PkgRadar

Maven · repo1.maven.org

io.github.woodser:monero-java

Java Process Spawn: Runtime.exec / ProcessBuilder — process spawning.

Why PkgRadar flagged 0.8.46

SeveritySignalEvidence
mediumJava Process SpawnRuntime.exec / ProcessBuilder — process spawning. · monero/wallet/MoneroWalletRpc.java
mediumJava Process SpawnRuntime.exec / ProcessBuilder — process spawning. · monero/daemon/MoneroDaemonRpc.java
mediumJava Static Init Side EffectStatic-initializer block contains process/network/reflection — runs on first class load (contributory signal). · monero/common/MoneroRpcConnection.java
mediumLarge Native Blob31337392 bytes · linux-arm64/libmonero-cpp.so
mediumLarge Native Blob32080192 bytes · linux-x86_64/libmonero-cpp.so
mediumLarge Native Blob26544616 bytes · mac-x86_64/libmonero-cpp.dylib
mediumLarge Native Blob23239632 bytes · mac-arm64/libmonero-cpp.dylib
mediumLarge Native Blob24661810 bytes · windows/libmonero-cpp.dll

Scanned versions

VersionVerdictScoreScanned (UTC)
0.8.46Review462026-06-17
0.8.45Review462026-06-17

Block this in CI

PkgRadar gates io.github.woodser:monero-java (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem maven io.github.woodser:[email protected]