Techini / vulnado

Purposely vulnerable Java application to help lead secure coding workshops
Apache License 2.0
0 stars 0 forks source link

Bump postgresql from 42.2.5 to 42.2.23 #136

Open dependabot-preview[bot] opened 3 years ago

dependabot-preview[bot] commented 3 years ago

Bumps postgresql from 42.2.5 to 42.2.23.

Changelog

Sourced from postgresql's changelog.

Changelog

Notable changes since version 42.0.0, read the complete History of Changes.

The format is based on Keep a Changelog.

[Unreleased]

Changed

Added

Fixed

[42.2.23] (2021-07-06 09:17:32 -0400)

Changed

  • renewed the SSL keys for testing

Added

Fixed

  • getColumnPrecision for Numeric when scale and precision not specified now returns 0 instead of 131089 fixes: Issue #2188
  • Calling refreshRow on an updateable resultset made the row readOnly. Fixes Issue #2193
  • results should be updateable if there is a unique index available PR#2199 Fixes Issue #2196
  • Rework sql type gathering to use OID instead of typname. This does not have the issue of name shadowing / qual-names, and has the added benefit of fixing #1948.

[42.2.22] (2021-06-16 10:09:33 -0400)

Changed

Added

Fixed

[42.2.21] (2021-06-10 10:08:21 -0400)

Changed

Added

Fixed

[42.2.20] (2021-04-19 15:38:44 -0400)

... (truncated)

Commits
  • d985dc1 Update Changelog (#2207)
  • e1b8437 backpatch #1949 (#2206)
  • 624d8b8 fix: jre6 jar not being created due to preprocessMain failing due to the dest...
  • 70f576c fix getColumnPrecision for Numeric when scale and precision not specified fix...
  • 8f42bf9 backpatch fixing refreshRow makes resultset readonly fixes Issue #2193 (#2202)
  • 8d7c78f Backpatch fixupdateable (#2200)
  • a59f810 test: Regenerate TLS certs with new expirations (#2201)
  • 466bad1 revert 4fa2d5bc1ed8 to fix the regression introduced. Fixes [Issue 2180](http...
  • 72da923 fix formatting (#2178)
  • 90e694d pre-release for 42.2.21 (#2176)
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) - `@dependabot use these labels` will set the current labels as the default for future PRs for this repo and language - `@dependabot use these reviewers` will set the current reviewers as the default for future PRs for this repo and language - `@dependabot use these assignees` will set the current assignees as the default for future PRs for this repo and language - `@dependabot use this milestone` will set the current milestone as the default for future PRs for this repo and language - `@dependabot badge me` will comment on this PR with code to add a "Dependabot enabled" badge to your readme Additionally, you can set the following in your Dependabot [dashboard](https://app.dependabot.com): - Update frequency (including time of day and day of week) - Pull request limits (per update run and/or open at any time) - Out-of-range updates (receive only lockfile updates, if desired) - Security updates (receive only security updates, if desired)
sonarcloud[bot] commented 3 years ago

Kudos, SonarCloud Quality Gate passed!

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
0.0% 0.0% Duplication