Skip to content

importing brevo with gradle brings unwanted dependencies, with CVE reports #1

@mathieuruellan

Description

@mathieuruellan

Hello,

I'm using brevo for a project of my company.

This is what i get when i'm importing brevo with api dependency, I don't get why my final app should have maven-core in runtime.

image

The other issue is theses deps have cve tickets, and if its' not a big problem with building tools, it shouldn't be bundled in a final running product. It blocks in the CI at the scan stage and could be a problem with our customer security audits.

image

Regards,

Mathieu Ruellan
Developer/Manager at MyScript

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions