[GH] (commons-compress): Workflow run "Coverage" is working again!

2024-04-18 Thread GitBox


The GitHub Actions job "Coverage" on commons-compress.git has succeeded.
Run started by GitHub user dependabot[bot] (triggered by dependabot[bot]).

Head commit for run:
79f1050c07da23b4c508526ce92674467b1b613d / dependabot[bot] 
<49699333+dependabot[bot]@users.noreply.github.com>
Bump org.slf4j:slf4j-api from 2.0.12 to 2.0.13

Bumps org.slf4j:slf4j-api from 2.0.12 to 2.0.13.

---
updated-dependencies:
- dependency-name: org.slf4j:slf4j-api
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] 

Report URL: https://github.com/apache/commons-compress/actions/runs/8748453395

With regards,
GitHub Actions via GitBox



[GH] (commons-compress): Workflow run "Coverage" is working again!

2024-04-18 Thread GitBox


The GitHub Actions job "Coverage" on commons-compress.git has succeeded.
Run started by GitHub user dependabot[bot] (triggered by dependabot[bot]).

Head commit for run:
79f1050c07da23b4c508526ce92674467b1b613d / dependabot[bot] 
<49699333+dependabot[bot]@users.noreply.github.com>
Bump org.slf4j:slf4j-api from 2.0.12 to 2.0.13

Bumps org.slf4j:slf4j-api from 2.0.12 to 2.0.13.

---
updated-dependencies:
- dependency-name: org.slf4j:slf4j-api
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] 

Report URL: https://github.com/apache/commons-compress/actions/runs/8748453673

With regards,
GitHub Actions via GitBox



[PR] Bump org.slf4j:slf4j-api from 2.0.12 to 2.0.13 [commons-compress]

2024-04-18 Thread via GitHub


dependabot[bot] opened a new pull request, #519:
URL: https://github.com/apache/commons-compress/pull/519

   Bumps org.slf4j:slf4j-api from 2.0.12 to 2.0.13.
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=org.slf4j:slf4j-api=maven=2.0.12=2.0.13)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   
   Dependabot commands and options
   
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI 
passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and 
block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. 
You can achieve the same result by closing it manually
   - `@dependabot show  ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: notifications-unsubscr...@commons.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



[PR] Bump actions/upload-artifact from 4.3.1 to 4.3.2 [commons-digester]

2024-04-18 Thread via GitHub


dependabot[bot] opened a new pull request, #151:
URL: https://github.com/apache/commons-digester/pull/151

   Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) 
from 4.3.1 to 4.3.2.
   
   Release notes
   Sourced from https://github.com/actions/upload-artifact/releases;>actions/upload-artifact's
 releases.
   
   v4.3.2
   What's Changed
   
   Update release-new-action-version.yml by https://github.com/konradpabjan;>@​konradpabjan in https://redirect.github.com/actions/upload-artifact/pull/516;>actions/upload-artifact#516
   Minor fix to the migration readme by https://github.com/andrewakim;>@​andrewakim in https://redirect.github.com/actions/upload-artifact/pull/523;>actions/upload-artifact#523
   Update readme with v3/v2/v1 deprecation notice by https://github.com/robherley;>@​robherley in https://redirect.github.com/actions/upload-artifact/pull/561;>actions/upload-artifact#561
   updating @actions/artifact dependency to v2.1.5 and 
@actions/core to v1.0.1 by https://github.com/eggyhead;>@​eggyhead in https://redirect.github.com/actions/upload-artifact/pull/562;>actions/upload-artifact#562
   
   New Contributors
   
   https://github.com/andrewakim;>@​andrewakim 
made their first contribution in https://redirect.github.com/actions/upload-artifact/pull/523;>actions/upload-artifact#523
   
   Full Changelog: https://github.com/actions/upload-artifact/compare/v4.3.1...v4.3.2;>https://github.com/actions/upload-artifact/compare/v4.3.1...v4.3.2
   
   
   
   Commits
   
   https://github.com/actions/upload-artifact/commit/1746f4ab65b179e0ea60a494b83293b640dd5bba;>1746f4a
 Revert updating to release 4.3.2
   https://github.com/actions/upload-artifact/commit/31685d04a0d6557fe2be4174c3ea69ee4cbfa6bb;>31685d0
 updating to release 4.3.2
   https://github.com/actions/upload-artifact/commit/18bf333cd2249fbbbdb605fd9d9ed57efd7adf34;>18bf333
 Merge pull request https://redirect.github.com/actions/upload-artifact/issues/562;>#562 
from actions/eggyhead/update-artifact-v215
   https://github.com/actions/upload-artifact/commit/dac413befa086181ab17cf3db942667aede55e0d;>dac413b
 update package lock version
   https://github.com/actions/upload-artifact/commit/bb3b4a3cdbef901e2e185ca492d513e798fd1b9f;>bb3b4a3
 updating package version
   https://github.com/actions/upload-artifact/commit/3e3da837d2a1e030e44fe2bb5c4b9f63c25f33e3;>3e3da83
 updating artifact and core dependencies
   https://github.com/actions/upload-artifact/commit/e35774f165aac0e3b0c8273137b1845a2ac8c5f1;>e35774f
 Merge pull request https://redirect.github.com/actions/upload-artifact/issues/561;>#561 
from actions/robherley/deprecation-notice
   https://github.com/actions/upload-artifact/commit/e63ea677fb182f6827027a7b74f61debfca990ab;>e63ea67
 Update readme with v3/v2/v1 deprecation notice
   https://github.com/actions/upload-artifact/commit/ef09cdac3e2d3e60d8ccadda691f4f1cec5035cb;>ef09cda
 Merge pull request https://redirect.github.com/actions/upload-artifact/issues/523;>#523 
from andrewakim/andrewakim/migration-readme-fix
   https://github.com/actions/upload-artifact/commit/00e36f94d817ea235422592a23d468b262071bf4;>00e36f9
 Minor fix to the migration readme
   Additional commits viewable in https://github.com/actions/upload-artifact/compare/5d5d22a31266ced268874388b861e4b58bb5c2f3...1746f4ab65b179e0ea60a494b83293b640dd5bba;>compare
 view
   
   
   
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/upload-artifact=github_actions=4.3.1=4.3.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   
   Dependabot commands and options
   
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI 
passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and 
block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. 
You can achieve the same result by closing it manually
   - `@dependabot show  ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - 

[PR] Bump github/codeql-action from 3.24.10 to 3.25.1 [commons-digester]

2024-04-18 Thread via GitHub


dependabot[bot] opened a new pull request, #150:
URL: https://github.com/apache/commons-digester/pull/150

   Bumps [github/codeql-action](https://github.com/github/codeql-action) from 
3.24.10 to 3.25.1.
   
   Changelog
   Sourced from https://github.com/github/codeql-action/blob/main/CHANGELOG.md;>github/codeql-action's
 changelog.
   
   CodeQL Action Changelog
   See the https://github.com/github/codeql-action/releases;>releases page for 
the relevant changes to the CodeQL CLI and language packs.
   Note that the only difference between v2 and v3 
of the CodeQL Action is the node version they support, with v3 
running on node 20 while we continue to release v2 to support 
running on node 16. For example 3.22.11 was the first 
v3 release and is functionally identical to 2.22.11. 
This approach ensures an easy way to track exactly which features are included 
in different versions, indicated by the minor and patch version numbers.
   [UNRELEASED]
   No user facing changes.
   3.25.1 - 17 Apr 2024
   
   We are rolling out a feature in April/May 2024 that improves the 
reliability and performance of analyzing code when analyzing a compiled 
language with the autobuild https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages#codeql-build-modes;>build
 mode. https://redirect.github.com/github/codeql-action/pull/2235;>#2235
   Fix a bug where the init Action would fail if 
--overwrite was specified in 
CODEQL_ACTION_EXTRA_OPTIONS. https://redirect.github.com/github/codeql-action/pull/2245;>#2245
   
   3.25.0 - 15 Apr 2024
   
   
   The deprecated feature for extracting dependencies for a Python analysis 
has been removed. https://redirect.github.com/github/codeql-action/pull/2224;>#2224
   As a result, the following inputs and environment variables are now 
ignored:
   
   The setup-python-dependencies input to the 
init Action
   The CODEQL_ACTION_DISABLE_PYTHON_DEPENDENCY_INSTALLATION 
environment variable
   
   We recommend removing any references to these from your workflows. For 
more information, see the release notes for CodeQL Action v3.23.0 and 
v2.23.0.
   
   
   Automatically overwrite an existing database if found on the filesystem. 
https://redirect.github.com/github/codeql-action/pull/2229;>#2229
   
   
   Bump the minimum CodeQL bundle version to 2.12.6. https://redirect.github.com/github/codeql-action/pull/2232;>#2232
   
   
   A more relevant log message and a diagnostic are now emitted when the 
file program is not installed on a Linux runner, but is required 
for Go tracing to succeed. https://redirect.github.com/github/codeql-action/pull/2234;>#2234
   
   
   3.24.10 - 05 Apr 2024
   
   Update default CodeQL bundle version to 2.17.0. https://redirect.github.com/github/codeql-action/pull/2219;>#2219
   Add a deprecation warning for customers using CodeQL version 2.12.5 and 
earlier. These versions of CodeQL were discontinued on 26 March 2024 alongside 
GitHub Enterprise Server 3.8, and will be unsupported by CodeQL Action versions 
3.25.0 and later and versions 2.25.0 and later. https://redirect.github.com/github/codeql-action/pull/2220;>#2220
   
   If you are using one of these versions, please update to CodeQL CLI 
version 2.12.6 or later. For instance, if you have specified a custom version 
of the CLI using the 'tools' input to the 'init' Action, you can remove this 
input to use the default version.
   Alternatively, if you want to continue using a version of the CodeQL CLI 
between 2.11.6 and 2.12.5, you can replace 
github/codeql-action/*@v3 by 
github/codeql-action/*@v3.24.10 and 
github/codeql-action/*@v2 by 
github/codeql-action/*@v2.24.10 in your code scanning workflow to 
ensure you continue using this version of the CodeQL Action.
   
   
   
   3.24.9 - 22 Mar 2024
   
   Update default CodeQL bundle version to 2.16.5. https://redirect.github.com/github/codeql-action/pull/2203;>#2203
   
   3.24.8 - 18 Mar 2024
   
   Improve the ease of debugging extraction issues by increasing the 
verbosity of the extractor logs when running in debug mode. https://redirect.github.com/github/codeql-action/pull/2195;>#2195
   
   3.24.7 - 12 Mar 2024
   
   Update default CodeQL bundle version to 2.16.4. https://redirect.github.com/github/codeql-action/pull/2185;>#2185
   
   3.24.6 - 29 Feb 2024
   
   
   ... (truncated)
   
   
   Commits
   
   https://github.com/github/codeql-action/commit/c7f9125735019aa87cfc361530512d50ea439c71;>c7f9125
 Merge pull request https://redirect.github.com/github/codeql-action/issues/2248;>#2248 
from github/update-v3.25.1-c4fb45143
   https://github.com/github/codeql-action/commit/1c7e8b2cf27fe2842c9131549befe9126c581615;>1c7e8b2
 Update changelog for v3.25.1
   https://github.com/github/codeql-action/commit/c4fb451437765abf5018c6fbf22cce1a7da1e5cc;>c4fb451
 Merge pull request https://redirect.github.com/github/codeql-action/issues/2245;>#2245 
from 

[PR] Bump org.slf4j:slf4j-simple from 2.0.12 to 2.0.13 [commons-dbcp]

2024-04-18 Thread via GitHub


dependabot[bot] opened a new pull request, #377:
URL: https://github.com/apache/commons-dbcp/pull/377

   Bumps org.slf4j:slf4j-simple from 2.0.12 to 2.0.13.
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=org.slf4j:slf4j-simple=maven=2.0.12=2.0.13)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   
   Dependabot commands and options
   
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI 
passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and 
block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. 
You can achieve the same result by closing it manually
   - `@dependabot show  ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: notifications-unsubscr...@commons.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



[GH] (commons-compress): Workflow run "Coverage" failed!

2024-04-18 Thread GitBox


The GitHub Actions job "Coverage" on commons-compress.git has failed.
Run started by GitHub user dependabot[bot] (triggered by dependabot[bot]).

Head commit for run:
c7f3717f46a1cbedb1e61c944944e038503fe11c / dependabot[bot] 
<49699333+dependabot[bot]@users.noreply.github.com>
Bump actions/upload-artifact from 4.3.1 to 4.3.2

Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) 
from 4.3.1 to 4.3.2.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- 
[Commits](https://github.com/actions/upload-artifact/compare/5d5d22a31266ced268874388b861e4b58bb5c2f3...1746f4ab65b179e0ea60a494b83293b640dd5bba)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] 

Report URL: https://github.com/apache/commons-compress/actions/runs/8748280410

With regards,
GitHub Actions via GitBox



[PR] Bump actions/upload-artifact from 4.3.1 to 4.3.2 [commons-compress]

2024-04-18 Thread via GitHub


dependabot[bot] opened a new pull request, #518:
URL: https://github.com/apache/commons-compress/pull/518

   Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) 
from 4.3.1 to 4.3.2.
   
   Release notes
   Sourced from https://github.com/actions/upload-artifact/releases;>actions/upload-artifact's
 releases.
   
   v4.3.2
   What's Changed
   
   Update release-new-action-version.yml by https://github.com/konradpabjan;>@​konradpabjan in https://redirect.github.com/actions/upload-artifact/pull/516;>actions/upload-artifact#516
   Minor fix to the migration readme by https://github.com/andrewakim;>@​andrewakim in https://redirect.github.com/actions/upload-artifact/pull/523;>actions/upload-artifact#523
   Update readme with v3/v2/v1 deprecation notice by https://github.com/robherley;>@​robherley in https://redirect.github.com/actions/upload-artifact/pull/561;>actions/upload-artifact#561
   updating @actions/artifact dependency to v2.1.5 and 
@actions/core to v1.0.1 by https://github.com/eggyhead;>@​eggyhead in https://redirect.github.com/actions/upload-artifact/pull/562;>actions/upload-artifact#562
   
   New Contributors
   
   https://github.com/andrewakim;>@​andrewakim 
made their first contribution in https://redirect.github.com/actions/upload-artifact/pull/523;>actions/upload-artifact#523
   
   Full Changelog: https://github.com/actions/upload-artifact/compare/v4.3.1...v4.3.2;>https://github.com/actions/upload-artifact/compare/v4.3.1...v4.3.2
   
   
   
   Commits
   
   https://github.com/actions/upload-artifact/commit/1746f4ab65b179e0ea60a494b83293b640dd5bba;>1746f4a
 Revert updating to release 4.3.2
   https://github.com/actions/upload-artifact/commit/31685d04a0d6557fe2be4174c3ea69ee4cbfa6bb;>31685d0
 updating to release 4.3.2
   https://github.com/actions/upload-artifact/commit/18bf333cd2249fbbbdb605fd9d9ed57efd7adf34;>18bf333
 Merge pull request https://redirect.github.com/actions/upload-artifact/issues/562;>#562 
from actions/eggyhead/update-artifact-v215
   https://github.com/actions/upload-artifact/commit/dac413befa086181ab17cf3db942667aede55e0d;>dac413b
 update package lock version
   https://github.com/actions/upload-artifact/commit/bb3b4a3cdbef901e2e185ca492d513e798fd1b9f;>bb3b4a3
 updating package version
   https://github.com/actions/upload-artifact/commit/3e3da837d2a1e030e44fe2bb5c4b9f63c25f33e3;>3e3da83
 updating artifact and core dependencies
   https://github.com/actions/upload-artifact/commit/e35774f165aac0e3b0c8273137b1845a2ac8c5f1;>e35774f
 Merge pull request https://redirect.github.com/actions/upload-artifact/issues/561;>#561 
from actions/robherley/deprecation-notice
   https://github.com/actions/upload-artifact/commit/e63ea677fb182f6827027a7b74f61debfca990ab;>e63ea67
 Update readme with v3/v2/v1 deprecation notice
   https://github.com/actions/upload-artifact/commit/ef09cdac3e2d3e60d8ccadda691f4f1cec5035cb;>ef09cda
 Merge pull request https://redirect.github.com/actions/upload-artifact/issues/523;>#523 
from andrewakim/andrewakim/migration-readme-fix
   https://github.com/actions/upload-artifact/commit/00e36f94d817ea235422592a23d468b262071bf4;>00e36f9
 Minor fix to the migration readme
   Additional commits viewable in https://github.com/actions/upload-artifact/compare/5d5d22a31266ced268874388b861e4b58bb5c2f3...1746f4ab65b179e0ea60a494b83293b640dd5bba;>compare
 view
   
   
   
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/upload-artifact=github_actions=4.3.1=4.3.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   
   Dependabot commands and options
   
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI 
passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and 
block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. 
You can achieve the same result by closing it manually
   - `@dependabot show  ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - 

[PR] Bump github/codeql-action from 3.24.10 to 3.25.1 [commons-compress]

2024-04-18 Thread via GitHub


dependabot[bot] opened a new pull request, #517:
URL: https://github.com/apache/commons-compress/pull/517

   Bumps [github/codeql-action](https://github.com/github/codeql-action) from 
3.24.10 to 3.25.1.
   
   Changelog
   Sourced from https://github.com/github/codeql-action/blob/main/CHANGELOG.md;>github/codeql-action's
 changelog.
   
   CodeQL Action Changelog
   See the https://github.com/github/codeql-action/releases;>releases page for 
the relevant changes to the CodeQL CLI and language packs.
   Note that the only difference between v2 and v3 
of the CodeQL Action is the node version they support, with v3 
running on node 20 while we continue to release v2 to support 
running on node 16. For example 3.22.11 was the first 
v3 release and is functionally identical to 2.22.11. 
This approach ensures an easy way to track exactly which features are included 
in different versions, indicated by the minor and patch version numbers.
   [UNRELEASED]
   No user facing changes.
   3.25.1 - 17 Apr 2024
   
   We are rolling out a feature in April/May 2024 that improves the 
reliability and performance of analyzing code when analyzing a compiled 
language with the autobuild https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages#codeql-build-modes;>build
 mode. https://redirect.github.com/github/codeql-action/pull/2235;>#2235
   Fix a bug where the init Action would fail if 
--overwrite was specified in 
CODEQL_ACTION_EXTRA_OPTIONS. https://redirect.github.com/github/codeql-action/pull/2245;>#2245
   
   3.25.0 - 15 Apr 2024
   
   
   The deprecated feature for extracting dependencies for a Python analysis 
has been removed. https://redirect.github.com/github/codeql-action/pull/2224;>#2224
   As a result, the following inputs and environment variables are now 
ignored:
   
   The setup-python-dependencies input to the 
init Action
   The CODEQL_ACTION_DISABLE_PYTHON_DEPENDENCY_INSTALLATION 
environment variable
   
   We recommend removing any references to these from your workflows. For 
more information, see the release notes for CodeQL Action v3.23.0 and 
v2.23.0.
   
   
   Automatically overwrite an existing database if found on the filesystem. 
https://redirect.github.com/github/codeql-action/pull/2229;>#2229
   
   
   Bump the minimum CodeQL bundle version to 2.12.6. https://redirect.github.com/github/codeql-action/pull/2232;>#2232
   
   
   A more relevant log message and a diagnostic are now emitted when the 
file program is not installed on a Linux runner, but is required 
for Go tracing to succeed. https://redirect.github.com/github/codeql-action/pull/2234;>#2234
   
   
   3.24.10 - 05 Apr 2024
   
   Update default CodeQL bundle version to 2.17.0. https://redirect.github.com/github/codeql-action/pull/2219;>#2219
   Add a deprecation warning for customers using CodeQL version 2.12.5 and 
earlier. These versions of CodeQL were discontinued on 26 March 2024 alongside 
GitHub Enterprise Server 3.8, and will be unsupported by CodeQL Action versions 
3.25.0 and later and versions 2.25.0 and later. https://redirect.github.com/github/codeql-action/pull/2220;>#2220
   
   If you are using one of these versions, please update to CodeQL CLI 
version 2.12.6 or later. For instance, if you have specified a custom version 
of the CLI using the 'tools' input to the 'init' Action, you can remove this 
input to use the default version.
   Alternatively, if you want to continue using a version of the CodeQL CLI 
between 2.11.6 and 2.12.5, you can replace 
github/codeql-action/*@v3 by 
github/codeql-action/*@v3.24.10 and 
github/codeql-action/*@v2 by 
github/codeql-action/*@v2.24.10 in your code scanning workflow to 
ensure you continue using this version of the CodeQL Action.
   
   
   
   3.24.9 - 22 Mar 2024
   
   Update default CodeQL bundle version to 2.16.5. https://redirect.github.com/github/codeql-action/pull/2203;>#2203
   
   3.24.8 - 18 Mar 2024
   
   Improve the ease of debugging extraction issues by increasing the 
verbosity of the extractor logs when running in debug mode. https://redirect.github.com/github/codeql-action/pull/2195;>#2195
   
   3.24.7 - 12 Mar 2024
   
   Update default CodeQL bundle version to 2.16.4. https://redirect.github.com/github/codeql-action/pull/2185;>#2185
   
   3.24.6 - 29 Feb 2024
   
   
   ... (truncated)
   
   
   Commits
   
   https://github.com/github/codeql-action/commit/c7f9125735019aa87cfc361530512d50ea439c71;>c7f9125
 Merge pull request https://redirect.github.com/github/codeql-action/issues/2248;>#2248 
from github/update-v3.25.1-c4fb45143
   https://github.com/github/codeql-action/commit/1c7e8b2cf27fe2842c9131549befe9126c581615;>1c7e8b2
 Update changelog for v3.25.1
   https://github.com/github/codeql-action/commit/c4fb451437765abf5018c6fbf22cce1a7da1e5cc;>c4fb451
 Merge pull request https://redirect.github.com/github/codeql-action/issues/2245;>#2245 
from 

[PR] Bump github/codeql-action from 3.24.10 to 3.25.1 [commons-dbcp]

2024-04-18 Thread via GitHub


dependabot[bot] opened a new pull request, #376:
URL: https://github.com/apache/commons-dbcp/pull/376

   Bumps [github/codeql-action](https://github.com/github/codeql-action) from 
3.24.10 to 3.25.1.
   
   Changelog
   Sourced from https://github.com/github/codeql-action/blob/main/CHANGELOG.md;>github/codeql-action's
 changelog.
   
   CodeQL Action Changelog
   See the https://github.com/github/codeql-action/releases;>releases page for 
the relevant changes to the CodeQL CLI and language packs.
   Note that the only difference between v2 and v3 
of the CodeQL Action is the node version they support, with v3 
running on node 20 while we continue to release v2 to support 
running on node 16. For example 3.22.11 was the first 
v3 release and is functionally identical to 2.22.11. 
This approach ensures an easy way to track exactly which features are included 
in different versions, indicated by the minor and patch version numbers.
   [UNRELEASED]
   No user facing changes.
   3.25.1 - 17 Apr 2024
   
   We are rolling out a feature in April/May 2024 that improves the 
reliability and performance of analyzing code when analyzing a compiled 
language with the autobuild https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages#codeql-build-modes;>build
 mode. https://redirect.github.com/github/codeql-action/pull/2235;>#2235
   Fix a bug where the init Action would fail if 
--overwrite was specified in 
CODEQL_ACTION_EXTRA_OPTIONS. https://redirect.github.com/github/codeql-action/pull/2245;>#2245
   
   3.25.0 - 15 Apr 2024
   
   
   The deprecated feature for extracting dependencies for a Python analysis 
has been removed. https://redirect.github.com/github/codeql-action/pull/2224;>#2224
   As a result, the following inputs and environment variables are now 
ignored:
   
   The setup-python-dependencies input to the 
init Action
   The CODEQL_ACTION_DISABLE_PYTHON_DEPENDENCY_INSTALLATION 
environment variable
   
   We recommend removing any references to these from your workflows. For 
more information, see the release notes for CodeQL Action v3.23.0 and 
v2.23.0.
   
   
   Automatically overwrite an existing database if found on the filesystem. 
https://redirect.github.com/github/codeql-action/pull/2229;>#2229
   
   
   Bump the minimum CodeQL bundle version to 2.12.6. https://redirect.github.com/github/codeql-action/pull/2232;>#2232
   
   
   A more relevant log message and a diagnostic are now emitted when the 
file program is not installed on a Linux runner, but is required 
for Go tracing to succeed. https://redirect.github.com/github/codeql-action/pull/2234;>#2234
   
   
   3.24.10 - 05 Apr 2024
   
   Update default CodeQL bundle version to 2.17.0. https://redirect.github.com/github/codeql-action/pull/2219;>#2219
   Add a deprecation warning for customers using CodeQL version 2.12.5 and 
earlier. These versions of CodeQL were discontinued on 26 March 2024 alongside 
GitHub Enterprise Server 3.8, and will be unsupported by CodeQL Action versions 
3.25.0 and later and versions 2.25.0 and later. https://redirect.github.com/github/codeql-action/pull/2220;>#2220
   
   If you are using one of these versions, please update to CodeQL CLI 
version 2.12.6 or later. For instance, if you have specified a custom version 
of the CLI using the 'tools' input to the 'init' Action, you can remove this 
input to use the default version.
   Alternatively, if you want to continue using a version of the CodeQL CLI 
between 2.11.6 and 2.12.5, you can replace 
github/codeql-action/*@v3 by 
github/codeql-action/*@v3.24.10 and 
github/codeql-action/*@v2 by 
github/codeql-action/*@v2.24.10 in your code scanning workflow to 
ensure you continue using this version of the CodeQL Action.
   
   
   
   3.24.9 - 22 Mar 2024
   
   Update default CodeQL bundle version to 2.16.5. https://redirect.github.com/github/codeql-action/pull/2203;>#2203
   
   3.24.8 - 18 Mar 2024
   
   Improve the ease of debugging extraction issues by increasing the 
verbosity of the extractor logs when running in debug mode. https://redirect.github.com/github/codeql-action/pull/2195;>#2195
   
   3.24.7 - 12 Mar 2024
   
   Update default CodeQL bundle version to 2.16.4. https://redirect.github.com/github/codeql-action/pull/2185;>#2185
   
   3.24.6 - 29 Feb 2024
   
   
   ... (truncated)
   
   
   Commits
   
   https://github.com/github/codeql-action/commit/c7f9125735019aa87cfc361530512d50ea439c71;>c7f9125
 Merge pull request https://redirect.github.com/github/codeql-action/issues/2248;>#2248 
from github/update-v3.25.1-c4fb45143
   https://github.com/github/codeql-action/commit/1c7e8b2cf27fe2842c9131549befe9126c581615;>1c7e8b2
 Update changelog for v3.25.1
   https://github.com/github/codeql-action/commit/c4fb451437765abf5018c6fbf22cce1a7da1e5cc;>c4fb451
 Merge pull request https://redirect.github.com/github/codeql-action/issues/2245;>#2245 
from 

[PR] Bump actions/upload-artifact from 4.3.1 to 4.3.2 [commons-dbcp]

2024-04-18 Thread via GitHub


dependabot[bot] opened a new pull request, #375:
URL: https://github.com/apache/commons-dbcp/pull/375

   Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) 
from 4.3.1 to 4.3.2.
   
   Release notes
   Sourced from https://github.com/actions/upload-artifact/releases;>actions/upload-artifact's
 releases.
   
   v4.3.2
   What's Changed
   
   Update release-new-action-version.yml by https://github.com/konradpabjan;>@​konradpabjan in https://redirect.github.com/actions/upload-artifact/pull/516;>actions/upload-artifact#516
   Minor fix to the migration readme by https://github.com/andrewakim;>@​andrewakim in https://redirect.github.com/actions/upload-artifact/pull/523;>actions/upload-artifact#523
   Update readme with v3/v2/v1 deprecation notice by https://github.com/robherley;>@​robherley in https://redirect.github.com/actions/upload-artifact/pull/561;>actions/upload-artifact#561
   updating @actions/artifact dependency to v2.1.5 and 
@actions/core to v1.0.1 by https://github.com/eggyhead;>@​eggyhead in https://redirect.github.com/actions/upload-artifact/pull/562;>actions/upload-artifact#562
   
   New Contributors
   
   https://github.com/andrewakim;>@​andrewakim 
made their first contribution in https://redirect.github.com/actions/upload-artifact/pull/523;>actions/upload-artifact#523
   
   Full Changelog: https://github.com/actions/upload-artifact/compare/v4.3.1...v4.3.2;>https://github.com/actions/upload-artifact/compare/v4.3.1...v4.3.2
   
   
   
   Commits
   
   https://github.com/actions/upload-artifact/commit/1746f4ab65b179e0ea60a494b83293b640dd5bba;>1746f4a
 Revert updating to release 4.3.2
   https://github.com/actions/upload-artifact/commit/31685d04a0d6557fe2be4174c3ea69ee4cbfa6bb;>31685d0
 updating to release 4.3.2
   https://github.com/actions/upload-artifact/commit/18bf333cd2249fbbbdb605fd9d9ed57efd7adf34;>18bf333
 Merge pull request https://redirect.github.com/actions/upload-artifact/issues/562;>#562 
from actions/eggyhead/update-artifact-v215
   https://github.com/actions/upload-artifact/commit/dac413befa086181ab17cf3db942667aede55e0d;>dac413b
 update package lock version
   https://github.com/actions/upload-artifact/commit/bb3b4a3cdbef901e2e185ca492d513e798fd1b9f;>bb3b4a3
 updating package version
   https://github.com/actions/upload-artifact/commit/3e3da837d2a1e030e44fe2bb5c4b9f63c25f33e3;>3e3da83
 updating artifact and core dependencies
   https://github.com/actions/upload-artifact/commit/e35774f165aac0e3b0c8273137b1845a2ac8c5f1;>e35774f
 Merge pull request https://redirect.github.com/actions/upload-artifact/issues/561;>#561 
from actions/robherley/deprecation-notice
   https://github.com/actions/upload-artifact/commit/e63ea677fb182f6827027a7b74f61debfca990ab;>e63ea67
 Update readme with v3/v2/v1 deprecation notice
   https://github.com/actions/upload-artifact/commit/ef09cdac3e2d3e60d8ccadda691f4f1cec5035cb;>ef09cda
 Merge pull request https://redirect.github.com/actions/upload-artifact/issues/523;>#523 
from andrewakim/andrewakim/migration-readme-fix
   https://github.com/actions/upload-artifact/commit/00e36f94d817ea235422592a23d468b262071bf4;>00e36f9
 Minor fix to the migration readme
   Additional commits viewable in https://github.com/actions/upload-artifact/compare/5d5d22a31266ced268874388b861e4b58bb5c2f3...1746f4ab65b179e0ea60a494b83293b640dd5bba;>compare
 view
   
   
   
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/upload-artifact=github_actions=4.3.1=4.3.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   
   Dependabot commands and options
   
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI 
passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and 
block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. 
You can achieve the same result by closing it manually
   - `@dependabot show  ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot 

[PR] Bump github/codeql-action from 3.24.10 to 3.25.1 [commons-net]

2024-04-18 Thread via GitHub


dependabot[bot] opened a new pull request, #243:
URL: https://github.com/apache/commons-net/pull/243

   Bumps [github/codeql-action](https://github.com/github/codeql-action) from 
3.24.10 to 3.25.1.
   
   Changelog
   Sourced from https://github.com/github/codeql-action/blob/main/CHANGELOG.md;>github/codeql-action's
 changelog.
   
   CodeQL Action Changelog
   See the https://github.com/github/codeql-action/releases;>releases page for 
the relevant changes to the CodeQL CLI and language packs.
   Note that the only difference between v2 and v3 
of the CodeQL Action is the node version they support, with v3 
running on node 20 while we continue to release v2 to support 
running on node 16. For example 3.22.11 was the first 
v3 release and is functionally identical to 2.22.11. 
This approach ensures an easy way to track exactly which features are included 
in different versions, indicated by the minor and patch version numbers.
   [UNRELEASED]
   No user facing changes.
   3.25.1 - 17 Apr 2024
   
   We are rolling out a feature in April/May 2024 that improves the 
reliability and performance of analyzing code when analyzing a compiled 
language with the autobuild https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages#codeql-build-modes;>build
 mode. https://redirect.github.com/github/codeql-action/pull/2235;>#2235
   Fix a bug where the init Action would fail if 
--overwrite was specified in 
CODEQL_ACTION_EXTRA_OPTIONS. https://redirect.github.com/github/codeql-action/pull/2245;>#2245
   
   3.25.0 - 15 Apr 2024
   
   
   The deprecated feature for extracting dependencies for a Python analysis 
has been removed. https://redirect.github.com/github/codeql-action/pull/2224;>#2224
   As a result, the following inputs and environment variables are now 
ignored:
   
   The setup-python-dependencies input to the 
init Action
   The CODEQL_ACTION_DISABLE_PYTHON_DEPENDENCY_INSTALLATION 
environment variable
   
   We recommend removing any references to these from your workflows. For 
more information, see the release notes for CodeQL Action v3.23.0 and 
v2.23.0.
   
   
   Automatically overwrite an existing database if found on the filesystem. 
https://redirect.github.com/github/codeql-action/pull/2229;>#2229
   
   
   Bump the minimum CodeQL bundle version to 2.12.6. https://redirect.github.com/github/codeql-action/pull/2232;>#2232
   
   
   A more relevant log message and a diagnostic are now emitted when the 
file program is not installed on a Linux runner, but is required 
for Go tracing to succeed. https://redirect.github.com/github/codeql-action/pull/2234;>#2234
   
   
   3.24.10 - 05 Apr 2024
   
   Update default CodeQL bundle version to 2.17.0. https://redirect.github.com/github/codeql-action/pull/2219;>#2219
   Add a deprecation warning for customers using CodeQL version 2.12.5 and 
earlier. These versions of CodeQL were discontinued on 26 March 2024 alongside 
GitHub Enterprise Server 3.8, and will be unsupported by CodeQL Action versions 
3.25.0 and later and versions 2.25.0 and later. https://redirect.github.com/github/codeql-action/pull/2220;>#2220
   
   If you are using one of these versions, please update to CodeQL CLI 
version 2.12.6 or later. For instance, if you have specified a custom version 
of the CLI using the 'tools' input to the 'init' Action, you can remove this 
input to use the default version.
   Alternatively, if you want to continue using a version of the CodeQL CLI 
between 2.11.6 and 2.12.5, you can replace 
github/codeql-action/*@v3 by 
github/codeql-action/*@v3.24.10 and 
github/codeql-action/*@v2 by 
github/codeql-action/*@v2.24.10 in your code scanning workflow to 
ensure you continue using this version of the CodeQL Action.
   
   
   
   3.24.9 - 22 Mar 2024
   
   Update default CodeQL bundle version to 2.16.5. https://redirect.github.com/github/codeql-action/pull/2203;>#2203
   
   3.24.8 - 18 Mar 2024
   
   Improve the ease of debugging extraction issues by increasing the 
verbosity of the extractor logs when running in debug mode. https://redirect.github.com/github/codeql-action/pull/2195;>#2195
   
   3.24.7 - 12 Mar 2024
   
   Update default CodeQL bundle version to 2.16.4. https://redirect.github.com/github/codeql-action/pull/2185;>#2185
   
   3.24.6 - 29 Feb 2024
   
   
   ... (truncated)
   
   
   Commits
   
   https://github.com/github/codeql-action/commit/c7f9125735019aa87cfc361530512d50ea439c71;>c7f9125
 Merge pull request https://redirect.github.com/github/codeql-action/issues/2248;>#2248 
from github/update-v3.25.1-c4fb45143
   https://github.com/github/codeql-action/commit/1c7e8b2cf27fe2842c9131549befe9126c581615;>1c7e8b2
 Update changelog for v3.25.1
   https://github.com/github/codeql-action/commit/c4fb451437765abf5018c6fbf22cce1a7da1e5cc;>c4fb451
 Merge pull request https://redirect.github.com/github/codeql-action/issues/2245;>#2245 
from 

[PR] Bump actions/upload-artifact from 4.3.1 to 4.3.2 [commons-net]

2024-04-18 Thread via GitHub


dependabot[bot] opened a new pull request, #244:
URL: https://github.com/apache/commons-net/pull/244

   Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) 
from 4.3.1 to 4.3.2.
   
   Release notes
   Sourced from https://github.com/actions/upload-artifact/releases;>actions/upload-artifact's
 releases.
   
   v4.3.2
   What's Changed
   
   Update release-new-action-version.yml by https://github.com/konradpabjan;>@​konradpabjan in https://redirect.github.com/actions/upload-artifact/pull/516;>actions/upload-artifact#516
   Minor fix to the migration readme by https://github.com/andrewakim;>@​andrewakim in https://redirect.github.com/actions/upload-artifact/pull/523;>actions/upload-artifact#523
   Update readme with v3/v2/v1 deprecation notice by https://github.com/robherley;>@​robherley in https://redirect.github.com/actions/upload-artifact/pull/561;>actions/upload-artifact#561
   updating @actions/artifact dependency to v2.1.5 and 
@actions/core to v1.0.1 by https://github.com/eggyhead;>@​eggyhead in https://redirect.github.com/actions/upload-artifact/pull/562;>actions/upload-artifact#562
   
   New Contributors
   
   https://github.com/andrewakim;>@​andrewakim 
made their first contribution in https://redirect.github.com/actions/upload-artifact/pull/523;>actions/upload-artifact#523
   
   Full Changelog: https://github.com/actions/upload-artifact/compare/v4.3.1...v4.3.2;>https://github.com/actions/upload-artifact/compare/v4.3.1...v4.3.2
   
   
   
   Commits
   
   https://github.com/actions/upload-artifact/commit/1746f4ab65b179e0ea60a494b83293b640dd5bba;>1746f4a
 Revert updating to release 4.3.2
   https://github.com/actions/upload-artifact/commit/31685d04a0d6557fe2be4174c3ea69ee4cbfa6bb;>31685d0
 updating to release 4.3.2
   https://github.com/actions/upload-artifact/commit/18bf333cd2249fbbbdb605fd9d9ed57efd7adf34;>18bf333
 Merge pull request https://redirect.github.com/actions/upload-artifact/issues/562;>#562 
from actions/eggyhead/update-artifact-v215
   https://github.com/actions/upload-artifact/commit/dac413befa086181ab17cf3db942667aede55e0d;>dac413b
 update package lock version
   https://github.com/actions/upload-artifact/commit/bb3b4a3cdbef901e2e185ca492d513e798fd1b9f;>bb3b4a3
 updating package version
   https://github.com/actions/upload-artifact/commit/3e3da837d2a1e030e44fe2bb5c4b9f63c25f33e3;>3e3da83
 updating artifact and core dependencies
   https://github.com/actions/upload-artifact/commit/e35774f165aac0e3b0c8273137b1845a2ac8c5f1;>e35774f
 Merge pull request https://redirect.github.com/actions/upload-artifact/issues/561;>#561 
from actions/robherley/deprecation-notice
   https://github.com/actions/upload-artifact/commit/e63ea677fb182f6827027a7b74f61debfca990ab;>e63ea67
 Update readme with v3/v2/v1 deprecation notice
   https://github.com/actions/upload-artifact/commit/ef09cdac3e2d3e60d8ccadda691f4f1cec5035cb;>ef09cda
 Merge pull request https://redirect.github.com/actions/upload-artifact/issues/523;>#523 
from andrewakim/andrewakim/migration-readme-fix
   https://github.com/actions/upload-artifact/commit/00e36f94d817ea235422592a23d468b262071bf4;>00e36f9
 Minor fix to the migration readme
   Additional commits viewable in https://github.com/actions/upload-artifact/compare/5d5d22a31266ced268874388b861e4b58bb5c2f3...1746f4ab65b179e0ea60a494b83293b640dd5bba;>compare
 view
   
   
   
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/upload-artifact=github_actions=4.3.1=4.3.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   
   Dependabot commands and options
   
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI 
passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and 
block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. 
You can achieve the same result by closing it manually
   - `@dependabot show  ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot 

[PR] Bump actions/upload-artifact from 4.3.1 to 4.3.2 [commons-io]

2024-04-18 Thread via GitHub


dependabot[bot] opened a new pull request, #614:
URL: https://github.com/apache/commons-io/pull/614

   Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) 
from 4.3.1 to 4.3.2.
   
   Release notes
   Sourced from https://github.com/actions/upload-artifact/releases;>actions/upload-artifact's
 releases.
   
   v4.3.2
   What's Changed
   
   Update release-new-action-version.yml by https://github.com/konradpabjan;>@​konradpabjan in https://redirect.github.com/actions/upload-artifact/pull/516;>actions/upload-artifact#516
   Minor fix to the migration readme by https://github.com/andrewakim;>@​andrewakim in https://redirect.github.com/actions/upload-artifact/pull/523;>actions/upload-artifact#523
   Update readme with v3/v2/v1 deprecation notice by https://github.com/robherley;>@​robherley in https://redirect.github.com/actions/upload-artifact/pull/561;>actions/upload-artifact#561
   updating @actions/artifact dependency to v2.1.5 and 
@actions/core to v1.0.1 by https://github.com/eggyhead;>@​eggyhead in https://redirect.github.com/actions/upload-artifact/pull/562;>actions/upload-artifact#562
   
   New Contributors
   
   https://github.com/andrewakim;>@​andrewakim 
made their first contribution in https://redirect.github.com/actions/upload-artifact/pull/523;>actions/upload-artifact#523
   
   Full Changelog: https://github.com/actions/upload-artifact/compare/v4.3.1...v4.3.2;>https://github.com/actions/upload-artifact/compare/v4.3.1...v4.3.2
   
   
   
   Commits
   
   https://github.com/actions/upload-artifact/commit/1746f4ab65b179e0ea60a494b83293b640dd5bba;>1746f4a
 Revert updating to release 4.3.2
   https://github.com/actions/upload-artifact/commit/31685d04a0d6557fe2be4174c3ea69ee4cbfa6bb;>31685d0
 updating to release 4.3.2
   https://github.com/actions/upload-artifact/commit/18bf333cd2249fbbbdb605fd9d9ed57efd7adf34;>18bf333
 Merge pull request https://redirect.github.com/actions/upload-artifact/issues/562;>#562 
from actions/eggyhead/update-artifact-v215
   https://github.com/actions/upload-artifact/commit/dac413befa086181ab17cf3db942667aede55e0d;>dac413b
 update package lock version
   https://github.com/actions/upload-artifact/commit/bb3b4a3cdbef901e2e185ca492d513e798fd1b9f;>bb3b4a3
 updating package version
   https://github.com/actions/upload-artifact/commit/3e3da837d2a1e030e44fe2bb5c4b9f63c25f33e3;>3e3da83
 updating artifact and core dependencies
   https://github.com/actions/upload-artifact/commit/e35774f165aac0e3b0c8273137b1845a2ac8c5f1;>e35774f
 Merge pull request https://redirect.github.com/actions/upload-artifact/issues/561;>#561 
from actions/robherley/deprecation-notice
   https://github.com/actions/upload-artifact/commit/e63ea677fb182f6827027a7b74f61debfca990ab;>e63ea67
 Update readme with v3/v2/v1 deprecation notice
   https://github.com/actions/upload-artifact/commit/ef09cdac3e2d3e60d8ccadda691f4f1cec5035cb;>ef09cda
 Merge pull request https://redirect.github.com/actions/upload-artifact/issues/523;>#523 
from andrewakim/andrewakim/migration-readme-fix
   https://github.com/actions/upload-artifact/commit/00e36f94d817ea235422592a23d468b262071bf4;>00e36f9
 Minor fix to the migration readme
   Additional commits viewable in https://github.com/actions/upload-artifact/compare/5d5d22a31266ced268874388b861e4b58bb5c2f3...1746f4ab65b179e0ea60a494b83293b640dd5bba;>compare
 view
   
   
   
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/upload-artifact=github_actions=4.3.1=4.3.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   
   Dependabot commands and options
   
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI 
passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and 
block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. 
You can achieve the same result by closing it manually
   - `@dependabot show  ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot 

[PR] Bump github/codeql-action from 3.24.10 to 3.25.1 [commons-io]

2024-04-18 Thread via GitHub


dependabot[bot] opened a new pull request, #613:
URL: https://github.com/apache/commons-io/pull/613

   Bumps [github/codeql-action](https://github.com/github/codeql-action) from 
3.24.10 to 3.25.1.
   
   Changelog
   Sourced from https://github.com/github/codeql-action/blob/main/CHANGELOG.md;>github/codeql-action's
 changelog.
   
   CodeQL Action Changelog
   See the https://github.com/github/codeql-action/releases;>releases page for 
the relevant changes to the CodeQL CLI and language packs.
   Note that the only difference between v2 and v3 
of the CodeQL Action is the node version they support, with v3 
running on node 20 while we continue to release v2 to support 
running on node 16. For example 3.22.11 was the first 
v3 release and is functionally identical to 2.22.11. 
This approach ensures an easy way to track exactly which features are included 
in different versions, indicated by the minor and patch version numbers.
   [UNRELEASED]
   No user facing changes.
   3.25.1 - 17 Apr 2024
   
   We are rolling out a feature in April/May 2024 that improves the 
reliability and performance of analyzing code when analyzing a compiled 
language with the autobuild https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages#codeql-build-modes;>build
 mode. https://redirect.github.com/github/codeql-action/pull/2235;>#2235
   Fix a bug where the init Action would fail if 
--overwrite was specified in 
CODEQL_ACTION_EXTRA_OPTIONS. https://redirect.github.com/github/codeql-action/pull/2245;>#2245
   
   3.25.0 - 15 Apr 2024
   
   
   The deprecated feature for extracting dependencies for a Python analysis 
has been removed. https://redirect.github.com/github/codeql-action/pull/2224;>#2224
   As a result, the following inputs and environment variables are now 
ignored:
   
   The setup-python-dependencies input to the 
init Action
   The CODEQL_ACTION_DISABLE_PYTHON_DEPENDENCY_INSTALLATION 
environment variable
   
   We recommend removing any references to these from your workflows. For 
more information, see the release notes for CodeQL Action v3.23.0 and 
v2.23.0.
   
   
   Automatically overwrite an existing database if found on the filesystem. 
https://redirect.github.com/github/codeql-action/pull/2229;>#2229
   
   
   Bump the minimum CodeQL bundle version to 2.12.6. https://redirect.github.com/github/codeql-action/pull/2232;>#2232
   
   
   A more relevant log message and a diagnostic are now emitted when the 
file program is not installed on a Linux runner, but is required 
for Go tracing to succeed. https://redirect.github.com/github/codeql-action/pull/2234;>#2234
   
   
   3.24.10 - 05 Apr 2024
   
   Update default CodeQL bundle version to 2.17.0. https://redirect.github.com/github/codeql-action/pull/2219;>#2219
   Add a deprecation warning for customers using CodeQL version 2.12.5 and 
earlier. These versions of CodeQL were discontinued on 26 March 2024 alongside 
GitHub Enterprise Server 3.8, and will be unsupported by CodeQL Action versions 
3.25.0 and later and versions 2.25.0 and later. https://redirect.github.com/github/codeql-action/pull/2220;>#2220
   
   If you are using one of these versions, please update to CodeQL CLI 
version 2.12.6 or later. For instance, if you have specified a custom version 
of the CLI using the 'tools' input to the 'init' Action, you can remove this 
input to use the default version.
   Alternatively, if you want to continue using a version of the CodeQL CLI 
between 2.11.6 and 2.12.5, you can replace 
github/codeql-action/*@v3 by 
github/codeql-action/*@v3.24.10 and 
github/codeql-action/*@v2 by 
github/codeql-action/*@v2.24.10 in your code scanning workflow to 
ensure you continue using this version of the CodeQL Action.
   
   
   
   3.24.9 - 22 Mar 2024
   
   Update default CodeQL bundle version to 2.16.5. https://redirect.github.com/github/codeql-action/pull/2203;>#2203
   
   3.24.8 - 18 Mar 2024
   
   Improve the ease of debugging extraction issues by increasing the 
verbosity of the extractor logs when running in debug mode. https://redirect.github.com/github/codeql-action/pull/2195;>#2195
   
   3.24.7 - 12 Mar 2024
   
   Update default CodeQL bundle version to 2.16.4. https://redirect.github.com/github/codeql-action/pull/2185;>#2185
   
   3.24.6 - 29 Feb 2024
   
   
   ... (truncated)
   
   
   Commits
   
   https://github.com/github/codeql-action/commit/c7f9125735019aa87cfc361530512d50ea439c71;>c7f9125
 Merge pull request https://redirect.github.com/github/codeql-action/issues/2248;>#2248 
from github/update-v3.25.1-c4fb45143
   https://github.com/github/codeql-action/commit/1c7e8b2cf27fe2842c9131549befe9126c581615;>1c7e8b2
 Update changelog for v3.25.1
   https://github.com/github/codeql-action/commit/c4fb451437765abf5018c6fbf22cce1a7da1e5cc;>c4fb451
 Merge pull request https://redirect.github.com/github/codeql-action/issues/2245;>#2245 
from 

[PR] Bump github/codeql-action from 3.24.10 to 3.25.1 [commons-scxml]

2024-04-18 Thread via GitHub


dependabot[bot] opened a new pull request, #217:
URL: https://github.com/apache/commons-scxml/pull/217

   Bumps [github/codeql-action](https://github.com/github/codeql-action) from 
3.24.10 to 3.25.1.
   
   Changelog
   Sourced from https://github.com/github/codeql-action/blob/main/CHANGELOG.md;>github/codeql-action's
 changelog.
   
   CodeQL Action Changelog
   See the https://github.com/github/codeql-action/releases;>releases page for 
the relevant changes to the CodeQL CLI and language packs.
   Note that the only difference between v2 and v3 
of the CodeQL Action is the node version they support, with v3 
running on node 20 while we continue to release v2 to support 
running on node 16. For example 3.22.11 was the first 
v3 release and is functionally identical to 2.22.11. 
This approach ensures an easy way to track exactly which features are included 
in different versions, indicated by the minor and patch version numbers.
   [UNRELEASED]
   No user facing changes.
   3.25.1 - 17 Apr 2024
   
   We are rolling out a feature in April/May 2024 that improves the 
reliability and performance of analyzing code when analyzing a compiled 
language with the autobuild https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages#codeql-build-modes;>build
 mode. https://redirect.github.com/github/codeql-action/pull/2235;>#2235
   Fix a bug where the init Action would fail if 
--overwrite was specified in 
CODEQL_ACTION_EXTRA_OPTIONS. https://redirect.github.com/github/codeql-action/pull/2245;>#2245
   
   3.25.0 - 15 Apr 2024
   
   
   The deprecated feature for extracting dependencies for a Python analysis 
has been removed. https://redirect.github.com/github/codeql-action/pull/2224;>#2224
   As a result, the following inputs and environment variables are now 
ignored:
   
   The setup-python-dependencies input to the 
init Action
   The CODEQL_ACTION_DISABLE_PYTHON_DEPENDENCY_INSTALLATION 
environment variable
   
   We recommend removing any references to these from your workflows. For 
more information, see the release notes for CodeQL Action v3.23.0 and 
v2.23.0.
   
   
   Automatically overwrite an existing database if found on the filesystem. 
https://redirect.github.com/github/codeql-action/pull/2229;>#2229
   
   
   Bump the minimum CodeQL bundle version to 2.12.6. https://redirect.github.com/github/codeql-action/pull/2232;>#2232
   
   
   A more relevant log message and a diagnostic are now emitted when the 
file program is not installed on a Linux runner, but is required 
for Go tracing to succeed. https://redirect.github.com/github/codeql-action/pull/2234;>#2234
   
   
   3.24.10 - 05 Apr 2024
   
   Update default CodeQL bundle version to 2.17.0. https://redirect.github.com/github/codeql-action/pull/2219;>#2219
   Add a deprecation warning for customers using CodeQL version 2.12.5 and 
earlier. These versions of CodeQL were discontinued on 26 March 2024 alongside 
GitHub Enterprise Server 3.8, and will be unsupported by CodeQL Action versions 
3.25.0 and later and versions 2.25.0 and later. https://redirect.github.com/github/codeql-action/pull/2220;>#2220
   
   If you are using one of these versions, please update to CodeQL CLI 
version 2.12.6 or later. For instance, if you have specified a custom version 
of the CLI using the 'tools' input to the 'init' Action, you can remove this 
input to use the default version.
   Alternatively, if you want to continue using a version of the CodeQL CLI 
between 2.11.6 and 2.12.5, you can replace 
github/codeql-action/*@v3 by 
github/codeql-action/*@v3.24.10 and 
github/codeql-action/*@v2 by 
github/codeql-action/*@v2.24.10 in your code scanning workflow to 
ensure you continue using this version of the CodeQL Action.
   
   
   
   3.24.9 - 22 Mar 2024
   
   Update default CodeQL bundle version to 2.16.5. https://redirect.github.com/github/codeql-action/pull/2203;>#2203
   
   3.24.8 - 18 Mar 2024
   
   Improve the ease of debugging extraction issues by increasing the 
verbosity of the extractor logs when running in debug mode. https://redirect.github.com/github/codeql-action/pull/2195;>#2195
   
   3.24.7 - 12 Mar 2024
   
   Update default CodeQL bundle version to 2.16.4. https://redirect.github.com/github/codeql-action/pull/2185;>#2185
   
   3.24.6 - 29 Feb 2024
   
   
   ... (truncated)
   
   
   Commits
   
   https://github.com/github/codeql-action/commit/c7f9125735019aa87cfc361530512d50ea439c71;>c7f9125
 Merge pull request https://redirect.github.com/github/codeql-action/issues/2248;>#2248 
from github/update-v3.25.1-c4fb45143
   https://github.com/github/codeql-action/commit/1c7e8b2cf27fe2842c9131549befe9126c581615;>1c7e8b2
 Update changelog for v3.25.1
   https://github.com/github/codeql-action/commit/c4fb451437765abf5018c6fbf22cce1a7da1e5cc;>c4fb451
 Merge pull request https://redirect.github.com/github/codeql-action/issues/2245;>#2245 
from 

[PR] Bump actions/upload-artifact from 4.3.1 to 4.3.2 [commons-scxml]

2024-04-18 Thread via GitHub


dependabot[bot] opened a new pull request, #216:
URL: https://github.com/apache/commons-scxml/pull/216

   Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) 
from 4.3.1 to 4.3.2.
   
   Release notes
   Sourced from https://github.com/actions/upload-artifact/releases;>actions/upload-artifact's
 releases.
   
   v4.3.2
   What's Changed
   
   Update release-new-action-version.yml by https://github.com/konradpabjan;>@​konradpabjan in https://redirect.github.com/actions/upload-artifact/pull/516;>actions/upload-artifact#516
   Minor fix to the migration readme by https://github.com/andrewakim;>@​andrewakim in https://redirect.github.com/actions/upload-artifact/pull/523;>actions/upload-artifact#523
   Update readme with v3/v2/v1 deprecation notice by https://github.com/robherley;>@​robherley in https://redirect.github.com/actions/upload-artifact/pull/561;>actions/upload-artifact#561
   updating @actions/artifact dependency to v2.1.5 and 
@actions/core to v1.0.1 by https://github.com/eggyhead;>@​eggyhead in https://redirect.github.com/actions/upload-artifact/pull/562;>actions/upload-artifact#562
   
   New Contributors
   
   https://github.com/andrewakim;>@​andrewakim 
made their first contribution in https://redirect.github.com/actions/upload-artifact/pull/523;>actions/upload-artifact#523
   
   Full Changelog: https://github.com/actions/upload-artifact/compare/v4.3.1...v4.3.2;>https://github.com/actions/upload-artifact/compare/v4.3.1...v4.3.2
   
   
   
   Commits
   
   https://github.com/actions/upload-artifact/commit/1746f4ab65b179e0ea60a494b83293b640dd5bba;>1746f4a
 Revert updating to release 4.3.2
   https://github.com/actions/upload-artifact/commit/31685d04a0d6557fe2be4174c3ea69ee4cbfa6bb;>31685d0
 updating to release 4.3.2
   https://github.com/actions/upload-artifact/commit/18bf333cd2249fbbbdb605fd9d9ed57efd7adf34;>18bf333
 Merge pull request https://redirect.github.com/actions/upload-artifact/issues/562;>#562 
from actions/eggyhead/update-artifact-v215
   https://github.com/actions/upload-artifact/commit/dac413befa086181ab17cf3db942667aede55e0d;>dac413b
 update package lock version
   https://github.com/actions/upload-artifact/commit/bb3b4a3cdbef901e2e185ca492d513e798fd1b9f;>bb3b4a3
 updating package version
   https://github.com/actions/upload-artifact/commit/3e3da837d2a1e030e44fe2bb5c4b9f63c25f33e3;>3e3da83
 updating artifact and core dependencies
   https://github.com/actions/upload-artifact/commit/e35774f165aac0e3b0c8273137b1845a2ac8c5f1;>e35774f
 Merge pull request https://redirect.github.com/actions/upload-artifact/issues/561;>#561 
from actions/robherley/deprecation-notice
   https://github.com/actions/upload-artifact/commit/e63ea677fb182f6827027a7b74f61debfca990ab;>e63ea67
 Update readme with v3/v2/v1 deprecation notice
   https://github.com/actions/upload-artifact/commit/ef09cdac3e2d3e60d8ccadda691f4f1cec5035cb;>ef09cda
 Merge pull request https://redirect.github.com/actions/upload-artifact/issues/523;>#523 
from andrewakim/andrewakim/migration-readme-fix
   https://github.com/actions/upload-artifact/commit/00e36f94d817ea235422592a23d468b262071bf4;>00e36f9
 Minor fix to the migration readme
   Additional commits viewable in https://github.com/actions/upload-artifact/compare/5d5d22a31266ced268874388b861e4b58bb5c2f3...1746f4ab65b179e0ea60a494b83293b640dd5bba;>compare
 view
   
   
   
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=actions/upload-artifact=github_actions=4.3.1=4.3.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   
   Dependabot commands and options
   
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI 
passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and 
block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. 
You can achieve the same result by closing it manually
   - `@dependabot show  ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot 

[PR] Bump org.apache.commons:commons-build-plugin from 1.13 to 1.14.0 [commons-parent]

2024-04-18 Thread via GitHub


dependabot[bot] opened a new pull request, #397:
URL: https://github.com/apache/commons-parent/pull/397

   Bumps 
[org.apache.commons:commons-build-plugin](https://github.com/apache/commons-build-plugin)
 from 1.13 to 1.14.0.
   
   Changelog
   Sourced from https://github.com/apache/commons-build-plugin/blob/master/RELEASE-NOTES.txt;>org.apache.commons:commons-build-plugin's
 changelog.
   
   Apache Commons Build Plugin Maven Mojo 1.14.0 RELEASE NOTES
   Apache Maven Mojo for Apache Commons Build tasks.
   For example:
   mvn commons-build:download-page [-Dcommons.release.version=1.2.3]
   To use a SNAPSHOT version (for testing etc)
   mvn org.apache.commons:commons-build-plugin:1.14.0-SNAPSHOT:download-page 
[-Dcommons.release.version=1.2.3]
   Feature release
   Changes in this version include:
   New features
   
   
 Add Maven property project.build.outputTimestamp 
for build reproducibility. Thanks to Gary Gregory.
   
   
   
   Fixed Bugs
   
   
 maven-plugin-report-plugin replaces 
maven-plugin-plugin report goal
   
   
   
 Fix up errors in GHA badges for Java and CodeQL
   
   
   
 Only use graalvm on Java11+; update to 22.3.3 which 
avoids NoClassDefFoundError messages
   
   
   
 Replace mail-archives.apache.org with 
lists.apache.org
   
   
   
 Drop mail archives that no longer exist (markmail, 
gmane, old.nabble)
   
   
   
 Disable moditect as it fails currently
   
   
   
   Changes
   
   
 Bump org.apache.maven.plugins:maven-plugin-plugin 
from 3.10.2 to 3.11.0 Thanks to Dependabot.
   
   
   
 Drop IRC references Thanks to Gary Gregory.
   
   
   
 Bump commons-parent from 58 to 69 
[#240](https://github.com/apache/commons-build-plugin/issues/240). Thanks to 
Gary Gregory.
   
   
   
 Bump org.apache.ant:ant-launcher from 1.10.12 to 
1.10.14. Thanks to Dependabot, Gary Gregory.
   
   
   
 Disable cyclonedx - not needed
   
   
   
 Drop outdated, unmaintained table of components in 
README in favour of link to website.
   
   
   
 Bump org.graalvm.js:js-scriptengine from 23.1.0 to 
24.0.0 [#236](https://github.com/apache/commons-build-plugin/issues/236). 
Thanks to Dependabot.
   
   
   
 Bump org.graalvm.js:js from 23.0.1 to 23.0.3. 
Thanks to Dependabot.
   
   
   
 Bump org.apache.maven:maven-core 3.9.4 to 3.9.6. 
Thanks to Gary Gregory.
   
   
   
 Bump org.apache.maven:maven-plugin-api 3.9.4 to 
3.9.6. Thanks to Gary Gregory.
   
   
   
 Bump org.apache.maven.plugin-tools:maven-script-ant 
3.9.0 to 3.12.0 
[#241](https://github.com/apache/commons-build-plugin/issues/241). Thanks to 
Gary Gregory.
   
   
   
 Bump 
org.apache.maven.plugin-tools:maven-plugin-tools-ant from 3.9.0 to 3.12.0 
[#242](https://github.com/apache/commons-build-plugin/issues/242). Thanks to 
Gary Gregory.
   
   
   
 Bump org.apache.maven.plugins:maven-artifact-plugin 
from 3.5.0 to 3.5.1 
[#393](https://github.com/apache/commons-build-plugin/issues/393). Thanks to 
Dependabot, Gary Gregory.
   
   
   
   For complete information on Apache Commons Build Plugin Maven Mojo, 
including instructions on how to submit bug reports,
   patches, or suggestions for improvement, see the Apache Commons Build Plugin 
Maven Mojo website:
   
   
   ... (truncated)
   
   
   Commits
   
   https://github.com/apache/commons-build-plugin/commit/005b742c583eab2dc87b3ec50a447574f7c26b2b;>005b742
 Prepare for the next release candidate
   https://github.com/apache/commons-build-plugin/commit/617df21eb171b875a4e7e270352699d77e39675e;>617df21
 Prepare for the next release candidate
   https://github.com/apache/commons-build-plugin/commit/3e4eac20bca703c24e62614bedccc7631716664b;>3e4eac2
 Prepare for the next release candidate
   https://github.com/apache/commons-build-plugin/commit/ec755383ba87d7d2849fdc26f957d4b29ee9a39c;>ec75538
 Prepare for the next release candidate
   https://github.com/apache/commons-build-plugin/commit/d7567af2b75024906ed99d20f51af1ac8139497a;>d7567af
 Prepare for the next release candidate
   https://github.com/apache/commons-build-plugin/commit/712c4781ca0a5dca492c46fb3de6ffe9c2cb2150;>712c478
 Bump github/codeql-action from 3.24.9 to 3.24.10 (https://redirect.github.com/apache/commons-build-plugin/issues/246;>#246)
   https://github.com/apache/commons-build-plugin/commit/965dd316ebc49021f112820aeb275d30cc69b043;>965dd31
 Bump codecov/codecov-action from 4.2.0 to 4.3.0 (https://redirect.github.com/apache/commons-build-plugin/issues/245;>#245)
   https://github.com/apache/commons-build-plugin/commit/b80b87aa3abed2529dcb1d8d6b1f0dab0bf643db;>b80b87a
 Bump some dependencies
   

[PR] Bump org.apache.maven.plugins:maven-jar-plugin from 3.3.0 to 3.4.0 [commons-parent]

2024-04-18 Thread via GitHub


dependabot[bot] opened a new pull request, #398:
URL: https://github.com/apache/commons-parent/pull/398

   Bumps 
[org.apache.maven.plugins:maven-jar-plugin](https://github.com/apache/maven-jar-plugin)
 from 3.3.0 to 3.4.0.
   
   Release notes
   Sourced from https://github.com/apache/maven-jar-plugin/releases;>org.apache.maven.plugins:maven-jar-plugin's
 releases.
   
   3.4.0
   
    New features and improvements
   
   https://issues.apache.org/jira/browse/MJAR-296;>[MJAR-296] 
- Allow including files excluded by default. (https://redirect.github.com/apache/maven-jar-plugin/pull/67;>#67) https://github.com/redzi;>@​redzi
   https://issues.apache.org/jira/browse/MJAR-302;>[MJAR-302] 
- Require Maven 3.6.3 (https://redirect.github.com/apache/maven-jar-plugin/pull/77;>#77) https://github.com/slawekjaranowski;>@​slawekjaranowski
   https://issues.apache.org/jira/browse/MJAR-292;>[MJAR-292] 
- Detect MRJAR and add Multi-Release manifest entry (https://redirect.github.com/apache/maven-jar-plugin/pull/57;>#57) https://github.com/jorsol;>@​jorsol
   
    Bug Fixes
   
   https://issues.apache.org/jira/browse/MJAR-62;>[MJAR-62] - 
Set Build-Jdk according to used toolchain (https://redirect.github.com/apache/maven-jar-plugin/pull/73;>#73) https://github.com/slawekjaranowski;>@​slawekjaranowski
   
    Dependency updates
   
   https://issues.apache.org/jira/browse/MJAR-306;>[MJAR-306] 
- Use properties for plugins versions in LifecycleMapping (https://redirect.github.com/apache/maven-jar-plugin/pull/82;>#82) https://github.com/slawekjaranowski;>@​slawekjaranowski
   Bump org.junit:junit-bom from 5.10.1 to 5.10.2 (https://redirect.github.com/apache/maven-jar-plugin/pull/74;>#74) https://github.com/dependabot;>@​dependabot
   https://issues.apache.org/jira/browse/MJAR-298;>[MJAR-298] 
- Update Maven-Archiver to 3.6.2 (https://redirect.github.com/apache/maven-jar-plugin/pull/78;>#78) https://github.com/slawekjaranowski;>@​slawekjaranowski
   Bump apache/maven-gh-actions-shared from 2 to 4 (https://redirect.github.com/apache/maven-jar-plugin/pull/72;>#72) https://github.com/dependabot;>@​dependabot
   Bump commons-io:commons-io from 2.14.0 to 2.15.1 (https://redirect.github.com/apache/maven-jar-plugin/pull/68;>#68) https://github.com/dependabot;>@​dependabot
   https://issues.apache.org/jira/browse/MJAR-297;>[MJAR-297] 
- Update Parent to 40 (https://redirect.github.com/apache/maven-jar-plugin/pull/64;>#64) https://github.com/jorsol;>@​jorsol
   https://issues.apache.org/jira/browse/MJAR-298;>[MJAR-298] 
- Update Maven-Archiver to 3.6.1 (https://redirect.github.com/apache/maven-jar-plugin/pull/65;>#65) https://github.com/jorsol;>@​jorsol
   https://issues.apache.org/jira/browse/MJAR-293;>[MJAR-293] 
- Update Parent to 39 (https://redirect.github.com/apache/maven-jar-plugin/pull/59;>#59) https://github.com/jorsol;>@​jorsol
   
    Maintenance
   
   https://issues.apache.org/jira/browse/MJAR-304;>[MJAR-304] 
- Refresh download page (https://redirect.github.com/apache/maven-jar-plugin/pull/80;>#80) https://github.com/slawekjaranowski;>@​slawekjaranowski
   https://issues.apache.org/jira/browse/MJAR-303;>[MJAR-303] 
- Cleanup declared dependencies (https://redirect.github.com/apache/maven-jar-plugin/pull/79;>#79) https://github.com/slawekjaranowski;>@​slawekjaranowski
   Remove dependency on plexus (https://redirect.github.com/apache/maven-jar-plugin/pull/63;>#63) https://github.com/elharo;>@​elharo
   
   
   
   
   Commits
   
   https://github.com/apache/maven-jar-plugin/commit/992f44a2ef710326a6b98e18d4e40f724bea5f90;>992f44a
 [maven-release-plugin] prepare release maven-jar-plugin-3.4.0
   https://github.com/apache/maven-jar-plugin/commit/5e31b9933a68a44b180a499636f7f43c8521648c;>5e31b99
 [MJAR-296] Allow including files excluded by default. (https://redirect.github.com/apache/maven-jar-plugin/issues/67;>#67)
   https://github.com/apache/maven-jar-plugin/commit/ddfb635b55ec1ad23f83c4884a743b4a6c80a273;>ddfb635
 [MJAR-306] Use properties for plugins versions in LifecycleMapping
   https://github.com/apache/maven-jar-plugin/commit/aeffa392dd83040cde908c633b0ce2406850193b;>aeffa39
 [MJAR-304] Refresh download page
   https://github.com/apache/maven-jar-plugin/commit/ee85d599e14cbc69b71c65ade07b57f616217b57;>ee85d59
 [MJAR-303] Cleanup declared dependencies
   https://github.com/apache/maven-jar-plugin/commit/845c12071f2ec733c985c3d0eab3e48b1c15a486;>845c120
 Bump org.junit:junit-bom from 5.10.1 to 5.10.2
   https://github.com/apache/maven-jar-plugin/commit/8dd0d3f176fb28aa779cd2ddec9c342e834f38c6;>8dd0d3f
 [MJAR-298] Update Maven-Archiver to 3.6.2
   https://github.com/apache/maven-jar-plugin/commit/1b958d1804fa894eb4838c13b0532742751e5836;>1b958d1
 [MJAR-302] Require Maven 3.6.3
   https://github.com/apache/maven-jar-plugin/commit/fa4330fa687a98b1fa43c9bc8a574408b2ffe40b;>fa4330f
 [MJAR-62] Set Build-Jdk according to used toolchain
   

[GH] (commons-codec): Workflow run "Java CI" is working again!

2024-04-18 Thread GitBox


The GitHub Actions job "Java CI" on commons-codec.git has succeeded.
Run started by GitHub user garydgregory (triggered by garydgregory).

Head commit for run:
63b03381a5717f5406032cb3de94670bab2ae3a6 / Gary Gregory 

Fix whitespace

Report URL: https://github.com/apache/commons-codec/actions/runs/8743516670

With regards,
GitHub Actions via GitBox



[GH] (commons-codec): Workflow run "Java CI" failed!

2024-04-18 Thread GitBox


The GitHub Actions job "Java CI" on commons-codec.git has failed.
Run started by GitHub user garydgregory (triggered by garydgregory).

Head commit for run:
7d6ac370aa78df55d0afbcd7600f9af350075247 / Gary Gregory 

Add Javadoc

Report URL: https://github.com/apache/commons-codec/actions/runs/8743478966

With regards,
GitHub Actions via GitBox



svn commit: r1086250 - in /websites/production/commons/content/proper/commons-imaging: ./ apidocs/ apidocs/org/apache/commons/imaging/ apidocs/org/apache/commons/imaging/bytesource/ apidocs/org/apache

2024-04-18 Thread ggregory
Author: ggregory
Date: Thu Apr 18 15:05:42 2024
New Revision: 1086250

Log:
Site checkin for project Apache Commons Imaging


[This commit notification would consist of 149 parts, 
which exceeds the limit of 50 ones, so it was shortened to the summary.]


[GH] (commons-imaging): Workflow run "Java CI" is working again!

2024-04-18 Thread GitBox


The GitHub Actions job "Java CI" on commons-imaging.git has succeeded.
Run started by GitHub user asfgit (triggered by asfgit).

Head commit for run:
7ed32300b3d8735003b0acf63e8f0686b9a3cef8 / Gary Gregory 
Bump to next development version

Report URL: https://github.com/apache/commons-imaging/actions/runs/8740151938

With regards,
GitHub Actions via GitBox



[GH] (commons-imaging): Workflow run "Java CI" failed!

2024-04-18 Thread GitBox


The GitHub Actions job "Java CI" on commons-imaging.git has failed.
Run started by GitHub user asfgit (triggered by asfgit).

Head commit for run:
6dc0ba92f62056584af40a24f6c8a8215469ca8f / Gary Gregory 
Prepare for the next release candidate

Report URL: https://github.com/apache/commons-imaging/actions/runs/8740122638

With regards,
GitHub Actions via GitBox



svn commit: r1086246 - /websites/staging/commons/trunk/content/index.html

2024-04-18 Thread buildbot
Author: buildbot
Date: Thu Apr 18 14:55:18 2024
New Revision: 1086246

Log:
Automatic Staging Site Publish by Buildbot

Modified:
websites/staging/commons/trunk/content/index.html

Modified: websites/staging/commons/trunk/content/index.html
==
--- websites/staging/commons/trunk/content/index.html (original)
+++ websites/staging/commons/trunk/content/index.html Thu Apr 18 14:55:18 2024
@@ -543,12 +543,12 @@
 
  A pure-Java image library.
 
-https://central.sonatype.com/artifact/org.apache.commons/commons-imaging/1.0.0-alpha4/jar;
 rel="nofollow">
-   https://img.shields.io/maven-central/v/org.apache.commons/commons-imaging; 
alt="1.0.0-alpha4" style="max-width:100%;" />
+https://central.sonatype.com/artifact/org.apache.commons/commons-imaging/1.0.0-alpha5/jar;
 rel="nofollow">
+   https://img.shields.io/maven-central/v/org.apache.commons/commons-imaging; 
alt="1.0.0-alpha5" style="max-width:100%;" />
   
-1.0.0-alpha4
+1.0.0-alpha5
   
-2024-04-02
+2024-04-18
 
 
 IO




svn commit: r1086247 - in /websites/production/commons/content: ./ dormant/ proper/ sandbox/

2024-04-18 Thread buildbot
Author: buildbot
Date: Thu Apr 18 14:55:19 2024
New Revision: 1086247

Log:
Publish commons site from 1086246

Added:
websites/production/commons/content/
  - copied from r1086246, websites/staging/commons/trunk/content/
websites/production/commons/content/dormant/
  - copied from r1086246, websites/production/commons/content/dormant/
websites/production/commons/content/proper/
  - copied from r1086246, websites/production/commons/content/proper/
websites/production/commons/content/sandbox/
  - copied from r1086246, websites/production/commons/content/sandbox/



[Math] Change on branch "master": Commons » commons-math - Build # 677 - Successful!

2024-04-18 Thread Apache Jenkins Server
Commons » commons-math - Build # 677 - Successful:

Check console output at 
https://ci-builds.apache.org/job/Commons/job/commons-math/677/ to view the 
results.