Skip to content

Bump org.owasp:dependency-check-maven from 12.2.1 to 13.0.0 - #239

Merged
Fishbowler merged 1 commit into
mainfrom
dependabot/maven/org.owasp-dependency-check-maven-12.2.2
Sep 8, 2026
Merged

Bump org.owasp:dependency-check-maven from 12.2.1 to 13.0.0#239
Fishbowler merged 1 commit into
mainfrom
dependabot/maven/org.owasp-dependency-check-maven-12.2.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 3, 2026

Copy link
Copy Markdown
Contributor

Bumps org.owasp:dependency-check-maven from 12.2.1 to 13.0.0.

Release notes

Sourced from org.owasp:dependency-check-maven's releases.

Version 13.0.0

What's Changed

... (truncated)

Changelog

Sourced from org.owasp:dependency-check-maven's changelog.

Change Log

For versions 13.0.0 and above, please see the the GitHub Releases page for the change log.

Version 12.2.2 (2026-05-03)

NOTE: The database schema was updated to fix #8466 - if using an external database the update scripts must be run!

  • feat: improve Sonatype Guide / OSS Index cache handling and insufficient credits error reporting (#8451)
  • feat: support and prefer githubID vuln identifiers from RetireJS (#8419)
  • fix(db): widen reference URL column to handle long Mozilla CVE URLs (#8467)
  • fix: add corepack to docker image (#8386)
  • fix: bump open-vulnerability-clients to resolve NVD timestamp parsing errors (#8427)
  • fix: de-duplicate and sort both includedBy and projectReferences in reports (#8440)
  • fix: migrate default OSS Index API URL to Sonatype Guide; supporting optional username (#8404)
  • docs: correct missing documentation for Gradle plugin (#8431)
  • docs: tweak docs site structure; documenting missing analyzers (#8462)
  • chore: remove spurious bundle-audit log line when there are no errors (#8454)
  • chore: tidy CHANGELOG formatting (#8414)
  • chore(fp): remove duplicate log4j FP suppressions (#8468)
  • build(deps): bump apache.ant.version from 1.10.16 to 1.10.17 (#8416)
  • build(deps): bump com.fasterxml.jackson:jackson-bom from 2.21.2 to 2.21.3 (#8465)
  • build(deps): bump com.google.guava:guava from 33.5.0-jre to 33.6.0-jre (#8420)
  • build(deps): bump com.mysql:mysql-connector-j from 9.6.0 to 9.7.0 (#8445)
  • build(deps): bump commons-codec:commons-codec from 1.21.0 to 1.22.0 (#8453)
  • build(deps): bump commons-io:commons-io from 2.21.0 to 2.22.0 (#8448)
  • build(deps): bump httpcomponents.client.version from 5.6 to 5.6.1 (#8432)
  • build(deps): bump joda-time:joda-time from 2.14.1 to 2.14.2 (#8464)
  • build(deps): bump org.apache.maven.plugins:maven-invoker-plugin from 3.9.1 to 3.10.0 (#8452)
  • build(deps): bump org.jsoup:jsoup from 1.22.1 to 1.22.2 (#8437)
  • build(deps): bump org.postgresql:postgresql from 42.7.10 to 42.7.11 (#8463)
  • build(deps): bump the actions-deps group with 8 updates (#8472)

See the full listing of changes

Commits
  • 4aacdb1 build: prepare release v13.0.0
  • ea6c70d docs: move changelog to github releases
  • d10333c build(deps): bump logback from 1.5.32 to 1.5.34 (#8698)
  • ef5fba7 build(deps): bump open-vulnerability-clients from 9.0.5 to 9.0.6 (#8697)
  • 1547a6f chore!: drop deprecated configuration, integration options & Nexus V2 Search ...
  • cddad18 build(deps): bump org.apache.groovy:groovy-ant from 5.0.6 to 5.0.8 (#8692)
  • 78dfd95 build(deps): bump org.jsoup:jsoup from 1.22.2 to 1.23.1 (#8693)
  • 2d3be64 build(deps): bump com.fasterxml.jackson:jackson-bom from 2.22.0 to 2.22.1 (#8...
  • 57f6189 build(deps): bump httpcomponents.client.version from 5.6.2 to 5.6.3 (#8695)
  • 30af761 build(deps): bump commons-codec:commons-codec from 1.22.0 to 1.22.1 (#8696)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Jun 3, 2026
@Fishbowler

Copy link
Copy Markdown
Member

@dependabot rebase

Bumps [org.owasp:dependency-check-maven](https://github.com/dependency-check/DependencyCheck) from 12.2.1 to 13.0.0.
- [Release notes](https://github.com/dependency-check/DependencyCheck/releases)
- [Changelog](https://github.com/dependency-check/DependencyCheck/blob/main/CHANGELOG.md)
- [Commits](dependency-check/DependencyCheck@v12.2.1...v13.0.0)

---
updated-dependencies:
- dependency-name: org.owasp:dependency-check-maven
  dependency-version: 12.2.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump org.owasp:dependency-check-maven from 12.2.1 to 12.2.2 Bump org.owasp:dependency-check-maven from 12.2.1 to 13.0.0 Sep 8, 2026
@dependabot
dependabot Bot force-pushed the dependabot/maven/org.owasp-dependency-check-maven-12.2.2 branch from 37b3b7e to f341867 Compare September 8, 2026 19:31
@Fishbowler
Fishbowler merged commit 300c3bd into main Sep 8, 2026
10 checks passed
@dependabot
dependabot Bot deleted the dependabot/maven/org.owasp-dependency-check-maven-12.2.2 branch September 8, 2026 19:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant