Skip to content

build(deps): bump com.puppycrawl.tools:checkstyle from 10.12.3 to 10.25.0#1881

Closed
dependabot[bot] wants to merge 1 commit into1.x.xfrom
dependabot/maven/com.puppycrawl.tools-checkstyle-10.25.0
Closed

build(deps): bump com.puppycrawl.tools:checkstyle from 10.12.3 to 10.25.0#1881
dependabot[bot] wants to merge 1 commit into1.x.xfrom
dependabot/maven/com.puppycrawl.tools-checkstyle-10.25.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Jun 12, 2025

Bumps com.puppycrawl.tools:checkstyle from 10.12.3 to 10.25.0.

Release notes

Sourced from com.puppycrawl.tools:checkstyle's releases.

checkstyle-10.25.0

Checkstyle 10.25.0 - https://checkstyle.org/releasenotes.html#Release_10.25.0

New:

#14945 - Add Check Support for Java 21 Record Pattern : New Check UnnecessaryNullCheckWithInstanceOf

Bug fixes:

#17120 - False positives for google_checks when using switch expression in lambda

checkstyle-10.24.0

Checkstyle 10.24.0 - https://checkstyle.org/releasenotes.html#Release_10.24.0

New:

#5983 - CLI: generate suppresion xml content (SuppressionFilter) for certain Checks but whole file with violation #16174 - New Check: MultiFileRegexpHeader to allow specify few header file to validate

Bug fixes:

#16786 - private enums being treated as public in JavadocVariableCheck #16564 - EmptyLineSeparator check does not validate newlines before comments in Interfaces #8807 - SuppressWithPlainTextCommentFilter is slow on files with multiple errors #14654 - incompatibility with google-java-format: CatchFormalParameter is indented by 4 spaces instead of 2 #15098 - Indentation of the Block child of switch rule is not validated when no braces

... (truncated)

Commits
  • 6242de6 [maven-release-plugin] prepare release checkstyle-10.25.0
  • 81f2fae doc: release notes for 10.25.0
  • c44cd64 infra: PR_NUMBER is not a special variable any more
  • ac2dfca infra: print more in logs to understand reasons of failure
  • b0e04b3 Pull #17146: allow cirrus to run on PR from its own repository
  • 7206dc2 dependency: bump pmd.version from 7.13.0 to 7.14.0
  • 42b8a4b Issue #17142: add excluded link to avoid false positives from broken link check
  • 8883d3b Issue #17139: build set JAVA_HOME and update PATH for OpenJDK installation
  • 2fff2de dependency: bump commons-beanutils:commons-beanutils
  • 57962fa Issue #17127: Add hazelcast project to no-error CI job
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [com.puppycrawl.tools:checkstyle](https://github.com/checkstyle/checkstyle) from 10.12.3 to 10.25.0.
- [Release notes](https://github.com/checkstyle/checkstyle/releases)
- [Commits](checkstyle/checkstyle@checkstyle-10.12.3...checkstyle-10.25.0)

---
updated-dependencies:
- dependency-name: com.puppycrawl.tools:checkstyle
  dependency-version: 10.25.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file maven labels Jun 12, 2025
@github-actions
Copy link
Copy Markdown
Contributor

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ❌ 1 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ✅ 0 package(s) with unknown licenses.
See the Details below.

Snapshot Warnings

⚠️: No snapshots were found for the head SHA 467553b.
Ensure that dependencies are being submitted on PR branches and consider enabling retry-on-snapshot-warnings. See the documentation for more information and troubleshooting advice.

License Issues

pom.xml

PackageVersionLicenseIssue Type
com.puppycrawl.tools:checkstyle10.25.0LGPL-2.1Incompatible License
Allowed Licenses: Apache-1.1, Apache-2.0, ISC, MIT, MIT-0, MIT-CMU, MIT-enna, MIT-feh, MIT-Festival, MIT-Modern-Variant, MIT-open-group, MIT-testregex, MIT-Wu, BSD-1-Clause, BSD-2-Clause, BSD-2-Clause-Views, BSD-3-Clause, BSD-3-Clause-Attribution, BSD-3-Clause-Clear, BSD-3-Clause-flex, BSD-3-Clause-HP, BSD-3-Clause-LBNL, BSD-3-Clause-Modification, BSD-3-Clause-No-Military-License, BSD-3-Clause-No-Nuclear-License, BSD-3-Clause-No-Nuclear-License-2014, BSD-3-Clause-No-Nuclear-Warranty, BSD-3-Clause-Open-MPI

OpenSSF Scorecard

PackageVersionScoreDetails
maven/com.puppycrawl.tools:checkstyle 10.25.0 🟢 6.8
Details
CheckScoreReason
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Maintained🟢 1030 commit(s) and 28 issue activity found in the last 90 days -- score normalized to 10
Code-Review🟢 6Found 17/25 approved changesets -- score normalized to 6
Security-Policy🟢 10security policy file detected
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
License🟢 10license file detected
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: githubv4.Query: Resource not accessible by integration
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Binary-Artifacts🟢 10no binaries found in the repo
Fuzzing🟢 10project is fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
SAST🟢 10SAST tool is run on all commits
Vulnerabilities🟢 100 existing vulnerabilities detected

Scanned Files

  • pom.xml

@sonarqubecloud
Copy link
Copy Markdown

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Jun 12, 2025

Looks like com.puppycrawl.tools:checkstyle is no longer a dependency, so this is no longer needed.

@dependabot dependabot Bot closed this Jun 12, 2025
@dependabot dependabot Bot deleted the dependabot/maven/com.puppycrawl.tools-checkstyle-10.25.0 branch June 12, 2025 10:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file maven size/XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants