Conversation
|
❌ Gradle check result for 66c937a: FAILURE Please examine the workflow log, locate, and copy-paste the failure(s) below, then iterate to green. Is the failure a flaky test unrelated to your change? |
|
@dependabot rebase |
66c937a to
7a27851
Compare
|
❌ Gradle check result for 22abb07: FAILURE Please examine the workflow log, locate, and copy-paste the failure(s) below, then iterate to green. Is the failure a flaky test unrelated to your change? |
|
@dependabot rebase |
22abb07 to
9ce025f
Compare
|
❌ Gradle check result for 7ccbcd1: FAILURE Please examine the workflow log, locate, and copy-paste the failure(s) below, then iterate to green. Is the failure a flaky test unrelated to your change? |
|
@dependabot rebase |
Bumps [net.minidev:json-smart](https://github.com/netplex/json-smart-v2) from 2.5.1 to 2.5.2. - [Release notes](https://github.com/netplex/json-smart-v2/releases) - [Commits](netplex/json-smart-v2@2.5.1...2.5.2) --- updated-dependencies: - dependency-name: net.minidev:json-smart dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
7ccbcd1 to
3b57765
Compare
Signed-off-by: dependabot[bot] <support@github.com>
|
@cwperks - Wondering if this change needs a changelog entry? |
|
❌ Gradle check result for be40049: null Please examine the workflow log, locate, and copy-paste the failure(s) below, then iterate to green. Is the failure a flaky test unrelated to your change? |
|
❕ Gradle check result for be40049: UNSTABLE
Please review all flaky tests that succeeded after retry and create an issue if one does not already exist to track the flaky failure. |
Codecov ReportAll modified and coverable lines are covered by tests ✅
Additional details and impacted files@@ Coverage Diff @@
## main #17376 +/- ##
=========================================
Coverage 72.43% 72.44%
+ Complexity 65591 65585 -6
=========================================
Files 5291 5291
Lines 304325 304325
Branches 44181 44181
=========================================
+ Hits 220445 220473 +28
+ Misses 65813 65754 -59
- Partials 18067 18098 +31 ☔ View full report in Codecov by Sentry. |
|
Looks like the CHANGELOG was skipped because it was done in #17378 for the same dep in a different module. These modules have not been switched over to use the gradle version catalog yet which will help reduce such cases from 2 separate PRs to a single dependabot PR. |
…y-hdfs (#17376) * Bump net.minidev:json-smart in /plugins/repository-hdfs Bumps [net.minidev:json-smart](https://github.com/netplex/json-smart-v2) from 2.5.1 to 2.5.2. - [Release notes](https://github.com/netplex/json-smart-v2/releases) - [Commits](netplex/json-smart-v2@2.5.1...2.5.2) --- updated-dependencies: - dependency-name: net.minidev:json-smart dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> * Updating SHAs Signed-off-by: dependabot[bot] <support@github.com> --------- Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> (cherry picked from commit 664f254) Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com>
…y-hdfs (#17376) (#17414) * Bump net.minidev:json-smart in /plugins/repository-hdfs Bumps [net.minidev:json-smart](https://github.com/netplex/json-smart-v2) from 2.5.1 to 2.5.2. - [Release notes](https://github.com/netplex/json-smart-v2/releases) - [Commits](netplex/json-smart-v2@2.5.1...2.5.2) --- updated-dependencies: - dependency-name: net.minidev:json-smart dependency-type: direct:production update-type: version-update:semver-patch ... * Updating SHAs --------- (cherry picked from commit 664f254) Signed-off-by: dependabot[bot] <support@github.com> Signed-off-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
|
@reta @peternied @cwperks any reason why dependabot missed this related bump? for CVE-2024-57699 EDIT: Seems we're limited to one open bump PR at a time with a weekly interval. OpenSearch/.github/dependabot.yml Lines 950 to 954 in 9bef705
Should be 3 :) |
Bumps net.minidev:json-smart from 2.5.1 to 2.5.2.
Release notes
Sourced from net.minidev:json-smart's releases.
... (truncated)
Commits
d4f7fa4migrate to s01.oss.sonatype.org9ca093ddocs: mark v2.5.2 not released now55fa105update maintainer github id and email (#234)7ecb1d3bump to version 2.5.2.852caf6Merge pull request #233 from ccudennec-otto/fix-CVE-2024-57699d1f4645Merge pull request #228 from netplex/dependabot/maven/json-smart/junit.versio...19a787eMerge pull request #230 from netplex/dependabot/maven/json-smart-action/junit...f2be4c1Merge pull request #229 from netplex/dependabot/maven/json-smart/org.apache.m...224943aMerge pull request #231 from netplex/dependabot/maven/json-smart-action/org.a...c21d854fix CVE-2024-57699 for predefined parsersDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)