Skip to content

chore: bump the minor-and-patch group with 7 updates - #411

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/minor-and-patch-8671437564
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/minor-and-patch-8671437564

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 7 updates:

Package From To
com.diffplug.spotless 8.10.2 8.10.3
com.diffplug.spotless:com.diffplug.spotless.gradle.plugin 8.3.0 8.10.3
dev.langchain4j:langchain4j 1.20.0 1.20.2
dev.langchain4j:langchain4j-core 1.20.0 1.20.2
dev.langchain4j:langchain4j-open-ai 1.20.0 1.20.2
dev.langchain4j:langchain4j-mcp 1.20.0-beta30 1.20.2-beta30
ch.qos.logback:logback-classic 1.6.4 1.6.5

Updates com.diffplug.spotless from 8.10.2 to 8.10.3

Release notes

Sourced from com.diffplug.spotless's releases.

Gradle Plugin v8.10.3

Changes

  • Generate formatter defaults from version catalog. (#3045)
  • Bump default gson version 2.13.2 -> 2.14.0. (#3045)
  • Bump default zjsonpatch version 0.4.14 -> 0.4.16. (#3045)
  • Bump default jackson-dataformat-yaml version 2.14.1 -> 2.20.1. (#3045)
  • Bump default ktfmt version 0.63 -> 0.64. (2988)
  • Bump default cleanthat version 2.25 -> 2.26. (#2882)
  • Bump default jackson version 2.20.1 -> 2.22.2. (#2819)
  • Bump default javaparser version 3.27.1 -> 3.28.2. (#3065)
  • Bump default palantir-java-format version 2.80.0 -> 2.98.0. (#3068)
  • Bump default scalafmt version 3.8.1 -> 3.11.5. (#2173)
  • Bump default google-java-format version 1.30.0 -> 1.36.1. (#3075)
  • Bump default gherkin-utils version 10.0.0 -> 12.0.2. (#2979)
  • We no longer publish a plugin marker for the legacy com.diffplug.gradle.spotless id, which has been redirecting to com.diffplug.spotless since 4.0. Builds that still request it now fail with Plugin [id: 'com.diffplug.gradle.spotless'] was not found instead of the migration message. (#3086)

Fixed

  • Fix release signing by using Gradle's required eight-digit signing subkey ID. (#3105)
  • Fix race when creating the npm install cache directory. ((#3096)
  • GrEclipse no longer emits expected OSGi and nested-jar warnings during initialization. (#2445)
  • typescript prettier() no longer emits a warning when its parser is already set to typescript. (#3098)
  • versionCatalog() preserves standalone comments at section boundaries and the end of the file. (#3048)
  • versionCatalog() preserves entries when comments contain unmatched brackets, preserves commas inside quoted strings, and keeps significant line boundaries in multiline entries. (#3042)
  • versionCatalog() now reports unfinished entries as lints at their starting line. These fail formatting by default, so upgrading may expose catalog errors that previously caused silent data loss. (#3042)
  • Stop calling deprecated Configuration.setVisible from Gradle 9.0.0 (#3053)
  • Eclipse JDT formatter step no longer fails with NoClassDefFoundError or NoSuchMethodError when lombok is active as a JVM agent (e.g. -javaagent:lombok.jar in Eclipse/VS Code/Cursor). (#2795)
Commits
  • eae36d8 Published gradle/8.10.3
  • 61e2016 Published maven/3.10.3
  • 49e0b07 Published lib/4.10.3
  • b7a7748 Fix release signing key ID format (#3105)
  • be8005a Document release signing correction (#3105)
  • 073fe61 Use short signing subkey ID for release publishing
  • 8ac44c7 Fix race when creating the npm install cache directory (#3096)
  • 3f2d955 Update dependency org.slf4j:slf4j-api to v2.0.20 (#3100)
  • 0c70ca8 Merge branch 'main' into fix/npm-cache-directory-race
  • bbf44a4 Fix GrEclipse initialization warnings (#3097)
  • Additional commits viewable in compare view

Updates com.diffplug.spotless:com.diffplug.spotless.gradle.plugin from 8.3.0 to 8.10.3

Release notes

Sourced from com.diffplug.spotless:com.diffplug.spotless.gradle.plugin's releases.

Gradle Plugin v8.10.3

Changes

  • Generate formatter defaults from version catalog. (#3045)
  • Bump default gson version 2.13.2 -> 2.14.0. (#3045)
  • Bump default zjsonpatch version 0.4.14 -> 0.4.16. (#3045)
  • Bump default jackson-dataformat-yaml version 2.14.1 -> 2.20.1. (#3045)
  • Bump default ktfmt version 0.63 -> 0.64. (2988)
  • Bump default cleanthat version 2.25 -> 2.26. (#2882)
  • Bump default jackson version 2.20.1 -> 2.22.2. (#2819)
  • Bump default javaparser version 3.27.1 -> 3.28.2. (#3065)
  • Bump default palantir-java-format version 2.80.0 -> 2.98.0. (#3068)
  • Bump default scalafmt version 3.8.1 -> 3.11.5. (#2173)
  • Bump default google-java-format version 1.30.0 -> 1.36.1. (#3075)
  • Bump default gherkin-utils version 10.0.0 -> 12.0.2. (#2979)
  • We no longer publish a plugin marker for the legacy com.diffplug.gradle.spotless id, which has been redirecting to com.diffplug.spotless since 4.0. Builds that still request it now fail with Plugin [id: 'com.diffplug.gradle.spotless'] was not found instead of the migration message. (#3086)

Fixed

  • Fix release signing by using Gradle's required eight-digit signing subkey ID. (#3105)
  • Fix race when creating the npm install cache directory. ((#3096)
  • GrEclipse no longer emits expected OSGi and nested-jar warnings during initialization. (#2445)
  • typescript prettier() no longer emits a warning when its parser is already set to typescript. (#3098)
  • versionCatalog() preserves standalone comments at section boundaries and the end of the file. (#3048)
  • versionCatalog() preserves entries when comments contain unmatched brackets, preserves commas inside quoted strings, and keeps significant line boundaries in multiline entries. (#3042)
  • versionCatalog() now reports unfinished entries as lints at their starting line. These fail formatting by default, so upgrading may expose catalog errors that previously caused silent data loss. (#3042)
  • Stop calling deprecated Configuration.setVisible from Gradle 9.0.0 (#3053)
  • Eclipse JDT formatter step no longer fails with NoClassDefFoundError or NoSuchMethodError when lombok is active as a JVM agent (e.g. -javaagent:lombok.jar in Eclipse/VS Code/Cursor). (#2795)

Gradle Plugin v8.10.2

Fixed

  • shortenFullyQualifiedTypes() now shortens fully-qualified types used in expression contexts (such as static method calls, static fields, and enum constants) while avoiding imports that would change how existing unqualified type references resolve. (#3039)
  • Eclipse JDT formatter step no longer fails with NoClassDefFoundError when lombok is active as a JVM agent (e.g. -javaagent:lombok.jar in Eclipse/VS Code/Cursor). (#2795)

Gradle Plugin v8.10.1

Fixed

  • prettier() and other npm-based steps no longer fail to start on npm 12 (EUNKNOWNCONFIG from --scripts-prepend-node-path). (#3024)
  • spotlessInternalRegisterDependencies now writes its output under a build directory that is configured after the plugin is applied, instead of always under the default build/. (#2114)
  • targetExclude now accepts a Gradle Directory, DirectoryProperty, or Provider<Directory> and excludes the files under it. Previously the directory was treated as a single file, so excluding one silently did nothing. (#2667)

Gradle Plugin v8.10.0

Added

  • New shortenFullyQualifiedTypes() step for Java, which replaces fully-qualified type names with their simple names and adds the imports they need. Best combined with importOrder() and removeUnusedImports(). (#2945)
  • Add embedded lockfiles to Eclipse JDT for every supported version (4.9 through 4.40), so eclipse() resolves from Maven Central instead of querying a P2 update site. Versions without an embedded lockfile still fall back to P2 provisioning. (#1996)

Fixed

  • removeUnusedImports no longer fails on Java import module declarations. (#2890)
  • expandWildcardImports() now builds its type-solver classpath from each Java source set's compile classpath instead of every resolvable configuration. Unrelated configurations (for example generated-code or custom resolvable configs that are not ready yet) are no longer resolved. (#2998)
  • spotlessCheck violation message now suggests the correct composite/included-build task path (e.g. ./gradlew :my-utils:spotlessApply) instead of a bare spotlessApply / :spotlessApply that does not select included-build tasks. (#2421)
  • Parallel multi-project builds no longer intermittently fail with "Cannot fingerprint input property 'stepsInternalEquality': ConfigurationCacheHackList cannot be serialized" / "Failed to provision P2 dependencies" when using eclipse() (or other P2-backed steps). Subprojects now share one deduping P2 provisioner and P2 queries are serialized process-wide. (#3004)

Changes

  • Default google-java-format remains 1.28.0 on JVM 17; bumps to 1.30.0 on JVM 21+; require at least 1.30.0 on JVM 25+ for import module support.
  • Bump default eclipse version to latest 4.39 -> 4.40. (#1996)

... (truncated)

Commits
  • eae36d8 Published gradle/8.10.3
  • 61e2016 Published maven/3.10.3
  • 49e0b07 Published lib/4.10.3
  • b7a7748 Fix release signing key ID format (#3105)
  • be8005a Document release signing correction (#3105)
  • 073fe61 Use short signing subkey ID for release publishing
  • 8ac44c7 Fix race when creating the npm install cache directory (#3096)
  • 3f2d955 Update dependency org.slf4j:slf4j-api to v2.0.20 (#3100)
  • 0c70ca8 Merge branch 'main' into fix/npm-cache-directory-race
  • bbf44a4 Fix GrEclipse initialization warnings (#3097)
  • Additional commits viewable in compare view

Updates dev.langchain4j:langchain4j from 1.20.0 to 1.20.2

Release notes

Sourced from dev.langchain4j:langchain4j's releases.

1.20.2 and 1.20.2-beta30

Full Changelog: langchain4j/langchain4j@1.20.1...1.20.2

1.20.1 and 1.20.1-beta30

What's Changed

Full Changelog: langchain4j/langchain4j@1.20.0...1.20.1

Commits

Updates dev.langchain4j:langchain4j-core from 1.20.0 to 1.20.2

Release notes

Sourced from dev.langchain4j:langchain4j-core's releases.

1.20.2 and 1.20.2-beta30

Full Changelog: langchain4j/langchain4j@1.20.1...1.20.2

1.20.1 and 1.20.1-beta30

What's Changed

Full Changelog: langchain4j/langchain4j@1.20.0...1.20.1

Commits

Updates dev.langchain4j:langchain4j-open-ai from 1.20.0 to 1.20.2

Release notes

Sourced from dev.langchain4j:langchain4j-open-ai's releases.

1.20.2 and 1.20.2-beta30

Full Changelog: langchain4j/langchain4j@1.20.1...1.20.2

1.20.1 and 1.20.1-beta30

What's Changed

Full Changelog: langchain4j/langchain4j@1.20.0...1.20.1

Commits

Updates dev.langchain4j:langchain4j-core from 1.20.0 to 1.20.2

Release notes

Sourced from dev.langchain4j:langchain4j-core's releases.

1.20.2 and 1.20.2-beta30

Full Changelog: langchain4j/langchain4j@1.20.1...1.20.2

1.20.1 and 1.20.1-beta30

What's Changed

Full Changelog: langchain4j/langchain4j@1.20.0...1.20.1

Commits

Updates dev.langchain4j:langchain4j-open-ai from 1.20.0 to 1.20.2

Release notes

Sourced from dev.langchain4j:langchain4j-open-ai's releases.

1.20.2 and 1.20.2-beta30

Full Changelog: langchain4j/langchain4j@1.20.1...1.20.2

1.20.1 and 1.20.1-beta30

What's Changed

Full Changelog: langchain4j/langchain4j@1.20.0...1.20.1

Commits

Updates dev.langchain4j:langchain4j-mcp from 1.20.0-beta30 to 1.20.2-beta30

Release notes

Sourced from dev.langchain4j:langchain4j-mcp's releases.

1.20.1 and 1.20.1-beta30

What's Changed

Full Changelog: langchain4j/langchain4j@1.20.0...1.20.1

Commits

Updates ch.qos.logback:logback-classic from 1.6.4 to 1.6.5

Release notes

Sourced from ch.qos.logback:logback-classic's releases.

Logback 1.6.5

2026-09-30 Release of logback version 1.6.5

• Fixed a vulnerability CVE-2026-104721 closely related to CVE-2026-19880. The fix in version 1.6.3, which strips forward and backward slashes from MDC values, was insufficient. An MDC value could still contain relative path components such as .., variable references such as /, or characters that are special in file name patterns and email addresses. This latest vulnerability was found and reported by François Martin (GitHub: @​martinfrancois, https://github.com/martinfrancois).

MDCBasedDiscriminator, used by SiftingAppender, now rejects MDC values instead of stripping characters from them. An MDC value is rejected if it is empty, if it is longer than 64 characters, if it contains the sequence .., or if it contains any of the following characters: / \ $ { } [ ] ( ) | ? * + % , @. When an MDC value is rejected, the discriminator returns the value of its DefaultValue property. A warning is emitted for each rejected value. These warnings are rate-limited.

• When compression is enabled, TimeBasedRollingPolicy and SizeAndTimeBasedRollingPolicy now also remove old log files that were never compressed, for example because the application was not running at rollover time. Previously, such files were ignored by maxHistory and accumulated indefinitely. This issue was discussed in discussions/1032. See TimeBasedRollingPolicy.

• SimpleInvocationGate, deprecated in version 1.6.3, is now marked for removal. Use FixedIntervalInvocationGate instead.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit d1b829dcdb9fd98511c64401beb1419a9c9384aa associated with the tag v_1.6.5. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Commits
  • d1b829d prepare release 1.6.5
  • 065b9b2 enhance protectin against mischievious MDC values in MDCBasedDiscriminator
  • b69beab complete commit in relation to discussion_1032
  • 7266c0b fix intermittently failing SocketAppenderMessageLossTest rest condition
  • a633bb0 fix intermittently failing SocketAppenderMessageLossTest rest condition
  • 2bc5bcc renamed tbrp and eclosingTBRP, other minor changes
  • 2cd8762 fix typo in AGENTS.md
  • 647846c fix errors when running tests under intellij IDEA
  • 1048917 removed ConsoleCharsetPropertyDefiner.java
  • 39b5002 added 'since' and 'forRemoval' attributes to SimpleInvocationGate @​Deprecatio...
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the minor-and-patch group with 7 updates:

| Package | From | To |
| --- | --- | --- |
| [com.diffplug.spotless](https://github.com/diffplug/spotless) | `8.10.2` | `8.10.3` |
| [com.diffplug.spotless:com.diffplug.spotless.gradle.plugin](https://github.com/diffplug/spotless) | `8.3.0` | `8.10.3` |
| [dev.langchain4j:langchain4j](https://github.com/langchain4j/langchain4j) | `1.20.0` | `1.20.2` |
| [dev.langchain4j:langchain4j-core](https://github.com/langchain4j/langchain4j) | `1.20.0` | `1.20.2` |
| [dev.langchain4j:langchain4j-open-ai](https://github.com/langchain4j/langchain4j) | `1.20.0` | `1.20.2` |
| [dev.langchain4j:langchain4j-mcp](https://github.com/langchain4j/langchain4j) | `1.20.0-beta30` | `1.20.2-beta30` |
| [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) | `1.6.4` | `1.6.5` |


Updates `com.diffplug.spotless` from 8.10.2 to 8.10.3
- [Release notes](https://github.com/diffplug/spotless/releases)
- [Changelog](https://github.com/diffplug/spotless/blob/main/CHANGES.md)
- [Commits](diffplug/spotless@gradle/8.10.2...gradle/8.10.3)

Updates `com.diffplug.spotless:com.diffplug.spotless.gradle.plugin` from 8.3.0 to 8.10.3
- [Release notes](https://github.com/diffplug/spotless/releases)
- [Changelog](https://github.com/diffplug/spotless/blob/main/CHANGES.md)
- [Commits](diffplug/spotless@gradle/8.3.0...gradle/8.10.3)

Updates `dev.langchain4j:langchain4j` from 1.20.0 to 1.20.2
- [Release notes](https://github.com/langchain4j/langchain4j/releases)
- [Commits](langchain4j/langchain4j@1.20.0...1.20.2)

Updates `dev.langchain4j:langchain4j-core` from 1.20.0 to 1.20.2
- [Release notes](https://github.com/langchain4j/langchain4j/releases)
- [Commits](langchain4j/langchain4j@1.20.0...1.20.2)

Updates `dev.langchain4j:langchain4j-open-ai` from 1.20.0 to 1.20.2
- [Release notes](https://github.com/langchain4j/langchain4j/releases)
- [Commits](langchain4j/langchain4j@1.20.0...1.20.2)

Updates `dev.langchain4j:langchain4j-core` from 1.20.0 to 1.20.2
- [Release notes](https://github.com/langchain4j/langchain4j/releases)
- [Commits](langchain4j/langchain4j@1.20.0...1.20.2)

Updates `dev.langchain4j:langchain4j-open-ai` from 1.20.0 to 1.20.2
- [Release notes](https://github.com/langchain4j/langchain4j/releases)
- [Commits](langchain4j/langchain4j@1.20.0...1.20.2)

Updates `dev.langchain4j:langchain4j-mcp` from 1.20.0-beta30 to 1.20.2-beta30
- [Release notes](https://github.com/langchain4j/langchain4j/releases)
- [Commits](https://github.com/langchain4j/langchain4j/commits)

Updates `ch.qos.logback:logback-classic` from 1.6.4 to 1.6.5
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.6.4...v_1.6.5)

---
updated-dependencies:
- dependency-name: com.diffplug.spotless
  dependency-version: 8.10.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: com.diffplug.spotless:com.diffplug.spotless.gradle.plugin
  dependency-version: 8.10.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: dev.langchain4j:langchain4j
  dependency-version: 1.20.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: dev.langchain4j:langchain4j-core
  dependency-version: 1.20.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: dev.langchain4j:langchain4j-open-ai
  dependency-version: 1.20.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: dev.langchain4j:langchain4j-core
  dependency-version: 1.20.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: dev.langchain4j:langchain4j-open-ai
  dependency-version: 1.20.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: dev.langchain4j:langchain4j-mcp
  dependency-version: 1.20.2-beta30
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: ch.qos.logback:logback-classic
  dependency-version: 1.6.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Oct 5, 2026
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Test Results

4 552 tests   4 546 ✅  4m 28s ⏱️
  364 suites      6 💤
  364 files        0 ❌

Results for commit 1c5194f.

@dependabot @github

dependabot Bot commented on behalf of github Oct 10, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 10, 2026
@dependabot
dependabot Bot deleted the dependabot/gradle/minor-and-patch-8671437564 branch October 10, 2026 13:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants