Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Feb 26, 2025

Bumps org.slf4j:slf4j-api from 1.7.36 to 2.0.17.

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Feb 26, 2025
@dependabot dependabot bot requested a review from a team as a code owner February 26, 2025 03:41
@dependabot dependabot bot added the java Pull requests that update Java code label Feb 26, 2025
@dependabot dependabot bot force-pushed the dependabot/gradle/org.slf4j-slf4j-api-2.0.17 branch from c8986b4 to da891bf Compare February 26, 2025 14:47
@Filip1x9
Copy link
Contributor

Filip1x9 commented Jun 6, 2025

@dependabot rebase

@dependabot dependabot bot force-pushed the dependabot/gradle/org.slf4j-slf4j-api-2.0.17 branch from da891bf to f9c1fd3 Compare June 6, 2025 09:50
@Filip1x9
Copy link
Contributor

Filip1x9 commented Feb 2, 2026

@dependabot rebase

@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Feb 2, 2026

Looks like this PR has been edited by someone other than Dependabot. That means Dependabot can't rebase it - sorry!

If you're happy for Dependabot to recreate it from scratch, overwriting any edits, you can request @dependabot recreate.

@Filip1x9
Copy link
Contributor

Filip1x9 commented Feb 2, 2026

@dependabot recreate

Bumps org.slf4j:slf4j-api from 1.7.36 to 2.0.17.

---
updated-dependencies:
- dependency-name: org.slf4j:slf4j-api
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/gradle/org.slf4j-slf4j-api-2.0.17 branch from 7658b8e to 1435ad9 Compare February 2, 2026 15:16
@RicoFactset
Copy link

Logo
Checkmarx One – Scan Summary & Details4019690c-6845-4a14-aba5-cff5ebaa5cd6

New Issues (1)

Checkmarx found the following issues in this Pull Request

# Severity Issue Source File / Package Checkmarx Insight
1 LOW CVE-2026-1225 Maven-ch.qos.logback:logback-core-1.3.15
detailsRecommended version: 1.5.25
Description: ACE vulnerability in configuration file processing by QOS.CH logback-core up to and including version 1.5.24 in Java applications, allows an attac...
Attack Vector: LOCAL
Attack Complexity: HIGH
Vulnerable Package

Use @Checkmarx to interact with Checkmarx PR Assistant.
Examples:
@Checkmarx how are you able to help me?
@Checkmarx rescan this PR

@Filip1x9 Filip1x9 merged commit 42e45c5 into main Feb 2, 2026
10 checks passed
@Filip1x9 Filip1x9 deleted the dependabot/gradle/org.slf4j-slf4j-api-2.0.17 branch February 2, 2026 16:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants