Bump org.codehaus.plexus:plexus-xml from 4.1.0 to 4.1.1 by dependabot[bot] · Pull Request #1759 · apache/maven-resolver
Bumps org.codehaus.plexus:plexus-xml from 4.1.0 to 4.1.1.
Release notes
Sourced from org.codehaus.plexus:plexus-xml's releases.
4.1.1
- Fix polynomial regular expression vulnerability in XML encoding detection (#68) @copilot-swe-agent[bot]
- Declare license info in POM (#62)
@Goooler👻 Maintenance
- JUnit Jupiter best practices (#72)
@slachiewicz📦 Dependency updates
- Bump org.codehaus.plexus:plexus from 24 to 25 (#77) @dependabot[bot]
- Bump org.apache.maven:maven-xml from 4.0.0-rc-4 to 4.0.0-rc-5 (#74) @dependabot[bot]
- Bump org.codehaus.plexus:plexus from 23 to 24 (#69) @dependabot[bot]
- Bump org.codehaus.plexus:plexus from 22 to 23 (#66) @dependabot[bot]
- Bump org.apache.maven:maven-xml from 4.0.0-rc-3 to 4.0.0-rc-4 (#65) @dependabot[bot]
- Bump org.codehaus.plexus:plexus from 21 to 22 (#63) @dependabot[bot]
- Bump org.codehaus.plexus:plexus from 20 to 21 (#61) @dependabot[bot]
Commits
8169130[maven-release-plugin] prepare release plexus-xml-4.1.1311f1d2Bump org.codehaus.plexus:plexus from 24 to 25a51782fBump org.apache.maven:maven-xml from 4.0.0-rc-4 to 4.0.0-rc-5bc07169JUnit Jupiter best practices9a87e5cFix polynomial regular expression vulnerability in XML encoding detection (#68)303c1a2Bump org.codehaus.plexus:plexus from 23 to 242294db6Bump org.codehaus.plexus:plexus from 22 to 23c6b2c7aBump org.apache.maven:maven-xml from 4.0.0-rc-3 to 4.0.0-rc-4bad0a2bDeclare license info in POM9434226Bump org.codehaus.plexus:plexus from 21 to 22- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)