Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all ):
dependency-check version : 6.1.5Report Generated On : Wed, 24 Nov 2021 10:25:08 GMTDependencies Scanned : 173 (173 unique)Vulnerable Dependencies : 0 Vulnerabilities Found : 0Vulnerabilities Suppressed : 61... NVD CVE Checked : 2021-11-24T10:12:09NVD CVE Modified : 2021-11-24T06:00:04VersionCheckOn : 2021-11-21T13:35:22Summary Display:
Showing Vulnerable Dependencies (click to show all) Dependencies HdrHistogram-2.1.12.jarDescription:
HdrHistogram supports the recording and analyzing sampled data value
counts across a configurable integer value range with configurable value
precision within the range. Value precision is expressed as the number of
significant digits in the value recording, and provides control over value
quantization behavior across the value range and the subsequent value
resolution at any given level.
License:
Public Domain, per Creative Commons CC0: http://creativecommons.org/publicdomain/zero/1.0/
BSD-2-Clause: https://opensource.org/licenses/BSD-2-Clause File Path: /home/jenkins/.mvnrepository/org/hdrhistogram/HdrHistogram/2.1.12/HdrHistogram-2.1.12.jar
MD5: 4b1acf3448b750cb485da7e37384fcd8
SHA1: 6eb7552156e0d517ae80cc2247be1427c8d90452
SHA256: 9b47fbae444feaac4b7e04f0ea294569e4bc282bc69d8c2ce2ac3f23577281e2
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name hdrhistogram Highest Vendor pom artifactid HdrHistogram Low Vendor Manifest bundle-symbolicname org.hdrhistogram.HdrHistogram Medium Vendor Manifest Implementation-Vendor-Id org.hdrhistogram Medium Vendor file name HdrHistogram High Vendor pom url http://hdrhistogram.github.io/HdrHistogram/ Highest Vendor pom groupid org.hdrhistogram Highest Vendor pom groupid hdrhistogram Highest Vendor pom name HdrHistogram High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product jar package name hdrhistogram Highest Product pom artifactid HdrHistogram Highest Product pom url http://hdrhistogram.github.io/HdrHistogram/ Medium Product jar package name version Highest Product file name HdrHistogram High Product pom groupid hdrhistogram Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product Manifest Bundle-Name HdrHistogram Medium Product Manifest Implementation-Title HdrHistogram High Product Manifest specification-title HdrHistogram Medium Product Manifest bundle-symbolicname org.hdrhistogram.HdrHistogram Medium Product pom name HdrHistogram High Version file version 2.1.12 High Version pom version 2.1.12 Highest Version Manifest Implementation-Version 2.1.12 High Version Manifest Bundle-Version 2.1.12 High
JavaEWAH-1.1.7.jarDescription:
The bit array data structure is implemented in Java as the BitSet class. Unfortunately, this fails to scale without compression.
JavaEWAH is a word-aligned compressed variant of the Java bitset class. It uses a 64-bit run-length encoding (RLE) compression scheme.
The goal of word-aligned compression is not to achieve the best compression, but rather to improve query processing time. Hence, we try to save CPU cycles, maybe at the expense of storage. However, the EWAH scheme we implemented is always more efficient storage-wise than an uncompressed bitmap (implemented in Java as the BitSet class). Unlike some alternatives, javaewah does not rely on a patented scheme. License:
Apache 2: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/com/googlecode/javaewah/JavaEWAH/1.1.7/JavaEWAH-1.1.7.jar
MD5: 32da68b9491cfde9c9194c53033c6bb0
SHA1: 570dde3cd706ae10c62fe19b150928cfdb415e87
SHA256: 3ecf8b2c602314341f5a2ace171ed04fc86f2d4ddf762180656e9b71134ae68f
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid JavaEWAH Low Vendor Manifest bundle-symbolicname com.googlecode.javaewah.JavaEWAH Medium Vendor jar package name javaewah Highest Vendor jar package name bitset Highest Vendor pom url lemire/javaewah Highest Vendor pom groupid com.googlecode.javaewah Highest Vendor jar package name googlecode Highest Vendor pom name JavaEWAH High Vendor file name JavaEWAH High Vendor pom groupid googlecode.javaewah Highest Product pom artifactid JavaEWAH Highest Product Manifest Bundle-Name JavaEWAH Medium Product pom url lemire/javaewah High Product jar package name javaewah Highest Product jar package name bitset Highest Product Manifest bundle-symbolicname com.googlecode.javaewah.JavaEWAH Medium Product jar package name googlecode Highest Product pom name JavaEWAH High Product file name JavaEWAH High Product pom groupid googlecode.javaewah Highest Version file version 1.1.7 High Version pom version 1.1.7 Highest Version Manifest Bundle-Version 1.1.7 High
LatencyUtils-2.0.3.jarDescription:
LatencyUtils is a package that provides latency recording and reporting utilities.
License:
Public Domain, per Creative Commons CC0: http://creativecommons.org/publicdomain/zero/1.0/ File Path: /home/jenkins/.mvnrepository/org/latencyutils/LatencyUtils/2.0.3/LatencyUtils-2.0.3.jar
MD5: 2ad12e1ef7614cecfb0483fa9ac6da73
SHA1: 769c0b82cb2421c8256300e907298a9410a2a3d3
SHA256: a32a9ffa06b2f4e01c5360f8f9df7bc5d9454a5d373cd8f361347fa5a57165ec
Referenced In Project/Scope: Entando Kubernetes Service:runtime
Evidence Type Source Name Value Confidence Vendor pom name LatencyUtils High Vendor pom groupid org.latencyutils Highest Vendor pom url http://latencyutils.github.io/LatencyUtils/ Highest Vendor jar package name latencyutils Highest Vendor pom groupid latencyutils Highest Vendor jar package name latencyutils Low Vendor pom artifactid LatencyUtils Low Vendor file name LatencyUtils High Product pom name LatencyUtils High Product jar package name latencyutils Highest Product pom groupid latencyutils Highest Product pom url http://latencyutils.github.io/LatencyUtils/ Medium Product pom artifactid LatencyUtils Highest Product file name LatencyUtils High Version pom version 2.0.3 Highest Version file version 2.0.3 High
accessors-smart-2.4.7.jarDescription:
Java reflect give poor performance on getter setter an constructor calls, accessors-smart use ASM to speed up those calls. License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/net/minidev/accessors-smart/2.4.7/accessors-smart-2.4.7.jar
MD5: 53cb6c796eb91346af5edb178c42b39b
SHA1: 3970cfc505e6657ca60f3aa57c849f6043000d7a
SHA256: ef5103429f101f7e3ff62f3a182342720439eaea43d2eed3119bba770bb202a9
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor file name accessors-smart High Vendor pom name ASM based accessors helper used by json-smart High Vendor pom artifactid accessors-smart Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom url https://urielch.github.io/ Highest Vendor pom organization url https://urielch.github.io/ Medium Vendor jar package name net Highest Vendor pom groupid net.minidev Highest Vendor jar package name asm Highest Vendor Manifest bundle-symbolicname net.minidev.accessors-smart Medium Vendor Manifest bundle-docurl https://urielch.github.io/ Low Vendor jar package name minidev Highest Vendor pom organization name Chemouni Uriel High Product file name accessors-smart High Product pom name ASM based accessors helper used by json-smart High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product jar package name net Highest Product pom url https://urielch.github.io/ Medium Product jar package name asm Highest Product pom groupid net.minidev Highest Product pom artifactid accessors-smart Highest Product Manifest bundle-symbolicname net.minidev.accessors-smart Medium Product Manifest bundle-docurl https://urielch.github.io/ Low Product jar package name minidev Highest Product Manifest Bundle-Name accessors-smart Medium Product pom organization name Chemouni Uriel Low Product pom organization url https://urielch.github.io/ Low Version Manifest Bundle-Version 2.4.7 High Version pom version 2.4.7 Highest Version file version 2.4.7 High
antlr-2.7.7.jarDescription:
A framework for constructing recognizers, compilers,
and translators from grammatical descriptions containing
Java, C#, C++, or Python actions.
License:
BSD License: http://www.antlr.org/license.html File Path: /home/jenkins/.mvnrepository/antlr/antlr/2.7.7/antlr-2.7.7.jar
MD5: f8f1352c52a4c6a500b597596501fc64
SHA1: 83cd2cd674a217ade95a4bb83a8a14f351f48bd0
SHA256: 88fbda4b912596b9f56e8e12e580cc954bacfb51776ecfddd3e18fc1cf56dc4c
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name java Highest Vendor jar package name python Highest Vendor jar package name antlr Low Vendor jar package name actions Highest Vendor pom groupid antlr Highest Vendor jar package name antlr Highest Vendor pom name AntLR Parser Generator High Vendor pom url http://www.antlr.org/ Highest Vendor pom artifactid antlr Low Vendor file name antlr High Vendor jar package name parser Highest Product jar package name java Highest Product jar package name python Highest Product jar package name actions Highest Product pom groupid antlr Highest Product jar package name antlr Highest Product pom name AntLR Parser Generator High Product file name antlr High Product jar package name parser Highest Product pom artifactid antlr Highest Product pom url http://www.antlr.org/ Medium Version file version 2.7.7 High Version pom version 2.7.7 Highest
apiguardian-api-1.1.0.jarDescription:
@API Guardian License:
The Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/org/apiguardian/apiguardian-api/1.1.0/apiguardian-api-1.1.0.jar
MD5: 944805817b648e558ed6be6fc7f054f3
SHA1: fc9dff4bb36d627bdc553de77e1f17efd790876c
SHA256: a9aae9ff8ae3e17a2a18f79175e82b16267c246fbbd3ca9dfbbb290b08dcfdd4
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom url apiguardian-team/apiguardian Highest Vendor jar package name apiguardian Highest Vendor pom groupid org.apiguardian Highest Vendor Manifest build-time 21:07:38.516+0200 Low Vendor Manifest build-revision e7f98b22d3b2a54033711e2666a047d1066b0b25 Low Vendor Manifest build-date 2019-06-06 Low Vendor pom groupid apiguardian Highest Vendor Manifest Implementation-Vendor apiguardian.org High Vendor pom name org.apiguardian:apiguardian-api High Vendor pom artifactid apiguardian-api Low Vendor file name apiguardian-api High Vendor jar package name api Highest Vendor Manifest specification-vendor apiguardian.org Low Product jar package name apiguardian Highest Product Manifest build-time 21:07:38.516+0200 Low Product pom artifactid apiguardian-api Highest Product Manifest build-revision e7f98b22d3b2a54033711e2666a047d1066b0b25 Low Product Manifest build-date 2019-06-06 Low Product pom groupid apiguardian Highest Product pom name org.apiguardian:apiguardian-api High Product Manifest specification-title apiguardian-api Medium Product pom url apiguardian-team/apiguardian High Product Manifest Implementation-Title apiguardian-api High Product file name apiguardian-api High Product jar package name api Highest Version Manifest Implementation-Version 1.1.0 High Version pom version 1.1.0 Highest Version file version 1.1.0 High
asm-9.1.jarDescription:
ASM, a very small and fast Java bytecode manipulation framework License:
BSD-3-Clause: https://asm.ow2.io/license.html File Path: /home/jenkins/.mvnrepository/org/ow2/asm/asm/9.1/asm-9.1.jar
MD5: 54b9f5d15e4877a4ea4cf9ec48e07afa
SHA1: a99500cf6eea30535eeac6be73899d048f8d12a8
SHA256: cda4de455fab48ff0bcb7c48b4639447d4de859a7afc30a094a986f0936beba2
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name objectweb Highest Vendor file name asm High Vendor pom parent-artifactid ow2 Low Vendor pom organization url http://www.ow2.org/ Medium Vendor pom groupid org.ow2.asm Highest Vendor pom artifactid asm Low Vendor pom name asm High Vendor jar package name asm Highest Vendor pom url http://asm.ow2.io/ Highest Vendor pom organization name OW2 High Vendor Manifest bundle-symbolicname org.objectweb.asm Medium Vendor pom parent-groupid org.ow2 Medium Vendor Manifest bundle-docurl http://asm.ow2.org Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor pom groupid ow2.asm Highest Product jar package name objectweb Highest Product file name asm High Product pom artifactid asm Highest Product pom organization name OW2 Low Product pom name asm High Product jar package name asm Highest Product pom parent-artifactid ow2 Medium Product Manifest bundle-symbolicname org.objectweb.asm Medium Product pom parent-groupid org.ow2 Medium Product pom organization url http://www.ow2.org/ Low Product pom url http://asm.ow2.io/ Medium Product Manifest bundle-docurl http://asm.ow2.org Low Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest Bundle-Name org.objectweb.asm Medium Product pom groupid ow2.asm Highest Product Manifest Implementation-Title ASM, a very small and fast Java bytecode manipulation framework High Version Manifest Implementation-Version 9.1 High Version pom parent-version 9.1 Low Version file version 9.1 High Version pom version 9.1 Highest
automaton-1.11-8.jarDescription:
A DFA/NFA (finite-state automata) implementation with
Unicode alphabet (UTF16) and support for the standard regular
expression operations (concatenation, union, Kleene star) and a number
of non-standard ones (intersection, complement, etc.) License:
BSD: http://www.opensource.org/licenses/bsd-license.php File Path: /home/jenkins/.mvnrepository/dk/brics/automaton/automaton/1.11-8/automaton-1.11-8.jar
MD5: 3467dcbbba2fe68a4e07a5826988e034
SHA1: 6ebfa65eb431ff4b715a23be7a750cbc4cc96d0f
SHA256: a24475f6ccfe1cc7a4fe9e34e05ce687b0ce0c6e8cb781e0eced3b186482c61e
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom url http://www.brics.dk/automaton/ Highest Vendor jar package name dk Highest Vendor jar package name state Highest Vendor pom name Automaton High Vendor jar package name brics Highest Vendor pom groupid dk.brics.automaton Highest Vendor jar package name automaton Highest Vendor pom artifactid automaton Low Vendor jar package name automaton Low Vendor jar package name brics Low Vendor file name automaton High Vendor jar package name dk Low Product jar package name brics Highest Product pom groupid dk.brics.automaton Highest Product jar package name automaton Highest Product pom url http://www.brics.dk/automaton/ Medium Product pom artifactid automaton Highest Product jar package name automaton Low Product jar package name dk Highest Product jar package name brics Low Product jar package name state Highest Product file name automaton High Product pom name Automaton High Version pom version 1.11-8 Highest
awaitility-4.0.1.jarDescription:
A Java DSL for synchronizing asynchronous operations License:
LICENSE.txt File Path: /home/jenkins/.mvnrepository/org/awaitility/awaitility/4.0.1/awaitility-4.0.1.jar
MD5: 9f8f697377751b4dbf53f377bda2dcce
SHA1: b1b83c03c9d58c8b1aaf116b1e5365fa2ed2b572
SHA256: b6660aa2fdbda01570713894dae0b5cb1688012ad7af1ad8a6c03b42ef6d3d08
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid awaitility Low Vendor pom groupid org.awaitility Highest Vendor jar package name awaitility Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom url http://awaitility.org Highest Vendor Manifest bundle-symbolicname org.awaitility Medium Vendor pom parent-groupid org.awaitility Medium Vendor pom parent-artifactid awaitility-parent Low Vendor pom name Awaitility High Vendor file name awaitility High Vendor pom groupid awaitility Highest Product pom artifactid awaitility Highest Product pom parent-artifactid awaitility-parent Medium Product Manifest Bundle-Name Awaitility Medium Product jar package name awaitility Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom url http://awaitility.org Medium Product Manifest bundle-symbolicname org.awaitility Medium Product pom parent-groupid org.awaitility Medium Product pom name Awaitility High Product file name awaitility High Product pom groupid awaitility Highest Version pom version 4.0.1 Highest Version file version 4.0.1 High Version Manifest Bundle-Version 4.0.1 High
bcpg-jdk15on-1.64.jarDescription:
The Bouncy Castle Java API for handling the OpenPGP protocol. This jar contains the OpenPGP API for JDK 1.5 to JDK 11. The APIs can be used in conjunction with a JCE/JCA provider such as the one provided with the Bouncy Castle Cryptography APIs. License:
Bouncy Castle Licence: https://www.bouncycastle.org/licence.html
Apache Software License, Version 1.1: https://www.apache.org/licenses/LICENSE-1.1 File Path: /home/jenkins/.mvnrepository/org/bouncycastle/bcpg-jdk15on/1.64/bcpg-jdk15on-1.64.jar
MD5: 498ac36829826fe4b0d12af9550b5b0c
SHA1: 56956a8c63ccadf62e7c678571cf86f30bd84441
SHA256: 10acaf221fc4e49d4a4067b02316271698e8742ef4b23cb5f2434a0e3502b7b4
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid bcpg-jdk15on Low Vendor Manifest application-library-allowable-codebase * Low Vendor pom groupid bouncycastle Highest Vendor jar package name bouncycastle Highest Vendor Manifest trusted-library true Low Vendor jar package name openpgp Highest Vendor Manifest application-name Bouncy Castle OpenPGP API Medium Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor pom url https://www.bouncycastle.org/java.html Highest Vendor Manifest automatic-module-name org.bouncycastle.pg Medium Vendor Manifest originally-created-by 25.222-b10 (Private Build) Low Vendor Manifest permissions all-permissions Low Vendor Manifest Implementation-Vendor-Id org.bouncycastle Medium Vendor pom groupid org.bouncycastle Highest Vendor Manifest bundle-symbolicname bcpg Medium Vendor Manifest extension-name org.bouncycastle.bcpg Medium Vendor jar package name bcpg Highest Vendor Manifest specification-vendor BouncyCastle.org Low Vendor file name bcpg-jdk15on High Vendor Manifest caller-allowable-codebase * Low Vendor Manifest codebase * Low Vendor pom name Bouncy Castle OpenPGP API High Vendor Manifest Implementation-Vendor BouncyCastle.org High Vendor Manifest multi-release true Low Product pom artifactid bcpg-jdk15on Highest Product Manifest bundle-symbolicname bcpg Medium Product Manifest application-library-allowable-codebase * Low Product Manifest extension-name org.bouncycastle.bcpg Medium Product Manifest Bundle-Name bcpg Medium Product pom url https://www.bouncycastle.org/java.html Medium Product jar package name bcpg Highest Product pom groupid bouncycastle Highest Product file name bcpg-jdk15on High Product Manifest caller-allowable-codebase * Low Product jar package name bouncycastle Highest Product Manifest trusted-library true Low Product jar package name openpgp Highest Product Manifest codebase * Low Product pom name Bouncy Castle OpenPGP API High Product Manifest application-name Bouncy Castle OpenPGP API Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest multi-release true Low Product Manifest automatic-module-name org.bouncycastle.pg Medium Product Manifest originally-created-by 25.222-b10 (Private Build) Low Product Manifest permissions all-permissions Low Version pom version 1.64 Highest Version Manifest Bundle-Version 1.64 High Version file version 1.64 High
bcpkix-jdk15on-1.64.jarDescription:
The Bouncy Castle Java APIs for CMS, PKCS, EAC, TSP, CMP, CRMF, OCSP, and certificate generation. This jar contains APIs for JDK 1.5 to JDK 11. The APIs can be used in conjunction with a JCE/JCA provider such as the one provided with the Bouncy Castle Cryptography APIs. License:
Bouncy Castle Licence: https://www.bouncycastle.org/licence.html File Path: /home/jenkins/.mvnrepository/org/bouncycastle/bcpkix-jdk15on/1.64/bcpkix-jdk15on-1.64.jar
MD5: ac323fe2770d772e94bb7bc3249904e5
SHA1: 3dac163e20110817d850d17e0444852a6d7d0bd7
SHA256: 84669138b1d99143e2c009024f67824ab8d3edb9b05b7591f5ebfb020a4bda71
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name tsp Highest Vendor Manifest bundle-symbolicname bcpkix Medium Vendor Manifest application-library-allowable-codebase * Low Vendor jar package name eac Highest Vendor Manifest extension-name org.bouncycastle.bcpkix Medium Vendor pom groupid bouncycastle Highest Vendor jar package name pkcs Highest Vendor jar package name bouncycastle Highest Vendor pom name Bouncy Castle PKIX, CMS, EAC, TSP, PKCS, OCSP, CMP, and CRMF APIs High Vendor Manifest trusted-library true Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor pom url https://www.bouncycastle.org/java.html Highest Vendor Manifest originally-created-by 25.222-b10 (Private Build) Low Vendor Manifest permissions all-permissions Low Vendor Manifest Implementation-Vendor-Id org.bouncycastle Medium Vendor jar package name crmf Highest Vendor pom groupid org.bouncycastle Highest Vendor Manifest automatic-module-name org.bouncycastle.pkix Medium Vendor file name bcpkix-jdk15on High Vendor Manifest specification-vendor BouncyCastle.org Low Vendor jar package name cms Highest Vendor Manifest caller-allowable-codebase * Low Vendor Manifest codebase * Low Vendor pom artifactid bcpkix-jdk15on Low Vendor Manifest Implementation-Vendor BouncyCastle.org High Vendor jar package name pkix Highest Vendor Manifest multi-release true Low Vendor jar package name ocsp Highest Vendor jar package name cmp Highest Vendor Manifest application-name Bouncy Castle PKIX API Medium Product jar package name tsp Highest Product Manifest bundle-symbolicname bcpkix Medium Product Manifest application-library-allowable-codebase * Low Product jar package name eac Highest Product Manifest extension-name org.bouncycastle.bcpkix Medium Product pom groupid bouncycastle Highest Product jar package name pkcs Highest Product jar package name bouncycastle Highest Product pom name Bouncy Castle PKIX, CMS, EAC, TSP, PKCS, OCSP, CMP, and CRMF APIs High Product Manifest trusted-library true Low Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest originally-created-by 25.222-b10 (Private Build) Low Product pom artifactid bcpkix-jdk15on Highest Product Manifest permissions all-permissions Low Product jar package name crmf Highest Product pom url https://www.bouncycastle.org/java.html Medium Product Manifest automatic-module-name org.bouncycastle.pkix Medium Product file name bcpkix-jdk15on High Product jar package name cms Highest Product Manifest caller-allowable-codebase * Low Product Manifest Bundle-Name bcpkix Medium Product Manifest codebase * Low Product jar package name pkix Highest Product Manifest multi-release true Low Product jar package name ocsp Highest Product jar package name cmp Highest Product Manifest application-name Bouncy Castle PKIX API Medium Version pom version 1.64 Highest Version Manifest Bundle-Version 1.64 High Version file version 1.64 High
bcprov-jdk15on-1.67.jarDescription:
The Bouncy Castle Crypto package is a Java implementation of cryptographic algorithms. This jar contains JCE provider and lightweight API for the Bouncy Castle Cryptography APIs for JDK 1.5 and up. License:
Bouncy Castle Licence: http://www.bouncycastle.org/licence.html File Path: /home/jenkins/.mvnrepository/org/bouncycastle/bcprov-jdk15on/1.67/bcprov-jdk15on-1.67.jar
MD5: adec6e4828f2438d31715a23889b0bcc
SHA1: 8c0998045da87dbc2f1d4b6480458ed811ca7b82
SHA256: fa0041a36f9f20af3c6b8dbf6eb49a969e2c9cc029049d61acc526ba3247b3ef
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name provider Highest Vendor pom artifactid bcprov-jdk15on Low Vendor pom name Bouncy Castle Provider High Vendor Manifest automatic-module-name org.bouncycastle.provider Medium Vendor Manifest application-library-allowable-codebase * Low Vendor pom groupid bouncycastle Highest Vendor jar package name bouncycastle Highest Vendor Manifest trusted-library true Low Vendor Manifest extension-name org.bouncycastle.bcprovider Medium Vendor Manifest application-name Bouncy Castle Provider Medium Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor Manifest originally-created-by 25.272-b10 (Private Build) Low Vendor Manifest permissions all-permissions Low Vendor Manifest Implementation-Vendor-Id org.bouncycastle Medium Vendor pom groupid org.bouncycastle Highest Vendor file name bcprov-jdk15on High Vendor Manifest specification-vendor BouncyCastle.org Low Vendor pom url http://www.bouncycastle.org/java.html Highest Vendor Manifest caller-allowable-codebase * Low Vendor Manifest bundle-symbolicname bcprov Medium Vendor Manifest codebase * Low Vendor jar package name crypto Highest Vendor Manifest Implementation-Vendor BouncyCastle.org High Vendor jar package name org Highest Vendor Manifest multi-release true Low Vendor jar package name jce Highest Product hint analyzer product legion-of-the-bouncy-castle-java-crytography-api High Product jar package name provider Highest Product pom name Bouncy Castle Provider High Product Manifest automatic-module-name org.bouncycastle.provider Medium Product pom artifactid bcprov-jdk15on Highest Product Manifest application-library-allowable-codebase * Low Product pom groupid bouncycastle Highest Product jar package name bouncycastle Highest Product Manifest trusted-library true Low Product Manifest extension-name org.bouncycastle.bcprovider Medium Product Manifest application-name Bouncy Castle Provider Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product Manifest originally-created-by 25.272-b10 (Private Build) Low Product Manifest permissions all-permissions Low Product pom url http://www.bouncycastle.org/java.html Medium Product file name bcprov-jdk15on High Product Manifest caller-allowable-codebase * Low Product Manifest bundle-symbolicname bcprov Medium Product Manifest codebase * Low Product jar package name crypto Highest Product Manifest multi-release true Low Product jar package name org Highest Product jar package name jce Highest Product Manifest Bundle-Name bcprov Medium Version pom version 1.67 Highest Version file version 1.67 High Version Manifest Bundle-Version 1.67 High
pkg:maven/org.bouncycastle/bcprov-jdk15on@1.67 (Confidence :High)cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle:1.67:*:*:*:*:*:*:* (Confidence :Low) suppress cpe:2.3:a:bouncycastle:legion-of-the-bouncy-castle-java-crytography-api:1.67:*:*:*:*:*:*:* (Confidence :Low) suppress byte-buddy-1.9.16.jarDescription:
Byte Buddy is a Java library for creating Java classes at run time.
This artifact is a build of Byte Buddy with all ASM dependencies repackaged into its own name space.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/net/bytebuddy/byte-buddy/1.9.16/byte-buddy-1.9.16.jar
MD5: 5f70996f05d320703b4a8ebd2657dcdd
SHA1: e7d63009be7b87ff1f15b72e5b8c59c897a8d8bd
SHA256: 6b71e4f70c96b67d420f592148aa4fd1966aba458b35d11f491ff13de97dc862
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom name Byte Buddy (without dependencies) High Vendor pom parent-artifactid byte-buddy-parent Low Vendor pom groupid net.bytebuddy Highest Vendor Manifest bundle-symbolicname net.bytebuddy.byte-buddy Medium Vendor jar package name bytebuddy Highest Vendor file name byte-buddy High Vendor jar package name net Highest Vendor Manifest multi-release true Low Vendor jar package name build Highest Vendor jar package name asm Highest Vendor pom artifactid byte-buddy Low Product pom name Byte Buddy (without dependencies) High Product pom artifactid byte-buddy Highest Product file name byte-buddy High Product Manifest Bundle-Name Byte Buddy (without dependencies) Medium Product jar package name net Highest Product pom parent-artifactid byte-buddy-parent Medium Product jar package name asm Highest Product pom groupid net.bytebuddy Highest Product Manifest bundle-symbolicname net.bytebuddy.byte-buddy Medium Product jar package name bytebuddy Highest Product Manifest multi-release true Low Product jar package name build Highest Version Manifest Bundle-Version 1.9.16 High Version pom version 1.9.16 Highest Version file version 1.9.16 High
byte-buddy-1.9.16.jar (shaded: net.bytebuddy:byte-buddy-dep:1.9.16)Description:
Byte Buddy is a Java library for creating Java classes at run time.
This artifact is a build of Byte Buddy with a remaining dependency onto ASM.
You should never depend on this module without repackaging Byte Buddy and ASM into your own namespace.
File Path: /home/jenkins/.mvnrepository/net/bytebuddy/byte-buddy/1.9.16/byte-buddy-1.9.16.jar/META-INF/maven/net.bytebuddy/byte-buddy-dep/pom.xmlMD5: 075a226f7deb87c6dee195c79fadf984SHA1: 5d488c03efcaee9285f5bb1d51200beddc8e2235SHA256: 594d3dae331688e9fd5b0606bbc69a9f021961baa853d83b17af7e0f862ee31dReferenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid byte-buddy-parent Low Vendor pom name Byte Buddy (with dependencies) High Vendor pom artifactid byte-buddy-dep Low Vendor pom groupid net.bytebuddy Highest Product pom name Byte Buddy (with dependencies) High Product pom groupid net.bytebuddy Highest Product pom parent-artifactid byte-buddy-parent Medium Product pom artifactid byte-buddy-dep Highest Version pom version 1.9.16 Highest
caffeine-2.9.2.jarDescription:
A high performance caching library License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/com/github/ben-manes/caffeine/caffeine/2.9.2/caffeine-2.9.2.jar
MD5: 7aa86dc0c185691ebfedf507cd02f0bf
SHA1: 0a17ed335e0ce2d337750772c0709b79af35a842
SHA256: ff0245864c6d38c2129981b5f0efc8146057fe4a55497c2345aeded46a2513b9
Referenced In Project/Scope: Entando Kubernetes Service:runtime
Evidence Type Source Name Value Confidence Vendor pom groupid github.ben-manes.caffeine Highest Vendor jar package name benmanes Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor jar package name cache Highest Vendor file name caffeine High Vendor Manifest automatic-module-name com.github.benmanes.caffeine Medium Vendor jar package name caffeine Highest Vendor pom groupid com.github.ben-manes.caffeine Highest Vendor Manifest bundle-symbolicname com.github.ben-manes.caffeine Medium Vendor pom url ben-manes/caffeine Highest Vendor jar package name github Highest Vendor pom name Caffeine cache High Vendor pom artifactid caffeine Low Product pom groupid github.ben-manes.caffeine Highest Product jar package name benmanes Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product jar package name cache Highest Product file name caffeine High Product Manifest Bundle-Name com.github.ben-manes.caffeine Medium Product Manifest automatic-module-name com.github.benmanes.caffeine Medium Product jar package name caffeine Highest Product pom artifactid caffeine Highest Product pom url ben-manes/caffeine High Product Manifest bundle-symbolicname com.github.ben-manes.caffeine Medium Product jar package name github Highest Product pom name Caffeine cache High Version file version 2.9.2 High Version pom version 2.9.2 Highest Version Manifest Bundle-Version 2.9.2 High
checker-qual-3.10.0.jarDescription:
checker-qual contains annotations (type qualifiers)
used by the Checker Framework to type-check Java source code.
Please see artifact: org.checkerframework:checker License:
The MIT License: http://opensource.org/licenses/MIT File Path: /home/jenkins/.mvnrepository/org/checkerframework/checker-qual/3.10.0/checker-qual-3.10.0.jar
MD5: d7e964cf19235ee401c48383306aec86
SHA1: 710fd6abff4b26b40dc0917050dc4c67efcf60b6
SHA256: a4dc882ca6aac496d33381e5e5eb0604c45483b004bc3eac9368f1bb17cb2512
Referenced In Project/Scope: Entando Kubernetes Service:runtime
Evidence Type Source Name Value Confidence Vendor file name checker-qual High Vendor jar package name qual Highest Vendor pom artifactid checker-qual Low Vendor pom url https://checkerframework.org Highest Vendor Manifest implementation-url https://checkerframework.org Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest automatic-module-name org.checkerframework.checker.qual Medium Vendor Manifest bundle-symbolicname checker-qual Medium Vendor pom name Checker Qual High Vendor pom groupid org.checkerframework Highest Vendor jar package name checker Highest Vendor pom groupid checkerframework Highest Vendor jar package name framework Highest Vendor jar package name checkerframework Highest Product file name checker-qual High Product jar package name qual Highest Product Manifest implementation-url https://checkerframework.org Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest automatic-module-name org.checkerframework.checker.qual Medium Product Manifest bundle-symbolicname checker-qual Medium Product pom artifactid checker-qual Highest Product pom url https://checkerframework.org Medium Product pom name Checker Qual High Product jar package name checker Highest Product Manifest Bundle-Name checker-qual Medium Product pom groupid checkerframework Highest Product jar package name framework Highest Product jar package name checkerframework Highest Version file version 3.10.0 High Version Manifest Bundle-Version 3.10.0 High Version Manifest Implementation-Version 3.10.0 High Version pom version 3.10.0 Highest
classgraph-4.8.69.jarDescription:
The uber-fast, ultra-lightweight classpath and module scanner for JVM languages. License:
The MIT License (MIT): http://opensource.org/licenses/MIT File Path: /home/jenkins/.mvnrepository/io/github/classgraph/classgraph/4.8.69/classgraph-4.8.69.jar
MD5: 8efc889aefd4c9cbe12ffcef62443d70
SHA1: 6bd8c9033563e162b5c12de12b139724dbf71f48
SHA256: 0d895e0d92e992c0dc5156c89629553740c1b5c976927fee4d32b704f2f37105
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest bundle-symbolicname io.github.classgraph.classgraph Medium Vendor file name classgraph High Vendor pom groupid io.github.classgraph Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor jar package name classgraph Highest Vendor Manifest bundle-category Utilities Low Vendor Manifest build-jdk-spec 1.8 Low Vendor pom artifactid classgraph Low Vendor jar package name io Highest Vendor jar package name scanner Highest Vendor pom url classgraph/classgraph Highest Vendor Manifest multi-release true Low Vendor jar package name github Highest Vendor pom name ClassGraph High Product Manifest Bundle-Name ClassGraph Medium Product Manifest bundle-symbolicname io.github.classgraph.classgraph Medium Product Manifest specification-title ClassGraph Medium Product file name classgraph High Product Manifest Implementation-Title ClassGraph High Product pom groupid io.github.classgraph Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product pom artifactid classgraph Highest Product jar package name classgraph Highest Product Manifest bundle-category Utilities Low Product Manifest build-jdk-spec 1.8 Low Product jar package name scanner Highest Product jar package name io Highest Product pom url classgraph/classgraph High Product Manifest multi-release true Low Product jar package name github Highest Product pom name ClassGraph High Version file version 4.8.69 High Version Manifest Bundle-Version 4.8.69 High Version Manifest Implementation-Version 4.8.69 High Version pom version 4.8.69 Highest
classmate-1.5.1.jarDescription:
Library for introspecting types with full generic information
including resolving of field and method types.
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/com/fasterxml/classmate/1.5.1/classmate-1.5.1.jar
MD5: e91fcd30ba329fd1b0b6dc5321fd067c
SHA1: 3fe0bed568c62df5e89f4f174c101eab25345b6c
SHA256: aab4de3006808c09d25dd4ff4a3611cfb63c95463cfd99e73d2e1680d229a33b
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-groupid com.fasterxml Medium Vendor jar package name types Highest Vendor pom artifactid classmate Low Vendor pom name ClassMate High Vendor Manifest Implementation-Vendor fasterxml.com High Vendor Manifest automatic-module-name com.fasterxml.classmate Medium Vendor Manifest implementation-build-date 2019-10-19 22:46:35+0000 Low Vendor jar package name fasterxml Highest Vendor Manifest specification-vendor fasterxml.com Low Vendor pom organization name fasterxml.com High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor jar package name classmate Highest Vendor Manifest bundle-symbolicname com.fasterxml.classmate Medium Vendor pom groupid com.fasterxml Highest Vendor pom url FasterXML/java-classmate Highest Vendor Manifest Implementation-Vendor-Id com.fasterxml Medium Vendor pom groupid fasterxml Highest Vendor file name classmate High Vendor pom parent-artifactid oss-parent Low Vendor Manifest bundle-docurl https://github.com/FasterXML/java-classmate Low Vendor pom organization url https://fasterxml.com Medium Product Manifest specification-title ClassMate Medium Product pom parent-groupid com.fasterxml Medium Product pom organization name fasterxml.com Low Product Manifest Implementation-Title ClassMate High Product jar package name types Highest Product Manifest Bundle-Name ClassMate Medium Product pom name ClassMate High Product pom url FasterXML/java-classmate High Product pom organization url https://fasterxml.com Low Product Manifest automatic-module-name com.fasterxml.classmate Medium Product Manifest implementation-build-date 2019-10-19 22:46:35+0000 Low Product pom parent-artifactid oss-parent Medium Product jar package name fasterxml Highest Product jar package name filter Highest Product pom artifactid classmate Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product jar package name classmate Highest Product Manifest bundle-symbolicname com.fasterxml.classmate Medium Product pom groupid fasterxml Highest Product file name classmate High Product Manifest bundle-docurl https://github.com/FasterXML/java-classmate Low Version file version 1.5.1 High Version Manifest Bundle-Version 1.5.1 High Version Manifest Implementation-Version 1.5.1 High Version pom parent-version 1.5.1 Low Version pom version 1.5.1 Highest
commons-codec-1.15.jarDescription:
The Apache Commons Codec package contains simple encoder and decoders for
various formats such as Base64 and Hexadecimal. In addition to these
widely used encoders and decoders, the codec package also maintains a
collection of phonetic encoding utilities.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/commons-codec/commons-codec/1.15/commons-codec-1.15.jar
MD5: 303baf002ce6d382198090aedd9d79a2
SHA1: 49d94806b6e3dc933dacbd8acb0fdbab8ebd1e5d
SHA256: b3e9f6d63a790109bf0d056611fbed1cf69055826defeb9894a71369d246ed63
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid commons-parent Low Vendor pom name Apache Commons Codec High Vendor pom parent-groupid org.apache.commons Medium Vendor file name commons-codec High Vendor pom groupid commons-codec Highest Vendor jar package name commons Highest Vendor pom url https://commons.apache.org/proper/commons-codec/ Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor Manifest build-jdk-spec 1.8 Low Vendor pom artifactid commons-codec Low Vendor jar package name codec Highest Vendor Manifest automatic-module-name org.apache.commons.codec Medium Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-codec/ Low Vendor jar package name apache Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest bundle-symbolicname org.apache.commons.commons-codec Medium Vendor jar package name encoder Highest Product pom name Apache Commons Codec High Product pom parent-groupid org.apache.commons Medium Product file name commons-codec High Product pom groupid commons-codec Highest Product jar package name commons Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product pom artifactid commons-codec Highest Product Manifest build-jdk-spec 1.8 Low Product pom parent-artifactid commons-parent Medium Product Manifest Implementation-Title Apache Commons Codec High Product Manifest specification-title Apache Commons Codec Medium Product jar package name codec Highest Product Manifest automatic-module-name org.apache.commons.codec Medium Product pom url https://commons.apache.org/proper/commons-codec/ Medium Product Manifest bundle-docurl https://commons.apache.org/proper/commons-codec/ Low Product jar package name apache Highest Product Manifest Bundle-Name Apache Commons Codec Medium Product jar package name encoder Highest Product Manifest bundle-symbolicname org.apache.commons.commons-codec Medium Version pom version 1.15 Highest Version pom parent-version 1.15 Low Version file version 1.15 High Version Manifest Implementation-Version 1.15 High
commons-collections4-4.4.jarDescription:
The Apache Commons Collections package contains types that extend and augment the Java Collections Framework. License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/org/apache/commons/commons-collections4/4.4/commons-collections4-4.4.jar
MD5: 4a37023740719b391f10030362c86be6
SHA1: 62ebe7544cb7164d87e0637a2a6a2bdc981395e8
SHA256: 1df8b9430b5c8ed143d7815e403e33ef5371b2400aadbe9bda0883762e0846d1
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid commons-parent Low Vendor Manifest bundle-symbolicname org.apache.commons.commons-collections4 Medium Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-collections/ Low Vendor pom parent-groupid org.apache.commons Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor jar package name commons Highest Vendor pom name Apache Commons Collections High Vendor jar package name collections4 Highest Vendor Manifest automatic-module-name org.apache.commons.collections4 Medium Vendor pom artifactid commons-collections4 Low Vendor pom groupid org.apache.commons Highest Vendor pom url https://commons.apache.org/proper/commons-collections/ Highest Vendor file name commons-collections4 High Vendor Manifest implementation-url https://commons.apache.org/proper/commons-collections/ Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor jar package name apache Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache.commons Medium Vendor pom groupid apache.commons Highest Product pom url https://commons.apache.org/proper/commons-collections/ Medium Product Manifest bundle-symbolicname org.apache.commons.commons-collections4 Medium Product Manifest bundle-docurl https://commons.apache.org/proper/commons-collections/ Low Product Manifest Implementation-Title Apache Commons Collections High Product pom parent-groupid org.apache.commons Medium Product Manifest specification-title Apache Commons Collections Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product jar package name commons Highest Product Manifest Bundle-Name Apache Commons Collections Medium Product pom name Apache Commons Collections High Product jar package name collections4 Highest Product Manifest automatic-module-name org.apache.commons.collections4 Medium Product pom artifactid commons-collections4 Highest Product pom parent-artifactid commons-parent Medium Product file name commons-collections4 High Product Manifest implementation-url https://commons.apache.org/proper/commons-collections/ Low Product jar package name apache Highest Product pom groupid apache.commons Highest Version pom version 4.4 Highest Version Manifest Implementation-Version 4.4 High Version file version 4.4 High Version pom parent-version 4.4 Low
commons-compress-1.21.jarDescription:
Apache Commons Compress software defines an API for working with
compression and archive formats. These include: bzip2, gzip, pack200,
lzma, xz, Snappy, traditional Unix Compress, DEFLATE, DEFLATE64, LZ4,
Brotli, Zstandard and ar, cpio, jar, tar, zip, dump, 7z, arj.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/org/apache/commons/commons-compress/1.21/commons-compress-1.21.jar
MD5: 2a713d10331bc4e13459a3dc0463f16f
SHA1: 4ec95b60d4e86b5c95a0e919cb172a0af98011ef
SHA256: 6aecfd5459728a595601cfa07258d131972ffc39b492eb48bdd596577a2f244a
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid commons-compress Low Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor Manifest bundle-symbolicname org.apache.commons.commons-compress Medium Vendor Manifest implementation-build UNKNOWN@r60e3d9f6bef1e431f8738e881c051d706f81e6cf; 2021-07-09 16:56:00+0000 Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom url https://commons.apache.org/proper/commons-compress/ Highest Vendor jar package name compress Highest Vendor jar package name commons Highest Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-compress/ Low Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest extension-name org.apache.commons.compress Medium Vendor pom groupid org.apache.commons Highest Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor file name commons-compress High Vendor pom name Apache Commons Compress High Vendor Manifest automatic-module-name org.apache.commons.compress Medium Vendor jar package name apache Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor pom groupid apache.commons Highest Product pom parent-groupid org.apache.commons Medium Product pom artifactid commons-compress Highest Product Manifest bundle-symbolicname org.apache.commons.commons-compress Medium Product Manifest implementation-build UNKNOWN@r60e3d9f6bef1e431f8738e881c051d706f81e6cf; 2021-07-09 16:56:00+0000 Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product jar package name compress Highest Product jar package name commons Highest Product Manifest Implementation-Title Apache Commons Compress High Product pom url https://commons.apache.org/proper/commons-compress/ Medium Product Manifest bundle-docurl https://commons.apache.org/proper/commons-compress/ Low Product Manifest build-jdk-spec 1.8 Low Product Manifest extension-name org.apache.commons.compress Medium Product pom parent-artifactid commons-parent Medium Product Manifest Bundle-Name Apache Commons Compress Medium Product file name commons-compress High Product pom name Apache Commons Compress High Product Manifest automatic-module-name org.apache.commons.compress Medium Product jar package name apache Highest Product Manifest specification-title Apache Commons Compress Medium Product pom groupid apache.commons Highest Version pom version 1.21 Highest Version file version 1.21 High Version Manifest Implementation-Version 1.21 High Version pom parent-version 1.21 Low
commons-io-2.8.0.jarDescription:
The Apache Commons IO library contains utility classes, stream implementations, file filters,
file comparators, endian transformation classes, and much more.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/commons-io/commons-io/2.8.0/commons-io-2.8.0.jar
MD5: 21ba575792e2694c39af13918a80550b
SHA1: 92999e26e6534606b5678014e66948286298a35c
SHA256: 02f291e5d1243dc143496e3cbbb40a1ced47aa58f2d633d3e38780cd068d5074
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor pom groupid commons-io Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor jar package name commons Highest Vendor Manifest automatic-module-name org.apache.commons.io Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor pom artifactid commons-io Low Vendor jar package name io Highest Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-io/ Low Vendor file name commons-io High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor jar package name file Highest Vendor pom url https://commons.apache.org/proper/commons-io/ Highest Vendor jar package name apache Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest bundle-symbolicname org.apache.commons.commons-io Medium Vendor pom name Apache Commons IO High Product pom parent-groupid org.apache.commons Medium Product pom groupid commons-io Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest Implementation-Title Apache Commons IO High Product jar package name commons Highest Product Manifest Bundle-Name Apache Commons IO Medium Product Manifest automatic-module-name org.apache.commons.io Medium Product pom artifactid commons-io Highest Product Manifest build-jdk-spec 1.8 Low Product pom url https://commons.apache.org/proper/commons-io/ Medium Product pom parent-artifactid commons-parent Medium Product jar package name io Highest Product Manifest bundle-docurl https://commons.apache.org/proper/commons-io/ Low Product file name commons-io High Product Manifest specification-title Apache Commons IO Medium Product jar package name file Highest Product jar package name apache Highest Product Manifest bundle-symbolicname org.apache.commons.commons-io Medium Product pom name Apache Commons IO High Version Manifest Implementation-Version 2.8.0 High Version pom parent-version 2.8.0 Low Version Manifest Bundle-Version 2.8.0 High Version file version 2.8.0 High Version pom version 2.8.0 Highest
commons-lang3-3.12.0.jarDescription:
Apache Commons Lang, a package of Java utility classes for the
classes that are in java.lang's hierarchy, or are considered to be so
standard as to justify existence in java.lang.
License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/org/apache/commons/commons-lang3/3.12.0/commons-lang3-3.12.0.jar
MD5: 19fe50567358922bdad277959ea69545
SHA1: c6842c86792ff03b9f1d1fe2aab8dc23aa6c6f0e
SHA256: d919d904486c037f8d193412da0c92e22a9fa24230b9d67a57855c5c31c7e94e
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid commons-parent Low Vendor Manifest bundle-symbolicname org.apache.commons.lang3 Medium Vendor pom parent-groupid org.apache.commons Medium Vendor Manifest bundle-docurl https://commons.apache.org/proper/commons-lang/ Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor jar package name lang3 Highest Vendor jar package name commons Highest Vendor Manifest automatic-module-name org.apache.commons.lang3 Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor pom groupid org.apache.commons Highest Vendor pom artifactid commons-lang3 Low Vendor pom name Apache Commons Lang High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom url https://commons.apache.org/proper/commons-lang/ Highest Vendor jar package name apache Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom groupid apache.commons Highest Vendor file name commons-lang3 High Product Manifest Implementation-Title Apache Commons Lang High Product Manifest specification-title Apache Commons Lang Medium Product Manifest bundle-symbolicname org.apache.commons.lang3 Medium Product pom parent-groupid org.apache.commons Medium Product Manifest bundle-docurl https://commons.apache.org/proper/commons-lang/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product jar package name lang3 Highest Product jar package name commons Highest Product pom artifactid commons-lang3 Highest Product Manifest automatic-module-name org.apache.commons.lang3 Medium Product Manifest build-jdk-spec 1.8 Low Product pom parent-artifactid commons-parent Medium Product pom name Apache Commons Lang High Product Manifest Bundle-Name Apache Commons Lang Medium Product jar package name apache Highest Product pom url https://commons.apache.org/proper/commons-lang/ Medium Product pom groupid apache.commons Highest Product file name commons-lang3 High Version pom version 3.12.0 Highest Version file version 3.12.0 High Version Manifest Implementation-Version 3.12.0 High Version Manifest Bundle-Version 3.12.0 High Version pom parent-version 3.12.0 Low
commons-logging-1.2.jarDescription:
Apache Commons Logging is a thin adapter allowing configurable bridging to other,
well known logging systems. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/commons-logging/commons-logging/1.2/commons-logging-1.2.jar
MD5: 040b4b4d8eac886f6b4a2a3bd2f31b00
SHA1: 4bfc12adfe4842bf07b657f0369c4cb522955686
SHA256: daddea1ea0be0f56978ab3006b8ac92834afeefbd9b7e4e6316fca57df0fa636
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid commons-parent Low Vendor pom parent-groupid org.apache.commons Medium Vendor file name commons-logging High Vendor jar package name logging Highest Vendor pom name Apache Commons Logging High Vendor Manifest bundle-symbolicname org.apache.commons.logging Medium Vendor jar package name commons Highest Vendor Manifest bundle-docurl http://commons.apache.org/proper/commons-logging/ Low Vendor pom artifactid commons-logging Low Vendor pom groupid commons-logging Highest Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest implementation-build tags/LOGGING_1_2_RC2@r1608092; 2014-07-05 20:11:44+0200 Low Vendor pom url http://commons.apache.org/proper/commons-logging/ Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor jar package name apache Highest Vendor Manifest Implementation-Vendor-Id org.apache Medium Product pom parent-groupid org.apache.commons Medium Product file name commons-logging High Product pom artifactid commons-logging Highest Product jar package name logging Highest Product pom name Apache Commons Logging High Product Manifest bundle-symbolicname org.apache.commons.logging Medium Product jar package name commons Highest Product pom url http://commons.apache.org/proper/commons-logging/ Medium Product Manifest specification-title Apache Commons Logging Medium Product Manifest bundle-docurl http://commons.apache.org/proper/commons-logging/ Low Product pom groupid commons-logging Highest Product pom parent-artifactid commons-parent Medium Product Manifest Bundle-Name Apache Commons Logging Medium Product Manifest implementation-build tags/LOGGING_1_2_RC2@r1608092; 2014-07-05 20:11:44+0200 Low Product jar package name apache Highest Product Manifest Implementation-Title Apache Commons Logging High Version Manifest Implementation-Version 1.2 High Version pom parent-version 1.2 Low Version file version 1.2 High Version pom version 1.2 Highest
dom4j-2.1.3.jarDescription:
flexible XML framework for Java License:
BSD 3-clause New License: https://github.com/dom4j/dom4j/blob/master/LICENSE File Path: /home/jenkins/.mvnrepository/org/dom4j/dom4j/2.1.3/dom4j-2.1.3.jar
MD5: 41efcf234c5a05a8c590f9b51d53ca66
SHA1: a75914155a9f5808963170ec20653668a2ffd2fd
SHA256: 549f3007c6290f6a901e57d1d331b4ed0e6bf7384f78bf10316ffceeca834de6
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name dom4j Highest Vendor pom groupid org.dom4j Highest Vendor pom groupid dom4j Highest Vendor pom url http://dom4j.github.io/ Highest Vendor jar package name dom4j Low Vendor file name dom4j High Vendor pom name dom4j High Vendor pom artifactid dom4j Low Product pom artifactid dom4j Highest Product jar package name dom4j Highest Product pom groupid dom4j Highest Product file name dom4j High Product pom name dom4j High Product pom url http://dom4j.github.io/ Medium Version pom version 2.1.3 Highest Version file version 2.1.3 High
entando-k8s-custom-model-6.3.4.jarDescription:
Entando's Kubernetes Custom Resources License:
GNU LESSER GENERAL PUBLIC LICENSE, Version 2.1, February 1999: https://www.gnu.org/licenses/lgpl-2.1.txt File Path: /home/jenkins/.mvnrepository/org/entando/entando-k8s-custom-model/6.3.4/entando-k8s-custom-model-6.3.4.jar
MD5: c744809d5012ba2e91767c76349709bd
SHA1: d40dc798900cb12eb1275bca1ce755a59a3aa09d
SHA256: d77e0ec0f4eb5707ebf3668bee92afeefed142b80506ba90f59e566a55002c94
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest build-jdk-spec 11 Low Vendor pom artifactid entando-k8s-custom-model Low Vendor pom organization name Entando Inc. High Vendor pom groupid entando Highest Vendor pom url https://central.entando.com Highest Vendor jar package name model Highest Vendor pom organization url http://www.entando.com/ Medium Vendor file name entando-k8s-custom-model High Vendor jar package name entando Highest Vendor jar package name kubernetes Highest Vendor Manifest implementation-build 6.3.4 Low Vendor pom parent-groupid org.entando Medium Vendor pom name Entando Kubernetes Custom Model High Vendor Manifest Implementation-Vendor Entando Inc. High Vendor pom groupid org.entando Highest Vendor pom parent-artifactid entando-quarkus-parent Low Product Manifest build-jdk-spec 11 Low Product pom artifactid entando-k8s-custom-model Highest Product pom url https://central.entando.com Medium Product pom groupid entando Highest Product jar package name model Highest Product pom parent-artifactid entando-quarkus-parent Medium Product file name entando-k8s-custom-model High Product jar package name entando Highest Product jar package name kubernetes Highest Product Manifest implementation-build 6.3.4 Low Product pom parent-groupid org.entando Medium Product pom name Entando Kubernetes Custom Model High Product pom organization url http://www.entando.com/ Low Product Manifest Implementation-Title Entando Kubernetes Custom Model High Product pom organization name Entando Inc. Low Version file version 6.3.4 High Version Manifest implementation-build 6.3.4 Low Version Manifest Implementation-Version 6.3.4 High Version pom parent-version 6.3.4 Low Version pom version 6.3.4 Highest
error_prone_annotations-2.5.1.jarLicense:
Apache 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/com/google/errorprone/error_prone_annotations/2.5.1/error_prone_annotations-2.5.1.jar
MD5: 2bf3239388cf5c817cd83ecb692b045f
SHA1: 562d366678b89ce5d6b6b82c1a073880341e3fba
SHA256: ff80626baaf12a09342befd4e84cba9d50662f5fcd7f7a9b3490a6b7cf87e66c
Referenced In Project/Scope: Entando Kubernetes Service:runtime
Evidence Type Source Name Value Confidence Vendor pom artifactid error_prone_annotations Low Vendor jar package name errorprone Highest Vendor jar package name google Highest Vendor file name error_prone_annotations High Vendor pom groupid com.google.errorprone Highest Vendor pom parent-artifactid error_prone_parent Low Vendor Manifest automatic-module-name com.google.errorprone.annotations Medium Vendor jar package name annotations Highest Vendor pom groupid google.errorprone Highest Vendor pom parent-groupid com.google.errorprone Medium Vendor pom name error-prone annotations High Product pom artifactid error_prone_annotations Highest Product jar package name errorprone Highest Product jar package name google Highest Product pom parent-artifactid error_prone_parent Medium Product file name error_prone_annotations High Product Manifest automatic-module-name com.google.errorprone.annotations Medium Product jar package name annotations Highest Product pom groupid google.errorprone Highest Product pom parent-groupid com.google.errorprone Medium Product pom name error-prone annotations High Version file version 2.5.1 High Version pom version 2.5.1 Highest
evo-inflector-1.2.2.jarDescription:
Evo Inflector implements English pluralization algorithm. License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/org/atteo/evo-inflector/1.2.2/evo-inflector-1.2.2.jar
MD5: da63c9ef600b74c760d81a09f9053d04
SHA1: 2551aad98d65ac5464d81fe05f0e1516cfe471c9
SHA256: c485c110870c597ba401dda2c7c5819a3b2e15ee064f539323138302bd591d48
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom url http://atteo.org/static/evo-inflector Highest Vendor jar package name english Highest Vendor pom groupid org.atteo Highest Vendor jar package name atteo Highest Vendor pom parent-artifactid parent Low Vendor jar package name evo Highest Vendor pom parent-groupid org.atteo Medium Vendor jar package name evo Low Vendor pom artifactid evo-inflector Low Vendor jar package name inflector Highest Vendor jar package name atteo Low Vendor file name evo-inflector High Vendor pom groupid atteo Highest Vendor jar package name inflector Low Vendor pom name Evo Inflector High Product jar package name english Highest Product jar package name atteo Highest Product pom artifactid evo-inflector Highest Product pom url http://atteo.org/static/evo-inflector Medium Product jar package name evo Highest Product pom parent-groupid org.atteo Medium Product jar package name evo Low Product pom parent-artifactid parent Medium Product jar package name inflector Highest Product file name evo-inflector High Product pom groupid atteo Highest Product jar package name inflector Low Product pom name Evo Inflector High Version pom version 1.2.2 Highest Version file version 1.2.2 High Version pom parent-version 1.2.2 Low
faux-pas-0.8.0.jarDescription:
Error handling in Functional Programming License:
MIT License: https://opensource.org/licenses/MIT File Path: /home/jenkins/.mvnrepository/org/zalando/faux-pas/0.8.0/faux-pas-0.8.0.jar
MD5: 882e0a168fca081e0f97f16c3b1b2ce1
SHA1: 4a2d93111b2b5e35577fdf641a7551d3544b414f
SHA256: feb16c2d73cd1746d6717f52e67d50ccbec7789416597c9d08adbb641efc8e88
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor file name faux-pas High Vendor pom name Faux Pas High Vendor jar package name zalando Low Vendor pom groupid zalando Highest Vendor pom url zalando/faux-pas Highest Vendor pom artifactid faux-pas Low Vendor jar package name fauxpas Low Vendor pom groupid org.zalando Highest Vendor pom organization name Zalando SE High Vendor jar package name zalando Highest Product file name faux-pas High Product pom name Faux Pas High Product pom groupid zalando Highest Product jar package name fauxpas Low Product pom artifactid faux-pas Highest Product pom organization name Zalando SE Low Product pom url zalando/faux-pas High Product jar package name zalando Highest Version pom version 0.8.0 Highest Version file version 0.8.0 High
generex-1.0.2.jarDescription:
Generex A Java Library for regex to Strings generation License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/com/github/mifmif/generex/1.0.2/generex-1.0.2.jar
MD5: a832db42f9e1c4f76930f547f6f80998
SHA1: b378f873b4e8d7616c3d920e2132cb1c87679600
SHA256: 8f8ce233c335e08e113a3f9579de1046fb19927e82468b1bbebcd6cba8760b81
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name generex Highest Vendor Manifest Implementation-Vendor-Id com.github.mifmif Medium Vendor pom url mifmif/Generex/tree/master Highest Vendor pom groupid github.mifmif Highest Vendor file name generex High Vendor pom name Generex High Vendor jar package name regex Highest Vendor pom groupid com.github.mifmif Highest Vendor Manifest implementation-url https://github.com/mifmif/Generex/tree/master Low Vendor jar package name mifmif Highest Vendor pom artifactid generex Low Product jar package name generex Highest Product pom artifactid generex Highest Product Manifest Implementation-Title Generex High Product Manifest specification-title Generex Medium Product pom groupid github.mifmif Highest Product file name generex High Product pom name Generex High Product jar package name regex Highest Product Manifest implementation-url https://github.com/mifmif/Generex/tree/master Low Product jar package name mifmif Highest Product pom url mifmif/Generex/tree/master High Version file version 1.0.2 High Version pom version 1.0.2 Highest Version Manifest Implementation-Version 1.0.2 High
h2-1.4.199.jarDescription:
H2 Database Engine License:
MPL 2.0 or EPL 1.0: http://h2database.com/html/license.html File Path: /home/jenkins/.mvnrepository/com/h2database/h2/1.4.199/h2-1.4.199.jar
MD5: f805f57d838de4b42ce01c7f85e46e1c
SHA1: 7bf08152984ed8859740ae3f97fae6c72771ae45
SHA256: 3125a16743bc6b4cfbb61abba783203f1fb68230aa0fdc97898f796f99a5d42e
Referenced In Project/Scope: Entando Kubernetes Service:runtime
Evidence Type Source Name Value Confidence Vendor jar package name engine Highest Vendor Manifest bundle-symbolicname com.h2database Medium Vendor pom groupid h2database Highest Vendor pom name H2 Database Engine High Vendor jar package name database Highest Vendor file name h2 High Vendor Manifest bundle-category jdbc Low Vendor jar package name h2 Highest Vendor pom groupid com.h2database Highest Vendor Manifest automatic-module-name com.h2database Medium Vendor Manifest multi-release true Low Vendor pom artifactid h2 Low Vendor Manifest provide-capability osgi.service;objectClass:List=org.osgi.service.jdbc.DataSourceFactory Low Vendor Manifest implementation-url http://www.h2database.com Low Vendor pom url http://www.h2database.com Highest Product Manifest Bundle-Name H2 Database Engine Medium Product jar package name engine Highest Product Manifest bundle-symbolicname com.h2database Medium Product pom groupid h2database Highest Product pom name H2 Database Engine High Product pom url http://www.h2database.com Medium Product jar package name jdbc Highest Product jar package name database Highest Product file name h2 High Product Manifest bundle-category jdbc Low Product pom artifactid h2 Highest Product jar package name h2 Highest Product Manifest Implementation-Title H2 Database Engine High Product Manifest automatic-module-name com.h2database Medium Product jar package name service Highest Product Manifest multi-release true Low Product jar package name org Highest Product Manifest provide-capability osgi.service;objectClass:List=org.osgi.service.jdbc.DataSourceFactory Low Product Manifest implementation-url http://www.h2database.com Low Version Manifest Implementation-Version 1.4.199 High Version Manifest Bundle-Version 1.4.199 High Version pom version 1.4.199 Highest Version file version 1.4.199 High
hamcrest-2.2.jarDescription:
Core API and libraries of hamcrest matcher framework. License:
BSD License 3: http://opensource.org/licenses/BSD-3-Clause File Path: /home/jenkins/.mvnrepository/org/hamcrest/hamcrest/2.2/hamcrest-2.2.jar
MD5: 10b47e837f271d0662f28780e60388e8
SHA1: 1820c0968dba3a11a1b30669bb1f01978a91dedc
SHA256: 5e62846a89f05cd78cd9c1a553f340d002458380c320455dd1f8fc5497a8a1c1
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid org.hamcrest Highest Vendor file name hamcrest High Vendor pom url http://hamcrest.org/JavaHamcrest/ Highest Vendor jar package name matcher Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor pom groupid hamcrest Highest Vendor Manifest bundle-symbolicname org.hamcrest Medium Vendor Manifest Implementation-Vendor hamcrest.org High Vendor jar package name core Highest Vendor pom name Hamcrest High Vendor Manifest automatic-module-name org.hamcrest Medium Vendor jar package name hamcrest Highest Vendor pom artifactid hamcrest Low Product file name hamcrest High Product pom artifactid hamcrest Highest Product Manifest Implementation-Title hamcrest High Product pom url http://hamcrest.org/JavaHamcrest/ Medium Product jar package name matcher Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product pom groupid hamcrest Highest Product Manifest bundle-symbolicname org.hamcrest Medium Product jar package name core Highest Product pom name Hamcrest High Product jar package name hamcrest Highest Product Manifest automatic-module-name org.hamcrest Medium Product Manifest Bundle-Name hamcrest Medium Version pom version 2.2 Highest Version file version 2.2 High Version Manifest Implementation-Version 2.2 High Version Manifest Bundle-Version 2.2 High
hibernate-commons-annotations-5.1.2.Final.jarDescription:
Common reflection code used in support of annotation processing License:
GNU Library General Public License v2.1 or later: http://www.opensource.org/licenses/LGPL-2.1 File Path: /home/jenkins/.mvnrepository/org/hibernate/common/hibernate-commons-annotations/5.1.2.Final/hibernate-commons-annotations-5.1.2.Final.jar
MD5: 2a2490b3eb8e7585a6a899d27d7ed43f
SHA1: e59ffdbc6ad09eeb33507b39ffcf287679a498c8
SHA256: 1c7ce712b2679fea0a5441eb02a04144297125b768944819be0765befb996275
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest Implementation-Vendor-Id org.hibernate Medium Vendor pom organization name Hibernate.org High Vendor pom name Hibernate Commons Annotations High Vendor Manifest implementation-url http://hibernate.org Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Hibernate.org High Vendor pom artifactid hibernate-commons-annotations Low Vendor jar package name common Highest Vendor hint analyzer vendor redhat Highest Vendor jar package name annotations Highest Vendor pom groupid hibernate.common Highest Vendor Manifest automatic-module-name org.hibernate.commons.annotations Medium Vendor pom organization url http://hibernate.org Medium Vendor jar package name hibernate Highest Vendor jar package name reflection Highest Vendor pom groupid org.hibernate.common Highest Vendor pom url http://hibernate.org Highest Vendor file name hibernate-commons-annotations High Vendor Manifest bundle-symbolicname org.hibernate.common.hibernate-commons-annotations Medium Product pom organization url http://hibernate.org Low Product pom name Hibernate Commons Annotations High Product Manifest implementation-url http://hibernate.org Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product jar package name version Highest Product Manifest Bundle-Name hibernate-commons-annotations Medium Product pom artifactid hibernate-commons-annotations Highest Product jar package name common Highest Product jar package name annotations Highest Product pom organization name Hibernate.org Low Product pom groupid hibernate.common Highest Product Manifest automatic-module-name org.hibernate.commons.annotations Medium Product jar package name hibernate Highest Product jar package name reflection Highest Product pom url http://hibernate.org Medium Product file name hibernate-commons-annotations High Product Manifest bundle-symbolicname org.hibernate.common.hibernate-commons-annotations Medium Version pom version 5.1.2.Final Highest Version Manifest Bundle-Version 5.1.2.Final High Version Manifest Implementation-Version 5.1.2.Final High
hibernate-core-5.4.28.Final.jarDescription:
Hibernate's core ORM functionality License:
GNU Library General Public License v2.1 or later: http://www.opensource.org/licenses/LGPL-2.1 File Path: /home/jenkins/.mvnrepository/org/hibernate/hibernate-core/5.4.28.Final/hibernate-core-5.4.28.Final.jar
MD5: b82ef126a37e8423b1a102f9a905dffa
SHA1: c096dbb27f83655ec252165340b532733c58e8fb
SHA256: baebf41f25bd106e11a2954772bfea96723dc37b1abe7dc8fc861e5fce9ccbed
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid org.hibernate Highest Vendor Manifest Implementation-Vendor-Id org.hibernate Medium Vendor pom organization name Hibernate.org High Vendor Manifest implementation-url http://hibernate.org/orm Low Vendor pom artifactid hibernate-core Low Vendor pom url http://hibernate.org/orm Highest Vendor Manifest specification-vendor Hibernate.org Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor file name hibernate-core High Vendor Manifest Implementation-Vendor Hibernate.org High Vendor pom groupid hibernate Highest Vendor hint analyzer vendor redhat Highest Vendor Manifest bundle-docurl http://www.hibernate.org/orm/5.4 Low Vendor Manifest bundle-symbolicname org.hibernate.orm.core Medium Vendor pom organization url http://hibernate.org Medium Vendor jar package name hibernate Highest Vendor pom name Hibernate ORM - hibernate-core High Vendor Manifest automatic-module-name org.hibernate.orm.core Medium Product pom artifactid hibernate-core Highest Product pom organization url http://hibernate.org Low Product Manifest implementation-url http://hibernate.org/orm Low Product hint analyzer product orm Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product file name hibernate-core High Product jar package name version Highest Product pom groupid hibernate Highest Product Manifest bundle-docurl http://www.hibernate.org/orm/5.4 Low Product jar package name filter Highest Product Manifest Bundle-Name hibernate-core Medium Product pom organization name Hibernate.org Low Product Manifest bundle-symbolicname org.hibernate.orm.core Medium Product Manifest Implementation-Title hibernate-core High Product pom url http://hibernate.org/orm Medium Product jar package name hibernate Highest Product pom name Hibernate ORM - hibernate-core High Product Manifest automatic-module-name org.hibernate.orm.core Medium Product Manifest specification-title hibernate-core Medium Version pom version 5.4.28.Final Highest Version Manifest Implementation-Version 5.4.28.Final High Version Manifest Bundle-Version 5.4.28.Final High
httpclient-4.5.13.jarDescription:
Apache HttpComponents Client
File Path: /home/jenkins/.mvnrepository/org/apache/httpcomponents/httpclient/4.5.13/httpclient-4.5.13.jarMD5: 40d6b9075fbd28fa10292a45a0db9457SHA1: e5f6cae5ca7ecaac1ec2827a9e2d65ae2869cadaSHA256: 6fe9026a566c6a5001608cf3fc32196641f6c1e5e1986d1037ccdbd5f31ef743Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-groupid org.apache.httpcomponents Medium Vendor pom name Apache HttpClient High Vendor jar package name client Highest Vendor file name httpclient High Vendor Manifest automatic-module-name org.apache.httpcomponents.httpclient Medium Vendor Manifest implementation-url http://hc.apache.org/httpcomponents-client Low Vendor Manifest Implementation-Vendor-Id org.apache.httpcomponents Medium Vendor jar package name httpclient Highest Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom parent-artifactid httpcomponents-client Low Vendor pom groupid apache.httpcomponents Highest Vendor pom artifactid httpclient Low Vendor jar package name apache Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom url http://hc.apache.org/httpcomponents-client Highest Vendor pom groupid org.apache.httpcomponents Highest Product pom parent-groupid org.apache.httpcomponents Medium Product pom parent-artifactid httpcomponents-client Medium Product pom url http://hc.apache.org/httpcomponents-client Medium Product pom name Apache HttpClient High Product jar package name client Highest Product file name httpclient High Product Manifest automatic-module-name org.apache.httpcomponents.httpclient Medium Product Manifest specification-title Apache HttpClient Medium Product jar package name http Highest Product Manifest implementation-url http://hc.apache.org/httpcomponents-client Low Product jar package name httpclient Highest Product pom groupid apache.httpcomponents Highest Product pom artifactid httpclient Highest Product jar package name apache Highest Product Manifest Implementation-Title Apache HttpClient High Version pom version 4.5.13 Highest Version file version 4.5.13 High Version Manifest Implementation-Version 4.5.13 High
httpcore-4.4.14.jarDescription:
Apache HttpComponents Core (blocking I/O)
File Path: /home/jenkins/.mvnrepository/org/apache/httpcomponents/httpcore/4.4.14/httpcore-4.4.14.jarMD5: 2b3991eda121042765a5ee299556c200SHA1: 9dd1a631c082d92ecd4bd8fd4cf55026c720a8c1SHA256: f956209e450cb1d0c51776dfbd23e53e9dd8db9a1298ed62b70bf0944ba63b28Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor file name httpcore High Vendor pom parent-groupid org.apache.httpcomponents Medium Vendor pom artifactid httpcore Low Vendor Manifest implementation-build ${scmBranch}@r${buildNumber}; 2020-11-26 19:07:01+0000 Low Vendor pom parent-artifactid httpcomponents-core Low Vendor Manifest automatic-module-name org.apache.httpcomponents.httpcore Medium Vendor Manifest implementation-url http://hc.apache.org/httpcomponents-core-ga Low Vendor pom name Apache HttpCore High Vendor pom url http://hc.apache.org/httpcomponents-core-ga Highest Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom groupid apache.httpcomponents Highest Vendor Manifest url http://hc.apache.org/httpcomponents-core-ga Low Vendor jar package name apache Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor Manifest Implementation-Vendor-Id org.apache Medium Vendor pom groupid org.apache.httpcomponents Highest Product file name httpcore High Product pom parent-groupid org.apache.httpcomponents Medium Product pom url http://hc.apache.org/httpcomponents-core-ga Medium Product pom artifactid httpcore Highest Product Manifest implementation-build ${scmBranch}@r${buildNumber}; 2020-11-26 19:07:01+0000 Low Product Manifest specification-title HttpComponents Apache HttpCore Medium Product Manifest automatic-module-name org.apache.httpcomponents.httpcore Medium Product jar package name http Highest Product Manifest implementation-url http://hc.apache.org/httpcomponents-core-ga Low Product pom name Apache HttpCore High Product pom groupid apache.httpcomponents Highest Product Manifest url http://hc.apache.org/httpcomponents-core-ga Low Product Manifest Implementation-Title HttpComponents Apache HttpCore High Product jar package name apache Highest Product pom parent-artifactid httpcomponents-core Medium Version Manifest Implementation-Version 4.4.14 High Version file version 4.4.14 High Version pom version 4.4.14 Highest
istack-commons-runtime-3.0.12.jarDescription:
istack common utility code License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /home/jenkins/.mvnrepository/com/sun/istack/istack-commons-runtime/3.0.12/istack-commons-runtime-3.0.12.jar
MD5: 1952bd76321f8580cfaa57e332a68287
SHA1: cbbe1a62b0cc6c85972e99d52aaee350153dc530
SHA256: 27d85fc134c9271d5c79d3300fc4669668f017e72409727c428f54f2417f04cd
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid com.sun.istack Highest Vendor Manifest Implementation-Vendor-Id com.sun.istack Medium Vendor Manifest implementation-build-id 3.0.12 - 7ed1368 Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor pom groupid sun.istack Highest Vendor pom parent-artifactid istack-commons Low Vendor Manifest bundle-symbolicname com.sun.istack.commons-runtime Medium Vendor jar package name istack Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid istack-commons-runtime Low Vendor jar package name sun Highest Vendor jar package name com Highest Vendor pom parent-groupid com.sun.istack Medium Vendor file name istack-commons-runtime High Vendor Manifest multi-release true Low Vendor pom name istack common utility code runtime High Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor jar (hint) package name oracle Highest Product Manifest implementation-build-id 3.0.12 - 7ed1368 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product pom groupid sun.istack Highest Product jar package name istack Highest Product Manifest bundle-symbolicname com.sun.istack.commons-runtime Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product jar package name sun Highest Product pom artifactid istack-commons-runtime Highest Product jar package name com Highest Product pom parent-groupid com.sun.istack Medium Product pom parent-artifactid istack-commons Medium Product file name istack-commons-runtime High Product Manifest Bundle-Name istack common utility code runtime Medium Product Manifest multi-release true Low Product pom name istack common utility code runtime High Version pom version 3.0.12 Highest Version file version 3.0.12 High Version Manifest implementation-build-id 3.0.12 Low Version Manifest Bundle-Version 3.0.12 High
jackson-annotations-2.12.5.jarDescription:
Core annotations used for value types, used by Jackson data binding package.
License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/com/fasterxml/jackson/core/jackson-annotations/2.12.5/jackson-annotations-2.12.5.jar
MD5: a09b3eef2766eeff04829294720777b3
SHA1: 52d929d5bb21d0186fe24c09624cc3ee4bafc3b3
SHA256: 517926d9fe04cadd55120790d0b5355e4f656ffe2969e4d480a0e7f95a983e9e
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom url http://github.com/FasterXML/jackson Highest Vendor file name jackson-annotations High Vendor jar package name jackson Highest Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor pom parent-artifactid jackson-parent Low Vendor pom name Jackson-annotations High Vendor Manifest implementation-build-date 2021-08-26 23:31:26+0000 Low Vendor Manifest bundle-docurl http://github.com/FasterXML/jackson Low Vendor pom groupid fasterxml.jackson.core Highest Vendor pom artifactid jackson-annotations Low Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor jar package name fasterxml Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest specification-vendor FasterXML Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium Vendor pom groupid com.fasterxml.jackson.core Highest Product file name jackson-annotations High Product jar package name jackson Highest Product pom artifactid jackson-annotations Highest Product pom url http://github.com/FasterXML/jackson Medium Product hint analyzer product modules Highest Product pom parent-groupid com.fasterxml.jackson Medium Product pom name Jackson-annotations High Product Manifest implementation-build-date 2021-08-26 23:31:26+0000 Low Product Manifest bundle-docurl http://github.com/FasterXML/jackson Low Product pom groupid fasterxml.jackson.core Highest Product Manifest Bundle-Name Jackson-annotations Medium Product jar package name fasterxml Highest Product Manifest build-jdk-spec 1.8 Low Product hint analyzer product java8 Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest Implementation-Title Jackson-annotations High Product pom parent-artifactid jackson-parent Medium Product Manifest specification-title Jackson-annotations Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-annotations Medium Version file version 2.12.5 High Version Manifest Bundle-Version 2.12.5 High Version Manifest Implementation-Version 2.12.5 High Version pom parent-version 2.12.5 Low Version pom version 2.12.5 Highest
jackson-core-2.12.5.jarDescription:
Core Jackson processing abstractions (aka Streaming API), implementation for JSON License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/com/fasterxml/jackson/core/jackson-core/2.12.5/jackson-core-2.12.5.jar
MD5: b24f3a25bc033352f1c3ab2c683b926c
SHA1: 725e364cc71b80e60fa450bd06d75cdea7fb2d59
SHA256: 0c9860b8fb6f24f59e083e0b92a17c515c45312951fc272d093e4709faed6356
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom name Jackson-core High Vendor jar package name jackson Highest Vendor Manifest implementation-build-date 2021-08-26 23:57:55+0000 Low Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low Vendor pom groupid fasterxml.jackson.core Highest Vendor pom parent-artifactid jackson-base Low Vendor pom url FasterXML/jackson-core Highest Vendor file name jackson-core High Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor jar package name fasterxml Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest specification-vendor FasterXML Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor jar package name json Highest Vendor jar package name core Highest Vendor jar package name base Highest Vendor pom artifactid jackson-core Low Vendor pom groupid com.fasterxml.jackson.core Highest Product jar package name jackson Highest Product Manifest Bundle-Name Jackson-core Medium Product Manifest implementation-build-date 2021-08-26 23:57:55+0000 Low Product hint analyzer product modules Highest Product pom parent-groupid com.fasterxml.jackson Medium Product Manifest bundle-docurl https://github.com/FasterXML/jackson-core Low Product Manifest Implementation-Title Jackson-core High Product jar package name filter Highest Product Manifest build-jdk-spec 1.8 Low Product hint analyzer product java8 Highest Product jar package name json Highest Product jar package name core Highest Product jar package name base Highest Product pom name Jackson-core High Product pom url FasterXML/jackson-core High Product jar package name version Highest Product pom groupid fasterxml.jackson.core Highest Product file name jackson-core High Product jar package name fasterxml Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-core Medium Product pom artifactid jackson-core Highest Product pom parent-artifactid jackson-base Medium Product Manifest specification-title Jackson-core Medium Version file version 2.12.5 High Version Manifest Bundle-Version 2.12.5 High Version Manifest Implementation-Version 2.12.5 High Version pom version 2.12.5 Highest
jackson-databind-2.10.5.1.jarDescription:
General data-binding functionality for Jackson: works on core streaming API License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/com/fasterxml/jackson/core/jackson-databind/2.10.5.1/jackson-databind-2.10.5.1.jar
MD5: 3aec7825a3153ea9d62582e1f6efea0b
SHA1: 7ff756c3af1fe95cb3cddba9158fc3289ca06387
SHA256: f93db83891a53e8d268e2cc8fcd88ead2981edc2163e35c2a52c88d9ab57b4a0
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest implementation-build-date 2020-12-02 03:47:00+0000 Low Vendor pom url http://github.com/FasterXML/jackson Highest Vendor jar package name jackson Highest Vendor pom parent-groupid com.fasterxml.jackson Medium Vendor file name jackson-databind High Vendor Manifest bundle-docurl http://github.com/FasterXML/jackson Low Vendor jar package name databind Highest Vendor pom groupid fasterxml.jackson.core Highest Vendor pom parent-artifactid jackson-base Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.core Medium Vendor jar package name fasterxml Highest Vendor Manifest specification-vendor FasterXML Low Vendor Manifest Implementation-Vendor FasterXML High Vendor pom artifactid jackson-databind Low Vendor pom name jackson-databind High Vendor pom groupid com.fasterxml.jackson.core Highest Vendor Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium Product Manifest implementation-build-date 2020-12-02 03:47:00+0000 Low Product jar package name jackson Highest Product pom url http://github.com/FasterXML/jackson Medium Product hint analyzer product modules Highest Product Manifest Implementation-Title jackson-databind High Product pom parent-groupid com.fasterxml.jackson Medium Product file name jackson-databind High Product Manifest bundle-docurl http://github.com/FasterXML/jackson Low Product jar package name databind Highest Product pom groupid fasterxml.jackson.core Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product jar package name fasterxml Highest Product hint analyzer product java8 Highest Product Manifest Bundle-Name jackson-databind Medium Product Manifest specification-title jackson-databind Medium Product pom parent-artifactid jackson-base Medium Product pom artifactid jackson-databind Highest Product pom name jackson-databind High Product Manifest bundle-symbolicname com.fasterxml.jackson.core.jackson-databind Medium Version pom version 2.10.5.1 Highest Version Manifest Bundle-Version 2.10.5.1 High Version Manifest Implementation-Version 2.10.5.1 High Version file version 2.10.5.1 High Version pom parent-version 2.10.5.1 Low
jackson-dataformat-yaml-2.9.9.jarDescription:
Support for reading and writing YAML-encoded data via Jackson abstractions.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/com/fasterxml/jackson/dataformat/jackson-dataformat-yaml/2.9.9/jackson-dataformat-yaml-2.9.9.jar
MD5: d69448f6ca2107748153c5366a98c101
SHA1: 0ccc00ed13e4d74f9c5cc30465b6fc4fe5ce5473
SHA256: 2a0fcacfaba5128a7164c2311b35a35e2f9eedb29f5935de5553716b454455cf
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom url FasterXML/jackson-dataformats-text Highest Vendor jar package name jackson Highest Vendor pom parent-groupid com.fasterxml.jackson.dataformat Medium Vendor pom parent-artifactid jackson-dataformats-text Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-dataformats-text Low Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.dataformat Medium Vendor file name jackson-dataformat-yaml High Vendor pom groupid com.fasterxml.jackson.dataformat Highest Vendor Manifest implementation-build-date 2019-05-16 06:02:17+0000 Low Vendor Manifest automatic-module-name com.fasterxml.jackson.dataformat.yaml Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor jar package name fasterxml Highest Vendor Manifest specification-vendor FasterXML Low Vendor Manifest Implementation-Vendor FasterXML High Vendor jar package name dataformat Highest Vendor pom groupid fasterxml.jackson.dataformat Highest Vendor jar package name yaml Highest Vendor pom artifactid jackson-dataformat-yaml Low Vendor pom name Jackson-dataformat-YAML High Vendor Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-yaml Medium Product Manifest Bundle-Name Jackson-dataformat-YAML Medium Product jar package name jackson Highest Product Manifest specification-title Jackson-dataformat-YAML Medium Product pom parent-groupid com.fasterxml.jackson.dataformat Medium Product Manifest bundle-docurl https://github.com/FasterXML/jackson-dataformats-text Low Product Manifest Implementation-Title Jackson-dataformat-YAML High Product file name jackson-dataformat-yaml High Product pom url FasterXML/jackson-dataformats-text High Product Manifest implementation-build-date 2019-05-16 06:02:17+0000 Low Product Manifest automatic-module-name com.fasterxml.jackson.dataformat.yaml Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product pom parent-artifactid jackson-dataformats-text Medium Product jar package name fasterxml Highest Product pom artifactid jackson-dataformat-yaml Highest Product jar package name dataformat Highest Product pom groupid fasterxml.jackson.dataformat Highest Product jar package name yaml Highest Product pom name Jackson-dataformat-YAML High Product Manifest bundle-symbolicname com.fasterxml.jackson.dataformat.jackson-dataformat-yaml Medium Version Manifest Implementation-Version 2.9.9 High Version Manifest Bundle-Version 2.9.9 High Version pom version 2.9.9 Highest Version file version 2.9.9 High
jackson-datatype-jdk8-2.12.5.jarDescription:
Add-on module for Jackson (http://jackson.codehaus.org) to support
JDK 8 data types.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/com/fasterxml/jackson/datatype/jackson-datatype-jdk8/2.12.5/jackson-datatype-jdk8-2.12.5.jar
MD5: 3b2b8f0a1612ec9e94d5823c1d01df2a
SHA1: 6b2f79547d217ad50dfc5b57af7444a3aa583b43
SHA256: 8a622d3ee65bf02b41bce57aa5b5eadfbf093b99446ec7d4566026a7800262a1
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name jackson Highest Vendor jar package name datatype Highest Vendor pom parent-artifactid jackson-modules-java8 Low Vendor pom groupid com.fasterxml.jackson.datatype Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom name Jackson datatype: jdk8 High Vendor pom parent-groupid com.fasterxml.jackson.module Medium Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jdk8 Low Vendor pom artifactid jackson-datatype-jdk8 Low Vendor jar package name fasterxml Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest specification-vendor FasterXML Low Vendor file name jackson-datatype-jdk8 High Vendor pom groupid fasterxml.jackson.datatype Highest Vendor Manifest Implementation-Vendor FasterXML High Vendor jar package name jdk8 Highest Vendor Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jdk8 Medium Vendor Manifest implementation-build-date 2021-08-27 01:10:29+0000 Low Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.datatype Medium Product Manifest Bundle-Name Jackson datatype: jdk8 Medium Product Manifest specification-title Jackson datatype: jdk8 Medium Product pom artifactid jackson-datatype-jdk8 Highest Product jar package name jackson Highest Product jar package name datatype Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom name Jackson datatype: jdk8 High Product pom parent-groupid com.fasterxml.jackson.module Medium Product Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jdk8 Low Product jar package name fasterxml Highest Product Manifest build-jdk-spec 1.8 Low Product file name jackson-datatype-jdk8 High Product pom groupid fasterxml.jackson.datatype Highest Product jar package name jdk8 Highest Product pom parent-artifactid jackson-modules-java8 Medium Product Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jdk8 Medium Product Manifest implementation-build-date 2021-08-27 01:10:29+0000 Low Product Manifest Implementation-Title Jackson datatype: jdk8 High Version file version 2.12.5 High Version Manifest Bundle-Version 2.12.5 High Version Manifest Implementation-Version 2.12.5 High Version pom version 2.12.5 Highest
jackson-datatype-jsr310-2.12.5.jarDescription:
Add-on module to support JSR-310 (Java 8 Date & Time API) data types. License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/com/fasterxml/jackson/datatype/jackson-datatype-jsr310/2.12.5/jackson-datatype-jsr310-2.12.5.jar
MD5: 7d52861e175f974b5028b0c9a187f233
SHA1: a0a9870b681a72789c5c6bdc380e45ab719c6aa3
SHA256: fc8af8cae7520f324b68506d74cb6df1513299040469a331c0f38b6f5bc31ceb
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor file name jackson-datatype-jsr310 High Vendor jar package name jsr310 Highest Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jsr310 Low Vendor jar package name jackson Highest Vendor jar package name datatype Highest Vendor pom artifactid jackson-datatype-jsr310 Low Vendor pom parent-artifactid jackson-modules-java8 Low Vendor pom groupid com.fasterxml.jackson.datatype Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom parent-groupid com.fasterxml.jackson.module Medium Vendor Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jsr310 Medium Vendor jar package name fasterxml Highest Vendor pom name Jackson datatype: JSR310 High Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest specification-vendor FasterXML Low Vendor pom groupid fasterxml.jackson.datatype Highest Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest implementation-build-date 2021-08-27 01:10:29+0000 Low Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.datatype Medium Product file name jackson-datatype-jsr310 High Product jar package name jsr310 Highest Product Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-datatype-jsr310 Low Product jar package name jackson Highest Product jar package name datatype Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom parent-groupid com.fasterxml.jackson.module Medium Product Manifest Implementation-Title Jackson datatype: JSR310 High Product pom artifactid jackson-datatype-jsr310 Highest Product jar package name fasterxml Highest Product Manifest bundle-symbolicname com.fasterxml.jackson.datatype.jackson-datatype-jsr310 Medium Product pom name Jackson datatype: JSR310 High Product Manifest build-jdk-spec 1.8 Low Product pom groupid fasterxml.jackson.datatype Highest Product Manifest Bundle-Name Jackson datatype: JSR310 Medium Product pom parent-artifactid jackson-modules-java8 Medium Product Manifest implementation-build-date 2021-08-27 01:10:29+0000 Low Product Manifest specification-title Jackson datatype: JSR310 Medium Version file version 2.12.5 High Version Manifest Bundle-Version 2.12.5 High Version Manifest Implementation-Version 2.12.5 High Version pom version 2.12.5 Highest
jackson-datatype-problem-0.23.0.jarDescription:
Add-on module to support Problem data types. File Path: /home/jenkins/.mvnrepository/org/zalando/jackson-datatype-problem/0.23.0/jackson-datatype-problem-0.23.0.jarMD5: 568f613fc7bfd858cee61f932a6b6397SHA1: a8dcc007754dbd0b38d01c91e02756458d88f522SHA256: f297e601a744a35c61789b28cb9fec1133723395facbff93f0ad83dde39d734aReferenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-groupid org.zalando Medium Vendor pom artifactid jackson-datatype-problem Low Vendor jar package name problem Highest Vendor jar package name zalando Low Vendor pom groupid zalando Highest Vendor pom groupid org.zalando Highest Vendor pom name Jackson-datatype-Problem High Vendor jar package name problem Low Vendor jar package name zalando Highest Vendor pom parent-artifactid problem-parent Low Vendor file name jackson-datatype-problem High Product pom parent-groupid org.zalando Medium Product jar package name problem Highest Product pom groupid zalando Highest Product pom name Jackson-datatype-Problem High Product jar package name problem Low Product pom artifactid jackson-datatype-problem Highest Product jar package name zalando Highest Product file name jackson-datatype-problem High Product pom parent-artifactid problem-parent Medium Version pom version 0.23.0 Highest Version file version 0.23.0 High
jackson-module-jaxb-annotations-2.12.5.jarDescription:
Support for using JAXB annotations as an alternative to "native" Jackson annotations, for configuring
data-binding.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/com/fasterxml/jackson/module/jackson-module-jaxb-annotations/2.12.5/jackson-module-jaxb-annotations-2.12.5.jar
MD5: 944573d254d593e81a7df39ebec352fa
SHA1: 02b389d7206327e54ae31f709ab75a4a3f33e148
SHA256: bf99ed1f3a19f3341d11261685c87fc5e9cfc5d05f48d60312a1465b4997a110
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name jaxb Highest Vendor pom url FasterXML/jackson-modules-base Highest Vendor pom artifactid jackson-module-jaxb-annotations Low Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-base Low Vendor pom name Jackson module: JAXB Annotations High Vendor jar package name jackson Highest Vendor jar package name module Highest Vendor Manifest bundle-symbolicname com.fasterxml.jackson.module.jackson-module-jaxb-annotations Medium Vendor pom groupid fasterxml.jackson.module Highest Vendor pom parent-groupid com.fasterxml.jackson.module Medium Vendor pom parent-artifactid jackson-modules-base Low Vendor file name jackson-module-jaxb-annotations High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor pom groupid com.fasterxml.jackson.module Highest Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.module Medium Vendor jar package name fasterxml Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest specification-vendor FasterXML Low Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest multi-release true Low Vendor Manifest implementation-build-date 2021-08-27 01:07:35+0000 Low Product jar package name jaxb Highest Product Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-base Low Product pom name Jackson module: JAXB Annotations High Product jar package name jackson Highest Product jar package name module Highest Product Manifest bundle-symbolicname com.fasterxml.jackson.module.jackson-module-jaxb-annotations Medium Product pom groupid fasterxml.jackson.module Highest Product pom parent-groupid com.fasterxml.jackson.module Medium Product file name jackson-module-jaxb-annotations High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product Manifest Bundle-Name Jackson module: JAXB Annotations Medium Product jar package name fasterxml Highest Product Manifest build-jdk-spec 1.8 Low Product pom url FasterXML/jackson-modules-base High Product Manifest Implementation-Title Jackson module: JAXB Annotations High Product Manifest specification-title Jackson module: JAXB Annotations Medium Product Manifest multi-release true Low Product pom artifactid jackson-module-jaxb-annotations Highest Product Manifest implementation-build-date 2021-08-27 01:07:35+0000 Low Product pom parent-artifactid jackson-modules-base Medium Version file version 2.12.5 High Version Manifest Bundle-Version 2.12.5 High Version Manifest Implementation-Version 2.12.5 High Version pom version 2.12.5 Highest
jackson-module-parameter-names-2.12.5.jarDescription:
Add-on module for Jackson (http://jackson.codehaus.org) to support
introspection of method/constructor parameter names, without having to add explicit property name annotation.
License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/com/fasterxml/jackson/module/jackson-module-parameter-names/2.12.5/jackson-module-parameter-names-2.12.5.jar
MD5: c472f1b1eaa76fc6f454b4e1e348ed88
SHA1: 2c85c2036d0851425a260c01eb5f7ddbed1eeb00
SHA256: 220b1b72a4f56d896c3a427a7ff4e690434fc2e28ef3ceff24dc3a656b1ac315
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom name Jackson-module-parameter-names High Vendor jar package name jackson Highest Vendor jar package name module Highest Vendor pom parent-artifactid jackson-modules-java8 Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom groupid fasterxml.jackson.module Highest Vendor Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-module-parameter-names Low Vendor pom parent-groupid com.fasterxml.jackson.module Medium Vendor pom groupid com.fasterxml.jackson.module Highest Vendor Manifest Implementation-Vendor-Id com.fasterxml.jackson.module Medium Vendor jar package name fasterxml Highest Vendor file name jackson-module-parameter-names High Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest specification-vendor FasterXML Low Vendor Manifest bundle-symbolicname com.fasterxml.jackson.module.jackson-module-parameter-names Medium Vendor Manifest Implementation-Vendor FasterXML High Vendor Manifest implementation-build-date 2021-08-27 01:10:29+0000 Low Vendor pom artifactid jackson-module-parameter-names Low Product pom name Jackson-module-parameter-names High Product jar package name jackson Highest Product jar package name module Highest Product pom artifactid jackson-module-parameter-names Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom groupid fasterxml.jackson.module Highest Product Manifest bundle-docurl https://github.com/FasterXML/jackson-modules-java8/jackson-module-parameter-names Low Product pom parent-groupid com.fasterxml.jackson.module Medium Product jar package name fasterxml Highest Product file name jackson-module-parameter-names High Product Manifest build-jdk-spec 1.8 Low Product Manifest bundle-symbolicname com.fasterxml.jackson.module.jackson-module-parameter-names Medium Product Manifest specification-title Jackson-module-parameter-names Medium Product Manifest Implementation-Title Jackson-module-parameter-names High Product Manifest Bundle-Name Jackson-module-parameter-names Medium Product pom parent-artifactid jackson-modules-java8 Medium Product Manifest implementation-build-date 2021-08-27 01:10:29+0000 Low Version file version 2.12.5 High Version Manifest Bundle-Version 2.12.5 High Version Manifest Implementation-Version 2.12.5 High Version pom version 2.12.5 Highest
jakarta.activation-1.2.2.jarDescription:
Jakarta Activation License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /home/jenkins/.mvnrepository/com/sun/activation/jakarta.activation/1.2.2/jakarta.activation-1.2.2.jar
MD5: 0b8bee3bf29b9a015f8b992035581a7c
SHA1: 74548703f9851017ce2f556066659438019e7eb5
SHA256: 02156773e4ae9d048d14a56ad35d644bee9f1052a791d072df3ded3c656e6e1a
Referenced In Project/Scope: Entando Kubernetes Service:runtime
Evidence Type Source Name Value Confidence Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor pom name Jakarta Activation High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=9.0))" Low Vendor pom parent-artifactid all Low Vendor pom parent-groupid com.sun.activation Medium Vendor jar package name activation Highest Vendor file name jakarta.activation High Vendor Manifest extension-name jakarta.activation Medium Vendor pom groupid sun.activation Highest Vendor Manifest Implementation-Vendor-Id com.sun Medium Vendor jar package name sun Highest Vendor Manifest specification-vendor Eclipse Foundation Low Vendor Manifest bundle-symbolicname com.sun.activation.jakarta.activation Medium Vendor pom artifactid jakarta.activation Low Vendor pom groupid com.sun.activation Highest Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor jar (hint) package name oracle Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product pom name Jakarta Activation High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=9.0))" Low Product pom parent-groupid com.sun.activation Medium Product jar package name activation Highest Product file name jakarta.activation High Product Manifest extension-name jakarta.activation Medium Product pom groupid sun.activation Highest Product jar package name sun Highest Product Manifest specification-title Jakarta Activation Specification Medium Product jar package name javax Highest Product Manifest Bundle-Name Jakarta Activation Medium Product pom artifactid jakarta.activation Highest Product Manifest bundle-symbolicname com.sun.activation.jakarta.activation Medium Product Manifest Implementation-Title javax.activation High Product pom parent-artifactid all Medium Version pom version 1.2.2 Highest Version file version 1.2.2 High Version Manifest Implementation-Version 1.2.2 High Version Manifest Bundle-Version 1.2.2 High
jakarta.activation-api-1.2.2.jarDescription:
Jakarta Activation API jar License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /home/jenkins/.mvnrepository/jakarta/activation/jakarta.activation-api/1.2.2/jakarta.activation-api-1.2.2.jar
MD5: 1cbb480310fa1987f9db7a3ed7118af7
SHA1: 99f53adba383cb1bf7c3862844488574b559621f
SHA256: a187a939103aef5849a7af84bd7e27be2d120c410af291437375ffe061f4f09d
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest bundle-symbolicname jakarta.activation-api Medium Vendor pom artifactid jakarta.activation-api Low Vendor pom groupid jakarta.activation Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=9.0))" Low Vendor pom parent-artifactid all Low Vendor pom parent-groupid com.sun.activation Medium Vendor jar package name activation Highest Vendor Manifest extension-name jakarta.activation Medium Vendor Manifest Implementation-Vendor-Id com.sun Medium Vendor pom name Jakarta Activation API jar High Vendor file name jakarta.activation-api High Vendor Manifest specification-vendor Eclipse Foundation Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Product pom artifactid jakarta.activation-api Highest Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest bundle-symbolicname jakarta.activation-api Medium Product pom groupid jakarta.activation Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=9.0))" Low Product pom parent-groupid com.sun.activation Medium Product jar package name activation Highest Product Manifest extension-name jakarta.activation Medium Product pom name Jakarta Activation API jar High Product Manifest Bundle-Name Jakarta Activation API jar Medium Product file name jakarta.activation-api High Product Manifest Implementation-Title jakarta.activation.jakarta.activation-api High Product Manifest specification-title jakarta.activation.jakarta.activation-api Medium Product pom parent-artifactid all Medium Version pom version 1.2.2 Highest Version file version 1.2.2 High Version Manifest Implementation-Version 1.2.2 High Version Manifest Bundle-Version 1.2.2 High
jakarta.annotation-api-1.3.5.jarDescription:
Jakarta Annotations API License:
EPL 2.0: http://www.eclipse.org/legal/epl-2.0
GPL2 w/ CPE: https://www.gnu.org/software/classpath/license.html File Path: /home/jenkins/.mvnrepository/jakarta/annotation/jakarta.annotation-api/1.3.5/jakarta.annotation-api-1.3.5.jar
MD5: 8b165cf58df5f8c2a222f637c0a07c97
SHA1: 59eb84ee0d616332ff44aba065f3888cf002cd2d
SHA256: 85fb03fc054cdf4efca8efd9b6712bbb418e1ab98241c4539c8585bbc23e1b8a
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom url https://projects.eclipse.org/projects/ee4j.ca Highest Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest automatic-module-name java.annotation Medium Vendor pom name Jakarta Annotations API High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom groupid jakarta.annotation Highest Vendor file name jakarta.annotation-api High Vendor jar package name annotation Highest Vendor Manifest bundle-symbolicname jakarta.annotation-api Medium Vendor Manifest specification-vendor Eclipse Foundation Low Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor Manifest extension-name jakarta.annotation Medium Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor pom artifactid jakarta.annotation-api Low Vendor pom parent-artifactid ca-parent Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest automatic-module-name java.annotation Medium Product pom name Jakarta Annotations API High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product file name jakarta.annotation-api High Product pom groupid jakarta.annotation Highest Product pom parent-artifactid ca-parent Medium Product jar package name annotation Highest Product Manifest bundle-symbolicname jakarta.annotation-api Medium Product Manifest extension-name jakarta.annotation Medium Product pom url https://projects.eclipse.org/projects/ee4j.ca Medium Product pom artifactid jakarta.annotation-api Highest Product Manifest Bundle-Name Jakarta Annotations API Medium Version Manifest Bundle-Version 1.3.5 High Version Manifest Implementation-Version 1.3.5 High Version file version 1.3.5 High Version pom version 1.3.5 Highest
jakarta.validation-api-2.0.2.jarDescription:
Jakarta Bean Validation API
License:
Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/jakarta/validation/jakarta.validation-api/2.0.2/jakarta.validation-api-2.0.2.jar
MD5: 77501d529c1928c9bac2500cc9f93fb0
SHA1: 5eacc6522521f7eacb081f95cee1e231648461e7
SHA256: b42d42428f3d922c892a909fa043287d577c0c5b165ad9b7d568cebf87fc9ea4
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor file name jakarta.validation-api High Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom name Jakarta Bean Validation API High Vendor pom url https://beanvalidation.org Highest Vendor Manifest automatic-module-name java.validation Medium Vendor pom groupid jakarta.validation Highest Vendor pom parent-artifactid project Low Vendor pom parent-groupid org.eclipse.ee4j Medium Vendor jar package name validation Highest Vendor Manifest bundle-symbolicname jakarta.validation.jakarta.validation-api Medium Vendor pom artifactid jakarta.validation-api Low Product file name jakarta.validation-api High Product Manifest bundle-docurl https://www.eclipse.org Low Product pom parent-artifactid project Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom url https://beanvalidation.org Medium Product pom name Jakarta Bean Validation API High Product Manifest automatic-module-name java.validation Medium Product pom groupid jakarta.validation Highest Product pom parent-groupid org.eclipse.ee4j Medium Product jar package name validation Highest Product Manifest bundle-symbolicname jakarta.validation.jakarta.validation-api Medium Product Manifest Bundle-Name Jakarta Bean Validation API Medium Product pom artifactid jakarta.validation-api Highest Version Manifest Bundle-Version 2.0.2 High Version pom version 2.0.2 Highest Version file version 2.0.2 High Version pom parent-version 2.0.2 Low
jakarta.xml.bind-api-2.3.3.jarDescription:
Jakarta XML Binding API 2.3 Design Specification License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /home/jenkins/.mvnrepository/jakarta/xml/bind/jakarta.xml.bind-api/2.3.3/jakarta.xml.bind-api-2.3.3.jar
MD5: 61286918ca0192e9f87d1358aef718dd
SHA1: 48e3b9cfc10752fba3521d6511f4165bea951801
SHA256: c04539f472e9a6dd0c7685ea82d677282269ab8e7baca2e14500e381e0c6cec5
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest build-jdk-spec 11 Low Vendor pom artifactid jakarta.xml.bind-api Low Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor pom groupid jakarta.xml.bind Highest Vendor Manifest bundle-symbolicname jakarta.xml.bind-api Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest extension-name jakarta.xml.bind Medium Vendor file name jakarta.xml.bind-api High Vendor jar package name xml Highest Vendor pom name Jakarta XML Binding API High Vendor Manifest specification-vendor Eclipse Foundation Low Vendor pom parent-artifactid jakarta.xml.bind-api-parent Low Vendor jar package name bind Highest Vendor Manifest implementation-build-id 2.3.3-RELEASE-fd06b2b Low Vendor Manifest multi-release true Low Product Manifest build-jdk-spec 11 Low Product Manifest bundle-docurl https://www.eclipse.org Low Product pom groupid jakarta.xml.bind Highest Product pom parent-artifactid jakarta.xml.bind-api-parent Medium Product Manifest bundle-symbolicname jakarta.xml.bind-api Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest extension-name jakarta.xml.bind Medium Product file name jakarta.xml.bind-api High Product jar package name xml Highest Product pom name Jakarta XML Binding API High Product Manifest Bundle-Name Jakarta XML Binding API Medium Product jar package name bind Highest Product Manifest implementation-build-id 2.3.3-RELEASE-fd06b2b Low Product Manifest multi-release true Low Product pom artifactid jakarta.xml.bind-api Highest Version pom version 2.3.3 Highest Version file version 2.3.3 High Version Manifest Implementation-Version 2.3.3 High Version Manifest Bundle-Version 2.3.3 High
jandex-2.2.3.Final.jarDescription:
Parent POM for JBoss projects. Provides default project build configuration. License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/org/jboss/jandex/2.2.3.Final/jandex-2.2.3.Final.jar
MD5: 721b5868cfbb718dd97facc96929dde8
SHA1: d3865101f0666b63586683bd811d754517f331ab
SHA256: 0544d55ec0cb378fd8f3b20e66277f893f3094cb67e71a1ec0cce6ce150f83b3
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid jboss-parent Low Vendor jar package name indexer Highest Vendor pom groupid org.jboss Highest Vendor Manifest bundle-symbolicname org.jboss.jandex Medium Vendor Manifest java-vendor AdoptOpenJDK Medium Vendor Manifest implementation-url http://www.jboss.org/jandex Low Vendor pom parent-groupid org.jboss Medium Vendor Manifest bundle-docurl http://www.jboss.org Low Vendor hint analyzer vendor redhat Highest Vendor pom groupid jboss Highest Vendor Manifest specification-vendor JBoss by Red Hat Low Vendor jar package name jboss Highest Vendor pom name Java Annotation Indexer High Vendor Manifest automatic-module-name org.jboss.jandex Medium Vendor file name jandex High Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest build-timestamp Fri, 22 Jan 2021 15:14:59 -0600 Low Vendor pom artifactid jandex Low Vendor Manifest Implementation-Vendor-Id org.jboss Medium Vendor Manifest os-arch x86_64 Low Vendor jar package name jandex Highest Vendor Manifest os-name Mac OS X Medium Product jar package name indexer Highest Product pom artifactid jandex Highest Product Manifest Implementation-Title Java Annotation Indexer High Product Manifest specification-title Java Annotation Indexer Medium Product Manifest bundle-symbolicname org.jboss.jandex Medium Product Manifest implementation-url http://www.jboss.org/jandex Low Product pom parent-groupid org.jboss Medium Product Manifest bundle-docurl http://www.jboss.org Low Product Manifest Bundle-Name Java Annotation Indexer Medium Product pom groupid jboss Highest Product jar package name jboss Highest Product pom name Java Annotation Indexer High Product Manifest automatic-module-name org.jboss.jandex Medium Product file name jandex High Product pom parent-artifactid jboss-parent Medium Product Manifest build-timestamp Fri, 22 Jan 2021 15:14:59 -0600 Low Product Manifest os-arch x86_64 Low Product jar package name jandex Highest Product Manifest os-name Mac OS X Medium Version Manifest Bundle-Version 2.2.3.Final High Version Manifest Implementation-Version 2.2.3.Final High Version pom parent-version 2.2.3.Final Low Version pom version 2.2.3.Final Highest
java-semver-0.9.0.jarDescription:
Java implementation of the SemVer Specification License:
The MIT License: http://www.opensource.org/licenses/mit-license.php File Path: /home/jenkins/.mvnrepository/com/github/zafarkhaja/java-semver/0.9.0/java-semver-0.9.0.jar
MD5: 9417096ff6a9db74db273abbda0f334e
SHA1: 59a83ca73c72a5e25b3f0b1bb305230a11000329
SHA256: 2218c73b40f9af98b570d084420c1b4a81332297bd7fc27ddd552e903be8e93c
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid com.github.zafarkhaja Highest Vendor jar package name semver Low Vendor jar package name github Low Vendor pom artifactid java-semver Low Vendor jar package name semver Highest Vendor jar package name zafarkhaja Low Vendor pom name Java SemVer High Vendor jar package name zafarkhaja Highest Vendor pom url zafarkhaja/jsemver Highest Vendor file name java-semver High Vendor pom groupid github.zafarkhaja Highest Vendor jar package name github Highest Product pom url zafarkhaja/jsemver High Product jar package name semver Low Product jar package name semver Highest Product jar package name zafarkhaja Low Product pom name Java SemVer High Product file name java-semver High Product pom groupid github.zafarkhaja Highest Product jar package name github Highest Product pom artifactid java-semver Highest Product jar package name zafarkhaja Highest Version file version 0.9.0 High Version pom version 0.9.0 Highest
javassist-3.23.1-GA.jarDescription:
Javassist (JAVA programming ASSISTant) makes Java bytecode manipulation
simple. It is a class library for editing bytecodes in Java.
License:
MPL 1.1: http://www.mozilla.org/MPL/MPL-1.1.html
LGPL 2.1: http://www.gnu.org/licenses/lgpl-2.1.html
Apache License 2.0: http://www.apache.org/licenses/ File Path: /home/jenkins/.mvnrepository/org/javassist/javassist/3.23.1-GA/javassist-3.23.1-GA.jar
MD5: c99b30482cfdcd42bdc301970a3b2d5d
SHA1: c072c13dcb7f705471c40bafb1536171df850ab2
SHA256: d2b14c09763523374624f32a09d6e31fcb174082a97addb5ae2d580b474fd806
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom organization name Shigeru Chiba, www.javassist.org High Vendor Manifest bundle-symbolicname javassist Medium Vendor pom name Javassist High Vendor pom artifactid javassist Low Vendor jar package name javassist Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor pom groupid org.javassist Highest Vendor pom groupid javassist Highest Vendor file name javassist High Vendor pom url http://www.javassist.org/ Highest Vendor Manifest specification-vendor Shigeru Chiba, www.javassist.org Low Vendor jar package name bytecode Highest Product Manifest bundle-symbolicname javassist Medium Product pom name Javassist High Product pom artifactid javassist Highest Product Manifest Bundle-Name Javassist Medium Product pom url http://www.javassist.org/ Medium Product jar package name javassist Highest Product Manifest specification-title Javassist Medium Product pom organization name Shigeru Chiba, www.javassist.org Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product pom groupid javassist Highest Product file name javassist High Product jar package name bytecode Highest Version Manifest specification-version 3.23.1-GA High Version pom version 3.23.1-GA Highest
javax.activation-api-1.2.0.jarDescription:
JavaBeans Activation Framework API jar License:
https://github.com/javaee/activation/blob/master/LICENSE.txt File Path: /home/jenkins/.mvnrepository/javax/activation/javax.activation-api/1.2.0/javax.activation-api-1.2.0.jar
MD5: 5e50e56bcf4a3ef3bc758f69f7643c3b
SHA1: 85262acf3ca9816f9537ca47d5adeabaead7cb16
SHA256: 43fdef0b5b6ceb31b0424b208b930c74ab58fac2ceeb7b3f6fd3aeb8b5ca4393
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor file name javax.activation-api High Vendor pom parent-artifactid all Low Vendor pom parent-groupid com.sun.activation Medium Vendor jar package name activation Highest Vendor Manifest specification-vendor Oracle Low Vendor Manifest Implementation-Vendor-Id com.sun Medium Vendor pom artifactid javax.activation-api Low Vendor pom name JavaBeans Activation Framework API jar High Vendor jar package name javax Highest Vendor pom groupid javax.activation Highest Vendor Manifest (hint) specification-vendor sun Low Vendor Manifest (hint) Implementation-Vendor sun High Vendor Manifest extension-name javax.activation Medium Vendor Manifest originally-created-by 1.8.0_141 (Oracle Corporation) Low Vendor Manifest automatic-module-name java.activation Medium Vendor Manifest bundle-symbolicname javax.activation-api Medium Vendor Manifest bundle-docurl http://www.oracle.com Low Vendor Manifest Implementation-Vendor Oracle High Product file name javax.activation-api High Product Manifest Implementation-Title javax.activation.javax.activation-api High Product Manifest specification-title javax.activation.javax.activation-api Medium Product pom parent-groupid com.sun.activation Medium Product jar package name activation Highest Product pom artifactid javax.activation-api Highest Product pom name JavaBeans Activation Framework API jar High Product jar package name javax Highest Product Manifest Bundle-Name JavaBeans Activation Framework API jar Medium Product pom groupid javax.activation Highest Product pom parent-artifactid all Medium Product Manifest extension-name javax.activation Medium Product Manifest originally-created-by 1.8.0_141 (Oracle Corporation) Low Product Manifest automatic-module-name java.activation Medium Product Manifest bundle-symbolicname javax.activation-api Medium Product Manifest bundle-docurl http://www.oracle.com Low Version pom version 1.2.0 Highest Version file version 1.2.0 High Version Manifest Bundle-Version 1.2.0 High Version Manifest Implementation-Version 1.2.0 High
javax.annotation-api-1.3.2.jarDescription:
Common Annotations for the JavaTM Platform API License:
CDDL + GPLv2 with classpath exception: https://github.com/javaee/javax.annotation/blob/master/LICENSE File Path: /home/jenkins/.mvnrepository/javax/annotation/javax.annotation-api/1.3.2/javax.annotation-api-1.3.2.jar
MD5: 2ab1973eefffaa2aeec47d50b9e40b9d
SHA1: 934c04d3cfef185a8008e7bf34331b79730a9d43
SHA256: e04ba5195bcd555dc95650f7cc614d151e4bcd52d29a10b8aa2197f3ab89ab9b
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-groupid net.java Medium Vendor Manifest automatic-module-name java.annotation Medium Vendor pom parent-artifactid jvnet-parent Low Vendor pom organization name GlassFish Community High Vendor pom name ${extension.name} API High Vendor jar package name javax Highest Vendor pom artifactid javax.annotation-api Low Vendor jar package name annotation Highest Vendor Manifest Implementation-Vendor GlassFish Community High Vendor Manifest specification-vendor Oracle Corporation Low Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor pom url http://jcp.org/en/jsr/detail?id=250 Highest Vendor file name javax.annotation-api High Vendor pom groupid javax.annotation Highest Vendor Manifest bundle-symbolicname javax.annotation-api Medium Vendor Manifest bundle-docurl https://javaee.github.io/glassfish Low Vendor Manifest extension-name javax.annotation Medium Vendor pom organization url https://javaee.github.io/glassfish Medium Product pom parent-groupid net.java Medium Product pom url http://jcp.org/en/jsr/detail?id=250 Medium Product Manifest automatic-module-name java.annotation Medium Product pom organization name GlassFish Community Low Product pom name ${extension.name} API High Product jar package name javax Highest Product jar package name annotation Highest Product pom organization url https://javaee.github.io/glassfish Low Product pom parent-artifactid jvnet-parent Medium Product pom artifactid javax.annotation-api Highest Product file name javax.annotation-api High Product pom groupid javax.annotation Highest Product Manifest Bundle-Name javax.annotation API Medium Product Manifest bundle-symbolicname javax.annotation-api Medium Product Manifest bundle-docurl https://javaee.github.io/glassfish Low Product Manifest extension-name javax.annotation Medium Version pom parent-version 1.3.2 Low Version file version 1.3.2 High Version pom version 1.3.2 Highest Version Manifest Implementation-Version 1.3.2 High Version Manifest Bundle-Version 1.3.2 High
javax.persistence-api-2.2.jarDescription:
Java(TM) Persistence API License:
Eclipse Public License v1.0: http://www.eclipse.org/legal/epl-v10.html
Eclipse Distribution License v. 1.0: http://www.eclipse.org/org/documents/edl-v10.php File Path: /home/jenkins/.mvnrepository/javax/persistence/javax.persistence-api/2.2/javax.persistence-api-2.2.jar
MD5: e6520b3435f5b6d58eee415b5542abf8
SHA1: 25665ac8c0b62f50e6488173233239120fc52c96
SHA256: 5578b71b37999a5eaed3fea0d14aa61c60c6ec6328256f2b63472f336318baf4
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-groupid net.java Medium Vendor pom artifactid javax.persistence-api Low Vendor jar package name persistence Highest Vendor Manifest bundle-symbolicname javax.persistence-api Medium Vendor file name javax.persistence-api High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest automatic-module-name java.persistence Medium Vendor Manifest extension-name javax.persistence Medium Vendor pom parent-artifactid jvnet-parent Low Vendor jar package name javax Highest Vendor pom url javaee/jpa-spec Highest Vendor Manifest specification-vendor Oracle Corporation Low Vendor Manifest Implementation-Vendor-Id com.oracle Medium Vendor pom groupid javax.persistence Highest Product pom parent-groupid net.java Medium Product Manifest Bundle-Name Java(TM) Persistence API jar Medium Product pom artifactid javax.persistence-api Highest Product jar package name persistence Highest Product Manifest bundle-symbolicname javax.persistence-api Medium Product file name javax.persistence-api High Product pom url javaee/jpa-spec High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product jar package name version Highest Product Manifest automatic-module-name java.persistence Medium Product Manifest extension-name javax.persistence Medium Product jar package name javax Highest Product pom parent-artifactid jvnet-parent Medium Product pom groupid javax.persistence Highest Version pom version 2.2 Highest Version file version 2.2 High Version pom parent-version 2.2 Low Version Manifest Implementation-Version 2.2 High Version Manifest Bundle-Version 2.2 High
jaxb-api-2.3.1.jarDescription:
JAXB (JSR 222) API License:
https://oss.oracle.com/licenses/CDDL+GPL-1.1, https://oss.oracle.com/licenses/CDDL+GPL-1.1 File Path: /home/jenkins/.mvnrepository/javax/xml/bind/jaxb-api/2.3.1/jaxb-api-2.3.1.jar
MD5: bcf270d320f645ad19f5edb60091e87f
SHA1: 8531ad5ac454cc2deb9d4d32c40c4d7451939b5d
SHA256: 88b955a0df57880a26a74708bc34f74dcaf8ebf4e78843a28b50eae945732b06
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name jaxb Highest Vendor Manifest extension-name javax.xml.bind Medium Vendor Manifest implementation-build-id UNKNOWN-7de2ca118a0cfc4a373872915aef59148dff5f93, 2018-09-12T06:28:43-0700 Low Vendor Manifest bundle-docurl http://www.oracle.com/ Low Vendor jar package name javax Highest Vendor jar package name xml Highest Vendor Manifest bundle-symbolicname jaxb-api Medium Vendor pom parent-artifactid jaxb-api-parent Low Vendor Manifest specification-vendor Oracle Corporation Low Vendor Manifest Implementation-Vendor-Id org.glassfish Medium Vendor jar package name bind Highest Vendor file name jaxb-api High Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor pom groupid javax.xml.bind Highest Vendor pom artifactid jaxb-api Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version>=1.8))" Low Vendor Manifest multi-release true Low Product jar package name jaxb Highest Product Manifest extension-name javax.xml.bind Medium Product pom artifactid jaxb-api Highest Product Manifest implementation-build-id UNKNOWN-7de2ca118a0cfc4a373872915aef59148dff5f93, 2018-09-12T06:28:43-0700 Low Product Manifest bundle-docurl http://www.oracle.com/ Low Product Manifest specification-title jaxb-api Medium Product jar package name javax Highest Product jar package name xml Highest Product Manifest bundle-symbolicname jaxb-api Medium Product jar package name bind Highest Product file name jaxb-api High Product pom groupid javax.xml.bind Highest Product Manifest Bundle-Name jaxb-api Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version>=1.8))" Low Product Manifest multi-release true Low Product pom parent-artifactid jaxb-api-parent Medium Version Manifest Bundle-Version 2.3.1 High Version pom version 2.3.1 Highest Version file version 2.3.1 High
jaxb-runtime-2.3.5.jarDescription:
JAXB (JSR 222) Reference Implementation License:
http://www.eclipse.org/org/documents/edl-v10.php File Path: /home/jenkins/.mvnrepository/org/glassfish/jaxb/jaxb-runtime/2.3.5/jaxb-runtime-2.3.5.jar
MD5: 2d3790292a30333a14b7fb1143864a9c
SHA1: a169a961a2bb9ac69517ec1005e451becf5cdfab
SHA256: 4a25453756d08be89c6537cc26fea237677ab99eea857ce1bcb84346715cfae4
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid org.glassfish.jaxb Highest Vendor file name jaxb-runtime High Vendor Manifest git-revision f01d8db Low Vendor pom parent-artifactid jaxb-runtime-parent Low Vendor Manifest Implementation-Vendor-Id org.glassfish.jaxb Medium Vendor Manifest bundle-docurl https://www.eclipse.org Low Vendor Manifest implementation-build-id 2.3.5 - f01d8db Low Vendor pom name JAXB Runtime High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom groupid glassfish.jaxb Highest Vendor jar package name sun Highest Vendor jar package name xml Highest Vendor pom artifactid jaxb-runtime Low Vendor pom parent-groupid com.sun.xml.bind.mvn Medium Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest Vendor jar package name com Highest Vendor jar package name bind Highest Vendor Manifest multi-release true Low Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor jar (hint) package name oracle Highest Vendor Manifest bundle-symbolicname org.glassfish.jaxb.runtime Medium Product file name jaxb-runtime High Product Manifest git-revision f01d8db Low Product Manifest bundle-docurl https://www.eclipse.org Low Product Manifest implementation-build-id 2.3.5 - f01d8db Low Product pom name JAXB Runtime High Product pom artifactid jaxb-runtime Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom groupid glassfish.jaxb Highest Product jar package name sun Highest Product Manifest Bundle-Name JAXB Runtime Medium Product jar package name xml Highest Product pom parent-artifactid jaxb-runtime-parent Medium Product Manifest Implementation-Title Jakarta XML Binding Implementation High Product pom parent-groupid com.sun.xml.bind.mvn Medium Product jar package name com Highest Product jar package name bind Highest Product Manifest specification-title Jakarta XML Binding Medium Product Manifest multi-release true Low Product Manifest bundle-symbolicname org.glassfish.jaxb.runtime Medium Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium Version pom version 2.3.5 Highest Version file version 2.3.5 High Version Manifest build-id 2.3.5 Medium Version Manifest Implementation-Version 2.3.5 High Version Manifest major-version 2.3.5 Medium Version Manifest implementation-build-id 2.3.5 Low Version Manifest Bundle-Version 2.3.5 High
jboss-logging-3.4.2.Final.jarDescription:
The JBoss Logging Framework License:
Apache License, version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/org/jboss/logging/jboss-logging/3.4.2.Final/jboss-logging-3.4.2.Final.jar
MD5: b050c93a9bfbcd28546cec7511a82e9a
SHA1: e517b8a93dd9962ed5481345e4d262fdd47c4217
SHA256: 804d824c9144561ef85a626e453b90a9ce81c103c3910851e057d79ed84c2e38
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid jboss-parent Low Vendor pom groupid jboss.logging Highest Vendor pom groupid org.jboss.logging Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor jar package name logging Highest Vendor Manifest java-vendor Red Hat, Inc. Medium Vendor pom parent-groupid org.jboss Medium Vendor file name jboss-logging High Vendor Manifest bundle-docurl http://www.jboss.org Low Vendor hint analyzer vendor redhat Highest Vendor Manifest bundle-symbolicname org.jboss.logging.jboss-logging Medium Vendor Manifest specification-vendor JBoss by Red Hat Low Vendor jar package name jboss Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor Manifest implementation-url http://www.jboss.org Low Vendor Manifest os-arch amd64 Low Vendor pom name JBoss Logging 3 High Vendor pom url http://www.jboss.org Highest Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest Implementation-Vendor-Id org.jboss.logging Medium Vendor Manifest os-name Linux Medium Vendor Manifest automatic-module-name org.jboss.logging Medium Vendor pom artifactid jboss-logging Low Product Manifest Implementation-Title JBoss Logging 3 High Product pom groupid jboss.logging Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product jar package name logging Highest Product pom parent-groupid org.jboss Medium Product pom url http://www.jboss.org Medium Product file name jboss-logging High Product Manifest bundle-docurl http://www.jboss.org Low Product Manifest bundle-symbolicname org.jboss.logging.jboss-logging Medium Product Manifest specification-title JBoss Logging 3 Medium Product jar package name jboss Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest implementation-url http://www.jboss.org Low Product Manifest os-arch amd64 Low Product pom parent-artifactid jboss-parent Medium Product pom artifactid jboss-logging Highest Product pom name JBoss Logging 3 High Product Manifest Bundle-Name JBoss Logging 3 Medium Product Manifest os-name Linux Medium Product Manifest automatic-module-name org.jboss.logging Medium Version Manifest Implementation-Version 3.4.2.Final High Version pom parent-version 3.4.2.Final Low Version pom version 3.4.2.Final Highest Version Manifest Bundle-Version 3.4.2.Final High
jboss-transaction-api_1.2_spec-1.1.1.Final.jarDescription:
The Java Transaction 1.2 API classes License:
Common Development and Distribution License: http://repository.jboss.org/licenses/cddl.txt
GNU General Public License, Version 2 with the Classpath Exception: http://repository.jboss.org/licenses/gpl-2.0-ce.txt File Path: /home/jenkins/.mvnrepository/org/jboss/spec/javax/transaction/jboss-transaction-api_1.2_spec/1.1.1.Final/jboss-transaction-api_1.2_spec-1.1.1.Final.jar
MD5: 1e633c47138aba999d39692a31a1a124
SHA1: a8485cab9484dda36e9a8c319e76b5cc18797b58
SHA256: a310a50b9bdc44aaf36362dc9bb212235a147ffa8ef72dc9544a39c329eabbc3
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest os-arch x86 Low Vendor pom parent-artifactid jboss-parent Low Vendor pom groupid org.jboss.spec.javax.transaction Highest Vendor file name jboss-transaction-api_1.2_spec-1.1.1.Final High Vendor jar package name transaction Highest Vendor pom parent-groupid org.jboss Medium Vendor Manifest bundle-docurl http://www.jboss.org Low Vendor jar package name javax Highest Vendor hint analyzer vendor redhat Highest Vendor Manifest automatic-module-name java.transaction Medium Vendor Manifest os-name Windows 10 Medium Vendor Manifest Implementation-Vendor-Id org.jboss.spec.javax.transaction Medium Vendor Manifest bundle-symbolicname org.jboss.spec.javax.transaction.jboss-transaction-api_1.2_spec Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor pom artifactid jboss-transaction-api_1.2_spec Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor pom groupid jboss.spec.javax.transaction Highest Vendor Manifest Implementation-Vendor JBoss by Red Hat High Vendor Manifest implementation-url http://www.jboss.org/jboss-transaction-api_1.2_spec Low Vendor pom name Java Transaction API High Product Manifest os-arch x86 Low Product file name jboss-transaction-api_1.2_spec-1.1.1.Final High Product jar package name transaction Highest Product Manifest Implementation-Title Java Transaction API High Product pom parent-groupid org.jboss Medium Product Manifest bundle-docurl http://www.jboss.org Low Product jar package name javax Highest Product Manifest automatic-module-name java.transaction Medium Product Manifest os-name Windows 10 Medium Product pom artifactid jboss-transaction-api_1.2_spec Highest Product Manifest bundle-symbolicname org.jboss.spec.javax.transaction.jboss-transaction-api_1.2_spec Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product Manifest specification-title JSR 907: Java Transaction API (JTA) Medium Product pom parent-artifactid jboss-parent Medium Product pom groupid jboss.spec.javax.transaction Highest Product Manifest implementation-url http://www.jboss.org/jboss-transaction-api_1.2_spec Low Product pom name Java Transaction API High Product Manifest Bundle-Name Java Transaction API Medium Version Manifest Implementation-Version 1.1.1.Final High Version pom parent-version 1.1.1.Final Low Version Manifest Bundle-Version 1.1.1.Final High Version pom version 1.1.1.Final Highest
jcip-annotations-1.0-1.jarDescription:
A clean room implementation of the JCIP Annotations based entirely on the specification provided by the javadocs.
License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/com/github/stephenc/jcip/jcip-annotations/1.0-1/jcip-annotations-1.0-1.jar
MD5: d62dbfa8789378457ada685e2f614846
SHA1: ef31541dd28ae2cefdd17c7ebf352d93e9058c63
SHA256: 4fccff8382aafc589962c4edb262f6aa595e34f1e11e61057d1c6a96e8fc7323
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid com.github.stephenc.jcip Highest Vendor pom artifactid jcip-annotations Low Vendor jar package name annotations Low Vendor pom name JCIP Annotations under Apache License High Vendor pom url http://stephenc.github.com/jcip-annotations Highest Vendor jar package name jcip Highest Vendor jar package name net Low Vendor pom groupid github.stephenc.jcip Highest Vendor jar package name annotations Highest Vendor jar package name jcip Low Vendor file name jcip-annotations High Product pom url http://stephenc.github.com/jcip-annotations Medium Product jar package name annotations Low Product pom name JCIP Annotations under Apache License High Product jar package name jcip Highest Product pom groupid github.stephenc.jcip Highest Product pom artifactid jcip-annotations Highest Product jar package name annotations Highest Product jar package name jcip Low Product file name jcip-annotations High Version pom version 1.0-1 Highest
jcl-over-slf4j-1.7.32.jarDescription:
JCL 1.2 implemented over SLF4J License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/org/slf4j/jcl-over-slf4j/1.7.32/jcl-over-slf4j-1.7.32.jar
MD5: 8788169f5d5be6550efc75d3bfffc82c
SHA1: 32c060250bcc5282cdbc1fd7008c12eb4ebad00e
SHA256: 60f3bda5922e3912889cca1311d1b227753610bf60cb4e5e914e8b2eaa0326b4
Referenced In Project/Scope: Entando Kubernetes Service:runtime
Evidence Type Source Name Value Confidence Vendor pom name JCL 1.2 implemented over SLF4J High Vendor file name jcl-over-slf4j High Vendor pom parent-groupid org.slf4j Medium Vendor Manifest automatic-module-name org.apache.commons.logging Medium Vendor jar package name logging Highest Vendor jar package name commons Highest Vendor Manifest bundle-symbolicname jcl.over.slf4j Medium Vendor pom parent-artifactid slf4j-parent Low Vendor pom groupid org.slf4j Highest Vendor pom artifactid jcl-over-slf4j Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor jar package name apache Highest Vendor pom groupid slf4j Highest Vendor pom url http://www.slf4j.org Highest Product Manifest Implementation-Title jcl-over-slf4j High Product pom parent-artifactid slf4j-parent Medium Product pom name JCL 1.2 implemented over SLF4J High Product file name jcl-over-slf4j High Product pom parent-groupid org.slf4j Medium Product Manifest automatic-module-name org.apache.commons.logging Medium Product pom url http://www.slf4j.org Medium Product jar package name logging Highest Product jar package name commons Highest Product Manifest bundle-symbolicname jcl.over.slf4j Medium Product Manifest Bundle-Name jcl-over-slf4j Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product pom artifactid jcl-over-slf4j Highest Product jar package name apache Highest Product pom groupid slf4j Highest Version Manifest Bundle-Version 1.7.32 High Version Manifest Implementation-Version 1.7.32 High Version file version 1.7.32 High Version pom version 1.7.32 Highest
jna-4.5.1.jarDescription:
Java Native Access License:
LGPL, version 2.1: http://www.gnu.org/licenses/licenses.html
Apache License v2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/net/java/dev/jna/jna/4.5.1/jna-4.5.1.jar
MD5: 2309aa0981207a1e853dd9c806c44082
SHA1: 65bd0cacc9c79a21c6ed8e9f588577cd3c2f85b9
SHA256: fbc9de96a0cc193a125b4008dbc348e9ed54e5e13fc67b8ed40e645d303cc51b
Referenced In Project/Scope: Entando Kubernetes Service:runtime
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor JNA Development Team Low Vendor Manifest bundle-symbolicname com.sun.jna Medium Vendor Manifest bundle-nativecode com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win32, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win32, com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win, com/sun/jna/w32ce-arm/jnidispatch.dll; processor=arm;osname=wince, com/sun/jna/sunos-x86/libjnidispatch.so; processor=x86;osname=sunos, com/sun/jna/sunos-x86-64/libjnidispatch.so; processor=x86-64;osname=sunos, com/sun/jna/sunos-sparc/libjnidispatch.so; processor=sparc;osname=sunos, com/sun/jna/sunos-sparcv9/libjnidispatch.so; processor=sparcv9;osname=sunos, com/sun/jna/aix-ppc/libjnidispatch.a; processor=ppc;osname=aix, com/sun/jna/aix-ppc64/libjnidispatch.a; processor=ppc64;osname=aix, com/sun/jna/linux-ppc/libjnidispatch.so; processor=ppc;osname=linux, com/sun/jna/linux-ppc64/libjnidispatch.so; processor=ppc64;osname=linux, com/sun/jna/linux-ppc64le/libjnidispatch.so; processor=ppc64le;osname=linux, com/sun/jna/linux-x86/libjnidispatch.so; processor=x86;osname=linux, com/sun/jna/linux-x86-64/libjnidispatch.so; processor=x86-64;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm;osname=linux, com/sun/jna/linux-armel/libjnidispatch.so; processor=armel;osname=linux, com/sun/jna/linux-aarch64/libjnidispatch.so; processor=aarch64;osname=linux, com/sun/jna/linux-ia64/libjnidispatch.so; processor=ia64;osname=linux, com/sun/jna/linux-sparcv9/libjnidispatch.so; processor=sparcv9;osname=linux, com/sun/jna/linux-mips64el/libjnidispatch.so; processor=mips64el;osname=linux, com/sun/jna/linux-s390x/libjnidispatch.so; processor=S390x;osname=linux, com/sun/jna/freebsd-x86/libjnidispatch.so; processor=x86;osname=freebsd, com/sun/jna/freebsd-x86-64/libjnidispatch.so; processor=x86-64;osname=freebsd, com/sun/jna/openbsd-x86/libjnidispatch.so; processor=x86;osname=openbsd, com/sun/jna/openbsd-x86-64/libjnidispatch.so; processor=x86-64;osname=openbsd, com/sun/jna/darwin/libjnidispatch.jnilib; osname=macosx;processor=x86;processor=x86-64;processor=ppc Low Vendor Manifest Implementation-Vendor JNA Development Team High Vendor Manifest bundle-category jni Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.4 Low Vendor jar package name sun Highest Vendor pom name Java Native Access High Vendor pom groupid net.java.dev.jna Highest Vendor Manifest bundle-activationpolicy lazy Low Vendor file name jna High Vendor jar package name native Highest Vendor pom artifactid jna Low Vendor pom url java-native-access/jna Highest Vendor jar (hint) package name oracle Highest Vendor jar package name jna Highest Product Manifest bundle-symbolicname com.sun.jna Medium Product Manifest bundle-nativecode com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win32, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win32, com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win, com/sun/jna/w32ce-arm/jnidispatch.dll; processor=arm;osname=wince, com/sun/jna/sunos-x86/libjnidispatch.so; processor=x86;osname=sunos, com/sun/jna/sunos-x86-64/libjnidispatch.so; processor=x86-64;osname=sunos, com/sun/jna/sunos-sparc/libjnidispatch.so; processor=sparc;osname=sunos, com/sun/jna/sunos-sparcv9/libjnidispatch.so; processor=sparcv9;osname=sunos, com/sun/jna/aix-ppc/libjnidispatch.a; processor=ppc;osname=aix, com/sun/jna/aix-ppc64/libjnidispatch.a; processor=ppc64;osname=aix, com/sun/jna/linux-ppc/libjnidispatch.so; processor=ppc;osname=linux, com/sun/jna/linux-ppc64/libjnidispatch.so; processor=ppc64;osname=linux, com/sun/jna/linux-ppc64le/libjnidispatch.so; processor=ppc64le;osname=linux, com/sun/jna/linux-x86/libjnidispatch.so; processor=x86;osname=linux, com/sun/jna/linux-x86-64/libjnidispatch.so; processor=x86-64;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm;osname=linux, com/sun/jna/linux-armel/libjnidispatch.so; processor=armel;osname=linux, com/sun/jna/linux-aarch64/libjnidispatch.so; processor=aarch64;osname=linux, com/sun/jna/linux-ia64/libjnidispatch.so; processor=ia64;osname=linux, com/sun/jna/linux-sparcv9/libjnidispatch.so; processor=sparcv9;osname=linux, com/sun/jna/linux-mips64el/libjnidispatch.so; processor=mips64el;osname=linux, com/sun/jna/linux-s390x/libjnidispatch.so; processor=S390x;osname=linux, com/sun/jna/freebsd-x86/libjnidispatch.so; processor=x86;osname=freebsd, com/sun/jna/freebsd-x86-64/libjnidispatch.so; processor=x86-64;osname=freebsd, com/sun/jna/openbsd-x86/libjnidispatch.so; processor=x86;osname=openbsd, com/sun/jna/openbsd-x86-64/libjnidispatch.so; processor=x86-64;osname=openbsd, com/sun/jna/darwin/libjnidispatch.jnilib; osname=macosx;processor=x86;processor=x86-64;processor=ppc Low Product Manifest bundle-category jni Low Product Manifest bundle-requiredexecutionenvironment J2SE-1.4 Low Product pom artifactid jna Highest Product jar package name sun Highest Product pom name Java Native Access High Product pom url java-native-access/jna High Product Manifest Implementation-Title com.sun.jna High Product pom groupid net.java.dev.jna Highest Product Manifest specification-title Java Native Access (JNA) Medium Product Manifest bundle-activationpolicy lazy Low Product file name jna High Product jar package name native Highest Product jar package name win32 Highest Product Manifest Bundle-Name jna Medium Product jar package name jna Highest Product jar package name library Highest Version pom version 4.5.1 Highest Version file version 4.5.1 High Version Manifest Bundle-Version 4.5.1 High
jna-4.5.1.jar: jnidispatch.dllFile Path: /home/jenkins/.mvnrepository/net/java/dev/jna/jna/4.5.1/jna-4.5.1.jar/com/sun/jna/win32-x86/jnidispatch.dllMD5: 9268651539d1ecbec9e6ed81aeced380SHA1: a7c725bce11d28000dd49a3717288b098a588c9fSHA256: 67059e9d04131cf85b41b881d214fc745d8e165859dadb7634114e7e96eb6e42Referenced In Project/Scope: Entando Kubernetes Service:runtime
Evidence Type Source Name Value Confidence Vendor file name jnidispatch High Product file name jnidispatch High
jna-4.5.1.jar: jnidispatch.dllFile Path: /home/jenkins/.mvnrepository/net/java/dev/jna/jna/4.5.1/jna-4.5.1.jar/com/sun/jna/win32-x86-64/jnidispatch.dllMD5: 1164914ca1307de98cc0d57e42285ef2SHA1: 9387f983c88c425c91e5caae2409cf4180b02096SHA256: 0525f9e2db0146f7abcc8cd86cf4fb01721fad0d5c9a1806b5805bb789eb8c98Referenced In Project/Scope: Entando Kubernetes Service:runtime
Evidence Type Source Name Value Confidence Vendor file name jnidispatch High Product file name jnidispatch High
jna-platform-4.5.1.jarDescription:
Java Native Access Platform License:
LGPL, version 2.1: http://www.gnu.org/licenses/licenses.html
Apache License v2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/net/java/dev/jna/jna-platform/4.5.1/jna-platform-4.5.1.jar
MD5: 9c7b0fcb0472ae92b50ce17577e370d1
SHA1: 117d52c9f672d8b7ea80a81464c33ef843de9254
SHA256: 84c8667555ee8dd91fef44b451419f6f16f71f727d5fc475a10c2663eba83abb
Referenced In Project/Scope: Entando Kubernetes Service:runtime
Evidence Type Source Name Value Confidence Vendor Manifest specification-vendor JNA Development Team Low Vendor Manifest Implementation-Vendor JNA Development Team High Vendor Manifest bundle-category jni Low Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.4 Low Vendor jar package name sun Highest Vendor pom artifactid jna-platform Low Vendor Manifest require-bundle com.sun.jna;bundle-version="4.5.1" Low Vendor pom groupid net.java.dev.jna Highest Vendor Manifest bundle-symbolicname com.sun.jna.platform Medium Vendor pom name Java Native Access Platform High Vendor jar package name platform Highest Vendor pom url java-native-access/jna Highest Vendor jar (hint) package name oracle Highest Vendor file name jna-platform High Vendor jar package name jna Highest Product Manifest Implementation-Title com.sun.jna.platform High Product Manifest bundle-category jni Low Product Manifest bundle-requiredexecutionenvironment J2SE-1.4 Low Product jar package name sun Highest Product Manifest Bundle-Name jna-platform Medium Product Manifest require-bundle com.sun.jna;bundle-version="4.5.1" Low Product pom url java-native-access/jna High Product pom artifactid jna-platform Highest Product pom groupid net.java.dev.jna Highest Product Manifest specification-title Java Native Access (JNA) Medium Product Manifest bundle-symbolicname com.sun.jna.platform Medium Product pom name Java Native Access Platform High Product jar package name platform Highest Product file name jna-platform High Product jar package name jna Highest Version pom version 4.5.1 Highest Version file version 4.5.1 High Version Manifest Bundle-Version 4.5.1 High
jsch-0.1.54.jarDescription:
JSch is a pure Java implementation of SSH2 License:
Revised BSD: http://www.jcraft.com/jsch/LICENSE.txt File Path: /home/jenkins/.mvnrepository/com/jcraft/jsch/0.1.54/jsch-0.1.54.jar
MD5: 56a6c6fc5819e21c665355b39b9097d8
SHA1: da3584329a263616e277e15462b387addd1b208d
SHA256: 92eb273a3316762478fdd4fe03a0ce1842c56f496c9c12fe1235db80450e1fdb
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom name JSch High Vendor jar package name jcraft Highest Vendor pom url http://www.jcraft.com/jsch/ Highest Vendor jar package name jsch Low Vendor pom organization url http://www.jcraft.com/ Medium Vendor pom groupid com.jcraft Highest Vendor pom groupid jcraft Highest Vendor pom organization name JCraft,Inc. High Vendor file name jsch High Vendor pom artifactid jsch Low Vendor jar package name jcraft Low Vendor jar package name jsch Highest Product pom groupid jcraft Highest Product pom name JSch High Product jar package name jcraft Highest Product file name jsch High Product pom artifactid jsch Highest Product jar package name jsch Low Product pom organization url http://www.jcraft.com/ Low Product pom url http://www.jcraft.com/jsch/ Medium Product pom organization name JCraft,Inc. Low Product jar package name jsch Highest Version pom version 0.1.54 Highest Version file version 0.1.54 High
json-path-2.5.0.jarDescription:
Java port of Stefan Goessner JsonPath. License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/com/jayway/jsonpath/json-path/2.5.0/json-path-2.5.0.jar
MD5: c16241d78783e2e2b93429afb4c783aa
SHA1: c35ef29095125b51638d19120f63e2b56eff20e9
SHA256: 4ed3c4c2d4e477cb2a349c0ebb8c22f0584702221ddbaafd166fddcd2101029b
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom name project ':json-path' High Vendor pom groupid jayway.jsonpath Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid json-path Low Vendor jar package name jayway Highest Vendor pom url jayway/JsonPath Highest Vendor pom groupid com.jayway.jsonpath Highest Vendor jar package name path Highest Vendor jar package name json Highest Vendor Manifest bundle-symbolicname com.jayway.jsonpath.json-path Medium Vendor jar package name jsonpath Highest Vendor file name json-path High Product pom name project ':json-path' High Product pom groupid jayway.jsonpath Highest Product pom url jayway/JsonPath High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest Bundle-Name json-path Medium Product jar package name jayway Highest Product pom artifactid json-path Highest Product jar package name filter Highest Product jar package name path Highest Product jar package name json Highest Product Manifest bundle-symbolicname com.jayway.jsonpath.json-path Medium Product jar package name jsonpath Highest Product file name json-path High Product Manifest Implementation-Title json-path High Version Manifest Bundle-Version 2.5.0 High Version Manifest Implementation-Version 2.5.0 High Version file version 2.5.0 High Version pom version 2.5.0 Highest
json-smart-2.4.7.jarDescription:
JSON (JavaScript Object Notation) is a lightweight data-interchange format. It is easy for humans to read and write. It is easy for machines to parse and generate. It is based on a subset of the JavaScript Programming Language, Standard ECMA-262 3rd Edition - December 1999. JSON is a text format that is completely language independent but uses conventions that are familiar to programmers of the C-family of languages, including C, C++, C#, Java, JavaScript, Perl, Python, and many others. These properties make JSON an ideal data-interchange language. License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/net/minidev/json-smart/2.4.7/json-smart-2.4.7.jar
MD5: f04005088df03f6efac608a7a5d53cd1
SHA1: 8d7f4c1530c07c54930935f3da85f48b83b3c109
SHA256: 28c17ed16ac22e6845743fd1e84321edf5d7735fc216e44ee269d106bf3d8146
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid json-smart Low Vendor pom url https://urielch.github.io/ Highest Vendor pom organization url https://urielch.github.io/ Medium Vendor pom name JSON Small and Fast Parser High Vendor jar package name parser Highest Vendor jar package name net Highest Vendor pom groupid net.minidev Highest Vendor Manifest bundle-docurl https://urielch.github.io/ Low Vendor jar package name minidev Highest Vendor jar package name json Highest Vendor Manifest bundle-symbolicname net.minidev.json-smart Medium Vendor file name json-smart High Vendor pom organization name Chemouni Uriel High Product pom artifactid json-smart Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom name JSON Small and Fast Parser High Product jar package name parser Highest Product jar package name net Highest Product pom url https://urielch.github.io/ Medium Product pom groupid net.minidev Highest Product jar package name json Highest Product Manifest bundle-docurl https://urielch.github.io/ Low Product Manifest Bundle-Name json-smart Medium Product jar package name minidev Highest Product Manifest bundle-symbolicname net.minidev.json-smart Medium Product file name json-smart High Product pom organization name Chemouni Uriel Low Product pom organization url https://urielch.github.io/ Low Version Manifest Bundle-Version 2.4.7 High Version pom version 2.4.7 Highest Version file version 2.4.7 High
jsr305-3.0.2.jarDescription:
JSR305 Annotations for Findbugs License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/com/google/code/findbugs/jsr305/3.0.2/jsr305-3.0.2.jar
MD5: dd83accb899363c32b07d7a1b2e4ce40
SHA1: 25ea2e8b0c338a877313bd4672d3fe056ea78f0d
SHA256: 766ad2a0783f2687962c8ad74ceecc38a28b9f72a2d085ee438b7813e928d0c7
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest bundle-symbolicname org.jsr-305 Medium Vendor pom url http://findbugs.sourceforge.net/ Highest Vendor file name jsr305 High Vendor pom artifactid jsr305 Low Vendor pom name FindBugs-jsr305 High Vendor pom groupid google.code.findbugs Highest Vendor pom groupid com.google.code.findbugs Highest Product Manifest bundle-symbolicname org.jsr-305 Medium Product file name jsr305 High Product Manifest Bundle-Name FindBugs-jsr305 Medium Product pom name FindBugs-jsr305 High Product pom url http://findbugs.sourceforge.net/ Medium Product pom groupid google.code.findbugs Highest Product pom artifactid jsr305 Highest Version Manifest Bundle-Version 3.0.2 High Version pom version 3.0.2 Highest Version file version 3.0.2 High
jul-to-slf4j-1.7.32.jarDescription:
JUL to SLF4J bridge File Path: /home/jenkins/.mvnrepository/org/slf4j/jul-to-slf4j/1.7.32/jul-to-slf4j-1.7.32.jarMD5: cf36bbee73d82b6b96a6414ef9f54df1SHA1: 8a055c04ab44e8e8326901cadf89080721348bdbSHA256: 6dee8d85ad6943aff0600f14897c469e64bae0413ee33a15c448af00432c0642Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest bundle-symbolicname jul.to.slf4j Medium Vendor pom artifactid jul-to-slf4j Low Vendor pom parent-groupid org.slf4j Medium Vendor pom name JUL to SLF4J bridge High Vendor jar package name slf4j Highest Vendor file name jul-to-slf4j High Vendor pom parent-artifactid slf4j-parent Low Vendor pom groupid org.slf4j Highest Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor pom groupid slf4j Highest Vendor jar package name bridge Highest Vendor pom url http://www.slf4j.org Highest Product pom artifactid jul-to-slf4j Highest Product Manifest bundle-symbolicname jul.to.slf4j Medium Product pom parent-artifactid slf4j-parent Medium Product pom parent-groupid org.slf4j Medium Product pom url http://www.slf4j.org Medium Product pom name JUL to SLF4J bridge High Product jar package name slf4j Highest Product file name jul-to-slf4j High Product Manifest Bundle-Name jul-to-slf4j Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product pom groupid slf4j Highest Product jar package name bridge Highest Version Manifest Bundle-Version 1.7.32 High Version Manifest Implementation-Version 1.7.32 High Version file version 1.7.32 High Version pom version 1.7.32 Highest
jzlib-1.1.1.jarDescription:
JZlib is a re-implementation of zlib in pure Java License:
Revised BSD: http://www.jcraft.com/jzlib/LICENSE.txt File Path: /home/jenkins/.mvnrepository/com/jcraft/jzlib/1.1.1/jzlib-1.1.1.jar
MD5: 553b605c56ec6f508ab46ed026e21622
SHA1: a1551373315ffc2f96130a0e5704f74e151777ba
SHA256: 5cb1e9f9cf0be011487545694ff0a178237c6bfcbb21c97865cdc52c60b9347a
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid jzlib Low Vendor jar package name jzlib Low Vendor jar package name jzlib Highest Vendor pom url http://www.jcraft.com/jzlib/ Highest Vendor jar package name jcraft Highest Vendor pom name JZlib High Vendor pom organization url http://www.jcraft.com/ Medium Vendor pom groupid com.jcraft Highest Vendor pom groupid jcraft Highest Vendor pom organization name JCraft,Inc. High Vendor file name jzlib High Vendor jar package name jcraft Low Product jar package name jzlib Low Product jar package name jzlib Highest Product pom groupid jcraft Highest Product jar package name jcraft Highest Product pom name JZlib High Product pom organization url http://www.jcraft.com/ Low Product pom url http://www.jcraft.com/jzlib/ Medium Product file name jzlib High Product pom organization name JCraft,Inc. Low Product pom artifactid jzlib Highest Version pom version 1.1.1 Highest Version file version 1.1.1 High
kubernetes-client-4.10.3.jarFile Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-client/4.10.3/kubernetes-client-4.10.3.jarMD5: 07f7e47f352be91d0bdb373520e2d1c4SHA1: 7000f01dc1ef12dff25c0f9979becce540f74b26SHA256: 64a9d6e5e42b3d67e45760a99fc368239e6853fa76986ed08c4a48f27a8e0fefReferenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid kubernetes-client-project Low Vendor pom groupid io.fabric8 Highest Vendor pom artifactid kubernetes-client Low Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor file name kubernetes-client High Vendor Manifest build-jdk-spec 14 Low Vendor jar package name fabric8 Highest Vendor jar package name client Highest Vendor pom name Fabric8 :: Kubernetes :: Java Client High Product pom groupid io.fabric8 Highest Product jar package name kubernetes Highest Product pom artifactid kubernetes-client Highest Product jar package name io Highest Product file name kubernetes-client High Product Manifest build-jdk-spec 14 Low Product jar package name fabric8 Highest Product pom parent-artifactid kubernetes-client-project Medium Product jar package name client Highest Product pom name Fabric8 :: Kubernetes :: Java Client High Version pom version 4.10.3 Highest Version file version 4.10.3 High
kubernetes-model-admissionregistration-4.10.3.jarDescription:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-admissionregistration/4.10.3/kubernetes-model-admissionregistration-4.10.3.jar
MD5: 6cee0d468f74352c5a0bbb7641eef974
SHA1: 92aa117119fbe0559f0b5ebb548c3a8ad2e77902
SHA256: 2f189af15c564ff796691b7d11cd1c8929b51a3597bb2e339ec3407c9632d9ff
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest build-timestamp ${build.datetime} Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid kubernetes-model-admissionregistration Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor file name kubernetes-model-admissionregistration High Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-admissionregistration Medium Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor pom name Fabric8 :: Kubernetes Model :: Admission Registration, Authentication and Authorization High Vendor Manifest java-vendor Oracle Corporation Medium Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-admissionregistration/ Low Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Product Manifest build-timestamp ${build.datetime} Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Admission Registration, Authentication and Authorization High Product file name kubernetes-model-admissionregistration High Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product jar package name io Highest Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-admissionregistration Medium Product Manifest os-arch amd64 Low Product pom name Fabric8 :: Kubernetes Model :: Admission Registration, Authentication and Authorization High Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Admission Registration, Authentication and Authorization Medium Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-admissionregistration/ Low Product Manifest specification-title Fabric8 :: Kubernetes Model :: Admission Registration, Authentication and Authorization Medium Product pom parent-artifactid kubernetes-model-generator Medium Product pom artifactid kubernetes-model-admissionregistration Highest Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
kubernetes-model-apiextensions-4.10.3.jarDescription:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-apiextensions/4.10.3/kubernetes-model-apiextensions-4.10.3.jar
MD5: fadd6f5239e4a5f5792547f9f830e0be
SHA1: f59b61eec3666fbca6577f3db953e6a15fc2c4a8
SHA256: 14453ac8dc0eed3b3156ff23d5e6972d3408893469459b73019c276cfd65e338
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-apiextensions Medium Vendor Manifest build-timestamp ${build.datetime} Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor pom artifactid kubernetes-model-apiextensions Low Vendor pom name Fabric8 :: Kubernetes Model :: API Extensions High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor jar package name api Highest Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor file name kubernetes-model-apiextensions High Vendor Manifest specification-vendor Red Hat Low Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-apiextensions/ Low Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-apiextensions Medium Product Manifest specification-title Fabric8 :: Kubernetes Model :: API Extensions Medium Product Manifest build-timestamp ${build.datetime} Low Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: API Extensions Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid kubernetes-model-apiextensions Highest Product pom name Fabric8 :: Kubernetes Model :: API Extensions High Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product jar package name io Highest Product Manifest os-arch amd64 Low Product pom parent-artifactid kubernetes-model-generator Medium Product jar package name api Highest Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Product file name kubernetes-model-apiextensions High Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: API Extensions High Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-apiextensions/ Low Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
kubernetes-model-apps-4.10.3.jarDescription:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-apps/4.10.3/kubernetes-model-apps-4.10.3.jar
MD5: c3f8d600e86db925475db33868ed4aa4
SHA1: 7ead298312bc14a73d48c102d65c01b827f1e01f
SHA256: 95b93b241d76c88f70c73078e5316b5a127fb1cf89ded89d08aec9f7faf0752d
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest build-timestamp ${build.datetime} Low Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-apps/ Low Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-apps Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor file name kubernetes-model-apps High Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor pom name Fabric8 :: Kubernetes Model :: Apps High Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor pom artifactid kubernetes-model-apps Low Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Product Manifest build-timestamp ${build.datetime} Low Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-apps/ Low Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Apps High Product pom artifactid kubernetes-model-apps Highest Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-apps Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Fabric8 :: Kubernetes Model :: Apps Medium Product file name kubernetes-model-apps High Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product jar package name io Highest Product pom name Fabric8 :: Kubernetes Model :: Apps High Product Manifest os-arch amd64 Low Product pom parent-artifactid kubernetes-model-generator Medium Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Apps Medium Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
kubernetes-model-autoscaling-4.10.3.jarDescription:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-autoscaling/4.10.3/kubernetes-model-autoscaling-4.10.3.jar
MD5: e19219399d89b7bd6857a513f1a0e3f4
SHA1: 08f7176dcd771a711595b36d2c7f6c29125422fd
SHA256: f287f7877d0b94ea257094786df0cf41bcac03e20fcf5f83e45073782e8d38b6
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest build-timestamp ${build.datetime} Low Vendor pom name Fabric8 :: Kubernetes Model :: Autoscaling High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor file name kubernetes-model-autoscaling High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-autoscaling/ Low Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-autoscaling Medium Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor pom artifactid kubernetes-model-autoscaling Low Vendor Manifest specification-vendor Red Hat Low Product pom artifactid kubernetes-model-autoscaling Highest Product Manifest build-timestamp ${build.datetime} Low Product pom name Fabric8 :: Kubernetes Model :: Autoscaling High Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Autoscaling Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Autoscaling High Product file name kubernetes-model-autoscaling High Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product jar package name io Highest Product Manifest os-arch amd64 Low Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-autoscaling/ Low Product Manifest specification-title Fabric8 :: Kubernetes Model :: Autoscaling Medium Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-autoscaling Medium Product pom parent-artifactid kubernetes-model-generator Medium Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
kubernetes-model-batch-4.10.3.jarDescription:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-batch/4.10.3/kubernetes-model-batch-4.10.3.jar
MD5: 072af6ea7246e921f0851f5968767377
SHA1: 89382157261fbf748fc2c8a3b961fde12ae5077e
SHA256: 31023e04d13e4c6b4e8ea99ce7c14a70a55afa4a67d86aa9b71f0ad1e9d636ae
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest build-timestamp ${build.datetime} Low Vendor file name kubernetes-model-batch High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor pom artifactid kubernetes-model-batch Low Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-batch/ Low Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor pom name Fabric8 :: Kubernetes Model :: Batch High Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-batch Medium Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Product Manifest specification-title Fabric8 :: Kubernetes Model :: Batch Medium Product Manifest build-timestamp ${build.datetime} Low Product file name kubernetes-model-batch High Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Batch High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-batch/ Low Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product jar package name io Highest Product Manifest os-arch amd64 Low Product pom artifactid kubernetes-model-batch Highest Product pom parent-artifactid kubernetes-model-generator Medium Product pom name Fabric8 :: Kubernetes Model :: Batch High Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Batch Medium Product jar package name fabric8 Highest Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-batch Medium Product Manifest os-name Linux Medium Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
kubernetes-model-certificates-4.10.3.jarDescription:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-certificates/4.10.3/kubernetes-model-certificates-4.10.3.jar
MD5: defa9d55ee2706f1cc69c9a9a77f02d2
SHA1: 4591fc267e8475386f5ef74e0878751dbda1e064
SHA256: 3edcc947621f1e545313de08862a75abebc799d241add83192596df8db9296f8
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom name Fabric8 :: Kubernetes Model :: Certificates High Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-certificates/ Low Vendor Manifest build-timestamp ${build.datetime} Low Vendor file name kubernetes-model-certificates High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor pom artifactid kubernetes-model-certificates Low Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-certificates Medium Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Product pom name Fabric8 :: Kubernetes Model :: Certificates High Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-certificates/ Low Product Manifest build-timestamp ${build.datetime} Low Product file name kubernetes-model-certificates High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Fabric8 :: Kubernetes Model :: Certificates Medium Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product pom artifactid kubernetes-model-certificates Highest Product jar package name io Highest Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Certificates High Product Manifest os-arch amd64 Low Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Certificates Medium Product pom parent-artifactid kubernetes-model-generator Medium Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-certificates Medium Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
kubernetes-model-common-4.10.3.jarDescription:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-common/4.10.3/kubernetes-model-common-4.10.3.jar
MD5: b63abe4efb0ea5da9d232e142636575d
SHA1: 57e09b193b72c046bad0eb9670f0d36cae872882
SHA256: cde8031d89c67c452c354112a8d4ba7a97da684bb65d6dc0f25e3d50b175ac01
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom name Fabric8 :: Kubernetes Model :: Common High Vendor Manifest build-timestamp ${build.datetime} Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor jar package name model Highest Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor file name kubernetes-model-common High Vendor pom artifactid kubernetes-model-common Low Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-common Medium Vendor Manifest java-vendor Oracle Corporation Medium Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-common/ Low Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Product pom name Fabric8 :: Kubernetes Model :: Common High Product Manifest build-timestamp ${build.datetime} Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product jar package name model Highest Product file name kubernetes-model-common High Product pom artifactid kubernetes-model-common Highest Product Manifest bundle-docurl http://redhat.com Low Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Common High Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product jar package name io Highest Product Manifest os-arch amd64 Low Product Manifest specification-title Fabric8 :: Kubernetes Model :: Common Medium Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-common Medium Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-common/ Low Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Common Medium Product pom parent-artifactid kubernetes-model-generator Medium Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
kubernetes-model-coordination-4.10.3.jarDescription:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-coordination/4.10.3/kubernetes-model-coordination-4.10.3.jar
MD5: b65f294c3186fc805ae36e7b2b71e84a
SHA1: 6ac4d6b2e06102f5bc06baa9439bfe969915e1d1
SHA256: 3dc62a48e1bfe395eb46067639fdf8fa1fd2251742a92660248cc8f1c05dbced
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-coordination Medium Vendor Manifest build-timestamp ${build.datetime} Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor file name kubernetes-model-coordination High Vendor pom artifactid kubernetes-model-coordination Low Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-coordination/ Low Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor pom name Fabric8 :: Kubernetes Model :: Coordination High Vendor Manifest specification-vendor Red Hat Low Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-coordination Medium Product Manifest build-timestamp ${build.datetime} Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Coordination High Product file name kubernetes-model-coordination High Product pom artifactid kubernetes-model-coordination Highest Product Manifest bundle-docurl http://redhat.com Low Product Manifest specification-title Fabric8 :: Kubernetes Model :: Coordination Medium Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Coordination Medium Product jar package name io Highest Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-coordination/ Low Product Manifest os-arch amd64 Low Product pom parent-artifactid kubernetes-model-generator Medium Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Product pom name Fabric8 :: Kubernetes Model :: Coordination High Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
kubernetes-model-core-4.10.3.jarDescription:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-core/4.10.3/kubernetes-model-core-4.10.3.jar
MD5: c6a7512ce00eae6ef60c37e29fd4f375
SHA1: 09f62304f580db3639cf389e0acfd34cbd185181
SHA256: f63ae5abbc1cfb02defd81292277e4e1553eb1af699e3d0b46d1f3144b45f1b6
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-core Medium Vendor Manifest build-timestamp ${build.datetime} Low Vendor pom artifactid kubernetes-model-core Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor file name kubernetes-model-core High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor pom name Fabric8 :: Kubernetes Model :: Core High Vendor jar package name fabric8 Highest Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-core/ Low Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Core High Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-core Medium Product pom artifactid kubernetes-model-core Highest Product Manifest build-timestamp ${build.datetime} Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Core Medium Product file name kubernetes-model-core High Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product jar package name io Highest Product Manifest os-arch amd64 Low Product pom name Fabric8 :: Kubernetes Model :: Core High Product pom parent-artifactid kubernetes-model-generator Medium Product jar package name fabric8 Highest Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-core/ Low Product Manifest os-name Linux Medium Product Manifest specification-title Fabric8 :: Kubernetes Model :: Core Medium Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
kubernetes-model-discovery-4.10.3.jarDescription:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-discovery/4.10.3/kubernetes-model-discovery-4.10.3.jar
MD5: e7654b5b9e64654ccf2b9b6c3c75f8f5
SHA1: 442295684873890f67be8a04687ea3c9db4b5e07
SHA256: 06a50b3336e4e645284a60a6c2da5d4f645714d5caf2e1d4bdfb78084167d427
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-discovery Medium Vendor Manifest build-timestamp ${build.datetime} Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor pom name Fabric8 :: Kubernetes Model :: Discovery High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor pom artifactid kubernetes-model-discovery Low Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-discovery/ Low Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor file name kubernetes-model-discovery High Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-discovery Medium Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Discovery High Product Manifest specification-title Fabric8 :: Kubernetes Model :: Discovery Medium Product Manifest build-timestamp ${build.datetime} Low Product pom artifactid kubernetes-model-discovery Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom name Fabric8 :: Kubernetes Model :: Discovery High Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Discovery Medium Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-discovery/ Low Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product file name kubernetes-model-discovery High Product jar package name io Highest Product Manifest os-arch amd64 Low Product pom parent-artifactid kubernetes-model-generator Medium Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
kubernetes-model-events-4.10.3.jarDescription:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-events/4.10.3/kubernetes-model-events-4.10.3.jar
MD5: a15a6f685f935e953105577fa748b077
SHA1: 80b8ab35905af4b6275aca895191ad14af98109d
SHA256: ad0e9e7df773f4574f2e66bf9e089917fbf51a3052568cd7f3c3ce5ecb7579b9
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest build-timestamp ${build.datetime} Low Vendor pom artifactid kubernetes-model-events Low Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-events Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor pom name Fabric8 :: Kubernetes Model :: Events High Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-events/ Low Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor file name kubernetes-model-events High Vendor Manifest specification-vendor Red Hat Low Product Manifest build-timestamp ${build.datetime} Low Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Events High Product Manifest specification-title Fabric8 :: Kubernetes Model :: Events Medium Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-events Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Events Medium Product pom artifactid kubernetes-model-events Highest Product pom name Fabric8 :: Kubernetes Model :: Events High Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-events/ Low Product pom groupid io.fabric8 Highest Product jar package name io Highest Product Manifest os-arch amd64 Low Product pom parent-artifactid kubernetes-model-generator Medium Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Product file name kubernetes-model-events High Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
kubernetes-model-extensions-4.10.3.jarDescription:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-extensions/4.10.3/kubernetes-model-extensions-4.10.3.jar
MD5: 04630c15b3d2b62fda015f18043ac5f9
SHA1: 31c055f04039f64e6915815e5821f3fb339fbedc
SHA256: 18921f8104abbbfc2ad9c48dd444e4f5de24ffed4b7e9167c86fb115e31f4f3f
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest build-timestamp ${build.datetime} Low Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-extensions Medium Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-extensions/ Low Vendor pom artifactid kubernetes-model-extensions Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom name Fabric8 :: Kubernetes Model :: Extensions High Vendor Manifest Implementation-Vendor Red Hat High Vendor file name kubernetes-model-extensions High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Product Manifest build-timestamp ${build.datetime} Low Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-extensions Medium Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-extensions/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom name Fabric8 :: Kubernetes Model :: Extensions High Product file name kubernetes-model-extensions High Product Manifest bundle-docurl http://redhat.com Low Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Extensions Medium Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product jar package name io Highest Product Manifest specification-title Fabric8 :: Kubernetes Model :: Extensions Medium Product Manifest os-arch amd64 Low Product pom parent-artifactid kubernetes-model-generator Medium Product pom artifactid kubernetes-model-extensions Highest Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Extensions High Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
kubernetes-model-metrics-4.10.3.jarDescription:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-metrics/4.10.3/kubernetes-model-metrics-4.10.3.jar
MD5: e5bf7835b5bc783df7b066c0e34f8f1b
SHA1: 288c7ef09755201ab46e0c35ef8d0342178863fd
SHA256: 24557760da4ae2572ec7e00301b4a67a7d77efaa68136017674a577fc904a7a6
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest build-timestamp ${build.datetime} Low Vendor pom artifactid kubernetes-model-metrics Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-metrics Medium Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor file name kubernetes-model-metrics High Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-metrics/ Low Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Vendor pom name Fabric8 :: Kubernetes Model :: Metrics High Product Manifest build-timestamp ${build.datetime} Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-metrics Medium Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Metrics High Product pom artifactid kubernetes-model-metrics Highest Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Metrics Medium Product pom groupid io.fabric8 Highest Product jar package name io Highest Product Manifest os-arch amd64 Low Product Manifest specification-title Fabric8 :: Kubernetes Model :: Metrics Medium Product pom parent-artifactid kubernetes-model-generator Medium Product file name kubernetes-model-metrics High Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-metrics/ Low Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Product pom name Fabric8 :: Kubernetes Model :: Metrics High Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
kubernetes-model-networking-4.10.3.jarDescription:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-networking/4.10.3/kubernetes-model-networking-4.10.3.jar
MD5: 2896a6994209aa2e0031e0ca14ad7de3
SHA1: ec16136e628435a4d72adcc2883be27224750750
SHA256: b87286743689abcbd9e96e99e46ae9bdec2a4a25ffcac21248613db1d6a8ec60
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom name Fabric8 :: Kubernetes Model :: Networking High Vendor Manifest build-timestamp ${build.datetime} Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-networking Medium Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor file name kubernetes-model-networking High Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-networking/ Low Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor pom artifactid kubernetes-model-networking Low Vendor Manifest specification-vendor Red Hat Low Product pom name Fabric8 :: Kubernetes Model :: Networking High Product Manifest build-timestamp ${build.datetime} Low Product pom artifactid kubernetes-model-networking Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Networking Medium Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-networking Medium Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product file name kubernetes-model-networking High Product jar package name io Highest Product Manifest os-arch amd64 Low Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Networking High Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-networking/ Low Product pom parent-artifactid kubernetes-model-generator Medium Product Manifest specification-title Fabric8 :: Kubernetes Model :: Networking Medium Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
kubernetes-model-policy-4.10.3.jarDescription:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-policy/4.10.3/kubernetes-model-policy-4.10.3.jar
MD5: ed96100acb469bf5f58679800453d809
SHA1: 96c6927bb400212fb55ce3869ad014b629018f62
SHA256: aa1c6337d50fe8934f6de3df159f2a34e0065162e9ccfd6f7154dcf225d52dd4
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor file name kubernetes-model-policy High Vendor Manifest build-timestamp ${build.datetime} Low Vendor pom name Fabric8 :: Kubernetes Model :: Policy High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor pom artifactid kubernetes-model-policy Low Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-policy Medium Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-policy/ Low Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Policy Medium Product file name kubernetes-model-policy High Product Manifest build-timestamp ${build.datetime} Low Product pom name Fabric8 :: Kubernetes Model :: Policy High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Policy High Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product jar package name io Highest Product pom artifactid kubernetes-model-policy Highest Product Manifest os-arch amd64 Low Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-policy Medium Product Manifest specification-title Fabric8 :: Kubernetes Model :: Policy Medium Product pom parent-artifactid kubernetes-model-generator Medium Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-policy/ Low Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
kubernetes-model-rbac-4.10.3.jarDescription:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-rbac/4.10.3/kubernetes-model-rbac-4.10.3.jar
MD5: df4e63427eaceaf83f51cf7efe2ecea7
SHA1: a0d8a77633a34e5b7d342d044242581116fbac31
SHA256: 559e64c1b8971ebe07d4d48d71d1546e3e298a8dda73859738957bcf97698a8c
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid kubernetes-model-rbac Low Vendor Manifest build-timestamp ${build.datetime} Low Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-rbac/ Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor file name kubernetes-model-rbac High Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-rbac Medium Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Vendor pom name Fabric8 :: Kubernetes Model :: RBAC High Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: RBAC High Product pom artifactid kubernetes-model-rbac Highest Product Manifest build-timestamp ${build.datetime} Low Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-rbac/ Low Product Manifest specification-title Fabric8 :: Kubernetes Model :: RBAC Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product file name kubernetes-model-rbac High Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product jar package name io Highest Product Manifest os-arch amd64 Low Product pom parent-artifactid kubernetes-model-generator Medium Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: RBAC Medium Product jar package name fabric8 Highest Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-rbac Medium Product Manifest os-name Linux Medium Product pom name Fabric8 :: Kubernetes Model :: RBAC High Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
kubernetes-model-scheduling-4.10.3.jarDescription:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-scheduling/4.10.3/kubernetes-model-scheduling-4.10.3.jar
MD5: be4662b1c1747a4dfe248b7d58b6f1bb
SHA1: 08a23b73bc2a92690aff91959709c90065a868c2
SHA256: 151e649ba57ddb0429965224e73489d500f49c391070c68bda2a2b11c55b2d71
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-scheduling/ Low Vendor Manifest build-timestamp ${build.datetime} Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-scheduling Medium Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom artifactid kubernetes-model-scheduling Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor pom name Fabric8 :: Kubernetes Model :: Scheduling High Vendor file name kubernetes-model-scheduling High Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Scheduling Medium Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-scheduling/ Low Product Manifest build-timestamp ${build.datetime} Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Scheduling High Product pom artifactid kubernetes-model-scheduling Highest Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-scheduling Medium Product jar package name io Highest Product Manifest os-arch amd64 Low Product pom parent-artifactid kubernetes-model-generator Medium Product Manifest specification-title Fabric8 :: Kubernetes Model :: Scheduling Medium Product pom name Fabric8 :: Kubernetes Model :: Scheduling High Product file name kubernetes-model-scheduling High Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
kubernetes-model-settings-4.10.3.jarDescription:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-settings/4.10.3/kubernetes-model-settings-4.10.3.jar
MD5: 21c76a9bad8257af78b6fd8ddf9e54dd
SHA1: 3729088030327b772abbc987382385979737fbdd
SHA256: 94c44ffe08999a0f875aae3e545eff15a045fbf6c2b33ed24fa39e8981cea955
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid kubernetes-model-settings Low Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-settings Medium Vendor Manifest build-timestamp ${build.datetime} Low Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-settings/ Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor file name kubernetes-model-settings High Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor pom name Fabric8 :: Kubernetes Model :: Settings High Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-settings Medium Product Manifest build-timestamp ${build.datetime} Low Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Settings High Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-settings/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Fabric8 :: Kubernetes Model :: Settings Medium Product file name kubernetes-model-settings High Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product pom name Fabric8 :: Kubernetes Model :: Settings High Product jar package name io Highest Product Manifest os-arch amd64 Low Product pom parent-artifactid kubernetes-model-generator Medium Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Settings Medium Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Product pom artifactid kubernetes-model-settings Highest Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
kubernetes-model-storageclass-4.10.3.jarDescription:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-storageclass/4.10.3/kubernetes-model-storageclass-4.10.3.jar
MD5: b435f102f179b904ecf16f4a0f2ef3b2
SHA1: 846f5abc9af8c1674870984d9c933ee057589087
SHA256: f9fe066696e141b4ddfde6a7e7bd33e499f164950c1bb1b9c09a12ddfba34f53
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest build-timestamp ${build.datetime} Low Vendor pom artifactid kubernetes-model-storageclass Low Vendor pom name Fabric8 :: Kubernetes Model :: Storage Class High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-storageclass/ Low Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-storageclass Medium Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Vendor file name kubernetes-model-storageclass High Product Manifest build-timestamp ${build.datetime} Low Product pom name Fabric8 :: Kubernetes Model :: Storage Class High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-storageclass/ Low Product pom artifactid kubernetes-model-storageclass Highest Product Manifest bundle-docurl http://redhat.com Low Product Manifest specification-title Fabric8 :: Kubernetes Model :: Storage Class Medium Product jar package name kubernetes Highest Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Storage Class High Product pom groupid io.fabric8 Highest Product jar package name io Highest Product Manifest os-arch amd64 Low Product pom parent-artifactid kubernetes-model-generator Medium Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-storageclass Medium Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Storage Class Medium Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Product file name kubernetes-model-storageclass High Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
log4j-api-2.13.2.jarDescription:
The Apache Log4j API License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/org/apache/logging/log4j/log4j-api/2.13.2/log4j-api-2.13.2.jar
MD5: 06bddceaba5261c0b3370e497248c5b3
SHA1: 567ea514dedd8679c429c5b5b39b0d67b6464c3c
SHA256: 4dd502df82236031b8d32a243e6b210a6b9517333d9fe8116130e7743b6c038f
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid log4j Low Vendor file name log4j-api High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom groupid org.apache.logging.log4j Highest Vendor jar package name logging Highest Vendor Manifest log4jreleasemanager Ralph Goers Low Vendor Manifest implementation-url https://logging.apache.org/log4j/2.x/log4j-api/ Low Vendor pom parent-groupid org.apache.logging.log4j Medium Vendor Manifest bundle-docurl https://www.apache.org/ Low Vendor jar package name log4j Highest Vendor Manifest bundle-symbolicname org.apache.logging.log4j.api Medium Vendor Manifest log4jreleasekey B3D8E1BA Low Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor pom artifactid log4j-api Low Vendor jar package name org Highest Vendor Manifest Implementation-Vendor-Id org.apache.logging.log4j Medium Vendor Manifest multi-release true Low Vendor pom groupid apache.logging.log4j Highest Vendor jar package name apache Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Vendor pom name Apache Log4j API High Product file name log4j-api High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product jar package name logging Highest Product Manifest log4jreleasemanager Ralph Goers Low Product Manifest Implementation-Title Apache Log4j API High Product Manifest specification-title Apache Log4j API Medium Product Manifest implementation-url https://logging.apache.org/log4j/2.x/log4j-api/ Low Product pom parent-groupid org.apache.logging.log4j Medium Product Manifest bundle-docurl https://www.apache.org/ Low Product jar package name log4j Highest Product pom artifactid log4j-api Highest Product Manifest bundle-symbolicname org.apache.logging.log4j.api Medium Product Manifest log4jreleasekey B3D8E1BA Low Product pom parent-artifactid log4j Medium Product jar package name org Highest Product Manifest multi-release true Low Product pom groupid apache.logging.log4j Highest Product jar package name apache Highest Product pom name Apache Log4j API High Product Manifest Bundle-Name Apache Log4j API Medium Version Manifest Bundle-Version 2.13.2 High Version Manifest log4jreleaseversion 2.13.2 Medium Version pom version 2.13.2 Highest Version file version 2.13.2 High Version Manifest Implementation-Version 2.13.2 High
log4j-to-slf4j-2.13.2.jarDescription:
The Apache Log4j binding between Log4j 2 API and SLF4J. License:
https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/org/apache/logging/log4j/log4j-to-slf4j/2.13.2/log4j-to-slf4j-2.13.2.jar
MD5: fc11c5236c20899bd4cf25a17ca1262c
SHA1: 7e2845170ed4fdeb87f1fdc9131b743c61645da3
SHA256: 74dc47c6b5066cdb8b2404cde9f5459847ed83ed7c0d297c5598220be96979e7
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid log4j Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest implementation-url https://logging.apache.org/log4j/2.x/log4j-to-slf4j/ Low Vendor pom groupid org.apache.logging.log4j Highest Vendor jar package name logging Highest Vendor Manifest log4jreleasemanager Ralph Goers Low Vendor jar package name slf4j Highest Vendor pom name Apache Log4j to SLF4J Adapter High Vendor pom artifactid log4j-to-slf4j Low Vendor pom parent-groupid org.apache.logging.log4j Medium Vendor Manifest bundle-docurl https://www.apache.org/ Low Vendor Manifest automatic-module-name org.apache.logging.slf4j Medium Vendor Manifest bundle-symbolicname org.apache.logging.log4j.to-slf4j Medium Vendor Manifest log4jreleasekey B3D8E1BA Low Vendor file name log4j-to-slf4j High Vendor Manifest specification-vendor The Apache Software Foundation Low Vendor Manifest Implementation-Vendor-Id org.apache.logging.log4j Medium Vendor pom groupid apache.logging.log4j Highest Vendor jar package name apache Highest Vendor Manifest Implementation-Vendor The Apache Software Foundation High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest implementation-url https://logging.apache.org/log4j/2.x/log4j-to-slf4j/ Low Product jar package name logging Highest Product Manifest log4jreleasemanager Ralph Goers Low Product jar package name slf4j Highest Product pom name Apache Log4j to SLF4J Adapter High Product pom parent-groupid org.apache.logging.log4j Medium Product Manifest bundle-docurl https://www.apache.org/ Low Product Manifest automatic-module-name org.apache.logging.slf4j Medium Product Manifest bundle-symbolicname org.apache.logging.log4j.to-slf4j Medium Product Manifest specification-title Apache Log4j to SLF4J Adapter Medium Product pom artifactid log4j-to-slf4j Highest Product Manifest log4jreleasekey B3D8E1BA Low Product Manifest Bundle-Name Apache Log4j to SLF4J Adapter Medium Product file name log4j-to-slf4j High Product pom parent-artifactid log4j Medium Product pom groupid apache.logging.log4j Highest Product jar package name apache Highest Product Manifest Implementation-Title Apache Log4j to SLF4J Adapter High Version Manifest Bundle-Version 2.13.2 High Version Manifest log4jreleaseversion 2.13.2 Medium Version pom version 2.13.2 Highest Version file version 2.13.2 High Version Manifest Implementation-Version 2.13.2 High
logback-classic-1.2.6.jarDescription:
logback-classic module License:
http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html File Path: /home/jenkins/.mvnrepository/ch/qos/logback/logback-classic/1.2.6/logback-classic-1.2.6.jar
MD5: 196b120a3c9f01a5b9b2ed5220359963
SHA1: b09efa852337fa0dd9859614389eec58dc287116
SHA256: 5c4b268dee383be9e2ca639ef57f5547ab8f26120ee945e9fa2029aec1194758
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name ch Highest Vendor Manifest bundle-symbolicname ch.qos.logback.classic Medium Vendor Manifest bundle-docurl http://www.qos.ch Low Vendor file name logback-classic High Vendor jar package name qos Highest Vendor pom name Logback Classic Module High Vendor jar package name logback Highest Vendor jar package name classic Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest originally-created-by Apache Maven Bundle Plugin Low Vendor pom parent-artifactid logback-parent Low Vendor pom groupid ch.qos.logback Highest Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low Vendor pom artifactid logback-classic Low Product pom artifactid logback-classic Highest Product jar package name ch Highest Product Manifest bundle-symbolicname ch.qos.logback.classic Medium Product Manifest bundle-docurl http://www.qos.ch Low Product file name logback-classic High Product jar package name qos Highest Product pom name Logback Classic Module High Product jar package name logback Highest Product pom parent-artifactid logback-parent Medium Product Manifest Bundle-Name Logback Classic Module Medium Product jar package name classic Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest originally-created-by Apache Maven Bundle Plugin Low Product Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low Product pom groupid ch.qos.logback Highest Version Manifest Bundle-Version 1.2.6 High Version pom version 1.2.6 Highest Version file version 1.2.6 High
logback-core-1.2.6.jarDescription:
logback-core module License:
http://www.eclipse.org/legal/epl-v10.html, http://www.gnu.org/licenses/old-licenses/lgpl-2.1.html File Path: /home/jenkins/.mvnrepository/ch/qos/logback/logback-core/1.2.6/logback-core-1.2.6.jar
MD5: b1930b5651377477a06ade2319f70dfc
SHA1: 25be1abb32e870ff042e698a799b56587e0dca9a
SHA256: bd230183f6bd7d023076d8e91571b04651504fab905d52885c4b6e867962377e
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom name Logback Core Module High Vendor jar package name ch Highest Vendor Manifest bundle-docurl http://www.qos.ch Low Vendor file name logback-core High Vendor jar package name qos Highest Vendor jar package name logback Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Vendor Manifest originally-created-by Apache Maven Bundle Plugin Low Vendor jar package name core Highest Vendor Manifest bundle-symbolicname ch.qos.logback.core Medium Vendor pom parent-artifactid logback-parent Low Vendor pom artifactid logback-core Low Vendor pom groupid ch.qos.logback Highest Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low Product pom name Logback Core Module High Product jar package name ch Highest Product Manifest bundle-docurl http://www.qos.ch Low Product Manifest Bundle-Name Logback Core Module Medium Product file name logback-core High Product jar package name qos Highest Product jar package name logback Highest Product pom parent-artifactid logback-parent Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.6))" Low Product Manifest originally-created-by Apache Maven Bundle Plugin Low Product jar package name core Highest Product pom artifactid logback-core Highest Product Manifest bundle-symbolicname ch.qos.logback.core Medium Product Manifest bundle-requiredexecutionenvironment JavaSE-1.6 Low Product pom groupid ch.qos.logback Highest Version Manifest Bundle-Version 1.2.6 High Version pom version 1.2.6 Highest Version file version 1.2.6 High
logging-interceptor-3.14.9.jarFile Path: /home/jenkins/.mvnrepository/com/squareup/okhttp3/logging-interceptor/3.14.9/logging-interceptor-3.14.9.jarMD5: a4a7a01e41cdfd68ce6d9090c38102d2SHA1: 7358b6fa1d6c1c8b8c01cb05acd74dbe6d680fb1SHA256: 68346e3613fcdb572427e2ed6b826582b174db3e20f84f485bc56f3923e2d4c5Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest automatic-module-name okhttp3.logging Medium Vendor pom groupid squareup.okhttp3 Highest Vendor pom parent-groupid com.squareup.okhttp3 Medium Vendor pom artifactid logging-interceptor Low Vendor jar package name okhttp3 Highest Vendor jar package name logging Highest Vendor pom name OkHttp Logging Interceptor High Vendor pom groupid com.squareup.okhttp3 Highest Vendor file name logging-interceptor High Vendor pom parent-artifactid parent Low Product Manifest automatic-module-name okhttp3.logging Medium Product pom groupid squareup.okhttp3 Highest Product pom parent-groupid com.squareup.okhttp3 Medium Product jar package name okhttp3 Highest Product jar package name logging Highest Product pom parent-artifactid parent Medium Product pom name OkHttp Logging Interceptor High Product pom artifactid logging-interceptor Highest Product file name logging-interceptor High Version pom version 3.14.9 Highest Version file version 3.14.9 High
lombok-1.18.22.jarDescription:
Spice up your java: Automatic Resource Management, automatic generation of getters, setters, equals, hashCode and toString, and more! License:
The MIT License: https://projectlombok.org/LICENSE File Path: /home/jenkins/.mvnrepository/org/projectlombok/lombok/1.18.22/lombok-1.18.22.jar
MD5: 30905901647fe0ebb06fb20ee8a638bf
SHA1: 9c08ea24c6eb714e2d6170e8122c069a0ba9aacf
SHA256: ecef1581411d7a82cc04281667ee0bac5d7c0a5aae74cfc38430396c91c31831
Referenced In Project/Scope: Entando Kubernetes Service:provided
Evidence Type Source Name Value Confidence Vendor jar package name java Highest Vendor file name lombok High Vendor Manifest can-redefine-classes true Low Vendor Manifest automatic-module-name lombok Medium Vendor pom groupid org.projectlombok Highest Vendor jar package name lombok Highest Vendor pom name Project Lombok High Vendor pom groupid projectlombok Highest Vendor jar package name tostring Highest Vendor pom url https://projectlombok.org Highest Vendor pom artifactid lombok Low Product jar package name java Highest Product file name lombok High Product Manifest can-redefine-classes true Low Product Manifest automatic-module-name lombok Medium Product pom url https://projectlombok.org Medium Product jar package name lombok Highest Product pom artifactid lombok Highest Product pom name Project Lombok High Product pom groupid projectlombok Highest Product jar package name tostring Highest Version file version 1.18.22 High Version Manifest lombok-version 1.18.22 Medium Version pom version 1.18.22 Highest
micrometer-core-1.7.5.jarDescription:
Application monitoring instrumentation facade License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/micrometer/micrometer-core/1.7.5/micrometer-core-1.7.5.jar
MD5: e068d437ac0bfbadc7c856710539a703
SHA1: 660ac702b89180b0b902ba9e4366e1b5784823d3
SHA256: d01220a71202893dddc87bfb0d6b0597f2a14db75a875a6bc231b9d4ac0234e6
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name micrometer Highest Vendor Manifest build-job deploy Low Vendor pom url micrometer-metrics/micrometer Highest Vendor Manifest built-os Linux Low Vendor Manifest branch 85d992ddc377bac753fd0e9b2c3cce616e95116d Low Vendor Manifest build-date 2021-10-14_23:04:59 Low Vendor Manifest module-owner tludwig@vmware.com Low Vendor Manifest full-change 85d992ddc377bac753fd0e9b2c3cce616e95116d Low Vendor pom name micrometer-core High Vendor Manifest change 85d992d Low Vendor pom groupid io.micrometer Highest Vendor file name micrometer-core High Vendor Manifest module-email tludwig@vmware.com Low Vendor Manifest automatic-module-name micrometer.core Medium Vendor Manifest built-status integration Low Vendor Manifest module-source /micrometer-core Low Vendor Manifest module-origin micrometer-metrics/micrometer.git Low Vendor Manifest build-host a33db759a05d Low Vendor jar package name io Highest Vendor pom artifactid micrometer-core Low Vendor jar package name core Highest Vendor Manifest build-number 10942 Low Product jar package name micrometer Highest Product Manifest build-job deploy Low Product Manifest built-os Linux Low Product Manifest branch 85d992ddc377bac753fd0e9b2c3cce616e95116d Low Product Manifest build-date 2021-10-14_23:04:59 Low Product Manifest module-owner tludwig@vmware.com Low Product Manifest full-change 85d992ddc377bac753fd0e9b2c3cce616e95116d Low Product pom name micrometer-core High Product Manifest change 85d992d Low Product file name micrometer-core High Product pom groupid io.micrometer Highest Product Manifest module-email tludwig@vmware.com Low Product Manifest automatic-module-name micrometer.core Medium Product Manifest built-status integration Low Product Manifest module-source /micrometer-core Low Product pom url micrometer-metrics/micrometer High Product Manifest module-origin micrometer-metrics/micrometer.git Low Product jar package name io Highest Product Manifest build-host a33db759a05d Low Product jar package name core Highest Product Manifest build-number 10942 Low Product Manifest Implementation-Title io.micrometer#micrometer-core;1.7.5 High Product pom artifactid micrometer-core Highest Version pom version 1.7.5 Highest Version file version 1.7.5 High Version Manifest Implementation-Version 1.7.5 High
nimbus-jose-jwt-9.10.1.jarDescription:
Java library for Javascript Object Signing and Encryption (JOSE) and
JSON Web Tokens (JWT)
License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/com/nimbusds/nimbus-jose-jwt/9.10.1/nimbus-jose-jwt-9.10.1.jar
MD5: c9674e47e1f2dc327c2588dcef049ff9
SHA1: 40d15f46a2f453686baae7f16c29ca2e21c9448e
SHA256: 8fbab1a5392df7f865d2b6837405d12c346284a7196533540fe3e9d8aba4a002
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name jose Highest Vendor Manifest build-date ${timestamp} Low Vendor jar package name jwt Highest Vendor Manifest build-number ${buildNumber} Low Vendor file name nimbus-jose-jwt High Vendor pom groupid nimbusds Highest Vendor Manifest bundle-symbolicname com.nimbusds.nimbus-jose-jwt Medium Vendor pom artifactid nimbus-jose-jwt Low Vendor pom organization name Connect2id Ltd. High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor Manifest specification-vendor Connect2id Ltd. Low Vendor Manifest implementation-url https://bitbucket.org/connect2id/nimbus-jose-jwt Low Vendor Manifest automatic-module-name com.nimbusds.jose.jwt Medium Vendor Manifest Implementation-Vendor Connect2id Ltd. High Vendor jar package name json Highest Vendor pom url https://bitbucket.org/connect2id/nimbus-jose-jwt Highest Vendor pom name Nimbus JOSE+JWT High Vendor Manifest build-tag 9.10.1 Low Vendor Manifest Implementation-Vendor-Id com.nimbusds Medium Vendor pom organization url https://connect2id.com Medium Vendor pom groupid com.nimbusds Highest Vendor jar package name nimbusds Highest Vendor Manifest bundle-docurl https://connect2id.com Low Product jar package name jose Highest Product Manifest build-date ${timestamp} Low Product jar package name jwt Highest Product Manifest build-number ${buildNumber} Low Product file name nimbus-jose-jwt High Product pom groupid nimbusds Highest Product pom organization url https://connect2id.com Low Product Manifest bundle-symbolicname com.nimbusds.nimbus-jose-jwt Medium Product pom url https://bitbucket.org/connect2id/nimbus-jose-jwt Medium Product Manifest specification-title Nimbus JOSE+JWT Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product pom organization name Connect2id Ltd. Low Product Manifest implementation-url https://bitbucket.org/connect2id/nimbus-jose-jwt Low Product Manifest Bundle-Name Nimbus JOSE+JWT Medium Product Manifest automatic-module-name com.nimbusds.jose.jwt Medium Product pom artifactid nimbus-jose-jwt Highest Product jar package name json Highest Product pom name Nimbus JOSE+JWT High Product Manifest build-tag 9.10.1 Low Product Manifest Implementation-Title Nimbus JOSE+JWT High Product jar package name nimbusds Highest Product Manifest bundle-docurl https://connect2id.com Low Version file version 9.10.1 High Version Manifest build-tag 9.10.1 Low Version Manifest Bundle-Version 9.10.1 High Version Manifest Implementation-Version 9.10.1 High Version pom version 9.10.1 Highest
ojdbc8-19.3.0.0.jarDescription:
Oracle JDBC Driver compatible with JDK8, JDK9, and JDK11 License:
Oracle Free Use Terms and Conditions (FUTC) File Path: /home/jenkins/.mvnrepository/com/oracle/ojdbc/ojdbc8/19.3.0.0/ojdbc8-19.3.0.0.jar
MD5: 0b2a8e010df63e6feb396287d2ea7dbd
SHA1: 967c0b1a2d5b1435324de34a9b8018d294f8f47b
SHA256: a66d27a14f3adee484427cc4de008af85a5c3e78e2e3285a4dba1277332978a5
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom name ojdbc8 High Vendor jar package name driver Highest Vendor jar (hint) package name sun Highest Vendor Manifest repository-id JAVAVM_19.0.0.0.0_LINUX.X64_190404 Low Vendor pom groupid oracle.ojdbc Highest Vendor jar package name jdbc Highest Vendor pom url https://www.oracle.com/database/technologies/appdev/jdbc.html Highest Vendor file name ojdbc8 High Vendor pom groupid com.oracle.ojdbc Highest Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor jar package name oracle Highest Vendor pom artifactid ojdbc8 Low Vendor Manifest specification-vendor Sun Microsystems Inc. Low Product file name ojdbc8 High Product pom name ojdbc8 High Product pom url https://www.oracle.com/database/technologies/appdev/jdbc.html Medium Product jar package name driver Highest Product Manifest Implementation-Title JDBC High Product Manifest repository-id JAVAVM_19.0.0.0.0_LINUX.X64_190404 Low Product pom artifactid ojdbc8 Highest Product pom groupid oracle.ojdbc Highest Product jar package name oracle Highest Product Manifest specification-title JDBC Medium Product jar package name jdbc Highest Version pom version 19.3.0.0 Highest Version file version 19.3.0.0 High
okhttp-3.14.9.jarFile Path: /home/jenkins/.mvnrepository/com/squareup/okhttp3/okhttp/3.14.9/okhttp-3.14.9.jarMD5: 69e22f2ccb614cf1bcfcca5cf7711045SHA1: 3e6d101343c7ea687cd593e4990f73b25c878383SHA256: 2570fab55515cbf881d7a4ceef49fc515490bc027057e666776a2832465aeca0Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid squareup.okhttp3 Highest Vendor pom artifactid okhttp Low Vendor Manifest automatic-module-name okhttp3 Medium Vendor pom parent-groupid com.squareup.okhttp3 Medium Vendor jar package name okhttp3 Highest Vendor pom name OkHttp High Vendor file name okhttp High Vendor pom groupid com.squareup.okhttp3 Highest Vendor pom parent-artifactid parent Low Product pom groupid squareup.okhttp3 Highest Product pom artifactid okhttp Highest Product Manifest automatic-module-name okhttp3 Medium Product pom parent-groupid com.squareup.okhttp3 Medium Product jar package name okhttp3 Highest Product pom parent-artifactid parent Medium Product pom name OkHttp High Product file name okhttp High Version pom version 3.14.9 Highest Version file version 3.14.9 High
okio-1.17.2.jarFile Path: /home/jenkins/.mvnrepository/com/squareup/okio/okio/1.17.2/okio-1.17.2.jarMD5: 54a6a8979bd8e64e1fbf21d511654737SHA1: 78c7820b205002da4d2d137f6f312bd64b3d6049SHA256: f80ce42d2ffac47ad4c47e1d6f980d604d247ceb1a886705cf4581ab0c9fe2b8Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor file name okio High Vendor pom parent-artifactid okio-parent Low Vendor pom groupid com.squareup.okio Highest Vendor Manifest automatic-module-name okio Medium Vendor pom parent-groupid com.squareup.okio Medium Vendor jar package name okio Highest Vendor pom groupid squareup.okio Highest Vendor pom artifactid okio Low Vendor pom name Okio High Product pom parent-artifactid okio-parent Medium Product file name okio High Product Manifest automatic-module-name okio Medium Product pom parent-groupid com.squareup.okio Medium Product jar package name okio Highest Product pom groupid squareup.okio Highest Product pom artifactid okio Highest Product pom name Okio High Version pom version 1.17.2 Highest Version file version 1.17.2 High
ons-19.3.0.0.jarDescription:
Java Client-Side Oracle Notification Services(ONS) License:
Oracle Free Use Terms and Conditions (FUTC) File Path: /home/jenkins/.mvnrepository/com/oracle/ojdbc/ons/19.3.0.0/ons-19.3.0.0.jar
MD5: ac4a31065dcbf2286a46cb68e9f4d1fd
SHA1: cf3f3ef525c61a27fe9952652a156ddd738b1cd5
SHA256: 6e3f243700716c4fa2e9ddfaa08c9394ad6fda3a640d3bef03941f7b573df9d7
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom name ons High Vendor jar package name notification Highest Vendor file name ons High Vendor jar (hint) package name sun Highest Vendor pom groupid com.oracle.ojdbc Highest Vendor Manifest label ONS_19.0.0.0.0_LINUX.X64_181205.1445 Low Vendor pom groupid oracle.ojdbc Highest Vendor jar package name oracle Highest Vendor pom artifactid ons Low Vendor jar package name ons Highest Vendor pom url https://www.oracle.com/database/technologies/appdev/jdbc.html Highest Product pom name ons High Product jar package name notification Highest Product pom url https://www.oracle.com/database/technologies/appdev/jdbc.html Medium Product file name ons High Product Manifest label ONS_19.0.0.0.0_LINUX.X64_181205.1445 Low Product pom groupid oracle.ojdbc Highest Product jar package name oracle Highest Product pom artifactid ons Highest Product jar package name ons Highest Version pom version 19.3.0.0 Highest Version file version 19.3.0.0 High
openshift-model-4.10.3.jarDescription:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/openshift-model/4.10.3/openshift-model-4.10.3.jar
MD5: 67954130a04755a48d6f49a8f87c917d
SHA1: 182b41135b66fe48b08ee93f1fe801d097f18600
SHA256: 1444819cf232cdb806d2f5c5af68b9085235c23e7092d2b2656499cda939c612
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest build-timestamp ${build.datetime} Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid openshift-model Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest bundle-symbolicname io.fabric8.openshift-model Medium Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor pom name Fabric8 :: OpenShift Model High Vendor jar package name openshift Highest Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor file name openshift-model High Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/openshift-model/ Low Product pom artifactid openshift-model Highest Product Manifest Bundle-Name Fabric8 :: OpenShift Model Medium Product Manifest build-timestamp ${build.datetime} Low Product Manifest specification-title Fabric8 :: OpenShift Model Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest bundle-symbolicname io.fabric8.openshift-model Medium Product pom name Fabric8 :: OpenShift Model High Product jar package name openshift Highest Product Manifest bundle-docurl http://redhat.com Low Product pom groupid io.fabric8 Highest Product jar package name io Highest Product Manifest os-arch amd64 Low Product file name openshift-model High Product pom parent-artifactid kubernetes-model-generator Medium Product Manifest Implementation-Title Fabric8 :: OpenShift Model High Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/openshift-model/ Low Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
oraclepki-19.3.0.0.jarDescription:
Oracle PKI to access Oracle Wallets from Java License:
Oracle Free Use Terms and Conditions (FUTC) File Path: /home/jenkins/.mvnrepository/com/oracle/ojdbc/oraclepki/19.3.0.0/oraclepki-19.3.0.0.jar
MD5: babe79be0b8106cd1090a7194994b300
SHA1: 0e52a34f271c6c62ee1a73b71cc19da5459b709f
SHA256: 04bdcbaa8da2c5800403ad0f448bec2867c6e9a12665d3f2c2aba1539dec24dc
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor file name oraclepki High Vendor pom name oraclepki High Vendor jar (hint) package name sun Highest Vendor pom groupid com.oracle.ojdbc Highest Vendor pom artifactid oraclepki Low Vendor pom groupid oracle.ojdbc Highest Vendor jar package name oracle Highest Vendor jar package name oraclepki Highest Vendor jar package name pki Highest Vendor pom url https://www.oracle.com/database/technologies/appdev/jdbc.html Highest Product file name oraclepki High Product pom url https://www.oracle.com/database/technologies/appdev/jdbc.html Medium Product pom name oraclepki High Product Manifest specification-title ENTSEC_DB19.3.0.0.0_GENERIC_190302.0616 Medium Product pom artifactid oraclepki Highest Product pom groupid oracle.ojdbc Highest Product jar package name oracle Highest Product jar package name oraclepki Highest Product jar package name pki Highest Version pom version 19.3.0.0 Highest Version file version 19.3.0.0 High
org.eclipse.jgit-5.7.0.202003110725-r.jarDescription:
Repository access and algorithms
File Path: /home/jenkins/.mvnrepository/org/eclipse/jgit/org.eclipse.jgit/5.7.0.202003110725-r/org.eclipse.jgit-5.7.0.202003110725-r.jarMD5: 1b6c6a4c5f8e33485d7aa247321314bbSHA1: 8dfe333ee6850df171a3d6b696aca3f93e23abc3SHA256: ee13076c3f832048f1a0ca272b221d2b69f10919e3bfd5d1b1e5ff7cf661e417Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid eclipse.jgit Highest Vendor jar package name eclipse Highest Vendor Manifest bundle-symbolicname org.eclipse.jgit Medium Vendor pom parent-groupid org.eclipse.jgit Medium Vendor jar package name repository Highest Vendor Manifest Implementation-Vendor-Id org.eclipse.jgit Medium Vendor pom parent-artifactid org.eclipse.jgit-parent Low Vendor pom groupid org.eclipse.jgit Highest Vendor Manifest automatic-module-name org.eclipse.jgit Medium Vendor Manifest bundle-requiredexecutionenvironment JavaSE-1.8 Low Vendor jar package name http Highest Vendor Manifest bundle-localization plugin Low Vendor Manifest Implementation-Vendor Eclipse.org - JGit High Vendor Manifest build-jdk-spec 1.8 Low Vendor pom artifactid eclipse.jgit Low Vendor file name org.eclipse.jgit High Vendor Manifest bundle-activationpolicy lazy Low Vendor jar package name jgit Highest Vendor pom name JGit - Core High Vendor Manifest implementation-vendor-url http://www.eclipse.org/jgit/ Medium Product pom groupid eclipse.jgit Highest Product jar package name eclipse Highest Product Manifest bundle-symbolicname org.eclipse.jgit Medium Product Manifest Bundle-Name %Bundle-Name Medium Product pom parent-groupid org.eclipse.jgit Medium Product pom parent-artifactid org.eclipse.jgit-parent Medium Product jar package name repository Highest Product Manifest Implementation-Title JGit org.eclipse.jgit High Product pom artifactid eclipse.jgit Highest Product Manifest automatic-module-name org.eclipse.jgit Medium Product Manifest bundle-requiredexecutionenvironment JavaSE-1.8 Low Product Manifest bundle-localization plugin Low Product Manifest build-jdk-spec 1.8 Low Product file name org.eclipse.jgit High Product Manifest bundle-activationpolicy lazy Low Product jar package name jgit Highest Product pom name JGit - Core High Product pom artifactid org.eclipse.jgit Highest Version pom version 5.7.0.202003110725-r Highest Version Manifest Bundle-Version 5.7.0.202003110725-r High Version Manifest Implementation-Version 5.7.0.202003110725-r High
org.osgi.core-4.3.1.jarDescription:
OSGi Service Platform Release 4 Version 4.3, Core Interfaces
and Classes for use in compiling bundles.
License:
Apache License, Version 2.0
:
http://opensource.org/licenses/apache2.0.php
File Path: /home/jenkins/.mvnrepository/org/osgi/org.osgi.core/4.3.1/org.osgi.core-4.3.1.jar
MD5: 8053bbc1b55d51f5abae005625209d08
SHA1: 5458ffe2ba049e76c29f2df2dc3ffccddf8b839e
SHA256: 10dad99322b2081015749e2d21538a4a9bc4cb3699d3b7b41ce452a544b09abe
Referenced In Project/Scope: Entando Kubernetes Service:runtime
Evidence Type Source Name Value Confidence Vendor file name org.osgi.core High Vendor Manifest bundle-symbolicname osgi.core Medium Vendor pom artifactid
org.osgi.core
Low Vendor pom organization url
http://www.osgi.org
Medium Vendor jar package name version Highest Vendor Manifest bundle-copyright Copyright (c) OSGi Alliance (2000, 2012). All Rights Reserved. Low Vendor jar package name osgi Highest Vendor pom groupid
org.osgi
Highest Vendor pom groupid org.osgi Highest Vendor pom url
http://www.osgi.org
Highest Vendor jar package name service Highest Vendor pom organization name
OSGi Alliance
High Vendor pom name
osgi.core
High Product file name org.osgi.core High Product Manifest bundle-symbolicname osgi.core Medium Product pom artifactid
org.osgi.core
Highest Product jar package name version Highest Product Manifest bundle-copyright Copyright (c) OSGi Alliance (2000, 2012). All Rights Reserved. Low Product jar package name osgi Highest Product Manifest Bundle-Name osgi.core Medium Product pom url
http://www.osgi.org
Medium Product pom groupid
org.osgi
Highest Product pom artifactid org.osgi.core Highest Product jar package name service Highest Product pom organization url
http://www.osgi.org
Low Product pom organization name
OSGi Alliance
Low Product pom name
osgi.core
High Version pom version
4.3.1
Highest
org.osgi.enterprise-4.2.0.jarDescription:
OSGi 4.2.0 Enterprise API License:
http://opensource.org/licenses/apache2.0.php; link="http://www.apache.org/licenses/LICENSE-2.0"; description="Apache License, Version 2.0" File Path: /home/jenkins/.mvnrepository/org/osgi/org.osgi.enterprise/4.2.0/org.osgi.enterprise-4.2.0.jar
MD5: c7e77f6056db8b4d6bd9ccf512b66f75
SHA1: 8634dcb0fc62196e820ed0f1062993c377f74972
SHA256: c05df7ec091e991712996e4ef9880b165bcde2c4127231607c58c3f558a65f2b
Referenced In Project/Scope: Entando Kubernetes Service:runtime
Evidence Type Source Name Value Confidence Vendor Manifest bundle-copyright Copyright (c) OSGi Alliance (2000, 2010). All Rights Reserved. Low Vendor file name org.osgi.enterprise High Vendor pom groupid osgi Highest Vendor pom groupid org.osgi Highest Vendor jar package name osgi Highest Vendor Manifest bundle-symbolicname osgi.enterprise Medium Vendor pom artifactid osgi.enterprise Low Product Manifest bundle-copyright Copyright (c) OSGi Alliance (2000, 2010). All Rights Reserved. Low Product Manifest Bundle-Name osgi.enterprise Medium Product file name org.osgi.enterprise High Product pom groupid osgi Highest Product pom artifactid osgi.enterprise Highest Product pom artifactid org.osgi.enterprise Highest Product jar package name service Highest Product jar package name osgi Highest Product Manifest bundle-symbolicname osgi.enterprise Medium Version pom version 4.2.0 Highest Version file version 4.2.0 High
osdt_cert-19.3.0.0.jarDescription:
osdt_cert.jar to access Oracle Wallets from Java License:
Oracle Free Use Terms and Conditions (FUTC) File Path: /home/jenkins/.mvnrepository/com/oracle/ojdbc/osdt_cert/19.3.0.0/osdt_cert-19.3.0.0.jar
MD5: 8bde9e2dabea91083a737ab02aed4b73
SHA1: c134652fdcb17ff72963d386efd8ade902d2eaff
SHA256: faa0cca594d354d5bb1f5eac3dafa1568387a27576813a9bd723d6fd8744be8c
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor file name osdt_cert High Vendor jar (hint) package name sun Highest Vendor pom artifactid osdt_cert Low Vendor pom groupid oracle.ojdbc Highest Vendor jar package name cert Highest Vendor pom url https://www.oracle.com/database/technologies/appdev/jdbc.html Highest Vendor Manifest specification-vendor Oracle Corporation Low Vendor pom name osdt_cert High Vendor pom groupid com.oracle.ojdbc Highest Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor jar package name oracle Highest Vendor Manifest repository-id ENTSEC_DB19.3.0.0.0_GENERIC_190302.0616 Low Product pom url https://www.oracle.com/database/technologies/appdev/jdbc.html Medium Product file name osdt_cert High Product jar package name security Highest Product pom name osdt_cert High Product Manifest specification-title Oracle Security Developer Tools Security Engine Medium Product jar package name oracle Highest Product Manifest Implementation-Title Oracle Security Developer Tools Security Engine High Product pom groupid oracle.ojdbc Highest Product pom artifactid osdt_cert Highest Product Manifest repository-id ENTSEC_DB19.3.0.0.0_GENERIC_190302.0616 Low Product jar package name cert Highest Version pom version 19.3.0.0 Highest Version file version 19.3.0.0 High
osdt_core-19.3.0.0.jarDescription:
osdt_core.jar to access Oracle Wallets from Java License:
Oracle Free Use Terms and Conditions (FUTC) File Path: /home/jenkins/.mvnrepository/com/oracle/ojdbc/osdt_core/19.3.0.0/osdt_core-19.3.0.0.jar
MD5: 74366ecfe0555a7ee277d1ce11a4933e
SHA1: 2e01c262879c97de876c238966eb1da48542f2e8
SHA256: c7a90c07a12e73d03c1edd6a02e699001213e698fe0f5225a2771ccd46ab0b63
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor file name osdt_core High Vendor jar (hint) package name sun Highest Vendor pom groupid oracle.ojdbc Highest Vendor pom artifactid osdt_core Low Vendor pom name osdt_core High Vendor pom url https://www.oracle.com/database/technologies/appdev/jdbc.html Highest Vendor Manifest specification-vendor Oracle Corporation Low Vendor pom groupid com.oracle.ojdbc Highest Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor jar package name oracle Highest Vendor jar package name core Highest Vendor Manifest repository-id ENTSEC_DB19.3.0.0.0_GENERIC_190302.0616 Low Product file name osdt_core High Product pom url https://www.oracle.com/database/technologies/appdev/jdbc.html Medium Product pom groupid oracle.ojdbc Highest Product pom artifactid osdt_core Highest Product pom name osdt_core High Product jar package name security Highest Product Manifest Implementation-Title Oracle Security Developer Tools Crypto High Product jar package name oracle Highest Product jar package name crypto Highest Product jar package name core Highest Product Manifest repository-id ENTSEC_DB19.3.0.0.0_GENERIC_190302.0616 Low Product Manifest specification-title Oracle Security Developer Tools Crypto Medium Version pom version 19.3.0.0 Highest Version file version 19.3.0.0 High
postgresql-42.2.13.jarDescription:
PostgreSQL JDBC Driver Postgresql License:
BSD-2-Clause: https://jdbc.postgresql.org/about/license.html File Path: /home/jenkins/.mvnrepository/org/postgresql/postgresql/42.2.13/postgresql-42.2.13.jar
MD5: 31d0fbb0ec31c681fcced463a4b1b8ce
SHA1: 750a4e6dbc753308f50e998920b760b2b5c048ad
SHA256: 66de7790e75c173501f6591114defa297455214eceb462a50b255867c48a8b68
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest provide-capability osgi.service;effective:=active;objectClass="org.osgi.service.jdbc.DataSourceFactory" Low Vendor jar package name driver Highest Vendor Manifest Implementation-Vendor PostgreSQL Global Development Group High Vendor pom groupid org.postgresql Highest Vendor jar package name postgresql Highest Vendor pom url https://jdbc.postgresql.org Highest Vendor jar package name jdbc Highest Vendor pom artifactid postgresql Low Vendor pom organization url https://jdbc.postgresql.org/ Medium Vendor pom organization name PostgreSQL Global Development Group High Vendor Manifest specification-vendor Oracle Corporation Low Vendor Manifest bundle-symbolicname org.postgresql.jdbc Medium Vendor pom name PostgreSQL JDBC Driver High Vendor Manifest bundle-docurl https://jdbc.postgresql.org/ Low Vendor Manifest bundle-copyright Copyright (c) 2003-2020, PostgreSQL Global Development Group Low Vendor Manifest require-capability osgi.ee;filter:="(&(|(osgi.ee=J2SE)(osgi.ee=JavaSE))(version>=1.8))" Low Vendor pom groupid postgresql Highest Vendor Manifest automatic-module-name org.postgresql.jdbc Medium Vendor Manifest Implementation-Vendor-Id org.postgresql Medium Vendor file name postgresql High Product Manifest provide-capability osgi.service;effective:=active;objectClass="org.osgi.service.jdbc.DataSourceFactory" Low Product jar package name driver Highest Product Manifest Implementation-Title PostgreSQL JDBC Driver High Product jar package name postgresql Highest Product jar package name version Highest Product jar package name jdbc Highest Product pom url https://jdbc.postgresql.org Medium Product Manifest Bundle-Name PostgreSQL JDBC Driver Medium Product jar package name osgi Highest Product pom artifactid postgresql Highest Product pom organization name PostgreSQL Global Development Group Low Product Manifest bundle-symbolicname org.postgresql.jdbc Medium Product pom name PostgreSQL JDBC Driver High Product Manifest bundle-docurl https://jdbc.postgresql.org/ Low Product Manifest bundle-copyright Copyright (c) 2003-2020, PostgreSQL Global Development Group Low Product Manifest require-capability osgi.ee;filter:="(&(|(osgi.ee=J2SE)(osgi.ee=JavaSE))(version>=1.8))" Low Product pom groupid postgresql Highest Product Manifest specification-title JDBC Medium Product pom organization url https://jdbc.postgresql.org/ Low Product Manifest automatic-module-name org.postgresql.jdbc Medium Product file name postgresql High Version Manifest Implementation-Version 42.2.13 High Version Manifest Bundle-Version 42.2.13 High Version pom version 42.2.13 Highest Version file version 42.2.13 High
problem-0.23.0.jarDescription:
An implementation of the application/problem+json draft. File Path: /home/jenkins/.mvnrepository/org/zalando/problem/0.23.0/problem-0.23.0.jarMD5: 1291e5bae7bfdf265ec3ba138e6d21cbSHA1: 749bcf31b8223309a3a330352c20d8692239ac1aSHA256: f3164255f334f9774a1b92c9f13aa8563f66424165df3592fa8c6005faf6a245Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-groupid org.zalando Medium Vendor file name problem High Vendor jar package name problem Highest Vendor pom name Problem High Vendor jar package name zalando Low Vendor pom groupid zalando Highest Vendor pom artifactid problem Low Vendor pom groupid org.zalando Highest Vendor jar package name problem Low Vendor jar package name zalando Highest Vendor pom parent-artifactid problem-parent Low Product pom parent-groupid org.zalando Medium Product file name problem High Product jar package name problem Highest Product pom name Problem High Product pom groupid zalando Highest Product jar package name problem Low Product pom artifactid problem Highest Product jar package name zalando Highest Product pom parent-artifactid problem-parent Medium Version pom version 0.23.0 Highest Version file version 0.23.0 High
problem-spring-common-0.25.2.jarDescription:
Spring common Advices for Problems File Path: /home/jenkins/.mvnrepository/org/zalando/problem-spring-common/0.25.2/problem-spring-common-0.25.2.jarMD5: 8b0340476b4b911d83b7e6de2110a86fSHA1: 64efe64b632c0d18a5fc7df733969252796d293aSHA256: 8eaac0fdad326dc7d732ed563d3aedda8356f3c6a38c67766160f3d22eb43eacReferenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-groupid org.zalando Medium Vendor pom name Problem: Spring Common High Vendor pom parent-artifactid problem-spring-parent Low Vendor jar package name zalando Low Vendor file name problem-spring-common High Vendor jar package name common Highest Vendor jar package name zalando Highest Vendor jar package name problem Highest Vendor jar package name spring Highest Vendor pom groupid zalando Highest Vendor pom groupid org.zalando Highest Vendor jar package name problem Low Vendor pom artifactid problem-spring-common Low Vendor jar package name spring Low Product pom parent-groupid org.zalando Medium Product pom name Problem: Spring Common High Product pom artifactid problem-spring-common Highest Product jar package name common Low Product file name problem-spring-common High Product jar package name common Highest Product jar package name zalando Highest Product pom parent-artifactid problem-spring-parent Medium Product jar package name problem Highest Product jar package name spring Highest Product pom groupid zalando Highest Product jar package name problem Low Product jar package name spring Low Version file version 0.25.2 High Version pom version 0.25.2 Highest
problem-spring-web-0.25.2.jarDescription:
Spring Controller Advices for Problems File Path: /home/jenkins/.mvnrepository/org/zalando/problem-spring-web/0.25.2/problem-spring-web-0.25.2.jarMD5: ade6cf924066bb05d680025078bdf68dSHA1: da209cac0bece7e6050e59ba7c3e57183db9c3c6SHA256: be40e998e2edcb239df4f19dedbd921c91873d203f3b53559486a791e946c58eReferenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-groupid org.zalando Medium Vendor jar package name web Highest Vendor pom name Problem: Spring Web High Vendor pom parent-artifactid problem-spring-parent Low Vendor jar package name zalando Low Vendor jar package name zalando Highest Vendor file name problem-spring-web High Vendor jar package name problem Highest Vendor jar package name spring Highest Vendor pom groupid zalando Highest Vendor pom artifactid problem-spring-web Low Vendor pom groupid org.zalando Highest Vendor jar package name problem Low Vendor jar package name spring Low Product pom parent-groupid org.zalando Medium Product jar package name web Highest Product jar package name web Low Product pom name Problem: Spring Web High Product jar package name zalando Highest Product file name problem-spring-web High Product pom parent-artifactid problem-spring-parent Medium Product jar package name problem Highest Product jar package name spring Highest Product pom groupid zalando Highest Product jar package name problem Low Product jar package name spring Low Product pom artifactid problem-spring-web Highest Version file version 0.25.2 High Version pom version 0.25.2 Highest
problem-spring-web-autoconfigure-0.25.2.jarDescription:
Spring autoconfiguration module for Problem Spring Web File Path: /home/jenkins/.mvnrepository/org/zalando/problem-spring-web-autoconfigure/0.25.2/problem-spring-web-autoconfigure-0.25.2.jarMD5: d1477740556ce8b8bff4bd13ded8a951SHA1: 3e49dfb131ac6ab943520fb4cf5ca7412889148dSHA256: fd236bc3220e6f32147db046c2c1ceacbb96fbd14c59a70bbc73801287c1373aReferenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-groupid org.zalando Medium Vendor pom artifactid problem-spring-web-autoconfigure Low Vendor jar package name web Highest Vendor pom parent-artifactid problem-spring-parent Low Vendor jar package name zalando Low Vendor file name problem-spring-web-autoconfigure High Vendor jar package name zalando Highest Vendor pom name Problem: Spring Web Autoconfiguration High Vendor jar package name problem Highest Vendor jar package name spring Highest Vendor pom groupid zalando Highest Vendor pom groupid org.zalando Highest Vendor jar package name problem Low Vendor jar package name spring Low Product pom parent-groupid org.zalando Medium Product pom artifactid problem-spring-web-autoconfigure Highest Product jar package name web Highest Product jar package name web Low Product file name problem-spring-web-autoconfigure High Product jar package name zalando Highest Product pom name Problem: Spring Web Autoconfiguration High Product pom parent-artifactid problem-spring-parent Medium Product jar package name problem Highest Product jar package name spring Highest Product pom groupid zalando Highest Product jar package name problem Low Product jar package name spring Low Version file version 0.25.2 High Version pom version 0.25.2 Highest
problem-spring-web-starter-0.25.2.jarDescription:
Spring starter module for Problem Spring Web File Path: /home/jenkins/.mvnrepository/org/zalando/problem-spring-web-starter/0.25.2/problem-spring-web-starter-0.25.2.jarMD5: a0ee52dfed5d26efac6d67b95427f4bdSHA1: 36940bd0d223416411a20981b883665e04d263faSHA256: f790520d5871ee10f14537d820ca530bde9300955da402660efb0335989ac204Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor file name problem-spring-web-starter High Vendor pom parent-groupid org.zalando Medium Vendor pom name Problem: Spring Web Starter High Vendor pom parent-artifactid problem-spring-parent Low Vendor pom groupid zalando Highest Vendor pom groupid org.zalando Highest Vendor pom artifactid problem-spring-web-starter Low Product file name problem-spring-web-starter High Product pom parent-groupid org.zalando Medium Product pom parent-artifactid problem-spring-parent Medium Product pom name Problem: Spring Web Starter High Product pom groupid zalando Highest Product pom artifactid problem-spring-web-starter Highest Version file version 0.25.2 High Version pom version 0.25.2 Highest
problem-violations-0.25.2.jarDescription:
Constraint violations Problems File Path: /home/jenkins/.mvnrepository/org/zalando/problem-violations/0.25.2/problem-violations-0.25.2.jarMD5: 70dddd39785af5f243f74ba3cf626ae2SHA1: 2bd65b384ebfe5611c545b3ba867b74ec8f1e643SHA256: 0991531d14040fa0ee7968b18f29ead3e0699400b2724a72f8b13176d5ede7e8Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-groupid org.zalando Medium Vendor pom parent-artifactid problem-spring-parent Low Vendor jar package name zalando Low Vendor pom name Problem: Violations High Vendor jar package name zalando Highest Vendor jar package name violations Low Vendor jar package name problem Highest Vendor pom artifactid problem-violations Low Vendor jar package name violations Highest Vendor pom groupid zalando Highest Vendor file name problem-violations High Vendor pom groupid org.zalando Highest Vendor jar package name problem Low Product pom parent-groupid org.zalando Medium Product pom parent-artifactid problem-spring-parent Medium Product jar package name violations Low Product jar package name problem Highest Product jar package name violations Highest Product pom groupid zalando Highest Product file name problem-violations High Product jar package name problem Low Product pom name Problem: Violations High Product jar package name zalando Highest Product pom artifactid problem-violations Highest Version file version 0.25.2 High Version pom version 0.25.2 Highest
simplefan-19.3.0.0.jarDescription:
Oracle Simple FAN License:
Oracle Free Use Terms and Conditions (FUTC) File Path: /home/jenkins/.mvnrepository/com/oracle/ojdbc/simplefan/19.3.0.0/simplefan-19.3.0.0.jar
MD5: 9a1f7448f4c1fb779b1d8816e51a2c2f
SHA1: bcbfbb3cc529995f33c8694eb7cbc605c129e4e6
SHA256: 5138d658edff0e0106f0559f68c72fb90f1cd34381492995b75d0012ea9e12f2
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor file name simplefan High Vendor pom name simplefan High Vendor jar (hint) package name sun Highest Vendor pom groupid com.oracle.ojdbc Highest Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor jar package name oracle Highest Vendor pom groupid oracle.ojdbc Highest Vendor jar package name simplefan Highest Vendor pom artifactid simplefan Low Vendor pom url https://www.oracle.com/database/technologies/appdev/jdbc.html Highest Product file name simplefan High Product Manifest Implementation-Title Oracle Simple FAN High Product pom url https://www.oracle.com/database/technologies/appdev/jdbc.html Medium Product pom name simplefan High Product pom artifactid simplefan Highest Product jar package name oracle Highest Product pom groupid oracle.ojdbc Highest Product jar package name simplefan Highest Version pom version 19.3.0.0 Highest Version file version 19.3.0.0 High
slf4j-api-1.7.32.jarDescription:
The slf4j API File Path: /home/jenkins/.mvnrepository/org/slf4j/slf4j-api/1.7.32/slf4j-api-1.7.32.jarMD5: fbcf58513bc25b80f075d812aad3e3cfSHA1: cdcff33940d9f2de763bc41ea05a0be5941176c3SHA256: 3624f8474c1af46d75f98bc097d7864a323c81b3808aa43689a6e1c601c027beReferenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom parent-groupid org.slf4j Medium Vendor pom artifactid slf4j-api Low Vendor Manifest automatic-module-name org.slf4j Medium Vendor jar package name slf4j Highest Vendor Manifest bundle-symbolicname slf4j.api Medium Vendor file name slf4j-api High Vendor pom parent-artifactid slf4j-parent Low Vendor pom name SLF4J API Module High Vendor pom groupid org.slf4j Highest Vendor Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Vendor pom groupid slf4j Highest Vendor pom url http://www.slf4j.org Highest Product pom parent-artifactid slf4j-parent Medium Product pom parent-groupid org.slf4j Medium Product pom url http://www.slf4j.org Medium Product Manifest automatic-module-name org.slf4j Medium Product jar package name slf4j Highest Product Manifest bundle-symbolicname slf4j.api Medium Product Manifest Implementation-Title slf4j-api High Product file name slf4j-api High Product pom name SLF4J API Module High Product Manifest Bundle-Name slf4j-api Medium Product Manifest bundle-requiredexecutionenvironment J2SE-1.5 Low Product pom groupid slf4j Highest Product pom artifactid slf4j-api Highest Version Manifest Bundle-Version 1.7.32 High Version Manifest Implementation-Version 1.7.32 High Version file version 1.7.32 High Version pom version 1.7.32 Highest
snakeyaml-1.27.jarDescription:
YAML 1.1 parser and emitter for Java License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/org/yaml/snakeyaml/1.27/snakeyaml-1.27.jar
MD5: 466ff09da784f9f21b2e6bf3b486a8cd
SHA1: 359d62567480b07a679dc643f82fc926b100eed5
SHA256: 7e7cce6740ed705bfdfaac7b442c1375d2986d2f2935936a5bd40c14e18fd736
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid org.yaml Highest Vendor file name snakeyaml High Vendor jar package name parser Highest Vendor Manifest bundle-symbolicname org.yaml.snakeyaml Medium Vendor pom url http://www.snakeyaml.org Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor jar package name snakeyaml Highest Vendor pom artifactid snakeyaml Low Vendor jar package name emitter Highest Vendor Manifest automatic-module-name org.yaml.snakeyaml Medium Vendor pom groupid yaml Highest Vendor jar package name yaml Highest Vendor pom name SnakeYAML High Product Manifest Bundle-Name SnakeYAML Medium Product file name snakeyaml High Product jar package name parser Highest Product Manifest bundle-symbolicname org.yaml.snakeyaml Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product jar package name snakeyaml Highest Product pom url http://www.snakeyaml.org Medium Product pom artifactid snakeyaml Highest Product jar package name emitter Highest Product Manifest automatic-module-name org.yaml.snakeyaml Medium Product pom groupid yaml Highest Product jar package name yaml Highest Product pom name SnakeYAML High Version file version 1.27 High Version pom version 1.27 Highest
spring-aop-5.3.12.jarDescription:
Spring AOP License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/spring-aop/5.3.12/spring-aop-5.3.12.jar
MD5: c7c78f7f1fc4072a29952df72b7f0cea
SHA1: 882db41939109e96f4c78cd5c0931cc4aebc3d58
SHA256: 7353fa4b7f27dbd85cf2a1cd87562466331825ae69c64b4840607b3fc6a66b0c
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor file name spring-aop High Vendor jar package name aop Highest Vendor hint analyzer vendor SpringSource Highest Vendor pom groupid org.springframework Highest Vendor hint analyzer vendor pivotal software Highest Vendor pom name Spring AOP High Vendor jar package name springframework Highest Vendor hint analyzer vendor vmware Highest Vendor pom url spring-projects/spring-framework Highest Vendor pom organization name Spring IO High Vendor pom artifactid spring-aop Low Vendor pom groupid springframework Highest Vendor pom organization url https://spring.io/projects/spring-framework Medium Vendor Manifest automatic-module-name spring.aop Medium Product file name spring-aop High Product pom url spring-projects/spring-framework High Product hint analyzer product springsource_spring_framework Highest Product jar package name aop Highest Product Manifest Implementation-Title spring-aop High Product pom organization url https://spring.io/projects/spring-framework Low Product pom name Spring AOP High Product jar package name springframework Highest Product pom artifactid spring-aop Highest Product pom organization name Spring IO Low Product pom groupid springframework Highest Product Manifest automatic-module-name spring.aop Medium Version Manifest Implementation-Version 5.3.12 High Version file version 5.3.12 High Version pom version 5.3.12 Highest
spring-beans-5.3.12.jarDescription:
Spring Beans License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/spring-beans/5.3.12/spring-beans-5.3.12.jar
MD5: 82732731c01daf384073dbe1ec1e2ec2
SHA1: caaa1d489bce88d6aa01ddd255ad5046acf8f282
SHA256: a88c010991f572723109ebd4d9c38974ddb78f4477f97cf48e9d364ec35f3432
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor hint analyzer vendor SpringSource Highest Vendor pom groupid org.springframework Highest Vendor Manifest automatic-module-name spring.beans Medium Vendor pom name Spring Beans High Vendor pom artifactid spring-beans Low Vendor hint analyzer vendor pivotal software Highest Vendor file name spring-beans High Vendor jar package name springframework Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name beans Highest Vendor pom url spring-projects/spring-framework Highest Vendor pom organization name Spring IO High Vendor pom groupid springframework Highest Vendor pom organization url https://spring.io/projects/spring-framework Medium Product pom url spring-projects/spring-framework High Product hint analyzer product springsource_spring_framework Highest Product Manifest automatic-module-name spring.beans Medium Product pom name Spring Beans High Product pom organization url https://spring.io/projects/spring-framework Low Product file name spring-beans High Product jar package name springframework Highest Product pom artifactid spring-beans Highest Product Manifest Implementation-Title spring-beans High Product jar package name beans Highest Product pom organization name Spring IO Low Product pom groupid springframework Highest Version Manifest Implementation-Version 5.3.12 High Version file version 5.3.12 High Version pom version 5.3.12 Highest
spring-boot-2.5.6.jarDescription:
Spring Boot License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/boot/spring-boot/2.5.6/spring-boot-2.5.6.jar
MD5: 3f340ad5b87ea6a0062b2251f95cf2b9
SHA1: d8c6b97fd3182fb6d7d06ebf710cd9ccabc83b89
SHA256: 26c625d41e8009308b9a7c6564a80e32264316c8d12b830ae2ef12bfd62d7756
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid springframework.boot Highest Vendor pom groupid org.springframework.boot Highest Vendor hint analyzer vendor SpringSource Highest Vendor pom name spring-boot High Vendor jar package name boot Highest Vendor hint analyzer vendor pivotal software Highest Vendor Manifest automatic-module-name spring.boot Medium Vendor pom url https://spring.io/projects/spring-boot Highest Vendor pom organization url https://spring.io Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor pom artifactid spring-boot Low Vendor jar package name springframework Highest Vendor hint analyzer vendor vmware Highest Vendor file name spring-boot High Vendor pom organization name Pivotal Software, Inc. High Product pom groupid springframework.boot Highest Product pom organization url https://spring.io Low Product Manifest Implementation-Title Spring Boot High Product pom name spring-boot High Product jar package name boot Highest Product pom url https://spring.io/projects/spring-boot Medium Product Manifest automatic-module-name spring.boot Medium Product pom artifactid spring-boot Highest Product Manifest build-jdk-spec 1.8 Low Product pom organization name Pivotal Software, Inc. Low Product jar package name springframework Highest Product file name spring-boot High Version Manifest Implementation-Version 2.5.6 High Version pom version 2.5.6 Highest Version file version 2.5.6 High
spring-boot-actuator-2.5.6.jarDescription:
Spring Boot Actuator License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/boot/spring-boot-actuator/2.5.6/spring-boot-actuator-2.5.6.jar
MD5: ae8638844328bac9924460607d2f5e8a
SHA1: 4e7d2607630342ef3b50f48edbf8e938b1eb3392
SHA256: 53511c4c61f76fb35a3a7cfca3e7793cf64454be5f3cffcdd002e2ba235ffbaf
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid springframework.boot Highest Vendor pom groupid org.springframework.boot Highest Vendor hint analyzer vendor SpringSource Highest Vendor jar package name boot Highest Vendor hint analyzer vendor pivotal software Highest Vendor file name spring-boot-actuator High Vendor pom url https://spring.io/projects/spring-boot Highest Vendor pom organization url https://spring.io Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor jar package name springframework Highest Vendor hint analyzer vendor vmware Highest Vendor Manifest automatic-module-name spring.boot.actuator Medium Vendor pom artifactid spring-boot-actuator Low Vendor pom organization name Pivotal Software, Inc. High Vendor pom name spring-boot-actuator High Product pom groupid springframework.boot Highest Product pom organization url https://spring.io Low Product Manifest Implementation-Title Spring Boot Actuator High Product jar package name boot Highest Product pom url https://spring.io/projects/spring-boot Medium Product file name spring-boot-actuator High Product Manifest build-jdk-spec 1.8 Low Product pom organization name Pivotal Software, Inc. Low Product jar package name springframework Highest Product Manifest automatic-module-name spring.boot.actuator Medium Product pom artifactid spring-boot-actuator Highest Product pom name spring-boot-actuator High Version Manifest Implementation-Version 2.5.6 High Version pom version 2.5.6 Highest Version file version 2.5.6 High
spring-boot-actuator-autoconfigure-2.5.6.jarDescription:
Spring Boot Actuator AutoConfigure License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/boot/spring-boot-actuator-autoconfigure/2.5.6/spring-boot-actuator-autoconfigure-2.5.6.jar
MD5: 0c4e924331d41b260c67661816540b09
SHA1: e7d19064fe5664600fbfa051277459ed94f5d266
SHA256: d9b8f57265d504b5145743ebec2a096c5fea5392345b7c9bc711bc544bf30db1
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid springframework.boot Highest Vendor Manifest automatic-module-name spring.boot.actuator.autoconfigure Medium Vendor pom artifactid spring-boot-actuator-autoconfigure Low Vendor pom groupid org.springframework.boot Highest Vendor hint analyzer vendor SpringSource Highest Vendor jar package name boot Highest Vendor hint analyzer vendor pivotal software Highest Vendor file name spring-boot-actuator-autoconfigure High Vendor pom url https://spring.io/projects/spring-boot Highest Vendor pom organization url https://spring.io Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor jar package name autoconfigure Highest Vendor jar package name springframework Highest Vendor hint analyzer vendor vmware Highest Vendor pom name spring-boot-actuator-autoconfigure High Vendor pom organization name Pivotal Software, Inc. High Product pom groupid springframework.boot Highest Product pom artifactid spring-boot-actuator-autoconfigure Highest Product Manifest automatic-module-name spring.boot.actuator.autoconfigure Medium Product pom organization url https://spring.io Low Product Manifest Implementation-Title Spring Boot Actuator AutoConfigure High Product jar package name boot Highest Product pom url https://spring.io/projects/spring-boot Medium Product file name spring-boot-actuator-autoconfigure High Product Manifest build-jdk-spec 1.8 Low Product pom organization name Pivotal Software, Inc. Low Product jar package name autoconfigure Highest Product jar package name springframework Highest Product pom name spring-boot-actuator-autoconfigure High Version Manifest Implementation-Version 2.5.6 High Version pom version 2.5.6 Highest Version file version 2.5.6 High
spring-boot-autoconfigure-2.5.6.jarDescription:
Spring Boot AutoConfigure License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/boot/spring-boot-autoconfigure/2.5.6/spring-boot-autoconfigure-2.5.6.jar
MD5: 92ba2eb63994abc4f543a7f84436fdb3
SHA1: b9f4016180c5242530da465561ff25c7cac14bf3
SHA256: 02fb184c2a9b1d913cea04e5517d45387eafdfc328925a6f26345933ce6276d4
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid springframework.boot Highest Vendor pom artifactid spring-boot-autoconfigure Low Vendor file name spring-boot-autoconfigure High Vendor pom groupid org.springframework.boot Highest Vendor hint analyzer vendor SpringSource Highest Vendor jar package name boot Highest Vendor hint analyzer vendor pivotal software Highest Vendor pom url https://spring.io/projects/spring-boot Highest Vendor pom organization url https://spring.io Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor jar package name autoconfigure Highest Vendor jar package name springframework Highest Vendor pom name spring-boot-autoconfigure High Vendor hint analyzer vendor vmware Highest Vendor Manifest automatic-module-name spring.boot.autoconfigure Medium Vendor pom organization name Pivotal Software, Inc. High Product pom groupid springframework.boot Highest Product pom artifactid spring-boot-autoconfigure Highest Product file name spring-boot-autoconfigure High Product pom organization url https://spring.io Low Product Manifest Implementation-Title Spring Boot AutoConfigure High Product jar package name boot Highest Product pom url https://spring.io/projects/spring-boot Medium Product Manifest build-jdk-spec 1.8 Low Product pom organization name Pivotal Software, Inc. Low Product jar package name autoconfigure Highest Product jar package name springframework Highest Product pom name spring-boot-autoconfigure High Product Manifest automatic-module-name spring.boot.autoconfigure Medium Version Manifest Implementation-Version 2.5.6 High Version pom version 2.5.6 Highest Version file version 2.5.6 High
spring-boot-starter-2.5.6.jarDescription:
Core starter, including auto-configuration support, logging and YAML License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/boot/spring-boot-starter/2.5.6/spring-boot-starter-2.5.6.jar
MD5: 54ffdb145c54231f998537ca9bf169b4
SHA1: 0d5d1fada1afe9a808abf48da7066a993cf679aa
SHA256: 061872103481aebd7cd55ac260bcdfb20ffe05d02a6cd62a7a095bd9cb235949
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid springframework.boot Highest Vendor Manifest spring-boot-jar-type dependencies-starter Low Vendor pom artifactid spring-boot-starter Low Vendor pom groupid org.springframework.boot Highest Vendor hint analyzer vendor SpringSource Highest Vendor pom name spring-boot-starter High Vendor hint analyzer vendor pivotal software Highest Vendor pom url https://spring.io/projects/spring-boot Highest Vendor pom organization url https://spring.io Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor hint analyzer vendor vmware Highest Vendor pom organization name Pivotal Software, Inc. High Vendor file name spring-boot-starter High Vendor Manifest automatic-module-name spring.boot.starter Medium Product pom groupid springframework.boot Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest Implementation-Title Core starter, including auto-configuration support, logging and YAML High Product Manifest spring-boot-jar-type dependencies-starter Low Product pom organization name Pivotal Software, Inc. Low Product pom organization url https://spring.io Low Product pom name spring-boot-starter High Product pom url https://spring.io/projects/spring-boot Medium Product pom artifactid spring-boot-starter Highest Product file name spring-boot-starter High Product Manifest automatic-module-name spring.boot.starter Medium Version Manifest Implementation-Version 2.5.6 High Version pom version 2.5.6 Highest Version file version 2.5.6 High
spring-boot-starter-actuator-2.5.6.jarDescription:
Starter for using Spring Boot's Actuator which provides production ready features to help you monitor and manage your application License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/boot/spring-boot-starter-actuator/2.5.6/spring-boot-starter-actuator-2.5.6.jar
MD5: 378a4f21fcb1f5c22d9f0fcc2b74c23c
SHA1: e5057388311b3566d49ba2021673e0022da1a99c
SHA256: f0c21601bca6ca7b0e2ac65ca4a5183a376e8be50d1c7c54b034b0cde06ada1b
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid springframework.boot Highest Vendor file name spring-boot-starter-actuator High Vendor Manifest spring-boot-jar-type dependencies-starter Low Vendor pom groupid org.springframework.boot Highest Vendor hint analyzer vendor SpringSource Highest Vendor Manifest automatic-module-name spring.boot.starter.actuator Medium Vendor hint analyzer vendor pivotal software Highest Vendor pom url https://spring.io/projects/spring-boot Highest Vendor pom organization url https://spring.io Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor hint analyzer vendor vmware Highest Vendor pom artifactid spring-boot-starter-actuator Low Vendor pom organization name Pivotal Software, Inc. High Vendor pom name spring-boot-starter-actuator High Product pom groupid springframework.boot Highest Product Manifest build-jdk-spec 1.8 Low Product file name spring-boot-starter-actuator High Product Manifest spring-boot-jar-type dependencies-starter Low Product pom organization name Pivotal Software, Inc. Low Product pom organization url https://spring.io Low Product Manifest automatic-module-name spring.boot.starter.actuator Medium Product pom artifactid spring-boot-starter-actuator Highest Product Manifest Implementation-Title Starter for using Spring Boot's Actuator which provides production ready features to help you monitor and manage your application High Product pom name spring-boot-starter-actuator High Product pom url https://spring.io/projects/spring-boot Medium Version Manifest Implementation-Version 2.5.6 High Version pom version 2.5.6 Highest Version file version 2.5.6 High
spring-boot-starter-hateoas-2.5.6.jarDescription:
Starter for building hypermedia-based RESTful web application with Spring MVC and Spring HATEOAS License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/boot/spring-boot-starter-hateoas/2.5.6/spring-boot-starter-hateoas-2.5.6.jar
MD5: 5194b2592e59789b48563d75e97cdc5a
SHA1: 8f80a0f1ea6fbeb239541d828ae83bd7e82af9bc
SHA256: 72eebdc94d9372f342a442529baa26b94b63acdcf63d3e4a20eb2feb77d0826b
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid springframework.boot Highest Vendor Manifest spring-boot-jar-type dependencies-starter Low Vendor pom groupid org.springframework.boot Highest Vendor hint analyzer vendor SpringSource Highest Vendor file name spring-boot-starter-hateoas High Vendor Manifest automatic-module-name spring.boot.starter.hateoas Medium Vendor hint analyzer vendor pivotal software Highest Vendor pom url https://spring.io/projects/spring-boot Highest Vendor pom organization url https://spring.io Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor hint analyzer vendor vmware Highest Vendor pom organization name Pivotal Software, Inc. High Vendor pom artifactid spring-boot-starter-hateoas Low Vendor pom name spring-boot-starter-hateoas High Product pom groupid springframework.boot Highest Product pom artifactid spring-boot-starter-hateoas Highest Product Manifest build-jdk-spec 1.8 Low Product Manifest spring-boot-jar-type dependencies-starter Low Product pom organization name Pivotal Software, Inc. Low Product pom organization url https://spring.io Low Product file name spring-boot-starter-hateoas High Product Manifest Implementation-Title Starter for building hypermedia-based RESTful web application with Spring MVC and Spring HATEOAS High Product Manifest automatic-module-name spring.boot.starter.hateoas Medium Product pom url https://spring.io/projects/spring-boot Medium Product pom name spring-boot-starter-hateoas High Version Manifest Implementation-Version 2.5.6 High Version pom version 2.5.6 Highest Version file version 2.5.6 High
spring-boot-starter-json-2.5.6.jarDescription:
Starter for reading and writing json License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/boot/spring-boot-starter-json/2.5.6/spring-boot-starter-json-2.5.6.jar
MD5: 493d5c1be108792c2cc908f987743181
SHA1: 6ef5a7087e18ed4f3736c8752440ecd489c36a4d
SHA256: e3e0b8bfd8f4e23a8564461d7e3dc09545371b9eeea579fefa3e2fee085bc9da
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid springframework.boot Highest Vendor Manifest automatic-module-name spring.boot.starter.json Medium Vendor Manifest spring-boot-jar-type dependencies-starter Low Vendor pom groupid org.springframework.boot Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor pivotal software Highest Vendor file name spring-boot-starter-json High Vendor pom url https://spring.io/projects/spring-boot Highest Vendor pom organization url https://spring.io Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor hint analyzer vendor vmware Highest Vendor pom artifactid spring-boot-starter-json Low Vendor pom organization name Pivotal Software, Inc. High Vendor pom name spring-boot-starter-json High Product pom groupid springframework.boot Highest Product Manifest automatic-module-name spring.boot.starter.json Medium Product Manifest build-jdk-spec 1.8 Low Product Manifest spring-boot-jar-type dependencies-starter Low Product pom organization name Pivotal Software, Inc. Low Product pom organization url https://spring.io Low Product pom artifactid spring-boot-starter-json Highest Product pom name spring-boot-starter-json High Product pom url https://spring.io/projects/spring-boot Medium Product file name spring-boot-starter-json High Product Manifest Implementation-Title Starter for reading and writing json High Version Manifest Implementation-Version 2.5.6 High Version pom version 2.5.6 Highest Version file version 2.5.6 High
spring-boot-starter-logging-2.5.6.jarDescription:
Starter for logging using Logback. Default logging starter License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/boot/spring-boot-starter-logging/2.5.6/spring-boot-starter-logging-2.5.6.jar
MD5: 1211f5da8a33213d5842496b5602ecb4
SHA1: a900356a11b1a41f4277136f1d13ce7a13f43b3c
SHA256: dc84bdbb017ef84492904f32190c631b57e0117a82fd36fd3bd86d8ceca65a3c
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid springframework.boot Highest Vendor Manifest spring-boot-jar-type dependencies-starter Low Vendor pom name spring-boot-starter-logging High Vendor pom groupid org.springframework.boot Highest Vendor hint analyzer vendor SpringSource Highest Vendor hint analyzer vendor pivotal software Highest Vendor pom url https://spring.io/projects/spring-boot Highest Vendor pom organization url https://spring.io Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor file name spring-boot-starter-logging High Vendor Manifest automatic-module-name spring.boot.starter.logging Medium Vendor pom artifactid spring-boot-starter-logging Low Vendor hint analyzer vendor vmware Highest Vendor pom organization name Pivotal Software, Inc. High Product pom groupid springframework.boot Highest Product Manifest build-jdk-spec 1.8 Low Product file name spring-boot-starter-logging High Product Manifest automatic-module-name spring.boot.starter.logging Medium Product Manifest spring-boot-jar-type dependencies-starter Low Product pom organization name Pivotal Software, Inc. Low Product pom organization url https://spring.io Low Product pom name spring-boot-starter-logging High Product pom url https://spring.io/projects/spring-boot Medium Product pom artifactid spring-boot-starter-logging Highest Product Manifest Implementation-Title Starter for logging using Logback. Default logging starter High Version Manifest Implementation-Version 2.5.6 High Version pom version 2.5.6 Highest Version file version 2.5.6 High
spring-boot-starter-oauth2-resource-server-2.5.6.jarDescription:
Starter for using Spring Security's OAuth2 resource server features License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/boot/spring-boot-starter-oauth2-resource-server/2.5.6/spring-boot-starter-oauth2-resource-server-2.5.6.jar
MD5: 13f63195760b5481d44ee2dc8b61067e
SHA1: 1f67981948d55874cef17008d3506cb2ddbf7ee2
SHA256: 92c38b42aa5c074f9ddd4cde36f7be202591697c44b31834533339dbc411156e
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid springframework.boot Highest Vendor Manifest spring-boot-jar-type dependencies-starter Low Vendor pom groupid org.springframework.boot Highest Vendor pom artifactid spring-boot-starter-oauth2-resource-server Low Vendor hint analyzer vendor SpringSource Highest Vendor pom name spring-boot-starter-oauth2-resource-server High Vendor hint analyzer vendor pivotal software Highest Vendor pom url https://spring.io/projects/spring-boot Highest Vendor pom organization url https://spring.io Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor file name spring-boot-starter-oauth2-resource-server High Vendor hint analyzer vendor vmware Highest Vendor Manifest automatic-module-name spring.boot.starter.oauth2.resource.server Medium Vendor pom organization name Pivotal Software, Inc. High Product pom groupid springframework.boot Highest Product Manifest build-jdk-spec 1.8 Low Product file name spring-boot-starter-oauth2-resource-server High Product Manifest spring-boot-jar-type dependencies-starter Low Product pom organization name Pivotal Software, Inc. Low Product pom organization url https://spring.io Low Product pom name spring-boot-starter-oauth2-resource-server High Product Manifest automatic-module-name spring.boot.starter.oauth2.resource.server Medium Product Manifest Implementation-Title Starter for using Spring Security's OAuth2 resource server features High Product pom artifactid spring-boot-starter-oauth2-resource-server Highest Product pom url https://spring.io/projects/spring-boot Medium Version Manifest Implementation-Version 2.5.6 High Version pom version 2.5.6 Highest Version file version 2.5.6 High
spring-boot-starter-security-2.5.6.jarDescription:
Starter for using Spring Security License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/boot/spring-boot-starter-security/2.5.6/spring-boot-starter-security-2.5.6.jar
MD5: a57ca6bd94dbc3d364c161c10a3249e4
SHA1: af5827b9e08ea631fa213cccd1144fbdfee32896
SHA256: d7ed4280801be5edec8bc8a6aa617d8cd739188e018b8fb31e30c2e20d3c77ba
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest automatic-module-name spring.boot.starter.security Medium Vendor pom groupid springframework.boot Highest Vendor Manifest spring-boot-jar-type dependencies-starter Low Vendor pom artifactid spring-boot-starter-security Low Vendor pom groupid org.springframework.boot Highest Vendor hint analyzer vendor SpringSource Highest Vendor pom name spring-boot-starter-security High Vendor hint analyzer vendor pivotal software Highest Vendor pom url https://spring.io/projects/spring-boot Highest Vendor pom organization url https://spring.io Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor file name spring-boot-starter-security High Vendor hint analyzer vendor vmware Highest Vendor pom organization name Pivotal Software, Inc. High Product Manifest automatic-module-name spring.boot.starter.security Medium Product pom groupid springframework.boot Highest Product Manifest build-jdk-spec 1.8 Low Product pom artifactid spring-boot-starter-security Highest Product Manifest spring-boot-jar-type dependencies-starter Low Product pom organization name Pivotal Software, Inc. Low Product pom organization url https://spring.io Low Product file name spring-boot-starter-security High Product pom name spring-boot-starter-security High Product Manifest Implementation-Title Starter for using Spring Security High Product pom url https://spring.io/projects/spring-boot Medium Version Manifest Implementation-Version 2.5.6 High Version pom version 2.5.6 Highest Version file version 2.5.6 High
spring-boot-starter-tomcat-2.5.6.jarDescription:
Starter for using Tomcat as the embedded servlet container. Default servlet container starter used by spring-boot-starter-web License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/boot/spring-boot-starter-tomcat/2.5.6/spring-boot-starter-tomcat-2.5.6.jar
MD5: f485b483abe867ee78f2c41f399d2fb4
SHA1: 6d1a04a727d9d09b99207864ceb0a4567e53730a
SHA256: 31fb9314ae22bcc1b69697bd812486084940768a9d861799bf9caa5518bbc8c2
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid springframework.boot Highest Vendor file name spring-boot-starter-tomcat High Vendor Manifest spring-boot-jar-type dependencies-starter Low Vendor pom groupid org.springframework.boot Highest Vendor hint analyzer vendor SpringSource Highest Vendor pom artifactid spring-boot-starter-tomcat Low Vendor hint analyzer vendor pivotal software Highest Vendor pom url https://spring.io/projects/spring-boot Highest Vendor pom organization url https://spring.io Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor pom name spring-boot-starter-tomcat High Vendor hint analyzer vendor vmware Highest Vendor pom organization name Pivotal Software, Inc. High Vendor Manifest automatic-module-name spring.boot.starter.tomcat Medium Product pom groupid springframework.boot Highest Product file name spring-boot-starter-tomcat High Product Manifest build-jdk-spec 1.8 Low Product pom name spring-boot-starter-tomcat High Product Manifest spring-boot-jar-type dependencies-starter Low Product pom organization name Pivotal Software, Inc. Low Product pom organization url https://spring.io Low Product Manifest Implementation-Title Starter for using Tomcat as the embedded servlet container. Default servlet container starter used by spring-boot-starter-web High Product pom artifactid spring-boot-starter-tomcat Highest Product pom url https://spring.io/projects/spring-boot Medium Product Manifest automatic-module-name spring.boot.starter.tomcat Medium Version Manifest Implementation-Version 2.5.6 High Version pom version 2.5.6 Highest Version file version 2.5.6 High
spring-boot-starter-web-2.5.6.jarDescription:
Starter for building web, including RESTful, applications using Spring MVC. Uses Tomcat as the default embedded container License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/boot/spring-boot-starter-web/2.5.6/spring-boot-starter-web-2.5.6.jar
MD5: abae630a06a3e6581d9fb93656d18264
SHA1: 46b479490170914f7477b96a21241183b181c24d
SHA256: 2374266336e8852144b0cb7bd149509535bf5dbc6b66b896d5a185d55bb22b5e
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid springframework.boot Highest Vendor Manifest automatic-module-name spring.boot.starter.web Medium Vendor pom name spring-boot-starter-web High Vendor Manifest spring-boot-jar-type dependencies-starter Low Vendor pom groupid org.springframework.boot Highest Vendor hint analyzer vendor SpringSource Highest Vendor file name spring-boot-starter-web High Vendor hint analyzer vendor pivotal software Highest Vendor pom url https://spring.io/projects/spring-boot Highest Vendor pom organization url https://spring.io Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor hint analyzer vendor vmware Highest Vendor pom artifactid spring-boot-starter-web Low Vendor pom organization name Pivotal Software, Inc. High Product pom groupid springframework.boot Highest Product Manifest Implementation-Title Starter for building web, including RESTful, applications using Spring MVC. Uses Tomcat as the default embedded container High Product Manifest automatic-module-name spring.boot.starter.web Medium Product Manifest build-jdk-spec 1.8 Low Product pom name spring-boot-starter-web High Product Manifest spring-boot-jar-type dependencies-starter Low Product pom organization name Pivotal Software, Inc. Low Product pom organization url https://spring.io Low Product pom artifactid spring-boot-starter-web Highest Product file name spring-boot-starter-web High Product pom url https://spring.io/projects/spring-boot Medium Version Manifest Implementation-Version 2.5.6 High Version pom version 2.5.6 Highest Version file version 2.5.6 High
spring-context-5.3.12.jarDescription:
Spring Context License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/spring-context/5.3.12/spring-context-5.3.12.jar
MD5: 43c39504a5f8e00dc94884f264572bd6
SHA1: d5f5f044e05109b7f3337ea2cf692fd62d1ecbb6
SHA256: 719997d09349d26ae2189a7b89958f2c2918bda952da71ef272c8c7a34d412b8
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name context Highest Vendor hint analyzer vendor SpringSource Highest Vendor pom groupid org.springframework Highest Vendor file name spring-context High Vendor pom artifactid spring-context Low Vendor Manifest automatic-module-name spring.context Medium Vendor hint analyzer vendor pivotal software Highest Vendor jar package name springframework Highest Vendor hint analyzer vendor vmware Highest Vendor pom name Spring Context High Vendor pom url spring-projects/spring-framework Highest Vendor pom organization name Spring IO High Vendor pom groupid springframework Highest Vendor pom organization url https://spring.io/projects/spring-framework Medium Product jar package name context Highest Product Manifest Implementation-Title spring-context High Product pom url spring-projects/spring-framework High Product hint analyzer product springsource_spring_framework Highest Product file name spring-context High Product Manifest automatic-module-name spring.context Medium Product pom organization url https://spring.io/projects/spring-framework Low Product pom artifactid spring-context Highest Product jar package name springframework Highest Product pom name Spring Context High Product pom organization name Spring IO Low Product pom groupid springframework Highest Version Manifest Implementation-Version 5.3.12 High Version file version 5.3.12 High Version pom version 5.3.12 Highest
spring-core-5.3.12.jarDescription:
Spring Core License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/spring-core/5.3.12/spring-core-5.3.12.jar
MD5: c081557104b477e4389e695379142e3f
SHA1: 662e6536968246af9baa84fbac2d3eb56a04fda9
SHA256: d8442313d1c028a179915a9fcc1c0814f4afe1cca6adf85776ce25636afb5416
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom name Spring Core High Vendor hint analyzer vendor SpringSource Highest Vendor pom groupid org.springframework Highest Vendor hint analyzer vendor pivotal software Highest Vendor pom artifactid spring-core Low Vendor jar package name io Highest Vendor jar package name springframework Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name core Highest Vendor pom url spring-projects/spring-framework Highest Vendor pom organization name Spring IO High Vendor file name spring-core High Vendor pom groupid springframework Highest Vendor pom organization url https://spring.io/projects/spring-framework Medium Vendor Manifest automatic-module-name spring.core Medium Product pom name Spring Core High Product pom url spring-projects/spring-framework High Product hint analyzer product springsource_spring_framework Highest Product pom artifactid spring-core Highest Product pom organization url https://spring.io/projects/spring-framework Low Product jar package name io Highest Product jar package name springframework Highest Product jar package name core Highest Product pom organization name Spring IO Low Product file name spring-core High Product pom groupid springframework Highest Product Manifest Implementation-Title spring-core High Product Manifest automatic-module-name spring.core Medium Version Manifest Implementation-Version 5.3.12 High Version file version 5.3.12 High Version pom version 5.3.12 Highest
spring-expression-5.3.12.jarDescription:
Spring Expression Language (SpEL) License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/spring-expression/5.3.12/spring-expression-5.3.12.jar
MD5: e6d640e68a84f185c6463666f474c0f7
SHA1: 50c82e995b3b8e20a3f313b4356237db5a26e14a
SHA256: a173fb51e241bebbcf07e23ae575b892cba478552ced848a7ad706f616ef0fe1
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid spring-expression Low Vendor pom name Spring Expression Language (SpEL) High Vendor hint analyzer vendor SpringSource Highest Vendor pom groupid org.springframework Highest Vendor jar package name spel Highest Vendor hint analyzer vendor pivotal software Highest Vendor jar package name expression Highest Vendor jar package name springframework Highest Vendor hint analyzer vendor vmware Highest Vendor Manifest automatic-module-name spring.expression Medium Vendor pom url spring-projects/spring-framework Highest Vendor pom organization name Spring IO High Vendor file name spring-expression High Vendor pom groupid springframework Highest Vendor pom organization url https://spring.io/projects/spring-framework Medium Product pom artifactid spring-expression Highest Product pom name Spring Expression Language (SpEL) High Product pom url spring-projects/spring-framework High Product hint analyzer product springsource_spring_framework Highest Product jar package name spel Highest Product jar package name expression Highest Product pom organization url https://spring.io/projects/spring-framework Low Product jar package name springframework Highest Product Manifest Implementation-Title spring-expression High Product Manifest automatic-module-name spring.expression Medium Product pom organization name Spring IO Low Product file name spring-expression High Product pom groupid springframework Highest Version Manifest Implementation-Version 5.3.12 High Version file version 5.3.12 High Version pom version 5.3.12 Highest
spring-hateoas-1.3.5.jarDescription:
Library to support implementing representations for
hyper-text driven REST web services.
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/hateoas/spring-hateoas/1.3.5/spring-hateoas-1.3.5.jar
MD5: aff79183329ba23793824c2e0125432e
SHA1: fa1149021856e8dc62125058dd966490d03915b5
SHA256: 14ba3d086e93a9c0602e9af77e5bc87171c57a84abdcee1d46973852194a27b9
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name support Highest Vendor hint analyzer vendor SpringSource Highest Vendor Manifest automatic-module-name spring.hateoas Medium Vendor pom url spring-projects/spring-hateoas Highest Vendor hint analyzer vendor pivotal software Highest Vendor pom artifactid spring-hateoas Low Vendor pom organization name Pivotal, Inc. High Vendor pom groupid org.springframework.hateoas Highest Vendor jar package name hateoas Highest Vendor file name spring-hateoas High Vendor jar package name springframework Highest Vendor hint analyzer vendor vmware Highest Vendor pom name Spring HATEOAS High Vendor pom groupid springframework.hateoas Highest Vendor pom organization url https://www.spring.io Medium Product jar package name support Highest Product pom artifactid spring-hateoas Highest Product pom url spring-projects/spring-hateoas High Product pom organization url https://www.spring.io Low Product Manifest Implementation-Title Spring HATEOAS High Product Manifest automatic-module-name spring.hateoas Medium Product pom organization name Pivotal, Inc. Low Product jar package name hateoas Highest Product file name spring-hateoas High Product jar package name springframework Highest Product pom name Spring HATEOAS High Product pom groupid springframework.hateoas Highest Version Manifest Implementation-Version 1.3.5 High Version file version 1.3.5 High Version pom version 1.3.5 Highest
spring-jcl-5.3.12.jarDescription:
Spring Commons Logging Bridge License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/spring-jcl/5.3.12/spring-jcl-5.3.12.jar
MD5: 12e1e7dc6be3dbe9efd7d80a520f9235
SHA1: 2b5f5bb4a78af879bd174ceff5226da3f014ab9d
SHA256: d638106092147f89d157d002addc7f9ce2dc0350440915176ed30f6047a9ff53
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor hint analyzer vendor SpringSource Highest Vendor pom groupid org.springframework Highest Vendor jar package name logging Highest Vendor Manifest automatic-module-name spring.jcl Medium Vendor jar package name commons Highest Vendor pom artifactid spring-jcl Low Vendor hint analyzer vendor pivotal software Highest Vendor pom name Spring Commons Logging Bridge High Vendor file name spring-jcl High Vendor hint analyzer vendor vmware Highest Vendor pom url spring-projects/spring-framework Highest Vendor pom organization name Spring IO High Vendor pom groupid springframework Highest Vendor pom organization url https://spring.io/projects/spring-framework Medium Product pom url spring-projects/spring-framework High Product hint analyzer product springsource_spring_framework Highest Product jar package name logging Highest Product Manifest automatic-module-name spring.jcl Medium Product jar package name commons Highest Product pom organization url https://spring.io/projects/spring-framework Low Product pom name Spring Commons Logging Bridge High Product file name spring-jcl High Product Manifest Implementation-Title spring-jcl High Product pom artifactid spring-jcl Highest Product pom organization name Spring IO Low Product pom groupid springframework Highest Version Manifest Implementation-Version 5.3.12 High Version file version 5.3.12 High Version pom version 5.3.12 Highest
spring-plugin-core-2.0.0.RELEASE.jarDescription:
Core plugin infrastructure File Path: /home/jenkins/.mvnrepository/org/springframework/plugin/spring-plugin-core/2.0.0.RELEASE/spring-plugin-core-2.0.0.RELEASE.jarMD5: a89cd7b77db3ed7d0c9ea71ee9784e2eSHA1: 95fc8c13037630f4aba9c51141f535becec00fe6SHA256: 6e6d026d6b572495533692173a264c6959f48d5ef7f3d6faf4555a577d4a38d2Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid org.springframework.plugin Highest Vendor file name spring-plugin-core High Vendor hint analyzer vendor SpringSource Highest Vendor pom name Spring Plugin - Core High Vendor pom parent-artifactid spring-plugin Low Vendor pom parent-groupid org.springframework.plugin Medium Vendor hint analyzer vendor pivotal software Highest Vendor jar package name springframework Highest Vendor hint analyzer vendor vmware Highest Vendor pom groupid springframework.plugin Highest Vendor pom artifactid spring-plugin-core Low Vendor jar package name core Highest Vendor jar package name plugin Highest Vendor Manifest automatic-module-name spring.plugin.core Medium Product file name spring-plugin-core High Product pom parent-artifactid spring-plugin Medium Product jar package name springframework Highest Product pom groupid springframework.plugin Highest Product pom name Spring Plugin - Core High Product jar package name core Highest Product Manifest Implementation-Title Spring Plugin - Core High Product jar package name plugin Highest Product Manifest automatic-module-name spring.plugin.core Medium Product pom parent-groupid org.springframework.plugin Medium Product pom artifactid spring-plugin-core Highest Version Manifest Implementation-Version 2.0.0.RELEASE High Version pom version 2.0.0.RELEASE Highest
spring-security-config-5.5.3.jarDescription:
Spring Security License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/security/spring-security-config/5.5.3/spring-security-config-5.5.3.jar
MD5: 62cabeb1ce90745553211ee0d538a0e2
SHA1: 106b6a1af7460d64fab64ba5bbfe3f52f0eec139
SHA256: cc2adfa29a3451fe9a3c3162c750443d57e5b9acbfd6d3d215a14d803c779c2f
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid springframework.security Highest Vendor pom url https://spring.io/projects/spring-security Highest Vendor hint analyzer vendor SpringSource Highest Vendor pom name spring-security-config High Vendor pom groupid org.springframework.security Highest Vendor hint analyzer vendor pivotal software Highest Vendor pom artifactid spring-security-config Low Vendor pom organization url https://spring.io Medium Vendor jar package name security Highest Vendor jar package name config Highest Vendor jar package name springframework Highest Vendor hint analyzer vendor vmware Highest Vendor Manifest automatic-module-name spring.security.config Medium Vendor file name spring-security-config High Vendor pom organization name Pivotal Software, Inc. High Product pom groupid springframework.security Highest Product pom organization url https://spring.io Low Product pom name spring-security-config High Product pom artifactid spring-security-config Highest Product jar package name security Highest Product pom organization name Pivotal Software, Inc. Low Product pom url https://spring.io/projects/spring-security Medium Product jar package name config Highest Product jar package name springframework Highest Product Manifest automatic-module-name spring.security.config Medium Product file name spring-security-config High Product Manifest Implementation-Title spring-security-config High Version pom version 5.5.3 Highest Version file version 5.5.3 High Version Manifest Implementation-Version 5.5.3 High
spring-security-core-5.5.3.jarDescription:
Spring Security License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/security/spring-security-core/5.5.3/spring-security-core-5.5.3.jar
MD5: f2b8304a5c8bf5515c8ac41b57feb1ba
SHA1: 82152ffbb7d248e0903732c74e1578317d8dc8de
SHA256: f93c2e7b6e8a28107e983d7cad45836b52e8eec7651a83ef6dd2e97bc7ea7487
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid springframework.security Highest Vendor pom url https://spring.io/projects/spring-security Highest Vendor hint analyzer vendor SpringSource Highest Vendor pom groupid org.springframework.security Highest Vendor hint analyzer vendor pivotal software Highest Vendor Manifest automatic-module-name spring.security.core Medium Vendor pom organization url https://spring.io Medium Vendor file name spring-security-core High Vendor jar package name security Highest Vendor jar package name springframework Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name core Highest Vendor pom artifactid spring-security-core Low Vendor pom organization name Pivotal Software, Inc. High Vendor pom name spring-security-core High Product pom groupid springframework.security Highest Product pom organization url https://spring.io Low Product Manifest automatic-module-name spring.security.core Medium Product file name spring-security-core High Product Manifest Implementation-Title spring-security-core High Product jar package name security Highest Product pom organization name Pivotal Software, Inc. Low Product pom url https://spring.io/projects/spring-security Medium Product jar package name springframework Highest Product jar package name core Highest Product pom artifactid spring-security-core Highest Product pom name spring-security-core High Version pom version 5.5.3 Highest Version file version 5.5.3 High Version Manifest Implementation-Version 5.5.3 High
spring-security-crypto-5.5.3.jarDescription:
Spring Security License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/security/spring-security-crypto/5.5.3/spring-security-crypto-5.5.3.jar
MD5: 99a0df99dbdf76e06cb1d0483c7efc33
SHA1: 45fc09a7a2484ef843a9db4652e6ff984bc2e537
SHA256: fe205ca5abe5086c0eec259d80c1354d5421a9f08ed9770d8ee736f46106b4e3
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid springframework.security Highest Vendor pom url https://spring.io/projects/spring-security Highest Vendor hint analyzer vendor SpringSource Highest Vendor pom groupid org.springframework.security Highest Vendor file name spring-security-crypto High Vendor Manifest automatic-module-name spring.security.crypto Medium Vendor hint analyzer vendor pivotal software Highest Vendor pom organization url https://spring.io Medium Vendor jar package name security Highest Vendor jar package name springframework Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name crypto Highest Vendor pom organization name Pivotal Software, Inc. High Vendor pom artifactid spring-security-crypto Low Vendor pom name spring-security-crypto High Product pom groupid springframework.security Highest Product pom artifactid spring-security-crypto Highest Product pom organization url https://spring.io Low Product file name spring-security-crypto High Product Manifest automatic-module-name spring.security.crypto Medium Product Manifest Implementation-Title spring-security-crypto High Product jar package name security Highest Product pom organization name Pivotal Software, Inc. Low Product pom url https://spring.io/projects/spring-security Medium Product jar package name springframework Highest Product jar package name crypto Highest Product pom name spring-security-crypto High Version pom version 5.5.3 Highest Version file version 5.5.3 High Version Manifest Implementation-Version 5.5.3 High
spring-security-jwt-1.1.1.RELEASE.jarDescription:
Spring Security JWT is a small utility library for encoding and decoding JSON Web Tokens.
It belongs to the family of Spring Security crypto libraries that handle encoding and decoding text as
a general, useful thing to be able to do. License:
Apache 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/org/springframework/security/spring-security-jwt/1.1.1.RELEASE/spring-security-jwt-1.1.1.RELEASE.jar
MD5: 703d7744e66813c46202efbbf645ac8e
SHA1: 32a64cdbe06b8aa8fe98e59689cf0c377725868b
SHA256: acc5a1e0eeeffde0d7b8a18cdbe3245915e00203f90e98db7f3b7dbdeea75e5a
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid springframework.security Highest Vendor jar package name jwt Low Vendor pom artifactid spring-security-jwt Low Vendor hint analyzer vendor SpringSource Highest Vendor jar package name jwt Highest Vendor pom url spring-projects/spring-security-oauth Highest Vendor pom groupid org.springframework.security Highest Vendor file name spring-security-jwt High Vendor hint analyzer vendor pivotal software Highest Vendor pom organization name SpringSource High Vendor jar package name security Highest Vendor jar package name springframework Highest Vendor hint analyzer vendor vmware Highest Vendor pom organization url https://www.springsource.com Medium Vendor pom name Spring Security JWT Library High Vendor jar package name crypto Highest Vendor jar package name springframework Low Vendor jar package name security Low Product pom groupid springframework.security Highest Product jar package name jwt Low Product pom artifactid spring-security-jwt Highest Product pom organization url https://www.springsource.com Low Product jar package name jwt Highest Product file name spring-security-jwt High Product pom url spring-projects/spring-security-oauth High Product pom organization name SpringSource Low Product jar package name security Highest Product jar package name springframework Highest Product pom name Spring Security JWT Library High Product jar package name crypto Highest Product jar package name security Low Version pom version 1.1.1.RELEASE Highest
spring-security-oauth2-2.5.0.RELEASE.jarDescription:
Module for providing OAuth2 support to Spring Security File Path: /home/jenkins/.mvnrepository/org/springframework/security/oauth/spring-security-oauth2/2.5.0.RELEASE/spring-security-oauth2-2.5.0.RELEASE.jarMD5: 24f3fb1f36d13103e0e5d65c0309d4d0SHA1: 853f4c0e69d4690be4fff0c3dee8f696dd017373SHA256: 161284e83cefdb54d4f152757f7f63d4e9d8b40967f4f4cd98c1b858dab3561aReferenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor hint analyzer vendor SpringSource Highest Vendor jar package name oauth2 Low Vendor pom parent-artifactid spring-security-oauth-parent Low Vendor hint analyzer vendor pivotal software Highest Vendor pom parent-groupid org.springframework.security.oauth Medium Vendor pom artifactid spring-security-oauth2 Low Vendor pom groupid org.springframework.security.oauth Highest Vendor jar package name security Highest Vendor jar package name springframework Highest Vendor hint analyzer vendor vmware Highest Vendor pom name OAuth2 for Spring Security High Vendor file name spring-security-oauth2 High Vendor pom groupid springframework.security.oauth Highest Vendor jar package name oauth2 Highest Vendor jar package name springframework Low Vendor jar package name security Low Product pom artifactid spring-security-oauth2 Highest Product jar package name security Highest Product jar package name springframework Highest Product pom name OAuth2 for Spring Security High Product file name spring-security-oauth2 High Product jar package name oauth2 Low Product pom groupid springframework.security.oauth Highest Product jar package name oauth2 Highest Product pom parent-artifactid spring-security-oauth-parent Medium Product jar package name security Low Product pom parent-groupid org.springframework.security.oauth Medium Version pom version 2.5.0.RELEASE Highest
spring-security-oauth2-autoconfigure-2.5.6.jarDescription:
spring-security-oauth2-autoconfigure License:
The Apache Software License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/org/springframework/security/oauth/boot/spring-security-oauth2-autoconfigure/2.5.6/spring-security-oauth2-autoconfigure-2.5.6.jar
MD5: ecff8a2fad8994cce5d7529dcd792da1
SHA1: 7cee8bead4415bf621b6d3d85c37ca38f274bf58
SHA256: b7ab3026575cf57323f8512888fdedad76f740263c614b63145ee40f3af54f4f
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom artifactid spring-security-oauth2-autoconfigure Low Vendor pom name spring-security-oauth2-autoconfigure High Vendor hint analyzer vendor SpringSource Highest Vendor jar package name boot Highest Vendor pom organization url https://spring.io/ Medium Vendor hint analyzer vendor pivotal software Highest Vendor pom groupid springframework.security.oauth.boot Highest Vendor pom organization name spring.io High Vendor jar package name security Highest Vendor Manifest automatic-module-name spring.security.oauth2.autoconfigure Medium Vendor jar package name autoconfigure Highest Vendor jar package name springframework Highest Vendor pom url https://spring.io/spring-security Highest Vendor hint analyzer vendor vmware Highest Vendor file name spring-security-oauth2-autoconfigure High Vendor pom groupid org.springframework.security.oauth.boot Highest Product pom organization name spring.io Low Product pom url https://spring.io/spring-security Medium Product pom name spring-security-oauth2-autoconfigure High Product jar package name boot Highest Product pom artifactid spring-security-oauth2-autoconfigure Highest Product Manifest Implementation-Title spring-security-oauth2-autoconfigure High Product pom groupid springframework.security.oauth.boot Highest Product jar package name security Highest Product jar package name autoconfigure Highest Product Manifest automatic-module-name spring.security.oauth2.autoconfigure Medium Product jar package name springframework Highest Product file name spring-security-oauth2-autoconfigure High Product pom organization url https://spring.io/ Low Version Manifest Implementation-Version 2.5.6 High Version pom version 2.5.6 Highest Version file version 2.5.6 High
spring-security-oauth2-core-5.5.3.jarDescription:
Spring Security License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/security/spring-security-oauth2-core/5.5.3/spring-security-oauth2-core-5.5.3.jar
MD5: d62042b633e33ae241f77171f1c27240
SHA1: ba885b53d35458455d3e817488be616dbcc97f88
SHA256: d2694dced57880f68221a4c993e641cd6408788af47029156c92f11e45216650
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid springframework.security Highest Vendor pom url https://spring.io/projects/spring-security Highest Vendor pom artifactid spring-security-oauth2-core Low Vendor file name spring-security-oauth2-core High Vendor hint analyzer vendor SpringSource Highest Vendor pom groupid org.springframework.security Highest Vendor hint analyzer vendor pivotal software Highest Vendor pom organization url https://spring.io Medium Vendor jar package name security Highest Vendor jar package name springframework Highest Vendor hint analyzer vendor vmware Highest Vendor pom name spring-security-oauth2-core High Vendor Manifest automatic-module-name spring.security.oauth2.core Medium Vendor jar package name core Highest Vendor jar package name oauth2 Highest Vendor pom organization name Pivotal Software, Inc. High Product pom groupid springframework.security Highest Product pom artifactid spring-security-oauth2-core Highest Product file name spring-security-oauth2-core High Product pom organization url https://spring.io Low Product jar package name security Highest Product pom organization name Pivotal Software, Inc. Low Product pom url https://spring.io/projects/spring-security Medium Product jar package name springframework Highest Product pom name spring-security-oauth2-core High Product Manifest automatic-module-name spring.security.oauth2.core Medium Product Manifest Implementation-Title spring-security-oauth2-core High Product jar package name core Highest Product jar package name oauth2 Highest Version pom version 5.5.3 Highest Version file version 5.5.3 High Version Manifest Implementation-Version 5.5.3 High
spring-security-oauth2-jose-5.5.3.jarDescription:
Spring Security License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/security/spring-security-oauth2-jose/5.5.3/spring-security-oauth2-jose-5.5.3.jar
MD5: 15cfe75bd0bb4768a371f7b8565e10b7
SHA1: 16692b027d0b8f348d71e6fd06f065a97fcfcfb8
SHA256: c30bfaa30b8343fd53d4e822efbf2b0cd81c73e05644ba289ee2c3a67eed7d46
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name jose Highest Vendor pom groupid springframework.security Highest Vendor pom url https://spring.io/projects/spring-security Highest Vendor hint analyzer vendor SpringSource Highest Vendor pom groupid org.springframework.security Highest Vendor pom artifactid spring-security-oauth2-jose Low Vendor hint analyzer vendor pivotal software Highest Vendor pom name spring-security-oauth2-jose High Vendor Manifest automatic-module-name spring.security.oauth2.jose Medium Vendor pom organization url https://spring.io Medium Vendor jar package name security Highest Vendor jar package name springframework Highest Vendor hint analyzer vendor vmware Highest Vendor jar package name oauth2 Highest Vendor file name spring-security-oauth2-jose High Vendor pom organization name Pivotal Software, Inc. High Product Manifest Implementation-Title spring-security-oauth2-jose High Product jar package name jose Highest Product pom groupid springframework.security Highest Product pom organization url https://spring.io Low Product pom artifactid spring-security-oauth2-jose Highest Product pom name spring-security-oauth2-jose High Product Manifest automatic-module-name spring.security.oauth2.jose Medium Product jar package name security Highest Product pom organization name Pivotal Software, Inc. Low Product pom url https://spring.io/projects/spring-security Medium Product jar package name springframework Highest Product jar package name oauth2 Highest Product file name spring-security-oauth2-jose High Version pom version 5.5.3 Highest Version file version 5.5.3 High Version Manifest Implementation-Version 5.5.3 High
spring-security-oauth2-resource-server-5.5.3.jarDescription:
Spring Security License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/security/spring-security-oauth2-resource-server/5.5.3/spring-security-oauth2-resource-server-5.5.3.jar
MD5: 1d7ffe49c780a03c1052b3d73c3c7d56
SHA1: 44ae67c07e247d1a048bc5210534f24c933ade46
SHA256: a5d7bb257200f7f8670cd68c0c11fa4f84f003ca4f9d96c5cf2bbeea36824e7a
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid springframework.security Highest Vendor pom url https://spring.io/projects/spring-security Highest Vendor pom name spring-security-oauth2-resource-server High Vendor hint analyzer vendor SpringSource Highest Vendor pom groupid org.springframework.security Highest Vendor hint analyzer vendor pivotal software Highest Vendor jar package name server Highest Vendor pom organization url https://spring.io Medium Vendor file name spring-security-oauth2-resource-server High Vendor jar package name security Highest Vendor jar package name springframework Highest Vendor hint analyzer vendor vmware Highest Vendor Manifest automatic-module-name spring.security.oauth2.resource.server Medium Vendor jar package name oauth2 Highest Vendor pom organization name Pivotal Software, Inc. High Vendor pom artifactid spring-security-oauth2-resource-server Low Product pom groupid springframework.security Highest Product pom name spring-security-oauth2-resource-server High Product pom organization url https://spring.io Low Product pom artifactid spring-security-oauth2-resource-server Highest Product jar package name server Highest Product Manifest Implementation-Title spring-security-oauth2-resource-server High Product file name spring-security-oauth2-resource-server High Product jar package name security Highest Product pom organization name Pivotal Software, Inc. Low Product pom url https://spring.io/projects/spring-security Medium Product jar package name springframework Highest Product Manifest automatic-module-name spring.security.oauth2.resource.server Medium Product jar package name oauth2 Highest Version pom version 5.5.3 Highest Version file version 5.5.3 High Version Manifest Implementation-Version 5.5.3 High
spring-security-web-5.5.3.jarDescription:
Spring Security License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/security/spring-security-web/5.5.3/spring-security-web-5.5.3.jar
MD5: da65178f71a882657df61b5e4610f3d8
SHA1: 2d2b773e2af5b5984852db8857a77175ce4e1104
SHA256: 27ec26414a4e60cdf0a5405ae2a7a90bf53b08ccc232670370ca1657490e87b7
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid springframework.security Highest Vendor pom url https://spring.io/projects/spring-security Highest Vendor jar package name web Highest Vendor hint analyzer vendor SpringSource Highest Vendor pom groupid org.springframework.security Highest Vendor pom artifactid spring-security-web Low Vendor pom name spring-security-web High Vendor hint analyzer vendor pivotal software Highest Vendor Manifest automatic-module-name spring.security.web Medium Vendor pom organization url https://spring.io Medium Vendor jar package name security Highest Vendor file name spring-security-web High Vendor jar package name springframework Highest Vendor hint analyzer vendor vmware Highest Vendor pom organization name Pivotal Software, Inc. High Product pom groupid springframework.security Highest Product jar package name web Highest Product pom organization url https://spring.io Low Product pom artifactid spring-security-web Highest Product pom name spring-security-web High Product Manifest automatic-module-name spring.security.web Medium Product jar package name security Highest Product pom organization name Pivotal Software, Inc. Low Product pom url https://spring.io/projects/spring-security Medium Product file name spring-security-web High Product jar package name springframework Highest Product Manifest Implementation-Title spring-security-web High Version pom version 5.5.3 Highest Version file version 5.5.3 High Version Manifest Implementation-Version 5.5.3 High
spring-web-5.3.12.jarDescription:
Spring Web License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/spring-web/5.3.12/spring-web-5.3.12.jar
MD5: e5ae6d9d2041baa1cae562f4e1bec16b
SHA1: 78991a50d17da49bddc4987a2cc8b83d46c402a7
SHA256: 0eb6a5643098a163dcb6e33b690d8441cee5a2d9e908e6723c860a11fdf5d125
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name web Highest Vendor hint analyzer vendor SpringSource Highest Vendor pom groupid org.springframework Highest Vendor pom name Spring Web High Vendor file name spring-web High Vendor hint analyzer vendor pivotal software Highest Vendor jar package name springframework Highest Vendor hint analyzer vendor vmware Highest Vendor pom artifactid spring-web Low Vendor pom url spring-projects/spring-framework Highest Vendor pom organization name Spring IO High Vendor Manifest automatic-module-name spring.web Medium Vendor pom groupid springframework Highest Vendor pom organization url https://spring.io/projects/spring-framework Medium Product Manifest Implementation-Title spring-web High Product jar package name web Highest Product pom url spring-projects/spring-framework High Product hint analyzer product springsource_spring_framework Highest Product pom name Spring Web High Product file name spring-web High Product pom organization url https://spring.io/projects/spring-framework Low Product jar package name springframework Highest Product pom organization name Spring IO Low Product pom artifactid spring-web Highest Product Manifest automatic-module-name spring.web Medium Product pom groupid springframework Highest Version Manifest Implementation-Version 5.3.12 High Version file version 5.3.12 High Version pom version 5.3.12 Highest
spring-webmvc-5.3.12.jarDescription:
Spring Web MVC License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0 File Path: /home/jenkins/.mvnrepository/org/springframework/spring-webmvc/5.3.12/spring-webmvc-5.3.12.jar
MD5: 55068f0b241a110cc116fbcec6926a04
SHA1: 3d92ad6c28bfa5923183f328f5bfa1e39ec32714
SHA256: d6c6567c04ebfcc9605dfe105817427eda3d8583b98c32b6a4eed802da843836
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name web Highest Vendor hint analyzer vendor SpringSource Highest Vendor pom groupid org.springframework Highest Vendor file name spring-webmvc High Vendor pom name Spring Web MVC High Vendor hint analyzer vendor pivotal software Highest Vendor pom artifactid spring-webmvc Low Vendor jar package name springframework Highest Vendor hint analyzer vendor vmware Highest Vendor Manifest automatic-module-name spring.webmvc Medium Vendor jar package name mvc Highest Vendor pom url spring-projects/spring-framework Highest Vendor pom organization name Spring IO High Vendor pom groupid springframework Highest Vendor pom organization url https://spring.io/projects/spring-framework Medium Product jar package name web Highest Product Manifest Implementation-Title spring-webmvc High Product pom url spring-projects/spring-framework High Product hint analyzer product springsource_spring_framework Highest Product file name spring-webmvc High Product pom name Spring Web MVC High Product pom organization url https://spring.io/projects/spring-framework Low Product pom artifactid spring-webmvc Highest Product jar package name springframework Highest Product Manifest automatic-module-name spring.webmvc Medium Product jar package name mvc Highest Product pom organization name Spring IO Low Product pom groupid springframework Highest Version Manifest Implementation-Version 5.3.12 High Version file version 5.3.12 High Version pom version 5.3.12 Highest
springdoc-openapi-common-1.5.11.jarFile Path: /home/jenkins/.mvnrepository/org/springdoc/springdoc-openapi-common/1.5.11/springdoc-openapi-common-1.5.11.jarMD5: 85b8411e7e2c553955ef684e26eac165SHA1: b894394e678e7fc1693de64f8b9333cdc46020e4SHA256: 00220d4b9a7cef122bac8afbef5c34d95ad113ba7f7f62286ff11529cb2dac6cReferenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest build-jdk-spec 11 Low Vendor pom parent-groupid org.springdoc Medium Vendor pom parent-artifactid springdoc-openapi Low Vendor file name springdoc-openapi-common High Vendor pom groupid springdoc Highest Vendor pom groupid org.springdoc Highest Vendor Manifest automatic-module-name org.springdoc.openapi.common Medium Vendor pom artifactid springdoc-openapi-common Low Vendor jar package name springdoc Highest Product Manifest build-jdk-spec 11 Low Product pom parent-groupid org.springdoc Medium Product pom artifactid springdoc-openapi-common Highest Product file name springdoc-openapi-common High Product pom groupid springdoc Highest Product Manifest Implementation-Title springdoc-openapi-common High Product pom parent-artifactid springdoc-openapi Medium Product Manifest automatic-module-name org.springdoc.openapi.common Medium Product jar package name springdoc Highest Version Manifest Implementation-Version 1.5.11 High Version file version 1.5.11 High Version pom version 1.5.11 Highest
springdoc-openapi-ui-1.5.11.jarFile Path: /home/jenkins/.mvnrepository/org/springdoc/springdoc-openapi-ui/1.5.11/springdoc-openapi-ui-1.5.11.jarMD5: 6d8b59b20fde8087bba428bbdc9b63aaSHA1: dd3f7cb89154683bee6fb440b9b9854cc962c1d1SHA256: 05674afc536272946f7d5bf759577dc3319c7fbd7ea11c001c6ae4cf2adbf293Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest automatic-module-name org.springdoc.openapi.ui Medium Vendor Manifest build-jdk-spec 1.8 Low Vendor pom parent-groupid org.springdoc Medium Vendor pom parent-artifactid springdoc-openapi Low Vendor file name springdoc-openapi-ui High Vendor pom groupid springdoc Highest Vendor pom groupid org.springdoc Highest Vendor jar package name ui Highest Vendor pom artifactid springdoc-openapi-ui Low Vendor jar package name springdoc Highest Product Manifest automatic-module-name org.springdoc.openapi.ui Medium Product Manifest build-jdk-spec 1.8 Low Product pom parent-groupid org.springdoc Medium Product file name springdoc-openapi-ui High Product pom artifactid springdoc-openapi-ui Highest Product Manifest Implementation-Title springdoc-openapi-ui High Product pom groupid springdoc Highest Product pom parent-artifactid springdoc-openapi Medium Product jar package name ui Highest Product jar package name springdoc Highest Version Manifest Implementation-Version 1.5.11 High Version file version 1.5.11 High Version pom version 1.5.11 Highest
springdoc-openapi-webmvc-core-1.5.11.jarFile Path: /home/jenkins/.mvnrepository/org/springdoc/springdoc-openapi-webmvc-core/1.5.11/springdoc-openapi-webmvc-core-1.5.11.jarMD5: 6e5942ab387ac6bb95d7069578610ca0SHA1: 25afdfba1b5b9f42044e8d48d6b0b0c5d53837dbSHA256: 0548a95bef267edd1383e3ec1fe174f32722d5bc1300c08b6789d4648caa886cReferenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor file name springdoc-openapi-webmvc-core High Vendor Manifest build-jdk-spec 1.8 Low Vendor pom parent-groupid org.springdoc Medium Vendor pom parent-artifactid springdoc-openapi Low Vendor jar package name webmvc Highest Vendor pom groupid springdoc Highest Vendor pom artifactid springdoc-openapi-webmvc-core Low Vendor pom groupid org.springdoc Highest Vendor jar package name core Highest Vendor Manifest automatic-module-name org.springdoc.openapi.webmvc.core Medium Vendor jar package name springdoc Highest Product file name springdoc-openapi-webmvc-core High Product Manifest build-jdk-spec 1.8 Low Product pom parent-groupid org.springdoc Medium Product jar package name webmvc Highest Product pom groupid springdoc Highest Product jar package name core Highest Product pom parent-artifactid springdoc-openapi Medium Product Manifest automatic-module-name org.springdoc.openapi.webmvc.core Medium Product pom artifactid springdoc-openapi-webmvc-core Highest Product Manifest Implementation-Title springdoc-openapi-webmvc-core High Product jar package name springdoc Highest Version Manifest Implementation-Version 1.5.11 High Version file version 1.5.11 High Version pom version 1.5.11 Highest
swagger-annotations-2.1.11.jarDescription:
swagger-annotations License:
"Apache License 2.0";link="http://www.apache.org/licenses/LICENSE-2.0.html" File Path: /home/jenkins/.mvnrepository/io/swagger/core/v3/swagger-annotations/2.1.11/swagger-annotations-2.1.11.jar
MD5: 22875b2e87d5df5c237941b6efeb802f
SHA1: 4a00eee38735189a15fbdfa2169aadbff9c1779a
SHA256: 9b0c7b108a07f1ceafa52eeecfabd1c46dd8f9c3d38f09434fb5863c72220d6c
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest bundle-developers fehguy;email="fehguy@gmail.com";name="Tony Tam",webron;email="webron@gmail.com";name="Ron Ratovsky" Low Vendor jar package name swagger Highest Vendor Manifest automatic-module-name io.swagger.v3.oas.annotations Medium Vendor jar package name v3 Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid swagger-annotations Low Vendor pom name swagger-annotations High Vendor pom parent-artifactid swagger-project Low Vendor Manifest bundle-symbolicname io.swagger.core.v3.swagger-annotations Medium Vendor Manifest mode development Low Vendor pom groupid io.swagger.core.v3 Highest Vendor jar package name oas Highest Vendor jar package name io Highest Vendor Manifest bundle-docurl https://github.com/swagger-api/swagger-core/modules/swagger-annotations Low Vendor file name swagger-annotations High Vendor Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-annotations Low Product Manifest bundle-developers fehguy;email="fehguy@gmail.com";name="Tony Tam",webron;email="webron@gmail.com";name="Ron Ratovsky" Low Product jar package name swagger Highest Product Manifest automatic-module-name io.swagger.v3.oas.annotations Medium Product Manifest Bundle-Name swagger-annotations Medium Product jar package name v3 Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid swagger-annotations Highest Product pom name swagger-annotations High Product Manifest bundle-symbolicname io.swagger.core.v3.swagger-annotations Medium Product Manifest mode development Low Product pom parent-artifactid swagger-project Medium Product pom groupid io.swagger.core.v3 Highest Product jar package name oas Highest Product jar package name io Highest Product Manifest bundle-docurl https://github.com/swagger-api/swagger-core/modules/swagger-annotations Low Product file name swagger-annotations High Product Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-annotations Low Version pom version 2.1.11 Highest Version file version 2.1.11 High Version Manifest implementation-version 2.1.11 High Version Manifest Bundle-Version 2.1.11 High
swagger-core-2.1.11.jarDescription:
swagger-core License:
"Apache License 2.0";link="http://www.apache.org/licenses/LICENSE-2.0.html" File Path: /home/jenkins/.mvnrepository/io/swagger/core/v3/swagger-core/2.1.11/swagger-core-2.1.11.jar
MD5: e9f0b2b493824550eea41ed6a37564be
SHA1: 61bb7d3ecbf9aa84ac4c218c09528d46d8a59119
SHA256: db4af5598192c1bf1106543a56e03ed3698742133fae08580bbf07e0b99cd376
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor file name swagger-core High Vendor Manifest bundle-developers fehguy;email="fehguy@gmail.com";name="Tony Tam",webron;email="webron@gmail.com";name="Ron Ratovsky" Low Vendor jar package name swagger Highest Vendor jar package name v3 Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest bundle-docurl https://github.com/swagger-api/swagger-core/modules/swagger-core Low Vendor pom parent-artifactid swagger-project Low Vendor Manifest mode development Low Vendor pom name swagger-core High Vendor pom groupid io.swagger.core.v3 Highest Vendor Manifest build-jdk-spec 1.8 Low Vendor jar package name io Highest Vendor Manifest bundle-symbolicname io.swagger.core.v3.swagger-core Medium Vendor Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-core Low Vendor Manifest automatic-module-name io.swagger.v3.core Medium Vendor jar package name core Highest Vendor pom artifactid swagger-core Low Product file name swagger-core High Product Manifest bundle-developers fehguy;email="fehguy@gmail.com";name="Tony Tam",webron;email="webron@gmail.com";name="Ron Ratovsky" Low Product jar package name swagger Highest Product jar package name v3 Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest bundle-docurl https://github.com/swagger-api/swagger-core/modules/swagger-core Low Product Manifest mode development Low Product pom parent-artifactid swagger-project Medium Product pom name swagger-core High Product Manifest build-jdk-spec 1.8 Low Product pom groupid io.swagger.core.v3 Highest Product jar package name io Highest Product Manifest bundle-symbolicname io.swagger.core.v3.swagger-core Medium Product Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-core Low Product jar package name core Highest Product Manifest automatic-module-name io.swagger.v3.core Medium Product pom artifactid swagger-core Highest Product Manifest Bundle-Name swagger-core Medium Version pom version 2.1.11 Highest Version file version 2.1.11 High Version Manifest implementation-version 2.1.11 High Version Manifest Bundle-Version 2.1.11 High
swagger-integration-2.1.11.jarDescription:
swagger-integration License:
"Apache License 2.0";link="http://www.apache.org/licenses/LICENSE-2.0.html" File Path: /home/jenkins/.mvnrepository/io/swagger/core/v3/swagger-integration/2.1.11/swagger-integration-2.1.11.jar
MD5: 6b15b92233fc5189eae9a67a269adfe0
SHA1: f21b84e72d479f4032479838a48e2310d83dad22
SHA256: e7965f7aa0ad374663d2c7de982ab1fbc8b8a94db2ca58e367da70d71c4e6bda
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest bundle-symbolicname io.swagger.core.v3.swagger-integration Medium Vendor Manifest bundle-developers fehguy;email="fehguy@gmail.com";name="Tony Tam",webron;email="webron@gmail.com";name="Ron Ratovsky" Low Vendor jar package name swagger Highest Vendor jar package name v3 Highest Vendor file name swagger-integration High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom parent-artifactid swagger-project Low Vendor Manifest mode development Low Vendor pom groupid io.swagger.core.v3 Highest Vendor jar package name oas Highest Vendor pom artifactid swagger-integration Low Vendor jar package name io Highest Vendor pom name swagger-integration High Vendor Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-integration Low Vendor Manifest automatic-module-name io.swagger.v3.oas.integration Medium Vendor Manifest bundle-docurl https://github.com/swagger-api/swagger-core/modules/swagger-integration Low Product Manifest bundle-symbolicname io.swagger.core.v3.swagger-integration Medium Product Manifest bundle-developers fehguy;email="fehguy@gmail.com";name="Tony Tam",webron;email="webron@gmail.com";name="Ron Ratovsky" Low Product jar package name swagger Highest Product jar package name v3 Highest Product file name swagger-integration High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest Bundle-Name swagger-integration Medium Product Manifest mode development Low Product pom artifactid swagger-integration Highest Product pom parent-artifactid swagger-project Medium Product pom groupid io.swagger.core.v3 Highest Product jar package name oas Highest Product jar package name io Highest Product pom name swagger-integration High Product Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-integration Low Product Manifest automatic-module-name io.swagger.v3.oas.integration Medium Product Manifest bundle-docurl https://github.com/swagger-api/swagger-core/modules/swagger-integration Low Version pom version 2.1.11 Highest Version file version 2.1.11 High Version Manifest implementation-version 2.1.11 High Version Manifest Bundle-Version 2.1.11 High
swagger-models-2.1.11.jarDescription:
swagger-models License:
"Apache License 2.0";link="http://www.apache.org/licenses/LICENSE-2.0.html" File Path: /home/jenkins/.mvnrepository/io/swagger/core/v3/swagger-models/2.1.11/swagger-models-2.1.11.jar
MD5: 15c31f78254607fdbd4a44474a817a77
SHA1: 1dc340dedb35c95a6d482f082a37c112d222cabc
SHA256: 0411f0f532d756f39b575a6691b754e3e2be1847b3ddd2fe9bb6191c25119c43
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest bundle-developers fehguy;email="fehguy@gmail.com";name="Tony Tam",webron;email="webron@gmail.com";name="Ron Ratovsky" Low Vendor jar package name swagger Highest Vendor jar package name v3 Highest Vendor pom artifactid swagger-models Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor file name swagger-models High Vendor pom parent-artifactid swagger-project Low Vendor Manifest mode development Low Vendor Manifest bundle-docurl https://github.com/swagger-api/swagger-core/modules/swagger-models Low Vendor Manifest automatic-module-name io.swagger.v3.oas.models Medium Vendor pom groupid io.swagger.core.v3 Highest Vendor jar package name oas Highest Vendor jar package name io Highest Vendor pom name swagger-models High Vendor Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-models Low Vendor Manifest bundle-symbolicname io.swagger.core.v3.swagger-models Medium Product Manifest bundle-developers fehguy;email="fehguy@gmail.com";name="Tony Tam",webron;email="webron@gmail.com";name="Ron Ratovsky" Low Product jar package name swagger Highest Product jar package name v3 Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product file name swagger-models High Product Manifest mode development Low Product Manifest bundle-docurl https://github.com/swagger-api/swagger-core/modules/swagger-models Low Product Manifest automatic-module-name io.swagger.v3.oas.models Medium Product Manifest Bundle-Name swagger-models Medium Product pom parent-artifactid swagger-project Medium Product pom groupid io.swagger.core.v3 Highest Product jar package name oas Highest Product jar package name io Highest Product pom name swagger-models High Product Manifest url https://github.com/swagger-api/swagger-core/modules/swagger-models Low Product Manifest bundle-symbolicname io.swagger.core.v3.swagger-models Medium Product pom artifactid swagger-models Highest Version pom version 2.1.11 Highest Version file version 2.1.11 High Version Manifest implementation-version 2.1.11 High Version Manifest Bundle-Version 2.1.11 High
swagger-ui-3.52.3.jarDescription:
WebJar for Swagger UI License:
Apache 2.0: https://github.com/swagger-api/swagger-ui File Path: /home/jenkins/.mvnrepository/org/webjars/swagger-ui/3.52.3/swagger-ui-3.52.3.jar
MD5: 0b58661d7c45fd8bc89bfc47c803d669
SHA1: fd724ab45bb21a4d93197f1d87e7e4b67406f924
SHA256: 58159e717b88f591b1ace79f0c3b4d034152e12ea6e17ce41bed502f755114dd
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom name Swagger UI High Vendor pom groupid webjars Highest Vendor pom groupid org.webjars Highest Vendor Manifest bundle-symbolicname org.webjars.swagger-ui Medium Vendor file name swagger-ui High Vendor pom artifactid swagger-ui Low Vendor pom url http://webjars.org Highest Product pom name Swagger UI High Product pom groupid webjars Highest Product pom artifactid swagger-ui Highest Product Manifest Bundle-Name Swagger UI Medium Product Manifest bundle-symbolicname org.webjars.swagger-ui Medium Product pom url http://webjars.org Medium Product file name swagger-ui High Version file version 3.52.3 High Version pom version 3.52.3 Highest Version Manifest Bundle-Version 3.52.3 High
tomcat-annotations-api-9.0.54.jarDescription:
Annotations Package License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/org/apache/tomcat/tomcat-annotations-api/9.0.54/tomcat-annotations-api-9.0.54.jar
MD5: 9c9cc210cbd36b5385cfe012d0703c64
SHA1: adcd23cacfcff8775b6ce3f7f44c25c05bea6fdc
SHA256: a4cf43a40fd34cb3f2100b4191fc01374b5a1fd8e2e93d5b46d0dc21f3b19ec7
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest provide-capability osgi.contract;osgi.contract=JavaAnnotation;version:List="1.3,1.2,1.1,1";uses:="javax.annotation,javax.annotation.security,javax.annotation.sql" Low Vendor file name tomcat-annotations-api High Vendor Manifest bundle-symbolicname org.apache.tomcat-annotations-api Medium Vendor manifest: javax/annotation/ Implementation-Vendor Apache Software Foundation Medium Vendor pom groupid apache.tomcat Highest Vendor manifest: javax/annotation/sql/ Implementation-Vendor Apache Software Foundation Medium Vendor pom artifactid tomcat-annotations-api Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor manifest: javax/annotation/security/ Implementation-Vendor Apache Software Foundation Medium Vendor pom url https://tomcat.apache.org/ Highest Vendor pom groupid org.apache.tomcat Highest Product Manifest provide-capability osgi.contract;osgi.contract=JavaAnnotation;version:List="1.3,1.2,1.1,1";uses:="javax.annotation,javax.annotation.security,javax.annotation.sql" Low Product file name tomcat-annotations-api High Product manifest: javax/annotation/ Specification-Title Common Annotations Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product manifest: javax/annotation/security/ Specification-Title Common Annotations Medium Product manifest: javax/annotation/sql/ Specification-Title Common Annotations Medium Product jar package name javax Highest Product jar package name annotation Highest Product pom url https://tomcat.apache.org/ Medium Product pom artifactid tomcat-annotations-api Highest Product jar package name sql Highest Product Manifest bundle-symbolicname org.apache.tomcat-annotations-api Medium Product pom groupid apache.tomcat Highest Product jar package name security Highest Product manifest: javax/annotation/sql/ Implementation-Title javax.annotation Medium Product Manifest Bundle-Name tomcat-annotations-api Medium Product manifest: javax/annotation/security/ Implementation-Title javax.annotation Medium Product manifest: javax/annotation/ Implementation-Title javax.annotation Medium Version Manifest Bundle-Version 9.0.54 High Version pom version 9.0.54 Highest Version file version 9.0.54 High
tomcat-embed-core-9.0.54.jarDescription:
Core Tomcat implementation License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/org/apache/tomcat/embed/tomcat-embed-core/9.0.54/tomcat-embed-core-9.0.54.jar
MD5: 80b9a7093a9fd68742974eb90dfb33ac
SHA1: 34322c731b2394ea13681cfae0be9cd72f46f88d
SHA256: 287f5b91c434df0eef104389c52c480ab4b66f80b494c16607fd82ae9217f8e3
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name tomcat Highest Vendor Manifest Implementation-Vendor Apache Software Foundation High Vendor manifest: javax/servlet/resources/ Implementation-Vendor Apache Software Foundation Medium Vendor pom groupid apache.tomcat.embed Highest Vendor Manifest bundle-symbolicname org.apache.tomcat-embed-core Medium Vendor Manifest specification-vendor Apache Software Foundation Low Vendor manifest: javax/security/auth/message/config/ Implementation-Vendor Apache Software Foundation Medium Vendor Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.processor)(version>=1.0.0)(!(version>=2.0.0)))",osgi.serviceloader;filter:="(osgi.serviceloader=org.apache.juli.logging.Log)";osgi.serviceloader="org.apache.juli.logging.Log",osgi.contract;osgi.contract=JavaAnnotation;filter:="(&(osgi.contract=JavaAnnotation)(version=1.3.0))",osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor manifest: javax/servlet/descriptor/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/servlet/http/ Implementation-Vendor Apache Software Foundation Medium Vendor file name tomcat-embed-core High Vendor manifest: javax/servlet/ Implementation-Vendor Apache Software Foundation Medium Vendor pom groupid org.apache.tomcat.embed Highest Vendor manifest: javax/servlet/annotation/ Implementation-Vendor Apache Software Foundation Medium Vendor manifest: javax/security/auth/message/module/ Implementation-Vendor Apache Software Foundation Medium Vendor jar package name core Highest Vendor Manifest provide-capability osgi.contract;osgi.contract=JavaJASPIC;version:List="1.1,1";uses:="javax.security.auth.message,javax.security.auth.message.callback,javax.security.auth.message.config,javax.security.auth.message.module",osgi.contract;osgi.contract=JavaServlet;version:List="4.0,3.1,3,2.5";uses:="javax.servlet,javax.servlet.annotation,javax.servlet.descriptor,javax.servlet.http,javax.servlet.resources" Low Vendor pom artifactid tomcat-embed-core Low Vendor manifest: javax/security/auth/message/callback/ Implementation-Vendor Apache Software Foundation Medium Vendor pom url https://tomcat.apache.org/ Highest Vendor jar package name apache Highest Vendor manifest: javax/security/auth/message/ Implementation-Vendor Apache Software Foundation Medium Product jar package name juli Highest Product manifest: javax/servlet/ Implementation-Title javax.servlet Medium Product pom groupid apache.tomcat.embed Highest Product jar package name auth Highest Product jar package name message Highest Product jar package name logging Highest Product Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.processor)(version>=1.0.0)(!(version>=2.0.0)))",osgi.serviceloader;filter:="(osgi.serviceloader=org.apache.juli.logging.Log)";osgi.serviceloader="org.apache.juli.logging.Log",osgi.contract;osgi.contract=JavaAnnotation;filter:="(&(osgi.contract=JavaAnnotation)(version=1.3.0))",osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product jar package name descriptor Highest Product manifest: javax/servlet/http/ Specification-Title Java API for Servlets Medium Product jar package name javax Highest Product jar package name annotation Highest Product jar package name java Highest Product jar package name filter Highest Product file name tomcat-embed-core High Product manifest: javax/servlet/descriptor/ Implementation-Title javax.servlet Medium Product manifest: javax/servlet/resources/ Implementation-Title javax.servlet Medium Product jar package name core Highest Product Manifest provide-capability osgi.contract;osgi.contract=JavaJASPIC;version:List="1.1,1";uses:="javax.security.auth.message,javax.security.auth.message.callback,javax.security.auth.message.config,javax.security.auth.message.module",osgi.contract;osgi.contract=JavaServlet;version:List="4.0,3.1,3,2.5";uses:="javax.servlet,javax.servlet.annotation,javax.servlet.descriptor,javax.servlet.http,javax.servlet.resources" Low Product manifest: javax/servlet/ Specification-Title Java API for Servlets Medium Product manifest: javax/servlet/annotation/ Implementation-Title javax.servlet Medium Product jar package name servlet Highest Product manifest: javax/security/auth/message/module/ Specification-Title Java Authentication SPI for Containers Medium Product Manifest Implementation-Title Apache Tomcat High Product jar package name tomcat Highest Product manifest: javax/security/auth/message/config/ Implementation-Title javax.security.auth.message Medium Product jar package name servlets Highest Product manifest: javax/security/auth/message/ Specification-Title Java Authentication SPI for Containers Medium Product manifest: javax/security/auth/message/callback/ Implementation-Title javax.security.auth.message Medium Product manifest: javax/servlet/descriptor/ Specification-Title Java API for Servlets Medium Product Manifest bundle-symbolicname org.apache.tomcat-embed-core Medium Product manifest: javax/security/auth/message/ Implementation-Title javax.security.auth.message Medium Product pom url https://tomcat.apache.org/ Medium Product manifest: javax/servlet/http/ Implementation-Title javax.servlet Medium Product jar package name http Highest Product manifest: javax/security/auth/message/module/ Implementation-Title javax.security.auth.message Medium Product jar package name security Highest Product jar package name processor Highest Product Manifest specification-title Apache Tomcat Medium Product manifest: javax/security/auth/message/callback/ Specification-Title Java Authentication SPI for Containers Medium Product Manifest Bundle-Name tomcat-embed-core Medium Product manifest: javax/security/auth/message/config/ Specification-Title Java Authentication SPI for Containers Medium Product pom artifactid tomcat-embed-core Highest Product jar package name apache Highest Product manifest: javax/servlet/annotation/ Specification-Title Java API for Servlets Medium Product manifest: javax/servlet/resources/ Specification-Title Java API for Servlets Medium Version Manifest Implementation-Version 9.0.54 High Version Manifest Bundle-Version 9.0.54 High Version pom version 9.0.54 Highest Version file version 9.0.54 High
tomcat-embed-el-9.0.54.jarDescription:
Core Tomcat implementation License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/org/apache/tomcat/embed/tomcat-embed-el/9.0.54/tomcat-embed-el-9.0.54.jar
MD5: 1fdec539727d8d7805bb10da923e4505
SHA1: 9edb062d38d0fd8a165289f44b28b3b0e0e11ed7
SHA256: 7b8f4c699d4969d96c2c9502c234a2d95081910bde4e01acbf9773a2672f4c20
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor Manifest Implementation-Vendor Apache Software Foundation High Vendor pom groupid apache.tomcat.embed Highest Vendor jar package name el Highest Vendor Manifest specification-vendor Apache Software Foundation Low Vendor pom artifactid tomcat-embed-el Low Vendor Manifest bundle-symbolicname org.apache.tomcat-embed-jasper-el Medium Vendor pom groupid org.apache.tomcat.embed Highest Vendor manifest: javax/el/ Implementation-Vendor Apache Software Foundation Medium Vendor file name tomcat-embed-el High Vendor pom url https://tomcat.apache.org/ Highest Vendor jar package name apache Highest Vendor Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.processor)(version>=1.0.0)(!(version>=2.0.0)))",osgi.serviceloader;filter:="(osgi.serviceloader=javax.el.ExpressionFactory)";osgi.serviceloader="javax.el.ExpressionFactory",osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))",osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.registrar)(version>=1.0.0)(!(version>=2.0.0)))" Low Vendor Manifest provide-capability osgi.contract;osgi.contract=JavaEL;version:List="3.0,2.2,2.1";uses:="javax.el",osgi.service;objectClass:List="javax.el.ExpressionFactory";effective:=active,osgi.serviceloader;osgi.serviceloader="javax.el.ExpressionFactory";register:="org.apache.el.ExpressionFactoryImpl" Low Product pom artifactid tomcat-embed-el Highest Product Manifest Bundle-Name tomcat-embed-jasper-el Medium Product pom groupid apache.tomcat.embed Highest Product jar package name el Highest Product jar package name expressionfactoryimpl Highest Product jar package name expressionfactory Highest Product Manifest bundle-symbolicname org.apache.tomcat-embed-jasper-el Medium Product jar package name javax Highest Product jar package name expression Highest Product manifest: javax/el/ Implementation-Title javax.el Medium Product pom url https://tomcat.apache.org/ Medium Product Manifest specification-title Apache Tomcat Medium Product file name tomcat-embed-el High Product manifest: javax/el/ Specification-Title Expression Language Medium Product jar package name apache Highest Product Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.processor)(version>=1.0.0)(!(version>=2.0.0)))",osgi.serviceloader;filter:="(osgi.serviceloader=javax.el.ExpressionFactory)";osgi.serviceloader="javax.el.ExpressionFactory",osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))",osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.registrar)(version>=1.0.0)(!(version>=2.0.0)))" Low Product Manifest Implementation-Title Apache Tomcat High Product Manifest provide-capability osgi.contract;osgi.contract=JavaEL;version:List="3.0,2.2,2.1";uses:="javax.el",osgi.service;objectClass:List="javax.el.ExpressionFactory";effective:=active,osgi.serviceloader;osgi.serviceloader="javax.el.ExpressionFactory";register:="org.apache.el.ExpressionFactoryImpl" Low Version Manifest Implementation-Version 9.0.54 High Version Manifest Bundle-Version 9.0.54 High Version pom version 9.0.54 Highest Version file version 9.0.54 High
tomcat-embed-websocket-9.0.54.jarDescription:
Core Tomcat implementation License:
Apache License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/org/apache/tomcat/embed/tomcat-embed-websocket/9.0.54/tomcat-embed-websocket-9.0.54.jar
MD5: cdbe02507576eef018fdae6287b83057
SHA1: ae018906cecb818a8c6f2316d7b0793beadf6609
SHA256: 6397e08ab013c0283b7294c78600399dafa86e46df37cff59bbca88928a33464
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor jar package name tomcat Highest Vendor Manifest Implementation-Vendor Apache Software Foundation High Vendor pom groupid apache.tomcat.embed Highest Vendor Manifest provide-capability osgi.contract;osgi.contract=JavaWebSockets;version:List="1.1,1";uses:="javax.websocket,javax.websocket.server",osgi.service;objectClass:List="javax.websocket.ContainerProvider";effective:=active,osgi.service;objectClass:List="javax.websocket.server.ServerEndpointConfig$Configurator";effective:=active,osgi.serviceloader;osgi.serviceloader="javax.websocket.ContainerProvider";register:="org.apache.tomcat.websocket.WsContainerProvider",osgi.serviceloader;osgi.serviceloader="javax.websocket.server.ServerEndpointConfig$Configurator";register:="org.apache.tomcat.websocket.server.DefaultServerEndpointConfigurator" Low Vendor manifest: javax/websocket/ Implementation-Vendor Apache Software Foundation Medium Vendor Manifest specification-vendor Apache Software Foundation Low Vendor jar package name websocket Highest Vendor Manifest bundle-symbolicname org.apache.tomcat-embed-websocket Medium Vendor file name tomcat-embed-websocket High Vendor manifest: javax/websocket/server/ Implementation-Vendor Apache Software Foundation Medium Vendor pom groupid org.apache.tomcat.embed Highest Vendor Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.processor)(version>=1.0.0)(!(version>=2.0.0)))",osgi.serviceloader;filter:="(osgi.serviceloader=javax.websocket.ContainerProvider)";osgi.serviceloader="javax.websocket.ContainerProvider",osgi.serviceloader;filter:="(osgi.serviceloader=javax.websocket.server.ServerEndpointConfig$Configurator)";osgi.serviceloader="javax.websocket.server.ServerEndpointConfig$Configurator",osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))",osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.registrar)(version>=1.0.0)(!(version>=2.0.0)))",osgi.contract;osgi.contract=JavaServlet;filter:="(&(osgi.contract=JavaServlet)(version=4.0.0))" Low Vendor pom artifactid tomcat-embed-websocket Low Vendor pom url https://tomcat.apache.org/ Highest Vendor jar package name apache Highest Product jar package name tomcat Highest Product manifest: javax/websocket/server/ Specification-Title WebSocket Medium Product pom groupid apache.tomcat.embed Highest Product Manifest provide-capability osgi.contract;osgi.contract=JavaWebSockets;version:List="1.1,1";uses:="javax.websocket,javax.websocket.server",osgi.service;objectClass:List="javax.websocket.ContainerProvider";effective:=active,osgi.service;objectClass:List="javax.websocket.server.ServerEndpointConfig$Configurator";effective:=active,osgi.serviceloader;osgi.serviceloader="javax.websocket.ContainerProvider";register:="org.apache.tomcat.websocket.WsContainerProvider",osgi.serviceloader;osgi.serviceloader="javax.websocket.server.ServerEndpointConfig$Configurator";register:="org.apache.tomcat.websocket.server.DefaultServerEndpointConfigurator" Low Product jar package name websocket Highest Product jar package name wscontainerprovider Highest Product Manifest bundle-symbolicname org.apache.tomcat-embed-websocket Medium Product jar package name javax Highest Product pom url https://tomcat.apache.org/ Medium Product file name tomcat-embed-websocket High Product manifest: javax/websocket/ Implementation-Title javax.websocket Medium Product jar package name server Highest Product jar package name serverendpointconfig$configurator Highest Product jar package name serverendpointconfig Highest Product Manifest specification-title Apache Tomcat Medium Product Manifest require-capability osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.processor)(version>=1.0.0)(!(version>=2.0.0)))",osgi.serviceloader;filter:="(osgi.serviceloader=javax.websocket.ContainerProvider)";osgi.serviceloader="javax.websocket.ContainerProvider",osgi.serviceloader;filter:="(osgi.serviceloader=javax.websocket.server.ServerEndpointConfig$Configurator)";osgi.serviceloader="javax.websocket.server.ServerEndpointConfig$Configurator",osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))",osgi.extender;filter:="(&(osgi.extender=osgi.serviceloader.registrar)(version>=1.0.0)(!(version>=2.0.0)))",osgi.contract;osgi.contract=JavaServlet;filter:="(&(osgi.contract=JavaServlet)(version=4.0.0))" Low Product manifest: javax/websocket/ Specification-Title WebSocket Medium Product pom artifactid tomcat-embed-websocket Highest Product Manifest Bundle-Name tomcat-embed-websocket Medium Product jar package name containerprovider Highest Product manifest: javax/websocket/server/ Implementation-Title javax.websocket Medium Product jar package name apache Highest Product Manifest Implementation-Title Apache Tomcat High Version Manifest Implementation-Version 9.0.54 High Version Manifest Bundle-Version 9.0.54 High Version pom version 9.0.54 Highest Version file version 9.0.54 High
txw2-2.3.5.jarDescription:
TXW is a library that allows you to write XML documents.
File Path: /home/jenkins/.mvnrepository/org/glassfish/jaxb/txw2/2.3.5/txw2-2.3.5.jarMD5: 67005a4cf5ee9cfd82edec1bdbecb32bSHA1: ec8930fa62e7b1758b1664d135f50c7abe86a4a3SHA256: 7d75ea1151367fb66287011d9941715f645922932554acba0c5ac3aec67fb01fReferenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid org.glassfish.jaxb Highest Vendor Manifest git-revision f01d8db Low Vendor pom parent-artifactid jaxb-txw-parent Low Vendor pom groupid glassfish.jaxb Highest Vendor jar package name sun Highest Vendor file name txw2 High Vendor jar package name xml Highest Vendor pom name TXW2 Runtime High Vendor pom parent-groupid com.sun.xml.bind.mvn Medium Vendor pom url https://eclipse-ee4j.github.io/jaxb-ri/ Highest Vendor jar package name txw Highest Vendor Manifest Implementation-Vendor Eclipse Foundation High Vendor jar package name txw2 Highest Vendor jar (hint) package name oracle Highest Vendor Manifest Implementation-Vendor-Id org.eclipse Medium Vendor pom artifactid txw2 Low Product Manifest git-revision f01d8db Low Product pom artifactid txw2 Highest Product pom groupid glassfish.jaxb Highest Product jar package name sun Highest Product file name txw2 High Product jar package name xml Highest Product pom name TXW2 Runtime High Product Manifest Implementation-Title Jakarta XML Binding Implementation High Product pom parent-groupid com.sun.xml.bind.mvn Medium Product pom parent-artifactid jaxb-txw-parent Medium Product Manifest specification-title Jakarta XML Binding Medium Product jar package name txw Highest Product jar package name txw2 Highest Product pom url https://eclipse-ee4j.github.io/jaxb-ri/ Medium Version pom version 2.3.5 Highest Version file version 2.3.5 High Version Manifest build-id 2.3.5 Medium Version Manifest Implementation-Version 2.3.5 High Version Manifest major-version 2.3.5 Medium
ucp-19.3.0.0.jarDescription:
Oracle Universal Connection Pool (UCP) License:
Oracle Free Use Terms and Conditions (FUTC) File Path: /home/jenkins/.mvnrepository/com/oracle/ojdbc/ucp/19.3.0.0/ucp-19.3.0.0.jar
MD5: 9845d08450b16c7ae81da60689d27f3c
SHA1: 796b661b0bb1818b7c04171837356acddcea504c
SHA256: 23d8debe40a764df74d5eda7e8c1ce9b2c190a34f739ca4d751eaa94114d31cc
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor file name ucp High Vendor jar (hint) package name sun Highest Vendor pom groupid com.oracle.ojdbc Highest Vendor Manifest Implementation-Vendor Oracle Corporation High Vendor jar package name oracle Highest Vendor pom groupid oracle.ojdbc Highest Vendor jar package name ucp Highest Vendor pom artifactid ucp Low Vendor pom name ucp High Vendor Manifest build-info 190404 Low Vendor pom url https://www.oracle.com/database/technologies/appdev/jdbc.html Highest Product pom url https://www.oracle.com/database/technologies/appdev/jdbc.html Medium Product file name ucp High Product pom artifactid ucp Highest Product jar package name oracle Highest Product pom groupid oracle.ojdbc Highest Product jar package name ucp Highest Product pom name ucp High Product Manifest Implementation-Title Oracle Universal Connection Pool High Product Manifest build-info 190404 Low Version pom version 19.3.0.0 Highest Version file version 19.3.0.0 High
validation-api-2.0.1.Final.jarDescription:
Bean Validation API
License:
Apache License 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/javax/validation/validation-api/2.0.1.Final/validation-api-2.0.1.Final.jar
MD5: 5d02c034034a7a16725ceff787e191d6
SHA1: cb855558e6271b1b32e716d24cb85c7f583ce09e
SHA256: 9873b46df1833c9ee8f5bc1ff6853375115dadd8897bcb5a0dffb5848835ee6c
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid javax.validation Highest Vendor file name validation-api High Vendor jar package name validation Highest Vendor Manifest bundle-symbolicname javax.validation.api Medium Vendor pom artifactid validation-api Low Vendor pom url http://beanvalidation.org Highest Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom name Bean Validation API High Vendor Manifest automatic-module-name java.validation Medium Vendor jar package name javax Highest Product pom groupid javax.validation Highest Product Manifest Bundle-Name Bean Validation API Medium Product file name validation-api High Product jar package name validation Highest Product Manifest bundle-symbolicname javax.validation.api Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom name Bean Validation API High Product pom artifactid validation-api Highest Product Manifest automatic-module-name java.validation Medium Product jar package name javax Highest Product pom url http://beanvalidation.org Medium Version Manifest Bundle-Version 2.0.1.Final High Version pom version 2.0.1.Final Highest
waffle-jna-1.9.1.jarDescription:
WAFFLE JNA implementation File Path: /home/jenkins/.mvnrepository/com/github/waffle/waffle-jna/1.9.1/waffle-jna-1.9.1.jarMD5: dad462f82a87162d867f1920c1e88ac8SHA1: da610d1564ab9e4993ffa5e1e0c407027fede00dSHA256: 5dfeb0acbe917b90af65705c614243b84d4b1b9d92858eeaeafa8885fca0f88eReferenced In Project/Scope: Entando Kubernetes Service:runtime
Evidence Type Source Name Value Confidence Vendor Manifest Implementation-Vendor-Id com.github.waffle Medium Vendor pom parent-groupid com.github.waffle Medium Vendor Manifest build-time 2018-07-02 00:54:43 Low Vendor Manifest git-revision Low Vendor jar package name windows Highest Vendor pom name waffle-jna High Vendor Manifest os-name Windows 10 Medium Vendor Manifest specification-vendor com.github.waffle Low Vendor pom artifactid waffle-jna Low Vendor Manifest copyright 2018 Low Vendor pom parent-artifactid waffle-parent Low Vendor Manifest Implementation-Vendor com.github.waffle High Vendor Manifest os-arch amd64 Low Vendor Manifest implementation-url https://waffle.github.com/waffle/ Low Vendor file name waffle-jna High Vendor pom url https://waffle.github.com/waffle/ Highest Vendor pom groupid github.waffle Highest Vendor pom groupid com.github.waffle Highest Vendor jar package name waffle Highest Product pom parent-artifactid waffle-parent Medium Product pom parent-groupid com.github.waffle Medium Product Manifest Implementation-Title waffle-jna High Product Manifest build-time 2018-07-02 00:54:43 Low Product Manifest git-revision Low Product jar package name windows Highest Product pom name waffle-jna High Product Manifest os-name Windows 10 Medium Product Manifest copyright 2018 Low Product pom artifactid waffle-jna Highest Product Manifest os-arch amd64 Low Product Manifest implementation-url https://waffle.github.com/waffle/ Low Product file name waffle-jna High Product pom groupid github.waffle Highest Product Manifest specification-title waffle-jna Medium Product jar package name waffle Highest Product pom url https://waffle.github.com/waffle/ Medium Version file version 1.9.1 High Version Manifest Implementation-Version 1.9.1 High Version pom version 1.9.1 Highest
webjars-locator-core-0.46.jarDescription:
WebJar Locator Core functionality License:
MIT: https://github.com/webjars/webjars-locator-core/blob/master/LICENSE.md File Path: /home/jenkins/.mvnrepository/org/webjars/webjars-locator-core/0.46/webjars-locator-core-0.46.jar
MD5: 467243ddcdf07d23e2bd040ae096d61f
SHA1: 2c207eae0bf475d6e2444ece594c199f1f418322
SHA256: 2295de3f8b84fd2f55aca565a97213e826f8bbad1ca8b16a8c75aa98f7a20110
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom groupid webjars Highest Vendor pom artifactid webjars-locator-core Low Vendor jar package name webjars Low Vendor pom groupid org.webjars Highest Vendor jar package name webjars Highest Vendor pom name webjars-locator-core High Vendor file name webjars-locator-core High Vendor pom url http://webjars.org Highest Product pom groupid webjars Highest Product jar package name webjars Highest Product pom url http://webjars.org Medium Product pom name webjars-locator-core High Product pom artifactid webjars-locator-core Highest Product file name webjars-locator-core High Version file version 0.46 High Version pom version 0.46 Highest
zjsonpatch-0.3.0.jarDescription:
Java Library to find / apply JSON Patches according to RFC 6902 License:
The Apache Software License, Version 2.0: http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/zjsonpatch/0.3.0/zjsonpatch-0.3.0.jar
MD5: c47f98189f594bd86ccbf40c5391b600
SHA1: d3ebf0f291297649b4c8dc3ecc81d2eddedc100d
SHA256: ae4e5e931646a25cb09b55186de4f3346e358e01130bef279ddf495a719c71d5
Referenced In Project/Scope: Entando Kubernetes Service:compile
Evidence Type Source Name Value Confidence Vendor pom url fabric8io/zjsonpatch/ Highest Vendor Manifest build-timestamp ${build.datetime} Low Vendor file name zjsonpatch High Vendor Manifest implementation-url https://github.com/fabric8io/zjsonpatch/ Low Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Vendor pom name zjsonpatch High Vendor pom groupid io.fabric8 Highest Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor jar package name zjsonpatch Highest Vendor pom artifactid zjsonpatch Low Vendor Manifest bundle-symbolicname io.fabric8.zjsonpatch Medium Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Product Manifest build-timestamp ${build.datetime} Low Product Manifest Implementation-Title zjsonpatch High Product file name zjsonpatch High Product pom artifactid zjsonpatch Highest Product Manifest specification-title zjsonpatch Medium Product Manifest implementation-url https://github.com/fabric8io/zjsonpatch/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.7))" Low Product pom name zjsonpatch High Product pom groupid io.fabric8 Highest Product jar package name io Highest Product Manifest os-arch amd64 Low Product pom url fabric8io/zjsonpatch/ High Product jar package name zjsonpatch Highest Product Manifest Bundle-Name zjsonpatch Medium Product Manifest bundle-symbolicname io.fabric8.zjsonpatch Medium Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Version file version 0.3.0 High Version pom version 0.3.0 Highest Version Manifest Implementation-Version 0.3.0 High Version Manifest Bundle-Version 0.3.0 High
Suppressed Vulnerabilities entando-k8s-custom-model-6.3.4.jar Description:
Entando's Kubernetes Custom Resources License:
GNU LESSER GENERAL PUBLIC LICENSE, Version 2.1, February 1999: https://www.gnu.org/licenses/lgpl-2.1.txt File Path: /home/jenkins/.mvnrepository/org/entando/entando-k8s-custom-model/6.3.4/entando-k8s-custom-model-6.3.4.jar
MD5: c744809d5012ba2e91767c76349709bd
SHA1: d40dc798900cb12eb1275bca1ce755a59a3aa09d
SHA256: d77e0ec0f4eb5707ebf3668bee92afeefed142b80506ba90f59e566a55002c94
Evidence Type Source Name Value Confidence Vendor Manifest build-jdk-spec 11 Low Vendor pom artifactid entando-k8s-custom-model Low Vendor pom organization name Entando Inc. High Vendor pom groupid entando Highest Vendor pom url https://central.entando.com Highest Vendor jar package name model Highest Vendor pom organization url http://www.entando.com/ Medium Vendor file name entando-k8s-custom-model High Vendor jar package name entando Highest Vendor jar package name kubernetes Highest Vendor Manifest implementation-build 6.3.4 Low Vendor pom parent-groupid org.entando Medium Vendor pom name Entando Kubernetes Custom Model High Vendor Manifest Implementation-Vendor Entando Inc. High Vendor pom groupid org.entando Highest Vendor pom parent-artifactid entando-quarkus-parent Low Product Manifest build-jdk-spec 11 Low Product pom artifactid entando-k8s-custom-model Highest Product pom url https://central.entando.com Medium Product pom groupid entando Highest Product jar package name model Highest Product pom parent-artifactid entando-quarkus-parent Medium Product file name entando-k8s-custom-model High Product jar package name entando Highest Product jar package name kubernetes Highest Product Manifest implementation-build 6.3.4 Low Product pom parent-groupid org.entando Medium Product pom name Entando Kubernetes Custom Model High Product pom organization url http://www.entando.com/ Low Product Manifest Implementation-Title Entando Kubernetes Custom Model High Product pom organization name Entando Inc. Low Version file version 6.3.4 High Version Manifest implementation-build 6.3.4 Low Version Manifest Implementation-Version 6.3.4 High Version pom parent-version 6.3.4 Low Version pom version 6.3.4 Highest
cpe:2.3:a:kubernetes:kubernetes:6.3.4:*:*:*:*:*:*:* suppressed (Confidence :Low)Notes: A whole lot of false positives based on K8S's internals that have nothing to do with our CRDs Suppressed Vulnerabilities CVE-2020-8554 suppressed
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
MEDIUM (5.0) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L References:
Vulnerable Software & Versions:
kubernetes-client-4.10.3.jar File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-client/4.10.3/kubernetes-client-4.10.3.jarMD5: 07f7e47f352be91d0bdb373520e2d1c4SHA1: 7000f01dc1ef12dff25c0f9979becce540f74b26SHA256: 64a9d6e5e42b3d67e45760a99fc368239e6853fa76986ed08c4a48f27a8e0fef
Evidence Type Source Name Value Confidence Vendor pom parent-artifactid kubernetes-client-project Low Vendor pom groupid io.fabric8 Highest Vendor pom artifactid kubernetes-client Low Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor file name kubernetes-client High Vendor Manifest build-jdk-spec 14 Low Vendor jar package name fabric8 Highest Vendor jar package name client Highest Vendor pom name Fabric8 :: Kubernetes :: Java Client High Product pom groupid io.fabric8 Highest Product jar package name kubernetes Highest Product pom artifactid kubernetes-client Highest Product jar package name io Highest Product file name kubernetes-client High Product Manifest build-jdk-spec 14 Low Product jar package name fabric8 Highest Product pom parent-artifactid kubernetes-client-project Medium Product jar package name client Highest Product pom name Fabric8 :: Kubernetes :: Java Client High Version pom version 4.10.3 Highest Version file version 4.10.3 High
cpe:2.3:a:kubernetes:java:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Low)Notes: A false positives relative to K8S's client that has nothing to do with the imported one by Fabric8 cpe:2.3:a:kubernetes:kubernetes:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Highest)Notes: A whole lot of false positives based on K8S's internals that have nothing to do with our CRDs Suppressed Vulnerabilities CVE-2020-8554 suppressed
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
MEDIUM (5.0) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L References:
Vulnerable Software & Versions:
CVE-2020-8570 suppressed
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:P CVSSv3:
HIGH (7.5) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-25738 suppressed
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:L/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
MEDIUM (6.7) CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
kubernetes-model-admissionregistration-4.10.3.jar Description:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-admissionregistration/4.10.3/kubernetes-model-admissionregistration-4.10.3.jar
MD5: 6cee0d468f74352c5a0bbb7641eef974
SHA1: 92aa117119fbe0559f0b5ebb548c3a8ad2e77902
SHA256: 2f189af15c564ff796691b7d11cd1c8929b51a3597bb2e339ec3407c9632d9ff
Evidence Type Source Name Value Confidence Vendor Manifest build-timestamp ${build.datetime} Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid kubernetes-model-admissionregistration Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor file name kubernetes-model-admissionregistration High Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-admissionregistration Medium Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor pom name Fabric8 :: Kubernetes Model :: Admission Registration, Authentication and Authorization High Vendor Manifest java-vendor Oracle Corporation Medium Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-admissionregistration/ Low Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Product Manifest build-timestamp ${build.datetime} Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Admission Registration, Authentication and Authorization High Product file name kubernetes-model-admissionregistration High Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product jar package name io Highest Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-admissionregistration Medium Product Manifest os-arch amd64 Low Product pom name Fabric8 :: Kubernetes Model :: Admission Registration, Authentication and Authorization High Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Admission Registration, Authentication and Authorization Medium Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-admissionregistration/ Low Product Manifest specification-title Fabric8 :: Kubernetes Model :: Admission Registration, Authentication and Authorization Medium Product pom parent-artifactid kubernetes-model-generator Medium Product pom artifactid kubernetes-model-admissionregistration Highest Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
cpe:2.3:a:kubernetes:java:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Low)Notes: A false positives relative to K8S's client that has nothing to do with the imported one by Fabric8 cpe:2.3:a:kubernetes:kubernetes:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Highest)Notes: A whole lot of false positives based on K8S's internals that have nothing to do with our CRDs Suppressed Vulnerabilities CVE-2020-8554 suppressed
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
MEDIUM (5.0) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L References:
Vulnerable Software & Versions:
CVE-2020-8570 suppressed
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:P CVSSv3:
HIGH (7.5) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-25738 suppressed
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:L/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
MEDIUM (6.7) CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
kubernetes-model-apiextensions-4.10.3.jar Description:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-apiextensions/4.10.3/kubernetes-model-apiextensions-4.10.3.jar
MD5: fadd6f5239e4a5f5792547f9f830e0be
SHA1: f59b61eec3666fbca6577f3db953e6a15fc2c4a8
SHA256: 14453ac8dc0eed3b3156ff23d5e6972d3408893469459b73019c276cfd65e338
Evidence Type Source Name Value Confidence Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-apiextensions Medium Vendor Manifest build-timestamp ${build.datetime} Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor pom artifactid kubernetes-model-apiextensions Low Vendor pom name Fabric8 :: Kubernetes Model :: API Extensions High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor jar package name api Highest Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor file name kubernetes-model-apiextensions High Vendor Manifest specification-vendor Red Hat Low Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-apiextensions/ Low Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-apiextensions Medium Product Manifest specification-title Fabric8 :: Kubernetes Model :: API Extensions Medium Product Manifest build-timestamp ${build.datetime} Low Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: API Extensions Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom artifactid kubernetes-model-apiextensions Highest Product pom name Fabric8 :: Kubernetes Model :: API Extensions High Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product jar package name io Highest Product Manifest os-arch amd64 Low Product pom parent-artifactid kubernetes-model-generator Medium Product jar package name api Highest Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Product file name kubernetes-model-apiextensions High Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: API Extensions High Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-apiextensions/ Low Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
cpe:2.3:a:kubernetes:java:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Low)Notes: A false positives relative to K8S's client that has nothing to do with the imported one by Fabric8 cpe:2.3:a:kubernetes:kubernetes:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Highest)Notes: A whole lot of false positives based on K8S's internals that have nothing to do with our CRDs Suppressed Vulnerabilities CVE-2020-8554 suppressed
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
MEDIUM (5.0) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L References:
Vulnerable Software & Versions:
CVE-2020-8570 suppressed
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:P CVSSv3:
HIGH (7.5) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-25738 suppressed
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:L/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
MEDIUM (6.7) CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
kubernetes-model-apps-4.10.3.jar Description:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-apps/4.10.3/kubernetes-model-apps-4.10.3.jar
MD5: c3f8d600e86db925475db33868ed4aa4
SHA1: 7ead298312bc14a73d48c102d65c01b827f1e01f
SHA256: 95b93b241d76c88f70c73078e5316b5a127fb1cf89ded89d08aec9f7faf0752d
Evidence Type Source Name Value Confidence Vendor Manifest build-timestamp ${build.datetime} Low Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-apps/ Low Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-apps Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor file name kubernetes-model-apps High Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor pom name Fabric8 :: Kubernetes Model :: Apps High Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor pom artifactid kubernetes-model-apps Low Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Product Manifest build-timestamp ${build.datetime} Low Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-apps/ Low Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Apps High Product pom artifactid kubernetes-model-apps Highest Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-apps Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Fabric8 :: Kubernetes Model :: Apps Medium Product file name kubernetes-model-apps High Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product jar package name io Highest Product pom name Fabric8 :: Kubernetes Model :: Apps High Product Manifest os-arch amd64 Low Product pom parent-artifactid kubernetes-model-generator Medium Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Apps Medium Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
cpe:2.3:a:kubernetes:java:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Low)Notes: A false positives relative to K8S's client that has nothing to do with the imported one by Fabric8 cpe:2.3:a:kubernetes:kubernetes:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Highest)Notes: A whole lot of false positives based on K8S's internals that have nothing to do with our CRDs Suppressed Vulnerabilities CVE-2020-8554 suppressed
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
MEDIUM (5.0) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L References:
Vulnerable Software & Versions:
CVE-2020-8570 suppressed
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:P CVSSv3:
HIGH (7.5) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-25738 suppressed
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:L/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
MEDIUM (6.7) CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
kubernetes-model-autoscaling-4.10.3.jar Description:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-autoscaling/4.10.3/kubernetes-model-autoscaling-4.10.3.jar
MD5: e19219399d89b7bd6857a513f1a0e3f4
SHA1: 08f7176dcd771a711595b36d2c7f6c29125422fd
SHA256: f287f7877d0b94ea257094786df0cf41bcac03e20fcf5f83e45073782e8d38b6
Evidence Type Source Name Value Confidence Vendor Manifest build-timestamp ${build.datetime} Low Vendor pom name Fabric8 :: Kubernetes Model :: Autoscaling High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor file name kubernetes-model-autoscaling High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-autoscaling/ Low Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-autoscaling Medium Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor pom artifactid kubernetes-model-autoscaling Low Vendor Manifest specification-vendor Red Hat Low Product pom artifactid kubernetes-model-autoscaling Highest Product Manifest build-timestamp ${build.datetime} Low Product pom name Fabric8 :: Kubernetes Model :: Autoscaling High Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Autoscaling Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Autoscaling High Product file name kubernetes-model-autoscaling High Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product jar package name io Highest Product Manifest os-arch amd64 Low Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-autoscaling/ Low Product Manifest specification-title Fabric8 :: Kubernetes Model :: Autoscaling Medium Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-autoscaling Medium Product pom parent-artifactid kubernetes-model-generator Medium Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
cpe:2.3:a:kubernetes:java:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Low)Notes: A false positives relative to K8S's client that has nothing to do with the imported one by Fabric8 cpe:2.3:a:kubernetes:kubernetes:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Highest)Notes: A whole lot of false positives based on K8S's internals that have nothing to do with our CRDs Suppressed Vulnerabilities CVE-2020-8554 suppressed
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
MEDIUM (5.0) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L References:
Vulnerable Software & Versions:
CVE-2020-8570 suppressed
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:P CVSSv3:
HIGH (7.5) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-25738 suppressed
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:L/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
MEDIUM (6.7) CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
kubernetes-model-batch-4.10.3.jar Description:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-batch/4.10.3/kubernetes-model-batch-4.10.3.jar
MD5: 072af6ea7246e921f0851f5968767377
SHA1: 89382157261fbf748fc2c8a3b961fde12ae5077e
SHA256: 31023e04d13e4c6b4e8ea99ce7c14a70a55afa4a67d86aa9b71f0ad1e9d636ae
Evidence Type Source Name Value Confidence Vendor Manifest build-timestamp ${build.datetime} Low Vendor file name kubernetes-model-batch High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor pom artifactid kubernetes-model-batch Low Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-batch/ Low Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor pom name Fabric8 :: Kubernetes Model :: Batch High Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-batch Medium Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Product Manifest specification-title Fabric8 :: Kubernetes Model :: Batch Medium Product Manifest build-timestamp ${build.datetime} Low Product file name kubernetes-model-batch High Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Batch High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-batch/ Low Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product jar package name io Highest Product Manifest os-arch amd64 Low Product pom artifactid kubernetes-model-batch Highest Product pom parent-artifactid kubernetes-model-generator Medium Product pom name Fabric8 :: Kubernetes Model :: Batch High Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Batch Medium Product jar package name fabric8 Highest Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-batch Medium Product Manifest os-name Linux Medium Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
cpe:2.3:a:kubernetes:java:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Low)Notes: A false positives relative to K8S's client that has nothing to do with the imported one by Fabric8 cpe:2.3:a:kubernetes:kubernetes:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Highest)Notes: A whole lot of false positives based on K8S's internals that have nothing to do with our CRDs Suppressed Vulnerabilities CVE-2020-8554 suppressed
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
MEDIUM (5.0) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L References:
Vulnerable Software & Versions:
CVE-2020-8570 suppressed
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:P CVSSv3:
HIGH (7.5) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-25738 suppressed
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:L/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
MEDIUM (6.7) CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
kubernetes-model-certificates-4.10.3.jar Description:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-certificates/4.10.3/kubernetes-model-certificates-4.10.3.jar
MD5: defa9d55ee2706f1cc69c9a9a77f02d2
SHA1: 4591fc267e8475386f5ef74e0878751dbda1e064
SHA256: 3edcc947621f1e545313de08862a75abebc799d241add83192596df8db9296f8
Evidence Type Source Name Value Confidence Vendor pom name Fabric8 :: Kubernetes Model :: Certificates High Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-certificates/ Low Vendor Manifest build-timestamp ${build.datetime} Low Vendor file name kubernetes-model-certificates High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor pom artifactid kubernetes-model-certificates Low Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-certificates Medium Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Product pom name Fabric8 :: Kubernetes Model :: Certificates High Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-certificates/ Low Product Manifest build-timestamp ${build.datetime} Low Product file name kubernetes-model-certificates High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Fabric8 :: Kubernetes Model :: Certificates Medium Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product pom artifactid kubernetes-model-certificates Highest Product jar package name io Highest Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Certificates High Product Manifest os-arch amd64 Low Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Certificates Medium Product pom parent-artifactid kubernetes-model-generator Medium Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-certificates Medium Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
cpe:2.3:a:kubernetes:java:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Low)Notes: A false positives relative to K8S's client that has nothing to do with the imported one by Fabric8 cpe:2.3:a:kubernetes:kubernetes:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Highest)Notes: A whole lot of false positives based on K8S's internals that have nothing to do with our CRDs Suppressed Vulnerabilities CVE-2020-8554 suppressed
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
MEDIUM (5.0) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L References:
Vulnerable Software & Versions:
CVE-2020-8570 suppressed
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:P CVSSv3:
HIGH (7.5) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-25738 suppressed
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:L/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
MEDIUM (6.7) CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
kubernetes-model-common-4.10.3.jar Description:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-common/4.10.3/kubernetes-model-common-4.10.3.jar
MD5: b63abe4efb0ea5da9d232e142636575d
SHA1: 57e09b193b72c046bad0eb9670f0d36cae872882
SHA256: cde8031d89c67c452c354112a8d4ba7a97da684bb65d6dc0f25e3d50b175ac01
Evidence Type Source Name Value Confidence Vendor pom name Fabric8 :: Kubernetes Model :: Common High Vendor Manifest build-timestamp ${build.datetime} Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor jar package name model Highest Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor file name kubernetes-model-common High Vendor pom artifactid kubernetes-model-common Low Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-common Medium Vendor Manifest java-vendor Oracle Corporation Medium Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-common/ Low Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Product pom name Fabric8 :: Kubernetes Model :: Common High Product Manifest build-timestamp ${build.datetime} Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product jar package name model Highest Product file name kubernetes-model-common High Product pom artifactid kubernetes-model-common Highest Product Manifest bundle-docurl http://redhat.com Low Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Common High Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product jar package name io Highest Product Manifest os-arch amd64 Low Product Manifest specification-title Fabric8 :: Kubernetes Model :: Common Medium Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-common Medium Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-common/ Low Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Common Medium Product pom parent-artifactid kubernetes-model-generator Medium Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
cpe:2.3:a:kubernetes:java:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Low)Notes: A false positives relative to K8S's client that has nothing to do with the imported one by Fabric8 cpe:2.3:a:kubernetes:kubernetes:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Highest)Notes: A whole lot of false positives based on K8S's internals that have nothing to do with our CRDs Suppressed Vulnerabilities CVE-2020-8554 suppressed
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
MEDIUM (5.0) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L References:
Vulnerable Software & Versions:
CVE-2020-8570 suppressed
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:P CVSSv3:
HIGH (7.5) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-25738 suppressed
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:L/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
MEDIUM (6.7) CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
kubernetes-model-coordination-4.10.3.jar Description:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-coordination/4.10.3/kubernetes-model-coordination-4.10.3.jar
MD5: b65f294c3186fc805ae36e7b2b71e84a
SHA1: 6ac4d6b2e06102f5bc06baa9439bfe969915e1d1
SHA256: 3dc62a48e1bfe395eb46067639fdf8fa1fd2251742a92660248cc8f1c05dbced
Evidence Type Source Name Value Confidence Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-coordination Medium Vendor Manifest build-timestamp ${build.datetime} Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor file name kubernetes-model-coordination High Vendor pom artifactid kubernetes-model-coordination Low Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-coordination/ Low Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor pom name Fabric8 :: Kubernetes Model :: Coordination High Vendor Manifest specification-vendor Red Hat Low Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-coordination Medium Product Manifest build-timestamp ${build.datetime} Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Coordination High Product file name kubernetes-model-coordination High Product pom artifactid kubernetes-model-coordination Highest Product Manifest bundle-docurl http://redhat.com Low Product Manifest specification-title Fabric8 :: Kubernetes Model :: Coordination Medium Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Coordination Medium Product jar package name io Highest Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-coordination/ Low Product Manifest os-arch amd64 Low Product pom parent-artifactid kubernetes-model-generator Medium Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Product pom name Fabric8 :: Kubernetes Model :: Coordination High Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
cpe:2.3:a:kubernetes:java:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Low)Notes: A false positives relative to K8S's client that has nothing to do with the imported one by Fabric8 cpe:2.3:a:kubernetes:kubernetes:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Highest)Notes: A whole lot of false positives based on K8S's internals that have nothing to do with our CRDs Suppressed Vulnerabilities CVE-2020-8554 suppressed
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
MEDIUM (5.0) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L References:
Vulnerable Software & Versions:
CVE-2020-8570 suppressed
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:P CVSSv3:
HIGH (7.5) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-25738 suppressed
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:L/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
MEDIUM (6.7) CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
kubernetes-model-core-4.10.3.jar Description:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-core/4.10.3/kubernetes-model-core-4.10.3.jar
MD5: c6a7512ce00eae6ef60c37e29fd4f375
SHA1: 09f62304f580db3639cf389e0acfd34cbd185181
SHA256: f63ae5abbc1cfb02defd81292277e4e1553eb1af699e3d0b46d1f3144b45f1b6
Evidence Type Source Name Value Confidence Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-core Medium Vendor Manifest build-timestamp ${build.datetime} Low Vendor pom artifactid kubernetes-model-core Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor file name kubernetes-model-core High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor pom name Fabric8 :: Kubernetes Model :: Core High Vendor jar package name fabric8 Highest Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-core/ Low Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Core High Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-core Medium Product pom artifactid kubernetes-model-core Highest Product Manifest build-timestamp ${build.datetime} Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Core Medium Product file name kubernetes-model-core High Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product jar package name io Highest Product Manifest os-arch amd64 Low Product pom name Fabric8 :: Kubernetes Model :: Core High Product pom parent-artifactid kubernetes-model-generator Medium Product jar package name fabric8 Highest Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-core/ Low Product Manifest os-name Linux Medium Product Manifest specification-title Fabric8 :: Kubernetes Model :: Core Medium Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
cpe:2.3:a:kubernetes:java:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Low)Notes: A false positives relative to K8S's client that has nothing to do with the imported one by Fabric8 cpe:2.3:a:kubernetes:kubernetes:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Highest)Notes: A whole lot of false positives based on K8S's internals that have nothing to do with our CRDs Suppressed Vulnerabilities CVE-2020-8554 suppressed
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
MEDIUM (5.0) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L References:
Vulnerable Software & Versions:
CVE-2020-8570 suppressed
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:P CVSSv3:
HIGH (7.5) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-25738 suppressed
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:L/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
MEDIUM (6.7) CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
kubernetes-model-discovery-4.10.3.jar Description:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-discovery/4.10.3/kubernetes-model-discovery-4.10.3.jar
MD5: e7654b5b9e64654ccf2b9b6c3c75f8f5
SHA1: 442295684873890f67be8a04687ea3c9db4b5e07
SHA256: 06a50b3336e4e645284a60a6c2da5d4f645714d5caf2e1d4bdfb78084167d427
Evidence Type Source Name Value Confidence Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-discovery Medium Vendor Manifest build-timestamp ${build.datetime} Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor pom name Fabric8 :: Kubernetes Model :: Discovery High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor pom artifactid kubernetes-model-discovery Low Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-discovery/ Low Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor file name kubernetes-model-discovery High Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-discovery Medium Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Discovery High Product Manifest specification-title Fabric8 :: Kubernetes Model :: Discovery Medium Product Manifest build-timestamp ${build.datetime} Low Product pom artifactid kubernetes-model-discovery Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom name Fabric8 :: Kubernetes Model :: Discovery High Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Discovery Medium Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-discovery/ Low Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product file name kubernetes-model-discovery High Product jar package name io Highest Product Manifest os-arch amd64 Low Product pom parent-artifactid kubernetes-model-generator Medium Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
Suppressed Vulnerabilities CVE-2020-8554 suppressed
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
MEDIUM (5.0) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L References:
Vulnerable Software & Versions:
kubernetes-model-events-4.10.3.jar Description:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-events/4.10.3/kubernetes-model-events-4.10.3.jar
MD5: a15a6f685f935e953105577fa748b077
SHA1: 80b8ab35905af4b6275aca895191ad14af98109d
SHA256: ad0e9e7df773f4574f2e66bf9e089917fbf51a3052568cd7f3c3ce5ecb7579b9
Evidence Type Source Name Value Confidence Vendor Manifest build-timestamp ${build.datetime} Low Vendor pom artifactid kubernetes-model-events Low Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-events Medium Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor pom name Fabric8 :: Kubernetes Model :: Events High Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-events/ Low Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor file name kubernetes-model-events High Vendor Manifest specification-vendor Red Hat Low Product Manifest build-timestamp ${build.datetime} Low Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Events High Product Manifest specification-title Fabric8 :: Kubernetes Model :: Events Medium Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-events Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Events Medium Product pom artifactid kubernetes-model-events Highest Product pom name Fabric8 :: Kubernetes Model :: Events High Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-events/ Low Product pom groupid io.fabric8 Highest Product jar package name io Highest Product Manifest os-arch amd64 Low Product pom parent-artifactid kubernetes-model-generator Medium Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Product file name kubernetes-model-events High Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
cpe:2.3:a:kubernetes:java:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Low)Notes: A false positives relative to K8S's client that has nothing to do with the imported one by Fabric8 cpe:2.3:a:kubernetes:kubernetes:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Highest)Notes: A whole lot of false positives based on K8S's internals that have nothing to do with our CRDs Suppressed Vulnerabilities CVE-2020-8554 suppressed
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
MEDIUM (5.0) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L References:
Vulnerable Software & Versions:
CVE-2020-8570 suppressed
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:P CVSSv3:
HIGH (7.5) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-25738 suppressed
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:L/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
MEDIUM (6.7) CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
kubernetes-model-extensions-4.10.3.jar Description:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-extensions/4.10.3/kubernetes-model-extensions-4.10.3.jar
MD5: 04630c15b3d2b62fda015f18043ac5f9
SHA1: 31c055f04039f64e6915815e5821f3fb339fbedc
SHA256: 18921f8104abbbfc2ad9c48dd444e4f5de24ffed4b7e9167c86fb115e31f4f3f
Evidence Type Source Name Value Confidence Vendor Manifest build-timestamp ${build.datetime} Low Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-extensions Medium Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-extensions/ Low Vendor pom artifactid kubernetes-model-extensions Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom name Fabric8 :: Kubernetes Model :: Extensions High Vendor Manifest Implementation-Vendor Red Hat High Vendor file name kubernetes-model-extensions High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Product Manifest build-timestamp ${build.datetime} Low Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-extensions Medium Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-extensions/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product pom name Fabric8 :: Kubernetes Model :: Extensions High Product file name kubernetes-model-extensions High Product Manifest bundle-docurl http://redhat.com Low Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Extensions Medium Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product jar package name io Highest Product Manifest specification-title Fabric8 :: Kubernetes Model :: Extensions Medium Product Manifest os-arch amd64 Low Product pom parent-artifactid kubernetes-model-generator Medium Product pom artifactid kubernetes-model-extensions Highest Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Extensions High Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
cpe:2.3:a:kubernetes:java:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Low)Notes: A false positives relative to K8S's client that has nothing to do with the imported one by Fabric8 cpe:2.3:a:kubernetes:kubernetes:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Highest)Notes: A whole lot of false positives based on K8S's internals that have nothing to do with our CRDs Suppressed Vulnerabilities CVE-2020-8554 suppressed
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
MEDIUM (5.0) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L References:
Vulnerable Software & Versions:
CVE-2020-8570 suppressed
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:P CVSSv3:
HIGH (7.5) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-25738 suppressed
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:L/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
MEDIUM (6.7) CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
kubernetes-model-metrics-4.10.3.jar Description:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-metrics/4.10.3/kubernetes-model-metrics-4.10.3.jar
MD5: e5bf7835b5bc783df7b066c0e34f8f1b
SHA1: 288c7ef09755201ab46e0c35ef8d0342178863fd
SHA256: 24557760da4ae2572ec7e00301b4a67a7d77efaa68136017674a577fc904a7a6
Evidence Type Source Name Value Confidence Vendor Manifest build-timestamp ${build.datetime} Low Vendor pom artifactid kubernetes-model-metrics Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-metrics Medium Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor file name kubernetes-model-metrics High Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-metrics/ Low Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Vendor pom name Fabric8 :: Kubernetes Model :: Metrics High Product Manifest build-timestamp ${build.datetime} Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-metrics Medium Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Metrics High Product pom artifactid kubernetes-model-metrics Highest Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Metrics Medium Product pom groupid io.fabric8 Highest Product jar package name io Highest Product Manifest os-arch amd64 Low Product Manifest specification-title Fabric8 :: Kubernetes Model :: Metrics Medium Product pom parent-artifactid kubernetes-model-generator Medium Product file name kubernetes-model-metrics High Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-metrics/ Low Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Product pom name Fabric8 :: Kubernetes Model :: Metrics High Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
cpe:2.3:a:kubernetes:java:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Low)Notes: A false positives relative to K8S's client that has nothing to do with the imported one by Fabric8 cpe:2.3:a:kubernetes:kubernetes:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Highest)Notes: A whole lot of false positives based on K8S's internals that have nothing to do with our CRDs Suppressed Vulnerabilities CVE-2020-8554 suppressed
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
MEDIUM (5.0) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L References:
Vulnerable Software & Versions:
CVE-2020-8570 suppressed
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:P CVSSv3:
HIGH (7.5) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-25738 suppressed
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:L/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
MEDIUM (6.7) CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
kubernetes-model-networking-4.10.3.jar Description:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-networking/4.10.3/kubernetes-model-networking-4.10.3.jar
MD5: 2896a6994209aa2e0031e0ca14ad7de3
SHA1: ec16136e628435a4d72adcc2883be27224750750
SHA256: b87286743689abcbd9e96e99e46ae9bdec2a4a25ffcac21248613db1d6a8ec60
Evidence Type Source Name Value Confidence Vendor pom name Fabric8 :: Kubernetes Model :: Networking High Vendor Manifest build-timestamp ${build.datetime} Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-networking Medium Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor file name kubernetes-model-networking High Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-networking/ Low Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor pom artifactid kubernetes-model-networking Low Vendor Manifest specification-vendor Red Hat Low Product pom name Fabric8 :: Kubernetes Model :: Networking High Product Manifest build-timestamp ${build.datetime} Low Product pom artifactid kubernetes-model-networking Highest Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Networking Medium Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-networking Medium Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product file name kubernetes-model-networking High Product jar package name io Highest Product Manifest os-arch amd64 Low Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Networking High Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-networking/ Low Product pom parent-artifactid kubernetes-model-generator Medium Product Manifest specification-title Fabric8 :: Kubernetes Model :: Networking Medium Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
cpe:2.3:a:kubernetes:java:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Low)Notes: A false positives relative to K8S's client that has nothing to do with the imported one by Fabric8 cpe:2.3:a:kubernetes:kubernetes:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Highest)Notes: A whole lot of false positives based on K8S's internals that have nothing to do with our CRDs Suppressed Vulnerabilities CVE-2020-8554 suppressed
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
MEDIUM (5.0) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L References:
Vulnerable Software & Versions:
CVE-2020-8570 suppressed
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:P CVSSv3:
HIGH (7.5) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-25738 suppressed
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:L/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
MEDIUM (6.7) CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
kubernetes-model-policy-4.10.3.jar Description:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-policy/4.10.3/kubernetes-model-policy-4.10.3.jar
MD5: ed96100acb469bf5f58679800453d809
SHA1: 96c6927bb400212fb55ce3869ad014b629018f62
SHA256: aa1c6337d50fe8934f6de3df159f2a34e0065162e9ccfd6f7154dcf225d52dd4
Evidence Type Source Name Value Confidence Vendor file name kubernetes-model-policy High Vendor Manifest build-timestamp ${build.datetime} Low Vendor pom name Fabric8 :: Kubernetes Model :: Policy High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor pom artifactid kubernetes-model-policy Low Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-policy Medium Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-policy/ Low Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Policy Medium Product file name kubernetes-model-policy High Product Manifest build-timestamp ${build.datetime} Low Product pom name Fabric8 :: Kubernetes Model :: Policy High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Policy High Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product jar package name io Highest Product pom artifactid kubernetes-model-policy Highest Product Manifest os-arch amd64 Low Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-policy Medium Product Manifest specification-title Fabric8 :: Kubernetes Model :: Policy Medium Product pom parent-artifactid kubernetes-model-generator Medium Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-policy/ Low Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
cpe:2.3:a:kubernetes:java:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Low)Notes: A false positives relative to K8S's client that has nothing to do with the imported one by Fabric8 cpe:2.3:a:kubernetes:kubernetes:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Highest)Notes: A whole lot of false positives based on K8S's internals that have nothing to do with our CRDs Suppressed Vulnerabilities CVE-2020-8554 suppressed
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
MEDIUM (5.0) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L References:
Vulnerable Software & Versions:
CVE-2020-8570 suppressed
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:P CVSSv3:
HIGH (7.5) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-25738 suppressed
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:L/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
MEDIUM (6.7) CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
kubernetes-model-rbac-4.10.3.jar Description:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-rbac/4.10.3/kubernetes-model-rbac-4.10.3.jar
MD5: df4e63427eaceaf83f51cf7efe2ecea7
SHA1: a0d8a77633a34e5b7d342d044242581116fbac31
SHA256: 559e64c1b8971ebe07d4d48d71d1546e3e298a8dda73859738957bcf97698a8c
Evidence Type Source Name Value Confidence Vendor pom artifactid kubernetes-model-rbac Low Vendor Manifest build-timestamp ${build.datetime} Low Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-rbac/ Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor file name kubernetes-model-rbac High Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-rbac Medium Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Vendor pom name Fabric8 :: Kubernetes Model :: RBAC High Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: RBAC High Product pom artifactid kubernetes-model-rbac Highest Product Manifest build-timestamp ${build.datetime} Low Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-rbac/ Low Product Manifest specification-title Fabric8 :: Kubernetes Model :: RBAC Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product file name kubernetes-model-rbac High Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product jar package name io Highest Product Manifest os-arch amd64 Low Product pom parent-artifactid kubernetes-model-generator Medium Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: RBAC Medium Product jar package name fabric8 Highest Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-rbac Medium Product Manifest os-name Linux Medium Product pom name Fabric8 :: Kubernetes Model :: RBAC High Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
cpe:2.3:a:kubernetes:java:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Low)Notes: A false positives relative to K8S's client that has nothing to do with the imported one by Fabric8 cpe:2.3:a:kubernetes:kubernetes:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Highest)Notes: A whole lot of false positives based on K8S's internals that have nothing to do with our CRDs Suppressed Vulnerabilities CVE-2020-8554 suppressed
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
MEDIUM (5.0) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L References:
Vulnerable Software & Versions:
CVE-2020-8570 suppressed
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:P CVSSv3:
HIGH (7.5) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-25738 suppressed
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:L/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
MEDIUM (6.7) CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
kubernetes-model-scheduling-4.10.3.jar Description:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-scheduling/4.10.3/kubernetes-model-scheduling-4.10.3.jar
MD5: be4662b1c1747a4dfe248b7d58b6f1bb
SHA1: 08a23b73bc2a92690aff91959709c90065a868c2
SHA256: 151e649ba57ddb0429965224e73489d500f49c391070c68bda2a2b11c55b2d71
Evidence Type Source Name Value Confidence Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-scheduling/ Low Vendor Manifest build-timestamp ${build.datetime} Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-scheduling Medium Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom artifactid kubernetes-model-scheduling Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor pom name Fabric8 :: Kubernetes Model :: Scheduling High Vendor file name kubernetes-model-scheduling High Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Scheduling Medium Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-scheduling/ Low Product Manifest build-timestamp ${build.datetime} Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Scheduling High Product pom artifactid kubernetes-model-scheduling Highest Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-scheduling Medium Product jar package name io Highest Product Manifest os-arch amd64 Low Product pom parent-artifactid kubernetes-model-generator Medium Product Manifest specification-title Fabric8 :: Kubernetes Model :: Scheduling Medium Product pom name Fabric8 :: Kubernetes Model :: Scheduling High Product file name kubernetes-model-scheduling High Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
cpe:2.3:a:kubernetes:java:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Low)Notes: A false positives relative to K8S's client that has nothing to do with the imported one by Fabric8 cpe:2.3:a:kubernetes:kubernetes:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Highest)Notes: A whole lot of false positives based on K8S's internals that have nothing to do with our CRDs Suppressed Vulnerabilities CVE-2020-8554 suppressed
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
MEDIUM (5.0) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L References:
Vulnerable Software & Versions:
CVE-2020-8570 suppressed
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:P CVSSv3:
HIGH (7.5) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-25738 suppressed
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:L/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
MEDIUM (6.7) CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
kubernetes-model-settings-4.10.3.jar Description:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-settings/4.10.3/kubernetes-model-settings-4.10.3.jar
MD5: 21c76a9bad8257af78b6fd8ddf9e54dd
SHA1: 3729088030327b772abbc987382385979737fbdd
SHA256: 94c44ffe08999a0f875aae3e545eff15a045fbf6c2b33ed24fa39e8981cea955
Evidence Type Source Name Value Confidence Vendor pom artifactid kubernetes-model-settings Low Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-settings Medium Vendor Manifest build-timestamp ${build.datetime} Low Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-settings/ Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor file name kubernetes-model-settings High Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor pom name Fabric8 :: Kubernetes Model :: Settings High Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-settings Medium Product Manifest build-timestamp ${build.datetime} Low Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Settings High Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-settings/ Low Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest specification-title Fabric8 :: Kubernetes Model :: Settings Medium Product file name kubernetes-model-settings High Product Manifest bundle-docurl http://redhat.com Low Product jar package name kubernetes Highest Product pom groupid io.fabric8 Highest Product pom name Fabric8 :: Kubernetes Model :: Settings High Product jar package name io Highest Product Manifest os-arch amd64 Low Product pom parent-artifactid kubernetes-model-generator Medium Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Settings Medium Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Product pom artifactid kubernetes-model-settings Highest Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
cpe:2.3:a:kubernetes:java:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Low)Notes: A false positives relative to K8S's client that has nothing to do with the imported one by Fabric8 cpe:2.3:a:kubernetes:kubernetes:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Highest)Notes: A whole lot of false positives based on K8S's internals that have nothing to do with our CRDs Suppressed Vulnerabilities CVE-2020-8554 suppressed
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
MEDIUM (5.0) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L References:
Vulnerable Software & Versions:
CVE-2020-8570 suppressed
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:P CVSSv3:
HIGH (7.5) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-25738 suppressed
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:L/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
MEDIUM (6.7) CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
kubernetes-model-storageclass-4.10.3.jar Description:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/kubernetes-model-storageclass/4.10.3/kubernetes-model-storageclass-4.10.3.jar
MD5: b435f102f179b904ecf16f4a0f2ef3b2
SHA1: 846f5abc9af8c1674870984d9c933ee057589087
SHA256: f9fe066696e141b4ddfde6a7e7bd33e499f164950c1bb1b9c09a12ddfba34f53
Evidence Type Source Name Value Confidence Vendor Manifest build-timestamp ${build.datetime} Low Vendor pom artifactid kubernetes-model-storageclass Low Vendor pom name Fabric8 :: Kubernetes Model :: Storage Class High Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-storageclass/ Low Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name kubernetes Highest Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor Manifest bundle-symbolicname io.fabric8.kubernetes-model-storageclass Medium Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Vendor file name kubernetes-model-storageclass High Product Manifest build-timestamp ${build.datetime} Low Product pom name Fabric8 :: Kubernetes Model :: Storage Class High Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/kubernetes-model-storageclass/ Low Product pom artifactid kubernetes-model-storageclass Highest Product Manifest bundle-docurl http://redhat.com Low Product Manifest specification-title Fabric8 :: Kubernetes Model :: Storage Class Medium Product jar package name kubernetes Highest Product Manifest Implementation-Title Fabric8 :: Kubernetes Model :: Storage Class High Product pom groupid io.fabric8 Highest Product jar package name io Highest Product Manifest os-arch amd64 Low Product pom parent-artifactid kubernetes-model-generator Medium Product Manifest bundle-symbolicname io.fabric8.kubernetes-model-storageclass Medium Product Manifest Bundle-Name Fabric8 :: Kubernetes Model :: Storage Class Medium Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Product file name kubernetes-model-storageclass High Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
Suppressed Vulnerabilities CVE-2020-8554 suppressed
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
MEDIUM (5.0) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L References:
Vulnerable Software & Versions:
openshift-model-4.10.3.jar Description:
Java client for Kubernetes and OpenShift License:
http://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/io/fabric8/openshift-model/4.10.3/openshift-model-4.10.3.jar
MD5: 67954130a04755a48d6f49a8f87c917d
SHA1: 182b41135b66fe48b08ee93f1fe801d097f18600
SHA256: 1444819cf232cdb806d2f5c5af68b9085235c23e7092d2b2656499cda939c612
Evidence Type Source Name Value Confidence Vendor Manifest build-timestamp ${build.datetime} Low Vendor Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Vendor pom artifactid openshift-model Low Vendor Manifest Implementation-Vendor Red Hat High Vendor Manifest bundle-symbolicname io.fabric8.openshift-model Medium Vendor Manifest Implementation-Vendor-Id io.fabric8 Medium Vendor pom name Fabric8 :: OpenShift Model High Vendor jar package name openshift Highest Vendor Manifest bundle-docurl http://redhat.com Low Vendor pom groupid io.fabric8 Highest Vendor jar package name io Highest Vendor Manifest os-arch amd64 Low Vendor pom parent-artifactid kubernetes-model-generator Low Vendor Manifest java-vendor Oracle Corporation Medium Vendor file name openshift-model High Vendor jar package name fabric8 Highest Vendor Manifest os-name Linux Medium Vendor Manifest specification-vendor Red Hat Low Vendor Manifest implementation-url http://fabric8.io/kubernetes-model-generator/openshift-model/ Low Product pom artifactid openshift-model Highest Product Manifest Bundle-Name Fabric8 :: OpenShift Model Medium Product Manifest build-timestamp ${build.datetime} Low Product Manifest specification-title Fabric8 :: OpenShift Model Medium Product Manifest require-capability osgi.ee;filter:="(&(osgi.ee=JavaSE)(version=1.8))" Low Product Manifest bundle-symbolicname io.fabric8.openshift-model Medium Product pom name Fabric8 :: OpenShift Model High Product jar package name openshift Highest Product Manifest bundle-docurl http://redhat.com Low Product pom groupid io.fabric8 Highest Product jar package name io Highest Product Manifest os-arch amd64 Low Product file name openshift-model High Product pom parent-artifactid kubernetes-model-generator Medium Product Manifest Implementation-Title Fabric8 :: OpenShift Model High Product jar package name fabric8 Highest Product Manifest os-name Linux Medium Product Manifest implementation-url http://fabric8.io/kubernetes-model-generator/openshift-model/ Low Version Manifest Implementation-Version 4.10.3 High Version Manifest Bundle-Version 4.10.3 High Version pom version 4.10.3 Highest Version file version 4.10.3 High
cpe:2.3:a:kubernetes:java:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Low)Notes: A false positives relative to K8S's client that has nothing to do with the imported one by Fabric8 cpe:2.3:a:kubernetes:kubernetes:4.10.3:*:*:*:*:*:*:* suppressed (Confidence :Low)Notes: A whole lot of false positives based on K8S's internals that have nothing to do with our CRDs Suppressed Vulnerabilities CVE-2020-8554 suppressed
Kubernetes API server in all versions allow an attacker who is able to create a ClusterIP service and set the spec.externalIPs field, to intercept traffic to that IP address. Additionally, an attacker who is able to patch the status (which is considered a privileged operation and should not typically be granted to users) of a LoadBalancer service can set the status.loadBalancer.ingress.ip to similar effect. CWE-863 Incorrect Authorization
CVSSv2:
Base Score: MEDIUM (6.0) Vector: /AV:N/AC:M/Au:S/C:P/I:P/A:P CVSSv3:
MEDIUM (5.0) CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L References:
Vulnerable Software & Versions:
CVE-2020-8570 suppressed
Kubernetes Java client libraries in version 10.0.0 and versions prior to 9.0.1 allow writes to paths outside of the current directory when copying multiple files from a remote pod which sends a maliciously crafted archive. This can potentially overwrite any files on the system of the process executing the client code. CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv2:
Base Score: MEDIUM (6.4) Vector: /AV:N/AC:L/Au:N/C:N/I:P/A:P CVSSv3:
HIGH (7.5) CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N References:
Vulnerable Software & Versions: (show all )
CVE-2021-25738 suppressed
Loading specially-crafted yaml with the Kubernetes Java Client library can lead to code execution. CWE-20 Improper Input Validation
CVSSv2:
Base Score: MEDIUM (4.6) Vector: /AV:L/AC:L/Au:N/C:P/I:P/A:P CVSSv3:
MEDIUM (6.7) CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )
spring-security-jwt-1.1.1.RELEASE.jar Description:
Spring Security JWT is a small utility library for encoding and decoding JSON Web Tokens.
It belongs to the family of Spring Security crypto libraries that handle encoding and decoding text as
a general, useful thing to be able to do. License:
Apache 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt File Path: /home/jenkins/.mvnrepository/org/springframework/security/spring-security-jwt/1.1.1.RELEASE/spring-security-jwt-1.1.1.RELEASE.jar
MD5: 703d7744e66813c46202efbbf645ac8e
SHA1: 32a64cdbe06b8aa8fe98e59689cf0c377725868b
SHA256: acc5a1e0eeeffde0d7b8a18cdbe3245915e00203f90e98db7f3b7dbdeea75e5a
Evidence Type Source Name Value Confidence Vendor pom groupid springframework.security Highest Vendor jar package name jwt Low Vendor pom artifactid spring-security-jwt Low Vendor hint analyzer vendor SpringSource Highest Vendor jar package name jwt Highest Vendor pom url spring-projects/spring-security-oauth Highest Vendor pom groupid org.springframework.security Highest Vendor file name spring-security-jwt High Vendor hint analyzer vendor pivotal software Highest Vendor pom organization name SpringSource High Vendor jar package name security Highest Vendor jar package name springframework Highest Vendor hint analyzer vendor vmware Highest Vendor pom organization url https://www.springsource.com Medium Vendor pom name Spring Security JWT Library High Vendor jar package name crypto Highest Vendor jar package name springframework Low Vendor jar package name security Low Product pom groupid springframework.security Highest Product jar package name jwt Low Product pom artifactid spring-security-jwt Highest Product pom organization url https://www.springsource.com Low Product jar package name jwt Highest Product file name spring-security-jwt High Product pom url spring-projects/spring-security-oauth High Product pom organization name SpringSource Low Product jar package name security Highest Product jar package name springframework Highest Product pom name Spring Security JWT Library High Product jar package name crypto Highest Product jar package name security Low Version pom version 1.1.1.RELEASE Highest
Suppressed Vulnerabilities CVE-2021-22112 suppressed
Spring Security 5.4.x prior to 5.4.4, 5.3.x prior to 5.3.8.RELEASE, 5.2.x prior to 5.2.9.RELEASE, and older unsupported versions can fail to save the SecurityContext if it is changed more than once in a single request.A malicious user cannot cause the bug to happen (it must be programmed in). However, if the application's intent is to only allow the user to run with elevated privileges in a small portion of the application, the bug can be leveraged to extend those privileges to the rest of the application. NVD-CWE-noinfo
Notes: -->
spring-security-jwt*@1.1.1.RELEASE
CVSSv2:
Base Score: HIGH (9.0) Vector: /AV:N/AC:L/Au:S/C:C/I:C/A:C CVSSv3:
HIGH (8.8) CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H References:
Vulnerable Software & Versions: (show all )