Flagsmith / Flagsmith/flagsmith-java-client
Dependency Resolution: org.apache.maven:maven-artifact resolving org.codehaus.plexus:plexus-utils
- Dominant language
- Java
- Stars
- 28
- Forks
- 22
- PR merge metrics
- No merged PRs in 30d
Description
Our vulnerability scanner is flagging a vulnerability in `org.codehaus.plexus:plexus-utils`, and it looks like it is being pulled in transitively via this library.
https://github.com/Flagsmith/flagsmith-java-client/blob/main/pom.xml#L105-L109
```
> ./gradlew :dependencyInsight --dependency org.codehaus.plexus:plexus-utils --configuration compileClasspath
org.codehaus.plexus:plexus-utils:3.2.1
\--- org.apache.maven:maven-artifact:3.6.3
+--- compileClasspath (requested org.apache.maven:maven-artifact:{strictly 3.6.3})
\--- com.flagsmith:flagsmith-java-client:8.1.1
+--- compileClasspath
```
Two questions:
1. Is this library required for run time?
2. Is the expectation that consumers pin this version to a newer one?
I also suspect its flagging what is possibly a false positive, but of course, since the scanner flags it people are complaining.
Contributor guide
No contributing guide indexed for this repository
Research direction
Inspect pom.xml lines 105-109 and run the reported dependencyInsight command for org.codehaus.plexus:plexus-utils. Trace why org.apache.maven:maven-artifact is present, determine whether it is needed at runtime, and document or implement the supported version-resolution approach for consumers.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- build-system, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100