Skip to content

Conversation

@bact
Copy link
Collaborator

@bact bact commented Sep 16, 2025

  • Update to latest version of minor version
  • Update spdx-maven-plugin to 1.0.3

Note that a new release of spdx-java-core is required in order to have a spdx-java-core that depends on commons-lang3 version without known security issue.
The new release spdx-java-core will then be used by the new releases of spdx-java-model-2_X, spdx-java-model-3_X, and later spdx-java-library.
See: spdx/Spdx-Java-Library#345 (comment)

- Update to latest version of minor version
- Update spdx-maven-plugin to 1.0.3

Signed-off-by: Arthit Suriyawongkul <arthit@gmail.com>
@bact bact added the dependencies Pull requests that update a dependency file label Sep 16, 2025
Copy link
Member

@goneall goneall left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@goneall goneall merged commit ef47b16 into spdx:main Sep 17, 2025
3 checks passed
@bact bact deleted the update-deps branch September 17, 2025 20:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants