Skip to content

Conversation

@dependabot-preview
Copy link
Contributor

@dependabot-preview dependabot-preview bot commented Oct 31, 2019

Bumps findsecbugs-plugin from 1.10.0 to 1.10.1.

Release notes

Sourced from findsecbugs-plugin's releases.

Version 1.10.1 - HacktoberFIX

This minor update is there to introduce a fix : find-sec-bugs/find-sec-bugs#526

A new detector Pebble template injection is also added. Thanks to @​sa160690.

Messages from many detectors were also updated. Multiple broken links or out-dated links were corrected. find-sec-bugs/find-sec-bugs#528

> sha1sum findsecbugs-cli-1.10.1.zip
fad67bc6c31032dd3cf7419c1f4abe2376658757 *findsecbugs-cli-1.10.1.zip

> md5sum findsecbugs-cli-1.10.1.zip
1eecbef120b61e0ce4870c38fe28fccd *findsecbugs-cli-1.10.1.zip
Commits
  • 7f7e491 Update the description for Pebble injection. #521
  • b3d423b Merge branch 'master' of github.com:h3xstream/find-sec-bugs
  • 4f42487 Updating link to https when appropriate + Multiple link updated to the most r...
  • 2e48505 Merge pull request #527 from h3xstream/master
  • baa812d Fix key misspell #526
  • 5b8c68a Merge pull request #522 from sa160690/master
  • f476ed4 Issue#521: Detect Pebble template library #521
  • 4e3e44c Merge pull request #520 from h3xstream/master
  • 25f8dcd Miscellaneous code change for readability, unnecessary code and general good ...
  • 4cb69d7 Move the badges lower to avoid overflow
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

Dependabot will merge this PR once CI passes on it, as requested by @AndyScherzinger.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in your Dependabot dashboard:

  • Update frequency (including time of day and day of week)
  • Pull request limits (per update run and/or open at any time)
  • Automerge options (never/patch/minor, and dev/runtime dependencies)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

@dependabot-preview dependabot-preview bot added 3. to review dependencies Pull requests that update a dependency file labels Oct 31, 2019
@nextcloud-android-bot
Copy link
Collaborator

APK file: https://www.kaminsky.me/nc-dev/android-artifacts/11477.apk

qrcode

To test this change/fix you can simply download above APK file and install and test it in parallel to your existing Nextcloud app.

@nextcloud-android-bot
Copy link
Collaborator

@nextcloud-android-bot
Copy link
Collaborator

Codacy

304

Lint

TypemasterPR
Warnings5959
Errors00

SpotBugs (new)

Warning TypeNumber
Bad practice Warnings26
Correctness Warnings69
Internationalization Warnings13
Malicious code vulnerability Warnings5
Multithreaded correctness Warnings9
Performance Warnings119
Security Warnings44
Dodgy code Warnings138
Total423

SpotBugs (master)

Warning TypeNumber
Bad practice Warnings26
Correctness Warnings69
Internationalization Warnings13
Malicious code vulnerability Warnings5
Multithreaded correctness Warnings9
Performance Warnings119
Security Warnings44
Dodgy code Warnings138
Total423

@dependabot-preview
Copy link
Contributor Author

One of your CI runs failed on this pull request, so Dependabot won't merge it.

Dependabot will still automatically merge this pull request if you amend it and your tests pass.

@AndyScherzinger AndyScherzinger merged commit e3280b0 into master Oct 31, 2019
@delete-merged-branch delete-merged-branch bot deleted the dependabot/gradle/com.h3xstream.findsecbugs-findsecbugs-plugin-1.10.1 branch October 31, 2019 22:35
@AndyScherzinger AndyScherzinger added this to the Nextcloud App 3.10.0 milestone Oct 31, 2019
tobiasKaminsky added a commit that referenced this pull request Nov 1, 2019
e3280b0 Merge pull request #4775 from nextcloud/dependabot/gradle/com.h3xstream.findsecbugs-findsecbugs-plugin-1.10.1
575cd01 Bump findsecbugs-plugin from 1.10.0 to 1.10.1
946e5c2 Merge pull request #4768 from nextcloud/colorNames
78ed97c [tx-robot] updated from transifex
f77b5bd daily dev 20191031
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

3. to review dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants