Context
Dependabot PR #22 still proposed Java-incompatible bumps after #19:
- spring-security-web 5.8.16 → 6.5.11 (Java 17)
- jackrabbit-jcr-commons → 2.22.2 (Java 11)
- shiro-web → 2.2.0 (Java 11)
Version-range ignores were not enough for grouped multi-directory security PRs.
Fix
Full-ignore those three product lines (manual review only for 5.8.x / 2.20.x security patches). Expand group exclude-patterns. Close #22.
Context
Dependabot PR #22 still proposed Java-incompatible bumps after #19:
Version-range ignores were not enough for grouped multi-directory security PRs.
Fix
Full-ignore those three product lines (manual review only for 5.8.x / 2.20.x security patches). Expand group exclude-patterns. Close #22.