jacoco-maven-plugin has dependency on Maven 3.0 which has a known security issue.
envgap__jacoco__jacoco-1203
01 / FAILURE SIGNATURE
As reported upstream
No identifying execution failure has been captured.
Not a benchmark task.
- In a clean container the reported failure did not reproduce, or the known fix did not make the project run.
02 / ENVIRONMENT RECIPE
- Base commit
d5c0a83bb58933b488fffc06a54941ba9615de7f- Manifest
jacoco-maven-plugin/pom.xml- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / ORIGINAL ISSUE TEXT
jacoco/jacoco #1203 · read the original issue
### Scenario * JaCoCo version: 0.8.7 * Operating system: Any * Tool integration: Maven * Description of your use case: Security ### Current Behaviour BlackDuck reports a transitive dependency on Maven 3.0 which has a security issue.  ### Wanted Behaviour Update the version of Maven referenced to 3.8.1
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]