PkgRadar

Maven · repo1.maven.org

org.hl7.fhir.publisher:org.hl7.fhir.publisher.core

Java Process Spawn: Runtime.exec / ProcessBuilder — process spawning.

Why PkgRadar flagged 2.2.9

SeveritySignalEvidence
mediumJava Process SpawnRuntime.exec / ProcessBuilder — process spawning. · org/hl7/fhir/igtools/publisher/FSHRunner.java
mediumJava Process SpawnRuntime.exec / ProcessBuilder — process spawning. · org/hl7/fhir/igtools/publisher/GitUtilities.java
mediumJava Process SpawnRuntime.exec / ProcessBuilder — process spawning. · org/hl7/fhir/igtools/publisher/PublisherGenerator.java
mediumRemote Payloadmatched "cURL " · org/hl7/fhir/igtools/web/PublicationProcess.java

Scanned versions

VersionVerdictScoreScanned (UTC)
2.2.9Review172026-06-12

Block this in CI

PkgRadar gates org.hl7.fhir.publisher:org.hl7.fhir.publisher.core (and every other dependency) before it merges. One line in your pipeline:

pkgradar gate --ecosystem maven org.hl7.fhir.publisher:[email protected]