BenF-DemoCorp-mend / WebGoat-Remediate

Other
0 stars 1 forks source link

Update dependency org.owasp:dependency-check-maven to v6.5.3 #6

Closed mend-for-github-com[bot] closed 7 months ago

mend-for-github-com[bot] commented 7 months ago

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
org.owasp:dependency-check-maven (source) 6.5.1 -> 6.5.3 age adoption passing confidence

Release Notes

jeremylong/DependencyCheck (org.owasp:dependency-check-maven) ### [`v6.5.3`](https://togithub.com/jeremylong/DependencyCheck/blob/HEAD/CHANGELOG.md#Version-653-2022-01-12) [Compare Source](https://togithub.com/jeremylong/DependencyCheck/compare/v6.5.2...v6.5.3) ##### Changed - Performance improvements for some Maven projects (see [#​3923](https://togithub.com/jeremylong/DependencyCheck/issues/3923) and [#​3931](https://togithub.com/jeremylong/DependencyCheck/issues/3931)). - Fixed bug in npm version handling introduced in 6.5.2 (see [#​3956](https://togithub.com/jeremylong/DependencyCheck/issues/3956)). - Improved the node package analyzer to correctly report the origin of a dependency (see [#​3970](https://togithub.com/jeremylong/DependencyCheck/issues/3970)). - General code maintenance and false positive reductions. See the full listing of [changes](https://togithub.com/jeremylong/DependencyCheck/milestone/39?closed=1). ### [`v6.5.2`](https://togithub.com/jeremylong/DependencyCheck/blob/HEAD/CHANGELOG.md#Version-652-2022-01-03) [Compare Source](https://togithub.com/jeremylong/DependencyCheck/compare/v6.5.1...v6.5.2) ##### Changed - Fixed false positives around log4j-api and Log4j-web ([#​3910](https://togithub.com/jeremylong/DependencyCheck/issues/3910) & [#​3937](https://togithub.com/jeremylong/DependencyCheck/issues/3937)). - Bug fix when processing NPM lock files ([#​3893](https://togithub.com/jeremylong/DependencyCheck/issues/3893)). - Added missing `pnpm` argmument to the CLI ([#​3916](https://togithub.com/jeremylong/DependencyCheck/issues/3916)). - General code maintenance and false positive reductions. See the full listing of [changes](https://togithub.com/jeremylong/DependencyCheck/milestone/38?closed=1).

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


mend-for-github-com[bot] commented 7 months ago

Renovate Ignore Notification

Because you closed this PR without merging, Renovate will ignore this update (6.5.3). You will get a PR once a newer version is released. To ignore this dependency forever, add it to the ignoreDeps array of your Renovate config.

If you accidentally closed this PR, or if you changed your mind: rename this PR to get a fresh replacement PR.