Skip to content

Bump io.spring.gradle:spring-security-project-plugin from 1.0.19 to 1.0.20 - #19832

Open
dependabot[bot] wants to merge 1 commit into
7.0.xfrom
dependabot/gradle/7.0.x/io.spring.gradle-spring-security-project-plugin-1.0.20
Open

dependabot[bot] wants to merge 1 commit into
7.0.xfrom
dependabot/gradle/7.0.x/io.spring.gradle-spring-security-project-plugin-1.0.20

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps io.spring.gradle:spring-security-project-plugin from 1.0.19 to 1.0.20.

Release notes

Sourced from io.spring.gradle:spring-security-project-plugin's releases.

1.0.20

⭐ New Features

  • Add Develocity Conventions #119
  • Deprecate Unused Workflows #130
  • Update to Use SHA References #131

🪲 Bug Fixes

  • release-announcements-stage should checkout the code before running publish-release-notes #116
  • release-announcements-stage should grant pull-requests permission #118

🔨 Dependency Upgrades

  • Bump actions/setup-node from 4 to 7 #129
  • Bump actions/upload-artifact from 4 to 7 #127
  • Bump brace-expansion in /update-bot #145
  • Bump github/codeql-action/analyze from 3.38.2 to 4.38.2 #135
  • Bump gradle-wrapper from 9.2.1 to 9.7.1 #122
  • Bump gradle-wrapper from 9.2.1 to 9.8.0 #133
  • Bump io.spring.develocity.conventions from 0.0.25 to 0.0.26 #125
  • Bump io.spring.javaformat:spring-javaformat-gradle-plugin from 0.0.41 to 0.0.48 #123
  • Bump io.spring.security.release from 1.0.3 to 1.0.19 #120
  • Bump org.jfrog.buildinfo:build-info-extractor-gradle from 5.2.0 to 6.0.4 #124
  • Bump spring-io/artifactory-deploy-action from 0.0.4 to 0.0.5 #121
  • Bump spring-io/artifactory-deploy-action from 0.0.5 to 0.0.6 #138
  • Bump spring-io/central-publish-action from 0.3.0 to 0.4.0 #137
  • Bump spring-io/spring-github-workflows/.github/workflows/spring-merge-dependabot-pr.yml from 0c09eb4023e17dd6ca395a0f4e406a4f7506a58d to 798bca4d6aecf03e5166d85789c33c20a65499e1 #139
  • Bump spring-io/spring-release-actions/announce-on-gchat from 0.0.6 to 0.0.7 #132
  • Bump spring-io/spring-release-actions/compute-version from 0.0.6 to 0.0.7 #136
  • Bump spring-io/spring-security-actions/publish-release-notes from 0.0.2 to 0.0.3 #128
  • Bump spring-io/spring-security-release-tools/.github/actions/send-notification from 1.0.17 to 1.0.19 #134
  • Bump spring-io/spring-security-release-tools/.github/workflows/dispatch-deploy-docs.yml from 1.0.15 to 1.0.18 #126
Commits
  • 6803d77 Release 1.0.20
  • 6becf58 Revert "Release 1.0.20"
  • dbe3b12 Disable Caching on Uncacheable Tasks
  • 96ba494 Release 1.0.20
  • f832599 Bump org.jfrog.buildinfo:build-info-extractor-gradle from 5.2.0 to 6.0.4
  • 17d415a Update codeql-analyze Action
  • b7be527 Bump github/codeql-action/analyze from 3.38.2 to 4.38.2
  • 0637592 Bump spring-io/artifactory-deploy-action from 0.0.5 to 0.0.6
  • e3d3a22 Bump spring-io/spring-github-workflows/.github/workflows/spring-merge-dependa...
  • 11ff071 Bump spring-io/central-publish-action from 0.3.0 to 0.4.0
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [io.spring.gradle:spring-security-project-plugin](https://github.com/spring-io/spring-security-release-tools) from 1.0.19 to 1.0.20.
- [Release notes](https://github.com/spring-io/spring-security-release-tools/releases)
- [Changelog](https://github.com/spring-io/spring-security-release-tools/blob/main/RELEASE.adoc)
- [Commits](spring-io/spring-security-release-tools@1.0.19...1.0.20)

---
updated-dependencies:
- dependency-name: io.spring.gradle:spring-security-project-plugin
  dependency-version: 1.0.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added in: build An issue in the build type: dependency-upgrade A dependency upgrade labels Oct 5, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in: build An issue in the build type: dependency-upgrade A dependency upgrade

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants