Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 19, 2026

Bumps org.codehaus.mojo:versions-maven-plugin from 2.5 to 2.21.0.

Release notes

Sourced from org.codehaus.mojo:versions-maven-plugin's releases.

2.21.0

🚀 New features and improvements

🐛 Bug Fixes

  • #1331: Fix NPE in restrictionForUnchangedSegment if actual version is null (#1332) @​andrzejj0
  • #1310: Corrected UseDepVersionMojo + handling a similar case in SetMojo, SetScmTagMojo, UpdateChildModulesMojo (#1322) @​andrzejj0
  • UseDepVersionMoto should process all projects on the project list (#1320) @​andrzejj0
  • Fixed #1317: Regression coming from ArtifactVersions::filter when currentVersion is null and ignoredVersions is not null (#1319) @​andrzejj0

📝 Documentation updates

📦 Dependency updates

2.20.1

🐛 Bug Fixes

2.20.0

🚀 New features and improvements

🐛 Bug Fixes

📝 Documentation updates

... (truncated)

Changelog

Sourced from org.codehaus.mojo:versions-maven-plugin's changelog.

Release Notes

2.6

  • [Pull Request #252][pull-252]

    Thanks to Edward Maxwell-Lyte 2248005+edwardmlyte@users.noreply.github.com

    Minor spelling corrections

  • [Fixed Issue 157][issue-157]

    Document the end of versioning limitations in Maven 3.x There may remain good reasons for defining custom versioning rules to let versions-maven-plugin apply, but at least not the old Maven 2.x limitation

  • [Fixed Issue 256][issue-256]

    if initial and new version are equals, just display initial this means this is a plugin version that requires a Maven version that is not compatible with project minimum version, not really a proposed upgrade

  • [Fixed Issue 237][issue-237]

    Thanks to Julian Di Leonardo DiJu519@users.noreply.github.com

    Adding parent processing to UseLatestVersion/UseLatestSnapshot/UseLatestRelease

  • [Fixed Issue 190][issue-190]

    Thanks to Julian Di Leonardo DiJu519@users.noreply.github.com

    Fixing issue in update-child-modules, where root module's version was being used in all downstream children even when a child's parent was different.

  • [Fixed Issue 219][issue-219]

    Added threadSafe=true to goals to prevent warning in Maven builds if you start Maven via: mvn -T ..

  • [Fixed Issue 215][issue-215]

Commits
  • 1cdedea [maven-release-plugin] prepare release 2.21.0
  • b947957 Fix README typos in Contributing section
  • b85c0a8 Bump project version to 2.21.0-SNAPSHOT
  • 7ae3767 Bump byteBuddyVersion from 1.18.3 to 1.18.4 (#1335)
  • 38afa9f Bump org.apache.maven.plugin-testing:maven-plugin-testing-harness
  • 39af6a2 Bump org.codehaus.plexus:plexus-archiver from 4.10.4 to 4.11.0
  • f51b9d5 #1331: Fix NPE in restrictionForUnchangedSegment if actual version is null (#...
  • 8d209b3 Bump org.codehaus.mojo:mojo-parent from 94 to 95 (#1330)
  • 4929d48 Bump byteBuddyVersion from 1.18.2 to 1.18.3 (#1329)
  • cb84d01 Add versions.skip parameter to skip plugin execution (#1328)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [org.codehaus.mojo:versions-maven-plugin](https://github.com/mojohaus/versions) from 2.5 to 2.21.0.
- [Release notes](https://github.com/mojohaus/versions/releases)
- [Changelog](https://github.com/mojohaus/versions/blob/master/ReleaseNotes.md)
- [Commits](mojohaus/versions@versions-maven-plugin-2.5...2.21.0)

---
updated-dependencies:
- dependency-name: org.codehaus.mojo:versions-maven-plugin
  dependency-version: 2.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Jan 19, 2026
@github-actions
Copy link

PR: #38
Mode: squash
Topic: GH-sandbox-38
Change-Ids:
I1254299b3f3063b118be371d8d66f01a2de93a8a
Digest: 80e4c057d09c
GitHub-Hash: c2616a3f089b3fce

Note: This metadata is also included in the Gerrit commit message for reconciliation.

@github-actions
Copy link

Change raised in Gerrit by GitHub2Gerrit: https://gerrit.linuxfoundation.org/infra/c/sandbox/+/74063

lfit-replication pushed a commit that referenced this pull request Jan 29, 2026
…5 to 2.21.0

Bumps org.codehaus.mojo:versions-maven-plugin from 2.5 to 2.21.0.
## Release notes

Sourced from org.codehaus.mojo:versions-maven-plugin's releases.

2.21.0

🚀 New features and improvements

Add versions.skip parameter to skip plugin execution (#1328) @​jorgheymans

🐛 Bug Fixes

#1331: Fix NPE in restrictionForUnchangedSegment if actual version is null (#1332) @​andrzejj0
#1310: Corrected UseDepVersionMojo + handling a similar case in SetMojo, SetScmTagMojo, UpdateChildModulesMojo (#1322) @​andrzejj0
UseDepVersionMoto should process all projects on the project list (#1320) @​andrzejj0
Fixed #1317: Regression coming from ArtifactVersions::filter when currentVersion is null and ignoredVersions is not null (#1319) @​andrzejj0

📝 Documentation updates

Fix README typos in Contributing section (#1337) @​kranthipoturaju
#1323: Documentation (#1324) @​andrzejj0

📦 Dependency updates

Bump byteBuddyVersion from 1.18.3 to 1.18.4 (#1335) @dependabot[bot]
Bump org.apache.maven.plugin-testing:maven-plugin-testing-harness from 3.4.0 to 3.5.0 (#1333) @dependabot[bot]
Bump org.codehaus.plexus:plexus-archiver from 4.10.4 to 4.11.0 (#1334) @dependabot[bot]
Bump org.codehaus.mojo:mojo-parent from 94 to 95 (#1330) @dependabot[bot]
Bump byteBuddyVersion from 1.18.2 to 1.18.3 (#1329) @dependabot[bot]
Bump org.apache.commons:commons-text from 1.14.0 to 1.15.0 (#1325) @dependabot[bot]
Bump byteBuddyVersion from 1.18.1 to 1.18.2 (#1318) @dependabot[bot]

2.20.1

🐛 Bug Fixes

Fixed #1313: Do not show existing version as update (#1315) @​andrzejj0

2.20.0

🚀 New features and improvements

Allow filtering out pre releases in use-latest-versions (#1283) @​Artur-
#979: Output file is not overwritten by default (#1279) @​andrzejj0

🐛 Bug Fixes

Fixed a problem with dependency management filtering in the logged results (#1298) @​andrzejj0
Fixes #1295: getAllUpdates(boolean) should respect currentVersionRange (#1297) @​andrzejj0

Fixed #1287 - Versionless dependencies in dependencyManagement accepted by maven, but not bij resolve-ranges (#1288) @​maroschutte
Artifact comparison should use semantic version comparison. (#1281) @​andrzejj0
Resolves #1150: Resolve multiple level properties (properties resolving to properties) (#1276) @​andrzejj0

📝 Documentation updates

... (truncated)

## Changelog

Sourced from org.codehaus.mojo:versions-maven-plugin's changelog.

Release Notes
2.6

[Pull Request #252][pull-252]
Thanks to Edward Maxwell-Lyte 2248005+edwardmlyte@users.noreply.github.com
Minor spelling corrections

[Fixed Issue 157][issue-157]
Document the end of versioning limitations in Maven 3.x
There may remain good reasons for defining custom versioning rules to
let versions-maven-plugin apply, but at least not the old Maven 2.x
limitation

[Fixed Issue 256][issue-256]
if initial and new version are equals, just display initial
this means this is a plugin version that requires a Maven version that
is not compatible with project minimum version, not really a proposed
upgrade

[Fixed Issue 237][issue-237]
Thanks to Julian Di Leonardo DiJu519@users.noreply.github.com
Adding parent processing to UseLatestVersion/UseLatestSnapshot/UseLatestRelease

[Fixed Issue 190][issue-190]
Thanks to Julian Di Leonardo DiJu519@users.noreply.github.com
Fixing issue in update-child-modules, where root module's version was
being used in all downstream children even when a child's parent was
different.

[Fixed Issue 219][issue-219]
Added threadSafe=true to goals to prevent
warning in Maven builds if you start Maven
via: mvn -T ..

[Fixed Issue 215][issue-215]

## Commits

1cdedea [maven-release-plugin] prepare release 2.21.0
b947957 Fix README typos in Contributing section
b85c0a8 Bump project version to 2.21.0-SNAPSHOT
7ae3767 Bump byteBuddyVersion from 1.18.3 to 1.18.4 (#1335)
38afa9f Bump org.apache.maven.plugin-testing:maven-plugin-testing-harness
39af6a2 Bump org.codehaus.plexus:plexus-archiver from 4.10.4 to 4.11.0
f51b9d5 #1331: Fix NPE in restrictionForUnchangedSegment if actual version is null (#
8d209b3 Bump org.codehaus.mojo:mojo-parent from 94 to 95 (#1330)
4929d48 Bump byteBuddyVersion from 1.18.2 to 1.18.3 (#1329)
cb84d01 Add versions.skip parameter to skip plugin execution (#1328)
Additional commits viewable in compare view

![Dependabot compatibility score](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)

Issue-ID: CIMAN-33
Signed-off-by: dependabot[bot] <support@github.com>
Change-Id: I1254299b3f3063b118be371d8d66f01a2de93a8a
GitHub-PR: #38
GitHub-Hash: c2616a3f089b3fce
Signed-off-by: lfit.gh2gerrit <releng+lfit-gh2gerrit@linuxfoundation.org>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants