Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Update all non-major dependencies #4168

Open
wants to merge 1 commit into
base: develop
Choose a base branch
from

Conversation

renovate-bot
Copy link
Contributor

@renovate-bot renovate-bot commented Nov 18, 2024

This PR contains the following updates:

Package Type Update Change Age Adoption Passing Confidence
bitnami/kafka (source) minor 3.8.1-debian-12-r1 -> 3.9.0-debian-12-r3 age adoption passing confidence
gradle (source) minor 8.10.2 -> 8.11.1 age adoption passing confidence
mariadb service minor 11.5 -> 11.6 age adoption passing confidence
postgres service minor 16.4 -> 16.6 age adoption passing confidence
org.mariadb.jdbc:mariadb-java-client (source) devDependencies patch 3.5.0 -> 3.5.1 age adoption passing confidence
org.owasp.esapi:esapi (source) devDependencies minor 2.5.5.0 -> 2.6.0.0 age adoption passing confidence
org.apache.activemq:activemq-client (source) devDependencies patch 6.1.3 -> 6.1.4 age adoption passing confidence
org.springdoc:springdoc-openapi-starter-webmvc-ui (source) devDependencies minor 2.6.0 -> 2.7.0 age adoption passing confidence
org.projectlombok:lombok (source) devDependencies patch 1.18.34 -> 1.18.36 age adoption passing confidence
io.github.classgraph:classgraph devDependencies patch 4.8.177 -> 4.8.179 age adoption passing confidence
org.openapi.generator plugin minor 7.8.0 -> 7.10.0 age adoption passing confidence
io.swagger.core.v3.swagger-gradle-plugin plugin patch 2.2.23 -> 2.2.26 age adoption passing confidence
org.springframework.boot plugin minor 3.3.5 -> 3.4.0 age adoption passing confidence
org.quartz-scheduler:quartz (source) devDependencies minor 2.3.2 -> 2.5.0 age adoption passing confidence
commons-io:commons-io (source) devDependencies minor 2.17.0 -> 2.18.0 age adoption passing confidence
com.google.googlejavaformat:google-java-format devDependencies minor 1.24.0 -> 1.25.0 age adoption passing confidence
software.amazon.awssdk:bom devDependencies patch 2.29.9 -> 2.29.21 age adoption passing confidence
io.netty:netty-bom (source) devDependencies patch 4.1.114.Final -> 4.1.115.Final age adoption passing confidence
org.springframework.boot:spring-boot-dependencies (source) devDependencies minor 3.3.5 -> 3.4.0 age adoption passing confidence
org.springframework:spring-framework-bom devDependencies minor 6.1.14 -> 6.2.0 age adoption passing confidence
io.micrometer:micrometer-bom devDependencies minor 1.13.6 -> 1.14.1 age adoption passing confidence

Release Notes

gradle/gradle (gradle)

v8.11.1

Compare Source

v8.11: 8.11

Compare Source

The Gradle team is excited to announce Gradle 8.11.

Read the Release Notes

We would like to thank the following community members for their contributions to this release of Gradle:
Adam,
alyssoncs,
Bilel MEDIMEGH,
Björn Kautler,
Chuck Thomas,
Daniel Lacasse,
Finn Petersen,
JK,
Jérémie Bresson,
luozexuan,
Mahdi Hosseinzadeh,
Markus Gaisbauer,
Matthew Haughton,
Matthew Von-Maszewski,
ploober,
Siarhei,
Titus James,
vrp0211

Upgrade instructions

Switch your build to use Gradle 8.11 by updating your wrapper:

./gradlew wrapper --gradle-version=8.11

See the Gradle 8.x upgrade guide to learn about deprecations, breaking changes and other considerations when upgrading.

For Java, Groovy, Kotlin and Android compatibility, see the full compatibility notes.

Reporting problems

If you find a problem with this release, please file a bug on GitHub Issues adhering to our issue guidelines.
If you're not sure you're encountering a bug, please use the forum.

We hope you will build happiness with Gradle, and we look forward to your feedback via Twitter or on GitHub.

mariadb-corporation/mariadb-connector-j (org.mariadb.jdbc:mariadb-java-client)

v3.5.1

Compare Source

Full Changelog

Notable changes
  • CONJ-1193 Implement parsec authentication
  • CONJ-1207 New HaMode: sequential write, loadbalance read
  • CONJ-1208 permit bulk for INSERT ON DUPLICATE KEY UPDATE commands for 11.5.1+ servers
Bugs Fixed
  • CONJ-1053 Mark waffle-jna dependency optional in module descriptor
  • CONJ-1196 setObject on java.util.Date was considered was a java.sql.Date and truncate hour/minutes/seconds/ms while it must be considered like a java.sql.Timestamp
  • CONJ-1211 jdbc 4.3 enquoteIdentifier missing validation
  • CONJ-1213 sql command ending with semicolon and trailing space are not using bulk
springdoc/springdoc-openapi (org.springdoc:springdoc-openapi-starter-webmvc-ui)

v2.7.0

Compare Source

Added
  • #​2777 - Add SortAsQueryParam annotation
Changed
  • Upgrade spring-boot to 3.4.0
  • Upgrade swagger-ui to 5.18.2
  • Upgrade spring-security-oauth2-authorization-server to 1.4.0
projectlombok/lombok (org.projectlombok:lombok)

v1.18.36

quartz-scheduler/quartz (org.quartz-scheduler:quartz)

v2.5.0: Quartz 2.5.0

Most Significant Changes This Release (over 2.4.0):

  • Move to Jakarta namespace

All changes/updates:

Open Issues

Completed Issues

v2.4.0: Quartz 2.4.0

Most Significant Changes This Release:

  • Quartz 2.4.0 now requires minimum Java version of Java 8
  • Quartz build system moved to Gradle
  • 3rd party libraries (slf4j, log4j, Hikari, etc.) upgraded to more recent versions
  • Maven POMs generated from gradle declare 3rd party dependencies as "provided" scope
  • Removal of old TerracottaJobStore
  • "NativeJob" class removed from "quartz-jobs" artifact. This resolves security concerns related to code execution. While it is possible to safely use this Job class, it is a risk for users that don’t engage some thought. If you wish to still use this job or something like it, the source code for it can now be found as "example15".
  • Example programs can now simply be executed via gradle. See the "examples_guide.txt" file in the examples folder of the quartz repository for full description and info.

All changes/updates:

Open Issues

Completed Issues

google/google-java-format (com.google.googlejavaformat:google-java-format)

v1.25.0

The minimum support JDK version to run google-java-format is now JDK 17 (#​1159). Using google-java-format to format earlier versions of the language is still supported, but running the formatter itself on JDK 17 or newer is required.

Changes:

  • Various improvements to text block formatting
  • Improve formatting of when pattern guards

Full Changelog: google/google-java-format@v1.24.0...v1.25.0

spring-projects/spring-boot (org.springframework.boot:spring-boot-dependencies)

v3.4.0

v3.3.6

Compare Source

spring-projects/spring-framework (org.springframework:spring-framework-bom)

v6.2.0

Compare Source

⭐ New Features

  • Update UndertowHttpHandlerAdapter to dispatch #​33885
  • Refine @Contract Javadoc to mention this and new return values #​33849
  • AOT processing for bean validation does not consider cascaded and container element constraints #​33842
  • Avoid repeated resolving of singleton beans through @Lazy proxy #​33841
  • Regiser runtime hints for @TestBean fully-qualified method names #​33836
  • Introduce support for custom reason in @DisabledInAotMode #​33833
  • Use optimistic locking where possible in ResponseBodyEmitter #​33831
  • Revise cookies support with Apache HTTP Components in WebClient and WebTestClient #​33822
  • Remove the pure attribute from @Contract #​33820
  • Introduce @CheckReturnValue annotation #​33818
  • ResourceHttpRequestHandler throwing IllegalArgumentException if resource doesn't end with slash breaks some third-party libraris #​33815
  • Provide first-class virtual thread option on ThreadPoolTaskExecutor/ThreadPoolTaskScheduler #​33807
  • HttpServiceProxyFactory should omit optional @RequestParam if converted from null to empty string #​33794
  • Reactor Netty response should not buffer the full response #​33781
  • Relax the visibility of MockMVC DSL constructors #​33778
  • Support Publisher to InputStream conversion #​31677

🐞 Bug Fixes

  • MockReset should be honored without @Mockito[Spy]Bean fields #​33829
  • Test Bean Overrides do not honor @Primary semantics #​33819
  • Bean Overrides cannot reliably override beans created by a FactoryBean with generics #​33811
  • Bean Overrides for certain FactoryBean use cases no longer work #​33800
  • @MockitoBean, @MockitoSpyBean, & @TestBean do not work with @DirtiesContext "before method" modes #​33783
  • Deprecate exchangeTimeout and refactor readTimeout in ReactorClientHttpRequestFactory #​33782

📔 Documentation

  • Revise documentation for SpEL PropertyAccessor and IndexAccessor APIs regarding ordering #​33862
  • Document UrlHandler Servlet and reactive filters #​33784
  • Improve documentation for SpelCompilerMode #​33223

🔨 Dependency Upgrades

  • Upgrade to ASM 9.7.1 (for early Java 24 support) #​33821
  • Upgrade to Micrometer 1.14.0 #​33876
  • Upgrade to Reactor 2024.0.0 #​33878

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Hejow, @​OlegDokuka, and @​lucky8987

v6.1.15

Compare Source

⭐ New Features

  • Use UriUtils to process static resource paths #​33859
  • Prefer modified resources over the originals in TestCompiler #​33850
  • Improve iteration methods in native headers to MultiValueMap adapters #​33823
  • Deregister empty Cache from CacheManager #​33813
  • Rename aopAvailable constants in TransactionSynchronizationUtils for better GraalVM native image support #​33796
  • Load-time weaving support for WildFly 24+ #​33728

🐞 Bug Fixes

  • DefaultClientRequestObservationConvention generates wrong uri tag when missing path #​33867
  • HttpComponentsClientHttpRequestFactory setReadTimeout not working with httpclient 5.4 #​33806
  • HttpHeaders.writeableHttpHeaders(new HttpHeaders(readOnlyHttpHeaders)) is not writeable #​33789
  • RestClient exchange methods are not nullable #​33779
  • Throw SpelParseException for unsupported character in SpelExpressionParser #​33767
  • DefaultMessageListenerContainer reports incorrect jms.process.message count #​33758
  • Autowiring fails if multiple non-highest @Priority beans exist with same priority #​33733
  • Jackson2Decoder leaks on WebClient timeout #​33731
  • DefaultServerRequestObservationConvention throws when response status is zero #​33725
  • Aspect executed twice - @AfterThrowing #​33704
  • parts w/o filename in Content-Disposition header are not cleaned from temp folder (skipped by StandardServletMultipartResolver) #​33511

📔 Documentation

  • Resources link points to wrong section of reference guide #​33882
  • Remove mentions of Joda-Time support #​33881
  • SimpleAsyncTaskExecutor blocks calling thread when concurrencyLimit set #​33873
  • Fix formatting issue in validation section of reference guide #​33871
  • Fix typo in reference documentation #​33865
  • Fix XML bean reference example in reference manual #​33855
  • Fix a typo in documentation #​33846
  • Numerous warnings when injecting dependencies into configuration that implements CachingConfigurer #​33834
  • @Async documentation should not suggest deprecated classes #​33805
  • Document that circular dependencies should be avoided in AOT mode #​33786
  • Inconsistent Lifecycle Management with Virtual Threads in Spring Boot Async Configuration #​33780
  • Fix incorrect regex rendering in MVC controller documentation #​33766
  • Improve documentation for allowEagerInit parameter in getBeanNamesForType() #​33740
  • Fix Javadoc in ReactorNetty2ResourceFactory #​33735
  • Document options for handling Date/Time parsing and formatting issues with JDK 20+ #​33151

🔨 Dependency Upgrades

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​Torres-09, @​ZLATAN628, @​hosamaly, @​izeye, @​kunaljani1100, @​ngocnhan-tran1996, and @​wilkinsona

micrometer-metrics/micrometer (io.micrometer:micrometer-bom)

v1.14.1: 1.14.1

📔 Documentation
  • Gauges may be silently ignored when MeterFilters drop or transform tags #​5616
🔨 Dependency Upgrades
  • Bump com.netflix.spectator:spectator-reg-atlas from 1.8.1 to 1.8.2 #​5685
  • Bump software.amazon.awssdk:cloudwatch from 2.29.7 to 2.29.14 #​5669
  • Bump shaded netty to 4.1.115.Final in micrometer-registry-statsd to address CVE-2024-47535 #​5660
❤️ Contributors

Thank you to all the contributors who worked on this release:

@​izeye

v1.14.0: 1.14.0

Micrometer 1.14.0 is the GA version of a new feature release. See our support policy for support timelines.

Below are the combined release notes of all the pre-release milestones and release candidate preceding this GA release.

⚠️ Noteworthy

  • Support ExponentialHistogram in OTLP #​3861
  • Virtual thread metrics #​3956
  • Validate expected Observation API call ordering on TestObservationRegistry #​5239

⭐ New Features / Enhancements

  • Expose TestObservationRegistry as an AssertJ AssertProvider #​5551
  • Use failure with actual and expected message to improve IDE experience for ObservationContextAssert #​5550
  • Replace @Nonnull(when = When.MAYBE) with @CheckForNull in @Nullable #​5485
  • Warn about Prometheus meter registration failure #​5228
  • Improve performance of merging two Tags/KeyValues instances #​5140
  • Allow user-provided custom scheduler for periodically binding KafkaMetrics #​4976
  • Allow specifying the meterNameConsumer for HighCardinalityTagsDetector #​4028
  • Virtual thread metrics #​3956
  • Allow tagsBasedOnJoinPoint to override extraTags with CountedAspect #​2461
  • Configurable _source.enabled Elastic mapping property #​1629
  • Skip registering Caffeine meters when statistics are not enabled #​5409
  • Log a warning when instrumenting a cache that is not recording stats in CaffeineCacheMetrics #​5402
  • MultiGauge.register should accept more types #​5390
  • Metrics not collected after ExecutorService recreation #​5366
  • Add "cancelled" information to the GrpcServerObservationContext #​5301
  • process_start_time_seconds HELP description inconsistency between Prometheus and micrometer #​5290
  • Add history-tracking to ObservationValidator #​5370
  • [dynatrace/v2] reduce log verbosity #​5306
  • Validate expected Observation API call ordering on TestObservationRegistry #​5239
  • Add JvmThreadDeadlockMetrics #​5222
  • Allow multiple MeterTag annotations for multiple tags from same target #​4081
  • Support ExponentialHistogram in OTLP #​3861
  • Expose ForkJoinPool parallelism and pool size metrics #​5236
  • Allow custom ThreadFactory for OtlpMeterRegistry #​5153
  • Do not register GC metrics when GC notifications are unavailable #​5149
  • Cancelled status code not reported in the gRPC server metrics #​5109
  • Add counter of failed attempts to retrieve a connection from the pool #​5057
  • Add Support for @MeterTag to @Counted #​4725
  • Compile-time weaving support for aspects #​1149
  • Service level objectives support on @Timed annotation #​5145

📔 Documentation

  • Add docs for ObservationValidator #​5387
  • Add docs for multiple MeterTag annotations #​5641
  • Add docs for @MeterTag for @Counted #​5640
  • Add docs for JvmThreadDeadlockMetrics #​5614
  • Add docs for ForkJoinPool parallelism and pool size metrics #​5611
  • Add docs for VirtualThreadMetrics #​5610

🔨 Dependency Upgrades

  • Bump io.prometheus:prometheus-metrics-bom to 1.3.3 #​5649
  • Bump software.amazon.awssdk:cloudwatch to 2.29.7 #​5645
  • Bump com.google.cloud:libraries-bom to 26.50.0 #​5638
  • Bump com.signalfx.public:signalfx-java to 1.0.47 #​5635
  • Bump com.google.auth:google-auth-library-oauth2-http to 1.29.0 #​5634
  • Bump software.amazon.awssdk:cloudwatch to 2.29.6 #​5631
  • Bump com.netflix.spectator:spectator-reg-atlas to 1.8.1 #​5630
  • Bump com.google.cloud:google-cloud-monitoring to 3.54.0 #​5628
  • Bump dropwizard-metrics to 4.2.28 #​5569
  • Bump io.opentelemetry.proto:opentelemetry-proto to 1.3.2-alpha #​5268
  • Bump org.hdrhistogram:HdrHistogram to 2.2.2 #​5171

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​codesimplicity, @​genuss, @​izeye, @​mihalyr, @​lcavadas, @​filiphr, @​sean-heller, @​vasiliy-sarzhynskyi, @​ArtyomGabeev, @​kinddevil, @​mstyura, @​madhead, @​pirgeo, @​rkurniawati, @​lenin-jaganathan, @​smaxx

v1.13.8: 1.13.8

📔 Documentation

  • Gauges may be silently ignored when MeterFilters drop or transform tags #​5616

🔨 Dependency Upgrades

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​izeye

v1.13.7: 1.13.7

🐞 Bug Fixes

  • Native Image Hazelcast error: java.lang.NoSuchMethodError: com.hazelcast.map.IMap.getName() #​5604

📔 Documentation

  • Add documentation for @Counted #​5613

🔨 Dependency Upgrades

  • Bump com.signalfx.public:signalfx-java from 1.0.46 to 1.0.47 #​5623
  • Bump com.fasterxml.jackson.core:jackson-databind from 2.17.2 to 2.17.3 #​5622

📝 Tasks

  • Enable japicmp task for micrometer-registry-statsd #​5612
  • Improve UCUM time unit mapping for Dynatrace #​5594

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​izeye


Configuration

📅 Schedule: Branch creation - "before 4am on Monday" (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@forking-renovate forking-renovate bot added the renovate https://renovate.whitesourcesoftware.com [FINERACT-962] label Nov 18, 2024
@renovate-bot renovate-bot force-pushed the renovate/all-minor-patch branch 16 times, most recently from a0dd95c to d113b9d Compare November 23, 2024 22:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
renovate https://renovate.whitesourcesoftware.com [FINERACT-962]
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant