smallrye / smallrye-common

Common utilities for SmallRye
Apache License 2.0
21 stars 24 forks source link

Bump maven-artifact from 3.8.6 to 3.9.0 #204

Closed dependabot[bot] closed 1 year ago

dependabot[bot] commented 1 year ago

Bumps maven-artifact from 3.8.6 to 3.9.0.

Release notes

Sourced from maven-artifact's releases.

3.8.7

Sub-task

  • [MNG-7019] - Notify also at start when profile is missing

Bug

  • [MNG-7106] - VersionRange.toString() produces a string that cannot be parsed with VersionRange.createFromVersionSpec() for same lower and upper bounds
  • [MNG-7316] - REGRESSION: MavenProject.getAttachedArtifacts() is read-only
  • [MNG-7352] - org.apache.maven.toolchain.java.JavaToolchainImpl should be public
  • [MNG-7529] - Maven resolver makes bad repository choices when resolving version ranges
  • [MNG-7563] - REGRESSION: User properties now override model properties in dependencies
  • [MNG-7568] - [WARNING] The requested profile "ABCDEF" could not be activated because it does not exist.
  • [MNG-7578] - Building Linux image on Windows impossible (patch incuded)
  • [MNG-7600] - LocalRepositoryManager is created too early
  • [MNG-7621] - Parameter '-f' causes ignoring any 'maven.config' (only on Windows)
  • [MNG-7637] - Possible NPE in MavenProject#hashCode()
  • [MNG-7644] - Fix version comparison where .X1 < -X2 for any string qualifier X

Improvement

  • [MNG-7590] - Allow configure resolver by properties in settings.xml
  • [MNG-7645] - Implement some #toString() methods

Task

  • [MNG-7513] - Address commons-io_commons-io vulnerability found in maven latest version
  • [MNG-7634] - Revert MNG-5982 and MNG-7417
  • [MNG-7636] - Partially revert MNG-5868 to restore backward compatibility (see MNG-7316)

Dependency upgrade

  • [MNG-7506] - Upgrade Maven Wagon to 3.5.2
  • [MNG-7641] - Upgrade Maven Wagon to 3.5.3
Commits
  • 9b58d2b [maven-release-plugin] prepare release maven-3.9.0
  • 87f4044 Update git-blame-ignore-revs
  • e9d5708 Reformat
  • 1a600c7 [MNG-7675] Update Parent to 39 and reformat
  • a5d0ca4 Fix site plugin warning (#973)
  • 48cac1c [MNG-7672] Fork should only execute the project and its submodules (#969)
  • 8fa5545 Get rid of surefire watning, take 2 (#967)
  • 36f02c9 Get rid of surefire warning (#965)
  • f7ca0b6 [MNG-7608] Make native transport the default (#961)
  • 51354e6 [maven-3.9.x] [MNG-7666] Update default binding and lifecycle plugin versions...
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
dmlloyd commented 1 year ago

It looks like Maven changed ("fixed"?) their version comparison scheme, so it worked previously with 3.8.x and now fails with 3.9.0. I'll figure out some way to reconcile it.

dmlloyd commented 1 year ago

Back to this nonsense again; Maven reports that the canonical representation of version 0.0-1 is 1, yet it's not actually equal to 1 😵

dmlloyd commented 1 year ago

Between 3.8.6 and 3.8.7 of maven-artifact, several compares have changed behavior (see MNG-7701 for more info):

In addition canonicalization is working incorrectly; see MNG-7700 for more info.

dmlloyd commented 1 year ago

@dependabot rebase

dependabot[bot] commented 1 year ago

Looks like this PR is already up-to-date with main! If you'd still like to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

dependabot[bot] commented 1 year ago

Looks like org.apache.maven:maven-artifact is up-to-date now, so this is no longer needed.