stevespringett / nist-data-mirror

A simple Java command-line utility to mirror the CVE JSON data from NIST.
Apache License 2.0
206 stars 93 forks source link

Bump cyclonedx-maven-plugin from 2.0.3 to 2.1.1 #75

Closed dependabot[bot] closed 3 years ago

dependabot[bot] commented 3 years ago

Bumps cyclonedx-maven-plugin from 2.0.3 to 2.1.1.

Release notes

Sourced from cyclonedx-maven-plugin's releases.

2.1.1

Generates CycloneDX software bill of materials (SBOM) from Maven projects

2.1.0

Generates CycloneDX software bill of materials (SBOM) from Maven projects

Commits
  • 4171a7e [maven-release-plugin] prepare release cyclonedx-maven-plugin-2.1.1
  • bda96c2 updated core
  • f0ae864 bump
  • 4883dfd Merge pull request #70 from CycloneDX/dependabot/github_actions/actions/check...
  • 54d5390 Merge pull request #69 from CycloneDX/dependabot/maven/org.cyclonedx-cycloned...
  • d5583d2 Merge pull request #71 from CycloneDX/dependabot/maven/org.apache.maven.plugi...
  • 1841cf3 Bump maven-plugin-plugin from 3.5 to 3.6.0
  • 70a9d2a Bump actions/checkout from v1 to v2.3.4
  • 973872a Bump cyclonedx-core-java from 3.0.5 to 3.0.6
  • 0fec972 Create dependabot.yml
  • Additional commits viewable in compare view


Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)