Bump org.owasp.esapi:esapi from 2.6.1.0 to 2.6.2.0
Type: Pull Request
State: Open
Association: Contributor
Comments: 0
(about 1 year ago)
(about 1 year ago)
dependencies
Bumps org.owasp.esapi:esapi from 2.6.1.0 to 2.6.2.0.
Release notes
Sourced from org.owasp.esapi:esapi's releases.
esapi-2.6.2.0
Full Release Notes
Release notes for ESAPI release 2.6.2.0 are located at:
What's Changed
- This is a minor patch release with the intent of updating the Apache Commons BeanUtils dependency from v1.9.4 to v1.11.0 to CVE-2025-48734.
Full Changelog: https://github.com/ESAPI/esapi-java-legacy/compare/esapi-2.6.1.0...esapi-2.6.2.0
Other Notes
You may see GHAS Dependabot references to https://github.com/ESAPI/esapi-java-legacy/security/dependabot/17 for this (and previous releases). For a more thorough discussion of this, please see Discussion #877.
Configuration Jar
Note the associated file "esapi-2.6.2.0-configuration.jar" contains the default ESAPI configuration files under 'configuration/' (ESAPI.properties, validation.properties, etc.) and the file "esapi-2.6.2.0-configuration.jar.asc" is a GPG signature of that jar file made by Kevin W. Wall.
Commits
ba358e4Corrected version to 2.6.2.0; was 2.7.0.0-SNAPSHOT.38ce3a0Correct release date.b68e753Correct release date and other minor changes.fba99d8Merge pull request #884 from kwwall/2.6.2.0af4c901Merge pull request #882 from kwwall/develop950a56bUpdates to prep for ESAPI 2.6.2.0 release.5d6e2fdUpdate guessed release date for 2.6.1.0 to its actual release date. (Maven Ce...7067804Bump commons-beanutils:commons-beanutils from 1.9.4 to 1.11.0 (#881)e2183d6Prep 'develop' branch for next (SNAPSHOT) ESAPI release.- See full diff in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Pull Request Statistics
1
1
+1
-1
Package Dependencies
org.owasp.esapi:esapi
maven
2.6.1.0 → 2.6.2.0
Patch
Technical Details
| ID: | 1278806 |
| UUID: | 2563578785 |
| Node ID: | PR_kwDOAgAqvM6YzRuh |
| Host: | GitHub |
| Repository: | OWASP-Benchmark/BenchmarkJava |
| Merge State: | Unknown |