Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies; false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.

How to read the report | Suppressing false positives | Getting Help: github issues

Project: java-keyring-parent

com.github.javakeyring:java-keyring-parent:1.0.1

Scan Information (show all):

Summary

Display: Showing Vulnerable Dependencies (click to show all)

DependencyVulnerability IDsPackageHighest SeverityCVE CountConfidenceEvidence Count
secret-service-1.0.0-RC.3.jarpkg:maven/de.swiesend/secret-service@1.0.0-RC.3 020
dbus-java-3.0.2.jarpkg:maven/com.github.hypfvieh/dbus-java@3.0.2 024
java-utils-1.0.5.jarpkg:maven/com.github.hypfvieh/java-utils@1.0.5 027
hkdf-1.0.2.jarpkg:maven/at.favre.lib/hkdf@1.0.2 024
jna-5.5.0.jarpkg:maven/net.java.dev.jna/jna@5.5.0 039
jna-platform-5.5.0.jarpkg:maven/net.java.dev.jna/jna-platform@5.5.0 035
slf4j-api-1.7.29.jarpkg:maven/org.slf4j/slf4j-api@1.7.29 029
jna-5.5.0.jar: jnidispatch.dll 02
jna-5.5.0.jar: jnidispatch.dll 02

Dependencies

secret-service-1.0.0-RC.3.jar

Description:

        A Java library for storing secrets in a keyring over the D-Bus.
        Simply set and get passwords in a linux system.
    

License:

MIT License: https://opensource.org/licenses/MIT
File Path: /Users/rex.hoffman/.m2/repository/de/swiesend/secret-service/1.0.0-RC.3/secret-service-1.0.0-RC.3.jar
MD5: 9af6171cb69996163eb29b144b62c8fb
SHA1: 02bc8da124aad8ec3a8218e1e93f6006ea5ef999
SHA256:fb53b5d5cc4ecec6a09b1b249d06882184e742a3c8853d29afffa9fad26c4b8d
Referenced In Project/Scope:java-keyring:compile

Identifiers

dbus-java-3.0.2.jar

Description:

        Improved version of the DBus-Java library provided by freedesktop.org (https://dbus.freedesktop.org/doc/dbus-java/).
    

File Path: /Users/rex.hoffman/.m2/repository/com/github/hypfvieh/dbus-java/3.0.2/dbus-java-3.0.2.jar
MD5: 234b562c94258d34121fcfb1b11fde65
SHA1: 17ca6efc7423711bd6f04567d1bed0c22cfb01aa
SHA256:7be0fa42b2e4e7bed46670cbee7d9ade1057c7a10e4a941f06ca1e0877365574
Referenced In Project/Scope:java-keyring:compile

Identifiers

java-utils-1.0.5.jar

Description:

		A collection of utils commonly used in my projects.
		Feel free to use it (or parts of it) in your own projects.
	

License:

MIT License: http://www.opensource.org/licenses/mit-license.php
File Path: /Users/rex.hoffman/.m2/repository/com/github/hypfvieh/java-utils/1.0.5/java-utils-1.0.5.jar
MD5: 9b8a09e7196abe2c585acc7f74854612
SHA1: 32170cb49be33e8fd741770e3750789594fbf472
SHA256:2df8112e350cf38d53e21eb0b477c4136297cdc6d4ed52dbb00377f3a0bfb778
Referenced In Project/Scope:java-keyring:compile

Identifiers

hkdf-1.0.2.jar

Description:

A standalone Java implementation of HMAC-based key derivation function (HKDF) defined in RFC 5869 first
        described by Hugo Krawczyk. HKDF follows the "extract-then-expand" paradigm compatible with NIST Special
        Publication 800-56C
        "Two-Step Key Derivation" scheme.
    

License:

Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /Users/rex.hoffman/.m2/repository/at/favre/lib/hkdf/1.0.2/hkdf-1.0.2.jar
MD5: b799008b6022361e0fb4a691dda26047
SHA1: fa8be2262e0276d713327dcafe15d303174a23ba
SHA256:90ac3af7ea5e15b1a48fc10150144b0a3729bd39b3ae2345ef98159c3d118a25
Referenced In Project/Scope:java-keyring:compile

Identifiers

jna-5.5.0.jar

Description:

Java Native Access

License:

LGPL, version 2.1: http://www.gnu.org/licenses/licenses.html
Apache License v2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /Users/rex.hoffman/.m2/repository/net/java/dev/jna/jna/5.5.0/jna-5.5.0.jar
MD5: acfb5b5fd9ee10bf69497792fd469f85
SHA1: 0e0845217c4907822403912ad6828d8e0b256208
SHA256:b308faebfe4ed409de8410e0a632d164b2126b035f6eacff968d3908cafb4d9e
Referenced In Project/Scope:java-keyring:compile

Identifiers

jna-platform-5.5.0.jar

Description:

Java Native Access Platform

License:

LGPL, version 2.1: http://www.gnu.org/licenses/licenses.html
Apache License v2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /Users/rex.hoffman/.m2/repository/net/java/dev/jna/jna-platform/5.5.0/jna-platform-5.5.0.jar
MD5: 2f4a99c2758e72ee2b59a73586a2322f
SHA1: af38e7c4d0fc73c23ecd785443705bfdee5b90bf
SHA256:24d81621f82ac29fcdd9a74116031f5907a2343158e616f4573bbfa2434ae0d5
Referenced In Project/Scope:java-keyring:compile

Identifiers

slf4j-api-1.7.29.jar

Description:

The slf4j API

File Path: /Users/rex.hoffman/.m2/repository/org/slf4j/slf4j-api/1.7.29/slf4j-api-1.7.29.jar
MD5: 75191c97f2d6ef4f990cbb4b2e56a46b
SHA1: e56bf4473a4c6b71c7dd397a833dce86d1993d9d
SHA256:47b624903c712f9118330ad2fb91d0780f7f666c3f22919d0fc14522c5cad9ea
Referenced In Project/Scope:java-keyring:compile

Identifiers

jna-5.5.0.jar: jnidispatch.dll

File Path: /Users/rex.hoffman/.m2/repository/net/java/dev/jna/jna/5.5.0/jna-5.5.0.jar/com/sun/jna/win32-x86/jnidispatch.dll
MD5: 28d895a3cb7e9a0b6a5ae5ed6a62b254
SHA1: 703d8604a8d04d29c52c0ebcde1e86f3bc8ff824
SHA256:04c9a8ab43d1eb616b84d0686c8ae1d881ef03fe4f3aa26511e5b19d35ef16af
Referenced In Project/Scope:java-keyring:compile

Identifiers

  • None

jna-5.5.0.jar: jnidispatch.dll

File Path: /Users/rex.hoffman/.m2/repository/net/java/dev/jna/jna/5.5.0/jna-5.5.0.jar/com/sun/jna/win32-x86-64/jnidispatch.dll
MD5: e02979ecd43bcc9061eb2b494ab5af50
SHA1: 3122ac0e751660f646c73b10c4f79685aa65c545
SHA256:a66959bec2ef5af730198db9f3b3f7cab0d4ae70ce01bec02bf1d738e6d1ee7a
Referenced In Project/Scope:java-keyring:compile

Identifiers

  • None


This report contains data retrieved from the National Vulnerability Database.
This report may contain data retrieved from the NPM Public Advisories.
This report may contain data retrieved from RetireJS.
This report may contain data retrieved from the Sonatype OSS Index.