Skip to content

Releases: chains-project/maven-lockfile

Release v5.6.0

18 Jun 14:06
Compare
Choose a tag to compare

Changelog

🚀 Added

  • 03b1003 ✨ feat: Add exactVersionString to freeze target (#1204)
  • ce475db ✨ feat: Add sha256 and sha512 checksums to remote mode (#1200)
  • 2f5bf2c 👷 ci: Add githubusercontent release-assets to harden runner allowlists (#1252)
  • de9b046 👷 ci: Update gha.sum in CI for all PRs (#1245)
  • 40211d8 👷 ci: Remove ghasum binary after checksum verification (#1244)

🔄️ Changed

  • d98e4c9 🚸 feat: Change default checksumMode from local to remote (#1199)
  • ed338e7 💬 format: Format all checksums with capital letters (#1255)

📦 Dependencies

  • 40d9be9 ⬆️ (deps): Update step-security/harden-runner action to v2.12.1 (#1247)
  • 6bd867d ⬆️ (deps): Update dependency org.apache.logging.log4j:log4j-core to v2.25.0 (#1253)
  • 9fcb067 ⬆️ (deps): Update stefanzweifel/git-auto-commit-action action to v6.0.1 (#1250)
  • 7fd5c73 ⬆️ (deps): Update stefanzweifel/git-auto-commit-action action to v6 (#1249)
  • 79960ef ⬆️ (deps): Update github/codeql-action action to v3.29.0 (#1248)
  • 45f0ddd ⬆️ (deps): Update junit5 monorepo to v5.13.1 (#1242)

🏁 Release

  • 0df0638 🔖 Releasing version 5.6.0
  • 9851c72 🔖 Setting SNAPSHOT version 5.5.4-SNAPSHOT

Contributors

We'd like to thank the following people for their contributions:

Release v5.5.3

06 Jun 00:06
Compare
Choose a tag to compare

Changelog

🚀 Added

  • 737536f 👷 cd: Remove CD and verify OSSRH migration (#1240)
  • 8085f2a 👷 cd: Only deploy snapshots (#1239)
  • 6767d46 👷 cd: Migration to Maven Central Publisher API and CD (#1217)
  • 49b9f6c 👷 ci: Add minimum release age of 1d to renovate (#1238)
  • 0108499 👷 ci: Trigger ghasum update action for renovate PRs (#1237)
  • 54d8ead 👷 ci: Trigger ghasum on PR from renovate instead of branches (#1236)
  • a686b04 👷 ci: Automatically update gha.sum on Renovate PR (#1233)
  • 167ad68 👷 ci: Remove renovate pinGitHubActionDigests helper (#1232)
  • 8ad77c7 👷 ci: Update gha.sum for #1227 (#1229)
  • 1f23a67 👷 ci: Reset ossf/scorecard to without ghasum to only include allowlisted steps (#1227)
  • 158aa00 👷 ci: Add repo.spring.io to allowlisted endpoints for ossf/scorecard (#1224)
  • ef8a587 👷 ci: Remove pinDigest update from Renovate (#1221)
  • fb0b6cd 👷 ci: Add ghasum to github workflows (#1211)
  • 994e796 👷 ci: Use latest maven lockfile action (v5.5.2) (#1202)

📦 Dependencies

  • 8b77244 ⬆️ (deps): Update stefanzweifel/git-auto-commit-action action to v5.2.0 (#1234)
  • b55ba83 ⬆️ (deps): Update github/codeql-action action to v3.28.19 (#1222)
  • 040f6bb ⬆️ (config): migrate renovate config (#1228)
  • 9474a05 ⬆️ (deps): Update dependency org.apache.maven.plugins:maven-clean-plugin to v3.5.0 (#1216)
  • 8ce4b28 ⬆️ (deps): Update ossf/scorecard-action action to v2.4.2 (#1215)
  • 65490ae ⬆️ (deps): Update junit5 monorepo to v5.13.0 (#1214)
  • 09fb977 ⬆️ (deps): Update dependency com.diffplug.spotless:spotless-maven-plugin to v2.44.5 (#1212)
  • 8e0a5e9 ⬆️ (deps): Update dependency org.apache.groovy:groovy to v4.0.27 (#1210)
  • d563a05 ⬆️ (deps): Update dependency org.apache.maven.resolver:maven-resolver-api to v2.0.9 (#1209)
  • c9dbc9f ⬆️ (deps): Update github/codeql-action action to v3.28.18 (#1208)
  • edf641b ⬆️ (deps): Update actions/dependency-review-action action to v4.7.1 (#1207)
  • 6ad9a16 ⬆️ (deps): Update actions/dependency-review-action action to v4.7.0 (#1206)
  • 783131a ⬆️ (deps): Update actions/setup-go action to v5.5.0 (#1205)

📝 Documentation

  • 32637d1 📝 docs: Use latest version of lockfile in README (#1203)

🏁 Release

  • 849caed 🔖 Releasing version 5.5.3
  • a862ba3 🔖 Setting SNAPSHOT version 5.5.3-SNAPSHOT

Contributors

We'd like to thank the following people for their contributions:

Release v5.5.2

07 May 09:55
Compare
Choose a tag to compare

Changelog

🚀 Added

  • 1288296 👷 ci: Move GithubAction into action.yml (#1191)
  • 0bc0411 👷 ci: Ensure relase is not running when merging PRs (#1190)

📦 Dependencies

  • 32bbb53 ⬆️ (deps): Update github/codeql-action action to v3.28.17 (#1198)
  • 937b1cf ⬆️ (deps): Update quarkus.platform.version to v3.22.1 (#1197)
  • c5a0248 ⬆️ (deps): Update dependency org.codehaus.gmavenplus:gmavenplus-plugin to v4.2.0 (#1196)

🏁 Release

  • dbd9538 🔖 Releasing version 5.5.2
  • ecca88b 🔖 Setting SNAPSHOT version 5.5.2-SNAPSHOT

Contributors

We'd like to thank the following people for their contributions:

Release v5.5.1

25 Apr 09:16
Compare
Choose a tag to compare

Changelog

🔄️ Changed

  • 88f34bd 🔧 Specify view SCM url with tag of release (#1187)

📦 Dependencies

  • 7ac6373 ⬆️ (deps): Update dependency io.quarkus.platform:quarkus-maven-plugin to v3.21.4 (#1184)
  • 8a88390 ⬆️ (deps): Update dependency com.google.code.gson:gson to v2.13.1 (#1185)

🏁 Release

  • 8ddaeae 🔖 Releasing version 5.5.1
  • 19f9ae5 🔖 Setting SNAPSHOT version 5.5.1-SNAPSHOT

Contributors

We'd like to thank the following people for their contributions:

Release v5.5.0

23 Apr 17:09
Compare
Choose a tag to compare

Changelog

🚀 Added

  • 82dc650 👷 ci: Run release action in environment release (#1182)
  • c73c947 ✨ feat: Add resolved field (#1148)
  • 13286ac ✅ test: Rename artifact ids to match testcase (#1153)
  • 1c9164c ✨ feat: Resolve dependencies from other repositories than maven central (#1151)
  • a7580b2 👷 (CD) build: Grant id-token permission for build-and-push-action job (#1162)
  • 4f05138 👷 ci: Specify specific version in tag comment on github actions (#1133)
  • 310ec8e 👷 ci: Reset action to current version and use release 5.4.2 (#1140)

🗑 Removed

📦 Dependencies

  • 874e14e ⬆️ (deps): Update github/codeql-action action to v3.28.16 (#1181)
  • f67b0ec ⬆️ (deps): Update step-security/harden-runner action to v2.12.0 (#1179)
  • 367297c ⬆️ (deps): Update stefanzweifel/git-auto-commit-action action to v5.2.0 (#1178)
  • cf6dd8d ⬆️ (deps): Update dependency io.quarkiverse.githubaction:quarkus-github-action to v2.6.0 (#1177)
  • 1602e8f ⬆️ (deps): Update quarkus.platform.version to v3.21.3 (#1176)
  • e437240 ⬆️ (deps): Update dependency com.google.guava:guava to v33.4.8-jre (#1144)
  • 53b5b78 ⬆️ (deps): Update dependency org.apache.maven.resolver:maven-resolver-api to v2.0.8 (#1174)
  • 8a8f8e8 ⬆️ (deps): Update dependency commons-io:commons-io to v2.19.0 (#1173)
  • 4258fe1 ⬆️ (deps): Update dependency com.google.code.gson:gson to v2.13.0 (#1172)
  • 80f5f68 ⬆️ (deps): Update junit5 monorepo to v5.12.2 (#1171)
  • 1ac3851 ⬆️ (deps): Update quarkus.platform.version to v3.21.2 (#1170)
  • a91ea81 ⬆️ (deps): Update actions/setup-java action to v4.7.1 (#1169)
  • f0e0773 ⬆️ (deps): Update dependency com.diffplug.spotless:spotless-maven-plugin to v2.44.4 (#1166)
  • bef02bd ⬆️ (deps): Update github/codeql-action action to v3.28.15 (#1165)
  • 9cb9fc5 ⬆️ (deps): Update github/codeql-action action to v3.28.14 (#1164)
  • ca12a09 ⬆️ (deps): Update quarkus.platform.version to v3.21.1 (#1160)
  • 4a89f26 ⬆️ (deps): Update step-security/harden-runner action to v2.11.1 (#1159)
  • 52e9ded ⬆️ (deps): Update actions/dependency-review-action action to v4.6.0 (#1158)
  • 42c5732 ⬆️ (deps): Update dependency org.apache.maven.plugins:maven-surefire-plugin to v3.5.3 (#1156)
  • 88aa381 ⬆️ (deps): Update surefire-plugin.version to v3.5.3 (#1157)
  • e7365bb ⬆️ (deps): Update dependency org.apache.maven.plugins:maven-failsafe-plugin to v3.5.3 (#1155)
  • 4445428 ⬆️ (deps): Update dependency org.apache.maven.plugin-testing:maven-plugin-testing-harness to v4.0.0-beta-4 (#1154)
  • 17e3ff2 ⬆️ (deps): Update dependency org.apache.maven.plugins:maven-compiler-plugin to v3.14.0 (#1124)
  • ba750a3 ⬆️ (deps): Update dependency com.google.code.gson:gson to v2.12.1 (#1123)
  • 869bb60 ⬆️ (deps): Update quarkus.platform.version to v3.21.0 (#1147)
  • 75de1e9 ⬆️ (deps): Update dependency org.instancio:instancio-junit to v5.4.1 (#1127)
  • 0ce672e ⬆️ (deps): Update dependency org.apache.maven.resolver:maven-resolver-api to v2.0.7 (#1119)
  • 94a4cdb ⬆️ (deps): Update ossf/scorecard-action action to v2.4.1 (#1120)
  • ab8149d ⬆️ (deps): Update dependency org.apache.maven.plugins:maven-compiler-plugin to v3.14.0 (#1126)
  • c6ef95d ⬆️ (deps): Update junit5 monorepo to v5.12.1 (#1130)
  • 84d98e6 ⬆️ (deps): Update dependency org.apache.maven.plugin-testing:maven-plugin-testing-harness to v4.0.0-beta-3 (#1116)
  • fa38721 ⬆️ (deps): Update github/codeql-action action to v3.28.13 (#1145)
  • c84dfd7 ⬆️ (deps): Update dependency org.apache.maven.plugins:maven-clean-plugin to v3.4.1 (#1117)
  • 4129f6b ⬆️ (deps): Update actions/upload-artifact action to v4.6.2 (#1143)
  • bc2a889 ⬆️ (deps): Update quarkus.platform.version to v3.19.4 (#1131)

📝 Documentation

🏁 Release

  • 3e6d390 🔖 Releasing version 5.5.0
  • 357d14a 🚀 build (CD): Default to only sign sigstore during CD (#1175)
  • a093cbc 🚀 build: Remove comment in maven.config for older maven versions (#1163)
  • 04a9d4e 🚀 (CD) build: Sign with sigstore when publishing to maven central (#1161)
  • 18e0f9f 🔖(deps): Update github/codeql-action digest to 1b549b9 (#1142)
  • 8b8b020 🔖(deps): Update actions/upload-artifact digest to ea165f8 (#1139)
  • 6d3c565 🔖(deps): Update actions/setup-go digest to 0aaccfd (#1137)
  • bd1c055 🔖 Setting SNAPSHOT version 5.4.3-SNAPSHOT
  • db73334 🔖(deps): Update actions/cache digest to 5a3ec84 (#1135)

  • 889fa03 🧹 chore: remove digest updates as tags are mutable (#1121)
  • 24cef9b Ignore .vim folder
  • 66a48fd Merge remote-tracking branch 'origin/release/5.4.2'

Contributors

We'd like to thank the following people for their contributions:

Release v5.4.2

24 Mar 17:54
Compare
Choose a tag to compare

Changelog

🚀 Added

  • f287e2e 👷 ci: use interim action
  • c9d7656 👷 ci: lock action to 5.4.1 for interim due to release locked behind ci
  • 140cedb 👷 ci: Use version 5.4.1 in action (#1098)

🔒️ Security

📦 Dependencies

  • 8d03568 ⬆️ (deps): Update dependency org.slf4j:log4j-over-slf4j to v2.0.17 (#1106)
  • 29d8e4d ⬆️ (deps): Update dependency org.apache.maven.plugins:maven-install-plugin to v3.1.4 (#1105)
  • cacb48b ⬆️ (deps): Update dependency org.apache.maven.plugins:maven-deploy-plugin to v3.1.4 (#1104)
  • ff1be0a ⬆️ (deps): Update github/codeql-action action to v3.28.11 (#1073)
  • 1cd7e6d ⬆️ (deps): Update step-security/harden-runner action to v2.11.0 (#1082)
  • 066c6da ⬆️ (deps): Update dependency com.diffplug.spotless:spotless-maven-plugin to v2.44.3 (#1102)
  • 34d1d8b ⬆️ (deps): Update dependency org.apache.groovy:groovy to v4.0.26 (#1074)
  • e79ef1e ⬆️ (deps): Update actions/upload-artifact action to v4.6.1 (#1101)

🏁 Release

  • dd58d82 🔖 Releasing version 5.4.2
  • 964b103 🔖(deps): Update tj-actions/changed-files digest to 0e58ed8 (#1111)
  • 7c272e0 🔖(deps): Update tj-actions/changed-files digest to 9200e69 (#1078)
  • c795039 🔖(deps): Update github/codeql-action digest to 6bb031a (#1072)
  • 7a617ae 🔖(deps): Update actions/upload-artifact digest to 4cec3d8 (#1100)
  • b2cb45f 🔖(deps): Update actions/setup-java digest to 3a4f6e1 (#1075)
  • 4b9bf83 🔖(deps): Update actions/cache digest to d4323d4 (#1099)
  • 1102e1a 🔖 Setting SNAPSHOT version 5.4.2-SNAPSHOT

  • 8da1a90 doc: Add example of using flags in readme (#1096)
  • 3704f37 Revert "🔖(deps): Update tj-actions/changed-files digest to 0e58ed8 (#1111)"

Contributors

We'd like to thank the following people for their contributions:

Release v5.4.1

13 Mar 16:54
Compare
Choose a tag to compare

Changelog

🚀 Added

  • d881c5c 👷 ci: Use version 5.4.0 with removed non-allowlisted github actions (#1095)

🏁 Release

  • 352fc01 🔖 Releasing version 5.4.1
  • 9af76b7 🔖 Setting SNAPSHOT version 5.4.1-SNAPSHOT

Contributors

We'd like to thank the following people for their contributions:

Release v5.4.0

13 Mar 15:55
Compare
Choose a tag to compare

Changelog

🚀 Added

  • 86385b2 👷 ci: add content write permissions to jreleaser.yml action (#1093)
  • 84d4aa0 👷 ci: update maven-lockfile action to temporarily specify 5.3.5 (#1092)
  • 6d8b811 👷 ci: temporarily specify version 5.3.5 to use snapshot action (#1091)
  • efb83de 👷 ci: Use snapshot action for release (#1090)
  • 7584284 👷 ci: jbang manuall install cleanup (#1087) (#1087)
  • a56c2bf ✅ test: Fix differentLockfileNameValidateShouldSucceed integration test (#1089)
  • 7c30a4c 👷 Remove un-allowlisted actions (#1086)
  • a2cdd6a 👷 ci: Use latest version of maven-lockfile in CI (#1043)

📦 Dependencies

  • a949e68 ⬆️ (deps): Update github/codeql-action action to v3.28.2 (#1070)
  • 2efff28 ⬆️ (deps): Update dependency org.instancio:instancio-junit to v5.3.0 (#1068)
  • 10e9d3f ⬆️ (deps): Update step-security/harden-runner action to v2.10.4 (#1066)
  • eaad84e ⬆️ (deps): Update quarkus.platform.version to v3.17.7 (#1065)
  • 3579bec ⬆️ (deps): Update dependency com.diffplug.spotless:spotless-maven-plugin to v2.44.2 (#1063)
  • 6075b09 ⬆️ (deps): Update dependency org.apache.maven.plugins:maven-artifact-plugin to v3.6.0 (#1062)
  • 2e18552 ⬆️ (deps): Update github/codeql-action action to v3.28.1 (#1061)
  • 86ded26 ⬆️ (deps): Update actions/upload-artifact action to v4.6.0 (#1059)
  • 28df986 ⬆️ (deps): Update step-security/harden-runner action to v2.10.3 (#1057)
  • 593bd3d ⬆️ (deps): Update quarkus.platform.version to v3.17.6 (#1054)
  • d553f0e ⬆️ (deps): Update dependency com.diffplug.spotless:spotless-maven-plugin to v2.44.1 (#1052)
  • 6f49437 ⬆️ (deps): Update dependency org.codehaus.gmavenplus:gmavenplus-plugin to v4.1.1 (#1050)
  • 3314dbc ⬆️ (deps): Update github/codeql-action action to v3.28.0 (#1046)

📝 Documentation

  • 93d80d1 📝 👷 docs: ci: Document and update syncronizing lockfile with release (#1047)
  • 11c1d60 📝 docs: Update version of action in README.md to 5.3.5 (#1049)

🏁 Release

  • 7a33237 🔖 Releasing version 5.4.0
  • 42c33ff 🔖(deps): Update github/codeql-action digest to d68b2d4 (#1069)
  • dc264bb 🔖(deps): Update actions/setup-go digest to f111f33 (#1067)
  • c5298bd 🔖(deps): Update actions/upload-artifact digest to 65c4c4a (#1058)
  • 9e0be18 🔖(deps): Update github/codeql-action digest to b6a472f (#1060)
  • c06c479 🔖(deps): Update tj-actions/changed-files digest to d6e91a2 (#1051)
  • a042269 🔖(deps): Update github/codeql-action digest to 48ab28a (#1045)
  • d0f7427 🔖 Setting SNAPSHOT version 5.3.6-SNAPSHOT

Contributors

We'd like to thank the following people for their contributions:

Release v5.3.5

20 Dec 14:04
Compare
Choose a tag to compare

Changelog

🐛 Fixed

  • cda7810 💚 fix ci: Fix erroneous indentation in action.yml (#1041)

🏁 Release

  • bdabb56 🔖 Releasing version 5.3.5
  • a5221d0 🔖 Setting SNAPSHOT version 5.3.5-SNAPSHOT

Contributors

We'd like to thank the following people for their contributions:

Release v5.3.4

20 Dec 13:21
Compare
Choose a tag to compare

Changelog

🐛 Fixed

  • b1fc2a1 💚 fix ci: Trigger Pull-Request from CURL using JRELEASER_GITHUB_TOKEN (#1039)

🎲 Miscellaneous

  • 7711f3b 🔍:mag: test branch protection rule bypass using classic token

🏁 Release

  • ced582d 🔖 Releasing version 5.3.4
  • e29ca30 🔖 Setting SNAPSHOT version 5.3.4-SNAPSHOT

Contributors

We'd like to thank the following people for their contributions: