I’ve encountered a vulnerability after running the Snyk open source security management tool and am not sure how to resolve it.
This is an Android project with the robolectric dependency added.
✗ Dual license: CDDL-1.1, GPL-2.0-with-classpath-exception [High Severity][https://snyk.io/vuln/snyk:lic:maven:javax.annotation:javax.annotation-api:(CDDL-1.1_OR_GPL-2.0-with-classpath-exception)]
in javax.annotation:[email protected]
introduced by org.robolectric:[email protected] > javax.annotation:[email protected]
and 4 other path(s)