Bump org.owasp:dependency-check-maven from 12.1.1 to 12.1.2
Open
Number: #317
Type: Pull Request
State: Open
Type: Pull Request
State: Open
Author:
dependabot[bot]
Association: Contributor
Comments: 0
Association: Contributor
Comments: 0
Created:
June 09, 2025 at 04:47 AM UTC
(about 1 year ago)
(about 1 year ago)
Updated:
June 09, 2025 at 04:47 AM UTC
(about 1 year ago)
(about 1 year ago)
Labels:
dependencies java
dependencies java
Description:
Bumps org.owasp:dependency-check-maven from 12.1.1 to 12.1.2.
Release notes
Sourced from org.owasp:dependency-check-maven's releases.
Version 12.1.2
Refer to the CHANGELOG.md for information about improvements and upgrade notes.
Changelog
Sourced from org.owasp:dependency-check-maven's changelog.
Version 12.1.2 (2025-06-07)
- fix: Allow configuring OSS Index user/pw directly (#7640)
- fix: remove vulnerable transitive dependency - beanutils (#7705)
- fix: Simplify PHP framework suppression for Composer (#7693)
- fix: update CPE pattern to remove FP (#7684)
- fix(cli): Patch generated Windows shell script for JAVACMD installs with spaces (#7653)
- fix: Resolve various WCAG accessibility / css issues in the HTML report (#7629)
- fix: #7510 Display a dedicated message when receiving an HTTP 403 (#7575)
- docs: Make
Vulnerability SourcesinRelated Workclearer (#7691)- docs: #7610 add a reference to NVD mirroring in getting started documentation (#7611)
See the full listing of changes
Commits
4744206build: prepare release v12.1.2624c3cadocs: release 12.1.2ce126c7build(deps-dev): bump io.netty:netty-codec-http from 4.2.1.Final to 4.2.2.Fin...9c1312aMerge branch 'main' into dependabot/maven/io.netty-netty-codec-http-4.2.2.Finala6abd65build(deps): bump golang from 1.24.3-alpine to 1.24.4-alpine (#7710)4cde0d7build(deps-dev): bump io.netty:netty-codec-http116fdabbuild(deps): bump golang from 1.24.3-alpine to 1.24.4-alpinef551343fix(fp): remove iicu4j FP (#7707)6296163fix(fp): remove iicu4j FP0e0cd58fix: remove vulnerable transitive dependency - beanutils (#7705)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Pull Request Statistics
Commits:
1
1
Files Changed:
1
1
Additions:
+1
+1
Deletions:
-1
-1
Package Dependencies
Package:
org.owasp:dependency-check-maven
Ecosystem:
maven
maven
Version Change:
12.1.1 → 12.1.2
Update Type:
Patch
Patch
Technical Details
| ID: | 1319660 |
| UUID: | 2577346882 |
| Node ID: | PR_kwDOAOu-Q86ZnzFC |
| Host: | GitHub |
| Repository: | dschadow/JavaSecurity |
| Merge State: | Unknown |