Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Oct 10, 2022

Bumps spotbugs-maven-plugin from 4.7.2.0 to 4.7.2.1.

Release notes

Sourced from spotbugs-maven-plugin's releases.

Spotbugs Maven Plugin 4.7.2.1

  • Bumps groovy to 4.0.5
  • Bumps asm to 9.4

Build Related

  • For reproducible builds, timestamp is now more accurate to the release.
Commits
  • 21e2e70 [maven-release-plugin] prepare release spotbugs-maven-plugin-4.7.2.1
  • 719192f Merge pull request #496 from spotbugs/renovate/asm.version
  • f57b664 Update dependency org.ow2.asm:asm-bom to v9.4
  • e2921d8 Merge pull request #495 from hazendaz/spotbugs
  • 6bf634d Merge pull request #494 from spotbugs/renovate/slf4jversion
  • f1b84ab Update slf4jVersion to v2.0.3
  • f9dc957 [pom] Bump junit to 5.9.1
  • 683ecb8 Merge pull request #493 from spotbugs/renovate/slf4jversion
  • 6cb063c Update dependency org.slf4j:slf4j-api to v2.0.2
  • 62c90ef Merge pull request #492 from spotbugs/renovate/groovy-monorepo
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [spotbugs-maven-plugin](https://github.com/spotbugs/spotbugs-maven-plugin) from 4.7.2.0 to 4.7.2.1.
- [Release notes](https://github.com/spotbugs/spotbugs-maven-plugin/releases)
- [Commits](spotbugs/spotbugs-maven-plugin@spotbugs-maven-plugin-4.7.2.0...spotbugs-maven-plugin-4.7.2.1)

---
updated-dependencies:
- dependency-name: com.github.spotbugs:spotbugs-maven-plugin
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Oct 10, 2022
@tiagobcx
Copy link
Contributor

Logo
Checkmarx AST – Scan Summary & Details9cab28c4-45ce-423c-9c33-68239c2498e5

New Issues

Severity Issue File / Package Scan Engine
HIGH CVE-2022-42003 Maven-com.fasterxml.jackson.core:jackson-databind-2.13.4 CxSCA

@cx-pedro-lopes cx-pedro-lopes merged commit fc20334 into main Oct 10, 2022
@dependabot dependabot bot deleted the dependabot/maven/com.github.spotbugs-spotbugs-maven-plugin-4.7.2.1 branch October 10, 2022 19:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants