Skip to content

Bump the maven group across 15 directories with 17 updates - #3

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/v2/googlecloud-to-googlecloud/maven-5f9e0741d4
Open

Bump the maven group across 15 directories with 17 updates#3
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/v2/googlecloud-to-googlecloud/maven-5f9e0741d4

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 7, 2026

Copy link
Copy Markdown

Bumps the maven group with 2 updates in the /v2/googlecloud-to-googlecloud directory: org.apache.hadoop:hadoop-common and org.apache.derby:derby.
Bumps the maven group with 8 updates in the /v1 directory:

Package From To
org.apache.hadoop:hadoop-common 2.8.5 3.4.0
org.apache.derby:derby 10.14.2.0 10.17.1.0
org.json:json 20200518 20231013
commons-io:commons-io 2.4 2.14.0
org.apache.kafka:kafka-clients 1.0.0 3.9.2
org.springframework:spring-expression 5.2.8.RELEASE 5.3.39
junit:junit 4.13 4.13.1
com.puppycrawl.tools:checkstyle 8.7 8.29

Bumps the maven group with 1 update in the /v2/streaming-data-generator directory: org.yaml:snakeyaml.
Bumps the maven group with 13 updates in the /v2 directory:

Package From To
org.apache.hadoop:hadoop-common 2.8.5 3.4.0
org.apache.derby:derby 10.14.2.0 10.17.1.0
org.json:json 20160810 20231013
org.apache.kafka:kafka-clients 2.3.0 3.9.2
junit:junit 4.13 4.13.1
com.puppycrawl.tools:checkstyle 8.7 8.29
org.yaml:snakeyaml 1.23 2.0
org.apache.avro:avro 1.8.2 1.11.4
io.grpc:grpc-netty-shaded 1.45.1 1.75.0
com.google.guava:guava 25.1-jre 32.0.0-jre
org.apache.commons:commons-configuration2 2.5 2.15.0
commons-beanutils:commons-beanutils 1.9.3 1.11.0
org.postgresql:postgresql 42.2.2 42.7.11

Bumps the maven group with 1 update in the /v2/kafka-common directory: org.apache.kafka:kafka-clients.
Bumps the maven group with 1 update in the /v2/datastream-to-sql directory: org.postgresql:postgresql.
Bumps the maven group with 1 update in the /v2/datastream-to-spanner directory: org.json:json.
Bumps the maven group with 1 update in the /v2/datastream-to-postgres directory: org.postgresql:postgresql.
Bumps the maven group with 1 update in the /v2/common directory: org.apache.avro:avro.
Bumps the maven group with 4 updates in the /v2/cdc-parent directory: io.grpc:grpc-netty-shaded, com.google.guava:guava, org.apache.commons:commons-configuration2 and commons-beanutils:commons-beanutils.
Bumps the maven group with 2 updates in the /v2/cdc-parent/cdc-embedded-connector directory: org.apache.commons:commons-configuration2 and commons-beanutils:commons-beanutils.
Bumps the maven group with 2 updates in the /syndeo-template directory: org.apache.kafka:kafka-clients and com.google.protobuf:protobuf-java.
Bumps the maven group with 2 updates in the /structured-logging directory: com.puppycrawl.tools:checkstyle and ch.qos.logback:logback-classic.
Bumps the maven group with 17 updates in the / directory:

Package From To
org.apache.hadoop:hadoop-common 2.8.5 3.4.0
org.apache.derby:derby 10.14.2.0 10.17.1.0
org.json:json 20160810 20231013
commons-io:commons-io 2.4 2.14.0
org.apache.kafka:kafka-clients 1.0.0 3.9.2
org.springframework:spring-expression 5.2.8.RELEASE 5.3.39
junit:junit 4.13 4.13.1
com.puppycrawl.tools:checkstyle 8.7 8.29
org.yaml:snakeyaml 1.23 2.0
org.apache.avro:avro 1.8.2 1.11.4
io.grpc:grpc-netty-shaded 1.45.1 1.75.0
com.google.guava:guava 25.1-jre 32.0.0-jre
org.apache.commons:commons-configuration2 2.5 2.15.0
commons-beanutils:commons-beanutils 1.9.3 1.11.0
org.postgresql:postgresql 42.2.2 42.7.11
com.google.protobuf:protobuf-java 3.21.5 3.25.5
ch.qos.logback:logback-classic 1.2.10 1.2.13

Bumps the maven group with 2 updates in the /it directory: com.puppycrawl.tools:checkstyle and com.google.guava:guava.

Updates org.apache.hadoop:hadoop-common from 2.8.5 to 3.4.0

Updates org.apache.derby:derby from 10.14.2.0 to 10.17.1.0

Updates org.apache.hadoop:hadoop-common from 2.8.5 to 3.4.0

Updates org.apache.derby:derby from 10.14.2.0 to 10.17.1.0

Updates org.json:json from 20200518 to 20231013

Release notes

Sourced from org.json:json's releases.

20231013

Pull Request Description
#793 Reverted #761
#792 update the docs for release 20231013
#783 optLong vs getLong inconsistencies
#782 Fix XMLTest.testIndentComplicatedJsonObjectWithArrayAndWithConfig() for Windows
#779 add validity check for JSONObject constructors
#778 Fix XMLTest.testIndentComplicatedJsonObjectWithArrayAndWithConfig() for Windows
#776 Update [JUnit to version 4.13.2
#774 Removing unneeded synchronization
#773 Add optJSONArray method to JSONObject with a default value
#772 Disallow nested objects and arrays as keys in objects
#779 Unit test cleanup
#769 Addressed Java 17 compile warnings
#764 Update CodeQL action version
#761 Add module-info
#759 JSON parsing should detect embedded 
#753 Updated new object methods
#752 Fixes possible unit test bug when compiling/testing on Windows

20230618

Pull Request Description
#749 Prep for release 20230618
#740 Fixed Flaky Tests Caused by JSON permutations
#734 Fixed Flaky Tests Caused by JSON permutations
#733 JSONTokener implemented java.io.Closeable
#731 Removing commented out code in JSONObject optDouble()
#729 Refactor ParserConfiguration class hierarchy

20230227

Pull Request Description
#723 Protect JSONML from stack overflow exceptions caused by recursion
#720 Limit the XML nesting depth for CVE-2022-45688
#711 Revert pull 707 - interviewbit spam
#704 Move javadoc comments above the interface definition to make it visible
#703 Update Releases.md for JSONObject(Map): Throws NPE if key is null
#696 Update JSONPointerTest for NonDex compatibility
#694 Pretty print XML
#692 Example.md syntax highlight and indentation
#691 Create unit tests for various number formats

20220924

Pull Request Description
#688 Update copyright to Public Domain
#687 Fix a typo
#685 JSONObject map type unit tests

... (truncated)

Changelog

Sourced from org.json:json's changelog.

20231013 First release with minimum Java version 1.8. Recent commits, including fixes for CVE-2023-5072.

20230618 Final release with Java 1.6 compatibility. Future releases will require Java 1.8 or greater.

20230227 Fix for CVE-2022-45688 and recent commits

20220924 New License - public domain, and some minor updates

20220320 Wrap StackOverflow with JSONException

20211205 Recent commits and some bug fixes for similar()

20210307 Recent commits and potentially breaking fix to JSONPointer

20201115 Recent commits and first release after project structure change

Commits

Updates commons-io:commons-io from 2.4 to 2.14.0

Updates org.apache.kafka:kafka-clients from 1.0.0 to 3.9.2

Updates org.springframework:spring-expression from 5.2.8.RELEASE to 5.3.39

Release notes

Sourced from org.springframework:spring-expression's releases.

v5.3.39

⭐ New Features

  • SimpleEvaluationContext should disable array allocation #33386

v5.3.38

⭐ New Features

  • Efficient handling of conditional HTTP requests #33378

🐞 Bug Fixes

  • Fix incorrect weak ETag validation #33377
  • SimpleEvaluationContext does not enforce read-only semantics #33320
  • ConversionService cannot convert primitive array to Object[] #33314
  • SpEL Indexer silently ignores failure to set property as index #33312
  • Mockito mock falsely initialized as CGLIB proxy with AspectJ aspect #33142
  • "file:." cannot be resolved to java.nio.file.Path (and plain "." value resolves to classpath root) #33140

📔 Documentation

  • Typo in Annotation-driven Listener Endpoints section of Spring Framework documentation #33052
  • Container Extension Points section of Spring Framework documentation refers to the wrong property name #33039
  • Incorrect constructor details in the javadoc for ApplicationContextEvent #33034

🔨 Dependency Upgrades

  • Upgrade to Reactor 2020.0.47 #33322

v5.3.37

⭐ New Features

  • AnnotationUtils performance degrades with deep stacks #32923

🐞 Bug Fixes

  • AspectJ CTW aspects executed twice #32974
  • SpEL compilation fails when indexing into a Map with a primitive #32911
  • SpEL compilation fails when indexing into an array or list with an Integer #32909
  • Application not starting with @EnableTransactionManagement(mode = AdviceMode.ASPECTJ) #32885

🔨 Dependency Upgrades

  • Upgrade to Reactor 2020.0.45 #33010

v5.3.36

🐞 Bug Fixes

  • Overridden aspect method runs twice #32868
  • @DateTimeFormat(iso = DateTimeFormat.ISO.DATE\_TIME) cannot convert UTC without milliseconds to java.util.Date #32860

... (truncated)

Commits
  • f1b128b Release v5.3.39
  • 8a44eaa Next development version (v5.3.39-SNAPSHOT)
  • f44d13c Disable array allocation in case of no constructor resolution
  • f00bc7b Remove snapshot repo
  • 582bfcc Efficient ETag parsing
  • 406b33d Upgrade to Netty 4.1.112
  • f9c3d00 Introduce withAssignmentDisabled() option for SimpleEvaluationContext
  • d2715d2 Fix incorrect weak ETag assertion
  • 57b02da Upgrade to Reactor 2020.0.47
  • df33bf2 Sync GHA setup
  • Additional commits viewable in compare view

Updates junit:junit from 4.13 to 4.13.1

Release notes

Sourced from junit:junit's releases.

JUnit 4.13.1

Please refer to the release notes for details.

Changelog

Sourced from junit:junit's changelog.

Summary of changes in version 4.13.1

Rules

Security fix: TemporaryFolder now limits access to temporary folders on Java 1.7 or later

A local information disclosure vulnerability in TemporaryFolder has been fixed. See the published security advisory for details.

Test Runners

[Pull request #1669:](junit-team/junit#1669) Make FrameworkField constructor public

Prior to this change, custom runners could make FrameworkMethod instances, but not FrameworkField instances. This small change allows for both now, because FrameworkField's constructor has been promoted from package-private to public.

Commits

Updates com.puppycrawl.tools:checkstyle from 8.7 to 8.29

Commits
  • 8933d03 [maven-release-plugin] prepare release checkstyle-8.29
  • bd45909 Issue #7487: refactor code to use DetailAST.hasChildren()
  • 317e51f Issue #7487: add method hasChildren() to DetailAST
  • 89b4dcd Issue #3238: Java 8 Grammar: annotations on arrays and varargs
  • 252cd89 dependency: bump junit-pioneer from 0.5.1 to 0.5.2
  • 2ee2615 dependency: bump junit.version from 5.5.2 to 5.6.0
  • 4ed7cb8 minor: add space before xml comment end '-->' to ease reading and make links ...
  • c46a16d Issue #7468: disable 'external-parameter-entities' feature by default
  • dfed794 minor: add missing test case to SuperCloneCheckTest
  • 24e7bdf dependency: bump antlr4.version from 4.7.2 to 4.8-1
  • Additional commits viewable in compare view

Updates org.yaml:snakeyaml from 1.23 to 2.0

Commits
  • c98ffba issue 561: add negative test case
  • e2ca740 Use Maven wrapper on github
  • 49d91a1 Fix target for github
  • 19e331d Disable toolchain for github
  • 42c7812 Cobertura plugin does not work
  • 03c82b5 Rename GlobalTagRejectionTest to be run by Maven
  • 6e8cd89 Remove cobertura
  • d9b0f48 Improve Javadoc
  • 519791a Run install and site goals under docker
  • 82f33d2 Merge branch 'master' into add-module-info
  • Additional commits viewable in compare view

Updates org.apache.hadoop:hadoop-common from 2.8.5 to 3.4.0

Updates org.apache.derby:derby from 10.14.2.0 to 10.17.1.0

Updates org.json:json from 20160810 to 20231013

Release notes

Sourced from org.json:json's releases.

20231013

Pull Request Description
#793 Reverted #761
#792 update the docs for release 20231013
#783 optLong vs getLong inconsistencies
#782 Fix XMLTest.testIndentComplicatedJsonObjectWithArrayAndWithConfig() for Windows
#779 add validity check for JSONObject constructors
#778 Fix XMLTest.testIndentComplicatedJsonObjectWithArrayAndWithConfig() for Windows
#776 Update [JUnit to version 4.13.2
#774 Removing unneeded synchronization
#773 Add optJSONArray method to JSONObject with a default value
#772 Disallow nested objects and arrays as keys in objects
#779 Unit test cleanup
#769 Addressed Java 17 compile warnings
#764 Update CodeQL action version
#761 Add module-info
#759 JSON parsing should detect embedded 
#753 Updated new object methods
#752 Fixes possible unit test bug when compiling/testing on Windows

20230618

Pull Request Description
#749 Prep for release 20230618
#740 Fixed Flaky Tests Caused by JSON permutations
#734 Fixed Flaky Tests Caused by JSON permutations
#733 JSONTokener implemented java.io.Closeable
#731 Removing commented out code in JSONObject optDouble()
#729 Refactor ParserConfiguration class hierarchy

20230227

Pull Request Description
#723 Protect JSONML from stack overflow exceptions caused by recursion
#720 Limit the XML nesting depth for CVE-2022-45688
#711 Revert pull 707 - interviewbit spam
#704 Move javadoc comments above the interface definition to make it visible
#703 Update Releases.md for JSONObject(Map): Throws NPE if key is null
#696 Update JSONPointerTest for NonDex compatibility
#694 Pretty print XML
#692 Example.md syntax highlight and indentation
#691 Create unit tests for various number formats

20220924

Pull Request Description
#688 Update copyright to Public Domain
#687 Fix a typo
#685 JSONObject map type unit tests

... (truncated)

Changelog

Sourced from org.json:json's changelog.

20231013 First release with minimum Java version 1.8. Recent commits, including fixes for CVE-2023-5072.

20230618 Final release with Java 1.6 compatibility. Future releases will require Java 1.8 or greater.

20230227 Fix for CVE-2022-45688 and recent commits

20220924 New License - public domain, and some minor updates

20220320 Wrap StackOverflow with JSONException

20211205 Recent commits and some bug fixes for similar()

20210307 Recent commits and potentially breaking fix to JSONPointer

20201115 Recent commits and first release after project structure change

Commits

Updates org.apache.kafka:kafka-clients from 2.3.0 to 3.9.2

Updates junit:junit from 4.13 to 4.13.1

Release notes

Sourced from junit:junit's releases.

JUnit 4.13.1

Please refer to the release notes for details.

Changelog

Sourced from junit:junit's changelog.

Summary of changes in version 4.13.1

Rules

Security fix: TemporaryFolder now limits access to temporary folders on Java 1.7 or later

A local information disclosure vulnerability in TemporaryFolder has been fixed. See the published security advisory for details.

Test Runners

[Pull request #1669:](junit-team/junit#1669) Make FrameworkField constructor public

Prior to this change, custom runners could make FrameworkMethod instances, but not FrameworkField instances. This small change allows for both now, because FrameworkField's constructor has been promoted from package-private to public.

Commits

Updates com.puppycrawl.tools:checkstyle from 8.7 to 8.29

Commits
  • 8933d03 [maven-release-plugin] prepare release checkstyle-8.29
  • bd45909 Issue #7487: refactor code to use DetailAST.hasChildren()
  • 317e51f Issue #7487: add method hasChildren() to DetailAST
  • 89b4dcd Issue #3238: Java 8 Grammar: annotations on arrays and varargs
  • 252cd89 dependency: bump junit-pioneer from 0.5.1 to 0.5.2
  • 2ee2615 dependency: bump junit.version from 5.5.2 to 5.6.0
  • 4ed7cb8 minor: add space before xml comment end '-->' to ease reading and make links ...
  • c46a16d Issue #7468: disable 'external-parameter-entities' feature by default
  • dfed794 minor: add missing test case to SuperCloneCheckTest
  • 24e7bdf dependency: bump antlr4.version from 4.7.2 to 4.8-1
  • Additional commits viewable in compare view

Updates org.yaml:snakeyaml from 1.23 to 2.0

Commits
  • c98ffba issue 561: add negative test case
  • e2ca740 Use Maven wrapper on github
  • 49d91a1 Fix target for github
  • 19e331d Disable toolchain for github
  • 42c7812 Cobertura plugin does not work
  • 03c82b5 Rename GlobalTagRejectionTest to be run by Maven
  • 6e8cd89 Remove cobertura
  • d9b0f48 Improve Javadoc
  • 519791a Run install and site goals under docker
  • 82f33d2 Merge branch 'master' into add-module-info
  • Additional commits viewable in compare view

Updates org.apache.avro:avro from 1.8.2 to 1.11.4

Updates io.grpc:grpc-netty-shaded from 1.45.1 to 1.75.0

Release notes

Sourced from io.grpc:grpc-netty-shaded's releases.

v1.75.0

Behavior Changes

  • binder: Introduce server pre-authorization (#12127). grpc-binder clients authorize servers by checking the UID of the sender of the SETUP_TRANSPORT Binder transaction against some SecurityPolicy. But merely binding to an unauthorized server to learn its UID can enable "keep-alive" and "background activity launch" abuse, even if security policy ultimately causes the grpc connection to fail. Pre-authorization mitigates this kind of abuse by resolving addresses and authorizing a candidate server Application's UID before binding to it. Pre-auth is especially important when the server's address is not fixed in advance but discovered by PackageManager lookup.

Bug Fixes

  • core: grpc-timeout should always be positive (#12201) (6dfa03c51). There is a local race between when the deadline is checked before sending the RPC and when the timeout is calculated to put on-the-wire. The code replaced negative timeouts with 0 nanoseconds. gRPC’s PROTOCOL-HTTP2 spec states that timeouts should be positive, so now non-positive values are replaced with 1 nanosecond
  • core: Improved DEADLINE_EXCEEDED message for delayed calls (6ff8ecac0). Delayed calls are the first calls on a Channel before name resolution has resolved addresses. Previously you could see confusing errors saying the deadline “will be exceeded in” X time. The message tense was simply wrong, and now will be correct: deadline “was exceeded after” X time.
  • xds: PriorityLB now only uses the failOverTimer to start additional priorities, not fail RPCs (c4256add4). You should no longer see “Connection timeout for priority” errors.

Improvements

  • netty: Count sent RST_STREAMs against NettyServerBuilder.maxRstFramesPerWindow() limit (#12288). This extends the Rapid Reset tool to also cover MadeYouReset. the reset stream count will cause a 420 "Enhance your calm response" to be sent. This depends on Netty 4.1.124 for a bug fix to actually call the encoder by the frame writer.
  • xds: Convert CdsLb to XdsDepManager (297ab05ef). This is part of gRFC A74 to have atomic xDS config updates. This is an internal change, but does change the error description seen in certain cases, especially DEADLINE_EXCEEDED on a brand-new channel.
  • census: APIs for stats and tracing (#12050) (919370172). Client channel and server builders with interceptors and factories respectively for stats and tracing.
  • stub: simplify BlockingClientCall infinite blocking (#12217) (ba0a7329d). Move deadline computation into overloads with finite timeouts. Blocking calls without timeouts now do not have to read the clock.
  • xds: Do RLS fallback policy eagar start (#12211) (42e1829b3). In gRPC-Java, the xDS clusters were lazily subscribed, which meant the fallback target which is returned in the RLS config wasn’t subscribed until a RPC actually falls back to it. The delayed resource subscription process in gRPC Java made it more susceptible to the effects of the INITIAL_RESOURCE_FETCH_TIMEOUT compared to other programming languages. It also had impact beyond the RLS cache expiration case, for example, when the first time the client initialized the channel, we couldn't fallback when the intended target times out, because of the lazy subscription. This change starts the fallback LB policy for the default target at the start of RLS policy instead of only when falling back to the default target, which fixes the above mentioned problems.
  • xds: Aggregate cluster fixes (A75) (#12186) (7e982e48a). The earlier implementation of aggregate clusters concatenated the priorities from the underlying clusters into a single list, so that it could use a single LB policy defined at the aggregate cluster layer to choose a priority from that combined list. However, it turns out that aggregate clusters don't actually define the LB policy in the aggregate cluster; instead, the aggregate cluster uses a special cluster-provided LB policy that first chooses the underlying cluster and then delegates to the LB policy of the underlying cluster. This change implements that.
  • api: set size correctly for sets and maps in handling Metadata values to be exchanged during a call (#12229) (80217275d)
  • xds: xdsClient cache transient error for new watchers (#12291). When a resource update is NACKed, cache the error and update new watchers that get added with that error instead of making them hang.
  • xds: Avoid PriorityLb re-enabling timer on duplicate CONNECTING (#12289). If a LB policy gives extraneous updates with state CONNECTING, then it was possible to re-create failOverTimer which would then wait the 10 seconds for the child to finish CONNECTING. We only want to give the child one opportunity after transitioning out of READY/IDLE.
  • xds: Use a different log name for XdsClientImpl and ControlPlaneClient (#12287). ControlPlaneClient uses "xds-cp-client" now instead of "xds-client" while logging.

Dependencies Changes

  • Upgrade to Netty 4.1.124.Final (#12286). This implicitly disables NettyAdaptiveCumulator (#11284), which can have a performance impact. We delayed upgrading Netty to give time to rework the optimization, but we've gone too long already without upgrading which causes problems for vulnerability tracking.
  • bazel: Use jar_jar to avoid xds deps (#12243) (8f09b9689). The //xds and //xds:orca targets now use jar_jar to shade the protobuf generated code. This allows them to use their own private copy of the protos and drop direct Bazel dependencies on cel-spec, grpc, rules_go, com_github_cncf_xds, envoy_api, com_envoyproxy_protoc_gen_validate, and opencensus_proto. This mirrors the shading of protobuf messages done for grpc-xds provided on Maven Central and should simplify dependency management
  • Protobuf upgraded to 3.25.8
  • proto-google-common-protos upgraded to 2.59.2
  • s2a-proto upgraded to 1.1.2
  • google-cloud-logging upgraded to 3.23.1 (used by gcp-observability)
  • OpenTelemetry upgraded to 1.52.0

Documentation

  • Clarify requirements for creating a cross-user Channel. (#12181). The @SystemApi runtime visibility requirement isn't really new. It has always been implicit in the required INTERACT_ACROSS_USERS permission, which can only be held by system apps in production. Now deprecated BinderChannelBuilder#bindAsUser has always required SDK_INT >= 30. This change just copies that requirement forward to its replacement APIs in AndroidComponentAddress and the TARGET_ANDROID_USER NameResolver.Args.
  • api: Add more Javadoc for NameResolver.Listener2 interface (#12220) (d352540a0)

Thanks to

@​benjaminp @​werkt @​kilink @​vimanikag

v1.74.0

Behavior Changes

  • compiler: Default to @generated=omit (f8700a13a). This omits javax.annotation.Generated from the generated code and makes the org.apache.tomcat:annotations-api compile-only dependency unnecessary (README and examples changes forthcoming; we delayed those changes until the release landed). You can use the option @generated=javax for the previous behavior, but please also file an issue so we can develop alternatives
  • compiler: generate blocking v2 unary calls that throw StatusException (#12126) (a16d65591). Previously, the new blocking stub API was identical to the older blocking stub for unary RPCs and used the unchecked StatusRuntimeException. However, feedback demonstrated it was confusing to mix that with the checked StatusException in BlockingClientCall. Now the new blocking stub uses StatusException throughout. grpc-java continues to support the old generated code, but the version of protoc-gen-grpc-java will dictate which API you see. If you support multiple generated code versions, you can use the older blocking v1 stub for unary RPCs

Bug Fixes

  • netty: Fix a race that caused RPCs to hang on start when a GOAWAY was received while the RPCs’ headers were being written to the OS (b04c673fd, 15c757398). This was a very old race, not a recent regression. All streams should now properly fail instead of hanging, although in some cases they may be transparently retried

... (truncated)

Commits
  • 3abc0e6 Bump version to 1.75.0
  • cbfe6c1 Update README etc to reference 1.75.0
  • a0f3520 Revert "Release v1.75.0 (#12294)" (#12295)
  • 7ef13f4 Release v1.75.0 (#12294)
  • 14fd8ef xds: xdsClient caches transient error for new watchers (v1.75.x backport) (#1...
  • 653d076 xds: Avoid PriorityLb re-enabling timer on duplicate CONNECTING (#12289)
  • a5c2b1a netty: Count sent RST_STREAMs against limit (1.75.x backport) (#12288)
  • 0d3e828 xds: Use a different log name for XdsClientImpl and ControlPlaneClient (1.75....
  • d750e9d Upgrade to Netty 4.1.124.Final (v1.75.x backport) (#12286)
  • 19c579e Bump versions of dependencies (#12252)
  • Additional commits viewable in compare view

Updates com.google.guava:guava from 25.1-jre to 32.0.0-jre

Release notes

Sourced from com.google.guava:guava's releases.

32.0.0

Maven

<dependency>
  <groupId>com.google.guava</groupId>
  <artifactId>guava</artifactId>
  <version>32.0.0-jre</version>
  <!-- or, for Android: -->
  <version>32.0.0-android</version>
</dependency>

Jar files

Guava requires one runtime dependency, which you can download here:

Javadoc

JDiff

Changelog

Security fixes

While CVE-2020-8908 was officially closed when we deprecated Files.createTempDir in Guava 30.0, we've heard from users that even recent versions of Guava have been listed as vulnerable in other databases of security vulnerabilities. In response, we've reimplemented the method (and the very rarely used FileBackedOutputStream class, which had a similar issue) to eliminate the insecure behavior entirely. This change could technically affect users in a number of different ways (discussed under "Incompatible changes" below), but in practice, the only problem users are likely to encounter is with Windows. If you are using those APIs under Windows, you should skip 32.0.0 and go straight to 32.0.1 which fixes the problem. (Unfortunately, we didn't think of the Windows problem until after the release. And while we warn that common.io in particular may not work under Windows, we didn't intend to regress support.) Sorry for the trouble.

Incompatible changes

Although this release bumps Guava's major version number, it makes no binary-incompatible changes to the guava artifact.

One change could cause issues for Widows users, and a few other changes could cause issues for users in more usual situations:

  • The new implementations of Files.createTempDir and FileBackedOutputStream

Bumps the maven group with 2 updates in the /v2/googlecloud-to-googlecloud directory: org.apache.hadoop:hadoop-common and org.apache.derby:derby.
Bumps the maven group with 8 updates in the /v1 directory:

| Package | From | To |
| --- | --- | --- |
| org.apache.hadoop:hadoop-common | `2.8.5` | `3.4.0` |
| org.apache.derby:derby | `10.14.2.0` | `10.17.1.0` |
| [org.json:json](https://github.com/douglascrockford/JSON-java) | `20200518` | `20231013` |
| commons-io:commons-io | `2.4` | `2.14.0` |
| org.apache.kafka:kafka-clients | `1.0.0` | `3.9.2` |
| [org.springframework:spring-expression](https://github.com/spring-projects/spring-framework) | `5.2.8.RELEASE` | `5.3.39` |
| [junit:junit](https://github.com/junit-team/junit4) | `4.13` | `4.13.1` |
| [com.puppycrawl.tools:checkstyle](https://github.com/checkstyle/checkstyle) | `8.7` | `8.29` |

Bumps the maven group with 1 update in the /v2/streaming-data-generator directory: [org.yaml:snakeyaml](https://bitbucket.org/snakeyaml/snakeyaml).
Bumps the maven group with 13 updates in the /v2 directory:

| Package | From | To |
| --- | --- | --- |
| org.apache.hadoop:hadoop-common | `2.8.5` | `3.4.0` |
| org.apache.derby:derby | `10.14.2.0` | `10.17.1.0` |
| [org.json:json](https://github.com/douglascrockford/JSON-java) | `20160810` | `20231013` |
| org.apache.kafka:kafka-clients | `2.3.0` | `3.9.2` |
| [junit:junit](https://github.com/junit-team/junit4) | `4.13` | `4.13.1` |
| [com.puppycrawl.tools:checkstyle](https://github.com/checkstyle/checkstyle) | `8.7` | `8.29` |
| [org.yaml:snakeyaml](https://bitbucket.org/snakeyaml/snakeyaml) | `1.23` | `2.0` |
| org.apache.avro:avro | `1.8.2` | `1.11.4` |
| [io.grpc:grpc-netty-shaded](https://github.com/grpc/grpc-java) | `1.45.1` | `1.75.0` |
| [com.google.guava:guava](https://github.com/google/guava) | `25.1-jre` | `32.0.0-jre` |
| org.apache.commons:commons-configuration2 | `2.5` | `2.15.0` |
| commons-beanutils:commons-beanutils | `1.9.3` | `1.11.0` |
| [org.postgresql:postgresql](https://github.com/pgjdbc/pgjdbc) | `42.2.2` | `42.7.11` |

Bumps the maven group with 1 update in the /v2/kafka-common directory: org.apache.kafka:kafka-clients.
Bumps the maven group with 1 update in the /v2/datastream-to-sql directory: [org.postgresql:postgresql](https://github.com/pgjdbc/pgjdbc).
Bumps the maven group with 1 update in the /v2/datastream-to-spanner directory: [org.json:json](https://github.com/douglascrockford/JSON-java).
Bumps the maven group with 1 update in the /v2/datastream-to-postgres directory: [org.postgresql:postgresql](https://github.com/pgjdbc/pgjdbc).
Bumps the maven group with 1 update in the /v2/common directory: org.apache.avro:avro.
Bumps the maven group with 4 updates in the /v2/cdc-parent directory: [io.grpc:grpc-netty-shaded](https://github.com/grpc/grpc-java), [com.google.guava:guava](https://github.com/google/guava), org.apache.commons:commons-configuration2 and commons-beanutils:commons-beanutils.
Bumps the maven group with 2 updates in the /v2/cdc-parent/cdc-embedded-connector directory: org.apache.commons:commons-configuration2 and commons-beanutils:commons-beanutils.
Bumps the maven group with 2 updates in the /syndeo-template directory: org.apache.kafka:kafka-clients and [com.google.protobuf:protobuf-java](https://github.com/protocolbuffers/protobuf).
Bumps the maven group with 2 updates in the /structured-logging directory: [com.puppycrawl.tools:checkstyle](https://github.com/checkstyle/checkstyle) and [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback).
Bumps the maven group with 17 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| org.apache.hadoop:hadoop-common | `2.8.5` | `3.4.0` |
| org.apache.derby:derby | `10.14.2.0` | `10.17.1.0` |
| [org.json:json](https://github.com/douglascrockford/JSON-java) | `20160810` | `20231013` |
| commons-io:commons-io | `2.4` | `2.14.0` |
| org.apache.kafka:kafka-clients | `1.0.0` | `3.9.2` |
| [org.springframework:spring-expression](https://github.com/spring-projects/spring-framework) | `5.2.8.RELEASE` | `5.3.39` |
| [junit:junit](https://github.com/junit-team/junit4) | `4.13` | `4.13.1` |
| [com.puppycrawl.tools:checkstyle](https://github.com/checkstyle/checkstyle) | `8.7` | `8.29` |
| [org.yaml:snakeyaml](https://bitbucket.org/snakeyaml/snakeyaml) | `1.23` | `2.0` |
| org.apache.avro:avro | `1.8.2` | `1.11.4` |
| [io.grpc:grpc-netty-shaded](https://github.com/grpc/grpc-java) | `1.45.1` | `1.75.0` |
| [com.google.guava:guava](https://github.com/google/guava) | `25.1-jre` | `32.0.0-jre` |
| org.apache.commons:commons-configuration2 | `2.5` | `2.15.0` |
| commons-beanutils:commons-beanutils | `1.9.3` | `1.11.0` |
| [org.postgresql:postgresql](https://github.com/pgjdbc/pgjdbc) | `42.2.2` | `42.7.11` |
| [com.google.protobuf:protobuf-java](https://github.com/protocolbuffers/protobuf) | `3.21.5` | `3.25.5` |
| [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) | `1.2.10` | `1.2.13` |

Bumps the maven group with 2 updates in the /it directory: [com.puppycrawl.tools:checkstyle](https://github.com/checkstyle/checkstyle) and [com.google.guava:guava](https://github.com/google/guava).


Updates `org.apache.hadoop:hadoop-common` from 2.8.5 to 3.4.0

Updates `org.apache.derby:derby` from 10.14.2.0 to 10.17.1.0

Updates `org.apache.hadoop:hadoop-common` from 2.8.5 to 3.4.0

Updates `org.apache.derby:derby` from 10.14.2.0 to 10.17.1.0

Updates `org.json:json` from 20200518 to 20231013
- [Release notes](https://github.com/douglascrockford/JSON-java/releases)
- [Changelog](https://github.com/stleary/JSON-java/blob/master/docs/RELEASES.md)
- [Commits](stleary/JSON-java@2020051...2023101)

Updates `commons-io:commons-io` from 2.4 to 2.14.0

Updates `org.apache.kafka:kafka-clients` from 1.0.0 to 3.9.2

Updates `org.springframework:spring-expression` from 5.2.8.RELEASE to 5.3.39
- [Release notes](https://github.com/spring-projects/spring-framework/releases)
- [Commits](spring-projects/spring-framework@v5.2.8.RELEASE...v5.3.39)

Updates `junit:junit` from 4.13 to 4.13.1
- [Release notes](https://github.com/junit-team/junit4/releases)
- [Changelog](https://github.com/junit-team/junit4/blob/main/doc/ReleaseNotes4.13.1.md)
- [Commits](junit-team/junit4@r4.13...r4.13.1)

Updates `com.puppycrawl.tools:checkstyle` from 8.7 to 8.29
- [Release notes](https://github.com/checkstyle/checkstyle/releases)
- [Commits](checkstyle/checkstyle@checkstyle-8.7...checkstyle-8.29)

Updates `org.yaml:snakeyaml` from 1.23 to 2.0
- [Commits](https://bitbucket.org/snakeyaml/snakeyaml/branches/compare/snakeyaml-2.0..snakeyaml-1.23)

Updates `org.apache.hadoop:hadoop-common` from 2.8.5 to 3.4.0

Updates `org.apache.derby:derby` from 10.14.2.0 to 10.17.1.0

Updates `org.json:json` from 20160810 to 20231013
- [Release notes](https://github.com/douglascrockford/JSON-java/releases)
- [Changelog](https://github.com/stleary/JSON-java/blob/master/docs/RELEASES.md)
- [Commits](stleary/JSON-java@2020051...2023101)

Updates `org.apache.kafka:kafka-clients` from 2.3.0 to 3.9.2

Updates `junit:junit` from 4.13 to 4.13.1
- [Release notes](https://github.com/junit-team/junit4/releases)
- [Changelog](https://github.com/junit-team/junit4/blob/main/doc/ReleaseNotes4.13.1.md)
- [Commits](junit-team/junit4@r4.13...r4.13.1)

Updates `com.puppycrawl.tools:checkstyle` from 8.7 to 8.29
- [Release notes](https://github.com/checkstyle/checkstyle/releases)
- [Commits](checkstyle/checkstyle@checkstyle-8.7...checkstyle-8.29)

Updates `org.yaml:snakeyaml` from 1.23 to 2.0
- [Commits](https://bitbucket.org/snakeyaml/snakeyaml/branches/compare/snakeyaml-2.0..snakeyaml-1.23)

Updates `org.apache.avro:avro` from 1.8.2 to 1.11.4

Updates `io.grpc:grpc-netty-shaded` from 1.45.1 to 1.75.0
- [Release notes](https://github.com/grpc/grpc-java/releases)
- [Commits](grpc/grpc-java@v1.45.1...v1.75.0)

Updates `com.google.guava:guava` from 25.1-jre to 32.0.0-jre
- [Release notes](https://github.com/google/guava/releases)
- [Commits](https://github.com/google/guava/commits)

Updates `org.apache.commons:commons-configuration2` from 2.5 to 2.15.0

Updates `commons-beanutils:commons-beanutils` from 1.9.3 to 1.11.0

Updates `org.postgresql:postgresql` from 42.2.2 to 42.7.11
- [Release notes](https://github.com/pgjdbc/pgjdbc/releases)
- [Changelog](https://github.com/pgjdbc/pgjdbc/blob/master/CHANGELOG.md)
- [Commits](pgjdbc/pgjdbc@REL42.2.2...REL42.7.11)

Updates `org.apache.kafka:kafka-clients` from 2.3.0 to 3.9.2

Updates `org.postgresql:postgresql` from 42.2.2 to 42.7.11
- [Release notes](https://github.com/pgjdbc/pgjdbc/releases)
- [Changelog](https://github.com/pgjdbc/pgjdbc/blob/master/CHANGELOG.md)
- [Commits](pgjdbc/pgjdbc@REL42.2.2...REL42.7.11)

Updates `org.json:json` from 20160810 to 20231013
- [Release notes](https://github.com/douglascrockford/JSON-java/releases)
- [Changelog](https://github.com/stleary/JSON-java/blob/master/docs/RELEASES.md)
- [Commits](stleary/JSON-java@2020051...2023101)

Updates `org.postgresql:postgresql` from 42.2.2 to 42.7.11
- [Release notes](https://github.com/pgjdbc/pgjdbc/releases)
- [Changelog](https://github.com/pgjdbc/pgjdbc/blob/master/CHANGELOG.md)
- [Commits](pgjdbc/pgjdbc@REL42.2.2...REL42.7.11)

Updates `org.apache.avro:avro` from 1.8.2 to 1.11.4

Updates `io.grpc:grpc-netty-shaded` from 1.45.1 to 1.75.0
- [Release notes](https://github.com/grpc/grpc-java/releases)
- [Commits](grpc/grpc-java@v1.45.1...v1.75.0)

Updates `com.google.guava:guava` from 25.1-jre to 32.0.0-jre
- [Release notes](https://github.com/google/guava/releases)
- [Commits](https://github.com/google/guava/commits)

Updates `org.apache.commons:commons-configuration2` from 2.5 to 2.15.0

Updates `commons-beanutils:commons-beanutils` from 1.9.3 to 1.11.0

Updates `org.apache.commons:commons-configuration2` from 2.5 to 2.15.0

Updates `commons-beanutils:commons-beanutils` from 1.9.3 to 1.11.0

Updates `org.apache.kafka:kafka-clients` from 2.4.1 to 3.9.2

Updates `com.google.protobuf:protobuf-java` from 3.21.5 to 3.25.5
- [Release notes](https://github.com/protocolbuffers/protobuf/releases)
- [Commits](protocolbuffers/protobuf@v3.21.5...v3.25.5)

Updates `com.puppycrawl.tools:checkstyle` from 8.7 to 8.29
- [Release notes](https://github.com/checkstyle/checkstyle/releases)
- [Commits](checkstyle/checkstyle@checkstyle-8.7...checkstyle-8.29)

Updates `ch.qos.logback:logback-classic` from 1.2.10 to 1.2.13
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.2.10...v_1.2.13)

Updates `org.apache.hadoop:hadoop-common` from 2.8.5 to 3.4.0

Updates `org.apache.derby:derby` from 10.14.2.0 to 10.17.1.0

Updates `org.json:json` from 20160810 to 20231013
- [Release notes](https://github.com/douglascrockford/JSON-java/releases)
- [Changelog](https://github.com/stleary/JSON-java/blob/master/docs/RELEASES.md)
- [Commits](stleary/JSON-java@2020051...2023101)

Updates `commons-io:commons-io` from 2.4 to 2.14.0

Updates `org.apache.kafka:kafka-clients` from 1.0.0 to 3.9.2

Updates `org.springframework:spring-expression` from 5.2.8.RELEASE to 5.3.39
- [Release notes](https://github.com/spring-projects/spring-framework/releases)
- [Commits](spring-projects/spring-framework@v5.2.8.RELEASE...v5.3.39)

Updates `junit:junit` from 4.13 to 4.13.1
- [Release notes](https://github.com/junit-team/junit4/releases)
- [Changelog](https://github.com/junit-team/junit4/blob/main/doc/ReleaseNotes4.13.1.md)
- [Commits](junit-team/junit4@r4.13...r4.13.1)

Updates `com.puppycrawl.tools:checkstyle` from 8.7 to 8.29
- [Release notes](https://github.com/checkstyle/checkstyle/releases)
- [Commits](checkstyle/checkstyle@checkstyle-8.7...checkstyle-8.29)

Updates `org.yaml:snakeyaml` from 1.23 to 2.0
- [Commits](https://bitbucket.org/snakeyaml/snakeyaml/branches/compare/snakeyaml-2.0..snakeyaml-1.23)

Updates `org.apache.avro:avro` from 1.8.2 to 1.11.4

Updates `io.grpc:grpc-netty-shaded` from 1.45.1 to 1.75.0
- [Release notes](https://github.com/grpc/grpc-java/releases)
- [Commits](grpc/grpc-java@v1.45.1...v1.75.0)

Updates `com.google.guava:guava` from 25.1-jre to 32.0.0-jre
- [Release notes](https://github.com/google/guava/releases)
- [Commits](https://github.com/google/guava/commits)

Updates `org.apache.commons:commons-configuration2` from 2.5 to 2.15.0

Updates `commons-beanutils:commons-beanutils` from 1.9.3 to 1.11.0

Updates `org.postgresql:postgresql` from 42.2.2 to 42.7.11
- [Release notes](https://github.com/pgjdbc/pgjdbc/releases)
- [Changelog](https://github.com/pgjdbc/pgjdbc/blob/master/CHANGELOG.md)
- [Commits](pgjdbc/pgjdbc@REL42.2.2...REL42.7.11)

Updates `com.google.protobuf:protobuf-java` from 3.21.5 to 3.25.5
- [Release notes](https://github.com/protocolbuffers/protobuf/releases)
- [Commits](protocolbuffers/protobuf@v3.21.5...v3.25.5)

Updates `ch.qos.logback:logback-classic` from 1.2.10 to 1.2.13
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.2.10...v_1.2.13)

Updates `com.puppycrawl.tools:checkstyle` from 8.7 to 8.29
- [Release notes](https://github.com/checkstyle/checkstyle/releases)
- [Commits](checkstyle/checkstyle@checkstyle-8.7...checkstyle-8.29)

Updates `com.google.guava:guava` from 31.0.1-jre to 32.0.0-jre
- [Release notes](https://github.com/google/guava/releases)
- [Commits](https://github.com/google/guava/commits)

---
updated-dependencies:
- dependency-name: org.apache.hadoop:hadoop-common
  dependency-version: 3.4.0
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.derby:derby
  dependency-version: 10.17.1.0
  dependency-type: direct:development
  dependency-group: maven
- dependency-name: org.apache.hadoop:hadoop-common
  dependency-version: 3.4.0
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.derby:derby
  dependency-version: 10.17.1.0
  dependency-type: direct:development
  dependency-group: maven
- dependency-name: org.json:json
  dependency-version: '20231013'
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: commons-io:commons-io
  dependency-version: 2.14.0
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.kafka:kafka-clients
  dependency-version: 3.9.2
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.springframework:spring-expression
  dependency-version: 5.3.39
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: junit:junit
  dependency-version: 4.13.1
  dependency-type: direct:development
  dependency-group: maven
- dependency-name: com.puppycrawl.tools:checkstyle
  dependency-version: '8.29'
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.yaml:snakeyaml
  dependency-version: '2.0'
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.hadoop:hadoop-common
  dependency-version: 3.4.0
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.derby:derby
  dependency-version: 10.17.1.0
  dependency-type: direct:development
  dependency-group: maven
- dependency-name: org.json:json
  dependency-version: '20231013'
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.kafka:kafka-clients
  dependency-version: 3.9.2
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: junit:junit
  dependency-version: 4.13.1
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: com.puppycrawl.tools:checkstyle
  dependency-version: '8.29'
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.yaml:snakeyaml
  dependency-version: '2.0'
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.avro:avro
  dependency-version: 1.11.4
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: io.grpc:grpc-netty-shaded
  dependency-version: 1.75.0
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: com.google.guava:guava
  dependency-version: 32.0.0-jre
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.commons:commons-configuration2
  dependency-version: 2.15.0
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: commons-beanutils:commons-beanutils
  dependency-version: 1.11.0
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.postgresql:postgresql
  dependency-version: 42.7.11
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.kafka:kafka-clients
  dependency-version: 3.9.2
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.postgresql:postgresql
  dependency-version: 42.7.11
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.json:json
  dependency-version: '20231013'
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.postgresql:postgresql
  dependency-version: 42.7.11
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.avro:avro
  dependency-version: 1.11.4
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: io.grpc:grpc-netty-shaded
  dependency-version: 1.75.0
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: com.google.guava:guava
  dependency-version: 32.0.0-jre
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.commons:commons-configuration2
  dependency-version: 2.15.0
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: commons-beanutils:commons-beanutils
  dependency-version: 1.11.0
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.commons:commons-configuration2
  dependency-version: 2.15.0
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: commons-beanutils:commons-beanutils
  dependency-version: 1.11.0
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.kafka:kafka-clients
  dependency-version: 3.9.2
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: com.google.protobuf:protobuf-java
  dependency-version: 3.25.5
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: com.puppycrawl.tools:checkstyle
  dependency-version: '8.29'
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: ch.qos.logback:logback-classic
  dependency-version: 1.2.13
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.hadoop:hadoop-common
  dependency-version: 3.4.0
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.derby:derby
  dependency-version: 10.17.1.0
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.json:json
  dependency-version: '20231013'
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: commons-io:commons-io
  dependency-version: 2.14.0
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.kafka:kafka-clients
  dependency-version: 3.9.2
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.springframework:spring-expression
  dependency-version: 5.3.39
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: junit:junit
  dependency-version: 4.13.1
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: com.puppycrawl.tools:checkstyle
  dependency-version: '8.29'
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.yaml:snakeyaml
  dependency-version: '2.0'
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.avro:avro
  dependency-version: 1.11.4
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: io.grpc:grpc-netty-shaded
  dependency-version: 1.75.0
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: com.google.guava:guava
  dependency-version: 32.0.0-jre
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.commons:commons-configuration2
  dependency-version: 2.15.0
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: commons-beanutils:commons-beanutils
  dependency-version: 1.11.0
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.postgresql:postgresql
  dependency-version: 42.7.11
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: com.google.protobuf:protobuf-java
  dependency-version: 3.25.5
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: ch.qos.logback:logback-classic
  dependency-version: 1.2.13
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: com.puppycrawl.tools:checkstyle
  dependency-version: '8.29'
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: com.google.guava:guava
  dependency-version: 32.0.0-jre
  dependency-type: direct:production
  dependency-group: maven
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Jul 7, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants