This is an automated email from the ASF dual-hosted git repository.

jbonofre pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/arrow-java.git


The following commit(s) were added to refs/heads/main by this push:
     new fcba1b034 MINOR: Bump org.cyclonedx:cyclonedx-maven-plugin from 2.9.1 
to 2.9.2 (#1198)
fcba1b034 is described below

commit fcba1b0345faed30621863af85a102c6d2fc1362
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
AuthorDate: Wed Jul 1 07:51:48 2026 +0200

    MINOR: Bump org.cyclonedx:cyclonedx-maven-plugin from 2.9.1 to 2.9.2 (#1198)
    
    Bumps
    
[org.cyclonedx:cyclonedx-maven-plugin](https://github.com/CycloneDX/cyclonedx-maven-plugin)
    from 2.9.1 to 2.9.2.
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    
href="https://github.com/CycloneDX/cyclonedx-maven-plugin/releases";>org.cyclonedx:cyclonedx-maven-plugin's
    releases</a>.</em></p>
    <blockquote>
    <h2>2.9.2</h2>
    <!-- raw HTML omitted -->
    <h2>🚀 New features and improvements</h2>
    <ul>
    <li>chore: upgrade maven-dependency-analyzer/asm, support Java 25 (<a
    
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/630";>#630</a>)
    <a href="https://github.com/shihyuho";><code>@​shihyuho</code></a></li>
    </ul>
    <h2>📦 Dependency updates</h2>
    <ul>
    <li>Bump commons-codec:commons-codec from 1.17.1 to 1.22.0 (<a
    
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/650";>#650</a>)
    @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
    <li>Bump org.apache.commons:commons-lang3 from 3.17.0 to 3.19.0 (<a
    
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/622";>#622</a>)
    @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
    <li>chore: upgrade maven-dependency-analyzer/asm, support Java 25 (<a
    
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/630";>#630</a>)
    <a href="https://github.com/shihyuho";><code>@​shihyuho</code></a></li>
    </ul>
    <h2>đź”§ Build</h2>
    <ul>
    <li>update scm urls (<a
    
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/662";>#662</a>)
    <a href="https://github.com/hboutemy";><code>@​hboutemy</code></a></li>
    <li>switch to Central Publishing Portal (<a
    
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/659";>#659</a>)
    <a href="https://github.com/hboutemy";><code>@​hboutemy</code></a></li>
    <li>Bump org.apache.maven.plugins:maven-project-info-reports-plugin from
    3.8.0 to 3.9.0 (<a
    
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/655";>#655</a>)
    @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
    <li>Bump plugin-tools.version from 3.15.0 to 3.15.2 (<a
    
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/654";>#654</a>)
    @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
    <li>Bump io.takari.maven.plugins:takari-plugin-integration-testing from
    3.0.1 to 3.1.1 (<a
    
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/616";>#616</a>)
    @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
    <li>Bump org.apache.maven.plugins:maven-invoker-plugin from 3.7.0 to
    3.9.1 (<a
    
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/617";>#617</a>)
    @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
    <li>Bump io.takari.maven.plugins:takari-plugin-testing from 3.0.0 to
    3.1.1 (<a
    
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/618";>#618</a>)
    @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
    <li>Bump org.apache.maven.plugins:maven-compiler-plugin from 3.13.0 to
    3.14.1 (<a
    
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/621";>#621</a>)
    @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
    <li>Bump actions/checkout from 6.0.1 to 6.0.2 (<a
    
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/639";>#639</a>)
    @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
    <li>Bump actions/setup-java from 4 to 5 (<a
    
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/620";>#620</a>)
    @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
    <li>use shields.io badge (<a
    
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/648";>#648</a>)
    <a href="https://github.com/hboutemy";><code>@​hboutemy</code></a></li>
    <li>Bump actions/checkout from 6.0.0 to 6.0.1 (<a
    
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/635";>#635</a>)
    @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
    <li>Bump actions/checkout from 4.2.2 to 6.0.0 (<a
    
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/633";>#633</a>)
    @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
    <li>chore: GH workflow permissions (<a
    
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/606";>#606</a>)
    <a
    href="https://github.com/jkowalleck";><code>@​jkowalleck</code></a></li>
    <li>simplify compiler release configuration (<a
    
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/518";>#518</a>)
    <a href="https://github.com/hboutemy";><code>@​hboutemy</code></a></li>
    <li>Bump JamesIves/github-pages-deploy-action from 4.7.1 to 4.7.3 (<a
    
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/590";>#590</a>)
    @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
    <li>upgrade to Doxia 2: m-site-p and skin (<a
    
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/593";>#593</a>)
    <a href="https://github.com/hboutemy";><code>@​hboutemy</code></a></li>
    <li>add Reproducible Central report (<a
    
href="https://redirect.github.com/CycloneDX/cyclonedx-maven-plugin/pull/592";>#592</a>)
    <a href="https://github.com/hboutemy";><code>@​hboutemy</code></a></li>
    </ul>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    
href="https://github.com/CycloneDX/cyclonedx-maven-plugin/commit/0fe189d0cd2c80acb1f518e53fbb703456e6534a";><code>0fe189d</code></a>
    [maven-release-plugin] prepare release cyclonedx-maven-plugin-2.9.2</li>
    <li><a
    
href="https://github.com/CycloneDX/cyclonedx-maven-plugin/commit/96c218c71646aa987d5778b9f0f035f40ff45239";><code>96c218c</code></a>
    update scm urls</li>
    <li><a
    
href="https://github.com/CycloneDX/cyclonedx-maven-plugin/commit/0fe08b4215263965690c0a0a022c1fdbc396cad8";><code>0fe08b4</code></a>
    Revert &quot;Bump JamesIves/github-pages-deploy-action from 4.7.3 to
    4.8.0&quot;</li>
    <li><a
    
href="https://github.com/CycloneDX/cyclonedx-maven-plugin/commit/6779e48e4108e5c1881109f39ebda293311ec591";><code>6779e48</code></a>
    Revert &quot;Bump release-drafter/release-drafter from 6 to 7&quot;</li>
    <li><a
    
href="https://github.com/CycloneDX/cyclonedx-maven-plugin/commit/955fead7657740f51b738de11961d4c1eb233bb3";><code>955fead</code></a>
    switch to Central Publishing Portal</li>
    <li><a
    
href="https://github.com/CycloneDX/cyclonedx-maven-plugin/commit/50dbac7e4cd969764e2bfb8e971b0fcf5fcbebba";><code>50dbac7</code></a>
    Bump release-drafter/release-drafter from 6 to 7</li>
    <li><a
    
href="https://github.com/CycloneDX/cyclonedx-maven-plugin/commit/d50bc582155e15a6a1560edab0f1e94d019601e1";><code>d50bc58</code></a>
    Bump org.apache.maven.plugins:maven-project-info-reports-plugin</li>
    <li><a
    
href="https://github.com/CycloneDX/cyclonedx-maven-plugin/commit/1034644886969032df5552fd4132102baeca40c8";><code>1034644</code></a>
    Bump plugin-tools.version from 3.15.0 to 3.15.2</li>
    <li><a
    
href="https://github.com/CycloneDX/cyclonedx-maven-plugin/commit/018ab8e4fdf3b73049497a76bea952983b88389f";><code>018ab8e</code></a>
    Bump commons-codec:commons-codec from 1.17.1 to 1.22.0</li>
    <li><a
    
href="https://github.com/CycloneDX/cyclonedx-maven-plugin/commit/e3597051e8c6eb694e9ccd044b9b5a0829166add";><code>e359705</code></a>
    Bump JamesIves/github-pages-deploy-action from 4.7.3 to 4.8.0</li>
    <li>Additional commits viewable in <a
    
href="https://github.com/CycloneDX/cyclonedx-maven-plugin/compare/cyclonedx-maven-plugin-2.9.1...cyclonedx-maven-plugin-2.9.2";>compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    [![Dependabot compatibility
    
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=org.cyclonedx:cyclonedx-maven-plugin&package-manager=maven&previous-version=2.9.1&new-version=2.9.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] 
<49699333+dependabot[bot]@users.noreply.github.com>
---
 pom.xml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/pom.xml b/pom.xml
index c39eafc20..6a97ac462 100644
--- a/pom.xml
+++ b/pom.xml
@@ -522,7 +522,7 @@ under the License.
         <plugin>
           <groupId>org.cyclonedx</groupId>
           <artifactId>cyclonedx-maven-plugin</artifactId>
-          <version>2.9.1</version>
+          <version>2.9.2</version>
         </plugin>
         <plugin>
           <groupId>org.apache.drill.tools</groupId>

Reply via email to