{"package":"io.quarkus:quarkus-core","ecosystem":"maven","latest_version":"3.23.0","description":"","license":"","license_risk":"unknown","commercial_use_notes":"No license declared in registry metadata — verify manually before commercial use.","homepage":"https://search.maven.org/artifact/io.quarkus/quarkus-core","repository":"","downloads_weekly":143871,"health":{"score":57,"risk":"high","breakdown":{"maintenance":10,"popularity":14,"security":18,"maturity":15,"community":0},"deprecated":false,"max_score":100},"vulnerabilities":{"count":2,"critical":0,"high":1,"medium":1,"low":0,"details":[{"vuln_id":"CVE-2023-2974","severity":"medium","summary":"quarkus-core vulnerable to client driven TLS cipher downgrading","affected_versions":"<2.16.8.Final|=0.11.0|=0.12.0|=0.13.0|=0.13.1|=0.13.2|=0.13.3|=0.14.0|=0.15.0|=0.16.0|=0.16.1|=0.17.0|=0.18.0|=0.19.0|=0.19.1|=0.20.0|=0.21.0|=0.21.1|=0.21.2|=0.22.0|=0.23.0|=0.23.1|=0.23.2|=0.24.0|=0.25.0|=0.26.0|=0.26.1|=0.27.0|=0.28.0|=0.28.1|=1.0.0.CR1|=1.0.0.CR2|=1.0.0.Final|=1.0.1.Final|=1.1.0.CR1|=1.1.0.Final|=1.1.1.Final|=1.10.0.CR1|=1.10.0.Final|=1.10.1.Final|=1.10.2.Final|=1.10.3.Final|=1.10.4.Final|=1.10.5.Final|=1.11.0.Beta1|=1.11.0.Beta2|=1.11.0.CR1|=1.11.0.Final|=1.11.1.Final|=1.11.2.Final|=1.11.3.Final|=1.11.4.Final|=1.11.5.Final|=1.11.6.Final|=1.11.7.Final|=1.12.0.CR1|=1.12.0.Final|=1.12.1.Final|=1.12.2.Final|=1.13.0.CR1|=1.13.0.Final|=1.13.1.Final|=1.13.2.Final|=1.13.3.Final|=1.13.4.Final|=1.13.5.Final|=1.13.6.Final|=1.13.7.Final|=1.2.0.CR1|=1.2.0.Final|=1.2.1.Final|=1.3.0.Alpha1|=1.3.0.Alpha2|=1.3.0.CR1|=1.3.0.CR2|=1.3.0.Final|=1.3.1.Final|=1.3.2.Final|=1.3.3.Final|=1.3.4.Final|=1.4.0.CR1|=1.4.0.Final|=1.4.1.Final|=1.4.2.Final|=1.5.0.CR1|=1.5.0.Final|=1.5.1.Final|=1.5.2.Final|=1.6.0.CR1|=1.6.0.Final|=1.6.1.Final|=1.7.0.CR1|=1.7.0.CR2|=1.7.0.Final|=1.7.1.Final|=1.7.2.Final|=1.7.3.Final|=1.7.4.Final|=1.7.5.Final|=1.7.6.Final|=1.8.0.CR1|=1.8.0.Final|=1.8.1.Final|=1.8.2.Final|=1.8.3.Final|=1.9.0.CR1|=1.9.0.Final|=1.9.1.Final|=1.9.2.Final|=2.0.0.Alpha1|=2.0.0.Alpha2|=2.0.0.Alpha3|=2.0.0.CR1|=2.0.0.CR2|=2.0.0.CR3|=2.0.0.Final|=2.0.1.Final|=2.0.2.Final|=2.0.3.Final|=2.1.0.CR1|=2.1.0.Final|=2.1.1.Final|=2.1.2.Final|=2.1.3.Final|=2.1.4.Final|=2.10.0.CR1|=2.10.0.Final|=2.10.1.Final|=2.10.2.Final|=2.10.3.Final|=2.10.4.Final|=2.11.0.CR1|=2.11.0.Final|=2.11.1.Final|=2.11.2.Final|=2.11.3.Final|=2.12.0.CR1|=2.12.0.Final|=2.12.1.Final|=2.12.2.Final|=2.12.3.Final|=2.13.0.CR1|=2.13.0.Final|=2.13.1.Final|=2.13.2.Final|=2.13.3.Final|=2.13.4.Final|=2.13.5.Final|=2.13.6.Final|=2.13.7.Final|=2.13.8.Final|=2.13.9.Final|=2.14.0.CR1|=2.14.0.Final|=2.14.1.Final|=2.14.2.Final|=2.14.3.Final|=2.15.0.CR1|=2.15.0.Final|=2.15.1.Final|=2.15.2.Final|=2.15.3.Final|=2.16.0.CR1|=2.16.0.Final|=2.16.1.Final|=2.16.2.Final|=2.16.3.Final|=2.16.4.Final|=2.16.5.Final|=2.16.6.Final|=2.16.7.Final|=2.2.0.CR1|=2.2.0.Final|=2.2.1.Final|=2.2.2.Final|=2.2.3.Final|=2.2.4.Final|=2.2.5.Final|=2.3.0.CR1|=2.3.0.Final|=2.3.1.Final|=2.4.0.CR1|=2.4.0.Final|=2.4.1.Final|=2.4.2.Final|=2.5.0.CR1|=2.5.0.Final|=2.5.1.Final|=2.5.2.Final|=2.5.3.Final|=2.5.4.Final|=2.6.0.CR1|=2.6.0.Final|=2.6.1.Final|=2.6.2.Final|=2.6.3.Final|=2.7.0.CR1|=2.7.0.Final|=2.7.1.Final|=2.7.2.Final|=2.7.3.Final|=2.7.4.Final|=2.7.5.Final|=2.7.6.Final|=2.7.7.Final|=2.8.0.CR1|=2.8.0.Final|=2.8.1.Final|=2.8.2.Final|=2.8.3.Final|=2.9.0.CR1|=2.9.0.Final|=2.9.1.Final|=2.9.2.Final","fixed_version":"2.16.8.Final","source":"osv","published_at":"2023-07-04T15:30:18Z","in_kev":false,"epss_prob":0.00489,"epss_percentile":0.65566,"threat_tier":"theoretical"},{"vuln_id":"CVE-2024-2700","severity":"high","summary":"quarkus-core leaks local environment variables from Quarkus namespace during application's build","affected_versions":">=3.9.0.CR1,<3.9.2|>=3.3.0.CR1,<3.8.4|<3.2.12.Final|=3.9.0|=3.9.0.CR1|=3.9.0.CR2|=3.9.1|=3.3.0|=3.3.0.CR1|=3.3.1|=3.3.2|=3.3.3|=3.4.0|=3.4.0.CR1|=3.4.1|=3.4.2|=3.4.3|=3.5.0|=3.5.0.CR1|=3.5.1|=3.5.2|=3.5.3|=3.6.0|=3.6.0.CR1|=3.6.1|=3.6.2|=3.6.3|=3.6.4|=3.6.5|=3.6.6|=3.6.7|=3.6.8|=3.6.9|=3.7.0|=3.7.0.CR1|=3.7.1|=3.7.2|=3.7.3|=3.7.4|=3.8.0|=3.8.0.CR1|=3.8.1|=3.8.2|=3.8.3|=0.11.0|=0.12.0|=0.13.0|=0.13.1|=0.13.2|=0.13.3|=0.14.0|=0.15.0|=0.16.0|=0.16.1|=0.17.0|=0.18.0|=0.19.0|=0.19.1|=0.20.0|=0.21.0|=0.21.1|=0.21.2|=0.22.0|=0.23.0|=0.23.1|=0.23.2|=0.24.0|=0.25.0|=0.26.0|=0.26.1|=0.27.0|=0.28.0|=0.28.1|=1.0.0.CR1|=1.0.0.CR2|=1.0.0.Final|=1.0.1.Final|=1.1.0.CR1|=1.1.0.Final|=1.1.1.Final|=1.10.0.CR1|=1.10.0.Final|=1.10.1.Final|=1.10.2.Final|=1.10.3.Final|=1.10.4.Final|=1.10.5.Final|=1.11.0.Beta1|=1.11.0.Beta2|=1.11.0.CR1|=1.11.0.Final|=1.11.1.Final|=1.11.2.Final|=1.11.3.Final|=1.11.4.Final|=1.11.5.Final|=1.11.6.Final|=1.11.7.Final|=1.12.0.CR1|=1.12.0.Final|=1.12.1.Final|=1.12.2.Final|=1.13.0.CR1|=1.13.0.Final|=1.13.1.Final|=1.13.2.Final|=1.13.3.Final|=1.13.4.Final|=1.13.5.Final|=1.13.6.Final|=1.13.7.Final|=1.2.0.CR1|=1.2.0.Final|=1.2.1.Final|=1.3.0.Alpha1|=1.3.0.Alpha2|=1.3.0.CR1|=1.3.0.CR2|=1.3.0.Final|=1.3.1.Final|=1.3.2.Final|=1.3.3.Final|=1.3.4.Final|=1.4.0.CR1|=1.4.0.Final|=1.4.1.Final|=1.4.2.Final|=1.5.0.CR1|=1.5.0.Final|=1.5.1.Final|=1.5.2.Final|=1.6.0.CR1|=1.6.0.Final|=1.6.1.Final|=1.7.0.CR1|=1.7.0.CR2|=1.7.0.Final|=1.7.1.Final|=1.7.2.Final|=1.7.3.Final|=1.7.4.Final|=1.7.5.Final|=1.7.6.Final|=1.8.0.CR1|=1.8.0.Final|=1.8.1.Final|=1.8.2.Final|=1.8.3.Final|=1.9.0.CR1|=1.9.0.Final|=1.9.1.Final|=1.9.2.Final|=2.0.0.Alpha1|=2.0.0.Alpha2|=2.0.0.Alpha3|=2.0.0.CR1|=2.0.0.CR2|=2.0.0.CR3|=2.0.0.Final|=2.0.1.Final|=2.0.2.Final|=2.0.3.Final|=2.1.0.CR1|=2.1.0.Final|=2.1.1.Final|=2.1.2.Final|=2.1.3.Final|=2.1.4.Final|=2.10.0.CR1|=2.10.0.Final|=2.10.1.Final|=2.10.2.Final|=2.10.3.Final|=2.10.4.Final|=2.11.0.CR1|=2.11.0.Final|=2.11.1.Final|=2.11.2.Final|=2.11.3.Final|=2.12.0.CR1|=2.12.0.Final|=2.12.1.Final|=2.12.2.Final|=2.12.3.Final|=2.13.0.CR1|=2.13.0.Final|=2.13.1.Final|=2.13.2.Final|=2.13.3.Final|=2.13.4.Final|=2.13.5.Final|=2.13.6.Final|=2.13.7.Final|=2.13.8.Final|=2.13.9.Final|=2.14.0.CR1|=2.14.0.Final|=2.14.1.Final|=2.14.2.Final|=2.14.3.Final|=2.15.0.CR1|=2.15.0.Final|=2.15.1.Final|=2.15.2.Final|=2.15.3.Final|=2.16.0.CR1|=2.16.0.Final|=2.16.1.Final|=2.16.10.Final|=2.16.11.Final|=2.16.12.Final|=2.16.2.Final|=2.16.3.Final|=2.16.4.Final|=2.16.5.Final|=2.16.6.Final|=2.16.7.Final|=2.16.8.Final|=2.16.9.Final|=2.2.0.CR1|=2.2.0.Final|=2.2.1.Final|=2.2.2.Final|=2.2.3.Final|=2.2.4.Final|=2.2.5.Final|=2.3.0.CR1|=2.3.0.Final|=2.3.1.Final|=2.4.0.CR1|=2.4.0.Final|=2.4.1.Final|=2.4.2.Final|=2.5.0.CR1|=2.5.0.Final|=2.5.1.Final|=2.5.2.Final|=2.5.3.Final|=2.5.4.Final|=2.6.0.CR1|=2.6.0.Final|=2.6.1.Final|=2.6.2.Final|=2.6.3.Final|=2.7.0.CR1|=2.7.0.Final|=2.7.1.Final|=2.7.2.Final|=2.7.3.Final|=2.7.4.Final|=2.7.5.Final|=2.7.6.Final|=2.7.7.Final|=2.8.0.CR1|=2.8.0.Final|=2.8.1.Final|=2.8.2.Final|=2.8.3.Final|=2.9.0.CR1|=2.9.0.Final|=2.9.1.Final|=2.9.2.Final|=3.0.0.Alpha1|=3.0.0.Alpha2|=3.0.0.Alpha3|=3.0.0.Alpha4|=3.0.0.Alpha5|=3.0.0.Alpha6|=3.0.0.Beta1|=3.0.0.CR1|=3.0.0.CR2|=3.0.0.Final|=3.0.1.Final|=3.0.2.Final|=3.0.3.Final|=3.0.4.Final|=3.1.0.CR1|=3.1.0.Final|=3.1.1.Final|=3.1.2.Final|=3.1.3.Final|=3.2.0.CR1|=3.2.0.Final|=3.2.1.Final|=3.2.10.Final|=3.2.11.Final|=3.2.2.Final|=3.2.3.Final|=3.2.4.Final|=3.2.5.Final|=3.2.6.Final|=3.2.7.Final|=3.2.8.Final|=3.2.9.Final","fixed_version":"3.2.12.Final","source":"osv","published_at":"2024-04-04T15:30:34Z","in_kev":false,"epss_prob":0.00044,"epss_percentile":0.13266,"threat_tier":"theoretical"}],"actively_exploited_count":0,"likely_exploited_count":0},"versions":{"latest":"3.23.0","total_count":377,"recent":["3.23.0","3.23.0.CR1","3.22.3","3.20.1","3.15.5","3.22.2","3.22.1","3.21.4","3.22.0","3.22.0.CR1","3.21.3","3.21.2","3.21.1","3.20.0","3.21.0","3.19.4","3.21.0.CR1","3.20.0.CR1","3.19.3","3.15.4"]},"metadata":{"deprecated":false,"deprecated_message":null,"maintainers_count":0,"first_published":null,"last_published":"2025-05-22T12:52:10+00:00","dependencies_count":0,"dependencies":[]},"github_stats":null,"bundle":null,"typescript":null,"known_issues":{"bugs_count":0,"bugs_severity":{},"status_breakdown":{},"link":null,"scope":"none"},"historical_compromise":null,"recommendation":{"action":"update_required","issues":["Moderate health score (57/100) — verify manually","1 high severity vulnerabilities"],"use_version":"3.23.0","version_hint":"Update to >= 3.2.12.Final to fix known vulnerabilities","summary":"io.quarkus:quarkus-core@3.23.0 has vulnerabilities — update to latest"},"version_scoped":null,"_meta":{"endpoint":"check","tier":"full","philosophy":"DepScope is free. Use the cheapest endpoint that answers your real question.","cheaper_alternatives":[{"endpoint":"/api/exists/maven/io.quarkus%3Aquarkus-core","tokens_estimated":12,"use_when":"you only need to know if the package exists (hallucination guard)"},{"endpoint":"/api/health/maven/io.quarkus%3Aquarkus-core","tokens_estimated":80,"use_when":"you only need a 0-100 score for go/no-go (>=70 = safe)"},{"endpoint":"/api/prompt/maven/io.quarkus%3Aquarkus-core","tokens_estimated":280,"use_when":"you want a plain-text LLM-friendly brief instead of JSON"},{"endpoint":"POST /api/check_bulk","tokens_estimated":60,"use_when":"you have 5+ packages to check; sends one round-trip instead of N"}],"docs":"https://depscope.dev/integrate"},"requested_version":null,"_cache":"miss","_response_ms":364,"_powered_by":"depscope.dev — free package intelligence for AI agents","typosquat":{"is_suspected":false},"maintainer_trust":{"available":true,"bus_factor_3m":26,"active_contributors_12m":26,"primary_author_ratio":0.2,"owner_account_age_days":2623,"is_archived":false,"stars":15628,"alerts":[]},"malicious":{"is_malicious":false},"scorecard":{"available":true,"score":6.1,"tier":"moderate"},"quality":{"available":false},"breaking_changes_link":{"url":"/api/breaking/maven/io.quarkus:quarkus-core","count":18,"hint":"Use this endpoint to get version-pair breaking changes + migration hints."},"co_used_with":[{"package":"org.springframework:spring-portlet","occurrences":7},{"package":"ncr-background_fu","occurrences":2},{"package":"org.springframework:spring-hibernate3","occurrences":2}],"version_history_summary":{"total_versions":20,"first_release_age_days":1349,"last_release_days_ago":347,"avg_days_between_releases":71,"release_velocity":"moderate"}}