[jira] [Created] (TIKA-4240) Change dependabot to weekly

2024-04-11 Thread Tim Allison (Jira)
Tim Allison created TIKA-4240: - Summary: Change dependabot to weekly Key: TIKA-4240 URL: https://issues.apache.org/jira/browse/TIKA-4240 Project: Tika Issue Type: Task Reporter: Tim

[jira] [Resolved] (TIKA-4240) Change dependabot to weekly

2024-04-11 Thread Tim Allison (Jira)
[ https://issues.apache.org/jira/browse/TIKA-4240?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Tim Allison resolved TIKA-4240. --- Resolution: Fixed Let's see how this goes. Thank you! > Change dependabot to weekly >

[jira] [Commented] (TIKA-4240) Change dependabot to weekly

2024-04-11 Thread Tilman Hausherr (Jira)
[ https://issues.apache.org/jira/browse/TIKA-4240?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17836236#comment-17836236 ] Tilman Hausherr commented on TIKA-4240: --- I prefer daily but if more people feel pressured or annoyed

junk cves -- rant

2024-04-11 Thread Tim Allison
I just excluded joda-time because of this: CVE-2024-23080 https://nvd.nist.gov/vuln/detail/CVE-2024-23080 This is an NPE in joda-time version 2.12.5. That's two versions before the current...is it actually still in there. And more importantly, an NPE is not a CVE in Java. People, please. And

[PR] Bump org.springframework:spring-context from 5.3.33 to 5.3.34 [tika]

2024-04-11 Thread via GitHub
dependabot[bot] opened a new pull request, #1722: URL: https://github.com/apache/tika/pull/1722 [![Dependabot compatibility

[jira] [Commented] (TIKA-4240) Change dependabot to weekly

2024-04-11 Thread Tim Allison (Jira)
[ https://issues.apache.org/jira/browse/TIKA-4240?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17836228#comment-17836228 ] Tim Allison commented on TIKA-4240: --- Thank you, [~tilman]! Should I revert to daily? > Change

[jira] [Commented] (TIKA-4240) Change dependabot to weekly

2024-04-11 Thread Tilman Hausherr (Jira)
[ https://issues.apache.org/jira/browse/TIKA-4240?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17836224#comment-17836224 ] Tilman Hausherr commented on TIKA-4240: --- Not a burden (that was Eric, sort-of), I just don't have

Re: [PR] Bump org.springframework:spring-context from 5.3.33 to 5.3.34 [tika]

2024-04-11 Thread via GitHub
THausherr merged PR #1722: URL: https://github.com/apache/tika/pull/1722 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail:

[jira] [Updated] (TIKA-4240) Change dependabot to weekly

2024-04-11 Thread Tilman Hausherr (Jira)
[ https://issues.apache.org/jira/browse/TIKA-4240?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Tilman Hausherr updated TIKA-4240: -- Component/s: build > Change dependabot to weekly > --- > >

[jira] [Commented] (TIKA-4240) Change dependabot to weekly

2024-04-11 Thread Hudson (Jira)
[ https://issues.apache.org/jira/browse/TIKA-4240?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=17836257#comment-17836257 ] Hudson commented on TIKA-4240: -- FAILURE: Integrated in Jenkins build Tika ยป tika-main-jdk11 #1601 (See