[GitHub] [jspwiki] juanpablo-santos closed pull request #219: Bump gson from 2.9.0 to 2.9.1

2022-10-19 Thread GitBox
juanpablo-santos closed pull request #219: Bump gson from 2.9.0 to 2.9.1 URL: https://github.com/apache/jspwiki/pull/219 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsu

[GitHub] [jspwiki] juanpablo-santos closed pull request #224: Bump maven-project-info-reports-plugin from 3.4.0 to 3.4.1

2022-10-19 Thread GitBox
juanpablo-santos closed pull request #224: Bump maven-project-info-reports-plugin from 3.4.0 to 3.4.1 URL: https://github.com/apache/jspwiki/pull/224 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to

[GitHub] [jspwiki] juanpablo-santos closed pull request #225: Bump mockito.version from 4.6.1 to 4.7.0

2022-10-19 Thread GitBox
juanpablo-santos closed pull request #225: Bump mockito.version from 4.6.1 to 4.7.0 URL: https://github.com/apache/jspwiki/pull/225 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comme

[GitHub] [jspwiki] juanpablo-santos closed pull request #233: Bump selenide from 6.6.6 to 6.9.0

2022-10-19 Thread GitBox
juanpablo-santos closed pull request #233: Bump selenide from 6.6.6 to 6.9.0 URL: https://github.com/apache/jspwiki/pull/233 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To

[GitHub] [jspwiki] dependabot[bot] commented on pull request #233: Bump selenide from 6.6.6 to 6.9.0

2022-10-19 Thread GitBox
dependabot[bot] commented on PR #233: URL: https://github.com/apache/jspwiki/pull/233#issuecomment-1284533528 OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let m

[GitHub] [jspwiki] dependabot[bot] commented on pull request #219: Bump gson from 2.9.0 to 2.9.1

2022-10-19 Thread GitBox
dependabot[bot] commented on PR #219: URL: https://github.com/apache/jspwiki/pull/219#issuecomment-1284533514 OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let m

[GitHub] [jspwiki] dependabot[bot] commented on pull request #224: Bump maven-project-info-reports-plugin from 3.4.0 to 3.4.1

2022-10-19 Thread GitBox
dependabot[bot] commented on PR #224: URL: https://github.com/apache/jspwiki/pull/224#issuecomment-1284533526 OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let m

[GitHub] [jspwiki] dependabot[bot] commented on pull request #225: Bump mockito.version from 4.6.1 to 4.7.0

2022-10-19 Thread GitBox
dependabot[bot] commented on PR #225: URL: https://github.com/apache/jspwiki/pull/225#issuecomment-1284533539 OK, I won't notify you again about this release, but will get in touch when a new version is available. You can also ignore all major, minor, or patch releases for a dependency by a

[GitHub] [jspwiki] juanpablo-santos merged pull request #220: Add missing licences.

2022-10-19 Thread GitBox
juanpablo-santos merged PR #220: URL: https://github.com/apache/jspwiki/pull/220 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: dev-unsubscr...@jspwiki

[GitHub] [jspwiki] juanpablo-santos commented on pull request #220: Add missing licences.

2022-10-19 Thread GitBox
juanpablo-santos commented on PR #220: URL: https://github.com/apache/jspwiki/pull/220#issuecomment-1284534743 merged in 2.12.0-git-01, thanks! -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [jspwiki] juanpablo-santos closed pull request #228: [SECURITY] Fix Partial Path Traversal Vulnerability

2022-10-19 Thread GitBox
juanpablo-santos closed pull request #228: [SECURITY] Fix Partial Path Traversal Vulnerability URL: https://github.com/apache/jspwiki/pull/228 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the spe

[GitHub] [jspwiki] juanpablo-santos commented on pull request #228: [SECURITY] Fix Partial Path Traversal Vulnerability

2022-10-19 Thread GitBox
juanpablo-santos commented on PR #228: URL: https://github.com/apache/jspwiki/pull/228#issuecomment-1284553889 Hi, as of the PR: > To clarify, the uid is not ever controlled by an outside actor? It is only ever an internal value not supplied by user controlled data? I'm sayi

[GitHub] [jspwiki] dependabot[bot] opened a new pull request, #237: Bump glob from 7.2.0 to 7.2.3

2022-10-19 Thread GitBox
dependabot[bot] opened a new pull request, #237: URL: https://github.com/apache/jspwiki/pull/237 Bumps [glob](https://github.com/isaacs/node-glob) from 7.2.0 to 7.2.3. Commits https://github.com/isaacs/node-glob/commit/c3cd57ae128faa0e9190492acc743bb779ac4054";>c3cd57a 7.2.3

[GitHub] [jspwiki] dependabot[bot] opened a new pull request, #238: Bump jetty-all from 9.4.48.v20220622 to 9.4.49.v20220914

2022-10-19 Thread GitBox
dependabot[bot] opened a new pull request, #238: URL: https://github.com/apache/jspwiki/pull/238 Bumps jetty-all from 9.4.48.v20220622 to 9.4.49.v20220914. [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=org.ecl

[GitHub] [jspwiki] dependabot[bot] opened a new pull request, #239: Bump cargo-maven3-plugin from 1.9.13 to 1.10.2

2022-10-19 Thread GitBox
dependabot[bot] opened a new pull request, #239: URL: https://github.com/apache/jspwiki/pull/239 Bumps cargo-maven3-plugin from 1.9.13 to 1.10.2. [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=org.codehaus.carg