Bumps org.owasp:dependency-check-maven from 9.0.10 to 9.1.0.
Release notesSourced from org.owasp:dependency-check-maven's releases.
ChangelogVersion 9.1.0
Refer to the CHANGELOG.md for information about improvements and upgrade notes.
Sourced from org.owasp:dependency-check-maven's changelog.
CommitsVersion 9.1.0 (2024-03-31)
- feat: Add v2 support for maven_install.json (#6528)
- build(deps): bump open-vulnerability-client (#6554)
- resolves update issues due to CVSS Metrics 4.0
- build(deps): bump jackson.version from 2.16.0 to 2.16.1 (#6353)
- build(deps): bump org.jsoup:jsoup from 1.16.2 to 1.17.2 (#6362)
- build(deps): bump golang from 1.21.5-alpine to 1.22.1-alpine (#6506)
See the full listing of changes.
e0b9397build: prepare release v9.1.03f1b558docs: prepare release 9.1.0c364269build(deps): bump jackson.version from 2.16.0 to 2.16.1 (#6353)d2c04b5build(deps): bump org.jsoup:jsoup from 1.16.2 to 1.17.2 (#6362)e8c4ca3build(deps): bump open-vulnerability-client (#6554)2e6a231build(deps): bump golang from 1.21.5-alpine to 1.22.1-alpine (#6506)0e183dabuild(deps): bump actions/setup-java from 3 to 4 (#6172)42adde4fix: typo (#6526)f60c867feat: Add v2 support for maven_install.json (#6528)a6a8f21Merge pull request #1 from nutshelllabs/ef/add-maven-install-v2-support- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)