Problem
Dependabot opened multi-package PRs (#16, #17) that bump dependencies past our Java 8 caps, including:
- Spring Framework 5.3.x → 6.2.x
- Spring Security 5.8.x → 6.0.0
- Hibernate 5.6.x → 6.0.0
- CXF 3.5.x → 4.1.x
- ActiveMQ 5.16.x → 5.19.x
- Tika 2.9.x → 3.2.x
- Derby 10.14.x → 10.17.x
These should have been blocked by .github/dependabot.yml ignore rules.
Likely causes
- Config used only
directory: "/", so nested manifests (/system, /projects/sitemanage, …) did not inherit ignores.
- Invalid version constraint
>=*jre11* on mssql-jdbc (not a valid Dependabot/Maven requirement) may interfere with ignore loading.
- Grouped multi-directory PRs (“the maven group”) bundled ignored majors with safe patches; no group exclude-patterns existed.
- Hibernate 6 was never on the ignore list.
Fix
Rewrite dependabot.yml to use multi-directory globs, valid version ranges, Java 8 groups with exclude-patterns, and missing caps.
Problem
Dependabot opened multi-package PRs (#16, #17) that bump dependencies past our Java 8 caps, including:
These should have been blocked by
.github/dependabot.ymlignore rules.Likely causes
directory: "/", so nested manifests (/system,/projects/sitemanage, …) did not inherit ignores.>=*jre11*onmssql-jdbc(not a valid Dependabot/Maven requirement) may interfere with ignore loading.Fix
Rewrite dependabot.yml to use multi-directory globs, valid version ranges, Java 8 groups with exclude-patterns, and missing caps.