chore(deps): bump the gradle group across 1 directory with 12 updates - #1891
Open
dependabot[bot] wants to merge 37 commits into
Open
chore(deps): bump the gradle group across 1 directory with 12 updates#1891dependabot[bot] wants to merge 37 commits into
dependabot[bot] wants to merge 37 commits into
Conversation
Stomp version
Release of version 2021.03.0
Release of version 2021.04.0
Release of version 2021.08.1
Releases/2021.08.1
Release of version 2021.09.0
Release of version 2021.11.0
Release of version 2021.12.0
Release of version 2022.01.0
Release of version 2022.03.0
releases/2022.03.0
Releases/2022.03.0
Release of version 2022.04.0
releases/2022.04.0
Releases/2022.04.0
Release of version 2022.08.0
Release of version 2022.10.0
Release of version 2022.12.0
Update topology-processor
Release of version 2023.01.0
Release of version 2023.03.0
Release of version 2023.05.0
Release of version 2023.07.0
Release of version 2024.06.0
Release of version 2025.01.0
Release of version 2025.06.0
Release of version 2025.09.0
Release of version 2026.02.0
Releases/2026.02.1
docs: add security policy
Bumps the gradle group with 9 updates in the / directory: | Package | From | To | | --- | --- | --- | | org.eclipse.jetty:jetty-http | `11.0.24` | `12.0.33` | | [com.fasterxml.jackson.core:jackson-core](https://github.com/FasterXML/jackson-core) | `2.9.5` | `2.18.6` | | [org.apache.shiro:shiro-core](https://github.com/apache/shiro) | `2.0.0` | `2.2.1` | | commons-io:commons-io | `2.6` | `2.14.0` | | org.apache.commons:commons-lang3 | `3.4` | `3.18.0` | | [com.hazelcast:hazelcast](https://github.com/hazelcast/hazelcast) | `3.9.3` | `5.2.5` | | [org.apache.thrift:libthrift](https://github.com/apache/thrift) | `0.10.0` | `0.23.0` | | org.apache.poi:poi-ooxml | `3.17` | `5.4.0` | | org.apache.santuario:xmlsec | `2.1.0` | `2.2.6` | Updates `org.eclipse.jetty:jetty-http` from 11.0.24 to 12.0.33 Updates `com.fasterxml.jackson.core:jackson-core` from 2.9.5 to 2.18.6 - [Commits](FasterXML/jackson-core@jackson-core-2.9.5...jackson-core-2.18.6) Updates `com.fasterxml.jackson.core:jackson-databind` from 2.9.5 to 2.18.6 - [Commits](https://github.com/FasterXML/jackson/commits) Updates `org.apache.shiro:shiro-core` from 2.0.0 to 2.2.1 - [Release notes](https://github.com/apache/shiro/releases) - [Changelog](https://github.com/apache/shiro/blob/main/RELEASE-NOTES) - [Commits](apache/shiro@shiro-root-2.0.0...shiro-root-2.2.1) Updates `org.apache.shiro:shiro-web` from 2.0.0 to 2.2.1 - [Release notes](https://github.com/apache/shiro/releases) - [Changelog](https://github.com/apache/shiro/blob/main/RELEASE-NOTES) - [Commits](apache/shiro@shiro-root-2.0.0...shiro-root-2.2.1) Updates `commons-io:commons-io` from 2.6 to 2.14.0 Updates `org.apache.commons:commons-lang3` from 3.4 to 3.18.0 Updates `com.hazelcast:hazelcast` from 3.9.3 to 5.2.5 - [Release notes](https://github.com/hazelcast/hazelcast/releases) - [Commits](hazelcast/hazelcast@v3.9.3...v5.2.5) Updates `org.apache.thrift:libthrift` from 0.10.0 to 0.23.0 - [Release notes](https://github.com/apache/thrift/releases) - [Changelog](https://github.com/apache/thrift/blob/master/CHANGES.md) - [Commits](apache/thrift@0.10.0...v0.23.0) Updates `org.apache.poi:poi-ooxml` from 3.17 to 5.4.0 Updates `org.apache.santuario:xmlsec` from 2.1.0 to 2.2.6 Updates `org.bouncycastle:bcpkix-jdk15on` from 1.58 to 1.70 - [Changelog](https://github.com/bcgit/bc-java/blob/main/docs/releasenotes.html) - [Commits](https://github.com/bcgit/bc-java/commits) --- updated-dependencies: - dependency-name: org.eclipse.jetty:jetty-http dependency-version: 12.0.33 dependency-type: direct:production dependency-group: gradle - dependency-name: com.fasterxml.jackson.core:jackson-core dependency-version: 2.18.6 dependency-type: direct:production dependency-group: gradle - dependency-name: com.fasterxml.jackson.core:jackson-databind dependency-version: 2.18.6 dependency-type: direct:production dependency-group: gradle - dependency-name: org.apache.shiro:shiro-core dependency-version: 2.2.1 dependency-type: direct:production dependency-group: gradle - dependency-name: org.apache.shiro:shiro-web dependency-version: 2.2.1 dependency-type: direct:production dependency-group: gradle - dependency-name: commons-io:commons-io dependency-version: 2.14.0 dependency-type: direct:production dependency-group: gradle - dependency-name: org.apache.commons:commons-lang3 dependency-version: 3.18.0 dependency-type: direct:production dependency-group: gradle - dependency-name: com.hazelcast:hazelcast dependency-version: 5.2.5 dependency-type: direct:production dependency-group: gradle - dependency-name: org.apache.thrift:libthrift dependency-version: 0.23.0 dependency-type: direct:production dependency-group: gradle - dependency-name: org.apache.poi:poi-ooxml dependency-version: 5.4.0 dependency-type: direct:production dependency-group: gradle - dependency-name: org.apache.santuario:xmlsec dependency-version: 2.2.6 dependency-type: direct:production dependency-group: gradle - dependency-name: org.bouncycastle:bcpkix-jdk15on dependency-version: '1.70' dependency-type: direct:production dependency-group: gradle ... Signed-off-by: dependabot[bot] <support@github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the gradle group with 9 updates in the / directory:
11.0.2412.0.332.9.52.18.62.0.02.2.12.62.14.03.43.18.03.9.35.2.50.10.00.23.03.175.4.02.1.02.2.6Updates
org.eclipse.jetty:jetty-httpfrom 11.0.24 to 12.0.33Updates
com.fasterxml.jackson.core:jackson-corefrom 2.9.5 to 2.18.6Commits
9a46ef8[maven-release-plugin] prepare release jackson-core-2.18.65f192dbPrep for 2.18.6 releaseb0c428eEnforceStreamReadConstraints.maxNumberLengthfor non-blocking (async) pars...7c8b6d5Add test for nesting forDataInput-backedJsonParser(#1550)97a647bUpdate CI: JDK 23 -> 251601331(backport from 2.21) Fix #1548: validate max doc length for fixed buffer inpu...fae2542release notes update70c99baUpdate UTF8DataInputJsonParser.java (#1512)caea665Post-release dep version bump635d3bd[maven-release-plugin] prepare for next development iterationUpdates
com.fasterxml.jackson.core:jackson-databindfrom 2.9.5 to 2.18.6Commits
Updates
org.apache.shiro:shiro-corefrom 2.0.0 to 2.2.1Release notes
Sourced from org.apache.shiro:shiro-core's releases.
... (truncated)
Changelog
Sourced from org.apache.shiro:shiro-core's changelog.
Commits
9182c1d[maven-release-plugin] prepare release shiro-root-2.2.1744128dDeprecate RandomSessionIdGenerator due to insufficient entropy (#2770)e384e9dchore(jacoco): added exclusion for weld client proxy (#2769)eed8ab0chore: update shiro.doap file with more recent versions and maintainers (#2768)0499524chore(deps): bump bytebuddy.version from 1.18.8 to 1.18.10 (#2752)bc928d0Update and expand the CITATION file (#2766)dd5d096Configure EditorConfig for more file types (#2747)3b54e71[CI] Pin to sha all pre-commit hooks and clean up (#2730)5da6b13chore(deps): bump com.github.siom79.japicmp:japicmp-maven-plugin (#2751)169f55achore(deps): bump org.jboss.shrinkwrap.resolver:shrinkwrap-resolver-bom (#2750)Updates
org.apache.shiro:shiro-webfrom 2.0.0 to 2.2.1Release notes
Sourced from org.apache.shiro:shiro-web's releases.
... (truncated)
Changelog
Sourced from org.apache.shiro:shiro-web's changelog.
Commits
9182c1d[maven-release-plugin] prepare release shiro-root-2.2.1744128dDeprecate RandomSessionIdGenerator due to insufficient entropy (#2770)e384e9dchore(jacoco): added exclusion for weld client proxy (#2769)eed8ab0chore: update shiro.doap file with more recent versions and maintainers (#2768)0499524chore(deps): bump bytebuddy.version from 1.18.8 to 1.18.10 (#2752)bc928d0Update and expand the CITATION file (#2766)dd5d096Configure EditorConfig for more file types (#2747)3b54e71[CI] Pin to sha all pre-commit hooks and clean up (#2730)5da6b13chore(deps): bump com.github.siom79.japicmp:japicmp-maven-plugin (#2751)169f55achore(deps): bump org.jboss.shrinkwrap.resolver:shrinkwrap-resolver-bom (#2750)Updates
commons-io:commons-iofrom 2.6 to 2.14.0Updates
org.apache.commons:commons-lang3from 3.4 to 3.18.0Updates
com.hazelcast:hazelcastfrom 3.9.3 to 5.2.5Release notes
Sourced from com.hazelcast:hazelcast's releases.
... (truncated)
Commits
8b1bd72Upgrade version to 5.2.5c4f388dAdding OS RN for 5.2.5 (#827)0c3b54dBest-effort fix for merging metadata over WAN after merge rejection [5.2.5] (...1eec447Extend permission checks in MessageTasks and add a test coverage [HZ-2090] [5...e394e3dFix K8s service port [CN-894] [5.2.5] (#797)06a10be[BACKPORT] Do not try to connect to the old member list after the cluster cha...1239695Make MigrationListener timers use wall-clock not CPU time [5.2.5][HZ-2651][HZ...3939548Correctly WAN replicate IMap metadata when updating existing records (#6514) ...6c471c1Use MapContainer to filter maps to be cleaned up when migrating off a partiti...366fad9Bumpgrpcto mitigate CVE-2023-44487 [5.2.5]Updates
org.apache.thrift:libthriftfrom 0.10.0 to 0.23.0Release notes
Sourced from org.apache.thrift:libthrift's releases.
... (truncated)
Changelog
Sourced from org.apache.thrift:libthrift's changelog.
... (truncated)
Commits
e4b684fUpdated CHANGES.mdc4cbe43Address vulnerabilities in Rack68ac8e9Enable TLS hostname verification in TNonblockingSSLSocket5e4f01dHarden Node.js WebSocket server handlinge242889Add input validation to Swift protocol layer4af8c7cAdd recursion depth limit to Node.js protocol skip()a30c552Enable TLS hostname verification in TSSLTransportFactory0f8ec9cFix parent class resolution in c_glib generated dispatch_call276ec88THRIFT-5929: Fix build failure on PHP 8.5 due to removed zend_exception_get_d...17f2c13Added missing 0.23.0 JIRA tickets to CHANGES.mdUpdates
org.apache.poi:poi-ooxmlfrom 3.17 to 5.4.0Updates
org.apache.santuario:xmlsecfrom 2.1.0 to 2.2.6Updates
org.bouncycastle:bcpkix-jdk15onfrom 1.58 to 1.70Changelog
Sourced from org.bouncycastle:bcpkix-jdk15on's changelog.
... (truncated)
Commits
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditionsYou can disable automated security fix PRs for this repo from the Security Alerts page.