Releases: chains-project/maven-lockfile
Releases · chains-project/maven-lockfile
Release v5.6.0
Changelog
🚀 Added
- 03b1003 ✨ feat: Add exactVersionString to freeze target (#1204)
- ce475db ✨ feat: Add
sha256
andsha512
checksums to remote mode (#1200) - 2f5bf2c 👷 ci: Add githubusercontent release-assets to harden runner allowlists (#1252)
- de9b046 👷 ci: Update gha.sum in CI for all PRs (#1245)
- 40211d8 👷 ci: Remove ghasum binary after checksum verification (#1244)
🔄️ Changed
- d98e4c9 🚸 feat: Change default checksumMode from local to remote (#1199)
- ed338e7 💬 format: Format all checksums with capital letters (#1255)
📦 Dependencies
- 40d9be9 ⬆️ (deps): Update step-security/harden-runner action to v2.12.1 (#1247)
- 6bd867d ⬆️ (deps): Update dependency org.apache.logging.log4j:log4j-core to v2.25.0 (#1253)
- 9fcb067 ⬆️ (deps): Update stefanzweifel/git-auto-commit-action action to v6.0.1 (#1250)
- 7fd5c73 ⬆️ (deps): Update stefanzweifel/git-auto-commit-action action to v6 (#1249)
- 79960ef ⬆️ (deps): Update github/codeql-action action to v3.29.0 (#1248)
- 45f0ddd ⬆️ (deps): Update junit5 monorepo to v5.13.1 (#1242)
🏁 Release
Contributors
We'd like to thank the following people for their contributions:
- Aman Sharma ()
- Elias Lundell (@LogFlames)
- LogFlames (@LogFlames)
Release v5.5.3
Changelog
🚀 Added
- 737536f 👷 cd: Remove CD and verify OSSRH migration (#1240)
- 8085f2a 👷 cd: Only deploy snapshots (#1239)
- 6767d46 👷 cd: Migration to Maven Central Publisher API and CD (#1217)
- 49b9f6c 👷 ci: Add minimum release age of 1d to renovate (#1238)
- 0108499 👷 ci: Trigger ghasum update action for renovate PRs (#1237)
- 54d8ead 👷 ci: Trigger ghasum on PR from renovate instead of branches (#1236)
- a686b04 👷 ci: Automatically update gha.sum on Renovate PR (#1233)
- 167ad68 👷 ci: Remove renovate pinGitHubActionDigests helper (#1232)
- 8ad77c7 👷 ci: Update gha.sum for #1227 (#1229)
- 1f23a67 👷 ci: Reset ossf/scorecard to without ghasum to only include allowlisted steps (#1227)
- 158aa00 👷 ci: Add repo.spring.io to allowlisted endpoints for ossf/scorecard (#1224)
- ef8a587 👷 ci: Remove pinDigest update from Renovate (#1221)
- fb0b6cd 👷 ci: Add ghasum to github workflows (#1211)
- 994e796 👷 ci: Use latest maven lockfile action (v5.5.2) (#1202)
📦 Dependencies
- 8b77244 ⬆️ (deps): Update stefanzweifel/git-auto-commit-action action to v5.2.0 (#1234)
- b55ba83 ⬆️ (deps): Update github/codeql-action action to v3.28.19 (#1222)
- 040f6bb ⬆️ (config): migrate renovate config (#1228)
- 9474a05 ⬆️ (deps): Update dependency org.apache.maven.plugins:maven-clean-plugin to v3.5.0 (#1216)
- 8ce4b28 ⬆️ (deps): Update ossf/scorecard-action action to v2.4.2 (#1215)
- 65490ae ⬆️ (deps): Update junit5 monorepo to v5.13.0 (#1214)
- 09fb977 ⬆️ (deps): Update dependency com.diffplug.spotless:spotless-maven-plugin to v2.44.5 (#1212)
- 8e0a5e9 ⬆️ (deps): Update dependency org.apache.groovy:groovy to v4.0.27 (#1210)
- d563a05 ⬆️ (deps): Update dependency org.apache.maven.resolver:maven-resolver-api to v2.0.9 (#1209)
- c9dbc9f ⬆️ (deps): Update github/codeql-action action to v3.28.18 (#1208)
- edf641b ⬆️ (deps): Update actions/dependency-review-action action to v4.7.1 (#1207)
- 6ad9a16 ⬆️ (deps): Update actions/dependency-review-action action to v4.7.0 (#1206)
- 783131a ⬆️ (deps): Update actions/setup-go action to v5.5.0 (#1205)
📝 Documentation
🏁 Release
Contributors
We'd like to thank the following people for their contributions:
- Elias Lundell (@LogFlames)
- LogFlames (@LogFlames)
Release v5.5.2
Changelog
🚀 Added
- 1288296 👷 ci: Move GithubAction into action.yml (#1191)
- 0bc0411 👷 ci: Ensure relase is not running when merging PRs (#1190)
📦 Dependencies
- 32bbb53 ⬆️ (deps): Update github/codeql-action action to v3.28.17 (#1198)
- 937b1cf ⬆️ (deps): Update quarkus.platform.version to v3.22.1 (#1197)
- c5a0248 ⬆️ (deps): Update dependency org.codehaus.gmavenplus:gmavenplus-plugin to v4.2.0 (#1196)
🏁 Release
Contributors
We'd like to thank the following people for their contributions:
- Elias Lundell (@LogFlames)
Release v5.5.1
Changelog
🔄️ Changed
📦 Dependencies
- 7ac6373 ⬆️ (deps): Update dependency io.quarkus.platform:quarkus-maven-plugin to v3.21.4 (#1184)
- 8a88390 ⬆️ (deps): Update dependency com.google.code.gson:gson to v2.13.1 (#1185)
🏁 Release
Contributors
We'd like to thank the following people for their contributions:
- Elias Lundell (@LogFlames)
Release v5.5.0
Changelog
🚀 Added
- 82dc650 👷 ci: Run release action in environment release (#1182)
- c73c947 ✨ feat: Add resolved field (#1148)
- 13286ac ✅ test: Rename artifact ids to match testcase (#1153)
- 1c9164c ✨ feat: Resolve dependencies from other repositories than maven central (#1151)
- a7580b2 👷 (CD) build: Grant id-token permission for build-and-push-action job (#1162)
- 4f05138 👷 ci: Specify specific version in tag comment on github actions (#1133)
- 310ec8e 👷 ci: Reset action to current version and use release 5.4.2 (#1140)
🗑 Removed
📦 Dependencies
- 874e14e ⬆️ (deps): Update github/codeql-action action to v3.28.16 (#1181)
- f67b0ec ⬆️ (deps): Update step-security/harden-runner action to v2.12.0 (#1179)
- 367297c ⬆️ (deps): Update stefanzweifel/git-auto-commit-action action to v5.2.0 (#1178)
- cf6dd8d ⬆️ (deps): Update dependency io.quarkiverse.githubaction:quarkus-github-action to v2.6.0 (#1177)
- 1602e8f ⬆️ (deps): Update quarkus.platform.version to v3.21.3 (#1176)
- e437240 ⬆️ (deps): Update dependency com.google.guava:guava to v33.4.8-jre (#1144)
- 53b5b78 ⬆️ (deps): Update dependency org.apache.maven.resolver:maven-resolver-api to v2.0.8 (#1174)
- 8a8f8e8 ⬆️ (deps): Update dependency commons-io:commons-io to v2.19.0 (#1173)
- 4258fe1 ⬆️ (deps): Update dependency com.google.code.gson:gson to v2.13.0 (#1172)
- 80f5f68 ⬆️ (deps): Update junit5 monorepo to v5.12.2 (#1171)
- 1ac3851 ⬆️ (deps): Update quarkus.platform.version to v3.21.2 (#1170)
- a91ea81 ⬆️ (deps): Update actions/setup-java action to v4.7.1 (#1169)
- f0e0773 ⬆️ (deps): Update dependency com.diffplug.spotless:spotless-maven-plugin to v2.44.4 (#1166)
- bef02bd ⬆️ (deps): Update github/codeql-action action to v3.28.15 (#1165)
- 9cb9fc5 ⬆️ (deps): Update github/codeql-action action to v3.28.14 (#1164)
- ca12a09 ⬆️ (deps): Update quarkus.platform.version to v3.21.1 (#1160)
- 4a89f26 ⬆️ (deps): Update step-security/harden-runner action to v2.11.1 (#1159)
- 52e9ded ⬆️ (deps): Update actions/dependency-review-action action to v4.6.0 (#1158)
- 42c5732 ⬆️ (deps): Update dependency org.apache.maven.plugins:maven-surefire-plugin to v3.5.3 (#1156)
- 88aa381 ⬆️ (deps): Update surefire-plugin.version to v3.5.3 (#1157)
- e7365bb ⬆️ (deps): Update dependency org.apache.maven.plugins:maven-failsafe-plugin to v3.5.3 (#1155)
- 4445428 ⬆️ (deps): Update dependency org.apache.maven.plugin-testing:maven-plugin-testing-harness to v4.0.0-beta-4 (#1154)
- 17e3ff2 ⬆️ (deps): Update dependency org.apache.maven.plugins:maven-compiler-plugin to v3.14.0 (#1124)
- ba750a3 ⬆️ (deps): Update dependency com.google.code.gson:gson to v2.12.1 (#1123)
- 869bb60 ⬆️ (deps): Update quarkus.platform.version to v3.21.0 (#1147)
- 75de1e9 ⬆️ (deps): Update dependency org.instancio:instancio-junit to v5.4.1 (#1127)
- 0ce672e ⬆️ (deps): Update dependency org.apache.maven.resolver:maven-resolver-api to v2.0.7 (#1119)
- 94a4cdb ⬆️ (deps): Update ossf/scorecard-action action to v2.4.1 (#1120)
- ab8149d ⬆️ (deps): Update dependency org.apache.maven.plugins:maven-compiler-plugin to v3.14.0 (#1126)
- c6ef95d ⬆️ (deps): Update junit5 monorepo to v5.12.1 (#1130)
- 84d98e6 ⬆️ (deps): Update dependency org.apache.maven.plugin-testing:maven-plugin-testing-harness to v4.0.0-beta-3 (#1116)
- fa38721 ⬆️ (deps): Update github/codeql-action action to v3.28.13 (#1145)
- c84dfd7 ⬆️ (deps): Update dependency org.apache.maven.plugins:maven-clean-plugin to v3.4.1 (#1117)
- 4129f6b ⬆️ (deps): Update actions/upload-artifact action to v4.6.2 (#1143)
- bc2a889 ⬆️ (deps): Update quarkus.platform.version to v3.19.4 (#1131)
📝 Documentation
🏁 Release
- 3e6d390 🔖 Releasing version 5.5.0
- 357d14a 🚀 build (CD): Default to only sign sigstore during CD (#1175)
- a093cbc 🚀 build: Remove comment in maven.config for older maven versions (#1163)
- 04a9d4e 🚀 (CD) build: Sign with sigstore when publishing to maven central (#1161)
- 18e0f9f 🔖(deps): Update github/codeql-action digest to 1b549b9 (#1142)
- 8b8b020 🔖(deps): Update actions/upload-artifact digest to ea165f8 (#1139)
- 6d3c565 🔖(deps): Update actions/setup-go digest to 0aaccfd (#1137)
- bd1c055 🔖 Setting SNAPSHOT version 5.4.3-SNAPSHOT
- db73334 🔖(deps): Update actions/cache digest to 5a3ec84 (#1135)
- 889fa03 🧹 chore: remove digest updates as tags are mutable (#1121)
- 24cef9b Ignore .vim folder
- 66a48fd Merge remote-tracking branch 'origin/release/5.4.2'
Contributors
We'd like to thank the following people for their contributions:
- Aman Sharma ()
- Elias Lundell (@LogFlames)
- LogFlames (@LogFlames)
Release v5.4.2
Changelog
🚀 Added
- f287e2e 👷 ci: use interim action
- c9d7656 👷 ci: lock action to 5.4.1 for interim due to release locked behind ci
- 140cedb 👷 ci: Use version 5.4.1 in action (#1098)
🔒️ Security
📦 Dependencies
- 8d03568 ⬆️ (deps): Update dependency org.slf4j:log4j-over-slf4j to v2.0.17 (#1106)
- 29d8e4d ⬆️ (deps): Update dependency org.apache.maven.plugins:maven-install-plugin to v3.1.4 (#1105)
- cacb48b ⬆️ (deps): Update dependency org.apache.maven.plugins:maven-deploy-plugin to v3.1.4 (#1104)
- ff1be0a ⬆️ (deps): Update github/codeql-action action to v3.28.11 (#1073)
- 1cd7e6d ⬆️ (deps): Update step-security/harden-runner action to v2.11.0 (#1082)
- 066c6da ⬆️ (deps): Update dependency com.diffplug.spotless:spotless-maven-plugin to v2.44.3 (#1102)
- 34d1d8b ⬆️ (deps): Update dependency org.apache.groovy:groovy to v4.0.26 (#1074)
- e79ef1e ⬆️ (deps): Update actions/upload-artifact action to v4.6.1 (#1101)
🏁 Release
- dd58d82 🔖 Releasing version 5.4.2
- 964b103 🔖(deps): Update tj-actions/changed-files digest to 0e58ed8 (#1111)
- 7c272e0 🔖(deps): Update tj-actions/changed-files digest to 9200e69 (#1078)
- c795039 🔖(deps): Update github/codeql-action digest to 6bb031a (#1072)
- 7a617ae 🔖(deps): Update actions/upload-artifact digest to 4cec3d8 (#1100)
- b2cb45f 🔖(deps): Update actions/setup-java digest to 3a4f6e1 (#1075)
- 4b9bf83 🔖(deps): Update actions/cache digest to d4323d4 (#1099)
- 1102e1a 🔖 Setting SNAPSHOT version 5.4.2-SNAPSHOT
- 8da1a90 doc: Add example of using flags in readme (#1096)
- 3704f37 Revert "🔖(deps): Update tj-actions/changed-files digest to 0e58ed8 (#1111)"
Contributors
We'd like to thank the following people for their contributions:
- Elias Lundell ()
- Martin Monperrus (@monperrus)
Release v5.4.1
Changelog
🚀 Added
🏁 Release
Contributors
We'd like to thank the following people for their contributions:
- Elias Lundell (@LogFlames)
Release v5.4.0
Changelog
🚀 Added
- 86385b2 👷 ci: add content write permissions to jreleaser.yml action (#1093)
- 84d4aa0 👷 ci: update maven-lockfile action to temporarily specify 5.3.5 (#1092)
- 6d8b811 👷 ci: temporarily specify version 5.3.5 to use snapshot action (#1091)
- efb83de 👷 ci: Use snapshot action for release (#1090)
- 7584284 👷 ci: jbang manuall install cleanup (#1087) (#1087)
- a56c2bf ✅ test: Fix differentLockfileNameValidateShouldSucceed integration test (#1089)
- 7c30a4c 👷 Remove un-allowlisted actions (#1086)
- a2cdd6a 👷 ci: Use latest version of maven-lockfile in CI (#1043)
📦 Dependencies
- a949e68 ⬆️ (deps): Update github/codeql-action action to v3.28.2 (#1070)
- 2efff28 ⬆️ (deps): Update dependency org.instancio:instancio-junit to v5.3.0 (#1068)
- 10e9d3f ⬆️ (deps): Update step-security/harden-runner action to v2.10.4 (#1066)
- eaad84e ⬆️ (deps): Update quarkus.platform.version to v3.17.7 (#1065)
- 3579bec ⬆️ (deps): Update dependency com.diffplug.spotless:spotless-maven-plugin to v2.44.2 (#1063)
- 6075b09 ⬆️ (deps): Update dependency org.apache.maven.plugins:maven-artifact-plugin to v3.6.0 (#1062)
- 2e18552 ⬆️ (deps): Update github/codeql-action action to v3.28.1 (#1061)
- 86ded26 ⬆️ (deps): Update actions/upload-artifact action to v4.6.0 (#1059)
- 28df986 ⬆️ (deps): Update step-security/harden-runner action to v2.10.3 (#1057)
- 593bd3d ⬆️ (deps): Update quarkus.platform.version to v3.17.6 (#1054)
- d553f0e ⬆️ (deps): Update dependency com.diffplug.spotless:spotless-maven-plugin to v2.44.1 (#1052)
- 6f49437 ⬆️ (deps): Update dependency org.codehaus.gmavenplus:gmavenplus-plugin to v4.1.1 (#1050)
- 3314dbc ⬆️ (deps): Update github/codeql-action action to v3.28.0 (#1046)
📝 Documentation
- 93d80d1 📝 👷 docs: ci: Document and update syncronizing lockfile with release (#1047)
- 11c1d60 📝 docs: Update version of action in README.md to 5.3.5 (#1049)
🏁 Release
- 7a33237 🔖 Releasing version 5.4.0
- 42c33ff 🔖(deps): Update github/codeql-action digest to d68b2d4 (#1069)
- dc264bb 🔖(deps): Update actions/setup-go digest to f111f33 (#1067)
- c5298bd 🔖(deps): Update actions/upload-artifact digest to 65c4c4a (#1058)
- 9e0be18 🔖(deps): Update github/codeql-action digest to b6a472f (#1060)
- c06c479 🔖(deps): Update tj-actions/changed-files digest to d6e91a2 (#1051)
- a042269 🔖(deps): Update github/codeql-action digest to 48ab28a (#1045)
- d0f7427 🔖 Setting SNAPSHOT version 5.3.6-SNAPSHOT
Contributors
We'd like to thank the following people for their contributions:
- Elias Lundell (@LogFlames)
- LogFlames (@LogFlames)
- Martin Monperrus (@monperrus)
Release v5.3.5
Changelog
🐛 Fixed
🏁 Release
Contributors
We'd like to thank the following people for their contributions:
- Elias Lundell (@LogFlames)
Release v5.3.4
Changelog
🐛 Fixed
🎲 Miscellaneous
- 7711f3b 🔍:mag: test branch protection rule bypass using classic token
🏁 Release
Contributors
We'd like to thank the following people for their contributions:
- Elias Lundell (@LogFlames)