Skip to content
This repository was archived by the owner on Dec 19, 2023. It is now read-only.

chore(deps): update all non-major dependencies #948

Merged
merged 1 commit into from
Jun 15, 2023

Conversation

renovate[bot]
Copy link

@renovate renovate bot commented May 18, 2023

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
@commitlint/cli (source) 17.6.3 -> 17.6.5 age adoption passing confidence
@commitlint/config-conventional (source) 17.6.3 -> 17.6.5 age adoption passing confidence
org.sonarqube 4.0.0.2929 -> 4.2.1.3168 age adoption passing confidence
org.springframework.boot 3.0.7 -> 3.1.0 age adoption passing confidence
com.graphql-java:graphql-java 20.2 -> 20.4 age adoption passing confidence

Release Notes

conventional-changelog/commitlint (@​commitlint/cli)

v17.6.5

Compare Source

Note: Version bump only for package @​commitlint/cli

conventional-changelog/commitlint (@​commitlint/config-conventional)

v17.6.5

Compare Source

Note: Version bump only for package @​commitlint/config-conventional

graphql-java/graphql-java

v20.4: 20.4

This is a special release with only one commit: updating the version of Guava to 32.0.0 to address CVE-2023-2976.

graphql-java shades in selected classes of Guava. Although this library does not use any of the code described in the CVE, we received reports in #​3239 that the Guava POM inside the jar was incorrectly triggering security scanners. We'd prefer to keep those security scanners happy and upgrade the Guava version.

What's Changed

Full Changelog: graphql-java/graphql-java@v20.3...v20.4

v20.3: 20.3

This is a special release with only one commit: reverting stricter parseValue scalar coercion. It is a backport of https://github.com/graphql-java/graphql-java/pull/3186

We received feedback that the stricter coercion was difficult without a migration pathway. The next release will include an input interceptor to enable monitoring and/or custom modification of inputs.

What's Changed

Full Changelog: graphql-java/graphql-java@v20.2...v20.3


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label May 18, 2023
@github-actions
Copy link

github-actions bot commented May 18, 2023

Test Results

  96 files    96 suites   1m 11s ⏱️
283 tests 283 ✔️ 0 💤 0
288 runs  288 ✔️ 0 💤 0

Results for commit 4647ec1.

♻️ This comment has been updated with latest results.

@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 5b9fc4f to 1d6c312 Compare May 26, 2023 16:19
@renovate renovate bot changed the title chore(deps): update plugin org.springframework.boot to v3.1.0 chore(deps): update all non-major dependencies May 26, 2023
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from ea64ade to b8fdb07 Compare May 31, 2023 17:09
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from b8fdb07 to eae1587 Compare June 8, 2023 06:02
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from eae1587 to 4647ec1 Compare June 12, 2023 11:40
@sonarqubecloud
Copy link

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
No Duplication information No Duplication information

@oliemansm oliemansm merged commit cb82525 into master Jun 15, 2023
@renovate renovate bot deleted the renovate/all-minor-patch branch June 15, 2023 16:15
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant