Skip to content

Bump spotbugs-maven-plugin from 3.1.9 to 4.3.0#31

Closed
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/maven/com.github.spotbugs-spotbugs-maven-plugin-4.3.0
Closed

Bump spotbugs-maven-plugin from 3.1.9 to 4.3.0#31
dependabot[bot] wants to merge 1 commit intomasterfrom
dependabot/maven/com.github.spotbugs-spotbugs-maven-plugin-4.3.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Jul 15, 2021

Bumps spotbugs-maven-plugin from 3.1.9 to 4.3.0.

Release notes

Sourced from spotbugs-maven-plugin's releases.

Spotbugs Maven Plugin 4.2.0

  • Revert and adjust changes from 4.1.3 regarding resource resolution. A regression was caused in attempt to get rid of underlying deeply nested path for add-on plugins such as sb-contrib (fb-contrib). Prior logic restored and support for windows based path added. The underlying jars still get copied to target after this but no longer deeply nested. A separate ticket is open to look at figuring out how to remove those from creation.
  • Replace deprecated groovy toInteger with as Integer
  • Support spotbugs 4.2.0

Build changes

  • Replaced travis-ci with github actions.
  • Supporting build on windows / macos now in addition to ubuntu.

Spotbugs Maven Plugin 4.1.4

  • Support spotbugs 4.1.4

Spotbugs-maven-plugin 4.1.3

  • Aligment with spotbugs 4.1.3
  • Jdk 15/16 support
  • Fixes copy of repo being put until target (ie C_...) per #238
  • Reduces logging output below threshold per #237

Spotbugs-maven-plugin 4.0.4

  • Introduce failThreshold
  • Alignment with spotbugs 4.0.4
  • Remove old left over maven 2.2.1 classloader logic
  • library cleanup with groovy
  • Various library updates

Spotbugs-maven-plugin 4.0.0

  • [support] Aligns support to spotbugs 4.0.0
  • [support] Requires baseline maven 3.2.5 for building
  • [support] Supports jdk 8 through 15
  • [fix] Xml declaration with the effective encoding added when missing with windows handling
  • [fix] Tuned logging to prevent showing illegal reflective access from groovy. Will show under debug logging.

3.1.12.2 Release

  • Configurable output filename added
  • Added support for jdk 12 through 14

Groovy Patch Release against 3.1.12 spotbugs

This release is against spotbugs 3.1.12 and includes a patch to groovy 3.0.0 beta 2. This ensures that java warnings on newer jdks are no longer presented to the user of spotbugs maven plugin.

This release additionally contains updated third party software and fixes to ensure our site pages are properly released.

Note: While support for spotbugs with source paths has been included here, that feature aligns with spotbugs 4.0.0. In order to utilize the feature, you will need to override spotbugs with the most recent spotbugs beta release '4.0.0-beta3'. See here for details on support.

Commits
  • 5530040 [maven-release-plugin] prepare release spotbugs-maven-plugin-4.3.0
  • a32d2b3 [pom] Bump junit to 5.7.2
  • 8a31260 Merge pull request #336 from hazendaz/spotbugs
  • c9733e9 [pom] Bump spotbugs to 4.3.0
  • 92876e8 [pom] Remove old maven comment as we are now going to latest 3.8.1
  • 8ebfd75 [ci] Update since date as we switched to 4.3.x
  • e8e34a4 Merge pull request #334 from spotbugs/dependabot/maven/slf4jVersion-2.0.0-alpha2
  • 6891b9d Merge pull request #311 from spotbugs/dependabot/maven/mavenVersion-3.8.1
  • 1d7f14c Merge pull request #312 from spotbugs/dependabot/maven/org.apache.maven-maven...
  • 7ba7755 Merge pull request #335 from spotbugs/dependabot/maven/com.github.spotbugs-sp...
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [spotbugs-maven-plugin](https://github.com/spotbugs/spotbugs-maven-plugin) from 3.1.9 to 4.3.0.
- [Release notes](https://github.com/spotbugs/spotbugs-maven-plugin/releases)
- [Commits](spotbugs/spotbugs-maven-plugin@spotbugs-maven-plugin-3.1.9...spotbugs-maven-plugin-4.3.0)

---
updated-dependencies:
- dependency-name: com.github.spotbugs:spotbugs-maven-plugin
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Jul 15, 2021
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Sep 20, 2021

Superseded by #37.

@dependabot dependabot Bot closed this Sep 20, 2021
@dependabot dependabot Bot deleted the dependabot/maven/com.github.spotbugs-spotbugs-maven-plugin-4.3.0 branch September 20, 2021 01:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants