Open dependabot[bot] opened 1 year ago
A newer version of cyclonedx-python-lib exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged.
@dependabot rebase
Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!
If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate
.
Cyclone-dx dropped support for py 3.7 which would requires us to do so as well. Keeping this branch open for now.
Bumps cyclonedx-python-lib from 4.2.2 to 5.0.1.
Release notes
Sourced from cyclonedx-python-lib's releases.
... (truncated)
Changelog
Sourced from cyclonedx-python-lib's changelog.
... (truncated)
Commits
b777901
chore(release): 5.0.1aae7304
"chore(deps): revert bump python-semantic-release/python-semantic-release (#4...9c3ffac
chore(deps): bump python-semantic-release/python-semantic-release (#474)c4eaaa5
chore: makepyproject
parsable by dependabot (#477)c3254d0
docs: revisit project meta (#475)b9fcfb4
docs: fix RTFD build (#476)4454d60
chore(release): 5.0.026b151c
feat!: v5.0.0 (#440)50ce108
chore(release): 4.2.35fa66a0
fix: SPDX-expression-validation internal crashes are cought and handled (#471)You can trigger a rebase of this PR by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show