From 114487616b44338275ea7082fc247e846d2391fa Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Mon, 28 Sep 2026 20:36:34 +0000 Subject: [PATCH 1/2] chore(deps): bump com.fasterxml.jackson.core:jackson-databind Bumps the maven group with 1 update in the / directory: [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind). Updates `com.fasterxml.jackson.core:jackson-databind` from 2.22.1 to 2.22.2 - [Commits](https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.22.1...jackson-databind-2.22.2) --- updated-dependencies: - dependency-name: com.fasterxml.jackson.core:jackson-databind dependency-version: 2.22.2 dependency-type: direct:production dependency-group: maven ... Signed-off-by: dependabot[bot] --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index 5d992cfc..e860ba1b 100644 --- a/pom.xml +++ b/pom.xml @@ -117,7 +117,7 @@ com.fasterxml.jackson.core jackson-databind - 2.22.1 + 2.22.2 com.fasterxml.jackson.core From 986faa09e282d7596dd1bbd1221e04c9ccdd8b5b Mon Sep 17 00:00:00 2001 From: Tom Desair Date: Sun, 4 Oct 2026 20:41:04 +0200 Subject: [PATCH 2/2] fix: Do not run SonarCloud check for dependabot and pull requests --- .github/workflows/build.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index b682b04f..b95b4402 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -55,7 +55,7 @@ jobs: name: Update dependency graph uses: advanced-security/maven-dependency-submission-action@b275d12641ac2d2108b2cbb7598b154ad2f2cee8 # v5.0.0 - - if: ${{ matrix.run-sonarcloud }} + - if: ${{ matrix.run-sonarcloud && github.actor != 'dependabot[bot]' && github.event_name != 'pull_request' }} name: SonarCloud env: GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }}