Bump dependency-check-maven from 8.1.2 to 8.2.0
Bumps dependency-check-maven from 8.1.2 to 8.2.0.
Release notes
Sourced from dependency-check-maven's releases.
Version 8.2.0
Added
- Support msbuild Directory.build.props (#5475)
- better display of NPM audit references
- Add CVSS V3 results from NPM Audit results
Fixed
- Fix several issues on NPM Audit reporting (#5546)
- Case issue in SQL (#5557)
- Fix CWE(s) extraction for NPM Audit advisories
- Use the stable github_advisory_id instead of the now unstable id in NPM audit results
See the full listing of changes.
Changelog
Sourced from dependency-check-maven's changelog.
Version 8.2.0 (2023-03-22)
Added
- Support msbuild Directory.build.props (#5475)
- better display of NPM audit references
- Add CVSS V3 results from NPM Audit results
Fixed
- Fix several issues on NPM Audit reporting (#5546)
- Case issue in SQL (#5557)
- Fix CWE(s) extraction for NPM Audit advisories
- Use the stable github_advisory_id instead of the now unstable id in NPM audit results
See the full listing of changes.
Commits
-
1f914b4
build: prepare release v8.2.0 -
3f1c4fe
chore: prepare release -
f7548f3
build(deps): bump maven-release-plugin from 2.5.3 to 3.0.0 (#5570) -
302bf7c
build(deps): bump postgresql from 42.5.4 to 42.6.0 (#5568) -
866e16e
build(deps): bump violations-lib from 1.156.2 to 1.156.3 (#5563) -
1cb2f20
fix: Fix several issues on NPM Audit reporting (#5546) -
b54db81
build(deps): bump amannn/action-semantic-pull-request from 5.1.0 to 5.2.0 (#5... -
de780dd
build(deps): bump violations-lib from 1.156.2 to 1.156.3 -
3297c38
build: Fixup PR workflow for semgrep 1.15.0 release (#5560) -
5a17893
docs: Update arguments.md (#5565) - Additional commits viewable in compare view
Dependabot commands
You can trigger Dependabot actions by commenting on this MR
-
$dependabot rebase
will rebase this MR -
$dependabot recreate
will recreate this MR rewriting all the manual changes and resolving conflicts