samjcs / log4shell-possible-malware

Repo I found while it was in proccess of being deleted that could contain malware using the log4j exploit
0 stars 0 forks source link

Configure Renovate #1

Open renovate[bot] opened 2 years ago

renovate[bot] commented 2 years ago

Mend Renovate

Welcome to Renovate! This is an onboarding PR to help you understand and configure settings before regular Pull Requests begin.

🚦 To activate Renovate, merge this Pull Request. To disable Renovate, simply close this Pull Request unmerged.


Detected Package Files

Configuration Summary

Based on the default config's presets, Renovate will:

🔡 Do you want to change how Renovate upgrades your dependencies? Add your custom config to renovate.json in this branch. Renovate will update the Pull Request description the next time it runs.


What to Expect

With your current configuration, Renovate will create 24 Pull Requests:

Update dependency io.undertow:undertow-core to v2.2.24.Final [SECURITY] - Branch name: `renovate/maven-io.undertow-undertow-core-vulnerability` - Merge into: `main` - Upgrade [io.undertow:undertow-core](https://togithub.com/undertow-io/undertow) to `2.2.24.Final`
Update dependency org.apache.tomcat.embed:tomcat-embed-core to v8.5.93 [SECURITY] - Branch name: `renovate/maven-org.apache.tomcat.embed-tomcat-embed-core-vulnerability` - Merge into: `main` - Upgrade org.apache.tomcat.embed:tomcat-embed-core to `8.5.93`
Update dependency org.codehaus.groovy:groovy to v2.4.21 [SECURITY] - Branch name: `renovate/maven-org.codehaus.groovy-groovy-vulnerability` - Merge into: `main` - Upgrade [org.codehaus.groovy:groovy](https://togithub.com/apache/groovy) to `2.4.21`
Update dependency org.springframework:spring-beans to v5.2.20.RELEASE [SECURITY] - Branch name: `renovate/maven-org.springframework-spring-beans-vulnerability` - Merge into: `main` - Upgrade [org.springframework:spring-beans](https://togithub.com/spring-projects/spring-framework) to `5.2.20.RELEASE`
Update dependency org.springframework:spring-core to v5.2.24.RELEASE [SECURITY] - Branch name: `renovate/maven-org.springframework-spring-core-vulnerability` - Merge into: `main` - Upgrade [org.springframework:spring-core](https://togithub.com/spring-projects/spring-framework) to `5.2.24.RELEASE`
Update dependency org.springframework:spring-webmvc to v5.2.20.RELEASE [SECURITY] - Branch name: `renovate/maven-org.springframework-spring-webmvc-vulnerability` - Merge into: `main` - Upgrade [org.springframework:spring-webmvc](https://togithub.com/spring-projects/spring-framework) to `5.2.20.RELEASE`
Update dependency commons-collections:commons-collections to v3.2.2 [SECURITY] - Branch name: `renovate/maven-commons-collections-commons-collections-vulnerability` - Merge into: `main` - Upgrade commons-collections:commons-collections to `3.2.2`
Update dependency junit:junit to v4.13.1 [SECURITY] - Branch name: `renovate/maven-junit-junit-vulnerability` - Merge into: `main` - Upgrade [junit:junit](https://togithub.com/junit-team/junit4) to `4.13.1`
Update dependency org.apache.commons:commons-collections4 to v4.1 [SECURITY] - Branch name: `renovate/maven-org.apache.commons-commons-collections4-vulnerability` - Merge into: `main` - Upgrade [org.apache.commons:commons-collections4](https://git-wip-us.apache.org/repos/asf?p=commons-collections.git) to `4.1`
Update dependency org.apache.commons:commons-text to v1.10.0 [SECURITY] - Branch name: `renovate/maven-org.apache.commons-commons-text-vulnerability` - Merge into: `main` - Upgrade [org.apache.commons:commons-text](https://gitbox.apache.org/repos/asf?p=commons-text.git) to `1.10.0`
Update dependency org.springframework:spring-web to v6 [SECURITY] - Branch name: `renovate/maven-org.springframework-spring-web-vulnerability` - Merge into: `main` - Upgrade [org.springframework:spring-web](https://togithub.com/spring-projects/spring-framework) to `6.0.0`
Update dependency com.unboundid:unboundid-ldapsdk to v4.0.14 - Schedule: ["at any time"] - Branch name: `renovate/com.unboundid-unboundid-ldapsdk-4.x` - Merge into: `main` - Upgrade [com.unboundid:unboundid-ldapsdk](https://togithub.com/pingidentity/ldapsdk) to `4.0.14`
Update dependency net.jodah:expiringmap to v0.5.11 - Schedule: ["at any time"] - Branch name: `renovate/net.jodah-expiringmap-0.x` - Merge into: `main` - Upgrade [net.jodah:expiringmap](https://togithub.com/jhalterman/expiringmap) to `0.5.11`
Update dependency com.beust:jcommander to v1.82 - Schedule: ["at any time"] - Branch name: `renovate/com.beust-jcommander-1.x` - Merge into: `main` - Upgrade [com.beust:jcommander](https://togithub.com/cbeust/jcommander) to `1.82`
Update dependency com.nqzero:permit-reflect to v0.4 - Schedule: ["at any time"] - Branch name: `renovate/com.nqzero-permit-reflect-0.x` - Merge into: `main` - Upgrade com.nqzero:permit-reflect to `0.4`
Update dependency io.undertow:undertow-servlet to v2.3.10.Final - Schedule: ["at any time"] - Branch name: `renovate/io.undertow-undertow-servlet-2.x` - Merge into: `main` - Upgrade [io.undertow:undertow-servlet](https://togithub.com/undertow-io/undertow) to `2.3.10.Final`
Update dependency org.apache.maven.plugins:maven-compiler-plugin to v3.11.0 - Schedule: ["at any time"] - Branch name: `renovate/org.apache.maven.plugins-maven-compiler-plugin-3.x` - Merge into: `main` - Upgrade org.apache.maven.plugins:maven-compiler-plugin to `3.11.0`
Update dependency org.reflections:reflections to v0.10.2 - Schedule: ["at any time"] - Branch name: `renovate/org.reflections-reflections-0.x` - Merge into: `main` - Upgrade [org.reflections:reflections](https://togithub.com/ronmamo/reflections) to `0.10.2`
Update spring core to v5.3.31 - Schedule: ["at any time"] - Branch name: `renovate/spring-core` - Merge into: `main` - Upgrade [org.springframework:spring-test](https://togithub.com/spring-projects/spring-framework) to `5.3.31` - Upgrade [org.springframework:spring-context-support](https://togithub.com/spring-projects/spring-framework) to `5.3.31` - Upgrade [org.springframework:spring-aop](https://togithub.com/spring-projects/spring-framework) to `5.3.31` - Upgrade [org.springframework:spring-jdbc](https://togithub.com/spring-projects/spring-framework) to `5.3.31` - Upgrade [org.springframework:spring-tx](https://togithub.com/spring-projects/spring-framework) to `5.3.31` - Upgrade [org.springframework:spring-oxm](https://togithub.com/spring-projects/spring-framework) to `5.3.31`
Update dependency com.unboundid:unboundid-ldapsdk to v6 - Schedule: ["at any time"] - Branch name: `renovate/com.unboundid-unboundid-ldapsdk-6.x` - Merge into: `main` - Upgrade [com.unboundid:unboundid-ldapsdk](https://togithub.com/pingidentity/ldapsdk) to `6.0.11`
Update dependency org.apache.maven.plugins:maven-install-plugin to v3 - Schedule: ["at any time"] - Branch name: `renovate/org.apache.maven.plugins-maven-install-plugin-3.x` - Merge into: `main` - Upgrade org.apache.maven.plugins:maven-install-plugin to `3.1.1`
Update dependency org.ow2.asm:asm to v9 - Schedule: ["at any time"] - Branch name: `renovate/org.ow2.asm-asm-9.x` - Merge into: `main` - Upgrade [org.ow2.asm:asm](https://gitlab.ow2.org/asm/asm/) to `9.6`
Update openjdk Docker tag to v21 - Schedule: ["at any time"] - Branch name: `renovate/openjdk-21.x` - Merge into: `main` - Upgrade openjdk to `21-jdk-slim-buster`
Update spring core to v6 (major) - Schedule: ["at any time"] - Branch name: `renovate/major-spring-core` - Merge into: `main` - Upgrade [org.springframework:spring-test](https://togithub.com/spring-projects/spring-framework) to `6.1.2` - Upgrade [org.springframework:spring-context-support](https://togithub.com/spring-projects/spring-framework) to `6.1.2` - Upgrade [org.springframework:spring-aop](https://togithub.com/spring-projects/spring-framework) to `6.1.2` - Upgrade [org.springframework:spring-jdbc](https://togithub.com/spring-projects/spring-framework) to `6.1.2` - Upgrade [org.springframework:spring-tx](https://togithub.com/spring-projects/spring-framework) to `6.1.2` - Upgrade [org.springframework:spring-oxm](https://togithub.com/spring-projects/spring-framework) to `6.1.2`


🚸 Branch creation will be limited to maximum 2 per hour, so it doesn't swamp any CI resources or overwhelm the project. See docs for prhourlylimit for details.


[!WARNING] Please correct - or verify that you can safely ignore - these dependency lookup failures before you merge this PR.

  • Failed to look up maven package coherence:coherence

Files affected: pom.xml


❓ Got questions? Check out Renovate's Docs, particularly the Getting Started section. If you need any further assistance then you can also request help here.


This PR has been generated by Mend Renovate. View repository job log here.