← Back to issue list

build(deps): update bugfixes (main)

View original Github issue

Metadata

Project
craft-parts
Number
#1450
Type
pull request
State
closed
Author
renovate[bot]
Labels
PR: Dependencies
Created
Updated
Closed

Current evaluation

Closed without merging. The automated dependency update for maven-wrapper and maven-shade-plugin was not applied, likely due to failing CI checks or being superseded by a newer version.

Suggested action:

No scores available.

Issue body

This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [maven-wrapper](https://maven.apache.org/tools/wrapper/) ([source](https://redirect.github.com/apache/maven-wrapper)) | `3.3.2` → `3.3.4` | ![age](https://developer.mend.io/api/mc/badges/age/maven/org.apache.maven.wrapper:maven-wrapper/3.3.4?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/org.apache.maven.wrapper:maven-wrapper/3.3.2/3.3.4?slim=true) | | [org.apache.maven.plugins:maven-shade-plugin](https://maven.apache.org/plugins/) ([source](https://redirect.github.com/apache/maven-shade-plugin)) | `3.6.0` → `3.6.1` | ![age](https://developer.mend.io/api/mc/badges/age/maven/org.apache.maven.plugins:maven-shade-plugin/3.6.1?slim=true) | ![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/org.apache.maven.plugins:maven-shade-plugin/3.6.0/3.6.1?slim=true) | --- > [!WARNING] > Some dependencies could not be looked up. Check the Dependency Dashboard for more information. --- ### Release Notes <details> <summary>apache/maven-wrapper (maven-wrapper)</summary> ### [`v3.3.4`](https://redirect.github.com/apache/maven-wrapper/releases/tag/maven-wrapper-3.3.4): 3.3.4 [Compare Source](https://redirect.github.com/apache/maven-wrapper/compare/maven-wrapper-3.3.3...maven-wrapper-3.3.4) <!-- Optional: add a release summary here --> #### 🐛 Bug Fixes - Revert wrapper version removal ([#&#8203;365](https://redirect.github.com/apache/maven-wrapper/pull/365)) [@&#8203;breun](https://redirect.github.com/breun) #### 👻 Maintenance - Ensure Path Traversal is fully addressed in MavenWrapperDownloader ([#&#8203;363](https://redirect.github.com/apache/maven-wrapper/pull/363)) [@&#8203;hazendaz](https://redirect.github.com/hazendaz) ### [`v3.3.3`](https://redirect.github.com/apache/maven-wrapper/releases/tag/maven-wrapper-3.3.3): 3.3.3 [Compare Source](https://redirect.github.com/apache/maven-wrapper/compare/maven-wrapper-3.3.2...maven-wrapper-3.3.3) <!-- Optional: add a release summary here --> #### :boom: Breaking changes - Remove wrapper lifecycle ([#&#8203;357](https://redirect.github.com/apache/maven-wrapper/pull/357)) [@&#8203;slawekjaranowski](https://redirect.github.com/slawekjaranowski) #### 🚀 New features and improvements - Fix Maven wrapper support for snapshot distributions ([#&#8203;335](https://redirect.github.com/apache/maven-wrapper/pull/335)) [@&#8203;gnodet](https://redirect.github.com/gnodet) #### 🐛 Bug Fixes - [\[MWRAPPER-143\]](https://issues.apache.org/jira/browse/MWRAPPER-143) - The wrapperVersion property is not used in only-script mode ([#&#8203;145](https://redirect.github.com/apache/maven-wrapper/pull/145)) [@&#8203;bdemers](https://redirect.github.com/bdemers) - fix: Maven wrapper relative distributionUrl does not work (fixes [#&#8203;272](https://redirect.github.com/apache/maven-wrapper/issues/272)) ([#&#8203;107](https://redirect.github.com/apache/maven-wrapper/pull/107)) [@&#8203;danishcake](https://redirect.github.com/danishcake) - Fix Windows Junction Link support in mvnw\.cmd ([#&#8203;143](https://redirect.github.com/apache/maven-wrapper/pull/143)) [@&#8203;fp024](https://redirect.github.com/fp024) - [\[MWRAPPER-158\]](https://issues.apache.org/jira/browse/MWRAPPER-158) - Remove incorrect license header ([#&#8203;166](https://redirect.github.com/apache/maven-wrapper/pull/166)) [@&#8203;lbruun](https://redirect.github.com/lbruun) - [\[MWRAPPER-161\]](https://issues.apache.org/jira/browse/MWRAPPER-161) - Improve script directory detection when using sh mvnw ([#&#8203;329](https://redirect.github.com/apache/maven-wrapper/pull/329)) [@&#8203;ppkarwasz](https://redirect.github.com/ppkarwasz) - [\[MWRAPPER-162\]](https://issues.apache.org/jira/browse/MWRAPPER-162) - Removed dead link was getting 404 ([#&#8203;167](https://redirect.github.com/apache/maven-wrapper/pull/167)) [@&#8203;montu376](https://redirect.github.com/montu376) - [\[MWRAPPER-159\]](https://issues.apache.org/jira/browse/MWRAPPER-159) - Fix shellcheck in mvnw ([#&#8203;168](https://redirect.github.com/apache/maven-wrapper/pull/168)) [@&#8203;slawekjaranowski](https://redirect.github.com/slawekjaranowski) - [\[MWRAPPER-146\]](https://issues.apache.org/jira/browse/MWRAPPER-146) - Bad substitution on Windows if MVNW\_REPOURL is set on script-only ([#&#8203;151](https://redirect.github.com/apache/maven-wrapper/pull/151)) [@&#8203;jahk04](https://redirect.github.com/jahk04) - [\[MWRAPPER-147\]](https://issues.apache.org/jira/browse/MWRAPPER-147) - mvnw\.cmd fails to launch maven if username contains space ([#&#8203;152](https://redirect.github.com/apache/maven-wrapper/pull/152)) [@&#8203;sebthom](https://redirect.github.com/sebthom) - [\[MWRAPPER-150\]](https://issues.apache.org/jira/browse/MWRAPPER-150) - Fails to validate checksums on MacOS Sequoia ([#&#8203;155](https://redirect.github.com/apache/maven-wrapper/pull/155)) [@&#8203;jon-signal](https://redirect.github.com/jon-signal) - [\[MWRAPPER-111\]](https://issues.apache.org/jira/browse/MWRAPPER-111) - Trim whitespace when reading from properties file ([#&#8203;158](https://redirect.github.com/apache/maven-wrapper/pull/158)) [@&#8203;mhalbritter](https://redirect.github.com/mhalbritter) - [\[MWRAPPER-153\]](https://issues.apache.org/jira/browse/MWRAPPER-153) - Fixed only-mvnw\.cmd fails when FIPS mode is enabled on Windows hosts ([#&#8203;157](https://redirect.github.com/apache/maven-wrapper/pull/157)) [@&#8203;zbalkan](https://redirect.github.com/zbalkan) #### 📝 Documentation updates - Clarify usage of MAVEN\_USER\_HOME ([#&#8203;359](https://redirect.github.com/apache/maven-wrapper/pull/359)) [@&#8203;slawekjaranowski](https://redirect.github.com/slawekjaranowski) - site is now /tools/wrapper ([#&#8203;336](https://redirect.github.com/apache/maven-wrapper/pull/336)) [@&#8203;hboutemy](https://redirect.github.com/hboutemy) #### 👻 Maintenance - Use invoker version from parent ([#&#8203;356](https://redirect.github.com/apache/maven-wrapper/pull/356)) [@&#8203;slawekjaranowski](https://redirect.github.com/slawekjaranowski) - Refresh download page ([#&#8203;354](https://redirect.github.com/apache/maven-wrapper/pull/354)) [@&#8203;slawekjaranowski](https://redirect.github.com/slawekjaranowski) - Update site descriptor to 2.0.0 ([#&#8203;351](https://redirect.github.com/apache/maven-wrapper/pull/351)) [@&#8203;slawekjaranowski](https://redirect.github.com/slawekjaranowski) - Enable prevent branch protection rules ([#&#8203;348](https://redirect.github.com/apache/maven-wrapper/pull/348)) [@&#8203;slawekjaranowski](https://redirect.github.com/slawekjaranowski) - Copy edit docs ([#&#8203;344](https://redirect.github.com/apache/maven-wrapper/pull/344)) [@&#8203;elharo](https://redirect.github.com/elharo) - Prefer [@&#8203;Inject](https://redirect.github.com/Inject) ([#&#8203;343](https://redirect.github.com/apache/maven-wrapper/pull/343)) [@&#8203;elharo](https://redirect.github.com/elharo) - Bump shellcheck to 0.10.0 ([#&#8203;333](https://redirect.github.com/apache/maven-wrapper/pull/333)) [@&#8203;slachiewicz](https://redirect.github.com/slachiewicz) - Enable GitHub Issues ([#&#8203;169](https://redirect.github.com/apache/maven-wrapper/pull/169)) [@&#8203;slawekjaranowski](https://redirect.github.com/slawekjaranowski) - [\[MNGSITE-529\]](https://issues.apache.org/jira/browse/MNGSITE-529) - Rename "Goals" to "Plugin Documentation" ([#&#8203;163](https://redirect.github.com/apache/maven-wrapper/pull/163)) [@&#8203;Bukama](https://redirect.github.com/Bukama) #### 📦 Dependency updates - Bump mavenVersion from 3.9.6 to 3.9.11 ([#&#8203;360](https://redirect.github.com/apache/maven-wrapper/pull/360)) @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot) - Bump exec-maven-plugin to 3.5.1 in ITs ([#&#8203;355](https://redirect.github.com/apache/maven-wrapper/pull/355)) [@&#8203;slawekjaranowski](https://redirect.github.com/slawekjaranowski) - Bump org.codehaus.mojo:mrm-maven-plugin from 1.6.0 to 1.7.0 ([#&#8203;350](https://redirect.github.com/apache/maven-wrapper/pull/350)) @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot) - Bump org.codehaus.plexus:plexus-archiver from 4.10.0 to 4.10.1 ([#&#8203;349](https://redirect.github.com/apache/maven-wrapper/pull/349)) @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot) - Bump actions/checkout from 4 to 5 ([#&#8203;347](https://redirect.github.com/apache/maven-wrapper/pull/347)) @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot) - Bump commons-io:commons-io from 2.19.0 to 2.20.0 ([#&#8203;339](https://redirect.github.com/apache/maven-wrapper/pull/339)) @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot) - Bump commons-io:commons-io from 2.18.0 to 2.19.0 ([#&#8203;164](https://redirect.github.com/apache/maven-wrapper/pull/164)) @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot) - Bump org.apache.maven.resolver:maven-resolver-api from 1.9.20 to 1.9.24 ([#&#8203;334](https://redirect.github.com/apache/maven-wrapper/pull/334)) @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot) - Bump org.codehaus.plexus:plexus-io from 3.4.2 to 3.5.1 ([#&#8203;153](https://redirect.github.com/apache/maven-wrapper/pull/153)) @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot) - Bump org.codehaus.plexus:plexus-archiver from 4.9.2 to 4.10.0 ([#&#8203;147](https://redirect.github.com/apache/maven-wrapper/pull/147)) @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot) - Upgrade to parent pom 45 ([#&#8203;332](https://redirect.github.com/apache/maven-wrapper/pull/332)) [@&#8203;slachiewicz](https://redirect.github.com/slachiewicz) - [\[MWRAPPER-154\]](https://issues.apache.org/jira/browse/MWRAPPER-154) - Bump commons-io:commons-io from 2.16.1 to 2.18.0 ([#&#8203;161](https://redirect.github.com/apache/maven-wrapper/pull/161)) @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot) - Bump org.hamcrest:hamcrest from 2.2 to 3.0 ([#&#8203;149](https://redirect.github.com/apache/maven-wrapper/pull/149)) @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot) </details> --- ### Configuration 📅 **Schedule**: Branch creation - "every weekend" in timezone Etc/UTC, Automerge - At any time (no schedule defined). 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/canonical/craft-parts). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0Mi45NS4yIiwidXBkYXRlZEluVmVyIjoiNDIuOTUuMiIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiUFI6IERlcGVuZGVuY2llcyJdfQ==-->

Evaluation history

Date Model Scores Action Summary
qwen/qwen3.6-35b-a3b Closed without merging. The automated dependency update for maven-wrapper and maven-shade-plugin was not applied, likely due to failing CI checks or being superseded by a newer version.
qwen3.6-35b-a3b-mtp-q6 Merged automatically via Renovate bot. Updates maven-wrapper to 3.3.4 and maven-shade-plugin to 3.6.1 on the main branch.

Update history

No update history recorded yet.

Related issues

Issue Project State Summary Similarity
#1456 build(deps): update bugfixes (main) - autoclosed craft-parts closed Renovate dependency update for maven-wrapper and maven-shade-plugin was autoclosed due to a failing CI test. Not merged. Automatically recreated per configuration.
89%
#795 build(deps): update dependencies rockcraft closed Closed without merging. The pull request automated dependency updates via uv lock, bumping numerous packages and adjusting lock files. It received no reviews or CI checks before being closed.
74%
#1223 build(deps): update bugfixes (hotfix/1.5) rockcraft closed Closed unmerged due to failing CI checks across multiple test suites and linters. Dependency updates were not applied. The automated bot will recreate the request.
73%
#200 build(deps): update bugfixes (main) - abandoned craft-store closed Abandoned and closed without merging. Renovate flagged the dependency update for autoclosing, but branch modifications prevented automatic closure, leading to manual abandonment.
73%
#794 build(deps): update bugfixes (main) craft-application closed Closed without merging. The dependency update PR for pydantic-kitbash, pytest-mock, and setuptools was closed due to failing CI checks, including snap-tests, OSV-scanner, and lint, despite automerge being enabled.
73%
#202 build(deps): update bugfixes (hotfix/2.0) craft-archives closed Closed without merging after CI test failures. A maintainer requested removing the obsolete hotfix/2.0 branch, indicating the dependency update was abandoned or superseded.
73%
#326 build(deps): update bugfixes (hotfix/3.2) craft-store closed Closed without merging due to failing CI checks, including OSV-scanner and tests on Noble. The dependency updates for myst-parser, sphinx-lint, and sphinx-reredirects were abandoned and not applied to the hotfix branch.
73%
#1043 build(deps): update bugfixes (main) - autoclosed craft-parts closed Renovate autoclosed this dependency update without merging. It targeted canonical-sphinx-extensions, myst-parser, sphinx-reredirects, uvicorn, and watchfiles. All CI passed, but changes were abandoned due to inactivity.
72%
#678 build(deps): update dependencies rockcraft closed Closed without merging. The dependency update branch remained pending review with no comments or CI checks, and was likely abandoned due to prolonged inactivity and an unmet dependency on PR #675.
72%
#338 build(deps): update bugfixes (hotfix/3.2) craft-store closed Dependency updates were closed as stale. Failing OSV-scanner and minimum dependency checks led a maintainer to mark the branch stale, resulting in the pull request being abandoned without merging.
70%