SAP / fosstars-rating-core

A framework for defining ratings for open source projects. In particular, the framework offers a security rating for open source projects that may be used to assess the security risk that comes with open source components.
https://sap.github.io/fosstars-rating-core/
Apache License 2.0
59 stars 27 forks source link

Bump maven-model from 3.9.1 to 3.9.2 #949

Closed dependabot[bot] closed 11 months ago

dependabot[bot] commented 1 year ago

Bumps maven-model from 3.9.1 to 3.9.2.

Release notes

Sourced from maven-model's releases.

3.9.2

Release Notes - Maven - Version 3.9.2

Bug

  • [MNG-7750] - Interpolated properties in originalModel in an active profile.
  • [MNG-7759] - java.lang.NullPointerException at org.apache.maven.repository.internal.DefaultModelCache.newInstance (DefaultModelCache.java:37)

Improvement

  • [MNG-7712] - Core should issue a warning if plugin depends on maven-compat
  • [MNG-7741] - Add more information when using -Dmaven.repo.local.recordReverseTree=true
  • [MNG-7754] - Improvement and extension of plugin validation
  • [MNG-7767] - Tone down plugin validation report
  • [MNG-7778] - Maven should print suppressed exceptions when a mojo fails

Task

  • [MNG-7749] - Upgrade animal-sniffer from 1.21 to 1.23
  • [MNG-7774] - Maven config and command line interpolation

Dependency upgrade

  • [MNG-7670] - Upgrade misc dependencies
  • [MNG-7753] - Upgrade to Maven Resolver 1.9.8
  • [MNG-7769] - Upgrade to Maven Resolver 1.9.10
Commits
  • c961601 [maven-release-plugin] prepare release maven-3.9.2
  • c2331d3 [MNG-7778] - Include suppressed exceptions when logging failures (#1103)
  • 79556dd [MNG-7774] Maven config and command line interpolation (#1098)
  • 7cb87a6 [MNG-7769] Update Resolver to 1.9.10 (#1101)
  • a2428a6 [MNG-7767] Tone down plugin validator (#1092)
  • 924dbfe [MNG-7670] Update misc dependencies (#1089)
  • a4b7532 [MNG-7753] Upgrade to Resolver 1.9.8 (#1077)
  • eb7cdef [MNG-7759] Maven2 plugins will not have even session setter (#1084)
  • bc138dc [MNG-7741] Track missing files, plugin and parent pom dependencies (#1058)
  • 0f18470 [MNG-7750] Fix unwanted interpolation in plugins from profiles. (#1075)
  • Additional commits viewable in compare view


Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
> **Note** > Automatic rebases have been disabled on this pull request as it has been open for over 30 days.
dependabot[bot] commented 1 year ago

A newer version of org.apache.maven:maven-model exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged.

sourabhsparkala commented 11 months ago

@dependabot rebase

dependabot[bot] commented 11 months ago

Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!

If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

sourabhsparkala commented 11 months ago

@dependabot recreate

dependabot[bot] commented 11 months ago

Superseded by #967.