Skip to content

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented May 26, 2023

Mend Renovate

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
org.sonarqube 4.0.0.2929 -> 4.2.1.3168 age adoption passing confidence
com.fasterxml.jackson.core:jackson-databind (source) 2.15.1 -> 2.15.2 age adoption passing confidence
com.fasterxml.jackson.datatype:jackson-datatype-jdk8 2.15.1 -> 2.15.2 age adoption passing confidence
com.fasterxml.jackson.core:jackson-annotations (source) 2.15.1 -> 2.15.2 age adoption passing confidence
com.fasterxml.jackson.core:jackson-core 2.15.1 -> 2.15.2 age adoption passing confidence
com.graphql-java:graphql-java 20.2 -> 20.4 age adoption passing confidence

Release Notes

graphql-java/graphql-java

v20.4: 20.4

This is a special release with only one commit: updating the version of Guava to 32.0.0 to address CVE-2023-2976.

graphql-java shades in selected classes of Guava. Although this library does not use any of the code described in the CVE, we received reports in #​3239 that the Guava POM inside the jar was incorrectly triggering security scanners. We'd prefer to keep those security scanners happy and upgrade the Guava version.

What's Changed

Full Changelog: graphql-java/graphql-java@v20.3...v20.4

v20.3: 20.3

This is a special release with only one commit: reverting stricter parseValue scalar coercion. It is a backport of https://github.com/graphql-java/graphql-java/pull/3186

We received feedback that the stricter coercion was difficult without a migration pathway. The next release will include an input interceptor to enable monitoring and/or custom modification of inputs.

What's Changed

Full Changelog: graphql-java/graphql-java@v20.2...v20.3


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot added the dependencies Pull requests that update a dependency file label May 26, 2023
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from f003c35 to 88d6565 Compare May 29, 2023 03:02
@renovate renovate bot changed the title chore(deps): update plugin org.sonarqube to v4.1.0.3113 chore(deps): update all non-major dependencies May 29, 2023
@renovate renovate bot force-pushed the renovate/all-minor-patch branch 3 times, most recently from 466bce5 to 4573ea0 Compare May 31, 2023 17:23
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 4573ea0 to 5701e61 Compare June 8, 2023 08:13
@renovate renovate bot force-pushed the renovate/all-minor-patch branch from 5701e61 to 4cd2e0a Compare June 12, 2023 12:48
@sonarqubecloud
Copy link

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
No Duplication information No Duplication information

@oliemansm oliemansm merged commit 7a73ac0 into master Jun 14, 2023
@oliemansm oliemansm deleted the renovate/all-minor-patch branch June 14, 2023 13:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant