Skip to content

Sync master with upstream OWASP-Benchmark/BenchmarkJava - #11

Merged
fgibelin merged 20 commits into
masterfrom
sync-upstream-master-20261001
Oct 1, 2026
Merged

fgibelin merged 20 commits into
masterfrom
sync-upstream-master-20261001

Conversation

@fgibelin

@fgibelin fgibelin commented Oct 1, 2026

Copy link
Copy Markdown
Owner

Summary

  • Merge upstream OWASP-Benchmark/BenchmarkJava@1fadd6c7c into the fork's master history, preserving all upstream commits.
  • Bring Maven dependency and plugin updates and the CodeQL workflow update into the fork.

Validation

  • mvn -q spotless:check package passed locally.

dependabot Bot and others added 20 commits September 15, 2026 11:03
Bumps [org.apache.maven.plugins:maven-deploy-plugin](https://github.com/apache/maven-deploy-plugin) from 3.1.4 to 3.2.0.
- [Release notes](https://github.com/apache/maven-deploy-plugin/releases)
- [Commits](apache/maven-deploy-plugin@maven-deploy-plugin-3.1.4...maven-deploy-plugin-3.2.0)

---
updated-dependencies:
- dependency-name: org.apache.maven.plugins:maven-deploy-plugin
  dependency-version: 3.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [org.apache.maven.plugins:maven-install-plugin](https://github.com/apache/maven-install-plugin) from 3.1.4 to 3.2.0.
- [Release notes](https://github.com/apache/maven-install-plugin/releases)
- [Commits](apache/maven-install-plugin@maven-install-plugin-3.1.4...maven-install-plugin-3.2.0)

---
updated-dependencies:
- dependency-name: org.apache.maven.plugins:maven-install-plugin
  dependency-version: 3.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [org.codehaus.mojo:extra-enforcer-rules](https://github.com/mojohaus/extra-enforcer-rules) from 1.12.0 to 1.12.1.
- [Release notes](https://github.com/mojohaus/extra-enforcer-rules/releases)
- [Commits](mojohaus/extra-enforcer-rules@1.12.0...1.12.1)

---
updated-dependencies:
- dependency-name: org.codehaus.mojo:extra-enforcer-rules
  dependency-version: 1.12.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [org.codehaus.mojo:versions-maven-plugin](https://github.com/mojohaus/versions) from 2.21.0 to 2.22.0.
- [Release notes](https://github.com/mojohaus/versions/releases)
- [Changelog](https://github.com/mojohaus/versions/blob/master/ReleaseNotes.md)
- [Commits](mojohaus/versions@2.21.0...2.22.0)

---
updated-dependencies:
- dependency-name: org.codehaus.mojo:versions-maven-plugin
  dependency-version: 2.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps org.codehaus.cargo:cargo-maven3-plugin from 1.10.28 to 1.10.29.

---
updated-dependencies:
- dependency-name: org.codehaus.cargo:cargo-maven3-plugin
  dependency-version: 1.10.29
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [org.apache.httpcomponents.core5:httpcore5](https://github.com/apache/httpcomponents-core) from 5.4.3 to 5.4.4.
- [Changelog](https://github.com/apache/httpcomponents-core/blob/rel/v5.4.4/RELEASE_NOTES.txt)
- [Commits](apache/httpcomponents-core@rel/v5.4.3...rel/v5.4.4)

---
updated-dependencies:
- dependency-name: org.apache.httpcomponents.core5:httpcore5
  dependency-version: 5.4.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.22.2 to 2.22.3.
- [Commits](FasterXML/jackson-databind@jackson-databind-2.22.2...jackson-databind-2.22.3)

---
updated-dependencies:
- dependency-name: com.fasterxml.jackson.core:jackson-databind
  dependency-version: 2.22.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps org.slf4j:slf4j-reload4j from 2.0.19 to 2.0.20.

---
updated-dependencies:
- dependency-name: org.slf4j:slf4j-reload4j
  dependency-version: 2.0.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.37.9 to 4.38.2.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](github/codeql-action@v4.37.9...v4.38.2)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-version: 4.38.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
…t/github_actions/github/codeql-action-4.38.2

Bump github/codeql-action from 4.37.9 to 4.38.2
…t/maven/org.slf4j-slf4j-reload4j-2.0.20

Bump org.slf4j:slf4j-reload4j from 2.0.19 to 2.0.20
…t/maven/org.codehaus.cargo-cargo-maven3-plugin-1.10.29

Bump org.codehaus.cargo:cargo-maven3-plugin from 1.10.28 to 1.10.29
…t/maven/org.apache.httpcomponents.core5-httpcore5-5.4.4

Bump org.apache.httpcomponents.core5:httpcore5 from 5.4.3 to 5.4.4
…t/maven/com.fasterxml.jackson.core-jackson-databind-2.22.3

Bump com.fasterxml.jackson.core:jackson-databind from 2.22.2 to 2.22.3
…t/maven/org.apache.maven.plugins-maven-deploy-plugin-3.2.0

Bump org.apache.maven.plugins:maven-deploy-plugin from 3.1.4 to 3.2.0
…t/maven/org.apache.maven.plugins-maven-install-plugin-3.2.0

Bump org.apache.maven.plugins:maven-install-plugin from 3.1.4 to 3.2.0
…t/maven/org.codehaus.mojo-extra-enforcer-rules-1.12.1

Bump org.codehaus.mojo:extra-enforcer-rules from 1.12.0 to 1.12.1
…t/maven/org.codehaus.mojo-versions-maven-plugin-2.22.0

Bump org.codehaus.mojo:versions-maven-plugin from 2.21.0 to 2.22.0
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The version updates are valid, preserve the LDAP compatibility pin, and passed the documented Maven validation.

Review effort: Balanced
Findings: None

What changed in this PR

Synchronizes the fork with upstream dependency and CI maintenance updates.

Changes:

  • Updates Maven dependencies, plugins, LDAP API, and Tomcat.
  • Updates CodeQL actions to v4.38.2.
File Description
pom.xml Updates dependency, plugin, and server versions.
.github/​workflows/​codeql-analysis.yml Updates CodeQL initialization and analysis actions.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@fgibelin
fgibelin merged commit 4e7a73c into master Oct 1, 2026
6 checks passed
@fgibelin
fgibelin deleted the sync-upstream-master-20261001 branch October 1, 2026 12:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants