Uploaded image for project: 'Quarkus'
  1. Quarkus
  2. QUARKUS-7112

Bump org.cyclonedx:cyclonedx-core-java from 9.0.5 to 11.0.1 in /bom/application

XMLWordPrintable

    • Icon: Component Upgrade Component Upgrade
    • Resolution: Done
    • Icon: Major Major
    • 3.20.5.GA
    • None
    • team/eng
    • None

      Bumps org.cyclonedx:cyclonedx-core-java from 9.0.5 to 11.0.1.

      Release notes
      Sourced from org.cyclonedx:cyclonedx-core-java's releases.

      cyclonedx-core-java-11.0.1

      What's Changed
      Bug Fixes 🐛

      Fix SchemaFactory configuration of XML validator (GHSA-6fhj-vr9j-g45r) by @​nscuro in CycloneDX/cyclonedx-core-java#737

      Dependency Updates 🤖

      chore(deps): Bump org.jacoco:jacoco-maven-plugin from 0.8.13 to 0.8.14 by @​dependabot[bot] in CycloneDX/cyclonedx-core-java#727
      chore(deps): Bump github/codeql-action from 3.30.4 to 4.30.8 by @​dependabot[bot] in CycloneDX/cyclonedx-core-java#728
      chore(deps): Bump org.apache.maven.plugins:maven-enforcer-plugin from 3.6.1 to 3.6.2 by @​dependabot[bot] in CycloneDX/cyclonedx-core-java#725
      chore(deps): Bump github/codeql-action from 4.30.8 to 4.30.9 by @​dependabot[bot] in CycloneDX/cyclonedx-core-java#729
      chore(deps): Bump com.fasterxml.jackson:jackson-bom from 2.20.0 to 2.20.1 by @​dependabot[bot] in CycloneDX/cyclonedx-core-java#736
      chore(deps): Bump github/codeql-action from 4.30.9 to 4.31.2 by @​dependabot[bot] in CycloneDX/cyclonedx-core-java#735
      chore(deps): Bump actions/upload-artifact from 4.6.2 to 5.0.0 by @​dependabot[bot] in CycloneDX/cyclonedx-core-java#733
      chore(deps): Bump actions/download-artifact from 5.0.0 to 6.0.0 by @​dependabot[bot] in CycloneDX/cyclonedx-core-java#732
      chore(deps): Bump commons-io:commons-io from 2.20.0 to 2.21.0 by @​dependabot[bot] in CycloneDX/cyclonedx-core-java#742
      chore(deps): Bump org.apache.maven.plugins:maven-release-plugin from 3.1.1 to 3.2.0 by @​dependabot[bot] in CycloneDX/cyclonedx-core-java#741
      chore(deps): Bump commons-codec:commons-codec from 1.19.0 to 1.20.0 by @​dependabot[bot] in CycloneDX/cyclonedx-core-java#740
      chore(deps): Bump JamesIves/github-pages-deploy-action from 4.7.3 to 4.7.4 by @​dependabot[bot] in CycloneDX/cyclonedx-core-java#739

      Full Changelog: CycloneDX/cyclonedx-core-java@cyclonedx-core-java-11.0.0...cyclonedx-core-java-11.0.1
      cyclonedx-core-java-11.0.0

      What's Changed
      Breaking Changes 🚨

      Fix CryptoRef array type by @​mr-zepol in CycloneDX/cyclonedx-core-java#628

      Enhancements 🚀

      Polish code for Validation by @​mr-zepol in CycloneDX/cyclonedx-core-java#613
      Add Extra Validations For Metadata by @​mr-zepol in CycloneDX/cyclonedx-core-java#612
      Bump SPDX license list to 3.26.0 by @​nscuro in CycloneDX/cyclonedx-core-java#647
      #640 Added license names to license-mapping.json by @​bilak in CycloneDX/cyclonedx-core-java#641
      chore: GH workflow permissions by @​jkowalleck in CycloneDX/cyclonedx-core-java#654
      feat: Add Apache 2 License by @​jakub-bochenski in CycloneDX/cyclonedx-core-java#677
      feat: Add Eclipse Public License Version 1.0 by @​jakub-bochenski in CycloneDX/cyclonedx-core-java#676
      feat: Add ASL, version 2 and LGPL, version 2.1 by @​jakub-bochenski in CycloneDX/cyclonedx-core-java#675
      feat: Add GPL v2 with the Classpath exception by @​jakub-bochenski in CycloneDX/cyclonedx-core-java#673
      Added mapping for CPL license by @​t-swstk in CycloneDX/cyclonedx-core-java#697
      Adjust release process for new Maven Central publishing by @​nscuro in CycloneDX/cyclonedx-core-java#713
      Bump SPDX license list to 3.27.0 by @​stevenbuccini in CycloneDX/cyclonedx-core-java#715
      Update README with steps to update license list by @​stevenbuccini in CycloneDX/cyclonedx-core-java#720

      Bug Fixes 🐛

      Fix wrong property type in ComponentData.content by @​mr-zepol in CycloneDX/cyclonedx-core-java#627
      Fix failing GitHub Actions builds by @​nscuro in CycloneDX/cyclonedx-core-java#648
      Deserializer Nested Components in Metadata - Regression by @​mr-zepol in CycloneDX/cyclonedx-core-java#703
      Fix publish-snapshot workflow by @​nscuro in CycloneDX/cyclonedx-core-java#719
      Fix names of Maven Central secrets by @​nscuro in CycloneDX/cyclonedx-core-java#721

      Dependency Updates 🤖

      ... (truncated)

      Commits

      700ef74 [maven-release-plugin] prepare release cyclonedx-core-java-11.0.1
      474706a Merge pull request #739 from CycloneDX/dependabot/github_actions/JamesIves/gi...
      2806f1c Merge pull request #740 from CycloneDX/dependabot/maven/commons-codec-commons...
      929aee4 Merge pull request #741 from CycloneDX/dependabot/maven/org.apache.maven.plug...
      61386c5 Merge pull request #742 from CycloneDX/dependabot/maven/commons-io-commons-io...
      731b802 Merge pull request #737 from nscuro/fix-schemafactory-config
      794f524 chore(deps): Bump commons-io:commons-io from 2.20.0 to 2.21.0
      5b737aa chore(deps): Bump org.apache.maven.plugins:maven-release-plugin
      f06bedf chore(deps): Bump commons-codec:commons-codec from 1.19.0 to 1.20.0
      32a029a chore(deps): Bump JamesIves/github-pages-deploy-action
      Additional commits viewable in compare view

      Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.

      Dependabot commands and options

      You can trigger Dependabot actions by commenting on this PR:

      @dependabot rebase will rebase this PR
      @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
      @dependabot merge will merge this PR after your CI passes on it
      @dependabot squash and merge will squash and merge this PR after your CI passes on it
      @dependabot cancel merge will cancel a previously requested merge and block automerging
      @dependabot reopen will reopen this PR if it is closed
      @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
      @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
      @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
      @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
      @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
      You can disable automated security fix PRs for this repo from the Security Alerts page.

              jmartisk@redhat.com Jan Martiska
              msochure@redhat.com Miroslav Sochurek
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

                Created:
                Updated:
                Resolved: