fix(deps): update all minor dependencies#285
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
9011a7f to
cc41307
Compare
e84b08b to
b37930b
Compare
0070162 to
faa2ad2
Compare
dc51624 to
967da6b
Compare
967da6b to
365d4d2
Compare
883a1ab to
0facd37
Compare
2d11675 to
22c17a2
Compare
772202a to
ad56fc1
Compare
392736f to
45efd19
Compare
e9e4b0c to
7abb665
Compare
7abb665 to
e154ee6
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
25.0.1_8-jre→25.0.3_9-jrev2.5.0→v2.6.25.6.0.6792→5.7.0.69703.5.5→3.5.60.8.14→0.8.152.11.0→2.12.04.0.8→4.0.94.0.6→4.1.0Release Notes
softprops/action-gh-release (softprops/action-gh-release)
v2.6.2Compare Source
What's Changed
Other Changes 🔄
Full Changelog: softprops/action-gh-release@v2...v2.6.2
v2.6.1Compare Source
2.6.1is a patch release focused on restoring linked discussion thread creation whendiscussion_category_nameis set. It fixes#764, where the draft-first publish flowstopped carrying the discussion category through the final publish step.
If you still hit an issue after upgrading, please open a report with the bug template and include a minimal repro or sanitized workflow snippet where possible.
What's Changed
Bug fixes 🐛
v2.6.0Compare Source
2.6.0is a minor release centered onprevious_tagsupport forgenerate_release_notes,which lets workflows pin GitHub's comparison base explicitly instead of relying on the default range.
It also includes the recent concurrent asset upload recovery fix, a
working_directorydocs sync,a checked-bundle freshness guard for maintainers, and clearer immutable-prerelease guidance where
GitHub platform behavior imposes constraints on how prerelease asset uploads can be published.
If you still hit an issue after upgrading, please open a report with the bug template and include a minimal repro or sanitized workflow snippet where possible.
What's Changed
Exciting New Features 🎉
Bug fixes 🐛
Other Changes 🔄
v2.5.3Compare Source
2.5.3is a patch release focused on the remaining path-handling and release-selection bugs uncovered after2.5.2.It fixes
#639,#571,#280,#614,#311,#403, and#368.It also adds documentation clarifications for
#541,#645,#542,#393, and#411,where the current behavior is either usage-sensitive or constrained by GitHub platform limits rather than an action-side runtime bug.
If you still hit an issue after upgrading, please open a report with the bug template and include a minimal repro or sanitized workflow snippet where possible.
What's Changed
Bug fixes 🐛
Other Changes 🔄
preserve_order, and special-character asset filename behaviorFull Changelog: softprops/action-gh-release@v2...v2.5.3
v2.5.2Compare Source
2.5.2is a patch release focused on the remaining release-creation and prerelease regressions in the2.5.xbug-fix cycle.It fixes
#705, fixes#708, fixes#740, fixes#741, and fixes#722.Regression testing covers the shared-tag race, prerelease event behavior, dotfile asset labels,
same-filename concurrent uploads, and blocked-tag cleanup behavior.
If you still hit an issue after upgrading, please open a report with the bug template and include a minimal repro or sanitized workflow snippet where possible.
What's Changed
Bug fixes 🐛
New Contributors
Full Changelog: softprops/action-gh-release@v2...v2.5.2
v2.5.1Compare Source
2.5.1is a patch release focused on regressions introduced in2.5.0and on release lookup reliability.It fixes
#713, addresses#703, and fixes#724. Regression testing shows thatcurrent
masterno longer reproduces the finalize-race behavior reported in#704and#709.What's Changed
Bug fixes 🐛
Other Changes 🔄
New Contributors
Full Changelog: softprops/action-gh-release@v2...v2.5.1
SonarSource/sonar-scanner-maven (org.sonarsource.scanner.maven:sonar-maven-plugin)
v5.7.0.6970Compare Source
Release notes - Sonar Scanner for Maven - 5.7
Feature
SCANMAVEN-317 Support encryption of sonar.token, and other new secure properties
SCANMAVEN-332 support
modular-jarartifact typeSCANMAVEN-341 Rework the support of encrypted properties
Maintenance
SCANMAVEN-370 Prepare next development iteration 5.7.0
SCANMAVEN-372 Configure Renovate for sonar-scanner-maven
SCANMAVEN-373 SubmitReview: Use Vault token
SCANMAVEN-374 Unpin internal GitHub actions
SCANMAVEN-376 Use SonarSource/.../sonar-update-center-release@v1 instead of @master
SCANMAVEN-377 Update dependency org.assertj:assertj-core to v3.27.7 [SECURITY]
jacoco/jacoco (org.jacoco:jacoco-maven-plugin)
v0.8.15Compare Source
xmlunit/xmlunit (org.xmlunit:xmlunit-matchers)
v2.12.0Compare Source
bumped xmlunit-assertj3's dependency on assert to 3.27.7.
This is to make people aware of
GHSA-rqfh-9r24-8c9r
XMLUnit itself does not use the affected code in AssertJ so the upgrade is not strictly necessary - and this is why
the xmlunit-assertj module is not updated. In fact the assertions provided by xmlunit-assertj3 are the recommended
upgrade path for users of AssertJ 3.x+.
PRs #320 and
#321
actually made
withDTDParsingDisableddo what it says.This is a bugfix and in a way it is backwards incompatible as it changes default behavior in a way that I intended to
do with XMLUnit 2.6.0 eight years ago.
DocumentBuilderFactoryConfigurer.DefaultWithDTDParsingprovides thebehavior of XMLUnit 2.6.0 to 2.11.0.
PRs #326 by @jmestwa-coder
and #328
spring-projects/spring-boot (org.springframework.boot:spring-boot-starter-parent)
v4.1.0Compare Source
v4.0.7Compare Source
Configuration
📅 Schedule: (in timezone Europe/Paris)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.