Bump dependency-check-maven from 8.4.0 to 8.4.2
Bumps dependency-check-maven from 8.4.0 to 8.4.2.
Release notes
Sourced from dependency-check-maven's releases.
Version 8.4.2
- fix: correct log configuration in cli (#6002)
See the full listing of changes.
Version 8.4.1
- fix: upgrade to JCS3 (#5114)
- fix: Support ~= version specifier in requirements.txt and pipfile (#5902)
- fix: Version of dependency no longer ignored when CPE product has a 'java' suffix in a product name (#5901)
- fix: Do not filter out evidences added by hints (#5900)
- fix: fixes FP #5925 (#5927)
See the full listing of changes.
Changelog
Sourced from dependency-check-maven's changelog.
Version 8.4.2 (2023-10-22)
- fix: correct log configuration in cli (#6002)
See the full listing of changes.
Version 8.4.1 (2023-10-21)
Fixed
- fix: upgrade to JCS3 (#5114)
- fix: Support ~= version specifier in requirements.txt and pipfile (#5902)
- fix: Version of dependency no longer ignored when CPE product has a 'java' suffix in a product name (#5901)
- fix: Do not filter out evidences added by hints (#5900)
- fix: fixes FP #5925 (#5927)
See the full listing of changes.
Commits
-
c15b3b9
build: prepare release v8.4.2 -
dbdb84d
docs: release 8.4.2 -
74f5156
fix: dependabot config -
1162b3e
fix: correct log configuration in cli (#6002) -
e105540
chore: Release 8.4.1 (#6000) -
5cc8df0
build: prepare for next development iteration -
61377ad
build: prepare release v8.4.1 -
e2649a6
docs: prepare release -
778185b
build(deps): bump org.jacoco:jacoco-maven-plugin from 0.8.10 to 0.8.11 (#5994) -
81bd778
build(deps): bump se.bjurr.violations:violations-lib from 1.156.6 to 1.156.7 ... - Additional commits viewable in compare view
Dependabot commands
You can trigger Dependabot actions by commenting on this MR
-
$dependabot rebase
will rebase this MR -
$dependabot recreate
will recreate this MR rewriting all the manual changes and resolving conflicts