[PR] CXF-9037: NPE when using com.ctc.wstx.returnNullForDefaultNamespace=true [cxf]

2024-07-14 Thread via GitHub


reta opened a new pull request, #1962:
URL: https://github.com/apache/cxf/pull/1962

   NPE when using com.ctc.wstx.returnNullForDefaultNamespace=true


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@cxf.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



Re: [VOTE] Release CXF 4.0.5, 3.6.4 and 3.5.9

2024-07-14 Thread jgenender
+1

Jeff


> On Jul 12, 2024, at 2:14 PM, Freeman Fang  wrote:
> 
> Hi,
> 
> It’s been a while since the last releases and many issues have been
> addressed, so here is the VOTE for CXF 4.0.5, 3.6.4 and 3.5.9
> 
> Staging areas:
> https://repository.apache.org/content/repositories/orgapachecxf-1203
> https://repository.apache.org/content/repositories/orgapachecxf-1204
> https://repository.apache.org/content/repositories/orgapachecxf-1205
> 
> Tags:
> https://github.com/apache/cxf/commit/630d7368e073d379227d48ff4797c23377dc5ebf
> https://github.com/apache/cxf/commit/6b27aec74e5329b60e84ff2478c854bf2acf3db5
> https://github.com/apache/cxf/commit/8c68c138ce0b7f5c1945e744f7cf5067a8298374
> 
> I will keep the vote open for at least 72 hours(weekends not included).
> 
> Cheers
> Freeman



[PR] Bump org.apache.maven.plugins:maven-pmd-plugin from 3.21.2 to 3.24.0 [cxf-xjc-utils]

2024-07-14 Thread via GitHub


dependabot[bot] opened a new pull request, #156:
URL: https://github.com/apache/cxf-xjc-utils/pull/156

   Bumps 
[org.apache.maven.plugins:maven-pmd-plugin](https://github.com/apache/maven-pmd-plugin)
 from 3.21.2 to 3.24.0.
   
   Release notes
   Sourced from https://github.com/apache/maven-pmd-plugin/releases";>org.apache.maven.plugins:maven-pmd-plugin's
 releases.
   
   3.24.0
   🚀 New features and improvements
   
   https://issues.apache.org/jira/browse/MPMD-391";>[MPMD-391] 
- Log what developers care about and not what they don't (https://redirect.github.com/apache/maven-pmd-plugin/pull/156";>#156) 
https://github.com/michael-o";>@​michael-o
   
   🐛 Bug Fixes
   
   https://issues.apache.org/jira/browse/MPMD-399";>[MPMD-399] 
- Incorrect warning: The project X does not seem to be compi… (https://redirect.github.com/apache/maven-pmd-plugin/pull/154";>#154) 
https://github.com/michael-o";>@​michael-o
   
   📦 Dependency updates
   
   https://issues.apache.org/jira/browse/MPMD-400";>[MPMD-400] 
- Upgrade to PMD 7.3.0 (https://redirect.github.com/apache/maven-pmd-plugin/pull/157";>#157) 
https://github.com/michael-o";>@​michael-o
   Bump org.codehaus.mojo:animal-sniffer-maven-plugin from 1.23 to 1.24 (https://redirect.github.com/apache/maven-pmd-plugin/pull/155";>#155) 
https://github.com/dependabot";>@​dependabot
   Bump org.apache.maven.shared:maven-common-artifact-filters from 3.3.2 to 
3.4.0 (https://redirect.github.com/apache/maven-pmd-plugin/pull/153";>#153) 
https://github.com/dependabot";>@​dependabot
   
   👻 Maintenance
   
   Remove outdated (https://redirect.github.com/apache/maven-pmd-plugin/pull/158";>#158) 
https://github.com/michael-o";>@​michael-o
   
   3.23.0
   🐛 Bug Fixes
   
   https://issues.apache.org/jira/browse/MPMD-395";>[MPMD-395] 
- Build doesn't fail for invalid CPD format (https://redirect.github.com/apache/maven-pmd-plugin/pull/150";>#150) 
https://github.com/adangel";>@​adangel
   
   📦 Dependency updates
   
   https://issues.apache.org/jira/browse/MPMD-397";>[MPMD-397] 
- Upgrade to Maven 3.6.3 (https://redirect.github.com/apache/maven-pmd-plugin/pull/151";>#151) 
https://github.com/michael-o";>@​michael-o
   
   3.22.0
   
   🚀 New features and improvements
   
   https://issues.apache.org/jira/browse/MPMD-379";>[MPMD-379] 
- Upgrade to use PMD 7.0.0 by default (https://redirect.github.com/apache/maven-pmd-plugin/pull/144";>#144) 
https://github.com/mkolesnikov";>@​mkolesnikov
   
   📦 Dependency updates
   
   https://issues.apache.org/jira/browse/MPMD-394";>[MPMD-394] 
- Bump org.apache.maven.plugins:maven-plugins from 41 to 42 (https://redirect.github.com/apache/maven-pmd-plugin/pull/148";>#148) 
https://github.com/dependabot";>@​dependabot
   https://issues.apache.org/jira/browse/MPMD-393";>[MPMD-393] 
- Bump commons-io:commons-io from 2.16.0 to 2.16.1 (https://redirect.github.com/apache/maven-pmd-plugin/pull/147";>#147) 
https://github.com/dependabot";>@​dependabot
   https://issues.apache.org/jira/browse/MPMD-393";>[MPMD-393] 
- Bump commons-io:commons-io from 2.15.1 to 2.16.0 (https://redirect.github.com/apache/maven-pmd-plugin/pull/146";>#146) 
https://github.com/dependabot";>@​dependabot
   Bump apache/maven-gh-actions-shared from 3 to 4 (https://redirect.github.com/apache/maven-pmd-plugin/pull/143";>#143) 
https://github.com/dependabot";>@​dependabot
   Bump org.codehaus.plexus:plexus-resources from 1.2.0 to 1.3.0 (https://redirect.github.com/apache/maven-pmd-plugin/pull/140";>#140) 
https://github.com/dependabot";>@​dependabot
   Bump org.apache.commons:commons-lang3 from 3.12.0 to 3.14.0 (https://redirect.github.com/apache/maven-pmd-plugin/pull/137";>#137) 
https://github.com/dependabot";>@​dependabot
   Bump commons-io:commons-io from 2.11.0 to 2.15.1 (https://redirect.github.com/apache/maven-pmd-plugin/pull/138";>#138) 
https://github.com/dependabot";>@​dependabot
   
   👻 Maintenance
   
   Bump release-drafter/release-drafter from 5 to 6 (https://redirect.github.com/apache/maven-pmd-plugin/pull/142";>#142) 
https://github.com/dependabot";>@​dependabot
   
   
   
   
   Commits
   
   https://github.com/apache/maven-pmd-plugin/commit/af5fab9c8ceb70255afd1c6bc30b3a28940cbf53";>af5fab9
 [maven-release-plugin] prepare release maven-pmd-plugin-3.24.0
   https://github.com/apache/maven-pmd-plugin/commit/506de753934ae83dc2accfa2029878f1ca524c6c";>506de75
 Remove outdated invoker conditions
   https://github.com/apache/maven-pmd-plugin/commit/277a725cb31afa8c4c7d6905d1748919a4211a4f";>277a725
 [MPMD-391] Log what developers care about and not what they don't
   https://github.com/apache/maven-pmd-plugin/commit/7a3b2c2d516678f3e5ed6ec0c0c9f6298c5b9977";>7a3b2c2
 [MPMD-400] Upgrade to PMD 7.3.0
   https://github.com/apache/maven-pmd-plugin/commit/2a72cc86d5f25625059a2e7428038cb1841ac612";>2a72cc8
 [MPMD-399] Incorrect warning: The project X does not seem to be compiled. 
PMD...
   https://github.com/apache/maven-pmd-plugin/commit/71c807b40356b5e5f87a4cae

Re: [PR] Bump org.apache.maven.plugins:maven-pmd-plugin from 3.21.2 to 3.23.0 [cxf-xjc-utils]

2024-07-14 Thread via GitHub


dependabot[bot] commented on PR #153:
URL: https://github.com/apache/cxf-xjc-utils/pull/153#issuecomment-2227560483

   Superseded by #156.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@cxf.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



Re: [PR] Bump org.apache.maven.plugins:maven-pmd-plugin from 3.21.2 to 3.23.0 [cxf-xjc-utils]

2024-07-14 Thread via GitHub


dependabot[bot] closed pull request #153: Bump 
org.apache.maven.plugins:maven-pmd-plugin from 3.21.2 to 3.23.0
URL: https://github.com/apache/cxf-xjc-utils/pull/153


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@cxf.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



[PR] Bump github/codeql-action from 3.25.11 to 3.25.12 [cxf]

2024-07-14 Thread via GitHub


dependabot[bot] opened a new pull request, #1963:
URL: https://github.com/apache/cxf/pull/1963

   Bumps [github/codeql-action](https://github.com/github/codeql-action) from 
3.25.11 to 3.25.12.
   
   Changelog
   Sourced from https://github.com/github/codeql-action/blob/main/CHANGELOG.md";>github/codeql-action's
 changelog.
   
   CodeQL Action Changelog
   See the https://github.com/github/codeql-action/releases";>releases page for 
the relevant changes to the CodeQL CLI and language packs.
   Note that the only difference between v2 and v3 
of the CodeQL Action is the node version they support, with v3 
running on node 20 while we continue to release v2 to support 
running on node 16. For example 3.22.11 was the first 
v3 release and is functionally identical to 2.22.11. 
This approach ensures an easy way to track exactly which features are included 
in different versions, indicated by the minor and patch version numbers.
   [UNRELEASED]
   
   Add codeql-version to outputs. https://redirect.github.com/github/codeql-action/pull/2368";>#2368
   
   3.25.12 - 12 Jul 2024
   
   Improve the reliability and performance of analyzing code when analyzing 
a compiled language with the autobuild https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages#codeql-build-modes";>build
 mode on GitHub Enterprise Server. This feature is already available to 
GitHub.com users. https://redirect.github.com/github/codeql-action/pull/2353";>#2353
   Update default CodeQL bundle version to 2.18.0. https://redirect.github.com/github/codeql-action/pull/2364";>#2364
   
   3.25.11 - 28 Jun 2024
   
   Avoid failing the workflow run if there is an error while uploading 
debug artifacts. https://redirect.github.com/github/codeql-action/pull/2349";>#2349
   Update default CodeQL bundle version to 2.17.6. https://redirect.github.com/github/codeql-action/pull/2352";>#2352
   
   3.25.10 - 13 Jun 2024
   
   Update default CodeQL bundle version to 2.17.5. https://redirect.github.com/github/codeql-action/pull/2327";>#2327
   
   3.25.9 - 12 Jun 2024
   
   Avoid failing database creation if the database folder already exists 
and contains some unexpected files. Requires CodeQL 2.18.0 or higher. https://redirect.github.com/github/codeql-action/pull/2330";>#2330
   The init Action will attempt to clean up the database cluster directory 
before creating a new database and at the end of the job. This will help to 
avoid issues where the database cluster directory is left in an inconsistent 
state. https://redirect.github.com/github/codeql-action/pull/2332";>#2332
   
   3.25.8 - 04 Jun 2024
   
   Update default CodeQL bundle version to 2.17.4. https://redirect.github.com/github/codeql-action/pull/2321";>#2321
   
   3.25.7 - 31 May 2024
   
   We are rolling out a feature in May/June 2024 that will reduce the 
Actions cache usage of the Action by keeping only the newest TRAP cache for 
each language. https://redirect.github.com/github/codeql-action/pull/2306";>#2306
   
   3.25.6 - 20 May 2024
   
   Update default CodeQL bundle version to 2.17.3. https://redirect.github.com/github/codeql-action/pull/2295";>#2295
   
   3.25.5 - 13 May 2024
   
   Add a compatibility matrix of supported CodeQL Action, CodeQL CLI, and 
GitHub Enterprise Server versions to the https://github.com/github/codeql-action/blob/main/README.md";>https://github.com/github/codeql-action/blob/main/README.md.
 https://redirect.github.com/github/codeql-action/pull/2273";>#2273
   Avoid printing out a warning for a missing on.push trigger 
when the CodeQL Action is triggered via a workflow_call event. https://redirect.github.com/github/codeql-action/pull/2274";>#2274
   The tools: latest input to the init Action has 
been renamed to tools: linked. This option specifies that the 
Action should use the tools shipped at the same time as the Action. The old 
name will continue to work for backwards compatibility, but we recommend that 
new workflows use the new name. https://redirect.github.com/github/codeql-action/pull/2281";>#2281
   
   3.25.4 - 08 May 2024
   
   Update default CodeQL bundle version to 2.17.2. https://redirect.github.com/github/codeql-action/pull/2270";>#2270
   
   
   
   ... (truncated)
   
   
   Commits
   
   https://github.com/github/codeql-action/commit/4fa2a7953630fd2f3fb380f21be14ede0169dd4f";>4fa2a79
 Merge pull request https://redirect.github.com/github/codeql-action/issues/2369";>#2369 
from github/update-v3.25.12-947b18fb7
   https://github.com/github/codeql-action/commit/dec6fb713c18d10611178d0d693c19aea88c8e8d";>dec6fb7
 Update changelog for v3.25.12
   https://github.com/github/codeql-action/commit/947b18fb721ec7b717188ea2d1b77547494b5d71";>947b18f
 Merge pull request https://redirect.github.com/github/codeql-action/issues/2365";>#2365 
from github/dependabot/npm_and_yarn/npm-88aac57241
   https://github.com/github/codeql-action/commit/9ab727712f519b

[PR] Bump org.apache.maven.plugins:maven-release-plugin from 3.1.0 to 3.1.1 [cxf]

2024-07-14 Thread via GitHub


dependabot[bot] opened a new pull request, #1964:
URL: https://github.com/apache/cxf/pull/1964

   Bumps 
[org.apache.maven.plugins:maven-release-plugin](https://github.com/apache/maven-release)
 from 3.1.0 to 3.1.1.
   
   Commits
   
   https://github.com/apache/maven-release/commit/4f350d44478d2bf72a8da60395e0c1d1e045369a";>4f350d4
 [maven-release-plugin] prepare release maven-release-3.1.1
   https://github.com/apache/maven-release/commit/06f6de43312ee6cab4ec1a194781a61c5db5bdf9";>06f6de4
 [MRELEASE-1153] Revert parts of MRELEASE-1109 
(8dfcb47996320af5e6f0b2d50eac20...
   https://github.com/apache/maven-release/commit/985d0bcd3f9bd28fc8e78e9c0744abe66aeea7ef";>985d0bc
 [MRELEASE-1149] Current release of the plugin has configuration docs 
missing
   https://github.com/apache/maven-release/commit/47e94b43951778aa9cca7ebd960aa114efa9931a";>47e94b4
 [maven-release-plugin] prepare for next development iteration
   See full diff in https://github.com/apache/maven-release/compare/maven-release-3.1.0...maven-release-3.1.1";>compare
 view
   
   
   
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=org.apache.maven.plugins:maven-release-plugin&package-manager=maven&previous-version=3.1.0&new-version=3.1.1)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   
   Dependabot commands and options
   
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI 
passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and 
block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. 
You can achieve the same result by closing it manually
   - `@dependabot show  ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@cxf.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org



[PR] Bump org.apache.camel.springboot:camel-spring-boot-dependencies from 4.6.0 to 4.7.0 [cxf]

2024-07-14 Thread via GitHub


dependabot[bot] opened a new pull request, #1965:
URL: https://github.com/apache/cxf/pull/1965

   Bumps org.apache.camel.springboot:camel-spring-boot-dependencies from 4.6.0 
to 4.7.0.
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=org.apache.camel.springboot:camel-spring-boot-dependencies&package-manager=maven&previous-version=4.6.0&new-version=4.7.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   
   Dependabot commands and options
   
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI 
passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and 
block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. 
You can achieve the same result by closing it manually
   - `@dependabot show  ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: dev-unsubscr...@cxf.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org