tackle vulnerabilities reported in sonarqube https://sonarqube-prod.apps.wdc-sonarqube-prod.core.cirrus.ibm.com/projects