Use Java 17 for most of gradle-profiler tests #8
dependency-review-action.yml
on: pull_request
dependency-submission
1m 20s
Annotations
1 error, 10 warnings, and 1 notice
dependency-submission
Dependency review detected vulnerable packages.
|
OpenSSF Scorecard Warning
maven/com.google.code.findbugs:annotations has an OpenSSF Scorecard of 0.2, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
maven/javax.activation:javax.activation-api has an OpenSSF Scorecard of 2.7, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
maven/org.jetbrains.kotlin:kotlin-android-extensions has an OpenSSF Scorecard of 2.4, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
maven/org.jetbrains.kotlin:kotlin-assignment has an OpenSSF Scorecard of 2.4, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
maven/org.jetbrains.kotlin:kotlin-assignment-compiler-plugin-embeddable has an OpenSSF Scorecard of 2.4, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
maven/org.jetbrains.kotlin:kotlin-build-tools-api has an OpenSSF Scorecard of 2.4, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
maven/org.jetbrains.kotlin:kotlin-compiler-embeddable has an OpenSSF Scorecard of 2.4, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
maven/org.jetbrains.kotlin:kotlin-compiler-runner has an OpenSSF Scorecard of 2.4, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
maven/org.jetbrains.kotlin:kotlin-daemon-client has an OpenSSF Scorecard of 2.4, which is less than this repository's threshold of 3.
|
OpenSSF Scorecard Warning
maven/org.jetbrains.kotlin:kotlin-daemon-embeddable has an OpenSSF Scorecard of 2.4, which is less than this repository's threshold of 3.
|
dependency-submission
Submitted dependency-graph-reports/dependency_review_for_pull_requests-dependency-submission.json: The snapshot was accepted, but it is not for the default branch. It will not update dependency results for the repository.
|