PkgRadar

Maven · repo1.maven.org

org.daisy.dotify:dotify.library

Java Unsafe Deserialize

Why PkgRadar flagged 1.0.10

SeveritySignalEvidence
mediumJava Unsafe Deserializeorg/daisy/braille/utils/pef/PEFBookLoader.java
mediumJava Unsafe Deserializeorg/daisy/dotify/api/paper/UserPapersCollection.java

Showing signal labels only. Sign in to view the exact matched indicators for each finding.

Scanned versions

VersionVerdictScoreScanned (UTC)
1.0.10Review402026-06-22

Block this in CI

PkgRadar gates org.daisy.dotify:dotify.library (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem maven org.daisy.dotify:[email protected]