veithen commented on PR #772: URL: https://github.com/apache/axis-axis2-java-core/pull/772#issuecomment-2439759668
> @veithen I noticed Jetty has a later version than 12.0.9 - 12.0.14 - because I am trying to close AXIS2-6067 and manually ran dependency-check-maven from owasp. Any reason we are on 12.0.9 here? I noticed .github/dependabot.yml may need to be updated now that we are on jakarta. I've managed to fix it. It was caused by the `jetty.version` property being used in (unused) dependency management entries for artifacts that don't exist in version 12.x. It appears that in that situation, the regular Dependabot decides that a version update isn't possible. The update to 12.0.9 was triggered by a Dependabot alert though; it appears that in that case, Dependabot is a bit more forceful. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: java-dev-unsubscr...@axis.apache.org For queries about this service, please contact Infrastructure at: us...@infra.apache.org --------------------------------------------------------------------- To unsubscribe, e-mail: java-dev-unsubscr...@axis.apache.org For additional commands, e-mail: java-dev-h...@axis.apache.org