Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We鈥檒l occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump promoted-builds from 2.27 to 3.10.1 #324

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Apr 22, 2022

Bumps promoted-builds from 2.27 to 3.10.1.

Release notes

Sourced from promoted-builds's releases.

3.10

馃摝 Dependency updates

  • Use newer project-inheritance dependency (19.08.02 instead of 1.5.3) (#153) @鈥媕glick

馃摑 Documentation updates

3.9 (no functional changes)

馃懟 Maintenance

  • Fix incompatibility with Jenkins 2.266 and higher in test code. (#151) @鈥媕tnord

3.7

馃懟 Maintenance

3.6

馃殌 New features and improvements

馃懟 Maintenance

3.5

馃悰 Bug Fixes

馃摝 Dependency updates

馃懟 Maintenance

... (truncated)

Changelog

Sourced from promoted-builds's changelog.

Changelog

Version 3.3 and newer releases

See GitHub Releases

Version 3.2 (JUN 4, 2018)
Version 3.1 (Mar 12, 2018)
  • JENKINS-40803聽-聽Prevent infinite loop while promoting a build when the聽Config File Provider Plugin is installed.
Version 3.0 (Feb 26, 2018)
  • (https://github.com/jenkinsci/promoted-builds-plugin/blob/master/error) SECURITY-746 - Make permissions consistent for聽Approve, Re-Execute, and Force promotion actions
    • Users with just the Promotion/Promote permission are no longer allowed to re-execute or force promotions with a manual condition that specifies a list of users, unless the user is on that list

    • Users specified in a manual promotion condition are now allowed to force this promotion

    • Administrators are now able to approve any promotion with a manual condition

Compatibility Notes:

  • This change alters the behavior of the Plugin in some conditions, jobs may require reconfiguration.
  • Table below shows the permission changes. Legend:
    • Cells with bold red text - indicate combinations, which revoke dangerous permissions
    • (manual condition) - Action

(https://github.com/jenkinsci/promoted-builds-plugin/blob/master/permission)

Version 2.31.1 (Feb 13, 2018)
  • (https://github.com/jenkinsci/promoted-builds-plugin/blob/master/error) JENKINS-49433 - Prevent NullPointerException in JobDSL when omitting the聽evenIfUnstable argument
    • Affected JobDSL methods:聽selfPromotion(), parameterizedSelfPromotion(), downstream()
  • [(https://github.com/jenkinsci/promoted-builds-plugin/blob/master/error)

... (truncated)

Commits
  • 5fe37ca [maven-release-plugin] prepare release promoted-builds-3.10.1
  • 0a51bfe SECURITY-2692
  • 6c1d276 SECURITY-2670
  • 641f505 SECURITY-2655
  • 03309e6 [maven-release-plugin] prepare for next development iteration
  • 830c99d [maven-release-plugin] prepare release promoted-builds-3.10
  • 7788115 Merge pull request #152 from aHenryJard/JENKINS-65398_terminology
  • 97ee1d6 Merge pull request #153 from jglick/bump-project-inheritance
  • c1c6400 Use newer project-inheritance dep
  • c730037 Removing not necessary jelly attributes
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
  • @dependabot use these labels will set the current labels as the default for future PRs for this repo and language
  • @dependabot use these reviewers will set the current reviewers as the default for future PRs for this repo and language
  • @dependabot use these assignees will set the current assignees as the default for future PRs for this repo and language
  • @dependabot use this milestone will set the current milestone as the default for future PRs for this repo and language

You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [promoted-builds](https://github.com/jenkinsci/promoted-builds-plugin) from 2.27 to 3.10.1.
- [Release notes](https://github.com/jenkinsci/promoted-builds-plugin/releases)
- [Changelog](https://github.com/jenkinsci/promoted-builds-plugin/blob/master/CHANGELOG.md)
- [Commits](jenkinsci/promoted-builds-plugin@promoted-builds-2.27...promoted-builds-3.10.1)

---
updated-dependencies:
- dependency-name: org.jenkins-ci.plugins:promoted-builds
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Apr 22, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file java Pull requests that update Java code
Projects
None yet
0 participants