基础信息
项目名称:dropwizard/dropwizard
项目徽章:
仓库地址:https://github.com/pterodactyl/panel
检测报告地址:https://www.murphysec.com/console/report/1721149447194279936/1727853034140557312
此报告由Murphysec提供
漏洞列表
暂无
缺陷组件
暂无
许可证风险
许可证类型 | 相关组件 | 许可证风险 |
---|---|---|
Apache-2.0 | 97 | 低 |
EPL-2.0 | 46 | 低 |
自定义许可证 | 14 | 低 |
MIT | 12 | 低 |
GPL-2.0-with-classpath-exception | 1 | 中 |
MPL-2.0 | 2 | 低 |
EPL-1.0 | 4 | 低 |
LGPL-2.1-or-later | 2 | 低 |
GPL-2.0 | 1 | 中 |
LGPL-2.1 | 1 | 中 |
MPL-1.1 | 1 | 低 |
BSD-2-Clause | 1 | 低 |
SBOM清单
组件名称 | 组件版本 | 是否直接依赖 | 仓库 |
---|---|---|---|
io.dropwizard:dropwizard-jersey | 4.0.5-SNAPSHOT | 直接依赖 | maven |
com.google.j2objc:j2objc-annotations | 2.8 | 间接依赖 | maven |
io.dropwizard.metrics:metrics-jmx | 4.2.22 | 直接依赖 | maven |
org.glassfish.jersey.core:jersey-server | 3.0.12 | 直接依赖 | maven |
jakarta.el:jakarta.el-api | 4.0.0 | 间接依赖 | maven |
org.eclipse.jetty.http2:http2-hpack | 11.0.18 | 间接依赖 | maven |
org.jvnet.mimepull:mimepull | 1.9.15 | 间接依赖 | maven |
io.dropwizard:dropwizard-client | 4.0.5-SNAPSHOT | 直接依赖 | maven |
org.slf4j:jcl-over-slf4j | 2.0.9 | 直接依赖 | maven |
jakarta.xml.bind:jakarta.xml.bind-api | 3.0.1 | 直接依赖 | maven |
org.jboss.logging:jboss-logging | 3.5.3.Final | 间接依赖 | maven |
Sphinx | 7.2.6 | 间接依赖 | pip |
io.dropwizard:dropwizard-assets | 4.0.5-SNAPSHOT | 直接依赖 | maven |
org.eclipse.jetty.toolchain:jetty-jakarta-servlet-api | 5.0.2 | 间接依赖 | maven |
com.sun.istack:istack-commons-runtime | 4.0.1 | 间接依赖 | maven |
io.dropwizard:dropwizard-validation | 4.0.5-SNAPSHOT | 直接依赖 | maven |
io.dropwizard:dropwizard-migrations | 4.0.5-SNAPSHOT | 直接依赖 | maven |
org.jdbi:jdbi3-guava | 3.41.3 | 直接依赖 | maven |
io.dropwizard.metrics:metrics-jetty11 | 4.2.22 | 直接依赖 | maven |
org.opentest4j:opentest4j | 1.3.0 | 间接依赖 | maven |
jakarta.annotation:jakarta.annotation-api | 2.0.0 | 直接依赖 | maven |
io.leangen.geantyref:geantyref | 1.3.14 | 间接依赖 | maven |
jakarta.transaction:jakarta.transaction-api | 2.0.0 | 间接依赖 | maven |
org.apache.commons:commons-text | 1.11.0 | 直接依赖 | maven |
net.sourceforge.argparse4j:argparse4j | 0.9.0 | 直接依赖 | maven |
io.dropwizard:dropwizard-lifecycle | 4.0.5-SNAPSHOT | 直接依赖 | maven |
org.jboss:jandex | 2.4.2.Final | 间接依赖 | maven |
org.glassfish.jersey.media:jersey-media-jaxb | 3.0.12 | 间接依赖 | maven |
jakarta.ws.rs:jakarta.ws.rs-api | 3.0.0 | 直接依赖 | maven |
sphinx-rtd-theme | 1.3.0 | 间接依赖 | pip |
org.apache.commons:commons-math3 | 3.6.1 | 间接依赖 | maven |
org.junit.jupiter:junit-jupiter-params | 5.10.1 | 间接依赖 | maven |
org.eclipse.jetty:jetty-servlets | 11.0.18 | 直接依赖 | maven |
com.github.ben-manes.caffeine:caffeine | 3.1.8 | 直接依赖 | maven |
octokit | 8.0.0 | 间接依赖 | bundler |
org.eclipse.jetty:jetty-alpn-java-server | 11.0.18 | 直接依赖 | maven |
io.dropwizard:dropwizard-util | 4.0.5-SNAPSHOT | 直接依赖 | maven |
org.apache.commons:commons-collections4 | 4.4 | 间接依赖 | maven |
net.bytebuddy:byte-buddy-agent | 1.14.9 | 间接依赖 | maven |
com.fasterxml.jackson.datatype:jackson-datatype-hibernate5-jakarta | 2.16.0 | 直接依赖 | maven |
org.glassfish.jersey.test-framework.providers:jersey-test-framework-provider-inmemory | 3.0.12 | 直接依赖 | maven |
com.fasterxml.jackson.core:jackson-core | 2.16.0 | 直接依赖 | maven |
io.dropwizard.metrics:metrics-jersey3 | 4.2.22 | 直接依赖 | maven |
org.eclipse.jetty:jetty-util | 11.0.18 | 直接依赖 | maven |
sphinx-autobuild | 2021.3.14 | 间接依赖 | pip |
org.glassfish.jersey.inject:jersey-hk2 | 3.0.12 | 直接依赖 | maven |
io.dropwizard.metrics:metrics-json | 4.2.22 | 间接依赖 | maven |
io.dropwizard:dropwizard-http2 | 4.0.5-SNAPSHOT | 直接依赖 | maven |
org.junit.platform:junit-platform-engine | 1.10.1 | 间接依赖 | maven |
org.glassfish.jersey.ext:jersey-metainf-services | 3.0.12 | 直接依赖 | maven |
jakarta.inject:jakarta.inject-api | 2.0.1.MR | 直接依赖 | maven |
io.dropwizard:dropwizard-db | 4.0.5-SNAPSHOT | 直接依赖 | maven |
org.jdbi:jdbi3-core | 3.41.3 | 直接依赖 | maven |
com.mattbertolini:liquibase-slf4j | 5.0.0 | 直接依赖 | maven |
jakarta.activation:jakarta.activation-api | 2.0.1 | 直接依赖 | maven |
org.glassfish:jakarta.el | 4.0.2 | 直接依赖 | maven |
io.dropwizard:dropwizard-configuration | 4.0.5-SNAPSHOT | 直接依赖 | maven |
org.glassfish.hk2:hk2-utils | 3.0.5 | 间接依赖 | maven |
org.hibernate.validator:hibernate-validator | 7.0.5.Final | 直接依赖 | maven |
io.dropwizard:dropwizard-request-logging | 4.0.5-SNAPSHOT | 直接依赖 | maven |
org.glassfish.hk2:osgi-resource-locator | 1.0.3 | 间接依赖 | maven |
com.fasterxml.jackson.datatype:jackson-datatype-jdk8 | 2.16.0 | 直接依赖 | maven |
com.sun.activation:jakarta.activation | 2.0.1 | 间接依赖 | maven |
io.dropwizard:dropwizard-metrics-graphite | 4.0.5-SNAPSHOT | 直接依赖 | maven |
org.junit.jupiter:junit-jupiter | 5.10.1 | 直接依赖 | maven |
org.glassfish.jersey.containers:jersey-container-servlet | 3.0.12 | 直接依赖 | maven |
com.google.guava:guava | 32.1.3-jre | 直接依赖 | maven |
org.slf4j:slf4j-api | 2.0.9 | 直接依赖 | maven |
org.glassfish.jaxb:jaxb-runtime | 3.0.2 | 间接依赖 | maven |
org.junit.jupiter:junit-jupiter-api | 5.10.1 | 直接依赖 | maven |
io.dropwizard:dropwizard-jetty | 4.0.5-SNAPSHOT | 直接依赖 | maven |
org.eclipse.jetty.http2:http2-common | 11.0.18 | 间接依赖 | maven |
com.fasterxml.jackson.module:jackson-module-parameter-names | 2.16.0 | 直接依赖 | maven |
org.eclipse.jetty:jetty-alpn-server | 11.0.18 | 直接依赖 | maven |
org.junit.platform:junit-platform-commons | 1.10.1 | 直接依赖 | maven |
net.bytebuddy:byte-buddy | 1.14.10 | 直接依赖 | maven |
sawyer | 0.9.2 | 间接依赖 | bundler |
io.dropwizard:dropwizard-testing | 4.0.5-SNAPSHOT | 直接依赖 | maven |
org.liquibase:liquibase-core | 4.24.0 | 直接依赖 | maven |
org.openjdk.jmh:jmh-core | 1.37 | 直接依赖 | maven |
com.helger:profiler | 1.1.1 | 间接依赖 | maven |
io.dropwizard:dropwizard-jackson | 4.0.5-SNAPSHOT | 直接依赖 | maven |
org.apache.httpcomponents.core5:httpcore5-h2 | 5.2 | 间接依赖 | maven |
io.dropwizard.metrics:metrics-core | 4.2.22 | 直接依赖 | maven |
org.glassfish.hk2:hk2-api | 3.0.5 | 直接依赖 | maven |
org.glassfish.hk2.external:aopalliance-repackaged | 3.0.5 | 间接依赖 | maven |
com.fasterxml.jackson.core:jackson-databind | 2.16.0 | 直接依赖 | maven |
net.sf.jopt-simple:jopt-simple | 5.0.4 | 间接依赖 | maven |
org.glassfish.jersey.ext:jersey-bean-validation | 3.0.12 | 直接依赖 | maven |
org.slf4j:log4j-over-slf4j | 2.0.9 | 直接依赖 | maven |
com.h2database:h2 | 2.2.224 | 直接依赖 | maven |
io.dropwizard:dropwizard-hibernate | 4.0.5-SNAPSHOT | 直接依赖 | maven |
io.dropwizard:dropwizard-views-mustache | 4.0.5-SNAPSHOT | 直接依赖 | maven |
org.mockito:mockito-core | 5.7.0 | 直接依赖 | maven |
io.dropwizard.metrics:metrics-jakarta-servlets | 4.2.22 | 直接依赖 | maven |
org.glassfish.jaxb:jaxb-core | 3.0.2 | 间接依赖 | maven |
org.antlr:antlr4-runtime | 4.10.1 | 间接依赖 | maven |
io.dropwizard:dropwizard-health | 4.0.5-SNAPSHOT | 直接依赖 | maven |
org.eclipse.jetty:jetty-http | 11.0.18 | 直接依赖 | maven |
com.google.guava:listenablefuture | 9999.0-empty-to-avoid-conflict-with-guava | 间接依赖 | maven |
com.fasterxml.jackson.jakarta.rs:jackson-jakarta-rs-base | 2.16.0 | 间接依赖 | maven |
org.eclipse.jetty.toolchain.setuid:jetty-setuid-java | 1.0.4 | 直接依赖 | maven |
org.checkerframework:checker-qual | 3.40.0 | 直接依赖 | maven |
org.apache.tomcat:tomcat-juli | 10.1.16 | 间接依赖 | maven |
public_suffix | 5.0.3 | 间接依赖 | bundler |
io.dropwizard.metrics:metrics-annotation | 4.2.22 | 直接依赖 | maven |
lesscpy | 0.15.1 | 间接依赖 | pip |
org.eclipse.jetty:jetty-alpn-java-client | 11.0.18 | 直接依赖 | maven |
org.eclipse.jetty:jetty-server | 11.0.18 | 直接依赖 | maven |
com.google.guava:failureaccess | 1.0.1 | 间接依赖 | maven |
org.yaml:snakeyaml | 2.2 | 间接依赖 | maven |
io.dropwizard.logback:logback-throttling-appender | 1.4.1 | 直接依赖 | maven |
io.dropwizard.metrics:metrics-httpclient5 | 4.2.22 | 直接依赖 | maven |
org.eclipse.jetty:jetty-alpn-client | 11.0.18 | 间接依赖 | maven |
org.glassfish.jersey.containers:jersey-container-servlet-core | 3.0.12 | 直接依赖 | maven |
org.objenesis:objenesis | 3.3 | 间接依赖 | maven |
com.fasterxml.jackson.dataformat:jackson-dataformat-yaml | 2.16.0 | 直接依赖 | maven |
org.junit.jupiter:junit-jupiter-engine | 5.10.1 | 间接依赖 | maven |
org.hibernate.common:hibernate-commons-annotations | 6.0.6.Final | 间接依赖 | maven |
com.github.spullara.mustache.java:compiler | 0.9.11 | 直接依赖 | maven |
org.eclipse.jetty:jetty-alpn-conscrypt-server | 11.0.18 | 直接依赖 | maven |
io.dropwizard.metrics:metrics-jvm | 4.2.22 | 直接依赖 | maven |
io.dropwizard:dropwizard-servlets | 4.0.5-SNAPSHOT | 直接依赖 | maven |
ch.qos.logback:logback-classic | 1.4.11 | 直接依赖 | maven |
com.fasterxml.jackson.datatype:jackson-datatype-guava | 2.16.0 | 直接依赖 | maven |
jakarta.persistence:jakarta.persistence-api | 3.0.0 | 直接依赖 | maven |
io.dropwizard.metrics:metrics-caffeine | 4.2.22 | 直接依赖 | maven |
org.freemarker:freemarker | 2.3.32 | 直接依赖 | maven |
org.eclipse.jetty:jetty-servlet | 11.0.18 | 直接依赖 | maven |
io.dropwizard:dropwizard-auth | 4.0.5-SNAPSHOT | 直接依赖 | maven |
org.apache.commons:commons-lang3 | 3.14.0 | 间接依赖 | maven |
io.dropwizard:dropwizard-forms | 4.0.5-SNAPSHOT | 直接依赖 | maven |
com.fasterxml:classmate | 1.6.0 | 直接依赖 | maven |
org.glassfish.jersey.media:jersey-media-multipart | 3.0.12 | 直接依赖 | maven |
addressable | 2.8.5 | 间接依赖 | bundler |
org.glassfish.jersey.core:jersey-common | 3.0.12 | 直接依赖 | maven |
jakarta.validation:jakarta.validation-api | 3.0.2 | 直接依赖 | maven |
com.rabbitmq:amqp-client | 5.20.0 | 间接依赖 | maven |
faraday-net_http | 3.0.2 | 间接依赖 | bundler |
com.fasterxml.jackson.datatype:jackson-datatype-jsr310 | 2.16.0 | 直接依赖 | maven |
ch.qos.logback:logback-core | 1.4.11 | 直接依赖 | maven |
org.hibernate.orm:hibernate-core | 6.1.7.Final | 直接依赖 | maven |
jakarta.servlet:jakarta.servlet-api | 5.0.0 | 直接依赖 | maven |
ch.qos.logback:logback-access | 1.4.11 | 直接依赖 | maven |
org.eclipse.jetty:jetty-security | 11.0.18 | 直接依赖 | maven |
faraday | 2.7.11 | 间接依赖 | bundler |
org.eclipse.jetty.http2:http2-server | 11.0.18 | 直接依赖 | maven |
io.dropwizard:dropwizard-core | 4.0.5-SNAPSHOT | 直接依赖 | maven |
org.openjdk.jmh:jmh-generator-annprocess | 1.37 | 直接依赖 | maven |
org.apache.httpcomponents.core5:httpcore5 | 5.2.3 | 直接依赖 | maven |
io.dropwizard:dropwizard-metrics | 4.0.5-SNAPSHOT | 直接依赖 | maven |
io.dropwizard.metrics:metrics-healthchecks | 4.2.22 | 直接依赖 | maven |
org.javassist:javassist | 3.29.2-GA | 直接依赖 | maven |
com.fasterxml.jackson.module:jackson-module-blackbird | 2.16.0 | 直接依赖 | maven |
com.google.errorprone:error_prone_annotations | 2.23.0 | 直接依赖 | maven |
org.glassfish.jersey.test-framework:jersey-test-framework-core | 3.0.12 | 直接依赖 | maven |
org.apache.tomcat:tomcat-jdbc | 10.1.16 | 直接依赖 | maven |
org.hamcrest:hamcrest | 2.2 | 间接依赖 | maven |
org.conscrypt:conscrypt-openjdk-uber | 2.4.0 | 直接依赖 | maven |
io.dropwizard:dropwizard-views | 4.0.5-SNAPSHOT | 直接依赖 | maven |
ruby2_keywords | 0.0.5 | 间接依赖 | bundler |
io.dropwizard:dropwizard-logging | 4.0.5-SNAPSHOT | 直接依赖 | maven |
com.fasterxml.jackson.core:jackson-annotations | 2.16.0 | 直接依赖 | maven |
org.slf4j:jul-to-slf4j | 2.0.9 | 直接依赖 | maven |
org.eclipse.jetty:jetty-io | 11.0.18 | 直接依赖 | maven |
base64 | 0.1.1 | 间接依赖 | bundler |
com.fasterxml.jackson.jakarta.rs:jackson-jakarta-rs-json-provider | 2.16.0 | 直接依赖 | maven |
io.dropwizard.metrics:metrics-graphite | 4.2.22 | 直接依赖 | maven |
org.glassfish.hk2:hk2-locator | 3.0.5 | 间接依赖 | maven |
io.dropwizard.metrics:metrics-logback | 4.2.22 | 直接依赖 | maven |
org.glassfish.jaxb:txw2 | 3.0.2 | 间接依赖 | maven |
org.apiguardian:apiguardian-api | 1.1.2 | 间接依赖 | maven |
com.fasterxml.jackson.module:jackson-module-afterburner | 2.16.0 | 直接依赖 | maven |
org.apache.httpcomponents.client5:httpclient5 | 5.2.1 | 直接依赖 | maven |
com.opencsv:opencsv | 5.8 | 间接依赖 | maven |
io.dropwizard:dropwizard-views-freemarker | 4.0.5-SNAPSHOT | 直接依赖 | maven |
org.glassfish.jersey.core:jersey-client | 3.0.12 | 直接依赖 | maven |
org.jdbi:jdbi3-sqlobject | 3.41.3 | 直接依赖 | maven |
io.dropwizard.metrics:metrics-jdbi3 | 4.2.22 | 直接依赖 | maven |
org.glassfish.jersey.connectors:jersey-apache5-connector | 3.0.12 | 直接依赖 | maven |
com.fasterxml.jackson.module:jackson-module-jakarta-xmlbind-annotations | 2.16.0 | 间接依赖 | maven |