Skip to content

Bump spotbugs-maven-plugin from 3.1.9 to 4.4.1#37

Merged
stevespringett merged 1 commit intomasterfrom
dependabot/maven/com.github.spotbugs-spotbugs-maven-plugin-4.4.1
Sep 29, 2021
Merged

Bump spotbugs-maven-plugin from 3.1.9 to 4.4.1#37
stevespringett merged 1 commit intomasterfrom
dependabot/maven/com.github.spotbugs-spotbugs-maven-plugin-4.4.1

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Sep 20, 2021

Bumps spotbugs-maven-plugin from 3.1.9 to 4.4.1.

Release notes

Sourced from spotbugs-maven-plugin's releases.

Spotbugs Maven Plugin 4.2.0

  • Revert and adjust changes from 4.1.3 regarding resource resolution. A regression was caused in attempt to get rid of underlying deeply nested path for add-on plugins such as sb-contrib (fb-contrib). Prior logic restored and support for windows based path added. The underlying jars still get copied to target after this but no longer deeply nested. A separate ticket is open to look at figuring out how to remove those from creation.
  • Replace deprecated groovy toInteger with as Integer
  • Support spotbugs 4.2.0

Build changes

  • Replaced travis-ci with github actions.
  • Supporting build on windows / macos now in addition to ubuntu.

Spotbugs Maven Plugin 4.1.4

  • Support spotbugs 4.1.4

Spotbugs-maven-plugin 4.1.3

  • Aligment with spotbugs 4.1.3
  • Jdk 15/16 support
  • Fixes copy of repo being put until target (ie C_...) per #238
  • Reduces logging output below threshold per #237

Spotbugs-maven-plugin 4.0.4

  • Introduce failThreshold
  • Alignment with spotbugs 4.0.4
  • Remove old left over maven 2.2.1 classloader logic
  • library cleanup with groovy
  • Various library updates

Spotbugs-maven-plugin 4.0.0

  • [support] Aligns support to spotbugs 4.0.0
  • [support] Requires baseline maven 3.2.5 for building
  • [support] Supports jdk 8 through 15
  • [fix] Xml declaration with the effective encoding added when missing with windows handling
  • [fix] Tuned logging to prevent showing illegal reflective access from groovy. Will show under debug logging.

3.1.12.2 Release

  • Configurable output filename added
  • Added support for jdk 12 through 14

Groovy Patch Release against 3.1.12 spotbugs

This release is against spotbugs 3.1.12 and includes a patch to groovy 3.0.0 beta 2. This ensures that java warnings on newer jdks are no longer presented to the user of spotbugs maven plugin.

This release additionally contains updated third party software and fixes to ensure our site pages are properly released.

Note: While support for spotbugs with source paths has been included here, that feature aligns with spotbugs 4.0.0. In order to utilize the feature, you will need to override spotbugs with the most recent spotbugs beta release '4.0.0-beta3'. See here for details on support.

Commits
  • 741f662 [maven-release-plugin] prepare release spotbugs-maven-plugin-4.4.1
  • 4dacc01 [pom] Bump junit to 5.8.0
  • c8c8a68 [maven] Bump maven wrapper to 3.8.2
  • 0b029a8 Merge pull request #357 from spotbugs/dependabot/maven/scmPluginVersion-1.12.0
  • 34c1c99 Bump scmPluginVersion from 1.11.3 to 1.12.0
  • 1a259f2 Merge pull request #356 from spotbugs/dependabot/maven/jgit.version-5.13.0.20...
  • 915e5a0 Bump jgit.version from 5.12.0.202106070339-r to 5.13.0.202109080827-r
  • 675b7a3 Merge pull request #355 from hazendaz/spotbugs
  • 39d9fc6 Create codeql-analysis.yml
  • febf924 [pom] Bump spotbugs to 4.4.1
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [spotbugs-maven-plugin](https://github.com/spotbugs/spotbugs-maven-plugin) from 3.1.9 to 4.4.1.
- [Release notes](https://github.com/spotbugs/spotbugs-maven-plugin/releases)
- [Commits](spotbugs/spotbugs-maven-plugin@spotbugs-maven-plugin-3.1.9...spotbugs-maven-plugin-4.4.1)

---
updated-dependencies:
- dependency-name: com.github.spotbugs:spotbugs-maven-plugin
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Sep 20, 2021
@stevespringett stevespringett merged commit ef69e79 into master Sep 29, 2021
@dependabot dependabot Bot deleted the dependabot/maven/com.github.spotbugs-spotbugs-maven-plugin-4.4.1 branch September 29, 2021 01:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant