Bump the plugins group with 6 updates #2364
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Bumps the plugins group with 6 updates:
3.4.0
3.4.1
3.8.1
3.9.0
3.6.1
3.6.2
0.8.13
0.8.14
3.27.0
3.28.0
12.1.6
12.1.8
Updates
org.apache.maven.plugins:maven-archetype-plugin
from 3.4.0 to 3.4.1Release notes
Sourced from org.apache.maven.plugins:maven-archetype-plugin's releases.
Commits
9097959
[maven-release-plugin] prepare release maven-archetype-3.4.138d00bf
Use RESOLVED_VERSION for tag-template in release-draftere344a94
Remove jira from README, update social media links4a40785
Remove not existing module archetype-testing from documentation7a4e240
Use Maven 3.9.11 in dependencies, still requires 3.6.3 as minimum741ed2e
Bump org.codehaus.plexus:plexus-archiver from 4.10.1 to 4.10.20fbc317
Restore http in archetype descriptors444324a
- Fixed resource files without extension missing in create-from-project9cab90f
Add hacktoberfest label to projectff25739
Bump m-invoker-p to 3.9.1 - to allow build by JDK 25Updates
org.apache.maven.plugins:maven-dependency-plugin
from 3.8.1 to 3.9.0Release notes
Sourced from org.apache.maven.plugins:maven-dependency-plugin's releases.
... (truncated)
Commits
826e5f0
[maven-release-plugin] prepare release maven-dependency-plugin-3.9.00db1acc
Use Resolver API in go-offline for dependencies resolving (#1533)e50031a
Use Resolver API in go-offline for plugins resolving6ed4b1a
Bump org.apache.commons:commons-lang3 from 3.18.0 to 3.19.08776c61
Bump org.assertj:assertj-core from 3.27.5 to 3.27.6d2af78e
Ignore Mockito 5.x and SLF4j 2.x by dependabotdcd4b7d
Bump org.assertj:assertj-core from 3.27.4 to 3.27.57523948
Strict check of dependencies usage23186d4
Fixes #1522, add render-dependencies mojo (#1523)bc1893f
Use Resolver API in resolve-pluginUpdates
org.apache.maven.plugins:maven-enforcer-plugin
from 3.6.1 to 3.6.2Release notes
Sourced from org.apache.maven.plugins:maven-enforcer-plugin's releases.
Commits
82ba770
[maven-release-plugin] prepare release enforcer-3.6.25313c70
Bump m-invoker-p to 3.9.1ee5abee
Bump org.apache.commons:commons-lang3 from 3.18.0 to 3.19.06c5a152
Bump org.assertj:assertj-core from 3.27.5 to 3.27.689ccb70
Bump org.assertj:assertj-core from 3.27.4 to 3.27.5 (#931)03ed82d
Update Version Ranges link in site.xml (#926)d282dc4
Fixes #920 - Remove usage of Stack27e1f46
Use SessionData for cache storage (#930)a1bac9b
Fix formatting typo in dependencyConvergence.apt.vm870a1ed
Correct support parameters documentation for banned repositories ruleUpdates
org.jacoco:jacoco-maven-plugin
from 0.8.13 to 0.8.14Release notes
Sourced from org.jacoco:jacoco-maven-plugin's releases.
Commits
2eb2483
Prepare release v0.8.14de76181
KotlinSerializableFilter should filter more methods (#1971)89c4bd5
Fix NPE in KotlinSerializableFilter (#1970)0981128
Migrate release staging to the Central Publisher Portal (#1968)d07bc6b
Add filter for bytecode generated by Kotlin serialization compiler plugin (#1...5e35fd5
Upgrade maven-dependency-plugin to 3.9.0 (#1966)c2fe5cc
Upgrade ASM to 9.9 (#1965)b0f8e23
KotlinSafeCallOperatorFilter should filter "unoptimized" safe call followed b...c7bd3f4
Upgrade spotless-maven-plugin to 3.0.0 (#1961)faa289d
KotlinSafeCallOperatorFilter should not be affected by presence of pseudo ins...Updates
org.apache.maven.plugins:maven-pmd-plugin
from 3.27.0 to 3.28.0Release notes
Sourced from org.apache.maven.plugins:maven-pmd-plugin's releases.
Commits
f152a3a
[maven-release-plugin] prepare release maven-pmd-plugin-3.28.00678fd1
Update historical PMD version in docs41d5069
Bump org.apache.commons:commons-lang3 from 3.8.1 to 3.18.0 in ITs (#648)3ef805b
Bump pmdVersion from 7.16.0 to 7.17.0592d703
Add hacktoberfest label to projectced9373
Bump org.apache.commons:commons-lang3 from 3.18.0 to 3.19.0 (#658)3cf5bc1
Bump org.codehaus.plexus:plexus-resources from 1.3.0 to 1.3.1 (#654)9077c3b
Bump org.codehaus.plexus:plexus-i18n from 1.0-beta-10 to 1.0.0 (#655)12ed57a
feat: enable prevent branch protection rules (#653)fff2b95
Bump pmdVersion from 7.15.0 to 7.16.0 (#652)Updates
org.owasp:dependency-check-maven
from 12.1.6 to 12.1.8Release notes
Sourced from org.owasp:dependency-check-maven's releases.
Changelog
Sourced from org.owasp:dependency-check-maven's changelog.
Commits
2d29a0b
build: prepare release v12.1.8a06ba2e
docs: release 12.1.88230ba2
fix: improve VulnerableSoftware comparison (#8031)c4696c0
docs: add note about central analyzer for gradle (#8038)a8e00c8
build: fix flaky central test (#8039)52eefb7
build(deps): bump org.apache.maven.plugins:maven-artifact-plugin from 3.6.0 t...fd8371c
build(deps): bump org.apache.maven.plugins:maven-compiler-plugin from 3.14.0 ...5ac1edb
build(deps): bump org.jacoco:jacoco-maven-plugin from 0.8.13 to 0.8.14 (#8032)8ceb175
docs: Improve Gradle docs wrt experimental analyzers, use of Central and Prox...986afb0
build: release 12.1.7 (#8030)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase
will rebase this PR@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it@dependabot merge
will merge this PR after your CI passes on it@dependabot squash and merge
will squash and merge this PR after your CI passes on it@dependabot cancel merge
will cancel a previously requested merge and block automerging@dependabot reopen
will reopen this PR if it is closed@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major version
will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor version
will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>
will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>
will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>
will remove the ignore condition of the specified dependency and ignore conditions