Resolves #973: NPE if actual version is null for a dependency (#974) @ajarmoniuk
📦 Dependency updates
Bump org.springframework:spring-framework-bom from 3.2.17.RELEASE to 4.3.30.RELEASE in /versions-maven-plugin/src/it/it-property-updates-report-002-slow (#999) @dependabot
Bump org.apache.commons:commons-lang3 from 3.12.0 to 3.13.0 (#993) @dependabot
Bump org.codehaus.plexus:plexus-archiver from 4.7.1 to 4.8.0 (#989) @dependabot
Bump org.junit:junit-bom from 5.9.3 to 5.10.0 (#987) @dependabot
Document the end of versioning limitations in Maven 3.x
There may remain good reasons for defining custom versioning rules to
let versions-maven-plugin apply, but at least not the old Maven 2.x
limitation
[Fixed Issue 256][issue-256]
if initial and new version are equals, just display initial
this means this is a plugin version that requires a Maven version that
is not compatible with project minimum version, not really a proposed
upgrade
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Bumps org.codehaus.mojo:versions-maven-plugin from 2.1 to 2.16.2.
Release notes
Sourced from org.codehaus.mojo:versions-maven-plugin's releases.
... (truncated)
Changelog
Sourced from org.codehaus.mojo:versions-maven-plugin's changelog.
... (truncated)
Commits
6b33fbc
[maven-release-plugin] prepare release 2.16.2e56c8c4
Align update-parent and display-parent-update (#1017)1136bf4
Fix ISE with plugins aggregate report when reactor projects contains the same...2fd9c32
Reading project model should throw exception2ac332d
Bump org.codehaus.plexus:plexus-archiver from 4.8.0 to 4.9.0048d3a3
Bump org.apache.commons:commons-text from 1.10.0 to 1.11.04a397c2
Cleanup redundant definitions after pom update69cc330
Bump org.codehaus.mojo:mojo-parent from 76 to 77eca1e46
Bump commons-io:commons-io from 2.14.0 to 2.15.08fefd9d
Add dependency to plexus-xml 3.0.0Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show