Skip to content

chore(deps): update dependency com.github.eirslett:frontend-maven-plugin to v2 - #38

Open
renovate-wenisch-tech[bot] wants to merge 1 commit into
mainfrom
renovate/com.github.eirslett-frontend-maven-plugin-2.x
Open

renovate-wenisch-tech[bot] wants to merge 1 commit into
mainfrom
renovate/com.github.eirslett-frontend-maven-plugin-2.x

Conversation

@renovate-wenisch-tech

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
com.github.eirslett:frontend-maven-plugin 1.15.42.0.2 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

eirslett/frontend-maven-plugin (com.github.eirslett:frontend-maven-plugin)

v2.0.1

  • Use pnpm .mjs file if it exists to support 11+ (#​1224)

v2.0.0

This is a major version release, but there are no new features.
Lots of dependencies and minimum version requirements have been upgraded,
potentially breaking backwards compatibility.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown
Contributor

Trivy vulnerability report

Image: ghcr.io/wenisch-tech/s3webui:1.0.1-pr.38.267


Report Summary

┌───────────────────────────────────────────────────────────────┬───────┬─────────────────┐
│                            Target                             │ Type  │ Vulnerabilities │
├───────────────────────────────────────────────────────────────┼───────┼─────────────────┤
│ ghcr.io/wenisch-tech/s3webui:1.0.1-pr.38.267 (wolfi 20230201) │ wolfi │        0        │
├───────────────────────────────────────────────────────────────┼───────┼─────────────────┤
│ app/app.jar                                                   │  jar  │        0        │
└───────────────────────────────────────────────────────────────┴───────┴─────────────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


@renovate-wenisch-tech
renovate-wenisch-tech Bot force-pushed the renovate/com.github.eirslett-frontend-maven-plugin-2.x branch from 832f647 to beca3db Compare September 8, 2026 13:06
@github-actions

github-actions Bot commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

Trivy vulnerability report

Image: ghcr.io/wenisch-tech/s3webui:1.0.2-pr.38.274


Report Summary

┌───────────────────────────────────────────────────────────────┬───────┬─────────────────┐
│                            Target                             │ Type  │ Vulnerabilities │
├───────────────────────────────────────────────────────────────┼───────┼─────────────────┤
│ ghcr.io/wenisch-tech/s3webui:1.0.2-pr.38.274 (wolfi 20230201) │ wolfi │        0        │
├───────────────────────────────────────────────────────────────┼───────┼─────────────────┤
│ app/app.jar                                                   │  jar  │        3        │
└───────────────────────────────────────────────────────────────┴───────┴─────────────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


For OSS Maintainers: VEX Notice
--------------------------------
If you're an OSS maintainer and Trivy has detected vulnerabilities in your project that you believe are not actually exploitable, consider issuing a VEX (Vulnerability Exploitability eXchange) statement.
VEX allows you to communicate the actual status of vulnerabilities in your project, improving security transparency and reducing false positives for your users.
Learn more and start using VEX: https://trivy.dev/docs/v0.74/guide/supply-chain/vex/repo#publishing-vex-documents

To disable this notice, set the TRIVY_DISABLE_VEX_NOTICE environment variable.


Java (jar)
==========
Total: 3 (MEDIUM: 0, HIGH: 0, CRITICAL: 3)

┌─────────────────────────────────────────────────────┬────────────────┬──────────┬────────┬───────────────────┬───────────────────────────┬──────────────────────────────────────────────────────────────┐
│                       Library                       │ Vulnerability  │ Severity │ Status │ Installed Version │       Fixed Version       │                            Title                             │
├─────────────────────────────────────────────────────┼────────────────┼──────────┼────────┼───────────────────┼───────────────────────────┼──────────────────────────────────────────────────────────────┤
│ org.apache.tomcat.embed:tomcat-embed-core (app.jar) │ CVE-2026-65182 │ CRITICAL │ fixed  │ 11.0.24           │ 11.0.25, 10.1.58, 9.0.121 │ Apache Tomcat: Apache Tomcat: Security constraint bypass due │
│                                                     │                │          │        │                   │                           │ to improper access control...                                │
│                                                     │                │          │        │                   │                           │ https://avd.aquasec.com/nvd/cve-2026-65182                   │
│                                                     ├────────────────┤          │        │                   │                           ├──────────────────────────────────────────────────────────────┤
│                                                     │ CVE-2026-65905 │          │        │                   │                           │ tomcat: Apache Tomcat: Authentication bypass via limited     │
│                                                     │                │          │        │                   │                           │ replay attack in DIGEST authenticator...                     │
│                                                     │                │          │        │                   │                           │ https://avd.aquasec.com/nvd/cve-2026-65905                   │
│                                                     ├────────────────┤          │        │                   │                           ├──────────────────────────────────────────────────────────────┤
│                                                     │ CVE-2026-68525 │          │        │                   │                           │ org.apache.tomcat/tomcat: Apache Tomcat: Unauthorized        │
│                                                     │                │          │        │                   │                           │ resource access via FORM authentication bypass               │
│                                                     │                │          │        │                   │                           │ https://avd.aquasec.com/nvd/cve-2026-68525                   │
└─────────────────────────────────────────────────────┴────────────────┴──────────┴────────┴───────────────────┴───────────────────────────┴──────────────────────────────────────────────────────────────┘

@renovate-wenisch-tech
renovate-wenisch-tech Bot force-pushed the renovate/com.github.eirslett-frontend-maven-plugin-2.x branch from beca3db to 80e8734 Compare September 8, 2026 14:06
@github-actions

github-actions Bot commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

Trivy vulnerability report

Image: ghcr.io/wenisch-tech/s3webui:1.0.3-pr.38.279


Report Summary

┌───────────────────────────────────────────────────────────────┬───────┬─────────────────┐
│                            Target                             │ Type  │ Vulnerabilities │
├───────────────────────────────────────────────────────────────┼───────┼─────────────────┤
│ ghcr.io/wenisch-tech/s3webui:1.0.3-pr.38.279 (wolfi 20230201) │ wolfi │        0        │
├───────────────────────────────────────────────────────────────┼───────┼─────────────────┤
│ app/app.jar                                                   │  jar  │        0        │
└───────────────────────────────────────────────────────────────┴───────┴─────────────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


@renovate-wenisch-tech
renovate-wenisch-tech Bot force-pushed the renovate/com.github.eirslett-frontend-maven-plugin-2.x branch from 80e8734 to 2267d6e Compare September 8, 2026 18:09
@github-actions

github-actions Bot commented Sep 8, 2026

Copy link
Copy Markdown
Contributor

Trivy vulnerability report

Image: ghcr.io/wenisch-tech/s3webui:1.0.4-pr.38.282


Report Summary

┌───────────────────────────────────────────────────────────────┬───────┬─────────────────┐
│                            Target                             │ Type  │ Vulnerabilities │
├───────────────────────────────────────────────────────────────┼───────┼─────────────────┤
│ ghcr.io/wenisch-tech/s3webui:1.0.4-pr.38.282 (wolfi 20230201) │ wolfi │        0        │
├───────────────────────────────────────────────────────────────┼───────┼─────────────────┤
│ app/app.jar                                                   │  jar  │        0        │
└───────────────────────────────────────────────────────────────┴───────┴─────────────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


@renovate-wenisch-tech
renovate-wenisch-tech Bot force-pushed the renovate/com.github.eirslett-frontend-maven-plugin-2.x branch from 2267d6e to 1489e62 Compare September 10, 2026 18:08
@github-actions

Copy link
Copy Markdown
Contributor

Trivy vulnerability report

Image: ghcr.io/wenisch-tech/s3webui:1.2.1-pr.38.299


Report Summary

┌───────────────────────────────────────────────────────────────┬───────┬─────────────────┐
│                            Target                             │ Type  │ Vulnerabilities │
├───────────────────────────────────────────────────────────────┼───────┼─────────────────┤
│ ghcr.io/wenisch-tech/s3webui:1.2.1-pr.38.299 (wolfi 20230201) │ wolfi │        0        │
├───────────────────────────────────────────────────────────────┼───────┼─────────────────┤
│ app/app.jar                                                   │  jar  │        0        │
└───────────────────────────────────────────────────────────────┴───────┴─────────────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


@renovate-wenisch-tech
renovate-wenisch-tech Bot force-pushed the renovate/com.github.eirslett-frontend-maven-plugin-2.x branch from 1489e62 to ba4f271 Compare September 15, 2026 16:08
@github-actions

Copy link
Copy Markdown
Contributor

Trivy vulnerability report

Image: ghcr.io/wenisch-tech/s3webui:1.2.4-pr.38.322


Report Summary

┌───────────────────────────────────────────────────────────────┬───────┬─────────────────┐
│                            Target                             │ Type  │ Vulnerabilities │
├───────────────────────────────────────────────────────────────┼───────┼─────────────────┤
│ ghcr.io/wenisch-tech/s3webui:1.2.4-pr.38.322 (wolfi 20230201) │ wolfi │        1        │
├───────────────────────────────────────────────────────────────┼───────┼─────────────────┤
│ app/app.jar                                                   │  jar  │        0        │
└───────────────────────────────────────────────────────────────┴───────┴─────────────────┘
Legend:
- '-': Not scanned
- '0': Clean (no security findings detected)


For OSS Maintainers: VEX Notice
--------------------------------
If you're an OSS maintainer and Trivy has detected vulnerabilities in your project that you believe are not actually exploitable, consider issuing a VEX (Vulnerability Exploitability eXchange) statement.
VEX allows you to communicate the actual status of vulnerabilities in your project, improving security transparency and reducing false positives for your users.
Learn more and start using VEX: https://trivy.dev/docs/v0.74/guide/supply-chain/vex/repo#publishing-vex-documents

To disable this notice, set the TRIVY_DISABLE_VEX_NOTICE environment variable.


ghcr.io/wenisch-tech/s3webui:1.2.4-pr.38.322 (wolfi 20230201)
=============================================================
Total: 1 (MEDIUM: 1, HIGH: 0, CRITICAL: 0)

┌─────────┬────────────────┬──────────┬────────┬───────────────────┬───────────────┬───────────────────────────────────────────────────────────┐
│ Library │ Vulnerability  │ Severity │ Status │ Installed Version │ Fixed Version │                           Title                           │
├─────────┼────────────────┼──────────┼────────┼───────────────────┼───────────────┼───────────────────────────────────────────────────────────┤
│ zlib    │ CVE-2026-85091 │ MEDIUM   │ fixed  │ 1.3.2-r7          │ 1.3.3-r0      │ zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer │
│         │                │          │        │                   │               │ overflow vul ......                                       │
│         │                │          │        │                   │               │ https://avd.aquasec.com/nvd/cve-2026-85091                │
└─────────┴────────────────┴──────────┴────────┴───────────────────┴───────────────┴───────────────────────────────────────────────────────────┘

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants