[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #984: Bump hsqldb from 2.5.2 to 2.7.0

2022-10-22 Thread GitBox
dependabot[bot] commented on PR #984: URL: https://github.com/apache/logging-log4j2/pull/984#issuecomment-1287682550 Looks like this PR is already up-to-date with release-2.x! If you'd still like to recreate it from scratch, overwriting any edits, you can request `@dependabot recreate`.

[GitHub] [logging-log4j2] ppkarwasz commented on pull request #984: Bump hsqldb from 2.5.2 to 2.7.0

2022-10-22 Thread GitBox
ppkarwasz commented on PR #984: URL: https://github.com/apache/logging-log4j2/pull/984#issuecomment-1287682491 @dependabot rebase -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific

[GitHub] [logging-log4j2] ppkarwasz commented on pull request #1119: Bump kubernetes-client-bom from 5.12.2 to 6.2.0

2022-10-22 Thread GitBox
ppkarwasz commented on PR #1119: URL: https://github.com/apache/logging-log4j2/pull/1119#issuecomment-1287681395 Something in the API changed. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [logging-log4j2] ppkarwasz commented on pull request #927: Bump maven-core from 3.8.5 to 3.8.6

2022-10-22 Thread GitBox
ppkarwasz commented on PR #927: URL: https://github.com/apache/logging-log4j2/pull/927#issuecomment-1287679961 @dependabot rebase -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific

[GitHub] [logging-log4j2] ppkarwasz commented on pull request #1092: Bump actions/checkout from 3.0.2 to 3.1.0

2022-10-22 Thread GitBox
ppkarwasz commented on PR #1092: URL: https://github.com/apache/logging-log4j2/pull/1092#issuecomment-1287672135 @dependabot rebase -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1095: Bump mockito.version from 4.4.0 to 4.8.0

2022-10-22 Thread GitBox
dependabot[bot] commented on PR #1095: URL: https://github.com/apache/logging-log4j2/pull/1095#issuecomment-1287661520 Superseded by #1123. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [logging-log4j2] dependabot[bot] closed pull request #1095: Bump mockito.version from 4.4.0 to 4.8.0

2022-10-22 Thread GitBox
dependabot[bot] closed pull request #1095: Bump mockito.version from 4.4.0 to 4.8.0 URL: https://github.com/apache/logging-log4j2/pull/1095 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [logging-log4j2] dependabot[bot] opened a new pull request, #1123: Bump mockito.version from 4.4.0 to 4.8.1

2022-10-22 Thread GitBox
dependabot[bot] opened a new pull request, #1123: URL: https://github.com/apache/logging-log4j2/pull/1123 Bumps `mockito.version` from 4.4.0 to 4.8.1. Updates `mockito-core` from 4.4.0 to 4.8.1 Release notes Sourced from

[GitHub] [logging-log4j2] ppkarwasz commented on pull request #1095: Bump mockito.version from 4.4.0 to 4.8.0

2022-10-22 Thread GitBox
ppkarwasz commented on PR #1095: URL: https://github.com/apache/logging-log4j2/pull/1095#issuecomment-1287661053 @dependabot rebase -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1070: Bump cassandra-driver-core from 3.11.2 to 3.11.3

2022-10-21 Thread GitBox
dependabot[bot] commented on PR #1070: URL: https://github.com/apache/logging-log4j2/pull/1070#issuecomment-1287540392 OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor

[GitHub] [logging-log4j2] ppkarwasz closed pull request #1070: Bump cassandra-driver-core from 3.11.2 to 3.11.3

2022-10-21 Thread GitBox
ppkarwasz closed pull request #1070: Bump cassandra-driver-core from 3.11.2 to 3.11.3 URL: https://github.com/apache/logging-log4j2/pull/1070 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1121: Bump icu4j from 71.1 to 72.1

2022-10-21 Thread GitBox
dependabot[bot] commented on PR #1121: URL: https://github.com/apache/logging-log4j2/pull/1121#issuecomment-1287540222 OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor

[GitHub] [logging-log4j2] ppkarwasz closed pull request #1121: Bump icu4j from 71.1 to 72.1

2022-10-21 Thread GitBox
ppkarwasz closed pull request #1121: Bump icu4j from 71.1 to 72.1 URL: https://github.com/apache/logging-log4j2/pull/1121 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1114: Bump jackson-bom from 2.13.4 to 2.13.4.20221013

2022-10-21 Thread GitBox
dependabot[bot] commented on PR #1114: URL: https://github.com/apache/logging-log4j2/pull/1114#issuecomment-1287540002 OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor

[GitHub] [logging-log4j2] ppkarwasz closed pull request #1114: Bump jackson-bom from 2.13.4 to 2.13.4.20221013

2022-10-21 Thread GitBox
ppkarwasz closed pull request #1114: Bump jackson-bom from 2.13.4 to 2.13.4.20221013 URL: https://github.com/apache/logging-log4j2/pull/1114 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1106: Bump spotbugs-maven-plugin from 4.7.0.0 to 4.7.2.1

2022-10-21 Thread GitBox
dependabot[bot] commented on PR #1106: URL: https://github.com/apache/logging-log4j2/pull/1106#issuecomment-1287539748 OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor

[GitHub] [logging-log4j2] ppkarwasz closed pull request #1106: Bump spotbugs-maven-plugin from 4.7.0.0 to 4.7.2.1

2022-10-21 Thread GitBox
ppkarwasz closed pull request #1106: Bump spotbugs-maven-plugin from 4.7.0.0 to 4.7.2.1 URL: https://github.com/apache/logging-log4j2/pull/1106 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [logging-log4j2] ppkarwasz closed pull request #1110: Bump netty-bom from 4.1.80.Final to 4.1.84.Final

2022-10-21 Thread GitBox
ppkarwasz closed pull request #1110: Bump netty-bom from 4.1.80.Final to 4.1.84.Final URL: https://github.com/apache/logging-log4j2/pull/1110 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1110: Bump netty-bom from 4.1.80.Final to 4.1.84.Final

2022-10-21 Thread GitBox
dependabot[bot] commented on PR #1110: URL: https://github.com/apache/logging-log4j2/pull/1110#issuecomment-1287539895 OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1103: Bump groovy-bom from 3.0.10 to 3.0.13

2022-10-21 Thread GitBox
dependabot[bot] commented on PR #1103: URL: https://github.com/apache/logging-log4j2/pull/1103#issuecomment-1287539597 OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor

[GitHub] [logging-log4j2] ppkarwasz closed pull request #1103: Bump groovy-bom from 3.0.10 to 3.0.13

2022-10-21 Thread GitBox
ppkarwasz closed pull request #1103: Bump groovy-bom from 3.0.10 to 3.0.13 URL: https://github.com/apache/logging-log4j2/pull/1103 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1115: Bump de.flapdoodle.embed.mongo from 3.5.0 to 3.5.1

2022-10-21 Thread GitBox
dependabot[bot] commented on PR #1115: URL: https://github.com/apache/logging-log4j2/pull/1115#issuecomment-1287539381 Looks like de.flapdoodle.embed:de.flapdoodle.embed.mongo is up-to-date now, so this is no longer needed. -- This is an automated message from the Apache Git Service. To

[GitHub] [logging-log4j2] ppkarwasz closed pull request #1122: Bump spring-boot.version from 2.6.7 to 2.7.5

2022-10-21 Thread GitBox
ppkarwasz closed pull request #1122: Bump spring-boot.version from 2.6.7 to 2.7.5 URL: https://github.com/apache/logging-log4j2/pull/1122 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [logging-log4j2] dependabot[bot] closed pull request #1098: Bump spring-framework-bom from 5.3.20 to 5.3.23

2022-10-21 Thread GitBox
dependabot[bot] closed pull request #1098: Bump spring-framework-bom from 5.3.20 to 5.3.23 URL: https://github.com/apache/logging-log4j2/pull/1098 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1098: Bump spring-framework-bom from 5.3.20 to 5.3.23

2022-10-21 Thread GitBox
dependabot[bot] commented on PR #1098: URL: https://github.com/apache/logging-log4j2/pull/1098#issuecomment-1287539322 Looks like org.springframework:spring-framework-bom is up-to-date now, so this is no longer needed. -- This is an automated message from the Apache Git Service. To

[GitHub] [logging-log4j2] dependabot[bot] closed pull request #1115: Bump de.flapdoodle.embed.mongo from 3.5.0 to 3.5.1

2022-10-21 Thread GitBox
dependabot[bot] closed pull request #1115: Bump de.flapdoodle.embed.mongo from 3.5.0 to 3.5.1 URL: https://github.com/apache/logging-log4j2/pull/1115 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to

[GitHub] [logging-log4j2] ppkarwasz closed pull request #1090: Bump surefire-junit47 from 3.0.0-M6 to 3.0.0-M7

2022-10-21 Thread GitBox
ppkarwasz closed pull request #1090: Bump surefire-junit47 from 3.0.0-M6 to 3.0.0-M7 URL: https://github.com/apache/logging-log4j2/pull/1090 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1094: Bump json-unit from 2.35.0 to 2.36.0

2022-10-21 Thread GitBox
dependabot[bot] commented on PR #1094: URL: https://github.com/apache/logging-log4j2/pull/1094#issuecomment-1287539228 OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1122: Bump spring-boot.version from 2.6.7 to 2.7.5

2022-10-21 Thread GitBox
dependabot[bot] commented on PR #1122: URL: https://github.com/apache/logging-log4j2/pull/1122#issuecomment-1287539343 OK, I won't notify you again about this release, but will get in touch when a new version is available. You can also ignore all major, minor, or patch releases for a

[GitHub] [logging-log4j2] ppkarwasz closed pull request #1094: Bump json-unit from 2.35.0 to 2.36.0

2022-10-21 Thread GitBox
ppkarwasz closed pull request #1094: Bump json-unit from 2.35.0 to 2.36.0 URL: https://github.com/apache/logging-log4j2/pull/1094 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1090: Bump surefire-junit47 from 3.0.0-M6 to 3.0.0-M7

2022-10-21 Thread GitBox
dependabot[bot] commented on PR #1090: URL: https://github.com/apache/logging-log4j2/pull/1090#issuecomment-1287539132 OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1071: Bump junit-bom from 5.9.0 to 5.9.1

2022-10-21 Thread GitBox
dependabot[bot] commented on PR #1071: URL: https://github.com/apache/logging-log4j2/pull/1071#issuecomment-1287539041 OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor

[GitHub] [logging-log4j2] ppkarwasz closed pull request #1071: Bump junit-bom from 5.9.0 to 5.9.1

2022-10-21 Thread GitBox
ppkarwasz closed pull request #1071: Bump junit-bom from 5.9.0 to 5.9.1 URL: https://github.com/apache/logging-log4j2/pull/1071 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment.

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1036: Bump activemq-broker from 5.17.1 to 5.17.2

2022-10-21 Thread GitBox
dependabot[bot] commented on PR #1036: URL: https://github.com/apache/logging-log4j2/pull/1036#issuecomment-1287538928 OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor

[GitHub] [logging-log4j2] ppkarwasz closed pull request #1036: Bump activemq-broker from 5.17.1 to 5.17.2

2022-10-21 Thread GitBox
ppkarwasz closed pull request #1036: Bump activemq-broker from 5.17.1 to 5.17.2 URL: https://github.com/apache/logging-log4j2/pull/1036 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific

[GitHub] [logging-log4j2] ppkarwasz closed pull request #998: Bump embedded-ldap-junit from 0.8.1 to 0.9.0

2022-10-21 Thread GitBox
ppkarwasz closed pull request #998: Bump embedded-ldap-junit from 0.8.1 to 0.9.0 URL: https://github.com/apache/logging-log4j2/pull/998 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #998: Bump embedded-ldap-junit from 0.8.1 to 0.9.0

2022-10-21 Thread GitBox
dependabot[bot] commented on PR #998: URL: https://github.com/apache/logging-log4j2/pull/998#issuecomment-1287538803 OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #949: Bump jna from 5.11.0 to 5.12.1

2022-10-21 Thread GitBox
dependabot[bot] commented on PR #949: URL: https://github.com/apache/logging-log4j2/pull/949#issuecomment-1287538679 OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor

[GitHub] [logging-log4j2] ppkarwasz closed pull request #949: Bump jna from 5.11.0 to 5.12.1

2022-10-21 Thread GitBox
ppkarwasz closed pull request #949: Bump jna from 5.11.0 to 5.12.1 URL: https://github.com/apache/logging-log4j2/pull/949 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To

[GitHub] [logging-log4j2] ppkarwasz closed pull request #1048: Bump jctools-core from 3.3.0 to 4.0.1

2022-10-21 Thread GitBox
ppkarwasz closed pull request #1048: Bump jctools-core from 3.3.0 to 4.0.1 URL: https://github.com/apache/logging-log4j2/pull/1048 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1048: Bump jctools-core from 3.3.0 to 4.0.1

2022-10-21 Thread GitBox
dependabot[bot] commented on PR #1048: URL: https://github.com/apache/logging-log4j2/pull/1048#issuecomment-1287372679 OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor

[GitHub] [logging-log4j2] ppkarwasz commented on pull request #1048: Bump jctools-core from 3.3.0 to 4.0.1

2022-10-21 Thread GitBox
ppkarwasz commented on PR #1048: URL: https://github.com/apache/logging-log4j2/pull/1048#issuecomment-1287372648 Due to JCTools/JCTools/issues/367 we can not use this version. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1096: Bump spring-boot.version from 2.6.7 to 2.7.4

2022-10-21 Thread GitBox
dependabot[bot] commented on PR #1096: URL: https://github.com/apache/logging-log4j2/pull/1096#issuecomment-1286745010 Superseded by #1122. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [logging-log4j2] dependabot[bot] closed pull request #1096: Bump spring-boot.version from 2.6.7 to 2.7.4

2022-10-21 Thread GitBox
dependabot[bot] closed pull request #1096: Bump spring-boot.version from 2.6.7 to 2.7.4 URL: https://github.com/apache/logging-log4j2/pull/1096 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [logging-log4j2] dependabot[bot] opened a new pull request, #1122: Bump spring-boot.version from 2.6.7 to 2.7.5

2022-10-21 Thread GitBox
dependabot[bot] opened a new pull request, #1122: URL: https://github.com/apache/logging-log4j2/pull/1122 Bumps `spring-boot.version` from 2.6.7 to 2.7.5. Updates `spring-boot` from 2.6.7 to 2.7.5 Release notes Sourced from

[GitHub] [logging-log4j2] ppkarwasz commented on pull request #1098: Bump spring-framework-bom from 5.3.20 to 5.3.23

2022-10-20 Thread GitBox
ppkarwasz commented on PR #1098: URL: https://github.com/apache/logging-log4j2/pull/1098#issuecomment-1286086310 @dependabot rebase -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific

[GitHub] [logging-log4j2] ppkarwasz commented on pull request #1089: Bump kafka-clients from 1.1.1 to 3.3.1

2022-10-20 Thread GitBox
ppkarwasz commented on PR #1089: URL: https://github.com/apache/logging-log4j2/pull/1089#issuecomment-1285530739 @dependabot rebase -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1120: Bump org.eclipse.persistence.jpa from 2.7.11 to 4.0.0

2022-10-20 Thread GitBox
dependabot[bot] commented on PR #1120: URL: https://github.com/apache/logging-log4j2/pull/1120#issuecomment-1285529698 OK, I won't notify you about version 4.x.x again, unless you re-open this PR.  -- This is an automated message from the Apache Git Service. To respond to the message,

[GitHub] [logging-log4j2] dependabot[bot] closed pull request #1120: Bump org.eclipse.persistence.jpa from 2.7.11 to 4.0.0

2022-10-20 Thread GitBox
dependabot[bot] closed pull request #1120: Bump org.eclipse.persistence.jpa from 2.7.11 to 4.0.0 URL: https://github.com/apache/logging-log4j2/pull/1120 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go

[GitHub] [logging-log4j2] ppkarwasz commented on pull request #1120: Bump org.eclipse.persistence.jpa from 2.7.11 to 4.0.0

2022-10-20 Thread GitBox
ppkarwasz commented on PR #1120: URL: https://github.com/apache/logging-log4j2/pull/1120#issuecomment-1285529543 4.0 is a Jakarta EE version. @dependabot ignore this major version -- This is an automated message from the Apache Git Service. To respond to the message, please log on

[GitHub] [logging-log4j2] dependabot[bot] opened a new pull request, #1121: Bump icu4j from 71.1 to 72.1

2022-10-20 Thread GitBox
dependabot[bot] opened a new pull request, #1121: URL: https://github.com/apache/logging-log4j2/pull/1121 Bumps [icu4j](https://github.com/unicode-org/icu) from 71.1 to 72.1. Release notes Sourced from https://github.com/unicode-org/icu/releases;>icu4j's releases. ICU 72.1

[GitHub] [logging-log4j2] dependabot[bot] opened a new pull request, #1120: Bump org.eclipse.persistence.jpa from 2.7.11 to 4.0.0

2022-10-20 Thread GitBox
dependabot[bot] opened a new pull request, #1120: URL: https://github.com/apache/logging-log4j2/pull/1120 Bumps [org.eclipse.persistence.jpa](https://github.com/eclipse-ee4j/eclipselink) from 2.7.11 to 4.0.0. Release notes Sourced from

[GitHub] [logging-log4j2] dependabot[bot] closed pull request #1100: Bump kubernetes-client-bom from 5.12.2 to 6.1.1

2022-10-20 Thread GitBox
dependabot[bot] closed pull request #1100: Bump kubernetes-client-bom from 5.12.2 to 6.1.1 URL: https://github.com/apache/logging-log4j2/pull/1100 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1100: Bump kubernetes-client-bom from 5.12.2 to 6.1.1

2022-10-20 Thread GitBox
dependabot[bot] commented on PR #1100: URL: https://github.com/apache/logging-log4j2/pull/1100#issuecomment-1285263806 Superseded by #1119. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [logging-log4j2] dependabot[bot] opened a new pull request, #1119: Bump kubernetes-client-bom from 5.12.2 to 6.2.0

2022-10-20 Thread GitBox
dependabot[bot] opened a new pull request, #1119: URL: https://github.com/apache/logging-log4j2/pull/1119 Bumps [kubernetes-client-bom](https://github.com/fabric8io/kubernetes-client) from 5.12.2 to 6.2.0. Release notes Sourced from

[GitHub] [logging-log4j2] dependabot[bot] closed pull request #1082: Bump ossf/scorecard-action from 1.1.2 to 2.0.4

2022-10-19 Thread GitBox
dependabot[bot] closed pull request #1082: Bump ossf/scorecard-action from 1.1.2 to 2.0.4 URL: https://github.com/apache/logging-log4j2/pull/1082 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1082: Bump ossf/scorecard-action from 1.1.2 to 2.0.4

2022-10-19 Thread GitBox
dependabot[bot] commented on PR #1082: URL: https://github.com/apache/logging-log4j2/pull/1082#issuecomment-1283791758 Superseded by #1118. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [logging-log4j2] dependabot[bot] opened a new pull request, #1118: Bump ossf/scorecard-action from 1.1.2 to 2.0.6

2022-10-19 Thread GitBox
dependabot[bot] opened a new pull request, #1118: URL: https://github.com/apache/logging-log4j2/pull/1118 Bumps [ossf/scorecard-action](https://github.com/ossf/scorecard-action) from 1.1.2 to 2.0.6. Release notes Sourced from

[GitHub] [logging-log4j2] dependabot[bot] closed pull request #1104: Bump github/codeql-action from 2.1.22 to 2.1.27

2022-10-19 Thread GitBox
dependabot[bot] closed pull request #1104: Bump github/codeql-action from 2.1.22 to 2.1.27 URL: https://github.com/apache/logging-log4j2/pull/1104 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1104: Bump github/codeql-action from 2.1.22 to 2.1.27

2022-10-19 Thread GitBox
dependabot[bot] commented on PR #1104: URL: https://github.com/apache/logging-log4j2/pull/1104#issuecomment-1283791645 Superseded by #1117. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [logging-log4j2] dependabot[bot] closed pull request #1081: Bump actions/setup-java from 3.4.1 to 3.5.1

2022-10-19 Thread GitBox
dependabot[bot] closed pull request #1081: Bump actions/setup-java from 3.4.1 to 3.5.1 URL: https://github.com/apache/logging-log4j2/pull/1081 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [logging-log4j2] dependabot[bot] opened a new pull request, #1117: Bump github/codeql-action from 2.1.22 to 2.1.28

2022-10-19 Thread GitBox
dependabot[bot] opened a new pull request, #1117: URL: https://github.com/apache/logging-log4j2/pull/1117 Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2.1.22 to 2.1.28. Changelog Sourced from

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1081: Bump actions/setup-java from 3.4.1 to 3.5.1

2022-10-19 Thread GitBox
dependabot[bot] commented on PR #1081: URL: https://github.com/apache/logging-log4j2/pull/1081#issuecomment-1283791525 Superseded by #1116. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [logging-log4j2] dependabot[bot] opened a new pull request, #1116: Bump actions/setup-java from 3.4.1 to 3.6.0

2022-10-19 Thread GitBox
dependabot[bot] opened a new pull request, #1116: URL: https://github.com/apache/logging-log4j2/pull/1116 Bumps [actions/setup-java](https://github.com/actions/setup-java) from 3.4.1 to 3.6.0. Release notes Sourced from

[GitHub] [logging-log4j2] dependabot[bot] opened a new pull request, #1115: Bump de.flapdoodle.embed.mongo from 3.5.0 to 3.5.1

2022-10-19 Thread GitBox
dependabot[bot] opened a new pull request, #1115: URL: https://github.com/apache/logging-log4j2/pull/1115 Bumps [de.flapdoodle.embed.mongo](https://github.com/flapdoodle-oss/de.flapdoodle.embed.mongo) from 3.5.0 to 3.5.1. Changelog Sourced from

[GitHub] [logging-log4j-audit-sample] dependabot[bot] commented on pull request #5: Bump jackson-databind from 2.8.5 to 2.12.6.1

2022-10-18 Thread GitBox
dependabot[bot] commented on PR #5: URL: https://github.com/apache/logging-log4j-audit-sample/pull/5#issuecomment-1283039523 Superseded by #7. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to

[GitHub] [logging-log4j-audit-sample] dependabot[bot] closed pull request #5: Bump jackson-databind from 2.8.5 to 2.12.6.1

2022-10-18 Thread GitBox
dependabot[bot] closed pull request #5: Bump jackson-databind from 2.8.5 to 2.12.6.1 URL: https://github.com/apache/logging-log4j-audit-sample/pull/5 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to

[GitHub] [logging-log4j-audit-sample] dependabot[bot] opened a new pull request, #7: Bump jackson-databind from 2.8.5 to 2.13.4.1

2022-10-18 Thread GitBox
dependabot[bot] opened a new pull request, #7: URL: https://github.com/apache/logging-log4j-audit-sample/pull/7 Bumps [jackson-databind](https://github.com/FasterXML/jackson) from 2.8.5 to 2.13.4.1. Commits See full diff in https://github.com/FasterXML/jackson/commits;>compare

[GitHub] [logging-log4j-audit] dependabot[bot] closed pull request #25: Bump jackson-databind from 2.8.5 to 2.12.6.1

2022-10-18 Thread GitBox
dependabot[bot] closed pull request #25: Bump jackson-databind from 2.8.5 to 2.12.6.1 URL: https://github.com/apache/logging-log4j-audit/pull/25 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [logging-log4j-audit] dependabot[bot] commented on pull request #25: Bump jackson-databind from 2.8.5 to 2.12.6.1

2022-10-18 Thread GitBox
dependabot[bot] commented on PR #25: URL: https://github.com/apache/logging-log4j-audit/pull/25#issuecomment-1282800538 Superseded by #29. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [logging-log4j-audit] dependabot[bot] opened a new pull request, #29: Bump jackson-databind from 2.8.5 to 2.13.4.1

2022-10-18 Thread GitBox
dependabot[bot] opened a new pull request, #29: URL: https://github.com/apache/logging-log4j-audit/pull/29 Bumps [jackson-databind](https://github.com/FasterXML/jackson) from 2.8.5 to 2.13.4.1. Commits See full diff in https://github.com/FasterXML/jackson/commits;>compare view

[GitHub] [logging-log4j2] adwsingh commented on pull request #742: LOG4J2-3366 Fixes order of property sources

2022-10-18 Thread GitBox
adwsingh commented on PR #742: URL: https://github.com/apache/logging-log4j2/pull/742#issuecomment-1282641486 I have created a bug here, https://issues.apache.org/jira/browse/LOG4J2-3621 -- This is an automated message from the Apache Git Service. To respond to the message, please log on

[GitHub] [logging-log4j2] ppkarwasz commented on pull request #742: LOG4J2-3366 Fixes order of property sources

2022-10-18 Thread GitBox
ppkarwasz commented on PR #742: URL: https://github.com/apache/logging-log4j2/pull/742#issuecomment-1282613883 Hi @adwsingh, Old pre-2.10 properties such as `log4j.configurationFile` are overridden by any property in normalized form (e.g. the `log4j2.configurationFile` Java system

[GitHub] [logging-log4j2] adwsingh commented on pull request #742: LOG4J2-3366 Fixes order of property sources

2022-10-18 Thread GitBox
adwsingh commented on PR #742: URL: https://github.com/apache/logging-log4j2/pull/742#issuecomment-1282382575 This change along with https://github.com/apache/logging-log4j2/pull/975 broke one of our systems on upgrading to 2.19. In our applications we had both

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1109: Bump tomcat-juli from 10.0.23 to 10.1.1

2022-10-18 Thread GitBox
dependabot[bot] commented on PR #1109: URL: https://github.com/apache/logging-log4j2/pull/1109#issuecomment-1282074743 OK, I won't notify you about org.apache.tomcat:tomcat-juli again, unless you re-open this PR.  -- This is an automated message from the Apache Git Service. To respond

[GitHub] [logging-log4j2] dependabot[bot] closed pull request #1109: Bump tomcat-juli from 10.0.23 to 10.1.1

2022-10-18 Thread GitBox
dependabot[bot] closed pull request #1109: Bump tomcat-juli from 10.0.23 to 10.1.1 URL: https://github.com/apache/logging-log4j2/pull/1109 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [logging-log4j2] ppkarwasz commented on pull request #1109: Bump tomcat-juli from 10.0.23 to 10.1.1

2022-10-18 Thread GitBox
ppkarwasz commented on PR #1109: URL: https://github.com/apache/logging-log4j2/pull/1109#issuecomment-1282074673 This PR fails because Tomcat 10.1.0 requires Java 11. Since `tomcat-juli` have not changed in ages, I would keep the present version in both `release-2.x` and `master`.

[GitHub] [logging-log4j2] claire9910 closed pull request #1113: fix(sec): upgrade org.liquibase:liquibase-core to 4.8.0

2022-10-18 Thread GitBox
claire9910 closed pull request #1113: fix(sec): upgrade org.liquibase:liquibase-core to 4.8.0 URL: https://github.com/apache/logging-log4j2/pull/1113 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to

[GitHub] [logging-log4j2] eurrio closed pull request #1111: fix(sec): upgrade org.apache.kafka:kafka-clients to 2.7.2

2022-10-18 Thread GitBox
eurrio closed pull request #: fix(sec): upgrade org.apache.kafka:kafka-clients to 2.7.2 URL: https://github.com/apache/logging-log4j2/pull/ -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to

[GitHub] [logging-log4j2] vy merged pull request #1107: LOG4J2-3584 Make StatusConsoleListener use SimpleLogger internally.

2022-10-17 Thread GitBox
vy merged PR #1107: URL: https://github.com/apache/logging-log4j2/pull/1107 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail:

[GitHub] [logging-log4j2] ppkarwasz commented on pull request #1111: fix(sec): upgrade org.apache.kafka:kafka-clients to 2.7.2

2022-10-17 Thread GitBox
ppkarwasz commented on PR #: URL: https://github.com/apache/logging-log4j2/pull/#issuecomment-1280821401 @eurrio, IMHO and according to [MvnRepository](https://mvnrepository.com/artifact/org.apache.kafka/kafka-clients) that CVE does not apply to any Kafka client (as opposed

[GitHub] [logging-log4cxx] swebb2066 merged pull request #142: Prevent compilation errors when logchar is unichar

2022-10-16 Thread GitBox
swebb2066 merged PR #142: URL: https://github.com/apache/logging-log4cxx/pull/142 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail:

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1079: Bump de.flapdoodle.embed.mongo from 3.4.6 to 3.4.11

2022-10-16 Thread GitBox
dependabot[bot] commented on PR #1079: URL: https://github.com/apache/logging-log4j2/pull/1079#issuecomment-1280097566 OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor

[GitHub] [logging-log4j2] ppkarwasz closed pull request #1079: Bump de.flapdoodle.embed.mongo from 3.4.6 to 3.4.11

2022-10-16 Thread GitBox
ppkarwasz closed pull request #1079: Bump de.flapdoodle.embed.mongo from 3.4.6 to 3.4.11 URL: https://github.com/apache/logging-log4j2/pull/1079 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [logging-log4j2] vy commented on a diff in pull request #1107: LOG4J2-3584 Make StatusConsoleListener use SimpleLogger internally.

2022-10-16 Thread GitBox
vy commented on code in PR #1107: URL: https://github.com/apache/logging-log4j2/pull/1107#discussion_r996491237 ## log4j-api/src/main/java/org/apache/logging/log4j/status/StatusLogger.java: ## @@ -75,14 +75,23 @@ public final class StatusLogger extends AbstractLogger {

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #891: Bump junit-pioneer from 1.6.2 to 1.7.1

2022-10-15 Thread GitBox
dependabot[bot] commented on PR #891: URL: https://github.com/apache/logging-log4j2/pull/891#issuecomment-1279810378 OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor

[GitHub] [logging-log4j2] ppkarwasz commented on pull request #891: Bump junit-pioneer from 1.6.2 to 1.7.1

2022-10-15 Thread GitBox
ppkarwasz commented on PR #891: URL: https://github.com/apache/logging-log4j2/pull/891#issuecomment-1279810366 We can not upgrade until the fix to junit-pioneer/junit-pioneer/issues/623 is published. -- This is an automated message from the Apache Git Service. To respond to the message,

[GitHub] [logging-log4j2] ppkarwasz closed pull request #891: Bump junit-pioneer from 1.6.2 to 1.7.1

2022-10-15 Thread GitBox
ppkarwasz closed pull request #891: Bump junit-pioneer from 1.6.2 to 1.7.1 URL: https://github.com/apache/logging-log4j2/pull/891 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific

[GitHub] [logging-log4j2] ppkarwasz commented on a diff in pull request #1107: LOG4J2-3584 Make StatusConsoleListener use SimpleLogger internally.

2022-10-14 Thread GitBox
ppkarwasz commented on code in PR #1107: URL: https://github.com/apache/logging-log4j2/pull/1107#discussion_r995914364 ## log4j-api/src/main/java/org/apache/logging/log4j/status/StatusLogger.java: ## @@ -75,14 +75,23 @@ public final class StatusLogger extends AbstractLogger {

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1112: Bump jackson-bom from 2.13.4 to 2.13.4.20221012

2022-10-14 Thread GitBox
dependabot[bot] commented on PR #1112: URL: https://github.com/apache/logging-log4j2/pull/1112#issuecomment-1278783974 Superseded by #1114. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [logging-log4j2] dependabot[bot] closed pull request #1112: Bump jackson-bom from 2.13.4 to 2.13.4.20221012

2022-10-14 Thread GitBox
dependabot[bot] closed pull request #1112: Bump jackson-bom from 2.13.4 to 2.13.4.20221012 URL: https://github.com/apache/logging-log4j2/pull/1112 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to

[GitHub] [logging-log4j2] dependabot[bot] opened a new pull request, #1114: Bump jackson-bom from 2.13.4 to 2.13.4.20221013

2022-10-14 Thread GitBox
dependabot[bot] opened a new pull request, #1114: URL: https://github.com/apache/logging-log4j2/pull/1114 Bumps [jackson-bom](https://github.com/FasterXML/jackson-bom) from 2.13.4 to 2.13.4.20221013. Commits

[GitHub] [logging-log4j2] dependabot[bot] opened a new pull request, #1112: Bump jackson-bom from 2.13.4 to 2.13.4.20221012

2022-10-13 Thread GitBox
dependabot[bot] opened a new pull request, #1112: URL: https://github.com/apache/logging-log4j2/pull/1112 Bumps [jackson-bom](https://github.com/FasterXML/jackson-bom) from 2.13.4 to 2.13.4.20221012. Commits

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1099: Bump netty-bom from 4.1.80.Final to 4.1.82.Final

2022-10-12 Thread GitBox
dependabot[bot] commented on PR #1099: URL: https://github.com/apache/logging-log4j2/pull/1099#issuecomment-1275913611 Superseded by #1110. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [logging-log4j2] dependabot[bot] closed pull request #1099: Bump netty-bom from 4.1.80.Final to 4.1.82.Final

2022-10-12 Thread GitBox
dependabot[bot] closed pull request #1099: Bump netty-bom from 4.1.80.Final to 4.1.82.Final URL: https://github.com/apache/logging-log4j2/pull/1099 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to

[GitHub] [logging-log4j2] dependabot[bot] closed pull request #1080: Bump tomcat-juli from 10.0.23 to 10.1.0

2022-10-12 Thread GitBox
dependabot[bot] closed pull request #1080: Bump tomcat-juli from 10.0.23 to 10.1.0 URL: https://github.com/apache/logging-log4j2/pull/1080 -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [logging-log4j2] dependabot[bot] opened a new pull request, #1109: Bump tomcat-juli from 10.0.23 to 10.1.1

2022-10-12 Thread GitBox
dependabot[bot] opened a new pull request, #1109: URL: https://github.com/apache/logging-log4j2/pull/1109 Bumps tomcat-juli from 10.0.23 to 10.1.1. [![Dependabot compatibility

[GitHub] [logging-log4j2] dependabot[bot] commented on pull request #1080: Bump tomcat-juli from 10.0.23 to 10.1.0

2022-10-12 Thread GitBox
dependabot[bot] commented on PR #1080: URL: https://github.com/apache/logging-log4j2/pull/1080#issuecomment-1275913341 Superseded by #1109. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the

[GitHub] [logging-log4j2] dependabot[bot] opened a new pull request, #1110: Bump netty-bom from 4.1.80.Final to 4.1.84.Final

2022-10-12 Thread GitBox
dependabot[bot] opened a new pull request, #1110: URL: https://github.com/apache/logging-log4j2/pull/1110 Bumps [netty-bom](https://github.com/netty/netty) from 4.1.80.Final to 4.1.84.Final. Commits

[GitHub] [logging-log4j2] dependabot[bot] opened a new pull request, #1108: Bump actions/setup-python from 4.2.0 to 4.3.0

2022-10-11 Thread GitBox
dependabot[bot] opened a new pull request, #1108: URL: https://github.com/apache/logging-log4j2/pull/1108 Bumps [actions/setup-python](https://github.com/actions/setup-python) from 4.2.0 to 4.3.0. Release notes Sourced from

<    2   3   4   5   6   7   8   9   10   11   >