[PR] Bump github/codeql-action from 3.25.8 to 3.25.10 [cxf]

2024-06-16 Thread via GitHub


dependabot[bot] opened a new pull request, #1922:
URL: https://github.com/apache/cxf/pull/1922

   Bumps [github/codeql-action](https://github.com/github/codeql-action) from 
3.25.8 to 3.25.10.
   
   Changelog
   Sourced from https://github.com/github/codeql-action/blob/main/CHANGELOG.md";>github/codeql-action's
 changelog.
   
   CodeQL Action Changelog
   See the https://github.com/github/codeql-action/releases";>releases page for 
the relevant changes to the CodeQL CLI and language packs.
   Note that the only difference between v2 and v3 
of the CodeQL Action is the node version they support, with v3 
running on node 20 while we continue to release v2 to support 
running on node 16. For example 3.22.11 was the first 
v3 release and is functionally identical to 2.22.11. 
This approach ensures an easy way to track exactly which features are included 
in different versions, indicated by the minor and patch version numbers.
   [UNRELEASED]
   No user facing changes.
   3.25.10 - 13 Jun 2024
   
   Update default CodeQL bundle version to 2.17.5. https://redirect.github.com/github/codeql-action/pull/2327";>#2327
   
   3.25.9 - 12 Jun 2024
   
   Avoid failing database creation if the database folder already exists 
and contains some unexpected files. Requires CodeQL 2.18.0 or higher. https://redirect.github.com/github/codeql-action/pull/2330";>#2330
   The init Action will attempt to clean up the database cluster directory 
before creating a new database and at the end of the job. This will help to 
avoid issues where the database cluster directory is left in an inconsistent 
state. https://redirect.github.com/github/codeql-action/pull/2332";>#2332
   
   3.25.8 - 04 Jun 2024
   
   Update default CodeQL bundle version to 2.17.4. https://redirect.github.com/github/codeql-action/pull/2321";>#2321
   
   3.25.7 - 31 May 2024
   
   We are rolling out a feature in May/June 2024 that will reduce the 
Actions cache usage of the Action by keeping only the newest TRAP cache for 
each language. https://redirect.github.com/github/codeql-action/pull/2306";>#2306
   
   3.25.6 - 20 May 2024
   
   Update default CodeQL bundle version to 2.17.3. https://redirect.github.com/github/codeql-action/pull/2295";>#2295
   
   3.25.5 - 13 May 2024
   
   Add a compatibility matrix of supported CodeQL Action, CodeQL CLI, and 
GitHub Enterprise Server versions to the https://github.com/github/codeql-action/blob/main/README.md";>https://github.com/github/codeql-action/blob/main/README.md.
 https://redirect.github.com/github/codeql-action/pull/2273";>#2273
   Avoid printing out a warning for a missing on.push trigger 
when the CodeQL Action is triggered via a workflow_call event. https://redirect.github.com/github/codeql-action/pull/2274";>#2274
   The tools: latest input to the init Action has 
been renamed to tools: linked. This option specifies that the 
Action should use the tools shipped at the same time as the Action. The old 
name will continue to work for backwards compatibility, but we recommend that 
new workflows use the new name. https://redirect.github.com/github/codeql-action/pull/2281";>#2281
   
   3.25.4 - 08 May 2024
   
   Update default CodeQL bundle version to 2.17.2. https://redirect.github.com/github/codeql-action/pull/2270";>#2270
   
   3.25.3 - 25 Apr 2024
   
   Update default CodeQL bundle version to 2.17.1. https://redirect.github.com/github/codeql-action/pull/2247";>#2247
   Workflows running on macos-latest using CodeQL CLI versions 
before v2.15.1 will need to either upgrade their CLI version to v2.15.1 or 
newer, or change the platform to an Intel MacOS runner, such as 
macos-12. ARM machines with SIP disabled, including the newest 
macos-latest image, are unsupported for CLI versions before 
2.15.1. https://redirect.github.com/github/codeql-action/pull/2261";>#2261
   
   3.25.2 - 22 Apr 2024
   No user facing changes.
   
   
   ... (truncated)
   
   
   Commits
   
   https://github.com/github/codeql-action/commit/23acc5c183826b7a8a97bce3cecc52db901f8251";>23acc5c
 Merge pull request https://redirect.github.com/github/codeql-action/issues/2337";>#2337 
from github/update-v3.25.10-5bf6dad35
   https://github.com/github/codeql-action/commit/9b72dbdc68c8ff81c1067a930bd2864ea707129b";>9b72dbd
 Update changelog for v3.25.10
   https://github.com/github/codeql-action/commit/5bf6dad35b41961d8779984f426d6a539bbe5d10";>5bf6dad
 Merge pull request https://redirect.github.com/github/codeql-action/issues/2329";>#2329 
from github/henrymercer/csharp-buildless-rollback-me...
   https://github.com/github/codeql-action/commit/feec81c66bfd25a8de4024a727431eb5a4b31317";>feec81c
 Merge branch 'main' into henrymercer/csharp-buildless-rollback-mechanism
   https://github.com/github/codeql-action/commit/789b5f86ef49249530b3d018f3ab10640eff231c";>789b5f8
 Merge pull request https://redirect.github.com/github/codeql-action/issues/2328";>#2328 
from github/henrymercer/direct-tracing-fix
   https://github.com/github/c

[PR] Bump actions/checkout from 4.1.6 to 4.1.7 [cxf]

2024-06-16 Thread via GitHub


dependabot[bot] opened a new pull request, #1923:
URL: https://github.com/apache/cxf/pull/1923

   Bumps [actions/checkout](https://github.com/actions/checkout) from 4.1.6 to 
4.1.7.
   
   Release notes
   Sourced from https://github.com/actions/checkout/releases";>actions/checkout's 
releases.
   
   v4.1.7
   What's Changed
   
   Bump the minor-npm-dependencies group across 1 directory with 4 updates 
by https://github.com/dependabot";>@​dependabot in https://redirect.github.com/actions/checkout/pull/1739";>actions/checkout#1739
   Bump actions/checkout from 3 to 4 by https://github.com/dependabot";>@​dependabot in https://redirect.github.com/actions/checkout/pull/1697";>actions/checkout#1697
   Check out other refs/* by commit by https://github.com/orhantoy";>@​orhantoy in https://redirect.github.com/actions/checkout/pull/1774";>actions/checkout#1774
   Pin actions/checkout's own workflows to a known, good, stable version. 
by https://github.com/jww3";>@​jww3 in https://redirect.github.com/actions/checkout/pull/1776";>actions/checkout#1776
   
   New Contributors
   
   https://github.com/orhantoy";>@​orhantoy made 
their first contribution in https://redirect.github.com/actions/checkout/pull/1774";>actions/checkout#1774
   
   Full Changelog: https://github.com/actions/checkout/compare/v4.1.6...v4.1.7";>https://github.com/actions/checkout/compare/v4.1.6...v4.1.7
   
   
   
   Changelog
   Sourced from https://github.com/actions/checkout/blob/main/CHANGELOG.md";>actions/checkout's
 changelog.
   
   Changelog
   v4.1.7
   
   Bump the minor-npm-dependencies group across 1 directory with 4 updates 
by https://github.com/dependabot";>@​dependabot in https://redirect.github.com/actions/checkout/pull/1739";>actions/checkout#1739
   Bump actions/checkout from 3 to 4 by https://github.com/dependabot";>@​dependabot in https://redirect.github.com/actions/checkout/pull/1697";>actions/checkout#1697
   Check out other refs/* by commit by https://github.com/orhantoy";>@​orhantoy in https://redirect.github.com/actions/checkout/pull/1774";>actions/checkout#1774
   Pin actions/checkout's own workflows to a known, good, stable version. 
by https://github.com/jww3";>@​jww3 in https://redirect.github.com/actions/checkout/pull/1776";>actions/checkout#1776
   
   v4.1.6
   
   Check platform to set archive extension appropriately by https://github.com/cory-miller";>@​cory-miller in https://redirect.github.com/actions/checkout/pull/1732";>actions/checkout#1732
   
   v4.1.5
   
   Update NPM dependencies by https://github.com/cory-miller";>@​cory-miller in https://redirect.github.com/actions/checkout/pull/1703";>actions/checkout#1703
   Bump github/codeql-action from 2 to 3 by https://github.com/dependabot";>@​dependabot in https://redirect.github.com/actions/checkout/pull/1694";>actions/checkout#1694
   Bump actions/setup-node from 1 to 4 by https://github.com/dependabot";>@​dependabot in https://redirect.github.com/actions/checkout/pull/1696";>actions/checkout#1696
   Bump actions/upload-artifact from 2 to 4 by https://github.com/dependabot";>@​dependabot in https://redirect.github.com/actions/checkout/pull/1695";>actions/checkout#1695
   README: Suggest user.email to be 
41898282+github-actions[bot]@users.noreply.github.com by https://github.com/cory-miller";>@​cory-miller in https://redirect.github.com/actions/checkout/pull/1707";>actions/checkout#1707
   
   v4.1.4
   
   Disable extensions.worktreeConfig when disabling 
sparse-checkout by https://github.com/jww3";>@​jww3 in https://redirect.github.com/actions/checkout/pull/1692";>actions/checkout#1692
   Add dependabot config by https://github.com/cory-miller";>@​cory-miller in https://redirect.github.com/actions/checkout/pull/1688";>actions/checkout#1688
   Bump the minor-actions-dependencies group with 2 updates by https://github.com/dependabot";>@​dependabot in https://redirect.github.com/actions/checkout/pull/1693";>actions/checkout#1693
   Bump word-wrap from 1.2.3 to 1.2.5 by https://github.com/dependabot";>@​dependabot in https://redirect.github.com/actions/checkout/pull/1643";>actions/checkout#1643
   
   v4.1.3
   
   Check git version before attempting to disable 
sparse-checkout by https://github.com/jww3";>@​jww3 in https://redirect.github.com/actions/checkout/pull/1656";>actions/checkout#1656
   Add SSH user parameter by https://github.com/cory-miller";>@​cory-miller in https://redirect.github.com/actions/checkout/pull/1685";>actions/checkout#1685
   Update actions/checkout version in 
update-main-version.yml by https://github.com/jww3";>@​jww3 in https://redirect.github.com/actions/checkout/pull/1650";>actions/checkout#1650
   
   v4.1.2
   
   Fix: Disable sparse checkout whenever sparse-checkout 
option is not present https://github.com/dscho";>@​dscho in https://redirect.github.com/actions/checkout/pull/1598";>actions/checkout#1598
   
   v4.1.1
   
   Correct link to GitHub Docs by https://github.com/peterbe";>@​peterbe in https://redirect.githu

[PR] Bump cxf.xnio.version from 3.8.15.Final to 3.8.16.Final [cxf]

2024-06-16 Thread via GitHub


dependabot[bot] opened a new pull request, #1924:
URL: https://github.com/apache/cxf/pull/1924

   Bumps `cxf.xnio.version` from 3.8.15.Final to 3.8.16.Final.
   Updates `org.jboss.xnio:xnio-nio` from 3.8.15.Final to 3.8.16.Final
   
   Updates `org.jboss.xnio:xnio-api` from 3.8.15.Final to 3.8.16.Final
   
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   
   Dependabot commands and options
   
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI 
passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and 
block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. 
You can achieve the same result by closing it manually
   - `@dependabot show  ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@cxf.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



[PR] Bump org.apache.maven.plugins:maven-release-plugin from 3.0.1 to 3.1.0 [cxf]

2024-06-16 Thread via GitHub


dependabot[bot] opened a new pull request, #1925:
URL: https://github.com/apache/cxf/pull/1925

   Bumps 
[org.apache.maven.plugins:maven-release-plugin](https://github.com/apache/maven-release)
 from 3.0.1 to 3.1.0.
   
   Release notes
   Sourced from https://github.com/apache/maven-release/releases";>org.apache.maven.plugins:maven-release-plugin's
 releases.
   
   3.1.0
   
   🚀 New features and improvements
   
   https://issues.apache.org/jira/browse/MRELEASE-1145";>[MRELEASE-1145] 
- Upgrade to Maven 3.6.3 (https://redirect.github.com/apache/maven-release/pull/217";>#217) https://github.com/michael-o";>@​michael-o
   https://issues.apache.org/jira/browse/MRELEASE-1139";>[MRELEASE-1139] 
- Improve logging of sources for used credentials (https://redirect.github.com/apache/maven-release/pull/209";>#209) https://github.com/kwin";>@​kwin
   https://issues.apache.org/jira/browse/MRELEASE-1134";>[MRELEASE-1134] 
- Pass interactive flag to SCM provider (https://redirect.github.com/apache/maven-release/pull/197";>#197) https://github.com/kwin";>@​kwin
   
   🐛 Bug Fixes
   
   https://issues.apache.org/jira/browse/MRELEASE-1064";>[MRELEASE-1064] 
- [REGRESSION] release:branch uses https://github.com/releaseLabel";>@​releaseLabel instea… 
(https://redirect.github.com/apache/maven-release/pull/221";>#221) 
https://github.com/michael-o";>@​michael-o
   https://issues.apache.org/jira/browse/MRELEASE-1147";>[MRELEASE-1147] 
- https://github.com/junitVersion";>@​junitVersion@ 
never replaced in UTs (make explicit) (https://redirect.github.com/apache/maven-release/pull/220";>#220) https://github.com/michael-o";>@​michael-o
   https://issues.apache.org/jira/browse/MRELEASE-1148";>[MRELEASE-1148] 
- Release Manage pulls in transitive dependencies (https://redirect.github.com/apache/maven-release/pull/219";>#219) https://github.com/michael-o";>@​michael-o
   https://issues.apache.org/jira/browse/MRELEASE-1146";>[MRELEASE-1146] 
- maven-release-plugin tests do not properly check for … (https://redirect.github.com/apache/maven-release/pull/218";>#218) https://github.com/michael-o";>@​michael-o
   https://issues.apache.org/jira/browse/MRELEASE-1109";>[MRELEASE-1109] 
- patch JDomModel (https://redirect.github.com/apache/maven-release/pull/201";>#201) https://github.com/mkolesnikov";>@​mkolesnikov
   https://issues.apache.org/jira/browse/MRELEASE-1109";>[MRELEASE-1109] 
- Support CI friendly versions (https://redirect.github.com/apache/maven-release/pull/198";>#198) https://github.com/kwin";>@​kwin
   
   📦 Dependency updates
   
   Bump scmVersion from 2.0.1 to 2.1.0 (https://redirect.github.com/apache/maven-release/pull/213";>#213) https://github.com/dependabot";>@​dependabot
   Bump org.apache.maven.shared:maven-invoker from 3.2.0 to 3.3.0 (https://redirect.github.com/apache/maven-release/pull/215";>#215) https://github.com/dependabot";>@​dependabot
   Bump org.codehaus.plexus:plexus-interactivity-api from 1.2 to 1.3 (https://redirect.github.com/apache/maven-release/pull/210";>#210) https://github.com/dependabot";>@​dependabot
   Bump org.codehaus.plexus:plexus-interpolation from 1.26 to 1.27 (https://redirect.github.com/apache/maven-release/pull/206";>#206) https://github.com/dependabot";>@​dependabot
   Bump org.xmlunit:xmlunit-core from 2.9.1 to 2.10.0 (https://redirect.github.com/apache/maven-release/pull/214";>#214) https://github.com/dependabot";>@​dependabot
   https://issues.apache.org/jira/browse/MRELEASE-1144";>[MRELEASE-1144] 
- Upgrade to Parent 42 (https://redirect.github.com/apache/maven-release/pull/216";>#216) https://github.com/michael-o";>@​michael-o
   Bump apache/maven-gh-actions-shared from 3 to 4 (https://redirect.github.com/apache/maven-release/pull/212";>#212) https://github.com/dependabot";>@​dependabot
   Bump org.codehaus.plexus:plexus-interactivity-api from 1.1 to 1.2 (https://redirect.github.com/apache/maven-release/pull/207";>#207) https://github.com/dependabot";>@​dependabot
   Bump org.codehaus.mojo:mrm-maven-plugin from 1.5.0 to 1.6.0 (https://redirect.github.com/apache/maven-release/pull/200";>#200) https://github.com/dependabot";>@​dependabot
   Bump org.apache.maven.plugins:maven-invoker-plugin from 3.5.1 to 3.6.0 
(https://redirect.github.com/apache/maven-release/pull/204";>#204) 
https://github.com/dependabot";>@​dependabot
   Bump org.apache.commons:commons-lang3 from 3.12.0 to 3.14.0 (https://redirect.github.com/apache/maven-release/pull/205";>#205) https://github.com/dependabot";>@​dependabot
   https://issues.apache.org/jira/browse/MRELEASE-1128";>[MRELEASE-1128] 
- update maven-scm to 2.0.1 (https://redirect.github.com/apache/maven-release/pull/192";>#192) https://github.com/elharo";>@​elharo
   
   👻 Maintenance
   
   Bump release-drafter/release-drafter from 5 to 6 (https://redirect.github.com/apache/maven-release/pull/211";>#211) https://github.com/dependabot";>@​dependabot
   https://issues.apache.org/jira/browse/MRELEASE-1136";>[MRELEASE-1136] 
- Upgrade parent pom to

[PR] Bump org.apache.maven.plugins:maven-project-info-reports-plugin from 3.5.0 to 3.6.0 [cxf]

2024-06-16 Thread via GitHub


dependabot[bot] opened a new pull request, #1926:
URL: https://github.com/apache/cxf/pull/1926

   Bumps 
[org.apache.maven.plugins:maven-project-info-reports-plugin](https://github.com/apache/maven-project-info-reports-plugin)
 from 3.5.0 to 3.6.0.
   
   Commits
   
   https://github.com/apache/maven-project-info-reports-plugin/commit/f4d3a12764f9bea07b6c8dcfe2a74f9544f51de3";>f4d3a12
 [maven-release-plugin] prepare release 
maven-project-info-reports-plugin-3.6.0
   https://github.com/apache/maven-project-info-reports-plugin/commit/34ca65bc0fae866814b59c9bfe1795bbec80";>34ca65b
 [MPIR-461] Upgrade plugins and components (in ITs)
   https://github.com/apache/maven-project-info-reports-plugin/commit/a44cc8ab44dda25c08d658666e0b2dadf826f93d";>a44cc8a
 [MPIR-455] dependencies goal: add support for multi-release JARs
   https://github.com/apache/maven-project-info-reports-plugin/commit/be2e4ed4a7f6f53a53457896989307b8b4bc7089";>be2e4ed
 [MPIR-451] Rename "Dependency Information" to "Maven 
Coordinates"
   https://github.com/apache/maven-project-info-reports-plugin/commit/dc1710d595de4467be743d4c55a020eef1bc22e3";>dc1710d
 [MPIR-460] Dependency Information for maven-plugin
   https://github.com/apache/maven-project-info-reports-plugin/commit/2ca83d0d883f2a2400ccc5128d4a8339982a9785";>2ca83d0
 [MPIR-459] Refresh download page
   https://github.com/apache/maven-project-info-reports-plugin/commit/3ed99acda62c6f314fe64e6a5df1d49a4903c92e";>3ed99ac
 [MPIR-457] Upgrade to Parent 42 and Maven 3.6.3
   https://github.com/apache/maven-project-info-reports-plugin/commit/be2e5f910fe11ca224665d04258f94ea2799ed7a";>be2e5f9
 Bump maven-gh-actions-shared to v4
   https://github.com/apache/maven-project-info-reports-plugin/commit/70e41363aa1521523a04091337d5ce5e0c039897";>70e4136
 Add .factorypath to .gitignore
   https://github.com/apache/maven-project-info-reports-plugin/commit/33db4bdc1b750c1a9c9e4a61ba61e7a082bd1d74";>33db4bd
 [maven-release-plugin] prepare for next development iteration
   See full diff in https://github.com/apache/maven-project-info-reports-plugin/compare/maven-project-info-reports-plugin-3.5.0...maven-project-info-reports-plugin-3.6.0";>compare
 view
   
   
   
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=org.apache.maven.plugins:maven-project-info-reports-plugin&package-manager=maven&previous-version=3.5.0&new-version=3.6.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   
   Dependabot commands and options
   
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI 
passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and 
block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. 
You can achieve the same result by closing it manually
   - `@dependabot show  ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@cxf.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org