Skip to content

Bump dependency-check-maven from 8.1.2 to 8.2.0

Bumps dependency-check-maven from 8.1.2 to 8.2.0.

Release notes

Sourced from dependency-check-maven's releases.

Version 8.2.0

Added

  • Support msbuild Directory.build.props (#5475)
  • better display of NPM audit references
  • Add CVSS V3 results from NPM Audit results

Fixed

  • Fix several issues on NPM Audit reporting (#5546)
  • Case issue in SQL (#5557)
  • Fix CWE(s) extraction for NPM Audit advisories
  • Use the stable github_advisory_id instead of the now unstable id in NPM audit results

See the full listing of changes.

Changelog

Sourced from dependency-check-maven's changelog.

Version 8.2.0 (2023-03-22)

Added

  • Support msbuild Directory.build.props (#5475)
  • better display of NPM audit references
  • Add CVSS V3 results from NPM Audit results

Fixed

  • Fix several issues on NPM Audit reporting (#5546)
  • Case issue in SQL (#5557)
  • Fix CWE(s) extraction for NPM Audit advisories
  • Use the stable github_advisory_id instead of the now unstable id in NPM audit results

See the full listing of changes.

Commits
  • 1f914b4 build: prepare release v8.2.0
  • 3f1c4fe chore: prepare release
  • f7548f3 build(deps): bump maven-release-plugin from 2.5.3 to 3.0.0 (#5570)
  • 302bf7c build(deps): bump postgresql from 42.5.4 to 42.6.0 (#5568)
  • 866e16e build(deps): bump violations-lib from 1.156.2 to 1.156.3 (#5563)
  • 1cb2f20 fix: Fix several issues on NPM Audit reporting (#5546)
  • b54db81 build(deps): bump amannn/action-semantic-pull-request from 5.1.0 to 5.2.0 (#5...
  • de780dd build(deps): bump violations-lib from 1.156.2 to 1.156.3
  • 3297c38 build: Fixup PR workflow for semgrep 1.15.0 release (#5560)
  • 5a17893 docs: Update arguments.md (#5565)
  • Additional commits viewable in compare view


Dependabot commands
You can trigger Dependabot actions by commenting on this MR
  • $dependabot rebase will rebase this MR
  • $dependabot recreate will recreate this MR rewriting all the manual changes and resolving conflicts

Merge request reports

Loading