Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update dependency com.google.errorprone:error_prone_core to v2.22.0 (master) #1789

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

mend-for-github-com[bot]
Copy link

@mend-for-github-com mend-for-github-com bot commented Jun 19, 2023

This PR contains the following updates:

Package Type Update Change
com.google.errorprone:error_prone_core (source) dependencies minor 2.18.0 -> 2.22.0

By merging this PR, the issue #1611 will be automatically resolved and closed:

Severity CVSS Score CVE
High High 7.5 CVE-2022-3171
High High 7.5 CVE-2022-3509
High High 7.5 CVE-2022-3510

By merging this PR, the below vulnerabilities will be automatically resolved:

Severity CVSS Score CVE
High High 8.8 CVE-2023-4759

Release Notes

google/error-prone (com.google.errorprone:error_prone_core)

v2.22.0: Error Prone 2.22.0

We are considering raising the minimum supported JDK from JDK 11 to JDK 17 in a future release of Error Prone, see #​3803. Note that using a newer JDK version to run javac during the build doesn't prevent building code that is deployed to earlier versions, for example it's supported to use the JDK 17 javac and pass --release 11 to compile Java 11 code that is deployed to a JDK 11 runtime. If you have feedback, please comment on #​3803.

New checks:

Bug fixes and improvements:

  • Don't complain about literal IP addresses in AddressSelection (google/error-prone@44b6552)
  • Prevent SuggestedFixes#renameMethod from modifying return type declaration (#​4043)
  • Fix UnusedVariable false positives for private record parameters (#​2713)
  • When running in conservative mode, no longer assume that implementations of Map.get, etc. return null (#​2910)
  • CanIgnoreReturnValueSuggester: Support additional exempting method annotations (#​4009)
  • UnusedVariable: exclude junit5's @RegisterExtension (#​3892)
  • Support running all available patch checks (#​947)
  • Upgrade java-diff-utils 4.0 -> 4.12 (#​4081)
  • Flag unused Refaster template parameters (#​4060)
  • Support @SuppressWarnings("all") (#​4065)
  • Prevent Refaster UMemberSelect from matching method parameters (#​2456)
  • MissingDefault : Don't require // fall out comments on expression switches (#​2709)
  • Skip UnnecessaryLambda findings for usages in enhanced for loops (#​2518)
  • Fix bug where nested MissingBraces violations' suggested fixes result in broken code (#​3797)
  • Add support for specifying exemptPrefixes/exemptNames for UnusedVariable via flags (#​2753)
  • UnusedMethod: Added exempting variable annotations (#​2881)

Full Changelog: google/error-prone@v2.21.1...v2.22.0

v2.21.1: Error Prone 2.21.1

Changes:

  • Handle overlapping ranges in suppressedRegions (fixes #​4040)
  • Add AddressSelection to discourage APIs that convert a hostname to a single address

Full Changelog: google/error-prone@v2.21.0...v2.21.1

v2.21.0: Error Prone 2.21.0

New Checkers:

Fixed issues: #​3976, #​3986, #​4001, #​4002, #​4026, #​4027

Full Changelog: google/error-prone@v2.20.0...v2.21.0

v2.20.0: Error Prone 2.20.0

Changes:

  • This release is compatible with early-access builds of JDK 21.

New Checkers:

Fixes issues: #​2232, #​2243, #​2997, #​3301, #​3843, #​3903, #​3918, #​3923, #​3931, #​3945, #​3946

Full Changelog: google/error-prone@v2.19.1...v2.20.0

v2.19.1: Error Prone 2.19.1

This release fixes a binary compatibility issue when running on JDK 11, see #​3895

Full Changelog: google/error-prone@v2.19.0...v2.19.1

v2.19.0: Error Prone 2.19.0

New Checkers:

Fixes issues: #​956, #​3504, #​3654, #​3703, #​3731, #​3737, #​3760, #​3779, #​3796, #​3809, #​3813

Full Changelog: google/error-prone@v2.18.0...v2.19.0


  • If you want to rebase/retry this PR, check this box

@mend-for-github-com mend-for-github-com bot requested a review from a team as a code owner June 19, 2023 00:41
@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by WhiteSource label Jun 19, 2023
@CLAassistant
Copy link

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

@@ -5,7 +5,7 @@ subprojects {
dependencies {
errorproneJavac('com.google.errorprone:javac:9+181-r4173-1')
if (JavaVersion.current().isJava11Compatible()) {
errorprone('com.google.errorprone:error_prone_core:2.18.0')
errorprone('com.google.errorprone:error_prone_core:2.20.0')

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Who approves and merges this PR? considering there are some test failures?

@mend-for-github-com mend-for-github-com bot changed the title Update dependency com.google.errorprone:error_prone_core to v2.20.0 (master) chore(deps): update dependency com.google.errorprone:error_prone_core to v2.20.0 (master) Jul 17, 2023
@mend-for-github-com mend-for-github-com bot changed the title chore(deps): update dependency com.google.errorprone:error_prone_core to v2.20.0 (master) Update dependency com.google.errorprone:error_prone_core to v2.20.0 (master) Oct 3, 2023
@mend-for-github-com mend-for-github-com bot force-pushed the whitesource-remediate/master-com.google.errorprone-error_prone_core-2.x branch from ae015fe to 7156d87 Compare February 16, 2024 18:07
@mend-for-github-com mend-for-github-com bot changed the title Update dependency com.google.errorprone:error_prone_core to v2.20.0 (master) Update dependency com.google.errorprone:error_prone_core to v2.22.0 (master) Feb 16, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security fix Security fix generated by WhiteSource
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants