PkgRadar

Maven · repo1.maven.org

com.sagframe:sagacity-sqltoy

Java Unsafe Deserialize: ObjectInputStream / XStream.fromXML — untrusted deserialization sink.

Why PkgRadar flagged 5.6.80.jre8

SeveritySignalEvidence
mediumJava Unsafe DeserializeObjectInputStream / XStream.fromXML — untrusted deserialization sink. · org/sagacity/sqltoy/utils/IOUtil.java

Scanned versions

VersionVerdictScoreScanned (UTC)
5.6.80.jre8Review202026-06-11
5.6.79.jre8Review102026-06-11
5.6.79Review102026-06-11
5.6.79.RC5Review102026-06-11
5.6.79.RC4Review102026-06-11
5.6.79.RC3Review102026-06-11
5.6.79.RC2Review202026-06-10

Block this in CI

PkgRadar gates com.sagframe:sagacity-sqltoy (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem maven com.sagframe:[email protected]