Skip to content

chore: bump epam/ai-dial-ci/.github/workflows/java_release.yml from 3.0.2 to 3.1.1#1328

Merged
astsiapanay merged 1 commit intodevelopmentfrom
dependabot/github_actions/epam/ai-dial-ci/dot-github/workflows/java_release.yml-3.1.1
Jan 30, 2026
Merged

chore: bump epam/ai-dial-ci/.github/workflows/java_release.yml from 3.0.2 to 3.1.1#1328
astsiapanay merged 1 commit intodevelopmentfrom
dependabot/github_actions/epam/ai-dial-ci/dot-github/workflows/java_release.yml-3.1.1

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot bot commented on behalf of github Jan 28, 2026

Bumps epam/ai-dial-ci/.github/workflows/java_release.yml from 3.0.2 to 3.1.1.

Release notes

Sourced from epam/ai-dial-ci/.github/workflows/java_release.yml's releases.

3.1.1

What's Changed

Full Changelog: epam/ai-dial-ci@3.1.0...3.1.1

3.1.0

What's Changed

Full Changelog: epam/ai-dial-ci@3.0.2...3.1.0

Commits
  • ec8fe05 chore: bump actions/checkout from 6.0.1 to 6.0.2 in /actions/semantic_version...
  • 7a44774 chore: bump actions/checkout from 6.0.1 to 6.0.2 in /actions/generate_release...
  • 5256027 chore: bump actions/checkout from 6.0.1 to 6.0.2 (#415)
  • 8ab58d3 fix: poetry installation, initialization and caching in python workflows (#414)
  • ebeee5d chore: better cache key for python venv and poetry installation
  • 849c0df feat: Add optional runner cleanup before running python tests in python docke...
  • 5045d71 chore: bump actions/cache from 5.0.1 to 5.0.2 in /actions/python_prepare (#410)
  • 4b9f482 chore: bump github/codeql-action from 4.31.8 to 4.31.10 (#403)
  • c8cc80b chore: bump actions/upload-artifact from 5.0.0 to 6.0.0 (#400)
  • cd3e078 chore: bump actions/setup-node from 6.1.0 to 6.2.0 (#407)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Dependencies update github_actions Pull requests that update GitHub Actions code labels Jan 28, 2026
@dependabot dependabot bot added dependencies Dependencies update github_actions Pull requests that update GitHub Actions code labels Jan 28, 2026
@ai-dial-actions
Copy link
Copy Markdown
Contributor

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 22 package(s) with unknown licenses.
  • ⚠️ 3 packages with OpenSSF Scorecard issues.
See the Details below.

License Issues

settings.gradle

PackageVersionLicenseIssue Type
com.gradle:common-custom-user-data-gradle-plugin2.1NullUnknown License
com.gradle:develocity-gradle-plugin4.2NullUnknown License
org.apache.jclouds.api:atmos2.7.3NullUnknown License
org.apache.jclouds.api:filesystem2.7.3NullUnknown License
org.apache.jclouds.api:glacier2.7.3NullUnknown License
org.apache.jclouds.api:oauth2.7.3NullUnknown License
org.apache.jclouds.api:openstack-keystone2.7.3NullUnknown License
org.apache.jclouds.api:openstack-swift2.7.3NullUnknown License
org.apache.jclouds.api:rackspace-cloudfiles2.7.3NullUnknown License
org.apache.jclouds.api:rackspace-cloudidentity2.7.3NullUnknown License
org.apache.jclouds.api:s32.7.3NullUnknown License
org.apache.jclouds.api:sts2.7.3NullUnknown License
org.apache.jclouds.common:googlecloud2.7.3NullUnknown License
org.apache.jclouds.provider:aws-s32.7.3NullUnknown License
org.apache.jclouds.provider:azureblob2.7.3NullUnknown License
org.apache.jclouds.provider:b22.7.3NullUnknown License
org.apache.jclouds.provider:google-cloud-storage2.7.3NullUnknown License
org.apache.jclouds.provider:rackspace-cloudfiles-uk2.7.3NullUnknown License
org.apache.jclouds.provider:rackspace-cloudfiles-us2.7.3NullUnknown License
org.apache.jclouds:jclouds-allblobstore2.7.3NullUnknown License
org.apache.jclouds:jclouds-blobstore2.7.3NullUnknown License
org.apache.jclouds:jclouds-core2.7.3NullUnknown License

OpenSSF Scorecard

Scorecard details
PackageVersionScoreDetails
actions/epam/ai-dial-ci/.github/workflows/java_release.yml 3.1.1 UnknownUnknown
maven/aopalliance:aopalliance 1.0 UnknownUnknown
maven/com.google.inject.extensions:guice-assistedinject 7.0.0 🟢 5.2
Details
CheckScoreReason
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Maintained⚠️ 23 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 2
Code-Review⚠️ 1Found 5/29 approved changesets -- score normalized to 1
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies🟢 10all dependencies are pinned
Fuzzing🟢 10project is fuzzed
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases⚠️ -1no releases found
Security-Policy🟢 10security policy file detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Vulnerabilities⚠️ 19 existing vulnerabilities detected
maven/com.google.inject:guice 7.0.0 🟢 5.2
Details
CheckScoreReason
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Maintained⚠️ 23 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 2
Code-Review⚠️ 1Found 5/29 approved changesets -- score normalized to 1
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
License🟢 10license file detected
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies🟢 10all dependencies are pinned
Fuzzing🟢 10project is fuzzed
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases⚠️ -1no releases found
Security-Policy🟢 10security policy file detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Vulnerabilities⚠️ 19 existing vulnerabilities detected
maven/com.gradle:common-custom-user-data-gradle-plugin 2.1 UnknownUnknown
maven/com.gradle:develocity-gradle-plugin 4.2 UnknownUnknown
maven/com.sun.istack:istack-commons-runtime 4.1.2 🟢 5.5
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Code-Review🟢 10all changesets reviewed
Maintained⚠️ 00 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 0
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Security-Policy🟢 10security policy file detected
Vulnerabilities🟢 100 existing vulnerabilities detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
maven/jakarta.activation:jakarta.activation-api 2.1.3 UnknownUnknown
maven/jakarta.annotation:jakarta.annotation-api 2.0.0 UnknownUnknown
maven/jakarta.inject:jakarta.inject-api 2.0.1 UnknownUnknown
maven/jakarta.ws.rs:jakarta.ws.rs-api 3.0.0 UnknownUnknown
maven/jakarta.xml.bind:jakarta.xml.bind-api 4.0.2 UnknownUnknown
maven/org.apache.jclouds.api:atmos 2.7.3 UnknownUnknown
maven/org.apache.jclouds.api:filesystem 2.7.3 UnknownUnknown
maven/org.apache.jclouds.api:glacier 2.7.3 UnknownUnknown
maven/org.apache.jclouds.api:oauth 2.7.3 UnknownUnknown
maven/org.apache.jclouds.api:openstack-keystone 2.7.3 UnknownUnknown
maven/org.apache.jclouds.api:openstack-swift 2.7.3 UnknownUnknown
maven/org.apache.jclouds.api:rackspace-cloudfiles 2.7.3 UnknownUnknown
maven/org.apache.jclouds.api:rackspace-cloudidentity 2.7.3 UnknownUnknown
maven/org.apache.jclouds.api:s3 2.7.3 UnknownUnknown
maven/org.apache.jclouds.api:sts 2.7.3 UnknownUnknown
maven/org.apache.jclouds.common:googlecloud 2.7.3 UnknownUnknown
maven/org.apache.jclouds.provider:aws-s3 2.7.3 UnknownUnknown
maven/org.apache.jclouds.provider:azureblob 2.7.3 UnknownUnknown
maven/org.apache.jclouds.provider:b2 2.7.3 UnknownUnknown
maven/org.apache.jclouds.provider:google-cloud-storage 2.7.3 UnknownUnknown
maven/org.apache.jclouds.provider:rackspace-cloudfiles-uk 2.7.3 UnknownUnknown
maven/org.apache.jclouds.provider:rackspace-cloudfiles-us 2.7.3 UnknownUnknown
maven/org.apache.jclouds:jclouds-allblobstore 2.7.3 ⚠️ 1.3
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Maintained⚠️ 0project is archived
Code-Review⚠️ 0Found 2/30 approved changesets -- score normalized to 0
Token-Permissions⚠️ -1No tokens found
Dangerous-Workflow⚠️ -1no workflows found
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Security-Policy⚠️ 0security policy file not detected
License⚠️ 0license file not detected
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ -1no dependencies found
Fuzzing⚠️ 0project is not fuzzed
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Vulnerabilities⚠️ 038 existing vulnerabilities detected
maven/org.apache.jclouds:jclouds-blobstore 2.7.3 ⚠️ 1.3
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Maintained⚠️ 0project is archived
Code-Review⚠️ 0Found 2/30 approved changesets -- score normalized to 0
Token-Permissions⚠️ -1No tokens found
Dangerous-Workflow⚠️ -1no workflows found
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Security-Policy⚠️ 0security policy file not detected
License⚠️ 0license file not detected
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ -1no dependencies found
Fuzzing⚠️ 0project is not fuzzed
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Vulnerabilities⚠️ 038 existing vulnerabilities detected
maven/org.apache.jclouds:jclouds-core 2.7.3 ⚠️ 1.3
Details
CheckScoreReason
Packaging⚠️ -1packaging workflow not detected
Maintained⚠️ 0project is archived
Code-Review⚠️ 0Found 2/30 approved changesets -- score normalized to 0
Token-Permissions⚠️ -1No tokens found
Dangerous-Workflow⚠️ -1no workflows found
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Security-Policy⚠️ 0security policy file not detected
License⚠️ 0license file not detected
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 10no binaries found in the repo
Pinned-Dependencies⚠️ -1no dependencies found
Fuzzing⚠️ 0project is not fuzzed
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Vulnerabilities⚠️ 038 existing vulnerabilities detected
maven/org.checkerframework:checker-qual 3.43.0 🟢 3.7
Details
CheckScoreReason
Code-Review🟢 4Found 8/20 approved changesets -- score normalized to 4
Packaging⚠️ -1packaging workflow not detected
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Maintained🟢 1030 commit(s) and 10 issue activity found in the last 90 days -- score normalized to 10
Token-Permissions⚠️ -1No tokens found
Dangerous-Workflow⚠️ -1no workflows found
Security-Policy⚠️ 0security policy file not detected
License🟢 9license file detected
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Signed-Releases⚠️ 0Project has not signed or included provenance with any releases.
Binary-Artifacts⚠️ -1internal error: failure checking for Gradle wrapper validating Action: failure listing workflow runs: internal error: ListWorkflowRunsByFileName: GET https://api.github.com/repos/typetools/checker-framework/actions/workflows/gradle-wrapper-validation.yml-DISABLED/runs?status=success: 404 Not Found []
Fuzzing⚠️ 0project is not fuzzed
Vulnerabilities🟢 100 existing vulnerabilities detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
maven/org.eclipse.angus:angus-activation 2.0.2 🟢 3.3
Details
CheckScoreReason
Code-Review⚠️ 2Found 5/22 approved changesets -- score normalized to 2
Packaging⚠️ -1packaging workflow not detected
Binary-Artifacts🟢 10no binaries found in the repo
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Maintained⚠️ 00 commit(s) and 1 issue activity found in the last 90 days -- score normalized to 0
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
Security-Policy🟢 10security policy file detected
Vulnerabilities⚠️ 022 existing vulnerabilities detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0
maven/org.glassfish.jaxb:jaxb-core 4.0.5 🟢 6.3
Details
CheckScoreReason
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Packaging⚠️ -1packaging workflow not detected
Maintained🟢 64 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 6
Code-Review🟢 7Found 18/24 approved changesets -- score normalized to 7
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
License🟢 10license file detected
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
Security-Policy🟢 10security policy file detected
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 10no binaries found in the repo
Fuzzing🟢 10project is fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
SAST🟢 7SAST tool detected but not run on all commits
Vulnerabilities🟢 100 existing vulnerabilities detected
maven/org.glassfish.jaxb:jaxb-runtime 4.0.5 🟢 6.3
Details
CheckScoreReason
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Packaging⚠️ -1packaging workflow not detected
Maintained🟢 64 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 6
Code-Review🟢 7Found 18/24 approved changesets -- score normalized to 7
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
License🟢 10license file detected
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
Security-Policy🟢 10security policy file detected
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 10no binaries found in the repo
Fuzzing🟢 10project is fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
SAST🟢 7SAST tool detected but not run on all commits
Vulnerabilities🟢 100 existing vulnerabilities detected
maven/org.glassfish.jaxb:txw2 4.0.5 🟢 6.3
Details
CheckScoreReason
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Packaging⚠️ -1packaging workflow not detected
Maintained🟢 64 commit(s) and 4 issue activity found in the last 90 days -- score normalized to 6
Code-Review🟢 7Found 18/24 approved changesets -- score normalized to 7
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions⚠️ 0detected GitHub workflow tokens with excessive permissions
License🟢 10license file detected
Branch-Protection⚠️ 0branch protection not enabled on development/release branches
Security-Policy🟢 10security policy file detected
Signed-Releases⚠️ -1no releases found
Binary-Artifacts🟢 10no binaries found in the repo
Fuzzing🟢 10project is fuzzed
Pinned-Dependencies⚠️ 0dependency not pinned by hash detected -- score normalized to 0
SAST🟢 7SAST tool detected but not run on all commits
Vulnerabilities🟢 100 existing vulnerabilities detected

Scanned Files

  • .github/workflows/release.yml
  • settings.gradle

@dependabot dependabot bot force-pushed the dependabot/github_actions/epam/ai-dial-ci/dot-github/workflows/java_release.yml-3.1.1 branch from bf16e77 to c74a6b2 Compare January 30, 2026 09:32
@ai-dial-actions
Copy link
Copy Markdown
Contributor

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 2 package(s) with unknown licenses.
See the Details below.

License Issues

settings.gradle

PackageVersionLicenseIssue Type
com.gradle:common-custom-user-data-gradle-plugin2.1NullUnknown License
com.gradle:develocity-gradle-plugin4.2NullUnknown License

OpenSSF Scorecard

PackageVersionScoreDetails
actions/epam/ai-dial-ci/.github/workflows/java_release.yml 3.1.1 UnknownUnknown
maven/com.gradle:common-custom-user-data-gradle-plugin 2.1 UnknownUnknown
maven/com.gradle:develocity-gradle-plugin 4.2 UnknownUnknown

Scanned Files

  • .github/workflows/release.yml
  • settings.gradle

Bumps [epam/ai-dial-ci/.github/workflows/java_release.yml](https://github.com/epam/ai-dial-ci) from 3.0.2 to 3.1.1.
- [Release notes](https://github.com/epam/ai-dial-ci/releases)
- [Commits](epam/ai-dial-ci@3.0.2...3.1.1)

---
updated-dependencies:
- dependency-name: epam/ai-dial-ci/.github/workflows/java_release.yml
  dependency-version: 3.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/github_actions/epam/ai-dial-ci/dot-github/workflows/java_release.yml-3.1.1 branch from c74a6b2 to e725184 Compare January 30, 2026 09:33
@astsiapanay astsiapanay merged commit 73c25ec into development Jan 30, 2026
1 check failed
@dependabot dependabot bot deleted the dependabot/github_actions/epam/ai-dial-ci/dot-github/workflows/java_release.yml-3.1.1 branch January 30, 2026 09:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependencies update github_actions Pull requests that update GitHub Actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants