fix(deps): update dependency org.jsoup:jsoup to v1.23.2 - #723
Open
renovate[bot] wants to merge 1 commit into
Open
fix(deps): update dependency org.jsoup:jsoup to v1.23.2#723renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
renovate
Bot
force-pushed
the
renovate/jsoup
branch
from
July 30, 2026 05:40
dc5a74e to
daf7b12
Compare
renovate
Bot
force-pushed
the
renovate/jsoup
branch
from
August 26, 2026 03:26
daf7b12 to
2d9d1f3
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.22.1→1.23.2Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
jhy/jsoup (org.jsoup:jsoup)
v1.23.2Improvements
StreamParser.selectFirst(...)calls during progressive parsing, so later matches are returned with their parsed contents when earlier selections had left them as parser lookahead. E.g., given<title>One</title><p id=hit>Full</p><p>Next</p>, selectingtitleand then#hitnow advances the partial lookahead and returns<p id="hit">Full</p>, rather than returning an empty<p id="hit"></p>before its content is parsed. The updated readiness tracking follows StreamParser's normal emission order across implicit HTML structure and parser recovery. #2551W3CDomconversion performance for documents with many nested namespace declarations. The W3C converter now uses the same optimized namespace tracking as the XML parser. #2559W3CDomXML conversion to retain processing instructions, comments outside the root element, and CDATA sections, which were previously dropped or converted to text. #2572Elements#before(Node),after(Node),prepend(Node), andappend(Node)to match the existing HTML string methods. #953Connection.requestBodyStream(InputStream)now stream directly with the JDKHttpClienton Java 11+, rather than being loaded fully into memory first. #2575Jsoup.newSession()to ordinaryJsoup.connect(...)calls, reducing transport thread and connection setup churn under sustained request loads. Sessions with custom authentication or SSL contexts continue to use their own client. #2584Changes
Parser#setMaxDepth(int)to configure. #2570Bug Fixes
W3CDomnamespace conversion in several cases: #2559a:b:c, are normalized. Attributes that still cannot be represented are skipped, and unrepresentable elements no longer change the surrounding tree.W3CDomconversion of programmatically created or renamed elements whose names can be represented in a jsoup HTML DOM but are not valid XML names, such as1abc. These names are now normalized (e.g._1abc) instead of causing aNullPointerException. #2560nullelements or dropping attributes. For example, an attribute named1ais written as_1a. Additional leading underscores keep repaired attribute names unique if they conflict with another attribute. #2573HttpClientimplementation to accept responses missing aContent-Typeheader, matching theHttpURLConnectionimplementation. #2549+xmlsuffixes, including vendor-specific media types. #2550ValidationException. #2555</body>remain children of thehtmlelement, while comments after</html>remain children of the document. #2557re2jregular expression engine, memory allocation errors caused by complex selector patterns at match time are now normalized to aValidationExceptionwith aPattern complexity errormessage.title/textareacontent stays text through EOF, and custom text tags match exact names. #2577</template>tags without throwing aValidationException. #2581v1.23.1Improvements
Parser#setTrackPosition(true)). Source ranges are now stored in compact parser-owned span records instead of node and attribute user data, andPositionobjects are created lazily when source ranges are read. This cuts tracked DOM retained size by about 50-60% on representative benchmark documents, while keepingNode#sourceRange(),Element#endSourceRange(), andAttribute#sourceRange()behavior intact. #2498Element#classList(), an immutable snapshot of an element's class names in attribute order. UsehasClass()when you just need to test for one class,classList()when you want to read or iterate classes without needing a mutable result, andclassNames()when you want the existing mutable, deduplicated set that can be written back withclassNames(Set). The class APIs now share an HTML-whitespace scanner, which also makesclassNames()faster and lighter on allocation, especially when walking many elements without class names. #2500select,foreignObject, andtemplate. #2501<noscript>fallback markup is now parsed into an inspectable DOM subtree in both the document head and body. The fallback acts as a contained parsing island, so malformed markup cannot disrupt the surrounding document structure, while normal HTML tokenization still applies within it. This also improves round-trip serialization. #2537CookieStorecontinue to follow their configured scope. #2540AppendablewithNode#outerHtml(Appendable), without first creating aString. This complementsElement#html(Appendable), which appends inner HTML only. #2532re2jregular expression engine, stack overflows caused by complex selector patterns are now normalized to aValidationExceptionwith aPattern complexity errormessage. #2548Bug Fixes
<title><p>Foo</TiTLE>and<textarea><img src=x></TeXtArEa>now keep the tag-shaped content as text instead of promoting it to markup. #2503W3CDomXML conversion so plain XML elements don't serialize with the reserved XML namespace as the default namespace. Explicit XML namespaces andxml:*attributes are still preserved. #2504Locationis followed only for 301, 302, 303, 307, and 308 responses. Streamed request bodies are not buffered; if an automatic redirect requires replaying one, execution fails, so the caller can resend with a fresh stream. #2540rel=nofollow. #2543Build Changes
mvn clean verifydrops from ~ 1m18s to ~ 21 seconds.v1.22.2Improvements
NodeTraversorsupport for in-place DOM rewrites duringNodeVisitor.head(). Current-node edits such asremove,replace, andunwrapnow recover more predictably, while traversal stays within the original root subtree. This makes single-pass tree cleanup and normalization visitors easier to write, for example when unwrapping presentational elements or replacing text nodes as you walk the DOM. #2472Cleanermay be reused across concurrent threads, and that sharedSafelistinstances should not be mutated while in use. #2473TagSetfor current HTML elements: addeddialog,search,picture, andslot; madeins,del,button,audio,video, andcanvasinline by default (Tag#isInline(), aligned to phrasing content in the spec); and added readableElement.text()boundaries for controls and embedded objects via the newTag.TextBoundaryoption. This improves pretty-printing and keeps normalized text from running adjacent words together. #2493Bug Fixes
re2jdependency when not present. #2459NodeTraversorregression in 1.21.2 where removing or replacing the current node duringhead()could revisit the replacement node and loop indefinitely. The traversal docs now also clarify which inserted nodes are visited in the current pass. #2472available()call throwsIOException, as seen on JDK 8HttpURLConnection. #2474Cleanerno longer makes relative URL attributes in the input document absolute when cleaning or validating aDocument. URL normalization now applies only to the cleaned output, andSafelist.isSafeAttribute()is side effect free. #2475Cleanerno longer duplicates enforced attributes when the inputDocumentpreserves attribute case. A case-variant source attribute is now replaced by the enforced attribute in the cleaned output. #2476HttpClient, because the JDK would silently ignore that proxy and attempt to connect directly. Those requests now fall back to the legacyHttpURLConnectiontransport instead, which does support SOCKS. #2468Connection.Response.streamParser()andDataUtil.streamParser(Path, ...)could fail on small inputs without a declared charset, if the initial 5 KB charset sniff fully consumed the input and closed it before the stream parse began. #2483<!DOCTYPE root [<!ENTITY name "value">]>, now round-trip correctly. The subset is preserved as raw text only; entities are not expanded and external DTDs are not loaded. #2486Build Changes
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.