dependabot[bot] opened a new pull request, #2073: URL: https://github.com/apache/maven-resolver/pull/2073
Bumps [org.codehaus.plexus:plexus-utils](https://github.com/codehaus-plexus/plexus-utils) from 3.6.0 to 4.1.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/codehaus-plexus/plexus-utils/releases">org.codehaus.plexus:plexus-utils's releases</a>.</em></p> <blockquote> <h2>4.1.0</h2> <p><code>DirectoryScanner</code> no longer excludes <code>.gitignore</code> and <code>.cvsignore</code> by default. Code that relied on the old defaults has to add the two patterns explicitly. That change is what makes this a minor release rather than 4.0.4.</p> <h2>:boom: Breaking changes</h2> <ul> <li>Do not exclude ".gitignore" and ".cvsignore" by default (<a href="https://redirect.github.com/codehaus-plexus/plexus-utils/pull/326">#326</a>) <a href="https://github.com/kwin"><code>@kwin</code></a></li> </ul> <h2>👻 Maintenance</h2> <ul> <li>Rewrite README with usage, status and version guidance (<a href="https://redirect.github.com/codehaus-plexus/plexus-utils/pull/332">#332</a>) <a href="https://github.com/slachiewicz"><code>@slachiewicz</code></a></li> </ul> <h2>🔧 Build</h2> <ul> <li>Update parent to plexus 27 (<a href="https://redirect.github.com/codehaus-plexus/plexus-utils/pull/338">#338</a>) <a href="https://github.com/slachiewicz"><code>@slachiewicz</code></a></li> <li>Drop the Publish Site workflow (<a href="https://redirect.github.com/codehaus-plexus/plexus-utils/pull/337">#337</a>) <a href="https://github.com/slachiewicz"><code>@slachiewicz</code></a></li> <li>Add the Publish Site workflow (<a href="https://redirect.github.com/codehaus-plexus/plexus-utils/pull/334">#334</a>) <a href="https://github.com/slachiewicz"><code>@slachiewicz</code></a></li> <li>Use the shared release-drafter config instead of a local copy (<a href="https://redirect.github.com/codehaus-plexus/plexus-utils/pull/333">#333</a>) <a href="https://github.com/slachiewicz"><code>@slachiewicz</code></a></li> </ul> <h2>📦 Dependency updates</h2> <ul> <li>Bump the plexus dependencies released today (<a href="https://redirect.github.com/codehaus-plexus/plexus-utils/pull/340">#340</a>) <a href="https://github.com/slachiewicz"><code>@slachiewicz</code></a></li> <li>Bump org.codehaus.plexus:plexus from 25 to 26 (<a href="https://redirect.github.com/codehaus-plexus/plexus-utils/pull/335">#335</a>) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li> <li>Bump release-drafter/release-drafter from 7.6.0 to 7.7.0 (<a href="https://redirect.github.com/codehaus-plexus/plexus-utils/pull/331">#331</a>) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li> <li>Bump release-drafter/release-drafter from 7 to 7.6.0 (<a href="https://redirect.github.com/codehaus-plexus/plexus-utils/pull/330">#330</a>) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li> </ul> <h2>4.0.3</h2> <!-- raw HTML omitted --> <h2>🚀 New features and improvements</h2> <ul> <li>Add Automatic-Module-Name manifest entry (<a href="https://redirect.github.com/codehaus-plexus/plexus-utils/pull/314">#314</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> <li>V4 changes to make external usage easier (<a href="https://redirect.github.com/codehaus-plexus/plexus-utils/pull/278">#278</a>) <a href="https://github.com/Claudenw"><code>@Claudenw</code></a></li> </ul> <h2>🐛 Bug Fixes</h2> <ul> <li>Fix Zip Slip vulnerability in archive extraction (<a href="https://redirect.github.com/codehaus-plexus/plexus-utils/pull/296">#296</a>) @<a href="https://github.com/apps/copilot-swe-agent">copilot-swe-agent[bot]</a></li> </ul> <h2>👻 Maintenance</h2> <ul> <li>Move to Site 2.0 descriptor (<a href="https://redirect.github.com/codehaus-plexus/plexus-utils/pull/305">#305</a>) <a href="https://github.com/slachiewicz"><code>@slachiewicz</code></a></li> <li>JUnit Jupiter best practices & code cleanups (<a href="https://redirect.github.com/codehaus-plexus/plexus-utils/pull/302">#302</a>) <a href="https://github.com/slachiewicz"><code>@slachiewicz</code></a></li> <li>Replace <code>FileUtils.fileExists(String)</code> with JDK provided API (<a href="https://redirect.github.com/codehaus-plexus/plexus-utils/pull/301">#301</a>) <a href="https://github.com/slachiewicz"><code>@slachiewicz</code></a></li> <li>Declare license info in POM (<a href="https://redirect.github.com/codehaus-plexus/plexus-utils/pull/291">#291</a>) <a href="https://github.com/Goooler"><code>@Goooler</code></a></li> <li>Cleanup tests (<a href="https://redirect.github.com/codehaus-plexus/plexus-utils/pull/283">#283</a>) <a href="https://github.com/slachiewicz"><code>@slachiewicz</code></a></li> </ul> <h2>📦 Dependency updates</h2> <ul> <li>Bump release-drafter/release-drafter from 6 to 7 (<a href="https://redirect.github.com/codehaus-plexus/plexus-utils/pull/313">#313</a>) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li> <li>Bump org.codehaus.plexus:plexus from 24 to 25 (<a href="https://redirect.github.com/codehaus-plexus/plexus-utils/pull/309">#309</a>) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/codehaus-plexus/plexus-utils/commit/572ce90d98d71bfe29078b680fc14d3088f43a14"><code>572ce90</code></a> [maven-release-plugin] prepare release plexus-utils-4.1.0</li> <li><a href="https://github.com/codehaus-plexus/plexus-utils/commit/077e8010c109576715077f4a70094623295d5ce9"><code>077e801</code></a> Bump the plexus dependencies released today</li> <li><a href="https://github.com/codehaus-plexus/plexus-utils/commit/840a1b49b3b7bdc3f883ef0c698566988c7e21ec"><code>840a1b4</code></a> Update parent to plexus 27</li> <li><a href="https://github.com/codehaus-plexus/plexus-utils/commit/9c560fa3ea573e48d7d528c86eca4690ff1a6bc0"><code>9c560fa</code></a> Drop the Publish Site workflow</li> <li><a href="https://github.com/codehaus-plexus/plexus-utils/commit/5f96b03fefa9e3f9d7c47b88bebc400a44c88795"><code>5f96b03</code></a> Bump org.codehaus.plexus:plexus from 25 to 26</li> <li><a href="https://github.com/codehaus-plexus/plexus-utils/commit/4846c05a48b35bb12dc3fb5254b3b77b93784730"><code>4846c05</code></a> Add the Publish Site workflow</li> <li><a href="https://github.com/codehaus-plexus/plexus-utils/commit/4df3a8663601eaeb0fd5c71fd6bcc2b2ecc2234d"><code>4df3a86</code></a> Use the shared release-drafter config instead of a local copy</li> <li><a href="https://github.com/codehaus-plexus/plexus-utils/commit/9eb5fc61fe732c5e16737490f11b1898634252fe"><code>9eb5fc6</code></a> Apply spotless formatting to README</li> <li><a href="https://github.com/codehaus-plexus/plexus-utils/commit/f2856f90460216275047fa6c5b4c333726ee3f80"><code>f2856f9</code></a> Rewrite README with usage, status and version guidance</li> <li><a href="https://github.com/codehaus-plexus/plexus-utils/commit/62fe2fa47a81245ca0588a110c35a918a8f4402e"><code>62fe2fa</code></a> Bump release-drafter/release-drafter from 7.6.0 to 7.7.0</li> <li>Additional commits viewable in <a href="https://github.com/codehaus-plexus/plexus-utils/compare/plexus-utils-3.6.0...plexus-utils-4.1.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
