Update dependency org.ossreviewtoolkit:analyzer to v87.2.0#174
Merged
Conversation
sschuberth
approved these changes
May 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
87.1.0→87.2.0Release Notes
oss-review-toolkit/ort (org.ossreviewtoolkit:analyzer)
v87.2.0Compare Source
What's Changed
🐞 Bug Fixes
2305784bazel: Use the correct syntax for the fallback versiona0d6807model: Stop using notice files as resolved license files098ed19spdx: Track visited nodes per project type🎉 New Features
17e9c6ebazel: Allow to configure the Bazel version directly43bbdd9evaluator: AddgetNonApplicablePackageLicenseChoices()caa0da8evaluator: AddgetNonApplicableRepositoryLicenseChoices()77c47efmodel: AddeffectiveLicenseAndAppliedChoices()b8ca7f9model: Broaden the condition for including files in file archivesb52339bspdx: AddapplyAndGetChoices()✅ Tests
9e21070evaluator: Factor outOrtResult.setLicenseChoices()05c7db4mix: Update expected resultsd6a8479model: Ensure default patterns do not include arbitrary filesfac6b74model: Factor outDEFAULT_PATTERNS4c75ddfmodel: Trivially simplify some assertions5e94b25python: Update expected results🐘 Build & ⚙️ CI
a009a16detekt-rules: Remove an obsolete work-aroundb9b5176gradle: Work around the TAPI strictly depending on slf4j-api 2.0.17📖 Documentation
4a4fd89bazel: Move a code comment to the correct line4eccacamodel: Document that filename patterns get prepended with"**/"🔧 Chores
ca1d5fcmodel: Introduce a helper function to delete files on exitf845b89model: MovegetSubdirectoryForProvenance()nearby its only usead73569model: Remove Maven-specific logic from file archive creation8ce7a98spdx: Add a default value forSpdxLicenseChoice.given1b0d51aspdx: Remove a default argument to address an IDE hint🚀 Dependency Updates
6e18129bazel: Use a newer fallback version0ae2264Update the dependency-analysis-gradle-plugin to version 3.13.0f1a5a62Update the dependency-analysis-gradle-plugin to version 3.14.0b2501caupdate aws-java-sdk-v2 monorepo to v2.44.14b9a94a2update ch.qos.logback:logback-classic to v1.5.3370bfb2fupdate com.networknt:json-schema-validator to v3.0.3981a7f3update dev.panuszewski.typesafe-conventions to v0.11.14c27bb7update docker/build-push-action action to v7.2.0d36c1e2update docker/login-action action to v4.2.0d938a03update docker/metadata-action action to v6.1.0b5f49aeupdate docker/setup-buildx-action action to v4.1.023663c3update github/codeql-action action to v4.36.05311aadupdate io.ktor:ktor-version-catalog to v3.5.01de3472update ksp monorepo to v2.3.9b2e0293update org.apache.tika:tika-core to v3.3.17f749ecupdate org.graalvm.buildtools:native-gradle-plugin to v1.1.17f31a8bupdate org.slf4j:slf4j-api to v2.0.18Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.