matrei opened a new pull request, #16526: URL: https://github.com/apache/grails-core/pull/16526
Adds an `org.webjars*` ignore to the three `/grails-forge` Dependabot entries for 7.0.x, 7.1.x and 7.2.x. The pattern also covers the `org.webjars.npm` and `org.webjars.bower` groups. The webjars pinned by the test example apps and the spring-security-ui plugin are referenced by versioned asset paths (e.g. `webjars/bootstrap/3.3.6/...`). Dependabot only changes the build file, so its bumps leave those paths pointing at a version that is no longer on the classpath. The recent PRs also showed two other problems: - #16439, #16440, #16445 applied Bootstrap 3.3.7-1 to every example that declares `org.webjars:bootstrap`, which downgraded the `ldap` examples from 4.1.3. - #16438, #16441, #16444 bumped `jquery-ui-themes` to 1.10.4-1, a version that was never published, so every build failed. Webjar updates in these apps need the asset paths changed in the same commit, so they are better done by hand. See the discussion in https://github.com/apache/grails-core/pull/16519#issuecomment-5999067824. Dependabot reads its configuration from the default branch, so this takes effect once it is merged up to 8.0.x. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
