Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
- `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
- `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency
- `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions
Bumps the dependabot-dependency-updates group with 9 updates in the / directory:
2.0.13
2.0.16
2.17.1
2.17.2
2.17.0
2.17.2
3.7.1
3.8.0
3.3.0
3.5.0
3.7.0
3.10.0
10.0.2
10.0.4
3.2.4
3.2.5
2.8.0
2.8.1
Updates
org.slf4j:slf4j-simple
from 2.0.13 to 2.0.16Updates
com.fasterxml.jackson.core:jackson-databind
from 2.17.1 to 2.17.2Commits
Updates
com.fasterxml.jackson.dataformat:jackson-dataformat-yaml
from 2.17.0 to 2.17.2Commits
86f27f7
[maven-release-plugin] prepare release jackson-dataformats-text-2.17.229c3900
Prepare for 2.17.2 release6750677
Backport #481, update release notese51d723
CSV: fix issue in setSchema (#481)ff5d1d6
Back to snapshot dep2623f30
[maven-release-plugin] prepare for next development iterationd7b7bf1
[maven-release-plugin] prepare release jackson-dataformats-text-2.17.18de9ac8
Prepare for 2.17.1 release163849b
Fix #469: Add a way to distinguish between null and empty (#471)029030b
Fix one flag in #472Updates
org.apache.maven.plugins:maven-dependency-plugin
from 3.7.1 to 3.8.0Commits
75814c7
[maven-release-plugin] prepare release maven-dependency-plugin-3.8.050397c4
[MDEP-903] Upgrade to Doxia 2.0.0 Milestone Stack1115ecb
Bump org.codehaus.plexus:plexus-archiver from 4.9.2 to 4.10.05288cec
Bump org.apache.maven.plugins:maven-plugins from 42 to 43ea4d8e2
Bump jettyVersion from 9.4.54.v20240208 to 9.4.55.v202406272d0b82a
Bump org.codehaus.plexus:plexus-io from 3.4.2 to 3.5.086b7772
(doc) Remove repeated word94e1caf
Bump org.jsoup:jsoup from 1.17.2 to 1.18.106b4273
Bump org.assertj:assertj-core from 3.26.0 to 3.26.371cee33
Remove outdated invoker conditionsUpdates
org.apache.maven.plugins:maven-surefire-plugin
from 3.3.0 to 3.5.0Commits
c78365f
[maven-release-plugin] prepare release surefire-3.5.005e4681
[SUREFIRE-2227] Dynamically calculate xrefTestLocationf1a419a
[SUREFIRE-2228] Upgrade to Doxia 2.0.0 Milestone Stack5e14d4f
[SUREFIRE-2161] Align Mojo class names and output namesc0784ab
Bump org.apache.commons:commons-compress from 1.27.0 to 1.27.179ea717
[SUREFIRE-2256] Upgrade to Parent 434648b47
add Reproducible Builds badgef64c1b3
[maven-release-plugin] prepare for next development iteration3ae062d
[maven-release-plugin] prepare release surefire-3.4.0f0de8c0
Bump org.htmlunit:htmlunit from 4.3.0 to 4.4.0Updates
org.apache.maven.plugins:maven-javadoc-plugin
from 3.7.0 to 3.10.0Commits
487e479
[maven-release-plugin] prepare release maven-javadoc-plugin-3.10.09638a6a
[MJAVADOC-785] Align plugin implementation with AbstractMavenReport (maven-re...9d33925
[MJAVADOC-784] Upgrade to Doxia 2.0.0 Milestone Stacka11b921
[MJAVADOC-809] Align Mojo class names7c4b467
Bump org.apache.maven.plugins:maven-plugins from 42 to 43636442b
Improve ITsdbca15a
Bump org.hamcrest:hamcrest-core from 2.2 to 3.0d02bb88
Bump org.apache.commons:commons-lang3 from 3.15.0 to 3.16.00a850a1
[MJAVADOC-807] Simplify IT for MJAVADOC-49843e901f
Improve URL handlingUpdates
org.owasp:dependency-check-maven
from 10.0.2 to 10.0.4Release notes
Sourced from org.owasp:dependency-check-maven's releases.
Changelog
Sourced from org.owasp:dependency-check-maven's changelog.
Commits
5120cbd
build: prepare release v10.0.405df233
docs: release notes for 10.0.4a3a74bc
build(deps): bump org.apache.maven.plugins:maven-failsafe-plugin from 3.3.0 t...67c9d9e
build(deps): bump golang from 1.22.6-alpine to 1.23.0-alpine (#6893)1bc85e2
build(deps): bump org.apache.maven.plugins:maven-failsafe-plugin2fe67ed
build(deps): bump commons-codec:commons-codec from 1.17.0 to 1.17.1 (#6900)e835fad
build(deps): exclude unused dependency (#6916)ccc151a
fix: improve regex (#6917)e090d40
chore: additional tests (#6918)b4339ce
fix: correctly handle null values in cpeMatch (#6915)Updates
org.apache.maven.plugins:maven-gpg-plugin
from 3.2.4 to 3.2.5Release notes
Sourced from org.apache.maven.plugins:maven-gpg-plugin's releases.
Commits
737d4ee
[maven-release-plugin] prepare release maven-gpg-plugin-3.2.57747063
[MGPG-134] Update maven-invoker (#110)3df5f83
[MGPG-133] Bump org.simplify4u.plugins:pgpverify-maven-plugin from 1.17.0 to ...58a2069
[MGPG-132] Bump com.kohlschutter.junixsocket:junixsocket-core from 2.9.1 to 2...e911b43
[MGPG-131] Bump org.apache.maven.plugins:maven-plugins from 42 to 43 (#108)d2b60d3
[MGPG-130] Update sigstore extension for exclusion (#109)091f388
Bump org.apache.maven.plugins:maven-invoker-plugin from 3.6.1 to 3.7.0899f410
[MGPG-128] Parent POM 42, prerequisite 3.6.3 (#100)f0be6f3
[MGPG-127] Bump bouncycastleVersion from 1.78 to 1.78.1 (#98)7dd5166
[maven-release-plugin] prepare for next development iterationUpdates
org.cyclonedx:cyclonedx-maven-plugin
from 2.8.0 to 2.8.1Release notes
Sourced from org.cyclonedx:cyclonedx-maven-plugin's releases.
Commits
2de88e5
[maven-release-plugin] prepare release cyclonedx-maven-plugin-2.8.11510a02
upgrade cyclonedx-maven-plugin from 2.7.9 to 2.8.0448d117
Bump net.javacrumbs.json-unit:json-unit-assertj from 2.38.0 to 2.40.1cfcf26b
Bump org.apache.maven.plugins:maven-release-plugin from 3.0.1 to 3.1.1f95fe87
Bump org.apache.maven.plugins:maven-javadoc-plugin from 3.7.0 to 3.8.04ee61c3
Bump org.junit:junit-bom from 5.10.2 to 5.10.38eb5316
Bump org.apache.maven.plugins:maven-jar-plugin from 3.4.1 to 3.4.24c77122
replace CDX 1.5 deprecated tool7f34a10
Bump plugin-tools.version from 3.13.0 to 3.13.1ab713bb
Bump org.apache.maven.plugins:maven-project-info-reports-pluginDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show