Bump org.codehaus.plexus:plexus-io from 3.4.2 to 3.5.0#421
Conversation
|
We are facing a CVE-2020-10683 vulnerability in dom4j:
|
|
@dependabot rebase |
Bumps [org.codehaus.plexus:plexus-io](https://github.com/codehaus-plexus/plexus-io) from 3.4.2 to 3.5.0. - [Release notes](https://github.com/codehaus-plexus/plexus-io/releases) - [Changelog](https://github.com/codehaus-plexus/plexus-io/blob/master/ReleaseNotes.md) - [Commits](codehaus-plexus/plexus-io@plexus-io-3.4.2...plexus-io-3.5.0) --- updated-dependencies: - dependency-name: org.codehaus.plexus:plexus-io dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
d5bee4e to
2d0b82a
Compare
Bumps org.codehaus.plexus:plexus-io from 3.4.2 to 3.5.0.
Release notes
Sourced from org.codehaus.plexus:plexus-io's releases.
Commits
2c50803[maven-release-plugin] prepare release plexus-io-3.5.0b8e7d56(CI) skip Deploy06bba28Update test sisu to 0.9.0.M3 (test scope)d7a73bb---120d4f8Bump org.eclipse.sisu:org.eclipse.sisu.inject from 0.9.0.M2 to 0.9.0.M3aff4d36Bump org.codehaus.plexus:plexus-xml from 3.0.0 to 3.0.18f804deBump org.codehaus.plexus:plexus-utils from 4.0.0 to 4.0.199c666aBump commons-io:commons-io from 2.16.0 to 2.16.128bb843Bump commons-io:commons-io from 2.15.1 to 2.16.097207afBump org.codehaus.plexus:plexus from 16 to 17You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)