From 3a383f1a81ea79fc49bd37df7077185f60dee8c3 Mon Sep 17 00:00:00 2001 From: halibobo1205 Date: Fri, 12 Dec 2025 17:25:18 +0800 Subject: [PATCH 1/2] CI(Dependency): add Dependency Submission --- .github/workflows/dependency-submission.yml | 29 +++++++++++++++++++++ 1 file changed, 29 insertions(+) create mode 100644 .github/workflows/dependency-submission.yml diff --git a/.github/workflows/dependency-submission.yml b/.github/workflows/dependency-submission.yml new file mode 100644 index 00000000000..5c0771efa12 --- /dev/null +++ b/.github/workflows/dependency-submission.yml @@ -0,0 +1,29 @@ +name: Dependency Submission + +on: + push: + branches: [ 'develop', 'master', 'release_**', 'CI/dependency_check' ] + pull_request: + branches: [ 'develop', "release_**" , 'CI/dependency_check' ] + + workflow_dispatch: + +permissions: + contents: write + +jobs: + dependency-submission: + runs-on: ubuntu-24.04-arm + + steps: + - name: Checkout sources + uses: actions/checkout@v4 + - name: Setup Java + uses: actions/setup-java@v4 + with: + distribution: 'temurin' + java-version: 17 + - name: Setup Gradle + uses: gradle/actions/setup-gradle@v4 + - name: Generate and submit dependency graph + uses: gradle/actions/dependency-submission@v4 \ No newline at end of file From d7191198c581c3c7a4b95443eb05839c5f665e13 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Fri, 12 Dec 2025 09:38:51 +0000 Subject: [PATCH 2/2] build(deps): bump org.apache.commons:commons-lang3 from 3.4 to 3.18.0 Bumps org.apache.commons:commons-lang3 from 3.4 to 3.18.0. --- updated-dependencies: - dependency-name: org.apache.commons:commons-lang3 dependency-version: 3.18.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] --- build.gradle | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/build.gradle b/build.gradle index a77c5918752..1a865d6dc8c 100644 --- a/build.gradle +++ b/build.gradle @@ -80,7 +80,7 @@ subprojects { implementation group: 'ch.qos.logback', name: 'logback-classic', version: '1.2.13' implementation "com.google.code.findbugs:jsr305:3.0.0" implementation group: 'org.springframework', name: 'spring-context', version: "${springVersion}" - implementation "org.apache.commons:commons-lang3:3.4" + implementation "org.apache.commons:commons-lang3:3.18.0" implementation group: 'org.apache.commons', name: 'commons-math', version: '2.2' implementation "org.apache.commons:commons-collections4:4.1" implementation group: 'joda-time', name: 'joda-time', version: '2.3'