Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump spotbugs-annotations from 4.0.1 to 4.0.2 #58

Conversation

dependabot-preview[bot]
Copy link
Contributor

Bumps spotbugs-annotations from 4.0.1 to 4.0.2.

Release notes

Sourced from spotbugs-annotations's releases.

SpotBugs 4.0.2

CHANGELOG

Changelog

Sourced from spotbugs-annotations's changelog.

4.0.2 - 2020-04-15

Fixed

  • GUI was using older version of jdom2 compared to spotbugs in general, bumped it to match at 2.1.1
  • Numerous places in manifest, jnlp files, and sample analysis xml were indicating older asm that was already upgraded to 7.3.1, fixed
  • Added commons-text 1.8 which treats λ properly in xml as it is allowed as λ. Associated test was corrected to use proper junit and λ was changed to λ. The escape only was applicable to html. Commons-lang original treatment was incorrect.
  • Resolved fatal exception in html report if BugInstance contains multiple Class elements (#1025)

Changed

  • Upgrade ASM to 8.0.1 which supports Java14
  • Upgraded junit4 to 4.13
  • Upgraded ant to 1.10.7
  • Upgraded log4j2 to 2.13.1
  • Upgraded from commons-lang2 to commons-lang3 3.10
  • Added commons-text 1.8 due to items deprecated in commons-lang3 and moved to this project
  • replaced usage of org.xml.sax.helpers.XMLReaderFactory (deprecated since jdk9) with javax.xml.parsers.SAXParserFactory
Commits
  • af4a0e2 release SpotBugs v4.0.2
  • dfbac2f fix(deps): bump up ASM to 8.0.1 which supports Java 14
  • 45a15b8 Deprecations since JDK9 replacing usage of org.xml.sax.helpers.XMLReaderFacto...
  • 66dd3e5 Resolved XPathException generating html report with default.xsl
  • 3c72fe3 Resolved XPathException generating html report with fancy.xsl
  • 31ea5b5 [ci] Add library updates and details included in change set to change log.
  • b75b236 [gradle] Bump apache commons to commons lang 3.10 with code import fix
  • 3a7008a [gradle] Bump gui dom4j 2 to 2.1.1 matching the core
  • 2347786 [gradle] Bump log4j 2 to 2.13.1
  • 2d81627 [gradle] Bump ant to 1.10.7 (we are jdk8)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot badge me will comment on this PR with code to add a "Dependabot enabled" badge to your readme

Additionally, you can set the following in the .dependabot/config.yml file in this repo:

  • Update frequency
  • Automerge options (never/patch/minor, and dev/runtime dependencies)
  • Out-of-range updates (receive only lockfile updates, if desired)
  • Security updates (receive only security updates, if desired)

@dependabot-preview dependabot-preview bot added the dependencies Update of dependencies label Apr 15, 2020
@uhafner uhafner merged commit 6ccd115 into master Apr 15, 2020
@dependabot-preview dependabot-preview bot deleted the dependabot/maven/com.github.spotbugs-spotbugs-annotations-4.0.2 branch April 15, 2020 18:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Update of dependencies
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant