Skip to content

chore(deps): bump @cyclonedx/cdxgen from 11.2.7 to 11.3.1#235

Merged
edezekiel merged 1 commit into
mainfrom
dependabot/npm_and_yarn/cyclonedx/cdxgen-11.3.1
May 30, 2025
Merged

chore(deps): bump @cyclonedx/cdxgen from 11.2.7 to 11.3.1#235
edezekiel merged 1 commit into
mainfrom
dependabot/npm_and_yarn/cyclonedx/cdxgen-11.3.1

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github May 19, 2025

Bumps @cyclonedx/cdxgen from 11.2.7 to 11.3.1.

Release notes

Sourced from @​cyclonedx/cdxgen's releases.

Release v11.3.1

All cdxgen container images would now included a signed BOM as an attachment. Use oras discover and pull commands to download these attachments as shown here.

What's Changed

Other Changes

Full Changelog: cdxgen/cdxgen@v11.3.0...v11.3.1

Release v11.3.0

This is a major release. cdxgen now uses Node 24 in single executable applications (sea) and container images for improved performance. For the first time, our sea binaries are built with pnpm node_modules and therefore have an identical dependency tree to the source and container images. Thanks to the excellent work from @​malice00, our build workflows are modernised and scalable. We have also trimmed multiple container images by removing Java and other unneeded packages without any loss of functionality (For instance, by using atom native binary which doesn't require Java).

What's Changed

🧪 Testing

🏗️ Build System

Other Changes

New Contributors

Full Changelog: cdxgen/cdxgen@v11.2.7...v11.3.0

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels May 19, 2025
@dependabot dependabot Bot requested a review from a team as a code owner May 19, 2025 21:07
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code labels May 19, 2025
@rlmestre
Copy link
Copy Markdown
Contributor

@dependabot recreate

Bumps [@cyclonedx/cdxgen](https://github.com/CycloneDX/cdxgen) from 11.2.7 to 11.3.1.
- [Release notes](https://github.com/CycloneDX/cdxgen/releases)
- [Commits](cdxgen/cdxgen@v11.2.7...v11.3.1)

---
updated-dependencies:
- dependency-name: "@cyclonedx/cdxgen"
  dependency-version: 11.3.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/npm_and_yarn/cyclonedx/cdxgen-11.3.1 branch from 754a40c to d822043 Compare May 29, 2025 15:22
@rlmestre
Copy link
Copy Markdown
Contributor

We need this bumped to 11.3.2 to get an important change fixed upstream

@edezekiel edezekiel merged commit e054ed1 into main May 30, 2025
12 checks passed
@edezekiel edezekiel deleted the dependabot/npm_and_yarn/cyclonedx/cdxgen-11.3.1 branch May 30, 2025 14:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file javascript Pull requests that update javascript code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants