Skip to content

Bump vulnerable versions in IT fixtures where the version is incidental - #1723

Merged
slachiewicz merged 1 commit into
masterfrom
agent/it-fixture-versions
Oct 7, 2026
Merged

slachiewicz merged 1 commit into
masterfrom
agent/it-fixture-versions

Conversation

@slachiewicz

Copy link
Copy Markdown
Member

Clears Dependabot alerts on four IT fixtures: maven-core 3.0/3.6.3 → 3.9.16 in analyze-ignore-used-undeclared-dependency, tree and tree-scope (golden trees regenerated), and logback-core 1.5.6 → 1.5.34 in mdep-689-apply-filtering-go-offline-goal.

The PR does not touch fixtures where the old version is what the test exercises: list-repositories asserts on a repository declared in maven-core 3.2.5's POM chain, copy-dependencies-with-conflict needs org.jdom:jdom and org.lucee:jdom at the same version, and tree-verbose has its golden tree built around batik-bridge 1.7.

Verified: mvn -P run-its verify on these four ITs → passed under Maven 3.9.16, 4.0.0-rc-6 and 4.0.0-rc-7.

@slachiewicz slachiewicz added the dependencies Pull requests that update a dependency file label Oct 7, 2026
@slachiewicz
slachiewicz marked this pull request as ready for review October 7, 2026 20:00
@slachiewicz
slachiewicz merged commit f5040d9 into master Oct 7, 2026
21 checks passed
@slachiewicz
slachiewicz deleted the agent/it-fixture-versions branch October 7, 2026 20:16
@github-actions github-actions Bot added this to the 3.12.0 milestone Oct 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant