A framework for defining ratings for open-source projects.
In particular, the framework offers a security rating for open-source projects
that may be used to assess the security risk that comes with open-source components.
License | Apache 2.0 |
---|---|
Tags | sap |
HomePage | https://github.com/SAP/fosstars-rating-core |
Date | Jan 12, 2021 |
Files | jar (541 KB) View All |
Repositories | Central |
Ranking | #504340 in MvnRepository (See Top Artifacts) |
Vulnerabilities | Vulnerabilities from dependencies: CVE-2023-4759 CVE-2022-42889 CVE-2022-42004 View 8 more ... |
Compile Dependencies (13)
Category/License | Group / Artifact | Version | Updates | |
---|---|---|---|---|
JSON Lib Apache 2.0 | com.fasterxml.jackson.core » jackson-databind4 vulnerabilities | 2.11.1 | 2.16.0 | |
YAML Apache 2.0 | com.fasterxml.jackson.dataformat » jackson-dataformat-yaml | 2.11.1 | 2.16.0 | |
CLI Parser Apache 2.0 | commons-cli » commons-cli | 1.4 | 1.6.0 | |
Math Lib Apache 2.0 | org.apache.commons » commons-math3 | 3.6.1 | ✔ | |
Collections Apache 2.0 | org.apache.commons » commons-collections4 | 4.4 | ✔ | |
String Utils Apache 2.0 | org.apache.commons » commons-text1 vulnerability | 1.8 | 1.11.0 | |
HTTP Clients Apache 2.0 | org.apache.httpcomponents » httpclient1 vulnerability | 4.5.10 | 5.2.2 | |
Logging Apache 2.0 | org.apache.logging.log4j » log4j-api | 2.13.1 | 2.22.0 | |
Logging Apache 2.0 | org.apache.logging.log4j » log4j-core4 vulnerabilities | 2.13.2 | 2.22.0 | |
Build Model Apache 2.0 | org.apache.maven » maven-model | 3.6.2 | 3.9.5 | |
Git Tool BSDEDL | org.eclipse.jgit » org.eclipse.jgit1 vulnerability | 5.7.0.202003110725-r | 6.7.0.202309050840-r | |
GitHub API MIT | org.kohsuke » github-api | 1.116 | 1.318 | |
Apache 2.0 | us.springett » nist-data-mirror | 1.4.0 | 1.6.0 |
Test Dependencies (2)
Category/License | Group / Artifact | Version | Updates | |
---|---|---|---|---|
Testing EPL 2.0 | junit » junit | 4.13.1 | 5.10.1 | |
Mocking MIT | org.mockito » mockito-core | 3.2.4 | 5.7.0 |
Licenses
License | URL |
---|---|
The Apache License, Version 2.0 | http://www.apache.org/licenses/LICENSE-2.0.txt |
Developers
Name | Dev Id | Roles | Organization | |
---|---|---|---|---|
Artem Smotrakov | artem.smotrakov<at>sap.com | SAP | ||
Sourabh Sarvotham Parkala | sourabh.sarvotham.parkala<at>sap.com | SAP | ||
Michael Bolz | michael.bolz<at>sap.com | SAP | ||
Sachin Pattan | sachin.pattan<at>sap.com | SAP | ||
Manjunath Mandya Surendrakumar | manjunath.mandya.surendrakumar<at>sap.com | SAP |