Bump org.checkerframework:checker from 3.47.0 to 3.48.0
Bumps org.checkerframework:checker from 3.47.0 to 3.48.0.
Release notes
Sourced from org.checkerframework:checker's releases.
Checker Framework 3.48.0
Version 3.48.0 (October 2, 2024)
User-visible changes:
The new SqlQuotesChecker prevents errors in quoting in SQL queries. It prevents injection attacks that exploit quoting errors.
Aggregate Checkers now interleave error messages so that all errors about a line of code appear together.
Closed issues:
#3568, #6725, #6753, #6769, #6770, #6780, #6785, #6795, #6804, #6811, #6825.
Changelog
Sourced from org.checkerframework:checker's changelog.
Version 3.48.0 (October 2, 2024)
User-visible changes:
The new SqlQuotesChecker prevents errors in quoting in SQL queries. It prevents injection attacks that exploit quoting errors.
Aggregate Checkers now interleave error messages so that all errors about a line of code appear together.
Closed issues:
#3568, #6725, #6753, #6769, #6770, #6780, #6785, #6795, #6804, #6811, #6825.
Commits
8a5b585new release 3.48.033dfb84Fix links.dda798dPrep for release.fe16b7fRemove checker-qual files from shaded dataflow jar642a853Add a capture in type argument inferenceb96e777Capture the type of field accesses3b03b37Updating macOS installation instructions (#6827)3e837a5SkipTreeUtils.toStringTruncatedwhen debugging is disabledfe7b19fCheck for proper type97beabcFix a resource leak false positive due to a cast (#6821)- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebasewill rebase this PR -
@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it -
@dependabot mergewill merge this PR after your CI passes on it -
@dependabot squash and mergewill squash and merge this PR after your CI passes on it -
@dependabot cancel mergewill cancel a previously requested merge and block automerging -
@dependabot reopenwill reopen this PR if it is closed -
@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency -
@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)