Description
It suffers from multiple CVEs:
- guava < 24.1.1 is vulnerable to CVE-2018-10237.
- guava < 30.0 is vulnerable to CVE-2020-8908.
Moving to guava 30.1 will require moving to Java 8 so it's actually simpler to just remove the dependency altogether.