dependabot[bot] opened a new pull request, #99: URL: https://github.com/apache/tooling-atr-maven-plugin/pull/99
Bumps [org.apache.maven.resolver:maven-resolver-api](https://github.com/apache/maven-resolver) from 1.9.27 to 2.0.23. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/apache/maven-resolver/releases">org.apache.maven.resolver:maven-resolver-api's releases</a>.</em></p> <blockquote> <h2>2.0.23</h2> <!-- raw HTML omitted --> <h2>🚀 New features and improvements</h2> <ul> <li>Finish the repo key story (<a href="https://redirect.github.com/apache/maven-resolver/pull/2135">#2135</a>) <a href="https://github.com/cstamas"><code>@cstamas</code></a></li> <li>Fix: log only once the warning in DefRemoteRepoMan (<a href="https://redirect.github.com/apache/maven-resolver/pull/2100">#2100</a>) <a href="https://github.com/cstamas"><code>@cstamas</code></a></li> <li>Fix <a href="https://redirect.github.com/apache/maven-resolver/issues/2058">#2058</a>: Add links to configuration page (<a href="https://redirect.github.com/apache/maven-resolver/pull/2060">#2060</a>) <a href="https://github.com/Jamison929611"><code>@Jamison929611</code></a></li> <li>Eliminate per-node HashSet allocation in PathConflictResolver (<a href="https://redirect.github.com/apache/maven-resolver/pull/2075">#2075</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> </ul> <h2>🐛 Bug Fixes</h2> <ul> <li>fix: accept locally cached artifacts via same-id fallback when tracking URL changes (<a href="https://redirect.github.com/apache/maven-resolver/pull/2133">#2133</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> <li>Fix listener error swallowing (<a href="https://redirect.github.com/apache/maven-resolver/issues/1990">#1990</a>), SyncContext double-close (<a href="https://redirect.github.com/apache/maven-resolver/issues/1992">#1992</a>), and test flakiness (<a href="https://redirect.github.com/apache/maven-resolver/issues/1350">#1350</a>) (<a href="https://redirect.github.com/apache/maven-resolver/pull/2108">#2108</a>) <a href="https://github.com/slachiewicz"><code>@slachiewicz</code></a></li> <li><a href="https://issues.apache.org/jira/browse/MRESOLVER-379">[MRESOLVER-379]</a> - Preserve relocated candidates from version ranges (<a href="https://redirect.github.com/apache/maven-resolver/pull/2114">#2114</a>) <a href="https://github.com/jjj-n"><code>@jjj-n</code></a></li> <li>Create the local repository directory before resolving its real path (<a href="https://redirect.github.com/apache/maven-resolver/pull/2111">#2111</a>) <a href="https://github.com/slachiewicz"><code>@slachiewicz</code></a></li> <li>Optimize TrackingFileManager unit tests and fix potential lock leaks (<a href="https://redirect.github.com/apache/maven-resolver/issues/2094">#2094</a>) (<a href="https://redirect.github.com/apache/maven-resolver/pull/2102">#2102</a>) <a href="https://github.com/slachiewicz"><code>@slachiewicz</code></a></li> <li>Validate the repository key used in checksum summary file names (<a href="https://redirect.github.com/apache/maven-resolver/pull/2099">#2099</a>) <a href="https://github.com/slachiewicz"><code>@slachiewicz</code></a></li> <li>fix: bound response reads and sanitize remote-derived strings (<a href="https://redirect.github.com/apache/maven-resolver/pull/2081">#2081</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> <li>fix: earn trust labels through verification and bind tracking to URL (<a href="https://redirect.github.com/apache/maven-resolver/pull/2080">#2080</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> <li>fix: bind credentials to origin and reject TLS downgrade redirects (<a href="https://redirect.github.com/apache/maven-resolver/pull/2085">#2085</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> <li>fix: prevent remote signals from weakening operator-configured policy (<a href="https://redirect.github.com/apache/maven-resolver/pull/2082">#2082</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> <li>fix: atomic file publication and authenticated IPC lock daemon (<a href="https://redirect.github.com/apache/maven-resolver/pull/2083">#2083</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> <li>fix: deploy-side integrity must fail closed (<a href="https://redirect.github.com/apache/maven-resolver/pull/2084">#2084</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> <li>fix: harden opt-in transport and lock backends against unauthenticated infrastructure (<a href="https://redirect.github.com/apache/maven-resolver/pull/2086">#2086</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> <li>Compose named lock keys one segment per coordinate field (<a href="https://redirect.github.com/apache/maven-resolver/pull/2091">#2091</a>) <a href="https://github.com/slachiewicz"><code>@slachiewicz</code></a></li> <li>Resolve file transport locations with path operations instead of substring matching (<a href="https://redirect.github.com/apache/maven-resolver/pull/2088">#2088</a>) <a href="https://github.com/slachiewicz"><code>@slachiewicz</code></a></li> <li>Validate coordinate components in the Maven 2 layout and local path composer (<a href="https://redirect.github.com/apache/maven-resolver/pull/2087">#2087</a>) <a href="https://github.com/slachiewicz"><code>@slachiewicz</code></a></li> </ul> <h2>📝 Documentation updates</h2> <ul> <li>[docs] Clarify trusted checksum sources (<a href="https://redirect.github.com/apache/maven-resolver/pull/2127">#2127</a>) <a href="https://github.com/jiteshkhatri11"><code>@jiteshkhatri11</code></a></li> <li>Fix <a href="https://redirect.github.com/apache/maven-resolver/issues/2058">#2058</a>: Add links to configuration page (<a href="https://redirect.github.com/apache/maven-resolver/pull/2060">#2060</a>) <a href="https://github.com/Jamison929611"><code>@Jamison929611</code></a></li> </ul> <h2>👻 Maintenance</h2> <ul> <li>test: move from minio docker image (<a href="https://redirect.github.com/apache/maven-resolver/pull/2140">#2140</a>) <a href="https://github.com/cstamas"><code>@cstamas</code></a></li> <li>Fix listener error swallowing (<a href="https://redirect.github.com/apache/maven-resolver/issues/1990">#1990</a>), SyncContext double-close (<a href="https://redirect.github.com/apache/maven-resolver/issues/1992">#1992</a>), and test flakiness (<a href="https://redirect.github.com/apache/maven-resolver/issues/1350">#1350</a>) (<a href="https://redirect.github.com/apache/maven-resolver/pull/2108">#2108</a>) <a href="https://github.com/slachiewicz"><code>@slachiewicz</code></a></li> <li>Fix: tidy up f013 (<a href="https://redirect.github.com/apache/maven-resolver/pull/2104">#2104</a>) <a href="https://github.com/cstamas"><code>@cstamas</code></a></li> <li>Fix <a href="https://redirect.github.com/apache/maven-resolver/issues/2096">#2096</a>: harden NamedLocksTrackingFileManagerTest against CI load (<a href="https://redirect.github.com/apache/maven-resolver/pull/2098">#2098</a>) <a href="https://github.com/gnodet"><code>@gnodet</code></a></li> <li>Carry repository provenance into aggregateRepositories (<a href="https://redirect.github.com/apache/maven-resolver/pull/2090">#2090</a>) <a href="https://github.com/slachiewicz"><code>@slachiewicz</code></a></li> <li>Validate the repository key used as a local repository path segment (<a href="https://redirect.github.com/apache/maven-resolver/pull/2089">#2089</a>) <a href="https://github.com/slachiewicz"><code>@slachiewicz</code></a></li> </ul> <h2>📦 Dependency updates</h2> <ul> <li>Bump org.apache.maven.plugin-tools:maven-plugin-tools-api from 3.15.2 to 3.16.0 (<a href="https://redirect.github.com/apache/maven-resolver/pull/2136">#2136</a>) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li> <li>Bump version.slf4j from 2.0.18 to 2.0.19 (<a href="https://redirect.github.com/apache/maven-resolver/pull/2130">#2130</a>) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li> <li>Bump org.eclipse.jetty:jetty-bom from 12.1.12 to 12.1.13 (<a href="https://redirect.github.com/apache/maven-resolver/pull/2131">#2131</a>) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li> <li>Bump com.github.siom79.japicmp:japicmp-maven-plugin from 0.26.1 to 0.26.2 (<a href="https://redirect.github.com/apache/maven-resolver/pull/2129">#2129</a>) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li> <li>Deps: bump to BC provider 1.85.2 (<a href="https://redirect.github.com/apache/maven-resolver/pull/2097">#2097</a>) <a href="https://github.com/cstamas"><code>@cstamas</code></a></li> <li>Bump org.codehaus.plexus:plexus-utils from 3.6.1 to 3.6.2 (<a href="https://redirect.github.com/apache/maven-resolver/pull/2074">#2074</a>) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/apache/maven-resolver/commit/3cc91ea267616918bc6e2a17417edf053f8e92dc"><code>3cc91ea</code></a> [maven-release-plugin] prepare release maven-resolver-2.0.23</li> <li><a href="https://github.com/apache/maven-resolver/commit/b703cdbb98d57b1a98c39c7721b7c934937b9a69"><code>b703cdb</code></a> Finish the repo key story (<a href="https://redirect.github.com/apache/maven-resolver/issues/2135">#2135</a>)</li> <li><a href="https://github.com/apache/maven-resolver/commit/a719e8d0113312563b3647877f0dbc5947e4fed6"><code>a719e8d</code></a> test: move from minio docker image (<a href="https://redirect.github.com/apache/maven-resolver/issues/2140">#2140</a>)</li> <li><a href="https://github.com/apache/maven-resolver/commit/d1d8d940a94c20b04306e6e6214d316e42501948"><code>d1d8d94</code></a> Bump org.apache.maven.plugin-tools:maven-plugin-tools-api (<a href="https://redirect.github.com/apache/maven-resolver/issues/2136">#2136</a>)</li> <li><a href="https://github.com/apache/maven-resolver/commit/18753daa30739a699ea56e30865e8de7f4e58369"><code>18753da</code></a> fix: accept legacy ID-only tracking entries via backward-compatible fallback ...</li> <li><a href="https://github.com/apache/maven-resolver/commit/0a74153d40a5982adf2d6a7ee45ac0a6fccff7a3"><code>0a74153</code></a> Fix listener error swallowing (<a href="https://redirect.github.com/apache/maven-resolver/issues/1990">#1990</a>), SyncContext double-close (<a href="https://redirect.github.com/apache/maven-resolver/issues/1992">#1992</a>), and ...</li> <li><a href="https://github.com/apache/maven-resolver/commit/bd7421fc65fffff6ad3054cae7634441f622df1a"><code>bd7421f</code></a> [docs] Clarify trusted checksum sources (<a href="https://redirect.github.com/apache/maven-resolver/issues/2127">#2127</a>)</li> <li><a href="https://github.com/apache/maven-resolver/commit/534e16e8fb161a82f36a3a863b526340389c68cb"><code>534e16e</code></a> [MRESOLVER-379] Preserve relocated range candidates (<a href="https://redirect.github.com/apache/maven-resolver/issues/2114">#2114</a>)</li> <li><a href="https://github.com/apache/maven-resolver/commit/f786540666bc450132bf08dc7832f5d9d768669b"><code>f786540</code></a> Bump version.slf4j from 2.0.18 to 2.0.19 (<a href="https://redirect.github.com/apache/maven-resolver/issues/2130">#2130</a>)</li> <li><a href="https://github.com/apache/maven-resolver/commit/dec4ec3e908c68fa2ee3b6e41d2c2afcaf998f3d"><code>dec4ec3</code></a> Bump org.eclipse.jetty:jetty-bom from 12.1.12 to 12.1.13 (<a href="https://redirect.github.com/apache/maven-resolver/issues/2131">#2131</a>)</li> <li>Additional commits viewable in <a href="https://github.com/apache/maven-resolver/compare/maven-resolver-1.9.27...maven-resolver-2.0.23">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
