From cfe0b3962bf457d35d935c857c2767969e91ed81 Mon Sep 17 00:00:00 2001 From: Jeremy Long Date: Mon, 1 Jul 2024 06:30:53 -0400 Subject: [PATCH 1/4] docs: prepare release --- CHANGELOG.md | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 7a27b56476b..a6820a60db3 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,5 +1,17 @@ # Change Log +## [Version 10.0.0](https://github.com/jeremylong/DependencyCheck/releases/tag/v10.0.0) (2024-07-01) + +- **breaking change**: upgrade to dotnet 8.0 (#6580) + - Users of the AssemblyAnalyzer must upgrade/utilize dotnet 8 to analyze assemblies +- feat: fix the NVD API related errors by adding cvssV4 support (#6756) +- fix: avoid escaping unnecessary chars in HTML report suppression regexes (#6749) +- fix: #6688 Trim version number when parsin POM (#6705) +- fix: change request if lockfile is file v3 (#6690) +- fix: skip pyproject.toml unless it contains `tool.poetry` before ensuring lockfiles (#6681) + +See the full listing of [changes](https://github.com/jeremylong/DependencyCheck/milestone/83?closed=1). + ## [Version 9.2.0](https://github.com/jeremylong/DependencyCheck/releases/tag/v9.2.0) (2024-05-15) - docs: update logo per intellj (#6660) From 2ce874a68167672176d13daefb4201673b3558cc Mon Sep 17 00:00:00 2001 From: Jeremy Long Date: Mon, 1 Jul 2024 06:32:05 -0400 Subject: [PATCH 2/4] build: prepare release v10.0.0 --- ant/pom.xml | 4 ++-- archetype/pom.xml | 6 +++--- cli/pom.xml | 4 ++-- core/pom.xml | 4 ++-- maven/pom.xml | 4 ++-- pom.xml | 6 +++--- utils/pom.xml | 4 ++-- 7 files changed, 16 insertions(+), 16 deletions(-) diff --git a/ant/pom.xml b/ant/pom.xml index f89306d9ed9..a8a561cc7d5 100644 --- a/ant/pom.xml +++ b/ant/pom.xml @@ -20,7 +20,7 @@ Copyright (c) 2013 - Jeremy Long. All Rights Reserved. org.owasp dependency-check-parent - 10.0.0-SNAPSHOT + 10.0.0 dependency-check-ant @@ -32,7 +32,7 @@ Copyright (c) 2013 - Jeremy Long. All Rights Reserved. scm:git:https://github.com/jeremylong/DependencyCheck.git https://github.com/jeremylong/DependencyCheck/tree/main/ant scm:git:git@github.com:jeremylong/DependencyCheck.git - v6.4.1 + v10.0.0 diff --git a/archetype/pom.xml b/archetype/pom.xml index e224f201ad2..da7d72674e4 100644 --- a/archetype/pom.xml +++ b/archetype/pom.xml @@ -20,20 +20,20 @@ Copyright (c) 2017 Jeremy Long. All Rights Reserved. org.owasp dependency-check-parent - 10.0.0-SNAPSHOT + 10.0.0 dependency-check-plugin Dependency-Check Plugin Archetype jar - 2024-05-15T09:29:26Z + 2024-07-01T10:31:20Z scm:git:https://github.com/jeremylong/DependencyCheck.git https://github.com/jeremylong/DependencyCheck/tree/main/archetype scm:git:git@github.com:jeremylong/DependencyCheck.git - HEAD + v10.0.0 diff --git a/cli/pom.xml b/cli/pom.xml index a4a6a98f6c3..e17d9bee21e 100644 --- a/cli/pom.xml +++ b/cli/pom.xml @@ -20,7 +20,7 @@ Copyright (c) 2012 - Jeremy Long. All Rights Reserved. org.owasp dependency-check-parent - 10.0.0-SNAPSHOT + 10.0.0 dependency-check-cli @@ -32,7 +32,7 @@ Copyright (c) 2012 - Jeremy Long. All Rights Reserved. scm:git:https://github.com/jeremylong/DependencyCheck.git https://github.com/jeremylong/DependencyCheck/tree/main/cli scm:git:git@github.com:jeremylong/DependencyCheck.git - v6.4.1 + v10.0.0 dependency-check-${project.version} diff --git a/core/pom.xml b/core/pom.xml index 6625cb7559a..5f3a69d5fdd 100644 --- a/core/pom.xml +++ b/core/pom.xml @@ -20,7 +20,7 @@ Copyright (c) 2012 Jeremy Long. All Rights Reserved. org.owasp dependency-check-parent - 10.0.0-SNAPSHOT + 10.0.0 dependency-check-core @@ -32,7 +32,7 @@ Copyright (c) 2012 Jeremy Long. All Rights Reserved. scm:git:https://github.com/jeremylong/DependencyCheck.git https://github.com/jeremylong/DependencyCheck/tree/main/core scm:git:git@github.com:jeremylong/DependencyCheck.git - v6.4.1 + v10.0.0 diff --git a/maven/pom.xml b/maven/pom.xml index e837237101a..3fb967a27d2 100644 --- a/maven/pom.xml +++ b/maven/pom.xml @@ -20,7 +20,7 @@ Copyright (c) 2013 Jeremy Long. All Rights Reserved. org.owasp dependency-check-parent - 10.0.0-SNAPSHOT + 10.0.0 dependency-check-maven maven-plugin @@ -34,7 +34,7 @@ Copyright (c) 2013 Jeremy Long. All Rights Reserved. scm:git:https://github.com/jeremylong/DependencyCheck.git https://github.com/jeremylong/DependencyCheck/tree/master/maven scm:git:git@github.com:jeremylong/DependencyCheck.git - v6.4.1 + v10.0.0 3.1.0 diff --git a/pom.xml b/pom.xml index ff0ac6c771e..5df1afcf3a0 100644 --- a/pom.xml +++ b/pom.xml @@ -20,7 +20,7 @@ Copyright (c) 2012 - Jeremy Long org.owasp dependency-check-parent - 10.0.0-SNAPSHOT + 10.0.0 pom @@ -94,7 +94,7 @@ Copyright (c) 2012 - Jeremy Long scm:git:https://github.com/jeremylong/DependencyCheck.git https://github.com/jeremylong/DependencyCheck scm:git:https://github.com/jeremylong/DependencyCheck.git - v6.4.1 + v10.0.0 github @@ -112,7 +112,7 @@ Copyright (c) 2012 - Jeremy Long - 2024-05-15T09:29:26Z + 2024-07-01T10:31:20Z UTF-8 UTF-8 github diff --git a/utils/pom.xml b/utils/pom.xml index 1f1ebd0b864..c3cade30256 100644 --- a/utils/pom.xml +++ b/utils/pom.xml @@ -20,7 +20,7 @@ Copyright (c) 2014 - Jeremy Long. All Rights Reserved. org.owasp dependency-check-parent - 10.0.0-SNAPSHOT + 10.0.0 dependency-check-utils @@ -30,7 +30,7 @@ Copyright (c) 2014 - Jeremy Long. All Rights Reserved. scm:git:https://github.com/jeremylong/DependencyCheck.git https://github.com/jeremylong/DependencyCheck/tree/main/utils scm:git:git@github.com:jeremylong/DependencyCheck.git - v6.4.1 + v10.0.0 org.owasp.dependencycheck.utils.* From 9053d1f5ee0ef253ea876b0315b62572558f7889 Mon Sep 17 00:00:00 2001 From: Jeremy Long Date: Mon, 1 Jul 2024 06:32:05 -0400 Subject: [PATCH 3/4] build: prepare for next development iteration --- ant/pom.xml | 4 ++-- archetype/pom.xml | 6 +++--- cli/pom.xml | 4 ++-- core/pom.xml | 4 ++-- maven/pom.xml | 4 ++-- pom.xml | 6 +++--- utils/pom.xml | 4 ++-- 7 files changed, 16 insertions(+), 16 deletions(-) diff --git a/ant/pom.xml b/ant/pom.xml index a8a561cc7d5..7313462a506 100644 --- a/ant/pom.xml +++ b/ant/pom.xml @@ -20,7 +20,7 @@ Copyright (c) 2013 - Jeremy Long. All Rights Reserved. org.owasp dependency-check-parent - 10.0.0 + 10.0.1-SNAPSHOT dependency-check-ant @@ -32,7 +32,7 @@ Copyright (c) 2013 - Jeremy Long. All Rights Reserved. scm:git:https://github.com/jeremylong/DependencyCheck.git https://github.com/jeremylong/DependencyCheck/tree/main/ant scm:git:git@github.com:jeremylong/DependencyCheck.git - v10.0.0 + v6.4.1 diff --git a/archetype/pom.xml b/archetype/pom.xml index da7d72674e4..5ae18af7892 100644 --- a/archetype/pom.xml +++ b/archetype/pom.xml @@ -20,20 +20,20 @@ Copyright (c) 2017 Jeremy Long. All Rights Reserved. org.owasp dependency-check-parent - 10.0.0 + 10.0.1-SNAPSHOT dependency-check-plugin Dependency-Check Plugin Archetype jar - 2024-07-01T10:31:20Z + 2024-07-01T10:32:05Z scm:git:https://github.com/jeremylong/DependencyCheck.git https://github.com/jeremylong/DependencyCheck/tree/main/archetype scm:git:git@github.com:jeremylong/DependencyCheck.git - v10.0.0 + HEAD diff --git a/cli/pom.xml b/cli/pom.xml index e17d9bee21e..0fcbc262065 100644 --- a/cli/pom.xml +++ b/cli/pom.xml @@ -20,7 +20,7 @@ Copyright (c) 2012 - Jeremy Long. All Rights Reserved. org.owasp dependency-check-parent - 10.0.0 + 10.0.1-SNAPSHOT dependency-check-cli @@ -32,7 +32,7 @@ Copyright (c) 2012 - Jeremy Long. All Rights Reserved. scm:git:https://github.com/jeremylong/DependencyCheck.git https://github.com/jeremylong/DependencyCheck/tree/main/cli scm:git:git@github.com:jeremylong/DependencyCheck.git - v10.0.0 + v6.4.1 dependency-check-${project.version} diff --git a/core/pom.xml b/core/pom.xml index 5f3a69d5fdd..632a125fa3d 100644 --- a/core/pom.xml +++ b/core/pom.xml @@ -20,7 +20,7 @@ Copyright (c) 2012 Jeremy Long. All Rights Reserved. org.owasp dependency-check-parent - 10.0.0 + 10.0.1-SNAPSHOT dependency-check-core @@ -32,7 +32,7 @@ Copyright (c) 2012 Jeremy Long. All Rights Reserved. scm:git:https://github.com/jeremylong/DependencyCheck.git https://github.com/jeremylong/DependencyCheck/tree/main/core scm:git:git@github.com:jeremylong/DependencyCheck.git - v10.0.0 + v6.4.1 diff --git a/maven/pom.xml b/maven/pom.xml index 3fb967a27d2..aa5e161b9a5 100644 --- a/maven/pom.xml +++ b/maven/pom.xml @@ -20,7 +20,7 @@ Copyright (c) 2013 Jeremy Long. All Rights Reserved. org.owasp dependency-check-parent - 10.0.0 + 10.0.1-SNAPSHOT dependency-check-maven maven-plugin @@ -34,7 +34,7 @@ Copyright (c) 2013 Jeremy Long. All Rights Reserved. scm:git:https://github.com/jeremylong/DependencyCheck.git https://github.com/jeremylong/DependencyCheck/tree/master/maven scm:git:git@github.com:jeremylong/DependencyCheck.git - v10.0.0 + v6.4.1 3.1.0 diff --git a/pom.xml b/pom.xml index 5df1afcf3a0..7be50c7f728 100644 --- a/pom.xml +++ b/pom.xml @@ -20,7 +20,7 @@ Copyright (c) 2012 - Jeremy Long org.owasp dependency-check-parent - 10.0.0 + 10.0.1-SNAPSHOT pom @@ -94,7 +94,7 @@ Copyright (c) 2012 - Jeremy Long scm:git:https://github.com/jeremylong/DependencyCheck.git https://github.com/jeremylong/DependencyCheck scm:git:https://github.com/jeremylong/DependencyCheck.git - v10.0.0 + v6.4.1 github @@ -112,7 +112,7 @@ Copyright (c) 2012 - Jeremy Long - 2024-07-01T10:31:20Z + 2024-07-01T10:32:05Z UTF-8 UTF-8 github diff --git a/utils/pom.xml b/utils/pom.xml index c3cade30256..06360afa8d2 100644 --- a/utils/pom.xml +++ b/utils/pom.xml @@ -20,7 +20,7 @@ Copyright (c) 2014 - Jeremy Long. All Rights Reserved. org.owasp dependency-check-parent - 10.0.0 + 10.0.1-SNAPSHOT dependency-check-utils @@ -30,7 +30,7 @@ Copyright (c) 2014 - Jeremy Long. All Rights Reserved. scm:git:https://github.com/jeremylong/DependencyCheck.git https://github.com/jeremylong/DependencyCheck/tree/main/utils scm:git:git@github.com:jeremylong/DependencyCheck.git - v10.0.0 + v6.4.1 org.owasp.dependencycheck.utils.* From e31d456ec564e5e7bfdf0a23f0ae3b7663d5b48f Mon Sep 17 00:00:00 2001 From: Jeremy Long Date: Mon, 1 Jul 2024 06:37:16 -0400 Subject: [PATCH 4/4] Update CHANGELOG.md --- CHANGELOG.md | 1 + 1 file changed, 1 insertion(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index a6820a60db3..28afe4e40de 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -5,6 +5,7 @@ - **breaking change**: upgrade to dotnet 8.0 (#6580) - Users of the AssemblyAnalyzer must upgrade/utilize dotnet 8 to analyze assemblies - feat: fix the NVD API related errors by adding cvssV4 support (#6756) + - **breaking changes**: anyone utilizing a centralized database will need to upgrade the schema; see changes in [PR #6756](https://github.com/jeremylong/DependencyCheck/pull/6756/files#diff-ca432c4b41d39caa84d140e06694b09c7e6394c8a2db72ba27516dc77ee3bd67) - fix: avoid escaping unnecessary chars in HTML report suppression regexes (#6749) - fix: #6688 Trim version number when parsin POM (#6705) - fix: change request if lockfile is file v3 (#6690)