Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump commons-beanutils from 1.9.3 to 1.9.4 #5124

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Dec 16, 2020

Bumps commons-beanutils from 1.9.3 to 1.9.4.

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps commons-beanutils from 1.9.3 to 1.9.4.

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Dec 16, 2020
@MarkEWaite
Copy link
Contributor

MarkEWaite commented Dec 16, 2020

My bad experiences with commons-beanutils 1.9.4 are described in a mailing list item. In that item, Daniel Beck said:

commons-beanutils 1.9.4 is known to core maintainers to not be useable in Jenkins. We've now had two PRs (#4928 and #4328) for that update, both failed.

@dependabot ignore this dependency

@dependabot dependabot bot closed this Dec 16, 2020
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Dec 16, 2020

OK, I won't notify you about commons-beanutils:commons-beanutils again, unless you re-open this PR or update it yourself. 😢

@dependabot dependabot bot deleted the dependabot/maven/commons-beanutils-commons-beanutils-1.9.4 branch December 16, 2020 19:54
@basil
Copy link
Member

basil commented Dec 16, 2020

@dependabot ignore this dependency

@MarkEWaite Have we thought about whether we prefer the ignore option to the dependabot.yml configuration file to ignore preferences (created using @dependabot ignore commands) as described in the documentation? While both serve the same function, it seems to me that decentralized ignore preferences are hard to list and reason about, whereas keeping this information centralized in the dependabot.yml configuration file may make it easier to reason about the ignore list in the future. No strong preference one way or another, but it might be worth considering.

@jglick
Copy link
Member

jglick commented Dec 16, 2020

We've now had two PRs for that update

Links here please for reference?

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Dec 16, 2020

OK, I won't notify you about commons-beanutils:commons-beanutils again, unless you re-open this PR or update it yourself. 😢

@MarkEWaite
Copy link
Contributor

MarkEWaite commented Dec 16, 2020

We've now had two PRs for that update

Links here please for reference?

Sure, though I'm now paraphrasing Daniel rather than quoting Daniel:

commons-beanutils 1.9.4 is known to core maintainers to not be usable in Jenkins. We've now had two PRs (#4928 and #4328) for that update, both failed.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file java Pull requests that update Java code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants