PkgRadar

Maven · repo1.maven.org

com.github.eirslett:frontend-plugin-core

Java Process Spawn: Runtime.exec / ProcessBuilder — process spawning.

Why PkgRadar flagged 2.0.1

SeveritySignalEvidence
mediumJava Process SpawnRuntime.exec / ProcessBuilder — process spawning. · com/github/eirslett/maven/plugins/frontend/lib/ArchiveExtractor.java
mediumRemote Payloadmatched "github.com/yarnpkg/yarn/releases/download" · com/github/eirslett/maven/plugins/frontend/lib/YarnInstaller.java
mediumRemote Payloadmatched "github.com/oven-sh/bun/releases/download" · com/github/eirslett/maven/plugins/frontend/lib/BunInstaller.java

Scanned versions

VersionVerdictScoreScanned (UTC)
2.0.1Review192026-06-12

Block this in CI

PkgRadar gates com.github.eirslett:frontend-plugin-core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem maven com.github.eirslett:[email protected]