Bump the maven-dependencies group across 1 directory with 7 updates#121
Open
dependabot[bot] wants to merge 1 commit into
Open
Bump the maven-dependencies group across 1 directory with 7 updates#121dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the maven-dependencies group with 7 updates in the / directory: | Package | From | To | | --- | --- | --- | | org.slf4j:slf4j-api | `2.0.17` | `2.0.18` | | org.slf4j:slf4j-simple | `2.0.17` | `2.0.18` | | [org.junit.jupiter:junit-jupiter](https://github.com/junit-team/junit-framework) | `6.0.3` | `6.1.0` | | [org.apache.maven.plugins:maven-enforcer-plugin](https://github.com/apache/maven-enforcer) | `3.6.2` | `3.6.3` | | [org.apache.maven.plugins:maven-dependency-plugin](https://github.com/apache/maven-dependency-plugin) | `3.10.0` | `3.11.0` | | [org.apache.maven.plugins:maven-surefire-plugin](https://github.com/apache/maven-surefire) | `3.5.5` | `3.5.6` | | [org.owasp:dependency-check-maven](https://github.com/dependency-check/DependencyCheck) | `12.2.0` | `12.2.2` | Updates `org.slf4j:slf4j-api` from 2.0.17 to 2.0.18 Updates `org.slf4j:slf4j-simple` from 2.0.17 to 2.0.18 Updates `org.slf4j:slf4j-simple` from 2.0.17 to 2.0.18 Updates `org.junit.jupiter:junit-jupiter` from 6.0.3 to 6.1.0 - [Release notes](https://github.com/junit-team/junit-framework/releases) - [Commits](junit-team/junit-framework@r6.0.3...r6.1.0) Updates `org.apache.maven.plugins:maven-enforcer-plugin` from 3.6.2 to 3.6.3 - [Release notes](https://github.com/apache/maven-enforcer/releases) - [Commits](apache/maven-enforcer@enforcer-3.6.2...enforcer-3.6.3) Updates `org.apache.maven.plugins:maven-dependency-plugin` from 3.10.0 to 3.11.0 - [Release notes](https://github.com/apache/maven-dependency-plugin/releases) - [Commits](apache/maven-dependency-plugin@maven-dependency-plugin-3.10.0...maven-dependency-plugin-3.11.0) Updates `org.apache.maven.plugins:maven-surefire-plugin` from 3.5.5 to 3.5.6 - [Release notes](https://github.com/apache/maven-surefire/releases) - [Commits](apache/maven-surefire@surefire-3.5.5...surefire-3.5.6) Updates `org.owasp:dependency-check-maven` from 12.2.0 to 12.2.2 - [Release notes](https://github.com/dependency-check/DependencyCheck/releases) - [Changelog](https://github.com/dependency-check/DependencyCheck/blob/main/CHANGELOG.md) - [Commits](dependency-check/DependencyCheck@v12.2.0...v12.2.2) --- updated-dependencies: - dependency-name: org.slf4j:slf4j-api dependency-version: 2.0.18 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: maven-dependencies - dependency-name: org.slf4j:slf4j-simple dependency-version: 2.0.18 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: maven-dependencies - dependency-name: org.slf4j:slf4j-simple dependency-version: 2.0.18 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: maven-dependencies - dependency-name: org.junit.jupiter:junit-jupiter dependency-version: 6.1.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: maven-dependencies - dependency-name: org.apache.maven.plugins:maven-enforcer-plugin dependency-version: 3.6.3 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: maven-dependencies - dependency-name: org.apache.maven.plugins:maven-dependency-plugin dependency-version: 3.11.0 dependency-type: direct:development update-type: version-update:semver-minor dependency-group: maven-dependencies - dependency-name: org.apache.maven.plugins:maven-surefire-plugin dependency-version: 3.5.6 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: maven-dependencies - dependency-name: org.owasp:dependency-check-maven dependency-version: 12.2.2 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: maven-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the maven-dependencies group with 7 updates in the / directory:
2.0.172.0.182.0.172.0.186.0.36.1.03.6.23.6.33.10.03.11.03.5.53.5.612.2.012.2.2Updates
org.slf4j:slf4j-apifrom 2.0.17 to 2.0.18Updates
org.slf4j:slf4j-simplefrom 2.0.17 to 2.0.18Updates
org.slf4j:slf4j-simplefrom 2.0.17 to 2.0.18Updates
org.junit.jupiter:junit-jupiterfrom 6.0.3 to 6.1.0Release notes
Sourced from org.junit.jupiter:junit-jupiter's releases.
Commits
0dc3af1Release 6.1.01d13002Prepare 6.1.0 release notes072b217Update plugin spotless to v8.5.0 (#5668)3a53480Update Gradle to v9.5.1 (#5666)0e18a20Update zizmorcore/zizmor-action action to v0.5.4 (#5669)0a2634fUpdate github/codeql-action action to v4.35.5 (#5671)4dbd556Restructure workflows to have single "status" job (#5670)f2194ceIncrease timeout to reduce flakiness5c8fdd2Update dependency org.apache.groovy:groovy to v5.0.6 (#5659)43c6982Update dependency org.slf4j:slf4j-jdk14 to v2.0.18 (#5667)Updates
org.apache.maven.plugins:maven-enforcer-pluginfrom 3.6.2 to 3.6.3Release notes
Sourced from org.apache.maven.plugins:maven-enforcer-plugin's releases.
Commits
c7daff3[maven-release-plugin] prepare release enforcer-3.6.3ee46e78Make bannedDependencies report root and transitive dependency in case both ar...0806924Document the banMavenDefaults option for the requirePluginVersions rule. (#936)8e4f5b9Add better enforceBytecodeVersion rule based on mojohaus (#968)fd4b148Add fix for 21.0.10.0.1 issue (#967)f32d597Deps: Parent POM 48 and align deps (#979)df0f2a6Bump commons-codec:commons-codec from 1.21.0 to 1.22.0 (#976)2da7a68Add null checks for modelId in PluginWrapper91eb4d9Bump commons-io:commons-io from 2.21.0 to 2.22.0 (#975)b622245Bump mavenVersion from 3.9.14 to 3.9.15 (#973)Updates
org.apache.maven.plugins:maven-dependency-pluginfrom 3.10.0 to 3.11.0Release notes
Sourced from org.apache.maven.plugins:maven-dependency-plugin's releases.
Commits
c186d05[maven-release-plugin] prepare release maven-dependency-plugin-3.11.03712611Fix artifact relocation supporte873e0eManage ASM version 9.10 to support JDK 2770b5356fix: fix addParentPoms=true causes repositories to be ignored. (#1585)51d8939Fix false positive in analyze-exclusions with transitive dependency exclusion...02b865bBump eu.maveniverse.maven.domtrip:domtrip-core from 1.5.0 to 1.5.104f4de1Bump eu.maveniverse.maven.domtrip:domtrip-maven from 1.5.0 to 1.5.12812490Bump mavenVersion from 3.9.15 to 3.9.16ce117daBump org.apache.maven.shared:maven-dependency-analyzeraea7a64Prevent NPE (#1622)Updates
org.apache.maven.plugins:maven-surefire-pluginfrom 3.5.5 to 3.5.6Release notes
Sourced from org.apache.maven.plugins:maven-surefire-plugin's releases.
Commits
25ea054[maven-release-plugin] prepare release surefire-3.5.6e5f374cBump org.fusesource.jansi:jansi from 2.4.2 to 2.4.3dadd55bIssue #2613 Debugging failsafe tests: Message 'Listening for transport dt_soc...39dd250Bump commons-io:commons-io from 2.21.0 to 2.22.02774273Ensure that the statistics filename is calculated only once. (#3326) (#3327)0d5df8a3.5.x/bug/cherry pick embedded mode its (#3328)04ad9a2Use surefire 3.5.5 by project itself for testing37e8f69Addflakesattribute to use intestsuitereport (#3306) (#3308)a970fefIntroduce reportTestTimestamp option and include timestamp for test sets and ...e838393deploy 3.5.x branch to nexusUpdates
org.owasp:dependency-check-mavenfrom 12.2.0 to 12.2.2Release notes
Sourced from org.owasp:dependency-check-maven's releases.
Changelog
Sourced from org.owasp:dependency-check-maven's changelog.
... (truncated)
Commits
b51290fbuild: prepare release v12.2.270070a9docs: release 12.2.247aa0c7fix: widen reference URL column to handle long Mozilla CVE URLs (#8467)1de40c0build(deps): bump the actions-deps group with 8 updates (#8472)74678b0build(deps): bump com.fasterxml.jackson:jackson-bom from 2.21.2 to 2.21.3 (#8...3f83d80build(deps): bump org.postgresql:postgresql from 42.7.10 to 42.7.11 (#8463)04387c3build(deps): bump commons-codec:commons-codec from 1.21.0 to 1.22.0 (#8453)11e1771build(deps): bump org.apache.maven.plugins:maven-invoker-plugin from 3.9.1 to...e850545chore(fp): remove duplicate log4j FP suppressions (#8468)9acbb33feat: improve Sonatype Guide / OSS Index cache handling and insufficient cred...Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions