dbflute-session / tomcat-boot

boot library for web application by Tomcat
Apache License 2.0
3 stars 3 forks source link

Bump org.owasp:dependency-check-maven from 9.0.2 to 9.0.3 #212

Closed dependabot[bot] closed 7 months ago

dependabot[bot] commented 7 months ago

Bumps org.owasp:dependency-check-maven from 9.0.2 to 9.0.3.

Release notes

Sourced from org.owasp:dependency-check-maven's releases.

Version 9.0.3

  • fix: use Java properties for proxy configuration (#6238)
  • docs: update proxy configuration documentation (#6237)
  • docs: add documentation on caching (#6204)
  • docs: Clarify H2 database caching strategy (#6220)
  • docs: Update list of supported report formats (#6224)
  • docs: example 5 with new nvdDatafeedUrl parameter (#6215)
  • fix: prevent NPEs (#6232 and #6206)
  • fix: check valid for hours for NVD API (#6225)
  • fix: correct NVD cache last checked logic (#6218)
  • fix: nvd datafeed should process current year (#6213)
  • fix: correct references to cvssv2 and cvssv3 fields in json and xml reports (#6212)
  • fix: correct name on reference links in report (#6205)
  • fix: flaws int the gitlab report (#6193)

See the full listing of changes.

Changelog

Sourced from org.owasp:dependency-check-maven's changelog.

Version 9.0.3 (2023-12-06)

  • fix: use Java properties for proxy configuration (#6238)
  • docs: update proxy configuration documentation (#6237)
  • docs: add documentation on caching (#6204)
  • docs: Clarify H2 database caching strategy (#6220)
  • docs: Update list of supported report formats (#6224)
  • docs: example 5 with new nvdDatafeedUrl parameter (#6215)
  • fix: prevent NPEs (#6232 and #6206)
  • fix: check valid for hours for NVD API (#6225)
  • fix: correct NVD cache last checked logic (#6218)
  • fix: nvd datafeed should process current year (#6213)
  • fix: correct references to cvssv2 and cvssv3 fields in json and xml reports (#6212)
  • fix: correct name on reference links in report (#6205)
  • fix: flaws int the gitlab report (#6193)

See the full listing of changes.

Commits


Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)