Maven · repo1.maven.org
fr.inria.gforge.spoon:spoon-core
Java Unsafe Deserialize, Java Dynamic Classload, Java Process Spawn
Why PkgRadar flagged 11.3.1-beta-9
| Severity | Signal | Evidence |
|---|---|---|
| medium | Java Unsafe Deserialize | spoon/IncrementalLauncher.java |
| medium | Java Unsafe Deserialize | spoon/support/SerializationModelStreamer.java |
| medium | Java Dynamic Classload | spoon/support/StandardEnvironment.java |
| medium | Java Unsafe Deserialize | spoon/support/util/ByteSerialization.java |
| medium | Java Process Spawn | spoon/support/compiler/SpoonPom.java |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
11.3.1-beta-9 | Review | 25 | 2026-06-21 |
Block this in CI
pkgradar gate --ecosystem maven fr.inria.gforge.spoon:[email protected]