[GitHub] [commons-codec] garydgregory closed pull request #159: [SECURITY] Fix Temporary File Information Disclosure Vulnerability

2022-11-18 Thread GitBox
garydgregory closed pull request #159: [SECURITY] Fix Temporary File Information Disclosure Vulnerability URL: https://github.com/apache/commons-codec/pull/159 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL abov

[GitHub] [commons-codec] garydgregory commented on pull request #159: [SECURITY] Fix Temporary File Information Disclosure Vulnerability

2022-11-18 Thread GitBox
garydgregory commented on PR #159: URL: https://github.com/apache/commons-codec/pull/159#issuecomment-1320790327 In a test? Really? -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific co

[GitHub] [commons-codec] JLLeitschuh opened a new pull request, #159: [SECURITY] Fix Temporary File Information Disclosure Vulnerability

2022-11-18 Thread GitBox
JLLeitschuh opened a new pull request, #159: URL: https://github.com/apache/commons-codec/pull/159 # Security Vulnerability Fix This pull request fixes a Temporary File Information Disclosure Vulnerability, which existed in this project. ## Preamble The system tempor

[GitHub] [commons-imaging] JLLeitschuh opened a new pull request, #249: [SECURITY] Fix Temporary File Information Disclosure Vulnerability

2022-11-18 Thread GitBox
JLLeitschuh opened a new pull request, #249: URL: https://github.com/apache/commons-imaging/pull/249 # Security Vulnerability Fix This pull request fixes a Temporary File Information Disclosure Vulnerability, which existed in this project. ## Preamble The system temp

[GitHub] [commons-beanutils] dependabot[bot] opened a new pull request, #146: Bump japicmp-maven-plugin from 0.16.0 to 0.17.1

2022-11-18 Thread GitBox
dependabot[bot] opened a new pull request, #146: URL: https://github.com/apache/commons-beanutils/pull/146 Bumps [japicmp-maven-plugin](https://github.com/siom79/japicmp) from 0.16.0 to 0.17.1. Commits https://github.com/siom79/japicmp/commit/64c6164efaa04381e3ccc8e58cd39f6195c

[GitHub] [commons-text] garydgregory merged pull request #388: Bump jmh.version from 1.35 to 1.36

2022-11-18 Thread GitBox
garydgregory merged PR #388: URL: https://github.com/apache/commons-text/pull/388 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@com

[GitHub] [commons-text] garydgregory merged pull request #389: Bump mockito-inline from 4.8.1 to 4.9.0

2022-11-18 Thread GitBox
garydgregory merged PR #389: URL: https://github.com/apache/commons-text/pull/389 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@com

[GitHub] [commons-email] codecov-commenter commented on pull request #112: Bump slf4j-jdk14 from 1.7.7 to 2.0.4

2022-11-18 Thread GitBox
codecov-commenter commented on PR #112: URL: https://github.com/apache/commons-email/pull/112#issuecomment-1320478223 # [Codecov](https://codecov.io/gh/apache/commons-email/pull/112?src=pr&el=h1&utm_medium=referral&utm_source=github&utm_content=comment&utm_campaign=pr+comments&utm_term=The+A

[GitHub] [commons-email] dependabot[bot] opened a new pull request, #112: Bump slf4j-jdk14 from 1.7.7 to 2.0.4

2022-11-18 Thread GitBox
dependabot[bot] opened a new pull request, #112: URL: https://github.com/apache/commons-email/pull/112 Bumps [slf4j-jdk14](https://github.com/qos-ch/slf4j) from 1.7.7 to 2.0.4. Commits https://github.com/qos-ch/slf4j/commit/35dd7ff1e75cf83ffb6784a9537ff92c865e78b2";>35dd7ff rem

[GitHub] [commons-bcel] garydgregory merged pull request #170: Bump jmh.version from 1.35 to 1.36

2022-11-18 Thread GitBox
garydgregory merged PR #170: URL: https://github.com/apache/commons-bcel/pull/170 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@com

[GitHub] [commons-text] dependabot[bot] opened a new pull request, #389: Bump mockito-inline from 4.8.1 to 4.9.0

2022-11-18 Thread GitBox
dependabot[bot] opened a new pull request, #389: URL: https://github.com/apache/commons-text/pull/389 Bumps [mockito-inline](https://github.com/mockito/mockito) from 4.8.1 to 4.9.0. Release notes Sourced from https://github.com/mockito/mockito/releases";>mockito-inline's releases.

[GitHub] [commons-text] dependabot[bot] opened a new pull request, #388: Bump jmh.version from 1.35 to 1.36

2022-11-18 Thread GitBox
dependabot[bot] opened a new pull request, #388: URL: https://github.com/apache/commons-text/pull/388 Bumps `jmh.version` from 1.35 to 1.36. Updates `jmh-core` from 1.35 to 1.36 Commits https://github.com/openjdk/jmh/commit/f2f11b30667906438e3100e79af497f55d615398";>f2f11b3

[GitHub] [commons-lang] kinow merged pull request #991: Bump junit-pioneer from 1.8.0 to 1.9.0

2022-11-18 Thread GitBox
kinow merged PR #991: URL: https://github.com/apache/commons-lang/pull/991 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@commons.ap

[GitHub] [commons-lang] kinow merged pull request #990: Bump jmh.version from 1.35 to 1.36

2022-11-18 Thread GitBox
kinow merged PR #990: URL: https://github.com/apache/commons-lang/pull/990 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@commons.ap

[GitHub] [commons-io] kinow merged pull request #404: Bump jmh.version from 1.35 to 1.36

2022-11-18 Thread GitBox
kinow merged PR #404: URL: https://github.com/apache/commons-io/pull/404 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@commons.apac

[GitHub] [commons-configuration] kinow merged pull request #238: Bump slf4j.version from 2.0.2 to 2.0.4

2022-11-18 Thread GitBox
kinow merged PR #238: URL: https://github.com/apache/commons-configuration/pull/238 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@c

[GitHub] [commons-compress] kinow merged pull request #329: Bump slf4j-api from 2.0.3 to 2.0.4

2022-11-18 Thread GitBox
kinow merged PR #329: URL: https://github.com/apache/commons-compress/pull/329 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@common

[jira] [Comment Edited] (FILEUPLOAD-309) Release version 2.0.0

2022-11-18 Thread Andy Seaborne (Jira)
[ https://issues.apache.org/jira/browse/FILEUPLOAD-309?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17616378#comment-17616378 ] Andy Seaborne edited comment on FILEUPLOAD-309 at 11/18/22 7:28 PM: ---

[jira] [Work logged] (LANG-1677) It should be possible to exclude fields in ReflectionDiffBuilder

2022-11-18 Thread ASF GitHub Bot (Jira)
[ https://issues.apache.org/jira/browse/LANG-1677?focusedWorklogId=827250&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-827250 ] ASF GitHub Bot logged work on LANG-1677: Author: ASF GitHub Bot

[GitHub] [commons-lang] garydgregory commented on pull request #838: LANG-1677 : Add ReflectionDiffBuilder.setExcludeFieldNames(...) and DiffExclude a…

2022-11-18 Thread GitBox
garydgregory commented on PR #838: URL: https://github.com/apache/commons-lang/pull/838#issuecomment-1320420683 I will be busy this weekend with Commons BCEL and Commons Net, so probably after that. -- This is an automated message from the Apache Git Service. To respond to the message, p

[GitHub] [commons-rdf] dependabot[bot] commented on pull request #92: Bump slf4j-simple from 1.7.26 to 2.0.3

2022-11-18 Thread GitBox
dependabot[bot] commented on PR #92: URL: https://github.com/apache/commons-rdf/pull/92#issuecomment-1320419940 Superseded by #101. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific co

[GitHub] [commons-rdf] dependabot[bot] closed pull request #92: Bump slf4j-simple from 1.7.26 to 2.0.3

2022-11-18 Thread GitBox
dependabot[bot] closed pull request #92: Bump slf4j-simple from 1.7.26 to 2.0.3 URL: https://github.com/apache/commons-rdf/pull/92 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment

[GitHub] [commons-rdf] dependabot[bot] opened a new pull request, #101: Bump slf4j-simple from 1.7.26 to 2.0.4

2022-11-18 Thread GitBox
dependabot[bot] opened a new pull request, #101: URL: https://github.com/apache/commons-rdf/pull/101 Bumps [slf4j-simple](https://github.com/qos-ch/slf4j) from 1.7.26 to 2.0.4. Commits https://github.com/qos-ch/slf4j/commit/35dd7ff1e75cf83ffb6784a9537ff92c865e78b2";>35dd7ff rem

[GitHub] [commons-bcel] dependabot[bot] opened a new pull request, #170: Bump jmh.version from 1.35 to 1.36

2022-11-18 Thread GitBox
dependabot[bot] opened a new pull request, #170: URL: https://github.com/apache/commons-bcel/pull/170 Bumps `jmh.version` from 1.35 to 1.36. Updates `jmh-core` from 1.35 to 1.36 Commits https://github.com/openjdk/jmh/commit/f2f11b30667906438e3100e79af497f55d615398";>f2f11b3

[jira] [Work logged] (LANG-1677) It should be possible to exclude fields in ReflectionDiffBuilder

2022-11-18 Thread ASF GitHub Bot (Jira)
[ https://issues.apache.org/jira/browse/LANG-1677?focusedWorklogId=827248&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-827248 ] ASF GitHub Bot logged work on LANG-1677: Author: ASF GitHub Bot

[GitHub] [commons-lang] debae commented on pull request #838: LANG-1677 : Add ReflectionDiffBuilder.setExcludeFieldNames(...) and DiffExclude a…

2022-11-18 Thread GitBox
debae commented on PR #838: URL: https://github.com/apache/commons-lang/pull/838#issuecomment-1320414172 @garydgregory did you have the time too look into this PR -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL

[GitHub] [commons-jxpath] hummelm10 commented on pull request #26: Add an allow list for classes that can be loaded by JXPath

2022-11-18 Thread GitBox
hummelm10 commented on PR #26: URL: https://github.com/apache/commons-jxpath/pull/26#issuecomment-1320280537 > > > The CVE record has been updated to invalid so my request to edit the title of this PR to remove the CVE reference stands. > > > > > > For clarity, this is not tru

[GitHub] [commons-daemon] dependabot[bot] opened a new pull request, #66: Bump spotbugs-maven-plugin from 4.7.2.1 to 4.7.3.0

2022-11-18 Thread GitBox
dependabot[bot] opened a new pull request, #66: URL: https://github.com/apache/commons-daemon/pull/66 Bumps [spotbugs-maven-plugin](https://github.com/spotbugs/spotbugs-maven-plugin) from 4.7.2.1 to 4.7.3.0. Release notes Sourced from https://github.com/spotbugs/spotbugs-maven-plu

[GitHub] [commons-configuration] dependabot[bot] opened a new pull request, #239: Bump spring.version from 5.3.23 to 6.0.0

2022-11-18 Thread GitBox
dependabot[bot] opened a new pull request, #239: URL: https://github.com/apache/commons-configuration/pull/239 Bumps `spring.version` from 5.3.23 to 6.0.0. Updates `spring-core` from 5.3.23 to 6.0.0 Release notes Sourced from https://github.com/spring-projects/spring-framework/re

[GitHub] [commons-configuration] dependabot[bot] closed pull request #218: Bump slf4j.version from 2.0.2 to 2.0.3

2022-11-18 Thread GitBox
dependabot[bot] closed pull request #218: Bump slf4j.version from 2.0.2 to 2.0.3 URL: https://github.com/apache/commons-configuration/pull/218 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the spec

[GitHub] [commons-configuration] dependabot[bot] commented on pull request #218: Bump slf4j.version from 2.0.2 to 2.0.3

2022-11-18 Thread GitBox
dependabot[bot] commented on PR #218: URL: https://github.com/apache/commons-configuration/pull/218#issuecomment-1320220722 Superseded by #238. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to th

[GitHub] [commons-configuration] dependabot[bot] opened a new pull request, #238: Bump slf4j.version from 2.0.2 to 2.0.4

2022-11-18 Thread GitBox
dependabot[bot] opened a new pull request, #238: URL: https://github.com/apache/commons-configuration/pull/238 Bumps `slf4j.version` from 2.0.2 to 2.0.4. Updates `slf4j-api` from 2.0.2 to 2.0.4 Commits https://github.com/qos-ch/slf4j/commit/35dd7ff1e75cf83ffb6784a9537ff92c865

[GitHub] [commons-weaver] garydgregory commented on a diff in pull request #12: JUnit5 assertThrows ProvidersTest

2022-11-18 Thread GitBox
garydgregory commented on code in PR #12: URL: https://github.com/apache/commons-weaver/pull/12#discussion_r1026567810 ## processor/src/test/java/org/apache/commons/weaver/utils/ProvidersTest.java: ## @@ -29,17 +30,20 @@ import org.apache.commons.weaver.spi.Weaver; import org.

[GitHub] [commons-vfs] garydgregory closed pull request #335: Bump slf4j-simple from 1.7.26 to 2.0.4

2022-11-18 Thread GitBox
garydgregory closed pull request #335: Bump slf4j-simple from 1.7.26 to 2.0.4 URL: https://github.com/apache/commons-vfs/pull/335 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment.

[GitHub] [commons-vfs] garydgregory commented on pull request #335: Bump slf4j-simple from 1.7.26 to 2.0.4

2022-11-18 Thread GitBox
garydgregory commented on PR #335: URL: https://github.com/apache/commons-vfs/pull/335#issuecomment-1320170763 Close to open slot of other updates. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to

[GitHub] [commons-validator] garydgregory merged pull request #91: Bump actions/cache from 3.0.10 to 3.0.11

2022-11-18 Thread GitBox
garydgregory merged PR #91: URL: https://github.com/apache/commons-validator/pull/91 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@

[GitHub] [commons-validator] garydgregory merged pull request #96: Bump actions/upload-artifact from 3.1.0 to 3.1.1

2022-11-18 Thread GitBox
garydgregory merged PR #96: URL: https://github.com/apache/commons-validator/pull/96 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@

[GitHub] [commons-validator] garydgregory merged pull request #98: Bump actions/setup-java from 3.5.1 to 3.6.0

2022-11-18 Thread GitBox
garydgregory merged PR #98: URL: https://github.com/apache/commons-validator/pull/98 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@

[GitHub] [commons-validator] garydgregory commented on pull request #95: JUnit5 assertThrows UrlValidatorTest

2022-11-18 Thread GitBox
garydgregory commented on PR #95: URL: https://github.com/apache/commons-validator/pull/95#issuecomment-1320159884 -1 This is not better, let's wait until this component is on Java 8. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to G

[GitHub] [commons-skin] garydgregory merged pull request #18: Bump actions/upload-artifact from 3.1.0 to 3.1.1

2022-11-18 Thread GitBox
garydgregory merged PR #18: URL: https://github.com/apache/commons-skin/pull/18 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@commo

[GitHub] [commons-skin] garydgregory merged pull request #19: Bump github/codeql-action from 2.1.30 to 2.1.31

2022-11-18 Thread GitBox
garydgregory merged PR #19: URL: https://github.com/apache/commons-skin/pull/19 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@commo

[GitHub] [commons-scxml] garydgregory merged pull request #75: Bump actions/checkout from 3.0.2 to 3.1.0

2022-11-18 Thread GitBox
garydgregory merged PR #75: URL: https://github.com/apache/commons-scxml/pull/75 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@comm

[GitHub] [commons-scxml] garydgregory merged pull request #78: Bump actions/cache from 3.0.8 to 3.0.11

2022-11-18 Thread GitBox
garydgregory merged PR #78: URL: https://github.com/apache/commons-scxml/pull/78 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@comm

[GitHub] [commons-scxml] garydgregory merged pull request #79: Bump actions/setup-java from 3.5.1 to 3.6.0

2022-11-18 Thread GitBox
garydgregory merged PR #79: URL: https://github.com/apache/commons-scxml/pull/79 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@comm

[GitHub] [commons-scxml] garydgregory merged pull request #82: Bump actions/upload-artifact from 3.1.0 to 3.1.1

2022-11-18 Thread GitBox
garydgregory merged PR #82: URL: https://github.com/apache/commons-scxml/pull/82 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@comm

[GitHub] [commons-scxml] garydgregory merged pull request #83: Bump jackson-databind from 2.13.4 to 2.14.0

2022-11-18 Thread GitBox
garydgregory merged PR #83: URL: https://github.com/apache/commons-scxml/pull/83 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@comm

[GitHub] [commons-scxml] garydgregory merged pull request #84: Bump jackson-core from 2.13.4 to 2.14.0

2022-11-18 Thread GitBox
garydgregory merged PR #84: URL: https://github.com/apache/commons-scxml/pull/84 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@comm

[GitHub] [commons-parent] garydgregory merged pull request #174: Bump japicmp-maven-plugin from 0.16.0 to 0.17.1

2022-11-18 Thread GitBox
garydgregory merged PR #174: URL: https://github.com/apache/commons-parent/pull/174 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@c

[GitHub] [commons-lang] dependabot[bot] opened a new pull request, #991: Bump junit-pioneer from 1.8.0 to 1.9.0

2022-11-18 Thread GitBox
dependabot[bot] opened a new pull request, #991: URL: https://github.com/apache/commons-lang/pull/991 Bumps [junit-pioneer](https://github.com/junit-pioneer/junit-pioneer) from 1.8.0 to 1.9.0. Release notes Sourced from https://github.com/junit-pioneer/junit-pioneer/releases";>juni

[GitHub] [commons-lang] dependabot[bot] opened a new pull request, #990: Bump jmh.version from 1.35 to 1.36

2022-11-18 Thread GitBox
dependabot[bot] opened a new pull request, #990: URL: https://github.com/apache/commons-lang/pull/990 Bumps `jmh.version` from 1.35 to 1.36. Updates `jmh-core` from 1.35 to 1.36 Commits https://github.com/openjdk/jmh/commit/f2f11b30667906438e3100e79af497f55d615398";>f2f11b3

[GitHub] [commons-rdf] garydgregory merged pull request #82: Bump junit from 4.12 to 4.13.1 in /commons-rdf-examples

2022-11-18 Thread GitBox
garydgregory merged PR #82: URL: https://github.com/apache/commons-rdf/pull/82 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@common

[GitHub] [commons-rdf] garydgregory merged pull request #95: Bump actions/checkout from 3.0.2 to 3.1.0

2022-11-18 Thread GitBox
garydgregory merged PR #95: URL: https://github.com/apache/commons-rdf/pull/95 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@common

[GitHub] [commons-rdf] garydgregory merged pull request #97: Bump actions/cache from 3.0.8 to 3.0.11

2022-11-18 Thread GitBox
garydgregory merged PR #97: URL: https://github.com/apache/commons-rdf/pull/97 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@common

[GitHub] [commons-rdf] garydgregory merged pull request #99: Bump actions/setup-java from 3.5.1 to 3.6.0

2022-11-18 Thread GitBox
garydgregory merged PR #99: URL: https://github.com/apache/commons-rdf/pull/99 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@common

[GitHub] [commons-rdf] garydgregory merged pull request #100: Bump actions/upload-artifact from 3.1.0 to 3.1.1

2022-11-18 Thread GitBox
garydgregory merged PR #100: URL: https://github.com/apache/commons-rdf/pull/100 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@comm

[GitHub] [commons-parent] garydgregory commented on pull request #174: Bump japicmp-maven-plugin from 0.16.0 to 0.17.1

2022-11-18 Thread GitBox
garydgregory commented on PR #174: URL: https://github.com/apache/commons-parent/pull/174#issuecomment-1320137297 @dependabot rebase -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific c

[GitHub] [commons-io] garydgregory merged pull request #405: Bump mockito-inline from 4.8.1 to 4.9.0

2022-11-18 Thread GitBox
garydgregory merged PR #405: URL: https://github.com/apache/commons-io/pull/405 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@commo

[GitHub] [commons-io] garydgregory merged pull request #406: Bump junit-pioneer from 1.7.2 to 1.9.0

2022-11-18 Thread GitBox
garydgregory merged PR #406: URL: https://github.com/apache/commons-io/pull/406 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@commo

[GitHub] [commons-fileupload] dependabot[bot] commented on pull request #179: Bump spotbugs-maven-plugin from 4.7.2.1 to 4.7.3.0

2022-11-18 Thread GitBox
dependabot[bot] commented on PR #179: URL: https://github.com/apache/commons-fileupload/pull/179#issuecomment-1320115493 OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor ve

[GitHub] [commons-fileupload] garydgregory closed pull request #179: Bump spotbugs-maven-plugin from 4.7.2.1 to 4.7.3.0

2022-11-18 Thread GitBox
garydgregory closed pull request #179: Bump spotbugs-maven-plugin from 4.7.2.1 to 4.7.3.0 URL: https://github.com/apache/commons-fileupload/pull/179 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to t

[GitHub] [commons-exec] garydgregory commented on a diff in pull request #73: JUnit5 assertThrows Exec65Test

2022-11-18 Thread GitBox
garydgregory commented on code in PR #73: URL: https://github.com/apache/commons-exec/pull/73#discussion_r1026534070 ## src/test/java/org/apache/commons/exec/issues/Exec65Test.java: ## @@ -51,7 +53,8 @@ public void testExec65WitSleepUsingSleepCommandDirectly() throws Exception

[GitHub] [commons-dbcp] garydgregory merged pull request #235: Bump mockito-core from 4.8.1 to 4.9.0

2022-11-18 Thread GitBox
garydgregory merged PR #235: URL: https://github.com/apache/commons-dbcp/pull/235 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@com

[GitHub] [commons-dbcp] garydgregory merged pull request #238: Bump japicmp-maven-plugin from 0.16.0 to 0.17.1

2022-11-18 Thread GitBox
garydgregory merged PR #238: URL: https://github.com/apache/commons-dbcp/pull/238 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@com

[GitHub] [commons-crypto] garydgregory merged pull request #194: Bump jmh.version from 1.35 to 1.36

2022-11-18 Thread GitBox
garydgregory merged PR #194: URL: https://github.com/apache/commons-crypto/pull/194 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@c

[GitHub] [commons-compress] garydgregory merged pull request #330: Bump memoryfilesystem from 2.3.0 to 2.4.0

2022-11-18 Thread GitBox
garydgregory merged PR #330: URL: https://github.com/apache/commons-compress/pull/330 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...

[GitHub] [commons-compress] garydgregory merged pull request #331: Bump mockito.version from 4.8.1 to 4.9.0

2022-11-18 Thread GitBox
garydgregory merged PR #331: URL: https://github.com/apache/commons-compress/pull/331 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...

[GitHub] [commons-build-plugin] garydgregory merged pull request #103: Bump github/codeql-action from 2.1.30 to 2.1.31

2022-11-18 Thread GitBox
garydgregory merged PR #103: URL: https://github.com/apache/commons-build-plugin/pull/103 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubsc

[GitHub] [commons-build-plugin] garydgregory merged pull request #104: Bump maven-plugin-plugin from 3.6.4 to 3.7.0

2022-11-18 Thread GitBox
garydgregory merged PR #104: URL: https://github.com/apache/commons-build-plugin/pull/104 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubsc

[GitHub] [commons-build-plugin] garydgregory merged pull request #106: Bump spotbugs-maven-plugin from 4.7.2.1 to 4.7.3.0

2022-11-18 Thread GitBox
garydgregory merged PR #106: URL: https://github.com/apache/commons-build-plugin/pull/106 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubsc

[GitHub] [commons-beanutils] garydgregory merged pull request #143: Bump actions/upload-artifact from 3.1.0 to 3.1.1

2022-11-18 Thread GitBox
garydgregory merged PR #143: URL: https://github.com/apache/commons-beanutils/pull/143 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr..

[GitHub] [commons-beanutils] garydgregory merged pull request #144: Bump actions/setup-java from 3.5.1 to 3.6.0

2022-11-18 Thread GitBox
garydgregory merged PR #144: URL: https://github.com/apache/commons-beanutils/pull/144 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr..

[GitHub] [commons-csv] garydgregory merged pull request #282: Bump spotbugs-maven-plugin from 4.7.2.1 to 4.7.3.0

2022-11-18 Thread GitBox
garydgregory merged PR #282: URL: https://github.com/apache/commons-csv/pull/282 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@comm

[GitHub] [commons-csv] garydgregory merged pull request #283: Bump jmh-generator-annprocess from 1.35 to 1.36

2022-11-18 Thread GitBox
garydgregory merged PR #283: URL: https://github.com/apache/commons-csv/pull/283 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@comm

[GitHub] [commons-csv] garydgregory merged pull request #284: Bump mockito-core from 4.8.1 to 4.9.0

2022-11-18 Thread GitBox
garydgregory merged PR #284: URL: https://github.com/apache/commons-csv/pull/284 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@comm

[GitHub] [commons-csv] garydgregory merged pull request #285: Bump jmh-core from 1.35 to 1.36

2022-11-18 Thread GitBox
garydgregory merged PR #285: URL: https://github.com/apache/commons-csv/pull/285 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: issues-unsubscr...@comm

[jira] [Created] (DAEMON-450) Invoked "bin\tomcat9 //US/Tomcat9", logs directory will be inserted unwanted two ACLs

2022-11-18 Thread Norimasa Yamamoto (Jira)
Norimasa Yamamoto created DAEMON-450: Summary: Invoked "bin\tomcat9 //US/Tomcat9", logs directory will be inserted unwanted two ACLs Key: DAEMON-450 URL: https://issues.apache.org/jira/browse/DAEMON-450

[GitHub] [commons-jxpath] iamamoose commented on pull request #26: Add an allow list for classes that can be loaded by JXPath

2022-11-18 Thread GitBox
iamamoose commented on PR #26: URL: https://github.com/apache/commons-jxpath/pull/26#issuecomment-1319955459 > > The CVE record has been updated to invalid so my request to edit the title of this PR to remove the CVE reference stands. > > For clarity, this is not true. The record has

[jira] [Commented] (FILEUPLOAD-309) Release version 2.0.0

2022-11-18 Thread Thomas Heigl (Jira)
[ https://issues.apache.org/jira/browse/FILEUPLOAD-309?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17635846#comment-17635846 ] Thomas Heigl commented on FILEUPLOAD-309: - I second that, please release some

[GitHub] [commons-csv] dependabot[bot] opened a new pull request, #285: Bump jmh-core from 1.35 to 1.36

2022-11-18 Thread GitBox
dependabot[bot] opened a new pull request, #285: URL: https://github.com/apache/commons-csv/pull/285 Bumps [jmh-core](https://github.com/openjdk/jmh) from 1.35 to 1.36. Commits https://github.com/openjdk/jmh/commit/f2f11b30667906438e3100e79af497f55d615398";>f2f11b3 JMH v1.36.

[GitHub] [commons-csv] dependabot[bot] opened a new pull request, #284: Bump mockito-core from 4.8.1 to 4.9.0

2022-11-18 Thread GitBox
dependabot[bot] opened a new pull request, #284: URL: https://github.com/apache/commons-csv/pull/284 Bumps [mockito-core](https://github.com/mockito/mockito) from 4.8.1 to 4.9.0. Release notes Sourced from https://github.com/mockito/mockito/releases";>mockito-core's releases.

[GitHub] [commons-csv] dependabot[bot] opened a new pull request, #283: Bump jmh-generator-annprocess from 1.35 to 1.36

2022-11-18 Thread GitBox
dependabot[bot] opened a new pull request, #283: URL: https://github.com/apache/commons-csv/pull/283 Bumps [jmh-generator-annprocess](https://github.com/openjdk/jmh) from 1.35 to 1.36. Commits https://github.com/openjdk/jmh/commit/f2f11b30667906438e3100e79af497f55d615398";>f2f1

[GitHub] [commons-jexl] dependabot[bot] opened a new pull request, #142: Bump japicmp-maven-plugin from 0.16.0 to 0.17.1

2022-11-18 Thread GitBox
dependabot[bot] opened a new pull request, #142: URL: https://github.com/apache/commons-jexl/pull/142 Bumps [japicmp-maven-plugin](https://github.com/siom79/japicmp) from 0.16.0 to 0.17.1. Commits https://github.com/siom79/japicmp/commit/64c6164efaa04381e3ccc8e58cd39f6195cbd021

[GitHub] [commons-vfs] dependabot[bot] closed pull request #297: Bump sshd-core from 0.8.0 to 2.9.1

2022-11-18 Thread GitBox
dependabot[bot] closed pull request #297: Bump sshd-core from 0.8.0 to 2.9.1 URL: https://github.com/apache/commons-vfs/pull/297 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment.

[GitHub] [commons-vfs] dependabot[bot] commented on pull request #297: Bump sshd-core from 0.8.0 to 2.9.1

2022-11-18 Thread GitBox
dependabot[bot] commented on PR #297: URL: https://github.com/apache/commons-vfs/pull/297#issuecomment-1319848241 Superseded by #336. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific

[GitHub] [commons-vfs] dependabot[bot] opened a new pull request, #336: Bump sshd-core from 0.8.0 to 2.9.2

2022-11-18 Thread GitBox
dependabot[bot] opened a new pull request, #336: URL: https://github.com/apache/commons-vfs/pull/336 Bumps [sshd-core](https://github.com/apache/mina-sshd) from 0.8.0 to 2.9.2. Changelog Sourced from https://github.com/apache/mina-sshd/blob/master/CHANGES.md";>sshd-core's changelog

[GitHub] [commons-crypto] dependabot[bot] opened a new pull request, #194: Bump jmh.version from 1.35 to 1.36

2022-11-18 Thread GitBox
dependabot[bot] opened a new pull request, #194: URL: https://github.com/apache/commons-crypto/pull/194 Bumps `jmh.version` from 1.35 to 1.36. Updates `jmh-core` from 1.35 to 1.36 Commits https://github.com/openjdk/jmh/commit/f2f11b30667906438e3100e79af497f55d615398";>f2f11b3

[GitHub] [commons-vfs] dependabot[bot] opened a new pull request, #335: Bump slf4j-simple from 1.7.26 to 2.0.4

2022-11-18 Thread GitBox
dependabot[bot] opened a new pull request, #335: URL: https://github.com/apache/commons-vfs/pull/335 Bumps [slf4j-simple](https://github.com/qos-ch/slf4j) from 1.7.26 to 2.0.4. Commits https://github.com/qos-ch/slf4j/commit/35dd7ff1e75cf83ffb6784a9537ff92c865e78b2";>35dd7ff rem

[GitHub] [commons-vfs] dependabot[bot] opened a new pull request, #334: Bump slf4j.version from 1.7.36 to 2.0.4

2022-11-18 Thread GitBox
dependabot[bot] opened a new pull request, #334: URL: https://github.com/apache/commons-vfs/pull/334 Bumps `slf4j.version` from 1.7.36 to 2.0.4. Updates `slf4j-api` from 1.7.36 to 2.0.4 Commits https://github.com/qos-ch/slf4j/commit/35dd7ff1e75cf83ffb6784a9537ff92c865e78b2";>

[GitHub] [commons-parent] dependabot[bot] opened a new pull request, #174: Bump japicmp-maven-plugin from 0.16.0 to 0.17.1

2022-11-18 Thread GitBox
dependabot[bot] opened a new pull request, #174: URL: https://github.com/apache/commons-parent/pull/174 Bumps [japicmp-maven-plugin](https://github.com/siom79/japicmp) from 0.16.0 to 0.17.1. Commits https://github.com/siom79/japicmp/commit/64c6164efaa04381e3ccc8e58cd39f6195cbd0

[jira] [Comment Edited] (CLI-299) Add Automatic-Module-Name to MANIFEST.MF

2022-11-18 Thread Samael Bate (Jira)
[ https://issues.apache.org/jira/browse/CLI-299?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17635773#comment-17635773 ] Samael Bate edited comment on CLI-299 at 11/18/22 10:00 AM: is t

[jira] [Commented] (CLI-299) Add Automatic-Module-Name to MANIFEST.MF

2022-11-18 Thread Samael Bate (Jira)
[ https://issues.apache.org/jira/browse/CLI-299?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=17635773#comment-17635773 ] Samael Bate commented on CLI-299: - will this ever get merged/released? > Add Automatic-Modu

[GitHub] [commons-dbutils] dependabot[bot] opened a new pull request, #154: Bump mockito-core from 4.8.1 to 4.9.0

2022-11-18 Thread GitBox
dependabot[bot] opened a new pull request, #154: URL: https://github.com/apache/commons-dbutils/pull/154 Bumps [mockito-core](https://github.com/mockito/mockito) from 4.8.1 to 4.9.0. Release notes Sourced from https://github.com/mockito/mockito/releases";>mockito-core's releases.

[GitHub] [commons-jxpath] markt-asf commented on pull request #26: Add an allow list for classes that can be loaded by JXPath

2022-11-18 Thread GitBox
markt-asf commented on PR #26: URL: https://github.com/apache/commons-jxpath/pull/26#issuecomment-1319707214 There is no security vulnerability. This PR will be dealt with with the same priority as any other enhancement request. -- This is an automated message from the Apache Git Service.

[GitHub] [commons-jxpath] stephanborn commented on pull request #26: Add an allow list for classes that can be loaded by JXPath

2022-11-18 Thread GitBox
stephanborn commented on PR #26: URL: https://github.com/apache/commons-jxpath/pull/26#issuecomment-1319703699 Now as @kyakdan has renamed the PR's title to "get it merged" - is there a plan / schedule when this will be done and a new version with this included will be released? It would be