Skip to content

chore(deps): bump the maven-minor group across 1 directory with 13 updates#639

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/maven-minor-94fc7ea36a
Open

chore(deps): bump the maven-minor group across 1 directory with 13 updates#639
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/maven-minor-94fc7ea36a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown
Contributor

Bumps the maven-minor group with 13 updates in the / directory:

Package From To
org.junit:junit-bom 6.1.1 6.1.2
org.omnifaces:omnifaces 5.3.4 5.4.1
org.primefaces:primefaces 15.0.16 15.0.17
com.twelvemonkeys.servlet:servlet 3.13.1 3.14.0
com.twelvemonkeys.imageio:imageio-bmp 3.13.1 3.14.0
com.twelvemonkeys.imageio:imageio-jpeg 3.13.1 3.14.0
com.twelvemonkeys.imageio:imageio-tiff 3.13.1 3.14.0
com.twelvemonkeys.imageio:imageio-hdr 3.13.1 3.14.0
com.twelvemonkeys.imageio:imageio-webp 3.13.1 3.14.0
io.sentry:sentry-log4j2 8.47.0 8.49.0
org.eclipse.jetty.ee11:jetty-ee11-cdi 12.1.10 12.1.11
org.eclipse.jetty.ee11:jetty-ee11-maven-plugin 12.1.10 12.1.11
com.github.spotbugs:spotbugs-maven-plugin 4.10.2.0 4.10.3.0

Updates org.junit:junit-bom from 6.1.1 to 6.1.2

Release notes

Sourced from org.junit:junit-bom's releases.

JUnit 6.1.2 = Platform 6.1.2 + Jupiter 6.1.2 + Vintage 6.1.2

See Release Notes.

Full Changelog: junit-team/junit-framework@r6.1.1...r6.1.2

Commits
  • b685426 Release 6.1.2
  • ae244a6 Remove blanket outputDirectoryCreator from SuiteEngineTests (#5793)
  • 43bd154 Finalize 6.1.2 release notes
  • 0cd9510 Fix order of release note sections
  • a1507cb Add initial 6.1.2 release notes to release notes index
  • 9326641 Fix NoTestsDiscoveredException for suites containing only dynamic tests (#5839)
  • 2ef1123 Create initial 6.1.2 release notes from template
  • 83fa9ab Back to snapshots for further development
  • See full diff in compare view

Updates org.omnifaces:omnifaces from 5.3.4 to 5.4.1

Commits
  • e29f658 Prepare 5.4.1 release
  • c654a96 Cache collected select items per phase in SelectItemsConverter
  • 78eb8c7 Concatenate select-item converter attribute keys instead of String.format
  • e64345d Make ViewScopeStorageInSession.ActiveBeanStorages public
  • c7e1166 Cache OutputFormat capture keys instead of rebuilding per render
  • 990e6e8 Reuse the ResourceIdentifier key in CDNResourceHandler.decorateResource
  • 27ba40f Promote replaceFirstLiteral to Utils and drop per-call regex in resource hand...
  • 3ba5a3b Reuse a shared whitespace Pattern instead of split("\s+") per call
  • 17b0309 Avoid per-phase set allocation in CallbackPhaseListener
  • e3a44bc Rebuild o:tree node map once per render instead of per model node
  • Additional commits viewable in compare view

Updates org.primefaces:primefaces from 15.0.16 to 15.0.17

Release notes

Sourced from org.primefaces:primefaces's releases.

15.0.17

What's Changed

New Contributors

Full Changelog: primefaces/primefaces@v15.0.16...v15.0.17

Commits

Updates com.twelvemonkeys.servlet:servlet from 3.13.1 to 3.14.0

Release notes

Sourced from com.twelvemonkeys.servlet:servlet's releases.

TwelveMonkeys ImageIO 3.14.0 release notes

Introduces memory allocation guards, to avoid OOME situations.

What's Changed

New Contributors

Full Changelog: haraldk/TwelveMonkeys@twelvemonkeys-3.13.1...twelvemonkeys-3.14.0

Commits
  • 62f6e2f [maven-release-plugin] prepare release twelvemonkeys-3.14.0
  • 157a26c #1265: VP8Frame clean-up
  • f6bbfe4 #1278: common-image unit test clean-up
  • 94a2a46 Add common-image unit tests (#1278)
  • fd923d5 Avoid full-frame VP8 macroblock allocation for subsampled WebP reads (#1265)
  • cc9af05 Bump org.apache.maven.plugins:maven-help-plugin from 3.5.1 to 3.5.2
  • f4d813c Bump actions/setup-java from 5.3.0 to 5.4.0 in /.github/workflows
  • 7f209dc refactor(imageio): address review on destination allocation guard
  • d24bc14 fix(imageio): guard against unbounded allocation from declared dimensions
  • 942a1eb Bump mikepenz/action-junit-report in /.github/workflows
  • Additional commits viewable in compare view

Updates com.twelvemonkeys.imageio:imageio-bmp from 3.13.1 to 3.14.0

Updates com.twelvemonkeys.imageio:imageio-jpeg from 3.13.1 to 3.14.0

Updates com.twelvemonkeys.imageio:imageio-tiff from 3.13.1 to 3.14.0

Updates com.twelvemonkeys.imageio:imageio-hdr from 3.13.1 to 3.14.0

Updates com.twelvemonkeys.imageio:imageio-webp from 3.13.1 to 3.14.0

Updates com.twelvemonkeys.imageio:imageio-bmp from 3.13.1 to 3.14.0

Updates com.twelvemonkeys.imageio:imageio-jpeg from 3.13.1 to 3.14.0

Updates com.twelvemonkeys.imageio:imageio-tiff from 3.13.1 to 3.14.0

Updates com.twelvemonkeys.imageio:imageio-hdr from 3.13.1 to 3.14.0

Updates com.twelvemonkeys.imageio:imageio-webp from 3.13.1 to 3.14.0

Updates io.sentry:sentry-log4j2 from 8.47.0 to 8.49.0

Release notes

Sourced from io.sentry:sentry-log4j2's releases.

8.49.0

Features

  • Session Replay: Record segment names (transaction names) (#5763)

  • Add io.sentry:sentry-opentelemetry-bom to align Sentry OpenTelemetry modules with tested OpenTelemetry dependencies (#5629)

    • Spring Boot Gradle plugin: add the Sentry BOM to dependencyManagement; explicit imports are applied after Spring Boot's implicit BOM
      dependencyManagement {
        imports {
          mavenBom("io.sentry:sentry-opentelemetry-bom:<sentry-version>")
        }
      }
    • Gradle: import it as a platform and omit versions from Sentry OpenTelemetry and OpenTelemetry dependencies
      implementation(platform("io.sentry:sentry-opentelemetry-bom:<sentry-version>"))
    • Maven: import it before Spring Boot's BOM in the same <dependencyManagement> block, or in the child POM when using spring-boot-starter-parent
      <dependency>
        <groupId>io.sentry</groupId>
        <artifactId>sentry-opentelemetry-bom</artifactId>
        <version>${sentry.version}</version>
        <type>pom</type>
        <scope>import</scope>
      </dependency>

Fixes

  • Session Replay: Fix first recording segment missing for replays in buffer mode (#5753)
  • Session Replay: Fix error-to-replay linkage in buffer mode (#5754)
  • Prevent logs and metrics from remaining queued after a flush scheduling race (#5756)
  • Fix main thread identification for tombstone (native crash) events (#5742)
  • Prevent malformed JDBC URLs, which may contain credentials, from being printed to stdout (#5656)
  • Restrict JVM-global proxy authentication credentials to challenges from the configured proxy host (#5656)
  • Sanitize Spring 7 and Spring Jakarta WebClient span descriptions to prevent embedded URL credentials from being sent to Sentry (#5656)
  • Respect tracePropagationTargets when injecting Sentry tracing headers through the OpenTelemetry OTLP propagator (#5656)

Performance

  • Schedule transaction idle/deadline timeouts on a shared, dedicated executor instead of spawning a Timer thread per transaction (#5670)

Dependencies

  • Bump OpenTelemetry to support Spring Boot 4.1 (#5573)
    • If this causes issues for you because you are also using Spring Boot Dependency Management Plugin (io.spring.dependency-management), which may downgrade the OpenTelemetry SDK, please have a look at the changelog entry above that explains how to use sentry-opentelemetry-bom.
    • OpenTelemetry to 1.63.0 (was 1.60.1)

... (truncated)

Changelog

Sourced from io.sentry:sentry-log4j2's changelog.

8.49.0

Features

  • Session Replay: Record segment names (transaction names) (#5763)

  • Add io.sentry:sentry-opentelemetry-bom to align Sentry OpenTelemetry modules with tested OpenTelemetry dependencies (#5629)

    • Spring Boot Gradle plugin: add the Sentry BOM to dependencyManagement; explicit imports are applied after Spring Boot's implicit BOM
      dependencyManagement {
        imports {
          mavenBom("io.sentry:sentry-opentelemetry-bom:<sentry-version>")
        }
      }
    • Gradle: import it as a platform and omit versions from Sentry OpenTelemetry and OpenTelemetry dependencies
      implementation(platform("io.sentry:sentry-opentelemetry-bom:<sentry-version>"))
    • Maven: import it before Spring Boot's BOM in the same <dependencyManagement> block, or in the child POM when using spring-boot-starter-parent
      <dependency>
        <groupId>io.sentry</groupId>
        <artifactId>sentry-opentelemetry-bom</artifactId>
        <version>${sentry.version}</version>
        <type>pom</type>
        <scope>import</scope>
      </dependency>

Fixes

  • Session Replay: Fix first recording segment missing for replays in buffer mode (#5753)
  • Session Replay: Fix error-to-replay linkage in buffer mode (#5754)
  • Prevent logs and metrics from remaining queued after a flush scheduling race (#5756)
  • Fix main thread identification for tombstone (native crash) events (#5742)
  • Prevent malformed JDBC URLs, which may contain credentials, from being printed to stdout (#5656)
  • Restrict JVM-global proxy authentication credentials to challenges from the configured proxy host (#5656)
  • Sanitize Spring 7 and Spring Jakarta WebClient span descriptions to prevent embedded URL credentials from being sent to Sentry (#5656)
  • Respect tracePropagationTargets when injecting Sentry tracing headers through the OpenTelemetry OTLP propagator (#5656)

Performance

  • Schedule transaction idle/deadline timeouts on a shared, dedicated executor instead of spawning a Timer thread per transaction (#5670)

Dependencies

  • Bump OpenTelemetry to support Spring Boot 4.1 (#5573)
    • If this causes issues for you because you are also using Spring Boot Dependency Management Plugin (io.spring.dependency-management), which may downgrade the OpenTelemetry SDK, please have a look at the changelog entry above that explains how to use sentry-opentelemetry-bom.

... (truncated)

Commits
  • 53ff471 release: 8.49.0
  • 6424ca9 Use the same method to get url in all spring filters (#5656)
  • 955d0fc fix(samples): Use float literal for session-replay sample rate (#5764)
  • 0b8ad15 feat(samples): Enable Sentry Logs in the Android sample app (#5766)
  • a212e8f feat(replay): Record segment names (transaction names) (#5763)
  • bcd3e76 perf: Avoid per-transaction Timer thread in SentryTracer (JAVA-596) (#5670)
  • dd1eb0c build: Bump Spotless to 8.8.0 (#5720)
  • c971c04 build: Add Java 8 API compatibility checks (#5745)
  • c94d7ba fix(core): Inject replayId into trace context for buffer mode errors (#5754)
  • 31c558e fix(replay): Preserve segment ID after buffer-to-session conversion (#5753)
  • Additional commits viewable in compare view

Updates org.eclipse.jetty.ee11:jetty-ee11-cdi from 12.1.10 to 12.1.11

Updates org.eclipse.jetty.ee11:jetty-ee11-maven-plugin from 12.1.10 to 12.1.11

Updates com.github.spotbugs:spotbugs-maven-plugin from 4.10.2.0 to 4.10.3.0

Release notes

Sourced from com.github.spotbugs:spotbugs-maven-plugin's releases.

Spotbugs Maven Plugin 4.10.3.0

Summary

This release delivers improvements to reliability, maintainability, and reproducibility. The SpotBugs execution path has been modernized by replacing the Ant-based launcher with ProcessBuilder, temporary auxiliary classpath handling has been improved, and toolchain detection has been made more robust. Build tooling has also been cleaned up with Maven modernization efforts, improved reproducible artifact generation, and updated documentation. Additional fixes include improved artifact handling, test coverage improvements, and dependency updates.

What's Changed

New Contributors

Full Changelog: spotbugs/spotbugs-maven-plugin@spotbugs-maven-plugin-4.10.2.0...spotbugs-maven-plugin-4.10.3.0

Commits
  • f0e6f45 [maven-release-plugin] prepare release spotbugs-maven-plugin-4.10.3.0
  • 86af8d5 Merge pull request #1473 from spotbugs/renovate/spotbugs.version
  • 2fc1232 Update dependency com.github.spotbugs:spotbugs to v4.10.3
  • 8938370 Merge pull request #1472 from hazendaz/antwork
  • 68ee04d Replace 'ant' usage with process builder
  • 4fcdf58 Merge pull request #1471 from hazendaz/master
  • c97f85e [ci] Minor cleanup after toolchain adjustments
  • f7dde3a [nio] Change 'spotbugsAuxClasspath' file to a temp file and remove larger try...
  • ce2addb Merge pull request #1470 from hazendaz/restructure
  • bc53d37 [ci] readme update to reproducible builesd info
  • Additional commits viewable in compare view

Updates org.eclipse.jetty.ee11:jetty-ee11-maven-plugin from 12.1.10 to 12.1.11

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…dates

Bumps the maven-minor group with 13 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [org.junit:junit-bom](https://github.com/junit-team/junit-framework) | `6.1.1` | `6.1.2` |
| [org.omnifaces:omnifaces](https://github.com/omnifaces/omnifaces) | `5.3.4` | `5.4.1` |
| [org.primefaces:primefaces](https://github.com/primefaces/primefaces) | `15.0.16` | `15.0.17` |
| [com.twelvemonkeys.servlet:servlet](https://github.com/haraldk/TwelveMonkeys) | `3.13.1` | `3.14.0` |
| com.twelvemonkeys.imageio:imageio-bmp | `3.13.1` | `3.14.0` |
| com.twelvemonkeys.imageio:imageio-jpeg | `3.13.1` | `3.14.0` |
| com.twelvemonkeys.imageio:imageio-tiff | `3.13.1` | `3.14.0` |
| com.twelvemonkeys.imageio:imageio-hdr | `3.13.1` | `3.14.0` |
| com.twelvemonkeys.imageio:imageio-webp | `3.13.1` | `3.14.0` |
| [io.sentry:sentry-log4j2](https://github.com/getsentry/sentry-java) | `8.47.0` | `8.49.0` |
| org.eclipse.jetty.ee11:jetty-ee11-cdi | `12.1.10` | `12.1.11` |
| org.eclipse.jetty.ee11:jetty-ee11-maven-plugin | `12.1.10` | `12.1.11` |
| [com.github.spotbugs:spotbugs-maven-plugin](https://github.com/spotbugs/spotbugs-maven-plugin) | `4.10.2.0` | `4.10.3.0` |



Updates `org.junit:junit-bom` from 6.1.1 to 6.1.2
- [Release notes](https://github.com/junit-team/junit-framework/releases)
- [Commits](junit-team/junit-framework@r6.1.1...r6.1.2)

Updates `org.omnifaces:omnifaces` from 5.3.4 to 5.4.1
- [Commits](omnifaces/omnifaces@5.3.4...5.4.1)

Updates `org.primefaces:primefaces` from 15.0.16 to 15.0.17
- [Release notes](https://github.com/primefaces/primefaces/releases)
- [Commits](primefaces/primefaces@v15.0.16...v15.0.17)

Updates `com.twelvemonkeys.servlet:servlet` from 3.13.1 to 3.14.0
- [Release notes](https://github.com/haraldk/TwelveMonkeys/releases)
- [Commits](haraldk/TwelveMonkeys@twelvemonkeys-3.13.1...twelvemonkeys-3.14.0)

Updates `com.twelvemonkeys.imageio:imageio-bmp` from 3.13.1 to 3.14.0

Updates `com.twelvemonkeys.imageio:imageio-jpeg` from 3.13.1 to 3.14.0

Updates `com.twelvemonkeys.imageio:imageio-tiff` from 3.13.1 to 3.14.0

Updates `com.twelvemonkeys.imageio:imageio-hdr` from 3.13.1 to 3.14.0

Updates `com.twelvemonkeys.imageio:imageio-webp` from 3.13.1 to 3.14.0

Updates `com.twelvemonkeys.imageio:imageio-bmp` from 3.13.1 to 3.14.0

Updates `com.twelvemonkeys.imageio:imageio-jpeg` from 3.13.1 to 3.14.0

Updates `com.twelvemonkeys.imageio:imageio-tiff` from 3.13.1 to 3.14.0

Updates `com.twelvemonkeys.imageio:imageio-hdr` from 3.13.1 to 3.14.0

Updates `com.twelvemonkeys.imageio:imageio-webp` from 3.13.1 to 3.14.0

Updates `io.sentry:sentry-log4j2` from 8.47.0 to 8.49.0
- [Release notes](https://github.com/getsentry/sentry-java/releases)
- [Changelog](https://github.com/getsentry/sentry-java/blob/main/CHANGELOG.md)
- [Commits](getsentry/sentry-java@8.47.0...8.49.0)

Updates `org.eclipse.jetty.ee11:jetty-ee11-cdi` from 12.1.10 to 12.1.11

Updates `org.eclipse.jetty.ee11:jetty-ee11-maven-plugin` from 12.1.10 to 12.1.11

Updates `com.github.spotbugs:spotbugs-maven-plugin` from 4.10.2.0 to 4.10.3.0
- [Release notes](https://github.com/spotbugs/spotbugs-maven-plugin/releases)
- [Commits](spotbugs/spotbugs-maven-plugin@spotbugs-maven-plugin-4.10.2.0...spotbugs-maven-plugin-4.10.3.0)

Updates `org.eclipse.jetty.ee11:jetty-ee11-maven-plugin` from 12.1.10 to 12.1.11

---
updated-dependencies:
- dependency-name: org.junit:junit-bom
  dependency-version: 6.1.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor
- dependency-name: org.omnifaces:omnifaces
  dependency-version: 5.4.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor
- dependency-name: org.primefaces:primefaces
  dependency-version: 15.0.17
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor
- dependency-name: com.twelvemonkeys.servlet:servlet
  dependency-version: 3.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor
- dependency-name: com.twelvemonkeys.imageio:imageio-bmp
  dependency-version: 3.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor
- dependency-name: com.twelvemonkeys.imageio:imageio-jpeg
  dependency-version: 3.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor
- dependency-name: com.twelvemonkeys.imageio:imageio-tiff
  dependency-version: 3.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor
- dependency-name: com.twelvemonkeys.imageio:imageio-hdr
  dependency-version: 3.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor
- dependency-name: com.twelvemonkeys.imageio:imageio-webp
  dependency-version: 3.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor
- dependency-name: com.twelvemonkeys.imageio:imageio-bmp
  dependency-version: 3.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor
- dependency-name: com.twelvemonkeys.imageio:imageio-jpeg
  dependency-version: 3.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor
- dependency-name: com.twelvemonkeys.imageio:imageio-tiff
  dependency-version: 3.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor
- dependency-name: com.twelvemonkeys.imageio:imageio-hdr
  dependency-version: 3.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor
- dependency-name: com.twelvemonkeys.imageio:imageio-webp
  dependency-version: 3.14.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor
- dependency-name: io.sentry:sentry-log4j2
  dependency-version: 8.49.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor
- dependency-name: org.eclipse.jetty.ee11:jetty-ee11-cdi
  dependency-version: 12.1.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor
- dependency-name: org.eclipse.jetty.ee11:jetty-ee11-maven-plugin
  dependency-version: 12.1.11
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven-minor
- dependency-name: com.github.spotbugs:spotbugs-maven-plugin
  dependency-version: 4.10.3.0
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven-minor
- dependency-name: org.eclipse.jetty.ee11:jetty-ee11-maven-plugin
  dependency-version: 12.1.11
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Jul 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants