Sync master with upstream OWASP-Benchmark/BenchmarkJava - #11
Merged
Merged
Conversation
Bumps [org.apache.maven.plugins:maven-deploy-plugin](https://github.com/apache/maven-deploy-plugin) from 3.1.4 to 3.2.0. - [Release notes](https://github.com/apache/maven-deploy-plugin/releases) - [Commits](apache/maven-deploy-plugin@maven-deploy-plugin-3.1.4...maven-deploy-plugin-3.2.0) --- updated-dependencies: - dependency-name: org.apache.maven.plugins:maven-deploy-plugin dependency-version: 3.2.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [org.apache.maven.plugins:maven-install-plugin](https://github.com/apache/maven-install-plugin) from 3.1.4 to 3.2.0. - [Release notes](https://github.com/apache/maven-install-plugin/releases) - [Commits](apache/maven-install-plugin@maven-install-plugin-3.1.4...maven-install-plugin-3.2.0) --- updated-dependencies: - dependency-name: org.apache.maven.plugins:maven-install-plugin dependency-version: 3.2.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [org.codehaus.mojo:extra-enforcer-rules](https://github.com/mojohaus/extra-enforcer-rules) from 1.12.0 to 1.12.1. - [Release notes](https://github.com/mojohaus/extra-enforcer-rules/releases) - [Commits](mojohaus/extra-enforcer-rules@1.12.0...1.12.1) --- updated-dependencies: - dependency-name: org.codehaus.mojo:extra-enforcer-rules dependency-version: 1.12.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [org.codehaus.mojo:versions-maven-plugin](https://github.com/mojohaus/versions) from 2.21.0 to 2.22.0. - [Release notes](https://github.com/mojohaus/versions/releases) - [Changelog](https://github.com/mojohaus/versions/blob/master/ReleaseNotes.md) - [Commits](mojohaus/versions@2.21.0...2.22.0) --- updated-dependencies: - dependency-name: org.codehaus.mojo:versions-maven-plugin dependency-version: 2.22.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps org.codehaus.cargo:cargo-maven3-plugin from 1.10.28 to 1.10.29. --- updated-dependencies: - dependency-name: org.codehaus.cargo:cargo-maven3-plugin dependency-version: 1.10.29 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [org.apache.httpcomponents.core5:httpcore5](https://github.com/apache/httpcomponents-core) from 5.4.3 to 5.4.4. - [Changelog](https://github.com/apache/httpcomponents-core/blob/rel/v5.4.4/RELEASE_NOTES.txt) - [Commits](apache/httpcomponents-core@rel/v5.4.3...rel/v5.4.4) --- updated-dependencies: - dependency-name: org.apache.httpcomponents.core5:httpcore5 dependency-version: 5.4.4 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.22.2 to 2.22.3. - [Commits](FasterXML/jackson-databind@jackson-databind-2.22.2...jackson-databind-2.22.3) --- updated-dependencies: - dependency-name: com.fasterxml.jackson.core:jackson-databind dependency-version: 2.22.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps org.slf4j:slf4j-reload4j from 2.0.19 to 2.0.20. --- updated-dependencies: - dependency-name: org.slf4j:slf4j-reload4j dependency-version: 2.0.20 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.37.9 to 4.38.2. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@v4.37.9...v4.38.2) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.38.2 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
…t/github_actions/github/codeql-action-4.38.2 Bump github/codeql-action from 4.37.9 to 4.38.2
…t/maven/org.slf4j-slf4j-reload4j-2.0.20 Bump org.slf4j:slf4j-reload4j from 2.0.19 to 2.0.20
…t/maven/org.codehaus.cargo-cargo-maven3-plugin-1.10.29 Bump org.codehaus.cargo:cargo-maven3-plugin from 1.10.28 to 1.10.29
…t/maven/org.apache.httpcomponents.core5-httpcore5-5.4.4 Bump org.apache.httpcomponents.core5:httpcore5 from 5.4.3 to 5.4.4
…t/maven/com.fasterxml.jackson.core-jackson-databind-2.22.3 Bump com.fasterxml.jackson.core:jackson-databind from 2.22.2 to 2.22.3
…t/maven/org.apache.maven.plugins-maven-deploy-plugin-3.2.0 Bump org.apache.maven.plugins:maven-deploy-plugin from 3.1.4 to 3.2.0
…t/maven/org.apache.maven.plugins-maven-install-plugin-3.2.0 Bump org.apache.maven.plugins:maven-install-plugin from 3.1.4 to 3.2.0
…t/maven/org.codehaus.mojo-extra-enforcer-rules-1.12.1 Bump org.codehaus.mojo:extra-enforcer-rules from 1.12.0 to 1.12.1
…t/maven/org.codehaus.mojo-versions-maven-plugin-2.22.0 Bump org.codehaus.mojo:versions-maven-plugin from 2.21.0 to 2.22.0
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The version updates are valid, preserve the LDAP compatibility pin, and passed the documented Maven validation.
Review effort: Balanced
Findings: None
What changed in this PR
Synchronizes the fork with upstream dependency and CI maintenance updates.
Changes:
- Updates Maven dependencies, plugins, LDAP API, and Tomcat.
- Updates CodeQL actions to v4.38.2.
| File | Description |
|---|---|
pom.xml |
Updates dependency, plugin, and server versions. |
.github/workflows/codeql-analysis.yml |
Updates CodeQL initialization and analysis actions. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
OWASP-Benchmark/BenchmarkJava@1fadd6c7cinto the fork'smasterhistory, preserving all upstream commits.Validation
mvn -q spotless:check packagepassed locally.