forked from IBM/cics-bundle-common
-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update Mend: high confidence minor and patch dependency updates #27
Open
mend-for-github.aaakk.us.kg
wants to merge
1
commit into
main
Choose a base branch
from
whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates
base: main
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
mend-for-github.aaakk.us.kg
bot
added
the
security fix
Security fix generated by Mend
label
Jan 26, 2024
mend-for-github.aaakk.us.kg
bot
force-pushed
the
whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates
branch
2 times, most recently
from
January 29, 2024 07:03
546ac57
to
4a22d36
Compare
mend-for-github.aaakk.us.kg
bot
force-pushed
the
whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates
branch
4 times, most recently
from
February 9, 2024 06:20
cfc5e56
to
d3ef00a
Compare
mend-for-github.aaakk.us.kg
bot
force-pushed
the
whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates
branch
6 times, most recently
from
February 20, 2024 06:27
0101c45
to
90c305c
Compare
mend-for-github.aaakk.us.kg
bot
force-pushed
the
whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates
branch
4 times, most recently
from
February 25, 2024 06:10
ffa91d4
to
22cc09c
Compare
mend-for-github.aaakk.us.kg
bot
force-pushed
the
whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates
branch
2 times, most recently
from
March 13, 2024 05:56
e274bc8
to
20a73f3
Compare
mend-for-github.aaakk.us.kg
bot
force-pushed
the
whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates
branch
6 times, most recently
from
March 24, 2024 05:46
f4a652e
to
d4acfa5
Compare
mend-for-github.aaakk.us.kg
bot
force-pushed
the
whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates
branch
5 times, most recently
from
March 31, 2024 05:48
dfb0fb6
to
abb4bd6
Compare
mend-for-github.aaakk.us.kg
bot
force-pushed
the
whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates
branch
4 times, most recently
from
October 12, 2024 06:17
29e53a6
to
485bdeb
Compare
mend-for-github.aaakk.us.kg
bot
force-pushed
the
whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates
branch
4 times, most recently
from
October 22, 2024 06:20
522f508
to
108964b
Compare
mend-for-github.aaakk.us.kg
bot
force-pushed
the
whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates
branch
4 times, most recently
from
October 29, 2024 10:25
961d4cb
to
2e578a4
Compare
mend-for-github.aaakk.us.kg
bot
force-pushed
the
whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates
branch
3 times, most recently
from
November 5, 2024 10:05
856d826
to
fd66c8e
Compare
mend-for-github.aaakk.us.kg
bot
force-pushed
the
whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates
branch
6 times, most recently
from
November 19, 2024 16:02
3cacb8c
to
9f14e21
Compare
mend-for-github.aaakk.us.kg
bot
force-pushed
the
whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates
branch
4 times, most recently
from
December 4, 2024 18:27
21a1acc
to
e444cba
Compare
mend-for-github.aaakk.us.kg
bot
force-pushed
the
whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates
branch
3 times, most recently
from
December 14, 2024 08:15
cabe1d8
to
eca7814
Compare
mend-for-github.aaakk.us.kg
bot
force-pushed
the
whitesource-remediate/mend-high-confidence-minor-and-patch-dependency-updates
branch
from
December 15, 2024 09:54
eca7814
to
eec21e5
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
2.9.0
->2.10.0
2.9.0
->2.10.0
2.32.0
->2.35.2
2.11.0
->2.12.0
1.18.22
->1.18.36
3.10.0
->3.21.0
3.2.0
->3.3.1
3.2.2
->3.4.2
3.0.0-M1
->3.1.3
3.0.0-M1
->3.1.3
3.1.0
->3.4.0
1.6.8
->1.7.0
3.3.1
->3.11.2
3.2.1
->3.3.1
3.0.1
->3.2.7
4.5.3.0
->4.8.6.6
3.9.0
->3.13.0
3.0.0
->3.5.0
1.7.35
->1.7.36
1.7.35
->1.7.36
2.0.0
->2.5.0
By merging this PR, the issue #31 will be automatically resolved and closed:
Release Notes
xmlunit/xmlunit (org.xmlunit:xmlunit-matchers)
v2.10.0
Compare Source
add a new
ElementSelectors.byNameAndAllAttributes
variant that filters attributes before deciding whether elements canbe compared.
Inspired by Issue #259
By default the
TransformerFactory
s created will now try to disable extension functions. If you need extensionfunctions for your transformations you may want to pass in your own instance of
TransformerFactory
andTransformerFactoryConfigurer
may help with that.Inspired by Issue #264
This is tracked as CVE-2024-31573.
JAXPXPathEngine
will now try to disable the execution of extension functions by default but usesXPathFactory#setProperty
which is not available prior to Java 18. You may want to enable secure processing on anXPathFactory
instance you pass toJAXPXPathEngine
instead - andXPathFactoryConfigurer
may help with that.v2.9.1
Compare Source
fixed some AssertJ tests that didn't work on Windows.
Issue #252 and PR
#253 by
@Boiarshinov
added overloads to
ElementSelectors.byXPath
that accept aXPathEngine
argument.
Issue #255
added Cyclone DX SBOMs to release artifacts
wiremock/wiremock (com.github.tomakehurst:wiremock-jre8)
v2.35.2
Compare Source
v2.35.1
: - Security ReleaseCompare Source
🔒 This is a security release that addresses the following issues
Rebinding in WireMock and WireMock Studio webhooks, proxy and recorder modes
NOTE: WireMock Studio, a proprietary distribution discontinued in 2022, is also affected by those issues and also affected by CVE-2023-39967 - Overall CVSS Score 8.6 - “Controlled and full-read SSRF through URL parameter when testing a request, webhooks and proxy mode”. The fixes will not be provided. The vendor recommends migrating to WireMock Cloud which is available as SaaS and private beta for on-premises deployments
Credits: @W0rty, @numacanedo, @Mahoney, @tomakehurst, @oleg-nenashev
v2.35.0
Compare Source
Enhancements
Fixes
v2.34.0
Compare Source
This will be the final 2.x.x release and also the last to support Java 8.
Fixes
Enhancements
All dependencies brought up to date including Jetty to 9.4.48.v20220622.
v2.33.2
Compare Source
WireMock 2.33.1 was accidentally released using Java 11 rather than 8, resulting in class incompatibilities in places.
This release is functionally identical but built using Java 8.
v2.33.1
Compare Source
Fixes
v2.33.0
Compare Source
This is primarily a maintenance release that brings all dependency versions up to date including a version of Jackson containing the fix for CVE-2020-36518.
Enhancements
Performance
projectlombok/lombok (org.projectlombok:lombok)
v1.18.36
Compare Source
v1.18.34
Compare Source
v1.18.32
Compare Source
v1.18.30
Compare Source
v1.18.28
Compare Source
v1.18.26
Compare Source
v1.18.24
Compare Source
sonatype/nexus-maven-plugins (org.sonatype.plugins:nexus-staging-maven-plugin)
v1.7.0
Compare Source
v1.6.14
Compare Source
v1.6.13
Compare Source
v1.6.12
Compare Source
v1.6.11
Compare Source
v1.6.10
Compare Source
mojohaus/license-maven-plugin (org.codehaus.mojo:license-maven-plugin)
v2.5.0
Compare Source
❗ NOTICE
Due to
Doxia 2.x
stackmaven-site-plugin
3.20+ is required.https://cwiki.apache.org/confluence/display/MAVEN/Towards+Doxia+2.0.0+Stack
🚀 New features and improvements
🐛 Bug Fixes
📦 Dependency updates
👻 Maintenance
🔧 Build
v2.4.0
Compare Source
🚀 New features and improvements
🐛 Bug Fixes
📦 Dependency updates
👻 Maintenance
🔧 Build
v2.3.0
Compare Source
🚀 New features and improvements
🐛 Bug Fixes
📦 Dependency updates
👻 Maintenance
v2.2.0
Compare Source
🚀 New features and improvements
🐛 Bug Fixes
📦 Dependency updates
2007082
to2023022
in /src/it/add-third-party-missing-file (#460) @dependabot👻 Maintenance
v2.1.0
Compare Source
🚀 New features and improvements
🐛 Bug Fixes
📦 Dependency updates
👻 Maintenance
🔧 Build
v2.0.1
What's Changed
Configuration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.