It fixes a false positive CVE warning. The Java 7+ binary of the previous release contains metadata pointing to the snakeyaml library version 1.23. This causes the Trivy security scanner to wrongly report CVE-2017-18640, even though that snakeyaml version is not included in the binary.