Skip to content

Conversation

@MarkEWaite
Copy link
Contributor

Use plugin bom 5933.vcf06f7b_5d1a_2

Most recent release of plugin BOM. Unclear why dependabot did not propose the upgrade.

Testing done

Confirmed that automated tests pass with JDK 21 on Linux. Rely on ci.jenkins.io for Windows and JDK 25 testing.

Submitter checklist

  • Make sure you are opening from a topic/feature/bugfix branch (right side) and not your main branch!
  • Ensure that the pull request title represents the desired changelog entry
  • Please describe what you did

@MarkEWaite MarkEWaite requested a review from a team as a code owner January 16, 2026 18:29
@github-actions github-actions bot added the dependencies Pull requests that update a dependency file label Jan 16, 2026
@MarkEWaite MarkEWaite merged commit 580217e into jenkinsci:master Jan 16, 2026
17 checks passed
@jonesbusy
Copy link

There is indeed something wrong with dependabot.

Looking at a fork before switching my plugins to Renovate, I was able to capture on https://github.com/jonesbusy/jackson3-api-plugin/actions/runs/21078374618/job/60625838458 (PR created is not using latest bom: https://github.com/jonesbusy/jackson3-api-plugin/pull/2/files)

updater | 2026/01/16 19:31:32 INFO <job_1211336091> Checking if io.jenkins.tools.bom:bom-2.504.x 5622.vc9c3051619f5 needs updating
  proxy | 2026/01/16 19:31:32 [038] GET https://repo.jenkins-ci.org/public/org/jenkins-ci/plugins/plugin/5.28/plugin-5.28.pom
  proxy | 2026/01/16 19:31:32 [038] 200 https://repo.jenkins-ci.org/public/org/jenkins-ci/plugins/plugin/5.28/plugin-5.28.pom (cached)
  proxy | 2026/01/16 19:31:33 [041] GET https://repo.jenkins-ci.org/public/io/jenkins/tools/bom/bom-2.504.x/maven-metadata.xml
  proxy | 2026/01/16 19:31:33 [041] 200 https://repo.jenkins-ci.org/public/io/jenkins/tools/bom/bom-2.504.x/maven-metadata.xml
  proxy | 2026/01/16 19:31:33 [043] GET https://repo.jenkins-ci.org/public/io/jenkins/tools/bom/bom-2.504.x
  proxy | 2026/01/16 19:31:33 [043] 302 https://repo.jenkins-ci.org/public/io/jenkins/tools/bom/bom-2.504.x
  proxy | 2026/01/16 19:31:33 [045] GET https://repo.jenkins-ci.org/artifactory/public/io/jenkins/tools/bom/bom-2.504.x/
  proxy | 2026/01/16 19:31:33 [045] 200 https://repo.jenkins-ci.org/artifactory/public/io/jenkins/tools/bom/bom-2.504.x/
  proxy | 2026/01/16 19:31:33 [047] GET https://repo.jenkins-ci.org/incrementals/io/jenkins/tools/bom/bom-2.504.x
  proxy | 2026/01/16 19:31:33 [047] 302 https://repo.jenkins-ci.org/incrementals/io/jenkins/tools/bom/bom-2.504.x
  proxy | 2026/01/16 19:31:33 [049] GET https://repo.jenkins-ci.org/artifactory/incrementals/io/jenkins/tools/bom/bom-2.504.x/
  proxy | 2026/01/16 19:31:33 [049] 200 https://repo.jenkins-ci.org/artifactory/incrementals/io/jenkins/tools/bom/bom-2.504.x/
  proxy | 2026/01/16 19:31:34 [051] GET https://repo.maven.apache.org/maven2/io/jenkins/tools/bom/bom-2.504.x
  proxy | 2026/01/16 19:31:34 [051] 404 https://repo.maven.apache.org/maven2/io/jenkins/tools/bom/bom-2.504.x
updater | 2026/01/16 19:31:34 INFO <job_1211336091> Filtered out 31 non-vc9c3051619f5 classifier versions
  proxy | 2026/01/16 19:31:34 [053] HEAD https://repo.jenkins-ci.org/public/io/jenkins/tools/bom/bom-2.504.x/5681.v79d2ddf61465/bom-2.504.x-5681.v79d2ddf61465.pom
  proxy | 2026/01/16 19:31:34 [053] 200 https://repo.jenkins-ci.org/public/io/jenkins/tools/bom/bom-2.504.x/5681.v79d2ddf61465/bom-2.504.x-5681.v79d2ddf61465.pom
updater | 2026/01/16 19:31:34 INFO <job_1211336091> Latest version is 5681.v79d2ddf61465

The updater Filtered out 31 non-vc9c3051619f5 classifier versions is quite concerning.

There is something that dependabot doesn't like between those version

<version>5622.vc9c3051619f5</version>
<version>5659.vecf9e2dc5a_ed</version>
<version>5681.v79d2ddf61465</version>
<version>5701.va_b_018a_a_6b_0d3</version>

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

chore dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants