Skip to content

deps(deps): bump com.fasterxml.jackson:jackson-bom from 2.22.2 to 2.22.3 in the jackson group across 1 directory - #25

Merged
nil-malh merged 1 commit into
mainfrom
dependabot/maven/jackson-b1360e9ec2
Sep 30, 2026
Merged

nil-malh merged 1 commit into
mainfrom
dependabot/maven/jackson-b1360e9ec2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the jackson group with 1 update in the / directory: com.fasterxml.jackson:jackson-bom.

Updates com.fasterxml.jackson:jackson-bom from 2.22.2 to 2.22.3

Commits
  • 9b1c380 [maven-release-plugin] prepare release jackson-bom-2.22.3
  • f76ca14 Prep for 2.22.3 release
  • d6ac108 Merge branch '2.21' into 2.22
  • 093a05e Post-release dep version bump
  • e7a71a2 [maven-release-plugin] prepare for next development iteration
  • 62d4d51 [maven-release-plugin] prepare release jackson-bom-2.21.7
  • 6171b54 Prep for 2.21.7 release
  • 6702bf3 Merge branch '2.20' into 2.21
  • 2feb1f9 Merge branch '2.19' into 2.20
  • 1129aa0 Merge branch '2.18' into 2.19
  • Additional commits viewable in compare view

@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
maven/com.fasterxml.jackson:jackson-bom 2.22.3 UnknownUnknown
maven/org.mockito:mockito-core 5.24.0 🟢 7.3
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Security-Policy🟢 9security policy file detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Maintained🟢 1010 commit(s) and 8 issue activity found in the last 90 days -- score normalized to 10
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Binary-Artifacts🟢 9binaries present in source code
Packaging🟢 10packaging workflow detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
maven/org.slf4j:slf4j-api 2.0.20 🟢 5.8
Details
CheckScoreReason
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Code-Review⚠️ 0Found 1/30 approved changesets -- score normalized to 0
Token-Permissions🟢 10GitHub workflow tokens follow principle of least privilege
Security-Policy🟢 10security policy file detected
Packaging⚠️ -1packaging workflow not detected
Maintained🟢 1029 commit(s) and 3 issue activity found in the last 90 days -- score normalized to 10
Binary-Artifacts⚠️ 0binaries present in source code
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing🟢 10project is fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
maven/org.xmlunit:xmlunit-core 2.14.0 🟢 7.2
Details
CheckScoreReason
Dangerous-Workflow⚠️ -1no workflows found
Maintained🟢 1018 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
Token-Permissions⚠️ -1No tokens found
Security-Policy🟢 10security policy file detected
Packaging⚠️ -1packaging workflow not detected
Code-Review🟢 3Found 4/11 approved changesets -- score normalized to 3
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ -1no dependencies found
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing🟢 10project is fuzzed
License🟢 10license file detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Signed-Releases🟢 85 out of the last 5 releases have a total of 5 signed artifacts.
maven/org.xmlunit:xmlunit-matchers 2.14.0 🟢 7.2
Details
CheckScoreReason
Dangerous-Workflow⚠️ -1no workflows found
Maintained🟢 1018 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
Token-Permissions⚠️ -1No tokens found
Security-Policy🟢 10security policy file detected
Packaging⚠️ -1packaging workflow not detected
Code-Review🟢 3Found 4/11 approved changesets -- score normalized to 3
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ -1no dependencies found
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing🟢 10project is fuzzed
License🟢 10license file detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Signed-Releases🟢 85 out of the last 5 releases have a total of 5 signed artifacts.

Scanned Files

  • pom.xml

@github-actions

github-actions Bot commented Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

📋 Unreleased Changelog Preview

This is what the next release notes will look like based on commits in this PR.

Changelog

All notable changes to this project will be documented in this file.

[Unreleased]

⬆️ Dependency Updates

  • Bump the maven-plugins group with 4 updates (deps-dev) — @dependabot[bot]

  • Bump the kafka group with 3 updates (deps) — @dependabot[bot]

  • Bump the cucumber group across 1 directory with 4 updates (deps) — @dependabot[bot]

  • Bump org.mockito:mockito-core in the mockito group (deps-dev) — @dependabot[bot]

  • Bump org.slf4j:slf4j-api in the logging group (deps) — @dependabot[bot]

  • Bump xmlunit.version from 2.13.0 to 2.14.0 (deps) — @dependabot[bot]

  • Bump com.fasterxml.jackson:jackson-bom (deps)


Generated by git-cliff


🔄 Run #61 · Wed, 30 Sep 2026 18:58:17 GMT

@nil-malh

Copy link
Copy Markdown
Contributor

@dependabot rebase

Bumps the jackson group with 1 update in the / directory: [com.fasterxml.jackson:jackson-bom](https://github.com/FasterXML/jackson-bom).


Updates `com.fasterxml.jackson:jackson-bom` from 2.22.2 to 2.22.3
- [Commits](FasterXML/jackson-bom@jackson-bom-2.22.2...jackson-bom-2.22.3)

---
updated-dependencies:
- dependency-name: com.fasterxml.jackson:jackson-bom
  dependency-version: 2.22.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: jackson
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title deps(deps): bump com.fasterxml.jackson:jackson-bom from 2.22.2 to 2.22.3 in the jackson group deps(deps): bump com.fasterxml.jackson:jackson-bom from 2.22.2 to 2.22.3 in the jackson group across 1 directory Sep 30, 2026
@dependabot
dependabot Bot force-pushed the dependabot/maven/jackson-b1360e9ec2 branch from 53ecf91 to 9608694 Compare September 30, 2026 18:57
@nil-malh
nil-malh merged commit 8e953fa into main Sep 30, 2026
9 of 12 checks passed
@dependabot
dependabot Bot deleted the dependabot/maven/jackson-b1360e9ec2 branch September 30, 2026 18:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant