Skip to content

Bump the maven-minor-updates group with 53 updates - #4201

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/main/maven-minor-updates-4eb23ac797
Open

Bump the maven-minor-updates group with 53 updates#4201
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/main/maven-minor-updates-4eb23ac797

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 24, 2026

Copy link
Copy Markdown
Contributor

Bumps the maven-minor-updates group with 53 updates:

Package From To
org.apache.logging.log4j:log4j-api 2.24.3 2.26.1
org.apache.logging.log4j:log4j-api-test 2.24.3 2.26.1
org.apache.logging.log4j:log4j-iostreams 2.24.3 2.26.1
org.apache.logging.log4j:log4j-jpl 2.24.3 2.26.1
org.apache.logging.log4j:log4j-slf4j2-impl 2.24.3 2.26.1
org.apache.logging.log4j:log4j-slf4j-impl 2.24.3 2.26.1
org.apache.logging.log4j:log4j-to-jul 2.24.3 2.26.1
org.apache.logging.log4j:log4j-to-slf4j 2.24.3 2.26.1
org.apache.commons:commons-csv 1.14.0 1.14.1
commons-logging:commons-logging 1.3.5 1.4.0
ch.qos.logback:logback-core 1.5.18 1.5.38
org.slf4j:slf4j-api 2.0.17 2.0.18
tools.jackson:jackson-bom 3.0.0 3.2.1
org.mockito:mockito-bom 5.18.0 5.23.0
org.assertj:assertj-core 3.27.3 3.27.7
net.bytebuddy:byte-buddy 1.17.6 1.18.11
commons-codec:commons-codec 1.18.0 1.22.0
org.apache.commons:commons-dbcp2 2.13.0 2.14.0
commons-io:commons-io 2.20.0 2.22.0
org.apache.commons:commons-lang3 3.17.0 3.20.0
org.apache.commons:commons-pool2 2.12.1 2.13.1
com.google.guava:guava 33.4.8-jre 33.6.0-jre
com.google.guava:guava-testlib 33.4.8-jre 33.6.0-jre
com.h2database:h2 2.3.232 2.4.240
com.google.code.java-allocation-instrumenter:java-allocation-instrumenter 3.3.4 3.3.5
org.jctools:jctools-core 4.0.5 4.0.6
org.jmdns:jmdns 3.6.1 3.6.3
net.java.dev.jna:jna 5.17.0 5.19.1
org.apache.maven:maven-core 3.9.10 3.9.16
org.apache.maven:maven-model 3.9.10 3.9.16
org.openjdk.nashorn:nashorn-core 15.6 15.7
org.eclipse.platform:org.eclipse.osgi 3.23.100 3.24.200
org.codehaus.plexus:plexus-utils 3.6.0 3.6.1
org.xmlunit:xmlunit-core 2.10.3 2.12.0
org.xmlunit:xmlunit-matchers 2.10.3 2.12.0
biz.aQute.bnd:biz.aQute.bnd.annotation 7.1.0 7.3.0
com.github.spotbugs:spotbugs-annotations 4.9.3 4.10.3
io.fabric8:docker-maven-plugin 0.46.0 0.48.1
org.tukaani:xz 1.10 1.12
org.apache.commons:commons-compress 1.27.1 1.28.0
com.google.code.gson:gson 2.13.1 2.14.0
org.slf4j:slf4j-nop 2.0.17 2.0.18
com.fasterxml.jackson.core:jackson-databind 2.20.0 2.22.1
com.fasterxml.jackson.dataformat:jackson-dataformat-yaml 2.20.0 2.22.1
org.javassist:javassist 3.30.2-GA 3.32.0-GA
co.elastic.clients:elasticsearch-java 9.2.0 9.4.3
org.elasticsearch.client:elasticsearch-rest-client 9.2.0 9.4.3
co.elastic.logging:log4j2-ecs-layout 1.7.0 1.8.0
org.mongodb:bson 5.5.1 5.9.0
org.mongodb:mongodb-driver-core 5.5.1 5.9.0
org.mongodb:mongodb-driver-sync 5.5.1 5.9.0
org.slf4j:slf4j-simple 2.0.17 2.0.18
ch.qos.logback:logback-classic 1.5.18 1.5.38

Updates org.apache.logging.log4j:log4j-api from 2.24.3 to 2.26.1

Updates org.apache.logging.log4j:log4j-api-test from 2.24.3 to 2.26.1

Updates org.apache.logging.log4j:log4j-iostreams from 2.24.3 to 2.26.1

Updates org.apache.logging.log4j:log4j-jpl from 2.24.3 to 2.26.1

Updates org.apache.logging.log4j:log4j-slf4j2-impl from 2.24.3 to 2.26.1

Updates org.apache.logging.log4j:log4j-slf4j-impl from 2.24.3 to 2.26.1

Updates org.apache.logging.log4j:log4j-to-jul from 2.24.3 to 2.26.1

Updates org.apache.logging.log4j:log4j-to-slf4j from 2.24.3 to 2.26.1

Updates org.apache.logging.log4j:log4j-api-test from 2.24.3 to 2.26.1

Updates org.apache.logging.log4j:log4j-iostreams from 2.24.3 to 2.26.1

Updates org.apache.logging.log4j:log4j-jpl from 2.24.3 to 2.26.1

Updates org.apache.logging.log4j:log4j-slf4j2-impl from 2.24.3 to 2.26.1

Updates org.apache.logging.log4j:log4j-slf4j-impl from 2.24.3 to 2.26.1

Updates org.apache.logging.log4j:log4j-to-jul from 2.24.3 to 2.26.1

Updates org.apache.logging.log4j:log4j-to-slf4j from 2.24.3 to 2.26.1

Updates org.apache.commons:commons-csv from 1.14.0 to 1.14.1

Changelog

Sourced from org.apache.commons:commons-csv's changelog.

Apache Commons CSV 1.14.1 Release Notes

The Apache Commons CSV team is pleased to announce the release of Apache Commons CSV 1.14.1.

This document contains the release notes for the 1.14.1 version of Apache Commons CSV. Commons CSV reads and writes files in Comma Separated Value (CSV) format variations.

Commons CSV requires at least Java 8.

The Apache Commons CSV library provides a simple interface for reading and writing CSV files of various types.

This is a feature and maintenance release. Java 8 or later is required.

Changes in this version include:

Fixed Bugs

  • CSV-318: CSVPrinter.printRecord(Stream) hangs if given a parallel stream. Thanks to Joseph Shraibman, Gary Gregory.
  • CSV-318: CSVPrinter now uses an internal lock instead of synchronized methods. Thanks to Joseph Shraibman, Gary Gregory.
  •       org.apache.commons.csv.CSVPrinter.printRecords(ResultSet) now writes one record at a time using a lock. Thanks to Gary Gregory.
    

Changes

  •       Bump org.apache.commons:commons-parent from 81 to 85 [#542](https://github.com/apache/commons-csv/issues/542). Thanks to Gary Gregory, Dependabot.
    
  •       Bump commons-io:commons-io from 2.18.0 to 2.20.0. Thanks to Gary Gregory.
    
  •       Bump com.opencsv:opencsv from 5.10 to 5.11.2 [#545](https://github.com/apache/commons-csv/issues/545), [#551](https://github.com/apache/commons-csv/issues/551), [#553](https://github.com/apache/commons-csv/issues/553). Thanks to Gary Gregory, Dependabot.
    
  •       Bump org.apache.commons:commons-lang3 from 3.17.0 to 3.18.0 [#556](https://github.com/apache/commons-csv/issues/556). Thanks to Gary Gregory, Dependabot.
    
  •       Bump commons-codec:commons-codec from 1.18.0 to 1.19.0. Thanks to Gary Gregory.
    

Historical list of changes: https://commons.apache.org/proper/commons-csv/changes.html

For complete information on Apache Commons CSV, including instructions on how to submit bug reports, patches, or suggestions for improvement, see the Apache Commons CSV website:

https://commons.apache.org/proper/commons-csv/

Download page: https://commons.apache.org/proper/commons-csv/download_csv.cgi

Have fun! -Apache Commons CSV team


Commits
  • e14ef86 Ignore macOS file
  • d8724bf Prepare for the release candidate 1.14.1 RC1
  • b76971c Prepare for the next release candidate
  • b66814e Merge pull request #557 from apache/dependabot/github_actions/github/codeql-a...
  • 9c95e92 Bump github/codeql-action from 3.29.2 to 3.29.4
  • 1fb3716 Bump commons-codec:commons-codec from 1.18.0 to 1.19.0
  • 7b72c50 Merge some string literals
  • 9658373 Update the GitHub pull request template for AI
  • 67192a9 Bump commons-io:commons-io from 2.19.0 to 2.20.0
  • 59164c8 Bump com.opencsv:opencsv from 5.11.1 to 5.11.2 #553
  • Additional commits viewable in compare view

Updates commons-logging:commons-logging from 1.3.5 to 1.4.0

Changelog

Sourced from commons-logging:commons-logging's changelog.

Apache Commons Logging 1.4.0 Release Notes

The Apache Commons Logging team is pleased to announce the release of Apache Commons Logging 1.4.0.

Apache Commons Logging is a thin adapter allowing configurable bridging to other, well-known logging systems.

This is a feature and maintenance release. Java 8 or later is required.

Changes in this version

Fixed Bugs

  •           Use the new Apache oak leaf logo. Thanks to Gary Gregory.
    
  •           Fix broken URLs in website links. Thanks to Stanimir Stamenkov, Gary Gregory.
    
  •           Add support for Jakarta servlets, see org.apache.commons.logging.jakarta.ServletContextCleaner [#419](https://github.com/apache/commons-logging/issues/419). Thanks to Kiril Keranov, Gary Gregory.
    

Changes

  •           Bump org.apache.commons:commons-parent from 97 to 102. Thanks to Gary Gregory.
    
  •           Bump log4j2.version from 2.25.3 to 2.26.0. Thanks to Gary Gregory, Dependabot.
    
  •           Bump org.slf4j:slf4j-api from 2.0.17 to 2.0.18. Thanks to Gary Gregory, Dependabot.
    

Historical list of changes: https://commons.apache.org/proper/commons-logging/changes.html

Download it from https://commons.apache.org/proper/commons-logging/download_logging.cgi

For complete information on Apache Commons Logging, including instructions on how to submit bug reports, patches, or suggestions for improvement, see the Apache Commons Logging website:

https://commons.apache.org/proper/commons-logging/


Apache Commons Logging 1.3.6 Release Notes

The Apache Commons Logging team is pleased to announce the release of Apache Commons Logging 1.3.6.

Apache Commons Logging is a thin adapter allowing configurable bridging to other, well-known logging systems.

This is a feature and maintenance release. Java 8 or later is required.

Changes in this version

... (truncated)

Commits
  • ff5ff39 Prepare for the release candidate 1.4.0 RC1
  • a685f33 Prepare for the next release candidate
  • a253ab6 Bump org.slf4j:slf4j-api from 2.0.17 to 2.0.18.
  • d6c9b81 Javadoc
  • 1cf45b2 Update legacy GitHub links in CONTRIBUTING.md
  • 9b48b5b Bump org.apache.commons:commons-parent from 101 to 102.
  • 7a44cb6 Bump GH CI actions/dependency-review-action from 4.9.0 to 5.0.0
  • e884661 Bump GH CI actions/checkout from 6.0.2 to 6.0.3
  • f6ad6f9 Bump org.apache.commons:commons-parent from 100 to 101
  • b468740 Bump github/codeql-action from 4.36.0 to 4.36.2
  • Additional commits viewable in compare view

Updates ch.qos.logback:logback-core from 1.5.18 to 1.5.38

Release notes

Sourced from ch.qos.logback:logback-core's releases.

Logback 1.5.38

2026-07-09 Release of logback version 1.5.38

• In HardenedObjectInputStream, fixed a typo preventing Throwable objects from being white-filtered. This issue was reported in [PR #1045](qos-ch/logback#1045) by t0rchwo0d.

• A bitwise identical binary of this version can be reproduced by building from source code at commit d04984a41fce42977466f45a2f076f0ee5cc4207 associated with the tag v_1.5.38. Release built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Logback 1.5.37

2026-06-26 Release of logback version 1.5.37

  1. • Given the numerous vulnerabilities related to conditional configuration processing based on the evaluation of Java expressions using the Janino library, support for such expressions has been removed. Users are offered the an online migration service or the <condition> element introduced in version 1.5.20. See the relevant documentation for more details.

• A bitwise identical binary of this version can be reproduced by building from source code at commit c1df7f522e648eec7b4ef6a12c8758fec0f00048 associated with the tag v_1.5.37. Release built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Logback 1.5.36

2026-06-25 Release of logback version 1.5.36

• The 'condition' attribute in <if> elements now reject certain references that are associated with ACE attacks. This issue was reported by "yulate" (yulate531@gmail.com.com) and registered as CVE-2026-13006. Please note that version 1.5.37 provides the full fix to this vulnerability.

• A bitwise identical binary of this version can be reproduced by building from source code at commit 9b94c37562bf25a6a944146701d42ee6c4eee888 associated with the tag v_1.5.36. Release built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Logback 1.5.35

026-06-23 Release of logback version 1.5.35

• The 'condition' attribute in <if> elements now rejects unicode escape sequences (\u and \U). This closes a bypass of the existing prohibition on the new operator in Janino-evaluated conditions. This issue was reported by IcySun (icysun@qq.com) and registered as CVE-2026-13006. Please note that version 1.5.37 provides the full fix to this vulnerability.

• Added ConfiguratorRank.AUTHENTICATING (rank 100), the highest configurator rank, for certified/authenticating configurators discovered via the ServiceLoader mechanism. ContextInitializer now requires that at most one such configurator exist on the classpath; if more than one is found, initialization aborts with an error.

ConsoleCharsetPropertyDefiner is no longer shipped. The Java 21 multi-release compilation of logback-core has been disabled, which removes this class from the published artifact. Configurations that referenced ch.qos.logback.core.property.ConsoleCharsetPropertyDefiner will need an alternative approach for console charset detection.

• The logback-examples module is now included in artifacts published to Maven Central.

JoranConfigurator.makeAnotherInstance() and DefaultJoranConfigurator.performMultiStepConfigurationFileSearch() are now protected, allowing derived configurators to override these methods.

• A bitwise identical binary of this version can be reproduced by building from source code at commit 08bd1598d565d83444f72983935e7da4746783b7 associated with the tag v_1.5.35. Release built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Logback 1.5.34

2026-06-01 Release of logback version 1.5.34

• In case certain StackTraceElement values returned by the Throwable.getStackTrace method are null, StackTraceElementProxy substitutes a dummy instance instead of throwing an IllegalArgumentException. This resolves [issues #1040](qos-ch/logback#1040), reported by Naotsugu Kobayashi.

• HardenedObjectInputStream will now throw an InvalidClassException during deserialization attempts of Proxy classes. This change addresses potential deserialization whitelist bypass vulnerability reported by York Shen and registered as CVE-2026-10532.

• A bitwise identical binary of this version can be reproduced by building from source code at commit e62272ac152469aec1ede056c3c7d0d7314e7bfe associated with the tag v_1.5.34. This release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Logback 1.5.33

2026-05-27 Release of logback version 1.5.33

PropertiesConfiguratorModelHandler now registers properties file URLs to the ConfigurationWatchList when scan is enabled (via local scan="true" attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in issues/1034.

... (truncated)

Commits
  • d04984a prepare release 1.5.38
  • 4fffda6 updateversion of maven-gpg-plugin
  • 7ee48a1 Fixed a typo where java,lang.Throwable was written with a comma instead of a ...
  • 84580a2 remove license profile
  • f817c8d start work on 1.5.28-SNAPSHOT
  • c1df7f5 prepare release 1.5.37
  • a189967 remove conditional based on janino
  • aaa9052 start work on 1.5.37-SNAPSHOT
  • 9b94c37 prepare release 1.5.36
  • e6a8280 prevent attacks using disallowed references
  • Additional commits viewable in compare view

Updates org.slf4j:slf4j-api from 2.0.17 to 2.0.18

Updates tools.jackson:jackson-bom from 3.0.0 to 3.2.1

Commits
  • 6a1ef2f [maven-release-plugin] prepare release jackson-bom-3.2.1
  • ad919fe Prep for 3.2.1 release
  • 3169e44 Merge branch '3.1' into 3.2
  • 3fdc4a2 Post-release dep version bump
  • 39a41ff [maven-release-plugin] prepare for next development iteration
  • 4526fd9 [maven-release-plugin] prepare release jackson-bom-3.1.5
  • adf07de Prep for 3.1.5 release
  • 7cc1b15 Post-release dep version bump
  • c69c060 [maven-release-plugin] prepare for next development iteration
  • 421a5be [maven-release-plugin] prepare release jackson-bom-3.2.0
  • Additional commits viewable in compare view

Updates org.mockito:mockito-bom from 5.18.0 to 5.23.0

Release notes

Sourced from org.mockito:mockito-bom's releases.

v5.23.0

NOTE: Breaking change for Android

The mockito-android artifact has a breaking change: tests now require a device or emulator based on API 28+ (Android P). This is to enable new support for mocking Kotlin classes. See #3788 for more details.


Changelog generated by Shipkit Changelog Gradle Plugin

5.23.0

v5.22.0

Changelog generated by Shipkit Changelog Gradle Plugin

5.22.0

v5.21.0

Changelog generated by Shipkit Changelog Gradle Plugin

5.21.0

... (truncated)

Commits
  • a231205 Fix StackOverflowError with AbstractList after using mockSingleton (#3790)
  • f6a91a6 Replace mockito-android mock maker implementation with dexmaker-mockito-inlin...
  • aa2298a fix: make spotless happy
  • a6729d6 chore: update BDDMockito with jspecify annotation
  • bb83c92 chore: move jspecify as a compile only dependency
  • 47a4695 chore: add jspecify with minimal change. Fixes #3503
  • 25f1395 Add core API to enable Kotlin singleton mocking (#3762)
  • ef9ee55 Avoids mocking private static methods, as well as package-private static meth...
  • d16fcfc Bump graalvm/setup-graalvm from 1.4.4 to 1.4.5 (#3780)
  • 27eb8a3 Clarify RETURNS_MOCKS behavior with sealed abstract enums (Java 15+) (#3773)
  • Additional commits viewable in compare view

Updates org.assertj:assertj-core from 3.27.3 to 3.27.7

Release notes

Sourced from org.assertj:assertj-core's releases.

v3.27.7

🔒 Security

Core

🚫 Deprecated

Core

  • Deprecate XmlStringPrettyFormatter with no replacement

🐛 Bug Fixes

Guava

  • Navigation to assertj-core or guava types from assertj-guava Javadoc site has unnecessary header #3478

🔨 Dependency Upgrades

Core

  • Upgrade to Byte Buddy 1.18.3
  • Upgrade to JUnit BOM 5.14.1

Guava

  • Upgrade to Guava 33.5.0-jre

v3.27.6

🐛 Bug Fixes

Core

  • Add missing export for org.assertj.core.annotation #3951

❤️ Contributors

Thanks to all the contributors who worked on this release:

@​duponter

v3.27.5

⚡ Improvements

Core

  • ByteBuddy in AssertJ 3.27.4 not compatible with Java 25 #3946

... (truncated)

Commits
  • e840716 [maven-release-plugin] prepare release assertj-build-3.27.7
  • 85ca7eb Deprecate XmlStringPrettyFormatter
  • 77081dc Merge commit from fork
  • b68fc24 Bump github/codeql-action from 4.31.9 to 4.31.10 in the github-actions group ...
  • 0cf5bb6 Bump kotlin.version from 2.1.0 to 2.2.21
  • d393ef1 Abort tests when symbolic links cannot be created (#3788)
  • 2212433 Add IntelliJ custom inspection for test class names
  • 5717d02 Update JetBrains icon
  • a8ec20b Add icon for JetBrains products
  • c05fb3d Bump Maven to 3.9.12 and Wrapper to 3.3.4
  • Additional commits viewable in compare view

Updates net.bytebuddy:byte-buddy from 1.17.6 to 1.18.11

Release notes

Sourced from net.bytebuddy:byte-buddy's releases.

Byte Buddy 1.18.11

  • Add SBOM to published artifacts.
  • Check for traversable paths injected into class files as a rather hypothetical attack vector.

Byte Buddy 1.18.10

  • Delay change of default for unsage use to Java 26 and improve error message.

Byte Buddy 1.18.9

  • Disable use of Unsafe by default when Java 25or newer is discovered.
  • Check for escape when creating folders in Plugin.Engine.
  • Improve OpenJ9 attachment.
  • Avoid null pointer on missing annotation types.
  • Improve diagnostics for external agent attachment.
  • Improve on Gradle context discovery.
  • Support Android libraries on AGP9 or newer.
  • Update ASM.

Byte Buddy 1.18.8

  • Improve support for repeatable builds.
  • Fix reordering of exception table in type initializers when instrumenting.

Byte Buddy 1.18.7

  • Introduce new versioning concept with -jdk5 suffix for backwards-compatible jar and Java 8 baseline for regular jar.

Byte Buddy 1.18.5

  • Eagerly resolve of canonical files during attach emulation to avoid failure when process ends before file can be deleted.
  • Add super classes to hash code / equals computation in Advice that were missing.

Byte Buddy 1.18.4

  • Add support for new build description in Android 9.

Byte Buddy 1.18.3

  • Avoid using Class File API when Byte Buddy is loaded on the boot loader where multi-release jars are not available.
  • Add additional safety when processing class files with illegally formed parameters.
  • Update to latest ASM.

Byte Buddy 1.18.2

  • Support modifiers for value classes in Valhalla builds.
  • Improve use of build cache in Gradle.

Byte Buddy 1.18.1

  • Fix generated module-info to include new package.

Byte Buddy 1.18.0

  • Add support for module-info class files and ModuleDescriptions.
  • Allow for manipulating module information using the ByteBuddy API.

Byte Buddy 1.17.8

  • Avoid use of types that are deprecated as of Java 26.
  • Include ASM 9.9 that offers ASM support for Java 26.

... (truncated)

Changelog

Sourced from net.bytebuddy:byte-buddy's changelog.

2. July 2026: version 1.18.11

  • Add SBOM to published artifacts.
  • Check for traversable paths injected into class files as a rather hypothetical attack vector.

3. June 2026: version 1.18.10

  • Delay change of default for unsage use to Java 26 and improve error message.

1. June 2026: version 1.18.9

  • Disable use of Unsafe by default when Java 25or newer is discovered.
  • Check for escape when creating folders in Plugin.Engine.
  • Improve OpenJ9 attachment.
  • Avoid null pointer on missing annotation types.
  • Improve diagnostics for external agent attachment.
  • Improve on Gradle context discovery.
  • Support Android libraries on AGP9 or newer.
  • Update ASM.

1. April 2026: version 1.18.8

  • Improve support for repeatable builds.
  • Fix reordering of exception table in type initializers when instrumenting.

1. March 2026: version 1.18.7

  • Introduce new versioning concept with -jdk5 suffix for backwards-compatible jar and Java 8 baseline for regular jar.

27. February 2026: version 1.18.6

Accidental release during rework of release pipeline. Functional, but with incorrect suffices.

15. February 2026: version 1.18.5

  • Eagerly resolve of canonical files during attach emulation to avoid failure when process ends before file can be deleted.
  • Add super classes to hash code / equals computation in Advice that were missing.

16. January 2026: version 1.18.4

  • Add support for new build description in Android 9.

26. November 2025: version 1.18.3

  • Avoid using Class File API when Byte Buddy is loaded on the boot loader where multi-release jars are not available.
  • Add additional safety when processing class files with illegally formed parameters.
  • Update to latest ASM.

26. November 2025: version 1.18.2

... (truncated)

Commits
  • 88dd0a3 [publish] Releasing Byte Buddy 1.18.11
  • 46fcade [release] Release new version
  • 6a68de6 Prevent path traversal from crafted type names when writing class files to fo...
  • 9ba4ab6 Pin ClusterFuzzLite base image and actions by hash.
  • dd4f81e Add SBOM to build.
  • 7dd9a0d Update internal Byte Buddy and release notes
  • d6b3e15 [publish] Start next development iteration 1.18.11-SNAPSHOT
  • e85623d [publish] Releasing Byte Buddy 1.18.10
  • e3bfa68 [release] Release new version
  • 5821ccc Delay disabling of unsafe by default to Java 26 and improve on error message.
  • Additional commits viewable in compare view

Updates commons-codec:commons-codec from 1.18.0 to 1.22.0

Changelog

Sourced from commons-codec:commons-codec's changelog.

Apache Commons Codec 1.22.0 Release Notes

The Apache Commons Codec team is pleased to announce the release of Apache Commons Codec 1.22.0.

The Apache Commons Codec component contains encoders and decoders for formats such as Base16, Base32, Base64, digest, and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities.

This is a feature and maintenance release. Java 8 or later is required.

New features

  • CODEC-326: Add Base58 support. Thanks to Inkeet, Gary Gregory, Wolff Bock von Wuelfingen.
  •         Add BaseNCodecInputStream.AbstracBuilder.setByteArray(byte[]). Thanks to Gary Gregory.
    
  • CODEC-335: Add GitIdentifiers to compute Git blob and tree object identifiers. Thanks to Piotr P. Karwasz, Gary Gregory.

Fixed Bugs

  • CODEC-249: Fix Incorrect transform of CH digraph according Metaphone basic rules #423. Thanks to Shalu Jha, Andrey, Gary Gregory.
  • CODEC-317: ColognePhonetic can create duplicate consecutive codes in some cases. Thanks to DRUser123, Shalu Jha, Gary Gregory.
  •         Add boundary tests for BinaryCodec.fromAscii partial-bit inputs [#425](https://github.com/apache/commons-codec/issues/425). Thanks to fancying, Gary Gregory.
    
  • CODEC-336: Base64.Builder.setUrlSafe(boolean) Javadoc incorrectly states null is accepted for primitive boolean parameter. Thanks to Partha Paul, Gary Gregory.

Changes

  •         Bump org.apache.commons:commons-parent from 96 to 98. Thanks to Gary Gregory.
    

For complete information on Apache Commons Codec, including instructions on how to submit bug reports, patches, or suggestions for improvement, see the Apache Commons Codec website:

https://commons.apache.org/proper/commons-codec/

Download page: https://commons.apache.org/proper/commons-codec/download_codec.cgi


Apache Commons Codec 1.21.0 Release Notes

The Apache Commons Codec team is pleased to announce the release of Apache Commons Codec 1.21.0.

The Apache Commons Codec component contains encoders and decoders for formats such as Base16, Base32, Base64, digest, and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a

... (truncated)

Commits

Updates org.apache.commons:commons-dbcp2 from 2.13.0 to 2.14.0

Updates commons-io:commons-io from 2.20.0 to 2.22.0

Updates org.apache.commons:commons-lang3 from 3.17.0 to 3.20.0

Updates org.apache.commons:commons-pool2 from 2.12.1 to 2.13.1

Updates com.google.guava:guava from 33.4.8-jre to 33.6.0-jre

Release notes

Sourced from com.google.guava:guava's releases.

33.6.0

Maven

<dependency>
  <groupId>com.google.guava</groupId>
  <artifactId>guava</artifactId>
  <version>33.6.0-jre</version>
  <!-- or, for Android: -->
  <version>33.6.0-android</version>
</dependency>

Jar files

Guava requires one runtime dependency, which you can download here:

Javadoc

JDiff

Changelog

  • Migrated some classes from finalize() to PhantomReference in preparation for the removal of finalization. (786b619dd6, 7c6b17c, aeef90988d)
  • cache: Deprecated CacheBuilder APIs that use TimeUnit in favor of those that use Duration. (73f8b0bb84)
  • collect: Added toImmutableSortedMap collectors that use the natural comparator. (64d70b9f94)
  • collect: Changed ConcurrentHashMultiset, ImmutableMultimap, and TreeMultiset deserialization to avoid mutating final fields. In extremely unlikely scenarios in which an instance of that type contains an object that refers back to that instance, this could lead to a broken instance that throws NullPointerException when used. (8240c7e596, 046468055f)
  • graph: Removed @Beta from all APIs in the package. (dae9566b73)
  • graph: Added support to Graphs.transitiveClosure() for different strategies for adding self-loops. (2e13df25b2)
  • graph: Added an asNetwork() view to Graph and ValueGraph. (909c593c61)
  • hash: Added BloomFilter.serializedSize(). (df9bcc251a)
  • net: Added HttpHeaders.CDN_CACHE_CONTROL. (75331b5030)

33.5.0

Maven

<dependency>
</tr></table> 

... (truncated)

Commits

Updates com.google.guava:guava-testlib from 33.4.8-jre to 33.6.0-jre

Release notes

Sourced from com.google.guava:guava-testlib's releases.

33.6.0

Maven

<dependency>
  <groupId>com.google.guava</groupId>
  <artifactId>guava</artifactId>
  <version>33.6.0-jre</version>
  <!-- or, for Android: -->
  <version>33.6.0-android</version>
</dependency>

Jar files

Guava requires one runtime dependency, which you can download here:

Javadoc

JDiff

Changelog

  • Migrated some classes from finalize() to PhantomReference in preparation for the removal of finalization. (786b619dd6, 7c6b17c, aeef90988d)
  • cache: Deprecated CacheBuilder APIs that use TimeUnit in favor of those that use Duration. (73f8b0bb84)
  • collect: Added toImmutableSortedMap collectors that use the natural comparator. (64d70b9f94)
  • collect: Changed ConcurrentHashMultiset, ImmutableMultimap, and TreeMultiset deserialization to avoid mutating final fields. In extremely unlikely scenarios in which an instance of that type contains an object that refers back to that instance, this could lead to a broken instance that throws NullPointerException when used. (8240c7e596, 046468055f)
  • graph: Removed @Beta from all APIs in the package. (dae9566b73)
  • graph: Added support to Graphs.transitiveClosure() for different strategies for adding self-loops. (2e13df25b2)
  • graph: Added an asNetwork() view to Graph and ValueGraph. (909c593c61)
  • hash: Added BloomFilter.serializedSize(). (df9bcc251a)
  • net: Added HttpHeaders.CDN_CACHE_CONTROL. (75331b5030)

33.5.0

Maven

<dependency>
</tr></table> 

... (truncated)

Commits

Updates com.google.guava:guava-testlib from 33.4.8-jre to 33.6.0-jre

Release notes

Sourced from com.google.guava:guava-testlib's releases.

33.6.0

Maven

<dependency>
  <groupId>com.google.guava</groupId>
  <artifactId>guava</artifactId>
  <version>33.6.0-jre</version>
  <!-- or, for Android: -->
  <version>33.6.0-android</version>
</dependency>

Jar files

Guava requires one runtime dependency, which you can download here:

Javadoc

JDiff

Changelog

  • Migrated some classes from finalize() to PhantomReference in preparation for the removal of finalization. (786b619dd6, 7c6b17c, aeef90988d)
  • cache: Deprecated CacheBuilder APIs that use TimeUnit in favor of those that use Duration. (73f8b0bb84)
  • collect: Added toImmutableSortedMap collectors that use the natural comparator. (64d70b9f94)
  • collect: Changed ConcurrentHashMultiset, ImmutableMultimap, and TreeMultiset deserialization to avoid mutating final fields. In extremely unlikely scenarios in which an instance of that type contains an object that refers back to that instance, this could lead to a broken instance that throws NullPointerException when used. (8240c7e596, 046468055f)
  • graph: Removed @Beta from all APIs in the package. (dae9566b73)
  • graph: Added support to Graphs.transitiveClosure() for different strategies for adding self-loops. (2e13df25b2)
  • graph: Added an asNetwork() view to Graph and ValueGraph. (909c593c61)
  • hash: Added BloomFilter.serializedSize(). (df9bcc251a)
  • net: Added HttpHeaders.CDN_CACHE_CONTROL. (75331b5030)

33.5.0

Maven

<dependency>
</tr></table> 

... (truncated)

Commits

Updates com.h2database:h2 from 2.3.232 to 2.4.240

Release notes

Sourced from com.h2database:h2's releases.

Version 2.4.240

... (truncated)

Commits
  • c8eb81b in preparatio...

    Description has been truncated

Bumps the maven-minor-updates group with 53 updates:

| Package | From | To |
| --- | --- | --- |
| org.apache.logging.log4j:log4j-api | `2.24.3` | `2.26.1` |
| org.apache.logging.log4j:log4j-api-test | `2.24.3` | `2.26.1` |
| org.apache.logging.log4j:log4j-iostreams | `2.24.3` | `2.26.1` |
| org.apache.logging.log4j:log4j-jpl | `2.24.3` | `2.26.1` |
| org.apache.logging.log4j:log4j-slf4j2-impl | `2.24.3` | `2.26.1` |
| org.apache.logging.log4j:log4j-slf4j-impl | `2.24.3` | `2.26.1` |
| org.apache.logging.log4j:log4j-to-jul | `2.24.3` | `2.26.1` |
| org.apache.logging.log4j:log4j-to-slf4j | `2.24.3` | `2.26.1` |
| [org.apache.commons:commons-csv](https://github.com/apache/commons-csv) | `1.14.0` | `1.14.1` |
| [commons-logging:commons-logging](https://github.com/apache/commons-logging) | `1.3.5` | `1.4.0` |
| [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) | `1.5.18` | `1.5.38` |
| org.slf4j:slf4j-api | `2.0.17` | `2.0.18` |
| [tools.jackson:jackson-bom](https://github.com/FasterXML/jackson-bom) | `3.0.0` | `3.2.1` |
| [org.mockito:mockito-bom](https://github.com/mockito/mockito) | `5.18.0` | `5.23.0` |
| [org.assertj:assertj-core](https://github.com/assertj/assertj) | `3.27.3` | `3.27.7` |
| [net.bytebuddy:byte-buddy](https://github.com/raphw/byte-buddy) | `1.17.6` | `1.18.11` |
| [commons-codec:commons-codec](https://github.com/apache/commons-codec) | `1.18.0` | `1.22.0` |
| org.apache.commons:commons-dbcp2 | `2.13.0` | `2.14.0` |
| commons-io:commons-io | `2.20.0` | `2.22.0` |
| org.apache.commons:commons-lang3 | `3.17.0` | `3.20.0` |
| org.apache.commons:commons-pool2 | `2.12.1` | `2.13.1` |
| [com.google.guava:guava](https://github.com/google/guava) | `33.4.8-jre` | `33.6.0-jre` |
| [com.google.guava:guava-testlib](https://github.com/google/guava) | `33.4.8-jre` | `33.6.0-jre` |
| [com.h2database:h2](https://github.com/h2database/h2database) | `2.3.232` | `2.4.240` |
| [com.google.code.java-allocation-instrumenter:java-allocation-instrumenter](https://github.com/google/allocation-instrumenter) | `3.3.4` | `3.3.5` |
| [org.jctools:jctools-core](https://github.com/JCTools/JCTools) | `4.0.5` | `4.0.6` |
| [org.jmdns:jmdns](https://github.com/jmdns/jmdns) | `3.6.1` | `3.6.3` |
| [net.java.dev.jna:jna](https://github.com/java-native-access/jna) | `5.17.0` | `5.19.1` |
| org.apache.maven:maven-core | `3.9.10` | `3.9.16` |
| org.apache.maven:maven-model | `3.9.10` | `3.9.16` |
| [org.openjdk.nashorn:nashorn-core](https://github.com/openjdk/nashorn) | `15.6` | `15.7` |
| [org.eclipse.platform:org.eclipse.osgi](https://github.com/eclipse-equinox/equinox) | `3.23.100` | `3.24.200` |
| [org.codehaus.plexus:plexus-utils](https://github.com/codehaus-plexus/plexus-utils) | `3.6.0` | `3.6.1` |
| [org.xmlunit:xmlunit-core](https://github.com/xmlunit/xmlunit) | `2.10.3` | `2.12.0` |
| [org.xmlunit:xmlunit-matchers](https://github.com/xmlunit/xmlunit) | `2.10.3` | `2.12.0` |
| [biz.aQute.bnd:biz.aQute.bnd.annotation](https://github.com/bndtools/bnd) | `7.1.0` | `7.3.0` |
| [com.github.spotbugs:spotbugs-annotations](https://github.com/spotbugs/spotbugs) | `4.9.3` | `4.10.3` |
| [io.fabric8:docker-maven-plugin](https://github.com/fabric8io/docker-maven-plugin) | `0.46.0` | `0.48.1` |
| [org.tukaani:xz](https://github.com/tukaani-project/xz-java) | `1.10` | `1.12` |
| [org.apache.commons:commons-compress](https://github.com/apache/commons-compress) | `1.27.1` | `1.28.0` |
| [com.google.code.gson:gson](https://github.com/google/gson) | `2.13.1` | `2.14.0` |
| org.slf4j:slf4j-nop | `2.0.17` | `2.0.18` |
| [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson) | `2.20.0` | `2.22.1` |
| [com.fasterxml.jackson.dataformat:jackson-dataformat-yaml](https://github.com/FasterXML/jackson-dataformats-text) | `2.20.0` | `2.22.1` |
| [org.javassist:javassist](https://github.com/jboss-javassist/javassist) | `3.30.2-GA` | `3.32.0-GA` |
| [co.elastic.clients:elasticsearch-java](https://github.com/elastic/elasticsearch-java) | `9.2.0` | `9.4.3` |
| [org.elasticsearch.client:elasticsearch-rest-client](https://github.com/elastic/elasticsearch) | `9.2.0` | `9.4.3` |
| [co.elastic.logging:log4j2-ecs-layout](https://github.com/elastic/ecs-logging-java) | `1.7.0` | `1.8.0` |
| [org.mongodb:bson](https://github.com/mongodb/mongo-java-driver) | `5.5.1` | `5.9.0` |
| [org.mongodb:mongodb-driver-core](https://github.com/mongodb/mongo-java-driver) | `5.5.1` | `5.9.0` |
| [org.mongodb:mongodb-driver-sync](https://github.com/mongodb/mongo-java-driver) | `5.5.1` | `5.9.0` |
| org.slf4j:slf4j-simple | `2.0.17` | `2.0.18` |
| [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) | `1.5.18` | `1.5.38` |


Updates `org.apache.logging.log4j:log4j-api` from 2.24.3 to 2.26.1

Updates `org.apache.logging.log4j:log4j-api-test` from 2.24.3 to 2.26.1

Updates `org.apache.logging.log4j:log4j-iostreams` from 2.24.3 to 2.26.1

Updates `org.apache.logging.log4j:log4j-jpl` from 2.24.3 to 2.26.1

Updates `org.apache.logging.log4j:log4j-slf4j2-impl` from 2.24.3 to 2.26.1

Updates `org.apache.logging.log4j:log4j-slf4j-impl` from 2.24.3 to 2.26.1

Updates `org.apache.logging.log4j:log4j-to-jul` from 2.24.3 to 2.26.1

Updates `org.apache.logging.log4j:log4j-to-slf4j` from 2.24.3 to 2.26.1

Updates `org.apache.logging.log4j:log4j-api-test` from 2.24.3 to 2.26.1

Updates `org.apache.logging.log4j:log4j-iostreams` from 2.24.3 to 2.26.1

Updates `org.apache.logging.log4j:log4j-jpl` from 2.24.3 to 2.26.1

Updates `org.apache.logging.log4j:log4j-slf4j2-impl` from 2.24.3 to 2.26.1

Updates `org.apache.logging.log4j:log4j-slf4j-impl` from 2.24.3 to 2.26.1

Updates `org.apache.logging.log4j:log4j-to-jul` from 2.24.3 to 2.26.1

Updates `org.apache.logging.log4j:log4j-to-slf4j` from 2.24.3 to 2.26.1

Updates `org.apache.commons:commons-csv` from 1.14.0 to 1.14.1
- [Changelog](https://github.com/apache/commons-csv/blob/master/RELEASE-NOTES.txt)
- [Commits](apache/commons-csv@rel/commons-csv-1.14.0...rel/commons-csv-1.14.1)

Updates `commons-logging:commons-logging` from 1.3.5 to 1.4.0
- [Changelog](https://github.com/apache/commons-logging/blob/master/RELEASE-NOTES.txt)
- [Commits](apache/commons-logging@rel/commons-logging-1.3.5...rel/commons-logging-1.4.0)

Updates `ch.qos.logback:logback-core` from 1.5.18 to 1.5.38
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.5.18...v_1.5.38)

Updates `org.slf4j:slf4j-api` from 2.0.17 to 2.0.18

Updates `tools.jackson:jackson-bom` from 3.0.0 to 3.2.1
- [Commits](FasterXML/jackson-bom@jackson-bom-3.0.0...jackson-bom-3.2.1)

Updates `org.mockito:mockito-bom` from 5.18.0 to 5.23.0
- [Release notes](https://github.com/mockito/mockito/releases)
- [Commits](mockito/mockito@v5.18.0...v5.23.0)

Updates `org.assertj:assertj-core` from 3.27.3 to 3.27.7
- [Release notes](https://github.com/assertj/assertj/releases)
- [Commits](assertj/assertj@assertj-build-3.27.3...assertj-build-3.27.7)

Updates `net.bytebuddy:byte-buddy` from 1.17.6 to 1.18.11
- [Release notes](https://github.com/raphw/byte-buddy/releases)
- [Changelog](https://github.com/raphw/byte-buddy/blob/master/release-notes.md)
- [Commits](raphw/byte-buddy@byte-buddy-1.17.6...byte-buddy-1.18.11)

Updates `commons-codec:commons-codec` from 1.18.0 to 1.22.0
- [Changelog](https://github.com/apache/commons-codec/blob/master/RELEASE-NOTES.txt)
- [Commits](apache/commons-codec@rel/commons-codec-1.18.0...rel/commons-codec-1.22.0)

Updates `org.apache.commons:commons-dbcp2` from 2.13.0 to 2.14.0

Updates `commons-io:commons-io` from 2.20.0 to 2.22.0

Updates `org.apache.commons:commons-lang3` from 3.17.0 to 3.20.0

Updates `org.apache.commons:commons-pool2` from 2.12.1 to 2.13.1

Updates `com.google.guava:guava` from 33.4.8-jre to 33.6.0-jre
- [Release notes](https://github.com/google/guava/releases)
- [Commits](https://github.com/google/guava/commits)

Updates `com.google.guava:guava-testlib` from 33.4.8-jre to 33.6.0-jre
- [Release notes](https://github.com/google/guava/releases)
- [Commits](https://github.com/google/guava/commits)

Updates `com.google.guava:guava-testlib` from 33.4.8-jre to 33.6.0-jre
- [Release notes](https://github.com/google/guava/releases)
- [Commits](https://github.com/google/guava/commits)

Updates `com.h2database:h2` from 2.3.232 to 2.4.240
- [Release notes](https://github.com/h2database/h2database/releases)
- [Commits](h2database/h2database@version-2.3.232...version-2.4.240)

Updates `com.google.code.java-allocation-instrumenter:java-allocation-instrumenter` from 3.3.4 to 3.3.5
- [Release notes](https://github.com/google/allocation-instrumenter/releases)
- [Commits](google/allocation-instrumenter@java-allocation-instrumenter-3.3.4...java-allocation-instrumenter-3.3.5)

Updates `org.jctools:jctools-core` from 4.0.5 to 4.0.6
- [Release notes](https://github.com/JCTools/JCTools/releases)
- [Changelog](https://github.com/JCTools/JCTools/blob/master/RELEASE-NOTES.md)
- [Commits](JCTools/JCTools@v4.0.5...v4.0.6)

Updates `org.jmdns:jmdns` from 3.6.1 to 3.6.3
- [Release notes](https://github.com/jmdns/jmdns/releases)
- [Changelog](https://github.com/jmdns/jmdns/blob/main/CHANGELOG.txt)
- [Commits](jmdns/jmdns@3.6.1...v3.6.3)

Updates `net.java.dev.jna:jna` from 5.17.0 to 5.19.1
- [Changelog](https://github.com/java-native-access/jna/blob/master/CHANGES.md)
- [Commits](java-native-access/jna@5.17.0...5.19.1)

Updates `org.apache.maven:maven-core` from 3.9.10 to 3.9.16

Updates `org.apache.maven:maven-model` from 3.9.10 to 3.9.16

Updates `org.apache.maven:maven-model` from 3.9.10 to 3.9.16

Updates `org.openjdk.nashorn:nashorn-core` from 15.6 to 15.7
- [Changelog](https://github.com/openjdk/nashorn/blob/main/CHANGELOG.md)
- [Commits](openjdk/nashorn@release-15.6...release-15.7)

Updates `org.eclipse.platform:org.eclipse.osgi` from 3.23.100 to 3.24.200
- [Commits](https://github.com/eclipse-equinox/equinox/commits)

Updates `org.codehaus.plexus:plexus-utils` from 3.6.0 to 3.6.1
- [Release notes](https://github.com/codehaus-plexus/plexus-utils/releases)
- [Commits](codehaus-plexus/plexus-utils@plexus-utils-3.6.0...plexus-utils-3.6.1)

Updates `org.xmlunit:xmlunit-core` from 2.10.3 to 2.12.0
- [Release notes](https://github.com/xmlunit/xmlunit/releases)
- [Changelog](https://github.com/xmlunit/xmlunit/blob/main/RELEASE_NOTES.md)
- [Commits](xmlunit/xmlunit@v2.10.3...v2.12.0)

Updates `org.xmlunit:xmlunit-matchers` from 2.10.3 to 2.12.0
- [Release notes](https://github.com/xmlunit/xmlunit/releases)
- [Changelog](https://github.com/xmlunit/xmlunit/blob/main/RELEASE_NOTES.md)
- [Commits](xmlunit/xmlunit@v2.10.3...v2.12.0)

Updates `org.xmlunit:xmlunit-matchers` from 2.10.3 to 2.12.0
- [Release notes](https://github.com/xmlunit/xmlunit/releases)
- [Changelog](https://github.com/xmlunit/xmlunit/blob/main/RELEASE_NOTES.md)
- [Commits](xmlunit/xmlunit@v2.10.3...v2.12.0)

Updates `biz.aQute.bnd:biz.aQute.bnd.annotation` from 7.1.0 to 7.3.0
- [Release notes](https://github.com/bndtools/bnd/releases)
- [Commits](bndtools/bnd@7.1.0...7.3.0)

Updates `com.github.spotbugs:spotbugs-annotations` from 4.9.3 to 4.10.3
- [Release notes](https://github.com/spotbugs/spotbugs/releases)
- [Changelog](https://github.com/spotbugs/spotbugs/blob/master/CHANGELOG.md)
- [Commits](spotbugs/spotbugs@4.9.3...4.10.3)

Updates `io.fabric8:docker-maven-plugin` from 0.46.0 to 0.48.1
- [Release notes](https://github.com/fabric8io/docker-maven-plugin/releases)
- [Changelog](https://github.com/fabric8io/docker-maven-plugin/blob/master/doc/changelog.md)
- [Commits](fabric8io/docker-maven-plugin@v0.46.0...v0.48.1)

Updates `org.tukaani:xz` from 1.10 to 1.12
- [Release notes](https://github.com/tukaani-project/xz-java/releases)
- [Changelog](https://github.com/tukaani-project/xz-java/blob/master/NEWS.md)
- [Commits](tukaani-project/xz-java@v1.10...v1.12)

Updates `org.apache.commons:commons-compress` from 1.27.1 to 1.28.0
- [Changelog](https://github.com/apache/commons-compress/blob/master/RELEASE-NOTES.txt)
- [Commits](apache/commons-compress@rel/commons-compress-1.27.1...rel/commons-compress-1.28.0)

Updates `com.google.code.gson:gson` from 2.13.1 to 2.14.0
- [Release notes](https://github.com/google/gson/releases)
- [Changelog](https://github.com/google/gson/blob/main/CHANGELOG.md)
- [Commits](google/gson@gson-parent-2.13.1...gson-parent-2.14.0)

Updates `org.slf4j:slf4j-api` from 2.0.17 to 2.0.18

Updates `org.slf4j:slf4j-nop` from 2.0.17 to 2.0.18

Updates `com.fasterxml.jackson.core:jackson-databind` from 2.20.0 to 2.22.1
- [Commits](https://github.com/FasterXML/jackson/commits)

Updates `com.fasterxml.jackson.dataformat:jackson-dataformat-yaml` from 2.20.0 to 2.22.1
- [Commits](FasterXML/jackson-dataformats-text@jackson-dataformats-text-2.20.0...jackson-dataformats-text-2.22.1)

Updates `org.javassist:javassist` from 3.30.2-GA to 3.32.0-GA
- [Release notes](https://github.com/jboss-javassist/javassist/releases)
- [Changelog](https://github.com/jboss-javassist/javassist/blob/master/Changes.md)
- [Commits](https://github.com/jboss-javassist/javassist/commits)

Updates `co.elastic.clients:elasticsearch-java` from 9.2.0 to 9.4.3
- [Release notes](https://github.com/elastic/elasticsearch-java/releases)
- [Changelog](https://github.com/elastic/elasticsearch-java/blob/main/CHANGELOG.md)
- [Commits](elastic/elasticsearch-java@v9.2.0...v9.4.3)

Updates `org.elasticsearch.client:elasticsearch-rest-client` from 9.2.0 to 9.4.3
- [Release notes](https://github.com/elastic/elasticsearch/releases)
- [Changelog](https://github.com/elastic/elasticsearch/blob/main/docs/changelog.yml)
- [Commits](elastic/elasticsearch@v9.2.0...v9.4.3)

Updates `org.elasticsearch.client:elasticsearch-rest-client` from 9.2.0 to 9.4.3
- [Release notes](https://github.com/elastic/elasticsearch/releases)
- [Changelog](https://github.com/elastic/elasticsearch/blob/main/docs/changelog.yml)
- [Commits](elastic/elasticsearch@v9.2.0...v9.4.3)

Updates `com.fasterxml.jackson.dataformat:jackson-dataformat-yaml` from 2.20.0 to 2.22.1
- [Commits](FasterXML/jackson-dataformats-text@jackson-dataformats-text-2.20.0...jackson-dataformats-text-2.22.1)

Updates `co.elastic.logging:log4j2-ecs-layout` from 1.7.0 to 1.8.0
- [Release notes](https://github.com/elastic/ecs-logging-java/releases)
- [Commits](elastic/ecs-logging-java@v1.7.0...v1.8.0)

Updates `org.mongodb:bson` from 5.5.1 to 5.9.0
- [Release notes](https://github.com/mongodb/mongo-java-driver/releases)
- [Commits](mongodb/mongo-java-driver@r5.5.1...r5.9.0)

Updates `org.mongodb:mongodb-driver-core` from 5.5.1 to 5.9.0
- [Release notes](https://github.com/mongodb/mongo-java-driver/releases)
- [Commits](mongodb/mongo-java-driver@r5.5.1...r5.9.0)

Updates `org.mongodb:mongodb-driver-sync` from 5.5.1 to 5.9.0
- [Release notes](https://github.com/mongodb/mongo-java-driver/releases)
- [Commits](mongodb/mongo-java-driver@r5.5.1...r5.9.0)

Updates `org.mongodb:mongodb-driver-core` from 5.5.1 to 5.9.0
- [Release notes](https://github.com/mongodb/mongo-java-driver/releases)
- [Commits](mongodb/mongo-java-driver@r5.5.1...r5.9.0)

Updates `org.mongodb:mongodb-driver-sync` from 5.5.1 to 5.9.0
- [Release notes](https://github.com/mongodb/mongo-java-driver/releases)
- [Commits](mongodb/mongo-java-driver@r5.5.1...r5.9.0)

Updates `org.slf4j:slf4j-simple` from 2.0.17 to 2.0.18

Updates `ch.qos.logback:logback-classic` from 1.5.18 to 1.5.38
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.5.18...v_1.5.38)

---
updated-dependencies:
- dependency-name: org.apache.logging.log4j:log4j-api
  dependency-version: 2.26.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.apache.logging.log4j:log4j-api-test
  dependency-version: 2.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.apache.logging.log4j:log4j-iostreams
  dependency-version: 2.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.apache.logging.log4j:log4j-jpl
  dependency-version: 2.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.apache.logging.log4j:log4j-slf4j2-impl
  dependency-version: 2.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.apache.logging.log4j:log4j-slf4j-impl
  dependency-version: 2.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.apache.logging.log4j:log4j-to-jul
  dependency-version: 2.26.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.apache.logging.log4j:log4j-to-slf4j
  dependency-version: 2.26.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.apache.logging.log4j:log4j-api-test
  dependency-version: 2.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.apache.logging.log4j:log4j-iostreams
  dependency-version: 2.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.apache.logging.log4j:log4j-jpl
  dependency-version: 2.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.apache.logging.log4j:log4j-slf4j2-impl
  dependency-version: 2.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.apache.logging.log4j:log4j-slf4j-impl
  dependency-version: 2.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.apache.logging.log4j:log4j-to-jul
  dependency-version: 2.26.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.apache.logging.log4j:log4j-to-slf4j
  dependency-version: 2.26.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.apache.commons:commons-csv
  dependency-version: 1.14.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-updates
- dependency-name: commons-logging:commons-logging
  dependency-version: 1.4.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: ch.qos.logback:logback-core
  dependency-version: 1.5.38
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-updates
- dependency-name: org.slf4j:slf4j-api
  dependency-version: 2.0.18
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-updates
- dependency-name: tools.jackson:jackson-bom
  dependency-version: 3.2.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.mockito:mockito-bom
  dependency-version: 5.23.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.assertj:assertj-core
  dependency-version: 3.27.7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-updates
- dependency-name: net.bytebuddy:byte-buddy
  dependency-version: 1.18.11
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: commons-codec:commons-codec
  dependency-version: 1.22.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.apache.commons:commons-dbcp2
  dependency-version: 2.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: commons-io:commons-io
  dependency-version: 2.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.apache.commons:commons-lang3
  dependency-version: 3.20.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.apache.commons:commons-pool2
  dependency-version: 2.13.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: com.google.guava:guava
  dependency-version: 33.6.0-jre
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: com.google.guava:guava-testlib
  dependency-version: 33.6.0-jre
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: com.google.guava:guava-testlib
  dependency-version: 33.6.0-jre
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: com.h2database:h2
  dependency-version: 2.4.240
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: com.google.code.java-allocation-instrumenter:java-allocation-instrumenter
  dependency-version: 3.3.5
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-updates
- dependency-name: org.jctools:jctools-core
  dependency-version: 4.0.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-updates
- dependency-name: org.jmdns:jmdns
  dependency-version: 3.6.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven-minor-updates
- dependency-name: net.java.dev.jna:jna
  dependency-version: 5.19.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.apache.maven:maven-core
  dependency-version: 3.9.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-updates
- dependency-name: org.apache.maven:maven-model
  dependency-version: 3.9.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-updates
- dependency-name: org.apache.maven:maven-model
  dependency-version: 3.9.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-updates
- dependency-name: org.openjdk.nashorn:nashorn-core
  dependency-version: '15.7'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.eclipse.platform:org.eclipse.osgi
  dependency-version: 3.24.200
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.codehaus.plexus:plexus-utils
  dependency-version: 3.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-updates
- dependency-name: org.xmlunit:xmlunit-core
  dependency-version: 2.12.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.xmlunit:xmlunit-matchers
  dependency-version: 2.12.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.xmlunit:xmlunit-matchers
  dependency-version: 2.12.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: biz.aQute.bnd:biz.aQute.bnd.annotation
  dependency-version: 7.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: com.github.spotbugs:spotbugs-annotations
  dependency-version: 4.10.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: io.fabric8:docker-maven-plugin
  dependency-version: 0.48.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.tukaani:xz
  dependency-version: '1.12'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.apache.commons:commons-compress
  dependency-version: 1.28.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: com.google.code.gson:gson
  dependency-version: 2.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.slf4j:slf4j-api
  dependency-version: 2.0.18
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-updates
- dependency-name: org.slf4j:slf4j-nop
  dependency-version: 2.0.18
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-updates
- dependency-name: com.fasterxml.jackson.core:jackson-databind
  dependency-version: 2.22.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: com.fasterxml.jackson.dataformat:jackson-dataformat-yaml
  dependency-version: 2.22.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.javassist:javassist
  dependency-version: 3.32.0-GA
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: co.elastic.clients:elasticsearch-java
  dependency-version: 9.4.3
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.elasticsearch.client:elasticsearch-rest-client
  dependency-version: 9.4.3
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.elasticsearch.client:elasticsearch-rest-client
  dependency-version: 9.4.3
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: com.fasterxml.jackson.dataformat:jackson-dataformat-yaml
  dependency-version: 2.22.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: co.elastic.logging:log4j2-ecs-layout
  dependency-version: 1.8.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.mongodb:bson
  dependency-version: 5.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.mongodb:mongodb-driver-core
  dependency-version: 5.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.mongodb:mongodb-driver-sync
  dependency-version: 5.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.mongodb:mongodb-driver-core
  dependency-version: 5.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.mongodb:mongodb-driver-sync
  dependency-version: 5.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-updates
- dependency-name: org.slf4j:slf4j-simple
  dependency-version: 2.0.18
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-updates
- dependency-name: ch.qos.logback:logback-classic
  dependency-version: 1.5.38
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven-minor-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Related to third party dependency updates or migrations java Pull requests that update Java code labels Jul 24, 2026
@ramanathan1504

Copy link
Copy Markdown
Contributor

Fix #4007

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Related to third party dependency updates or migrations java Pull requests that update Java code

Projects

Development

Successfully merging this pull request may close these issues.

1 participant