Skip to content

Bump the monthly-batch group with 18 updates - #591

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/monthly-batch-268aaea054
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/monthly-batch-268aaea054

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the monthly-batch group with 18 updates:

Package From To
org.junit.jupiter:junit-jupiter-engine 5.13.4 6.1.3
org.junit.jupiter:junit-jupiter-api 5.13.4 6.1.3
com.puppycrawl.tools:checkstyle 13.10.0 14.3.0
net.sourceforge.pmd:pmd-core 7.27.0 7.28.0
net.sourceforge.pmd:pmd-java 7.27.0 7.28.0
net.sourceforge.pmd:pmd-javascript 7.27.0 7.28.0
net.sourceforge.pmd:pmd-jsp 7.27.0 7.28.0
com.github.spotbugs:spotbugs-maven-plugin 4.10.4.0 4.10.4.1
org.apache.maven.plugins:maven-compiler-plugin 3.15.0 3.16.0
org.apache.maven.plugins:maven-deploy-plugin 3.1.4 3.2.0
org.apache.maven.plugins:maven-install-plugin 3.1.4 3.2.0
org.apache.maven.plugins:maven-surefire-plugin 3.5.6 3.6.0
org.codehaus.mojo:exec-maven-plugin 3.6.3 3.6.4
org.codehaus.mojo:versions-maven-plugin 2.21.0 2.22.0
org.hjug.refactorfirst.plugin:refactor-first-maven-plugin 0.9.0 0.10.0
org.jreleaser:jreleaser-maven-plugin 1.25.0 1.26.0
io.vertx:vertx-core 5.1.6 5.2.0
org.apache.maven:apache-maven 3.9.16 3.10.0

Updates org.junit.jupiter:junit-jupiter-engine from 5.13.4 to 6.1.3

Release notes

Sourced from org.junit.jupiter:junit-jupiter-engine's releases.

JUnit 6.1.3 = Platform 6.1.3 + Jupiter 6.1.3 + Vintage 6.1.3

See Release Notes.

Full Changelog: junit-team/junit-framework@r6.1.2...r6.1.3

JUnit 6.1.2 = Platform 6.1.2 + Jupiter 6.1.2 + Vintage 6.1.2

See Release Notes.

Full Changelog: junit-team/junit-framework@r6.1.1...r6.1.2

JUnit 6.1.1 = Platform 6.1.1 + Jupiter 6.1.1 + Vintage 6.1.1

See Release Notes.

Full Changelog: junit-team/junit-framework@r6.1.0...r6.1.1

JUnit 6.1.0 = Platform 6.1.0 + Jupiter 6.1.0 + Vintage 6.1.0

See Release Notes.

New Contributors

Full Changelog: junit-team/junit-framework@r6.0.3...r6.1.0

JUnit 6.1.0-RC1 = Platform 6.1.0-RC1 + Jupiter 6.1.0-RC1 + Vintage 6.1.0-RC1

See Release Notes.

New Contributors

Full Changelog: junit-team/junit-framework@r6.1.0-M1...r6.1.0-RC1

JUnit 6.1.0-M1 = Platform 6.1.0-M1 + Jupiter 6.1.0-M1 + Vintage 6.1.0-M1

See Release Notes.

New Contributors

... (truncated)

Commits
  • f59f60d Release 6.1.3
  • cd8ec92 Finalize 6.1.3 release notes
  • c8729f2 Restore compatibility with GraalVM 25 (#5901)
  • ddc9e74 Update graalvm/setup-graalvm action to v1.6.4 (#5959)
  • fe2c52a Update plugin org.graalvm.buildtools.native to v1.1.7 (#5923)
  • 62afc02 Delay GraalVM plugin updates for 3 days
  • 0cc2902 Skip graalVmTest task if GraalVM env vars are not set
  • f6bbfc5 Move GraalVM tests to separate test task (#5903)
  • e87e052 Update plugin org.graalvm.buildtools.native to v1.1.6 (#5899)
  • 1cd56df Update plugin org.graalvm.buildtools.native to v1.1.5 (#5880)
  • Additional commits viewable in compare view

Updates org.junit.jupiter:junit-jupiter-api from 5.13.4 to 6.1.3

Release notes

Sourced from org.junit.jupiter:junit-jupiter-api's releases.

JUnit 6.1.3 = Platform 6.1.3 + Jupiter 6.1.3 + Vintage 6.1.3

See Release Notes.

Full Changelog: junit-team/junit-framework@r6.1.2...r6.1.3

JUnit 6.1.2 = Platform 6.1.2 + Jupiter 6.1.2 + Vintage 6.1.2

See Release Notes.

Full Changelog: junit-team/junit-framework@r6.1.1...r6.1.2

JUnit 6.1.1 = Platform 6.1.1 + Jupiter 6.1.1 + Vintage 6.1.1

See Release Notes.

Full Changelog: junit-team/junit-framework@r6.1.0...r6.1.1

JUnit 6.1.0 = Platform 6.1.0 + Jupiter 6.1.0 + Vintage 6.1.0

See Release Notes.

New Contributors

Full Changelog: junit-team/junit-framework@r6.0.3...r6.1.0

JUnit 6.1.0-RC1 = Platform 6.1.0-RC1 + Jupiter 6.1.0-RC1 + Vintage 6.1.0-RC1

See Release Notes.

New Contributors

Full Changelog: junit-team/junit-framework@r6.1.0-M1...r6.1.0-RC1

JUnit 6.1.0-M1 = Platform 6.1.0-M1 + Jupiter 6.1.0-M1 + Vintage 6.1.0-M1

See Release Notes.

New Contributors

... (truncated)

Commits
  • f59f60d Release 6.1.3
  • cd8ec92 Finalize 6.1.3 release notes
  • c8729f2 Restore compatibility with GraalVM 25 (#5901)
  • ddc9e74 Update graalvm/setup-graalvm action to v1.6.4 (#5959)
  • fe2c52a Update plugin org.graalvm.buildtools.native to v1.1.7 (#5923)
  • 62afc02 Delay GraalVM plugin updates for 3 days
  • 0cc2902 Skip graalVmTest task if GraalVM env vars are not set
  • f6bbfc5 Move GraalVM tests to separate test task (#5903)
  • e87e052 Update plugin org.graalvm.buildtools.native to v1.1.6 (#5899)
  • 1cd56df Update plugin org.graalvm.buildtools.native to v1.1.5 (#5880)
  • Additional commits viewable in compare view

Updates org.junit.jupiter:junit-jupiter-api from 5.13.4 to 6.1.3

Release notes

Sourced from org.junit.jupiter:junit-jupiter-api's releases.

JUnit 6.1.3 = Platform 6.1.3 + Jupiter 6.1.3 + Vintage 6.1.3

See Release Notes.

Full Changelog: junit-team/junit-framework@r6.1.2...r6.1.3

JUnit 6.1.2 = Platform 6.1.2 + Jupiter 6.1.2 + Vintage 6.1.2

See Release Notes.

Full Changelog: junit-team/junit-framework@r6.1.1...r6.1.2

JUnit 6.1.1 = Platform 6.1.1 + Jupiter 6.1.1 + Vintage 6.1.1

See Release Notes.

Full Changelog: junit-team/junit-framework@r6.1.0...r6.1.1

JUnit 6.1.0 = Platform 6.1.0 + Jupiter 6.1.0 + Vintage 6.1.0

See Release Notes.

New Contributors

Full Changelog: junit-team/junit-framework@r6.0.3...r6.1.0

JUnit 6.1.0-RC1 = Platform 6.1.0-RC1 + Jupiter 6.1.0-RC1 + Vintage 6.1.0-RC1

See Release Notes.

New Contributors

Full Changelog: junit-team/junit-framework@r6.1.0-M1...r6.1.0-RC1

JUnit 6.1.0-M1 = Platform 6.1.0-M1 + Jupiter 6.1.0-M1 + Vintage 6.1.0-M1

See Release Notes.

New Contributors

... (truncated)

Commits
  • f59f60d Release 6.1.3
  • cd8ec92 Finalize 6.1.3 release notes
  • c8729f2 Restore compatibility with GraalVM 25 (#5901)
  • ddc9e74 Update graalvm/setup-graalvm action to v1.6.4 (#5959)
  • fe2c52a Update plugin org.graalvm.buildtools.native to v1.1.7 (#5923)
  • 62afc02 Delay GraalVM plugin updates for 3 days
  • 0cc2902 Skip graalVmTest task if GraalVM env vars are not set
  • f6bbfc5 Move GraalVM tests to separate test task (#5903)
  • e87e052 Update plugin org.graalvm.buildtools.native to v1.1.6 (#5899)
  • 1cd56df Update plugin org.graalvm.buildtools.native to v1.1.5 (#5880)
  • Additional commits viewable in compare view

Updates com.puppycrawl.tools:checkstyle from 13.10.0 to 14.3.0

Release notes

Sourced from com.puppycrawl.tools:checkstyle's releases.

checkstyle-14.3.0

Checkstyle 14.3.0 - https://checkstyle.org/releasenotes.html#Release_14.3.0

New:

#14120 - Make Checkstyle an java module with module-info.java.

checkstyle-14.2.0

Checkstyle 14.2.0 - https://checkstyle.org/releasenotes.html#Release_14.2.0

New:

#19513 - ModifiedOrder: New property modifierOrder. #17723 - WhitespaceAfter: new token SINGLE_LINE_COMMENT to catch missing whitespace checks around // comments. #8312 - NoWhitespaceAfter: Allow for use of DO_WHILE, LITERAL_CATCH, LITERAL_FOR, LITERAL_IF, and LITERAL_WHILE. #17172 - AnnotationLocation new token MODULE_DEF. Google-style: incomplete coverage on annotation rules for modules. #14986 - New Check UnnecessaryPermitsClause. #7541 - new Check: GoolgeRightCurly. #19949 - New check: JavadocSeeTagOrder. #20639 - new Check: OpenjdkMethodThrowsAlignment.

Bug fixes:

#17663 - Indentation: missing violations for '->' and ',' in return statement continuation. #20541 - False Positive: Lambda is incorrectly flaged by OperatorWrap. #21739 - UnusedLocalVariable: false positive on unnamed variable _ inside anonymous class. #21613 - False negative: UnusedTryResourceShouldBeUnnamed treats same-named identifiers in catch/finally blocks as resource usage. #21695 - openjdk style: use custon modifierOrder at RedundantModifier. #21689 - Add GoogleRightCurly to google_checks.xml instead of RightCurly. #10924 - All checks that use AbstractCheck#getLine() should check code points instead of characters for spacing. #21139 - Performance: Avoid duplicate regex match in SuppressFilterElement.isFileMatch. #21528 - Add checks for Sun Style [4.2 - Wrapping Lines]. #21578 - False Negative: LambdaParameterName silently passes lambdas in switch rule. #21579 - False Negative: NeedBraces silently passes lambdas in switch rule. #5895 - CLI XML output file: file stops dead when an execption occurs. #11410 - False Negative: LeftCurlyCheck. #21583 - Update Documentation Comments Style Guide: add JavadocSeeTagOrder. #21609 - NPE in RightCurlyCheck. #19724 - google_checks.xml: JavadocMethod accessModifiers should include protected to match MissingJavadocMethod scope. #20963 - False negative in LeftCurly for types with option=eol. #21547 - add OpenjdkMethodThrowsAlignment check in openjdk_checks.xml. #20636 - False negatives regarding LeftCurly in openjdk_checks.xml. #17170 - Google-style: unfollowed rule on ordering and spacing of module directives. #21454 - google_checks.xml: false negative 4.3 One statement per line. #21501 - CommonUtil.getFileExtension includes parent-directory dots in the extension. #21445 - google_checks.xml: false negative 3.3.1.1 No module imports. #21477 - Add checks for Sun Style [4.1 - Line Length]. #21444 - google_checks.xml: false negative 3.2 Package declaration.

... (truncated)

Commits
  • bc58fc6 [maven-release-plugin] prepare release checkstyle-14.3.0
  • 5711c72 doc: release notes for 14.3.0
  • 4b8a5b3 minor: Bump version to 14.3.0-SNAPSHOT
  • a93f8f2 Issue #14120: add module-info.java to make Checkstyle an explicit Java module
  • 9e3482f [maven-release-plugin] prepare for next development iteration
  • 6a200bc [maven-release-plugin] prepare release checkstyle-14.2.0
  • 2d2b135 doc: release notes for 14.2.0
  • 194e7a2 Issue #20590: Improve Input coverage for compact sources for SuperCloneCheck
  • 123f477 Issue #17663: Indentation: missing violations for '->' and ',' in return stat...
  • 4b2f353 Issue #20541: fix OperatorWrap false positive for lambda with block body
  • Additional commits viewable in compare view

Updates net.sourceforge.pmd:pmd-core from 7.27.0 to 7.28.0

Release notes

Sourced from net.sourceforge.pmd:pmd-core's releases.

PMD 7.28.0 (25-September-2026)

25-September-2026 - 7.28.0

The PMD team is pleased to announce PMD 7.28.0.

This is a minor release.

Table Of Contents

🚀️ New and noteworthy

Kotlin XPath functions and type attributes

Type data is now accessible in XPath rules via new attributes and helper functions (see Kotlin XPath rule support):

  • Type-info Attributes: @TypeName, @ReturnTypeName, @AnnotationFqNames are exposed on declaration nodes (property, function, class, parameter, catch, for-loop, delegation specifier, annotation nodes). These attributes depend on type resolution: they are only available when auxClasspath is configured and the kotlin-type-mapper analysis has resolved the types.
  • General Attributes: @Mutable, @Identifier, @Name are exposed on declaration and import related nodes. These attributes don't depend on type resolution, so they're always present regardless of auxClasspath.
  • XPath functions:
    • pmd-kotlin:typeIs(typeName): matches if the node's type is typeName or a subtype.
    • pmd-kotlin:typeIsExactly(typeName): matches the exact declared type only (no subtypes).
    • pmd-kotlin:hasAnnotation(name): matches if the node has an annotation with the given simple or FQN.
    • pmd-kotlin:modifiers(): returns the modifier keywords of a declaration as a sequence.
    • pmd-kotlin:isNullable(): returns true if the node's declared type is nullable (has ?).
    • pmd-kotlin:hasUnresolvedReference(): returns true if the node contains an unresolved reference.
    • pmd-kotlin:matchesSig(signature): matches call sites by method signature pattern (supports wildcards).

🌟️ New and Changed Rules

New Rules

  • The new Java rule OnDemandImport reports on-demand imports, also known as wildcard imports. By default, static imports from JUnit and TestNG are allowed. The allowed static and type import packages can be configured with allowStaticImportsFrom and allowTypeImportsFrom.
  • The new Java rule LongLiteralEndingWithLowercaseL finds long literals ending with a lowercase l.

... (truncated)

Commits
  • 79726f0 [release] prepare release pmd_releases/7.28.0
  • ba7d31e Prepare pmd release 7.28.0
  • fb85046 Update contributors for 7.28.0
  • 5569f8c [doc] Update release notes for 7.28.0 (#7106)
  • ca7381c [doc] Add gradle environment vars example (#7111)
  • 388f07a [java] Fix #7101: Skip non-archive files on the auxclasspath (#7102)
  • 251ef73 [cli] Add the missing exit code 5 to the CLI help (#7090)
  • 1831734 [doc] TOC highlighting improvements (#7089)
  • 383ff52 [java] Fix #7056: Add JavaLanguageProperty to disable auxClasspath warnings (...
  • 0a14568 [java] New rule: InternalApiUsage (#6994)
  • Additional commits viewable in compare view

Updates net.sourceforge.pmd:pmd-java from 7.27.0 to 7.28.0

Release notes

Sourced from net.sourceforge.pmd:pmd-java's releases.

PMD 7.28.0 (25-September-2026)

25-September-2026 - 7.28.0

The PMD team is pleased to announce PMD 7.28.0.

This is a minor release.

Table Of Contents

🚀️ New and noteworthy

Kotlin XPath functions and type attributes

Type data is now accessible in XPath rules via new attributes and helper functions (see Kotlin XPath rule support):

  • Type-info Attributes: @TypeName, @ReturnTypeName, @AnnotationFqNames are exposed on declaration nodes (property, function, class, parameter, catch, for-loop, delegation specifier, annotation nodes). These attributes depend on type resolution: they are only available when auxClasspath is configured and the kotlin-type-mapper analysis has resolved the types.
  • General Attributes: @Mutable, @Identifier, @Name are exposed on declaration and import related nodes. These attributes don't depend on type resolution, so they're always present regardless of auxClasspath.
  • XPath functions:
    • pmd-kotlin:typeIs(typeName): matches if the node's type is typeName or a subtype.
    • pmd-kotlin:typeIsExactly(typeName): matches the exact declared type only (no subtypes).
    • pmd-kotlin:hasAnnotation(name): matches if the node has an annotation with the given simple or FQN.
    • pmd-kotlin:modifiers(): returns the modifier keywords of a declaration as a sequence.
    • pmd-kotlin:isNullable(): returns true if the node's declared type is nullable (has ?).
    • pmd-kotlin:hasUnresolvedReference(): returns true if the node contains an unresolved reference.
    • pmd-kotlin:matchesSig(signature): matches call sites by method signature pattern (supports wildcards).

🌟️ New and Changed Rules

New Rules

  • The new Java rule OnDemandImport reports on-demand imports, also known as wildcard imports. By default, static imports from JUnit and TestNG are allowed. The allowed static and type import packages can be configured with allowStaticImportsFrom and allowTypeImportsFrom.
  • The new Java rule LongLiteralEndingWithLowercaseL finds long literals ending with a lowercase l.

... (truncated)

Commits
  • 79726f0 [release] prepare release pmd_releases/7.28.0
  • ba7d31e Prepare pmd release 7.28.0
  • fb85046 Update contributors for 7.28.0
  • 5569f8c [doc] Update release notes for 7.28.0 (#7106)
  • ca7381c [doc] Add gradle environment vars example (#7111)
  • 388f07a [java] Fix #7101: Skip non-archive files on the auxclasspath (#7102)
  • 251ef73 [cli] Add the missing exit code 5 to the CLI help (#7090)
  • 1831734 [doc] TOC highlighting improvements (#7089)
  • 383ff52 [java] Fix #7056: Add JavaLanguageProperty to disable auxClasspath warnings (...
  • 0a14568 [java] New rule: InternalApiUsage (#6994)
  • Additional commits viewable in compare view

Updates net.sourceforge.pmd:pmd-javascript from 7.27.0 to 7.28.0

Release notes

Sourced from net.sourceforge.pmd:pmd-javascript's releases.

PMD 7.28.0 (25-September-2026)

25-September-2026 - 7.28.0

The PMD team is pleased to announce PMD 7.28.0.

This is a minor release.

Table Of Contents

🚀️ New and noteworthy

Kotlin XPath functions and type attributes

Type data is now accessible in XPath rules via new attributes and helper functions (see Kotlin XPath rule support):

  • Type-info Attributes: @TypeName, @ReturnTypeName, @AnnotationFqNames are exposed on declaration nodes (property, function, class, parameter, catch, for-loop, delegation specifier, annotation nodes). These attributes depend on type resolution: they are only available when auxClasspath is configured and the kotlin-type-mapper analysis has resolved the types.
  • General Attributes: @Mutable, @Identifier, @Name are exposed on declaration and import related nodes. These attributes don't depend on type resolution, so they're always present regardless of auxClasspath.
  • XPath functions:
    • pmd-kotlin:typeIs(typeName): matches if the node's type is typeName or a subtype.
    • pmd-kotlin:typeIsExactly(typeName): matches the exact declared type only (no subtypes).
    • pmd-kotlin:hasAnnotation(name): matches if the node has an annotation with the given simple or FQN.
    • pmd-kotlin:modifiers(): returns the modifier keywords of a declaration as a sequence.
    • pmd-kotlin:isNullable(): returns true if the node's declared type is nullable (has ?).
    • pmd-kotlin:hasUnresolvedReference(): returns true if the node contains an unresolved reference.
    • pmd-kotlin:matchesSig(signature): matches call sites by method signature pattern (supports wildcards).

🌟️ New and Changed Rules

New Rules

  • The new Java rule OnDemandImport reports on-demand imports, also known as wildcard imports. By default, static imports from JUnit and TestNG are allowed. The allowed static and type import packages can be configured with allowStaticImportsFrom and allowTypeImportsFrom.
  • The new Java rule LongLiteralEndingWithLowercaseL finds long literals ending with a lowercase l.

... (truncated)

Commits
  • 79726f0 [release] prepare release pmd_releases/7.28.0
  • ba7d31e Prepare pmd release 7.28.0
  • fb85046 Update contributors for 7.28.0
  • 5569f8c [doc] Update release notes for 7.28.0 (#7106)
  • ca7381c [doc] Add gradle environment vars example (#7111)
  • 388f07a [java] Fix #7101: Skip non-archive files on the auxclasspath (#7102)
  • 251ef73 [cli] Add the missing exit code 5 to the CLI help (#7090)
  • 1831734 [doc] TOC highlighting improvements (#7089)
  • 383ff52 [java] Fix #7056: Add JavaLanguageProperty to disable auxClasspath warnings (...
  • 0a14568 [java] New rule: InternalApiUsage (#6994)
  • Additional commits viewable in compare view

Updates net.sourceforge.pmd:pmd-jsp from 7.27.0 to 7.28.0

Release notes

Sourced from net.sourceforge.pmd:pmd-jsp's releases.

PMD 7.28.0 (25-September-2026)

25-September-2026 - 7.28.0

The PMD team is pleased to announce PMD 7.28.0.

This is a minor release.

Table Of Contents

🚀️ New and noteworthy

Kotlin XPath functions and type attributes

Type data is now accessible in XPath rules via new attributes and helper functions (see Kotlin XPath rule support):

  • Type-info Attributes: @TypeName, @ReturnTypeName, @AnnotationFqNames are exposed on declaration nodes (property, function, class, parameter, catch, for-loop, delegation specifier, annotation nodes). These attributes depend on type resolution: they are only available when auxClasspath is configured and the kotlin-type-mapper analysis has resolved the types.
  • General Attributes: @Mutable, @Identifier, @Name are exposed on declaration and import related nodes. These attributes don't depend on type resolution, so they're always present regardless of auxClasspath.
  • XPath functions:
    • pmd-kotlin:typeIs(typeName): matches if the node's type is typeName or a subtype.
    • pmd-kotlin:typeIsExactly(typeName): matches the exact declared type only (no subtypes).
    • pmd-kotlin:hasAnnotation(name): matches if the node has an annotation with the given simple or FQN.
    • pmd-kotlin:modifiers(): returns the modifier keywords of a declaration as a sequence.
    • pmd-kotlin:isNullable(): returns true if the node's declared type is nullable (has ?).
    • pmd-kotlin:hasUnresolvedReference(): returns true if the node contains an unresolved reference.
    • pmd-kotlin:matchesSig(signature): matches call sites by method signature pattern (supports wildcards).

🌟️ New and Changed Rules

New Rules

  • The new Java rule OnDemandImport reports on-demand imports, also known as wildcard imports. By default, static imports from JUnit and TestNG are allowed. The allowed static and type import packages can be configured with allowStaticImportsFrom and allowTypeImportsFrom.
  • The new Java rule LongLiteralEndingWithLowercaseL finds long literals ending with a lowercase l.

... (truncated)

Commits
  • 79726f0 [release] prepare release pmd_releases/7.28.0
  • ba7d31e Prepare pmd release 7.28.0
  • fb85046 Update contributors for 7.28.0
  • 5569f8c [doc] Update release notes for 7.28.0 (#7106)
  • ca7381c [doc] Add gradle environment vars example (#7111)
  • 388f07a [java] Fix #7101: Skip non-archive files on the auxclasspath (#7102)
  • 251ef73 [cli] Add the missing exit code 5 to the CLI help (#7090)
  • 1831734 [doc] TOC highlighting improvements (#7089)
  • 383ff52 [java] Fix #7056: Add JavaLanguageProperty to disable auxClasspath warnings (...
  • 0a14568 [java] New rule: InternalApiUsage (#6994)
  • Additional commits viewable in compare view

Updates net.sourceforge.pmd:pmd-java from 7.27.0 to 7.28.0

Release notes

Sourced from net.sourceforge.pmd:pmd-java's releases.

PMD 7.28.0 (25-September-2026)

25-September-2026 - 7.28.0

The PMD team is pleased to announce PMD 7.28.0.

This is a minor release.

Table Of Contents

🚀️ New and noteworthy

Kotlin XPath functions and type attributes

Type data is now accessible in XPath rules via new attributes and helper functions (see Kotlin XPath rule support):

  • Type-info Attributes: @TypeName, @ReturnTypeName, @AnnotationFqNames are exposed on declaration nodes (property, function, class, parameter, catch, for-loop, delegation specifier, annotation nodes). These attributes depend on type resolution: they are only available when auxClasspath is configured and the kotlin-type-mapper analysis has resolved the types.
  • General Attributes: @Mutable, @Identifier, @Name are exposed on declaration and import related nodes. These attributes don't depend on type resolution, so they're always present regardless of auxClasspath.
  • XPath functions:
    • pmd-kotlin:typeIs(typeName): matches if the node's type is typeName or a subtype.
    • pmd-kotlin:typeIsExactly(typeName): matches the exact declared type only (no subtypes).
    • pmd-kotlin:hasAnnotation(name): matches if the node has an annotation with the given simple or FQN.
    • pmd-kotlin:modifiers(): returns the modifier keywords of a declaration as a sequence.
    • pmd-kotlin:isNullable(): returns true if the node's declared type is nullable (has ?).
    • pmd-kotlin:hasUnresolvedReference(): returns true if the node contains an unresolved reference.
    • pmd-kotlin:matchesSig(signature): matches call sites by method signature pattern (supports wildcards).

🌟️ New and Changed Rules

New Rules

  • The new Java rule OnDemandImport reports on-demand imports, also known as wildcard imports. By default, static imports from JUnit and TestNG are allowed. The allowed static and type import packages can be configured with allowStaticImportsFrom and allowTypeImportsFrom.
  • The new Java rule LongLiteralEndingWithLowercaseL finds long literals ending with a lowercase l.

... (truncated)

Commits
  • 79726f0 [release] prepare release pmd_releases/7.28.0
  • ba7d31e Prepare pmd release 7.28.0
  • fb85046 Update contributors for 7.28.0
  • 5569f8c [doc] Update release notes for 7.28.0 (#7106)
  • ca7381c [doc] Add gradle environment vars example (#7111)
  • 388f07a [java] Fix #7101: Skip non-archive files on the auxclasspath (#7102)
  • 251ef73 [cli] Add the missing exit code 5 to the CLI help (#7090)
  • 1831734 [doc] TOC highlighting improvements (#7089)

Bumps the monthly-batch group with 18 updates:

| Package | From | To |
| --- | --- | --- |
| [org.junit.jupiter:junit-jupiter-engine](https://github.com/junit-team/junit-framework) | `5.13.4` | `6.1.3` |
| [org.junit.jupiter:junit-jupiter-api](https://github.com/junit-team/junit-framework) | `5.13.4` | `6.1.3` |
| [com.puppycrawl.tools:checkstyle](https://github.com/checkstyle/checkstyle) | `13.10.0` | `14.3.0` |
| [net.sourceforge.pmd:pmd-core](https://github.com/pmd/pmd) | `7.27.0` | `7.28.0` |
| [net.sourceforge.pmd:pmd-java](https://github.com/pmd/pmd) | `7.27.0` | `7.28.0` |
| [net.sourceforge.pmd:pmd-javascript](https://github.com/pmd/pmd) | `7.27.0` | `7.28.0` |
| [net.sourceforge.pmd:pmd-jsp](https://github.com/pmd/pmd) | `7.27.0` | `7.28.0` |
| [com.github.spotbugs:spotbugs-maven-plugin](https://github.com/spotbugs/spotbugs-maven-plugin) | `4.10.4.0` | `4.10.4.1` |
| [org.apache.maven.plugins:maven-compiler-plugin](https://github.com/apache/maven-compiler-plugin) | `3.15.0` | `3.16.0` |
| [org.apache.maven.plugins:maven-deploy-plugin](https://github.com/apache/maven-deploy-plugin) | `3.1.4` | `3.2.0` |
| [org.apache.maven.plugins:maven-install-plugin](https://github.com/apache/maven-install-plugin) | `3.1.4` | `3.2.0` |
| [org.apache.maven.plugins:maven-surefire-plugin](https://github.com/apache/maven-surefire) | `3.5.6` | `3.6.0` |
| [org.codehaus.mojo:exec-maven-plugin](https://github.com/mojohaus/exec-maven-plugin) | `3.6.3` | `3.6.4` |
| [org.codehaus.mojo:versions-maven-plugin](https://github.com/mojohaus/versions) | `2.21.0` | `2.22.0` |
| [org.hjug.refactorfirst.plugin:refactor-first-maven-plugin](https://github.com/refactorfirst/RefactorFirst) | `0.9.0` | `0.10.0` |
| [org.jreleaser:jreleaser-maven-plugin](https://github.com/jreleaser/jreleaser) | `1.25.0` | `1.26.0` |
| [io.vertx:vertx-core](https://github.com/eclipse/vert.x) | `5.1.6` | `5.2.0` |
| org.apache.maven:apache-maven | `3.9.16` | `3.10.0` |


Updates `org.junit.jupiter:junit-jupiter-engine` from 5.13.4 to 6.1.3
- [Release notes](https://github.com/junit-team/junit-framework/releases)
- [Commits](junit-team/junit-framework@r5.13.4...r6.1.3)

Updates `org.junit.jupiter:junit-jupiter-api` from 5.13.4 to 6.1.3
- [Release notes](https://github.com/junit-team/junit-framework/releases)
- [Commits](junit-team/junit-framework@r5.13.4...r6.1.3)

Updates `org.junit.jupiter:junit-jupiter-api` from 5.13.4 to 6.1.3
- [Release notes](https://github.com/junit-team/junit-framework/releases)
- [Commits](junit-team/junit-framework@r5.13.4...r6.1.3)

Updates `com.puppycrawl.tools:checkstyle` from 13.10.0 to 14.3.0
- [Release notes](https://github.com/checkstyle/checkstyle/releases)
- [Commits](checkstyle/checkstyle@checkstyle-13.10.0...checkstyle-14.3.0)

Updates `net.sourceforge.pmd:pmd-core` from 7.27.0 to 7.28.0
- [Release notes](https://github.com/pmd/pmd/releases)
- [Commits](pmd/pmd@pmd_releases/7.27.0...pmd_releases/7.28.0)

Updates `net.sourceforge.pmd:pmd-java` from 7.27.0 to 7.28.0
- [Release notes](https://github.com/pmd/pmd/releases)
- [Commits](pmd/pmd@pmd_releases/7.27.0...pmd_releases/7.28.0)

Updates `net.sourceforge.pmd:pmd-javascript` from 7.27.0 to 7.28.0
- [Release notes](https://github.com/pmd/pmd/releases)
- [Commits](pmd/pmd@pmd_releases/7.27.0...pmd_releases/7.28.0)

Updates `net.sourceforge.pmd:pmd-jsp` from 7.27.0 to 7.28.0
- [Release notes](https://github.com/pmd/pmd/releases)
- [Commits](pmd/pmd@pmd_releases/7.27.0...pmd_releases/7.28.0)

Updates `net.sourceforge.pmd:pmd-java` from 7.27.0 to 7.28.0
- [Release notes](https://github.com/pmd/pmd/releases)
- [Commits](pmd/pmd@pmd_releases/7.27.0...pmd_releases/7.28.0)

Updates `net.sourceforge.pmd:pmd-javascript` from 7.27.0 to 7.28.0
- [Release notes](https://github.com/pmd/pmd/releases)
- [Commits](pmd/pmd@pmd_releases/7.27.0...pmd_releases/7.28.0)

Updates `net.sourceforge.pmd:pmd-jsp` from 7.27.0 to 7.28.0
- [Release notes](https://github.com/pmd/pmd/releases)
- [Commits](pmd/pmd@pmd_releases/7.27.0...pmd_releases/7.28.0)

Updates `com.github.spotbugs:spotbugs-maven-plugin` from 4.10.4.0 to 4.10.4.1
- [Release notes](https://github.com/spotbugs/spotbugs-maven-plugin/releases)
- [Commits](spotbugs/spotbugs-maven-plugin@spotbugs-maven-plugin-4.10.4.0...spotbugs-maven-plugin-4.10.4.1)

Updates `org.apache.maven.plugins:maven-compiler-plugin` from 3.15.0 to 3.16.0
- [Release notes](https://github.com/apache/maven-compiler-plugin/releases)
- [Commits](apache/maven-compiler-plugin@maven-compiler-plugin-3.15.0...maven-compiler-plugin-3.16.0)

Updates `org.apache.maven.plugins:maven-deploy-plugin` from 3.1.4 to 3.2.0
- [Release notes](https://github.com/apache/maven-deploy-plugin/releases)
- [Commits](apache/maven-deploy-plugin@maven-deploy-plugin-3.1.4...maven-deploy-plugin-3.2.0)

Updates `org.apache.maven.plugins:maven-install-plugin` from 3.1.4 to 3.2.0
- [Release notes](https://github.com/apache/maven-install-plugin/releases)
- [Commits](apache/maven-install-plugin@maven-install-plugin-3.1.4...maven-install-plugin-3.2.0)

Updates `org.apache.maven.plugins:maven-surefire-plugin` from 3.5.6 to 3.6.0
- [Release notes](https://github.com/apache/maven-surefire/releases)
- [Commits](apache/maven-surefire@surefire-3.5.6...surefire-3.6.0)

Updates `org.codehaus.mojo:exec-maven-plugin` from 3.6.3 to 3.6.4
- [Release notes](https://github.com/mojohaus/exec-maven-plugin/releases)
- [Commits](mojohaus/exec-maven-plugin@3.6.3...3.6.4)

Updates `org.codehaus.mojo:versions-maven-plugin` from 2.21.0 to 2.22.0
- [Release notes](https://github.com/mojohaus/versions/releases)
- [Changelog](https://github.com/mojohaus/versions/blob/master/ReleaseNotes.md)
- [Commits](mojohaus/versions@2.21.0...2.22.0)

Updates `org.hjug.refactorfirst.plugin:refactor-first-maven-plugin` from 0.9.0 to 0.10.0
- [Release notes](https://github.com/refactorfirst/RefactorFirst/releases)
- [Commits](refactorfirst/RefactorFirst@0.9.0...0.10.0)

Updates `org.jreleaser:jreleaser-maven-plugin` from 1.25.0 to 1.26.0
- [Release notes](https://github.com/jreleaser/jreleaser/releases)
- [Commits](jreleaser/jreleaser@v1.25.0...v1.26.0)

Updates `io.vertx:vertx-core` from 5.1.6 to 5.2.0
- [Commits](eclipse-vertx/vert.x@5.1.6...5.2.0)

Updates `org.apache.maven:apache-maven` from 3.9.16 to 3.10.0

---
updated-dependencies:
- dependency-name: org.junit.jupiter:junit-jupiter-engine
  dependency-version: 6.1.3
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: monthly-batch
- dependency-name: org.junit.jupiter:junit-jupiter-api
  dependency-version: 6.1.3
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: monthly-batch
- dependency-name: org.junit.jupiter:junit-jupiter-api
  dependency-version: 6.1.3
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: monthly-batch
- dependency-name: com.puppycrawl.tools:checkstyle
  dependency-version: 14.3.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: monthly-batch
- dependency-name: net.sourceforge.pmd:pmd-core
  dependency-version: 7.28.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: monthly-batch
- dependency-name: net.sourceforge.pmd:pmd-java
  dependency-version: 7.28.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: monthly-batch
- dependency-name: net.sourceforge.pmd:pmd-javascript
  dependency-version: 7.28.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: monthly-batch
- dependency-name: net.sourceforge.pmd:pmd-jsp
  dependency-version: 7.28.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: monthly-batch
- dependency-name: net.sourceforge.pmd:pmd-java
  dependency-version: 7.28.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: monthly-batch
- dependency-name: net.sourceforge.pmd:pmd-javascript
  dependency-version: 7.28.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: monthly-batch
- dependency-name: net.sourceforge.pmd:pmd-jsp
  dependency-version: 7.28.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: monthly-batch
- dependency-name: com.github.spotbugs:spotbugs-maven-plugin
  dependency-version: 4.10.4.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: monthly-batch
- dependency-name: org.apache.maven.plugins:maven-compiler-plugin
  dependency-version: 3.16.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: monthly-batch
- dependency-name: org.apache.maven.plugins:maven-deploy-plugin
  dependency-version: 3.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: monthly-batch
- dependency-name: org.apache.maven.plugins:maven-install-plugin
  dependency-version: 3.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: monthly-batch
- dependency-name: org.apache.maven.plugins:maven-surefire-plugin
  dependency-version: 3.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: monthly-batch
- dependency-name: org.codehaus.mojo:exec-maven-plugin
  dependency-version: 3.6.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: monthly-batch
- dependency-name: org.codehaus.mojo:versions-maven-plugin
  dependency-version: 2.22.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: monthly-batch
- dependency-name: org.hjug.refactorfirst.plugin:refactor-first-maven-plugin
  dependency-version: 0.10.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: monthly-batch
- dependency-name: org.jreleaser:jreleaser-maven-plugin
  dependency-version: 1.26.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: monthly-batch
- dependency-name: io.vertx:vertx-core
  dependency-version: 5.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: monthly-batch
- dependency-name: org.apache.maven:apache-maven
  dependency-version: 3.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: monthly-batch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Oct 1, 2026
@sonarqubecloud

sonarqubecloud Bot commented Oct 1, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants