veithen commented on PR #772:
URL: 
https://github.com/apache/axis-axis2-java-core/pull/772#issuecomment-2439759668

   > @veithen I noticed Jetty has a later version than 12.0.9 - 12.0.14 - 
because I am trying to close AXIS2-6067 and manually ran dependency-check-maven 
from owasp. Any reason we are on 12.0.9 here? I noticed .github/dependabot.yml 
may need to be updated now that we are on jakarta.
   
   I've managed to fix it. It was caused by the `jetty.version` property being 
used in (unused) dependency management entries for artifacts that don't exist 
in version 12.x. It appears that in that situation, the regular Dependabot 
decides that a version update isn't possible. The update to 12.0.9 was 
triggered by a Dependabot alert though; it appears that in that case, 
Dependabot is a bit more forceful.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: java-dev-unsubscr...@axis.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org


---------------------------------------------------------------------
To unsubscribe, e-mail: java-dev-unsubscr...@axis.apache.org
For additional commands, e-mail: java-dev-h...@axis.apache.org

Reply via email to