Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump maven-bundle-plugin from 5.1.1 to 5.1.4 #747

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Feb 4, 2022

Bumps maven-bundle-plugin from 5.1.1 to 5.1.4.

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

colinduplantis and others added 30 commits March 24, 2021 12:31
#231 - Move FIX session stuff from web-admin to web-fix
#223 - Add permissions for trader to view session status
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Feb 4, 2022
colinduplantis and others added 22 commits February 15, 2022 09:52
Bumps [maven-compiler-plugin](https://github.com/apache/maven-compiler-plugin) from 3.8.1 to 3.10.0.
- [Release notes](https://github.com/apache/maven-compiler-plugin/releases)
- [Commits](apache/maven-compiler-plugin@maven-compiler-plugin-3.8.1...maven-compiler-plugin-3.10.0)

---
updated-dependencies:
- dependency-name: org.apache.maven.plugins:maven-compiler-plugin
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps `mvn.flyway.version` from 8.4.0 to 8.5.0.

Updates `flyway-core` from 8.4.0 to 8.5.0
- [Release notes](https://github.com/flyway/flyway/releases)
- [Commits](flyway/flyway@flyway-8.4.0...flyway-8.5.0)

Updates `flyway-maven-plugin` from 8.4.0 to 8.5.0
- [Release notes](https://github.com/flyway/flyway/releases)
- [Commits](flyway/flyway@flyway-8.4.0...flyway-8.5.0)

---
updated-dependencies:
- dependency-name: org.flywaydb:flyway-core
  dependency-type: direct:production
  update-type: version-update:semver-minor
- dependency-name: org.flywaydb:flyway-maven-plugin
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [maven-javadoc-plugin](https://github.com/apache/maven-javadoc-plugin) from 3.3.1 to 3.3.2.
- [Release notes](https://github.com/apache/maven-javadoc-plugin/releases)
- [Commits](apache/maven-javadoc-plugin@maven-javadoc-plugin-3.3.1...maven-javadoc-plugin-3.3.2)

---
updated-dependencies:
- dependency-name: org.apache.maven.plugins:maven-javadoc-plugin
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps `vaadin.version` from 21.0.0 to 22.0.5.

Updates `vaadin-bom` from 21.0.0 to 22.0.5

Updates `vaadin-maven-plugin` from 21.0.0 to 22.0.5

---
updated-dependencies:
- dependency-name: com.vaadin:vaadin-bom
  dependency-type: direct:production
  update-type: version-update:semver-major
- dependency-name: com.vaadin:vaadin-maven-plugin
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [protobuf-java](https://github.com/protocolbuffers/protobuf) from 3.19.0 to 3.19.2.
- [Release notes](https://github.com/protocolbuffers/protobuf/releases)
- [Changelog](https://github.com/protocolbuffers/protobuf/blob/master/generate_changelog.py)
- [Commits](protocolbuffers/protobuf@v3.19.0...v3.19.2)

---
updated-dependencies:
- dependency-name: com.google.protobuf:protobuf-java
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [maven-project-info-reports-plugin](https://github.com/apache/maven-project-info-reports-plugin) from 3.1.1 to 3.2.1.
- [Release notes](https://github.com/apache/maven-project-info-reports-plugin/releases)
- [Commits](apache/maven-project-info-reports-plugin@maven-project-info-reports-plugin-3.1.1...maven-project-info-reports-plugin-3.2.1)

---
updated-dependencies:
- dependency-name: org.apache.maven.plugins:maven-project-info-reports-plugin
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps wagon-ssh from 3.4.2 to 3.5.1.

---
updated-dependencies:
- dependency-name: org.apache.maven.wagon:wagon-ssh
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
….maven.wagon-wagon-ssh-3.5.1

Bump wagon-ssh from 3.4.2 to 3.5.1
….1.x/org.apache.maven.plugins-maven-compiler-plugin-3.10.0

Bump maven-compiler-plugin from 3.8.1 to 3.10.0
….1.x/mvn.flyway.version-8.5.0

Bump mvn.flyway.version from 8.4.0 to 8.5.0
….1.x/org.apache.maven.plugins-maven-javadoc-plugin-3.3.2

Bump maven-javadoc-plugin from 3.3.1 to 3.3.2
….1.x/vaadin.version-22.0.5

Bump vaadin.version from 21.0.0 to 22.0.5
….1.x/com.google.protobuf-protobuf-java-3.19.2

Bump protobuf-java from 3.19.0 to 3.19.2
….maven.plugins-maven-project-info-reports-plugin-3.2.1

Bump maven-project-info-reports-plugin from 3.1.1 to 3.2.1
@colinduplantis
Copy link
Member

@dependabot rebase

Bumps maven-bundle-plugin from 5.1.1 to 5.1.4.

---
updated-dependencies:
- dependency-name: org.apache.felix:maven-bundle-plugin
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot changed the base branch from master to branches/4.1.x February 16, 2022 13:02
@dependabot dependabot bot force-pushed the dependabot/maven/org.apache.felix-maven-bundle-plugin-5.1.4 branch from d5010e4 to b440edf Compare February 16, 2022 13:02
@gitguardian
Copy link

gitguardian bot commented Feb 16, 2022

⚠️ GitGuardian has uncovered 1 secret following the scan of your pull request.

Please consider investigating the findings and remediating the incidents. Failure to do so may lead to compromising the associated services or software components.

🔎 Details of the secret
Secret Commit Filename Detected At
Generic Database Assignment be8d339 packages/docker-package/src/main/sample_data/dare/conf/application.properties 21:55 April 2nd, 2021 View secret
🛠 Guidelines to remediate hardcoded secrets
  1. Understand the implications of revoking this secret by investigating where it is used in your code.
  2. Replace and store your secret safely. Learn here the best practices.
  3. Revoke and rotate this secret.
  4. If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.

To avoid such incidents in the future consider

GitGuardian is an automated secrets detection service.We help developers and security teams secure the modern software development process.

 

Our GitHub checks need improvements? Share your feedbacks

@colinduplantis colinduplantis merged commit f9f741c into branches/4.1.x Feb 16, 2022
@colinduplantis colinduplantis deleted the dependabot/maven/org.apache.felix-maven-bundle-plugin-5.1.4 branch February 16, 2022 13:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant