Dependency-Check is an open source tool performing a best effort analysis of 3rd party dependencies;
false positives and false negatives may exist in the analysis performed by the tool. Use of the tool and
the reporting provided constitutes acceptance for use in an AS IS condition, and there are NO warranties,
implied or otherwise, with regard to the analysis or its use. Any use of the tool and the reporting provided
is at the user’s risk. In no event shall the copyright holder or OWASP be held liable for any damages whatsoever
arising out of or in connection with the use of this tool, the analysis performed, or the resulting report.
Scan Information (
show all):
- dependency-check version: 5.2.1
- Report Generated On: Tue, 5 Nov 2019 16:56:25 -0800
- Dependencies Scanned: 9 (9 unique)
- Vulnerable Dependencies: 0
- Vulnerabilities Found: 0
- Vulnerabilities Suppressed: 0
- ...
- NVD CVE Checked: 2019-11-05T16:36:09
- NVD CVE Modified: 2019-11-05T15:01:47
- VersionCheckOn: 2019-11-05T16:36:09
Summary
Display:
Showing Vulnerable Dependencies (click to show all)Dependencies
secret-service-1.0.0-RC.3.jar
Description:
A Java library for storing secrets in a keyring over the D-Bus.
Simply set and get passwords in a linux system.
License:
MIT License: https://opensource.org/licenses/MIT
File Path: /Users/rex.hoffman/.m2/repository/de/swiesend/secret-service/1.0.0-RC.3/secret-service-1.0.0-RC.3.jar
MD5: 9af6171cb69996163eb29b144b62c8fb
SHA1: 02bc8da124aad8ec3a8218e1e93f6006ea5ef999
SHA256:fb53b5d5cc4ecec6a09b1b249d06882184e742a3c8853d29afffa9fad26c4b8d
Referenced In Project/Scope:java-keyring:compile
Evidence
Type | Source | Name | Value | Confidence |
---|
Vendor | file | name | secret-service | High |
Vendor | pom | artifactid | secret-service | Low |
Vendor | pom | name | secret-service | High |
Vendor | jar | package name | keyring | Highest |
Vendor | jar | package name | service | Highest |
Vendor | pom | groupid | de.swiesend | Highest |
Vendor | pom | url | swiesend/secret-service | Highest |
Vendor | jar | package name | secret | Low |
Vendor | jar | package name | freedesktop | Low |
Vendor | jar | package name | secret | Highest |
Product | file | name | secret-service | High |
Product | pom | name | secret-service | High |
Product | jar | package name | keyring | Highest |
Product | pom | artifactid | secret-service | Highest |
Product | jar | package name | service | Highest |
Product | pom | url | swiesend/secret-service | High |
Product | jar | package name | secret | Low |
Product | pom | groupid | de.swiesend | Low |
Product | jar | package name | secret | Highest |
Version | pom | version | 1.0.0-RC.3 | Highest |
dbus-java-3.0.2.jar
Description:
Improved version of the DBus-Java library provided by freedesktop.org (https://dbus.freedesktop.org/doc/dbus-java/).
File Path: /Users/rex.hoffman/.m2/repository/com/github/hypfvieh/dbus-java/3.0.2/dbus-java-3.0.2.jar
MD5: 234b562c94258d34121fcfb1b11fde65
SHA1: 17ca6efc7423711bd6f04567d1bed0c22cfb01aa
SHA256:7be0fa42b2e4e7bed46670cbee7d9ade1057c7a10e4a941f06ca1e0877365574
Referenced In Project/Scope:java-keyring:compile
Evidence
Type | Source | Name | Value | Confidence |
---|
Vendor | file | name | dbus-java | High |
Vendor | pom | artifactid | dbus-java | Low |
Vendor | pom | parent-artifactid | dbus-java-parent | Low |
Vendor | pom | name | ${project.artifactId} | High |
Vendor | Manifest | implementation-url | https://github.com/hypfvieh/dbus-java/dbus-java | Low |
Vendor | Manifest | Implementation-Vendor-Id | com.github.hypfvieh | Medium |
Vendor | jar | package name | freedesktop | Highest |
Vendor | pom | groupid | com.github.hypfvieh | Highest |
Vendor | pom | groupid | github.hypfvieh | Highest |
Vendor | pom | parent-groupid | com.github.hypfvieh | Medium |
Vendor | jar | package name | dbus | Highest |
Product | file | name | dbus-java | High |
Product | pom | name | ${project.artifactId} | High |
Product | pom | artifactid | dbus-java | Highest |
Product | Manifest | Implementation-Title | dbus-java | High |
Product | Manifest | implementation-url | https://github.com/hypfvieh/dbus-java/dbus-java | Low |
Product | pom | groupid | github.hypfvieh | Low |
Product | pom | parent-artifactid | dbus-java-parent | Medium |
Product | jar | package name | freedesktop | Highest |
Product | pom | parent-groupid | com.github.hypfvieh | Low |
Product | jar | package name | dbus | Highest |
Version | pom | version | 3.0.2 | Highest |
Version | file | version | 3.0.2 | Highest |
Version | Manifest | Implementation-Version | 3.0.2 | High |
java-utils-1.0.5.jar
Description:
A collection of utils commonly used in my projects.
Feel free to use it (or parts of it) in your own projects.
License:
MIT License: http://www.opensource.org/licenses/mit-license.php
File Path: /Users/rex.hoffman/.m2/repository/com/github/hypfvieh/java-utils/1.0.5/java-utils-1.0.5.jar
MD5: 9b8a09e7196abe2c585acc7f74854612
SHA1: 32170cb49be33e8fd741770e3750789594fbf472
SHA256:2df8112e350cf38d53e21eb0b477c4136297cdc6d4ed52dbb00377f3a0bfb778
Referenced In Project/Scope:java-keyring:compile
Evidence
Type | Source | Name | Value | Confidence |
---|
Vendor | pom | name | ${project.artifactId} | High |
Vendor | pom | url | hypfvieh/${project.artifactId} | Highest |
Vendor | pom | artifactid | java-utils | Low |
Vendor | Manifest | Implementation-Vendor-Id | com.github.hypfvieh | Medium |
Vendor | jar | package name | github | Highest |
Vendor | pom | groupid | com.github.hypfvieh | Highest |
Vendor | file | name | java-utils | High |
Vendor | Manifest | implementation-url | https://github.com/hypfvieh/java-utils | Low |
Vendor | jar | package name | hypfvieh | Highest |
Vendor | pom | parent-artifactid | mavencentral-deploy | Low |
Vendor | pom | groupid | github.hypfvieh | Highest |
Vendor | pom | parent-groupid | com.github.hypfvieh | Medium |
Product | pom | name | ${project.artifactId} | High |
Product | pom | parent-artifactid | mavencentral-deploy | Medium |
Product | pom | groupid | github.hypfvieh | Low |
Product | pom | url | hypfvieh/${project.artifactId} | High |
Product | jar | package name | github | Highest |
Product | file | name | java-utils | High |
Product | Manifest | Implementation-Title | java-utils | High |
Product | Manifest | implementation-url | https://github.com/hypfvieh/java-utils | Low |
Product | pom | parent-groupid | com.github.hypfvieh | Low |
Product | jar | package name | hypfvieh | Highest |
Product | pom | artifactid | java-utils | Highest |
Version | Manifest | Implementation-Version | 1.0.5 | High |
Version | pom | parent-version | 1.0.5 | Low |
Version | pom | version | 1.0.5 | Highest |
Version | file | version | 1.0.5 | Highest |
hkdf-1.0.2.jar
Description:
A standalone Java implementation of HMAC-based key derivation function (HKDF) defined in RFC 5869 first
described by Hugo Krawczyk. HKDF follows the "extract-then-expand" paradigm compatible with NIST Special
Publication 800-56C
"Two-Step Key Derivation" scheme.
License:
Apache License, Version 2.0: https://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /Users/rex.hoffman/.m2/repository/at/favre/lib/hkdf/1.0.2/hkdf-1.0.2.jar
MD5: b799008b6022361e0fb4a691dda26047
SHA1: fa8be2262e0276d713327dcafe15d303174a23ba
SHA256:90ac3af7ea5e15b1a48fc10150144b0a3729bd39b3ae2345ef98159c3d118a25
Referenced In Project/Scope:java-keyring:compile
Evidence
Type | Source | Name | Value | Confidence |
---|
Vendor | pom | artifactid | hkdf | Low |
Vendor | jar | package name | favre | Low |
Vendor | file | name | hkdf | High |
Vendor | jar | package name | at | Highest |
Vendor | jar | package name | lib | Low |
Vendor | pom | url | patrickfav/hkdf | Highest |
Vendor | jar | package name | at | Low |
Vendor | jar | package name | favre | Highest |
Vendor | jar | package name | lib | Highest |
Vendor | pom | groupid | at.favre.lib | Highest |
Vendor | pom | name | HKDF-RFC5869 | High |
Product | jar | package name | favre | Low |
Product | file | name | hkdf | High |
Product | jar | package name | at | Highest |
Product | pom | artifactid | hkdf | Highest |
Product | pom | groupid | at.favre.lib | Low |
Product | pom | url | patrickfav/hkdf | High |
Product | jar | package name | lib | Low |
Product | jar | package name | favre | Highest |
Product | jar | package name | lib | Highest |
Product | pom | name | HKDF-RFC5869 | High |
Product | jar | package name | crypto | Low |
Version | pom | version | 1.0.2 | Highest |
Version | file | version | 1.0.2 | Highest |
jna-5.5.0.jar
Description:
Java Native Access
License:
LGPL, version 2.1: http://www.gnu.org/licenses/licenses.html
Apache License v2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /Users/rex.hoffman/.m2/repository/net/java/dev/jna/jna/5.5.0/jna-5.5.0.jar
MD5: acfb5b5fd9ee10bf69497792fd469f85
SHA1: 0e0845217c4907822403912ad6828d8e0b256208
SHA256:b308faebfe4ed409de8410e0a632d164b2126b035f6eacff968d3908cafb4d9e
Referenced In Project/Scope:java-keyring:compile
Evidence
Type | Source | Name | Value | Confidence |
---|
Vendor | pom | url | java-native-access/jna | Highest |
Vendor | Manifest | bundle-activationpolicy | lazy | Low |
Vendor | Manifest | bundle-category | jni | Low |
Vendor | jar | package name | native | Highest |
Vendor | Manifest | bundle-requiredexecutionenvironment | JavaSE-1.6 | Low |
Vendor | jar (hint) | package name | oracle | Highest |
Vendor | file | name | jna | High |
Vendor | jar | package name | jna | Highest |
Vendor | Manifest | automatic-module-name | com.sun.jna | Medium |
Vendor | pom | artifactid | jna | Low |
Vendor | Manifest | bundle-symbolicname | com.sun.jna | Medium |
Vendor | Manifest | Implementation-Vendor | JNA Development Team | High |
Vendor | pom | name | Java Native Access | High |
Vendor | pom | groupid | net.java.dev.jna | Highest |
Vendor | Manifest | specification-vendor | JNA Development Team | Low |
Vendor | Manifest | bundle-nativecode | com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win32, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win32, com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win, com/sun/jna/w32ce-arm/jnidispatch.dll; processor=arm;osname=wince, com/sun/jna/sunos-x86/libjnidispatch.so; processor=x86;osname=sunos, com/sun/jna/sunos-x86-64/libjnidispatch.so; processor=x86-64;osname=sunos, com/sun/jna/sunos-sparc/libjnidispatch.so; processor=sparc;osname=sunos, com/sun/jna/sunos-sparcv9/libjnidispatch.so; processor=sparcv9;osname=sunos, com/sun/jna/aix-ppc/libjnidispatch.a; processor=ppc;osname=aix, com/sun/jna/aix-ppc64/libjnidispatch.a; processor=ppc64;osname=aix, com/sun/jna/linux-ppc/libjnidispatch.so; processor=ppc;osname=linux, com/sun/jna/linux-ppc64/libjnidispatch.so; processor=ppc64;osname=linux, com/sun/jna/linux-ppc64le/libjnidispatch.so; processor=ppc64le;osname=linux, com/sun/jna/linux-x86/libjnidispatch.so; processor=x86;osname=linux, com/sun/jna/linux-x86-64/libjnidispatch.so; processor=x86-64;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm_le;osname=linux, com/sun/jna/linux-armel/libjnidispatch.so; processor=armel;osname=linux, com/sun/jna/linux-aarch64/libjnidispatch.so; processor=aarch64;osname=linux, com/sun/jna/linux-ia64/libjnidispatch.so; processor=ia64;osname=linux, com/sun/jna/linux-sparcv9/libjnidispatch.so; processor=sparcv9;osname=linux, com/sun/jna/linux-mips64el/libjnidispatch.so; processor=mips64el;osname=linux, com/sun/jna/linux-s390x/libjnidispatch.so; processor=S390x;osname=linux, com/sun/jna/freebsd-x86/libjnidispatch.so; processor=x86;osname=freebsd, com/sun/jna/freebsd-x86-64/libjnidispatch.so; processor=x86-64;osname=freebsd, com/sun/jna/openbsd-x86/libjnidispatch.so; processor=x86;osname=openbsd, com/sun/jna/openbsd-x86-64/libjnidispatch.so; processor=x86-64;osname=openbsd, com/sun/jna/darwin/libjnidispatch.jnilib; osname=macosx;processor=x86;processor=x86-64;processor=ppc | Low |
Vendor | jar | package name | sun | Highest |
Product | Manifest | bundle-activationpolicy | lazy | Low |
Product | pom | groupid | net.java.dev.jna | Low |
Product | Manifest | bundle-category | jni | Low |
Product | jar | package name | native | Highest |
Product | jar | package name | win32 | Highest |
Product | Manifest | bundle-requiredexecutionenvironment | JavaSE-1.6 | Low |
Product | file | name | jna | High |
Product | jar | package name | jna | Highest |
Product | jar | package name | library | Highest |
Product | Manifest | specification-title | Java Native Access (JNA) | Medium |
Product | Manifest | automatic-module-name | com.sun.jna | Medium |
Product | pom | artifactid | jna | Highest |
Product | Manifest | Implementation-Title | com.sun.jna | High |
Product | pom | url | java-native-access/jna | High |
Product | Manifest | bundle-symbolicname | com.sun.jna | Medium |
Product | Manifest | Bundle-Name | jna | Medium |
Product | pom | name | Java Native Access | High |
Product | Manifest | bundle-nativecode | com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win32, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win32, com/sun/jna/win32-x86/jnidispatch.dll; processor=x86;osname=win, com/sun/jna/win32-x86-64/jnidispatch.dll; processor=x86-64;osname=win, com/sun/jna/w32ce-arm/jnidispatch.dll; processor=arm;osname=wince, com/sun/jna/sunos-x86/libjnidispatch.so; processor=x86;osname=sunos, com/sun/jna/sunos-x86-64/libjnidispatch.so; processor=x86-64;osname=sunos, com/sun/jna/sunos-sparc/libjnidispatch.so; processor=sparc;osname=sunos, com/sun/jna/sunos-sparcv9/libjnidispatch.so; processor=sparcv9;osname=sunos, com/sun/jna/aix-ppc/libjnidispatch.a; processor=ppc;osname=aix, com/sun/jna/aix-ppc64/libjnidispatch.a; processor=ppc64;osname=aix, com/sun/jna/linux-ppc/libjnidispatch.so; processor=ppc;osname=linux, com/sun/jna/linux-ppc64/libjnidispatch.so; processor=ppc64;osname=linux, com/sun/jna/linux-ppc64le/libjnidispatch.so; processor=ppc64le;osname=linux, com/sun/jna/linux-x86/libjnidispatch.so; processor=x86;osname=linux, com/sun/jna/linux-x86-64/libjnidispatch.so; processor=x86-64;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm;osname=linux, com/sun/jna/linux-arm/libjnidispatch.so; processor=arm_le;osname=linux, com/sun/jna/linux-armel/libjnidispatch.so; processor=armel;osname=linux, com/sun/jna/linux-aarch64/libjnidispatch.so; processor=aarch64;osname=linux, com/sun/jna/linux-ia64/libjnidispatch.so; processor=ia64;osname=linux, com/sun/jna/linux-sparcv9/libjnidispatch.so; processor=sparcv9;osname=linux, com/sun/jna/linux-mips64el/libjnidispatch.so; processor=mips64el;osname=linux, com/sun/jna/linux-s390x/libjnidispatch.so; processor=S390x;osname=linux, com/sun/jna/freebsd-x86/libjnidispatch.so; processor=x86;osname=freebsd, com/sun/jna/freebsd-x86-64/libjnidispatch.so; processor=x86-64;osname=freebsd, com/sun/jna/openbsd-x86/libjnidispatch.so; processor=x86;osname=openbsd, com/sun/jna/openbsd-x86-64/libjnidispatch.so; processor=x86-64;osname=openbsd, com/sun/jna/darwin/libjnidispatch.jnilib; osname=macosx;processor=x86;processor=x86-64;processor=ppc | Low |
Product | jar | package name | sun | Highest |
Version | file | version | 5.5.0 | Highest |
Version | pom | version | 5.5.0 | Highest |
Version | Manifest | Bundle-Version | 5.5.0 | High |
jna-platform-5.5.0.jar
Description:
Java Native Access Platform
License:
LGPL, version 2.1: http://www.gnu.org/licenses/licenses.html
Apache License v2.0: http://www.apache.org/licenses/LICENSE-2.0.txt
File Path: /Users/rex.hoffman/.m2/repository/net/java/dev/jna/jna-platform/5.5.0/jna-platform-5.5.0.jar
MD5: 2f4a99c2758e72ee2b59a73586a2322f
SHA1: af38e7c4d0fc73c23ecd785443705bfdee5b90bf
SHA256:24d81621f82ac29fcdd9a74116031f5907a2343158e616f4573bbfa2434ae0d5
Referenced In Project/Scope:java-keyring:compile
Evidence
Type | Source | Name | Value | Confidence |
---|
Vendor | Manifest | bundle-requiredexecutionenvironment | J2SE-1.4 | Low |
Vendor | pom | url | java-native-access/jna | Highest |
Vendor | Manifest | bundle-symbolicname | com.sun.jna.platform | Medium |
Vendor | Manifest | bundle-category | jni | Low |
Vendor | Manifest | automatic-module-name | com.sun.jna.platform | Medium |
Vendor | jar (hint) | package name | oracle | Highest |
Vendor | jar | package name | platform | Highest |
Vendor | jar | package name | jna | Highest |
Vendor | file | name | jna-platform | High |
Vendor | pom | artifactid | jna-platform | Low |
Vendor | Manifest | Implementation-Vendor | JNA Development Team | High |
Vendor | pom | groupid | net.java.dev.jna | Highest |
Vendor | Manifest | specification-vendor | JNA Development Team | Low |
Vendor | pom | name | Java Native Access Platform | High |
Vendor | Manifest | require-bundle | com.sun.jna;bundle-version="5.5.0" | Low |
Vendor | jar | package name | sun | Highest |
Product | Manifest | bundle-requiredexecutionenvironment | J2SE-1.4 | Low |
Product | Manifest | Bundle-Name | jna-platform | Medium |
Product | pom | groupid | net.java.dev.jna | Low |
Product | Manifest | Implementation-Title | com.sun.jna.platform | High |
Product | Manifest | bundle-symbolicname | com.sun.jna.platform | Medium |
Product | Manifest | bundle-category | jni | Low |
Product | Manifest | automatic-module-name | com.sun.jna.platform | Medium |
Product | jar | package name | platform | Highest |
Product | jar | package name | jna | Highest |
Product | Manifest | specification-title | Java Native Access (JNA) | Medium |
Product | file | name | jna-platform | High |
Product | pom | artifactid | jna-platform | Highest |
Product | pom | url | java-native-access/jna | High |
Product | pom | name | Java Native Access Platform | High |
Product | Manifest | require-bundle | com.sun.jna;bundle-version="5.5.0" | Low |
Product | jar | package name | sun | Highest |
Version | file | version | 5.5.0 | Highest |
Version | pom | version | 5.5.0 | Highest |
Version | Manifest | Bundle-Version | 5.5.0 | High |
slf4j-api-1.7.29.jar
Description:
The slf4j API
File Path: /Users/rex.hoffman/.m2/repository/org/slf4j/slf4j-api/1.7.29/slf4j-api-1.7.29.jar
MD5: 75191c97f2d6ef4f990cbb4b2e56a46b
SHA1: e56bf4473a4c6b71c7dd397a833dce86d1993d9d
SHA256:47b624903c712f9118330ad2fb91d0780f7f666c3f22919d0fc14522c5cad9ea
Referenced In Project/Scope:java-keyring:compile
Evidence
Type | Source | Name | Value | Confidence |
---|
Vendor | pom | url | http://www.slf4j.org | Highest |
Vendor | file | name | slf4j-api | High |
Vendor | pom | groupid | org.slf4j | Highest |
Vendor | pom | artifactid | slf4j-api | Low |
Vendor | pom | groupid | slf4j | Highest |
Vendor | pom | parent-artifactid | slf4j-parent | Low |
Vendor | Manifest | bundle-symbolicname | slf4j.api | Medium |
Vendor | pom | name | SLF4J API Module | High |
Vendor | Manifest | bundle-requiredexecutionenvironment | J2SE-1.5 | Low |
Vendor | Manifest | automatic-module-name | org.slf4j | Medium |
Vendor | jar | package name | slf4j | Highest |
Vendor | pom | parent-groupid | org.slf4j | Medium |
Product | file | name | slf4j-api | High |
Product | pom | artifactid | slf4j-api | Highest |
Product | Manifest | Bundle-Name | slf4j-api | Medium |
Product | pom | groupid | slf4j | Low |
Product | Manifest | bundle-symbolicname | slf4j.api | Medium |
Product | pom | name | SLF4J API Module | High |
Product | Manifest | bundle-requiredexecutionenvironment | J2SE-1.5 | Low |
Product | pom | parent-artifactid | slf4j-parent | Medium |
Product | Manifest | automatic-module-name | org.slf4j | Medium |
Product | pom | url | http://www.slf4j.org | Medium |
Product | Manifest | Implementation-Title | slf4j-api | High |
Product | pom | parent-groupid | org.slf4j | Low |
Product | jar | package name | slf4j | Highest |
Version | file | version | 1.7.29 | Highest |
Version | Manifest | Implementation-Version | 1.7.29 | High |
Version | pom | version | 1.7.29 | Highest |
Version | Manifest | Bundle-Version | 1.7.29 | High |
jna-5.5.0.jar: jnidispatch.dll
File Path: /Users/rex.hoffman/.m2/repository/net/java/dev/jna/jna/5.5.0/jna-5.5.0.jar/com/sun/jna/win32-x86/jnidispatch.dll
MD5: 28d895a3cb7e9a0b6a5ae5ed6a62b254
SHA1: 703d8604a8d04d29c52c0ebcde1e86f3bc8ff824
SHA256:04c9a8ab43d1eb616b84d0686c8ae1d881ef03fe4f3aa26511e5b19d35ef16af
Referenced In Project/Scope:java-keyring:compile
Evidence
Type | Source | Name | Value | Confidence |
---|
Vendor | file | name | jnidispatch | High |
Product | file | name | jnidispatch | High |
jna-5.5.0.jar: jnidispatch.dll
File Path: /Users/rex.hoffman/.m2/repository/net/java/dev/jna/jna/5.5.0/jna-5.5.0.jar/com/sun/jna/win32-x86-64/jnidispatch.dll
MD5: e02979ecd43bcc9061eb2b494ab5af50
SHA1: 3122ac0e751660f646c73b10c4f79685aa65c545
SHA256:a66959bec2ef5af730198db9f3b3f7cab0d4ae70ce01bec02bf1d738e6d1ee7a
Referenced In Project/Scope:java-keyring:compile
Evidence
Type | Source | Name | Value | Confidence |
---|
Vendor | file | name | jnidispatch | High |
Product | file | name | jnidispatch | High |