github-actions[bot] commented on PR #230:
URL: 
https://github.com/apache/santuario-xml-security-java/pull/230#issuecomment-1769929729

   <h1>Dependency Review</h1>
   The following issues were found:<ul><li>❌ 3 vulnerable package(s)</li><li>✅ 
0 package(s) with incompatible licenses</li><li>✅ 0 package(s) with invalid 
SPDX license definitions</li><li>⚠️ 4 package(s) with unknown 
licenses.</li></ul>
   See the Details below.<h2>Vulnerabilities</h2>
   <h4><em>pom.xml</em></h4>
   
<table><tr><th>Name</th><th>Version</th><th>Vulnerability</th><th>Severity</th></tr><tr><td>xalan:xalan</td><td>2.7.1</td><td><a
 href="https://github.com/advisories/GHSA-rc2w-r4jq-7pfx";>Improper 
Authorization in Apache Xalan-Java</a></td><td>high</td></tr><tr><td 
colspan="2"><td><a 
href="https://github.com/advisories/GHSA-9339-86wc-4qgf";>Apache Xalan Java XSLT 
library integer truncation issue when processing malicious XSLT 
stylesheets</a></td><td>high</td></tr><tr><td>xalan:xalan</td><td>2.7.1</td><td><a
 href="https://github.com/advisories/GHSA-rc2w-r4jq-7pfx";>Improper 
Authorization in Apache Xalan-Java</a></td><td>high</td></tr><tr><td 
colspan="2"><td><a 
href="https://github.com/advisories/GHSA-9339-86wc-4qgf";>Apache Xalan Java XSLT 
library integer truncation issue when processing malicious XSLT 
stylesheets</a></td><td>high</td></tr><tr><td><a 
href="https://github.com/jetty/jetty.project";>org.eclipse.jetty:jetty-http</a></td><td>11.0.15</td><td><a
 href="https://github.com/advisor
 ies/GHSA-hmr7-m48g-48f6">Jetty accepts "+" prefixed value in 
Content-Length</a></td><td>moderate</td></tr></table>
   <blockquote>Only included vulnerabilities with severity 
<strong>moderate</strong> or higher.</blockquote>
   <h2>License Issues</h2>
   <h4><em>pom.xml</em></h4>
   <table><tr><td>Package</td><td>Version</td><td>License</td><td>Issue 
Type</td></tr><tr><td><a 
href="https://github.com/jetty/jetty.project";>org.eclipse.jetty:jetty-http</a></td><td>11.0.15</td><td>Null</td><td>Unknown
 License</td></tr><tr><td><a 
href="https://github.com/jetty/jetty.project";>org.eclipse.jetty:jetty-servlets</a></td><td>11.0.15</td><td>Null</td><td>Unknown
 License</td></tr><tr><td><a 
href="https://github.com/jetty/jetty.project";>org.eclipse.jetty:jetty-servlets</a></td><td>11.0.15</td><td>Null</td><td>Unknown
 License</td></tr><tr><td><a 
href="https://github.com/jetty/jetty.project";>org.eclipse.jetty:jetty-security</a></td><td>11.0.15</td><td>Null</td><td>Unknown
 License</td></tr></table>
   <h2>Scanned Manifest Files</h2>
   
<details><summary>pom.xml</summary><ul><li>xalan:[email protected]</li><li>xalan:[email protected]</li><li>org.eclipse.jetty:[email protected]</li><li>org.eclipse.jetty:[email protected]</li><li>org.eclipse.jetty:[email protected]</li><li>org.eclipse.jetty.toolchain:[email protected]</li><li>org.eclipse.jetty:[email protected]</li><li>org.eclipse.jetty:[email protected]</li><li>org.eclipse.jetty:[email protected]</li><li>org.eclipse.jetty:[email protected]</li><li>org.eclipse.jetty:[email protected]</li><li>org.eclipse.jetty:[email protected]</li><li>org.eclipse.jetty:[email protected]</li><li>org.slf4j:[email protected]</li><li>xalan:[email protected]</li><li>xalan:[email protected]</li><li>xml-apis:[email protected]</li><li>org.eclipse.jetty.toolchain:[email protected]</li><li>org.eclipse.jetty:[email protected]</li><li>org.eclipse.jetty:[email protected]</li><li>org.eclipse.jetty:[email protected]</li><li>org.eclipse.jetty:jetty-serv
 
[email protected]</li><li>org.eclipse.jetty:[email protected]</li><li>org.eclipse.jetty:[email protected]</li><li>org.eclipse.jetty:[email protected]</li><li>org.eclipse.jetty:[email protected]</li><li>org.eclipse.jetty:[email protected]</li><li>org.eclipse.jetty:[email protected]</li><li>org.slf4j:[email protected]</li><li>xalan:[email protected]</li><li>xalan:[email protected]</li><li>xalan:[email protected]</li><li>xalan:[email protected]</li></ul></details>
   
   
   <!-- dependency-review-pr-comment-marker -->


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to