Skip to content

Unsafe Dependency Resolution through guru.nidi:code-assert #207

Open
@bonndan

Description

@bonndan

Hi!

First of all thanks for graphviz-java which works like a charm for my purposes.

My code is inspected by snyk.io and I get the following warning:

Affected module: com.beust:jcommander@1.48

Introduced through: guru.nidi:graphviz-java@0.18.1

Exploit maturity: No known exploit

Fixed in: com.beust:jcommander@1.75

Detailed paths
Introduced through: guru.nidi:graphviz-java@0.18.1 › guru.nidi:code-assert@0.9.15 › net.sourceforge.pmd:pmd-java@5.8.1 › net.sourceforge.pmd:pmd-core@5.8.1 › com.beust:jcommander@1.48

Could you have a look at that?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions