PkgRadar

Maven · repo1.maven.org

net.thevpc.nuts:nuts-runtime

Java Process Spawn: Runtime.exec / ProcessBuilder — process spawning.

Why PkgRadar flagged 0.8.9.0

SeveritySignalEvidence
mediumJava Process SpawnRuntime.exec / ProcessBuilder — process spawning. · net/thevpc/nuts/runtime/standalone/executor/system/ProcessBuilder2.java
mediumJava Process SpawnRuntime.exec / ProcessBuilder — process spawning. · net/thevpc/nuts/runtime/standalone/installer/svc/DefaultInstallSvcCommand.java
mediumRemote Payloadmatched "raw.githubusercontent.com" · net/thevpc/nuts/runtime/standalone/workspace/cmd/recom/AbstractRecommendationConnector.java
mediumRemote Payloadmatched "raw.githubusercontent.com" · net/thevpc/nuts/runtime/standalone/repository/impl/defaults/DefaultNRepoFactoryComponent.java

Scanned versions

VersionVerdictScoreScanned (UTC)
0.8.9.0Review542026-06-11

Block this in CI

PkgRadar gates net.thevpc.nuts:nuts-runtime (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem maven net.thevpc.nuts:[email protected]