# Dangerous fingerprint for shared library

**URL:** <https://community.jenkins.io/t/dangerous-fingerprint-for-shared-library/5347>\
**Category:** Ask a question\
**Tags:** pipeline\
**Created:** [January 17, 2023, 3:18pm UTC](https://community.jenkins.io/t/dangerous-fingerprint-for-shared-library/5347 "2023-01-17T15:18:09Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![rngkll](https://avatars.discourse-cdn.com/v4/letter/r/858c86/32.png) [@rngkll](https://community.jenkins.io/u/rngkll)\
**Post date:** [January 17, 2023, 3:18pm UTC](https://community.jenkins.io/t/dangerous-fingerprint-for-shared-library/5347/1 "2023-01-17T15:18:09Z")

</div>

Hi,

We are trying to extend the Jenkins pipeline with shared libraries.

We are building maven projects and we need to read the pom file, because we are trying to follow a test driven development, we used readFile from the shared library, in that way we can mock and test the content of the pom file.

We are getting a warning saying that the signature might introduce vulnerabilities.

Signature: method groovy.lang.GroovyObject getProperty java.lang.String

I had the idea that everything runs in a sandBox, readFile won’t be able to leave the sandbox.

Is there a better way of doing this?  
Is there any risk on using readFile on a shared library?

thanks in advance.
