Skip to content
This repository has been archived by the owner on Mar 31, 2022. It is now read-only.

chore(deps): Bump dependency-check-maven from 6.4.1 to 6.5.0 #738

Merged

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Nov 9, 2021

Bumps dependency-check-maven from 6.4.1 to 6.5.0.

Release notes

Sourced from dependency-check-maven's releases.

Version 6.5.0

Changes in this Release

  • Updated build configuration to create reproducible builds.
  • Updated automated release process to work with branch protection.
  • Resolved several false positives in the Java ecosystem.
  • Enabled the Swift Resolved analyzer per #3735
  • Improved iOS support per #3168 and #3765
  • Added the a new pnpm Analyzer
  • Fixed issue with some npm and yarn analysis failing due to large audit output
  • See the full listing of changes.
Changelog

Sourced from dependency-check-maven's changelog.

Version 6.5.0 (2021-11-08)

Changes

  • Updated build configuration to create reproducible builds.
  • Updated automated release process to work with branch protection.
  • Resolved several false positives in the Java ecosystem.
  • Enabled the Swift Resolved analyzer per #3735
  • Improved iOS support per #3168 and #3765
  • Added the a new pnpm Analyzer
  • Fixed issue with some npm and yarn analysis failing due to large audit output
  • See the full listing of changes.
Commits
  • 47737f0 [maven-release-plugin] prepare release v6.5.0
  • 0e10d48 6.5.0 release notes
  • d60ab27 Merge pull request #3781 from jeremylong/updateReleaseWorkflow
  • d280734 updated based on codacy recommendation
  • 0c35bb4 update release workflow for protected branches
  • 81990ea Merge pull request #3780 from jeremylong/reproducible
  • 24f58e9 updates for Reproducible Builds
  • 547e7a1 fp per #3778
  • 0f941ae make checkstyle and spotbugs happier
  • 167b20c Merge branch 'main' of github.com:jeremylong/DependencyCheck into main
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [dependency-check-maven](https://github.com/jeremylong/DependencyCheck) from 6.4.1 to 6.5.0.
- [Release notes](https://github.com/jeremylong/DependencyCheck/releases)
- [Changelog](https://github.com/jeremylong/DependencyCheck/blob/main/RELEASE_NOTES.md)
- [Commits](jeremylong/DependencyCheck@v6.4.1...v6.5.0)

---
updated-dependencies:
- dependency-name: org.owasp:dependency-check-maven
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added java Pull requests that update Java code dependencies Pull requests that update a dependency file labels Nov 9, 2021
@juliapampus juliapampus enabled auto-merge (squash) November 9, 2021 07:47
@juliapampus juliapampus merged commit 82e7e17 into main Nov 9, 2021
@juliapampus juliapampus deleted the dependabot/maven/main/org.owasp-dependency-check-maven-6.5.0 branch November 9, 2021 08:22
juliapampus added a commit that referenced this pull request Nov 15, 2021
* chore(deps): Bump dependency-check-maven from 6.4.1 to 6.5.0

Bumps [dependency-check-maven](https://github.com/jeremylong/DependencyCheck) from 6.4.1 to 6.5.0.
- [Release notes](https://github.com/jeremylong/DependencyCheck/releases)
- [Changelog](https://github.com/jeremylong/DependencyCheck/blob/main/RELEASE_NOTES.md)
- [Commits](jeremylong/DependencyCheck@v6.4.1...v6.5.0)

---
updated-dependencies:
- dependency-name: org.owasp:dependency-check-maven
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>

* docs: update CHANGELOG.md

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Julia Pampus <[email protected]>
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
dependencies Pull requests that update a dependency file java Pull requests that update Java code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant