dependabot[bot] opened a new pull request, #99:
URL: https://github.com/apache/tooling-atr-maven-plugin/pull/99

   Bumps 
[org.apache.maven.resolver:maven-resolver-api](https://github.com/apache/maven-resolver)
 from 1.9.27 to 2.0.23.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/apache/maven-resolver/releases";>org.apache.maven.resolver:maven-resolver-api's
 releases</a>.</em></p>
   <blockquote>
   <h2>2.0.23</h2>
   <!-- raw HTML omitted -->
   <h2>🚀 New features and improvements</h2>
   <ul>
   <li>Finish the repo key story (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2135";>#2135</a>) 
<a href="https://github.com/cstamas";><code>@​cstamas</code></a></li>
   <li>Fix: log only once the warning in DefRemoteRepoMan (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2100";>#2100</a>) 
<a href="https://github.com/cstamas";><code>@​cstamas</code></a></li>
   <li>Fix <a 
href="https://redirect.github.com/apache/maven-resolver/issues/2058";>#2058</a>: 
Add links to configuration page (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2060";>#2060</a>) 
<a href="https://github.com/Jamison929611";><code>@​Jamison929611</code></a></li>
   <li>Eliminate per-node HashSet allocation in PathConflictResolver (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2075";>#2075</a>) 
<a href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   </ul>
   <h2>🐛 Bug Fixes</h2>
   <ul>
   <li>fix: accept locally cached artifacts via same-id fallback when tracking 
URL changes (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2133";>#2133</a>) 
<a href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   <li>Fix listener error swallowing (<a 
href="https://redirect.github.com/apache/maven-resolver/issues/1990";>#1990</a>),
 SyncContext double-close (<a 
href="https://redirect.github.com/apache/maven-resolver/issues/1992";>#1992</a>),
 and test flakiness (<a 
href="https://redirect.github.com/apache/maven-resolver/issues/1350";>#1350</a>) 
(<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2108";>#2108</a>) 
<a href="https://github.com/slachiewicz";><code>@​slachiewicz</code></a></li>
   <li><a 
href="https://issues.apache.org/jira/browse/MRESOLVER-379";>[MRESOLVER-379]</a> 
- Preserve relocated candidates from version ranges (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2114";>#2114</a>) 
<a href="https://github.com/jjj-n";><code>@​jjj-n</code></a></li>
   <li>Create the local repository directory before resolving its real path (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2111";>#2111</a>) 
<a href="https://github.com/slachiewicz";><code>@​slachiewicz</code></a></li>
   <li>Optimize TrackingFileManager unit tests and fix potential lock leaks (<a 
href="https://redirect.github.com/apache/maven-resolver/issues/2094";>#2094</a>) 
(<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2102";>#2102</a>) 
<a href="https://github.com/slachiewicz";><code>@​slachiewicz</code></a></li>
   <li>Validate the repository key used in checksum summary file names (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2099";>#2099</a>) 
<a href="https://github.com/slachiewicz";><code>@​slachiewicz</code></a></li>
   <li>fix: bound response reads and sanitize remote-derived strings (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2081";>#2081</a>) 
<a href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   <li>fix: earn trust labels through verification and bind tracking to URL (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2080";>#2080</a>) 
<a href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   <li>fix: bind credentials to origin and reject TLS downgrade redirects (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2085";>#2085</a>) 
<a href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   <li>fix: prevent remote signals from weakening operator-configured policy 
(<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2082";>#2082</a>) 
<a href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   <li>fix: atomic file publication and authenticated IPC lock daemon (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2083";>#2083</a>) 
<a href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   <li>fix: deploy-side integrity must fail closed (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2084";>#2084</a>) 
<a href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   <li>fix: harden opt-in transport and lock backends against unauthenticated 
infrastructure (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2086";>#2086</a>) 
<a href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   <li>Compose named lock keys one segment per coordinate field (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2091";>#2091</a>) 
<a href="https://github.com/slachiewicz";><code>@​slachiewicz</code></a></li>
   <li>Resolve file transport locations with path operations instead of 
substring matching (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2088";>#2088</a>) 
<a href="https://github.com/slachiewicz";><code>@​slachiewicz</code></a></li>
   <li>Validate coordinate components in the Maven 2 layout and local path 
composer (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2087";>#2087</a>) 
<a href="https://github.com/slachiewicz";><code>@​slachiewicz</code></a></li>
   </ul>
   <h2>📝 Documentation updates</h2>
   <ul>
   <li>[docs] Clarify trusted checksum sources (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2127";>#2127</a>) 
<a 
href="https://github.com/jiteshkhatri11";><code>@​jiteshkhatri11</code></a></li>
   <li>Fix <a 
href="https://redirect.github.com/apache/maven-resolver/issues/2058";>#2058</a>: 
Add links to configuration page (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2060";>#2060</a>) 
<a href="https://github.com/Jamison929611";><code>@​Jamison929611</code></a></li>
   </ul>
   <h2>👻 Maintenance</h2>
   <ul>
   <li>test: move from minio docker image (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2140";>#2140</a>) 
<a href="https://github.com/cstamas";><code>@​cstamas</code></a></li>
   <li>Fix listener error swallowing (<a 
href="https://redirect.github.com/apache/maven-resolver/issues/1990";>#1990</a>),
 SyncContext double-close (<a 
href="https://redirect.github.com/apache/maven-resolver/issues/1992";>#1992</a>),
 and test flakiness (<a 
href="https://redirect.github.com/apache/maven-resolver/issues/1350";>#1350</a>) 
(<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2108";>#2108</a>) 
<a href="https://github.com/slachiewicz";><code>@​slachiewicz</code></a></li>
   <li>Fix: tidy up f013 (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2104";>#2104</a>) 
<a href="https://github.com/cstamas";><code>@​cstamas</code></a></li>
   <li>Fix <a 
href="https://redirect.github.com/apache/maven-resolver/issues/2096";>#2096</a>: 
harden NamedLocksTrackingFileManagerTest against CI load (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2098";>#2098</a>) 
<a href="https://github.com/gnodet";><code>@​gnodet</code></a></li>
   <li>Carry repository provenance into aggregateRepositories (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2090";>#2090</a>) 
<a href="https://github.com/slachiewicz";><code>@​slachiewicz</code></a></li>
   <li>Validate the repository key used as a local repository path segment (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2089";>#2089</a>) 
<a href="https://github.com/slachiewicz";><code>@​slachiewicz</code></a></li>
   </ul>
   <h2>📦 Dependency updates</h2>
   <ul>
   <li>Bump org.apache.maven.plugin-tools:maven-plugin-tools-api from 3.15.2 to 
3.16.0 (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2136";>#2136</a>) 
@<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
   <li>Bump version.slf4j from 2.0.18 to 2.0.19 (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2130";>#2130</a>) 
@<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
   <li>Bump org.eclipse.jetty:jetty-bom from 12.1.12 to 12.1.13 (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2131";>#2131</a>) 
@<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
   <li>Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.26.1 to 
0.26.2 (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2129";>#2129</a>) 
@<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
   <li>Deps: bump to BC provider 1.85.2 (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2097";>#2097</a>) 
<a href="https://github.com/cstamas";><code>@​cstamas</code></a></li>
   <li>Bump org.codehaus.plexus:plexus-utils from 3.6.1 to 3.6.2 (<a 
href="https://redirect.github.com/apache/maven-resolver/pull/2074";>#2074</a>) 
@<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/apache/maven-resolver/commit/3cc91ea267616918bc6e2a17417edf053f8e92dc";><code>3cc91ea</code></a>
 [maven-release-plugin] prepare release maven-resolver-2.0.23</li>
   <li><a 
href="https://github.com/apache/maven-resolver/commit/b703cdbb98d57b1a98c39c7721b7c934937b9a69";><code>b703cdb</code></a>
 Finish the repo key story (<a 
href="https://redirect.github.com/apache/maven-resolver/issues/2135";>#2135</a>)</li>
   <li><a 
href="https://github.com/apache/maven-resolver/commit/a719e8d0113312563b3647877f0dbc5947e4fed6";><code>a719e8d</code></a>
 test: move from minio docker image (<a 
href="https://redirect.github.com/apache/maven-resolver/issues/2140";>#2140</a>)</li>
   <li><a 
href="https://github.com/apache/maven-resolver/commit/d1d8d940a94c20b04306e6e6214d316e42501948";><code>d1d8d94</code></a>
 Bump org.apache.maven.plugin-tools:maven-plugin-tools-api (<a 
href="https://redirect.github.com/apache/maven-resolver/issues/2136";>#2136</a>)</li>
   <li><a 
href="https://github.com/apache/maven-resolver/commit/18753daa30739a699ea56e30865e8de7f4e58369";><code>18753da</code></a>
 fix: accept legacy ID-only tracking entries via backward-compatible fallback 
...</li>
   <li><a 
href="https://github.com/apache/maven-resolver/commit/0a74153d40a5982adf2d6a7ee45ac0a6fccff7a3";><code>0a74153</code></a>
 Fix listener error swallowing (<a 
href="https://redirect.github.com/apache/maven-resolver/issues/1990";>#1990</a>),
 SyncContext double-close (<a 
href="https://redirect.github.com/apache/maven-resolver/issues/1992";>#1992</a>),
 and ...</li>
   <li><a 
href="https://github.com/apache/maven-resolver/commit/bd7421fc65fffff6ad3054cae7634441f622df1a";><code>bd7421f</code></a>
 [docs] Clarify trusted checksum sources (<a 
href="https://redirect.github.com/apache/maven-resolver/issues/2127";>#2127</a>)</li>
   <li><a 
href="https://github.com/apache/maven-resolver/commit/534e16e8fb161a82f36a3a863b526340389c68cb";><code>534e16e</code></a>
 [MRESOLVER-379] Preserve relocated range candidates (<a 
href="https://redirect.github.com/apache/maven-resolver/issues/2114";>#2114</a>)</li>
   <li><a 
href="https://github.com/apache/maven-resolver/commit/f786540666bc450132bf08dc7832f5d9d768669b";><code>f786540</code></a>
 Bump version.slf4j from 2.0.18 to 2.0.19 (<a 
href="https://redirect.github.com/apache/maven-resolver/issues/2130";>#2130</a>)</li>
   <li><a 
href="https://github.com/apache/maven-resolver/commit/dec4ec3e908c68fa2ee3b6e41d2c2afcaf998f3d";><code>dec4ec3</code></a>
 Bump org.eclipse.jetty:jetty-bom from 12.1.12 to 12.1.13 (<a 
href="https://redirect.github.com/apache/maven-resolver/issues/2131";>#2131</a>)</li>
   <li>Additional commits viewable in <a 
href="https://github.com/apache/maven-resolver/compare/maven-resolver-1.9.27...maven-resolver-2.0.23";>compare
 view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=org.apache.maven.resolver:maven-resolver-api&package-manager=maven&previous-version=1.9.27&new-version=2.0.23)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to