Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update Dependencies #1251

Merged
merged 196 commits into from
Oct 24, 2023
Merged

Update Dependencies #1251

merged 196 commits into from
Oct 24, 2023

Conversation

ramsessanchez
Copy link
Contributor

A new minor version of core has not been released in some time, issue #1038 raises the point that the Okhttp3 dependency is using a vulnerable dependency and should be updated.

baywet and others added 30 commits June 26, 2023 10:37
Signed-off-by: Vincent Biret <[email protected]>
Signed-off-by: Vincent Biret <[email protected]>
Bumps [dependabot/fetch-metadata](https://github.com/dependabot/fetch-metadata) from 1.5.1 to 1.6.0.
- [Release notes](https://github.com/dependabot/fetch-metadata/releases)
- [Commits](dependabot/fetch-metadata@v1.5.1...v1.6.0)

---
updated-dependencies:
- dependency-name: dependabot/fetch-metadata
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
…/dependabot/fetch-metadata-1.6.0

chore(deps): bump dependabot/fetch-metadata from 1.5.1 to 1.6.0
Bumps [guava](https://github.com/google/guava) from 32.0.1-jre to 32.1.0-jre.
- [Release notes](https://github.com/google/guava/releases)
- [Commits](https://github.com/google/guava/commits)

---
updated-dependencies:
- dependency-name: com.google.guava:guava
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
…le.guava-guava-32.1.0-jre

chore(deps): bump guava from 32.0.1-jre to 32.1.0-jre
Bumps [guava](https://github.com/google/guava) from 32.1.0-jre to 32.1.1-jre.
- [Release notes](https://github.com/google/guava/releases)
- [Commits](https://github.com/google/guava/commits)

---
updated-dependencies:
- dependency-name: com.google.guava:guava
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [com.google.guava:guava](https://github.com/google/guava) from 32.0.1-jre to 32.1.1-jre.
- [Release notes](https://github.com/google/guava/releases)
- [Commits](https://github.com/google/guava/commits)

---
updated-dependencies:
- dependency-name: com.google.guava:guava
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [com.google.guava:guava](https://github.com/google/guava) from 32.0.1-jre to 32.1.1-jre.
- [Release notes](https://github.com/google/guava/releases)
- [Commits](https://github.com/google/guava/commits)

---
updated-dependencies:
- dependency-name: com.google.guava:guava
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
…/com.google.guava-guava-32.1.1-jre

chore(deps): bump com.google.guava:guava from 32.0.1-jre to 32.1.1-jre in /android
…gle.guava-guava-32.1.1-jre

chore(deps): bump com.google.guava:guava from 32.0.1-jre to 32.1.1-jre
…le.guava-guava-32.1.1-jre

chore(deps): bump guava from 32.1.0-jre to 32.1.1-jre
…t as FabricBot replacement

Owners of the FabricBot configuration should have received email notification. The same information contained in the email is published internally at: https://aka.ms/gim/fabricbot. Details on the replacement service and the syntax of the new yaml configuration file is available publicly at: https://microsoft.github.io/GitOps/policies/resource-management.html

Please review and merge this PR to complete the process of onboarding to the new service.
FabricBot: Onboarding to GitOps.ResourceManagement because of FabricBot decommissioning
Bumps [azure-core](https://github.com/Azure/azure-sdk-for-java) from 1.40.0 to 1.41.0.
- [Release notes](https://github.com/Azure/azure-sdk-for-java/releases)
- [Commits](Azure/azure-sdk-for-java@azure-core_1.40.0...azure-core_1.41.0)

---
updated-dependencies:
- dependency-name: com.azure:azure-core
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [com.azure:azure-core](https://github.com/Azure/azure-sdk-for-java) from 1.40.0 to 1.41.0.
- [Release notes](https://github.com/Azure/azure-sdk-for-java/releases)
- [Commits](Azure/azure-sdk-for-java@azure-core_1.40.0...azure-core_1.41.0)

---
updated-dependencies:
- dependency-name: com.azure:azure-core
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
…e-azure-core-1.41.0

chore(deps): bump azure-core from 1.40.0 to 1.41.0
…/com.azure-azure-core-1.41.0

chore(deps): bump com.azure:azure-core from 1.40.0 to 1.41.0 in /android
Bumps [com.azure:azure-identity](https://github.com/Azure/azure-sdk-for-java) from 1.9.1 to 1.9.2.
- [Release notes](https://github.com/Azure/azure-sdk-for-java/releases)
- [Commits](Azure/azure-sdk-for-java@azure-identity_1.9.1...azure-identity_1.9.2)

---
updated-dependencies:
- dependency-name: com.azure:azure-identity
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [com.azure:azure-identity](https://github.com/Azure/azure-sdk-for-java) from 1.9.1 to 1.9.2.
- [Release notes](https://github.com/Azure/azure-sdk-for-java/releases)
- [Commits](Azure/azure-sdk-for-java@azure-identity_1.9.1...azure-identity_1.9.2)

---
updated-dependencies:
- dependency-name: com.azure:azure-identity
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
baywet and others added 15 commits October 17, 2023 06:47
…d/com.squareup.okhttp3-okhttp-4.12.0

chore(deps): bump com.squareup.okhttp3:okhttp from 4.11.0 to 4.12.0 in /android
…uareup.okhttp3-okhttp-4.12.0

chore(deps): bump com.squareup.okhttp3:okhttp from 4.11.0 to 4.12.0
Bumps [com.azure:azure-core](https://github.com/Azure/azure-sdk-for-java) from 1.44.0 to 1.44.1.
- [Release notes](https://github.com/Azure/azure-sdk-for-java/releases)
- [Commits](Azure/azure-sdk-for-java@azure-core_1.44.0...azure-core_1.44.1)

---
updated-dependencies:
- dependency-name: com.azure:azure-core
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [com.azure:azure-core](https://github.com/Azure/azure-sdk-for-java) from 1.44.0 to 1.44.1.
- [Release notes](https://github.com/Azure/azure-sdk-for-java/releases)
- [Commits](Azure/azure-sdk-for-java@azure-core_1.44.0...azure-core_1.44.1)

---
updated-dependencies:
- dependency-name: com.azure:azure-core
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
…ure-azure-core-1.44.1

chore(deps): bump com.azure:azure-core from 1.44.0 to 1.44.1
…d/com.azure-azure-core-1.44.1

chore(deps): bump com.azure:azure-core from 1.44.0 to 1.44.1 in /android
Bumps [com.azure:azure-identity](https://github.com/Azure/azure-sdk-for-java) from 1.10.3 to 1.10.4.
- [Release notes](https://github.com/Azure/azure-sdk-for-java/releases)
- [Commits](Azure/azure-sdk-for-java@azure-identity_1.10.3...azure-identity_1.10.4)

---
updated-dependencies:
- dependency-name: com.azure:azure-identity
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
…s/interactiveBrowserSample/com.azure-azure-identity-1.10.4

chore(deps): bump com.azure:azure-identity from 1.10.3 to 1.10.4 in /samples/interactiveBrowserSample
Bumps [com.azure:azure-core](https://github.com/Azure/azure-sdk-for-java) from 1.44.0 to 1.44.1.
- [Release notes](https://github.com/Azure/azure-sdk-for-java/releases)
- [Commits](Azure/azure-sdk-for-java@azure-core_1.44.0...azure-core_1.44.1)

---
updated-dependencies:
- dependency-name: com.azure:azure-core
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
…re-azure-core-1.44.1

chore(deps): bump com.azure:azure-core from 1.44.0 to 1.44.1
Bumps [com.azure:azure-identity](https://github.com/Azure/azure-sdk-for-java) from 1.10.3 to 1.10.4.
- [Release notes](https://github.com/Azure/azure-sdk-for-java/releases)
- [Commits](Azure/azure-sdk-for-java@azure-identity_1.10.3...azure-identity_1.10.4)

---
updated-dependencies:
- dependency-name: com.azure:azure-identity
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
…s/deviceCodeSample/com.azure-azure-identity-1.10.4

chore(deps): bump com.azure:azure-identity from 1.10.3 to 1.10.4 in /samples/deviceCodeSample
Bumps com.github.spotbugs from 5.2.0 to 5.2.1.

---
updated-dependencies:
- dependency-name: com.github.spotbugs
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
…s/deviceCodeSample/com.github.spotbugs-5.2.1

chore(deps): bump com.github.spotbugs from 5.2.0 to 5.2.1 in /samples/deviceCodeSample
Update changelog for version 2.0.20
@ramsessanchez ramsessanchez requested a review from a team as a code owner October 23, 2023 22:04
andrueastman
andrueastman previously approved these changes Oct 24, 2023
baywet
baywet previously approved these changes Oct 24, 2023
calebkiage
calebkiage previously approved these changes Oct 24, 2023
@ramsessanchez ramsessanchez temporarily deployed to maven_central_snapshot October 24, 2023 15:13 — with GitHub Actions Inactive
@sonarcloud
Copy link

sonarcloud bot commented Oct 24, 2023

Kudos, SonarCloud Quality Gate passed!    Quality Gate passed

Bug A 0 Bugs
Vulnerability A 0 Vulnerabilities
Security Hotspot A 0 Security Hotspots
Code Smell A 0 Code Smells

No Coverage information No Coverage information
0.0% 0.0% Duplication

@ramsessanchez ramsessanchez merged commit 0d72a1e into master Oct 24, 2023
19 of 20 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

CVE-2023-3635: related to dependency com.squareup.okio:okio-jvm:3.0.0
5 participants