If anybody is using OWASP dependency-check for their builds, the new version 2.1.1 is over-sensitive compared to 2.1.0. I've opened an issue here

https://github.com/jeremylong/DependencyCheck/issues/894

Besides fontbox, it also reports javamail.

Tilman

Reply via email to