Skip to content

chore(deps): bump the maven-minor-and-patch group across 1 directory with 16 updates - #173

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/maven-minor-and-patch-cc28cc120a
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/maven-minor-and-patch-cc28cc120a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bumps the maven-minor-and-patch group with 16 updates in the / directory:

Package From To
org.apache.commons:commons-collections4 4.5.0 4.6.0
com.alibaba:qlexpress4 4.1.2 4.1.3
com.google.guava:guava 33.6.0-jre 33.7.2-jre
com.h2database:h2 2.3.232 2.5.252
org.springdoc:springdoc-openapi-starter-webmvc-api 3.0.3 3.1.1
io.swagger.core.v3:swagger-annotations-jakarta 2.2.47 2.2.55
org.apache.maven.plugins:maven-jar-plugin 3.5.0 3.5.1
org.apache.maven.plugins:maven-compiler-plugin 3.15.0 3.16.0
org.apache.maven.plugins:maven-surefire-plugin 3.5.6 3.6.0
com.diffplug.spotless:spotless-maven-plugin 3.9.0 3.10.3
com.github.siom79.japicmp:japicmp-maven-plugin 0.23.1 0.26.2
org.apache.maven.plugins:maven-install-plugin 3.1.4 3.2.0
org.apache.maven.plugins:maven-deploy-plugin 3.1.4 3.2.0
com.github.spotbugs:spotbugs-maven-plugin 4.10.2.0 4.10.4.1
org.cyclonedx:cyclonedx-maven-plugin 2.9.2 2.9.3
org.apache.maven:apache-maven 3.9.16 3.10.0

Updates org.apache.commons:commons-collections4 from 4.5.0 to 4.6.0

Updates com.alibaba:qlexpress4 from 4.1.2 to 4.1.3

Release notes

Sourced from com.alibaba:qlexpress4's releases.

v4.1.3

  • Feat: added LazyArgCustomFunction for custom Java functions that need lazy argument evaluation and short-circuit behavior #438 , Thanks @​yuxwang-wiley
  • Fix: loop control-flow bugs involving empty loop bodies and try/catch blocks #447 #448 , Thanks @​chenjunwenhao
  • Fix: parsing ambiguity around <, <=, <>, generic types, and diamond syntax #455 , Thanks @​qchole
  • Fix: getOutVarNames, so for-each loop variables are treated as local variables, not external dependencies #463 , Thanks @​jianjindream
Commits
  • 3f78121 Commit from GitHub Actions (Reduce Adoc)
  • 060d581 delete stable version note
  • c8c6522 Commit from GitHub Actions (Reduce Adoc)
  • aeacef9 4.1.3 release
  • 1b2e69f remove compile time function
  • c13037c compare test
  • 6bb24f2 Merge pull request #455 from qchole/lt
  • 3174c94 Merge pull request #463 from jianjindream/fix/issue-462-foreach-out-var
  • d86d175 fix: exclude for-each variables from getOutVarNames
  • 5870677 fix parse less op
  • Additional commits viewable in compare view

Updates com.google.guava:guava from 33.6.0-jre to 33.7.2-jre

Release notes

Sourced from com.google.guava:guava's releases.

33.7.2

Maven

<dependency>
  <groupId>com.google.guava</groupId>
  <artifactId>guava</artifactId>
  <version>33.7.2-jre</version>
  <!-- or, for Android: -->
  <version>33.7.2-android</version>
</dependency>

Jar files

Guava requires one runtime dependency, which you can download here:

Javadoc

JDiff

Changelog

33.7.1

Maven

<dependency>
  <groupId>com.google.guava</groupId>
  <artifactId>guava</artifactId>
  <version>33.7.1-jre</version>
  <!-- or, for Android: -->
  <version>33.7.1-android</version>
</dependency>
</tr></table> 

... (truncated)

Commits

Updates com.h2database:h2 from 2.3.232 to 2.5.252

Release notes

Sourced from com.h2database:h2's releases.

Version 2.5.252

version-2.5.250

... (truncated)

Commits
  • f986838 in preparation for a release
  • 06c34a7 Merge pull request #4418 from andreitokar/issues-4380-4376
  • 1aef3e0 #4376: Reading INFORMATION_SCHEMA.COLUMNS fails with a NPE while any material...
  • 4bb8aee #4380: creating a MATERIALIZED VIEW makes a persistent database permanently u...
  • 95b6af0 Merge pull request #4417 from andreitokar/issue-4395
  • 6ec30b6 #4395 disallow constraints between temporary and permanent tables
  • 0f0f856 Merge pull request #4416 from andreitokar/issue-4405
  • f718b76 #4405 SecureFileStore.readFully() may skip decryption
  • e231ff7 #4405 SecureFileStore.readFully() may skip
  • 4da0d1d Merge pull request #4415 from jjh75607/fix/log-sql-aarch64
  • Additional commits viewable in compare view

Updates org.springdoc:springdoc-openapi-starter-webmvc-api from 3.0.3 to 3.1.1

Release notes

Sourced from org.springdoc:springdoc-openapi-starter-webmvc-api's releases.

springdoc-openapi v3.1.1 released!

Security

  • GHSA-6f5m-mhjg-qwxq – MCP tool callbacks do not encode path parameters, allowing request retargeting
  • GHSA-4v2q-56v7-2cpw – MCP transport, admin and dashboard endpoints are exposed by default
  • GHSA-m4cg-mhpg-rh2r – MCP audit events record credentials and request/response bodies without redaction
  • GHSA-5f9r-4mc4-qh3c – Unbounded MCP pending-confirmation store allows memory exhaustion
  • GHSA-jcgg-59c8-w4wh – MCP request context in a ThreadLocal can leak headers between concurrent WebFlux requests
  • GHSA-rhhx-6j8h-8cvw – Unbounded per-locale OpenAPI cache allows memory exhaustion via Accept-Language
  • GHSA-c925-vm88-mpp9 – Scalar starters trust client-supplied forwarded headers and render from a shared mutable bean
  • CVE-2026-75838 – Cross-site scripting in the DOMPurify bundled with swagger-ui, addressed by upgrading swagger-ui to 5.32.14

Added

  • #3340 – Describe JsonNullable values without their Java wrapper
  • #3325 – Manage the swagger artifacts in springdoc-openapi-bom, so that modules holding only the annotations stay in lockstep
  • #3321 – Add springdoc.login-endpoint.username-example and springdoc.login-endpoint.password-example to document the Spring Security login endpoint

Changed

  • MCP is now opt-in. Set springdoc.ai.mcp.enabled=true, and springdoc.ai.mcp.dashboard-enabled=true for the dashboard
  • The Scalar starters no longer register forwarded-header handling. Set server.forward-headers-strategy=framework (or native) behind a trusted proxy
  • Add springdoc.cache.max-entries (default 100) to bound the per-locale OpenAPI cache
  • Add springdoc.ai.mcp.audit.redact (default true) to mask secrets in MCP audit events
  • Document that the MCP approval flow is a confirmation step, not an authorization control
  • Document the security policy and the release versioning scheme
  • #3351 – java.time.Duration, LocalTime and OffsetTime are now resolved by swagger-core instead of being forced to a bare string, so they carry a format (duration and partial-time respectively for the first two)
  • A property whose type only implements Set indirectly (LinkedHashSet, TreeSet, …) is now described with uniqueItems: true, following swagger-api/swagger-core#5265
  • Upgrade swagger-core to version 2.2.55
  • Upgrade swagger-ui to version 5.32.14

Fixed

  • #3328, #3337 – /v3/api-docs fails with a NullPointerException when spring-hateoas is on the classpath without HateoasProperties
  • #3314 – Json Processing Exception occurred is logged for every constrained parameter whose schema is not a JsonSchema
  • #3317 – An injected HttpHeaders parameter is described as a schema
  • #3332 – The properties a Kotlin entity inherits from an @Embeddable are missing from the Spring Data REST schemas
  • #3320 – @Order and Ordered ignored when applying customizers
  • #3319 – A Page nested in another schema is not replaced by PagedModel
  • #3313 – Springdoc auto-configurations rely on unspecified auto-configuration ordering
  • #3331 – Validation annotations declared inside Optional parameters are dropped
  • #3322 – Validation annotations on a container's type argument leak between parameters
  • #3315 – An OAS 3.1 JsonSchema cannot be cloned through JSON
  • #3300 – TYPE_USE annotations on @ParameterObject fields are not passed along
  • #3341 – Stabilize Spring Data Sort and Pageable schema property order
  • #3338 – Kotlin nullability interpretation of the Any? type
  • #3136 – A Spring Data REST association to a non-exported entity expands its @EmbeddedId and @MapsId fields recursively in the response schemas
  • The Spring Data REST response post-processing rewrote an association property in place, so the …Response refs could leak into the schema shared with the request body representation

New Contributors

... (truncated)

Changelog

Sourced from org.springdoc:springdoc-openapi-starter-webmvc-api's changelog.

[3.1.1] - 2026-09-06

Security

  • GHSA-6f5m-mhjg-qwxq – MCP tool callbacks do not encode path parameters, allowing request retargeting
  • GHSA-4v2q-56v7-2cpw – MCP transport, admin and dashboard endpoints are exposed by default
  • GHSA-m4cg-mhpg-rh2r – MCP audit events record credentials and request/response bodies without redaction
  • GHSA-5f9r-4mc4-qh3c – Unbounded MCP pending-confirmation store allows memory exhaustion
  • GHSA-jcgg-59c8-w4wh – MCP request context in a ThreadLocal can leak headers between concurrent WebFlux requests
  • GHSA-rhhx-6j8h-8cvw – Unbounded per-locale OpenAPI cache allows memory exhaustion via Accept-Language
  • GHSA-c925-vm88-mpp9 – Scalar starters trust client-supplied forwarded headers and render from a shared mutable bean
  • CVE-2026-75838 – Cross-site scripting in the DOMPurify bundled with swagger-ui, addressed by upgrading swagger-ui to 5.32.14

Added

  • #3340 – Describe JsonNullable values without their Java wrapper
  • #3325 – Manage the swagger artifacts in springdoc-openapi-bom, so that modules holding only the annotations stay in lockstep
  • #3321 – Add springdoc.login-endpoint.username-example and springdoc.login-endpoint.password-example to document the Spring Security login endpoint

Changed

  • MCP is now opt-in. Set springdoc.ai.mcp.enabled=true, and springdoc.ai.mcp.dashboard-enabled=true for the dashboard
  • The Scalar starters no longer register forwarded-header handling. Set server.forward-headers-strategy=framework (or native) behind a trusted proxy
  • Add springdoc.cache.max-entries (default 100) to bound the per-locale OpenAPI cache
  • Add springdoc.ai.mcp.audit.redact (default true) to mask secrets in MCP audit events
  • Document that the MCP approval flow is a confirmation step, not an authorization control
  • Document the security policy and the release versioning scheme
  • #3351 – java.time.Duration, LocalTime and OffsetTime are now resolved by swagger-core instead of being forced to a bare string, so they carry a format (duration and partial-time respectively for the first two)
  • A property whose type only implements Set indirectly (LinkedHashSet, TreeSet, …) is now described with uniqueItems: true, following swagger-api/swagger-core#5265
  • Upgrade swagger-core to version 2.2.55
  • Upgrade swagger-ui to version 5.32.14

Fixed

  • #3328, #3337 – /v3/api-docs fails with a NullPointerException when spring-hateoas is on the classpath without HateoasProperties
  • #3314 – Json Processing Exception occurred is logged for every constrained parameter whose schema is not a JsonSchema
  • #3317 – An injected HttpHeaders parameter is described as a schema
  • #3332 – The properties a Kotlin entity inherits from an @Embeddable are missing from the Spring Data REST schemas
  • #3320 – @Order and Ordered ignored when applying customizers
  • #3319 – A Page nested in another schema is not replaced by PagedModel
  • #3313 – Springdoc auto-configurations rely on unspecified auto-configuration ordering
  • #3331 – Validation annotations declared inside Optional parameters are dropped
  • #3322 – Validation annotations on a container's type argument leak between parameters
  • #3315 – An OAS 3.1 JsonSchema cannot be cloned through JSON
  • #3300 – TYPE_USE annotations on @ParameterObject fields are not passed along
  • #3341 – Stabilize Spring Data Sort and Pageable schema property order
  • #3338 – Kotlin nullability interpretation of the Any? type
  • #3136 – A Spring Data REST association to a non-exported entity expands its @EmbeddedId and @MapsId fields recursively in the response schemas
  • The Spring Data REST response post-processing rewrote an association property in place, so the …Response refs could leak into the schema shared with the request body representation

... (truncated)

Commits
  • 1cc87a7 [maven-release-plugin] prepare release v3.1.1
  • 4e8ac26 docs: record the swagger-ui 5.32.14 upgrade as a security fix for 3.1.1
  • 958c79a Merge swagger-core 2.2.55 upgrade
  • cf7d7c7 Upgrade swagger-core to 2.2.55
  • 186adb3 Record the swagger-core 2.2.54 upgrade in the changelog
  • 2498ffb Merge pull request #3351 from Mattias-Sehlstedt/update-swagger-core
  • d78abd9 upgrade swagger-core from 2.2.53 to 2.2.54
  • 9f7f099 Rewrite a copy of a Spring Data REST association property
  • f47060e Record #3321 in the changelog and align the buildRequestBody indent
  • ccb2fc0 Merge pull request #3323 from Mattias-Sehlstedt/feature/3321-login-example-va...
  • Additional commits viewable in compare view

Updates io.swagger.core.v3:swagger-annotations-jakarta from 2.2.47 to 2.2.55

Updates org.apache.maven.plugins:maven-jar-plugin from 3.5.0 to 3.5.1

Release notes

Sourced from org.apache.maven.plugins:maven-jar-plugin's releases.

3.5.1

📝 Documentation updates

  • Add AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (#550) @​potiuk

👻 Maintenance

  • Add AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (#550) @​potiuk
  • Use plugin version properties (3.x) (#535) @​Bukama

📦 Dependency updates

Commits
  • b0cd63d [maven-release-plugin] prepare release maven-jar-plugin-3.5.1
  • 5318a4f Add AGENTS.md + SECURITY.md security-model pointer for scanner discoverability
  • 8e0b9bb Bump org.apache.maven.plugins:maven-plugins from 48 to 49 (#547)
  • d5a438b Fix javadoc
  • 774fac9 Bump org.codehaus.plexus:plexus-archiver from 4.11.0 to 4.12.0
  • b71f403 Bump mavenVersion from 3.9.15 to 3.9.16 (#536)
  • 9f2a001 Use plugin version properties (3.x) (#535)
  • 68a978f Bump org.apache.maven.plugins:maven-plugins from 47 to 48 (#534)
  • e105821 Bump commons-io:commons-io from 2.21.0 to 2.22.0 (#529)
  • 953dc1a Bump mavenVersion from 3.9.14 to 3.9.15 (#528)
  • Additional commits viewable in compare view

Updates org.apache.maven.plugins:maven-compiler-plugin from 3.15.0 to 3.16.0

Release notes

Sourced from org.apache.maven.plugins:maven-compiler-plugin's releases.

3.16.0

🚀 New features and improvements

🐛 Bug Fixes

📝 Documentation updates

👻 Maintenance

📦 Dependency updates

Commits
  • e7bba6e [maven-release-plugin] prepare release maven-compiler-plugin-3.16.0
  • c906809 Avoid using deprecated method CompilerConfiguration.setCompilerVersion
  • ad74fee Replace adopt-openj9 by semeru JDK distribution on GH
  • beb0eda Recompile when dependencies change (#1102)
  • a0b689e [MCOMPILER-578] Track outputs across compiler executions (#1091)
  • 2e81228 Fix incremental detection of empty sources, 3.x (#1075)
  • 2132f5b configure ATR project
  • 5992b77 Build fails when annotation processor list is empty (but present) (#1077)
  • acccef7 Bump plexusCompilerVersion from 2.16.2 to 2.17.0
  • 72bc445 Bump org.codehaus.plexus:plexus-java from 1.5.2 to 1.6.0
  • Additional commits viewable in compare view

Updates org.apache.maven.plugins:maven-surefire-plugin from 3.5.6 to 3.6.0

Release notes

Sourced from org.apache.maven.plugins:maven-surefire-plugin's releases.

3.6.0

Please refer to the main page for what's new https://maven.apache.org/surefire/ And the migration page https://maven.apache.org/surefire/maven-surefire-plugin/whats-new-3-6-0.html

🚀 New features and improvements

🐛 Bug Fixes

📝 Documentation updates

👻 Maintenance

... (truncated)

Commits
  • 0ff622b [maven-release-plugin] prepare release surefire-3.6.0
  • bb3932a Let's go for 3.6.0 release
  • 3002a16 Bump mavenVersion from 3.9.14 to 3.9.16
  • 61a531d Bump Maven parent version from 47 to 49 (#3449)
  • e52ead4 [SUREFIRE-523] Link all reported tests to source XRef (#3445)
  • 45102fa [SUREFIRE-3446] Fix direct selection of JUnit Jupiter @​Nested classes (#3447)
  • b2e1f70 Fix #3303: distinguish JUnit 6 ParameterizedClass invocations (#3432)
  • c051938 Discover tests in a fork when a toolchain JDK is used (#3444)
  • db75df8 Bump org.codehaus.plexus:plexus-java from 1.5.2 to 1.6.0 (#3441)
  • 77f2759 Bump org.codehaus.plexus:plexus-interpolation from 1.29 to 1.30.0
  • Additional commits viewable in compare view

Updates com.diffplug.spotless:spotless-maven-plugin from 3.9.0 to 3.10.3

Release notes

Sourced from com.diffplug.spotless:spotless-maven-plugin's releases.

Maven Plugin v3.10.3

Changes

  • Generate formatter defaults from version catalog. (#3045)
  • Bump default gson version 2.13.2 -> 2.14.0. (#3045)
  • Bump default zjsonpatch version 0.4.14 -> 0.4.16. (#3045)
  • Bump default jackson-dataformat-yaml version 2.14.1 -> 2.20.1. (#3045)
  • Bump default ktfmt version 0.63 -> 0.64. (2988)
  • Bump default cleanthat version 2.25 -> 2.26. (#2882)
  • Bump default jackson version 2.20.1 -> 2.22.2. (#2819)
  • Bump default javaparser version 3.27.1 -> 3.28.2. (#3065)
  • Bump default palantir-java-format version 2.80.0 -> 2.98.0. (#3068)
  • Bump default scalafmt version 3.8.1 -> 3.11.5. (#2173)
  • Bump default google-java-format version 1.30.0 -> 1.36.1. (#3075)
  • Bump default gherkin-utils version 10.0.0 -> 12.0.2. (#2979)

Fixed

  • Fix release signing by using Gradle's required eight-digit signing subkey ID. (#3105)
  • Fix race when creating the npm install cache directory. ((#3096)
  • GrEclipse no longer emits expected OSGi and nested-jar warnings during initialization. (#2445)
  • typescript prettier() no longer emits a warning when its parser is already set to typescript. (#3098)
  • <versionCatalog> preserves standalone comments at section boundaries and the end of the file. (#3048)
  • <versionCatalog> preserves entries when comments contain unmatched brackets, preserves commas inside quoted strings, and keeps significant line boundaries in multiline entries. (#3042)
  • <versionCatalog> now reports unfinished entries as lints at their starting line. These fail formatting by default, so upgrading may expose catalog errors that previously caused silent data loss. (#3042)
  • Eclipse JDT formatter step no longer fails with NoClassDefFoundError or NoSuchMethodError when lombok is active as a JVM agent (e.g. -javaagent:lombok.jar in Eclipse/VS Code/Cursor). (#2795)

Maven Plugin v3.10.2

Fixed

  • <shortenFullyQualifiedTypes> now shortens fully-qualified types used in expression contexts (such as static method calls, static fields, and enum constants) while avoiding imports that would change how existing unqualified type references resolve. (#3039)
  • Eclipse JDT formatter step no longer fails with NoClassDefFoundError when lombok is active as a JVM agent (e.g. -javaagent:lombok.jar in Eclipse/VS Code/Cursor). (#2795)

Maven Plugin v3.10.1

Fixed

  • <prettier> and other npm-based steps no longer fail to start on npm 12 (EUNKNOWNCONFIG from --scripts-prepend-node-path). (#3024)

Maven Plugin v3.10.0

Added

  • New <shortenFullyQualifiedTypes> step for Java, which replaces fully-qualified type names with their simple names and adds the imports they need. Best combined with <importOrder> and <removeUnusedImports>. (#2945)
  • Add embedded lockfiles to Eclipse JDT for every supported version (4.9 through 4.40), so eclipse() resolves from Maven Central instead of querying a P2 update site. Versions without an embedded lockfile still fall back to P2 provisioning. (#1996)
  • Add support to apply alternate license header within same format (#872)
  • Add support to skip license header application based on source file content pattern (#650).

Fixed

  • removeUnusedImports no longer fails on Java import module declarations. (#2890)
  • Concurrent P2 provisioning no longer races Solstice's on-disk cache (affects Eclipse-based formatters under parallel builds). (#3004)

Changes

  • Default google-java-format remains 1.28.0 on JVM 17; bumps to 1.30.0 on JVM 21+; require at least 1.30.0 on JVM 25+ for import module support.
  • Bump default eclipse version to latest 4.39 -> 4.40. (#1996)
  • Document Maven skip properties spotless.skip, spotless.check.skip, and spotless.apply.skip. Goal-specific skips now live on their own mojos so they no longer leak across goals. (#3009)
  • Bump default adocfmt version 0.2.0 -> 0.3.1, which adds table formatting support (<formatTables>, <tableLayout>, <tableMaxLineWidth>, <tableBlankLines>).
Commits

…with 16 updates

Bumps the maven-minor-and-patch group with 16 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| org.apache.commons:commons-collections4 | `4.5.0` | `4.6.0` |
| [com.alibaba:qlexpress4](https://github.com/alibaba/QLExpress) | `4.1.2` | `4.1.3` |
| [com.google.guava:guava](https://github.com/google/guava) | `33.6.0-jre` | `33.7.2-jre` |
| [com.h2database:h2](https://github.com/h2database/h2database) | `2.3.232` | `2.5.252` |
| [org.springdoc:springdoc-openapi-starter-webmvc-api](https://github.com/springdoc/springdoc-openapi) | `3.0.3` | `3.1.1` |
| io.swagger.core.v3:swagger-annotations-jakarta | `2.2.47` | `2.2.55` |
| [org.apache.maven.plugins:maven-jar-plugin](https://github.com/apache/maven-jar-plugin) | `3.5.0` | `3.5.1` |
| [org.apache.maven.plugins:maven-compiler-plugin](https://github.com/apache/maven-compiler-plugin) | `3.15.0` | `3.16.0` |
| [org.apache.maven.plugins:maven-surefire-plugin](https://github.com/apache/maven-surefire) | `3.5.6` | `3.6.0` |
| [com.diffplug.spotless:spotless-maven-plugin](https://github.com/diffplug/spotless) | `3.9.0` | `3.10.3` |
| [com.github.siom79.japicmp:japicmp-maven-plugin](https://github.com/siom79/japicmp) | `0.23.1` | `0.26.2` |
| [org.apache.maven.plugins:maven-install-plugin](https://github.com/apache/maven-install-plugin) | `3.1.4` | `3.2.0` |
| [org.apache.maven.plugins:maven-deploy-plugin](https://github.com/apache/maven-deploy-plugin) | `3.1.4` | `3.2.0` |
| [com.github.spotbugs:spotbugs-maven-plugin](https://github.com/spotbugs/spotbugs-maven-plugin) | `4.10.2.0` | `4.10.4.1` |
| [org.cyclonedx:cyclonedx-maven-plugin](https://github.com/CycloneDX/cyclonedx-maven-plugin) | `2.9.2` | `2.9.3` |
| org.apache.maven:apache-maven | `3.9.16` | `3.10.0` |



Updates `org.apache.commons:commons-collections4` from 4.5.0 to 4.6.0

Updates `com.alibaba:qlexpress4` from 4.1.2 to 4.1.3
- [Release notes](https://github.com/alibaba/QLExpress/releases)
- [Commits](alibaba/QLExpress@v4.1.2...v4.1.3)

Updates `com.google.guava:guava` from 33.6.0-jre to 33.7.2-jre
- [Release notes](https://github.com/google/guava/releases)
- [Commits](https://github.com/google/guava/commits)

Updates `com.h2database:h2` from 2.3.232 to 2.5.252
- [Release notes](https://github.com/h2database/h2database/releases)
- [Commits](h2database/h2database@version-2.3.232...version-2.5.252)

Updates `org.springdoc:springdoc-openapi-starter-webmvc-api` from 3.0.3 to 3.1.1
- [Release notes](https://github.com/springdoc/springdoc-openapi/releases)
- [Changelog](https://github.com/springdoc/springdoc-openapi/blob/main/CHANGELOG.md)
- [Commits](springdoc/springdoc-openapi@v3.0.3...v3.1.1)

Updates `io.swagger.core.v3:swagger-annotations-jakarta` from 2.2.47 to 2.2.55

Updates `org.apache.maven.plugins:maven-jar-plugin` from 3.5.0 to 3.5.1
- [Release notes](https://github.com/apache/maven-jar-plugin/releases)
- [Commits](apache/maven-jar-plugin@maven-jar-plugin-3.5.0...maven-jar-plugin-3.5.1)

Updates `org.apache.maven.plugins:maven-compiler-plugin` from 3.15.0 to 3.16.0
- [Release notes](https://github.com/apache/maven-compiler-plugin/releases)
- [Commits](apache/maven-compiler-plugin@maven-compiler-plugin-3.15.0...maven-compiler-plugin-3.16.0)

Updates `org.apache.maven.plugins:maven-surefire-plugin` from 3.5.6 to 3.6.0
- [Release notes](https://github.com/apache/maven-surefire/releases)
- [Commits](apache/maven-surefire@surefire-3.5.6...surefire-3.6.0)

Updates `com.diffplug.spotless:spotless-maven-plugin` from 3.9.0 to 3.10.3
- [Release notes](https://github.com/diffplug/spotless/releases)
- [Changelog](https://github.com/diffplug/spotless/blob/main/CHANGES.md)
- [Commits](diffplug/spotless@maven/3.9.0...maven/3.10.3)

Updates `com.github.siom79.japicmp:japicmp-maven-plugin` from 0.23.1 to 0.26.2
- [Release notes](https://github.com/siom79/japicmp/releases)
- [Changelog](https://github.com/siom79/japicmp/blob/master/release.py)
- [Commits](siom79/japicmp@japicmp-base-0.23.1...japicmp-base-0.26.2)

Updates `org.apache.maven.plugins:maven-install-plugin` from 3.1.4 to 3.2.0
- [Release notes](https://github.com/apache/maven-install-plugin/releases)
- [Commits](apache/maven-install-plugin@maven-install-plugin-3.1.4...maven-install-plugin-3.2.0)

Updates `org.apache.maven.plugins:maven-deploy-plugin` from 3.1.4 to 3.2.0
- [Release notes](https://github.com/apache/maven-deploy-plugin/releases)
- [Commits](apache/maven-deploy-plugin@maven-deploy-plugin-3.1.4...maven-deploy-plugin-3.2.0)

Updates `com.github.spotbugs:spotbugs-maven-plugin` from 4.10.2.0 to 4.10.4.1
- [Release notes](https://github.com/spotbugs/spotbugs-maven-plugin/releases)
- [Commits](spotbugs/spotbugs-maven-plugin@spotbugs-maven-plugin-4.10.2.0...spotbugs-maven-plugin-4.10.4.1)

Updates `org.cyclonedx:cyclonedx-maven-plugin` from 2.9.2 to 2.9.3
- [Release notes](https://github.com/CycloneDX/cyclonedx-maven-plugin/releases)
- [Commits](CycloneDX/cyclonedx-maven-plugin@cyclonedx-maven-plugin-2.9.2...cyclonedx-maven-plugin-2.9.3)

Updates `org.apache.maven:apache-maven` from 3.9.16 to 3.10.0

---
updated-dependencies:
- dependency-name: org.apache.commons:commons-collections4
  dependency-version: 4.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-and-patch
- dependency-name: com.alibaba:qlexpress4
  dependency-version: 4.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-and-patch
- dependency-name: com.google.guava:guava
  dependency-version: 33.7.2-jre
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-and-patch
- dependency-name: com.h2database:h2
  dependency-version: 2.5.252
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-and-patch
- dependency-name: org.springdoc:springdoc-openapi-starter-webmvc-api
  dependency-version: 3.1.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-and-patch
- dependency-name: io.swagger.core.v3:swagger-annotations-jakarta
  dependency-version: 2.2.55
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-and-patch
- dependency-name: org.apache.maven.plugins:maven-jar-plugin
  dependency-version: 3.5.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-and-patch
- dependency-name: org.apache.maven.plugins:maven-compiler-plugin
  dependency-version: 3.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-and-patch
- dependency-name: org.apache.maven.plugins:maven-surefire-plugin
  dependency-version: 3.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-and-patch
- dependency-name: com.diffplug.spotless:spotless-maven-plugin
  dependency-version: 3.10.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-and-patch
- dependency-name: com.github.siom79.japicmp:japicmp-maven-plugin
  dependency-version: 0.26.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-and-patch
- dependency-name: org.apache.maven.plugins:maven-install-plugin
  dependency-version: 3.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-and-patch
- dependency-name: org.apache.maven.plugins:maven-deploy-plugin
  dependency-version: 3.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-and-patch
- dependency-name: com.github.spotbugs:spotbugs-maven-plugin
  dependency-version: 4.10.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-and-patch
- dependency-name: org.cyclonedx:cyclonedx-maven-plugin
  dependency-version: 2.9.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-and-patch
- dependency-name: org.apache.maven:apache-maven
  dependency-version: 3.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from yusu1210 as a code owner October 2, 2026 16:14
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants