Apache DS M27 release on its way

2023-10-09 Thread Emmanuel Lécharny
Hi! I have completed the steps to get Apache Directory Server 2.0.0.AM27 released. The only reason I have not yet started a vote is that I need to get teh Apache LDAP API 2.1.5 release validated, as the ApacheDS installers are now built by the Jenkins tasks, and it 'waits' (aka fails;-) for

Re: [PR] Bump com.alibaba:druid from 1.2.19 to 1.2.20 [directory-kerby]

2023-10-09 Thread via GitHub
coheigea merged PR #262: URL: https://github.com/apache/directory-kerby/pull/262 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail:

Re: [PR] Bump ossf/scorecard-action from 2.2.0 to 2.3.0 [directory-kerby]

2023-10-09 Thread via GitHub
coheigea merged PR #263: URL: https://github.com/apache/directory-kerby/pull/263 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail:

Re: [PR] Bump com.nimbusds:nimbus-jose-jwt from 9.35 to 9.36 [directory-kerby]

2023-10-09 Thread via GitHub
coheigea merged PR #261: URL: https://github.com/apache/directory-kerby/pull/261 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail:

Re: [PR] Bump github/codeql-action from 2.21.9 to 2.22.1 [directory-kerby]

2023-10-09 Thread via GitHub
coheigea merged PR #264: URL: https://github.com/apache/directory-kerby/pull/264 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail:

[PR] Bump ossf/scorecard-action from 2.2.0 to 2.3.0 [directory-server]

2023-10-09 Thread via GitHub
dependabot[bot] opened a new pull request, #117: URL: https://github.com/apache/directory-server/pull/117 Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) from 2.2.0 to 2.3.0. Release notes Sourced from

Re: [VOTE] Apache LDAP API 2.1.5

2023-10-09 Thread Emmanuel Lécharny
ok, Colm, this is clearly a SSHD issue. Nothing to do with mina-core that we use. We are safe. On 09/10/2023 11:11, Colm O hEigeartaigh wrote: +1. On a side note, Grype finds a CVE in Mina when I scan the API dist which looks like a false positive: mina-core 2.2.3

[PR] Bump com.gradle:gradle-enterprise-maven-extension from 1.18.1 to 1.19.2 [directory-scimple]

2023-10-09 Thread via GitHub
dependabot[bot] opened a new pull request, #389: URL: https://github.com/apache/directory-scimple/pull/389 Bumps com.gradle:gradle-enterprise-maven-extension from 1.18.1 to 1.19.2. [![Dependabot compatibility

[PR] Bump org.jboss.weld.se:weld-se-core from 5.1.1.Final to 5.1.2.Final [directory-scimple]

2023-10-09 Thread via GitHub
dependabot[bot] opened a new pull request, #388: URL: https://github.com/apache/directory-scimple/pull/388 Bumps org.jboss.weld.se:weld-se-core from 5.1.1.Final to 5.1.2.Final. [![Dependabot compatibility

[PR] Bump org.mockito:mockito-core from 5.5.0 to 5.6.0 [directory-scimple]

2023-10-09 Thread via GitHub
dependabot[bot] opened a new pull request, #387: URL: https://github.com/apache/directory-scimple/pull/387 Bumps [org.mockito:mockito-core](https://github.com/mockito/mockito) from 5.5.0 to 5.6.0. Release notes Sourced from

Re: [PR] Bump com.gradle:gradle-enterprise-maven-extension from 1.18.1 to 1.19.1 [directory-scimple]

2023-10-09 Thread via GitHub
dependabot[bot] closed pull request #376: Bump com.gradle:gradle-enterprise-maven-extension from 1.18.1 to 1.19.1 URL: https://github.com/apache/directory-scimple/pull/376 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use

Re: [PR] Bump com.gradle:gradle-enterprise-maven-extension from 1.18.1 to 1.19.1 [directory-scimple]

2023-10-09 Thread via GitHub
dependabot[bot] commented on PR #376: URL: https://github.com/apache/directory-scimple/pull/376#issuecomment-1753422196 Superseded by #389. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[PR] Bump version.quarkus from 3.4.1 to 3.4.2 [directory-scimple]

2023-10-09 Thread via GitHub
dependabot[bot] opened a new pull request, #386: URL: https://github.com/apache/directory-scimple/pull/386 Bumps `version.quarkus` from 3.4.1 to 3.4.2. Updates `io.quarkus.platform:quarkus-bom` from 3.4.1 to 3.4.2 Commits

[PR] Bump org.mockito:mockito-junit-jupiter from 5.5.0 to 5.6.0 [directory-scimple]

2023-10-09 Thread via GitHub
dependabot[bot] opened a new pull request, #385: URL: https://github.com/apache/directory-scimple/pull/385 Bumps [org.mockito:mockito-junit-jupiter](https://github.com/mockito/mockito) from 5.5.0 to 5.6.0. Release notes Sourced from

[PR] Bump github/codeql-action from 2.21.9 to 2.22.1 [directory-kerby]

2023-10-09 Thread via GitHub
dependabot[bot] opened a new pull request, #264: URL: https://github.com/apache/directory-kerby/pull/264 Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2.21.9 to 2.22.1. Changelog Sourced from

[PR] Bump ossf/scorecard-action from 2.2.0 to 2.3.0 [directory-kerby]

2023-10-09 Thread via GitHub
dependabot[bot] opened a new pull request, #263: URL: https://github.com/apache/directory-kerby/pull/263 Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) from 2.2.0 to 2.3.0. Release notes Sourced from

[PR] Bump com.nimbusds:nimbus-jose-jwt from 9.35 to 9.36 [directory-kerby]

2023-10-09 Thread via GitHub
dependabot[bot] opened a new pull request, #261: URL: https://github.com/apache/directory-kerby/pull/261 Bumps [com.nimbusds:nimbus-jose-jwt](https://bitbucket.org/connect2id/nimbus-jose-jwt) from 9.35 to 9.36. Changelog Sourced from

[PR] Bump com.alibaba:druid from 1.2.19 to 1.2.20 [directory-kerby]

2023-10-09 Thread via GitHub
dependabot[bot] opened a new pull request, #262: URL: https://github.com/apache/directory-kerby/pull/262 Bumps [com.alibaba:druid](https://github.com/alibaba/druid) from 1.2.19 to 1.2.20. Release notes Sourced from https://github.com/alibaba/druid/releases;>com.alibaba:druid's

Re: [VOTE] Apache LDAP API 2.1.5

2023-10-09 Thread Colm O hEigeartaigh
+1. On a side note, Grype finds a CVE in Mina when I scan the API dist which looks like a false positive: mina-core 2.2.3java-archive CVE-2023-35887 Medium https://nvd.nist.gov/vuln/detail/CVE-2023-35887 This issue affects Apache MINA: from 1.0 before 2.10. Users are

[VOTE] Apache LDAP API 2.1.5

2023-10-09 Thread Emmanuel Lécharny
Hi all, this is a vote for the release of Apache LDAP API 2.1.5 This release is just bumping up some dependencies like MINA 2.2.3, and a few others. It's needed for the coming release of Apache Directory Server. The revision :