Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
542 commits
Select commit Hold shift + click to select a range
3be5a9e
Merge pull request #516 from CycloneDX/dependabot/github_actions/acti…
nscuro Sep 25, 2024
c1c3cf7
Bump org.cyclonedx:cyclonedx-maven-plugin from 2.8.1 to 2.8.2
dependabot[bot] Sep 26, 2024
2e39c29
Bump actions/checkout from 4.1.7 to 4.2.0
dependabot[bot] Sep 26, 2024
115acd6
Merge pull request #519 from CycloneDX/dependabot/github_actions/acti…
nscuro Sep 26, 2024
46a9149
Merge pull request #518 from CycloneDX/dependabot/maven/org.cyclonedx…
nscuro Sep 26, 2024
e9d5d2d
Bump com.fasterxml.jackson.dataformat:jackson-dataformat-xml
dependabot[bot] Sep 27, 2024
017b642
Merge pull request #508 from CycloneDX/issue-507
nscuro Sep 28, 2024
d1c64ac
Merge pull request #517 from CycloneDX/dependabot/github_actions/gith…
nscuro Sep 28, 2024
3b22e47
Bump org.apache.maven.plugins:maven-gpg-plugin from 3.2.6 to 3.2.7
dependabot[bot] Sep 30, 2024
8a2a809
Bump JamesIves/github-pages-deploy-action from 4.6.4 to 4.6.8
dependabot[bot] Sep 30, 2024
5d2fd8e
Merge pull request #522 from CycloneDX/dependabot/github_actions/Jame…
nscuro Sep 30, 2024
82db7b1
Merge pull request #521 from CycloneDX/dependabot/maven/org.apache.ma…
nscuro Sep 30, 2024
770ab3a
Bump github/codeql-action from 3.26.9 to 3.26.10
dependabot[bot] Oct 1, 2024
deed379
Merge pull request #523 from CycloneDX/dependabot/github_actions/gith…
nscuro Oct 1, 2024
e9bca12
Bump org.junit.jupiter:junit-jupiter-params from 5.11.1 to 5.11.2
dependabot[bot] Oct 7, 2024
60a663b
Bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.0 to 3.5.1
dependabot[bot] Oct 7, 2024
585122a
Merge pull request #527 from CycloneDX/dependabot/maven/org.apache.ma…
nscuro Oct 7, 2024
3305eed
Merge pull request #526 from CycloneDX/dependabot/maven/org.junit.jup…
nscuro Oct 7, 2024
cf72264
Bump org.junit.jupiter:junit-jupiter-engine from 5.11.1 to 5.11.2
dependabot[bot] Oct 8, 2024
54ba327
Bump org.cyclonedx:cyclonedx-maven-plugin from 2.8.2 to 2.9.0
dependabot[bot] Oct 8, 2024
65b9ab8
Bump actions/checkout from 4.2.0 to 4.2.1
dependabot[bot] Oct 8, 2024
5e92e75
Bump actions/upload-artifact from 4.4.0 to 4.4.1
dependabot[bot] Oct 8, 2024
5a699cc
Bump github/codeql-action from 3.26.10 to 3.26.12
dependabot[bot] Oct 8, 2024
067c6ec
Merge pull request #532 from CycloneDX/dependabot/github_actions/gith…
nscuro Oct 8, 2024
423e577
Merge pull request #530 from CycloneDX/dependabot/github_actions/acti…
nscuro Oct 8, 2024
ca81043
Merge pull request #531 from CycloneDX/dependabot/github_actions/acti…
nscuro Oct 8, 2024
cf98e64
Merge pull request #529 from CycloneDX/dependabot/maven/org.cyclonedx…
nscuro Oct 8, 2024
7f6f9e7
Merge pull request #528 from CycloneDX/dependabot/maven/org.junit.jup…
nscuro Oct 8, 2024
a1131fd
Merge pull request #511 from CycloneDX/dependabot/maven/commons-io-co…
nscuro Oct 8, 2024
335c098
Merge pull request #520 from CycloneDX/dependabot/maven/com.fasterxml…
nscuro Oct 8, 2024
4ac498d
Bump org.apache.maven.plugins:maven-javadoc-plugin from 3.10.0 to 3.10.1
dependabot[bot] Oct 8, 2024
b38ba8d
Merge pull request #524 from CycloneDX/dependabot/maven/org.apache.ma…
nscuro Oct 8, 2024
6c99147
Bump actions/upload-artifact from 4.4.1 to 4.4.2
dependabot[bot] Oct 9, 2024
64485c9
Merge pull request #533 from CycloneDX/dependabot/github_actions/acti…
nscuro Oct 9, 2024
59873f5
Bump actions/upload-artifact from 4.4.2 to 4.4.3
dependabot[bot] Oct 10, 2024
ab8b17b
Fix apidocs path for doc publish workflow
nscuro Oct 11, 2024
75d2e49
Merge pull request #534 from CycloneDX/dependabot/github_actions/acti…
nscuro Oct 11, 2024
fefd250
Merge pull request #535 from nscuro/fix-apidocs-path
nscuro Oct 11, 2024
5f9681b
Bump version to 9.1.0-SNAPSHOT
nscuro Oct 11, 2024
90d3ec2
Bump github/codeql-action from 3.26.12 to 3.26.13
dependabot[bot] Oct 15, 2024
4b8a116
Merge pull request #537 from CycloneDX/dependabot/github_actions/gith…
nscuro Oct 15, 2024
8b7a876
Merge pull request #536 from nscuro/bump-version-9.1.0-snapshot
stevespringett Oct 15, 2024
888c8db
[maven-release-plugin] prepare release cyclonedx-core-java-9.1.0
stevespringett Oct 15, 2024
6cfef32
[maven-release-plugin] prepare for next development iteration
stevespringett Oct 15, 2024
f9d5de3
Bump com.networknt:json-schema-validator from 1.5.2 to 1.5.3 (#545)
dependabot[bot] Nov 21, 2024
f9b5bea
Bump com.fasterxml.jackson.dataformat:jackson-dataformat-xml (#544)
dependabot[bot] Nov 21, 2024
3aeeb7f
schema 1.6.1
jkowalleck Nov 18, 2024
f6821e7
tests 1.6.1
jkowalleck Nov 18, 2024
fce34d4
Fix Issues with Spec 1.6.1
mr-zepol Nov 21, 2024
1ee7b43
Bump JamesIves/github-pages-deploy-action from 4.6.8 to 4.6.9 (#548)
dependabot[bot] Nov 21, 2024
29fb243
Bump org.junit.jupiter:junit-jupiter-engine from 5.11.2 to 5.11.3 (#540)
dependabot[bot] Nov 21, 2024
41e7604
Bump org.junit.jupiter:junit-jupiter-params from 5.11.2 to 5.11.3 (#539)
dependabot[bot] Nov 21, 2024
8f46912
Bump commons-io:commons-io from 2.17.0 to 2.18.0 (#555)
dependabot[bot] Nov 21, 2024
ae500ce
Reduce duplicated code
mr-zepol Nov 21, 2024
78208b1
Bump github/codeql-action from 3.26.13 to 3.27.5 (#553)
dependabot[bot] Nov 22, 2024
d96bec5
Bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.1 to 3.5…
dependabot[bot] Nov 22, 2024
d36548a
Bump actions/checkout from 4.2.1 to 4.2.2 (#542)
dependabot[bot] Nov 22, 2024
763526b
Bump org.apache.maven.plugins:maven-javadoc-plugin from 3.10.1 to 3.1…
dependabot[bot] Nov 22, 2024
9a320b3
Bump actions/setup-java from 4.4.0 to 4.5.0 (#543)
dependabot[bot] Nov 22, 2024
d9f8d4c
Merge pull request #552 from CycloneDX/feat/cdx1.6.1
nscuro Nov 22, 2024
08a9448
Merge pull request #501 from CycloneDX/issue_497
nscuro Nov 22, 2024
16276f9
Merge pull request #556 from CycloneDX/polish_code
nscuro Nov 22, 2024
ebafc9d
Fix Issue
mr-zepol Sep 7, 2024
9ddb170
Change to support variables correctly
mr-zepol Jun 18, 2024
b5f8b0e
Testing
mr-zepol Aug 25, 2024
874ac73
Improvements and correction in deserializers
mr-zepol Aug 25, 2024
477bb93
Fix Signature issue with Signatories while serializing
mr-zepol Aug 27, 2024
14cdc47
Remove unused imports
mr-zepol Sep 4, 2024
16a7cce
Merge branch 'master' into master
mr-zepol Nov 23, 2024
b3d1783
Merge pull request #486 from CycloneDX/Env_vars_issue
nscuro Nov 23, 2024
dc017fd
Merge pull request #500 from CycloneDX/issue_498
nscuro Nov 23, 2024
e46f02a
Bump com.networknt:json-schema-validator from 1.5.3 to 1.5.4 (#557)
dependabot[bot] Nov 27, 2024
cdd525b
Bump com.fasterxml.jackson.dataformat:jackson-dataformat-xml
dependabot[bot] Nov 28, 2024
256b719
Merge pull request #438 from shaikhu/master
nscuro Nov 28, 2024
7ef8dc4
Merge pull request #558 from CycloneDX/dependabot/maven/com.fasterxml…
nscuro Nov 28, 2024
921d750
Bump org.cyclonedx:cyclonedx-maven-plugin from 2.9.0 to 2.9.1 (#560)
dependabot[bot] Dec 3, 2024
3768a15
Bump JamesIves/github-pages-deploy-action from 4.6.9 to 4.7.1 (#559)
dependabot[bot] Dec 3, 2024
b9d62c0
feat: enhance enums to have from*(String) methods
jeremylong Dec 3, 2024
2e3b7af
Merge pull request #561 from jeremylong/enhanceEnums
nscuro Dec 3, 2024
2082a52
Fix Issue 562
mr-zepol Dec 9, 2024
f4cc7f4
Fix Issue 492
mr-zepol Dec 10, 2024
54b3e3e
Allow to specify prettyPrint for toJsonString method
mr-zepol Dec 10, 2024
6100c3c
Bump org.apache.maven.plugins:maven-javadoc-plugin from 3.11.1 to 3.1…
dependabot[bot] Dec 10, 2024
825a09e
Bump github/codeql-action from 3.27.5 to 3.27.6 (#564)
dependabot[bot] Dec 10, 2024
6ec8ef7
Bump JamesIves/github-pages-deploy-action from 4.7.1 to 4.7.2 (#563)
dependabot[bot] Dec 10, 2024
f8cac88
Merge pull request #569 from CycloneDX/enhacement
nscuro Dec 10, 2024
c7c3aa9
Merge pull request #568 from CycloneDX/issue_562
nscuro Dec 10, 2024
73b795d
Bump github/codeql-action from 3.27.6 to 3.27.7
dependabot[bot] Dec 11, 2024
4145dce
Bump version to `10.0.0-SNAPSHOT`
nscuro Dec 11, 2024
cf92d86
Merge pull request #570 from CycloneDX/dependabot/github_actions/gith…
nscuro Dec 11, 2024
f631633
Initial commit
stevespringett Dec 11, 2024
70532c5
Changing scm urls to use https
stevespringett Dec 11, 2024
56933fa
initial commit
stevespringett Dec 11, 2024
b0a5961
[maven-release-plugin] prepare release cyclonedx-core-java-10.0.0
cdx-automation Dec 11, 2024
cbd38df
[maven-release-plugin] prepare for next development iteration
cdx-automation Dec 11, 2024
0a6732e
Bump github/codeql-action from 3.27.7 to 3.27.9 (#572)
dependabot[bot] Dec 14, 2024
37effda
docs: add version 10.0
jkowalleck Dec 14, 2024
83b9e3f
Add util methods
mr-zepol Dec 18, 2024
d1dd865
add new Enum based on the spec
mr-zepol Dec 18, 2024
8f1c119
Bump actions/upload-artifact from 4.4.3 to 4.5.0 (#577)
dependabot[bot] Dec 18, 2024
9bacfa9
Bump org.junit.jupiter:junit-jupiter-params from 5.11.3 to 5.11.4 (#575)
dependabot[bot] Dec 18, 2024
1523dd6
Bump org.junit.jupiter:junit-jupiter-engine from 5.11.3 to 5.11.4 (#576)
dependabot[bot] Dec 18, 2024
40037b2
Bump org.assertj:assertj-core from 3.26.3 to 3.27.0
dependabot[bot] Dec 20, 2024
a0a3d9e
Merge pull request #573 from CycloneDX/docs/readme-add-10.x
nscuro Dec 21, 2024
4fbdc6b
Merge pull request #579 from CycloneDX/add_enum_ack
nscuro Dec 21, 2024
66fcb64
Merge pull request #578 from CycloneDX/Add_util_methods
nscuro Dec 21, 2024
51dc9d2
Fix 571
mr-zepol Dec 14, 2024
26bd89a
Merge pull request #574 from CycloneDX/issue_571
nscuro Dec 21, 2024
d2d5d47
Merge pull request #580 from CycloneDX/dependabot/maven/org.assertj-a…
nscuro Dec 21, 2024
b1e4e45
refactor test
Bananeweizen Dec 21, 2024
3f16acf
Bump github/codeql-action from 3.27.9 to 3.28.0
dependabot[bot] Dec 23, 2024
509bfaf
Merge pull request #582 from CycloneDX/dependabot/github_actions/gith…
nscuro Dec 29, 2024
434391c
Merge pull request #581 from Bananeweizen/refactor_test
nscuro Dec 29, 2024
a4eed3a
Bump version to `10.1.0-SNAPSHOT`
nscuro Dec 29, 2024
46cbaec
Bump version in README
nscuro Dec 29, 2024
0a296a9
[maven-release-plugin] prepare release cyclonedx-core-java-10.1.0
cdx-automation Dec 29, 2024
16a44a3
[maven-release-plugin] prepare for next development iteration
cdx-automation Dec 29, 2024
8191643
Bump org.assertj:assertj-core from 3.27.0 to 3.27.1
dependabot[bot] Jan 2, 2025
f3611c7
Merge pull request #584 from CycloneDX/dependabot/maven/org.assertj-a…
nscuro Jan 5, 2025
6f0a914
Bump org.assertj:assertj-core from 3.27.1 to 3.27.2
dependabot[bot] Jan 6, 2025
a0ebec7
Bump commons-codec:commons-codec from 1.17.1 to 1.17.2
dependabot[bot] Jan 7, 2025
0fffcbb
Merge pull request #586 from CycloneDX/dependabot/maven/commons-codec…
nscuro Jan 7, 2025
2875cd6
Merge pull request #585 from CycloneDX/dependabot/maven/org.assertj-a…
nscuro Jan 7, 2025
6312a21
Bump actions/upload-artifact from 4.5.0 to 4.6.0 (#587)
dependabot[bot] Jan 11, 2025
99db5c3
Support extended ISO 8601 formats including optional milliseconds and…
mr-zepol Jan 11, 2025
230cd11
Merge pull request #588 from CycloneDX/Support_extended_formats
nscuro Jan 11, 2025
4be9675
Bump github/codeql-action from 3.28.0 to 3.28.1 (#589)
dependabot[bot] Jan 13, 2025
6b44020
Bump com.networknt:json-schema-validator from 1.5.4 to 1.5.5
dependabot[bot] Jan 15, 2025
962813c
Merge pull request #590 from CycloneDX/dependabot/maven/com.networknt…
nscuro Jan 15, 2025
d56f892
Remove duplicated code
mr-zepol Jan 16, 2025
8b8c093
Bump org.assertj:assertj-core from 3.27.2 to 3.27.3
dependabot[bot] Jan 20, 2025
196f527
Merge pull request #592 from CycloneDX/dependabot/maven/org.assertj-a…
nscuro Jan 20, 2025
495e343
Bump github/codeql-action from 3.28.1 to 3.28.3
dependabot[bot] Jan 23, 2025
841dc76
Merge pull request #594 from CycloneDX/dependabot/github_actions/gith…
nscuro Jan 23, 2025
eeb678a
Bump github/codeql-action from 3.28.3 to 3.28.4
dependabot[bot] Jan 24, 2025
2d3de59
Merge pull request #595 from CycloneDX/dependabot/github_actions/gith…
nscuro Jan 24, 2025
577c0ce
Bump github/codeql-action from 3.28.4 to 3.28.5
dependabot[bot] Jan 27, 2025
24edea0
Merge pull request #596 from CycloneDX/dependabot/github_actions/gith…
nscuro Jan 27, 2025
a8688e4
Bump github/codeql-action from 3.28.5 to 3.28.6
dependabot[bot] Jan 28, 2025
1fe5cfc
Bump commons-codec:commons-codec from 1.17.2 to 1.18.0
dependabot[bot] Jan 28, 2025
356a66c
Merge pull request #598 from CycloneDX/dependabot/maven/commons-codec…
nscuro Jan 28, 2025
654a25d
Merge pull request #597 from CycloneDX/dependabot/github_actions/gith…
nscuro Jan 28, 2025
ac6c08b
Bump github/codeql-action from 3.28.6 to 3.28.8
dependabot[bot] Jan 30, 2025
ffbf1c2
Merge pull request #601 from CycloneDX/dependabot/github_actions/gith…
nscuro Jan 30, 2025
6ba822e
Bump github/codeql-action from 3.28.8 to 3.28.9
dependabot[bot] Feb 10, 2025
b586017
Bump com.networknt:json-schema-validator from 1.5.5 to 1.5.6
dependabot[bot] Feb 20, 2025
5ea6e48
Bump JamesIves/github-pages-deploy-action from 4.7.2 to 4.7.3
dependabot[bot] Feb 20, 2025
ab938be
Merge pull request #603 from CycloneDX/dependabot/maven/com.networknt…
nscuro Feb 23, 2025
0a1a24e
Merge pull request #604 from CycloneDX/dependabot/github_actions/Jame…
nscuro Feb 23, 2025
b313c15
Merge pull request #602 from CycloneDX/dependabot/github_actions/gith…
nscuro Feb 23, 2025
eeece62
Bump org.junit.jupiter:junit-jupiter-params from 5.11.4 to 5.12.0
dependabot[bot] Feb 24, 2025
3332a51
Bump org.junit.jupiter:junit-jupiter-engine from 5.11.4 to 5.12.0
dependabot[bot] Feb 24, 2025
af5c89b
Bump actions/upload-artifact from 4.6.0 to 4.6.1
dependabot[bot] Feb 24, 2025
8da5cb0
Bump github/codeql-action from 3.28.9 to 3.28.10
dependabot[bot] Feb 24, 2025
63d662c
Merge pull request #608 from CycloneDX/dependabot/github_actions/gith…
nscuro Feb 24, 2025
d46ab8d
Merge pull request #607 from CycloneDX/dependabot/github_actions/acti…
nscuro Feb 24, 2025
8a15322
Merge pull request #606 from CycloneDX/dependabot/maven/org.junit.jup…
nscuro Feb 24, 2025
a506751
Merge pull request #605 from CycloneDX/dependabot/maven/org.junit.jup…
nscuro Feb 24, 2025
3781b64
PR Fix
mr-zepol Feb 27, 2025
69ebbf9
Bump actions/download-artifact from 4.1.8 to 4.1.9 (#609)
dependabot[bot] Feb 27, 2025
84546e2
Merge pull request #591 from CycloneDX/Polish_code
nscuro Feb 28, 2025
89a8be9
Bump com.fasterxml.jackson.dataformat:jackson-dataformat-xml
dependabot[bot] Mar 3, 2025
c598107
Bump github/codeql-action from 3.28.10 to 3.28.11
dependabot[bot] Mar 10, 2025
98d85f3
Merge pull request #611 from CycloneDX/dependabot/github_actions/gith…
nscuro Mar 11, 2025
5deb71c
Merge pull request #610 from CycloneDX/dependabot/maven/com.fasterxml…
nscuro Mar 11, 2025
3e34848
Bump version to 10.2.0-SNAPSHOT
nscuro Mar 11, 2025
1694d34
[maven-release-plugin] prepare release cyclonedx-core-java-10.2.0
cdx-automation Mar 11, 2025
9a72c27
[maven-release-plugin] prepare for next development iteration
cdx-automation Mar 11, 2025
3ccf24b
[maven-release-plugin] prepare release cyclonedx-core-java-10.2.1
cdx-automation Mar 12, 2025
a2d30ea
[maven-release-plugin] prepare for next development iteration
cdx-automation Mar 12, 2025
1e0560f
Add Extra Validations
mr-zepol Mar 12, 2025
36aca60
Polish code for validation
mr-zepol Mar 12, 2025
d661f9e
Merge pull request #613 from CycloneDX/improve_code
nscuro Mar 12, 2025
440b369
Merge pull request #612 from CycloneDX/add_validation
nscuro Mar 12, 2025
2028b42
Bump org.junit.jupiter:junit-jupiter-engine from 5.12.0 to 5.12.1
dependabot[bot] Mar 17, 2025
c3fcfe4
Bump org.junit.jupiter:junit-jupiter-params from 5.12.0 to 5.12.1
dependabot[bot] Mar 17, 2025
b4c75c4
Merge pull request #615 from CycloneDX/dependabot/maven/org.junit.jup…
nscuro Mar 17, 2025
e9fa73d
Merge pull request #614 from CycloneDX/dependabot/maven/org.junit.jup…
nscuro Mar 17, 2025
812865e
Bump actions/download-artifact from 4.1.9 to 4.2.0
dependabot[bot] Mar 19, 2025
0778b05
Merge pull request #617 from CycloneDX/dependabot/github_actions/acti…
nscuro Mar 19, 2025
6118e3b
Bump actions/download-artifact from 4.2.0 to 4.2.1
dependabot[bot] Mar 20, 2025
f121543
Bump actions/upload-artifact from 4.6.1 to 4.6.2
dependabot[bot] Mar 20, 2025
d7b523a
Bump github/codeql-action from 3.28.11 to 3.28.12
dependabot[bot] Mar 20, 2025
57d7593
Merge pull request #619 from CycloneDX/dependabot/github_actions/acti…
nscuro Mar 20, 2025
0cc9cfb
Merge pull request #620 from CycloneDX/dependabot/github_actions/gith…
nscuro Mar 20, 2025
877115d
Merge pull request #618 from CycloneDX/dependabot/github_actions/acti…
nscuro Mar 20, 2025
dbdfb0d
Bump github/codeql-action from 3.28.12 to 3.28.13
dependabot[bot] Mar 25, 2025
0a16fca
Merge pull request #621 from CycloneDX/dependabot/github_actions/gith…
nscuro Mar 25, 2025
970a3d4
Bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.2 to 3.5…
dependabot[bot] Mar 31, 2025
cd88e4e
Bump org.jacoco:jacoco-maven-plugin from 0.8.12 to 0.8.13 (#624)
dependabot[bot] Apr 7, 2025
c1ab197
Bump github/codeql-action from 3.28.13 to 3.28.15 (#625)
dependabot[bot] Apr 10, 2025
bfcb876
Fixes 616
mr-zepol Apr 10, 2025
ddc0d36
Fix 622
mr-zepol Apr 10, 2025
1636be5
Bump org.junit.jupiter:junit-jupiter-engine from 5.12.1 to 5.12.2
dependabot[bot] Apr 14, 2025
6ec0e5b
Bump org.junit.jupiter:junit-jupiter-params from 5.12.1 to 5.12.2
dependabot[bot] Apr 14, 2025
129b883
Bump commons-io:commons-io from 2.18.0 to 2.19.0
dependabot[bot] Apr 14, 2025
d3f8214
Merge pull request #627 from CycloneDX/issue_616
nscuro Apr 14, 2025
60e844e
Merge pull request #628 from CycloneDX/issue_622
nscuro Apr 14, 2025
88605af
Merge pull request #631 from CycloneDX/dependabot/maven/commons-io-co…
nscuro Apr 14, 2025
163378b
Merge pull request #630 from CycloneDX/dependabot/maven/org.junit.jup…
nscuro Apr 14, 2025
384ba06
Merge pull request #629 from CycloneDX/dependabot/maven/org.junit.jup…
nscuro Apr 14, 2025
844349d
Bump version to `11.0.0-SNAPSHOT`
nscuro Apr 14, 2025
4217ed4
Bump org.apache.commons:commons-collections4 from 4.4 to 4.5.0 (#633)
dependabot[bot] Apr 23, 2025
d43d4d8
Bump github/codeql-action from 3.28.15 to 3.28.16 (#634)
dependabot[bot] Apr 25, 2025
5cdbbfa
Bump actions/download-artifact from 4.2.1 to 4.3.0 (#635)
dependabot[bot] Apr 25, 2025
d088af8
Bump com.fasterxml.jackson.dataformat:jackson-dataformat-xml (#636)
dependabot[bot] Apr 25, 2025
b0bdc50
Merge pull request #632 from CycloneDX/nscuro-patch-1
nscuro Apr 26, 2025
76e1209
Bump github/codeql-action from 3.28.16 to 3.28.18
dependabot[bot] May 19, 2025
7d1b2c6
Bump com.networknt:json-schema-validator from 1.5.6 to 1.5.7
dependabot[bot] May 26, 2025
a96dfba
#640 Added license names to license-mapping.json
May 21, 2025
e5ce7e7
Merge pull request #644 from CycloneDX/dependabot/maven/com.networknt…
nscuro Jun 2, 2025
f3faba8
Merge pull request #639 from CycloneDX/dependabot/github_actions/gith…
nscuro Jun 2, 2025
c56c883
Fix failing GitHub Actions builds
nscuro Jun 3, 2025
13c3442
Merge pull request #648 from nscuro/fix-gha-builds
nscuro Jun 7, 2025
cb36d0b
Bump org.junit.jupiter:junit-jupiter-engine from 5.12.2 to 5.13.0
dependabot[bot] Jun 7, 2025
ab16b2c
Bump github/codeql-action from 3.28.18 to 3.28.19
dependabot[bot] Jun 7, 2025
fcf0dd1
Merge pull request #646 from CycloneDX/dependabot/maven/org.junit.jup…
nscuro Jun 7, 2025
57b89d6
Merge pull request #649 from CycloneDX/dependabot/github_actions/gith…
nscuro Jun 7, 2025
0ebdb2d
Bump org.junit.jupiter:junit-jupiter-params from 5.12.2 to 5.13.0
dependabot[bot] Jun 7, 2025
696f9b7
Merge pull request #645 from CycloneDX/dependabot/maven/org.junit.jup…
nscuro Jun 7, 2025
92c7609
Bump SPDX license list to 3.26.0
nscuro Jun 2, 2025
826936d
Merge pull request #647 from nscuro/bump-spdx-license-list-3.26.0
nscuro Jun 7, 2025
99d7c3e
Merge pull request #641 from bilak/feat/640-adding-license-names
nscuro Jun 11, 2025
9dc70d1
Bump github/codeql-action from 3.28.19 to 3.29.0 (#650)
dependabot[bot] Jun 12, 2025
5a0f385
Bump com.fasterxml.jackson.dataformat:jackson-dataformat-xml (#651)
dependabot[bot] Jun 19, 2025
20281f4
Bump org.junit.jupiter:junit-jupiter-engine from 5.13.1 to 5.13.2
dependabot[bot] Jun 25, 2025
8ff4d31
Bump org.junit.jupiter:junit-jupiter-params from 5.13.1 to 5.13.2
dependabot[bot] Jun 25, 2025
f3eadea
chore: GH workflow permissions
jkowalleck Jun 25, 2025
97f9bb1
Merge pull request #654 from CycloneDX/chore/gh-workflow-permissions
nscuro Jun 25, 2025
2b5d280
Merge pull request #653 from CycloneDX/dependabot/maven/org.junit.jup…
nscuro Jun 25, 2025
72c560d
Merge pull request #652 from CycloneDX/dependabot/maven/org.junit.jup…
nscuro Jun 25, 2025
9e2dcea
Bump com.networknt:json-schema-validator from 1.5.7 to 1.5.8
dependabot[bot] Jun 30, 2025
d3975a9
Bump github/codeql-action from 3.29.0 to 3.29.2
dependabot[bot] Jul 1, 2025
89f9b64
Bump org.apache.maven.plugins:maven-gpg-plugin from 3.2.7 to 3.2.8
dependabot[bot] Jul 3, 2025
4840d52
Bump org.apache.maven.plugins:maven-enforcer-plugin from 3.5.0 to 3.6.0
dependabot[bot] Jul 3, 2025
b021481
Bump org.junit.jupiter:junit-jupiter-params from 5.13.2 to 5.13.3
dependabot[bot] Jul 7, 2025
1d3a8bd
Bump org.junit.jupiter:junit-jupiter-engine from 5.13.2 to 5.13.3
dependabot[bot] Jul 7, 2025
d5ba897
Merge pull request #660 from CycloneDX/dependabot/maven/org.junit.jup…
nscuro Jul 8, 2025
24fb4f4
Merge pull request #661 from CycloneDX/dependabot/maven/org.junit.jup…
nscuro Jul 8, 2025
b76c475
Merge pull request #659 from CycloneDX/dependabot/maven/org.apache.ma…
nscuro Jul 8, 2025
fb95c2d
Merge pull request #658 from CycloneDX/dependabot/maven/org.apache.ma…
nscuro Jul 8, 2025
f20d9c4
Merge pull request #657 from CycloneDX/dependabot/github_actions/gith…
nscuro Jul 8, 2025
fed6ace
Merge pull request #656 from CycloneDX/dependabot/maven/com.networknt…
nscuro Jul 8, 2025
2b0ddb2
Bump org.apache.commons:commons-lang3 from 3.17.0 to 3.18.0
dependabot[bot] Jul 10, 2025
a67f6f2
Merge pull request #662 from CycloneDX/dependabot/maven/org.apache.co…
nscuro Jul 10, 2025
9c935d2
Merge branch 'upstream-master' into MergeFromUpstream
Jul 17, 2025
5296a5c
Remove duplicate XML headers
Jul 17, 2025
eb0d899
Fix all XML deserialization test cases
Jul 18, 2025
1206563
Update regression test to use single quotes to match jackson XML prolog
Jul 18, 2025
1946671
Update github actions
Jul 18, 2025
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
65 changes: 0 additions & 65 deletions .github/release-drafter.yml

This file was deleted.

20 changes: 20 additions & 0 deletions .github/release.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,20 @@
changelog:
categories:
- title: Breaking Changes 🚨
labels:
- breaking change
- title: Enhancements 🚀
labels:
- enhancement
- title: Bug Fixes 🐛
labels:
- bug
- title: Dependency Updates 🤖
labels:
- dependencies
- title: Documentation 📃
labels:
- documentation
- title: Other Changes
labels:
- "*"
54 changes: 14 additions & 40 deletions .github/workflows/codeql-analysis.yml
Original file line number Diff line number Diff line change
Expand Up @@ -2,65 +2,39 @@ name: "CodeQL"

on:
push:
branches: [master]
branches:
- master
pull_request:
# The branches below must be a subset of the branches above
branches: [master]
branches:
- master
schedule:
- cron: '0 9 * * 5'
- cron: '0 9 * * 5'

permissions: { }

jobs:
analyze:
name: Analyze
runs-on: ubuntu-latest

strategy:
fail-fast: false
matrix:
# Override automatic language detection by changing the below list
# Supported options are ['csharp', 'cpp', 'go', 'java', 'javascript', 'python']
language: ['java']
# Learn more...
# https://docs.github.com/en/github/finding-security-vulnerabilities-and-errors-in-your-code/configuring-code-scanning#overriding-automatic-language-detection

permissions:
security-events: write
steps:
- name: Checkout repository
uses: actions/checkout@v4.1.1
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # tag=v4.2.2
with:
# We must fetch at least the immediate parents so that if this is
# a pull request then we can checkout the head.
fetch-depth: 2

# If this run was triggered by a pull request event, then checkout
# the head of the pull request instead of the merge commit.
- run: git checkout HEAD^2
if: ${{ github.event_name == 'pull_request' }}

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v3
uses: github/codeql-action/init@181d5eefc20863364f96762470ba6f862bdef56b # tag=v3.29.2
with:
languages: ${{ matrix.language }}
# If you wish to specify custom queries, you can do so here or in a config file.
# By default, queries listed here will override any specified in a config file.
# Prefix the list here with "+" to use these queries and those in the config file.
# queries: ./path/to/local/query, your-org/your-repo/queries@main

# Autobuild attempts to build any compiled languages (C/C++, C#, or Java).
# If this step fails, then you should remove it and run the build manually (see below)
languages: java
- name: Autobuild
uses: github/codeql-action/autobuild@v3

# ℹ️ Command-line programs to run using the OS shell.
# 📚 https://git.io/JvXDl

# ✏️ If the Autobuild fails above, remove it and uncomment the following three lines
# and modify them (or add more) to build your code if your project
# uses a compiled language

#- run: |
# make bootstrap
# make release

uses: github/codeql-action/autobuild@181d5eefc20863364f96762470ba6f862bdef56b # tag=v3.29.2
- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v3
uses: github/codeql-action/analyze@181d5eefc20863364f96762470ba6f862bdef56b # tag=v3.29.2
18 changes: 10 additions & 8 deletions .github/workflows/docs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -6,24 +6,26 @@ on:
- master
workflow_dispatch:

permissions: { }

jobs:
build-documentation:
name: "Build documentation"
runs-on: ubuntu-latest
permissions:
contents: write # Required to push commits to gh-pages branch
timeout-minutes: 30
steps:
- uses: actions/checkout@v4.1.1
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # tag=v4.2.2
- name: Set up JDK 8
uses: actions/setup-java@v4
uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # tag=v4.7.1
with:
distribution: temurin
java-version: 8
- name: Build with Maven
run: mvn package --file pom.xml

run: mvn -B --no-transfer-progress package
- name: Deploy documentation
uses: JamesIves/github-pages-deploy-action@releases/v3
uses: JamesIves/github-pages-deploy-action@6c2d9db40f9296374acc17b90404b6e8864128c8 # tag=v4.7.3
with:
GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}
BRANCH: gh-pages
FOLDER: target/apidocs
branch: gh-pages
folder: target/reports/apidocs
4 changes: 2 additions & 2 deletions .github/workflows/java-maven.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,9 +15,9 @@ jobs:
group: ${{ github.workflow }}-${{ github.ref }}
steps:
- name: Checkout
uses: actions/checkout@v2
uses: actions/checkout@v4
- name: Set up JDK 8
uses: actions/setup-java@v2
uses: actions/setup-java@v4
with:
distribution: adopt
java-version: 8
Expand Down
49 changes: 37 additions & 12 deletions .github/workflows/maven.yml
Original file line number Diff line number Diff line change
@@ -1,22 +1,47 @@
name: Maven CI

on: [push, pull_request]
on:
push:
branches:
- master
pull_request:
branches:
- master

permissions: { }

jobs:
build:
test:
name: Test
strategy:
matrix:
os: [ ubuntu-latest ]
java-version: [ 8 ]
distro: [ 'zulu', 'temurin' ]
runs-on: ${{ matrix.os }}

java-version: [ 8, 11, 17, 21 ]
runs-on: ubuntu-latest
timeout-minutes: 5
steps:
- uses: actions/checkout@v4.1.1
- name: Checkout Repository
uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # tag=v4.2.2
- name: Set up JDK ${{ matrix.java-version }}
uses: actions/setup-java@v4
uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # tag=v4.7.1
with:
distribution: ${{ matrix.distro }}
distribution: temurin
java-version: ${{ matrix.java-version }}
- name: Build with Maven
run: mvn package --file pom.xml
cache: maven
- name: Test
run: mvn -B --no-transfer-progress clean verify
# Publishing coverage to Codacy is only possible for builds of push events.
# PRs from forks do not get access to repository secrets.
# https://securitylab.github.com/research/github-actions-preventing-pwn-requests/
- name: Publish test coverage
if: ${{ github.event_name != 'pull_request' && github.repository_owner == 'CycloneDX' && matrix.java-version == '21' }}
uses: codacy/codacy-coverage-reporter-action@89d6c85cfafaec52c72b6c5e8b2878d33104c699 # tag=v1.3.0
with:
project-token: ${{ secrets.CODACY_PROJECT_TOKEN }}
language: Java
coverage-reports: target/site/jacoco/jacoco.xml
- name: Upload PR test coverage report
if: ${{ github.event_name == 'pull_request' }}
uses: actions/upload-artifact@ea165f8d65b6e75b540449e92b4886f43607fa02 # tag=v4.6.2
with:
name: pr-test-coverage-report-java-${{ matrix.java-version }}
path: target/site/jacoco/jacoco.xml
32 changes: 32 additions & 0 deletions .github/workflows/pr-test-coverage.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,32 @@
name: Report PR Test Coverage

on:
workflow_run:
workflows:
- Maven CI
types:
- completed

permissions: { }

jobs:
publish:
name: Report Coverage
runs-on: ubuntu-latest
if: |-
github.event.workflow_run.event == 'pull_request'
&& github.event.workflow_run.conclusion == 'success'
steps:
- name: Download PR test coverage report
uses: actions/download-artifact@d3f86a106a0bac45b974a628896c90dbdf5c8093 # tag=v4.3.0
with:
name: pr-test-coverage-report-java-21
github-token: ${{ secrets.GITHUB_TOKEN }}
run-id: ${{ github.event.workflow_run.id }}
- name: Report Coverage to Codacy
run: |-
bash <(curl -Ls https://coverage.codacy.com/get.sh) report \
--project-token ${{ secrets.CODACY_PROJECT_TOKEN }} \
--commit-uuid ${{ github.event.workflow_run.head_sha }} \
--coverage-reports ./jacoco.xml \
--language Java
29 changes: 29 additions & 0 deletions .github/workflows/publish-snapshot.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
name: Maven Publish Snapshot

on: [workflow_dispatch]

permissions: {}

jobs:
build:

runs-on: ubuntu-latest

permissions:
contents: write # for git-push after version modifications

steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # tag=v4.2.2
- name: Set up JDK 8
uses: actions/setup-java@c5195efecf7bdfc987ee8bae7a71cb8b11521c00 # tag=v4.7.1
with:
java-version: '8'
distribution: 'temurin'
server-id: ossrh
server-username: MAVEN_USERNAME
server-password: MAVEN_PASSWORD
- name: Publish snapshot
run: mvn -B deploy
env:
MAVEN_USERNAME: ${{ secrets.OSSRH_USERNAME }}
MAVEN_PASSWORD: ${{ secrets.OSSRH_TOKEN }}
19 changes: 0 additions & 19 deletions .github/workflows/release-drafter.yml

This file was deleted.

Loading