RAT-532: Bump org.codehaus.plexus:plexus-utils from 3.6.0 to 4.0.3 in /apache-rat-plugin#641
Conversation
Bumps [org.codehaus.plexus:plexus-utils](https://github.com/codehaus-plexus/plexus-utils) from 3.6.0 to 4.0.3. - [Release notes](https://github.com/codehaus-plexus/plexus-utils/releases) - [Commits](codehaus-plexus/plexus-utils@plexus-utils-3.6.0...plexus-utils-4.0.3) --- updated-dependencies: - dependency-name: org.codehaus.plexus:plexus-utils dependency-version: 4.0.3 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <support@github.com>
|
@cstamas sorry to ask so directly - can this version be used with Maven 3.x or is the 4.x version somehow related to Maven4? Thanks |
|
Please stick with plexus-utils 3.x for Maven3 stuff. |
|
@dependabot rebase |
|
The dependabot.yml entry that created this PR has been deleted so this PR can't be rebased. Please close the PR so Dependabot can create a new one with the current dependabot.yml. |
|
Added v4.x to the ignore list as it is for Maven4 only. |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |
|
@cstamas is there a way to fix the security warning: or is this only an 4.x issue and can safely be ignored here? Thanks for your help |
|
codehaus-plexus/plexus-utils#296 (comment) Most probably with 3.6.1? |
|
Seems fix is already in codehaus-plexus/plexus-utils@plexus-utils-3.6.0...plexus-utils-3.x |
Bumps org.codehaus.plexus:plexus-utils from 3.6.0 to 4.0.3.
Release notes
Sourced from org.codehaus.plexus:plexus-utils's releases.
... (truncated)
Commits
c86a34f[maven-release-plugin] prepare release plexus-utils-4.0.3aa38f66Fix release-drafter v7 branch filtering (#322)08018c8Use filter-by-range instead of filter-by-commitish (#320)bcb8a13Scope release-drafter to master branch releases (#318)18fa340Fix release-drafter v7 label validation error (#317)a1d6820Fix release-drafter config for v7 (#316)4ffcc20Restore release-drafter config with correct tag template (#315)d250e15Add Automatic-Module-Name manifest entry (#314)96227deDelete .github/release-drafter.yml0da61cdBump release-drafter/release-drafter from 6 to 7Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)You can disable automated security fix PRs for this repo from the Security Alerts page.