dash-licenses
dash-licenses copied to clipboard
Bump org.cyclonedx:cyclonedx-maven-plugin from 2.7.10 to 2.8.0
Bumps org.cyclonedx:cyclonedx-maven-plugin from 2.7.10 to 2.8.0.
Release notes
Sourced from org.cyclonedx:cyclonedx-maven-plugin's releases.
2.8.0
🚀 New features and improvements
- convert external reference type by value instead of CONSTANT_NAME (#480)
@hboutemy- distribution-intake external reference is more accurate (#477)
@hboutemy- add 'build' lifecycle when CDX 1.5 (#462)
@hboutemy- document SBOM external references (#459)
@hboutemy- improve site generation (#458)
@hboutemy- upgrade to CycloneDX 1.5 (#457)
@hboutemy🐛 Bug Fixes
- check if configured schemaVersion is supported (#479)
@hboutemy📦 Dependency updates
- Bump org.apache.maven.plugins:maven-compiler-plugin from 3.12.1 to 3.13.0 (#478)
@dependabot- Bump actions/checkout from 4.1.1 to 4.1.2 (#474)
@dependabot- Bump org.apache.commons:commons-compress from 1.24.0 to 1.26.0 in /src/it/makeAggregateBom/util (#468)
@dependabot- Bump org.junit:junit-bom from 5.10.1 to 5.10.2 (#465)
@dependabot- Bump release-drafter/release-drafter from 5 to 6 (#464)
@dependabot- Bump commons-codec:commons-codec from 1.16.0 to 1.16.1 (#466)
@dependabot2.7.11
🚀 New features and improvements
- rename convert methohds to explicit project vs dependency (#456)
@hboutemy- cleanup unused code (#455)
@hboutemy- test dependency type=zip for #431 (reverts #9) (#454)
@hboutemy- Support metadata when dependency is any other dependency type than jar (#431)
@AlbGarciam- Add support for custom external references (#428)
@vy- Add a configuration option to skip undeployed artifacts (#435)
@ppkarwasz- use metadata properties in UUID (#441)
@hboutemy- Generate serial numbers deterministically (#420) (#425)
@vy📦 Dependency updates
- define plugin-tools.version property (#453)
@hboutemy- Bump org.apache.maven.plugin-tools:maven-plugin-annotations from 3.10.2 to 3.11.0 (#451)
@dependabot- Bump org.apache.maven.plugins:maven-plugin-report-plugin from 3.10.2 to 3.11.0 (#450)
@dependabot- Bump org.apache.maven.plugins:maven-plugin-plugin from 3.10.2 to 3.11.0 (#449)
@dependabot- Bump org.apache.maven.plugins:maven-compiler-plugin from 3.11.0 to 3.12.1 (#447)
@dependabot- Bump org.apache.maven.plugins:maven-plugin-plugin from 3.10.1 to 3.10.2 (#445)
@dependabot- Bump org.apache.maven.plugins:maven-project-info-reports-plugin from 3.4.5 to 3.5.0 (#442)
@dependabot- Bump org.apache.commons:commons-lang3 from 3.13.0 to 3.14.0 (#443)
@dependabot- Bump org.apache.maven.plugin-tools:maven-plugin-annotations from 3.10.1 to 3.10.2 (#444)
@dependabot
... (truncated)
Commits
90e3817[maven-release-plugin] prepare release cyclonedx-maven-plugin-2.8.0eed838econvert external reference type by value instead of default CONSTANT_NAME3fd83bfBump org.apache.maven.plugins:maven-compiler-plugin343c62dcheck if configured schemaVersion is supportedd001542distribution-intake external reference is more accuratefa5541dBump actions/checkout from 4.1.1 to 4.1.2a43cd05Bump org.apache.commons:commons-compress31ff1f4Bump org.junit:junit-bom from 5.10.1 to 5.10.2ce8a6e7Bump release-drafter/release-drafter from 5 to 616dcb5bBump commons-codec:commons-codec from 1.16.0 to 1.16.1- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)