{
  "@context": "https://openvex.dev/ns/v0.2.0",
  "@id": "https://data.datagrok.ai/vex/jkg_r/1.1.0.json",
  "author": "Datagrok",
  "timestamp": "2026-08-12T22:32:22Z",
  "version": 1,
  "statements": [
    {
      "vulnerability": {
        "name": "CVE-2018-10237"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_r@sha256:af3370504e92631b43deb2fcd21a4269da93558def0f07c66751c3a69b8ce394?tag=1.1.0"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_in_execute_path",
      "impact_statement": "guava 19.0 is vendored inside the r2pmml CRAN package's bundled Java converter jar (inst/java). The image ships no Java runtime, so the jar can never be loaded; r2pmml's Java conversion path is inert in this image."
    },
    {
      "vulnerability": {
        "name": "CVE-2020-8908"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_r@sha256:af3370504e92631b43deb2fcd21a4269da93558def0f07c66751c3a69b8ce394?tag=1.1.0"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_in_execute_path",
      "impact_statement": "guava 19.0 vendored in the r2pmml converter jar; no Java runtime in the image — same rationale as CVE-2018-10237."
    },
    {
      "vulnerability": {
        "name": "CVE-2023-2976"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_r@sha256:af3370504e92631b43deb2fcd21a4269da93558def0f07c66751c3a69b8ce394?tag=1.1.0"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_not_in_execute_path",
      "impact_statement": "guava 19.0 vendored in the r2pmml converter jar; no Java runtime in the image — same rationale as CVE-2018-10237."
    }
  ]
}
