Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 12, 2026

Bumps the plugins group with 2 updates in the / directory: com.puppycrawl.tools:checkstyle and org.owasp:dependency-check-maven.

Updates com.puppycrawl.tools:checkstyle from 12.3.0 to 13.0.0

Release notes

Sourced from com.puppycrawl.tools:checkstyle's releases.

checkstyle-13.0.0

Checkstyle 13.0.0 - https://checkstyle.org/releasenotes.html#Release_13.0.0

Breaking backward compatibility:

#17430 - Use jdk21 as minimial required

Bug fixes:

#18409 - Remove duplicate violations in WhitespaceAfter and WhitespaceAround in sun_checks.xml

checkstyle-12.3.1

Checkstyle 12.3.1 - https://checkstyle.org/releasenotes.html#Release_12.3.1

Bug fixes:

#17265 - Duplicate violations in WhitespaceAfter and WhitespaceAround in google config #17778 - Add support to properly follow Rule 7.1.1 General Form in Google Style Guide Implementation #18381 - NullPointerException in TextBlockGoogleStyleFormatting with text blocks in annotations #17727 - Need default config in google_checks.xml to forbid lowercase Javadoc beginnings

... (truncated)

Commits
  • d02376e [maven-release-plugin] prepare release checkstyle-13.0.0
  • e125229 doc: release notes for 13.0.0
  • 3e68230 Revert "doc: release notes for 13.0.0"
  • 610c605 Issue #17430: migration to jdk21 for release actions
  • ace8678 doc: release notes for 13.0.0
  • 042527c Issue #17428: Activated MissingNullCaseInSwitch
  • e16b3bc Issue #18034: Resolve PIT Mutation Suppression for NonVoidMethodCallMutation ...
  • 0cd8f7c infra: use 'React to comment' from Github
  • 9e3599a Issue #17674: remove supression
  • 80fbe6d infra: revert to 'true' to make it work, see #18507
  • Additional commits viewable in compare view

Updates org.owasp:dependency-check-maven from 12.1.9 to 12.2.0

Release notes

Sourced from org.owasp:dependency-check-maven's releases.

Version 12.2.0

Refer to the CHANGELOG.md for information about improvements and upgrade notes.

Changelog

Sourced from org.owasp:dependency-check-maven's changelog.

Version 12.2.0 (2026-01-09)

  • feat: package and utilize generated suppression file (#8116)

  • feat: override pnpm audit registry parameter (#8158)

  • feat: support multiple cvssBelow thresholds per version (#2563) (#8024)

  • feat: usage telemetry via scarf (#8066)

  • feat: add new suppression xsd allowing grouping of suppressions (#7957)

  • fix(ant): resolve relative paths against basedir (#8202)

  • fix: add hint for Elastic APM Java agent CPE mapping (#8200)

  • fix: Allow NVD data feed metadata downloads to fail on 1st Jan while logging correct errors (#8205)

  • fix(ant): resolve paths relative to basedir for suppression and output

  • fix: correct XML/JSON report CVSS field & HTML report URL mappings (#8156)

  • fix: log GrokAssembly output when dotnet invocation fails (#8141)

  • fix: correct reliability of Central etc (JCS cache) analyzers on Java 25/Docker by making CLI classpath deterministic (#8117)

  • docs: Update & correct README (#8166)

  • docs: update suppression schema version (#8136)

  • docs: fix typos in some files (#8135)

  • chore: remove duplicate suppression rules from base that are in the generated branch (#8138)

  • chore: remove suppression rules that were deleted from the generatedSuppression branch (#8119)

  • build: transition dependency to org.eclipse.parsson groupId (#8128)

  • See the full listing of changes

Commits
  • 909229e build: prepare release v12.2.0
  • f6f3d76 chore: reset snapshot version and fix site
  • 67d0d1a build: Release 12.2.0 (#8216)
  • 6f46091 build: prepare for next development iteration
  • 9ec772f build: prepare release v12.2.0
  • e81b240 docs: prepare release 12.2.0
  • 41f1cdf build(deps): bump junit.version from 5.14.1 to 5.14.2 (#8214)
  • 26cfd65 build(deps): bump org.sonatype.central:central-publishing-maven-plugin from 0...
  • f437aa0 fix(ant): resolve relative paths against basedir (#8202)
  • 7f63b48 Merge branch 'main' into fix-7918-ant-relative-paths
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the plugins group with 2 updates in the / directory: [com.puppycrawl.tools:checkstyle](https://github.com/checkstyle/checkstyle) and [org.owasp:dependency-check-maven](https://github.com/dependency-check/DependencyCheck).


Updates `com.puppycrawl.tools:checkstyle` from 12.3.0 to 13.0.0
- [Release notes](https://github.com/checkstyle/checkstyle/releases)
- [Commits](checkstyle/checkstyle@checkstyle-12.3.0...checkstyle-13.0.0)

Updates `org.owasp:dependency-check-maven` from 12.1.9 to 12.2.0
- [Release notes](https://github.com/dependency-check/DependencyCheck/releases)
- [Changelog](https://github.com/dependency-check/DependencyCheck/blob/main/CHANGELOG.md)
- [Commits](dependency-check/DependencyCheck@v12.1.9...v12.2.0)

---
updated-dependencies:
- dependency-name: com.puppycrawl.tools:checkstyle
  dependency-version: 13.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: plugins
- dependency-name: org.owasp:dependency-check-maven
  dependency-version: 12.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: plugins
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Jan 12, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant