PkgRadar

Maven · repo1.maven.org

com.vaadin:copilot

Java Process Spawn: Runtime.exec / ProcessBuilder — process spawning.

Why PkgRadar flagged 25.2.0-beta2

SeveritySignalEvidence
mediumJava Process SpawnRuntime.exec / ProcessBuilder — process spawning. · com/vaadin/copilot/ide/IdeUtils.java
mediumRemote Payloadmatched "github.com/HotswapProjects/HotswapAgent/releases/download" · com/vaadin/copilot/HotswapAgentDownloader.java
mediumRemote Payloadmatched "cUrl " · com/vaadin/copilot/SpringIntegration.java
mediumLarge Native Blob6500440 bytes · META-INF/native/libcom_vaadin_copilot_shaded_netty_quiche42_linux_x86_64.so
mediumLarge Native Blob6472008 bytes · META-INF/native/libcom_vaadin_copilot_shaded_netty_quiche42_linux_aarch_64.so
mediumLarge Native Blob6526144 bytes · META-INF/native/libcom_vaadin_copilot_shaded_netty_quiche42_osx_x86_64.jnilib
mediumLarge Native Blob6236656 bytes · META-INF/native/libcom_vaadin_copilot_shaded_netty_quiche42_osx_aarch_64.jnilib

Scanned versions

VersionVerdictScoreScanned (UTC)
25.2.0-beta2Review392026-06-12

Block this in CI

PkgRadar gates com.vaadin:copilot (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem maven com.vaadin:[email protected]