Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(distro): bump tomcat version to 10.1.35 and 9.0.99 TEST #4948

Closed
wants to merge 1 commit into from

Conversation

mboskamp
Copy link
Member

Related to #4942

@mboskamp mboskamp added the bot:java-dependency-check When assigned to a PR, generates SBOMs for the PR and base branch and compares them. label Feb 17, 2025
@mboskamp mboskamp self-assigned this Feb 17, 2025
Copy link

Java dependency diff

🔄 camunda-root: 7.23.0-SNAPSHOT => 7.23.0-SNAPSHOT  
 └─ 🔄 camunda-parent: 7.23.0-SNAPSHOT => 7.23.0-SNAPSHOT  
     └─ 🔄 camunda-database-settings: 7.23.0-SNAPSHOT => 7.23.0-SNAPSHOT  
         └─ 🔄 camunda-tomcat: 7.23.0-SNAPSHOT => 7.23.0-SNAPSHOT  
             ├─ 🔄 camunda-tomcat-assembly: 7.23.0-SNAPSHOT => 7.23.0-SNAPSHOT  
             │   └─ ⬆ tomcat: 10.1.34 ❓ => 10.1.35 ❓  
             └─ 🔄 camunda-bpm-tomcat: 7.23.0-SNAPSHOT => 7.23.0-SNAPSHOT  
                 └─ 🔄 camunda-tomcat-assembly: 7.23.0-SNAPSHOT => 7.23.0-SNAPSHOT  
                     └─ ⬆ tomcat: 10.1.34 ❓ => 10.1.35

Module details

tomcat:10.1.34

Declared licenses: None

Links: None

tomcat:10.1.35

Declared licenses: None

Links: None

Checklist

Unique changes

Unique additions

Developer comments

Glossary

Limitations

  • The reported transitive dependencies may not always be accurate in a multi-module project.
    The SBOM file format represents a unique dependency (coordinates + type) only once. In a multi-module
    project a dependency can be declared in multiple locations with different exclusions of transitive dependencies
    or different version overrides for transitive dependencies.

Emojies

  • ✔: All licenses are on the Go list
  • ⚠: (At least one) license is on the Caution list
  • ❌: (At least one) license is on the Stop list
  • ❓: (At least one) license cannot be determined or is unknown
  • ‼: Dependency has multiple licenses declared
  • ⬆: New dependency version is higher than previous
  • ⬇: New dependency version is lower than previous
  • 🔄: Dependency version is equal and the dependencies of this component changed (e.g. when comparing snapshots)
  • 🤷: The change of the dependency version can not be determined further (e.g. because the version does not follow semantic versioning)

@mboskamp
Copy link
Member Author

This PR was created to test the dependency check workflow after a change. Closing as it is not needed anymore.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bot:java-dependency-check When assigned to a PR, generates SBOMs for the PR and base branch and compares them.
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant