It’s totally fine in Maven, no need to rebuild or repackage anything. You just override version of libinsecure in your pom.xml and it uses the version you told it to
mvn dependency:tree -Dverbose
Or use maven-enforcer-plugin to fail the build on conflicts.