From a233e277f07708b3ff7469e7962d9b88c475d145 Mon Sep 17 00:00:00 2001 From: "octo-sts[bot]" <157150467+octo-sts@users.noreply.github.com> Date: Sat, 24 May 2025 07:18:56 +0000 Subject: [PATCH] gradle-8/8.14.1-r0: fix GHSA-vrpq-qp53-qv56 --- gradle-8.yaml | 4 +++- gradle-8/pombump-deps.yaml | 4 ++++ 2 files changed, 7 insertions(+), 1 deletion(-) create mode 100644 gradle-8/pombump-deps.yaml diff --git a/gradle-8.yaml b/gradle-8.yaml index c9d18a756f7..2c81b4fb8dc 100644 --- a/gradle-8.yaml +++ b/gradle-8.yaml @@ -3,7 +3,7 @@ package: version: "8.14.1" # For version upgrades check whether patches are still needed. # Upstream changes are being tracked in https://github.com/gradle/gradle/issues/25945 - epoch: 0 + epoch: 1 description: A Java project management and project comprehension tool. copyright: - license: Apache-2.0 @@ -38,6 +38,8 @@ pipeline: tag: v${{package.version}} expected-commit: c174b82566a79e3575bac8c7648c7b36cd815e94 + - uses: maven/pombump + - uses: patch with: patches: upgrade-deps.patch diff --git a/gradle-8/pombump-deps.yaml b/gradle-8/pombump-deps.yaml new file mode 100644 index 00000000000..7ffd4275f0f --- /dev/null +++ b/gradle-8/pombump-deps.yaml @@ -0,0 +1,4 @@ +patches: + - groupId: org.eclipse.jgit + artifactId: org.eclipse.jgit + version: 6.10.1.202505221210-r