[commons-math] branch master updated: Add ".gitattributes".

2022-12-17 Thread erans
This is an automated email from the ASF dual-hosted git repository.

erans pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/commons-math.git


The following commit(s) were added to refs/heads/master by this push:
 new 2998aa231 Add ".gitattributes".
2998aa231 is described below

commit 2998aa2312edd158b95f227d915ad400e699eba1
Author: Gilles Sadowski 
AuthorDate: Sat Dec 17 22:22:08 2022 +0100

Add ".gitattributes".

Update contributor guidelines.
---
 .gitattributes   |  2 ++
 src/site/xdoc/developers.xml | 17 +
 2 files changed, 7 insertions(+), 12 deletions(-)

diff --git a/.gitattributes b/.gitattributes
new file mode 100644
index 0..db173deb6
--- /dev/null
+++ b/.gitattributes
@@ -0,0 +1,2 @@
+* text=auto
+*.patch   -text
diff --git a/src/site/xdoc/developers.xml b/src/site/xdoc/developers.xml
index 25b4fbfff..386a71fb3 100644
--- a/src/site/xdoc/developers.xml
+++ b/src/site/xdoc/developers.xml
@@ -152,18 +152,11 @@
  Please make sure to set your IDE or editor to use spaces instead of tabs.
 
 
- Committers should configure the user.name,
- user.email and core.autocrlf
- git repository or global settings with git config.
- The first two settings define the identity and mail of the committer.
- The third setting deals with line endings to achieve consistency
- in line endings. Windows users should configure this setting to
- true (thus forcing git to convert CR/LF line endings
- in the workspace while maintaining LF only line endings in the repository)
- while OS X and Linux users should configure it to input
- (thus forcing git to only strip accidental CR/LF when committing into
- the repository, but never when cheking out files from the repository). 
See http://www.git-scm.com/book/en/Customizing-Git-Git-Configuration";>Customizing
+ Committers should configure the user.name and
+ user.email and git repository (or global) settings
+ with git config.
+ They define the identity and mail of the committer.
+ See http://www.git-scm.com/book/en/Customizing-Git-Git-Configuration";>Customizing
  Git - Git Configuration in the git book for explanation about how to
  configure these settings and more.
 



[commons-parent] branch master updated: Organize

2022-12-17 Thread ggregory
This is an automated email from the ASF dual-hosted git repository.

ggregory pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/commons-parent.git


The following commit(s) were added to refs/heads/master by this push:
 new 9d74c98  Organize
9d74c98 is described below

commit 9d74c98061e1e3aa9c7f9410fda753ddd6dd9161
Author: Gary Gregory 
AuthorDate: Sat Dec 17 16:22:38 2022 -0500

Organize
---
 src/changes/changes.xml | 5 +++--
 1 file changed, 3 insertions(+), 2 deletions(-)

diff --git a/src/changes/changes.xml b/src/changes/changes.xml
index 314b821..2c96e91 100644
--- a/src/changes/changes.xml
+++ b/src/changes/changes.xml
@@ -61,12 +61,13 @@ The  type attribute can be add,update,fix,remove.
 
 
 
+   
+   Add Privacy link to site.xml
+   
Bump 
apache from 28 to 29 #182.
Bump 
versions-maven-plugin from 2.13.0 to 2.14.1 #181, #187.
-   Add Privacy link to site.xml
 
 
-   
Make 
CycloneDX work better with multi-module projects.
New 
interface methods must be default methods to maintain BC.




[commons-numbers] branch master updated: Remove deprecated PMD rule

2022-12-17 Thread aherbert
This is an automated email from the ASF dual-hosted git repository.

aherbert pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/commons-numbers.git


The following commit(s) were added to refs/heads/master by this push:
 new a7b68e6f Remove deprecated PMD rule
a7b68e6f is described below

commit a7b68e6fa7f0731d5efe1cc7887beb302c38c969
Author: Alex Herbert 
AuthorDate: Sat Dec 17 19:37:37 2022 +

Remove deprecated PMD rule
---
 src/main/resources/pmd/pmd-ruleset.xml | 1 -
 1 file changed, 1 deletion(-)

diff --git a/src/main/resources/pmd/pmd-ruleset.xml 
b/src/main/resources/pmd/pmd-ruleset.xml
index abcc303a..94808ff8 100644
--- a/src/main/resources/pmd/pmd-ruleset.xml
+++ b/src/main/resources/pmd/pmd-ruleset.xml
@@ -53,7 +53,6 @@
 
   
   
-
 
 



[commons-math] branch master updated: Remove deprecated PMD rule

2022-12-17 Thread aherbert
This is an automated email from the ASF dual-hosted git repository.

aherbert pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/commons-math.git


The following commit(s) were added to refs/heads/master by this push:
 new 1b32ce9cb Remove deprecated PMD rule
1b32ce9cb is described below

commit 1b32ce9cb42e7d2d956ff5d7bcb2af212824106d
Author: Alex Herbert 
AuthorDate: Sat Dec 17 19:37:10 2022 +

Remove deprecated PMD rule
---
 src/main/resources/pmd/pmd-ruleset.xml | 1 -
 1 file changed, 1 deletion(-)

diff --git a/src/main/resources/pmd/pmd-ruleset.xml 
b/src/main/resources/pmd/pmd-ruleset.xml
index 7d51f4a21..000228d76 100644
--- a/src/main/resources/pmd/pmd-ruleset.xml
+++ b/src/main/resources/pmd/pmd-ruleset.xml
@@ -53,7 +53,6 @@
 
   
   
-
 
 



[commons-geometry] 01/02: Update to Commons Parent 55

2022-12-17 Thread aherbert
This is an automated email from the ASF dual-hosted git repository.

aherbert pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/commons-geometry.git

commit c3aa78a94996a18bf8b78e52968a1f210c546d2f
Author: Alex Herbert 
AuthorDate: Mon Dec 12 11:52:06 2022 +

Update to Commons Parent 55
---
 pom.xml | 8 +---
 1 file changed, 1 insertion(+), 7 deletions(-)

diff --git a/pom.xml b/pom.xml
index 30880770..22501487 100644
--- a/pom.xml
+++ b/pom.xml
@@ -20,7 +20,7 @@
   
 org.apache.commons
 commons-parent
-54
+55
   
 
   commons-geometry-parent
@@ -64,8 +64,6 @@
 
https://cdn.jsdelivr.net/npm/mathjax@3/es5/tex-mml-chtml.js
 
 ${basedir}
-
-true
 
 
-.gitattributes
   
 
   
@@ -355,8 +351,6 @@
 
src/site/resources/release-notes/RELEASE-NOTES-*.txt
 src/site/resources/txt/userguide/stress/**
 dist-archive/**
-
-.gitattributes
   
 
   



[commons-geometry] 02/02: Remove deprecated PMD rule

2022-12-17 Thread aherbert
This is an automated email from the ASF dual-hosted git repository.

aherbert pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/commons-geometry.git

commit 2aac9356b1e205a6e152031b64340213796701fc
Author: Alex Herbert 
AuthorDate: Sat Dec 17 19:36:30 2022 +

Remove deprecated PMD rule
---
 src/main/resources/pmd/pmd-ruleset.xml | 1 -
 1 file changed, 1 deletion(-)

diff --git a/src/main/resources/pmd/pmd-ruleset.xml 
b/src/main/resources/pmd/pmd-ruleset.xml
index 1d9845fc..4b510af1 100644
--- a/src/main/resources/pmd/pmd-ruleset.xml
+++ b/src/main/resources/pmd/pmd-ruleset.xml
@@ -54,7 +54,6 @@
 
   
   
-
 
 



[commons-geometry] branch master updated (e6046703 -> 2aac9356)

2022-12-17 Thread aherbert
This is an automated email from the ASF dual-hosted git repository.

aherbert pushed a change to branch master
in repository https://gitbox.apache.org/repos/asf/commons-geometry.git


from e6046703 Update release guide to remove CONTRIBUTING.md from 
distribution files
 new c3aa78a9 Update to Commons Parent 55
 new 2aac9356 Remove deprecated PMD rule

The 2 revisions listed above as "new" are entirely new to this
repository and will be described in separate emails.  The revisions
listed as "add" were already present in the repository and have only
been added to this reference.


Summary of changes:
 pom.xml| 8 +---
 src/main/resources/pmd/pmd-ruleset.xml | 1 -
 2 files changed, 1 insertion(+), 8 deletions(-)



[commons-rng] branch master updated: Remove deprecated PMD rule

2022-12-17 Thread aherbert
This is an automated email from the ASF dual-hosted git repository.

aherbert pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/commons-rng.git


The following commit(s) were added to refs/heads/master by this push:
 new 345c2d73 Remove deprecated PMD rule
345c2d73 is described below

commit 345c2d7396999af7bd6fd8cd1d5bc2dd5e15ad3b
Author: Alex Herbert 
AuthorDate: Sat Dec 17 19:35:48 2022 +

Remove deprecated PMD rule
---
 src/main/resources/pmd/pmd-ruleset.xml | 1 -
 1 file changed, 1 deletion(-)

diff --git a/src/main/resources/pmd/pmd-ruleset.xml 
b/src/main/resources/pmd/pmd-ruleset.xml
index 12566181..482b91e2 100644
--- a/src/main/resources/pmd/pmd-ruleset.xml
+++ b/src/main/resources/pmd/pmd-ruleset.xml
@@ -52,7 +52,6 @@
 
   
   
-
 
 



[commons-statistics] branch master updated: Remove deprecated PMD rule

2022-12-17 Thread aherbert
This is an automated email from the ASF dual-hosted git repository.

aherbert pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/commons-statistics.git


The following commit(s) were added to refs/heads/master by this push:
 new 2caf2ab  Remove deprecated PMD rule
2caf2ab is described below

commit 2caf2abd00aa0240041c03802085fa3361463e43
Author: Alex Herbert 
AuthorDate: Sat Dec 17 19:34:06 2022 +

Remove deprecated PMD rule
---
 src/conf/pmd/pmd-ruleset.xml | 1 -
 1 file changed, 1 deletion(-)

diff --git a/src/conf/pmd/pmd-ruleset.xml b/src/conf/pmd/pmd-ruleset.xml
index ce00cc4..92126a6 100644
--- a/src/conf/pmd/pmd-ruleset.xml
+++ b/src/conf/pmd/pmd-ruleset.xml
@@ -56,7 +56,6 @@
 
   
   
-
 
 



[commons-exec] 01/01: Merge pull request #80 from apache/dependabot/github_actions/actions/checkout-3.2.0

2022-12-17 Thread ggregory
This is an automated email from the ASF dual-hosted git repository.

ggregory pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/commons-exec.git

commit 693000ca1387f5c0df54d231bc9d7c4576b5b6c9
Merge: 9ff1bda 423cf30
Author: Gary Gregory 
AuthorDate: Sat Dec 17 08:51:04 2022 -0500

Merge pull request #80 from 
apache/dependabot/github_actions/actions/checkout-3.2.0

Bump actions/checkout from 3.1.0 to 3.2.0

 .github/workflows/codeql-analysis.yml | 2 +-
 .github/workflows/coverage.yml| 2 +-
 .github/workflows/maven.yml   | 2 +-
 .github/workflows/scorecards-analysis.yml | 2 +-
 4 files changed, 4 insertions(+), 4 deletions(-)




[commons-exec] branch master updated (9ff1bda -> 693000c)

2022-12-17 Thread ggregory
This is an automated email from the ASF dual-hosted git repository.

ggregory pushed a change to branch master
in repository https://gitbox.apache.org/repos/asf/commons-exec.git


from 9ff1bda  Merge pull request #81 from 
apache/dependabot/github_actions/actions/setup-java-3.9.0
 add 423cf30  Bump actions/checkout from 3.1.0 to 3.2.0
 new 693000c  Merge pull request #80 from 
apache/dependabot/github_actions/actions/checkout-3.2.0

The 1 revisions listed above as "new" are entirely new to this
repository and will be described in separate emails.  The revisions
listed as "add" were already present in the repository and have only
been added to this reference.


Summary of changes:
 .github/workflows/codeql-analysis.yml | 2 +-
 .github/workflows/coverage.yml| 2 +-
 .github/workflows/maven.yml   | 2 +-
 .github/workflows/scorecards-analysis.yml | 2 +-
 4 files changed, 4 insertions(+), 4 deletions(-)



[commons-exec] branch master updated (9a6fa48 -> 9ff1bda)

2022-12-17 Thread ggregory
This is an automated email from the ASF dual-hosted git repository.

ggregory pushed a change to branch master
in repository https://gitbox.apache.org/repos/asf/commons-exec.git


from 9a6fa48  Merge pull request #82 from 
apache/dependabot/github_actions/ossf/scorecard-action-2.1.0
 add 4906dc6  Bump actions/setup-java from 3.8.0 to 3.9.0
 add 9ff1bda  Merge pull request #81 from 
apache/dependabot/github_actions/actions/setup-java-3.9.0

No new revisions were added by this update.

Summary of changes:
 .github/workflows/coverage.yml | 2 +-
 .github/workflows/maven.yml| 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)



[commons-rdf] branch master updated (ca2a4f64 -> 577b7a6a)

2022-12-17 Thread ggregory
This is an automated email from the ASF dual-hosted git repository.

ggregory pushed a change to branch master
in repository https://gitbox.apache.org/repos/asf/commons-rdf.git


from ca2a4f64 Merge pull request #104 from 
apache/dependabot/github_actions/actions/setup-java-3.9.0
 add 83bb15b7 Bump ossf/scorecard-action from 2.0.6 to 2.1.0
 add 577b7a6a Merge pull request #105 from 
apache/dependabot/github_actions/ossf/scorecard-action-2.1.0

No new revisions were added by this update.

Summary of changes:
 .github/workflows/scorecards-analysis.yml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)



[commons-jxpath] branch master updated: Update for Scorecard 2

2022-12-17 Thread ggregory
This is an automated email from the ASF dual-hosted git repository.

ggregory pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/commons-jxpath.git


The following commit(s) were added to refs/heads/master by this push:
 new 72a6af0  Update for Scorecard 2
72a6af0 is described below

commit 72a6af083502bf3473b6e391a3ba33e7584bfe1a
Author: Gary Gregory 
AuthorDate: Sat Dec 17 08:43:40 2022 -0500

Update for Scorecard 2
---
 .github/workflows/scorecards-analysis.yml | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/.github/workflows/scorecards-analysis.yml 
b/.github/workflows/scorecards-analysis.yml
index bffdc1c..cb7a29e 100644
--- a/.github/workflows/scorecards-analysis.yml
+++ b/.github/workflows/scorecards-analysis.yml
@@ -33,7 +33,8 @@ jobs:
 permissions:
   security-events: write# Needed to upload the results to the 
code-scanning dashboard.
   actions: read
-  contents: read
+  id-token: write # This is required for requesting the JWT
+  contents: read  # This is required for actions/checkout
 
 steps:
 



[commons-text] branch master updated: Bump mockito-inline from 4.9.0 to 4.10.0 #396

2022-12-17 Thread ggregory
This is an automated email from the ASF dual-hosted git repository.

ggregory pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/commons-text.git


The following commit(s) were added to refs/heads/master by this push:
 new 65f3743a Bump mockito-inline from 4.9.0 to 4.10.0 #396
65f3743a is described below

commit 65f3743a0c0cc6879912e36715f28d1b5562f797
Author: Gary Gregory 
AuthorDate: Sat Dec 17 08:13:24 2022 -0500

Bump mockito-inline from 4.9.0 to 4.10.0 #396
---
 src/changes/changes.xml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/src/changes/changes.xml b/src/changes/changes.xml
index 3183c82d..2511e2be 100644
--- a/src/changes/changes.xml
+++ b/src/changes/changes.xml
@@ -59,7 +59,7 @@ The  type attribute can be add,update,fix,remove.
 Bump commons-rng-simple from 1.4 to 1.5 #370.
 Bump spotbugs-maven-plugin from 4.7.2.0 to 4.7.3.0 #371, 
#385.
 Bump spotbugs from 4.7.2 to 4.7.3 #373.
-Bump mockito-inline from 4.8.0 to 4.9.0 #380, #389.
+Bump mockito-inline from 4.8.0 to 4.10.0 #380, #389, 
#396.
 Bump jmh.version from 1.35 to 1.36 #388.
 Bump commons-parent from 54 to 55 #392.
   



[commons-text] branch master updated (3814fafd -> d341238c)

2022-12-17 Thread ggregory
This is an automated email from the ASF dual-hosted git repository.

ggregory pushed a change to branch master
in repository https://gitbox.apache.org/repos/asf/commons-text.git


from 3814fafd Bump ossf/scorecard-action from 2.0.6 to 2.1.0 (#394)
 add d341238c Bump mockito-inline from 4.9.0 to 4.10.0 (#396)

No new revisions were added by this update.

Summary of changes:
 pom.xml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)



[commons-text] branch master updated: Bump ossf/scorecard-action from 2.0.6 to 2.1.0 (#394)

2022-12-17 Thread ggregory
This is an automated email from the ASF dual-hosted git repository.

ggregory pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/commons-text.git


The following commit(s) were added to refs/heads/master by this push:
 new 3814fafd Bump ossf/scorecard-action from 2.0.6 to 2.1.0 (#394)
3814fafd is described below

commit 3814fafd343c69b0f4d11ba4d30a643b089edce1
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
AuthorDate: Sat Dec 17 08:12:44 2022 -0500

Bump ossf/scorecard-action from 2.0.6 to 2.1.0 (#394)

Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) 
from 2.0.6 to 2.1.0.
- [Release notes](https://github.com/ossf/scorecard-action/releases)
- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md)
- 
[Commits](https://github.com/ossf/scorecard-action/compare/99c53751e09b9529366343771cc321ec74e9bd3d...937ffa90d79c7d720498178154ad4c7ba1e4ad8c)

---
updated-dependencies:
- dependency-name: ossf/scorecard-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] 

Signed-off-by: dependabot[bot] 
Co-authored-by: dependabot[bot] 
<49699333+dependabot[bot]@users.noreply.github.com>
---
 .github/workflows/scorecards-analysis.yml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/.github/workflows/scorecards-analysis.yml 
b/.github/workflows/scorecards-analysis.yml
index 55cd061a..d24ca6be 100644
--- a/.github/workflows/scorecards-analysis.yml
+++ b/.github/workflows/scorecards-analysis.yml
@@ -45,7 +45,7 @@ jobs:
   persist-credentials: false
 
   - name: "Run analysis"
-uses: ossf/scorecard-action@99c53751e09b9529366343771cc321ec74e9bd3d   
 # 2.0.6
+uses: ossf/scorecard-action@937ffa90d79c7d720498178154ad4c7ba1e4ad8c   
 # 2.1.0
 with:
   results_file: results.sarif
   results_format: sarif



[commons-jxpath] branch master updated (0bc1d51 -> 72c5a30)

2022-12-17 Thread ggregory
This is an automated email from the ASF dual-hosted git repository.

ggregory pushed a change to branch master
in repository https://gitbox.apache.org/repos/asf/commons-jxpath.git


from 0bc1d51  Bump commons-parent from 54 to 55 #45
 add 2b60b87  Bump ossf/scorecard-action from 1.1.2 to 2.1.0
 add 72c5a30  Merge pull request #42 from 
apache/dependabot/github_actions/ossf/scorecard-action-2.1.0

No new revisions were added by this update.

Summary of changes:
 .github/workflows/scorecards-analysis.yml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)



[commons-jxpath] branch master updated: Bump commons-parent from 54 to 55 #45

2022-12-17 Thread ggregory
This is an automated email from the ASF dual-hosted git repository.

ggregory pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/commons-jxpath.git


The following commit(s) were added to refs/heads/master by this push:
 new 0bc1d51  Bump commons-parent from 54 to 55 #45
0bc1d51 is described below

commit 0bc1d51375d65fa0a52f60843ac9ebb0ef2c
Author: Gary Gregory 
AuthorDate: Sat Dec 17 08:11:55 2022 -0500

Bump commons-parent from 54 to 55 #45
---
 src/changes/changes.xml | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/src/changes/changes.xml b/src/changes/changes.xml
index 3039b2a..1159da7 100644
--- a/src/changes/changes.xml
+++ b/src/changes/changes.xml
@@ -107,6 +107,9 @@ The  type attribute can be add,update,fix,remove.
   
 Bump servlet-api from 2.4 to 2.5 #29.
   
+  
+Bump commons-parent from 54 to 55 #45.
+  
 
   
 



[commons-jxpath] branch master updated (77b4bc7 -> 0176f34)

2022-12-17 Thread ggregory
This is an automated email from the ASF dual-hosted git repository.

ggregory pushed a change to branch master
in repository https://gitbox.apache.org/repos/asf/commons-jxpath.git


from 77b4bc7  Merge pull request #44 from 
apache/dependabot/github_actions/actions/setup-java-3.9.0
 add 717287b  Bump commons-parent from 54 to 55
 new 0176f34  Merge pull request #45 from 
apache/dependabot/maven/org.apache.commons-commons-parent-55

The 1 revisions listed above as "new" are entirely new to this
repository and will be described in separate emails.  The revisions
listed as "add" were already present in the repository and have only
been added to this reference.


Summary of changes:
 pom.xml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)



[commons-jxpath] 01/01: Merge pull request #45 from apache/dependabot/maven/org.apache.commons-commons-parent-55

2022-12-17 Thread ggregory
This is an automated email from the ASF dual-hosted git repository.

ggregory pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/commons-jxpath.git

commit 0176f3402f68872bee5ad73123a5409f61df6211
Merge: 77b4bc7 717287b
Author: Gary Gregory 
AuthorDate: Sat Dec 17 08:09:58 2022 -0500

Merge pull request #45 from 
apache/dependabot/maven/org.apache.commons-commons-parent-55

Bump commons-parent from 54 to 55

 pom.xml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)



[commons-bcel] branch master updated: Bump ossf/scorecard-action from 2.0.6 to 2.1.0 (#193)

2022-12-17 Thread ggregory
This is an automated email from the ASF dual-hosted git repository.

ggregory pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/commons-bcel.git


The following commit(s) were added to refs/heads/master by this push:
 new 63a8456c Bump ossf/scorecard-action from 2.0.6 to 2.1.0 (#193)
63a8456c is described below

commit 63a8456c138505368f8a8db68ef9fb6881057bc1
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
AuthorDate: Sat Dec 17 08:06:53 2022 -0500

Bump ossf/scorecard-action from 2.0.6 to 2.1.0 (#193)

Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) 
from 2.0.6 to 2.1.0.
- [Release notes](https://github.com/ossf/scorecard-action/releases)
- [Changelog](https://github.com/ossf/scorecard-action/blob/main/RELEASE.md)
- 
[Commits](https://github.com/ossf/scorecard-action/compare/99c53751e09b9529366343771cc321ec74e9bd3d...937ffa90d79c7d720498178154ad4c7ba1e4ad8c)

---
updated-dependencies:
- dependency-name: ossf/scorecard-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] 

Signed-off-by: dependabot[bot] 
Co-authored-by: dependabot[bot] 
<49699333+dependabot[bot]@users.noreply.github.com>
---
 .github/workflows/scorecards-analysis.yml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/.github/workflows/scorecards-analysis.yml 
b/.github/workflows/scorecards-analysis.yml
index e9dd3e02..99ce3da9 100644
--- a/.github/workflows/scorecards-analysis.yml
+++ b/.github/workflows/scorecards-analysis.yml
@@ -45,7 +45,7 @@ jobs:
   persist-credentials: false
 
   - name: "Run analysis"
-uses: ossf/scorecard-action@99c53751e09b9529366343771cc321ec74e9bd3d   
 # 2.0.6
+uses: ossf/scorecard-action@937ffa90d79c7d720498178154ad4c7ba1e4ad8c   
 # 2.1.0
 with:
   results_file: results.sarif
   results_format: sarif



[commons-configuration] branch master updated: [INFRA-24015] Update for Scorecards 2 (#254)

2022-12-17 Thread ggregory
This is an automated email from the ASF dual-hosted git repository.

ggregory pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/commons-configuration.git


The following commit(s) were added to refs/heads/master by this push:
 new 7d8453f4 [INFRA-24015] Update for Scorecards 2 (#254)
7d8453f4 is described below

commit 7d8453f41c732e23c388db66ddaabf8a7f1fd716
Author: Arnout Engelen 
AuthorDate: Sat Dec 17 13:10:56 2022 +0100

[INFRA-24015] Update for Scorecards 2 (#254)

Similar to 
https://github.com/apache/commons-csv/commit/cafb4d2f43105cfc2322760e17aeb340ac4a6086
---
 .github/workflows/scorecards-analysis.yml | 3 ++-
 1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/.github/workflows/scorecards-analysis.yml 
b/.github/workflows/scorecards-analysis.yml
index 4f56c246..94e9a560 100644
--- a/.github/workflows/scorecards-analysis.yml
+++ b/.github/workflows/scorecards-analysis.yml
@@ -33,7 +33,8 @@ jobs:
 permissions:
   security-events: write# Needed to upload the results to the 
code-scanning dashboard.
   actions: read
-  contents: read
+  id-token: write # This is required for requesting the JWT
+  contents: read # This is required for actions/checkout
 
 steps: