Maven · repo1.maven.org
com.google.javascript:closure-compiler-unshaded
Java Unsafe Deserialize: ObjectInputStream / XStream.fromXML — untrusted deserialization sink.
Why PkgRadar flagged v20260610
| Severity | Signal | Evidence |
|---|---|---|
| medium | Java Unsafe Deserialize | ObjectInputStream / XStream.fromXML — untrusted deserialization sink. · com/google/javascript/jscomp/Compiler.java |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
v20260610 | Review | 6 | 2026-06-11 |
v20260607 | Review | 6 | 2026-06-09 |
v20260526 | Review | 6 | 2026-05-28 |
Block this in CI
pkgradar gate --ecosystem maven com.google.javascript:closure-compiler-unshaded@v20260610