Skip to content

Bump dependency-check-maven from 6.0.3 to 6.3.1#8

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/org.owasp-dependency-check-maven-6.3.1
Closed

Bump dependency-check-maven from 6.0.3 to 6.3.1#8
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/org.owasp-dependency-check-maven-6.3.1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2021

Copy link
Copy Markdown

Bumps dependency-check-maven from 6.0.3 to 6.3.1.

Release notes

Sourced from dependency-check-maven's releases.

Version 6.3.1

Changes in this Release

Version 6.3.0

Changes in this Release

  • Many updates were made to improve performance on large scans, reduce false positives, and other bug fixes.
  • Increased the width of four columns in the database; if you use a an external database you should also update the width (see upgrade_5.1.sql).
  • See the full listing of changes.

Version 6.2.2

Changes in this Release

Version 6.2.1

Changes in this Release

Version 6.2.0

Changes in this Release

  • Added an experimental Perl CPAN analyzer #3378
  • Improved database performance #3206
  • The archive analyzer now extracts files from RPM archives #3226
  • Ensure ordered output in reports #3243
  • Several minor bug fixes and updates to reduce false positives
  • See the full listing of changes.

Version 6.1.6

Changes in this Release

  • Resolved issue with Sarif report (#3243)
  • Resolved issue with Ruby Bundle Audit (#3256)
  • Several minor bug fixes and updates to reduce false positives
  • See the full listing of changes.

Version 6.1.5

Changes in this Release

  • Fixed a second NPE introduced in 6.1.3 (see #3246)
  • See the full listing of changes.

Version 6.1.4

Changes in this Release

  • Fixed an NPE introduced in 6.1.3 (see #3212)
  • See the full listing of changes.

Version 6.1.3

Changes in this Release

  • Modified the new CPE matching strategy to be more performant (#3207)

... (truncated)

Changelog

Sourced from dependency-check-maven's changelog.

Version 6.3.1 (2021-09-01)

Changes

Version 6.3.0 (2021-08-31)

Changes

  • Many updates were made to improve performance on large scans, reduce false positives, and other bug fixes.
  • Increased the width of four columns in the database; if you use a an external database you should also update the width (see upgrade_5.1.sql).
  • See the full listing of changes.

Version 6.2.2 (2021-06-10)

Changes

Version 6.2.1 (2021-06-08)

Changes

Version 6.2.0 (2021-05-29)

Changes

  • Added an experimental Perl CPAN analyzer #3378
    • Note that the full DSL of the CPAN is not yet supported so any required dependency is analyzed (i.e. there is no way to exclude development requirements)
  • Improved database performance #3206
  • The archive analyzer now extracts files from RPM archives #3226
  • Ensure ordered output in reports #3243
  • Several minor bug fixes and updates to reduce false positives
  • See the full listing of changes.

Version 6.1.6 (2021-04-29)

Changes

  • Resolved issue with Sarif report (#3243)
  • Resolved issue with Ruby Bundle Audit (#3256)
  • Several minor bug fixes and updates to reduce false positives
  • See the full listing of changes.

... (truncated)

Commits
  • 952d1f5 [maven-release-plugin] prepare release v6.3.1
  • ca8ee4d release 6.3.1
  • 3ed3ee0 Merge pull request #3619 from jeremylong/issue-3618
  • c5f6772 Make checkstyle happy
  • 24ff2e8 Changed resolution strategy to 'gather, then add additional identifiers' inst...
  • edbddd9 Use defensive copy to prevent ConcurrentModificationException due to addition...
  • f4b0335 snapshot version
  • fe94282 [maven-release-plugin] prepare release v6.3.0
  • 2b70aa9 release 6.3.0
  • 012a3e7 Merge pull request #3616 from jeremylong/dependabot/maven/jackson.version-2.12.5
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [dependency-check-maven](https://github.com/jeremylong/DependencyCheck) from 6.0.3 to 6.3.1.
- [Release notes](https://github.com/jeremylong/DependencyCheck/releases)
- [Changelog](https://github.com/jeremylong/DependencyCheck/blob/main/RELEASE_NOTES.md)
- [Commits](jeremylong/DependencyCheck@v6.0.3...v6.3.1)

---
updated-dependencies:
- dependency-name: org.owasp:dependency-check-maven
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Pull requests that update a dependency file label Sep 7, 2021
@dependabot @github

dependabot Bot commented on behalf of github May 18, 2022

Copy link
Copy Markdown
Author

Superseded by #10.

@dependabot dependabot Bot closed this May 18, 2022
@dependabot dependabot Bot deleted the dependabot/maven/org.owasp-dependency-check-maven-6.3.1 branch May 18, 2022 18:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants