Open keren-orca opened 2 years ago
Hi :wave:
Where this jar can be found? I do not find it from zookeeper archive page https://archive.apache.org/dist/zookeeper/zookeeper-3.4.13/
The error message is essentially from Java's internal classes verifying the integrity of the jar before handing out its contents. It appears as if your jar-file contains an improper (ill-formatted) META-INF/MANIFEST.MF that triggers the java internals to throw an exception because the signatures of the jar are corrupt. So it appears to be a typical scenario of "garbage in = garbage out". You should check your fat-jar creation process and ensure that the fat jar is either not signed at all, or otherwise properly signed.
Also be aware that typically a fat-jar scenario will increase the likelyhood of false positives and false negatives due to the way that DependencyCheck does its scanning. Having all composing libraries side-by-side in a folder rather than squashed together in a single fat jar is likely to give a better analysis result.
When running
dependency-check
onzookeeper-3.4.13-fatjar.jar
it fails with the following error:Version of dependency-check used 6.5.0
Expected behavior Scan
zookeeper-3.4.13-fatjar.jar
without errors