Bump dependency-check-maven from 7.3.2 to 7.4.0
Bumps dependency-check-maven from 7.3.2 to 7.4.0.
Release notes
Sourced from dependency-check-maven's releases.
Version 7.4.0
Added
- Add support for npm package lock v2 and v3 (#5078)
- Added experimental support for Python Poetry (#5025)
- Added a vanilla HTML report for use in Jenkins (#5053)
Changed
- Renamed
RELEASE_NOTES.md
toCHANGELOG.md
to be more conventional- Optimized checksum calculation to improve performance (#5112)
- Added support for scanning .NET assemblies when only the dotnet runtime is installed (#5087)
- Bumped several dependencies
Fixed
- Fixed bug when setting the proxy port (#5076)
- Resolved several FP and FN
See the full listing of changes.
Changelog
Sourced from dependency-check-maven's changelog.
Version 7.4.0 (2022-12-04)
Added
- Add support for npm package lock v2 and v3 (#5078)
- Added experimental support for Python Poetry (#5025)
- Added a vanilla HTML report for use in Jenkins (#5053)
Changed
- Renamed
RELEASE_NOTES.md
toCHANGELOG.md
to be more conventional- Optimized checksum calculation to improve performance (#5112)
- Added support for scanning .NET assemblies when only the dotnet runtime is installed (#5087)
- Bumped several dependencies
Fixed
- Fixed bug when setting the proxy port (#5076)
- Resolved several FP and FN
See the full listing of changes.
Commits
-
49e0afc
build:prepare release v7.4.0 -
a4ce937
build: bump patch version -
b9d1862
fix(doc): update release notes -
afb09b3
fix: Optimize file checksums calculation (#5112) -
823f739
Merge pull request #5113 from jeremylong/badge -
a43572c
fix: update build badge -
bad66cd
build(deps): bump maven-dependency-plugin from 3.3.0 to 3.4.0 (#5110) -
45887cd
fix(FP): Suppress improper CPE assignment for liferay subcomponents that are ... -
2b96890
build(deps): bump postgresql from 42.5.0 to 42.5.1 (#5088) -
bb8dae6
fix: Change dotnet invocation for 'detection on system path' to --info to sup... - Additional commits viewable in compare view
Dependabot commands
You can trigger Dependabot actions by commenting on this MR
-
$dependabot rebase
will rebase this MR -
$dependabot recreate
will recreate this MR rewriting all the manual changes and resolving conflicts