security/auth/message/module/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: jakarta/servlet/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: jakarta/servlet/annotation/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: jakarta/servlet/descriptor/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: jakarta/servlet/http/ Implementation-Vendor Apache Software Foundation Medium
Vendor manifest: jakarta/servlet/resources/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom artifactid tomcat-embed-core Highest
Vendor pom artifactid tomcat-embed-core Low
Vendor pom groupid org.apache.tomcat.embed Highest
Vendor pom url https://tomcat.apache.org/ Highest
Product file name tomcat-embed-core High
Product jar package name annotation Highest
Product jar package name apache Highest
Product jar package name auth Highest
Product jar package name core Highest
Product jar package name descriptor Highest
Product jar package name http Highest
Product jar package name jakarta Highest
Product jar package name message Highest
Product jar package name security Highest
Product jar package name servlet Highest
Product jar package name tomcat Highest
Product Manifest Bundle-Name tomcat-embed-core Medium
Product Manifest bundle-symbolicname org.apache.tomcat-embed-core Medium
Product Manifest Implementation-Title Apache Tomcat High
Product Manifest provide-capability osgi.contract;osgi.contract=JakartaAuthentication;version:Version="3.1";uses:="jakarta.security.auth.message,jakarta.security.auth.message.callback,jakarta.security.auth.message.config,jakarta.security.auth.message.module",osgi.contract;osgi.contract=JakartaServlet;version:Version="6.1";uses:="jakarta.servlet,jakarta.servlet.annotation,jakarta.servlet.descriptor,jakarta.servlet.http,jakarta.servlet.resources" Low
Product Manifest specification-title Apache Tomcat Medium
Product manifest: jakarta/security/auth/message/ Implementation-Title jakarta.security.auth.message Medium
Product manifest: jakarta/security/auth/message/ Specification-Title Jakarta Authentication SPI for Containers Medium
Product manifest: jakarta/security/auth/message/callback/ Implementation-Title jakarta.security.auth.message Medium
Product manifest: jakarta/security/auth/message/callback/ Specification-Title Jakarta Authentication SPI for Containers Medium
Product manifest: jakarta/security/auth/message/config/ Implementation-Title jakarta.security.auth.message Medium
Product manifest: jakarta/security/auth/message/config/ Specification-Title Jakarta Authentication SPI for Containers Medium
Product manifest: jakarta/security/auth/message/module/ Implementation-Title jakarta.security.auth.message Medium
Product manifest: jakarta/security/auth/message/module/ Specification-Title Jakarta Authentication SPI for Containers Medium
Product manifest: jakarta/servlet/ Implementation-Title jakarta.servlet Medium
Product manifest: jakarta/servlet/ Specification-Title Jakarta Servlet Medium
Product manifest: jakarta/servlet/annotation/ Implementation-Title jakarta.servlet Medium
Product manifest: jakarta/servlet/annotation/ Specification-Title Jakarta Servlet Medium
Product manifest: jakarta/servlet/descriptor/ Implementation-Title jakarta.servlet Medium
Product manifest: jakarta/servlet/descriptor/ Specification-Title Jakarta Servlet Medium
Product manifest: jakarta/servlet/http/ Implementation-Title jakarta.servlet Medium
Product manifest: jakarta/servlet/http/ Specification-Title Jakarta Servlet Medium
Product manifest: jakarta/servlet/resources/ Implementation-Title jakarta.servlet Medium
Product manifest: jakarta/servlet/resources/ Specification-Title Jakarta Servlet Medium
Product pom artifactid tomcat-embed-core Highest
Product pom groupid org.apache.tomcat.embed Highest
Product pom url https://tomcat.apache.org/ Medium
Version file version 11.0.15 High
Version Manifest Bundle-Version 11.0.15 High
Version Manifest Implementation-Version 11.0.15 High
Version pom version 11.0.15 Highest
Related Dependencies
tomcat-embed-websocket-11.0.15.jar
File Path: /home/runner/.m2/repository/org/apache/tomcat/embed/tomcat-embed-websocket/11.0.15/tomcat-embed-websocket-11.0.15.jar
MD5: 98def64566407991d8121221b7d31fcd
SHA1: 4c0eced7d97fe8404c722d5ff02757a05a6d5033
SHA256: a74b0b165768a7fa9d0fcedce544c71523763f8d25e148f578dd78ce152fb533
pkg:maven/org.apache.tomcat.embed/tomcat-embed-websocket@11.0.15
tomcat-embed-el-11.0.15.jar
Description:
Core Tomcat implementation
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /home/runner/.m2/repository/org/apache/tomcat/embed/tomcat-embed-el/11.0.15/tomcat-embed-el-11.0.15.jar
MD5: 617ed29f43eb23e65f520871beb8bb57
SHA1: f20bc5f17baa18abeca76a640ad774d6f80a265b
SHA256: 18b3c48bb62b1b01a3bbfe8f700574dca365b09f388fe299a65f8579e8e4d22a
Referenced In Project/Scope: waffle-spring-boot-autoconfigure4:compile
tomcat-embed-el-11.0.15.jar is in the transitive dependency tree of the listed items. Included by: pkg:maven/org.springframework.boot/spring-boot-starter-web@4.0.1
Evidence
Type Source Name Value Confidence
Vendor file name tomcat-embed-el High
Vendor jar package name apache Highest
Vendor jar package name el Highest
Vendor Manifest bundle-symbolicname org.apache.tomcat-embed-jasper-el Medium
Vendor Manifest Implementation-Vendor Apache Software Foundation High
Vendor Manifest provide-capability osgi.contract;osgi.contract=JakartaExpressionLanguage;version:Version="6.0";uses:="jakarta.el",osgi.service;objectClass:List="jakarta.el.ExpressionFactory";effective:=active,osgi.serviceloader;osgi.serviceloader="jakarta.el.ExpressionFactory";register:="org.apache.el.ExpressionFactoryImpl" Low
Vendor Manifest specification-vendor Apache Software Foundation Low
Vendor manifest: jakarta/el/ Implementation-Vendor Apache Software Foundation Medium
Vendor pom artifactid tomcat-embed-el Highest
Vendor pom artifactid tomcat-embed-el Low
Vendor pom groupid org.apache.tomcat.embed Highest
Vendor pom url https://tomcat.apache.org/ Highest
Product file name tomcat-embed-el High
Product jar package name apache Highest
Product jar package name el Highest
Product jar package name expression Highest
Product jar package name expressionfactory Highest
Product jar package name expressionfactoryimpl Highest
Product jar package name jakarta Highest
Product Manifest Bundle-Name tomcat-embed-jasper-el Medium
Product Manifest bundle-symbolicname org.apache.tomcat-embed-jasper-el Medium
Product Manifest Implementation-Title Apache Tomcat High
Product Manifest provide-capability osgi.contract;osgi.contract=JakartaExpressionLanguage;version:Version="6.0";uses:="jakarta.el",osgi.service;objectClass:List="jakarta.el.ExpressionFactory";effective:=active,osgi.serviceloader;osgi.serviceloader="jakarta.el.ExpressionFactory";register:="org.apache.el.ExpressionFactoryImpl" Low
Product Manifest specification-title Apache Tomcat Medium
Product manifest: jakarta/el/ Implementation-Title jakarta.annotation Medium
Product manifest: jakarta/el/ Specification-Title Jakarta Expression Language Medium
Product pom artifactid tomcat-embed-el Highest
Product pom groupid org.apache.tomcat.embed Highest
Product pom url https://tomcat.apache.org/ Medium
Version file version 11.0.15 High
Version Manifest Bundle-Version 11.0.15 High
Version Manifest Implementation-Version 11.0.15 High
Version pom version 11.0.15 Highest
pkg:maven/org.apache.tomcat.embed/tomcat-embed-el@11.0.15
(Confidence :High)