Flagsmith / Flagsmith/flagsmith-java-client

Dependency Resolution: org.apache.maven:maven-artifact resolving org.codehaus.plexus:plexus-utils

Open
#217 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
28
Forks
22
PR merge metrics
No merged PRs in 30d

Description

Our vulnerability scanner is flagging a vulnerability in `org.codehaus.plexus:plexus-utils`, and it looks like it is being pulled in transitively via this library.

https://github.com/Flagsmith/flagsmith-java-client/blob/main/pom.xml#L105-L109

```
> ./gradlew :dependencyInsight --dependency org.codehaus.plexus:plexus-utils --configuration compileClasspath
org.codehaus.plexus:plexus-utils:3.2.1
\--- org.apache.maven:maven-artifact:3.6.3
+--- compileClasspath (requested org.apache.maven:maven-artifact:{strictly 3.6.3})
\--- com.flagsmith:flagsmith-java-client:8.1.1
+--- compileClasspath
```

Two questions:
1. Is this library required for run time?
2. Is the expectation that consumers pin this version to a newer one?

I also suspect its flagging what is possibly a false positive, but of course, since the scanner flags it people are complaining.

Contributor guide

No contributing guide indexed for this repository

Research direction

Inspect pom.xml lines 105-109 and run the reported dependencyInsight command for org.codehaus.plexus:plexus-utils. Trace why org.apache.maven:maven-artifact is present, determine whether it is needed at runtime, and document or implement the supported version-resolution approach for consumers.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
build-system, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.