Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Conversation

@lewmilburn
Copy link
Collaborator

No description provided.

dependabot bot and others added 20 commits May 19, 2025 13:38
Bumps [org.jetbrains:annotations](https://github.com/JetBrains/java-annotations) from 26.0.1 to 26.0.2.
- [Release notes](https://github.com/JetBrains/java-annotations/releases)
- [Changelog](https://github.com/JetBrains/java-annotations/blob/master/CHANGELOG.md)
- [Commits](JetBrains/java-annotations@26.0.1...26.0.2)

---
updated-dependencies:
- dependency-name: org.jetbrains:annotations
  dependency-version: 26.0.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [org.apache.maven.plugins:maven-compiler-plugin](https://github.com/apache/maven-compiler-plugin) from 3.13.0 to 3.14.0.
- [Release notes](https://github.com/apache/maven-compiler-plugin/releases)
- [Commits](apache/maven-compiler-plugin@maven-compiler-plugin-3.13.0...maven-compiler-plugin-3.14.0)

---
updated-dependencies:
- dependency-name: org.apache.maven.plugins:maven-compiler-plugin
  dependency-version: 3.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps commons-io:commons-io from 2.18.0 to 2.19.0.

---
updated-dependencies:
- dependency-name: commons-io:commons-io
  dependency-version: 2.19.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [com.github.technicallycoded:FoliaLib](https://github.com/TechnicallyCoded/FoliaLib) from v0.4.3 to 0.4.4.
- [Release notes](https://github.com/TechnicallyCoded/FoliaLib/releases)
- [Commits](TechnicallyCoded/FoliaLib@0.4.3...0.4.4)

---
updated-dependencies:
- dependency-name: com.github.technicallycoded:FoliaLib
  dependency-version: 0.4.4
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
@github-actions
Copy link

Thank you for opening a pull request to Essence.

You've requested to merge something into main, please note that if you're adding, removing, or changing a feature on Essence you must merge into next-update so that compatability can be checked properly with any other pending changes.

We unfortunately do not accept any pull requests into main, for more information please click here. Please close and reopen your pull request into next-update if this is the case.

Thank you!

@github-actions
Copy link

github-actions bot commented May 19, 2025

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 3 package(s) with unknown licenses.
  • ⚠️ 1 packages with OpenSSF Scorecard issues.
See the Details below.

License Issues

pom.xml

PackageVersionLicenseIssue Type
com.github.technicallycoded:FoliaLib0.4.4NullUnknown License
com.tchristofferson:ConfigUpdater2.2-SNAPSHOTNullUnknown License
io.papermc.paper:paper-api1.21-R0.1-SNAPSHOTNullUnknown License

OpenSSF Scorecard

PackageVersionScoreDetails
actions/actions/setup-java 2.*.* 🟢 5.6
Details
CheckScoreReason
Code-Review🟢 10all changesets reviewed
Maintained🟢 34 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 3
Packaging⚠️ -1packaging workflow not detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Security-Policy🟢 9security policy file detected
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
SAST🟢 9SAST tool is not run on all commits -- score normalized to 9
Vulnerabilities🟢 82 existing vulnerabilities detected
maven/com.github.technicallycoded:FoliaLib 0.4.4 UnknownUnknown
maven/com.tchristofferson:ConfigUpdater 2.2-SNAPSHOT UnknownUnknown
maven/io.papermc.paper:paper-api 1.21-R0.1-SNAPSHOT UnknownUnknown
maven/org.apache.maven.plugins:maven-compiler-plugin 3.14.0 🟢 5.2
Details
CheckScoreReason
Code-Review🟢 6Found 8/13 approved changesets -- score normalized to 6
Packaging⚠️ -1packaging workflow not detected
Maintained🟢 1028 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 10
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Security-Policy🟢 10security policy file detected
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Vulnerabilities🟢 64 existing vulnerabilities detected
maven/org.jetbrains:annotations 26.0.2 ⚠️ 2
Details
CheckScoreReason
Maintained⚠️ 00 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
Dangerous-Workflow⚠️ -1no workflows found
Packaging⚠️ -1packaging workflow not detected
Code-Review⚠️ 2Found 5/18 approved changesets -- score normalized to 2
Binary-Artifacts🟢 9binaries present in source code
Token-Permissions⚠️ -1No tokens found
Pinned-Dependencies⚠️ -1no dependencies found
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Fuzzing⚠️ 0project is not fuzzed
Signed-Releases⚠️ -1no releases found
Security-Policy⚠️ 0security policy file not detected
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Vulnerabilities⚠️ 19 existing vulnerabilities detected

Scanned Files

  • .github/workflows/maven.yml
  • pom.xml

…ithub.technicallycoded-FoliaLib-0.4.4

Bump com.github.technicallycoded:FoliaLib from v0.4.3 to 0.4.4
…ns-io-commons-io-2.19.0

Bump commons-io:commons-io from 2.18.0 to 2.19.0
…pache.maven.plugins-maven-compiler-plugin-3.14.0

Bump org.apache.maven.plugins:maven-compiler-plugin from 3.13.0 to 3.14.0
…etbrains-annotations-26.0.2

Bump org.jetbrains:annotations from 26.0.1 to 26.0.2
@sonarqubecloud
Copy link

sonarqubecloud bot commented Aug 4, 2025

Quality Gate Failed Quality Gate failed

Failed conditions
15.3% Duplication on New Code (required ≤ 3%)

See analysis details on SonarQube Cloud

@lewmilburn lewmilburn merged commit 5c7ba81 into main Aug 4, 2025
6 of 7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants