Skip to content

Bump org.owasp:dependency-check-maven from 9.0.9 to 9.0.10

Bumps org.owasp:dependency-check-maven from 9.0.9 to 9.0.10.

Release notes

Sourced from org.owasp:dependency-check-maven's releases.

Version 9.0.10

Refer to the CHANGELOG.md for information about improvements and upgrade notes.

Changelog

Sourced from org.owasp:dependency-check-maven's changelog.

Version 9.0.10 (2024-03-15)

  • fix: #4321 Suppress redis server CVEs for client libraries (#4321) (#6489)
  • fix: bump commons-compress from 1.25.0 to 1.26.0 to fix CVE-2024-25710 and CVE-2024-26308 (#6492)
  • feat: Allow to pass NVD API key via environment variable (#6454)
  • fix: issue 5452 - ConcurrentModificationException in NodePackageAnalyzer.processDependencies - adding synchronized block (#6501)
  • docs: document the default data directory (#6484)
  • fix: prevent NPE in bundler audit (#6462)
  • fix: #6441 Improve suppression rule to not restrict to a single version (#6442)

See the full listing of changes.

Commits
  • b18a1d6 build: prepare release v9.0.10
  • b6a03c1 docs: prepare release 9.0.10
  • e57ec63 fix: #4321 Suppress redis server CVEs for client libraries (#4321) (#6489)
  • 04aff68 fix: bump commons-compress from 1.25.0 to 1.26.0 to fix CVE-2024-25710 and CV...
  • ea72798 feat: Allow to pass NVD API key via environment variable (#6454)
  • 44a3f16 fix: issue 5452 - ConcurrentModificationException in NodePackageAnalyzer.proc...
  • 873289e docs: document the default data directory (#6484)
  • 5df22e2 fix: prevent NPE in bundler audit (#6462)
  • 39631db fix: #6441 Improve suppression rule to not restrict to a single version (#6442)
  • 33c4c98 build: release 9.0.9 (#6396)
  • Additional commits viewable in compare view


Dependabot commands
You can trigger Dependabot actions by commenting on this MR
  • $dependabot recreate will recreate this MR rewriting all the manual changes and resolving conflicts

Merge request reports

Loading