PkgRadar

Maven · repo1.maven.org

io.openliberty.tools:ci.common

Java Dynamic Classload, Java Process Spawn, Java Static Init Side Effect

Why PkgRadar flagged 1.8.42

SeveritySignalEvidence
mediumJava Dynamic Classloadio/openliberty/tools/common/plugins/util/ServerFeatureUtil.java
mediumJava Dynamic Classloadio/openliberty/tools/common/plugins/util/PrepareFeatureUtil.java
mediumJava Dynamic Classloadio/openliberty/tools/common/plugins/util/BinaryScannerUtil.java
mediumJava Process Spawnio/openliberty/tools/common/plugins/util/ServerStatusUtil.java
mediumJava Process Spawnio/openliberty/tools/common/plugins/util/InstallFeatureUtil.java
mediumJava Process Spawnio/openliberty/tools/common/plugins/util/DevUtil.java
mediumJava Process Spawnio/openliberty/tools/common/plugins/util/AbstractContainerSupportUtil.java
mediumJava Static Init Side Effectio/openliberty/tools/common/plugins/config/ServerConfigDocument.java

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
1.8.42Review562026-06-24

Block this in CI

PkgRadar gates io.openliberty.tools:ci.common (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem maven io.openliberty.tools:[email protected]