Maven · repo1.maven.org
io.streamnative:kafka-clients
Java Process Spawn: Runtime.exec / ProcessBuilder — process spawning.
Why PkgRadar flagged 4.2.0.8
| Severity | Signal | Evidence |
|---|---|---|
| medium | Java Process Spawn | Runtime.exec / ProcessBuilder — process spawning. · org/apache/kafka/common/utils/Shell.java |
| medium | Java Static Init Side Effect | Static-initializer block contains process/network/reflection — runs on first class load (contributory signal). · org/apache/kafka/common/security/oauthbearer/internals/secured/HttpJwtRetriever.java |
Scanned versions
| Version | Verdict | Score | Scanned (UTC) |
|---|---|---|---|
4.2.0.8 | Review | 27 | 2026-06-17 |
Block this in CI
pkgradar gate --ecosystem maven io.streamnative:[email protected]