PkgRadar

Maven · repo1.maven.org

com.xceptance:xlt

Java Unsafe Deserialize, Java Process Spawn, Java Static Init Side Effect

Why PkgRadar flagged 10.0.0-beta-3

SeveritySignalEvidence
mediumJava Unsafe Deserializecom/xceptance/common/util/ObjectUtils.java
mediumJava Process Spawncom/xceptance/common/util/PropertyGroovySecurityUtils.java
mediumJava Process Spawncom/xceptance/xlt/agentcontroller/AgentImpl.java
mediumJava Process Spawncom/xceptance/xlt/clientperformance/ClientPerformanceUtils.java
mediumJava Static Init Side Effectcom/xceptance/xlt/clientperformance/ClientPerformanceUtils.java
mediumJava Static Init Side Effectcom/xceptance/xlt/engine/XltWebClient.java
mediumJava Static Init Side Effectorg/htmlunit/css/CssStyleSheet.java
mediumJava Static Init Side Effectorg/htmlunit/javascript/host/Location.java
mediumJava Static Init Side Effectorg/htmlunit/javascript/host/Window.java
mediumJava Static Init Side Effectorg/htmlunit/util/UrlUtils.java

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
10.0.0-beta-3Review572026-06-23

Block this in CI

PkgRadar gates com.xceptance:xlt (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem maven com.xceptance:[email protected]