This is an automated email from the ASF dual-hosted git repository.
jbonofre pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/arrow-java.git
The following commit(s) were added to refs/heads/main by this push:
new fcba1b034 MINOR: Bump org.cyclonedx:cyclonedx-maven-plugin from 2.9.1
to 2.9.2 (#1198)
fcba1b034 is described below
commit fcba1b0345faed30621863af85a102c6d2fc1362
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
AuthorDate: Wed Jul 1 07:51:48 2026 +0200
MINOR: Bump org.cyclonedx:cyclonedx-maven-plugin from 2.9.1 to 2.9.2 (#1198)
Bumps
[org.cyclonedx:cyclonedx-maven-plugin](https://github.com/CycloneDX/cyclonedx-maven-plugin)
from 2.9.1 to 2.9.2.
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/CycloneDX/cyclonedx-maven-plugin/releases">org.cyclonedx:cyclonedx-maven-plugin's
releases</a>.</em></p>
<blockquote>
<h2>2.9.2</h2>
<!-- raw HTML omitted -->
<h2>🚀 New features and improvements</h2>
<ul>
<li>chore: upgrade maven-dependency-analyzer/asm, support Java 25 (<a
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/630">#630</a>)
<a href="https://github.com/shihyuho"><code>@​shihyuho</code></a></li>
</ul>
<h2>📦 Dependency updates</h2>
<ul>
<li>Bump commons-codec:commons-codec from 1.17.1 to 1.22.0 (<a
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/650">#650</a>)
@<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
<li>Bump org.apache.commons:commons-lang3 from 3.17.0 to 3.19.0 (<a
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/622">#622</a>)
@<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
<li>chore: upgrade maven-dependency-analyzer/asm, support Java 25 (<a
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/630">#630</a>)
<a href="https://github.com/shihyuho"><code>@​shihyuho</code></a></li>
</ul>
<h2>đź”§ Build</h2>
<ul>
<li>update scm urls (<a
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/662">#662</a>)
<a href="https://github.com/hboutemy"><code>@​hboutemy</code></a></li>
<li>switch to Central Publishing Portal (<a
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/659">#659</a>)
<a href="https://github.com/hboutemy"><code>@​hboutemy</code></a></li>
<li>Bump org.apache.maven.plugins:maven-project-info-reports-plugin from
3.8.0 to 3.9.0 (<a
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/655">#655</a>)
@<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
<li>Bump plugin-tools.version from 3.15.0 to 3.15.2 (<a
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/654">#654</a>)
@<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
<li>Bump io.takari.maven.plugins:takari-plugin-integration-testing from
3.0.1 to 3.1.1 (<a
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/616">#616</a>)
@<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
<li>Bump org.apache.maven.plugins:maven-invoker-plugin from 3.7.0 to
3.9.1 (<a
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/617">#617</a>)
@<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
<li>Bump io.takari.maven.plugins:takari-plugin-testing from 3.0.0 to
3.1.1 (<a
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/618">#618</a>)
@<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
<li>Bump org.apache.maven.plugins:maven-compiler-plugin from 3.13.0 to
3.14.1 (<a
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/621">#621</a>)
@<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
<li>Bump actions/checkout from 6.0.1 to 6.0.2 (<a
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/639">#639</a>)
@<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
<li>Bump actions/setup-java from 4 to 5 (<a
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/620">#620</a>)
@<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
<li>use shields.io badge (<a
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/648">#648</a>)
<a href="https://github.com/hboutemy"><code>@​hboutemy</code></a></li>
<li>Bump actions/checkout from 6.0.0 to 6.0.1 (<a
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/635">#635</a>)
@<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
<li>Bump actions/checkout from 4.2.2 to 6.0.0 (<a
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/633">#633</a>)
@<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
<li>chore: GH workflow permissions (<a
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/606">#606</a>)
<a
href="https://github.com/jkowalleck"><code>@​jkowalleck</code></a></li>
<li>simplify compiler release configuration (<a
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/518">#518</a>)
<a href="https://github.com/hboutemy"><code>@​hboutemy</code></a></li>
<li>Bump JamesIves/github-pages-deploy-action from 4.7.1 to 4.7.3 (<a
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/590">#590</a>)
@<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li>
<li>upgrade to Doxia 2: m-site-p and skin (<a
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/593">#593</a>)
<a href="https://github.com/hboutemy"><code>@​hboutemy</code></a></li>
<li>add Reproducible Central report (<a
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/592">#592</a>)
<a href="https://github.com/hboutemy"><code>@​hboutemy</code></a></li>
</ul>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/CycloneDX/cyclonedx-maven-plugin/commit/0fe189d0cd2c80acb1f518e53fbb703456e6534a"><code>0fe189d</code></a>
[maven-release-plugin] prepare release cyclonedx-maven-plugin-2.9.2</li>
<li><a
href="https://github.com/CycloneDX/cyclonedx-maven-plugin/commit/96c218c71646aa987d5778b9f0f035f40ff45239"><code>96c218c</code></a>
update scm urls</li>
<li><a
href="https://github.com/CycloneDX/cyclonedx-maven-plugin/commit/0fe08b4215263965690c0a0a022c1fdbc396cad8"><code>0fe08b4</code></a>
Revert "Bump JamesIves/github-pages-deploy-action from 4.7.3 to
4.8.0"</li>
<li><a
href="https://github.com/CycloneDX/cyclonedx-maven-plugin/commit/6779e48e4108e5c1881109f39ebda293311ec591"><code>6779e48</code></a>
Revert "Bump release-drafter/release-drafter from 6 to 7"</li>
<li><a
href="https://github.com/CycloneDX/cyclonedx-maven-plugin/commit/955fead7657740f51b738de11961d4c1eb233bb3"><code>955fead</code></a>
switch to Central Publishing Portal</li>
<li><a
href="https://github.com/CycloneDX/cyclonedx-maven-plugin/commit/50dbac7e4cd969764e2bfb8e971b0fcf5fcbebba"><code>50dbac7</code></a>
Bump release-drafter/release-drafter from 6 to 7</li>
<li><a
href="https://github.com/CycloneDX/cyclonedx-maven-plugin/commit/d50bc582155e15a6a1560edab0f1e94d019601e1"><code>d50bc58</code></a>
Bump org.apache.maven.plugins:maven-project-info-reports-plugin</li>
<li><a
href="https://github.com/CycloneDX/cyclonedx-maven-plugin/commit/1034644886969032df5552fd4132102baeca40c8"><code>1034644</code></a>
Bump plugin-tools.version from 3.15.0 to 3.15.2</li>
<li><a
href="https://github.com/CycloneDX/cyclonedx-maven-plugin/commit/018ab8e4fdf3b73049497a76bea952983b88389f"><code>018ab8e</code></a>
Bump commons-codec:commons-codec from 1.17.1 to 1.22.0</li>
<li><a
href="https://github.com/CycloneDX/cyclonedx-maven-plugin/commit/e3597051e8c6eb694e9ccd044b9b5a0829166add"><code>e359705</code></a>
Bump JamesIves/github-pages-deploy-action from 4.7.3 to 4.8.0</li>
<li>Additional commits viewable in <a
href="https://github.com/CycloneDX/cyclonedx-maven-plugin/compare/cyclonedx-maven-plugin-2.9.1...cyclonedx-maven-plugin-2.9.2">compare
view</a></li>
</ul>
</details>
<br />
[](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't
alter it yourself. You can also trigger a rebase manually by commenting
`@dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
<details>
<summary>Dependabot commands and options</summary>
<br />
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore this major version` will close this PR and stop
Dependabot creating any more for this major version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this minor version` will close this PR and stop
Dependabot creating any more for this minor version (unless you reopen
the PR or upgrade to it yourself)
- `@dependabot ignore this dependency` will close this PR and stop
Dependabot creating any more for this dependency (unless you reopen the
PR or upgrade to it yourself)
</details>
Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot]
<49699333+dependabot[bot]@users.noreply.github.com>
---
pom.xml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/pom.xml b/pom.xml
index c39eafc20..6a97ac462 100644
--- a/pom.xml
+++ b/pom.xml
@@ -522,7 +522,7 @@ under the License.
<plugin>
<groupId>org.cyclonedx</groupId>
<artifactId>cyclonedx-maven-plugin</artifactId>
- <version>2.9.1</version>
+ <version>2.9.2</version>
</plugin>
<plugin>
<groupId>org.apache.drill.tools</groupId>