Bumps org.owasp:dependency-check-maven from 9.0.6 to 9.0.7.
Release notesSourced from org.owasp:dependency-check-maven's releases.
ChangelogVersion 9.0.7
Refer to the CHANGELOG.md for information about improvements and upgrade notes.
Sourced from org.owasp:dependency-check-maven's changelog.
CommitsVersion 9.0.7 (2023-12-18)
- docs: document insecure configuration for GHSA-qqhq-8r2c-c3f5 (#6315)
- fix: improve memory usage on NVD update (#6321)
- fix: skip pyproject.toml unless it contains
tool.poetry(#6316)- fix: resolve build error that may cause an issue on some JDK versions (#6312)
See the full listing of changes.
f7eab9fbuild: prepare release v9.0.760a3b38docs: prepare release1eedf4cfix: skip pyproject.toml unless it containstool.poetry(#6316)667fde1fix: improve memory usage on NVD update (#6321)8c6a97bbuild(deps): bump actions/github-script from 7.0.0 to 7.0.1 (#6079)1fee73adocs: document insecure configuration for GHSA-qqhq-8r2c-c3f5 (#6315)62ae1a1fix: resolve build error (#6312)793931achore: add codeql back (#6311)b511b03build: Release 9.0.6 (#6310)- See full diff in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)