GitHub / CycloneDX/cyclonedx-maven-plugin issues and pull requests
#608 - Safer - Compatible Updates to Fix Vulnerable Dependencies
Issue -
State: open - Opened by safer-bot 17 days ago
#607 - Updated pom.xml by Safer
Pull Request -
State: open - Opened by safer-bot 17 days ago
#606 - chore: GH workflow permissions
Pull Request -
State: closed - Opened by jkowalleck about 1 month ago
Labels: github_actions
#605 - skip logic in the plugin is broken
Issue -
State: closed - Opened by hgschmie about 2 months ago
- 2 comments
Labels: duplicate
#604 - Handle central-publishing-maven-plugin for skipNotDeployed detection
Pull Request -
State: open - Opened by apupier 3 months ago
- 7 comments
Labels: enhancement, major-rfe
#603 - SerialNumber of SBOMs are not unique
Issue -
State: open - Opened by MeikelVielhauer 3 months ago
- 4 comments
#602 - cyclonedx will generate extreme big log with so many duplicate info when enable maven debug mode
Issue -
State: open - Opened by TianMing2018 3 months ago
- 1 comment
Labels: duplicate
#601 - Bump io.takari.maven.plugins:takari-plugin-integration-testing from 3.0.1 to 3.1.0
Pull Request -
State: open - Opened by dependabot[bot] 3 months ago
Labels: dependencies, java
#600 - Bump io.takari.maven.plugins:takari-plugin-testing from 3.0.0 to 3.1.0
Pull Request -
State: open - Opened by dependabot[bot] 3 months ago
Labels: dependencies, java
#599 - Add support for supplementing POM models
Issue -
State: open - Opened by ppkarwasz 3 months ago
Labels: enhancement
#598 - Bump org.apache.maven.shared:maven-dependency-analyzer from 1.14.1 to 1.16.0
Pull Request -
State: open - Opened by dependabot[bot] 4 months ago
Labels: dependencies, java
#597 - Feature: Teach plugin to handle central-publishing-maven-plugin extension as deployment type
Issue -
State: open - Opened by hazendaz 4 months ago
- 2 comments
#596 - add IT for shipped/included dependencies vs not-shipped
Pull Request -
State: open - Opened by hboutemy 5 months ago
Labels: build
#595 - Cyclonedx seems to ignore some configuration options
Issue -
State: open - Opened by Furcraft 5 months ago
- 1 comment
#594 - Bump org.apache.maven.plugins:maven-compiler-plugin from 3.13.0 to 3.14.0
Pull Request -
State: open - Opened by dependabot[bot] 5 months ago
Labels: dependencies, java
#593 - upgrade to Doxia 2: m-site-p and skin
Pull Request -
State: closed - Opened by hboutemy 5 months ago
Labels: dependencies
#592 - add Reproducible Central report
Pull Request -
State: closed - Opened by hboutemy 5 months ago
Labels: build
#591 - Add a range of JRE versions as external dependency
Issue -
State: open - Opened by ppkarwasz 5 months ago
- 5 comments
#590 - Bump JamesIves/github-pages-deploy-action from 4.7.1 to 4.7.3
Pull Request -
State: closed - Opened by dependabot[bot] 5 months ago
Labels: dependencies, github_actions
#589 - Feature: detect shipped vs non shipped dependency => generate version-less component when not shipped
Issue -
State: open - Opened by hboutemy 6 months ago
- 9 comments
Labels: major-rfe
#588 - Jenkins-core with minimal version is included in bom.json when running makeAggregateBom for a Jenkins plugin
Issue -
State: open - Opened by Bruceliu-rs 8 months ago
- 6 comments
#587 - Bump org.apache.maven.plugins:maven-invoker-plugin from 3.7.0 to 3.9.0
Pull Request -
State: open - Opened by dependabot[bot] 8 months ago
Labels: dependencies, java
#586 - Bump JamesIves/github-pages-deploy-action from 4.7.1 to 4.7.2
Pull Request -
State: closed - Opened by dependabot[bot] 8 months ago
- 1 comment
Labels: dependencies, github_actions
#585 - Bump org.apache.maven.plugins:maven-invoker-plugin from 3.7.0 to 3.8.1
Pull Request -
State: closed - Opened by dependabot[bot] 8 months ago
- 1 comment
Labels: dependencies, java
#584 - upgrade github-pages-deploy-action
Pull Request -
State: closed - Opened by hboutemy 8 months ago
Labels: build
#583 - Incomplete manifest generated in case of intermediate issues in resolving artifacts
Issue -
State: open - Opened by goldmann 8 months ago
- 6 comments
#582 - Add manufacturer information to SBOM metadata
Pull Request -
State: open - Opened by kornefalk 8 months ago
- 12 comments
Labels: enhancement
#581 - Failed to execute goal org.cyclonedx:cyclonedx-maven-plugin:2.9.0:makeAggregateBom (default-cli) on project markedeve-service-udp: The BOM does not conform to the CycloneDX BOM standard as defined by the XSD
Issue -
State: open - Opened by wzd-hash 9 months ago
- 2 comments
#579 - Generated bom is invalid
Issue -
State: closed - Opened by crimsonvspurple 9 months ago
- 16 comments
Labels: invalid
#578 - Exclude Projects not working as expected when running goal 'makeAggregateBom'
Issue -
State: open - Opened by arkajnag23 9 months ago
- 5 comments
#577 - simplify code
Pull Request -
State: closed - Opened by hboutemy 9 months ago
Labels: enhancement
#576 - Examples
Pull Request -
State: open - Opened by hboutemy 9 months ago
- 5 comments
#575 - share isBlank(String)
Pull Request -
State: closed - Opened by hboutemy 9 months ago
Labels: enhancement, java
#574 - What if a Maven module produces multiple variants?
Issue -
State: open - Opened by raboof 9 months ago
- 4 comments
#573 - don't generate invalid SBOM on blank license: ignore instead
Pull Request -
State: closed - Opened by fupgang 9 months ago
- 5 comments
Labels: enhancement
#572 - Bump org.apache.maven.shared:maven-dependency-analyzer from 1.14.1 to 1.15.1
Pull Request -
State: open - Opened by dependabot[bot] 9 months ago
Labels: dependencies, java
#571 - Bump actions/checkout from 4.2.1 to 4.2.2
Pull Request -
State: closed - Opened by dependabot[bot] 9 months ago
Labels: github_actions, build
#570 - Bump org.apache.maven.plugins:maven-project-info-reports-plugin from 3.6.2 to 3.8.0
Pull Request -
State: closed - Opened by dependabot[bot] 9 months ago
Labels: build
#569 - Bump org.apache.maven.plugins:maven-site-plugin from 3.12.1 to 3.21.0
Pull Request -
State: closed - Opened by dependabot[bot] 9 months ago
- 2 comments
Labels: dependencies, java
#568 - Question - Help! Ignore transitive dependencies in SBOM
Issue -
State: closed - Opened by kirankumar-grootan 10 months ago
- 5 comments
Labels: wontfix
#567 - Bump org.apache.maven.shared:maven-dependency-analyzer from 1.14.1 to 1.15.0
Pull Request -
State: closed - Opened by dependabot[bot] 10 months ago
- 1 comment
Labels: dependencies, java
#566 - Bump org.apache.maven.plugins:maven-site-plugin from 3.12.1 to 3.20.0
Pull Request -
State: closed - Opened by dependabot[bot] 10 months ago
- 1 comment
Labels: dependencies, java
#565 - Bump actions/checkout from 4.2.0 to 4.2.1
Pull Request -
State: closed - Opened by dependabot[bot] 10 months ago
Labels: dependencies, github_actions
#564 - [WARNING] Unknown keyword meta:[enum|deprecated] - you should define your own Meta Schema
Issue -
State: open - Opened by garydgregory 10 months ago
- 3 comments
Labels: help wanted, build
#563 - Bump org.junit:junit-bom from 5.10.3 to 5.11.2
Pull Request -
State: closed - Opened by dependabot[bot] 10 months ago
Labels: java, build
#562 - Bump org.apache.maven.plugins:maven-project-info-reports-plugin from 3.6.2 to 3.7.0
Pull Request -
State: closed - Opened by dependabot[bot] 10 months ago
- 2 comments
Labels: build
#561 - Bump org.apache.maven.plugins:maven-gpg-plugin from 3.2.4 to 3.2.7
Pull Request -
State: closed - Opened by dependabot[bot] 10 months ago
Labels: java, build
#560 - run mvn verify in CI instead of package
Pull Request -
State: closed - Opened by hboutemy 10 months ago
Labels: build
#559 - fix site issues created by upgrades #553 and #552
Pull Request -
State: closed - Opened by hboutemy 10 months ago
Labels: build
#558 - Bump org.apache.maven.plugins:maven-javadoc-plugin from 3.8.0 to 3.10.1
Pull Request -
State: closed - Opened by dependabot[bot] 10 months ago
Labels: build
#557 - Consider adding a CONTRIBUTING.md file
Issue -
State: open - Opened by thesurlydev 10 months ago
- 1 comment
#556 - Support 1.6 spec
Pull Request -
State: closed - Opened by thesurlydev 10 months ago
- 3 comments
Labels: major-rfe
#555 - Bump actions/checkout from 4.1.7 to 4.2.0
Pull Request -
State: closed - Opened by dependabot[bot] 10 months ago
Labels: github_actions, build
#554 - Bump org.apache.maven.plugins:maven-javadoc-plugin from 3.8.0 to 3.10.0
Pull Request -
State: closed - Opened by dependabot[bot] 10 months ago
- 1 comment
Labels: dependencies, java
#553 - Bump org.apache.maven.plugins:maven-site-plugin from 3.12.1 to 3.20.0
Pull Request -
State: closed - Opened by dependabot[bot] 10 months ago
Labels: build
#552 - Bump org.apache.maven.plugins:maven-project-info-reports-plugin from 3.6.1 to 3.7.0
Pull Request -
State: closed - Opened by dependabot[bot] 10 months ago
Labels: dependencies, java
#551 - Bump plugin-tools.version from 3.13.1 to 3.15.0
Pull Request -
State: closed - Opened by dependabot[bot] 10 months ago
Labels: dependencies, java
#550 - display configured classifier from #506
Pull Request -
State: closed - Opened by hboutemy 10 months ago
Labels: bug
#549 - Bump io.takari.maven.plugins:takari-plugin-testing from 3.0.0 to 3.0.5
Pull Request -
State: closed - Opened by dependabot[bot] 11 months ago
- 1 comment
Labels: dependencies, java, build
#548 - Bump io.takari.maven.plugins:takari-plugin-integration-testing from 3.0.1 to 3.0.5
Pull Request -
State: closed - Opened by dependabot[bot] 11 months ago
- 1 comment
Labels: dependencies, java
#547 - Wrong log-message while attaching bom with classifier
Issue -
State: closed - Opened by jonnybecker 11 months ago
- 1 comment
Labels: bug
#546 - Bump org.apache.commons:commons-lang3 from 3.14.0 to 3.17.0
Pull Request -
State: closed - Opened by dependabot[bot] 11 months ago
Labels: dependencies, java
#545 - Bump io.takari.maven.plugins:takari-plugin-integration-testing from 3.0.1 to 3.0.4
Pull Request -
State: closed - Opened by dependabot[bot] 11 months ago
- 1 comment
Labels: dependencies, java
#544 - Bump io.takari.maven.plugins:takari-plugin-testing from 3.0.0 to 3.0.4
Pull Request -
State: closed - Opened by dependabot[bot] 11 months ago
- 1 comment
Labels: dependencies, java
#543 - Avoid resources filtering warning
Pull Request -
State: closed - Opened by Bananeweizen 12 months ago
- 1 comment
Labels: build
#542 - Make log output more easy to understand by sorting
Pull Request -
State: closed - Opened by Bananeweizen 12 months ago
- 1 comment
Labels: enhancement
#541 - Sort log output for easier understanding of excluded/not depended upon artifacts
Issue -
State: closed - Opened by Bananeweizen 12 months ago
#540 - Bump org.apache.commons:commons-lang3 from 3.14.0 to 3.16.0
Pull Request -
State: closed - Opened by dependabot[bot] 12 months ago
- 1 comment
Labels: dependencies, java
#539 - Bump org.cyclonedx:cyclonedx-core-java from 8.0.3 to 9.0.5
Pull Request -
State: closed - Opened by dependabot[bot] 12 months ago
- 3 comments
Labels: dependencies, java
#538 - Bump org.apache.commons:commons-lang3 from 3.14.0 to 3.15.0
Pull Request -
State: closed - Opened by dependabot[bot] 12 months ago
- 1 comment
Labels: dependencies, java
#537 - Bump commons-codec:commons-codec from 1.17.0 to 1.17.1
Pull Request -
State: closed - Opened by dependabot[bot] 12 months ago
Labels: dependencies, java
#536 - upgrade cyclonedx-maven-plugin from 2.7.9 to 2.8.0
Pull Request -
State: closed - Opened by hboutemy 12 months ago
Labels: dependencies, java
#535 - Bump org.apache.maven.plugins:maven-release-plugin from 3.0.1 to 3.1.1
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
Labels: dependencies, java
#533 - Bump org.apache.maven.plugins:maven-javadoc-plugin from 3.7.0 to 3.8.0
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
Labels: dependencies, java
#532 - Bump net.javacrumbs.json-unit:json-unit-assertj from 2.38.0 to 2.40.1
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
Labels: dependencies, java
#531 - Can 'externalReferences' be disabled?
Issue -
State: open - Opened by jonnybecker about 1 year ago
- 3 comments
#530 - Bump io.takari.maven.plugins:takari-plugin-testing from 3.0.0 to 3.0.3
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
- 1 comment
Labels: dependencies, java
#529 - Bump io.takari.maven.plugins:takari-plugin-integration-testing from 3.0.1 to 3.0.3
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
- 1 comment
Labels: dependencies, java
#528 - Bump org.apache.maven.plugins:maven-jar-plugin from 3.4.1 to 3.4.2
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
Labels: dependencies, java
#527 - Bump org.junit:junit-bom from 5.10.2 to 5.10.3
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
Labels: dependencies, java
#526 - Selecting outputFormat=json does not honor outputDirectory
Issue -
State: closed - Opened by wepackard about 1 year ago
- 1 comment
Labels: bug, invalid
#525 - Bump org.apache.maven.plugins:maven-project-info-reports-plugin from 3.5.0 to 3.6.1
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
Labels: dependencies, java
#524 - Bump org.cyclonedx:cyclonedx-core-java from 7.2.1 to 9.0.4 in /src/it/makeBom
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
- 1 comment
Labels: dependencies, java
#523 - Bump org.cyclonedx:cyclonedx-core-java from 8.0.3 to 9.0.4
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
- 1 comment
Labels: dependencies, java
#522 - Fix incorrect component type in aggregated SBOM (Multi-module project)
Pull Request -
State: closed - Opened by lonewalker0 about 1 year ago
Labels: bug
#521 - Default component type is set to "library" for non-library submodules in multimodule Maven project
Issue -
State: closed - Opened by lonewalker0 about 1 year ago
- 4 comments
#520 - Bump org.apache.maven.plugins:maven-project-info-reports-plugin from 3.5.0 to 3.6.0
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
- 1 comment
Labels: dependencies, java
#519 - Bump plugin-tools.version from 3.13.0 to 3.13.1
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
Labels: dependencies, java
#518 - simplify compiler release configuration
Pull Request -
State: closed - Opened by hboutemy about 1 year ago
- 4 comments
Labels: build
#517 - replace CDX 1.5 deprecated tool
Pull Request -
State: closed - Opened by hboutemy about 1 year ago
Labels: enhancement
#516 - Bump org.cyclonedx:cyclonedx-core-java from 8.0.3 to 9.0.3
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
- 1 comment
Labels: dependencies, java
#515 - Bump actions/checkout from 4.1.6 to 4.1.7
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
Labels: dependencies, github_actions
#514 - bom.xml has no licenses
Issue -
State: open - Opened by apusic about 1 year ago
- 1 comment
#513 - bom.xml has no licenses
Issue -
State: closed - Opened by apusic about 1 year ago
#512 - Bump org.apache.maven.plugins:maven-invoker-plugin from 3.6.1 to 3.7.0
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
Labels: dependencies, java
#511 - Bump org.apache.maven.plugins:maven-javadoc-plugin from 3.6.3 to 3.7.0
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
Labels: dependencies, java
#510 - Bump org.cyclonedx:cyclonedx-core-java from 8.0.3 to 9.0.2
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
- 1 comment
Labels: dependencies, java
#509 - Bump org.apache.maven.plugins:maven-enforcer-plugin from 3.4.1 to 3.5.0
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
Labels: dependencies, java
#508 - Bump org.apache.maven.shared:maven-dependency-tree from 3.2.1 to 3.3.0
Pull Request -
State: closed - Opened by dependabot[bot] about 1 year ago
Labels: dependencies, java