Bump org.owasp:dependency-check-maven from 12.1.3 to 12.1.5
Merged
Number: #340
Type: Pull Request
State: Merged
Type: Pull Request
State: Merged
Author:
dependabot[bot]
Association: Contributor
Comments: 0
Association: Contributor
Comments: 0
Created:
September 22, 2025 at 04:01 AM UTC
(9 months ago)
(9 months ago)
Updated:
September 22, 2025 at 05:29 AM UTC
(9 months ago)
(9 months ago)
Merged:
September 22, 2025 at 05:29 AM UTC
(9 months ago)
by dschadow
(9 months ago)
by dschadow
Time to Close:
about 1 hour
Labels:
dependencies java
dependencies java
Description:
Bumps org.owasp:dependency-check-maven from 12.1.3 to 12.1.5.
Release notes
Sourced from org.owasp:dependency-check-maven's releases.
Version 12.1.5
Refer to the CHANGELOG.md for information about improvements and upgrade notes.
Changelog
Sourced from org.owasp:dependency-check-maven's changelog.
Version 12.1.5 (2025-09-20)
- fix: Update to support OSS Index Authentication Requirements (#7920)
- Note: OSS Index will require authentication starting 9/22/2025. Users must configure a free account to continue using the OSS Index Analyzer. See https://ossindex.sonatype.org/doc/auth-required.
- fix: add CVSSv4 to suppressed entries in JSON report (#7900)
- fix: correctly utilize CVSSv4 from ossindex (#7899)
- fix: npe when processing cve with empty configuration (#7888)
- fix: Return unsorted vulnerabilities in new HashSet, avoiding CoMod (#7848)
- fix: Return unsorted vulnerabilities in new HashSet, avoiding CoMod
- fix: class loading problem with fat jars (#7786) (#7787)
- fix: Improve Artifactory handler log message (#7838)
- fix: classloading problem with fat jars (#7786)
- fix: Add null checking when parsing the license json in AbstractNpmAnalyzer. (#7784)
- fix(fp): resolves several false positives related to CVE-2021-41033 (#7736)
- docs: Clarify format of exclude patterns (#7879)
- docs: Document poetry-based analysis behaviour in Python analyzer (#7855)
- docs: request FP reporters use the latest version of ODC. (#7820)
- docs: update development pre-reqs (#7792)
- docs: fix minor typos in false positive issue template (#7763)
See the full listing of changes
Commits
71e0fd8build: prepare release v12.1.5d5198d5chore: bump project to 12.1.5ed80987chore: revert failed release (#7932)045e428chore: revert failed releaseaf34748build: release 12.1.4 (#7931)3220b96build: prepare for next development iterationdcfcc10build: prepare release v12.1.41d15a2ddocs: update changelog for release 12.1.4baf281bbuild(deps): bump actions/setup-dotnet from 4.3.1 to 5.0.0 (#7908)8ddda01build(deps): bump actions/setup-node from 4.4.0 to 5.0.0 (#7910)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Pull Request Statistics
Commits:
1
1
Files Changed:
1
1
Additions:
+1
+1
Deletions:
-1
-1
Package Dependencies
Package:
org.owasp:dependency-check-maven
Ecosystem:
maven
maven
Version Change:
12.1.3 → 12.1.5
Update Type:
Patch
Patch
Technical Details
| ID: | 8125243 |
| UUID: | 2847825471 |
| Node ID: | PR_kwDOAOu-Q86pvl4_ |
| Host: | GitHub |
| Repository: | dschadow/JavaSecurity |
| Merge State: | Unknown |