Skip to content

Instantly share code, notes, and snippets.

@ppkarwasz
Last active January 12, 2026 11:36
Show Gist options
  • Select an option

  • Save ppkarwasz/aef756778b0662b8db49416f6c9cdba7 to your computer and use it in GitHub Desktop.

Select an option

Save ppkarwasz/aef756778b0662b8db49416f6c9cdba7 to your computer and use it in GitHub Desktop.
Vulnerabilities in Apache Solr 9.9.0 (build environment + runtime, Maven-only)
# CVEs in Apache Solr 9.9.0 build/runtime environment up to 2025-11-06 (release of 9.10.0)
CVE-2016-1000027
CVE-2020-29582
CVE-2020-36518
CVE-2020-8908
CVE-2022-1471
CVE-2022-24329
CVE-2022-25857
CVE-2022-38749
CVE-2022-38750
CVE-2022-38751
CVE-2022-38752
CVE-2022-41854
CVE-2022-42003
CVE-2022-42004
CVE-2022-42889
CVE-2022-45868
CVE-2023-2976
CVE-2023-33201
CVE-2023-33202
CVE-2023-34055
CVE-2023-4759
CVE-2023-52428
CVE-2024-21634
CVE-2024-21742
CVE-2024-22243
CVE-2024-22259
CVE-2024-22262
CVE-2024-25710
CVE-2024-26308
CVE-2024-29857
CVE-2024-30171
CVE-2024-34447
CVE-2024-38808
CVE-2024-38809
CVE-2024-38816
CVE-2024-38819
CVE-2024-38820
CVE-2024-38828
CVE-2024-47535
CVE-2024-47554
CVE-2024-6763
CVE-2024-7254
CVE-2024-8184
CVE-2025-22233
CVE-2025-22235
CVE-2025-24970
CVE-2025-25193
CVE-2025-27817
CVE-2025-27818
CVE-2025-31672
CVE-2025-41242
CVE-2025-41249
CVE-2025-48734
CVE-2025-48924
CVE-2025-4949
CVE-2025-5115
CVE-2025-52999
CVE-2025-53864
CVE-2025-54988
CVE-2025-55163
CVE-2025-58056
CVE-2025-58057
CVE-2025-58457
CVE-2025-8885
biz.aQute.bnd:biz.aQute.bnd.annotation:6.4.1
ca.cutterslade.gradle:gradle-dependency-analyze:1.10.0
com.adobe.testing:s3mock:2.17.0
com.adobe.testing:s3mock-junit4:2.17.0
com.adobe.testing:s3mock-testsupport-common:2.17.0
com.adobe.xmp:xmpcore:6.1.10
com.amazonaws:aws-java-sdk-core:1.12.501
com.amazonaws:aws-java-sdk-kms:1.12.501
com.amazonaws:aws-java-sdk-s3:1.12.501
com.amazonaws:jmespath-java:1.12.501
com.atlassian.commonmark:commonmark:0.11.0
com.beust:jcommander:1.82
com.carrotsearch:hppc:0.10.0
com.carrotsearch.randomizedtesting:randomizedtesting-runner:2.7.9
com.carrotsearch.randomizedtesting:randomizedtesting-runner:2.8.1
com.cybozu.labs:langdetect:1.1-20120112
com.diffplug.durian:durian-collect:1.2.0
com.diffplug.durian:durian-core:1.2.0
com.diffplug.durian:durian-io:1.2.0
com.diffplug.spotless:spotless-lib:2.25.2
com.diffplug.spotless:spotless-lib-extra:2.25.2
com.diffplug.spotless:spotless-plugin-gradle:6.5.2
com.epam:parso:2.0.14
com.esotericsoftware:minlog:1.3.1
com.fasterxml.jackson.core:jackson-annotations:2.13.1
com.fasterxml.jackson.core:jackson-annotations:2.14.0
com.fasterxml.jackson.core:jackson-annotations:2.16.0
com.fasterxml.jackson.core:jackson-annotations:2.18.0
com.fasterxml.jackson.core:jackson-core:2.13.1
com.fasterxml.jackson.core:jackson-core:2.14.0
com.fasterxml.jackson.core:jackson-core:2.16.0
com.fasterxml.jackson.core:jackson-core:2.18.0
com.fasterxml.jackson.core:jackson-databind:2.13.1
com.fasterxml.jackson.core:jackson-databind:2.14.0
com.fasterxml.jackson.core:jackson-databind:2.16.0
com.fasterxml.jackson.core:jackson-databind:2.18.0
com.fasterxml.jackson.dataformat:jackson-dataformat-cbor:2.18.0
com.fasterxml.jackson.dataformat:jackson-dataformat-csv:2.18.0
com.fasterxml.jackson.dataformat:jackson-dataformat-smile:2.18.0
com.fasterxml.jackson.dataformat:jackson-dataformat-xml:2.18.0
com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.13.1
com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.14.0
com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.16.0
com.fasterxml.jackson.dataformat:jackson-dataformat-yaml:2.18.0
com.fasterxml.jackson.datatype:jackson-datatype-guava:2.13.1
com.fasterxml.jackson.datatype:jackson-datatype-guava:2.14.0
com.fasterxml.jackson.datatype:jackson-datatype-jdk8:2.18.0
com.fasterxml.jackson.datatype:jackson-datatype-joda:2.13.1
com.fasterxml.jackson.datatype:jackson-datatype-joda:2.14.0
com.fasterxml.jackson.datatype:jackson-datatype-jsr310:2.13.1
com.fasterxml.jackson.datatype:jackson-datatype-jsr310:2.14.0
com.fasterxml.jackson.datatype:jackson-datatype-jsr310:2.16.0
com.fasterxml.jackson.datatype:jackson-datatype-jsr310:2.18.0
com.fasterxml.jackson:jackson-bom:2.13.1
com.fasterxml.jackson:jackson-bom:2.14.0
com.fasterxml.jackson:jackson-bom:2.16.0
com.fasterxml.jackson:jackson-bom:2.18.0
com.fasterxml.jackson.jakarta.rs:jackson-jakarta-rs-base:2.18.0
com.fasterxml.jackson.jakarta.rs:jackson-jakarta-rs-json-provider:2.18.0
com.fasterxml.jackson.jaxrs:jackson-jaxrs-base:2.18.0
com.fasterxml.jackson.jaxrs:jackson-jaxrs-json-provider:2.18.0
com.fasterxml.jackson.module:jackson-module-afterburner:2.16.0
com.fasterxml.jackson.module:jackson-module-blackbird:2.16.0
com.fasterxml.jackson.module:jackson-module-jakarta-xmlbind-annotations:2.18.0
com.fasterxml.jackson.module:jackson-module-jaxb-annotations:2.18.0
com.fasterxml.jackson.module:jackson-module-kotlin:2.18.0
com.fasterxml.jackson.module:jackson-module-parameter-names:2.18.0
com.fasterxml.jackson.module:jackson-module-scala_2.13:2.18.0
com.fasterxml.woodstox:woodstox-core:7.0.0
com.github.ben-manes.caffeine:caffeine:2.8.1
com.github.ben-manes.caffeine:caffeine:2.9.3
com.github.ben-manes.caffeine:caffeine:3.1.8
com.github.curious-odd-man:rgxgen:1.3
com.github.curious-odd-man:rgxgen:1.4
com.github.jai-imageio:jai-imageio-core:1.4.0
com.github.java-json-tools:btf:1.3
com.github.java-json-tools:jackson-coreutils:2.0
com.github.java-json-tools:jackson-coreutils-equivalence:1.0
com.github.java-json-tools:json-patch:1.13
com.github.java-json-tools:json-schema-core:1.2.14
com.github.java-json-tools:json-schema-validator:2.2.14
com.github.java-json-tools:msg-simple:1.2
com.github.java-json-tools:uri-template:0.10
com.github.jknack:handlebars:4.2.1
com.github.jknack:handlebars-jackson2:4.2.1
com.github.joschi.jackson:jackson-datatype-threetenbp:2.10.0
com.github.joschi.jackson:jackson-datatype-threetenbp:2.12.5
com.github.junrar:junrar:7.5.3
com.github.kevinstern:software-and-algorithms:1.0
com.github.luben:zstd-jni:1.5.6-4
com.github.mifmif:generex:1.0.2
com.github.node-gradle:gradle-node-plugin:7.0.1
com.github.openjson:openjson:1.0.12
com.github.package-url:packageurl-java:1.4.1
com.github.spotbugs:spotbugs-annotations:4.8.6
com.github.spullara.mustache.java:compiler:0.9.6
com.github.stephenc.jcip:jcip-annotations:1.0-1
com.github.virtuald:curvesapi:1.07
com.google.android:annotations:4.1.1.4
com.google.api:api-common:2.33.0
com.google.api-client:google-api-client:2.6.0
com.google.api:gax:2.50.0
com.google.api:gax-grpc:2.50.0
com.google.api:gax-httpjson:2.50.0
com.google.api.grpc:gapic-google-cloud-storage-v2:2.40.1-alpha
com.google.api.grpc:grpc-google-cloud-storage-v2:2.40.1-alpha
com.google.api.grpc:proto-google-cloud-storage-v2:2.40.1-alpha
com.google.api.grpc:proto-google-common-protos:2.41.0
com.google.api.grpc:proto-google-iam-v1:1.36.0
com.google.apis:google-api-services-storage:v1-rev20240621-2.0.0
com.google.auth:google-auth-library-credentials:1.23.0
com.google.auth:google-auth-library-oauth2-http:1.23.0
com.google.auto:auto-common:1.2.2
com.google.auto.service:auto-service-annotations:1.0.1
com.google.auto.value:auto-value-annotations:1.10.4
com.google.auto.value:auto-value-annotations:1.9
com.google.cloud:google-cloud-bom:0.224.0
com.google.cloud:google-cloud-core:2.40.0
com.google.cloud:google-cloud-core-grpc:2.40.0
com.google.cloud:google-cloud-core-http:2.40.0
com.google.cloud:google-cloud-nio:0.127.20
com.google.cloud:google-cloud-storage:2.40.1
com.googlecode.concurrent-trees:concurrent-trees:2.6.1
com.google.code.findbugs:jsr305:3.0.2
com.google.code.gson:gson:2.11.0
com.google.code.gson:gson:2.9.0
com.googlecode.javaewah:JavaEWAH:1.1.12
com.googlecode.javaewah:JavaEWAH:1.2.3
com.googlecode.json-simple:json-simple:1.1.1
com.googlecode.juniversalchardet:juniversalchardet:1.0.3
com.googlecode.libphonenumber:libphonenumber:8.11.1
com.googlecode.plist:dd-plist:1.24
com.google.errorprone:error_prone_annotation:2.31.0
com.google.errorprone:error_prone_annotations:2.11.0
com.google.errorprone:error_prone_annotations:2.21.1
com.google.errorprone:error_prone_annotations:2.31.0
com.google.errorprone:error_prone_annotations:2.7.1
com.google.errorprone:error_prone_check_api:2.31.0
com.google.errorprone:error_prone_core:2.31.0
com.google.errorprone:error_prone_type_annotations:2.31.0
com.google.guava:failureaccess:1.0.1
com.google.guava:failureaccess:1.0.2
com.google.guava:guava:31.0.1-android
com.google.guava:guava:31.1-jre
com.google.guava:guava:32.1.3-jre
com.google.guava:guava:33.1.0-jre
com.google.guava:listenablefuture:9999.0-empty-to-avoid-conflict-with-guava
com.google.http-client:google-http-client:1.44.2
com.google.http-client:google-http-client-apache-v2:1.44.2
com.google.http-client:google-http-client-appengine:1.44.2
com.google.http-client:google-http-client-gson:1.44.2
com.google.http-client:google-http-client-jackson2:1.44.2
com.google.j2objc:j2objc-annotations:1.3
com.google.j2objc:j2objc-annotations:3.0.0
com.google.oauth-client:google-oauth-client:1.36.0
com.google.protobuf:protobuf-java:3.19.6
com.google.protobuf:protobuf-java:3.21.9
com.google.protobuf:protobuf-java:3.25.3
com.google.protobuf:protobuf-java-util:3.25.3
com.google.re2j:re2j:1.7
com.gradle:common-custom-user-data-gradle-plugin:2.0.2
com.gradle:develocity-gradle-plugin:3.18.2
com.h2database:h2:2.1.214
com.h3xstream.retirejs:retirejs-core:3.0.4
com.hankcs:aho-corasick-double-array-trie:1.2.3
com.healthmarketscience.jackcess:jackcess:4.0.2
com.healthmarketscience.jackcess:jackcess-encrypt:4.0.1
com.helger:profiler:1.1.1
com.ibm.icu:icu4j:74.2
com.j256.simplemagic:simplemagic:1.17
com.jayway.jsonpath:json-path:2.9.0
com.knuddels:jtokkit:1.1.0
com.lmax:disruptor:3.4.4
com.mchange:c3p0:0.9.5.5
com.mchange:mchange-commons-java:0.2.19
com.moandjiezana.toml:toml4j:0.7.2
commons-beanutils:commons-beanutils:1.9.4
commons-cli:commons-cli:1.4
commons-cli:commons-cli:1.5.0
commons-cli:commons-cli:1.9.0
commons-codec:commons-codec:1.11
commons-codec:commons-codec:1.16.0
commons-codec:commons-codec:1.17.1
commons-collections:commons-collections:3.2.2
commons-digester:commons-digester:2.1
commons-io:commons-io:2.11.0
commons-io:commons-io:2.15.0
commons-io:commons-io:2.17.0
commons-logging:commons-logging:1.2
commons-validator:commons-validator:1.7
com.netflix.nebula:nebula-dependency-recommender:11.0.0
com.netflix.nebula:nebula-gradle-interop:1.0.11
com.nimbusds:content-type:2.2
com.nimbusds:lang-tag:1.7
com.nimbusds:nimbus-jose-jwt:9.30.2
com.nimbusds:oauth2-oidc-sdk:10.10.1
com.palantir.gradle.consistentversions:gradle-consistent-versions:2.16.0
com.pff:java-libpst:0.9.3
com.rometools:rome:1.18.0
com.rometools:rome-utils:1.18.0
com.samskivert:jmustache:1.14
com.samskivert:jmustache:1.15
com.squareup.okhttp3:mockwebserver:4.11.0
com.squareup.okhttp3:okhttp:4.12.0
com.squareup.okhttp3:okhttp-sse:4.12.0
com.squareup.okio:okio:3.6.0
com.squareup.okio:okio-jvm:3.6.0
com.squareup.retrofit2:converter-jackson:2.9.0
com.squareup.retrofit2:retrofit:2.9.0
com.sun.activation:jakarta.activation:1.2.2
com.sun.activation:jakarta.activation:2.0.1
com.sun.istack:istack-commons-runtime:3.0.12
com.sun.mail:mailapi:1.6.2
com.tdunning:t-digest:3.3
com.thoughtworks.paranamer:paranamer:2.8
com.typesafe.scala-logging:scala-logging_2.13:3.9.5
com.vaadin.external.google:android-json:0.0.20131108.vaadin1
com.vladsch.flexmark:flexmark:0.64.8
com.vladsch.flexmark:flexmark-ext-abbreviation:0.64.8
com.vladsch.flexmark:flexmark-ext-attributes:0.64.8
com.vladsch.flexmark:flexmark-ext-autolink:0.64.8
com.vladsch.flexmark:flexmark-util:0.64.8
com.vladsch.flexmark:flexmark-util-ast:0.64.8
com.vladsch.flexmark:flexmark-util-builder:0.64.8
com.vladsch.flexmark:flexmark-util-collection:0.64.8
com.vladsch.flexmark:flexmark-util-data:0.64.8
com.vladsch.flexmark:flexmark-util-dependency:0.64.8
com.vladsch.flexmark:flexmark-util-format:0.64.8
com.vladsch.flexmark:flexmark-util-html:0.64.8
com.vladsch.flexmark:flexmark-util-misc:0.64.8
com.vladsch.flexmark:flexmark-util-options:0.64.8
com.vladsch.flexmark:flexmark-util-sequence:0.64.8
com.vladsch.flexmark:flexmark-util-visitor:0.64.8
com.yammer.metrics:metrics-core:2.2.0
com.zaxxer:SparseBitSet:1.2
de.l3s.boilerpipe:boilerpipe:1.1.0
de.thetaphi:forbiddenapis:3.9
de.undercouch:gradle-download-task:5.5.0
dev.ai4j:openai4j:0.22.0
dev.langchain4j:langchain4j-cohere:0.35.0
dev.langchain4j:langchain4j-core:0.35.0
dev.langchain4j:langchain4j-hugging-face:0.35.0
dev.langchain4j:langchain4j-mistral-ai:0.35.0
dev.langchain4j:langchain4j-open-ai:0.35.0
dk.brics.automaton:automaton:1.11-8
edu.ucar:cdm:4.5.5
edu.ucar:grib:4.5.5
edu.ucar:httpservices:4.5.5
edu.ucar:netcdf4:4.5.5
edu.ucar:udunits:4.5.5
edu.usc.ir:sentiment-analysis-parser:0.1
gradle.plugin.io.morethan.jmhreport:gradle-jmh-report:0.9.0
io.dropwizard.metrics:metrics-annotation:4.2.26
io.dropwizard.metrics:metrics-core:4.2.26
io.dropwizard.metrics:metrics-graphite:4.2.26
io.dropwizard.metrics:metrics-healthchecks:4.2.26
io.dropwizard.metrics:metrics-jetty10:4.2.26
io.dropwizard.metrics:metrics-jmx:4.2.26
io.dropwizard.metrics:metrics-json:4.2.26
io.dropwizard.metrics:metrics-jvm:4.2.26
io.dropwizard.metrics:metrics-servlets:4.2.26
io.github.classgraph:classgraph:4.8.165
io.github.eisop:dataflow-errorprone:3.41.0-eisop1
io.github.java-diff-utils:java-diff-utils:4.12
io.github.jeremylong:jcs3-slf4j:1.0.5
io.github.jeremylong:open-vulnerability-clients:5.1.1
io.github.microutils:kotlin-logging:3.0.5
io.github.microutils:kotlin-logging-jvm:3.0.5
io.grpc:grpc-alts:1.65.1
io.grpc:grpc-api:1.65.1
io.grpc:grpc-auth:1.65.1
io.grpc:grpc-context:1.65.1
io.grpc:grpc-core:1.65.1
io.grpc:grpc-googleapis:1.65.1
io.grpc:grpc-grpclb:1.65.1
io.grpc:grpc-inprocess:1.65.1
io.grpc:grpc-netty:1.65.1
io.grpc:grpc-netty-shaded:1.65.1
io.grpc:grpc-protobuf:1.65.1
io.grpc:grpc-protobuf-lite:1.65.1
io.grpc:grpc-rls:1.65.1
io.grpc:grpc-services:1.65.1
io.grpc:grpc-stub:1.65.1
io.grpc:grpc-util:1.65.1
io.grpc:grpc-xds:1.65.1
io.jaegertracing:jaeger-core:1.8.1
io.jaegertracing:jaeger-thrift:1.8.1
io.micrometer:micrometer-core:1.9.12
io.netty:netty-bom:4.1.114.Final
io.netty:netty-buffer:4.1.114.Final
io.netty:netty-codec:4.1.114.Final
io.netty:netty-codec-http2:4.1.114.Final
io.netty:netty-codec-http:4.1.114.Final
io.netty:netty-codec-socks:4.1.114.Final
io.netty:netty-common:4.1.114.Final
io.netty:netty-handler:4.1.114.Final
io.netty:netty-handler-proxy:4.1.114.Final
io.netty:netty-resolver:4.1.114.Final
io.netty:netty-tcnative-boringssl-static:2.0.66.Final
io.netty:netty-tcnative-classes:2.0.66.Final
io.netty:netty-transport:4.1.114.Final
io.netty:netty-transport-classes-epoll:4.1.114.Final
io.netty:netty-transport-native-epoll:4.1.114.Final
io.netty:netty-transport-native-unix-common:4.1.114.Final
io.opencensus:opencensus-api:0.31.1
io.opencensus:opencensus-contrib-http-util:0.31.1
io.opencensus:opencensus-proto:0.2.0
io.opentelemetry:opentelemetry-api:1.40.0
io.opentelemetry:opentelemetry-api-incubator:1.40.0-alpha
io.opentelemetry:opentelemetry-bom:1.40.0
io.opentelemetry:opentelemetry-context:1.40.0
io.opentelemetry:opentelemetry-exporter-common:1.40.0
io.opentelemetry:opentelemetry-exporter-otlp:1.40.0
io.opentelemetry:opentelemetry-exporter-otlp-common:1.40.0
io.opentelemetry:opentelemetry-exporter-sender-okhttp:1.40.0
io.opentelemetry:opentelemetry-opentracing-shim:1.40.0
io.opentelemetry:opentelemetry-sdk:1.40.0
io.opentelemetry:opentelemetry-sdk-common:1.40.0
io.opentelemetry:opentelemetry-sdk-extension-autoconfigure:1.40.0
io.opentelemetry:opentelemetry-sdk-extension-autoconfigure-spi:1.40.0
io.opentelemetry:opentelemetry-sdk-logs:1.40.0
io.opentelemetry:opentelemetry-sdk-metrics:1.40.0
io.opentelemetry:opentelemetry-sdk-trace:1.40.0
io.opentracing:opentracing-api:0.33.0
io.opentracing:opentracing-mock:0.33.0
io.opentracing:opentracing-noop:0.33.0
io.opentracing:opentracing-util:0.33.0
io.perfmark:perfmark-api:0.27.0
io.prometheus:prometheus-metrics-exposition-formats:1.1.0
io.prometheus:prometheus-metrics-model:1.1.0
io.prometheus:simpleclient:0.16.0
io.prometheus:simpleclient_common:0.16.0
io.prometheus:simpleclient_httpserver:0.16.0
io.sgr:s2-geometry-library-java:1.0.0
io.swagger.core.v3:swagger-annotations:2.1.13
io.swagger.core.v3:swagger-annotations:2.2.22
io.swagger.core.v3:swagger-annotations:2.2.4
io.swagger.core.v3:swagger-annotations-jakarta:2.2.22
io.swagger.core.v3:swagger-core:2.1.13
io.swagger.core.v3:swagger-core:2.2.22
io.swagger.core.v3:swagger-core:2.2.4
io.swagger.core.v3:swagger-core-jakarta:2.2.22
io.swagger.core.v3:swagger-gradle-plugin:2.2.2
io.swagger.core.v3:swagger-integration:2.2.22
io.swagger.core.v3:swagger-integration-jakarta:2.2.22
io.swagger.core.v3:swagger-jaxrs2:2.2.22
io.swagger.core.v3:swagger-jaxrs2-jakarta:2.2.22
io.swagger.core.v3:swagger-models:2.1.13
io.swagger.core.v3:swagger-models:2.2.22
io.swagger.core.v3:swagger-models:2.2.4
io.swagger.core.v3:swagger-models-jakarta:2.2.22
io.swagger.parser.v3:swagger-parser:2.0.31
io.swagger.parser.v3:swagger-parser:2.1.6
io.swagger.parser.v3:swagger-parser-core:2.0.31
io.swagger.parser.v3:swagger-parser-core:2.1.6
io.swagger.parser.v3:swagger-parser-v2-converter:2.0.31
io.swagger.parser.v3:swagger-parser-v2-converter:2.1.6
io.swagger.parser.v3:swagger-parser-v3:2.0.31
io.swagger.parser.v3:swagger-parser-v3:2.1.6
io.swagger:swagger-annotations:1.6.5
io.swagger:swagger-annotations:1.6.8
io.swagger:swagger-compat-spec-parser:1.0.57
io.swagger:swagger-compat-spec-parser:1.0.63
io.swagger:swagger-core:1.6.5
io.swagger:swagger-core:1.6.8
io.swagger:swagger-models:1.6.5
io.swagger:swagger-models:1.6.8
io.swagger:swagger-parser:1.0.57
io.swagger:swagger-parser:1.0.63
jakarta.activation:jakarta.activation-api:1.2.1
jakarta.activation:jakarta.activation-api:1.2.2
jakarta.activation:jakarta.activation-api:2.1.3
jakarta.annotation:jakarta.annotation-api:2.1.1
jakarta.inject:jakarta.inject-api:2.0.1
jakarta.servlet:jakarta.servlet-api:4.0.4
jakarta.transaction:jakarta.transaction-api:1.3.3
jakarta.validation:jakarta.validation-api:2.0.2
jakarta.validation:jakarta.validation-api:3.0.2
jakarta.websocket:jakarta.websocket-api:1.1.2
jakarta.ws.rs:jakarta.ws.rs-api:3.1.0
jakarta.xml.bind:jakarta.xml.bind-api:2.3.2
jakarta.xml.bind:jakarta.xml.bind-api:2.3.3
jakarta.xml.bind:jakarta.xml.bind-api:3.0.1
jakarta.xml.bind:jakarta.xml.bind-api:4.0.2
javax.activation:javax.activation-api:1.2.0
javax.inject:javax.inject:1
javax.measure:unit-api:1.0
javax.servlet:javax.servlet-api:3.1.0
javax.validation:validation-api:1.1.0.Final
javax.ws.rs:javax.ws.rs-api:2.0.1
javax.ws.rs:javax.ws.rs-api:2.1
javax.xml.bind:jaxb-api:2.2.12
javax.xml.bind:jaxb-api:2.3.1
joda-time:joda-time:2.10.4
joda-time:joda-time:2.10.8
joda-time:joda-time:2.8.1
junit:junit:4.13.1
junit:junit:4.13.2
net.arnx:jsonic:1.2.7
net.bytebuddy:byte-buddy:1.17.4
net.bytebuddy:byte-buddy-agent:1.17.4
net.gpedro.integrations.slack:slack-webhook:1.4.0
net.java.dev.javacc:javacc:7.0.12
net.java.dev.jna:jna:5.12.1
net.java.dev.jna:jna:5.5.0
net.ltgt.gradle:gradle-errorprone-plugin:3.1.0
net.minidev:accessors-smart:2.4.9
net.minidev:json-smart:2.4.10
net.sf.ehcache:ehcache-core:2.6.2
net.sf.jopt-simple:jopt-simple:5.0.4
net.sourceforge.argparse4j:argparse4j:0.7.0
net.thisptr:jackson-jq:0.0.13
no.nav.security:mock-oauth2-server:0.5.10
org.anarres.jdiagnostics:jdiagnostics:1.0.7
org.antlr:antlr4-runtime:4.11.1
org.apache.calcite.avatica:avatica-core:1.25.0
org.apache.calcite.avatica:avatica-metrics:1.25.0
org.apache.calcite:calcite-core:1.37.0
org.apache.calcite:calcite-linq4j:1.37.0
org.apache.commons:commons-collections4:4.4
org.apache.commons:commons-compress:1.21
org.apache.commons:commons-compress:1.25.0
org.apache.commons:commons-compress:1.26.1
org.apache.commons:commons-configuration2:2.11.0
org.apache.commons:commons-csv:1.9.0
org.apache.commons:commons-dbcp2:2.11.0
org.apache.commons:commons-exec:1.4.0
org.apache.commons:commons-jcs3-core:3.2
org.apache.commons:commons-lang3:3.12.0
org.apache.commons:commons-lang3:3.13.0
org.apache.commons:commons-lang3:3.15.0
org.apache.commons:commons-math3:3.6.1
org.apache.commons:commons-pool2:2.12.0
org.apache.commons:commons-text:1.10.0
org.apache.commons:commons-text:1.11.0
org.apache.commons:commons-text:1.12.0
org.apache.commons:commons-text:1.9
org.apache.curator:curator-client:5.7.0
org.apache.curator:curator-framework:5.7.0
org.apache.curator:curator-recipes:5.7.0
org.apache.hadoop:hadoop-annotations:3.4.0
org.apache.hadoop:hadoop-auth:3.4.0
org.apache.hadoop:hadoop-client-api:3.4.0
org.apache.hadoop:hadoop-client-minicluster:3.4.0
org.apache.hadoop:hadoop-client-runtime:3.4.0
org.apache.hadoop:hadoop-common:3.4.0
org.apache.hadoop:hadoop-hdfs:3.4.0
org.apache.hadoop:hadoop-minikdc:3.4.0
org.apache.hadoop.thirdparty:hadoop-shaded-guava:1.2.0
org.apache.httpcomponents.client5:httpclient5:5.2.1
org.apache.httpcomponents.core5:httpcore5:5.2
org.apache.httpcomponents.core5:httpcore5:5.2.3
org.apache.httpcomponents.core5:httpcore5-h2:5.2
org.apache.httpcomponents:httpclient:4.5.13
org.apache.httpcomponents:httpclient:4.5.14
org.apache.httpcomponents:httpcore:4.4.13
org.apache.httpcomponents:httpcore:4.4.16
org.apache.httpcomponents:httpmime:4.5.14
org.apache.james:apache-mime4j-core:0.8.4
org.apache.james:apache-mime4j-dom:0.8.4
org.apache.kafka:kafka_2.13:3.9.0
org.apache.kafka:kafka-clients:3.9.0
org.apache.kafka:kafka-group-coordinator:3.9.0
org.apache.kafka:kafka-group-coordinator-api:3.9.0
org.apache.kafka:kafka-metadata:3.9.0
org.apache.kafka:kafka-raft:3.9.0
org.apache.kafka:kafka-server:3.9.0
org.apache.kafka:kafka-server-common:3.9.0
org.apache.kafka:kafka-storage:3.9.0
org.apache.kafka:kafka-storage-api:3.9.0
org.apache.kafka:kafka-streams:3.9.0
org.apache.kafka:kafka-tools-api:3.9.0
org.apache.kafka:kafka-transaction-coordinator:3.9.0
org.apache.kerby:kerb-admin:2.0.3
org.apache.kerby:kerb-client:2.0.3
org.apache.kerby:kerb-common:2.0.3
org.apache.kerby:kerb-core:2.0.3
org.apache.kerby:kerb-crypto:2.0.3
org.apache.kerby:kerb-identity:2.0.3
org.apache.kerby:kerb-server:2.0.3
org.apache.kerby:kerb-simplekdc:2.0.3
org.apache.kerby:kerb-util:2.0.3
org.apache.kerby:kerby-asn1:2.0.3
org.apache.kerby:kerby-config:2.0.3
org.apache.kerby:kerby-pkix:2.0.3
org.apache.kerby:kerby-util:2.0.3
org.apache.logging.log4j:log4j-1.2-api:2.21.0
org.apache.logging.log4j:log4j-api:2.21.0
org.apache.logging.log4j:log4j-core:2.21.0
org.apache.logging.log4j:log4j-layout-template-json:2.21.0
org.apache.logging.log4j:log4j-slf4j2-impl:2.21.0
org.apache.logging.log4j:log4j-web:2.21.0
org.apache.lucene:lucene-analysis-common:9.12.2
org.apache.lucene:lucene-analysis-icu:9.12.2
org.apache.lucene:lucene-analysis-kuromoji:9.12.2
org.apache.lucene:lucene-analysis-morfologik:9.12.2
org.apache.lucene:lucene-analysis-nori:9.12.2
org.apache.lucene:lucene-analysis-opennlp:9.12.2
org.apache.lucene:lucene-analysis-phonetic:9.12.2
org.apache.lucene:lucene-analysis-smartcn:9.12.2
org.apache.lucene:lucene-analysis-stempel:9.12.2
org.apache.lucene:lucene-analyzers-common:8.11.2
org.apache.lucene:lucene-backward-codecs:9.12.2
org.apache.lucene:lucene-classification:9.12.2
org.apache.lucene:lucene-codecs:9.12.2
org.apache.lucene:lucene-core:8.11.2
org.apache.lucene:lucene-core:9.12.2
org.apache.lucene:lucene-expressions:9.12.2
org.apache.lucene:lucene-facet:9.12.2
org.apache.lucene:lucene-grouping:9.12.2
org.apache.lucene:lucene-highlighter:9.12.2
org.apache.lucene:lucene-join:9.12.2
org.apache.lucene:lucene-memory:9.12.2
org.apache.lucene:lucene-misc:9.12.2
org.apache.lucene:lucene-queries:8.11.2
org.apache.lucene:lucene-queries:9.12.2
org.apache.lucene:lucene-queryparser:8.11.2
org.apache.lucene:lucene-queryparser:9.12.2
org.apache.lucene:lucene-sandbox:8.11.2
org.apache.lucene:lucene-sandbox:9.12.2
org.apache.lucene:lucene-spatial3d:9.12.2
org.apache.lucene:lucene-spatial-extras:9.12.2
org.apache.lucene:lucene-suggest:9.12.2
org.apache.lucene:lucene-test-framework:9.12.2
org.apache.maven:maven-artifact:3.8.2
org.apache.maven:maven-builder-support:3.8.2
org.apache.maven:maven-model:3.8.2
org.apache.maven:maven-model-builder:3.8.2
org.apache.maven.shared:maven-dependency-analyzer:1.14.1
org.apache.opennlp:opennlp-tools:1.9.4
org.apache.pdfbox:fontbox:2.0.26
org.apache.pdfbox:jbig2-imageio:3.0.4
org.apache.pdfbox:jempbox:1.8.16
org.apache.pdfbox:pdfbox:2.0.26
org.apache.pdfbox:pdfbox-tools:2.0.26
org.apache.pdfbox:preflight:2.0.26
org.apache.pdfbox:xmpbox:2.0.26
org.apache.poi:poi:5.2.2
org.apache.poi:poi-ooxml:5.2.2
org.apache.poi:poi-ooxml-lite:5.2.2
org.apache.poi:poi-scratchpad:5.2.2
org.apache.rat:apache-rat:0.15
org.apache.rat:apache-rat-api:0.15
org.apache.rat:apache-rat-core:0.15
org.apache.rat:apache-rat-tasks:0.15
org.apache.sis.core:sis-feature:1.2
org.apache.sis.core:sis-metadata:1.2
org.apache.sis.core:sis-referencing:1.2
org.apache.sis.core:sis-utility:1.2
org.apache.sis.storage:sis-netcdf:1.2
org.apache.sis.storage:sis-storage:1.2
org.apache.thrift:libthrift:0.15.0
org.apache.tika:tika-core:1.28.5
org.apache.tika:tika-parsers:1.28.5
org.apache.tomcat:annotations-api:6.0.53
org.apache.tomcat.embed:tomcat-embed-el:9.0.76
org.apache.velocity:velocity-engine-core:2.3
org.apache.xmlbeans:xmlbeans:5.0.3
org.apache.yetus:audience-annotations:0.12.0
org.apache.zookeeper:zookeeper:3.9.3
org.apache.zookeeper:zookeeper-jute:3.9.3
org.apiguardian:apiguardian-api:1.1.2
org.bitbucket.b_c:jose4j:0.9.6
org.bouncycastle:bcmail-jdk15on:1.70
org.bouncycastle:bcpg-jdk18on:1.71
org.bouncycastle:bcpkix-jdk15on:1.70
org.bouncycastle:bcpkix-jdk18on:1.78.1
org.bouncycastle:bcprov-jdk15on:1.70
org.bouncycastle:bcprov-jdk18on:1.71
org.bouncycastle:bcprov-jdk18on:1.78.1
org.bouncycastle:bcutil-jdk15on:1.70
org.bouncycastle:bcutil-jdk18on:1.78.1
org.brotli:dec:0.1.2
org.carrot2:carrot2-core:4.5.1
org.carrot2:morfologik-fsa:2.1.9
org.carrot2:morfologik-polish:2.1.9
org.carrot2:morfologik-stemming:2.1.9
org.ccil.cowan.tagsoup:tagsoup:1.2.1
org.checkerframework:checker-compat-qual:2.5.5
org.checkerframework:checker-qual:3.12.0
org.checkerframework:checker-qual:3.19.0
org.checkerframework:checker-qual:3.37.0
org.checkerframework:checker-qual:3.44.0
org.codehaus.groovy:groovy:3.0.9
org.codehaus.groovy:groovy-xml:3.0.9
org.codehaus.janino:commons-compiler:3.1.11
org.codehaus.janino:janino:3.1.11
org.codehaus.plexus:plexus-interpolation:1.25
org.codehaus.plexus:plexus-utils:3.2.1
org.codehaus.woodstox:stax2-api:4.2.2
org.codelibs:jhighlight:1.1.0
org.commonmark:commonmark:0.21.0
org.conscrypt:conscrypt-openjdk-uber:2.5.2
org.eclipse.jdt:ecj:3.33.0
org.eclipse.jetty.http2:http2-client:10.0.22
org.eclipse.jetty.http2:http2-common:10.0.22
org.eclipse.jetty.http2:http2-hpack:10.0.22
org.eclipse.jetty.http2:http2-http-client-transport:10.0.22
org.eclipse.jetty.http2:http2-server:10.0.22
org.eclipse.jetty:jetty-alpn-client:10.0.22
org.eclipse.jetty:jetty-alpn-java-client:10.0.22
org.eclipse.jetty:jetty-alpn-java-server:10.0.22
org.eclipse.jetty:jetty-alpn-server:10.0.22
org.eclipse.jetty:jetty-client:10.0.22
org.eclipse.jetty:jetty-continuation:9.4.49.v20220914
org.eclipse.jetty:jetty-deploy:10.0.22
org.eclipse.jetty:jetty-http:10.0.22
org.eclipse.jetty:jetty-io:10.0.22
org.eclipse.jetty:jetty-jmx:10.0.22
org.eclipse.jetty:jetty-rewrite:10.0.22
org.eclipse.jetty:jetty-security:10.0.22
org.eclipse.jetty:jetty-server:10.0.22
org.eclipse.jetty:jetty-servlet:10.0.22
org.eclipse.jetty:jetty-servlets:10.0.22
org.eclipse.jetty:jetty-start:10.0.22
org.eclipse.jetty:jetty-util:10.0.22
org.eclipse.jetty:jetty-webapp:10.0.22
org.eclipse.jetty:jetty-xml:10.0.22
org.eclipse.jetty.toolchain:jetty-servlet-api:4.0.6
org.eclipse.jgit:org.eclipse.jgit:5.13.0.202109080827-r
org.eclipse.jgit:org.eclipse.jgit:6.7.0.202309050840-r
org.eclipse.packager:packager-core:0.19.0
org.eclipse.packager:packager-rpm:0.19.0
org.eclipse.sisu:org.eclipse.sisu.inject:0.3.4
org.freemarker:freemarker:2.3.32
org.gagravarr:vorbis-java-core:0.8
org.gagravarr:vorbis-java-tika:0.8
org.glassfish.hk2.external:aopalliance-repackaged:3.1.1
org.glassfish.hk2.external:jakarta.inject:2.6.1
org.glassfish.hk2:hk2-api:3.1.1
org.glassfish.hk2:hk2-locator:3.1.1
org.glassfish.hk2:hk2-utils:3.1.1
org.glassfish.hk2:osgi-resource-locator:1.0.3
org.glassfish:javax.json:1.1.4
org.glassfish.jaxb:jaxb-runtime:2.3.8
org.glassfish.jaxb:txw2:2.3.8
org.glassfish.jersey.containers:jersey-container-jetty-http:2.39.1
org.glassfish.jersey.core:jersey-client:3.1.9
org.glassfish.jersey.core:jersey-common:3.1.9
org.glassfish.jersey.core:jersey-server:3.1.9
org.glassfish.jersey.ext:jersey-entity-filtering:3.1.9
org.glassfish.jersey.inject:jersey-hk2:3.1.9
org.glassfish.jersey.media:jersey-media-json-jackson:3.1.9
org.gradle:github-dependency-graph-gradle-plugin:1.4.0
org.hamcrest:hamcrest:3.0
org.hamcrest:hamcrest-core:1.3
org.hamcrest:hamcrest-core:3.0
org.hdrhistogram:HdrHistogram:2.1.12
org.hsqldb:hsqldb:2.7.2
org.immutables:value-annotations:2.10.1
org.itadaki:bzip2:0.9.1
org.javassist:javassist:3.30.2-GA
org.jctools:jctools-core:4.0.5
org.jdom:jdom2:2.0.6.1
org.jetbrains:annotations:13.0
org.jetbrains:annotations:24.0.1
org.jetbrains.kotlin:kotlin-reflect:1.8.22
org.jetbrains.kotlin:kotlin-stdlib:1.1.2-3
org.jetbrains.kotlin:kotlin-stdlib:1.3.30
org.jetbrains.kotlin:kotlin-stdlib:1.3.50
org.jetbrains.kotlin:kotlin-stdlib:1.9.10
org.jetbrains.kotlin:kotlin-stdlib-common:1.3.30
org.jetbrains.kotlin:kotlin-stdlib-common:1.3.50
org.jetbrains.kotlin:kotlin-stdlib-common:1.9.10
org.jetbrains.kotlin:kotlin-stdlib-jdk7:1.3.30
org.jetbrains.kotlin:kotlin-stdlib-jdk7:1.3.50
org.jetbrains.kotlin:kotlin-stdlib-jdk7:1.9.10
org.jetbrains.kotlin:kotlin-stdlib-jdk8:1.3.30
org.jetbrains.kotlin:kotlin-stdlib-jdk8:1.3.50
org.jetbrains.kotlin:kotlin-stdlib-jdk8:1.9.10
org.jsoup:jsoup:1.16.2
org.jspecify:jspecify:1.0.0
org.latencyutils:LatencyUtils:2.0.3
org.locationtech.jts.io:jts-io-common:1.19.0
org.locationtech.jts:jts-core:1.19.0
org.locationtech.proj4j:proj4j:1.2.2
org.locationtech.spatial4j:spatial4j:0.8
org.lz4:lz4-java:1.8.0
org.mockito:mockito-core:5.16.1
org.mockito:mockito-subclass:5.16.1
org.mozilla:rhino:1.7.7.2
org.nibor.autolink:autolink:0.6.0
org.objenesis:objenesis:3.3
org.openapitools:openapi-generator:6.0.1
org.openapitools:openapi-generator:6.6.0
org.openapitools:openapi-generator-core:6.0.1
org.openapitools:openapi-generator-core:6.6.0
org.openapitools:openapi-generator-gradle-plugin:6.0.1
org.openapitools:openapi-generator-gradle-plugin:6.6.0
org.opengis:geoapi:3.0.1
org.openjdk.jmh:jmh-core:1.37
org.openjdk.jmh:jmh-generator-annprocess:1.37
org.osgi:org.osgi.resource:1.0.0
org.osgi:org.osgi.service.serviceloader:1.0.0
org.osgi:osgi.annotation:8.1.0
org.ow2.asm:asm:9.3
org.ow2.asm:asm:9.7
org.ow2.asm:asm-analysis:7.2
org.ow2.asm:asm-commons:7.2
org.ow2.asm:asm-tree:7.2
org.owasp:dependency-check-core:9.0.8
org.owasp:dependency-check-gradle:9.0.8
org.owasp:dependency-check-utils:9.0.8
org.pcollections:pcollections:4.0.1
org.quicktheories:quicktheories:0.26
org.reactivestreams:reactive-streams:1.0.4
org.rocksdb:rocksdbjni:7.9.2
org.scala-lang.modules:scala-collection-compat_2.13:2.10.0
org.scala-lang.modules:scala-java8-compat_2.13:1.0.2
org.scala-lang:scala-library:2.13.15
org.scala-lang:scala-reflect:2.13.14
org.semver4j:semver4j:5.2.2
org.semver4j:semver4j:5.3.0
org.slf4j:jcl-over-slf4j:1.7.28
org.slf4j:jcl-over-slf4j:2.0.13
org.slf4j:jul-to-slf4j:2.0.13
org.slf4j:slf4j-api:1.7.36
org.slf4j:slf4j-api:2.0.13
org.slf4j:slf4j-ext:1.7.36
org.slf4j:slf4j-simple:1.7.36
org.sonatype.goodies:package-url-java:1.1.1
org.sonatype.ossindex:ossindex-service-api:1.8.2
org.sonatype.ossindex:ossindex-service-client:1.8.2
org.springframework.boot:spring-boot:2.7.13
org.springframework.boot:spring-boot-actuator:2.7.13
org.springframework.boot:spring-boot-actuator-autoconfigure:2.7.13
org.springframework.boot:spring-boot-autoconfigure:2.7.13
org.springframework.boot:spring-boot-starter:2.7.13
org.springframework.boot:spring-boot-starter-actuator:2.7.13
org.springframework.boot:spring-boot-starter-jetty:2.7.13
org.springframework.boot:spring-boot-starter-json:2.7.13
org.springframework.boot:spring-boot-starter-logging:2.7.13
org.springframework.boot:spring-boot-starter-web:2.7.13
org.springframework:spring-aop:5.3.28
org.springframework:spring-beans:5.3.28
org.springframework:spring-context:5.3.28
org.springframework:spring-core:5.3.28
org.springframework:spring-expression:5.3.28
org.springframework:spring-jcl:5.3.28
org.springframework:spring-web:5.3.28
org.springframework:spring-webmvc:5.3.28
org.tallison:isoparser:1.9.41.7
org.tallison:jmatio:1.5
org.tallison:metadata-extractor:2.17.1.0
org.tallison.xmp:xmpcore-shaded:6.1.10
org.threeten:threetenbp:1.4.0
org.threeten:threetenbp:1.5.1
org.threeten:threetenbp:1.6.9
org.tukaani:xz:1.9
org.whitesource:pecoff4j:0.0.2.1
org.xerial.snappy:snappy-java:1.1.10.5
org.yaml:snakeyaml:1.28
org.yaml:snakeyaml:1.30
org.yaml:snakeyaml:1.33
org.yaml:snakeyaml:2.2
software.amazon.awssdk:annotations:2.31.77
software.amazon.awssdk:apache-client:2.31.77
software.amazon.awssdk:arns:2.31.77
software.amazon.awssdk:auth:2.31.77
software.amazon.awssdk:aws-core:2.31.77
software.amazon.awssdk:aws-query-protocol:2.31.77
software.amazon.awssdk:aws-xml-protocol:2.31.77
software.amazon.awssdk:bom:2.31.77
software.amazon.awssdk:checksums:2.31.77
software.amazon.awssdk:checksums-spi:2.31.77
software.amazon.awssdk:crt-core:2.31.77
software.amazon.awssdk:endpoints-spi:2.31.77
software.amazon.awssdk:http-auth:2.31.77
software.amazon.awssdk:http-auth-aws:2.31.77
software.amazon.awssdk:http-auth-aws-eventstream:2.31.77
software.amazon.awssdk:http-auth-spi:2.31.77
software.amazon.awssdk:http-client-spi:2.31.77
software.amazon.awssdk:identity-spi:2.31.77
software.amazon.awssdk:json-utils:2.31.77
software.amazon.awssdk:metrics-spi:2.31.77
software.amazon.awssdk:profiles:2.31.77
software.amazon.awssdk:protocol-core:2.31.77
software.amazon.awssdk:regions:2.31.77
software.amazon.awssdk:retries:2.31.77
software.amazon.awssdk:retries-spi:2.31.77
software.amazon.awssdk:s3:2.31.77
software.amazon.awssdk:sdk-core:2.31.77
software.amazon.awssdk:sts:2.31.77
software.amazon.awssdk:third-party-jackson-core:2.31.77
software.amazon.awssdk:url-connection-client:2.31.77
software.amazon.awssdk:utils:2.31.77
software.amazon.eventstream:eventstream:1.0.1
software.amazon.ion:ion-java:1.0.2
ua.net.nlp:morfologik-ukrainian-search:4.9.1
us.springett:cpe-parser:2.0.3
xerces:xercesImpl:2.12.2
#!/bin/bash
INPUT=$1
cat $INPUT | while IFS= read -r gav; do
parts=(${gav//:/ })
curl -L --silent \
-H "Accept: application/vnd.github+json" \
-H "X-GitHub-Api-Version: 2022-11-28" \
-H "Authorization: Bearer $GITHUB_TOKEN" \
"https://api.github.com/advisories?ecosystem=maven&affects=${parts[0]}:${parts[1]}@${parts[2]}" \
| jq -r .[].cve_id
done | sort -u
./gradlew -I init.gradle \
--dependency-verification=off \
--no-configuration-cache \
--no-configure-on-demand \
:ForceDependencyResolutionPlugin_resolveAllDependencies
jq -r .[].allDependencies[].id \
< build/reports/dependency-graph-snapshots/dependency-graph.json \
| grep -v '^\(root \)\?project' \
| sort -u > deps.txt
initscript {
repositories {
gradlePluginPortal()
}
dependencies {
classpath "org.gradle:github-dependency-graph-gradle-plugin:+"
}
}
apply plugin: org.gradle.dependencygraph.simple.SimpleDependencyGraphPlugin
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment