From a6d3346fdd1f3f010639f37220714833b4363ce3 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 30 Aug 2024 15:51:54 -0400 Subject: [PATCH 01/26] Bump org.apache.commons:commons-lang3 from 3.16.0 to 3.17.0 (#109) Bumps org.apache.commons:commons-lang3 from 3.16.0 to 3.17.0. --- updated-dependencies: - dependency-name: org.apache.commons:commons-lang3 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- plugin/pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/plugin/pom.xml b/plugin/pom.xml index 6633d682..8ca44d22 100644 --- a/plugin/pom.xml +++ b/plugin/pom.xml @@ -83,7 +83,7 @@ org.apache.commons commons-lang3 - 3.16.0 + 3.17.0 From 231431da495f521ffad8fbd785693604f8ce0b7e Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 2 Sep 2024 10:57:12 -0400 Subject: [PATCH 02/26] Bump org.yaml:snakeyaml from 2.2 to 2.3 (#110) Bumps [org.yaml:snakeyaml](https://bitbucket.org/snakeyaml/snakeyaml) from 2.2 to 2.3. - [Commits](https://bitbucket.org/snakeyaml/snakeyaml/branches/compare/snakeyaml-2.3..snakeyaml-2.2) --- updated-dependencies: - dependency-name: org.yaml:snakeyaml dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- plugin/pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/plugin/pom.xml b/plugin/pom.xml index 8ca44d22..ea4ee965 100644 --- a/plugin/pom.xml +++ b/plugin/pom.xml @@ -140,7 +140,7 @@ org.yaml snakeyaml - 2.2 + 2.3 2.7.15 - 5.11.0 + 5.11.1 From 56d8c2b17fe677d675a9be49ff530c42e3595c2a Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 27 Sep 2024 11:31:00 -0400 Subject: [PATCH 10/26] Bump version.fasterxml.jackson from 2.17.2 to 2.18.0 (#118) Bumps `version.fasterxml.jackson` from 2.17.2 to 2.18.0. Updates `com.fasterxml.jackson.core:jackson-annotations` from 2.17.2 to 2.18.0 - [Commits](https://github.com/FasterXML/jackson/commits) Updates `com.fasterxml.jackson.core:jackson-core` from 2.17.2 to 2.18.0 - [Commits](https://github.com/FasterXML/jackson-core/compare/jackson-core-2.17.2...jackson-core-2.18.0) Updates `com.fasterxml.jackson.core:jackson-databind` from 2.17.2 to 2.18.0 - [Commits](https://github.com/FasterXML/jackson/commits) Updates `com.fasterxml.jackson.dataformat:jackson-dataformat-xml` from 2.17.2 to 2.18.0 - [Commits](https://github.com/FasterXML/jackson-dataformat-xml/compare/jackson-dataformat-xml-2.17.2...jackson-dataformat-xml-2.18.0) --- updated-dependencies: - dependency-name: com.fasterxml.jackson.core:jackson-annotations dependency-type: direct:production update-type: version-update:semver-minor - dependency-name: com.fasterxml.jackson.core:jackson-core dependency-type: direct:production update-type: version-update:semver-minor - dependency-name: com.fasterxml.jackson.core:jackson-databind dependency-type: direct:production update-type: version-update:semver-minor - dependency-name: com.fasterxml.jackson.dataformat:jackson-dataformat-xml dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- plugin/pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/plugin/pom.xml b/plugin/pom.xml index 1ea2c23a..efce29f4 100644 --- a/plugin/pom.xml +++ b/plugin/pom.xml @@ -192,7 +192,7 @@ - 2.17.2 + 2.18.0 2.7.15 5.11.1 From ddb31387bfba2a1cac0449061639d87d7645afda Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 9 Oct 2024 10:45:24 -0400 Subject: [PATCH 11/26] Bump org.apache.maven.skins:maven-fluido-skin (#119) Bumps [org.apache.maven.skins:maven-fluido-skin](https://github.com/apache/maven-fluido-skin) from 2.0.0-M10 to 2.0.0-M11. - [Release notes](https://github.com/apache/maven-fluido-skin/releases) - [Commits](https://github.com/apache/maven-fluido-skin/compare/maven-fluido-skin-2.0.0-M10...maven-fluido-skin-2.0.0-M11) --- updated-dependencies: - dependency-name: org.apache.maven.skins:maven-fluido-skin dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index 7091e3df..4b4a1de5 100644 --- a/pom.xml +++ b/pom.xml @@ -358,7 +358,7 @@ UTF-8 11 ${project.build.directory}/log - 2.0.0-M10 + 2.0.0-M11 From bcc9640d02ddc03ad47e8b7127456625a926d2d5 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 9 Oct 2024 10:45:37 -0400 Subject: [PATCH 12/26] Bump version.junit.jupiter from 5.11.1 to 5.11.2 (#120) Bumps `version.junit.jupiter` from 5.11.1 to 5.11.2. Updates `org.junit.jupiter:junit-jupiter-api` from 5.11.1 to 5.11.2 - [Release notes](https://github.com/junit-team/junit5/releases) - [Commits](https://github.com/junit-team/junit5/compare/r5.11.1...r5.11.2) Updates `org.junit.jupiter:junit-jupiter-params` from 5.11.1 to 5.11.2 - [Release notes](https://github.com/junit-team/junit5/releases) - [Commits](https://github.com/junit-team/junit5/compare/r5.11.1...r5.11.2) --- updated-dependencies: - dependency-name: org.junit.jupiter:junit-jupiter-api dependency-type: direct:development update-type: version-update:semver-patch - dependency-name: org.junit.jupiter:junit-jupiter-params dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- plugin/pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/plugin/pom.xml b/plugin/pom.xml index efce29f4..8971acba 100644 --- a/plugin/pom.xml +++ b/plugin/pom.xml @@ -195,7 +195,7 @@ 2.18.0 2.7.15 - 5.11.1 + 5.11.2 From 54ba34c0ef406cb417addfbf46851c09f6971db9 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 9 Oct 2024 10:46:08 -0400 Subject: [PATCH 13/26] Bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.0 to 3.5.1 (#121) Bumps [org.apache.maven.plugins:maven-surefire-plugin](https://github.com/apache/maven-surefire) from 3.5.0 to 3.5.1. - [Release notes](https://github.com/apache/maven-surefire/releases) - [Commits](https://github.com/apache/maven-surefire/compare/surefire-3.5.0...surefire-3.5.1) --- updated-dependencies: - dependency-name: org.apache.maven.plugins:maven-surefire-plugin dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index 4b4a1de5..112fdd9d 100644 --- a/pom.xml +++ b/pom.xml @@ -206,7 +206,7 @@ org.apache.maven.plugins maven-surefire-plugin - 3.5.0 + 3.5.1 From c3979a883dd0053be33de6bdfc9a3e616271a8e7 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 22 Oct 2024 13:54:08 -0400 Subject: [PATCH 14/26] Bump version.junit.jupiter from 5.11.2 to 5.11.3 (#124) Bumps `version.junit.jupiter` from 5.11.2 to 5.11.3. Updates `org.junit.jupiter:junit-jupiter-api` from 5.11.2 to 5.11.3 - [Release notes](https://github.com/junit-team/junit5/releases) - [Commits](https://github.com/junit-team/junit5/compare/r5.11.2...r5.11.3) Updates `org.junit.jupiter:junit-jupiter-params` from 5.11.2 to 5.11.3 - [Release notes](https://github.com/junit-team/junit5/releases) - [Commits](https://github.com/junit-team/junit5/compare/r5.11.2...r5.11.3) --- updated-dependencies: - dependency-name: org.junit.jupiter:junit-jupiter-api dependency-type: direct:development update-type: version-update:semver-patch - dependency-name: org.junit.jupiter:junit-jupiter-params dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- plugin/pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/plugin/pom.xml b/plugin/pom.xml index 8971acba..7e3c4585 100644 --- a/plugin/pom.xml +++ b/plugin/pom.xml @@ -195,7 +195,7 @@ 2.18.0 2.7.15 - 5.11.2 + 5.11.3 From 7e21926c8ff08ecc39d2f08548d202e77b8aefb8 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 22 Oct 2024 13:54:20 -0400 Subject: [PATCH 15/26] Bump org.apache.maven.plugins:maven-project-info-reports-plugin (#125) Bumps [org.apache.maven.plugins:maven-project-info-reports-plugin](https://github.com/apache/maven-project-info-reports-plugin) from 3.7.0 to 3.8.0. - [Commits](https://github.com/apache/maven-project-info-reports-plugin/compare/maven-project-info-reports-plugin-3.7.0...maven-project-info-reports-plugin-3.8.0) --- updated-dependencies: - dependency-name: org.apache.maven.plugins:maven-project-info-reports-plugin dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index 112fdd9d..1d39d20b 100644 --- a/pom.xml +++ b/pom.xml @@ -179,7 +179,7 @@ org.apache.maven.plugins maven-project-info-reports-plugin - 3.7.0 + 3.8.0 From 461d63f33d1830bf03668dc28b12626521c3118f Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Wed, 23 Oct 2024 09:39:48 -0400 Subject: [PATCH 16/26] Bump org.apache.httpcomponents.core5:httpcore5 from 5.3 to 5.3.1 (#126) Bumps [org.apache.httpcomponents.core5:httpcore5](https://github.com/apache/httpcomponents-core) from 5.3 to 5.3.1. - [Changelog](https://github.com/apache/httpcomponents-core/blob/rel/v5.3.1/RELEASE_NOTES.txt) - [Commits](https://github.com/apache/httpcomponents-core/compare/rel/v5.3...rel/v5.3.1) --- updated-dependencies: - dependency-name: org.apache.httpcomponents.core5:httpcore5 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- plugin/pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/plugin/pom.xml b/plugin/pom.xml index 7e3c4585..eceac84c 100644 --- a/plugin/pom.xml +++ b/plugin/pom.xml @@ -95,7 +95,7 @@ org.apache.httpcomponents.core5 httpcore5 - 5.3 + 5.3.1 From 1b484f4a56c3c406c3b421ccc3f2fe0cda7ec08b Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 28 Oct 2024 11:26:04 -0400 Subject: [PATCH 17/26] Bump org.apache.maven.plugins:maven-jxr-plugin from 3.5.0 to 3.6.0 (#127) Bumps [org.apache.maven.plugins:maven-jxr-plugin](https://github.com/apache/maven-jxr) from 3.5.0 to 3.6.0. - [Release notes](https://github.com/apache/maven-jxr/releases) - [Commits](https://github.com/apache/maven-jxr/compare/jxr-3.5.0...jxr-3.6.0) --- updated-dependencies: - dependency-name: org.apache.maven.plugins:maven-jxr-plugin dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index 1d39d20b..c216ff26 100644 --- a/pom.xml +++ b/pom.xml @@ -173,7 +173,7 @@ org.apache.maven.plugins maven-jxr-plugin - 3.5.0 + 3.6.0 From 4412967f6c710389c27708b4dbecfbfb223df462 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 28 Oct 2024 11:26:15 -0400 Subject: [PATCH 18/26] Bump org.apache.maven.plugins:maven-dependency-plugin (#128) Bumps [org.apache.maven.plugins:maven-dependency-plugin](https://github.com/apache/maven-dependency-plugin) from 3.8.0 to 3.8.1. - [Release notes](https://github.com/apache/maven-dependency-plugin/releases) - [Commits](https://github.com/apache/maven-dependency-plugin/compare/maven-dependency-plugin-3.8.0...maven-dependency-plugin-3.8.1) --- updated-dependencies: - dependency-name: org.apache.maven.plugins:maven-dependency-plugin dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index c216ff26..2826ec26 100644 --- a/pom.xml +++ b/pom.xml @@ -48,7 +48,7 @@ org.apache.maven.plugins maven-dependency-plugin - 3.8.0 + 3.8.1 org.apache.maven.plugins From e6854cd3ef015df2d94f04d914775c6027564f00 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 28 Oct 2024 11:26:26 -0400 Subject: [PATCH 19/26] Bump org.apache.maven.plugin-tools:maven-plugin-annotations (#129) Bumps [org.apache.maven.plugin-tools:maven-plugin-annotations](https://github.com/apache/maven-plugin-tools) from 3.15.0 to 3.15.1. - [Release notes](https://github.com/apache/maven-plugin-tools/releases) - [Commits](https://github.com/apache/maven-plugin-tools/compare/maven-plugin-tools-3.15.0...maven-plugin-tools-3.15.1) --- updated-dependencies: - dependency-name: org.apache.maven.plugin-tools:maven-plugin-annotations dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- plugin/pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/plugin/pom.xml b/plugin/pom.xml index eceac84c..a13d298d 100644 --- a/plugin/pom.xml +++ b/plugin/pom.xml @@ -108,7 +108,7 @@ org.apache.maven.plugin-tools maven-plugin-annotations - 3.15.0 + 3.15.1 provided From fa9496656a2a7660871fe65dba4c3e95ad802adc Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 28 Oct 2024 11:26:35 -0400 Subject: [PATCH 20/26] Bump org.apache.maven.plugins:maven-plugin-plugin from 3.15.0 to 3.15.1 (#130) Bumps [org.apache.maven.plugins:maven-plugin-plugin](https://github.com/apache/maven-plugin-tools) from 3.15.0 to 3.15.1. - [Release notes](https://github.com/apache/maven-plugin-tools/releases) - [Commits](https://github.com/apache/maven-plugin-tools/compare/maven-plugin-tools-3.15.0...maven-plugin-tools-3.15.1) --- updated-dependencies: - dependency-name: org.apache.maven.plugins:maven-plugin-plugin dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index 2826ec26..b172f920 100644 --- a/pom.xml +++ b/pom.xml @@ -53,7 +53,7 @@ org.apache.maven.plugins maven-plugin-plugin - 3.15.0 + 3.15.1 org.apache.maven.plugins From 8da554489d76a1c48bdbd89176f74802cc093e48 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 29 Oct 2024 10:14:58 -0400 Subject: [PATCH 21/26] Bump version.fasterxml.jackson from 2.18.0 to 2.18.1 (#131) Bumps `version.fasterxml.jackson` from 2.18.0 to 2.18.1. Updates `com.fasterxml.jackson.core:jackson-annotations` from 2.18.0 to 2.18.1 - [Commits](https://github.com/FasterXML/jackson/commits) Updates `com.fasterxml.jackson.core:jackson-core` from 2.18.0 to 2.18.1 - [Commits](https://github.com/FasterXML/jackson-core/compare/jackson-core-2.18.0...jackson-core-2.18.1) Updates `com.fasterxml.jackson.core:jackson-databind` from 2.18.0 to 2.18.1 - [Commits](https://github.com/FasterXML/jackson/commits) Updates `com.fasterxml.jackson.dataformat:jackson-dataformat-xml` from 2.18.0 to 2.18.1 - [Commits](https://github.com/FasterXML/jackson-dataformat-xml/compare/jackson-dataformat-xml-2.18.0...jackson-dataformat-xml-2.18.1) --- updated-dependencies: - dependency-name: com.fasterxml.jackson.core:jackson-annotations dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: com.fasterxml.jackson.core:jackson-core dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: com.fasterxml.jackson.core:jackson-databind dependency-type: direct:production update-type: version-update:semver-patch - dependency-name: com.fasterxml.jackson.dataformat:jackson-dataformat-xml dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- plugin/pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/plugin/pom.xml b/plugin/pom.xml index a13d298d..6a8d14c2 100644 --- a/plugin/pom.xml +++ b/plugin/pom.xml @@ -192,7 +192,7 @@ - 2.18.0 + 2.18.1 2.7.15 5.11.3 From ee0337374dc12d2f6674573010e7fcd759ef86bc Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 29 Oct 2024 10:15:11 -0400 Subject: [PATCH 22/26] Bump org.apache.httpcomponents.client5:httpclient5 from 5.4 to 5.4.1 (#132) Bumps [org.apache.httpcomponents.client5:httpclient5](https://github.com/apache/httpcomponents-client) from 5.4 to 5.4.1. - [Changelog](https://github.com/apache/httpcomponents-client/blob/rel/v5.4.1/RELEASE_NOTES.txt) - [Commits](https://github.com/apache/httpcomponents-client/compare/rel/v5.4...rel/v5.4.1) --- updated-dependencies: - dependency-name: org.apache.httpcomponents.client5:httpclient5 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- plugin/pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/plugin/pom.xml b/plugin/pom.xml index 6a8d14c2..8621a051 100644 --- a/plugin/pom.xml +++ b/plugin/pom.xml @@ -89,7 +89,7 @@ org.apache.httpcomponents.client5 httpclient5 - 5.4 + 5.4.1 From 3997ee6ac99dd47d4f42d914479f73814d3355c8 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 18 Nov 2024 10:45:33 -0500 Subject: [PATCH 23/26] Bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.1 to 3.5.2 (#133) Bumps [org.apache.maven.plugins:maven-surefire-plugin](https://github.com/apache/maven-surefire) from 3.5.1 to 3.5.2. - [Release notes](https://github.com/apache/maven-surefire/releases) - [Commits](https://github.com/apache/maven-surefire/compare/surefire-3.5.1...surefire-3.5.2) --- updated-dependencies: - dependency-name: org.apache.maven.plugins:maven-surefire-plugin dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index b172f920..7250f2c8 100644 --- a/pom.xml +++ b/pom.xml @@ -206,7 +206,7 @@ org.apache.maven.plugins maven-surefire-plugin - 3.5.1 + 3.5.2 From 02171d7206b743f46057cd57997bc588068b9fe5 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 18 Nov 2024 10:46:12 -0500 Subject: [PATCH 24/26] Bump org.apache.maven.skins:maven-fluido-skin from 2.0.0-M11 to 2.0.0 (#134) Bumps [org.apache.maven.skins:maven-fluido-skin](https://github.com/apache/maven-fluido-skin) from 2.0.0-M11 to 2.0.0. - [Release notes](https://github.com/apache/maven-fluido-skin/releases) - [Commits](https://github.com/apache/maven-fluido-skin/compare/maven-fluido-skin-2.0.0-M11...maven-fluido-skin-2.0.0) --- updated-dependencies: - dependency-name: org.apache.maven.skins:maven-fluido-skin dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index 7250f2c8..57a0c551 100644 --- a/pom.xml +++ b/pom.xml @@ -358,7 +358,7 @@ UTF-8 11 ${project.build.directory}/log - 2.0.0-M11 + 2.0.0 From 38a24e82ba674d809fc5060ef5a575a808a692d4 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 18 Nov 2024 10:46:23 -0500 Subject: [PATCH 25/26] Bump org.codehaus.mojo:versions-maven-plugin from 2.17.1 to 2.18.0 (#135) Bumps [org.codehaus.mojo:versions-maven-plugin](https://github.com/mojohaus/versions) from 2.17.1 to 2.18.0. - [Release notes](https://github.com/mojohaus/versions/releases) - [Changelog](https://github.com/mojohaus/versions/blob/master/ReleaseNotes.md) - [Commits](https://github.com/mojohaus/versions/compare/2.17.1...2.18.0) --- updated-dependencies: - dependency-name: org.codehaus.mojo:versions-maven-plugin dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index 57a0c551..dcaca1cb 100644 --- a/pom.xml +++ b/pom.xml @@ -212,7 +212,7 @@ org.codehaus.mojo versions-maven-plugin - 2.17.1 + 2.18.0 From 4b4514984cbb8a2a53320ac2c45aee9ff2b39065 Mon Sep 17 00:00:00 2001 From: Alexey Zhukov Date: Mon, 18 Nov 2024 18:46:45 +0300 Subject: [PATCH 26/26] Positive Technologies Application Inspector (PT AI) SARIF report support (#123) * Positive Technologies Application Inspector SARIF report support added * PT AI tool name and version are shortened --- .../benchmarkutils/score/parsers/Reader.java | 2 + .../score/parsers/sarif/PTAIReader.java | 64 +++++++++++ .../score/parsers/sarif/PTAIReaderTest.java | 57 ++++++++++ .../testfiles/Benchmark_PTAI-v4.7.2.sarif | 104 ++++++++++++++++++ 4 files changed, 227 insertions(+) create mode 100644 plugin/src/main/java/org/owasp/benchmarkutils/score/parsers/sarif/PTAIReader.java create mode 100644 plugin/src/test/java/org/owasp/benchmarkutils/score/parsers/sarif/PTAIReaderTest.java create mode 100644 plugin/src/test/resources/testfiles/Benchmark_PTAI-v4.7.2.sarif diff --git a/plugin/src/main/java/org/owasp/benchmarkutils/score/parsers/Reader.java b/plugin/src/main/java/org/owasp/benchmarkutils/score/parsers/Reader.java index 97da88bf..f156ebb9 100644 --- a/plugin/src/main/java/org/owasp/benchmarkutils/score/parsers/Reader.java +++ b/plugin/src/main/java/org/owasp/benchmarkutils/score/parsers/Reader.java @@ -32,6 +32,7 @@ import org.owasp.benchmarkutils.score.parsers.sarif.CodeQLReader; import org.owasp.benchmarkutils.score.parsers.sarif.ContrastScanReader; import org.owasp.benchmarkutils.score.parsers.sarif.DatadogSastReader; +import org.owasp.benchmarkutils.score.parsers.sarif.PTAIReader; import org.owasp.benchmarkutils.score.parsers.sarif.PrecautionReader; import org.owasp.benchmarkutils.score.parsers.sarif.SemgrepSarifReader; import org.owasp.benchmarkutils.score.parsers.sarif.SnykReader; @@ -89,6 +90,7 @@ public static List allReaders() { new ParasoftReader(), new PrecautionReader(), new PMDReader(), + new PTAIReader(), new QualysWASReader(), new Rapid7Reader(), new ReshiftReader(), diff --git a/plugin/src/main/java/org/owasp/benchmarkutils/score/parsers/sarif/PTAIReader.java b/plugin/src/main/java/org/owasp/benchmarkutils/score/parsers/sarif/PTAIReader.java new file mode 100644 index 00000000..e0254829 --- /dev/null +++ b/plugin/src/main/java/org/owasp/benchmarkutils/score/parsers/sarif/PTAIReader.java @@ -0,0 +1,64 @@ +/** + * OWASP Benchmark Project + * + *

This file is part of the Open Web Application Security Project (OWASP) Benchmark Project For + * details, please see https://owasp.org/www-project-benchmark/. + * + *

The OWASP Benchmark is free software: you can redistribute it and/or modify it under the terms + * of the GNU General Public License as published by the Free Software Foundation, version 2. + * + *

The OWASP Benchmark is distributed in the hope that it will be useful, but WITHOUT ANY + * WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR + * PURPOSE. See the GNU General Public License for more details. + * + * @author Alexey Zhukov + * @created 2024 + */ +package org.owasp.benchmarkutils.score.parsers.sarif; + +import org.owasp.benchmarkutils.score.CweNumber; +import org.owasp.benchmarkutils.score.ResultFile; +import org.owasp.benchmarkutils.score.TestSuiteResults; + +public class PTAIReader extends SarifReader { + + static final int PTAI_CWE_EXTERNAL_FILEPATH_CONTROL = 73; + static final int PTAI_CWE_BLIND_XPATH_INJECTION = 91; + + static final String EXPECTED_TOOL_NAME = "Positive Technologies Application Inspector"; + static final String SHORTENED_TOOL_NAME = "PT Application Inspector"; + + public PTAIReader() { + super(EXPECTED_TOOL_NAME, true, CweSourceType.FIELD); + } + + @Override + public String toolName(ResultFile resultFile) { + return SHORTENED_TOOL_NAME; + } + + /** + * SARIF report tool version field is too long as it contains build number. Shorten it to X.Y.Z + */ + @Override + public void setVersion(ResultFile resultFile, TestSuiteResults testSuiteResults) { + super.setVersion(resultFile, testSuiteResults); + String version = testSuiteResults.getToolVersion(); + String[] versionItems = version.split("\\."); + if (versionItems.length < 4) return; + testSuiteResults.setToolVersion( + String.format("%s.%s.%s", versionItems[0], versionItems[1], versionItems[2])); + } + + @Override + public int mapCwe(int cwe) { + switch (cwe) { + case PTAI_CWE_EXTERNAL_FILEPATH_CONTROL: + return CweNumber.PATH_TRAVERSAL; + case PTAI_CWE_BLIND_XPATH_INJECTION: + return CweNumber.XPATH_INJECTION; + } + return cwe; + } +} diff --git a/plugin/src/test/java/org/owasp/benchmarkutils/score/parsers/sarif/PTAIReaderTest.java b/plugin/src/test/java/org/owasp/benchmarkutils/score/parsers/sarif/PTAIReaderTest.java new file mode 100644 index 00000000..6df8ffcc --- /dev/null +++ b/plugin/src/test/java/org/owasp/benchmarkutils/score/parsers/sarif/PTAIReaderTest.java @@ -0,0 +1,57 @@ +/** + * OWASP Benchmark Project + * + *

This file is part of the Open Web Application Security Project (OWASP) Benchmark Project For + * details, please see https://owasp.org/www-project-benchmark/. + * + *

The OWASP Benchmark is free software: you can redistribute it and/or modify it under the terms + * of the GNU General Public License as published by the Free Software Foundation, version 2. + * + *

The OWASP Benchmark is distributed in the hope that it will be useful, but WITHOUT ANY + * WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR + * PURPOSE. See the GNU General Public License for more details. + * + * @author Alexey Zhukov + * @created 2024 + */ +package org.owasp.benchmarkutils.score.parsers.sarif; + +import static org.junit.jupiter.api.Assertions.assertEquals; + +import org.junit.jupiter.api.BeforeEach; +import org.junit.jupiter.api.Test; +import org.owasp.benchmarkutils.score.*; +import org.owasp.benchmarkutils.score.parsers.ReaderTestBase; + +public class PTAIReaderTest extends ReaderTestBase { + + private ResultFile resultFile; + + @BeforeEach + void setUp() { + resultFile = TestHelper.resultFileOf("testfiles/Benchmark_PTAI-v4.7.2.sarif"); + BenchmarkScore.TESTCASENAME = "BenchmarkTest"; + } + + @Test + public void onlyPTAIReaderTestReportsCanReadAsTrue() { + assertOnlyMatcherClassIs(this.resultFile, PTAIReader.class); + } + + @Test + void readerHandlesGivenResultFile() throws Exception { + PTAIReader reader = new PTAIReader(); + TestSuiteResults result = reader.parse(resultFile); + + assertEquals(TestSuiteResults.ToolType.SAST, result.getToolType()); + + assertEquals("PT Application Inspector", result.getToolName()); + assertEquals("4.7.2", result.getToolVersion()); + + assertEquals(2, result.getTotalResults()); + + assertEquals(CweNumber.PATH_TRAVERSAL, result.get(1).get(0).getCWE()); + assertEquals(CweNumber.SQL_INJECTION, result.get(8).get(0).getCWE()); + } +} diff --git a/plugin/src/test/resources/testfiles/Benchmark_PTAI-v4.7.2.sarif b/plugin/src/test/resources/testfiles/Benchmark_PTAI-v4.7.2.sarif new file mode 100644 index 00000000..c861425d --- /dev/null +++ b/plugin/src/test/resources/testfiles/Benchmark_PTAI-v4.7.2.sarif @@ -0,0 +1,104 @@ +{ + "version": "2.1.0", + "$schema": "http://json.schemastore.org/sarif-2.1.0.json", + "runs": [ + { + "tool": { + "driver": { + "name": "Positive Technologies Application Inspector", + "version": "4.7.2.36549", + "organization": "Positive Technologies", + "informationUri": "https://www.ptsecurity.com/ww-en/products/ai/", + "rules": [ + { + "id": "SQL Injection", + "name": "SQL Injection", + "properties": { + "cwe": [ + "CWE-89" + ] + }, + "defaultConfiguration": { + "level": "error", + "enabled": true + }, + "messageStrings": { + "default": { + "text": "SQL Injection" + } + } + }, + { + "id": "Arbitrary File Reading", + "name": "Arbitrary File Reading", + "properties": { + "cwe": [ + "CWE-73" + ] + }, + "defaultConfiguration": { + "level": "error", + "enabled": true + }, + "messageStrings": { + "default": { + "text": "Arbitrary File Reading" + } + } + } + ] + } + }, + "results": [ + { + "ruleId": "Arbitrary File Reading", + "suppressions": [ + ], + "message": { + "id": "default", + "text": "Arbitrary File Reading" + }, + "locations": [ + { + "physicalLocation": { + "artifactLocation": { + "uri": "./src/main/java/org/owasp/benchmark/testcode/BenchmarkTest00001.java" + }, + "region": { + "startLine": 71, + "snippet": { + "text": "new java.io.FileInputStream(new java.io.File(fileName))" + } + } + } + } + ] + }, + { + "ruleId": "SQL Injection", + "suppressions": [ + ], + "message": { + "id": "default", + "text": "SQL Injection" + }, + "locations": [ + { + "physicalLocation": { + "artifactLocation": { + "uri": "./src/main/java/org/owasp/benchmark/testcode/BenchmarkTest00008.java" + }, + "region": { + "startLine": 57, + "snippet": { + "text": "connection.prepareCall(sql)" + } + } + } + } + ] + } + ] + } + ] +}