Skip to content

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Oct 9, 2025

Bumps org.codehaus.plexus:plexus-archiver from 4.10.1 to 4.10.3.

Release notes

Sourced from org.codehaus.plexus:plexus-archiver's releases.

4.10.3

👻 Maintenance

📦 Dependency updates

4.10.2

🐛 Bug Fixes

  • check minimum timestamp: avoid negative Zip 5455 Extended Timestamp (#388) @​hboutemy

📦 Dependency updates

Commits
  • d706569 [maven-release-plugin] prepare release plexus-archiver-4.10.3
  • b73b1ae Add comparison to Commons Compress in README
  • 05bfae8 Convert apt to markdown with doxia-converter
  • c9d01eb Update plexus-io to 3.5.2 and downgrade plexus-utils to 3.6.0
  • 6a62131 Fix handling of zip entries with unspecified modification time (-1)
  • a99931b Fix AbstractArchiver.getFiles() to return forward slashes for ZIP-based archi...
  • 59f8800 Reduce heap usage in Zip archiver to prevent OutOfMemoryError in CI builds (#...
  • c099a55 Bump com.github.luben:zstd-jni from 1.5.7-4 to 1.5.7-5
  • 89bcc54 [maven-release-plugin] prepare for next development iteration
  • e99ec39 [maven-release-plugin] prepare release plexus-archiver-4.10.2
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Oct 9, 2025
Bumps [org.codehaus.plexus:plexus-archiver](https://github.com/codehaus-plexus/plexus-archiver) from 4.10.1 to 4.10.3.
- [Release notes](https://github.com/codehaus-plexus/plexus-archiver/releases)
- [Changelog](https://github.com/codehaus-plexus/plexus-archiver/blob/master/ReleaseNotes.md)
- [Commits](codehaus-plexus/plexus-archiver@plexus-archiver-4.10.1...plexus-archiver-4.10.3)

---
updated-dependencies:
- dependency-name: org.codehaus.plexus:plexus-archiver
  dependency-version: 4.10.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/maven/org.codehaus.plexus-plexus-archiver-4.10.3 branch from f5ab5c4 to 21a96fd Compare October 10, 2025 05:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file java Pull requests that update Java code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

0 participants