Skip to content

chore(deps): bump the gradle group across 1 directory with 12 updates - #1891

Open
dependabot[bot] wants to merge 37 commits into
developfrom
dependabot/gradle/gradle-4026e5dbd3
Open

chore(deps): bump the gradle group across 1 directory with 12 updates#1891
dependabot[bot] wants to merge 37 commits into
developfrom
dependabot/gradle/gradle-4026e5dbd3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 18, 2026

Copy link
Copy Markdown

Bumps the gradle group with 9 updates in the / directory:

Package From To
org.eclipse.jetty:jetty-http 11.0.24 12.0.33
com.fasterxml.jackson.core:jackson-core 2.9.5 2.18.6
org.apache.shiro:shiro-core 2.0.0 2.2.1
commons-io:commons-io 2.6 2.14.0
org.apache.commons:commons-lang3 3.4 3.18.0
com.hazelcast:hazelcast 3.9.3 5.2.5
org.apache.thrift:libthrift 0.10.0 0.23.0
org.apache.poi:poi-ooxml 3.17 5.4.0
org.apache.santuario:xmlsec 2.1.0 2.2.6

Updates org.eclipse.jetty:jetty-http from 11.0.24 to 12.0.33

Updates com.fasterxml.jackson.core:jackson-core from 2.9.5 to 2.18.6

Commits
  • 9a46ef8 [maven-release-plugin] prepare release jackson-core-2.18.6
  • 5f192db Prep for 2.18.6 release
  • b0c428e Enforce StreamReadConstraints.maxNumberLength for non-blocking (async) pars...
  • 7c8b6d5 Add test for nesting for DataInput-backed JsonParser (#1550)
  • 97a647b Update CI: JDK 23 -> 25
  • 1601331 (backport from 2.21) Fix #1548: validate max doc length for fixed buffer inpu...
  • fae2542 release notes update
  • 70c99ba Update UTF8DataInputJsonParser.java (#1512)
  • caea665 Post-release dep version bump
  • 635d3bd [maven-release-plugin] prepare for next development iteration
  • Additional commits viewable in compare view

Updates com.fasterxml.jackson.core:jackson-databind from 2.9.5 to 2.18.6

Commits

Updates org.apache.shiro:shiro-core from 2.0.0 to 2.2.1

Release notes

Sourced from org.apache.shiro:shiro-core's releases.

Apache Shiro 2.2.1

Bug fixes

Security Improvements

Improvements

New Contributors

Dependency Updates

Full Changelog: apache/shiro@shiro-root-2.2.0...shiro-root-2.2.1

... (truncated)

Changelog

Sourced from org.apache.shiro:shiro-core's changelog.

Licensed to the Apache Software Foundation (ASF) under one

or more contributor license agreements. See the NOTICE file

distributed with this work for additional information

regarding copyright ownership. The ASF licenses this file

to you under the Apache License, Version 2.0 (the

"License"); you may not use this file except in compliance

with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing,

software distributed under the License is distributed on an

"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY

KIND, either express or implied. See the License for the

specific language governing permissions and limitations

under the License.

DEPRECATED

Currently Apache Shiro uses GitHub releases for release notes, so this file is no longer being updated. It will be removed in a future release.

DEPRECATED

This is not an official release notes document. It exists for Shiro developers to jot down their notes while working in the source code. These notes will be combined with Jira’s auto-generated release notes during a release for the total set.

###########################################################

Commits
  • 9182c1d [maven-release-plugin] prepare release shiro-root-2.2.1
  • 744128d Deprecate RandomSessionIdGenerator due to insufficient entropy (#2770)
  • e384e9d chore(jacoco): added exclusion for weld client proxy (#2769)
  • eed8ab0 chore: update shiro.doap file with more recent versions and maintainers (#2768)
  • 0499524 chore(deps): bump bytebuddy.version from 1.18.8 to 1.18.10 (#2752)
  • bc928d0 Update and expand the CITATION file (#2766)
  • dd5d096 Configure EditorConfig for more file types (#2747)
  • 3b54e71 [CI] Pin to sha all pre-commit hooks and clean up (#2730)
  • 5da6b13 chore(deps): bump com.github.siom79.japicmp:japicmp-maven-plugin (#2751)
  • 169f55a chore(deps): bump org.jboss.shrinkwrap.resolver:shrinkwrap-resolver-bom (#2750)
  • Additional commits viewable in compare view

Updates org.apache.shiro:shiro-web from 2.0.0 to 2.2.1

Release notes

Sourced from org.apache.shiro:shiro-web's releases.

Apache Shiro 2.2.1

Bug fixes

Security Improvements

Improvements

New Contributors

Dependency Updates

Full Changelog: apache/shiro@shiro-root-2.2.0...shiro-root-2.2.1

... (truncated)

Changelog

Sourced from org.apache.shiro:shiro-web's changelog.

Licensed to the Apache Software Foundation (ASF) under one

or more contributor license agreements. See the NOTICE file

distributed with this work for additional information

regarding copyright ownership. The ASF licenses this file

to you under the Apache License, Version 2.0 (the

"License"); you may not use this file except in compliance

with the License. You may obtain a copy of the License at

http://www.apache.org/licenses/LICENSE-2.0

Unless required by applicable law or agreed to in writing,

software distributed under the License is distributed on an

"AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY

KIND, either express or implied. See the License for the

specific language governing permissions and limitations

under the License.

DEPRECATED

Currently Apache Shiro uses GitHub releases for release notes, so this file is no longer being updated. It will be removed in a future release.

DEPRECATED

This is not an official release notes document. It exists for Shiro developers to jot down their notes while working in the source code. These notes will be combined with Jira’s auto-generated release notes during a release for the total set.

###########################################################

Commits
  • 9182c1d [maven-release-plugin] prepare release shiro-root-2.2.1
  • 744128d Deprecate RandomSessionIdGenerator due to insufficient entropy (#2770)
  • e384e9d chore(jacoco): added exclusion for weld client proxy (#2769)
  • eed8ab0 chore: update shiro.doap file with more recent versions and maintainers (#2768)
  • 0499524 chore(deps): bump bytebuddy.version from 1.18.8 to 1.18.10 (#2752)
  • bc928d0 Update and expand the CITATION file (#2766)
  • dd5d096 Configure EditorConfig for more file types (#2747)
  • 3b54e71 [CI] Pin to sha all pre-commit hooks and clean up (#2730)
  • 5da6b13 chore(deps): bump com.github.siom79.japicmp:japicmp-maven-plugin (#2751)
  • 169f55a chore(deps): bump org.jboss.shrinkwrap.resolver:shrinkwrap-resolver-bom (#2750)
  • Additional commits viewable in compare view

Updates commons-io:commons-io from 2.6 to 2.14.0

Updates org.apache.commons:commons-lang3 from 3.4 to 3.18.0

Updates com.hazelcast:hazelcast from 3.9.3 to 5.2.5

Release notes

Sourced from com.hazelcast:hazelcast's releases.

v5.2.5

This document lists the enhancements and fixed issues for the Hazelcast Platform 5.2.5 release. The numbers in the square brackets refer to the issues and pull requests in Hazelcast's GitHub repository.

Enhancements

  • Improved the permission checks in the file connectors by adding a method that returns the permissions required to resolve field names. #25674
  • Updated the versions of following dependencies: ** Snappy to 1.1.10.5 ** gRPC to 1.59 ** Netty to 4.1.100.Final ** Elasticsearch to 7.17.13 ** Everit JSON Schema to 1.14.3 #24866, #25820, #25708, #25729, #25775

Fixes

  • Fixed an issue where the entry listeners for Replicated Maps were checking the Map permissions instead of the Replicated Map permissions. #25971
  • Fixed an issue where the map entries' metadata, such as time-to-live and expiration, was not replicated correctly over WAN after updating existing entries. #25506
  • Fixed an issue where there was a difference between the elapsed clock time and elapsed total time when listening to migration events. #25066
  • Fixed an issue where the member list was not updated after a cluster failover scenario. #24944
  • Renamed the service port for Hazelcast clusters deployed in Kubernetes environments to hazelcast. The previous name, hazelcast-service-port, caused member auto-discovery for embedded deployments to fail. #24841
  • Fixed an issue where Hazelcast was sending empty map interceptor information to the members that are newly joined to the cluster; it was causing eager map initializations. #24669

Removed/Deprecated Features

  • Removed the evaluation tool (for trying out Platform 5.x features for IMDG 3.x users) and the relevant IMDG 3.x JAR libraries from Hazelcast Platform distributions. #25697

Contributors

We would like to thank the contributors from our open source community who worked on this release:

v5.2.4

This document lists the enhancements and fixed issues for the Hazelcast Platform 5.2.4 release. The numbers in the square brackets refer to the issues and pull requests in Hazelcast's GitHub repository (github.com/hazelcast/hazelcast).

Enhancements

  • Updated the version of jackson-core dependency to 2.15.2. #24730
  • Hazelcast was sending requests to Kubernetes API when deploying an application with embedded Hazelcast and service-dns (DNS lookup mode) specified to a Kubernetes cluster. This was causing the requests to be unsuccessful and the application not to start. This mechanism has been improved by creating Kubernetes client only for the DNS lookup mode. #24045

Fixes

  • Fixed an issue where some of the members in a Hazelcast cluster deployed on Kubernetes (as a statefulset) shut down with en exception in a delayed manner. #24709
  • Fixed an issue where Jet job snapshots could be prematurely deleted after a restart of a cluster, having lossless restart enabled. #24576
  • Fixed an issue where the SELECT COUNT(DISTINCT COLUMN) query for maps was producing incorrect results. #24490
  • Fixed various issues in [Health Monitor] including incorrect metric names. #24634
  • Fixed an issue where the REST calls were failing for Hazelcast clusters with TLS v1.3 configured, and deployed on Kubernetes. #24624
  • Fixed an issue where SQL statements were failing when a class (to determine the fields of a key/value pair) no longer exists but the mapping is still valid. #24043

... (truncated)

Commits
  • 8b1bd72 Upgrade version to 5.2.5
  • c4f388d Adding OS RN for 5.2.5 (#827)
  • 0c3b54d Best-effort fix for merging metadata over WAN after merge rejection [5.2.5] (...
  • 1eec447 Extend permission checks in MessageTasks and add a test coverage [HZ-2090] [5...
  • e394e3d Fix K8s service port [CN-894] [5.2.5] (#797)
  • 06a10be [BACKPORT] Do not try to connect to the old member list after the cluster cha...
  • 1239695 Make MigrationListener timers use wall-clock not CPU time [5.2.5][HZ-2651][HZ...
  • 3939548 Correctly WAN replicate IMap metadata when updating existing records (#6514) ...
  • 6c471c1 Use MapContainer to filter maps to be cleaned up when migrating off a partiti...
  • 366fad9 Bump grpc to mitigate CVE-2023-44487 [5.2.5]
  • Additional commits viewable in compare view

Updates org.apache.thrift:libthrift from 0.10.0 to 0.23.0

Release notes

Sourced from org.apache.thrift:libthrift's releases.

Version 0.23.0

Please head over to the official release download source: http://thrift.apache.org/download

The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.

Version 0.22.0

Please head over to the official release download source: http://thrift.apache.org/download

The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.

Version 0.21.0

Please head over to the official release download source: http://thrift.apache.org/download

The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.

Version 0.20.0

Please head over to the official release download source: http://thrift.apache.org/download

The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.

Version 0.19.0

Please head over to the official release download source: http://thrift.apache.org/download

The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.

Version 0.18.1

Please head over to the official release download source: http://thrift.apache.org/download

The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.

Version 0.18.0

Please head over to the official release download source: http://thrift.apache.org/download

The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.

Version 0.17.0

Please head over to the official release download source: http://thrift.apache.org/download

The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.

Version 0.16.0

For release 0.16.0 head over to the official release download source:

... (truncated)

Changelog

Sourced from org.apache.thrift:libthrift's changelog.

0.23.0

Build Process

C glib

  • THRIFT-5931 - thrift_ssl_socket_get_ssl_error() can underflow its remaining-buffer counter and write past the stack buffer
  • THRIFT-5871 - Improve MAX_MESSAGE_SIZE check and friends

C++

  • THRIFT-5911 - Inconsistent UUID compilation for aliased types
  • THRIFT-5912 - Assertion failed: delta > 0, file ThreadManagerTests.h, line 162
  • THRIFT-5880 - C++ TSocket on an IPv6-only system fails if you use a hostname of 127.0.0.1
  • THRIFT-3268 - warning: token pasting of ',' and __VA_ARGS__ is a GNU extension
  • THRIFT-5887 - build/cmake/ should be prepended (not appended) to CMAKE_MODULE_PATH
  • THRIFT-5878 - Add UUID support for THeaderProtocol and TProtocolTap
  • THRIFT-5898 - Unable to build Thrift as a shared library on Windows

Contributed

  • THRIFT-5920 - Remove threadsafe warnings in thrift-maven-plugin

Delphi

  • THRIFT-5939 - Replace GUID generation with stable UUID algorithm
  • THRIFT-5876 - Add Delphi WinHTTP client TLS1.3 support

Go

  • THRIFT-5896 - Race condition in TServerSocket.Addr() method

Java

  • THRIFT-5925 - UUID implementation in JAVA is not according to the Thrift Specification
  • THRIFT-5869 - Close the transport after TServerEventHandler deleteContext
  • THRIFT-5863 - Make TServerTransport able to customize the max message size
  • THRIFT-5774 - Add remote client's IP address to ServerContext in TServerEventHandler
  • THRIFT-4280 - Add async nonblocking ssl support in java client
  • THRIFT-5879 - java and kotlin cross tests fail in the GitHub action

netstd

... (truncated)

Commits
  • e4b684f Updated CHANGES.md
  • c4cbe43 Address vulnerabilities in Rack
  • 68ac8e9 Enable TLS hostname verification in TNonblockingSSLSocket
  • 5e4f01d Harden Node.js WebSocket server handling
  • e242889 Add input validation to Swift protocol layer
  • 4af8c7c Add recursion depth limit to Node.js protocol skip()
  • a30c552 Enable TLS hostname verification in TSSLTransportFactory
  • 0f8ec9c Fix parent class resolution in c_glib generated dispatch_call
  • 276ec88 THRIFT-5929: Fix build failure on PHP 8.5 due to removed zend_exception_get_d...
  • 17f2c13 Added missing 0.23.0 JIRA tickets to CHANGES.md
  • Additional commits viewable in compare view

Updates org.apache.poi:poi-ooxml from 3.17 to 5.4.0

Updates org.apache.santuario:xmlsec from 2.1.0 to 2.2.6

Updates org.bouncycastle:bcpkix-jdk15on from 1.58 to 1.70

Changelog

Sourced from org.bouncycastle:bcpkix-jdk15on's changelog.

2.2.1 Version Release: 1.85 Date:      2026, July 12th

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

poorva1209 and others added 30 commits April 16, 2021 09:55
poorva1209 and others added 7 commits October 1, 2025 12:46
Bumps the gradle group with 9 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| org.eclipse.jetty:jetty-http | `11.0.24` | `12.0.33` |
| [com.fasterxml.jackson.core:jackson-core](https://github.com/FasterXML/jackson-core) | `2.9.5` | `2.18.6` |
| [org.apache.shiro:shiro-core](https://github.com/apache/shiro) | `2.0.0` | `2.2.1` |
| commons-io:commons-io | `2.6` | `2.14.0` |
| org.apache.commons:commons-lang3 | `3.4` | `3.18.0` |
| [com.hazelcast:hazelcast](https://github.com/hazelcast/hazelcast) | `3.9.3` | `5.2.5` |
| [org.apache.thrift:libthrift](https://github.com/apache/thrift) | `0.10.0` | `0.23.0` |
| org.apache.poi:poi-ooxml | `3.17` | `5.4.0` |
| org.apache.santuario:xmlsec | `2.1.0` | `2.2.6` |



Updates `org.eclipse.jetty:jetty-http` from 11.0.24 to 12.0.33

Updates `com.fasterxml.jackson.core:jackson-core` from 2.9.5 to 2.18.6
- [Commits](FasterXML/jackson-core@jackson-core-2.9.5...jackson-core-2.18.6)

Updates `com.fasterxml.jackson.core:jackson-databind` from 2.9.5 to 2.18.6
- [Commits](https://github.com/FasterXML/jackson/commits)

Updates `org.apache.shiro:shiro-core` from 2.0.0 to 2.2.1
- [Release notes](https://github.com/apache/shiro/releases)
- [Changelog](https://github.com/apache/shiro/blob/main/RELEASE-NOTES)
- [Commits](apache/shiro@shiro-root-2.0.0...shiro-root-2.2.1)

Updates `org.apache.shiro:shiro-web` from 2.0.0 to 2.2.1
- [Release notes](https://github.com/apache/shiro/releases)
- [Changelog](https://github.com/apache/shiro/blob/main/RELEASE-NOTES)
- [Commits](apache/shiro@shiro-root-2.0.0...shiro-root-2.2.1)

Updates `commons-io:commons-io` from 2.6 to 2.14.0

Updates `org.apache.commons:commons-lang3` from 3.4 to 3.18.0

Updates `com.hazelcast:hazelcast` from 3.9.3 to 5.2.5
- [Release notes](https://github.com/hazelcast/hazelcast/releases)
- [Commits](hazelcast/hazelcast@v3.9.3...v5.2.5)

Updates `org.apache.thrift:libthrift` from 0.10.0 to 0.23.0
- [Release notes](https://github.com/apache/thrift/releases)
- [Changelog](https://github.com/apache/thrift/blob/master/CHANGES.md)
- [Commits](apache/thrift@0.10.0...v0.23.0)

Updates `org.apache.poi:poi-ooxml` from 3.17 to 5.4.0

Updates `org.apache.santuario:xmlsec` from 2.1.0 to 2.2.6

Updates `org.bouncycastle:bcpkix-jdk15on` from 1.58 to 1.70
- [Changelog](https://github.com/bcgit/bc-java/blob/main/docs/releasenotes.html)
- [Commits](https://github.com/bcgit/bc-java/commits)

---
updated-dependencies:
- dependency-name: org.eclipse.jetty:jetty-http
  dependency-version: 12.0.33
  dependency-type: direct:production
  dependency-group: gradle
- dependency-name: com.fasterxml.jackson.core:jackson-core
  dependency-version: 2.18.6
  dependency-type: direct:production
  dependency-group: gradle
- dependency-name: com.fasterxml.jackson.core:jackson-databind
  dependency-version: 2.18.6
  dependency-type: direct:production
  dependency-group: gradle
- dependency-name: org.apache.shiro:shiro-core
  dependency-version: 2.2.1
  dependency-type: direct:production
  dependency-group: gradle
- dependency-name: org.apache.shiro:shiro-web
  dependency-version: 2.2.1
  dependency-type: direct:production
  dependency-group: gradle
- dependency-name: commons-io:commons-io
  dependency-version: 2.14.0
  dependency-type: direct:production
  dependency-group: gradle
- dependency-name: org.apache.commons:commons-lang3
  dependency-version: 3.18.0
  dependency-type: direct:production
  dependency-group: gradle
- dependency-name: com.hazelcast:hazelcast
  dependency-version: 5.2.5
  dependency-type: direct:production
  dependency-group: gradle
- dependency-name: org.apache.thrift:libthrift
  dependency-version: 0.23.0
  dependency-type: direct:production
  dependency-group: gradle
- dependency-name: org.apache.poi:poi-ooxml
  dependency-version: 5.4.0
  dependency-type: direct:production
  dependency-group: gradle
- dependency-name: org.apache.santuario:xmlsec
  dependency-version: 2.2.6
  dependency-type: direct:production
  dependency-group: gradle
- dependency-name: org.bouncycastle:bcpkix-jdk15on
  dependency-version: '1.70'
  dependency-type: direct:production
  dependency-group: gradle
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Jul 18, 2026
@craigpnnl
craigpnnl changed the base branch from master to develop July 18, 2026 10:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants