Skip to content

chore: update dependency-check-maven to 12.2.2 - #2387

Merged
ewaostrowska merged 1 commit into
masterfrom
update-dependabot-12.2.2
Aug 25, 2026
Merged

chore: update dependency-check-maven to 12.2.2#2387
ewaostrowska merged 1 commit into
masterfrom
update-dependabot-12.2.2

Conversation

@ewaostrowska

@ewaostrowska ewaostrowska commented Aug 24, 2026

Copy link
Copy Markdown
Contributor

Pull Request

The 8.x line is obsolete and unsupported for current NVD usage; OWASP now requires Dependency-Check 12.1.0 or later.

Type of Change

  • 🐛 Bug fix
  • ✨ New feature
  • ♻️ Refactor (non-breaking change)
  • 🧪 Tests
  • 📝 Documentation
  • 🧹 Chore (build or tooling)

Checklist

  • I have added/updated tests as needed
  • I have added/updated documentation where applicable
  • The PR title is descriptive
  • The code builds and passes tests locally
  • I have linked related issues (if any)

Screenshots / Additional Context

@ewaostrowska
ewaostrowska requested a lite review from Copilot August 24, 2026 11:16
@ewaostrowska ewaostrowska changed the title chore: update dependabot to 12.2.2 chore: update dependency-check-maven to 12.2.2 Aug 24, 2026

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the OWASP Dependency-Check Maven plugin to a supported major version for current NVD usage, and adjusts Dependabot configuration intended to control how dependency updates are proposed.

Changes:

  • Bump org.owasp:dependency-check-maven from 8.1.2 to 12.2.2 in the security Maven profile.
  • Modify .github/dependabot.yml to attempt to restrict updates to minor/patch generally, while allowing major updates for Dependency-Check.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated 1 comment.

File Description
pom.xml Updates OWASP Dependency-Check Maven plugin version in the security profile.
.github/dependabot.yml Changes Dependabot update filtering configuration (currently uses an unsupported allow.update-types shape).

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .github/dependabot.yml
@ewaostrowska
ewaostrowska force-pushed the update-dependabot-12.2.2 branch from 1f40fc1 to f5f5d0c Compare August 24, 2026 12:48
@ewaostrowska
ewaostrowska requested a review from djankows August 24, 2026 12:48
@ewaostrowska
ewaostrowska force-pushed the update-dependabot-12.2.2 branch from f5f5d0c to d358e89 Compare August 25, 2026 08:12
@ewaostrowska
ewaostrowska force-pushed the update-dependabot-12.2.2 branch from d358e89 to d790da4 Compare August 25, 2026 08:23
@ewaostrowska
ewaostrowska merged commit f23d962 into master Aug 25, 2026
7 checks passed
@ewaostrowska
ewaostrowska deleted the update-dependabot-12.2.2 branch August 25, 2026 08:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants