Skip to content

Conversation

@renovate-bot
Copy link

@renovate-bot renovate-bot commented Apr 26, 2024

Welcome to Renovate! This is an onboarding PR to help you understand and configure settings before regular Pull Requests begin.

🚦 To activate Renovate, merge this Pull Request. To disable Renovate, simply close this Pull Request unmerged.


Detected Package Files

  • .github/workflows/unit-tests.yaml (github-actions)
  • app-gradle-plugin/settings.gradle.kts (gradle)
  • app-gradle-plugin/build.gradle.kts (gradle)
  • app-gradle-plugin/src/integTest/resources/projects/appyaml-project/build.gradle (gradle)
  • app-gradle-plugin/src/integTest/resources/projects/sourcecontext-project/build.gradle (gradle)
  • app-gradle-plugin/src/integTest/resources/projects/standard-project-java8/build.gradle (gradle)
  • app-gradle-plugin/gradle/wrapper/gradle-wrapper.properties (gradle-wrapper)
  • app-maven-plugin/pom.xml (maven)
  • appengine-plugins-core/pom.xml (maven)
  • pom.xml (maven)
  • .mvn/wrapper/maven-wrapper.properties (maven-wrapper)

Configuration Summary

Based on the default config's presets, Renovate will:

  • Start dependency updates only once this onboarding PR is merged
  • Hopefully safe environment variables to allow users to configure.
  • Show all Merge Confidence badges for pull requests.
  • Enable Renovate Dependency Dashboard creation.
  • Use semantic commit type fix for dependencies and chore for all others if semantic commits are in use.
  • Ignore node_modules, bower_components, vendor and various test/tests (except for nuget) directories.
  • Group known monorepo packages together.
  • Use curated list of recommended non-monorepo package groupings.
  • Show only the Age and Confidence Merge Confidence badges for pull requests.
  • Apply crowd-sourced package replacement rules.
  • Apply crowd-sourced workarounds for known problems with packages.
  • Ensure that every dependency pinned by digest and sourced from GitHub.com contains a link to the commit-to-commit diff
  • Correctly link to the source code for golang.org/x packages
  • Link to pkg.go.dev/... for golang.org/x packages' title

🔡 Do you want to change how Renovate upgrades your dependencies? Add your custom config to renovate.json in this branch. Renovate will update the Pull Request description the next time it runs.


What to Expect

With your current configuration, Renovate will create 55 Pull Requests:

chore(deps): update dependency com.google.cloud.artifactregistry:artifactregistry-maven-wagon to v2.2.5
chore(deps): update dependency maven to v3.9.12
  • Schedule: ["at any time"]
  • Branch name: renovate/maven-3.x
  • Merge into: main
  • Upgrade maven to 3.9.12
chore(deps): update dependency org.apache.maven.plugins:maven-deploy-plugin to v3.1.4
chore(deps): update dependency org.apache.maven.plugins:maven-gpg-plugin to v3.2.8
chore(deps): update dependency org.jacoco:jacoco-maven-plugin to v0.8.14
  • Schedule: ["at any time"]
  • Branch name: renovate/org.jacoco-jacoco-maven-plugin-0.x
  • Merge into: main
  • Upgrade org.jacoco:jacoco-maven-plugin to 0.8.14
chore(deps): update gradle to v6.9.4
  • Schedule: ["at any time"]
  • Branch name: renovate/gradle-6.x
  • Merge into: main
  • Upgrade gradle to 6.9.4
chore(deps): update plugin com.google.cloud.artifactregistry.gradle-plugin to v2.2.5
  • Schedule: ["at any time"]
  • Branch name: renovate/com.google.cloud.artifactregistry.gradle-plugin-2.x
  • Merge into: main
  • Upgrade com.google.cloud.artifactregistry.gradle-plugin to 2.2.5
fix(deps): update dependency com.google.guava:guava to v32.1.3-jre
  • Schedule: ["at any time"]
  • Branch name: renovate/guava-monorepo
  • Merge into: main
  • Upgrade com.google.guava:guava to 32.1.3-jre
fix(deps): update dependency jacoco to v0.8.14
  • Schedule: ["at any time"]
  • Branch name: renovate/jacoco-0.x
  • Merge into: main
  • Upgrade jacoco to 0.8.14
fix(deps): update maven.version to v3.9.12
chore(deps): update dependency com.coveo:fmt-maven-plugin to v2.13
  • Schedule: ["at any time"]
  • Branch name: renovate/com.coveo-fmt-maven-plugin-2.x
  • Merge into: main
  • Upgrade com.coveo:fmt-maven-plugin to 2.13
chore(deps): update dependency com.github.spotbugs:spotbugs-maven-plugin to v4.9.8.2
chore(deps): update dependency com.google.cloud.tools:linkage-checker-enforcer-rules to v0.3.0
chore(deps): update dependency com.google.errorprone:error_prone_core to v2.45.0
chore(deps): update dependency com.google.googlejavaformat:google-java-format to v1.33.0
chore(deps): update dependency com.puppycrawl.tools:checkstyle to v8.45.1
chore(deps): update dependency com.puppycrawl.tools:checkstyle to v10.26.1
chore(deps): update dependency com.uber.nullaway:nullaway to v0.12.15
  • Schedule: ["at any time"]
  • Branch name: renovate/com.uber.nullaway-nullaway-0.x
  • Merge into: main
  • Upgrade com.uber.nullaway:nullaway to 0.12.15
chore(deps): update dependency org.apache.maven.plugins:maven-checkstyle-plugin to v3.6.0
chore(deps): update dependency org.apache.maven.plugins:maven-compiler-plugin to v3.14.1
chore(deps): update dependency org.apache.maven.plugins:maven-enforcer-plugin to v3.6.2
chore(deps): update dependency org.apache.maven.plugins:maven-failsafe-plugin to v3.5.4
chore(deps): update dependency org.apache.maven.plugins:maven-jar-plugin to v3.5.0
chore(deps): update dependency org.apache.maven.plugins:maven-javadoc-plugin to v3.12.0
chore(deps): update dependency org.apache.maven.plugins:maven-plugin-plugin to v3.15.2
chore(deps): update dependency org.apache.maven.plugins:maven-pmd-plugin to v3.28.0
chore(deps): update dependency org.apache.maven.plugins:maven-source-plugin to v3.4.0
chore(deps): update dependency org.apache.maven.plugins:maven-surefire-plugin to v3.5.4
chore(deps): update dependency org.apache.maven.shared:maven-verifier to v1.8.0
chore(deps): update dependency org.codehaus.mojo:exec-maven-plugin to v3.6.3
chore(deps): update dependency org.sonatype.plugins:nexus-staging-maven-plugin to v1.7.0
chore(deps): update mockito monorepo
chore(deps): update plugin net.researchgate.release to v2.8.1
  • Schedule: ["at any time"]
  • Branch name: renovate/net.researchgate.release-2.x
  • Merge into: main
  • Upgrade net.researchgate.release to 2.8.1
fix(deps): update dependency checkstyle to v8.45.1
  • Schedule: ["at any time"]
  • Branch name: renovate/checkstyle-8.x
  • Merge into: main
  • Upgrade checkstyle to 8.45.1
fix(deps): update dependency com.google.code.gson:gson to v2.13.2
  • Schedule: ["at any time"]
  • Branch name: renovate/com.google.code.gson-gson-2.x
  • Merge into: main
  • Upgrade com.google.code.gson:gson to 2.13.2
fix(deps): update dependency commons-io:commons-io to v2.21.0
  • Schedule: ["at any time"]
  • Branch name: renovate/commons-io-commons-io-2.x
  • Merge into: main
  • Upgrade commons-io:commons-io to 2.21.0
fix(deps): update dependency googlejavaformat to v1.33.0
  • Schedule: ["at any time"]
  • Branch name: renovate/googlejavaformat-1.x
  • Merge into: main
  • Upgrade googleJavaFormat to 1.33.0
fix(deps): update dependency org.apache.commons:commons-lang3 to v3.20.0
fix(deps): update dependency org.apache.maven.plugin-tools:maven-plugin-annotations to v3.15.2
fix(deps): update dependency org.yaml:snakeyaml to v2.5
  • Schedule: ["at any time"]
  • Branch name: renovate/org.yaml-snakeyaml-2.x
  • Merge into: main
  • Upgrade org.yaml:snakeyaml to 2.5
chore(deps): update actions/cache action to v5
  • Schedule: ["at any time"]
  • Branch name: renovate/actions-cache-5.x
  • Merge into: main
  • Upgrade actions/cache to v5
chore(deps): update actions/checkout action to v6
  • Schedule: ["at any time"]
  • Branch name: renovate/actions-checkout-6.x
  • Merge into: main
  • Upgrade actions/checkout to v6
chore(deps): update actions/setup-java action to v5
  • Schedule: ["at any time"]
  • Branch name: renovate/actions-setup-java-5.x
  • Merge into: main
  • Upgrade actions/setup-java to v5
chore(deps): update dependency com.google.cloud.tools:linkage-checker-enforcer-rules to v1
chore(deps): update dependency com.puppycrawl.tools:checkstyle to v12
chore(deps): update dependency org.apache.felix:maven-bundle-plugin to v6
chore(deps): update google-github-actions/setup-gcloud action to v3
chore(deps): update gradle to v9
  • Schedule: ["at any time"]
  • Branch name: renovate/gradle-9.x
  • Merge into: main
  • Upgrade gradle to 9.2.1
chore(deps): update plugin io.github.gradle-nexus.publish-plugin to v2
  • Schedule: ["at any time"]
  • Branch name: renovate/io.github.gradle-nexus.publish-plugin-2.x
  • Merge into: main
  • Upgrade io.github.gradle-nexus.publish-plugin to 2.0.0
chore(deps): update plugin net.researchgate.release to v3
  • Schedule: ["at any time"]
  • Branch name: renovate/net.researchgate.release-3.x
  • Merge into: main
  • Upgrade net.researchgate.release to 3.1.0
fix(deps): update dependency checkstyle to v12
  • Schedule: ["at any time"]
  • Branch name: renovate/checkstyle-12.x
  • Merge into: main
  • Upgrade checkstyle to 12.3.1
fix(deps): update dependency com.google.guava:guava to v33
  • Schedule: ["at any time"]
  • Branch name: renovate/major-guava-monorepo
  • Merge into: main
  • Upgrade com.google.guava:guava to 33.5.0-jre
fix(deps): update dependency javax.servlet:javax.servlet-api to v4
fix(deps): update dependency org.mockito:mockito-core to v5
  • Schedule: ["at any time"]
  • Branch name: renovate/major-mockito-monorepo
  • Merge into: main
  • Upgrade org.mockito:mockito-core to 5.21.0
fix(deps): update javahamcrest monorepo to v3 (major)

🚸 Branch creation will be limited to maximum 2 per hour, so it doesn't swamp any CI resources or overwhelm the project. See docs for prhourlylimit for details.


❓ Got questions? Check out Renovate's Docs, particularly the Getting Started section.
If you need any further assistance then you can also request help here.


This PR was generated by Mend Renovate. View the repository job log.

@ludoch
Copy link
Collaborator

ludoch commented Nov 18, 2025

Fixing such pull would have avoided recent bug for obsolete and insecure deps.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants