-
Component Upgrade
-
Resolution: Done
-
Major
-
None
-
None
-
False
-
-
False
-
---
-
-
Bumps org.cyclonedx:cyclonedx-core-java from 9.0.5 to 11.0.1.
Release notes
Sourced from org.cyclonedx:cyclonedx-core-java's releases.
cyclonedx-core-java-11.0.1
What's Changed
Bug Fixes 🐛
Fix SchemaFactory configuration of XML validator (GHSA-6fhj-vr9j-g45r) by @nscuro in CycloneDX/cyclonedx-core-java#737
Dependency Updates 🤖
chore(deps): Bump org.jacoco:jacoco-maven-plugin from 0.8.13 to 0.8.14 by @dependabot[bot] in CycloneDX/cyclonedx-core-java#727
chore(deps): Bump github/codeql-action from 3.30.4 to 4.30.8 by @dependabot[bot] in CycloneDX/cyclonedx-core-java#728
chore(deps): Bump org.apache.maven.plugins:maven-enforcer-plugin from 3.6.1 to 3.6.2 by @dependabot[bot] in CycloneDX/cyclonedx-core-java#725
chore(deps): Bump github/codeql-action from 4.30.8 to 4.30.9 by @dependabot[bot] in CycloneDX/cyclonedx-core-java#729
chore(deps): Bump com.fasterxml.jackson:jackson-bom from 2.20.0 to 2.20.1 by @dependabot[bot] in CycloneDX/cyclonedx-core-java#736
chore(deps): Bump github/codeql-action from 4.30.9 to 4.31.2 by @dependabot[bot] in CycloneDX/cyclonedx-core-java#735
chore(deps): Bump actions/upload-artifact from 4.6.2 to 5.0.0 by @dependabot[bot] in CycloneDX/cyclonedx-core-java#733
chore(deps): Bump actions/download-artifact from 5.0.0 to 6.0.0 by @dependabot[bot] in CycloneDX/cyclonedx-core-java#732
chore(deps): Bump commons-io:commons-io from 2.20.0 to 2.21.0 by @dependabot[bot] in CycloneDX/cyclonedx-core-java#742
chore(deps): Bump org.apache.maven.plugins:maven-release-plugin from 3.1.1 to 3.2.0 by @dependabot[bot] in CycloneDX/cyclonedx-core-java#741
chore(deps): Bump commons-codec:commons-codec from 1.19.0 to 1.20.0 by @dependabot[bot] in CycloneDX/cyclonedx-core-java#740
chore(deps): Bump JamesIves/github-pages-deploy-action from 4.7.3 to 4.7.4 by @dependabot[bot] in CycloneDX/cyclonedx-core-java#739
Full Changelog: CycloneDX/cyclonedx-core-java@cyclonedx-core-java-11.0.0...cyclonedx-core-java-11.0.1
cyclonedx-core-java-11.0.0
What's Changed
Breaking Changes 🚨
Fix CryptoRef array type by @mr-zepol in CycloneDX/cyclonedx-core-java#628
Enhancements 🚀
Polish code for Validation by @mr-zepol in CycloneDX/cyclonedx-core-java#613
Add Extra Validations For Metadata by @mr-zepol in CycloneDX/cyclonedx-core-java#612
Bump SPDX license list to 3.26.0 by @nscuro in CycloneDX/cyclonedx-core-java#647
#640 Added license names to license-mapping.json by @bilak in CycloneDX/cyclonedx-core-java#641
chore: GH workflow permissions by @jkowalleck in CycloneDX/cyclonedx-core-java#654
feat: Add Apache 2 License by @jakub-bochenski in CycloneDX/cyclonedx-core-java#677
feat: Add Eclipse Public License Version 1.0 by @jakub-bochenski in CycloneDX/cyclonedx-core-java#676
feat: Add ASL, version 2 and LGPL, version 2.1 by @jakub-bochenski in CycloneDX/cyclonedx-core-java#675
feat: Add GPL v2 with the Classpath exception by @jakub-bochenski in CycloneDX/cyclonedx-core-java#673
Added mapping for CPL license by @t-swstk in CycloneDX/cyclonedx-core-java#697
Adjust release process for new Maven Central publishing by @nscuro in CycloneDX/cyclonedx-core-java#713
Bump SPDX license list to 3.27.0 by @stevenbuccini in CycloneDX/cyclonedx-core-java#715
Update README with steps to update license list by @stevenbuccini in CycloneDX/cyclonedx-core-java#720
Bug Fixes 🐛
Fix wrong property type in ComponentData.content by @mr-zepol in CycloneDX/cyclonedx-core-java#627
Fix failing GitHub Actions builds by @nscuro in CycloneDX/cyclonedx-core-java#648
Deserializer Nested Components in Metadata - Regression by @mr-zepol in CycloneDX/cyclonedx-core-java#703
Fix publish-snapshot workflow by @nscuro in CycloneDX/cyclonedx-core-java#719
Fix names of Maven Central secrets by @nscuro in CycloneDX/cyclonedx-core-java#721
Dependency Updates 🤖
... (truncated)
Commits
700ef74 [maven-release-plugin] prepare release cyclonedx-core-java-11.0.1
474706a Merge pull request #739 from CycloneDX/dependabot/github_actions/JamesIves/gi...
2806f1c Merge pull request #740 from CycloneDX/dependabot/maven/commons-codec-commons...
929aee4 Merge pull request #741 from CycloneDX/dependabot/maven/org.apache.maven.plug...
61386c5 Merge pull request #742 from CycloneDX/dependabot/maven/commons-io-commons-io...
731b802 Merge pull request #737 from nscuro/fix-schemafactory-config
794f524 chore(deps): Bump commons-io:commons-io from 2.20.0 to 2.21.0
5b737aa chore(deps): Bump org.apache.maven.plugins:maven-release-plugin
f06bedf chore(deps): Bump commons-codec:commons-codec from 1.19.0 to 1.20.0
32a029a chore(deps): Bump JamesIves/github-pages-deploy-action
Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebase will rebase this PR
@dependabot recreate will recreate this PR, overwriting any edits that have been made to it
@dependabot merge will merge this PR after your CI passes on it
@dependabot squash and merge will squash and merge this PR after your CI passes on it
@dependabot cancel merge will cancel a previously requested merge and block automerging
@dependabot reopen will reopen this PR if it is closed
@dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
@dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
@dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
@dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the Security Alerts page.
- links to
-
RHSA-2026:158794
Red Hat build of Quarkus 3.20.5 release and security update