Bump org.owasp:dependency-check-maven from 12.1.3 to 12.1.6
Closed
Number: #5497
Type: Pull Request
State: Closed
Type: Pull Request
State: Closed
Author:
dependabot[bot]
Association: Contributor
Comments: 2
Association: Contributor
Comments: 2
Created:
September 25, 2025 at 12:01 PM UTC
(about 1 month ago)
(about 1 month ago)
Updated:
September 29, 2025 at 07:13 PM UTC
(about 1 month ago)
(about 1 month ago)
Closed:
September 29, 2025 at 07:13 PM UTC
(about 1 month ago)
(about 1 month ago)
Time to Close:
4 days
Labels:
dependencies OCA Verified java
dependencies OCA Verified java
Description:
Bumps org.owasp:dependency-check-maven from 12.1.3 to 12.1.6.
Release notes
Sourced from org.owasp:dependency-check-maven's releases.
Version 12.1.6
Refer to the CHANGELOG.md for information about improvements and upgrade notes.
Version 12.1.5
Refer to the CHANGELOG.md for information about improvements and upgrade notes.
Changelog
Sourced from org.owasp:dependency-check-maven's changelog.
Version 12.1.6 (2025-09-24)
- fix: Disable OSS Index if its credentials are missing (#7963)
- fix: Correct CVSSv4 parsing for low precision OSSIndex values (#7935)
- fix(fp): Fix false positives for Redis Server against NPM/JS client libs (#7942)
- docs: Fix legacy GitHub links within docs and CHANGELOG (#7944)
- chore: fix version typo in security policy (#7936)
See the full listing of changes
Version 12.1.5 (2025-09-20)
- fix: Update to support OSS Index Authentication Requirements (#7920)
- Note: OSS Index will require authentication starting 9/22/2025. Users must configure a free account to continue using the OSS Index Analyzer. See https://ossindex.sonatype.org/doc/auth-required.
- fix: add CVSSv4 to suppressed entries in JSON report (#7900)
- fix: correctly utilize CVSSv4 from ossindex (#7899)
- fix: npe when processing cve with empty configuration (#7888)
- fix: Return unsorted vulnerabilities in new HashSet, avoiding CoMod (#7848)
- fix: Return unsorted vulnerabilities in new HashSet, avoiding CoMod
- fix: class loading problem with fat jars (#7786) (#7787)
- fix: Improve Artifactory handler log message (#7838)
- fix: classloading problem with fat jars (#7786)
- fix: Add null checking when parsing the license json in AbstractNpmAnalyzer. (#7784)
- fix(fp): resolves several false positives related to CVE-2021-41033 (#7736)
- docs: Clarify format of exclude patterns (#7879)
- docs: Document poetry-based analysis behaviour in Python analyzer (#7855)
- docs: request FP reporters use the latest version of ODC. (#7820)
- docs: update development pre-reqs (#7792)
- docs: fix minor typos in false positive issue template (#7763)
See the full listing of changes
Commits
0a9592cbuild: prepare release v12.1.6c7e992cdocs: release 12.1.693b0d1bbuild(deps): bump netty-codec-http from 5.2.4-final to 5.2.5-final (#7965)22ecc0bfix: Disable OSS Index if its credentials are missing (#7963)93422d2chore: Allow passing ossIndex credentials during false positive ops workflow ...34a1235docs: Fix legacy GitHub links within docs and CHANGELOG (#7944)c44ba32fix(fp): Fix false positives for Redis Server against NPM/JS client libs (#7942)4af07ccdocs: Implement #7808 to make changelog links clickable (#7945)6008202test: Fix AssemblyAnalyzerTest to be robust to Grok availability (#7950)b3aa3f2build: replace deprecated jlink argument (#7953)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Pull Request Statistics
Commits:
1
1
Files Changed:
1
1
Additions:
+1
+1
Deletions:
-1
-1
Package Dependencies
Package:
org.owasp:dependency-check-maven
Ecosystem:
maven
maven
Version Change:
12.1.3 → 12.1.6
Update Type:
Patch
Patch
Technical Details
| ID: | 8425722 |
| UUID: | 2860384975 |
| Node ID: | PR_kwDOBr-jP86qfgLP |
| Host: | GitHub |
| Repository: | oracle/weblogic-kubernetes-operator |
| Mergeable: | Yes |
| Merge State: | Clean |
| Rebaseable: | Yes |