{"id":1680,"name":"ch.qos.logback:logback-core","ecosystem":"maven","repository_url":"https://github.com/qos-ch/logback","issues_count":729,"created_at":"2025-06-06T15:01:48.530Z","updated_at":"2025-06-06T15:01:48.530Z","purl":"pkg:maven/ch.qos.logback:logback-core","metadata":{"id":4640348,"name":"ch.qos.logback:logback-core","ecosystem":"maven","description":"logback-core module","homepage":"http://logback.qos.ch","licenses":"Eclipse Public License - v 1.0,GNU Lesser General Public License","normalized_licenses":["EPL-1.0","LGPL-2.1+"],"repository_url":"https://github.com/qos-ch/logback","keywords_array":[],"namespace":"ch.qos.logback","versions_count":148,"first_release_published_at":"2006-08-23T16:15:56.000Z","latest_release_published_at":"2025-03-18T12:47:20.000Z","latest_release_number":"1.5.18","last_synced_at":"2025-05-31T20:04:11.883Z","created_at":"2022-07-25T15:31:56.897Z","updated_at":"2025-05-31T20:04:11.884Z","registry_url":"https://central.sonatype.com/artifact/ch.qos.logback/logback-core/","install_command":null,"documentation_url":"https://appdoc.app/artifact/ch.qos.logback/logback-core/","metadata":{},"repo_metadata":{"uuid":"283325","full_name":"qos-ch/logback","owner":"qos-ch","description":"The reliable, generic, fast and flexible logging framework for Java.","archived":false,"fork":false,"pushed_at":"2023-03-12T21:07:24.000Z","size":29145,"stargazers_count":2650,"open_issues_count":197,"forks_count":1186,"subscribers_count":160,"default_branch":"master","last_synced_at":"2023-03-13T16:46:38.378Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":"http://logback.qos.ch","language":"Java","has_issues":false,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"other","status":null,"scm":"git","pull_requests_enabled":true,"logo_url":null,"metadata":{"files":{"readme":"README.md","changelog":null,"contributing":"CONTRIBUTING.md","funding":".github/FUNDING.yml","license":"LICENSE.txt","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null},"funding":{"tidelift":"maven/ch.qos.logback:logback-classic","github":"qos-ch"}},"created_at":"2009-08-20T18:48:24.000Z","updated_at":"2023-03-13T00:32:43.000Z","dependencies_parsed_at":"2023-01-14T11:15:19.456Z","dependency_job_id":null,"html_url":"https://github.com/qos-ch/logback","commit_stats":null,"repository_url":"http://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/qos-ch%2Flogback","tags_url":"http://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/qos-ch%2Flogback/tags","manifests_url":"http://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/qos-ch%2Flogback/manifests","owner_url":"http://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/qos-ch","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":108921946,"host_url":"http://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"http://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"http://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names"},"owner_record":{"login":"qos-ch","name":"QOS.CH (Switzerland)","uuid":"1521407","kind":"organization","description":"","email":null,"website":"http://www.qos.ch","location":"Switzerland","twitter":"qos_ch","company":null,"avatar_url":"https://avatars.githubusercontent.com/u/1521407?v=4","repositories_count":12,"last_synced_at":"2023-02-20T15:36:17.591Z","metadata":{"has_sponsors_listing":true},"owner_url":"http://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/qos-ch"},"tags":[{"name":"v_1.3.3","sha":"daf07d203c1224d194a1f669b6db2f1eea96b8a4","kind":"tag","published_at":"2022-10-02T22:24:39.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.3.3","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.3.3"},{"name":"v1.3.2","sha":"146f33d52aba2e8071d354b3d5c1ffcfc2289d31","kind":"tag","published_at":"2022-10-02T20:04:55.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v1.3.2","html_url":"https://github.com/qos-ch/logback/releases/tag/v1.3.2"},{"name":"possible_mvn_issue","sha":"5f25ff98636abd8e78b1ee747e34b5c3f6c59ae9","kind":"tag","published_at":"2022-09-30T14:52:36.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/possible_mvn_issue","html_url":"https://github.com/qos-ch/logback/releases/tag/possible_mvn_issue"},{"name":"v_1.4.1","sha":"a432a5518fb783e2c64aba216e363bd444eac76d","kind":"tag","published_at":"2022-09-14T19:12:08.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.4.1","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.4.1"},{"name":"v_1.3.1","sha":"86976384fc980c187ca3aa3090075c05d1425427","kind":"tag","published_at":"2022-09-14T18:44:34.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.3.1","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.3.1"},{"name":"v_1.3.0","sha":"50449f830bd46bd547016b49475d2760686b15be","kind":"tag","published_at":"2022-08-28T17:33:03.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.3.0","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.3.0"},{"name":"v_1.4.0","sha":"e83403e15547abb077d5957e4fb8a302293541dc","kind":"tag","published_at":"2022-08-28T17:31:55.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.4.0","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.4.0"},{"name":"v_1.3.0-beta0","sha":"2e71c6c11eefd1184148e77bb2b8b4e03ab484ae","kind":"tag","published_at":"2022-08-09T09:24:50.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.3.0-beta0","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.3.0-beta0"},{"name":"v_1.3.0-alpha16","sha":"9058e9db1711022929e5e2eb273d3915b51b7471","kind":"tag","published_at":"2022-05-19T14:18:48.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.3.0-alpha16","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.3.0-alpha16"},{"name":"v_1.3.0-alpha15","sha":"96a1c3951d5e02e025ced99dd2852831e193aaa3","kind":"tag","published_at":"2022-05-09T17:36:18.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.3.0-alpha15","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.3.0-alpha15"},{"name":"v_1.2.11","sha":"4eb2914cb65214d13e14a9ed3dfb9f044df98358","kind":"tag","published_at":"2022-03-05T21:17:25.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.2.11","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.2.11"},{"name":"v_1.3.0-alpha14","sha":"92276ba52a6e360840acc8203c578d0b274041cc","kind":"tag","published_at":"2022-02-11T22:53:26.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.3.0-alpha14","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.3.0-alpha14"},{"name":"v_1.3.0-alpha13","sha":"34332a0c12751dec101cb6e1724d3930cfaab7e6","kind":"tag","published_at":"2022-01-31T17:13:25.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.3.0-alpha13","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.3.0-alpha13"},{"name":"v_1.2.10","sha":"15a182317df681c3076c0751b02d162133f72afc","kind":"tag","published_at":"2021-12-23T10:27:32.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.2.10","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.2.10"},{"name":"v_1.3.0-alpha12","sha":"351040224619f2695fceb11977125dcc149b9c20","kind":"tag","published_at":"2021-12-22T20:08:51.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.3.0-alpha12","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.3.0-alpha12"},{"name":"v_1.3.0-alpha12-SNAPSHOT","sha":"e9f34bcc374ad019e9edcc4b546028c541c0518f","kind":"tag","published_at":"2021-12-19T18:46:10.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.3.0-alpha12-SNAPSHOT","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.3.0-alpha12-SNAPSHOT"},{"name":"v_1.3.0-alpha11","sha":"e9f34bcc374ad019e9edcc4b546028c541c0518f","kind":"tag","published_at":"2021-12-19T18:45:38.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.3.0-alpha11","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.3.0-alpha11"},{"name":"v_1.2.9","sha":"3b9cd0efe0b3390026a04a6092aa03e433ddd330","kind":"tag","published_at":"2021-12-19T18:40:49.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.2.9","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.2.9"},{"name":"v_1.2.8","sha":"119847d9c3efb854d48ae208d6c848492f4024dc","kind":"tag","published_at":"2021-12-15T19:35:14.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.2.8","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.2.8"},{"name":"v_1.2.7","sha":"626c7733c188f2ad60c1348a493761f60e2d7958","kind":"tag","published_at":"2021-11-11T17:27:06.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.2.7","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.2.7"},{"name":"v_1.2.6","sha":"2f172d8bf5c72eac29bd95a5885c1f42e2b9409e","kind":"tag","published_at":"2021-09-09T22:32:45.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.2.6","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.2.6"},{"name":"v_1.3.0-alpha10","sha":"b6dbbba5b7cb97affd9e7ada6d44efc60f859e2d","kind":"tag","published_at":"2021-08-23T14:13:20.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.3.0-alpha10","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.3.0-alpha10"},{"name":"v_1.3.0-alpha9","sha":"d993a7abe495f04ad3bee033ad060711d05830e4","kind":"tag","published_at":"2021-08-13T11:42:42.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.3.0-alpha9","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.3.0-alpha9"},{"name":"v_1.3.0-alpha8","sha":"40da1f7435acd90f640b0fc0aa5d33894e472731","kind":"tag","published_at":"2021-08-12T21:45:10.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.3.0-alpha8","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.3.0-alpha8"},{"name":"v_1.3.0-alpha7","sha":"cfc8247f9215f2aa14715da95b5813393b9c4ada","kind":"tag","published_at":"2021-08-10T14:52:45.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.3.0-alpha7","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.3.0-alpha7"},{"name":"v_1.3.0-alpha6","sha":"364989315c257b2388d17cc757b1bc03f66e3a30","kind":"tag","published_at":"2021-07-28T21:27:27.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.3.0-alpha6","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.3.0-alpha6"},{"name":"v_1.2.5","sha":"1650e8db0941a87717b0f247acfefd4811cfaf41","kind":"tag","published_at":"2021-07-26T15:46:47.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.2.5","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.2.5"},{"name":"v_1.2.4","sha":"d5ca7b0e84891b92c60303064af043a2c1090b98","kind":"tag","published_at":"2021-07-19T06:53:48.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.2.4","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.2.4"},{"name":"v_1.3.0-alpha5","sha":"241d1e72b0ab24db502068bde5de8f6f562ef157","kind":"tag","published_at":"2019-10-11T18:26:10.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.3.0-alpha5","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.3.0-alpha5"},{"name":"list","sha":"597b272384cc02f711dbdf6895763e256eddaa76","kind":"commit","published_at":"2019-10-01T18:03:21.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/list","html_url":"https://github.com/qos-ch/logback/releases/tag/list"},{"name":"v_1.3.0-alpha4","sha":"e23e9c0e12dec801897fa440b2302b01dfa2abce","kind":"tag","published_at":"2018-02-11T21:24:57.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.3.0-alpha4","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.3.0-alpha4"},{"name":"v_1.3.0-alpha3","sha":"1f052b53a954bdfa8d893f9906b767821b3af62f","kind":"tag","published_at":"2018-02-10T07:41:59.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.3.0-alpha3","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.3.0-alpha3"},{"name":"v_1.3.0-alpha2","sha":"9b684f41c07d5ebfecfea1a2c5c6198d47c71ac2","kind":"tag","published_at":"2018-01-30T13:14:50.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.3.0-alpha2","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.3.0-alpha2"},{"name":"v_1.8.0-alpha1","sha":"99c8a252a8c5ed68cf26627d354b09756382e374","kind":"tag","published_at":"2018-01-29T23:51:27.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.8.0-alpha1","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.8.0-alpha1"},{"name":"v_1.3.0-alpha0","sha":"9d4cbcc80f30a6c6915f4ee667e72d69a159bde0","kind":"tag","published_at":"2018-01-18T19:54:34.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.3.0-alpha0","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.3.0-alpha0"},{"name":"v_1.2.3","sha":"a154cd1b564d436c90a26b8cb1a2e8ffff0a4a47","kind":"tag","published_at":"2017-04-01T04:33:19.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.2.3","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.2.3"},{"name":"v_1.2.2","sha":"52e4bd866891ecf81d940edb7ac23c6c87630ef3","kind":"tag","published_at":"2017-03-16T19:13:35.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.2.2","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.2.2"},{"name":"v_1.1.11","sha":"5bae54c53ac3cc429d29e3b782054b1b9b085313","kind":"tag","published_at":"2017-03-01T19:37:50.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.1.11","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.1.11"},{"name":"v_1.2.1","sha":"6b8284dfe93ff9b72b2a38e92109ebdde2e3f441","kind":"tag","published_at":"2017-02-09T13:05:51.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.2.1","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.2.1"},{"name":"v_1.2.0","sha":"dc4ed6962985897ea4a3a0318111cdef6993d620","kind":"tag","published_at":"2017-02-08T22:27:26.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.2.0","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.2.0"},{"name":"v_1.1.10","sha":"a160f220eca9adbd457d6a802186f200ec743cd6","kind":"tag","published_at":"2017-02-05T14:07:09.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.1.10","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.1.10"},{"name":"v_1.1.8","sha":"1213fcaa6428424de97ef7873f692b272c29873d","kind":"tag","published_at":"2016-12-09T10:33:39.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.1.8","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.1.8"},{"name":"v_1.1.7","sha":"2dad0019ebaff91a183200dab54e1e4a94407d5a","kind":"tag","published_at":"2016-03-29T20:27:13.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.1.7","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.1.7"},{"name":"v_1.1.6","sha":"506c979fbbb3c3ac33808cc1d1b2f3a39202e3c2","kind":"tag","published_at":"2016-02-29T22:13:17.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.1.6","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.1.6"},{"name":"v_1.1.5","sha":"b3f5e4684b472d58c88abdb82c094246ba65385b","kind":"tag","published_at":"2016-02-13T22:38:50.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.1.5","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.1.5"},{"name":"v_1.1.4","sha":"c43424f54f9977b391e637cf5c378b9eb9c1c291","kind":"tag","published_at":"2016-02-11T21:44:03.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.1.4","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.1.4"},{"name":"v_1.1.1","sha":"7fbebf45a375caa03c43b99b0953143986bdbf62","kind":"tag","published_at":"2014-02-05T23:16:11.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.1.1","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.1.1"},{"name":"v_1.1.0","sha":"fd8751f5c59d6ca1701e7a85f0856015875eee30","kind":"tag","published_at":"2014-01-29T17:52:37.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.1.0","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.1.0"},{"name":"v_1.0.13","sha":"633fda31f5a64bc765024029afe635a700734a57","kind":"tag","published_at":"2013-05-10T12:39:29.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.0.13","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.0.13"},{"name":"v_1.0.12","sha":"0ae98042840bf42f90bb8a17683dead5fe3137bc","kind":"tag","published_at":"2013-04-26T16:33:53.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.0.12","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.0.12"},{"name":"v_1.0.11","sha":"28a154ddf8441efdac7be8327e7bb16511580294","kind":"tag","published_at":"2013-03-25T15:09:21.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.0.11","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.0.11"},{"name":"v1.0.10","sha":"0bc40733a748cac21657e141f841c1ee81110a59","kind":"tag","published_at":"2013-03-15T17:15:53.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v1.0.10","html_url":"https://github.com/qos-ch/logback/releases/tag/v1.0.10"},{"name":"v_1.0.9","sha":"0ca57909d9394d361ce6f8f005f43159326c313e","kind":"tag","published_at":"2012-12-04T23:20:59.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.0.9","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.0.9"},{"name":"v_1.0.8","sha":"89237688457055ca4d89c901af551633e80bd0d4","kind":"tag","published_at":"2012-12-04T20:59:14.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.0.8","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.0.8"},{"name":"v_1.0.7","sha":"d39e17d03625e53f53c46e85c608df0a05e93994","kind":"tag","published_at":"2012-08-23T22:18:11.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.0.7","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.0.7"},{"name":"v_1.0.6","sha":"8b7001b5c98b8356ec5bf3ec6c1cc55deaf49701","kind":"tag","published_at":"2012-06-07T20:46:10.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.0.6","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.0.6"},{"name":"v_1.0.5","sha":"c26c545bc2d17bab5c4d91260dfeaa5d4d73ca24","kind":"tag","published_at":"2012-06-05T22:23:09.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.0.5","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.0.5"},{"name":"v_1.0.4","sha":"a773d9620f052a024285589c93cec345cddaab6b","kind":"tag","published_at":"2012-05-31T21:24:50.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.0.4","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.0.4"},{"name":"v_1.0.3","sha":"791680229b8644535b7b6e9b1aa8dc5ad1e17e0c","kind":"tag","published_at":"2012-05-03T22:53:39.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.0.3","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.0.3"},{"name":"v_1.0.2","sha":"7286a1b515a98ff515e663f2d4cec776337bee81","kind":"tag","published_at":"2012-04-26T13:21:01.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.0.2","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.0.2"},{"name":"v_1.0.1","sha":"c7b030cd07df26f42df90ff90cbefe86d444e751","kind":"tag","published_at":"2012-03-07T07:17:41.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.0.1","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.0.1"},{"name":"v_1.0.0","sha":"8febc7afcb01cbbae98b4cbad6c44e913b22076a","kind":"tag","published_at":"2011-11-01T17:48:20.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_1.0.0","html_url":"https://github.com/qos-ch/logback/releases/tag/v_1.0.0"},{"name":"v_0.9.30","sha":"e76ec4eb9ec7a28ee1732f04a248e228cad8ecc6","kind":"tag","published_at":"2011-09-20T22:26:19.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_0.9.30","html_url":"https://github.com/qos-ch/logback/releases/tag/v_0.9.30"},{"name":"v_0.9.29","sha":"0ce056dfde649ae95d5ab8bc95f7f5f232750a09","kind":"tag","published_at":"2011-06-09T22:07:15.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_0.9.29","html_url":"https://github.com/qos-ch/logback/releases/tag/v_0.9.29"},{"name":"v_0.9.28","sha":"8af4d7bdc94c647c6eb69980dab0696a927ae2fd","kind":"tag","published_at":"2011-01-25T22:15:03.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_0.9.28","html_url":"https://github.com/qos-ch/logback/releases/tag/v_0.9.28"},{"name":"v_0.9.27","sha":"c6c098ff63d8af47d10da2bb5a90f6aaea011c59","kind":"tag","published_at":"2010-12-22T22:11:30.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_0.9.27","html_url":"https://github.com/qos-ch/logback/releases/tag/v_0.9.27"},{"name":"v_0.9.26","sha":"3b87986bffa45b6f340b26fecdb177db3f24139b","kind":"commit","published_at":"2010-10-20T21:43:00.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_0.9.26","html_url":"https://github.com/qos-ch/logback/releases/tag/v_0.9.26"},{"name":"v_0.9.25","sha":"b5c7149857fa174693a8f21788174329afd123ab","kind":"tag","published_at":"2010-10-13T21:44:10.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_0.9.25","html_url":"https://github.com/qos-ch/logback/releases/tag/v_0.9.25"},{"name":"v_0.9.24","sha":"e666c7d8a37ebd144995b6c2d1da8597ce422167","kind":"tag","published_at":"2010-06-30T20:57:23.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_0.9.24","html_url":"https://github.com/qos-ch/logback/releases/tag/v_0.9.24"},{"name":"v_0.9.23","sha":"f8c4d4ca4162fc0bdd311db2508ba58be7c0d3ba","kind":"tag","published_at":"2010-06-29T13:50:22.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_0.9.23","html_url":"https://github.com/qos-ch/logback/releases/tag/v_0.9.23"},{"name":"v_0.9.22","sha":"2bcfa355ce7104f6230f5867e47d54e2dfe93439","kind":"tag","published_at":"2010-06-21T16:53:27.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_0.9.22","html_url":"https://github.com/qos-ch/logback/releases/tag/v_0.9.22"},{"name":"v_0.9.21","sha":"dbc4e3608b4e351bad6c6c15f7aefe4b6d569554","kind":"tag","published_at":"2010-05-08T23:14:55.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v_0.9.21","html_url":"https://github.com/qos-ch/logback/releases/tag/v_0.9.21"},{"name":"v0.9.20","sha":"03c8220d484fce4f8e7732e10fbb89014138bb3e","kind":"tag","published_at":"2010-04-01T21:49:39.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v0.9.20","html_url":"https://github.com/qos-ch/logback/releases/tag/v0.9.20"},{"name":"release_0.9.19","sha":"632b2a2c1dead29f4ebb504636c3a049c6fb89cf","kind":"tag","published_at":"2010-03-24T19:51:38.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release_0.9.19","html_url":"https://github.com/qos-ch/logback/releases/tag/release_0.9.19"},{"name":"v0.9.18","sha":"784d8468623a87ab8bd2faaf63b49e07da7757c2","kind":"tag","published_at":"2009-12-03T21:20:33.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/v0.9.18","html_url":"https://github.com/qos-ch/logback/releases/tag/v0.9.18"},{"name":"release_0.9.11","sha":"7541b0a3ae7bc4774b618c5895b897464fd874b7","kind":"tag","published_at":"2009-08-20T18:29:41.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release_0.9.11","html_url":"https://github.com/qos-ch/logback/releases/tag/release_0.9.11"},{"name":"release_0.9.17","sha":"f966228c6f9c0749c271370f202301afca3608b0","kind":"tag","published_at":"2009-08-20T18:29:41.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release_0.9.17","html_url":"https://github.com/qos-ch/logback/releases/tag/release_0.9.17"},{"name":"release_0.9.16","sha":"8731d4099f2a7d554fbd0ce3212eb863de915297","kind":"tag","published_at":"2009-08-20T18:29:41.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release_0.9.16","html_url":"https://github.com/qos-ch/logback/releases/tag/release_0.9.16"},{"name":"release_0.9.15","sha":"41ae42dd6d5824466ef36372df17f85c2081230a","kind":"tag","published_at":"2009-08-20T18:29:41.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release_0.9.15","html_url":"https://github.com/qos-ch/logback/releases/tag/release_0.9.15"},{"name":"release_0.9.14","sha":"5af711e0b4184beb1b7d4680af22a80d67456112","kind":"tag","published_at":"2009-08-20T18:29:41.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release_0.9.14","html_url":"https://github.com/qos-ch/logback/releases/tag/release_0.9.14"},{"name":"release_0.9.13","sha":"693e4fdb9ac9c95b7b053f93edb6c7531425cd83","kind":"tag","published_at":"2009-08-20T18:29:41.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release_0.9.13","html_url":"https://github.com/qos-ch/logback/releases/tag/release_0.9.13"},{"name":"release_0.9.10","sha":"d6534ae918cb2f13ccf748acb6bf7152208911c5","kind":"tag","published_at":"2009-08-20T18:29:41.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release_0.9.10","html_url":"https://github.com/qos-ch/logback/releases/tag/release_0.9.10"},{"name":"release_0.9.9","sha":"d0b7e80af4a274a17483dcb5c1d69c2a238a52a3","kind":"tag","published_at":"2009-08-20T18:29:41.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release_0.9.9","html_url":"https://github.com/qos-ch/logback/releases/tag/release_0.9.9"},{"name":"release_0.9.8","sha":"1380ec9a73c875a30f91ceadbb538367d1d84f59","kind":"tag","published_at":"2009-08-20T18:29:41.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release_0.9.8","html_url":"https://github.com/qos-ch/logback/releases/tag/release_0.9.8"},{"name":"release_0.9.6","sha":"5710a700bbc57806eff89ae5cfe13299e2da1d34","kind":"tag","published_at":"2009-08-20T18:29:41.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release_0.9.6","html_url":"https://github.com/qos-ch/logback/releases/tag/release_0.9.6"},{"name":"release-0.9.2","sha":"82899c734fd4a44d2d116f059675d3623b25c0c9","kind":"tag","published_at":"2009-08-20T18:29:40.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release-0.9.2","html_url":"https://github.com/qos-ch/logback/releases/tag/release-0.9.2"},{"name":"release-0.9.4","sha":"2abede3a58fc3f38b4aceaacabf90ed4b2f11fc5","kind":"tag","published_at":"2009-08-20T18:29:40.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release-0.9.4","html_url":"https://github.com/qos-ch/logback/releases/tag/release-0.9.4"},{"name":"release_0.9.1","sha":"4f4edde660293eb877f15fdb82f04c8c25a41969","kind":"tag","published_at":"2009-08-20T18:29:40.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release_0.9.1","html_url":"https://github.com/qos-ch/logback/releases/tag/release_0.9.1"},{"name":"release-0.8.1","sha":"2796674dab71c1d96f4468561e8996c693a8ba8a","kind":"tag","published_at":"2009-08-20T18:29:40.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release-0.8.1","html_url":"https://github.com/qos-ch/logback/releases/tag/release-0.8.1"},{"name":"release-0.8","sha":"6625b1bba0c5247d255ec85eb617866e23e2a2ba","kind":"tag","published_at":"2009-08-20T18:29:40.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release-0.8","html_url":"https://github.com/qos-ch/logback/releases/tag/release-0.8"},{"name":"release-0.9","sha":"974947868ca3082d5efce4c73ac8ae1bb333d047","kind":"tag","published_at":"2009-08-20T18:29:40.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release-0.9","html_url":"https://github.com/qos-ch/logback/releases/tag/release-0.9"},{"name":"release-0.7.1","sha":"cb2a40d7a22c98aaf31a4697b54ae65df58aab43","kind":"tag","published_at":"2009-08-20T18:29:40.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release-0.7.1","html_url":"https://github.com/qos-ch/logback/releases/tag/release-0.7.1"},{"name":"release-0.7","sha":"df0296ad15202b50051cc2a143e9d936ace067fa","kind":"tag","published_at":"2009-08-20T18:29:40.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release-0.7","html_url":"https://github.com/qos-ch/logback/releases/tag/release-0.7"},{"name":"release-0.6","sha":"119fa964b0572d749d898b9ac5fd17c632554f9a","kind":"tag","published_at":"2009-08-20T18:29:40.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release-0.6","html_url":"https://github.com/qos-ch/logback/releases/tag/release-0.6"},{"name":"release-0.5","sha":"b30ebdb20ca96c1fb9adca94d84a49bb8bbc6f4c","kind":"tag","published_at":"2009-08-20T18:29:40.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release-0.5","html_url":"https://github.com/qos-ch/logback/releases/tag/release-0.5"},{"name":"release-0.4","sha":"13173acfd0dee5119b99f1fa484b3d61d72f93a7","kind":"tag","published_at":"2009-08-20T18:29:40.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release-0.4","html_url":"https://github.com/qos-ch/logback/releases/tag/release-0.4"},{"name":"release-0.3","sha":"0b0aadcbf4ab166183c633984454bd756425512b","kind":"tag","published_at":"2009-08-20T18:29:40.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release-0.3","html_url":"https://github.com/qos-ch/logback/releases/tag/release-0.3"},{"name":"release-0.9.3","sha":"652ff2492bbe199a07530d5a38f5cb9689b0c072","kind":"tag","published_at":"2009-08-20T18:29:40.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release-0.9.3","html_url":"https://github.com/qos-ch/logback/releases/tag/release-0.9.3"},{"name":"release-0.2","sha":"ff98b18636b02d6bb18233070ac21231c8af69cf","kind":"tag","published_at":"2009-08-20T18:29:22.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release-0.2","html_url":"https://github.com/qos-ch/logback/releases/tag/release-0.2"},{"name":"release-0.2.5","sha":"dbaaa2e656413363ea959a16938e93adec566f1b","kind":"tag","published_at":"2009-08-20T18:29:05.000Z","download_url":"https://codeload.github.com/qos-ch/logback/tar.gz/release-0.2.5","html_url":"https://github.com/qos-ch/logback/releases/tag/release-0.2.5"}]},"repo_metadata_updated_at":"2023-03-21T20:58:03.750Z","dependent_packages_count":5539,"downloads":null,"downloads_period":null,"dependent_repos_count":43479,"rankings":{"downloads":null,"dependent_repos_count":0.02143944858539713,"dependent_packages_count":0.012222489380460047,"stargazers_count":6.330648393043199,"forks_count":4.613288450749379,"docker_downloads_count":null,"average":2.7443996954396086},"purl":"pkg:maven/ch.qos.logback/logback-core","advisories":[{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZtZmctcmpqbS1yanJq","url":"https://github.com/advisories/GHSA-vmfg-rjjm-rjrj","title":"QOS.ch Logback vulnerable to Deserialization of Untrusted Data","description":"QOS.ch Logback before 1.2.0 has a serialization vulnerability affecting the SocketServer and ServerSocketReceiver components. The RemoteStreamAppenderClient class in logback-classic and the SocketNode classes in logback-classic and logback-access allow data to be deserialized over a Java Socket, via an ObjectInputStream, without validating the data beforehand. When data is received from the Socket, to be logged, it is deserialized into Java objects.An attacker can exploit this vulnerability by sending malicious, serialized Java objects over the connection to the Socket, which may result in execution of arbitrary code when those objects are deserialized. Note that although logback-core is implicated by the Logback project here, the Sonatype Security Research team discovered that the vulnerability is actually present in the logback-classic and logback-access components. Versions prior to 1.2.0 are vulnerable, as stated in the advisory.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2021-06-07T16:07:36.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2017-5929","https://github.com/qos-ch/logback/commit/f46044b805bca91efe5fd6afe52257cd02f775f8","https://access.redhat.com/errata/RHSA-2017:1675","https://access.redhat.com/errata/RHSA-2017:1676","https://access.redhat.com/errata/RHSA-2017:1832","https://access.redhat.com/errata/RHSA-2018:2927","https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2017-5929","https://lists.apache.org/thread.html/18d509024d9aeb07f0e9579066f80bf5d4dcf20467b0c240043890d1@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/a6db61616180d73711d6db25703085940026e2dbc40f153f9d22b203@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/fa4eaaa6ff41ac6f79811e053c152ee89b7c5da8a6ac848ae97df67f@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r0bb19330e48d5ad784fa20dacba9e5538d8d60f5cd9142e0f1432b4b@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r2a08573ddee4a86dc96d469485a5843a01710ee0dc2078dfca410c79@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r2c2d57ca180e8173c90fe313ddf8eabbdcf8e3ae196f8b9f42599790@%3Ccommits.mnemonic.apache.org%3E","https://lists.apache.org/thread.html/r397bf63783240fbb5713389d3f889d287ae0c11509006700ac720037@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r4673642893562c58cbee60c151ded6c077e8a2d02296e862224a9161@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r718f27bed898008a8e037d9cc848cfc1df4d18abcbaee0cb0c142cfb@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/r967953a14e05016bc4bcae9ef3dd92e770181158b4246976ed8295c9@%3Cdev.brooklyn.apache.org%3E","https://lists.apache.org/thread.html/ra007cec726a3927c918ec94c4316d05d1829c49eae8dc3648adc35e2@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rbb4dfca2f7e3e8f3570eec21c79832d33a51dfde6762725660b60169@%3Cdev.mnemonic.apache.org%3E","https://lists.apache.org/thread.html/rc5f0cc2f3b153bdf15ee7389d78585829abc9c7af4d322ba1085dd3e@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rd2227af3c9ada2a72dc72ed05517f5857a34d487580e1f2803922ff9@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/re9b787727291786dfe088e3cd078c7d195c0b5781e15d3cd24a3b2fc@%3Cdev.mnemonic.apache.org%3E","https://logback.qos.ch/news.html","https://lists.apache.org/thread.html/r632ec30791b441e2eb5a3129532bf1b689bf181d0ef7daf50bcf0fd6@%3Ccommits.cassandra.apache.org%3E","https://github.com/advisories/GHSA-vmfg-rjjm-rjrj"],"source_kind":"github","identifiers":["GHSA-vmfg-rjjm-rjrj","CVE-2017-5929"],"repository_url":"https://github.com/qos-ch/logback","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"1.2.0","vulnerable_version_range":"\u003c 1.2.0"}],"ecosystem":"maven","package_name":"ch.qos.logback:logback-core"},{"versions":[{"first_patched_version":"1.2.0","vulnerable_version_range":"\u003c 1.2.0"}],"ecosystem":"maven","package_name":"ch.qos.logback:logback-classic"}],"created_at":"2022-12-21T16:12:59.825Z","updated_at":"2023-01-28T05:00:59.000Z","epss_percentage":0.16014,"epss_percentile":0.94387},{"uuid":"GSA_kwCzR0hTQS02djY3LTJ3cjUtZ3ZmNM4ABCoZ","url":"https://github.com/advisories/GHSA-6v67-2wr5-gvf4","title":"QOS.CH logback-core Server-Side Request Forgery vulnerability","description":"Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logback version 1.5.12 on the Java platform, allows an attacker to forge requests by compromising logback configuration files in XML.\n \nThe attacks involves the modification of DOCTYPE declaration in  XML configuration files.","origin":"UNSPECIFIED","severity":"LOW","published_at":"2024-12-19T18:31:37.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":2.4,"cvss_vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:N/VA:L/SC:H/SI:H/SA:H/V:D/U:Clear","references":["https://nvd.nist.gov/vuln/detail/CVE-2024-12801","https://logback.qos.ch/news.html#1.5.13","https://github.com/qos-ch/logback/commit/5f05041cba4c4ac0a62748c5c527a2da48999f2d","https://logback.qos.ch/news.html#1.3.15","https://github.com/advisories/GHSA-6v67-2wr5-gvf4"],"source_kind":"github","identifiers":["GHSA-6v67-2wr5-gvf4","CVE-2024-12801"],"repository_url":"https://github.com/qos-ch/logback","blast_radius":11.131870912622027,"packages":[{"versions":[{"first_patched_version":"1.3.15","vulnerable_version_range":"\u003c 1.3.15"},{"first_patched_version":"1.5.13","vulnerable_version_range":"\u003e= 1.4.0, \u003c 1.5.13"}],"ecosystem":"maven","package_name":"ch.qos.logback:logback-core"}],"created_at":"2024-12-19T23:08:03.314Z","updated_at":"2025-05-30T01:08:48.126Z","epss_percentage":0.00039,"epss_percentile":0.11116},{"uuid":"GSA_kwCzR0hTQS1wcjk4LTIzZjgtand4ds4ABCog","url":"https://github.com/advisories/GHSA-pr98-23f8-jwxv","title":"QOS.CH logback-core Expression Language Injection vulnerability","description":"ACE vulnerability in JaninoEventEvaluator by QOS.CH logback-core up to and including version 1.5.12 in Java applications allows attackers to execute arbitrary code by compromising an existing logback configuration file or by injecting an environment variable before program execution.\n\nMalicious logback configuration files can allow the attacker to execute arbitrary code using the JaninoEventEvaluator extension.\n\nA successful attack requires the user to have write access to a configuration file. Alternatively, the attacker could inject a malicious environment variable pointing to a malicious configuration file. In both cases, the attack requires existing privilege.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2024-12-19T18:31:37.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":5.9,"cvss_vector":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/RE:L/U:Clear","references":["https://nvd.nist.gov/vuln/detail/CVE-2024-12798","https://logback.qos.ch/news.html#1.5.13","https://github.com/qos-ch/logback/commit/2cb6d520df7592ef1c3a198f1b5df3c10c93e183","https://logback.qos.ch/news.html#1.3.15","https://github.com/advisories/GHSA-pr98-23f8-jwxv"],"source_kind":"github","identifiers":["GHSA-pr98-23f8-jwxv","CVE-2024-12798"],"repository_url":"https://github.com/qos-ch/logback","blast_radius":27.365849326862488,"packages":[{"versions":[{"first_patched_version":"1.3.15","vulnerable_version_range":"\u003c 1.3.15"},{"first_patched_version":"1.5.13","vulnerable_version_range":"\u003e= 1.4.0, \u003c 1.5.13"}],"ecosystem":"maven","package_name":"ch.qos.logback:logback-core"}],"created_at":"2024-12-19T23:08:03.343Z","updated_at":"2025-05-30T01:08:48.146Z","epss_percentage":0.0015,"epss_percentile":0.36716},{"uuid":"GSA_kwCzR0hTQS02NjhxLXFydjctOTlmbc0ctg","url":"https://github.com/advisories/GHSA-668q-qrv7-99fm","title":"Deserialization of Untrusted Data in logback","description":"In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2021-12-17T20:00:50.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2021-42550","https://github.com/cn-panda/logbackRceDemo","https://jira.qos.ch/browse/LOGBACK-1591","http://logback.qos.ch/news.html","https://github.com/qos-ch/logback/commit/87291079a1de9369ac67e20dc70a8fdc7cc4359c","https://github.com/qos-ch/logback/commit/ef4fc4186b74b45ce80d86833820106ff27edd42","https://github.com/qos-ch/logback/blob/1502cba4c1dfd135b2e715bc0cf80c0045d4d128/logback-site/src/site/pages/news.html","https://security.netapp.com/advisory/ntap-20211229-0001/","http://packetstormsecurity.com/files/167794/Open-Xchange-App-Suite-7.10.x-Cross-Site-Scripting-Command-Injection.html","http://seclists.org/fulldisclosure/2022/Jul/11","https://cert-portal.siemens.com/productcert/pdf/ssa-371761.pdf","https://github.com/advisories/GHSA-668q-qrv7-99fm"],"source_kind":"github","identifiers":["GHSA-668q-qrv7-99fm","CVE-2021-42550"],"repository_url":"https://github.com/cn-panda/logbackRceDemo","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"1.2.9","vulnerable_version_range":"\u003c 1.2.9"}],"ecosystem":"maven","package_name":"ch.qos.logback:logback-core"}],"created_at":"2022-12-21T16:12:31.790Z","updated_at":"2023-01-30T05:04:55.000Z","epss_percentage":0.01989,"epss_percentile":0.82532},{"uuid":"GSA_kwCzR0hTQS1nbTYyLXJ3NGctdnJjNM4AA3hi","url":"https://github.com/advisories/GHSA-gm62-rw4g-vrc4","title":"Logback is vulnerable to an attacker mounting a Denial-Of-Service attack by sending poisoned data","description":"A serialization vulnerability in logback receiver component part of logback version 1.4.13, 1.3.13 and 1.2.12 allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.\n","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2023-12-04T09:30:23.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2023-6481","https://logback.qos.ch/news.html#1.3.12","https://logback.qos.ch/news.html#1.3.14","https://github.com/qos-ch/logback/commit/7018a3609c7bcc9dc7bf5903509901a986e5f578","https://github.com/qos-ch/logback/commit/c612b2fa3caf6eef3c75f1cd5859438451d0fd6f","https://github.com/advisories/GHSA-gm62-rw4g-vrc4"],"source_kind":"github","identifiers":["GHSA-gm62-rw4g-vrc4","CVE-2023-6481"],"repository_url":"https://github.com/qos-ch/logback","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"1.2.13","vulnerable_version_range":"= 1.2.12"},{"first_patched_version":"1.3.14","vulnerable_version_range":"= 1.3.13"},{"first_patched_version":"1.4.14","vulnerable_version_range":"= 1.4.13"}],"ecosystem":"maven","package_name":"ch.qos.logback:logback-core"}],"created_at":"2023-12-08T16:05:37.960Z","updated_at":"2023-12-08T15:06:34.000Z","epss_percentage":0.00321,"epss_percentile":0.54494},{"uuid":"GSA_kwCzR0hTQS12bXE2LTVtNjgtZjUzbc4AA3ab","url":"https://github.com/advisories/GHSA-vmq6-5m68-f53m","title":"logback serialization vulnerability","description":"A serialization vulnerability in logback receiver component part of logback allows an attacker to mount a Denial-Of-Service attack by sending poisoned data.\n\nThis is only exploitable if logback receiver component is deployed. See https://logback.qos.ch/manual/receivers.html","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2023-11-29T12:30:16.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2023-6378","https://logback.qos.ch/news.html#1.3.12","https://github.com/qos-ch/logback/commit/9c782b45be4abdafb7e17481e24e7354c2acd1eb","https://github.com/qos-ch/logback/commit/b8eac23a9de9e05fb6d51160b3f46acd91af9731","https://logback.qos.ch/manual/receivers.html","https://github.com/qos-ch/logback/issues/745#issuecomment-1836227158","https://github.com/qos-ch/logback/commit/bb095154be011267b64e37a1d401546e7cc2b7c3","https://logback.qos.ch/news.html#1.2.13","https://security.netapp.com/advisory/ntap-20241129-0012","https://github.com/advisories/GHSA-vmq6-5m68-f53m"],"source_kind":"github","identifiers":["GHSA-vmq6-5m68-f53m","CVE-2023-6378"],"repository_url":"https://github.com/qos-ch/logback","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"1.2.13","vulnerable_version_range":"\u003c 1.2.13"},{"first_patched_version":"1.3.12","vulnerable_version_range":"\u003e= 1.3.0, \u003c 1.3.12"},{"first_patched_version":"1.4.12","vulnerable_version_range":"\u003e= 1.4.0, \u003c 1.4.12"}],"ecosystem":"maven","package_name":"ch.qos.logback:logback-classic"},{"versions":[{"first_patched_version":"1.2.13","vulnerable_version_range":"\u003c 1.2.13"},{"first_patched_version":"1.3.12","vulnerable_version_range":"\u003e= 1.3.0, \u003c 1.3.12"},{"first_patched_version":"1.4.12","vulnerable_version_range":"\u003e= 1.4.0, \u003c 1.4.12"}],"ecosystem":"maven","package_name":"ch.qos.logback:logback-core"}],"created_at":"2023-11-29T22:05:59.047Z","updated_at":"2024-11-29T12:31:48.000Z","epss_percentage":0.00652,"epss_percentile":0.69728}],"docker_usage_url":"https://docker.ecosyste.ms/usage/maven/ch.qos.logback:logback-core","docker_dependents_count":31628,"docker_downloads_count":5044715597,"usage_url":"https://repos.ecosyste.ms/usage/maven/ch.qos.logback:logback-core","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/maven/ch.qos.logback:logback-core/dependencies","status":null,"funding_links":["https://tidelift.com/funding/github/maven/ch.qos.logback:logback-classic","https://github.com/sponsors/qos-ch"],"critical":true,"versions_url":"https://packages.ecosyste.ms/api/v1/registries/repo1.maven.org/packages/ch.qos.logback:logback-core/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/repo1.maven.org/packages/ch.qos.logback:logback-core/version_numbers","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/repo1.maven.org/packages/ch.qos.logback:logback-core/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/repo1.maven.org/packages/ch.qos.logback:logback-core/related_packages","maintainers":[],"registry":{"name":"repo1.maven.org","url":"https://repo.maven.apache.org/maven2","ecosystem":"maven","default":true,"packages_count":517648,"maintainers_count":0,"namespaces_count":68787,"keywords_count":32037,"github":"maven-central","metadata":{"funded_packages_count":24975},"icon_url":"https://github.com/maven-central.png","created_at":"2022-07-21T16:40:13.074Z","updated_at":"2025-06-06T05:59:03.422Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/repo1.maven.org/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/repo1.maven.org/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/repo1.maven.org/namespaces"}},"unique_repositories_count":407,"unique_repositories_count_past_30_days":12,"recent_issues":[{"uuid":"4896866891","node_id":"PR_kwDOAFbEHc7yPm94","number":298,"state":"open","title":"SCANJLIB-320 Bump ch.qos.logback:logback-core from 1.5.21 to 1.5.34 in /its/it-tests","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-07-15T22:36:46.000Z","updated_at":"2026-07-15T22:39:40.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"SCANJLIB-320 Bump","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.5.21","new_version":"1.5.34","repository_url":"https://github.com/qos-ch/logback"}],"path":"/its/it-tests","ecosystem":"maven"},"body":"Bumps [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) from 1.5.21 to 1.5.34.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.34\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-06-01 Release of logback version 1.5.34\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In case certain StackTraceElement values returned by the Throwable.getStackTrace method are null, StackTraceElementProxy substitutes a dummy instance instead of throwing an IllegalArgumentException. This resolves [issues \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003e#1040\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003eqos-ch/logback#1040\u003c/a\u003e), reported by Naotsugu Kobayashi.\u003c/p\u003e\n\u003cp\u003e• HardenedObjectInputStream will now throw an InvalidClassException during deserialization attempts of Proxy classes. This change addresses potential deserialization whitelist bypass vulnerability reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-10532\"\u003eCVE-2026-10532\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bitwise identical binary of this version can be reproduced by building from source code at commit e62272ac152469aec1ede056c3c7d0d7314e7bfe associated with the tag v_1.5.34. This release was built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.32\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-16 Release of logback version 1.5.32\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In \u003ccode\u003eDefaultProcessor, \u003c/code\u003efixed incorrect check for dependencies contained within a parent model. Previous only the direct children were scanned. This fixes \u003ca href=\"https://redirect.github.com/qos-ch/logback-access/issues/34\"\u003elogback-access/issues/34\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit e807335a67535b4eacce94e942c0bcb649665d93 associated with the tag v_1.5.32. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback  1.5.31\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback version 1.5.31\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fixed missing META-INF/services directory in logback-classic.jar. This issue rendered logback-classic version 1.5.30 unusable with SLF4J.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 168e42f9f9a18a3ffdf31eb2bfe80a71e33ecd8b associated with the tag v_1.5.31. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.30\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback  version 1.5.30\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003cstrong\u003eIn this version, logback-classic.jar was missing the META-INF/services directory, making it unusable with SLF4J. Version 1.5.31 (released later on the same day) fixes this issue.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fix scanning issue when an included file becomes available at a later time. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1021\"\u003eissues/1021\u003c/a\u003e by Sergey Nazarov.\u003c/p\u003e\n\u003cp\u003e• Standardized code for version checking across modules.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 44164f10ca3fb44ce0e68519f13564b87e3aca61 associated with the tag v_1.5.30. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.29\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e62272ac152469aec1ede056c3c7d0d7314e7bfe\"\u003e\u003ccode\u003ee62272a\u003c/code\u003e\u003c/a\u003e prepare release 1.5.34\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/1e9e926db1529b729a0e2d29fdee151c2aea0341\"\u003e\u003ccode\u003e1e9e926\u003c/code\u003e\u003c/a\u003e add resolveProxyClassRejectsDynamicProxies unit test\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/2de5cbe90b74fa284685304bc91321313b0d8e2f\"\u003e\u003ccode\u003e2de5cbe\u003c/code\u003e\u003c/a\u003e added StackTraceElementProxyTest, minor edits to AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/0e9b9278b5d3f0b573762cd7b5482ed65244418e\"\u003e\u003ccode\u003e0e9b927\u003c/code\u003e\u003c/a\u003e in case StackTraceElement is null use a substitute, fixing issues/1040\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/f7a0654c2b7e8e1c461e3d9e483e82ef969b5818\"\u003e\u003ccode\u003ef7a0654\u003c/code\u003e\u003c/a\u003e prevent resolveProxyClass bypass\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/249b81f3754f1fb58f8507f244a36c7a940854c0\"\u003e\u003ccode\u003e249b81f\u003c/code\u003e\u003c/a\u003e docs are no longer distributed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/1c3b26a839f05b6bc1769e5a028ef326c711cec8\"\u003e\u003ccode\u003e1c3b26a\u003c/code\u003e\u003c/a\u003e start work on 1.5.34-SNAPSHOT\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.21...v_1.5.34\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=maven\u0026previous-version=1.5.21\u0026new-version=1.5.34)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/SonarSource/sonar-scanner-java-library/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/SonarSource/sonar-scanner-java-library/pull/298","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/SonarSource%2Fsonar-scanner-java-library/issues/298","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/298/packages"},{"uuid":"4858650370","node_id":"PR_kwDONE4-Kc7wWXrY","number":5,"state":"closed","title":"Bump ch.qos.logback:logback-core from 1.5.25 to 1.5.35","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-07-15T22:37:40.000Z","author_association":null,"state_reason":null,"created_at":"2026-07-10T21:05:59.000Z","updated_at":"2026-07-15T22:37:42.000Z","time_to_close":437501,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.5.25","new_version":"1.5.35","repository_url":"https://github.com/qos-ch/logback"}],"path":null,"ecosystem":"maven"},"body":"Bumps [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) from 1.5.25 to 1.5.35.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.35\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e026-06-23 Release of logback version 1.5.35\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• The 'condition' attribute in \u003ccode\u003e\u0026lt;if\u0026gt;\u003c/code\u003e elements now rejects unicode escape sequences (\\u and \\U). This closes a bypass of the existing prohibition on the new operator in Janino-evaluated conditions. This issue was reported by IcySun (\u003ca href=\"mailto:icysun@qq.com\"\u003eicysun@qq.com\u003c/a\u003e) and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-13006\"\u003eCVE-2026-13006\u003c/a\u003e.  \u003cstrong\u003ePlease note that version 1.5.37 provides the full fix to this vulnerability.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Added \u003ccode\u003eConfiguratorRank.AUTHENTICATING\u003c/code\u003e (rank 100), the highest configurator rank, for certified/authenticating configurators discovered via the ServiceLoader mechanism. \u003ccode\u003eContextInitializer\u003c/code\u003e now requires that at most one such configurator exist on the classpath; if more than one is found, initialization aborts with an error.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eConsoleCharsetPropertyDefiner\u003c/code\u003e is no longer shipped. The Java 21 multi-release compilation of logback-core has been disabled, which removes this class from the published artifact. Configurations that referenced \u003ccode\u003ech.qos.logback.core.property.ConsoleCharsetPropertyDefiner\u003c/code\u003e will need an alternative approach for console charset detection.\u003c/p\u003e\n\u003cp\u003e• The logback-examples module is now included in artifacts published to Maven Central.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eJoranConfigurator.makeAnotherInstance()\u003c/code\u003e and \u003ccode\u003eDefaultJoranConfigurator.performMultiStepConfigurationFileSearch()\u003c/code\u003e are now protected, allowing derived configurators to override these methods.\u003c/p\u003e\n\u003cp\u003e• A bitwise identical binary of this version can be reproduced by building from source code at commit 08bd1598d565d83444f72983935e7da4746783b7 associated with the tag v_1.5.35. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.34\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-06-01 Release of logback version 1.5.34\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In case certain StackTraceElement values returned by the Throwable.getStackTrace method are null, StackTraceElementProxy substitutes a dummy instance instead of throwing an IllegalArgumentException. This resolves [issues \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003e#1040\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003eqos-ch/logback#1040\u003c/a\u003e), reported by Naotsugu Kobayashi.\u003c/p\u003e\n\u003cp\u003e• HardenedObjectInputStream will now throw an InvalidClassException during deserialization attempts of Proxy classes. This change addresses potential deserialization whitelist bypass vulnerability reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-10532\"\u003eCVE-2026-10532\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bitwise identical binary of this version can be reproduced by building from source code at commit e62272ac152469aec1ede056c3c7d0d7314e7bfe associated with the tag v_1.5.34. This release was built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.32\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-16 Release of logback version 1.5.32\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In \u003ccode\u003eDefaultProcessor, \u003c/code\u003efixed incorrect check for dependencies contained within a parent model. Previous only the direct children were scanned. This fixes \u003ca href=\"https://redirect.github.com/qos-ch/logback-access/issues/34\"\u003elogback-access/issues/34\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit e807335a67535b4eacce94e942c0bcb649665d93 associated with the tag v_1.5.32. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback  1.5.31\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback version 1.5.31\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fixed missing META-INF/services directory in logback-classic.jar. This issue rendered logback-classic version 1.5.30 unusable with SLF4J.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/08bd1598d565d83444f72983935e7da4746783b7\"\u003e\u003ccode\u003e08bd159\u003c/code\u003e\u003c/a\u003e preapre release 1.5.35\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/37d256b825fc62b4a3908fa29d8b4e34acf79ed0\"\u003e\u003ccode\u003e37d256b\u003c/code\u003e\u003c/a\u003e indentation changes only\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d3d73078afbb0691423f60a066d77503fdf05fc3\"\u003e\u003ccode\u003ed3d7307\u003c/code\u003e\u003c/a\u003e minor comment\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fa0411a9393282ba69396ce65f122d281c079ac0\"\u003e\u003ccode\u003efa0411a\u003c/code\u003e\u003c/a\u003e radomize file location\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/834fdba8085727f96fc12214ff6dd71ab3ac6a25\"\u003e\u003ccode\u003e834fdba\u003c/code\u003e\u003c/a\u003e disable consoleCharset test\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/42eabc374ad8348e9f74e9cd4b59ae5168dd1c2b\"\u003e\u003ccode\u003e42eabc3\u003c/code\u003e\u003c/a\u003e fix messages in IfModelHandler\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/347efc8ec3f10defafd0cf6d4b9a0c81b3320c3a\"\u003e\u003ccode\u003e347efc8\u003c/code\u003e\u003c/a\u003e add unicode escape prevention\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/1b6ba73679437670b37aa1d9061ca82dfd554afb\"\u003e\u003ccode\u003e1b6ba73\u003c/code\u003e\u003c/a\u003e allow derived classes to override makeAnotherInstance\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/340e8be17c9a43d022c301e00b83601affd1fee5\"\u003e\u003ccode\u003e340e8be\u003c/code\u003e\u003c/a\u003e check for unicode escape codes in Janino conditions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/4468f5e5fb67872a14131a7d4feb736131d17202\"\u003e\u003ccode\u003e4468f5e\u003c/code\u003e\u003c/a\u003e adding support for certifying configurators\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.25...v_1.5.35\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=maven\u0026previous-version=1.5.25\u0026new-version=1.5.35)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Marcelektro/SocksProxyServer/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/Marcelektro/SocksProxyServer/pull/5","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Marcelektro%2FSocksProxyServer/issues/5","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/5/packages"},{"uuid":"4858499950","node_id":"PR_kwDOHeGOK87wV47S","number":13,"state":"closed","title":"Bump ch.qos.logback:logback-core from 1.2.11 to 1.5.35 in /java","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-07-15T22:02:50.000Z","author_association":null,"state_reason":null,"created_at":"2026-07-10T20:39:24.000Z","updated_at":"2026-07-15T22:02:52.000Z","time_to_close":437006,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.2.11","new_version":"1.5.35","repository_url":"https://github.com/qos-ch/logback"}],"path":"/java","ecosystem":"maven"},"body":"Bumps [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) from 1.2.11 to 1.5.35.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.35\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e026-06-23 Release of logback version 1.5.35\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• The 'condition' attribute in \u003ccode\u003e\u0026lt;if\u0026gt;\u003c/code\u003e elements now rejects unicode escape sequences (\\u and \\U). This closes a bypass of the existing prohibition on the new operator in Janino-evaluated conditions. This issue was reported by IcySun (\u003ca href=\"mailto:icysun@qq.com\"\u003eicysun@qq.com\u003c/a\u003e) and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-13006\"\u003eCVE-2026-13006\u003c/a\u003e.  \u003cstrong\u003ePlease note that version 1.5.37 provides the full fix to this vulnerability.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Added \u003ccode\u003eConfiguratorRank.AUTHENTICATING\u003c/code\u003e (rank 100), the highest configurator rank, for certified/authenticating configurators discovered via the ServiceLoader mechanism. \u003ccode\u003eContextInitializer\u003c/code\u003e now requires that at most one such configurator exist on the classpath; if more than one is found, initialization aborts with an error.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eConsoleCharsetPropertyDefiner\u003c/code\u003e is no longer shipped. The Java 21 multi-release compilation of logback-core has been disabled, which removes this class from the published artifact. Configurations that referenced \u003ccode\u003ech.qos.logback.core.property.ConsoleCharsetPropertyDefiner\u003c/code\u003e will need an alternative approach for console charset detection.\u003c/p\u003e\n\u003cp\u003e• The logback-examples module is now included in artifacts published to Maven Central.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eJoranConfigurator.makeAnotherInstance()\u003c/code\u003e and \u003ccode\u003eDefaultJoranConfigurator.performMultiStepConfigurationFileSearch()\u003c/code\u003e are now protected, allowing derived configurators to override these methods.\u003c/p\u003e\n\u003cp\u003e• A bitwise identical binary of this version can be reproduced by building from source code at commit 08bd1598d565d83444f72983935e7da4746783b7 associated with the tag v_1.5.35. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.34\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-06-01 Release of logback version 1.5.34\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In case certain StackTraceElement values returned by the Throwable.getStackTrace method are null, StackTraceElementProxy substitutes a dummy instance instead of throwing an IllegalArgumentException. This resolves [issues \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003e#1040\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003eqos-ch/logback#1040\u003c/a\u003e), reported by Naotsugu Kobayashi.\u003c/p\u003e\n\u003cp\u003e• HardenedObjectInputStream will now throw an InvalidClassException during deserialization attempts of Proxy classes. This change addresses potential deserialization whitelist bypass vulnerability reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-10532\"\u003eCVE-2026-10532\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bitwise identical binary of this version can be reproduced by building from source code at commit e62272ac152469aec1ede056c3c7d0d7314e7bfe associated with the tag v_1.5.34. This release was built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.32\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-16 Release of logback version 1.5.32\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In \u003ccode\u003eDefaultProcessor, \u003c/code\u003efixed incorrect check for dependencies contained within a parent model. Previous only the direct children were scanned. This fixes \u003ca href=\"https://redirect.github.com/qos-ch/logback-access/issues/34\"\u003elogback-access/issues/34\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit e807335a67535b4eacce94e942c0bcb649665d93 associated with the tag v_1.5.32. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback  1.5.31\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback version 1.5.31\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fixed missing META-INF/services directory in logback-classic.jar. This issue rendered logback-classic version 1.5.30 unusable with SLF4J.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/08bd1598d565d83444f72983935e7da4746783b7\"\u003e\u003ccode\u003e08bd159\u003c/code\u003e\u003c/a\u003e preapre release 1.5.35\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/37d256b825fc62b4a3908fa29d8b4e34acf79ed0\"\u003e\u003ccode\u003e37d256b\u003c/code\u003e\u003c/a\u003e indentation changes only\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d3d73078afbb0691423f60a066d77503fdf05fc3\"\u003e\u003ccode\u003ed3d7307\u003c/code\u003e\u003c/a\u003e minor comment\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fa0411a9393282ba69396ce65f122d281c079ac0\"\u003e\u003ccode\u003efa0411a\u003c/code\u003e\u003c/a\u003e radomize file location\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/834fdba8085727f96fc12214ff6dd71ab3ac6a25\"\u003e\u003ccode\u003e834fdba\u003c/code\u003e\u003c/a\u003e disable consoleCharset test\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/42eabc374ad8348e9f74e9cd4b59ae5168dd1c2b\"\u003e\u003ccode\u003e42eabc3\u003c/code\u003e\u003c/a\u003e fix messages in IfModelHandler\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/347efc8ec3f10defafd0cf6d4b9a0c81b3320c3a\"\u003e\u003ccode\u003e347efc8\u003c/code\u003e\u003c/a\u003e add unicode escape prevention\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/1b6ba73679437670b37aa1d9061ca82dfd554afb\"\u003e\u003ccode\u003e1b6ba73\u003c/code\u003e\u003c/a\u003e allow derived classes to override makeAnotherInstance\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/340e8be17c9a43d022c301e00b83601affd1fee5\"\u003e\u003ccode\u003e340e8be\u003c/code\u003e\u003c/a\u003e check for unicode escape codes in Janino conditions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/4468f5e5fb67872a14131a7d4feb736131d17202\"\u003e\u003ccode\u003e4468f5e\u003c/code\u003e\u003c/a\u003e adding support for certifying configurators\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.2.11...v_1.5.35\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=maven\u0026previous-version=1.2.11\u0026new-version=1.5.35)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Nortech-ai/tahu/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/Nortech-ai/tahu/pull/13","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Nortech-ai%2Ftahu/issues/13","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/13/packages"},{"uuid":"4815673816","node_id":"PR_kwDOAWH1ps7uKwyK","number":2963,"state":"open","title":"Bump ch.qos.logback:logback-core from 1.5.25 to 1.5.33","user":"dependabot[bot]","labels":["java","dependencies"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-07-06T03:19:34.000Z","updated_at":"2026-07-06T03:29:13.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.5.25","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"}],"path":null,"ecosystem":"maven"},"body":"Bumps [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) from 1.5.25 to 1.5.33.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.32\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-16 Release of logback version 1.5.32\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In \u003ccode\u003eDefaultProcessor, \u003c/code\u003efixed incorrect check for dependencies contained within a parent model. Previous only the direct children were scanned. This fixes \u003ca href=\"https://redirect.github.com/qos-ch/logback-access/issues/34\"\u003elogback-access/issues/34\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit e807335a67535b4eacce94e942c0bcb649665d93 associated with the tag v_1.5.32. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback  1.5.31\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback version 1.5.31\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fixed missing META-INF/services directory in logback-classic.jar. This issue rendered logback-classic version 1.5.30 unusable with SLF4J.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 168e42f9f9a18a3ffdf31eb2bfe80a71e33ecd8b associated with the tag v_1.5.31. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.30\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback  version 1.5.30\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003cstrong\u003eIn this version, logback-classic.jar was missing the META-INF/services directory, making it unusable with SLF4J. Version 1.5.31 (released later on the same day) fixes this issue.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fix scanning issue when an included file becomes available at a later time. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1021\"\u003eissues/1021\u003c/a\u003e by Sergey Nazarov.\u003c/p\u003e\n\u003cp\u003e• Standardized code for version checking across modules.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 44164f10ca3fb44ce0e68519f13564b87e3aca61 associated with the tag v_1.5.30. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.29\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-09 Release of logback version 1.5.29\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In response to \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1017\"\u003eissues/1017\u003c/a\u003e, appender names and appender references are once again subject to variable substitution, reverting the change introduced in version 1.5.28.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.28\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-06 Release of logback version 1.5.28\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Appender names or appender references are no longer subject to variable substitution.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.25...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=maven\u0026previous-version=1.5.25\u0026new-version=1.5.33)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/DataBiosphere/consent/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/DataBiosphere/consent/pull/2963","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/DataBiosphere%2Fconsent/issues/2963","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2963/packages"},{"uuid":"4815180474","node_id":"PR_kwDOMCQIy87uJR5J","number":254,"state":"open","title":"Bump ch.qos.logback:logback-core from 1.5.19 to 1.5.33 in /public/common/buildsupport/logging in the maven group across 1 directory","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-07-06T01:08:45.000Z","updated_at":"2026-07-06T01:09:23.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.5.19","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"}],"path":"/public/common/buildsupport/logging in the maven group across 1 directory","ecosystem":"maven"},"body":"Bumps the maven group with 1 update in the /public/common/buildsupport/logging directory: [ch.qos.logback:logback-core](https://github.com/qos-ch/logback).\n\nUpdates `ch.qos.logback:logback-core` from 1.5.19 to 1.5.33\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.32\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-16 Release of logback version 1.5.32\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In \u003ccode\u003eDefaultProcessor, \u003c/code\u003efixed incorrect check for dependencies contained within a parent model. Previous only the direct children were scanned. This fixes \u003ca href=\"https://redirect.github.com/qos-ch/logback-access/issues/34\"\u003elogback-access/issues/34\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit e807335a67535b4eacce94e942c0bcb649665d93 associated with the tag v_1.5.32. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback  1.5.31\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback version 1.5.31\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fixed missing META-INF/services directory in logback-classic.jar. This issue rendered logback-classic version 1.5.30 unusable with SLF4J.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 168e42f9f9a18a3ffdf31eb2bfe80a71e33ecd8b associated with the tag v_1.5.31. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.30\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback  version 1.5.30\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003cstrong\u003eIn this version, logback-classic.jar was missing the META-INF/services directory, making it unusable with SLF4J. Version 1.5.31 (released later on the same day) fixes this issue.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fix scanning issue when an included file becomes available at a later time. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1021\"\u003eissues/1021\u003c/a\u003e by Sergey Nazarov.\u003c/p\u003e\n\u003cp\u003e• Standardized code for version checking across modules.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 44164f10ca3fb44ce0e68519f13564b87e3aca61 associated with the tag v_1.5.30. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.29\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-09 Release of logback version 1.5.29\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In response to \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1017\"\u003eissues/1017\u003c/a\u003e, appender names and appender references are once again subject to variable substitution, reverting the change introduced in version 1.5.28.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.28\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-06 Release of logback version 1.5.28\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Appender names or appender references are no longer subject to variable substitution.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.19...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=maven\u0026previous-version=1.5.19\u0026new-version=1.5.33)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/SherfeyInv/nexus-public/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/SherfeyInv/nexus-public/pull/254","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/SherfeyInv%2Fnexus-public/issues/254","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/254/packages"},{"uuid":"4814622573","node_id":"PR_kwDOJGOX7c7uHluq","number":126,"state":"closed","title":"Bump ch.qos.logback:logback-core from 1.5.32 to 1.5.33 in /bundles/org.openhab.core.test","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-07-10T21:07:13.000Z","author_association":null,"state_reason":null,"created_at":"2026-07-05T22:11:06.000Z","updated_at":"2026-07-10T21:07:15.000Z","time_to_close":428167,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.5.32","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"}],"path":"/bundles/org.openhab.core.test","ecosystem":"maven"},"body":"Bumps [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) from 1.5.32 to 1.5.33.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=maven\u0026previous-version=1.5.32\u0026new-version=1.5.33)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/holgerfriedrich/openhab-core/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/holgerfriedrich/openhab-core/pull/126","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/holgerfriedrich%2Fopenhab-core/issues/126","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/126/packages"},{"uuid":"4814605856","node_id":"PR_kwDORTkenM7uHikD","number":47,"state":"open","title":"build(deps): bump ch.qos.logback:logback-core from 1.5.32 to 1.5.33","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-07-05T22:05:11.000Z","updated_at":"2026-07-05T22:07:15.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps)","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.5.32","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"}],"path":null,"ecosystem":"maven"},"body":"Bumps [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) from 1.5.32 to 1.5.33.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=maven\u0026previous-version=1.5.32\u0026new-version=1.5.33)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/KyrieChao/Failure/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/KyrieChao/Failure/pull/47","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/KyrieChao%2FFailure/issues/47","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/47/packages"},{"uuid":"4814012490","node_id":"PR_kwDOEeHssM7uFxPz","number":25,"state":"closed","title":"Bump ch.qos.logback:logback-core from 1.0.9 to 1.5.33","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-07-10T18:39:35.000Z","author_association":null,"state_reason":null,"created_at":"2026-07-05T18:44:54.000Z","updated_at":"2026-07-10T18:39:37.000Z","time_to_close":431681,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.0.9","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"}],"path":null,"ecosystem":"maven"},"body":"Bumps [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) from 1.0.9 to 1.5.33.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.32\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-16 Release of logback version 1.5.32\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In \u003ccode\u003eDefaultProcessor, \u003c/code\u003efixed incorrect check for dependencies contained within a parent model. Previous only the direct children were scanned. This fixes \u003ca href=\"https://redirect.github.com/qos-ch/logback-access/issues/34\"\u003elogback-access/issues/34\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit e807335a67535b4eacce94e942c0bcb649665d93 associated with the tag v_1.5.32. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback  1.5.31\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback version 1.5.31\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fixed missing META-INF/services directory in logback-classic.jar. This issue rendered logback-classic version 1.5.30 unusable with SLF4J.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 168e42f9f9a18a3ffdf31eb2bfe80a71e33ecd8b associated with the tag v_1.5.31. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.30\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback  version 1.5.30\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003cstrong\u003eIn this version, logback-classic.jar was missing the META-INF/services directory, making it unusable with SLF4J. Version 1.5.31 (released later on the same day) fixes this issue.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fix scanning issue when an included file becomes available at a later time. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1021\"\u003eissues/1021\u003c/a\u003e by Sergey Nazarov.\u003c/p\u003e\n\u003cp\u003e• Standardized code for version checking across modules.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 44164f10ca3fb44ce0e68519f13564b87e3aca61 associated with the tag v_1.5.30. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.29\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-09 Release of logback version 1.5.29\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In response to \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1017\"\u003eissues/1017\u003c/a\u003e, appender names and appender references are once again subject to variable substitution, reverting the change introduced in version 1.5.28.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.28\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-06 Release of logback version 1.5.28\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Appender names or appender references are no longer subject to variable substitution.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.0.9...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=maven\u0026previous-version=1.0.9\u0026new-version=1.5.33)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/data-integrations/hierarchy-plugins/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/data-integrations/hierarchy-plugins/pull/25","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/data-integrations%2Fhierarchy-plugins/issues/25","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/25/packages"},{"uuid":"4813818836","node_id":"PR_kwDOBpB9J87uFMEH","number":175,"state":"closed","title":"Bump ch.qos.logback:logback-core from 1.5.25 to 1.5.33 in /spring-boot-project/spring-boot-dependencies","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-07-10T15:45:23.000Z","author_association":null,"state_reason":null,"created_at":"2026-07-05T17:41:07.000Z","updated_at":"2026-07-10T15:45:25.000Z","time_to_close":425056,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.5.25","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"}],"path":"/spring-boot-project/spring-boot-dependencies","ecosystem":"maven"},"body":"Bumps [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) from 1.5.25 to 1.5.33.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.32\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-16 Release of logback version 1.5.32\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In \u003ccode\u003eDefaultProcessor, \u003c/code\u003efixed incorrect check for dependencies contained within a parent model. Previous only the direct children were scanned. This fixes \u003ca href=\"https://redirect.github.com/qos-ch/logback-access/issues/34\"\u003elogback-access/issues/34\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit e807335a67535b4eacce94e942c0bcb649665d93 associated with the tag v_1.5.32. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback  1.5.31\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback version 1.5.31\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fixed missing META-INF/services directory in logback-classic.jar. This issue rendered logback-classic version 1.5.30 unusable with SLF4J.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 168e42f9f9a18a3ffdf31eb2bfe80a71e33ecd8b associated with the tag v_1.5.31. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.30\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback  version 1.5.30\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003cstrong\u003eIn this version, logback-classic.jar was missing the META-INF/services directory, making it unusable with SLF4J. Version 1.5.31 (released later on the same day) fixes this issue.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fix scanning issue when an included file becomes available at a later time. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1021\"\u003eissues/1021\u003c/a\u003e by Sergey Nazarov.\u003c/p\u003e\n\u003cp\u003e• Standardized code for version checking across modules.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 44164f10ca3fb44ce0e68519f13564b87e3aca61 associated with the tag v_1.5.30. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.29\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-09 Release of logback version 1.5.29\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In response to \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1017\"\u003eissues/1017\u003c/a\u003e, appender names and appender references are once again subject to variable substitution, reverting the change introduced in version 1.5.28.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.28\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-06 Release of logback version 1.5.28\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Appender names or appender references are no longer subject to variable substitution.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.25...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=maven\u0026previous-version=1.5.25\u0026new-version=1.5.33)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Thoogend1/IDH10-MeerBier/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/Thoogend1/IDH10-MeerBier/pull/175","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Thoogend1%2FIDH10-MeerBier/issues/175","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/175/packages"},{"uuid":"4807816526","node_id":"PR_kwDON2_zC87tzT2e","number":481,"state":"open","title":"Bump ch.qos.logback:logback-core from 1.5.13 to 1.5.33 in /samples/client/petstore/jaxrs-cxf-client","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":6,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-07-04T05:43:40.000Z","updated_at":"2026-07-04T05:46:25.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.5.13","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"}],"path":"/samples/client/petstore/jaxrs-cxf-client","ecosystem":"maven"},"body":"Bumps [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) from 1.5.13 to 1.5.33.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.32\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-16 Release of logback version 1.5.32\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In \u003ccode\u003eDefaultProcessor, \u003c/code\u003efixed incorrect check for dependencies contained within a parent model. Previous only the direct children were scanned. This fixes \u003ca href=\"https://redirect.github.com/qos-ch/logback-access/issues/34\"\u003elogback-access/issues/34\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit e807335a67535b4eacce94e942c0bcb649665d93 associated with the tag v_1.5.32. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback  1.5.31\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback version 1.5.31\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fixed missing META-INF/services directory in logback-classic.jar. This issue rendered logback-classic version 1.5.30 unusable with SLF4J.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 168e42f9f9a18a3ffdf31eb2bfe80a71e33ecd8b associated with the tag v_1.5.31. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.30\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback  version 1.5.30\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003cstrong\u003eIn this version, logback-classic.jar was missing the META-INF/services directory, making it unusable with SLF4J. Version 1.5.31 (released later on the same day) fixes this issue.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fix scanning issue when an included file becomes available at a later time. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1021\"\u003eissues/1021\u003c/a\u003e by Sergey Nazarov.\u003c/p\u003e\n\u003cp\u003e• Standardized code for version checking across modules.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 44164f10ca3fb44ce0e68519f13564b87e3aca61 associated with the tag v_1.5.30. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.29\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-09 Release of logback version 1.5.29\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In response to \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1017\"\u003eissues/1017\u003c/a\u003e, appender names and appender references are once again subject to variable substitution, reverting the change introduced in version 1.5.28.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.28\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-06 Release of logback version 1.5.28\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Appender names or appender references are no longer subject to variable substitution.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.13...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=maven\u0026previous-version=1.5.13\u0026new-version=1.5.33)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Dustin4444/openapi-generator/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/Dustin4444/openapi-generator/pull/481","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Dustin4444%2Fopenapi-generator/issues/481","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/481/packages"},{"uuid":"4777750847","node_id":"PR_kwDOCWqSlc7sRcGV","number":2263,"state":"open","title":"Bump ch.qos.logback:logback-core from 1.5.20 to 1.5.35","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-06-30T14:38:52.000Z","updated_at":"2026-06-30T14:41:08.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.5.20","new_version":"1.5.35","repository_url":"https://github.com/qos-ch/logback"}],"path":null,"ecosystem":"maven"},"body":"Bumps [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) from 1.5.20 to 1.5.35.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.35\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e026-06-23 Release of logback version 1.5.35\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• The 'condition' attribute in \u003ccode\u003e\u0026lt;if\u0026gt;\u003c/code\u003e elements now rejects unicode escape sequences (\\u and \\U). This closes a bypass of the existing prohibition on the new operator in Janino-evaluated conditions. This issue was reported by IcySun (\u003ca href=\"mailto:icysun@qq.com\"\u003eicysun@qq.com\u003c/a\u003e) and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-13006\"\u003eCVE-2026-13006\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• Added \u003ccode\u003eConfiguratorRank.AUTHENTICATING\u003c/code\u003e (rank 100), the highest configurator rank, for certified/authenticating configurators discovered via the ServiceLoader mechanism. \u003ccode\u003eContextInitializer\u003c/code\u003e now requires that at most one such configurator exist on the classpath; if more than one is found, initialization aborts with an error.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eConsoleCharsetPropertyDefiner\u003c/code\u003e is no longer shipped. The Java 21 multi-release compilation of logback-core has been disabled, which removes this class from the published artifact. Configurations that referenced \u003ccode\u003ech.qos.logback.core.property.ConsoleCharsetPropertyDefiner\u003c/code\u003e will need an alternative approach for console charset detection.\u003c/p\u003e\n\u003cp\u003e• The logback-examples module is now included in artifacts published to Maven Central.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eJoranConfigurator.makeAnotherInstance()\u003c/code\u003e and \u003ccode\u003eDefaultJoranConfigurator.performMultiStepConfigurationFileSearch()\u003c/code\u003e are now protected, allowing derived configurators to override these methods.\u003c/p\u003e\n\u003cp\u003e• A bitwise identical binary of this version can be reproduced by building from source code at commit 08bd1598d565d83444f72983935e7da4746783b7 associated with the tag v_1.5.35. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.34\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-06-01 Release of logback version 1.5.34\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In case certain StackTraceElement values returned by the Throwable.getStackTrace method are null, StackTraceElementProxy substitutes a dummy instance instead of throwing an IllegalArgumentException. This resolves [issues \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003e#1040\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003eqos-ch/logback#1040\u003c/a\u003e), reported by Naotsugu Kobayashi.\u003c/p\u003e\n\u003cp\u003e• HardenedObjectInputStream will now throw an InvalidClassException during deserialization attempts of Proxy classes. This change addresses potential deserialization whitelist bypass vulnerability reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-10532\"\u003eCVE-2026-10532\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bitwise identical binary of this version can be reproduced by building from source code at commit e62272ac152469aec1ede056c3c7d0d7314e7bfe associated with the tag v_1.5.34. This release was built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.32\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-16 Release of logback version 1.5.32\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In \u003ccode\u003eDefaultProcessor, \u003c/code\u003efixed incorrect check for dependencies contained within a parent model. Previous only the direct children were scanned. This fixes \u003ca href=\"https://redirect.github.com/qos-ch/logback-access/issues/34\"\u003elogback-access/issues/34\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit e807335a67535b4eacce94e942c0bcb649665d93 associated with the tag v_1.5.32. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback  1.5.31\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback version 1.5.31\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fixed missing META-INF/services directory in logback-classic.jar. This issue rendered logback-classic version 1.5.30 unusable with SLF4J.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/08bd1598d565d83444f72983935e7da4746783b7\"\u003e\u003ccode\u003e08bd159\u003c/code\u003e\u003c/a\u003e preapre release 1.5.35\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/37d256b825fc62b4a3908fa29d8b4e34acf79ed0\"\u003e\u003ccode\u003e37d256b\u003c/code\u003e\u003c/a\u003e indentation changes only\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d3d73078afbb0691423f60a066d77503fdf05fc3\"\u003e\u003ccode\u003ed3d7307\u003c/code\u003e\u003c/a\u003e minor comment\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fa0411a9393282ba69396ce65f122d281c079ac0\"\u003e\u003ccode\u003efa0411a\u003c/code\u003e\u003c/a\u003e radomize file location\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/834fdba8085727f96fc12214ff6dd71ab3ac6a25\"\u003e\u003ccode\u003e834fdba\u003c/code\u003e\u003c/a\u003e disable consoleCharset test\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/42eabc374ad8348e9f74e9cd4b59ae5168dd1c2b\"\u003e\u003ccode\u003e42eabc3\u003c/code\u003e\u003c/a\u003e fix messages in IfModelHandler\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/347efc8ec3f10defafd0cf6d4b9a0c81b3320c3a\"\u003e\u003ccode\u003e347efc8\u003c/code\u003e\u003c/a\u003e add unicode escape prevention\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/1b6ba73679437670b37aa1d9061ca82dfd554afb\"\u003e\u003ccode\u003e1b6ba73\u003c/code\u003e\u003c/a\u003e allow derived classes to override makeAnotherInstance\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/340e8be17c9a43d022c301e00b83601affd1fee5\"\u003e\u003ccode\u003e340e8be\u003c/code\u003e\u003c/a\u003e check for unicode escape codes in Janino conditions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/4468f5e5fb67872a14131a7d4feb736131d17202\"\u003e\u003ccode\u003e4468f5e\u003c/code\u003e\u003c/a\u003e adding support for certifying configurators\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.20...v_1.5.35\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=maven\u0026previous-version=1.5.20\u0026new-version=1.5.35)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/navikt/veilarbportefolje/pull/2263","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/navikt%2Fveilarbportefolje/issues/2263","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2263/packages"},{"uuid":"4746076339","node_id":"PR_kwDOSh_Isc7qrGPx","number":28,"state":"open","title":"chore(deps): bump ch.qos.logback:logback-core from 1.3.12 to 1.5.25 in the gradle group across 1 directory","user":"dependabot[bot]","labels":["dependency-upgrade"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-06-25T17:34:27.000Z","updated_at":"2026-06-25T17:40:53.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.3.12","new_version":"1.5.25","repository_url":"https://github.com/qos-ch/logback"}],"path":"the gradle group across 1 directory","ecosystem":"maven"},"body":"Bumps the gradle group with 1 update in the / directory: [ch.qos.logback:logback-core](https://github.com/qos-ch/logback).\n\nUpdates `ch.qos.logback:logback-core` from 1.3.12 to 1.5.25\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.25\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-01-17 Release of logback version 1.5.25\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• When processing configuration files, logback-core will now only instantiate components compatible with the class expected by the encapsulating class. This fixes an ACE vulnerability recorded as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-1225\"\u003eCVE-2026-1225\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• In configuration files, referencing a single undeclared appender would cause all referenced appenders to be skipped. This issue was discovered in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/997\"\u003eissues/997\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• Added VersionUtil class to logback-core. This utility class checks for version compatibility issues and alerts the user if need be.\u003c/p\u003e\n\u003cp\u003e• Added \u003ca href=\"https://logback.qos.ch/manual/layouts.html#epoch\"\u003eEpochConverter\u003c/a\u003e to output milliseconds/seconds since epoch. This enhancement was requested by Duncan Jauncey in \u003ca href=\"https://redirect.github.com/qos-ch/logback/pull/1000\"\u003eissues/1000\u003c/a\u003e who also provided the relevant implementation PR.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit f426e0002800cfb507f393fcacffe0761a425220 associated with the tag v_1.5.25. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.24\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-01-06 Release of logback version 1.5.24\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Added ExpressionPropertyCondition a PropertyCondition that can evaluate boolean expressions similar to Java. See \u003ca href=\"https://logback.qos.ch/manual/configuration.html#conditionalExp\"\u003ethe relevant documentation\u003c/a\u003e for further details.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 62bc5fc245dd3a52f3dd45e232733f4cefb4806d associated with the tag v_1.5.24. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.23\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2025-12-21 Release of logback version 1.5.23\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In response to \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/959\"\u003eissues/959\u003c/a\u003e file name collisions are detected at configuration time by analyzing the configuration file and no longer at run time. This avoids the \u003ccode\u003eConcurrentModificationException\u003c/code\u003e reported in the issue.\u003c/p\u003e\n\u003cp\u003e• ZIP and XZ compression now use a \u003ccode\u003eBufferedOutputStream\u003c/code\u003e when writing to the compressed file. This issue was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/988\"\u003eissues/988\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 0bcc3feb54a6d99caac70969ee5f8334aad1fbaf associated with the tag v_1.5.23. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.22\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2025-12-11 Release of logback version 1.5.22\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In order to prevent involuntary information leakage, Logback will no longer output the value of a substituted variable, if the variable name contains any of the case-insensitive strings \u0026quot;password\u0026quot;, \u0026quot;secret\u0026quot; or \u0026quot;confidential\u0026quot;. This problem was reported by Chintan Rohila in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/986\"\u003eissues/986\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• Logback now takes the overridden \u003ccode\u003etoString()\u003c/code\u003e method of \u003ccode\u003eThrowable\u003c/code\u003e subclasses into account when  printing stack traces. This issue was reported in \u003ca href=\"https://jira.qos.ch/browse/LOGBACK-543\"\u003eLOGBACK-543\u003c/a\u003e by Alvin Chee, with a fix provided in \u003ca href=\"https://redirect.github.com/qos-ch/logback/pull/404\"\u003ePR 404\u003c/a\u003e by Brett Kail.\u003c/p\u003e\n\u003cp\u003e• Instead of limit-counting guard, Logback now uses a tumbling-window guard to rate limit internal error messages.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 572379aabd2f672b49593e4020696c624541e5b0 associated with the tag v_1.5.22. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.21\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2025-11-10 Release of logback version 1.5.21\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Invocations of turbo filters in isDebugEnabled, isInfoEnabled()... remain as they were, untouched. However, any installed instances of TurboFilter are now invoked also from within the log(LoggingEvent) method of \u003ca href=\"https://github.com/qos-ch/logback/blob/master/logback-classic/src/main/java/ch/qos/logback/classic/Logger.java#L817\"\u003eLogger\u003c/a\u003e with the contents of the LoggingEvent, typically via the fluent API. This fixes \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/871\"\u003eissues/871\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• Removed reentry-guard in most subclasses of \u003ccode\u003eUnsynchronizedAppenderBase\u003c/code\u003e where it was not needed.\u003c/p\u003e\n\u003cp\u003e• \u003ca href=\"https://logback.qos.ch/manual/configuration.html#auto_configuration\"\u003eInitialization procedure\u003c/a\u003e has been simplified by removing the step instantiating a \u003ccode\u003eSerializedModelConfigurator\u003c/code\u003e. However, it is still possible to set up \u003ccode\u003eSerializedModelConfigurator\u003c/code\u003e as a custom configurator.\u003c/p\u003e\n\u003cp\u003e• JsonEncoder is now friendlier to derivation by sub-classes as requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/979\"\u003eissues/979.\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/f426e0002800cfb507f393fcacffe0761a425220\"\u003e\u003ccode\u003ef426e00\u003c/code\u003e\u003c/a\u003e prepare release of 1.5.25\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d28931f3b9ede954285cd22d44e029142bba52e6\"\u003e\u003ccode\u003ed28931f\u003c/code\u003e\u003c/a\u003e restrict object creation to expected supertype\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/aa264f7ad2bb65c2d5ab046754741e56234c9096\"\u003e\u003ccode\u003eaa264f7\u003c/code\u003e\u003c/a\u003e test default variable values in appender-ref ref attribute\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/8fb403ab6d1a36b351e9095f8ee1c6c3ad8e0405\"\u003e\u003ccode\u003e8fb403a\u003c/code\u003e\u003c/a\u003e adjust copyright year\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b294a12ff9f2bb2f03168590da1c6d7cbfd71cfe\"\u003e\u003ccode\u003eb294a12\u003c/code\u003e\u003c/a\u003e check optionList in start()\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b65040a3b5d844a791bd3cc690ca44e9e024e04d\"\u003e\u003ccode\u003eb65040a\u003c/code\u003e\u003c/a\u003e Add EpochConverter for milliseconds/seconds since epoch (related to issue \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/96\"\u003e#96\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/069017445b41e9c3a23bda2be446663dca3c4453\"\u003e\u003ccode\u003e0690174\u003c/code\u003e\u003c/a\u003e cla for Duncan Jauncey\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/71dc2afc1046e7b7e218dbfbcde3b0c549bc2fba\"\u003e\u003ccode\u003e71dc2af\u003c/code\u003e\u003c/a\u003e Removed email address for Tony.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/1f97ae1844b1be8486e4e9cade98d7123d3eded5\"\u003e\u003ccode\u003e1f97ae1\u003c/code\u003e\u003c/a\u003e check for undeclared by referenced appenders\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b07355e26aaf128c8303393b7e2ed3d4687c7736\"\u003e\u003ccode\u003eb07355e\u003c/code\u003e\u003c/a\u003e Move the artifact version checking code to VersionUtil in logback-core.\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.3.12...v_1.5.25\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=gradle\u0026previous-version=1.3.12\u0026new-version=1.5.25)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/kestra-io/plugin-huawei/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/kestra-io/plugin-huawei/pull/28","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/kestra-io%2Fplugin-huawei/issues/28","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/28/packages"},{"uuid":"4620762590","node_id":"PR_kwDORpI3ds7kT5Y4","number":134,"state":"closed","title":"build(deps): bump the all-maven group across 1 directory with 115 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-06-14T02:02:27.000Z","author_association":null,"state_reason":null,"created_at":"2026-06-09T09:33:49.000Z","updated_at":"2026-06-14T02:02:36.000Z","time_to_close":404918,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"all-maven","update_count":115,"packages":[{"name":"org.springframework.boot:spring-boot-starter-parent","old_version":"3.5.14","new_version":"4.0.6","repository_url":"https://github.com/spring-projects/spring-boot"},{"name":"org.springframework.ai:spring-ai-bom","old_version":"1.0.0","new_version":"1.1.7","repository_url":"https://github.com/spring-projects/spring-ai"},{"name":"com.squareup.okio:okio-jvm","old_version":"3.6.0","new_version":"3.17.0","repository_url":"https://github.com/square/okio"},{"name":"com.squareup.okio:okio","old_version":"3.4.0","new_version":"3.17.0","repository_url":"https://github.com/square/okio"},{"name":"org.springframework.cloud:spring-cloud-dependencies","old_version":"2025.0.2","new_version":"2025.1.1","repository_url":"https://github.com/spring-cloud/spring-cloud-release"},{"name":"io.opentelemetry.instrumentation:opentelemetry-instrumentation-annotations","old_version":"2.22.0","new_version":"2.28.1","repository_url":"https://github.com/open-telemetry/opentelemetry-java-instrumentation"},{"name":"org.apache.xmlbeans:xmlbeans","old_version":"5.1.1","new_version":"5.3.0"},{"name":"commons-io:commons-io","old_version":"2.19.0","new_version":"2.22.0"},{"name":"org.jsoup:jsoup","old_version":"1.18.1","new_version":"1.22.2","repository_url":"https://github.com/jhy/jsoup"},{"name":"org.jetbrains:annotations","old_version":"24.0.1","new_version":"26.1.0","repository_url":"https://github.com/JetBrains/java-annotations"},{"name":"org.apache.commons:commons-compress","old_version":"1.24.0","new_version":"1.28.0","repository_url":"https://github.com/apache/commons-compress"},{"name":"com.github.pagehelper:pagehelper","old_version":"5.3.3","new_version":"6.1.1","repository_url":"https://github.com/pagehelper/Mybatis-PageHelper"},{"name":"com.iwhaleai.byai:by-framework","old_version":"0.2.6","new_version":"0.2.8"},{"name":"com.fasterxml.woodstox:woodstox-core","old_version":"7.0.0","new_version":"7.2.1","repository_url":"https://github.com/FasterXML/woodstox"},{"name":"org.glassfish.hk2:hk2-api","old_version":"3.1.1","new_version":"4.0.1"},{"name":"org.eclipse.parsson:parsson","old_version":"1.1.7","new_version":"1.1.9","repository_url":"https://github.com/eclipse-ee4j/parsson"},{"name":"com.google.errorprone:error_prone_annotations","old_version":"2.36.0","new_version":"2.49.0"},{"name":"org.opengauss:opengauss-jdbc","old_version":"6.0.0","new_version":"6.0.3"},{"name":"com.alibaba:druid","old_version":"1.2.23","new_version":"1.2.28","repository_url":"https://github.com/alibaba/druid"},{"name":"com.mysql:mysql-connector-j","old_version":"8.4.0","new_version":"9.7.0","repository_url":"https://github.com/mysql/mysql-connector-j"},{"name":"org.mybatis:mybatis","old_version":"3.5.14","new_version":"3.5.19","repository_url":"https://github.com/mybatis/mybatis-3"},{"name":"org.mybatis:mybatis-spring","old_version":"3.0.3","new_version":"4.0.0","repository_url":"https://github.com/mybatis/spring"},{"name":"org.apache.commons:commons-lang3","old_version":"3.13.0","new_version":"3.20.0"},{"name":"org.apache.commons:commons-collections4","old_version":"4.4","new_version":"4.5.0"},{"name":"commons-codec:commons-codec","old_version":"1.16.0","new_version":"1.22.0","repository_url":"https://github.com/apache/commons-codec"},{"name":"jakarta.xml.bind:jakarta.xml.bind-api","old_version":"4.0.0","new_version":"4.0.5","repository_url":"https://github.com/jakartaee/jaxb-api"},{"name":"org.glassfish.jaxb:jaxb-runtime","old_version":"4.0.2","new_version":"4.0.9"},{"name":"jakarta.activation:jakarta.activation-api","old_version":"2.1.1","new_version":"2.1.4","repository_url":"https://github.com/jakartaee/jaf-api"},{"name":"io.github.resilience4j:resilience4j-spring-boot3","old_version":"2.0.2","new_version":"2.4.0"},{"name":"io.github.resilience4j:resilience4j-circuitbreaker","old_version":"2.0.2","new_version":"2.4.0"},{"name":"io.github.resilience4j:resilience4j-ratelimiter","old_version":"2.0.2","new_version":"2.4.0","repository_url":"https://github.com/resilience4j/resilience4j"},{"name":"io.github.resilience4j:resilience4j-retry","old_version":"2.0.2","new_version":"2.4.0","repository_url":"https://github.com/resilience4j/resilience4j"},{"name":"io.github.resilience4j:resilience4j-bulkhead","old_version":"2.0.2","new_version":"2.4.0"},{"name":"io.github.resilience4j:resilience4j-timelimiter","old_version":"2.0.2","new_version":"2.4.0","repository_url":"https://github.com/resilience4j/resilience4j"},{"name":"org.springdoc:springdoc-openapi-starter-webmvc-ui","old_version":"2.8.8","new_version":"3.0.3","repository_url":"https://github.com/springdoc/springdoc-openapi"},{"name":"org.springdoc:springdoc-openapi-starter-common","old_version":"2.8.8","new_version":"3.0.3","repository_url":"https://github.com/springdoc/springdoc-openapi"},{"name":"io.jsonwebtoken:jjwt-api","old_version":"0.11.5","new_version":"0.13.0","repository_url":"https://github.com/jwtk/jjwt"},{"name":"io.jsonwebtoken:jjwt-impl","old_version":"0.11.5","new_version":"0.13.0","repository_url":"https://github.com/jwtk/jjwt"},{"name":"io.jsonwebtoken:jjwt-jackson","old_version":"0.11.5","new_version":"0.13.0"},{"name":"com.alibaba:transmittable-thread-local","old_version":"2.14.2","new_version":"2.14.5","repository_url":"https://github.com/alibaba/transmittable-thread-local"},{"name":"org.junit.jupiter:junit-jupiter","old_version":"5.10.0","new_version":"6.1.0","repository_url":"https://github.com/junit-team/junit-framework"},{"name":"com.alibaba:fastjson","old_version":"2.0.53","new_version":"2.0.62","repository_url":"https://github.com/alibaba/fastjson2"},{"name":"redis.clients:jedis","old_version":"6.0.0","new_version":"7.5.2"},{"name":"com.squareup.okhttp3:okhttp","old_version":"4.12.0","new_version":"5.4.0","repository_url":"https://github.com/square/okhttp"},{"name":"com.squareup.okhttp3:okhttp-sse","old_version":"4.12.0","new_version":"5.4.0","repository_url":"https://github.com/square/okhttp"},{"name":"com.google.protobuf:protobuf-java","old_version":"3.24.4","new_version":"4.35.0"},{"name":"org.apache.poi:poi","old_version":"5.2.4","new_version":"5.5.1"},{"name":"org.apache.poi:poi-ooxml","old_version":"5.2.4","new_version":"5.5.1"},{"name":"org.apache.poi:poi-scratchpad","old_version":"5.2.4","new_version":"5.5.1"},{"name":"fr.opensagres.xdocreport:fr.opensagres.poi.xwpf.converter.pdf","old_version":"2.0.4","new_version":"2.2.0"},{"name":"org.hibernate.validator:hibernate-validator","old_version":"8.0.1.Final","new_version":"9.1.0.Final","repository_url":"https://github.com/hibernate/hibernate-validator"},{"name":"ch.qos.logback:logback-classic","old_version":"1.5.18","new_version":"1.5.34","repository_url":"https://github.com/qos-ch/logback"},{"name":"ch.qos.logback:logback-core","old_version":"1.5.18","new_version":"1.5.34","repository_url":"https://github.com/qos-ch/logback"},{"name":"org.apache.tomcat:tomcat-annotations-api","old_version":"10.1.55","new_version":"11.0.22"},{"name":"org.apache.tomcat.embed:tomcat-embed-el","old_version":"10.1.55","new_version":"11.0.22"},{"name":"com.google.guava:guava","old_version":"33.4.8-jre","new_version":"33.6.0-jre","repository_url":"https://github.com/google/guava"},{"name":"org.springframework.security:spring-security-crypto","old_version":"6.5.9","new_version":"7.0.5","repository_url":"https://github.com/spring-projects/spring-security"},{"name":"org.springframework.security:spring-security-web","old_version":"6.5.9","new_version":"7.0.5","repository_url":"https://github.com/spring-projects/spring-security"},{"name":"org.springframework.security:spring-security-core","old_version":"6.5.9","new_version":"7.0.5","repository_url":"https://github.com/spring-projects/spring-security"},{"name":"org.springframework.security:spring-security-config","old_version":"6.5.9","new_version":"7.0.5","repository_url":"https://github.com/spring-projects/spring-security"},{"name":"org.yaml:snakeyaml","old_version":"2.0","new_version":"2.6"},{"name":"com.itextpdf:itextpdf","old_version":"5.5.13.4","new_version":"5.5.13.5","repository_url":"https://github.com/itext/itextpdf"},{"name":"io.netty:netty-all","old_version":"4.1.133.Final","new_version":"4.2.15.Final","repository_url":"https://github.com/netty/netty"},{"name":"org.apache.kafka:kafka-clients","old_version":"3.9.2","new_version":"4.3.0"},{"name":"com.auth0:java-jwt","old_version":"4.4.0","new_version":"4.5.2"},{"name":"org.apache.httpcomponents:httpclient","old_version":"4.5.13","new_version":"4.5.14"},{"name":"com.alibaba:druid-spring-boot-starter","old_version":"1.1.9","new_version":"1.2.28","repository_url":"https://github.com/alibaba/druid"},{"name":"io.minio:minio","old_version":"8.6.0","new_version":"9.0.1","repository_url":"https://github.com/minio/minio-java"},{"name":"commons-net:commons-net","old_version":"3.9.0","new_version":"3.13.0","repository_url":"https://github.com/apache/commons-net"},{"name":"com.clickhouse:clickhouse-jdbc","old_version":"0.4.6","new_version":"0.9.8","repository_url":"https://github.com/ClickHouse/clickhouse-java"},{"name":"com.vesoft:client","old_version":"3.0.0","new_version":"3.8.4"},{"name":"co.elastic.clients:elasticsearch-java","old_version":"8.15.5","new_version":"9.4.2","repository_url":"https://github.com/elastic/elasticsearch-java"},{"name":"org.elasticsearch.client:elasticsearch-rest-client","old_version":"8.15.5","new_version":"9.4.2","repository_url":"https://github.com/elastic/elasticsearch"},{"name":"org.elasticsearch:elasticsearch","old_version":"8.15.5","new_version":"9.4.2","repository_url":"https://github.com/elastic/elasticsearch"},{"name":"org.elasticsearch:elasticsearch-x-content","old_version":"8.15.5","new_version":"9.4.2","repository_url":"https://github.com/elastic/elasticsearch"},{"name":"com.baomidou:mybatis-plus-extension","old_version":"3.5.5","new_version":"3.5.16","repository_url":"https://github.com/baomidou/mybatis-plus"},{"name":"org.springframework.boot:spring-boot-starter-test","old_version":"3.2.0","new_version":"4.0.6","repository_url":"https://github.com/spring-projects/spring-boot"},{"name":"com.baomidou:mybatis-plus-boot-starter","old_version":"3.5.5","new_version":"3.5.16","repository_url":"https://github.com/baomidou/mybatis-plus"},{"name":"com.github.jsqlparser:jsqlparser","old_version":"4.5","new_version":"5.3","repository_url":"https://github.com/JSQLParser/JSqlParser"},{"name":"com.aliyun:tea","old_version":"1.3.1","new_version":"1.4.2","repository_url":"https://github.com/aliyun/tea-java"},{"name":"commons-logging:commons-logging","old_version":"1.2","new_version":"1.3.6","repository_url":"https://github.com/apache/commons-logging"},{"name":"com.aliyun:tea-util","old_version":"0.2.23","new_version":"0.2.27","repository_url":"https://github.com/aliyun/tea-util"},{"name":"org.jacoco:org.jacoco.agent","old_version":"0.8.8","new_version":"0.8.15","repository_url":"https://github.com/jacoco/jacoco"},{"name":"com.aliyun:tea-openapi","old_version":"0.3.8","new_version":"0.3.15","repository_url":"https://github.com/aliyun/darabonba-openapi"},{"name":"com.github.pagehelper:pagehelper-spring-boot-starter","old_version":"1.4.7","new_version":"4.1.0","repository_url":"https://github.com/pagehelper/pagehelper-spring-boot"},{"name":"com.aliyun:dingtalk","old_version":"2.2.17","new_version":"2.2.53","repository_url":"https://github.com/aliyun/alibabacloud-sdk"},{"name":"com.aliyun:dysmsapi20170525","old_version":"2.0.24","new_version":"4.5.1","repository_url":"https://github.com/aliyun/alibabacloud-sdk"},{"name":"com.aliyun:credentials-java","old_version":"1.0.2","new_version":"1.0.3","repository_url":"https://github.com/aliyun/credentials-java"},{"name":"org.mybatis.spring.boot:mybatis-spring-boot-starter","old_version":"3.0.4","new_version":"4.0.1","repository_url":"https://github.com/mybatis/spring-boot-starter"},{"name":"org.xerial.snappy:snappy-java","old_version":"1.1.10.5","new_version":"1.1.10.8","repository_url":"https://github.com/xerial/snappy-java"},{"name":"joda-time:joda-time","old_version":"2.10.10","new_version":"2.14.2","repository_url":"https://github.com/JodaOrg/joda-time"},{"name":"io.swagger:swagger-annotations","old_version":"1.5.24","new_version":"1.6.16"},{"name":"tools.jackson.core:jackson-core","old_version":"3.1.1","new_version":"3.2.0"},{"name":"tools.jackson.core:jackson-databind","old_version":"3.1.1","new_version":"3.2.0"},{"name":"tools.jackson.dataformat:jackson-dataformat-yaml","old_version":"3.1.1","new_version":"3.2.0"},{"name":"org.projectlombok:lombok","old_version":"1.18.38","new_version":"1.18.46","repository_url":"https://github.com/projectlombok/lombok"},{"name":"jakarta.annotation:jakarta.annotation-api","old_version":"2.1.1","new_version":"3.0.0","repository_url":"https://github.com/jakartaee/common-annotations-api"},{"name":"cn.hutool:hutool-all","old_version":"5.8.38","new_version":"5.8.46","repository_url":"https://github.com/looly/hutool"},{"name":"com.aliyun.oss:aliyun-sdk-oss","old_version":"3.17.2","new_version":"3.18.5","repository_url":"https://github.com/aliyun/aliyun-oss-java-sdk"},{"name":"org.xerial:sqlite-jdbc","old_version":"3.46.1.0","new_version":"3.53.2.0","repository_url":"https://github.com/xerial/sqlite-jdbc"},{"name":"com.google.zxing:core","old_version":"3.3.3","new_version":"3.5.4","repository_url":"https://github.com/zxing/zxing"},{"name":"com.dingtalk.open:app-stream-client","old_version":"1.0.5","new_version":"1.3.12"},{"name":"io.modelcontextprotocol.sdk:mcp","old_version":"1.0.0","new_version":"1.1.3","repository_url":"https://github.com/modelcontextprotocol/java-sdk"},{"name":"dev.langchain4j:langchain4j-mcp","old_version":"1.1.0-beta7","new_version":"1.16.1-beta26","repository_url":"https://github.com/langchain4j/langchain4j"},{"name":"dev.langchain4j:langchain4j-core","old_version":"1.1.0","new_version":"1.16.1","repository_url":"https://github.com/langchain4j/langchain4j"},{"name":"dev.langchain4j:langchain4j","old_version":"1.1.0","new_version":"1.16.1","repository_url":"https://github.com/langchain4j/langchain4j"},{"name":"org.apache.pdfbox:pdfbox","old_version":"3.0.3","new_version":"3.0.7"},{"name":"com.github.librepdf:openpdf","old_version":"1.3.30","new_version":"3.0.5"},{"name":"mysql:mysql-connector-java","old_version":"5.1.26","new_version":"8.0.33"},{"name":"org.apache.maven.plugins:maven-dependency-plugin","old_version":"3.6.1","new_version":"3.11.0","repository_url":"https://github.com/apache/maven-dependency-plugin"},{"name":"org.apache.maven.plugins:maven-compiler-plugin","old_version":"3.11.0","new_version":"3.15.0","repository_url":"https://github.com/apache/maven-compiler-plugin"},{"name":"org.apache.maven.plugins:maven-enforcer-plugin","old_version":"3.4.1","new_version":"3.6.3","repository_url":"https://github.com/apache/maven-enforcer"},{"name":"org.apache.maven.plugins:maven-surefire-plugin","old_version":"3.2.5","new_version":"3.5.6","repository_url":"https://github.com/apache/maven-surefire"},{"name":"org.apache.maven.plugins:maven-help-plugin","old_version":"3.4.1","new_version":"3.5.1","repository_url":"https://github.com/apache/maven-help-plugin"},{"name":"org.mybatis.generator:mybatis-generator-maven-plugin","old_version":"1.3.7","new_version":"2.0.0"}],"path":null,"ecosystem":"maven"},"body":"Bumps the all-maven group with 115 updates in the /byclaw-be directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [org.springframework.boot:spring-boot-starter-parent](https://github.com/spring-projects/spring-boot) | `3.5.14` | `4.0.6` |\n| [org.springframework.ai:spring-ai-bom](https://github.com/spring-projects/spring-ai) | `1.0.0` | `1.1.7` |\n| [com.squareup.okio:okio-jvm](https://github.com/square/okio) | `3.6.0` | `3.17.0` |\n| [com.squareup.okio:okio](https://github.com/square/okio) | `3.4.0` | `3.17.0` |\n| [org.springframework.cloud:spring-cloud-dependencies](https://github.com/spring-cloud/spring-cloud-release) | `2025.0.2` | `2025.1.1` |\n| [io.opentelemetry.instrumentation:opentelemetry-instrumentation-annotations](https://github.com/open-telemetry/opentelemetry-java-instrumentation) | `2.22.0` | `2.28.1` |\n| org.apache.xmlbeans:xmlbeans | `5.1.1` | `5.3.0` |\n| commons-io:commons-io | `2.19.0` | `2.22.0` |\n| [org.jsoup:jsoup](https://github.com/jhy/jsoup) | `1.18.1` | `1.22.2` |\n| [org.jetbrains:annotations](https://github.com/JetBrains/java-annotations) | `24.0.1` | `26.1.0` |\n| [org.apache.commons:commons-compress](https://github.com/apache/commons-compress) | `1.24.0` | `1.28.0` |\n| [com.github.pagehelper:pagehelper](https://github.com/pagehelper/Mybatis-PageHelper) | `5.3.3` | `6.1.1` |\n| com.iwhaleai.byai:by-framework | `0.2.6` | `0.2.8` |\n| [com.fasterxml.woodstox:woodstox-core](https://github.com/FasterXML/woodstox) | `7.0.0` | `7.2.1` |\n| org.glassfish.hk2:hk2-api | `3.1.1` | `4.0.1` |\n| [org.eclipse.parsson:parsson](https://github.com/eclipse-ee4j/parsson) | `1.1.7` | `1.1.9` |\n| com.google.errorprone:error_prone_annotations | `2.36.0` | `2.49.0` |\n| org.opengauss:opengauss-jdbc | `6.0.0` | `6.0.3` |\n| [com.alibaba:druid](https://github.com/alibaba/druid) | `1.2.23` | `1.2.28` |\n| [com.mysql:mysql-connector-j](https://github.com/mysql/mysql-connector-j) | `8.4.0` | `9.7.0` |\n| [org.mybatis:mybatis](https://github.com/mybatis/mybatis-3) | `3.5.14` | `3.5.19` |\n| [org.mybatis:mybatis-spring](https://github.com/mybatis/spring) | `3.0.3` | `4.0.0` |\n| org.apache.commons:commons-lang3 | `3.13.0` | `3.20.0` |\n| org.apache.commons:commons-collections4 | `4.4` | `4.5.0` |\n| [commons-codec:commons-codec](https://github.com/apache/commons-codec) | `1.16.0` | `1.22.0` |\n| [jakarta.xml.bind:jakarta.xml.bind-api](https://github.com/jakartaee/jaxb-api) | `4.0.0` | `4.0.5` |\n| org.glassfish.jaxb:jaxb-runtime | `4.0.2` | `4.0.9` |\n| [jakarta.activation:jakarta.activation-api](https://github.com/jakartaee/jaf-api) | `2.1.1` | `2.1.4` |\n| io.github.resilience4j:resilience4j-spring-boot3 | `2.0.2` | `2.4.0` |\n| io.github.resilience4j:resilience4j-circuitbreaker | `2.0.2` | `2.4.0` |\n| [io.github.resilience4j:resilience4j-ratelimiter](https://github.com/resilience4j/resilience4j) | `2.0.2` | `2.4.0` |\n| [io.github.resilience4j:resilience4j-retry](https://github.com/resilience4j/resilience4j) | `2.0.2` | `2.4.0` |\n| io.github.resilience4j:resilience4j-bulkhead | `2.0.2` | `2.4.0` |\n| [io.github.resilience4j:resilience4j-timelimiter](https://github.com/resilience4j/resilience4j) | `2.0.2` | `2.4.0` |\n| [org.springdoc:springdoc-openapi-starter-webmvc-ui](https://github.com/springdoc/springdoc-openapi) | `2.8.8` | `3.0.3` |\n| [org.springdoc:springdoc-openapi-starter-common](https://github.com/springdoc/springdoc-openapi) | `2.8.8` | `3.0.3` |\n| [io.jsonwebtoken:jjwt-api](https://github.com/jwtk/jjwt) | `0.11.5` | `0.13.0` |\n| [io.jsonwebtoken:jjwt-impl](https://github.com/jwtk/jjwt) | `0.11.5` | `0.13.0` |\n| io.jsonwebtoken:jjwt-jackson | `0.11.5` | `0.13.0` |\n| [com.alibaba:transmittable-thread-local](https://github.com/alibaba/transmittable-thread-local) | `2.14.2` | `2.14.5` |\n| [org.junit.jupiter:junit-jupiter](https://github.com/junit-team/junit-framework) | `5.10.0` | `6.1.0` |\n| [com.alibaba:fastjson](https://github.com/alibaba/fastjson2) | `2.0.53` | `2.0.62` |\n| redis.clients:jedis | `6.0.0` | `7.5.2` |\n| [com.squareup.okhttp3:okhttp](https://github.com/square/okhttp) | `4.12.0` | `5.4.0` |\n| [com.squareup.okhttp3:okhttp-sse](https://github.com/square/okhttp) | `4.12.0` | `5.4.0` |\n| com.google.protobuf:protobuf-java | `3.24.4` | `4.35.0` |\n| org.apache.poi:poi | `5.2.4` | `5.5.1` |\n| org.apache.poi:poi-ooxml | `5.2.4` | `5.5.1` |\n| org.apache.poi:poi-scratchpad | `5.2.4` | `5.5.1` |\n| fr.opensagres.xdocreport:fr.opensagres.poi.xwpf.converter.pdf | `2.0.4` | `2.2.0` |\n| [org.hibernate.validator:hibernate-validator](https://github.com/hibernate/hibernate-validator) | `8.0.1.Final` | `9.1.0.Final` |\n| [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) | `1.5.18` | `1.5.34` |\n| [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) | `1.5.18` | `1.5.34` |\n| org.apache.tomcat:tomcat-annotations-api | `10.1.55` | `11.0.22` |\n| org.apache.tomcat.embed:tomcat-embed-el | `10.1.55` | `11.0.22` |\n| [com.google.guava:guava](https://github.com/google/guava) | `33.4.8-jre` | `33.6.0-jre` |\n| [org.springframework.security:spring-security-crypto](https://github.com/spring-projects/spring-security) | `6.5.9` | `7.0.5` |\n| [org.springframework.security:spring-security-web](https://github.com/spring-projects/spring-security) | `6.5.9` | `7.0.5` |\n| [org.springframework.security:spring-security-core](https://github.com/spring-projects/spring-security) | `6.5.9` | `7.0.5` |\n| [org.springframework.security:spring-security-config](https://github.com/spring-projects/spring-security) | `6.5.9` | `7.0.5` |\n| [org.yaml:snakeyaml](https://bitbucket.org/snakeyaml/snakeyaml) | `2.0` | `2.6` |\n| [com.itextpdf:itextpdf](https://github.com/itext/itextpdf) | `5.5.13.4` | `5.5.13.5` |\n| [io.netty:netty-all](https://github.com/netty/netty) | `4.1.133.Final` | `4.2.15.Final` |\n| org.apache.kafka:kafka-clients | `3.9.2` | `4.3.0` |\n| com.auth0:java-jwt | `4.4.0` | `4.5.2` |\n| org.apache.httpcomponents:httpclient | `4.5.13` | `4.5.14` |\n| [com.alibaba:druid-spring-boot-starter](https://github.com/alibaba/druid) | `1.1.9` | `1.2.28` |\n| [io.minio:minio](https://github.com/minio/minio-java) | `8.6.0` | `9.0.1` |\n| [commons-net:commons-net](https://github.com/apache/commons-net) | `3.9.0` | `3.13.0` |\n| [com.clickhouse:clickhouse-jdbc](https://github.com/ClickHouse/clickhouse-java) | `0.4.6` | `0.9.8` |\n| com.vesoft:client | `3.0.0` | `3.8.4` |\n| [co.elastic.clients:elasticsearch-java](https://github.com/elastic/elasticsearch-java) | `8.15.5` | `9.4.2` |\n| [org.elasticsearch.client:elasticsearch-rest-client](https://github.com/elastic/elasticsearch) | `8.15.5` | `9.4.2` |\n| [org.elasticsearch:elasticsearch](https://github.com/elastic/elasticsearch) | `8.15.5` | `9.4.2` |\n| [org.elasticsearch:elasticsearch-x-content](https://github.com/elastic/elasticsearch) | `8.15.5` | `9.4.2` |\n| [com.baomidou:mybatis-plus-extension](https://github.com/baomidou/mybatis-plus) | `3.5.5` | `3.5.16` |\n| [org.springframework.boot:spring-boot-starter-test](https://github.com/spring-projects/spring-boot) | `3.2.0` | `4.0.6` |\n| [com.baomidou:mybatis-plus-boot-starter](https://github.com/baomidou/mybatis-plus) | `3.5.5` | `3.5.16` |\n| [com.github.jsqlparser:jsqlparser](https://github.com/JSQLParser/JSqlParser) | `4.5` | `5.3` |\n| [com.aliyun:tea](https://github.com/aliyun/tea-java) | `1.3.1` | `1.4.2` |\n| [commons-logging:commons-logging](https://github.com/apache/commons-logging) | `1.2` | `1.3.6` |\n| [com.aliyun:tea-util](https://github.com/aliyun/tea-util) | `0.2.23` | `0.2.27` |\n| [org.jacoco:org.jacoco.agent](https://github.com/jacoco/jacoco) | `0.8.8` | `0.8.15` |\n| [com.aliyun:tea-openapi](https://github.com/aliyun/darabonba-openapi) | `0.3.8` | `0.3.15` |\n| [com.github.pagehelper:pagehelper-spring-boot-starter](https://github.com/pagehelper/pagehelper-spring-boot) | `1.4.7` | `4.1.0` |\n| [com.aliyun:dingtalk](https://github.com/aliyun/alibabacloud-sdk) | `2.2.17` | `2.2.53` |\n| [com.aliyun:dysmsapi20170525](https://github.com/aliyun/alibabacloud-sdk) | `2.0.24` | `4.5.1` |\n| [com.aliyun:credentials-java](https://github.com/aliyun/credentials-java) | `1.0.2` | `1.0.3` |\n| [org.mybatis.spring.boot:mybatis-spring-boot-starter](https://github.com/mybatis/spring-boot-starter) | `3.0.4` | `4.0.1` |\n| [org.xerial.snappy:snappy-java](https://github.com/xerial/snappy-java) | `1.1.10.5` | `1.1.10.8` |\n| [joda-time:joda-time](https://github.com/JodaOrg/joda-time) | `2.10.10` | `2.14.2` |\n| io.swagger:swagger-annotations | `1.5.24` | `1.6.16` |\n| tools.jackson.core:jackson-core | `3.1.1` | `3.2.0` |\n| tools.jackson.core:jackson-databind | `3.1.1` | `3.2.0` |\n| tools.jackson.dataformat:jackson-dataformat-yaml | `3.1.1` | `3.2.0` |\n| [org.projectlombok:lombok](https://github.com/projectlombok/lombok) | `1.18.38` | `1.18.46` |\n| [jakarta.annotation:jakarta.annotation-api](https://github.com/jakartaee/common-annotations-api) | `2.1.1` | `3.0.0` |\n| [cn.hutool:hutool-all](https://github.com/looly/hutool) | `5.8.38` | `5.8.46` |\n| [com.aliyun.oss:aliyun-sdk-oss](https://github.com/aliyun/aliyun-oss-java-sdk) | `3.17.2` | `3.18.5` |\n| [org.xerial:sqlite-jdbc](https://github.com/xerial/sqlite-jdbc) | `3.46.1.0` | `3.53.2.0` |\n| [com.google.zxing:core](https://github.com/zxing/zxing) | `3.3.3` | `3.5.4` |\n| com.dingtalk.open:app-stream-client | `1.0.5` | `1.3.12` |\n| [io.modelcontextprotocol.sdk:mcp](https://github.com/modelcontextprotocol/java-sdk) | `1.0.0` | `1.1.3` |\n| [dev.langchain4j:langchain4j-mcp](https://github.com/langchain4j/langchain4j) | `1.1.0-beta7` | `1.16.1-beta26` |\n| [dev.langchain4j:langchain4j-core](https://github.com/langchain4j/langchain4j) | `1.1.0` | `1.16.1` |\n| [dev.langchain4j:langchain4j](https://github.com/langchain4j/langchain4j) | `1.1.0` | `1.16.1` |\n| org.apache.pdfbox:pdfbox | `3.0.3` | `3.0.7` |\n| com.github.librepdf:openpdf | `1.3.30` | `3.0.5` |\n| mysql:mysql-connector-java | `5.1.26` | `8.0.33` |\n| [org.apache.maven.plugins:maven-dependency-plugin](https://github.com/apache/maven-dependency-plugin) | `3.6.1` | `3.11.0` |\n| [org.apache.maven.plugins:maven-compiler-plugin](https://github.com/apache/maven-compiler-plugin) | `3.11.0` | `3.15.0` |\n| [org.apache.maven.plugins:maven-enforcer-plugin](https://github.com/apache/maven-enforcer) | `3.4.1` | `3.6.3` |\n| [org.apache.maven.plugins:maven-surefire-plugin](https://github.com/apache/maven-surefire) | `3.2.5` | `3.5.6` |\n| [org.apache.maven.plugins:maven-help-plugin](https://github.com/apache/maven-help-plugin) | `3.4.1` | `3.5.1` |\n| org.mybatis.generator:mybatis-generator-maven-plugin | `1.3.7` | `2.0.0` |\n\n\nUpdates `org.springframework.boot:spring-boot-starter-parent` from 3.5.14 to 4.0.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/spring-projects/spring-boot/releases\"\u003eorg.springframework.boot:spring-boot-starter-parent's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.0.6\u003c/h2\u003e\n\u003ch2\u003e:lady_beetle: Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDefault security is misconfigured when spring-boot-actuator-autoconfigure is present and spring-boot-health is not \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50188\"\u003e#50188\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eElasticsearch Rest5Client auto-configuration misconfigures underlying HTTP client \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50187\"\u003e#50187\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eApplicationPidFileWriter does not handle symlinks correctly \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50185\"\u003e#50185\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRandomValuePropertySource is not suitable for secrets \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50183\"\u003e#50183\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCassandra auto-configuration misconfigures CqlSessionBuilder \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50180\"\u003e#50180\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eApplicationTemp does not handle symlinks correctly \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50178\"\u003e#50178\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemote DevTools performs comparison incorrectly \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50176\"\u003e#50176\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003espring.rabbitmq.ssl.verify-hostname is applied inconsistently \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50174\"\u003e#50174\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWhole number values are ignored when configuring min and max expected values and SLO boundaries for a distribution summary meter \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50077\"\u003e#50077\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eClassic starters are missing several modules \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50071\"\u003e#50071\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eModule spring-boot-resttestclient is missing from spring-boot-starter-test-classic \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/pull/50069\"\u003e#50069\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAnnotations like \u003ccode\u003e@Ssl\u003c/code\u003e don't work on \u003ccode\u003e@Bean\u003c/code\u003e methods when using \u003ccode\u003e@ServiceConnection\u003c/code\u003e \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50064\"\u003e#50064\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEnversRevisionRepositoriesRegistrar should reuse \u003ccode\u003e@EnableEnversRepositories\u003c/code\u003e rather than configuring the JPA counterpart \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50039\"\u003e#50039\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWebFlux Cloud Foundry links endpoint includes query string from received request in resolved links \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50017\"\u003e#50017\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImports on a containing test class are ignored when a nested class has imports \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50012\"\u003e#50012\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWith spring.jackson.use-jackson2-defaults set to true, FAIL_ON_UNKNOWN_PROPERTIES is enabled \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/49951\"\u003e#49951\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e500 response from env endpoint when supplied pattern is invalid \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/49946\"\u003e#49946\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReactive MongoDB starter has a transitive dependency on the synchronous MongoDB driver \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/49945\"\u003e#49945\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHTTP method is lost when configuring excludes in EndpointRequest \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/49943\"\u003e#49943\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHonor HttpMethod for reactive additional endpoint paths \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/49880\"\u003e#49880\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDocker Compose support doesn't work with apache/artemis image \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/49869\"\u003e#49869\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDocker Compose support doesn't work with apache/activemq image \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/49866\"\u003e#49866\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSpring Security's PathPatternRequestMatcher.Builder is not auto-configured when using WebMvcTest and spring-boot-security-test \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/49854\"\u003e#49854\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAPI versioning path strategy should be applied path last as it is not meant to yield \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/49800\"\u003e#49800\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e:notebook_with_decorative_cover: Documentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate docs to encourage Java fundamentals for beginners that prefer to learn that way \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50146\"\u003e#50146\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHTTP Service Interface Clients still document that API versioning can be configured via properties \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50126\"\u003e#50126\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eLink to the observability section of the Lettuce documentation is broken \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50097\"\u003e#50097\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJavadoc for StaticResourceLocation.FAVICON doesn't describe icons location \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50085\"\u003e#50085\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMySamlRelyingPartyConfiguration is missing a Kotlin sample \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50024\"\u003e#50024\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIncorrect default value for management.httpexchanges.recording.include in configuration metadata \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50019\"\u003e#50019\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eLink to the Kubernetes documentation when discussing startup probes \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50015\"\u003e#50015\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTypo in JdbcSessionAutoConfiguration Javadoc \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/pull/49873\"\u003e#49873\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eClarify that configuration property default values are not available through the Environment \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/49851\"\u003e#49851\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDocument the need for Liquibase and Flyway starters \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/pull/49839\"\u003e#49839\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eKafka documentation refers to deprecated JSON serializer and deserializer classes \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/pull/49826\"\u003e#49826\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e:hammer: Dependency Upgrades\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to Elasticsearch Client 9.2.8 \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50027\"\u003e#50027\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade to Groovy 5.0.5 \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/49911\"\u003e#49911\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade to Hibernate 7.2.12.Final \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50134\"\u003e#50134\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade to Jackson Bom 3.1.2 \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50051\"\u003e#50051\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade to \u003ca href=\"https://github.com/jaxen-xpath/jaxen/releases/tag/v2.0.1\"\u003eJaxen 2.0.1\u003c/a\u003e \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50104\"\u003e#50104\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade to \u003ca href=\"https://github.com/FirebirdSQL/jaybird/releases/tag/v6.0.5\"\u003eJaybird 6.0.5\u003c/a\u003e \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/49914\"\u003e#49914\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/8821ad2cd381bb4b9615a61479e1de7305a8ba39\"\u003e\u003ccode\u003e8821ad2\u003c/code\u003e\u003c/a\u003e Release v4.0.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/9e4048a03f17adfe78057a3c4d5b4693305c0ae0\"\u003e\u003ccode\u003e9e4048a\u003c/code\u003e\u003c/a\u003e Merge branch '3.5.x' into 4.0.x\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/20bb11c3984802990572ddbeae8b66885a8f2462\"\u003e\u003ccode\u003e20bb11c\u003c/code\u003e\u003c/a\u003e Next development version (v3.5.15-SNAPSHOT)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/98daa8ea30f39a5b0ca6768b5cbc2dc8698ef4e1\"\u003e\u003ccode\u003e98daa8e\u003c/code\u003e\u003c/a\u003e Merge branch '3.5.x' into 4.0.x\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/874f6294b91da18367b8b5ab7b2fad3fa23cfba6\"\u003e\u003ccode\u003e874f629\u003c/code\u003e\u003c/a\u003e Fix default security with actuator but without health\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/e41b3bf731d1134bc18ec1f68ac01e0fe1c54923\"\u003e\u003ccode\u003ee41b3bf\u003c/code\u003e\u003c/a\u003e Enable hostname verification for SSL connections to Elasticsearch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/ef8527bb0ef8f564f4f9c57a7be99a7aa96c6ab0\"\u003e\u003ccode\u003eef8527b\u003c/code\u003e\u003c/a\u003e Merge branch '3.5.x' into 4.0.x\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/4a7bd332b6d19fef1aa4cf28434985f2b03a2e0f\"\u003e\u003ccode\u003e4a7bd33\u003c/code\u003e\u003c/a\u003e Merge branch '3.5.x' into 4.0.x\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/3a9d836621605d39cfd88b677f2c6085aa1a1402\"\u003e\u003ccode\u003e3a9d836\u003c/code\u003e\u003c/a\u003e Merge branch '3.5.x' into 4.0.x\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/8e013b6f909c3882ed87ca78111e4a8bfe33ff72\"\u003e\u003ccode\u003e8e013b6\u003c/code\u003e\u003c/a\u003e Merge branch '3.5.x' into 4.0.x\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/spring-projects/spring-boot/compare/v3.5.14...v4.0.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.springframework.ai:spring-ai-bom` from 1.0.0 to 1.1.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/spring-projects/spring-ai/releases\"\u003eorg.springframework.ai:spring-ai-bom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eSpring AI 1.1.7\u003c/h2\u003e\n\u003ch2\u003e:star: New Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOllama doesnt work in a graalvm native image \u003ca href=\"https://redirect.github.com/spring-projects/spring-ai/issues/6064\"\u003e#6064\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e:lady_beetle: Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOpenAiChatModel streaming drops chunks due to internal switchMap when using buffered concatMap \u003ca href=\"https://redirect.github.com/spring-projects/spring-ai/issues/6122\"\u003e#6122\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eRedisVectorStore#doDelete\u003c/code\u003e only deletes the 10 first messages \u003ca href=\"https://redirect.github.com/spring-projects/spring-ai/issues/6066\"\u003e#6066\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003eSpring AI 1.1.6 Release Notes\u003c/h1\u003e\n\u003ch2\u003e🎯 Highlights\u003c/h2\u003e\n\u003cp\u003eThis release includes 1 new features, 5 bug fixes, 2 documentation improvements, 5 other improvements.\u003c/p\u003e\n\u003ch2\u003e⏪ Breaking Changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChat memory advisors now require an explicit conversation ID to be supplied. This is a behavioral change that affects how chat memory is scoped and managed. Applications relying on implicit conversation IDs must be updated to supply an explicit ID. \u003ca href=\"https://github.com/spring-projects/spring-ai/commit/13cde419e30042c663706f130dd65b80d92d4667\"\u003e13cde41\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e⚠️ Upgrading Notes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePromptChatMemoryAdvisor is now deprecated and chat memory advisors require an explicit conversation ID. Update your code to: (1) replace PromptChatMemoryAdvisor with the recommended alternative, and (2) ensure an explicit conversation ID is supplied when using any chat memory advisor. \u003ca href=\"https://github.com/spring-projects/spring-ai/commit/917f62ebec13cf01027c094dd36d4106b1c8dc47\"\u003e917f62e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e⭐ New Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMCP auto-configuration now includes the missing \u003ca href=\"https://github.com/ConditionalOnMissingBean\"\u003e\u003ccode\u003e@​ConditionalOnMissingBean\u003c/code\u003e\u003c/a\u003e check, allowing users to provide their own bean definitions and override the auto-configured MCP beans as expected in Spring Boot auto-configuration patterns. \u003ca href=\"https://github.com/spring-projects/spring-ai/commit/d4025e5d8ede18158cbd9b53b1cc4a0ad107af3a\"\u003ed4025e5\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🪲 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue where the MilvusVectorStore's doDelete method incorrectly escaped strings in the ID list, which could cause deletion operations to fail or behave unexpectedly. \u003ca href=\"https://github.com/spring-projects/spring-ai/commit/20206a46408ef8a9609f54afc7c82a0b5fd2e357\"\u003e20206a4\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed the ChatClientAdvisorTests test suite to supply an explicit conversation ID, aligning tests with the new requirement for explicit conversation IDs in chat memory advisors. \u003ca href=\"https://github.com/spring-projects/spring-ai/commit/704e5c6519c150662c7338782639fa84ffe8c9ed\"\u003e704e5c6\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed the MistralAiChatModelObservationIT integration test to ensure observation functionality works correctly with the MistralAI chat model provider. \u003ca href=\"https://github.com/spring-projects/spring-ai/commit/a89145db26831f2f8bf22e0f76155ecebd8d7c5c\"\u003ea89145d\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCorrects an issue where configured options were not being properly included in MistralAI API requests, ensuring all user-defined settings are correctly passed through. \u003ca href=\"https://github.com/spring-projects/spring-ai/commit/7bcf32aa134b3954ba70bed625de4adcbfe8fab4\"\u003e7bcf32a\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eResolves a regression in how AssistantMessage.ToolCall.id is handled when using the Ollama integration, restoring correct tool call identification behavior. \u003ca href=\"https://github.com/spring-projects/spring-ai/commit/bb9d65ea96d3d57cf3c7467fb82e86bc25c9f238\"\u003ebb9d65e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📓 Documentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCorrected typographical errors in the MCP (Model Context Protocol) documentation for improved readability and accuracy. \u003ca href=\"https://github.com/spring-projects/spring-ai/commit/a1ad7f2a4a784432dde61520723fb80119008320\"\u003ea1ad7f2\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed broken xref anchors in the documentation to restore proper cross-reference navigation between documentation sections. \u003ca href=\"https://github.com/spring-projects/spring-ai/commit/f03c104234de47a9e91d0a7f312f458ebeb5cbe9\"\u003ef03c104\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔨 Dependency Upgrades\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated MCP SDK from version 0.17.0 to 0.18.2 and MCP annotations from 0.8.0 to 0.9.0, bringing in the latest MCP protocol improvements and bug fixes. \u003ca href=\"https://redirect.github.com/spring-projects/spring-ai/pull/5961\"\u003e#5961\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔩 Build Updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated the project build to use JDK 17.0.19, ensuring compatibility and incorporating the latest Java 17 patch release for the build environment. \u003ca href=\"https://github.com/spring-projects/spring-ai/commit/27281e62dec4fd0857ab3d0da79cd3b83105b260\"\u003e27281e6\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReorganizes the project structure by relocating Spring AI starter modules to a dedicated starters/ directory for better maintainability and clarity. \u003ca href=\"https://github.com/spring-projects/spring-ai/commit/22f867673c0d59a4607022d0a5992b5f0c59f6ef\"\u003e22f8676\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🙏 Contributors\u003c/h2\u003e\n\u003cp\u003eThanks to all contributors who made this release possible:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tzolov\"\u003e\u003ccode\u003eChristian Tzolov (@​tzolov)\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/emileplas\"\u003e\u003ccode\u003eEmile Plas (@​emileplas)\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ilayaperumalg\"\u003e\u003ccode\u003eIlayaperumal Gopinathan (@​ilayaperumalg)\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sobychacko\"\u003e\u003ccode\u003eSoby Chacko (@​sobychacko)\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-ai/commit/d8503868d3e84547db51d8f10379e1a075fe2d99\"\u003e\u003ccode\u003ed850386\u003c/code\u003e\u003c/a\u003e Release version 1.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-ai/commit/5b78fe924eb2327f652cbdae1531999a6a98ba81\"\u003e\u003ccode\u003e5b78fe9\u003c/code\u003e\u003c/a\u003e Harden filename handling in AnthropicSkillsResponseHelper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-ai/commit/3fc37483ae6b215efc743f41b303820091b05aee\"\u003e\u003ccode\u003e3fc3748\u003c/code\u003e\u003c/a\u003e Fix deprecated model for OpenAI SDK Image model\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-ai/commit/b83d3928cd84f547c094a89d23969b256b567f4b\"\u003e\u003ccode\u003eb83d392\u003c/code\u003e\u003c/a\u003e Fix OpenAI ITs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-ai/commit/f63fac2a2d968bccd1cbc3c62a7ad78294f16ed5\"\u003e\u003ccode\u003ef63fac2\u003c/code\u003e\u003c/a\u003e Fix deprecated audio models in OpenAI API and OpenAI SDK\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-ai/commit/9a5f2154bdda22949091ffd7ae4f532934d0092f\"\u003e\u003ccode\u003e9a5f215\u003c/code\u003e\u003c/a\u003e fix: update OpenAI image API to gpt-image-1-mini, dropping DALL-E support\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-ai/commit/30c7be9000b8a9afd58e3a580b5424630e6d7509\"\u003e\u003ccode\u003e30c7be9\u003c/code\u003e\u003c/a\u003e fix: Add missing configurations for ChatModel streaming tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-ai/commit/42b9cc72e1d665a417403e403828228bcff254d4\"\u003e\u003ccode\u003e42b9cc7\u003c/code\u003e\u003c/a\u003e Replace switchMap with concatMap/map to prevent streaming data loss (\u003ca href=\"https://redirect.github.com/spring-projects/spring-ai/issues/6106\"\u003e#6106\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-ai/commit/24a89f5555be3d6db006dfb46930b569a28a51ee\"\u003e\u003ccode\u003e24a89f5\u003c/code\u003e\u003c/a\u003e Fix Redis vector store filter delete to paginate search results\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-ai/commit/df99841177c419d09f936d917fb673fb4eecf4ad\"\u003e\u003ccode\u003edf99841\u003c/code\u003e\u003c/a\u003e Add Ollama ThinkOption runtime hints\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/spring-projects/spring-ai/compare/v1.0.0...v1.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.squareup.okio:okio-jvm` from 3.6.0 to 3.17.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/square/okio/blob/master/CHANGELOG.md\"\u003ecom.squareup.okio:okio-jvm's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 3.17.0\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003e2026-03-11\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eNew: Adjust down the Kotlin stdlib dependency to [Kotlin 2.1.21][kotlin_2_1_21]. Okio is built\nwith an up-to-date Kotlin compiler (2.2.21), but depends on an older kotlin-stdlib. We're doing\nthis so you can update Okio and Kotlin independently.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix: Return the correct timestamp in \u003ccode\u003eFileMetadata.createdAtMillis\u003c/code\u003e on Kotlin/Native on UNIX\nplatforms. We were incorrectly using the POSIX \u003ccode\u003ectime\u003c/code\u003e (\u003cem\u003echange\u003c/em\u003e time) instead of the\n\u003ccode\u003ebirthtime\u003c/code\u003e. With this fix Okio now prefers \u003ccode\u003estatx()\u003c/code\u003e over \u003ccode\u003estat()\u003c/code\u003e on native platforms. This\nAPI first appeared in Linux in 4.11 (2017) and Android in API 30 (2020).\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.16.4\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003e2025-11-17\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix: Don't delay triggering timeouts. In 3.16.0 we introduced a regression that caused timeouts\nto fire later than they were supposed to.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.16.3\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003e2025-11-14\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eThis release is the same as 3.16.2. We forgot to cherry-pick a commit before we released!\u003c/p\u003e\n\u003ch2\u003eVersion 3.16.2\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003e2025-10-14\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix: \u003ccode\u003eokio-assetfilesystem\u003c/code\u003e APIs now correctly restored as visible to Kotlin.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.16.1\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003e2025-10-09\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix: Don't crash when calling \u003ccode\u003eSocket.shutdownOutput()\u003c/code\u003e or \u003ccode\u003eshutdownInput()\u003c/code\u003e on an \u003ccode\u003eSSLSocket\u003c/code\u003e on\nAndroid API 21. This method throws an \u003ccode\u003eUnsupportedOperationException\u003c/code\u003e, so we now catch that and\nclose the underlying stream instead.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.16.0\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003e2025-07-29\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix: Change \u003ccode\u003eSocket.asOkioSocket()\u003c/code\u003e to resolve its source \u003ccode\u003eInputStream\u003c/code\u003e and \u003ccode\u003eOutputStream\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/80a50234e5edb96041a8168c4754ba9e1ff3625a\"\u003e\u003ccode\u003e80a5023\u003c/code\u003e\u003c/a\u003e Prepare for release 3.17.0.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/65c0c26bb5242b697ffc28f6c666ae0a01197ff6\"\u003e\u003ccode\u003e65c0c26\u003c/code\u003e\u003c/a\u003e Switch to FileMetadata to use statx instead of stat on Linux and Apple platfo...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/b11f17b233601af92ae1fabea3fecdeea0608631\"\u003e\u003ccode\u003eb11f17b\u003c/code\u003e\u003c/a\u003e Remove Kotlin/JS IR default parameter workarounds. (\u003ca href=\"https://redirect.github.com/square/okio/issues/1786\"\u003e#1786\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/b35f473635db8ad9d5a9b096780e960d1b8f7d4d\"\u003e\u003ccode\u003eb35f473\u003c/code\u003e\u003c/a\u003e Update Gradle to v9.4.0 (\u003ca href=\"https://redirect.github.com/square/okio/issues/1785\"\u003e#1785\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/cbcee31f2bcb7e6f606d8eafc45f4c8ea7228cae\"\u003e\u003ccode\u003ecbcee31\u003c/code\u003e\u003c/a\u003e Update actions/upload-artifact action to v7 (\u003ca href=\"https://redirect.github.com/square/okio/issues/1783\"\u003e#1783\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/fc7aecb7f6f7a123f2024ab6397da04311546bf2\"\u003e\u003ccode\u003efc7aecb\u003c/code\u003e\u003c/a\u003e Update dependency com.android.tools.build:gradle to v9.0.1 (\u003ca href=\"https://redirect.github.com/square/okio/issues/1781\"\u003e#1781\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/79aa26755c77df8c4d0233926c7308fd353ad697\"\u003e\u003ccode\u003e79aa267\u003c/code\u003e\u003c/a\u003e Drop \u003ccode\u003eisWasm()\u003c/code\u003e early return workaround for KT-60212. (\u003ca href=\"https://redirect.github.com/square/okio/issues/1777\"\u003e#1777\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/45459dca7d40b4c2df1454a0f363e0b8e153beb5\"\u003e\u003ccode\u003e45459dc\u003c/code\u003e\u003c/a\u003e Fix result of an 'errnoToIOException' call is not thrown. inside `PosixFileSy...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/9fbab0f7ab00b525b0ae331c8c3ac3c645afc8c8\"\u003e\u003ccode\u003e9fbab0f\u003c/code\u003e\u003c/a\u003e Decode env variables in WASI tests (\u003ca href=\"https://redirect.github.com/square/okio/issues/1773\"\u003e#1773\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/50abe8900f2e7bd48d4afc77bda0afd74fc790ac\"\u003e\u003ccode\u003e50abe89\u003c/code\u003e\u003c/a\u003e Stop using AssertJ (\u003ca href=\"https://redirect.github.com/square/okio/issues/1771\"\u003e#1771\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/square/okio/compare/parent-3.6.0...parent-3.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.squareup.okio:okio` from 3.4.0 to 3.17.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/square/okio/blob/master/CHANGELOG.md\"\u003ecom.squareup.okio:okio's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 3.17.0\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003e2026-03-11\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eNew: Adjust down the Kotlin stdlib dependency to [Kotlin 2.1.21][kotlin_2_1_21]. Okio is built\nwith an up-to-date Kotlin compiler (2.2.21), but depends on an older kotlin-stdlib. We're doing\nthis so you can update Okio and Kotlin independently.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix: Return the correct timestamp in \u003ccode\u003eFileMetadata.createdAtMillis\u003c/code\u003e on Kotlin/Native on UNIX\nplatforms. We were incorrectly using the POSIX \u003ccode\u003ectime\u003c/code\u003e (\u003cem\u003echange\u003c/em\u003e time) instead of the\n\u003ccode\u003ebirthtime\u003c/code\u003e. With this fix Okio now prefers \u003ccode\u003estatx()\u003c/code\u003e over \u003ccode\u003estat()\u003c/code\u003e on native platforms. This\nAPI first appeared in Linux in 4.11 (2017) and Android in API 30 (2020).\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.16.4\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003e2025-11-17\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix: Don't delay triggering timeouts. In 3.16.0 we introduced a regression that caused timeouts\nto fire later than they were supposed to.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.16.3\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003e2025-11-14\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eThis release is the same as 3.16.2. We forgot to cherry-pick a commit before we released!\u003c/p\u003e\n\u003ch2\u003eVersion 3.16.2\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003e2025-10-14\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix: \u003ccode\u003eokio-assetfilesystem\u003c/code\u003e APIs now correctly restored as visible to Kotlin.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.16.1\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003e2025-10-09\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix: Don't crash when calling \u003ccode\u003eSocket.shutdownOutput()\u003c/code\u003e or \u003ccode\u003eshutdownInput()\u003c/code\u003e on an \u003ccode\u003eSSLSocket\u003c/code\u003e on\nAndroid API 21. This method throws an \u003ccode\u003eUnsupportedOperationException\u003c/code\u003e, so we now catch that and\nclose the underlying stream instead.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.16.0\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003e2025-07-29\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix: Change \u003ccode\u003eSocket.asOkioSocket()\u003c/code\u003e to resolve its source \u003ccode\u003eInputStream\u003c/code\u003e and \u003ccode\u003eOutputStream\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/80a50234e5edb96041a8168c4754ba9e1ff3625a\"\u003e\u003ccode\u003e80a5023\u003c/code\u003e\u003c/a\u003e Prepare for release 3.17.0.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/65c0c26bb5242b697ffc28f6c666ae0a01197ff6\"\u003e\u003ccode\u003e65c0c26\u003c/code\u003e\u003c/a\u003e Switch to FileMetadata to use statx instead of stat on Linux and Apple platfo...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/b11f17b233601af92ae1fabea3fecdeea0608631\"\u003e\u003ccode\u003eb11f17b\u003c/code\u003e\u003c/a\u003e Remove Kotlin/JS IR default parameter workarounds. (\u003ca href=\"https://redirect.github.com/square/okio/issues/1786\"\u003e#1786\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/b35f473635db8ad9d5a9b096780e960d1b8f7d4d\"\u003e\u003ccode\u003eb35f473\u003c/code\u003e\u003c/a\u003e Update Gradle to v9.4.0 (\u003ca href=\"https://redirect.github.com/square/okio/issues/1785\"\u003e#1785\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/cbcee31f2bcb7e6f606d8eafc45f4c8ea7228cae\"\u003e\u003ccode\u003ecbcee31\u003c/code\u003e\u003c/a\u003e Update actions/upload-artifact action to v7 (\u003ca href=\"https://redirect.github.com/square/okio/issues/1783\"\u003e#1783\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/fc7aecb7f6f7a123f2024ab6397da04311546bf2\"\u003e\u003ccode\u003efc7aecb\u003c/code\u003e\u003c/a\u003e Update dependency com.android.tools.build:gradle to v9.0.1 (\u003ca href=\"https://redirect.github.com/square/okio/issues/1781\"\u003e#1781\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/79aa26755c77df8c4d0233926c7308fd353ad697\"\u003e\u003ccode\u003e79aa267\u003c/code\u003e\u003c/a\u003e Drop \u003ccode\u003eisWasm()\u003c/code\u003e early return workaround for KT-60212. (\u003ca href=\"https://redirect.github.com/square/okio/issues/1777\"\u003e#1777\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/45459dca7d40b4c2df1454a0f363e0b8e153beb5\"\u003e\u003ccode\u003e45459dc\u003c/code\u003e\u003c/a\u003e Fix result of an 'errnoToIOException' call is not thrown. inside `PosixFileSy...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/9fbab0f7ab00b525b0ae331c8c3ac3c645afc8c8\"\u003e\u003ccode\u003e9fbab0f\u003c/code\u003e\u003c/a\u003e Decode env variables in WASI tests (\u003ca href=\"https://redirect.github.com/square/okio/issues/1773\"\u003e#1773\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/50abe8900f2e7bd48d4afc77bda0afd74fc790ac\"\u003e\u003ccode\u003e50abe89\u003c/code\u003e\u003c/a\u003e Stop using AssertJ (\u003ca href=\"https://redirect.github.com/square/okio/issues/1771\"\u003e#1771\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/square/okio/compare/parent-3.4.0...parent-3.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.springframework.cloud:spring-cloud-dependencies` from 2025.0.2 to 2025.1.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/releases\"\u003eorg.springframework.cloud:spring-cloud-dependencies's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2025.1.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump antora from 3.2.0-alpha.10 to 3.2.0-alpha.11 in /docs by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/spring-cloud/spring-cloud-release/pull/447\"\u003espring-cloud/spring-cloud-release#447\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.springframework.cloud:spring-cloud-contract-dependencies from 5.0.1-SNAPSHOT to 5.0.2-SNAPSHOT by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/spring-cloud/spring-cloud-release/pull/454\"\u003espring-cloud/spring-cloud-release#454\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.springframework.cloud:spring-cloud-contract-dependencies from 5.0.1-SNAPSHOT to 5.0.2-SNAPSHOT by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/spring-cloud/spring-cloud-release/pull/453\"\u003espring-cloud/spring-cloud-release#453\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/cache from 4 to 5 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/spring-cloud/spring-cloud-release/pull/456\"\u003espring-cloud/spring-cloud-release#456\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven:maven-model from 3.9.11 to 3.9.12 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/spring-cloud/spring-cloud-release/pull/461\"\u003espring-cloud/spring-cloud-release#461\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven:maven-model from 3.9.11 to 3.9.12 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/spring-cloud/spring-cloud-release/pull/460\"\u003espring-cloud/spring-cloud-release#460\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/compare/v2025.1.0...v2025.1.1\"\u003ehttps://github.com/spring-cloud/spring-cloud-release/compare/v2025.1.0...v2025.1.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/commit/dbb12bfc2b899fb0845fe4b3c6dc07bc3c1828e2\"\u003e\u003ccode\u003edbb12bf\u003c/code\u003e\u003c/a\u003e Update SNAPSHOT to 2025.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/commit/edc8bcb1d195cb0a9fa96efc82ccb3dfdaf2fd39\"\u003e\u003ccode\u003eedc8bcb\u003c/code\u003e\u003c/a\u003e Bumping versions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/commit/a9f418316485581438af2fa1db54f7ff5e80b17e\"\u003e\u003ccode\u003ea9f4183\u003c/code\u003e\u003c/a\u003e Use Spring Boot 4.0.2-SNAPSHOT\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/commit/da7ad033005dd53554ad5aea9eeefab9416c1661\"\u003e\u003ccode\u003eda7ad03\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/spring-cloud/spring-cloud-release/issues/460\"\u003e#460\u003c/a\u003e from spring-cloud/dependabot/maven/org.apache.maven-m...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/commit/49b10e643ffdb36873b3abb0bcd0539e0942f0c6\"\u003e\u003ccode\u003e49b10e6\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/spring-cloud/spring-cloud-release/issues/461\"\u003e#461\u003c/a\u003e from spring-cloud/dependabot/maven/main/org.apache.ma...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/commit/59782becdf97cb4db3693fc9d3688e85fde493b5\"\u003e\u003ccode\u003e59782be\u003c/code\u003e\u003c/a\u003e Bump org.apache.maven:maven-model from 3.9.11 to 3.9.12\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/commit/89c8dd1e2610118b12e9d9ccb64945833a0ade22\"\u003e\u003ccode\u003e89c8dd1\u003c/code\u003e\u003c/a\u003e Bump org.apache.maven:maven-model from 3.9.11 to 3.9.12\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/commit/96a5fb078d5eb2d80baec60004f1cb2518290afe\"\u003e\u003ccode\u003e96a5fb0\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/spring-cloud/spring-cloud-release/issues/456\"\u003e#456\u003c/a\u003e from spring-cloud/dependabot/github_actions/main/acti...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/commit/5d22a1d1f65df1f7a8c5bc021f5cc5dc44398072\"\u003e\u003ccode\u003e5d22a1d\u003c/code\u003e\u003c/a\u003e Bump actions/cache from 4 to 5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/commit/ec45c6d4c7d7e49695e3c6c9fa68abd3823a770d\"\u003e\u003ccode\u003eec45c6d\u003c/code\u003e\u003c/a\u003e Bumping versions\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/compare/v2025.0.2...v2025.1.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `io.opentelemetry.instrumentation:opentelemetry-instrumentation-annotations` from 2.22.0 to 2.28.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/releases\"\u003eio.opentelemetry.instrumentation:opentelemetry-instrumentation-annotations's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 2.28.1\u003c/h2\u003e\n\u003cp\u003eThis release targets the OpenTelemetry SDK 1.62.0.\u003c/p\u003e\n\u003cp\u003eNote that many artifacts have the \u003ccode\u003e-alpha\u003c/code\u003e suffix attached to their version number, reflecting that they will continue to have breaking changes. Please see \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/blob/main/VERSIONING.md#opentelemetry-java-instrumentation-versioning\"\u003eVERSIONING.md\u003c/a\u003e for more details.\u003c/p\u003e\n\u003ch3\u003e🛠️ Bug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix javaagent startup failures when declarative configuration uses bundled contrib components, such as the rule-based routing sampler. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18813\"\u003e#18813\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 2.28.0\u003c/h2\u003e\n\u003cp\u003eThis release targets the OpenTelemetry SDK 1.62.0.\u003c/p\u003e\n\u003cp\u003eNote that many artifacts have the \u003ccode\u003e-alpha\u003c/code\u003e suffix attached to their version number, reflecting that they will continue to have breaking changes. Please see \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/blob/main/VERSIONING.md#opentelemetry-java-instrumentation-versioning\"\u003eVERSIONING.md\u003c/a\u003e for more details.\u003c/p\u003e\n\u003ch3\u003e⚠️ Breaking changes to non-stable APIs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved the obsolete internal \u003ccode\u003eClassInjector\u003c/code\u003e/\u003ccode\u003eProxyInjectionBuilder\u003c/code\u003e API used by the old \u003ccode\u003eExperimentalInstrumentationModule.injectClasses(ClassInjector)\u003c/code\u003e path; use \u003ccode\u003eExperimentalInstrumentationModule.exposedClassNames()\u003c/code\u003e instead. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18112\"\u003e#18112\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemoved previously deprecated non-stable API methods and the deprecated \u003ccode\u003eopentelemetry-runtime-telemetry-java8\u003c/code\u003e and \u003ccode\u003eopentelemetry-runtime-telemetry-java17\u003c/code\u003e library aliases. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18136\"\u003e#18136\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemoved the previously deprecated \u003ccode\u003ecaptureEventName\u003c/code\u003e library builder setting from the logback-appender-1.0 and log4j-appender-2.17 \u003ccode\u003eOpenTelemetryAppender\u003c/code\u003e, and the corresponding \u003ccode\u003eotel.instrumentation.{logback-appender,log4j-appender,jboss-logmanager}.experimental.capture-event-name\u003c/code\u003e javaagent properties. Use the \u003ccode\u003eotel.event.name\u003c/code\u003e key in MDC / context data / key-value pairs / Logstash markers / structured arguments instead. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18223\"\u003e#18223\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemoved previously deprecated experimental config properties \u003ccode\u003eotel.instrumentation.http.client.experimental.redact-query-parameters\u003c/code\u003e and \u003ccode\u003eotel.instrumentation.common.experimental.db-sqlcommenter.enabled\u003c/code\u003e; use \u003ccode\u003eotel.instrumentation.sanitization.url.experimental.sensitive-query-parameters\u003c/code\u003e and \u003ccode\u003eotel.instrumentation.common.db.experimental.sqlcommenter.enabled\u003c/code\u003e instead. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18229\"\u003e#18229\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemoved the deprecated \u003ccode\u003eotel.instrumentation.servlet.experimental.add-trace-id-request-attribute\u003c/code\u003e property; use \u003ccode\u003eotel.instrumentation.servlet.experimental.trace-id-request-attribute.enabled\u003c/code\u003e instead. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18237\"\u003e#18237\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReshaped the ktor \u003ccode\u003eExperimental\u003c/code\u003e helper from a class with a \u003ccode\u003ecompanion object\u003c/code\u003e to a top-level \u003ccode\u003eobject\u003c/code\u003e. Kotlin source callers (\u003ccode\u003eExperimental.emitExperimentalTelemetry(...)\u003c/code\u003e) are unaffected, but pre-compiled consumers must be recompiled against the new artifact. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18343\"\u003e#18343\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🚫 Deprecations\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eotel.instrumentation.jaxws-cxf-3.0.enabled\u003c/code\u003e in favor of \u003ccode\u003eotel.instrumentation.jaxws-2.0-cxf-3.0.enabled\u003c/code\u003e, and \u003ccode\u003eotel.instrumentation.jaxws-metro-2.2.enabled\u003c/code\u003e in favor of \u003ccode\u003eotel.instrumentation.jaxws-2.0-metro-2.2.enabled\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18184\"\u003e#18184\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🌟 New javaagent instrumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Apache Thrift 0.13 instrumentation for RPC client and server spans and metrics. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18405\"\u003e#18405\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🌟 New library instrumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Apache Thrift 0.13 library instrumentation for RPC client and server spans and metrics. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18405\"\u003e#18405\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e📈 Enhancements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCouchbase 3.1 javaagent instrumentation now emits the more conventional instrumentation scope name \u003ccode\u003eio.opentelemetry.couchbase-3.1\u003c/code\u003e instead of \u003ccode\u003eio.opentelemetry.javaagent.couchbase-3.1\u003c/code\u003e when \u003ccode\u003eotel.instrumentation.common.v3-preview\u003c/code\u003e is enabled. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18426\"\u003e#18426\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eWicket resource requests now use the resource reference class name in the server span name when \u003ccode\u003eotel.instrumentation.common.v3-preview\u003c/code\u003e is enabled. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18312\"\u003e#18312\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18775\"\u003e#18775\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDecide whether javaagent helper classes are injected into the application class loader or isolated based on the advice classes used by an instrumentation. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/17815\"\u003e#17815\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eImprove cgroup v2 container ID detection for Podman by supporting additional \u003ccode\u003emountinfo\u003c/code\u003e layouts and warning when multiple candidate IDs are found. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18272\"\u003e#18272\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🛠️ Bug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix Pekko HTTP and Tapir server route tracking so server span names and \u003ccode\u003ehttp.route\u003c/code\u003e preserve the most specific matched route across nested directives, exceptions, and timeouts; this may change span names and \u003ccode\u003ehttp.route\u003c/code\u003e values for affected routes. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/16390\"\u003e#16390\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix context loss in Finagle HTTP instrumentation across Netty-to-Finagle request conversion and \u003ccode\u003etwitter-util\u003c/code\u003e Future/Promise asynchronous boundaries. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/17867\"\u003e#17867\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix virtual-thread pinning caused by weak-map stale-entry cleanup running on virtual threads; cleanup now runs from the background thread instead. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18113\"\u003e#18113\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAvoid linking batch consumer spans to the ambient consumer span when records or messages have no propagation headers. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18154\"\u003e#18154\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eresetOnEachOperator()\u003c/code\u003e for Reactor 3.1 so it also removes the scheduler hook when instrumentation is disabled. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18258\"\u003e#18258\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnd spans when RxJava 1.0 subscriptions throw synchronously. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18265\"\u003e#18265\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/blob/main/CHANGELOG.md\"\u003eio.opentelemetry.instrumentation:opentelemetry-instrumentation-annotations's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 2.28.1 (2026-05-20)\u003c/h2\u003e\n\u003cp\u003eThis release targets the OpenTelemetry SDK 1.62.0.\u003c/p\u003e\n\u003cp\u003eNote that many artifacts have the \u003ccode\u003e-alpha\u003c/code\u003e suffix attached to their version\nnumber, reflecting that they will continue to have breaking changes. Please see\n\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/blob/main/VERSIONING.md#opentelemetry-java-instrumentation-versioning\"\u003eVERSIONING.md\u003c/a\u003e\nfor more details.\u003c/p\u003e\n\u003ch3\u003e🛠️ Bug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix javaagent startup failures when declarative configuration uses bundled contrib components,\nsuch as the rule-based routing sampler.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18813\"\u003e#18813\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 2.28.0 (2026-05-19)\u003c/h2\u003e\n\u003cp\u003eThis release targets the OpenTelemetry SDK 1.62.0.\u003c/p\u003e\n\u003cp\u003eNote that many artifacts have the \u003ccode\u003e-alpha\u003c/code\u003e suffix attached to their version\nnumber, reflecting that they will continue to have breaking changes. Please see\n\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/blob/main/VERSIONING.md#opentelemetry-java-instrumentation-versioning\"\u003eVERSIONING.md\u003c/a\u003e\nfor more details.\u003c/p\u003e\n\u003ch3\u003e⚠️ Breaking changes to non-stable APIs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved the obsolete internal \u003ccode\u003eClassInjector\u003c/code\u003e/\u003ccode\u003eProxyInjectionBuilder\u003c/code\u003e API used by the old\n\u003ccode\u003eExperimentalInstrumentationModule.injectClasses(ClassInjector)\u003c/code\u003e path; use\n\u003ccode\u003eExperimentalInstrumentationModule.exposedClassNames()\u003c/code\u003e instead.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18112\"\u003e#18112\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemoved previously deprecated non-stable API methods and the deprecated\n\u003ccode\u003eopentelemetry-runtime-telemetry-java8\u003c/code\u003e and \u003ccode\u003eopentelemetry-runtime-telemetry-java17\u003c/code\u003e library\naliases.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18136\"\u003e#18136\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemoved the previously deprecated \u003ccode\u003ecaptureEventName\u003c/code\u003e library builder setting from the\nlogback-appender-1.0 and log4j-appender-2.17 \u003ccode\u003eOpenTelemetryAppender\u003c/code\u003e, and the corresponding\n\u003ccode\u003eotel.instrumentation.{logback-appender,log4j-appender,jboss-logmanager}.experimental.capture-event-name\u003c/code\u003e\njavaagent properties. Use the \u003ccode\u003eotel.event.name\u003c/code\u003e key in MDC / context data / key-value pairs /\nLogstash markers / structured arguments instead.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18223\"\u003e#18223\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemoved previously deprecated experimental config properties\n\u003ccode\u003eotel.instrumentation.http.client.experimental.redact-query-parameters\u003c/code\u003e and\n\u003ccode\u003eotel.instrumentation.common.experimental.db-sqlcommenter.enabled\u003c/code\u003e; use\n\u003ccode\u003eotel.instrumentation.sanitization.url.experimental.sensitive-query-parameters\u003c/code\u003e and\n\u003ccode\u003eotel.instrumentation.common.db.experimental.sqlcommenter.enabled\u003c/code\u003e instead.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18229\"\u003e#18229\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemoved the deprecated \u003ccode\u003eotel.instrumentation.servlet.experimental.add-trace-id-request-attribute\u003c/code\u003e\nproperty; use \u003ccode\u003eotel.instrumentation.servlet.experimental.trace-id-request-attribute.enabled\u003c/code\u003e\ninstead.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18237\"\u003e#18237\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/7ad453a58de282ea04fd88f4178d70a65468b93c\"\u003e\u003ccode\u003e7ad453a\u003c/code\u003e\u003c/a\u003e [release/v2.28.x] Prepare release 2.28.1 (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/18818\"\u003e#18818\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/1f0b4b27c6e3c96d3098fa7a4ece9404ba7c55bd\"\u003e\u003ccode\u003e1f0b4b2\u003c/code\u003e\u003c/a\u003e Prepare change log for upcoming patch release (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/18816\"\u003e#18816\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/f4b9d76e1c8425b53bd1f22a1e5f8612e30659fc\"\u003e\u003ccode\u003ef4b9d76\u003c/code\u003e\u003c/a\u003e [release/v2.28.x] fix(deps): update opentelemetry-java-contrib monorepo to v1...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/9ef68e6b114b2d1fc1f6a3fbc576cb37fc71e893\"\u003e\u003ccode\u003e9ef68e6\u003c/code\u003e\u003c/a\u003e [release/v2.28.x] Prepare release 2.28.0 (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/18791\"\u003e#18791\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/5d26f13fa3a9c8d67d336649796620d65733fc09\"\u003e\u003ccode\u003e5d26f13\u003c/code\u003e\u003c/a\u003e Draft release notes (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/18774\"\u003e#18774\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/37540625c9d7928152a4fe3e52ed255255f6d895\"\u003e\u003ccode\u003e3754062\u003c/code\u003e\u003c/a\u003e Gate Wicket resource span names on v3 preview (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/18775\"\u003e#18775\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/f6f123d374986c34b3e2eee412551de7f6aec58b\"\u003e\u003ccode\u003ef6f123d\u003c/code\u003e\u003c/a\u003e Preserve Spring resource provider class names (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/18785\"\u003e#18785\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/4c6155a89b5abe035197a4a87375cbebbcce8d04\"\u003e\u003ccode\u003e4c6155a\u003c/code\u003e\u003c/a\u003e Normalize internal and resource javaagent packages (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/18746\"\u003e#18746\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/d7b88cef8d7dcc75745520bff25a3ac38a949c75\"\u003e\u003ccode\u003ed7b88ce\u003c/code\u003e\u003c/a\u003e Rename servlet common root package (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/18778\"\u003e#18778\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/d52a5ff2c5aaeb8e5eb2a7149d05a998c7815fdc\"\u003e\u003ccode\u003ed52a5ff\u003c/code\u003e\u003c/a\u003e Rename servlet common snippet package (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/18777\"\u003e#18777\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/compare/v2.22.0...v2.28.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.xmlbeans:xmlbeans` from 5.1.1 to 5.3.0\n\nUpdates `commons-io:commons-io` from 2.19.0 to 2.22.0\n\nUpdates `org.jsoup:jsoup` from 1.18.1 to 1.22.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jhy/jsoup/releases\"\u003eorg.jsoup:jsoup's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ejsoup Java HTML Parser release 1.22.2\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003ejsoup 1.22.2\u003c/strong\u003e is out now, with fixes and refinements across the library. It makes editing the DOM during traversal more predictable, refreshes the default HTML tag definitions with newer elements and better text boundaries, and improves reliability in parsing and HTTP transport. The release also fixes a number of edge cases in cleaning, stream parsing, XML doctype handling, and Android packaging.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003ejsoup\u003c/strong\u003e is a Java library for working with real-world HTML and XML. It provides a very convenient API for extracting and manipulating data, using the best of HTML5 DOM methods and CSS selectors.\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/jhy/jsoup/blob/HEAD/download\"\u003e\u003cstrong\u003eDownload\u003c/strong\u003e\u003c/a\u003e jsoup now.\u003c/p\u003e\n\u003ch2\u003eImprovements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eExpanded and clarified \u003ccode\u003eNodeTraversor\u003c/code\u003e support for in-place DOM rewrites during \u003ccode\u003eNodeVisitor.head()\u003c/code\u003e. Current-node edits such as \u003ccode\u003eremove\u003c/code\u003e, \u003ccode\u003ereplace\u003c/code\u003e, and \u003ccode\u003eunwrap\u003c/code\u003e now recover more predictably, while traversal stays within the original root subtree. This makes single-pass tree cleanup and normalization visitors easier to write, for example when unwrapping presentational elements or replacing text nodes as you walk the DOM. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2472\"\u003e#2472\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eDocumentation: clarified that a configured \u003ccode\u003eCleaner\u003c/code\u003e may be reused across concurrent threads, and that shared \u003ccode\u003eSafelist\u003c/code\u003e instances should not be mutated while in use. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2473\"\u003e#2473\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eUpdated the default HTML \u003ccode\u003eTagSet\u003c/code\u003e for current HTML elements: added \u003ccode\u003edialog\u003c/code\u003e, \u003ccode\u003esearch\u003c/code\u003e, \u003ccode\u003epicture\u003c/code\u003e, and \u003ccode\u003eslot\u003c/code\u003e; made \u003ccode\u003eins\u003c/code\u003e, \u003ccode\u003edel\u003c/code\u003e, \u003ccode\u003ebutton\u003c/code\u003e, \u003ccode\u003eaudio\u003c/code\u003e, \u003ccode\u003evideo\u003c/code\u003e, and \u003ccode\u003ecanvas\u003c/code\u003e inline by default (\u003ccode\u003eTag#isInline()\u003c/code\u003e, aligned to phrasing content in the spec); and added readable \u003ccode\u003eElement.text()\u003c/code\u003e boundaries for controls and embedded objects via the new \u003ccode\u003eTag.TextBoundary\u003c/code\u003e option. This improves pretty-printing and keeps normalized text from running adjacent words together. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2493\"\u003e#2493\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAndroid (R8/ProGuard): added a rule to ignore the optional \u003ccode\u003ere2j\u003c/code\u003e dependency when not present. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2459\"\u003e#2459\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eFixed a \u003ccode\u003eNodeTraversor\u003c/code\u003e regression in 1.21.2 where removing or replacing the current node during \u003ccode\u003ehead()\u003c/code\u003e could revisit the replacement node and loop indefinitely. The traversal docs now also clarify which inserted nodes are visited in the current pass. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2472\"\u003e#2472\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eParsing during charset sniffing no longer fails if an advisory \u003ccode\u003eavailable()\u003c/code\u003e call throws \u003ccode\u003eIOException\u003c/code\u003e, as seen on JDK 8 \u003ccode\u003eHttpURLConnection\u003c/code\u003e. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2474\"\u003e#2474\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eCleaner\u003c/code\u003e no longer makes relative URL attributes in the input document absolute when cleaning or validating a \u003ccode\u003eDocument\u003c/code\u003e. URL normalization now applies only to the cleaned output, and \u003ccode\u003eSafelist.isSafeAttribute()\u003c/code\u003e is side effect free. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2475\"\u003e#2475\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eCleaner\u003c/code\u003e no longer duplicates enforced attributes when the input \u003ccode\u003eDocument\u003c/code\u003e preserves attribute case. A case-variant source attribute is now replaced by the enforced attribute in the cleaned output. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2476\"\u003e#2476\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eIf a per-request SOCKS proxy is configured, jsoup now avoids using the JDK \u003ccode\u003eHttpClient\u003c/code\u003e, because the JDK would silently ignore that proxy and attempt to connect directly. Those requests now fall back to the legacy \u003ccode\u003eHttpURLConnection\u003c/code\u003e transport instead, which does support SOCKS. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2468\"\u003e#2468\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eConnection.Response.streamParser()\u003c/code\u003e and \u003ccode\u003eDataUtil.streamParser(Path, ...)\u003c/code\u003e could fail on small inputs without a declared charset, if the initial 5 KB charset sniff fully consumed the input and closed it before the stream parse began. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2483\"\u003e#2483\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eIn XML mode, doctypes with an internal subset, such as \u003ccode\u003e\u0026lt;!DOCTYPE root [\u0026lt;!ENTITY name \u0026quot;value\u0026quot;\u0026gt;]\u0026gt;\u003c/code\u003e, now round-trip correctly. The subset is preserved as raw text only; entities are not expanded and external DTDs are not loaded. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2486\"\u003e#2486\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBuild Changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMigrated the integration test server from Jetty to Netty, which actively maintains support for our minimum JDK target (8). \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2491\"\u003e#2491\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003eMy sincere thanks to everyone who contributed to this release!\nIf you have any suggestions for the next release, I would love to hear them; please get in touch via \u003ca href=\"https://github.com/jhy/jsoup/discussions\"\u003ejsoup discussions\u003c/a\u003e, or with me \u003ca href=\"https://jhedley.com/\"\u003edirectly\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eYou can also \u003c!-- raw HTML omitted --\u003efollow me\u003c!-- raw HTML omitted --\u003e (\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e@\u003ca href=\"mailto:jhy@tilde.zone\"\u003ejhy@tilde.zone\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e) on Mastodon / Fediverse to receive occasional notes about jsoup releases.\u003c/p\u003e\n\u003ch2\u003ejsoup Java HTML Parser release 1.22.1\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003ejsoup 1.22.1\u003c/strong\u003e is out now, adding support for the \u003ccode\u003ere2j\u003c/code\u003e regular expression engine for regex-based CSS selectors, a configurable maximum parser depth, and numerous bug fixes and improvements.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003ejsoup\u003c/strong\u003e is a Java library for working with real-world HTML and XML. It provides a very convenient API for extracting and manipulating data, using the best of HTML5 DOM methods and CSS selectors.\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://jsoup.org/download\"\u003e\u003cstrong\u003eDownload\u003c/strong\u003e\u003c/a\u003e jsoup now.\u003c/p\u003e\n\u003ch3\u003eImprovements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded support for using the \u003ccode\u003ere2j\u003c/code\u003e regular expression engine for regex-based CSS selectors (e.g. \u003ccode\u003e[attr~=regex]\u003c/code\u003e, \u003ccode\u003e:matches(regex)\u003c/code\u003e), which ensures linear-time performance for regex evaluation. This allows safer handling of arbitrary user-supplied query regexes. To enable, add the \u003ccode\u003ecom.google.re2j\u003c/code\u003e dependency to your classpath, e.g.:\u003c/li\u003e\n\u003c/ul\u003e\n\u003cpre lang=\"xml\"\u003e\u003ccode\u003e  \u0026lt;dependency\u0026gt;\r\n    \u0026lt;groupId\u0026gt;com.google.re2j\u0026lt;/groupId\u0026gt;\r\n    \u0026lt;artifactId\u0026gt;re2j\u0026lt;/artifactId\u0026gt;\r\n    \u0026lt;version\u0026gt;1.8\u0026lt;/version\u0026gt;\r\n  \u0026lt;/dependency\u0026gt;\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003e(If you already have that dependency in your classpath, but you want to keep using the Java regex engine, you can disable re2j via \u003ccode\u003eSystem.setProperty(\u0026quot;jsoup.useRe2j\u0026quot;, \u0026quot;false\u0026quot;)\u003c/code\u003e.) You can confirm that the re2j engine has been enable...\n\n_Description has been truncated_","html_url":"https://github.com/beyonai/ByClaw/pull/134","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/beyonai%2FByClaw/issues/134","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/134/packages"},{"uuid":"4609245594","node_id":"PR_kwDOB20KpM7jtzlL","number":2763,"state":"closed","title":"Bump the dependencies group across 1 directory with 14 updates","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-06-09T00:35:45.000Z","author_association":null,"state_reason":null,"created_at":"2026-06-08T00:35:52.000Z","updated_at":"2026-06-09T00:35:47.000Z","time_to_close":86393,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"dependencies","update_count":14,"packages":[{"name":"com.puppycrawl.tools:checkstyle","old_version":"13.4.2","new_version":"13.5.0","repository_url":"https://github.com/checkstyle/checkstyle"},{"name":"org.ow2.asm:asm","old_version":"9.10","new_version":"9.10.1"},{"name":"org.ow2.asm:asm-commons","old_version":"9.10","new_version":"9.10.1"},{"name":"org.ow2.asm:asm-tree","old_version":"9.10","new_version":"9.10.1"},{"name":"org.ow2.asm:asm-util","old_version":"9.10","new_version":"9.10.1"},{"name":"com.sun.xml.bind:jaxb-core","old_version":"4.0.8","new_version":"4.0.9"},{"name":"com.sun.xml.bind:jaxb-impl","old_version":"4.0.8","new_version":"4.0.9"},{"name":"com.sun.xml.bind:jaxb-xjc","old_version":"4.0.8","new_version":"4.0.9"},{"name":"com.sun.xml.ws:jaxws-rt","old_version":"4.0.4","new_version":"4.0.5"},{"name":"org.eclipse.parsson:parsson","old_version":"1.1.7","new_version":"1.1.9","repository_url":"https://github.com/eclipse-ee4j/parsson"},{"name":"org.mongodb:mongodb-driver-sync","old_version":"5.7.0","new_version":"5.8.0","repository_url":"https://github.com/mongodb/mongo-java-driver"},{"name":"com.oracle.nosql.sdk:nosqldriver","old_version":"5.4.21","new_version":"5.4.22","repository_url":"https://github.com/oracle/nosql-java-sdk"},{"name":"ch.qos.logback:logback-core","old_version":"1.5.32","new_version":"1.5.34","repository_url":"https://github.com/qos-ch/logback"},{"name":"ch.qos.logback:logback-classic","old_version":"1.5.32","new_version":"1.5.34","repository_url":"https://github.com/qos-ch/logback"}],"path":null,"ecosystem":"maven"},"body":"Bumps the dependencies group with 14 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [com.puppycrawl.tools:checkstyle](https://github.com/checkstyle/checkstyle) | `13.4.2` | `13.5.0` |\n| org.ow2.asm:asm | `9.10` | `9.10.1` |\n| org.ow2.asm:asm-commons | `9.10` | `9.10.1` |\n| org.ow2.asm:asm-tree | `9.10` | `9.10.1` |\n| org.ow2.asm:asm-util | `9.10` | `9.10.1` |\n| com.sun.xml.bind:jaxb-core | `4.0.8` | `4.0.9` |\n| com.sun.xml.bind:jaxb-impl | `4.0.8` | `4.0.9` |\n| com.sun.xml.bind:jaxb-xjc | `4.0.8` | `4.0.9` |\n| com.sun.xml.ws:jaxws-rt | `4.0.4` | `4.0.5` |\n| [org.eclipse.parsson:parsson](https://github.com/eclipse-ee4j/parsson) | `1.1.7` | `1.1.9` |\n| [org.mongodb:mongodb-driver-sync](https://github.com/mongodb/mongo-java-driver) | `5.7.0` | `5.8.0` |\n| [com.oracle.nosql.sdk:nosqldriver](https://github.com/oracle/nosql-java-sdk) | `5.4.21` | `5.4.22` |\n| [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) | `1.5.32` | `1.5.34` |\n| [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) | `1.5.32` | `1.5.34` |\n\n\nUpdates `com.puppycrawl.tools:checkstyle` from 13.4.2 to 13.5.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/checkstyle/checkstyle/releases\"\u003ecom.puppycrawl.tools:checkstyle's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003echeckstyle-13.5.0\u003c/h2\u003e\n\u003cp\u003eCheckstyle 13.5.0 - \u003ca href=\"https://checkstyle.org/releasenotes.html#Release_13.5.0\"\u003ehttps://checkstyle.org/releasenotes.html#Release_13.5.0\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eNew:\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19496\"\u003e#19496\u003c/a\u003e - AvoidStarImport: new property maxAllowedStarImports to allow atmost one star import in a file.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/14782\"\u003e#14782\u003c/a\u003e - LITERAL_DEFAULT token support in RightCurlyCheck.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/15484\"\u003e#15484\u003c/a\u003e - New Check UnusedTryResourceShouldBeUnnamed.\u003c/p\u003e\n\u003cp\u003eBug fixes:\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/17697\"\u003e#17697\u003c/a\u003e - Google style: Disallow comments enclosed in boxes.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19641\"\u003e#19641\u003c/a\u003e - Add checks for OpenJDK Style §3.10 - Variable Declarations.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19640\"\u003e#19640\u003c/a\u003e - Add checks for OpenJDK Style §4.1 - Package Names.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/18227\"\u003e#18227\u003c/a\u003e - Extend TextBlockGoogleStyleFormatting to check indentation of each line in the blocks.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19770\"\u003e#19770\u003c/a\u003e - JavadocTypeCheck incorrectly matches record component \u003ccode\u003e@\u003c/code\u003eparam tags using prefix instead of exact match.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/17052\"\u003e#17052\u003c/a\u003e - Add support for flexible constructor bodies (JEP 513) targeted for JDK25.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/17464\"\u003e#17464\u003c/a\u003e - RequireThis false positive inside annotation definition.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19623\"\u003e#19623\u003c/a\u003e - Add checks for OpenJDK Style  §3.3 - Import statements.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/17203\"\u003e#17203\u003c/a\u003e - PatternVariableAssignment check false negative when pattern variable extends beyond the statement of introduction.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19716\"\u003e#19716\u003c/a\u003e - False Negative: SimplifyBooleanExpression does not report with paranthesized boolean literals in ternary operators.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19617\"\u003e#19617\u003c/a\u003e - Add checks for OpenJDK Style §2 - Java Source Files.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/17253\"\u003e#17253\u003c/a\u003e - Google-style: Illegal to break the line before or after the lambda arrow.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19149\"\u003e#19149\u003c/a\u003e - update MissingJavadocTypeCheck to use AST of javadoc.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/2629\"\u003e#2629\u003c/a\u003e - IndentationCheck: incorrect validation for class definition.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/5685\"\u003e#5685\u003c/a\u003e - Indentation: false positive for try child on the same line.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/11822\"\u003e#11822\u003c/a\u003e - RequireThisCheck giving multiple violation for classes nested in lambdas.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19622\"\u003e#19622\u003c/a\u003e - Add checks for OpenJDK Style §3.2 - Package declaration.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/checkstyle/checkstyle/commit/110e63eee6e634b5ebcdf21b1cd1c96c518007d8\"\u003e\u003ccode\u003e110e63e\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release checkstyle-13.5.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/checkstyle/checkstyle/commit/47d9268a1fb45beb3a67be12ff934b80a9d2f10b\"\u003e\u003ccode\u003e47d9268\u003c/code\u003e\u003c/a\u003e doc: release notes for 13.5.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/checkstyle/checkstyle/commit/2ae101f6a70ffd4a232b2d30a4bb0a2dc42d9b9e\"\u003e\u003ccode\u003e2ae101f\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19793\"\u003e#19793\u003c/a\u003e: Anchor IndentationCheck regex in google_checks.xml SuppressWith...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/checkstyle/checkstyle/commit/fb3c9e949e61b3573202b5884d54b4d598400743\"\u003e\u003ccode\u003efb3c9e9\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19827\"\u003e#19827\u003c/a\u003e: Complete removal of chapter numbers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/checkstyle/checkstyle/commit/e2b04118c7103e5564518edfa770e0b8d786b7aa\"\u003e\u003ccode\u003ee2b0411\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/18435\"\u003e#18435\u003c/a\u003e: Fix xdocs Examples AST Consistency Test - nowhitespacebefore\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/checkstyle/checkstyle/commit/096df1df3554905130a45b4af4fb05512bc10a50\"\u003e\u003ccode\u003e096df1d\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19764\"\u003e#19764\u003c/a\u003e: Move violation comment out of Javadoc\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/checkstyle/checkstyle/commit/4d69a3f4e3abf67f960703eae7fe3212dc2694e3\"\u003e\u003ccode\u003e4d69a3f\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19993\"\u003e#19993\u003c/a\u003e: Regexp check for unnecessary // ok comments is configured under...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/checkstyle/checkstyle/commit/035297e75b576c07316070e092576674b72ef3f5\"\u003e\u003ccode\u003e035297e\u003c/code\u003e\u003c/a\u003e dependency: bump org.pitest:pitest-maven from 1.25.2 to 1.25.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/checkstyle/checkstyle/commit/6b827897c8cc3f2414a0543bd97b3704a6e5aaa0\"\u003e\u003ccode\u003e6b82789\u003c/code\u003e\u003c/a\u003e supplemental: Fixes Overloaded Methods Order\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/checkstyle/checkstyle/commit/d9306dab50c1a267c03595acbedbc8f0650a79b4\"\u003e\u003ccode\u003ed9306da\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/18435\"\u003e#18435\u003c/a\u003e: Fix xdocs Examples AST Consistency Test - linelength\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/checkstyle/checkstyle/compare/checkstyle-13.4.2...checkstyle-13.5.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.ow2.asm:asm` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-commons` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-tree` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-util` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-commons` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-tree` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-util` from 9.10 to 9.10.1\n\nUpdates `com.sun.xml.bind:jaxb-core` from 4.0.8 to 4.0.9\n\nUpdates `com.sun.xml.bind:jaxb-impl` from 4.0.8 to 4.0.9\n\nUpdates `com.sun.xml.bind:jaxb-xjc` from 4.0.8 to 4.0.9\n\nUpdates `com.sun.xml.bind:jaxb-impl` from 4.0.8 to 4.0.9\n\nUpdates `com.sun.xml.bind:jaxb-xjc` from 4.0.8 to 4.0.9\n\nUpdates `com.sun.xml.ws:jaxws-rt` from 4.0.4 to 4.0.5\n\nUpdates `org.eclipse.parsson:parsson` from 1.1.7 to 1.1.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/eclipse-ee4j/parsson/releases\"\u003eorg.eclipse.parsson:parsson's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.1.9\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePublish Central releases automatically by \u003ca href=\"https://github.com/jbescos\"\u003e\u003ccode\u003e@​jbescos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/171\"\u003eeclipse-ee4j/parsson#171\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/eclipse-ee4j/parsson/compare/1.1.8...1.1.9\"\u003ehttps://github.com/eclipse-ee4j/parsson/compare/1.1.8...1.1.9\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.1.8\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate deprecated GH actions by \u003ca href=\"https://github.com/jbescos\"\u003e\u003ccode\u003e@​jbescos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/136\"\u003eeclipse-ee4j/parsson#136\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMake JsonArrayImpl implement RandomAccess by \u003ca href=\"https://github.com/marschall\"\u003e\u003ccode\u003e@​marschall\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/135\"\u003eeclipse-ee4j/parsson#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplement JsonStructureParser.currentEvent() by \u003ca href=\"https://github.com/marschall\"\u003e\u003ccode\u003e@​marschall\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/134\"\u003eeclipse-ee4j/parsson#134\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove unused method by \u003ca href=\"https://github.com/pzygielo\"\u003e\u003ccode\u003e@​pzygielo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/137\"\u003eeclipse-ee4j/parsson#137\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRename parameter to match field by \u003ca href=\"https://github.com/pzygielo\"\u003e\u003ccode\u003e@​pzygielo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/138\"\u003eeclipse-ee4j/parsson#138\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplement JsonStructureParser#getValue methods by \u003ca href=\"https://github.com/marschall\"\u003e\u003ccode\u003e@​marschall\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/140\"\u003eeclipse-ee4j/parsson#140\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse assertThrows by \u003ca href=\"https://github.com/marschall\"\u003e\u003ccode\u003e@​marschall\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/142\"\u003eeclipse-ee4j/parsson#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix compilation failes by \u003ca href=\"https://github.com/marschall\"\u003e\u003ccode\u003e@​marschall\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/144\"\u003eeclipse-ee4j/parsson#144\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdding Dependabot for dependency management by \u003ca href=\"https://github.com/mswatosh\"\u003e\u003ccode\u003e@​mswatosh\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/148\"\u003eeclipse-ee4j/parsson#148\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ejson input size limit by \u003ca href=\"https://github.com/jbescos\"\u003e\u003ccode\u003e@​jbescos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/169\"\u003eeclipse-ee4j/parsson#169\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd Maven Central publishing release profile by \u003ca href=\"https://github.com/jbescos\"\u003e\u003ccode\u003e@​jbescos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/170\"\u003eeclipse-ee4j/parsson#170\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marschall\"\u003e\u003ccode\u003e@​marschall\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/135\"\u003eeclipse-ee4j/parsson#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mswatosh\"\u003e\u003ccode\u003e@​mswatosh\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/148\"\u003eeclipse-ee4j/parsson#148\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/eclipse-ee4j/parsson/compare/1.1.7...1.1.8\"\u003ehttps://github.com/eclipse-ee4j/parsson/compare/1.1.7...1.1.8\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/f7204e83adb07bfe9f722bbd914dc680b1071114\"\u003e\u003ccode\u003ef7204e8\u003c/code\u003e\u003c/a\u003e Prepare release org.eclipse.parsson:project:1.1.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/2d01f006047e05cef49d13abe5ab25d66108f71a\"\u003e\u003ccode\u003e2d01f00\u003c/code\u003e\u003c/a\u003e Publish Central releases automatically (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/171\"\u003e#171\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/10920a209563d8a0ac13ca3d41e3c6066367835f\"\u003e\u003ccode\u003e10920a2\u003c/code\u003e\u003c/a\u003e Add Maven Central publishing release profile (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/170\"\u003e#170\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c\"\u003e\u003ccode\u003e134e8d1\u003c/code\u003e\u003c/a\u003e json input size limit (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/169\"\u003e#169\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/0789993205ee613ad63710bd3eafb96cd97afbde\"\u003e\u003ccode\u003e0789993\u003c/code\u003e\u003c/a\u003e Adding Dependabot for dependency management (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/148\"\u003e#148\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/216b15d0e9231546fa542467f9a3732973619b26\"\u003e\u003ccode\u003e216b15d\u003c/code\u003e\u003c/a\u003e Fix compilation failes (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/144\"\u003e#144\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/34177db697ee56f8e7a41f6b5998404681baf251\"\u003e\u003ccode\u003e34177db\u003c/code\u003e\u003c/a\u003e Use assertThrows (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/142\"\u003e#142\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/9d6796013c7a526c7ac80edd690e16bb4a186dd4\"\u003e\u003ccode\u003e9d67960\u003c/code\u003e\u003c/a\u003e Implement JsonStructureParser#getValue methods (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/140\"\u003e#140\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/7c8c2444c61b6b1f44c2c2f36e6ebf905b2c7624\"\u003e\u003ccode\u003e7c8c244\u003c/code\u003e\u003c/a\u003e Rename parameter to match field (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/138\"\u003e#138\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/4dda2e0195dcde4f11eda1c31c642d84eda50ae5\"\u003e\u003ccode\u003e4dda2e0\u003c/code\u003e\u003c/a\u003e Remove unused method (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/137\"\u003e#137\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/eclipse-ee4j/parsson/compare/1.1.7...1.1.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.mongodb:mongodb-driver-sync` from 5.7.0 to 5.8.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mongodb/mongo-java-driver/releases\"\u003eorg.mongodb:mongodb-driver-sync's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eJava Driver 5.8.0 (May 28, 2026)\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003e🔥 Enhancements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded typed builder API for vector search index definitions \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1960\"\u003e#1960\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003e$rerank\u003c/code\u003e aggregation stage support (MongoDB 8.3 / Atlas) \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1963\"\u003e#1963\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003evectorSearch\u003c/code\u003e operator support for the \u003ccode\u003e$search\u003c/code\u003e pipeline stage \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1962\"\u003e#1962\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003estoredSource\u003c/code\u003e support for vector search indexes and \u003ccode\u003ereturnStoredSource\u003c/code\u003e for \u003ccode\u003e$vectorSearch\u003c/code\u003e queries \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1977\"\u003e#1977\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eBinaryVector\u003c/code\u003e and \u003ccode\u003eVectorSearchQuery\u003c/code\u003e \u003ccode\u003evectorSearch\u003c/code\u003e overloads to the Scala driver \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1986\"\u003e#1986\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eOptimized \u003ccode\u003eRawBsonDocument\u003c/code\u003e encode and decode by eliminating intermediate allocations \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1988\"\u003e#1988\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePreliminary refactoring for backpressure support \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1952\"\u003e#1952\u003c/a\u003e by \u003ca href=\"https://github.com/stIncMale\"\u003e\u003ccode\u003e@​stIncMale\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSmall improvements related to value-based classes \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1964\"\u003e#1964\u003c/a\u003e by \u003ca href=\"https://github.com/stIncMale\"\u003e\u003ccode\u003e@​stIncMale\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🛠 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed OSGi bundle resolution failure when Micrometer is not present \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1982\"\u003e#1982\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded missing Javadoc to \u003ccode\u003eMongodbObservation\u003c/code\u003e and \u003ccode\u003eMongodbObservationContext\u003c/code\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e📦 Dependency Updates\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpgraded \u003ccode\u003elibmongocrypt\u003c/code\u003e to 1.18.1 \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1983\"\u003e#1983\u003c/a\u003e by \u003ca href=\"https://github.com/strogiyotec\"\u003e\u003ccode\u003e@​strogiyotec\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🧪 Testing \u0026amp; CI\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003eAGENTS.md\u003c/code\u003e for AI coding agent support across all modules by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded test cases for new auto-embedding index fields \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1936\"\u003e#1936\u003c/a\u003e by \u003ca href=\"https://github.com/strogiyotec\"\u003e\u003ccode\u003e@​strogiyotec\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded Scala 3 to \u003ccode\u003epublish.sh\u003c/code\u003e \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1958\"\u003e#1958\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eNamespaceExists\u003c/code\u003e test failure \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1956\"\u003e#1956\u003c/a\u003e by \u003ca href=\"https://github.com/nhachicha\"\u003e\u003ccode\u003e@​nhachicha\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSimplified \u003ccode\u003eRetryState\u003c/code\u003e creation as preliminary backpressure work \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1961\"\u003e#1961\u003c/a\u003e by \u003ca href=\"https://github.com/stIncMale\"\u003e\u003ccode\u003e@​stIncMale\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMade \u003ccode\u003eRetryState.isLastAttempt\u003c/code\u003e private and simplified code \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1967\"\u003e#1967\u003c/a\u003e by \u003ca href=\"https://github.com/stIncMale\"\u003e\u003ccode\u003e@​stIncMale\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/techbelle\"\u003e\u003ccode\u003e@​techbelle\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1972\"\u003emongodb/mongo-java-driver#1972\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVerifying artifact signatures\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://www.mongodb.com/docs/drivers/java/sync/current/security/validate-signatures/\"\u003ehttps://www.mongodb.com/docs/drivers/java/sync/current/security/validate-signatures/\u003c/a\u003e for the full procedure.\u003c/p\u003e\n\u003cp\u003eTo download and import the public key for verifying signatures, execute\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003egpg --keyserver hkps://keyserver.ubuntu.com --recv-keys 1a75005e142192223d6a7c3b76e0008d166740a8\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/mongodb/mongo-java-driver/compare/r5.7.0...r5.8.0\"\u003ehttps://github.com/mongodb/mongo-java-driver/compare/r5.7.0...r5.8.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/6024ca9f6ca226cffb7526659b19810707970310\"\u003e\u003ccode\u003e6024ca9\u003c/code\u003e\u003c/a\u003e Version: bump 5.8.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/f3bbdb2701b8c462c64db4c5f3f2c61b23b723e9\"\u003e\u003ccode\u003ef3bbdb2\u003c/code\u003e\u003c/a\u003e Add BinaryVector and VectorSearchQuery vectorSearch overloads to Scala driver...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/966ababa45a5d38a644bc8e8ce8de58eb882dd66\"\u003e\u003ccode\u003e966abab\u003c/code\u003e\u003c/a\u003e Upgrade libmongocrypt version to 1.18.1 (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/1983\"\u003e#1983\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/98e07611f0f0c3e22d89cfb766137e59ab7b2a2f\"\u003e\u003ccode\u003e98e0761\u003c/code\u003e\u003c/a\u003e Optimize RawBsonDocument encode and decode by eliminating intermediate alloca...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/40ee8d511e4541727de2edc4527d209d842fd607\"\u003e\u003ccode\u003e40ee8d5\u003c/code\u003e\u003c/a\u003e Fix NamespaceExists test failure (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/1956\"\u003e#1956\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/541af753642b070a04ec64f54b9af018d297c2d3\"\u003e\u003ccode\u003e541af75\u003c/code\u003e\u003c/a\u003e Mark micrometer OSGi imports as optional and add bundle resolution test (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/1982\"\u003e#1982\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/cd6c045cf866d6d5038fcbcf8825742174a3903a\"\u003e\u003ccode\u003ecd6c045\u003c/code\u003e\u003c/a\u003e Add storedSource support for vector search indexes and returnStoredSource for...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/717da9c63b5531e35e684bc0a8043500b3fa7560\"\u003e\u003ccode\u003e717da9c\u003c/code\u003e\u003c/a\u003e Revert \u0026quot;Resolve TLS channel address before opening socket\u0026quot; (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/1979\"\u003e#1979\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/58122f6b280cda429af25f69e3692132e1eabb60\"\u003e\u003ccode\u003e58122f6\u003c/code\u003e\u003c/a\u003e Add vectorSearch operator for $search pipeline stage (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/1962\"\u003e#1962\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/13d4aef5f58283977042340ee8d7d9af4a1786d4\"\u003e\u003ccode\u003e13d4aef\u003c/code\u003e\u003c/a\u003e Resolve TLS channel address before opening socket\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mongodb/mongo-java-driver/compare/r5.7.0...r5.8.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.oracle.nosql.sdk:nosqldriver` from 5.4.21 to 5.4.22\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/oracle/nosql-java-sdk/releases\"\u003ecom.oracle.nosql.sdk:nosqldriver's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e5.4.22\u003c/h2\u003e\n\u003ch2\u003e[5.4.22] 2026-05-15\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded redaction of sensitive HTTP header values in debug logging by default,\nplus the \u003ccode\u003ecom.oracle.nosql.sdk.nosqldriver.log-sensitive-headers\u003c/code\u003e system\nproperty to allow full header values when needed for debugging.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed bug in handling of empty namespaces in prepared statements.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated Netty version to 4.1.133.Final\u003c/li\u003e\n\u003cli\u003eUpdated Jackson-core to 2.18.7\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/oracle/nosql-java-sdk/blob/main/CHANGELOG.md\"\u003ecom.oracle.nosql.sdk:nosqldriver's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[5.4.22] 2026-05-15\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded redaction of sensitive HTTP header values in debug logging by default,\nplus the \u003ccode\u003ecom.oracle.nosql.sdk.nosqldriver.log-sensitive-headers\u003c/code\u003e system\nproperty to allow full header values when needed for debugging.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed bug in handling of empty namespaces in prepared statements.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated Netty version to 4.1.133.Final\u003c/li\u003e\n\u003cli\u003eUpdated Jackson-core to 2.18.7\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/801ba4070febb5c0e870ab8cdb5ee7938831a545\"\u003e\u003ccode\u003e801ba40\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/oracle/nosql-java-sdk/issues/204\"\u003e#204\u003c/a\u003e from oracle/fix/netty-4.1.133\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/d7c7ed22b8c9437041dc473577d899dcf984db31\"\u003e\u003ccode\u003ed7c7ed2\u003c/code\u003e\u003c/a\u003e additional changes for 5.4.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/e27f8f7c19a457ebdb8cd8130db61f75064ccc43\"\u003e\u003ccode\u003ee27f8f7\u003c/code\u003e\u003c/a\u003e update 3rd parties\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/0c21037e61f44fac98af2e52b2506c3a0bcb9028\"\u003e\u003ccode\u003e0c21037\u003c/code\u003e\u003c/a\u003e Handle null or empty namespace list in prepared statements (\u003ca href=\"https://redirect.github.com/oracle/nosql-java-sdk/issues/200\"\u003e#200\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/b81457b2e65e323c30cda83d6ce7cee8cb771a83\"\u003e\u003ccode\u003eb81457b\u003c/code\u003e\u003c/a\u003e Moving to 5.4.22-SNAPSHOT (\u003ca href=\"https://redirect.github.com/oracle/nosql-java-sdk/issues/199\"\u003e#199\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/6248e8b0d53c269a888bc335faeede7c5619f323\"\u003e\u003ccode\u003e6248e8b\u003c/code\u003e\u003c/a\u003e implemented UNION (and a few other query operators) (\u003ca href=\"https://redirect.github.com/oracle/nosql-java-sdk/issues/184\"\u003e#184\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/d09ae8bbcdd1ae459d80ad269c2ef1ff33ed65cd\"\u003e\u003ccode\u003ed09ae8b\u003c/code\u003e\u003c/a\u003e Cleaned up compiler warnings\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/7f8a40f0c92b0a63e7c2d81f65daa03971b2b38d\"\u003e\u003ccode\u003e7f8a40f\u003c/code\u003e\u003c/a\u003e Redact sensitive HTTP headers in debug logging (\u003ca href=\"https://redirect.github.com/oracle/nosql-java-sdk/issues/198\"\u003e#198\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/4a3e9e5298a11450a9fe85a5857c2a0e75686c2a\"\u003e\u003ccode\u003e4a3e9e5\u003c/code\u003e\u003c/a\u003e Preparing for 5.4.21 release (\u003ca href=\"https://redirect.github.com/oracle/nosql-java-sdk/issues/196\"\u003e#196\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/oracle/nosql-java-sdk/compare/v5.4.21...v5.4.22\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ch.qos.logback:logback-core` from 1.5.32 to 1.5.34\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.34\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-06-01 Release of logback version 1.5.34\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In case certain StackTraceElement values returned by the Throwable.getStackTrace method are null, StackTraceElementProxy substitutes a dummy instance instead of throwing an IllegalArgumentException. This resolves [issues \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003e#1040\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003eqos-ch/logback#1040\u003c/a\u003e), reported by Naotsugu Kobayashi.\u003c/p\u003e\n\u003cp\u003e• HardenedObjectInputStream will now throw an InvalidClassException during deserialization attempts of Proxy classes. This change addresses potential deserialization whitelist bypass vulnerability reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-10532\"\u003eCVE-2026-10532\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bitwise identical binary of this version can be reproduced by building from source code at commit e62272ac152469aec1ede056c3c7d0d7314e7bfe associated with the tag v_1.5.34. This release was built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e62272ac152469aec1ede056c3c7d0d7314e7bfe\"\u003e\u003ccode\u003ee62272a\u003c/code\u003e\u003c/a\u003e prepare release 1.5.34\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/1e9e926db1529b729a0e2d29fdee151c2aea0341\"\u003e\u003ccode\u003e1e9e926\u003c/code\u003e\u003c/a\u003e add resolveProxyClassRejectsDynamicProxies unit test\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/2de5cbe90b74fa284685304bc91321313b0d8e2f\"\u003e\u003ccode\u003e2de5cbe\u003c/code\u003e\u003c/a\u003e added StackTraceElementProxyTest, minor edits to AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/0e9b9278b5d3f0b573762cd7b5482ed65244418e\"\u003e\u003ccode\u003e0e9b927\u003c/code\u003e\u003c/a\u003e in case StackTraceElement is null use a substitute, fixing issues/1040\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/f7a0654c2b7e8e1c461e3d9e483e82ef969b5818\"\u003e\u003ccode\u003ef7a0654\u003c/code\u003e\u003c/a\u003e prevent resolveProxyClass bypass\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/249b81f3754f1fb58f8507f244a36c7a940854c0\"\u003e\u003ccode\u003e249b81f\u003c/code\u003e\u003c/a\u003e docs are no longer distributed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/1c3b26a839f05b6bc1769e5a028ef326c711cec8\"\u003e\u003ccode\u003e1c3b26a\u003c/code\u003e\u003c/a\u003e start work on 1.5.34-SNAPSHOT\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.34\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ch.qos.logback:logback-classic` from 1.5.32 to 1.5.34\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-classic's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.34\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-06-01 Release of logback version 1.5.34\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In case certain StackTraceElement values returned by the Throwable.getStackTrace method are null, StackTraceElementProxy substitutes a dummy instance instead of throwing an IllegalArgumentException. This resolves [issues \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003e#1040\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003eqos-ch/logback#1040\u003c/a\u003e), reported by Naotsugu Kobayashi.\u003c/p\u003e\n\u003cp\u003e• HardenedObjectInputStream will now throw an InvalidClassException during deserialization attempts of Proxy classes. This change addresses potential deserialization whitelist bypass vulnerability reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-10532\"\u003eCVE-2026-10532\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bitwise identical binary of this version can be reproduced by building from source code at commit e62272ac152469aec1ede056c3c7d0d7314e7bfe associated with the tag v_1.5.34. This release was built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e62272ac152469aec1ede056c3c7d0d7314e7bfe\"\u003e\u003ccode\u003ee62272a\u003c/code\u003e\u003c/a\u003e prepare release 1.5.34\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/1e9e926db1529b729a0e2d29fdee151c2aea0341\"\u003e\u003ccode\u003e1e9e926\u003c/code\u003e\u003c/a\u003e add resolveProxyClassRejectsDynamicProxies unit test\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/2de5cbe90b74fa284685304bc91321313b0d8e2f\"\u003e\u003ccode\u003e2de5cbe\u003c/code\u003e\u003c/a\u003e added StackTraceElementProxyTest, minor edits to AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/0e9b9278b5d3f0b573762cd7b5482ed65244418e\"\u003e\u003ccode\u003e0e9b927\u003c/code\u003e\u003c/a\u003e in case StackTraceElement is null use a substitute, fixing issues/1040\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/f7a0654c2b7e8e1c461e3d9e483e82ef969b5818\"\u003e\u003ccode\u003ef7a0654\u003c/code\u003e\u003c/a\u003e prevent resolveProxyClass bypass\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/249b81f3754f1fb58f8507f244a36c7a940854c0\"\u003e\u003ccode\u003e249b81f\u003c/code\u003e\u003c/a\u003e docs are no longer distributed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/1c3b26a839f05b6bc1769e5a028ef326c711cec8\"\u003e\u003ccode\u003e1c3b26a\u003c/code\u003e\u003c/a\u003e start work on 1.5.34-SNAPSHOT\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.34\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ch.qos.logback:logback-classic` from 1.5.32 to 1.5.34\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-classic's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.34\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-06-01 Release of logback version 1.5.34\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In case certain StackTraceElement values returned by the Throwable.getStackTrace method are null, StackTraceElementProxy substitutes a dummy instance instead of throwing an IllegalArgumentException. This resolves [issues \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003e#1040\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003eqos-ch/logback#1040\u003c/a\u003e), reported by Naotsugu Kobayashi.\u003c/p\u003e\n\u003cp\u003e• HardenedObjectInputStream will now throw an InvalidClassException during deserialization attempts of Proxy classes. This change addresses potential deserialization whitelist bypass vulnerability reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-10532\"\u003eCVE-2026-10532\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bitwise identical binary of this version can be reproduced by building from source code at commit e62272ac152469aec1ede056c3c7d0d7314e7bfe associated with the tag v_1.5.34. This release was built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e62272ac152469aec1ede056c3c7d0d7314e7bfe\"\u003e\u003ccode\u003ee62272a\u003c/code\u003e\u003c/a\u003e prepare release 1.5.34\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/1e9e926db1529b729a0e2d29fdee151c2aea0341\"\u003e\u003ccode\u003e1e9e926\u003c/code\u003e\u003c/a\u003e add resolveProxyClassRejectsDynamicProxies unit test\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/2de5cbe90b74fa284685304bc91321313b0d8e2f\"\u003e\u003ccode\u003e2de5cbe\u003c/code\u003e\u003c/a\u003e added StackTraceElementProxyTest, minor edits to AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/0e9b9278b5d3f0b573762cd7b5482ed65244418e\"\u003e\u003ccode\u003e0e9b927\u003c/code\u003e\u003c/a\u003e in case StackTraceElement is null use a substitute, fixing issues/1040\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/f7a0654c2b7e8e1c461e3d9e483e82ef969b5818\"\u003e\u003ccode\u003ef7a0654\u003c/code\u003e\u003c/a\u003e prevent resolveProxyClass bypass\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/249b81f3754f1fb58f8507f244a36c7a940854c0\"\u003e\u003ccode\u003e249b81f\u003c/code\u003e\u003c/a\u003e docs are no longer distributed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/1c3b26a839f05b6bc1769e5a028ef326c711cec8\"\u003e\u003ccode\u003e1c3b26a\u003c/code\u003e\u003c/a\u003e start work on 1.5.34-SNAPSHOT\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.34\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/eclipse-ee4j/eclipselink/pull/2763","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/eclipse-ee4j%2Feclipselink/issues/2763","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2763/packages"},{"uuid":"4556533413","node_id":"PR_kwDOP2l8iM7hCp0D","number":104,"state":"open","title":"chore(deps): bump the maven-minor-patch group across 1 directory with 9 updates","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-05-31T04:13:17.000Z","updated_at":"2026-05-31T04:13:29.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"maven-minor-patch","update_count":9,"packages":[{"name":"ch.qos.logback:logback-classic","old_version":"1.5.32","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"},{"name":"ch.qos.logback:logback-core","old_version":"1.5.32","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"},{"name":"org.flywaydb:flyway-core","old_version":"12.4.0","new_version":"12.7.0"},{"name":"com.auth0:java-jwt","old_version":"4.5.1","new_version":"4.5.2","repository_url":"https://github.com/auth0/java-jwt"},{"name":"com.fasterxml.jackson.core:jackson-core","old_version":"2.21.2","new_version":"2.21.4","repository_url":"https://github.com/FasterXML/jackson-core"},{"name":"org.flywaydb:flyway-maven-plugin","old_version":"12.4.0","new_version":"12.7.0"},{"name":"org.apache.maven.plugins:maven-surefire-plugin","old_version":"3.5.5","new_version":"3.5.6","repository_url":"https://github.com/apache/maven-surefire"},{"name":"org.apache.maven.plugins:maven-failsafe-plugin","old_version":"3.5.5","new_version":"3.5.6","repository_url":"https://github.com/apache/maven-surefire"},{"name":"org.sonarsource.scanner.maven:sonar-maven-plugin","old_version":"5.6.0.6792","new_version":"5.7.0.6970","repository_url":"https://github.com/SonarSource/sonar-scanner-maven"}],"path":null,"ecosystem":"maven"},"body":"Bumps the maven-minor-patch group with 9 updates in the /backend directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) | `1.5.32` | `1.5.33` |\n| [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) | `1.5.32` | `1.5.33` |\n| org.flywaydb:flyway-core | `12.4.0` | `12.7.0` |\n| [com.auth0:java-jwt](https://github.com/auth0/java-jwt) | `4.5.1` | `4.5.2` |\n| [com.fasterxml.jackson.core:jackson-core](https://github.com/FasterXML/jackson-core) | `2.21.2` | `2.21.4` |\n| org.flywaydb:flyway-maven-plugin | `12.4.0` | `12.7.0` |\n| [org.apache.maven.plugins:maven-surefire-plugin](https://github.com/apache/maven-surefire) | `3.5.5` | `3.5.6` |\n| [org.apache.maven.plugins:maven-failsafe-plugin](https://github.com/apache/maven-surefire) | `3.5.5` | `3.5.6` |\n| [org.sonarsource.scanner.maven:sonar-maven-plugin](https://github.com/SonarSource/sonar-scanner-maven) | `5.6.0.6792` | `5.7.0.6970` |\n\n\nUpdates `ch.qos.logback:logback-classic` from 1.5.32 to 1.5.33\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-classic's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ch.qos.logback:logback-core` from 1.5.32 to 1.5.33\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ch.qos.logback:logback-core` from 1.5.32 to 1.5.33\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.flywaydb:flyway-core` from 12.4.0 to 12.7.0\n\nUpdates `com.auth0:java-jwt` from 4.5.1 to 4.5.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/auth0/java-jwt/releases\"\u003ecom.auth0:java-jwt's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.5.2\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAdded\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eChore: Bump update commons-beanutils dependency \u003ca href=\"https://redirect.github.com/auth0/java-jwt/pull/761\"\u003e#761\u003c/a\u003e (\u003ca href=\"https://github.com/tanya732\"\u003etanya732\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChore: Update Readme with Java 21 \u003ca href=\"https://redirect.github.com/auth0/java-jwt/pull/760\"\u003e#760\u003c/a\u003e (\u003ca href=\"https://github.com/tanya732\"\u003etanya732\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/auth0/java-jwt/blob/master/CHANGELOG.md\"\u003ecom.auth0:java-jwt's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/auth0/java-jwt/tree/4.5.2\"\u003e4.5.2\u003c/a\u003e (2026-04-29)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/auth0/java-jwt/compare/4.5.1...4.5.2\"\u003eFull Changelog\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eAdded\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eChore: Bump update commons-beanutils dependency \u003ca href=\"https://redirect.github.com/auth0/java-jwt/pull/761\"\u003e#761\u003c/a\u003e (\u003ca href=\"https://github.com/tanya732\"\u003etanya732\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChore: Update Readme with Java 21 \u003ca href=\"https://redirect.github.com/auth0/java-jwt/pull/760\"\u003e#760\u003c/a\u003e (\u003ca href=\"https://github.com/tanya732\"\u003etanya732\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/auth0/java-jwt/commit/695fd2bea64b8466b872a9d0c2e7019fee7ac86f\"\u003e\u003ccode\u003e695fd2b\u003c/code\u003e\u003c/a\u003e Release 4.5.2 (\u003ca href=\"https://redirect.github.com/auth0/java-jwt/issues/765\"\u003e#765\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/auth0/java-jwt/commit/4ac31787e2bb264d346ddb51b54ce4893d51eb18\"\u003e\u003ccode\u003e4ac3178\u003c/code\u003e\u003c/a\u003e Release 4.5.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/auth0/java-jwt/commit/d056a79e402d6d6c667a1d5fe9233dd87240da1c\"\u003e\u003ccode\u003ed056a79\u003c/code\u003e\u003c/a\u003e Bump com.fasterxml.jackson.core:jackson-databind from 2.21.2 to 2.21.3 in /li...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/auth0/java-jwt/commit/37f195a954cce32abd4b4eb212e8b7695781c2bb\"\u003e\u003ccode\u003e37f195a\u003c/code\u003e\u003c/a\u003e Bump com.fasterxml.jackson.core:jackson-databind in /lib\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/auth0/java-jwt/commit/dba4c93e2ef37b82b45776d41f8dcbc24df8335a\"\u003e\u003ccode\u003edba4c93\u003c/code\u003e\u003c/a\u003e Chore: Bump update commons-beanutils dependency (\u003ca href=\"https://redirect.github.com/auth0/java-jwt/issues/761\"\u003e#761\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/auth0/java-jwt/commit/84d4c8f383ae7c06e0e53f5bd7d84324ad3bcad9\"\u003e\u003ccode\u003e84d4c8f\u003c/code\u003e\u003c/a\u003e Merge branch 'master' into chore/bump-commons-beanutils\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/auth0/java-jwt/commit/5c923d4981ba39c18d530ba3e155c314b6cfd4e1\"\u003e\u003ccode\u003e5c923d4\u003c/code\u003e\u003c/a\u003e Chore: Add SCA scan workflow (\u003ca href=\"https://redirect.github.com/auth0/java-jwt/issues/762\"\u003e#762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/auth0/java-jwt/commit/09a4da58242a52bd937c7ac1b2914adc8a80e73c\"\u003e\u003ccode\u003e09a4da5\u003c/code\u003e\u003c/a\u003e Merge branch 'master' into chore/add-sca-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/auth0/java-jwt/commit/ef47e64ba46e5bb39abc68ddbfcd49f61cac4ec7\"\u003e\u003ccode\u003eef47e64\u003c/code\u003e\u003c/a\u003e Chore: Add SCA scan workflow\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/auth0/java-jwt/commit/3fcfbcb3bed8a66ddb37be63bb3cfea7b873312b\"\u003e\u003ccode\u003e3fcfbcb\u003c/code\u003e\u003c/a\u003e Chore: Bump update commons-beanutils dependency\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/auth0/java-jwt/compare/4.5.1...4.5.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.core:jackson-core` from 2.21.2 to 2.21.4\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/f17a4f7a7ffe895be367ce91afc6b06632643126\"\u003e\u003ccode\u003ef17a4f7\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-core-2.21.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/c6411e17ced5463d93fc6577f7bd5a76a43fd1e5\"\u003e\u003ccode\u003ec6411e1\u003c/code\u003e\u003c/a\u003e Prep for 2.21.4 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/52633da4cc57d73d149af203b145b221af08257f\"\u003e\u003ccode\u003e52633da\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/1fa7bb9c536fa64d63e790747a4e8c1d41e77fe0\"\u003e\u003ccode\u003e1fa7bb9\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/6dea8a80278a46a26880c3a9964b848da8ce78d8\"\u003e\u003ccode\u003e6dea8a8\u003c/code\u003e\u003c/a\u003e Merge branch '2.18' into 2.19\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/ada244d0a1df6fbd318fd813fff444a2cbcf2398\"\u003e\u003ccode\u003eada244d\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/52f69d357431805db816c1f11e2403143dea49e6\"\u003e\u003ccode\u003e52f69d3\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/899d70ae7ddf5bb42db09bfe3c384b7fe4b68808\"\u003e\u003ccode\u003e899d70a\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-core-2.18.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/a006b52ed5de9ac8e94a0074e7e0c09317b5c15d\"\u003e\u003ccode\u003ea006b52\u003c/code\u003e\u003c/a\u003e Prep for 2.18.8 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/4c058160d03fcf6b66d9a270e1a1b1451c8108f3\"\u003e\u003ccode\u003e4c05816\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-core/compare/jackson-core-2.21.2...jackson-core-2.21.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.flywaydb:flyway-maven-plugin` from 12.4.0 to 12.7.0\n\nUpdates `org.apache.maven.plugins:maven-surefire-plugin` from 3.5.5 to 3.5.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/apache/maven-surefire/releases\"\u003eorg.apache.maven.plugins:maven-surefire-plugin's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.5.6\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e🚀 New features and improvements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIntroduce reportTestTimestamp option and include timestamp for test sets and test cases (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3261\"\u003e#3261\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3302\"\u003e#3302\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIssue \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/2613\"\u003e#2613\u003c/a\u003e Debugging failsafe tests: Message 'Listening for transport dt_socket at address' is not displayed anymore when using maven.surefire.debug (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3353\"\u003e#3353\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3354\"\u003e#3354\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEnsure that the statistics filename is calculated only once. (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3326\"\u003e#3326\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3327\"\u003e#3327\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eflakes\u003c/code\u003e attribute to use in \u003ccode\u003etestsuite\u003c/code\u003e report (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3306\"\u003e#3306\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3308\"\u003e#3308\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[BACKPORT 3.5.x] \u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-2049\"\u003e[SUREFIRE-2049]\u003c/a\u003e - Fix SHUTDOWN type lost during command serialization. (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3270\"\u003e#3270\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3289\"\u003e#3289\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: null guard for context map (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3269\"\u003e#3269\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3272\"\u003e#3272\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e👻 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e3.5.x/bug/cherry pick embedded mode its (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3328\"\u003e#3328\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse surefire 3.5.5 by project itself for testing (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3324\"\u003e#3324\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFollow Oracle javadoc guidelines (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3177\"\u003e#3177\u003c/a\u003e) \u003ca href=\"https://github.com/elharo\"\u003e\u003ccode\u003e@​elharo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📦 Dependency updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump org.fusesource.jansi:jansi from 2.4.2 to 2.4.3 (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3334\"\u003e#3334\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump commons-io:commons-io from 2.21.0 to 2.22.0 (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3350\"\u003e#3350\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/25ea054860a5c1e5932b360d8aa0a31944c2b841\"\u003e\u003ccode\u003e25ea054\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release surefire-3.5.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/e5f374ccdefd5b40d75e0072a754708183d9ec5e\"\u003e\u003ccode\u003ee5f374c\u003c/code\u003e\u003c/a\u003e Bump org.fusesource.jansi:jansi from 2.4.2 to 2.4.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/dadd55b7a6a3a0336c253413f68c4f08092328c2\"\u003e\u003ccode\u003edadd55b\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/2613\"\u003e#2613\u003c/a\u003e Debugging failsafe tests: Message 'Listening for transport dt_soc...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/39dd250a44f1f2f1f18ea1881d78ac341222ea97\"\u003e\u003ccode\u003e39dd250\u003c/code\u003e\u003c/a\u003e Bump commons-io:commons-io from 2.21.0 to 2.22.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/27742739c8cc6e4676611ac4bfe42870f74fd0f3\"\u003e\u003ccode\u003e2774273\u003c/code\u003e\u003c/a\u003e Ensure that the statistics filename is calculated only once. (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3326\"\u003e#3326\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3327\"\u003e#3327\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/0d5df8a3b4606622a67922405488d4b182409893\"\u003e\u003ccode\u003e0d5df8a\u003c/code\u003e\u003c/a\u003e 3.5.x/bug/cherry pick embedded mode its (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3328\"\u003e#3328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/04ad9a293f5cee5e95c5cd5a2e751723be66deff\"\u003e\u003ccode\u003e04ad9a2\u003c/code\u003e\u003c/a\u003e Use surefire 3.5.5 by project itself for testing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/37e8f694c18ca664a8e45e934a43d4870e799c45\"\u003e\u003ccode\u003e37e8f69\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003eflakes\u003c/code\u003e attribute to use in \u003ccode\u003etestsuite\u003c/code\u003e report (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3306\"\u003e#3306\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3308\"\u003e#3308\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/a970fefe4dbc173acacf79389d812f91f6ef027a\"\u003e\u003ccode\u003ea970fef\u003c/code\u003e\u003c/a\u003e Introduce reportTestTimestamp option and include timestamp for test sets and ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/e838393bbb127a7798d13283b9af7cfa0afec3a8\"\u003e\u003ccode\u003ee838393\u003c/code\u003e\u003c/a\u003e deploy 3.5.x branch to nexus\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/apache/maven-surefire/compare/surefire-3.5.5...surefire-3.5.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.maven.plugins:maven-failsafe-plugin` from 3.5.5 to 3.5.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/apache/maven-surefire/releases\"\u003eorg.apache.maven.plugins:maven-failsafe-plugin's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.5.6\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e🚀 New features and improvements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIntroduce reportTestTimestamp option and include timestamp for test sets and test cases (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3261\"\u003e#3261\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3302\"\u003e#3302\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIssue \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/2613\"\u003e#2613\u003c/a\u003e Debugging failsafe tests: Message 'Listening for transport dt_socket at address' is not displayed anymore when using maven.surefire.debug (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3353\"\u003e#3353\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3354\"\u003e#3354\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEnsure that the statistics filename is calculated only once. (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3326\"\u003e#3326\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3327\"\u003e#3327\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eflakes\u003c/code\u003e attribute to use in \u003ccode\u003etestsuite\u003c/code\u003e report (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3306\"\u003e#3306\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3308\"\u003e#3308\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[BACKPORT 3.5.x] \u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-2049\"\u003e[SUREFIRE-2049]\u003c/a\u003e - Fix SHUTDOWN type lost during command serialization. (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3270\"\u003e#3270\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3289\"\u003e#3289\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: null guard for context map (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3269\"\u003e#3269\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3272\"\u003e#3272\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e👻 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e3.5.x/bug/cherry pick embedded mode its (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3328\"\u003e#3328\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse surefire 3.5.5 by project itself for testing (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3324\"\u003e#3324\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFollow Oracle javadoc guidelines (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3177\"\u003e#3177\u003c/a\u003e) \u003ca href=\"https://github.com/elharo\"\u003e\u003ccode\u003e@​elharo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📦 Dependency updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump org.fusesource.jansi:jansi from 2.4.2 to 2.4.3 (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3334\"\u003e#3334\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump commons-io:commons-io from 2.21.0 to 2.22.0 (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3350\"\u003e#3350\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/25ea054860a5c1e5932b360d8aa0a31944c2b841\"\u003e\u003ccode\u003e25ea054\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release surefire-3.5.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/e5f374ccdefd5b40d75e0072a754708183d9ec5e\"\u003e\u003ccode\u003ee5f374c\u003c/code\u003e\u003c/a\u003e Bump org.fusesource.jansi:jansi from 2.4.2 to 2.4.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/dadd55b7a6a3a0336c253413f68c4f08092328c2\"\u003e\u003ccode\u003edadd55b\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/2613\"\u003e#2613\u003c/a\u003e Debugging failsafe tests: Message 'Listening for transport dt_soc...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/39dd250a44f1f2f1f18ea1881d78ac341222ea97\"\u003e\u003ccode\u003e39dd250\u003c/code\u003e\u003c/a\u003e Bump commons-io:commons-io from 2.21.0 to 2.22.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/27742739c8cc6e4676611ac4bfe42870f74fd0f3\"\u003e\u003ccode\u003e2774273\u003c/code\u003e\u003c/a\u003e Ensure that the statistics filename is calculated only once. (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3326\"\u003e#3326\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3327\"\u003e#3327\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/0d5df8a3b4606622a67922405488d4b182409893\"\u003e\u003ccode\u003e0d5df8a\u003c/code\u003e\u003c/a\u003e 3.5.x/bug/cherry pick embedded mode its (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3328\"\u003e#3328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/04ad9a293f5cee5e95c5cd5a2e751723be66deff\"\u003e\u003ccode\u003e04ad9a2\u003c/code\u003e\u003c/a\u003e Use surefire 3.5.5 by project itself for testing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/37e8f694c18ca664a8e45e934a43d4870e799c45\"\u003e\u003ccode\u003e37e8f69\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003eflakes\u003c/code\u003e attribute to use in \u003ccode\u003etestsuite\u003c/code\u003e report (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3306\"\u003e#3306\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3308\"\u003e#3308\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/a970fefe4dbc173acacf79389d812f91f6ef027a\"\u003e\u003ccode\u003ea970fef\u003c/code\u003e\u003c/a\u003e Introduce reportTestTimestamp option and include timestamp for test sets and ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/e838393bbb127a7798d13283b9af7cfa0afec3a8\"\u003e\u003ccode\u003ee838393\u003c/code\u003e\u003c/a\u003e deploy 3.5.x branch to nexus\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/apache/maven-surefire/compare/surefire-3.5.5...surefire-3.5.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.sonarsource.scanner.maven:sonar-maven-plugin` from 5.6.0.6792 to 5.7.0.6970\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SonarSource/sonar-scanner-maven/releases\"\u003eorg.sonarsource.scanner.maven:sonar-maven-plugin's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e5.7.0.6970\u003c/h2\u003e\n\u003ch1\u003eRelease notes - Sonar Scanner for Maven - 5.7\u003c/h1\u003e\n\u003ch3\u003eFeature\u003c/h3\u003e\n\u003cp\u003e\u003ca href=\"https://sonarsource.atlassian.net/browse/SCANMAVEN-317\"\u003eSCANMAVEN-317\u003c/a\u003e Support encryption of sonar.token, and other new secure properties\n\u003ca href=\"https://sonarsource.atlassian.net/browse/SCANMAVEN-332\"\u003eSCANMAVEN-332\u003c/a\u003e support \u003ccode\u003emodular-jar\u003c/code\u003e artifact type\n\u003ca href=\"https://sonarsource.atlassian.net/browse/SCANMAVEN-341\"\u003eSCANMAVEN-341\u003c/a\u003e Rework the support of encrypted properties\u003c/p\u003e\n\u003ch3\u003eMaintenance\u003c/h3\u003e\n\u003cp\u003e\u003ca href=\"https://sonarsource.atlassian.net/browse/SCANMAVEN-370\"\u003eSCANMAVEN-370\u003c/a\u003e Prepare next development iteration 5.7.0\n\u003ca href=\"https://sonarsource.atlassian.net/browse/SCANMAVEN-372\"\u003eSCANMAVEN-372\u003c/a\u003e Configure Renovate for sonar-scanner-maven\n\u003ca href=\"https://sonarsource.atlassian.net/browse/SCANMAVEN-373\"\u003eSCANMAVEN-373\u003c/a\u003e SubmitReview: Use Vault token\n\u003ca href=\"https://sonarsource.atlassian.net/browse/SCANMAVEN-374\"\u003eSCANMAVEN-374\u003c/a\u003e Unpin internal GitHub actions\n\u003ca href=\"https://sonarsource.atlassian.net/browse/SCANMAVEN-376\"\u003eSCANMAVEN-376\u003c/a\u003e Use SonarSource/.../sonar-update-center-release@v1 instead of \u003ca href=\"https://github.com/master\"\u003e\u003ccode\u003e@​master\u003c/code\u003e\u003c/a\u003e\n\u003ca href=\"https://sonarsource.atlassian.net/browse/SCANMAVEN-377\"\u003eSCANMAVEN-377\u003c/a\u003e Update dependency org.assertj:assertj-core to v3.27.7 [SECURITY]\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SonarSource/sonar-scanner-maven/commit/9e114d74155442c40a927a7491718dde472b43fc\"\u003e\u003ccode\u003e9e114d7\u003c/code\u003e\u003c/a\u003e SCANMAVEN-332 Support modular-jar (\u003ca href=\"https://redirect.github.com/SonarSource/sonar-scanner-maven/issues/402\"\u003e#402\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SonarSource/sonar-scanner-maven/commit/7424fe56eeaabf1d9abd4d43bec6eff694c18c55\"\u003e\u003ccode\u003e7424fe5\u003c/code\u003e\u003c/a\u003e SCANMAVEN-317 - Support encryption of sonar.token, and other new secure prope...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SonarSource/sonar-scanner-maven/commit/b8ff39f9c72f56cac1e302ac8ec9854b5a8f25cd\"\u003e\u003ccode\u003eb8ff39f\u003c/code\u003e\u003c/a\u003e SCANMAVEN-341 Fix regex for encrypted property filtering for mvn4 and add tes...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SonarSource/sonar-scanner-maven/commit/b4c0b4ae8638e87874786fdf055e8ac904eadeab\"\u003e\u003ccode\u003eb4c0b4a\u003c/code\u003e\u003c/a\u003e SCANMAVEN-377 Update dependency org.assertj:assertj-core to v3.27.7 [SECURITY...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SonarSource/sonar-scanner-maven/commit/cd195065d088e8fade81b59c3c78068dc393a291\"\u003e\u003ccode\u003ecd19506\u003c/code\u003e\u003c/a\u003e SCANMAVEN-372 Configure Renovate (\u003ca href=\"https://redirect.github.com/SonarSource/sonar-scanner-maven/issues/393\"\u003e#393\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SonarSource/sonar-scanner-maven/commit/944f55249fb64c3fa7bf2258974ca281375af257\"\u003e\u003ccode\u003e944f552\u003c/code\u003e\u003c/a\u003e SCANMAVEN-376 Use SonarSource/.../sonar-update-center-release@v1 instead of @...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SonarSource/sonar-scanner-maven/commit/2832b8a069e8e9ac83ece6b0111f723f653dbda2\"\u003e\u003ccode\u003e2832b8a\u003c/code\u003e\u003c/a\u003e SCANMAVEN-374 Unpin internal GitHub actions (\u003ca href=\"https://redirect.github.com/SonarSource/sonar-scanner-maven/issues/396\"\u003e#396\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SonarSource/sonar-scanner-maven/commit/81caeeb11b25dd0ca8aafc0aefc46390350d3e9e\"\u003e\u003ccode\u003e81caeeb\u003c/code\u003e\u003c/a\u003e SCANMAVEN-373 SubmitReview: Use Vault token (\u003ca href=\"https://redirect.github.com/SonarSource/sonar-scanner-maven/issues/395\"\u003e#395\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SonarSource/sonar-scanner-maven/commit/c62dd7423fb4b2b7dffe457849e51c38dcc779cc\"\u003e\u003ccode\u003ec62dd74\u003c/code\u003e\u003c/a\u003e SCANMAVEN-370 Prepare next development iteration 5.7.0 (\u003ca href=\"https://redirect.github.com/SonarSource/sonar-scanner-maven/issues/392\"\u003e#392\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/SonarSource/sonar-scanner-maven/compare/5.6.0.6792...5.7.0.6970\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/Pololac/PowerMe/pull/104","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Pololac%2FPowerMe/issues/104","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/104/packages"},{"uuid":"4552613454","node_id":"PR_kwDOAB81F87g2zOl","number":15211,"state":"closed","title":"[12.1.x EE11] Bump the dev-dependencies group across 1 directory with 14 updates","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-06-06T00:11:37.000Z","author_association":null,"state_reason":null,"created_at":"2026-05-30T01:03:05.000Z","updated_at":"2026-06-06T00:11:39.000Z","time_to_close":601712,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"[12.1.x EE11] Bump","group_name":"dev-dependencies","update_count":14,"packages":[{"name":"org.ow2.asm:asm","old_version":"9.10","new_version":"9.10.1"},{"name":"org.ow2.asm:asm-commons","old_version":"9.10","new_version":"9.10.1"},{"name":"org.ow2.asm:asm-bom","old_version":"9.10","new_version":"9.10.1"},{"name":"org.apache.maven.surefire:surefire-junit47","old_version":"3.5.5","new_version":"3.5.6"},{"name":"com.fasterxml.jackson:jackson-bom","old_version":"2.21.3","new_version":"2.21.4","repository_url":"https://github.com/FasterXML/jackson-bom"},{"name":"io.netty:netty-bom","old_version":"4.2.13.Final","new_version":"4.2.14.Final","repository_url":"https://github.com/netty/netty"},{"name":"org.hibernate.search:hibernate-search-bom","old_version":"8.3.1.Final","new_version":"8.4.0.Final","repository_url":"https://github.com/hibernate/hibernate-search"},{"name":"org.junit:junit-bom","old_version":"6.0.3","new_version":"6.1.0","repository_url":"https://github.com/junit-team/junit-framework"},{"name":"ch.qos.logback:logback-core","old_version":"1.5.32","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"},{"name":"org.codehaus.plexus:plexus-classworlds","old_version":"2.11.0","new_version":"2.12.0","repository_url":"https://github.com/codehaus-plexus/plexus-classworlds"},{"name":"eu.maveniverse.maven.njord:extension3","old_version":"0.9.6","new_version":"0.9.7","repository_url":"https://github.com/maveniverse/njord"},{"name":"eu.maveniverse.maven.plugins:njord","old_version":"0.9.6","new_version":"0.9.7","repository_url":"https://github.com/maveniverse/njord"},{"name":"org.apache.maven.extensions:maven-build-cache-extension","old_version":"1.2.2","new_version":"1.2.3","repository_url":"https://github.com/apache/maven-build-cache-extension"}],"path":null,"ecosystem":"maven"},"body":"Bumps the dev-dependencies group with 13 updates in the /jetty-ee11 directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| org.ow2.asm:asm | `9.10` | `9.10.1` |\n| org.ow2.asm:asm-commons | `9.10` | `9.10.1` |\n| org.ow2.asm:asm-bom | `9.10` | `9.10.1` |\n| org.apache.maven.surefire:surefire-junit47 | `3.5.5` | `3.5.6` |\n| [com.fasterxml.jackson:jackson-bom](https://github.com/FasterXML/jackson-bom) | `2.21.3` | `2.21.4` |\n| [io.netty:netty-bom](https://github.com/netty/netty) | `4.2.13.Final` | `4.2.14.Final` |\n| [org.hibernate.search:hibernate-search-bom](https://github.com/hibernate/hibernate-search) | `8.3.1.Final` | `8.4.0.Final` |\n| [org.junit:junit-bom](https://github.com/junit-team/junit-framework) | `6.0.3` | `6.1.0` |\n| [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) | `1.5.32` | `1.5.33` |\n| [org.codehaus.plexus:plexus-classworlds](https://github.com/codehaus-plexus/plexus-classworlds) | `2.11.0` | `2.12.0` |\n| [eu.maveniverse.maven.njord:extension3](https://github.com/maveniverse/njord) | `0.9.6` | `0.9.7` |\n| [eu.maveniverse.maven.plugins:njord](https://github.com/maveniverse/njord) | `0.9.6` | `0.9.7` |\n| [org.apache.maven.extensions:maven-build-cache-extension](https://github.com/apache/maven-build-cache-extension) | `1.2.2` | `1.2.3` |\n\n\nUpdates `org.ow2.asm:asm` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-commons` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-bom` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-commons` from 9.10 to 9.10.1\n\nUpdates `org.apache.maven.surefire:surefire-junit47` from 3.5.5 to 3.5.6\n\nUpdates `com.fasterxml.jackson:jackson-bom` from 2.21.3 to 2.21.4\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-bom/commit/d1abd31e4fec3035965d57a05a6256171ea8d980\"\u003e\u003ccode\u003ed1abd31\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-bom-2.21.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-bom/commit/2aaea43db8480aa7d405ebc0de503cffc864f6f6\"\u003e\u003ccode\u003e2aaea43\u003c/code\u003e\u003c/a\u003e Prep for 2.21.4 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-bom/commit/9d3a9d54e40312ef0ac9192d599b59b541f65fb8\"\u003e\u003ccode\u003e9d3a9d5\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-bom/commit/84bcf7f5b268bc2b47a92bd08391f75e9d956793\"\u003e\u003ccode\u003e84bcf7f\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/FasterXML/jackson-bom/compare/jackson-bom-2.21.3...jackson-bom-2.21.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `io.netty:netty-bom` from 4.2.13.Final to 4.2.14.Final\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/netty/netty/releases\"\u003eio.netty:netty-bom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003enetty-4.2.14.Final\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHTTP: Fix revapi failure introduced by 84530fa81e12dcd1d42310bb20c1385cb44128d8 by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16748\"\u003enetty/netty#16748\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHTTP: Re-add constructor to HttpProxyHandler that was removed by mistake by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16747\"\u003enetty/netty#16747\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMarshalling: Explicit document security requirements by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16752\"\u003enetty/netty#16752\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix io_uring op completion TRACE logging by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16755\"\u003enetty/netty#16755\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eQuic: Ensure writes are done before notify close promise of QuicheQui… by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16758\"\u003enetty/netty#16758\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid re-parsing openssl key material with non-cached provider by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16759\"\u003enetty/netty#16759\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin HTTP/RTSP version + method normalization to Locale.US by \u003ca href=\"https://github.com/daguimu\"\u003e\u003ccode\u003e@​daguimu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16765\"\u003enetty/netty#16765\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFill MsgHdrMemoryArray#hdrs with null entry on release by \u003ca href=\"https://github.com/tsegismont\"\u003e\u003ccode\u003e@​tsegismont\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16764\"\u003enetty/netty#16764\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRevapi: Use default \u0026quot;oldVersion\u0026quot; by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16774\"\u003enetty/netty#16774\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdaptive: Fix concurrency issue in adaptive allocator by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16767\"\u003enetty/netty#16767\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAuto-port 4.2: Make bulk byte moving in ByteBuf faster by \u003ca href=\"https://github.com/netty-project-bot\"\u003e\u003ccode\u003e@​netty-project-bot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16781\"\u003enetty/netty#16781\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin multipart Content-Type / Content-Transfer-Encoding case folding to Locale.US by \u003ca href=\"https://github.com/daguimu\"\u003e\u003ccode\u003e@​daguimu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16768\"\u003enetty/netty#16768\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove dead native declarations by \u003ca href=\"https://github.com/pandareen\"\u003e\u003ccode\u003e@​pandareen\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16783\"\u003enetty/netty#16783\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIsolate tests that modify available Security providers by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16793\"\u003enetty/netty#16793\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove test annotations from a method that isn't a test by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16792\"\u003enetty/netty#16792\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEnable OpenSslCachingKeyMaterialProvider to evict stale entries after cert rotation by \u003ca href=\"https://github.com/zhangweikop\"\u003e\u003ccode\u003e@​zhangweikop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16523\"\u003enetty/netty#16523\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIoUring: extend user data from short to long by \u003ca href=\"https://github.com/dreamlike-ocean\"\u003e\u003ccode\u003e@​dreamlike-ocean\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16682\"\u003enetty/netty#16682\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRevert CompositeByteBuf component search fast path by \u003ca href=\"https://github.com/yawkat\"\u003e\u003ccode\u003e@​yawkat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16811\"\u003enetty/netty#16811\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHTTP2: Use 100 as default max concurrent streams setting by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16804\"\u003enetty/netty#16804\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix ResumptionController wrapping by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16815\"\u003enetty/netty#16815\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eResolve all localhost addresses without querying DNS servers by \u003ca href=\"https://github.com/JulianVennen\"\u003e\u003ccode\u003e@​JulianVennen\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16749\"\u003enetty/netty#16749\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIpFilter: Fix ClassCastException caused by IpSubnetFilter if only ipv6 rules are configured but remote peer is using ipv4 by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16803\"\u003enetty/netty#16803\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix memoryAddress() for direct ByteBuffers wrapped by Unpooled without Unsafe by \u003ca href=\"https://github.com/dreamlike-ocean\"\u003e\u003ccode\u003e@​dreamlike-ocean\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16788\"\u003enetty/netty#16788\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRoute synchronous onLookupComplete exceptions via fireExceptionCaught by \u003ca href=\"https://github.com/kwondh5217\"\u003e\u003ccode\u003e@​kwondh5217\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16794\"\u003enetty/netty#16794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIoUring: Stop generic FileRegion drain loop when transferred() reaches count() by \u003ca href=\"https://github.com/LuciferYang\"\u003e\u003ccode\u003e@​LuciferYang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16826\"\u003enetty/netty#16826\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMQTT: Allow MQTT 5 CONNECT with password only by \u003ca href=\"https://github.com/shblue21\"\u003e\u003ccode\u003e@​shblue21\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16833\"\u003enetty/netty#16833\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix MQTT decoder size check after variable header replay by \u003ca href=\"https://github.com/daguimu\"\u003e\u003ccode\u003e@​daguimu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16787\"\u003enetty/netty#16787\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pandareen\"\u003e\u003ccode\u003e@​pandareen\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16783\"\u003enetty/netty#16783\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zhangweikop\"\u003e\u003ccode\u003e@​zhangweikop\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16523\"\u003enetty/netty#16523\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JulianVennen\"\u003e\u003ccode\u003e@​JulianVennen\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16749\"\u003enetty/netty#16749\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kwondh5217\"\u003e\u003ccode\u003e@​kwondh5217\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16794\"\u003enetty/netty#16794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/shblue21\"\u003e\u003ccode\u003e@​shblue21\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16833\"\u003enetty/netty#16833\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/netty/netty/compare/netty-4.2.13.Final...netty-4.2.14.Final\"\u003ehttps://github.com/netty/netty/compare/netty-4.2.13.Final...netty-4.2.14.Final\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/0a60b753d5b0de9f58e245538d61c11dc6cfc4b2\"\u003e\u003ccode\u003e0a60b75\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release netty-4.2.14.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/72df658e5fdd1cc6d65bce1e0917ec31a9560269\"\u003e\u003ccode\u003e72df658\u003c/code\u003e\u003c/a\u003e Fix MQTT decoder size check after variable header replay (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16787\"\u003e#16787\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/7125dba6b20822aa72dd8359b350c2f3b9a545d9\"\u003e\u003ccode\u003e7125dba\u003c/code\u003e\u003c/a\u003e MQTT: Allow MQTT 5 CONNECT with password only (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16833\"\u003e#16833\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/9e19320a5855746970d05a5cd785d73a17cc694d\"\u003e\u003ccode\u003e9e19320\u003c/code\u003e\u003c/a\u003e IoUring: Stop generic FileRegion drain loop when transferred() reaches count(...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/4ce9f17f05c67b72c87bc83951800bad245fe162\"\u003e\u003ccode\u003e4ce9f17\u003c/code\u003e\u003c/a\u003e Route synchronous onLookupComplete exceptions via fireExceptionCaught (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16794\"\u003e#16794\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/f7b1b7de625031cc60e6eaecb889c97303588759\"\u003e\u003ccode\u003ef7b1b7d\u003c/code\u003e\u003c/a\u003e Fix memoryAddress() for direct ByteBuffers wrapped by Unpooled without Unsafe...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/0ccb265cadf91b2e09c2f479c9194d193d7a5dbc\"\u003e\u003ccode\u003e0ccb265\u003c/code\u003e\u003c/a\u003e IpFilter: Fix ClassCastException caused by IpSubnetFilter if only ipv6 rules ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/a6aeb6deffda3e45904edd05abc5cdddcd438794\"\u003e\u003ccode\u003ea6aeb6d\u003c/code\u003e\u003c/a\u003e Resolve all localhost addresses without querying DNS servers (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16749\"\u003e#16749\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/c328ba2ab89d2c90c80be1d2de1cfbb8f94c438b\"\u003e\u003ccode\u003ec328ba2\u003c/code\u003e\u003c/a\u003e Fix ResumptionController wrapping (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16815\"\u003e#16815\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/bc5862ba488c569c888d3b82048083041f66e880\"\u003e\u003ccode\u003ebc5862b\u003c/code\u003e\u003c/a\u003e HTTP2: Use 100 as default max concurrent streams setting (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16804\"\u003e#16804\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/netty/netty/compare/netty-4.2.13.Final...netty-4.2.14.Final\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.hibernate.search:hibernate-search-bom` from 8.3.1.Final to 8.4.0.Final\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hibernate/hibernate-search/releases\"\u003eorg.hibernate.search:hibernate-search-bom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 8.4.0.Final\u003c/h2\u003e\n\u003ch1\u003eHibernate Search 8.4.0.Final released\u003c/h1\u003e\n\u003cp\u003eWe are pleased to announce the release of Hibernate Search 8.4: 8.4.0.Final.\u003c/p\u003e\n\u003cp\u003eYou can find the full list of 8.4.0.Final changes \u003ca href=\"https://hibernate.atlassian.net/issues/?jql=project%20%3D%20HSEARCH%20AND%20fixVersion%20%3D%208.4.0.Final\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eWhat's new\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSee the \u003ca href=\"https://hibernate.org/search/releases/8.4\"\u003ewebsite\u003c/a\u003e for requirements and compatibilities.\u003c/li\u003e\n\u003cli\u003eSee the \u003ca href=\"https://docs.hibernate.org/search/8.4/whats-new/en-US/html_single/\"\u003eWhat's New\u003c/a\u003e guide for details about new features and capabilities.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eConclusion\u003c/h2\u003e\n\u003cp\u003eFor additional details, see:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe \u003ca href=\"https://hibernate.org/search/releases/8.4/\"\u003erelease page\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/migration/html_single/\"\u003eMigration Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/getting-started/orm/en-US/html_single/\"\u003eORM Getting Started Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/getting-started/standalone/en-US/html_single/\"\u003eStandalone Getting Started Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/reference/en-US/html_single/\"\u003eReference Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/api\"\u003eAPI docs\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eVisit the \u003ca href=\"https://hibernate.org/community/\"\u003ewebsite\u003c/a\u003e for details on getting in touch with us.\u003c/p\u003e\n\u003ch2\u003eRelease 8.4.0.CR1\u003c/h2\u003e\n\u003ch1\u003eHibernate Search 8.4.0.CR1 released\u003c/h1\u003e\n\u003cp\u003eWe are pleased to announce the release of Hibernate Search 8.4: 8.4.0.CR1.\u003c/p\u003e\n\u003cp\u003eYou can find the full list of 8.4.0.CR1 changes \u003ca href=\"https://hibernate.atlassian.net/issues/?jql=project%20%3D%20HSEARCH%20AND%20fixVersion%20%3D%208.4.0.CR1\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eWhat's new\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSee the \u003ca href=\"https://hibernate.org/search/releases/8.4\"\u003ewebsite\u003c/a\u003e for requirements and compatibilities.\u003c/li\u003e\n\u003cli\u003eSee the \u003ca href=\"https://docs.hibernate.org/search/8.4/whats-new/en-US/html_single/\"\u003eWhat's New\u003c/a\u003e guide for details about new features and capabilities.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eConclusion\u003c/h2\u003e\n\u003cp\u003eFor additional details, see:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe \u003ca href=\"https://hibernate.org/search/releases/8.4/\"\u003erelease page\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/migration/html_single/\"\u003eMigration Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/getting-started/orm/en-US/html_single/\"\u003eORM Getting Started Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/getting-started/standalone/en-US/html_single/\"\u003eStandalone Getting Started Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/reference/en-US/html_single/\"\u003eReference Guide\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hibernate/hibernate-search/blob/main/changelog.txt\"\u003eorg.hibernate.search:hibernate-search-bom's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.4.0.Final (2026-05-27)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://hibernate.atlassian.net/projects/HSEARCH/versions/39072\"\u003ehttps://hibernate.atlassian.net/projects/HSEARCH/versions/39072\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e** Improvement\n* HSEARCH-5630 Update to Hibernate ORM 7.4.0.Final\n* HSEARCH-5629 Use Maven 3.9.16 as a required minimum version for the build\n* HSEARCH-5627 Switch from the Search session holder to a Hibernate ORM session extension\n* HSEARCH-5626 Update Elasticsearch client (elasticsearch-rest-client) to 9.4.1\n* HSEARCH-5625 Test against latest Elasticsearch 9.4.1\n* HSEARCH-5624 Update Elasticsearch client (elasticsearch-rest5-client) to 9.4.1\u003c/p\u003e\n\u003ch2\u003e8.4.0.CR1 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://hibernate.atlassian.net/projects/HSEARCH/versions/37437\"\u003ehttps://hibernate.atlassian.net/projects/HSEARCH/versions/37437\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e** Bug\n* HSEARCH-5595 \u003ccode\u003echeckstyle:check\u003c/code\u003e is not build cache relocatable due to project resources including the workspace root\u003c/p\u003e\n\u003cp\u003e** Improvement\n* HSEARCH-5623 Update to Hibernate ORM 7.4.0.CR1\n* HSEARCH-5622 Update Elasticsearch client (elasticsearch-rest5-client) to 9.4.0\n* HSEARCH-5621 Update Elasticsearch client (elasticsearch-rest-client) to 9.4.0\n* HSEARCH-5620 Add compatibility with Elasticsearch 9.4\n* HSEARCH-5619 Upgrade to GSON 2.14.0\n* HSEARCH-5618 Update Jackson to 2.21.3\n* HSEARCH-5617 Update to AWS SDK 2.44.1\n* HSEARCH-5616 Update Elasticsearch client (elasticsearch-rest-client) to 9.3.4\n* HSEARCH-5613 Use Maven 3.9.15 as a required minimum version for the build\n* HSEARCH-5612 Upgrade to commons-codec 1.22.0\n* HSEARCH-5611 Update Apache HTTP Client components to 5.6.1\n* HSEARCH-5609 Update Elasticsearch client (elasticsearch-rest-client) to 9.3.3\n* HSEARCH-5608 Update Elasticsearch client (elasticsearch-rest5-client) to 9.3.4\n* HSEARCH-5607 Update Elasticsearch rest client (opensearch-rest-client) to 3.6.0\n* HSEARCH-5606 Add compatibility with OpenSearch 3.6\n* HSEARCH-5601 Update to commons-logging to 1.3.6\n* HSEARCH-5600 Update Jackson to 2.21.2\n* HSEARCH-5599 Update Apache HTTP Core client components to 5.4.2\n* HSEARCH-5598 Update Elasticsearch client (elasticsearch-rest-client) to 9.3.2\n* HSEARCH-5597 Update Elasticsearch client (elasticsearch-rest5-client) to 9.3.3\u003c/p\u003e\n\u003cp\u003e** Task\n* HSEARCH-5596 Use changeDetection config option instead of the deprecated overwrite in maven-resources-plugin\n* HSEARCH-5280 Look into \u003ccode\u003eOutboxPollingAutomaticIndexingDynamicShardingRebalancingIT#agentJoined\u003c/code\u003e test\n* HSEARCH-5242 Investigate why building hibernate-search-integrationtest-performance-backend-lucene fails on some envs\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/7369a18fc526aaffba13336fdcdc95a333702b19\"\u003e\u003ccode\u003e7369a18\u003c/code\u003e\u003c/a\u003e [Jenkins release job] Preparing release 8.4.0.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/4e26c085ba83c21cde89022a2f10864b08711e25\"\u003e\u003ccode\u003e4e26c08\u003c/code\u003e\u003c/a\u003e [Jenkins release job] changelog.txt updated by release build 8.4.0.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/fe410d2d5c25d9e05648f67c027441564a32be03\"\u003e\u003ccode\u003efe410d2\u003c/code\u003e\u003c/a\u003e HSEARCH-5630 Add a few migration notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/87335b65fd124493bf91ad83de78f64eafc1155c\"\u003e\u003ccode\u003e87335b6\u003c/code\u003e\u003c/a\u003e HSEARCH-5630 Update to Hibernate ORM 7.4.0.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/58d6af143d22c9ce55872c9f13c51c8dd8e03d32\"\u003e\u003ccode\u003e58d6af1\u003c/code\u003e\u003c/a\u003e HSEARCH-5624 Update Elasticsearch client (elasticsearch-rest5-client) to 9.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/9efe369fcb419ded47b3e77a02b3d84451e64853\"\u003e\u003ccode\u003e9efe369\u003c/code\u003e\u003c/a\u003e Bump the build-dependencies group with 4 updates\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/bc1c18509b22d2b1fa9e41149fbe5cf166d7f663\"\u003e\u003ccode\u003ebc1c185\u003c/code\u003e\u003c/a\u003e Use the ssh URL for updating the website during the release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/311adb00224ab04fc2c397da94cf41a373338801\"\u003e\u003ccode\u003e311adb0\u003c/code\u003e\u003c/a\u003e HSEARCH-5627 Mention limitations of a StatelessSession\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/d429b05110cf6015d70faa6278176c6b3e7defa0\"\u003e\u003ccode\u003ed429b05\u003c/code\u003e\u003c/a\u003e HSEARCH-5627 Better error message for \u0026quot;incompatible\u0026quot; session types\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/2eaeb282d9d9bc136bc32f93ca12634374e249d4\"\u003e\u003ccode\u003e2eaeb28\u003c/code\u003e\u003c/a\u003e HSEARCH-5627 Add a simple StatelessSession test\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hibernate/hibernate-search/compare/8.3.1.Final...8.4.0.Final\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.junit:junit-bom` from 6.0.3 to 6.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/junit-team/junit-framework/releases\"\u003eorg.junit:junit-bom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eJUnit 6.1.0 = Platform 6.1.0 + Jupiter 6.1.0 + Vintage 6.1.0\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0/release-notes.html\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JarvisCraft\"\u003e\u003ccode\u003e@​JarvisCraft\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5633\"\u003ejunit-team/junit-framework#5633\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Maran23\"\u003e\u003ccode\u003e@​Maran23\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5644\"\u003ejunit-team/junit-framework#5644\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eJUnit 6.1.0-RC1 = Platform 6.1.0-RC1 + Jupiter 6.1.0-RC1 + Vintage 6.1.0-RC1\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0-RC1/release-notes/\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mariokhoury4\"\u003e\u003ccode\u003e@​mariokhoury4\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/4574\"\u003ejunit-team/junit-framework#4574\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Ogu1208\"\u003e\u003ccode\u003e@​Ogu1208\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5145\"\u003ejunit-team/junit-framework#5145\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/HyungGeun94\"\u003e\u003ccode\u003e@​HyungGeun94\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5271\"\u003ejunit-team/junit-framework#5271\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yalishevant\"\u003e\u003ccode\u003e@​yalishevant\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5316\"\u003ejunit-team/junit-framework#5316\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JINU-CHANG\"\u003e\u003ccode\u003e@​JINU-CHANG\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5290\"\u003ejunit-team/junit-framework#5290\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jaschdoc\"\u003e\u003ccode\u003e@​jaschdoc\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5427\"\u003ejunit-team/junit-framework#5427\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kawshikbuet17\"\u003e\u003ccode\u003e@​kawshikbuet17\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5561\"\u003ejunit-team/junit-framework#5561\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/msridhar\"\u003e\u003ccode\u003e@​msridhar\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5602\"\u003ejunit-team/junit-framework#5602\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.1.0-M1...r6.1.0-RC1\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.1.0-M1...r6.1.0-RC1\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eJUnit 6.1.0-M1 = Platform 6.1.0-M1 + Jupiter 6.1.0-M1 + Vintage 6.1.0-M1\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0-M1/release-notes/\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vy\"\u003e\u003ccode\u003e@​vy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5041\"\u003ejunit-team/junit-framework#5041\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Pankraz76\"\u003e\u003ccode\u003e@​Pankraz76\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5006\"\u003ejunit-team/junit-framework#5006\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/arukiidou\"\u003e\u003ccode\u003e@​arukiidou\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5066\"\u003ejunit-team/junit-framework#5066\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/laeubi\"\u003e\u003ccode\u003e@​laeubi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5092\"\u003ejunit-team/junit-framework#5092\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jihun4452\"\u003e\u003ccode\u003e@​jihun4452\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5088\"\u003ejunit-team/junit-framework#5088\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TWiStErRob\"\u003e\u003ccode\u003e@​TWiStErRob\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5133\"\u003ejunit-team/junit-framework#5133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.0...r6.1.0-M1\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.0.0...r6.1.0-M1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0dc3af1cb1973d257b5bc75d81e02454d5e4e556\"\u003e\u003ccode\u003e0dc3af1\u003c/code\u003e\u003c/a\u003e Release 6.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/1d130020c85170edcb46ce7ed1f7f78824e37c04\"\u003e\u003ccode\u003e1d13002\u003c/code\u003e\u003c/a\u003e Prepare 6.1.0 release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/072b2175bbd7b0b3b26f5d928550ec7a21e68268\"\u003e\u003ccode\u003e072b217\u003c/code\u003e\u003c/a\u003e Update plugin spotless to v8.5.0 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5668\"\u003e#5668\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/3a53480218f4b752a9ca77506e10632cd483c0f8\"\u003e\u003ccode\u003e3a53480\u003c/code\u003e\u003c/a\u003e Update Gradle to v9.5.1 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5666\"\u003e#5666\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0e18a20a9f98d063ae02b3ba19329143f5c7f034\"\u003e\u003ccode\u003e0e18a20\u003c/code\u003e\u003c/a\u003e Update zizmorcore/zizmor-action action to v0.5.4 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5669\"\u003e#5669\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0a2634fb9cbbd057b02cf629d7d272c16d62be4b\"\u003e\u003ccode\u003e0a2634f\u003c/code\u003e\u003c/a\u003e Update github/codeql-action action to v4.35.5 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5671\"\u003e#5671\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/4dbd5561b00ac761a62c516bfaec51c212a2d60c\"\u003e\u003ccode\u003e4dbd556\u003c/code\u003e\u003c/a\u003e Restructure workflows to have single \u0026quot;status\u0026quot; job (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5670\"\u003e#5670\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/f2194cebe377512cb0ade388c62a881a0bcf5d3e\"\u003e\u003ccode\u003ef2194ce\u003c/code\u003e\u003c/a\u003e Increase timeout to reduce flakiness\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/5c8fdd2df65b763151cccbe669ea9e1c3155efcd\"\u003e\u003ccode\u003e5c8fdd2\u003c/code\u003e\u003c/a\u003e Update dependency org.apache.groovy:groovy to v5.0.6 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5659\"\u003e#5659\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/43c6982324602582902c9bdb213fd5e007f9cf3d\"\u003e\u003ccode\u003e43c6982\u003c/code\u003e\u003c/a\u003e Update dependency org.slf4j:slf4j-jdk14 to v2.0.18 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5667\"\u003e#5667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.ow2.asm:asm-bom` from 9.10 to 9.10.1\n\nUpdates `ch.qos.logback:logback-core` from 1.5.32 to 1.5.33\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.codehaus.plexus:plexus-classworlds` from 2.11.0 to 2.12.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/releases\"\u003eorg.codehaus.plexus:plexus-classworlds's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.12.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cul\u003e\n\u003cli\u003eFix loadGlob using OR instead of AND for glob matching (\u003ca href=\"https://redirect.github.com/codehaus-plexus/plexus-classworlds/pull/147\"\u003e#147\u003c/a\u003e) \u003ca href=\"https://github.com/gnodet\"\u003e\u003ccode\u003e@​gnodet\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/commit/352e533ee33c8bae87b96255ae37f3dfe8b39c21\"\u003e\u003ccode\u003e352e533\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release plexus-classworlds-2.12.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/commit/9d5a694fa806a2c9d5344deba166f8cd3d2dc17d\"\u003e\u003ccode\u003e9d5a694\u003c/code\u003e\u003c/a\u003e Fix test to use File API for glob pattern (Windows compat)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/commit/6cff36d2d2a56c34c5229a0304ee73b1069703b2\"\u003e\u003ccode\u003e6cff36d\u003c/code\u003e\u003c/a\u003e Fix loadGlob using OR instead of AND for glob matching\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/commit/98ef018f4e644e246ef650a8de9a3a1d51103b22\"\u003e\u003ccode\u003e98ef018\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/compare/plexus-classworlds-2.11.0...plexus-classworlds-2.12.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.junit.platform:junit-platform-engine` from 6.0.3 to 6.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/junit-team/junit-framework/releases\"\u003eorg.junit.platform:junit-platform-engine's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eJUnit 6.1.0 = Platform 6.1.0 + Jupiter 6.1.0 + Vintage 6.1.0\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0/release-notes.html\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JarvisCraft\"\u003e\u003ccode\u003e@​JarvisCraft\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5633\"\u003ejunit-team/junit-framework#5633\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Maran23\"\u003e\u003ccode\u003e@​Maran23\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5644\"\u003ejunit-team/junit-framework#5644\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eJUnit 6.1.0-RC1 = Platform 6.1.0-RC1 + Jupiter 6.1.0-RC1 + Vintage 6.1.0-RC1\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0-RC1/release-notes/\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mariokhoury4\"\u003e\u003ccode\u003e@​mariokhoury4\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/4574\"\u003ejunit-team/junit-framework#4574\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Ogu1208\"\u003e\u003ccode\u003e@​Ogu1208\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5145\"\u003ejunit-team/junit-framework#5145\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/HyungGeun94\"\u003e\u003ccode\u003e@​HyungGeun94\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5271\"\u003ejunit-team/junit-framework#5271\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yalishevant\"\u003e\u003ccode\u003e@​yalishevant\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5316\"\u003ejunit-team/junit-framework#5316\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JINU-CHANG\"\u003e\u003ccode\u003e@​JINU-CHANG\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5290\"\u003ejunit-team/junit-framework#5290\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jaschdoc\"\u003e\u003ccode\u003e@​jaschdoc\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5427\"\u003ejunit-team/junit-framework#5427\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kawshikbuet17\"\u003e\u003ccode\u003e@​kawshikbuet17\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5561\"\u003ejunit-team/junit-framework#5561\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/msridhar\"\u003e\u003ccode\u003e@​msridhar\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5602\"\u003ejunit-team/junit-framework#5602\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.1.0-M1...r6.1.0-RC1\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.1.0-M1...r6.1.0-RC1\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eJUnit 6.1.0-M1 = Platform 6.1.0-M1 + Jupiter 6.1.0-M1 + Vintage 6.1.0-M1\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0-M1/release-notes/\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vy\"\u003e\u003ccode\u003e@​vy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5041\"\u003ejunit-team/junit-framework#5041\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Pankraz76\"\u003e\u003ccode\u003e@​Pankraz76\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5006\"\u003ejunit-team/junit-framework#5006\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/arukiidou\"\u003e\u003ccode\u003e@​arukiidou\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5066\"\u003ejunit-team/junit-framework#5066\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/laeubi\"\u003e\u003ccode\u003e@​laeubi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5092\"\u003ejunit-team/junit-framework#5092\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jihun4452\"\u003e\u003ccode\u003e@​jihun4452\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5088\"\u003ejunit-team/junit-framework#5088\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TWiStErRob\"\u003e\u003ccode\u003e@​TWiStErRob\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5133\"\u003ejunit-team/junit-framework#5133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.0...r6.1.0-M1\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.0.0...r6.1.0-M1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0dc3af1cb1973d257b5bc75d81e02454d5e4e556\"\u003e\u003ccode\u003e0dc3af1\u003c/code\u003e\u003c/a\u003e Release 6.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/1d130020c85170edcb46ce7ed1f7f78824e37c04\"\u003e\u003ccode\u003e1d13002\u003c/code\u003e\u003c/a\u003e Prepare 6.1.0 release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/072b2175bbd7b0b3b26f5d928550ec7a21e68268\"\u003e\u003ccode\u003e072b217\u003c/code\u003e\u003c/a\u003e Update plugin spotless to v8.5.0 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5668\"\u003e#5668\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/3a53480218f4b752a9ca77506e10632cd483c0f8\"\u003e\u003ccode\u003e3a53480\u003c/code\u003e\u003c/a\u003e Update Gradle to v9.5.1 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5666\"\u003e#5666\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0e18a20a9f98d063ae02b3ba19329143f5c7f034\"\u003e\u003ccode\u003e0e18a20\u003c/code\u003e\u003c/a\u003e Update zizmorcore/zizmor-action action to v0.5.4 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5669\"\u003e#5669\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0a2634fb9cbbd057b02cf629d7d272c16d62be4b\"\u003e\u003ccode\u003e0a2634f\u003c/code\u003e\u003c/a\u003e Update github/codeql-action action to v4.35.5 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5671\"\u003e#5671\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/4dbd5561b00ac761a62c516bfaec51c212a2d60c\"\u003e\u003ccode\u003e4dbd556\u003c/code\u003e\u003c/a\u003e Restructure workflows to have single \u0026quot;status\u0026quot; job (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5670\"\u003e#5670\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/f2194cebe377512cb0ade388c62a881a0bcf5d3e\"\u003e\u003ccode\u003ef2194ce\u003c/code\u003e\u003c/a\u003e Increase timeout to reduce flakiness\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/5c8fdd2df65b763151cccbe669ea9e1c3155efcd\"\u003e\u003ccode\u003e5c8fdd2\u003c/code\u003e\u003c/a\u003e Update dependency org.apache.groovy:groovy to v5.0.6 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5659\"\u003e#5659\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/43c6982324602582902c9bdb213fd5e007f9cf3d\"\u003e\u003ccode\u003e43c6982\u003c/code\u003e\u003c/a\u003e Update dependency org.slf4j:slf4j-jdk14 to v2.0.18 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5667\"\u003e#5667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `eu.maveniverse.maven.njord:extension3` from 0.9.6 to 0.9.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/maveniverse/njord/releases\"\u003eeu.maveniverse.maven.njord:extension3's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.9.7\u003c/h2\u003e\n\u003cp\u003eMaintenance and updates.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump org.codehaus.plexus:plexus-classworlds from 2.11.0 to 2.12.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/301\"\u003emaveniverse/njord#301\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.junit.jupiter:junit-jupiter-api from 6.0.3 to 6.1.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/300\"\u003emaveniverse/njord#300\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.mima from 2.4.43 to 2.4.44 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/298\"\u003emaveniverse/njord#298\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.maven from 3.9.15 to 3.9.16 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/297\"\u003emaveniverse/njord#297\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.ow2.asm:asm from 9.10 to 9.10.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/305\"\u003emaveniverse/njord#305\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.json:json from 20251224 to 20260522 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/304\"\u003emaveniverse/njord#304\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.maveniverseShared from 0.2.3 to 0.2.4 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/303\"\u003emaveniverse/njord#303\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDeps: parent POM 55 and others by \u003ca href=\"https://github.com/cstamas\"\u003e\u003ccode\u003e@​cstamas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/306\"\u003emaveniverse/njord#306\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/maveniverse/njord/compare/release-0.9.6...release-0.9.7\"\u003ehttps://github.com/maveniverse/njord/compare/release-0.9.6...release-0.9.7\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/b1d8216ca4e8634858babb37c2e1474b1de8889f\"\u003e\u003ccode\u003eb1d8216\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release release-0.9.7 [skip ci]\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/2ea8dd7fc5c4e54c12904c6364bd2a0c2bae5814\"\u003e\u003ccode\u003e2ea8dd7\u003c/code\u003e\u003c/a\u003e Deps: parent POM 55 and others (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/306\"\u003e#306\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/1d8212610fc034982dd9f2c2955c77abee27b651\"\u003e\u003ccode\u003e1d82126\u003c/code\u003e\u003c/a\u003e Bump version.maveniverseShared from 0.2.3 to 0.2.4 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/303\"\u003e#303\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/3f90e7e5515846ed5fcc34f62f8c7d8b582cb75f\"\u003e\u003ccode\u003e3f90e7e\u003c/code\u003e\u003c/a\u003e Bump org.json:json from 20251224 to 20260522 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/304\"\u003e#304\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/4084d479efcec09fd0c9140126e76f34e6b5e0f7\"\u003e\u003ccode\u003e4084d47\u003c/code\u003e\u003c/a\u003e Bump org.ow2.asm:asm from 9.10 to 9.10.1 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/305\"\u003e#305\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/e363ff5d85abd697f700547f9664ca55ccd9aa71\"\u003e\u003ccode\u003ee363ff5\u003c/code\u003e\u003c/a\u003e Bump version.maven from 3.9.15 to 3.9.16 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/f861a12563dc553f7568aa813baaa4a42869f8a7\"\u003e\u003ccode\u003ef861a12\u003c/code\u003e\u003c/a\u003e Bump version.mima from 2.4.43 to 2.4.44 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/298\"\u003e#298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/e337af459ea61cbd62de3b4d4276039e143f1aaa\"\u003e\u003ccode\u003ee337af4\u003c/code\u003e\u003c/a\u003e Bump org.junit.jupiter:junit-jupiter-api from 6.0.3 to 6.1.0 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/300\"\u003e#300\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/5dfc3a10fb37c92f5382bd01b94c473e32ffd109\"\u003e\u003ccode\u003e5dfc3a1\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-classworlds from 2.11.0 to 2.12.0 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/301\"\u003e#301\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/495a36dc1602d5c7a766e74a8fc2de48a958e6ca\"\u003e\u003ccode\u003e495a36d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/maveniverse/njord/compare/release-0.9.6...release-0.9.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `eu.maveniverse.maven.plugins:njord` from 0.9.6 to 0.9.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/maveniverse/njord/releases\"\u003eeu.maveniverse.maven.plugins:njord's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.9.7\u003c/h2\u003e\n\u003cp\u003eMaintenance and updates.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump org.codehaus.plexus:plexus-classworlds from 2.11.0 to 2.12.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/301\"\u003emaveniverse/njord#301\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.junit.jupiter:junit-jupiter-api from 6.0.3 to 6.1.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/300\"\u003emaveniverse/njord#300\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.mima from 2.4.43 to 2.4.44 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/298\"\u003emaveniverse/njord#298\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.maven from 3.9.15 to 3.9.16 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/297\"\u003emaveniverse/njord#297\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.ow2.asm:asm from 9.10 to 9.10.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/305\"\u003emaveniverse/njord#305\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.json:json from 20251224 to 20260522 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/304\"\u003emaveniverse/njord#304\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.maveniverseShared from 0.2.3 to 0.2.4 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/303\"\u003emaveniverse/njord#303\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDeps: parent POM 55 and others by \u003ca href=\"https://github.com/cstamas\"\u003e\u003ccode\u003e@​cstamas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/306\"\u003emaveniverse/njord#306\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/maveniverse/njord/compare/release-0.9.6...release-0.9.7\"\u003ehttps://github.com/maveniverse/njord/compare/release-0.9.6...release-0.9.7\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/b1d8216ca4e8634858babb37c2e1474b1de8889f\"\u003e\u003ccode\u003eb1d8216\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release release-0.9.7 [skip ci]\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/2ea8dd7fc5c4e54c12904c6364bd2a0c2bae5814\"\u003e\u003ccode\u003e2ea8dd7\u003c/code\u003e\u003c/a\u003e Deps: parent POM 55 and others (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/306\"\u003e#306\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/1d8212610fc034982dd9f2c2955c77abee27b651\"\u003e\u003ccode\u003e1d82126\u003c/code\u003e\u003c/a\u003e Bump version.maveniverseShared from 0.2.3 to 0.2.4 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/303\"\u003e#303\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/3f90e7e5515846ed5fcc34f62f8c7d8b582cb75f\"\u003e\u003ccode\u003e3f90e7e\u003c/code\u003e\u003c/a\u003e Bump org.json:json from 20251224 to 20260522 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/304\"\u003e#304\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/4084d479efcec09fd0c9140126e76f34e6b5e0f7\"\u003e\u003ccode\u003e4084d47\u003c/code\u003e\u003c/a\u003e Bump org.ow2.asm:asm from 9.10 to 9.10.1 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/305\"\u003e#305\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/e363ff5d85abd697f700547f9664ca55ccd9aa71\"\u003e\u003ccode\u003ee363ff5\u003c/code\u003e\u003c/a\u003e Bump version.maven from 3.9.15 to 3.9.16 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/f861a12563dc553f7568aa813baaa4a42869f8a7\"\u003e\u003ccode\u003ef861a12\u003c/code\u003e\u003c/a\u003e Bump version.mima from 2.4.43 to 2.4.44 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/298\"\u003e#298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/e337af459ea61cbd62de3b4d4276039e143f1aaa\"\u003e\u003ccode\u003ee337af4\u003c/code\u003e\u003c/a\u003e Bump org.junit.jupiter:junit-jupiter-api from 6.0.3 to 6.1.0 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/300\"\u003e#300\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/5dfc3a10fb37c92f5382bd01b94c473e32ffd109\"\u003e\u003ccode\u003e5dfc3a1\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-classworlds from 2.11.0 to 2.12.0 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/301\"\u003e#301\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/495a36dc1602d5c7a766e74a8fc2de48a958e6ca\"\u003e\u003ccode\u003e495a36d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/maveniverse/njord/compare/release-0.9.6...release-0.9.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.maven.extensions:maven-build-cache-extension` from 1.2.2 to 1.2.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/apache/maven-build-cache-extension/releases\"\u003eorg.apache.maven.extensions:maven-build-cache-extension's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.3\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e🚀 New features and improvements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIssue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/336\"\u003e#336\u003c/a\u003e Add command line flag to override maxBuildsCached (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/489\"\u003e#489\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/MBUILDCACHE-73\"\u003e[MBUILDCACHE-73]\u003c/a\u003e - Allow arbitrary expressions as additional reconcilation properties (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/416\"\u003e#416\u003c/a\u003e) \u003ca href=\"https://github.com/pdudits\"\u003e\u003ccode\u003e@​pdudits\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/480\"\u003e#480\u003c/a\u003e - execute blocking hostname resolution asynchronously and implement timeout and caching (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/481\"\u003e#481\u003c/a\u003e) \u003ca href=\"https://github.com/marcuslinke\"\u003e\u003ccode\u003e@​marcuslinke\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDo not read a JAR completely into a byte-array before computing the SHA (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/470\"\u003e#470\u003c/a\u003e) \u003ca href=\"https://github.com/jvdvegt\"\u003e\u003ccode\u003e@​jvdvegt\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Test Only] Comprehensive test coverage (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/462\"\u003e#462\u003c/a\u003e) \u003ca href=\"https://github.com/AlexanderAshitkin\"\u003e\u003ccode\u003e@​AlexanderAshitkin\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOnly set the project artifact if it is the actual JAR (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/453\"\u003e#453\u003c/a\u003e) \u003ca href=\"https://github.com/mensinda\"\u003e\u003ccode\u003e@​mensinda\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/423\"\u003e#423\u003c/a\u003e — include declared input files in cache checksum for pom-packaged modules (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/482\"\u003e#482\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix issue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/463\"\u003e#463\u003c/a\u003e Unexpected cache miss due to previously downloaded remote cache entry with skipTests (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/472\"\u003e#472\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIssue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/345\"\u003e#345\u003c/a\u003e fix possible NPE with Intellij (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/473\"\u003e#473\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTest-jar type dependencies fail to be resolved during checksum calculation with -f builds (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/468\"\u003e#468\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix for issue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/450\"\u003e#450\u003c/a\u003e - fixed CacheUtils.unzip to properly restore unix permissions on file systems that support it (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/451\"\u003e#451\u003c/a\u003e) \u003ca href=\"https://github.com/eyforia\"\u003e\u003ccode\u003e@​eyforia\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📝 Documentation updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocumentation fixes and updates (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/460\"\u003e#460\u003c/a\u003e) \u003ca href=\"https://github.com/AlexanderAshitkin\"\u003e\u003ccode\u003e@​AlexanderAshitkin\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e👻 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFinish breaking dependency on org.apache.http in RemoteCacheRepositoryImpl (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/441\"\u003e#441\u003c/a\u003e) \u003ca href=\"https://github.com/elharo\"\u003e\u003ccode\u003e@​elharo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove undeclared NotNull annotations (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/440\"\u003e#440\u003c/a\u003e) \u003ca href=\"https://github.com/elharo\"\u003e\u003ccode\u003e@​elharo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFill in two more used dependencies SLF4J and sisu.plexus (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/438\"\u003e#438\u003c/a\u003e) \u003ca href=\"https://github.com/elharo\"\u003e\u003ccode\u003e@​elharo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🚦 Tests\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix findFirstMainSourceFile to skip invoker test projects (src/it/) in p12 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/474\"\u003e#474\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Test Only] Comprehensive test coverage (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/462\"\u003e#462\u003c/a\u003e) \u003ca href=\"https://github.com/AlexanderAshitkin\"\u003e\u003ccode\u003e@​AlexanderAshitkin\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📦 Dependency updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate 48 and Maven 3.9.16 (in Maven 3 profile) (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/490\"\u003e#490\u003c/a\u003e) \u003ca href=\"https://github.com/Bukama\"\u003e\u003ccode\u003e@​Bukama\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump com.github.tomakehurst:wiremock-jre8 from 2.35.2 to 3.0.1 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/485\"\u003e#485\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-invoker-plugin from 3.10.0 to 3.10.1 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/484\"\u003e#484\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump com.google.guava:guava from 30.1.1-jre to 32.0.0-jre in /src/test/projects/reference-test-projects/p06-dep-edge-cases/bom-b (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/464\"\u003e#464\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.junit:junit-bom from 5.14.3 to 5.14.4 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/479\"\u003e#479\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.commons:commons-lang3 from 3.14.0 to 3.18.0 in /src/test/projects/reference-test-projects/p18-maven4-native/platform-bom (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/465\"\u003e#465\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-invoker-plugin from 3.9.1 to 3.10.0 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/478\"\u003e#478\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump commons-io:commons-io from 2.21.0 to 2.22.0 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/477\"\u003e#477\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.testcontainers:testcontainers-bom from 2.0.4 to 2.0.5 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/476\"\u003e#476\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump com.fasterxml.jackson.core:jackson-annotations from 2.15.4 to 2.21 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/475\"\u003e#475\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.testcontainers:testcontainers-bom from 2.0.3 to 2.0.4 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/466\"\u003e#466\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump resolverVersion from 1.9.26 to 1.9.27 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/459\"\u003e#459\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump resolverVersion from 1.9.25 to 1.9.26 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/458\"\u003e#458\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.junit:junit-bom from 5.14.2 to 5.14.3 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/457\"\u003e#457\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/f9f25d2f6acd78238471f7f36e1efe93fb8b7e50\"\u003e\u003ccode\u003ef9f25d2\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release maven-build-cache-extension-1.2.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/7bd513b6515e526554067386d2d4b1e67fb7e2cb\"\u003e\u003ccode\u003e7bd513b\u003c/code\u003e\u003c/a\u003e Update 48 and Maven 3.9.16 (in Maven 3 profile) (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/490\"\u003e#490\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/ada66d445c228ba9abe52e42632fc237af38f89f\"\u003e\u003ccode\u003eada66d4\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/336\"\u003e#336\u003c/a\u003e Add command line flag to override maxBuildsCached (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/489\"\u003e#489\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/c915399e169c6c3633b4a12be0fc1e9579114f50\"\u003e\u003ccode\u003ec915399\u003c/code\u003e\u003c/a\u003e [MBUILDCACHE-73] Allow arbitrary expressions as additional reconcilation prop...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/0b7d080ffca2a32c892208bbfafbd18b9dd32a92\"\u003e\u003ccode\u003e0b7d080\u003c/code\u003e\u003c/a\u003e Bump com.github.tomakehurst:wiremock-jre8 from 2.35.2 to 3.0.1 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/485\"\u003e#485\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/051a319a8f063ea59f97709186e8966e2969a1e4\"\u003e\u003ccode\u003e051a319\u003c/code\u003e\u003c/a\u003e Only set the project artifact if it is the actual JAR (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/453\"\u003e#453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/6a48e056a89316d5c3a007098cd32aa9aa5e1a5e\"\u003e\u003ccode\u003e6a48e05\u003c/code\u003e\u003c/a\u003e Bump org.apache.maven.plugins:maven-invoker-plugin from 3.10.0 to 3.10.1 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/484\"\u003e#484\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/5032c5d805f4071d34ecea96f40d80117369654a\"\u003e\u003ccode\u003e5032c5d\u003c/code\u003e\u003c/a\u003e fix: \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/480\"\u003e#480\u003c/a\u003e - execute blocking hostname resolution asynchronously and implement...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/dc7069f9e25acfafa6cc41ebba48bcbe43e5bc4b\"\u003e\u003ccode\u003edc7069f\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/423\"\u003e#423\u003c/a\u003e add an IT and a fix (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/482\"\u003e#482\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/929bed8890bc43128818277c13b6f8c1c05e5f8c\"\u003e\u003ccode\u003e929bed8\u003c/code\u003e\u003c/a\u003e Bump com.google.guava:guava\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/apache/maven-build-cache-extension/compare/maven-build-cache-extension-1.2.2...maven-build-cache-extension-1.2.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `eu.maveniverse.maven.plugins:njord` from 0.9.6 to 0.9.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/maveniverse/njord/releases\"\u003eeu.maveniverse.maven.plugins:njord's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.9.7\u003c/h2\u003e\n\u003cp\u003eMaintenance and updates.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump org.codehaus.plexus:plexus-classworlds from 2.11.0 to 2.12.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/301\"\u003emaveniverse/njord#301\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.junit.jupiter:junit-jupiter-api from 6.0.3 to 6.1.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/300\"\u003emaveniverse/njord#300\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.mima from 2.4.43 to 2.4.44 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/298\"\u003emaveniverse/njord#298\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.maven from 3.9.15 to 3.9.16 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/297\"\u003emaveniverse/njord#297\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.ow2.asm:asm from 9.10 to 9.10.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pul...\n\n_Description has been truncated_","html_url":"https://github.com/jetty/jetty.project/pull/15211","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/jetty%2Fjetty.project/issues/15211","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/15211/packages"},{"uuid":"4552609919","node_id":"PR_kwDOAB81F87g2ye7","number":15208,"state":"closed","title":"[12.1.x EE10] Bump the dev-dependencies group across 1 directory with 14 updates","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-06-06T00:11:29.000Z","author_association":null,"state_reason":null,"created_at":"2026-05-30T01:02:12.000Z","updated_at":"2026-06-06T00:11:31.000Z","time_to_close":601757,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"[12.1.x EE10] Bump","group_name":"dev-dependencies","update_count":14,"packages":[{"name":"org.ow2.asm:asm","old_version":"9.10","new_version":"9.10.1"},{"name":"org.ow2.asm:asm-commons","old_version":"9.10","new_version":"9.10.1"},{"name":"org.ow2.asm:asm-bom","old_version":"9.10","new_version":"9.10.1"},{"name":"org.apache.maven.surefire:surefire-junit47","old_version":"3.5.5","new_version":"3.5.6"},{"name":"com.fasterxml.jackson:jackson-bom","old_version":"2.21.3","new_version":"2.21.4","repository_url":"https://github.com/FasterXML/jackson-bom"},{"name":"io.netty:netty-bom","old_version":"4.2.13.Final","new_version":"4.2.14.Final","repository_url":"https://github.com/netty/netty"},{"name":"org.hibernate.search:hibernate-search-bom","old_version":"8.3.1.Final","new_version":"8.4.0.Final","repository_url":"https://github.com/hibernate/hibernate-search"},{"name":"org.junit:junit-bom","old_version":"6.0.3","new_version":"6.1.0","repository_url":"https://github.com/junit-team/junit-framework"},{"name":"ch.qos.logback:logback-core","old_version":"1.5.32","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"},{"name":"org.codehaus.plexus:plexus-classworlds","old_version":"2.11.0","new_version":"2.12.0","repository_url":"https://github.com/codehaus-plexus/plexus-classworlds"},{"name":"eu.maveniverse.maven.njord:extension3","old_version":"0.9.6","new_version":"0.9.7","repository_url":"https://github.com/maveniverse/njord"},{"name":"eu.maveniverse.maven.plugins:njord","old_version":"0.9.6","new_version":"0.9.7","repository_url":"https://github.com/maveniverse/njord"},{"name":"org.apache.maven.extensions:maven-build-cache-extension","old_version":"1.2.2","new_version":"1.2.3","repository_url":"https://github.com/apache/maven-build-cache-extension"}],"path":null,"ecosystem":"maven"},"body":"Bumps the dev-dependencies group with 13 updates in the /jetty-ee10 directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| org.ow2.asm:asm | `9.10` | `9.10.1` |\n| org.ow2.asm:asm-commons | `9.10` | `9.10.1` |\n| org.ow2.asm:asm-bom | `9.10` | `9.10.1` |\n| org.apache.maven.surefire:surefire-junit47 | `3.5.5` | `3.5.6` |\n| [com.fasterxml.jackson:jackson-bom](https://github.com/FasterXML/jackson-bom) | `2.21.3` | `2.21.4` |\n| [io.netty:netty-bom](https://github.com/netty/netty) | `4.2.13.Final` | `4.2.14.Final` |\n| [org.hibernate.search:hibernate-search-bom](https://github.com/hibernate/hibernate-search) | `8.3.1.Final` | `8.4.0.Final` |\n| [org.junit:junit-bom](https://github.com/junit-team/junit-framework) | `6.0.3` | `6.1.0` |\n| [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) | `1.5.32` | `1.5.33` |\n| [org.codehaus.plexus:plexus-classworlds](https://github.com/codehaus-plexus/plexus-classworlds) | `2.11.0` | `2.12.0` |\n| [eu.maveniverse.maven.njord:extension3](https://github.com/maveniverse/njord) | `0.9.6` | `0.9.7` |\n| [eu.maveniverse.maven.plugins:njord](https://github.com/maveniverse/njord) | `0.9.6` | `0.9.7` |\n| [org.apache.maven.extensions:maven-build-cache-extension](https://github.com/apache/maven-build-cache-extension) | `1.2.2` | `1.2.3` |\n\n\nUpdates `org.ow2.asm:asm` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-commons` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-bom` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-commons` from 9.10 to 9.10.1\n\nUpdates `org.apache.maven.surefire:surefire-junit47` from 3.5.5 to 3.5.6\n\nUpdates `com.fasterxml.jackson:jackson-bom` from 2.21.3 to 2.21.4\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-bom/commit/d1abd31e4fec3035965d57a05a6256171ea8d980\"\u003e\u003ccode\u003ed1abd31\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-bom-2.21.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-bom/commit/2aaea43db8480aa7d405ebc0de503cffc864f6f6\"\u003e\u003ccode\u003e2aaea43\u003c/code\u003e\u003c/a\u003e Prep for 2.21.4 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-bom/commit/9d3a9d54e40312ef0ac9192d599b59b541f65fb8\"\u003e\u003ccode\u003e9d3a9d5\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-bom/commit/84bcf7f5b268bc2b47a92bd08391f75e9d956793\"\u003e\u003ccode\u003e84bcf7f\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/FasterXML/jackson-bom/compare/jackson-bom-2.21.3...jackson-bom-2.21.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `io.netty:netty-bom` from 4.2.13.Final to 4.2.14.Final\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/netty/netty/releases\"\u003eio.netty:netty-bom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003enetty-4.2.14.Final\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHTTP: Fix revapi failure introduced by 84530fa81e12dcd1d42310bb20c1385cb44128d8 by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16748\"\u003enetty/netty#16748\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHTTP: Re-add constructor to HttpProxyHandler that was removed by mistake by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16747\"\u003enetty/netty#16747\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMarshalling: Explicit document security requirements by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16752\"\u003enetty/netty#16752\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix io_uring op completion TRACE logging by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16755\"\u003enetty/netty#16755\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eQuic: Ensure writes are done before notify close promise of QuicheQui… by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16758\"\u003enetty/netty#16758\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid re-parsing openssl key material with non-cached provider by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16759\"\u003enetty/netty#16759\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin HTTP/RTSP version + method normalization to Locale.US by \u003ca href=\"https://github.com/daguimu\"\u003e\u003ccode\u003e@​daguimu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16765\"\u003enetty/netty#16765\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFill MsgHdrMemoryArray#hdrs with null entry on release by \u003ca href=\"https://github.com/tsegismont\"\u003e\u003ccode\u003e@​tsegismont\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16764\"\u003enetty/netty#16764\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRevapi: Use default \u0026quot;oldVersion\u0026quot; by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16774\"\u003enetty/netty#16774\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdaptive: Fix concurrency issue in adaptive allocator by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16767\"\u003enetty/netty#16767\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAuto-port 4.2: Make bulk byte moving in ByteBuf faster by \u003ca href=\"https://github.com/netty-project-bot\"\u003e\u003ccode\u003e@​netty-project-bot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16781\"\u003enetty/netty#16781\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin multipart Content-Type / Content-Transfer-Encoding case folding to Locale.US by \u003ca href=\"https://github.com/daguimu\"\u003e\u003ccode\u003e@​daguimu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16768\"\u003enetty/netty#16768\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove dead native declarations by \u003ca href=\"https://github.com/pandareen\"\u003e\u003ccode\u003e@​pandareen\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16783\"\u003enetty/netty#16783\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIsolate tests that modify available Security providers by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16793\"\u003enetty/netty#16793\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove test annotations from a method that isn't a test by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16792\"\u003enetty/netty#16792\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEnable OpenSslCachingKeyMaterialProvider to evict stale entries after cert rotation by \u003ca href=\"https://github.com/zhangweikop\"\u003e\u003ccode\u003e@​zhangweikop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16523\"\u003enetty/netty#16523\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIoUring: extend user data from short to long by \u003ca href=\"https://github.com/dreamlike-ocean\"\u003e\u003ccode\u003e@​dreamlike-ocean\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16682\"\u003enetty/netty#16682\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRevert CompositeByteBuf component search fast path by \u003ca href=\"https://github.com/yawkat\"\u003e\u003ccode\u003e@​yawkat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16811\"\u003enetty/netty#16811\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHTTP2: Use 100 as default max concurrent streams setting by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16804\"\u003enetty/netty#16804\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix ResumptionController wrapping by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16815\"\u003enetty/netty#16815\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eResolve all localhost addresses without querying DNS servers by \u003ca href=\"https://github.com/JulianVennen\"\u003e\u003ccode\u003e@​JulianVennen\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16749\"\u003enetty/netty#16749\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIpFilter: Fix ClassCastException caused by IpSubnetFilter if only ipv6 rules are configured but remote peer is using ipv4 by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16803\"\u003enetty/netty#16803\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix memoryAddress() for direct ByteBuffers wrapped by Unpooled without Unsafe by \u003ca href=\"https://github.com/dreamlike-ocean\"\u003e\u003ccode\u003e@​dreamlike-ocean\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16788\"\u003enetty/netty#16788\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRoute synchronous onLookupComplete exceptions via fireExceptionCaught by \u003ca href=\"https://github.com/kwondh5217\"\u003e\u003ccode\u003e@​kwondh5217\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16794\"\u003enetty/netty#16794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIoUring: Stop generic FileRegion drain loop when transferred() reaches count() by \u003ca href=\"https://github.com/LuciferYang\"\u003e\u003ccode\u003e@​LuciferYang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16826\"\u003enetty/netty#16826\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMQTT: Allow MQTT 5 CONNECT with password only by \u003ca href=\"https://github.com/shblue21\"\u003e\u003ccode\u003e@​shblue21\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16833\"\u003enetty/netty#16833\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix MQTT decoder size check after variable header replay by \u003ca href=\"https://github.com/daguimu\"\u003e\u003ccode\u003e@​daguimu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16787\"\u003enetty/netty#16787\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pandareen\"\u003e\u003ccode\u003e@​pandareen\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16783\"\u003enetty/netty#16783\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zhangweikop\"\u003e\u003ccode\u003e@​zhangweikop\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16523\"\u003enetty/netty#16523\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JulianVennen\"\u003e\u003ccode\u003e@​JulianVennen\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16749\"\u003enetty/netty#16749\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kwondh5217\"\u003e\u003ccode\u003e@​kwondh5217\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16794\"\u003enetty/netty#16794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/shblue21\"\u003e\u003ccode\u003e@​shblue21\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16833\"\u003enetty/netty#16833\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/netty/netty/compare/netty-4.2.13.Final...netty-4.2.14.Final\"\u003ehttps://github.com/netty/netty/compare/netty-4.2.13.Final...netty-4.2.14.Final\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/0a60b753d5b0de9f58e245538d61c11dc6cfc4b2\"\u003e\u003ccode\u003e0a60b75\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release netty-4.2.14.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/72df658e5fdd1cc6d65bce1e0917ec31a9560269\"\u003e\u003ccode\u003e72df658\u003c/code\u003e\u003c/a\u003e Fix MQTT decoder size check after variable header replay (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16787\"\u003e#16787\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/7125dba6b20822aa72dd8359b350c2f3b9a545d9\"\u003e\u003ccode\u003e7125dba\u003c/code\u003e\u003c/a\u003e MQTT: Allow MQTT 5 CONNECT with password only (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16833\"\u003e#16833\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/9e19320a5855746970d05a5cd785d73a17cc694d\"\u003e\u003ccode\u003e9e19320\u003c/code\u003e\u003c/a\u003e IoUring: Stop generic FileRegion drain loop when transferred() reaches count(...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/4ce9f17f05c67b72c87bc83951800bad245fe162\"\u003e\u003ccode\u003e4ce9f17\u003c/code\u003e\u003c/a\u003e Route synchronous onLookupComplete exceptions via fireExceptionCaught (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16794\"\u003e#16794\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/f7b1b7de625031cc60e6eaecb889c97303588759\"\u003e\u003ccode\u003ef7b1b7d\u003c/code\u003e\u003c/a\u003e Fix memoryAddress() for direct ByteBuffers wrapped by Unpooled without Unsafe...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/0ccb265cadf91b2e09c2f479c9194d193d7a5dbc\"\u003e\u003ccode\u003e0ccb265\u003c/code\u003e\u003c/a\u003e IpFilter: Fix ClassCastException caused by IpSubnetFilter if only ipv6 rules ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/a6aeb6deffda3e45904edd05abc5cdddcd438794\"\u003e\u003ccode\u003ea6aeb6d\u003c/code\u003e\u003c/a\u003e Resolve all localhost addresses without querying DNS servers (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16749\"\u003e#16749\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/c328ba2ab89d2c90c80be1d2de1cfbb8f94c438b\"\u003e\u003ccode\u003ec328ba2\u003c/code\u003e\u003c/a\u003e Fix ResumptionController wrapping (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16815\"\u003e#16815\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/bc5862ba488c569c888d3b82048083041f66e880\"\u003e\u003ccode\u003ebc5862b\u003c/code\u003e\u003c/a\u003e HTTP2: Use 100 as default max concurrent streams setting (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16804\"\u003e#16804\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/netty/netty/compare/netty-4.2.13.Final...netty-4.2.14.Final\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.hibernate.search:hibernate-search-bom` from 8.3.1.Final to 8.4.0.Final\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hibernate/hibernate-search/releases\"\u003eorg.hibernate.search:hibernate-search-bom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 8.4.0.Final\u003c/h2\u003e\n\u003ch1\u003eHibernate Search 8.4.0.Final released\u003c/h1\u003e\n\u003cp\u003eWe are pleased to announce the release of Hibernate Search 8.4: 8.4.0.Final.\u003c/p\u003e\n\u003cp\u003eYou can find the full list of 8.4.0.Final changes \u003ca href=\"https://hibernate.atlassian.net/issues/?jql=project%20%3D%20HSEARCH%20AND%20fixVersion%20%3D%208.4.0.Final\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eWhat's new\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSee the \u003ca href=\"https://hibernate.org/search/releases/8.4\"\u003ewebsite\u003c/a\u003e for requirements and compatibilities.\u003c/li\u003e\n\u003cli\u003eSee the \u003ca href=\"https://docs.hibernate.org/search/8.4/whats-new/en-US/html_single/\"\u003eWhat's New\u003c/a\u003e guide for details about new features and capabilities.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eConclusion\u003c/h2\u003e\n\u003cp\u003eFor additional details, see:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe \u003ca href=\"https://hibernate.org/search/releases/8.4/\"\u003erelease page\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/migration/html_single/\"\u003eMigration Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/getting-started/orm/en-US/html_single/\"\u003eORM Getting Started Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/getting-started/standalone/en-US/html_single/\"\u003eStandalone Getting Started Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/reference/en-US/html_single/\"\u003eReference Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/api\"\u003eAPI docs\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eVisit the \u003ca href=\"https://hibernate.org/community/\"\u003ewebsite\u003c/a\u003e for details on getting in touch with us.\u003c/p\u003e\n\u003ch2\u003eRelease 8.4.0.CR1\u003c/h2\u003e\n\u003ch1\u003eHibernate Search 8.4.0.CR1 released\u003c/h1\u003e\n\u003cp\u003eWe are pleased to announce the release of Hibernate Search 8.4: 8.4.0.CR1.\u003c/p\u003e\n\u003cp\u003eYou can find the full list of 8.4.0.CR1 changes \u003ca href=\"https://hibernate.atlassian.net/issues/?jql=project%20%3D%20HSEARCH%20AND%20fixVersion%20%3D%208.4.0.CR1\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eWhat's new\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSee the \u003ca href=\"https://hibernate.org/search/releases/8.4\"\u003ewebsite\u003c/a\u003e for requirements and compatibilities.\u003c/li\u003e\n\u003cli\u003eSee the \u003ca href=\"https://docs.hibernate.org/search/8.4/whats-new/en-US/html_single/\"\u003eWhat's New\u003c/a\u003e guide for details about new features and capabilities.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eConclusion\u003c/h2\u003e\n\u003cp\u003eFor additional details, see:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe \u003ca href=\"https://hibernate.org/search/releases/8.4/\"\u003erelease page\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/migration/html_single/\"\u003eMigration Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/getting-started/orm/en-US/html_single/\"\u003eORM Getting Started Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/getting-started/standalone/en-US/html_single/\"\u003eStandalone Getting Started Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/reference/en-US/html_single/\"\u003eReference Guide\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hibernate/hibernate-search/blob/main/changelog.txt\"\u003eorg.hibernate.search:hibernate-search-bom's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.4.0.Final (2026-05-27)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://hibernate.atlassian.net/projects/HSEARCH/versions/39072\"\u003ehttps://hibernate.atlassian.net/projects/HSEARCH/versions/39072\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e** Improvement\n* HSEARCH-5630 Update to Hibernate ORM 7.4.0.Final\n* HSEARCH-5629 Use Maven 3.9.16 as a required minimum version for the build\n* HSEARCH-5627 Switch from the Search session holder to a Hibernate ORM session extension\n* HSEARCH-5626 Update Elasticsearch client (elasticsearch-rest-client) to 9.4.1\n* HSEARCH-5625 Test against latest Elasticsearch 9.4.1\n* HSEARCH-5624 Update Elasticsearch client (elasticsearch-rest5-client) to 9.4.1\u003c/p\u003e\n\u003ch2\u003e8.4.0.CR1 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://hibernate.atlassian.net/projects/HSEARCH/versions/37437\"\u003ehttps://hibernate.atlassian.net/projects/HSEARCH/versions/37437\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e** Bug\n* HSEARCH-5595 \u003ccode\u003echeckstyle:check\u003c/code\u003e is not build cache relocatable due to project resources including the workspace root\u003c/p\u003e\n\u003cp\u003e** Improvement\n* HSEARCH-5623 Update to Hibernate ORM 7.4.0.CR1\n* HSEARCH-5622 Update Elasticsearch client (elasticsearch-rest5-client) to 9.4.0\n* HSEARCH-5621 Update Elasticsearch client (elasticsearch-rest-client) to 9.4.0\n* HSEARCH-5620 Add compatibility with Elasticsearch 9.4\n* HSEARCH-5619 Upgrade to GSON 2.14.0\n* HSEARCH-5618 Update Jackson to 2.21.3\n* HSEARCH-5617 Update to AWS SDK 2.44.1\n* HSEARCH-5616 Update Elasticsearch client (elasticsearch-rest-client) to 9.3.4\n* HSEARCH-5613 Use Maven 3.9.15 as a required minimum version for the build\n* HSEARCH-5612 Upgrade to commons-codec 1.22.0\n* HSEARCH-5611 Update Apache HTTP Client components to 5.6.1\n* HSEARCH-5609 Update Elasticsearch client (elasticsearch-rest-client) to 9.3.3\n* HSEARCH-5608 Update Elasticsearch client (elasticsearch-rest5-client) to 9.3.4\n* HSEARCH-5607 Update Elasticsearch rest client (opensearch-rest-client) to 3.6.0\n* HSEARCH-5606 Add compatibility with OpenSearch 3.6\n* HSEARCH-5601 Update to commons-logging to 1.3.6\n* HSEARCH-5600 Update Jackson to 2.21.2\n* HSEARCH-5599 Update Apache HTTP Core client components to 5.4.2\n* HSEARCH-5598 Update Elasticsearch client (elasticsearch-rest-client) to 9.3.2\n* HSEARCH-5597 Update Elasticsearch client (elasticsearch-rest5-client) to 9.3.3\u003c/p\u003e\n\u003cp\u003e** Task\n* HSEARCH-5596 Use changeDetection config option instead of the deprecated overwrite in maven-resources-plugin\n* HSEARCH-5280 Look into \u003ccode\u003eOutboxPollingAutomaticIndexingDynamicShardingRebalancingIT#agentJoined\u003c/code\u003e test\n* HSEARCH-5242 Investigate why building hibernate-search-integrationtest-performance-backend-lucene fails on some envs\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/7369a18fc526aaffba13336fdcdc95a333702b19\"\u003e\u003ccode\u003e7369a18\u003c/code\u003e\u003c/a\u003e [Jenkins release job] Preparing release 8.4.0.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/4e26c085ba83c21cde89022a2f10864b08711e25\"\u003e\u003ccode\u003e4e26c08\u003c/code\u003e\u003c/a\u003e [Jenkins release job] changelog.txt updated by release build 8.4.0.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/fe410d2d5c25d9e05648f67c027441564a32be03\"\u003e\u003ccode\u003efe410d2\u003c/code\u003e\u003c/a\u003e HSEARCH-5630 Add a few migration notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/87335b65fd124493bf91ad83de78f64eafc1155c\"\u003e\u003ccode\u003e87335b6\u003c/code\u003e\u003c/a\u003e HSEARCH-5630 Update to Hibernate ORM 7.4.0.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/58d6af143d22c9ce55872c9f13c51c8dd8e03d32\"\u003e\u003ccode\u003e58d6af1\u003c/code\u003e\u003c/a\u003e HSEARCH-5624 Update Elasticsearch client (elasticsearch-rest5-client) to 9.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/9efe369fcb419ded47b3e77a02b3d84451e64853\"\u003e\u003ccode\u003e9efe369\u003c/code\u003e\u003c/a\u003e Bump the build-dependencies group with 4 updates\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/bc1c18509b22d2b1fa9e41149fbe5cf166d7f663\"\u003e\u003ccode\u003ebc1c185\u003c/code\u003e\u003c/a\u003e Use the ssh URL for updating the website during the release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/311adb00224ab04fc2c397da94cf41a373338801\"\u003e\u003ccode\u003e311adb0\u003c/code\u003e\u003c/a\u003e HSEARCH-5627 Mention limitations of a StatelessSession\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/d429b05110cf6015d70faa6278176c6b3e7defa0\"\u003e\u003ccode\u003ed429b05\u003c/code\u003e\u003c/a\u003e HSEARCH-5627 Better error message for \u0026quot;incompatible\u0026quot; session types\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/2eaeb282d9d9bc136bc32f93ca12634374e249d4\"\u003e\u003ccode\u003e2eaeb28\u003c/code\u003e\u003c/a\u003e HSEARCH-5627 Add a simple StatelessSession test\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hibernate/hibernate-search/compare/8.3.1.Final...8.4.0.Final\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.junit:junit-bom` from 6.0.3 to 6.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/junit-team/junit-framework/releases\"\u003eorg.junit:junit-bom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eJUnit 6.1.0 = Platform 6.1.0 + Jupiter 6.1.0 + Vintage 6.1.0\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0/release-notes.html\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JarvisCraft\"\u003e\u003ccode\u003e@​JarvisCraft\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5633\"\u003ejunit-team/junit-framework#5633\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Maran23\"\u003e\u003ccode\u003e@​Maran23\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5644\"\u003ejunit-team/junit-framework#5644\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eJUnit 6.1.0-RC1 = Platform 6.1.0-RC1 + Jupiter 6.1.0-RC1 + Vintage 6.1.0-RC1\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0-RC1/release-notes/\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mariokhoury4\"\u003e\u003ccode\u003e@​mariokhoury4\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/4574\"\u003ejunit-team/junit-framework#4574\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Ogu1208\"\u003e\u003ccode\u003e@​Ogu1208\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5145\"\u003ejunit-team/junit-framework#5145\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/HyungGeun94\"\u003e\u003ccode\u003e@​HyungGeun94\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5271\"\u003ejunit-team/junit-framework#5271\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yalishevant\"\u003e\u003ccode\u003e@​yalishevant\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5316\"\u003ejunit-team/junit-framework#5316\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JINU-CHANG\"\u003e\u003ccode\u003e@​JINU-CHANG\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5290\"\u003ejunit-team/junit-framework#5290\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jaschdoc\"\u003e\u003ccode\u003e@​jaschdoc\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5427\"\u003ejunit-team/junit-framework#5427\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kawshikbuet17\"\u003e\u003ccode\u003e@​kawshikbuet17\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5561\"\u003ejunit-team/junit-framework#5561\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/msridhar\"\u003e\u003ccode\u003e@​msridhar\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5602\"\u003ejunit-team/junit-framework#5602\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.1.0-M1...r6.1.0-RC1\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.1.0-M1...r6.1.0-RC1\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eJUnit 6.1.0-M1 = Platform 6.1.0-M1 + Jupiter 6.1.0-M1 + Vintage 6.1.0-M1\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0-M1/release-notes/\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vy\"\u003e\u003ccode\u003e@​vy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5041\"\u003ejunit-team/junit-framework#5041\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Pankraz76\"\u003e\u003ccode\u003e@​Pankraz76\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5006\"\u003ejunit-team/junit-framework#5006\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/arukiidou\"\u003e\u003ccode\u003e@​arukiidou\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5066\"\u003ejunit-team/junit-framework#5066\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/laeubi\"\u003e\u003ccode\u003e@​laeubi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5092\"\u003ejunit-team/junit-framework#5092\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jihun4452\"\u003e\u003ccode\u003e@​jihun4452\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5088\"\u003ejunit-team/junit-framework#5088\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TWiStErRob\"\u003e\u003ccode\u003e@​TWiStErRob\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5133\"\u003ejunit-team/junit-framework#5133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.0...r6.1.0-M1\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.0.0...r6.1.0-M1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0dc3af1cb1973d257b5bc75d81e02454d5e4e556\"\u003e\u003ccode\u003e0dc3af1\u003c/code\u003e\u003c/a\u003e Release 6.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/1d130020c85170edcb46ce7ed1f7f78824e37c04\"\u003e\u003ccode\u003e1d13002\u003c/code\u003e\u003c/a\u003e Prepare 6.1.0 release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/072b2175bbd7b0b3b26f5d928550ec7a21e68268\"\u003e\u003ccode\u003e072b217\u003c/code\u003e\u003c/a\u003e Update plugin spotless to v8.5.0 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5668\"\u003e#5668\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/3a53480218f4b752a9ca77506e10632cd483c0f8\"\u003e\u003ccode\u003e3a53480\u003c/code\u003e\u003c/a\u003e Update Gradle to v9.5.1 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5666\"\u003e#5666\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0e18a20a9f98d063ae02b3ba19329143f5c7f034\"\u003e\u003ccode\u003e0e18a20\u003c/code\u003e\u003c/a\u003e Update zizmorcore/zizmor-action action to v0.5.4 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5669\"\u003e#5669\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0a2634fb9cbbd057b02cf629d7d272c16d62be4b\"\u003e\u003ccode\u003e0a2634f\u003c/code\u003e\u003c/a\u003e Update github/codeql-action action to v4.35.5 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5671\"\u003e#5671\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/4dbd5561b00ac761a62c516bfaec51c212a2d60c\"\u003e\u003ccode\u003e4dbd556\u003c/code\u003e\u003c/a\u003e Restructure workflows to have single \u0026quot;status\u0026quot; job (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5670\"\u003e#5670\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/f2194cebe377512cb0ade388c62a881a0bcf5d3e\"\u003e\u003ccode\u003ef2194ce\u003c/code\u003e\u003c/a\u003e Increase timeout to reduce flakiness\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/5c8fdd2df65b763151cccbe669ea9e1c3155efcd\"\u003e\u003ccode\u003e5c8fdd2\u003c/code\u003e\u003c/a\u003e Update dependency org.apache.groovy:groovy to v5.0.6 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5659\"\u003e#5659\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/43c6982324602582902c9bdb213fd5e007f9cf3d\"\u003e\u003ccode\u003e43c6982\u003c/code\u003e\u003c/a\u003e Update dependency org.slf4j:slf4j-jdk14 to v2.0.18 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5667\"\u003e#5667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.ow2.asm:asm-bom` from 9.10 to 9.10.1\n\nUpdates `ch.qos.logback:logback-core` from 1.5.32 to 1.5.33\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.codehaus.plexus:plexus-classworlds` from 2.11.0 to 2.12.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/releases\"\u003eorg.codehaus.plexus:plexus-classworlds's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.12.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cul\u003e\n\u003cli\u003eFix loadGlob using OR instead of AND for glob matching (\u003ca href=\"https://redirect.github.com/codehaus-plexus/plexus-classworlds/pull/147\"\u003e#147\u003c/a\u003e) \u003ca href=\"https://github.com/gnodet\"\u003e\u003ccode\u003e@​gnodet\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/commit/352e533ee33c8bae87b96255ae37f3dfe8b39c21\"\u003e\u003ccode\u003e352e533\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release plexus-classworlds-2.12.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/commit/9d5a694fa806a2c9d5344deba166f8cd3d2dc17d\"\u003e\u003ccode\u003e9d5a694\u003c/code\u003e\u003c/a\u003e Fix test to use File API for glob pattern (Windows compat)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/commit/6cff36d2d2a56c34c5229a0304ee73b1069703b2\"\u003e\u003ccode\u003e6cff36d\u003c/code\u003e\u003c/a\u003e Fix loadGlob using OR instead of AND for glob matching\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/commit/98ef018f4e644e246ef650a8de9a3a1d51103b22\"\u003e\u003ccode\u003e98ef018\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/compare/plexus-classworlds-2.11.0...plexus-classworlds-2.12.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.junit.platform:junit-platform-engine` from 6.0.3 to 6.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/junit-team/junit-framework/releases\"\u003eorg.junit.platform:junit-platform-engine's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eJUnit 6.1.0 = Platform 6.1.0 + Jupiter 6.1.0 + Vintage 6.1.0\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0/release-notes.html\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JarvisCraft\"\u003e\u003ccode\u003e@​JarvisCraft\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5633\"\u003ejunit-team/junit-framework#5633\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Maran23\"\u003e\u003ccode\u003e@​Maran23\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5644\"\u003ejunit-team/junit-framework#5644\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eJUnit 6.1.0-RC1 = Platform 6.1.0-RC1 + Jupiter 6.1.0-RC1 + Vintage 6.1.0-RC1\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0-RC1/release-notes/\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mariokhoury4\"\u003e\u003ccode\u003e@​mariokhoury4\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/4574\"\u003ejunit-team/junit-framework#4574\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Ogu1208\"\u003e\u003ccode\u003e@​Ogu1208\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5145\"\u003ejunit-team/junit-framework#5145\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/HyungGeun94\"\u003e\u003ccode\u003e@​HyungGeun94\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5271\"\u003ejunit-team/junit-framework#5271\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yalishevant\"\u003e\u003ccode\u003e@​yalishevant\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5316\"\u003ejunit-team/junit-framework#5316\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JINU-CHANG\"\u003e\u003ccode\u003e@​JINU-CHANG\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5290\"\u003ejunit-team/junit-framework#5290\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jaschdoc\"\u003e\u003ccode\u003e@​jaschdoc\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5427\"\u003ejunit-team/junit-framework#5427\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kawshikbuet17\"\u003e\u003ccode\u003e@​kawshikbuet17\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5561\"\u003ejunit-team/junit-framework#5561\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/msridhar\"\u003e\u003ccode\u003e@​msridhar\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5602\"\u003ejunit-team/junit-framework#5602\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.1.0-M1...r6.1.0-RC1\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.1.0-M1...r6.1.0-RC1\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eJUnit 6.1.0-M1 = Platform 6.1.0-M1 + Jupiter 6.1.0-M1 + Vintage 6.1.0-M1\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0-M1/release-notes/\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vy\"\u003e\u003ccode\u003e@​vy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5041\"\u003ejunit-team/junit-framework#5041\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Pankraz76\"\u003e\u003ccode\u003e@​Pankraz76\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5006\"\u003ejunit-team/junit-framework#5006\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/arukiidou\"\u003e\u003ccode\u003e@​arukiidou\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5066\"\u003ejunit-team/junit-framework#5066\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/laeubi\"\u003e\u003ccode\u003e@​laeubi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5092\"\u003ejunit-team/junit-framework#5092\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jihun4452\"\u003e\u003ccode\u003e@​jihun4452\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5088\"\u003ejunit-team/junit-framework#5088\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TWiStErRob\"\u003e\u003ccode\u003e@​TWiStErRob\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5133\"\u003ejunit-team/junit-framework#5133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.0...r6.1.0-M1\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.0.0...r6.1.0-M1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0dc3af1cb1973d257b5bc75d81e02454d5e4e556\"\u003e\u003ccode\u003e0dc3af1\u003c/code\u003e\u003c/a\u003e Release 6.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/1d130020c85170edcb46ce7ed1f7f78824e37c04\"\u003e\u003ccode\u003e1d13002\u003c/code\u003e\u003c/a\u003e Prepare 6.1.0 release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/072b2175bbd7b0b3b26f5d928550ec7a21e68268\"\u003e\u003ccode\u003e072b217\u003c/code\u003e\u003c/a\u003e Update plugin spotless to v8.5.0 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5668\"\u003e#5668\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/3a53480218f4b752a9ca77506e10632cd483c0f8\"\u003e\u003ccode\u003e3a53480\u003c/code\u003e\u003c/a\u003e Update Gradle to v9.5.1 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5666\"\u003e#5666\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0e18a20a9f98d063ae02b3ba19329143f5c7f034\"\u003e\u003ccode\u003e0e18a20\u003c/code\u003e\u003c/a\u003e Update zizmorcore/zizmor-action action to v0.5.4 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5669\"\u003e#5669\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0a2634fb9cbbd057b02cf629d7d272c16d62be4b\"\u003e\u003ccode\u003e0a2634f\u003c/code\u003e\u003c/a\u003e Update github/codeql-action action to v4.35.5 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5671\"\u003e#5671\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/4dbd5561b00ac761a62c516bfaec51c212a2d60c\"\u003e\u003ccode\u003e4dbd556\u003c/code\u003e\u003c/a\u003e Restructure workflows to have single \u0026quot;status\u0026quot; job (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5670\"\u003e#5670\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/f2194cebe377512cb0ade388c62a881a0bcf5d3e\"\u003e\u003ccode\u003ef2194ce\u003c/code\u003e\u003c/a\u003e Increase timeout to reduce flakiness\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/5c8fdd2df65b763151cccbe669ea9e1c3155efcd\"\u003e\u003ccode\u003e5c8fdd2\u003c/code\u003e\u003c/a\u003e Update dependency org.apache.groovy:groovy to v5.0.6 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5659\"\u003e#5659\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/43c6982324602582902c9bdb213fd5e007f9cf3d\"\u003e\u003ccode\u003e43c6982\u003c/code\u003e\u003c/a\u003e Update dependency org.slf4j:slf4j-jdk14 to v2.0.18 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5667\"\u003e#5667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `eu.maveniverse.maven.njord:extension3` from 0.9.6 to 0.9.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/maveniverse/njord/releases\"\u003eeu.maveniverse.maven.njord:extension3's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.9.7\u003c/h2\u003e\n\u003cp\u003eMaintenance and updates.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump org.codehaus.plexus:plexus-classworlds from 2.11.0 to 2.12.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/301\"\u003emaveniverse/njord#301\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.junit.jupiter:junit-jupiter-api from 6.0.3 to 6.1.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/300\"\u003emaveniverse/njord#300\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.mima from 2.4.43 to 2.4.44 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/298\"\u003emaveniverse/njord#298\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.maven from 3.9.15 to 3.9.16 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/297\"\u003emaveniverse/njord#297\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.ow2.asm:asm from 9.10 to 9.10.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/305\"\u003emaveniverse/njord#305\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.json:json from 20251224 to 20260522 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/304\"\u003emaveniverse/njord#304\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.maveniverseShared from 0.2.3 to 0.2.4 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/303\"\u003emaveniverse/njord#303\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDeps: parent POM 55 and others by \u003ca href=\"https://github.com/cstamas\"\u003e\u003ccode\u003e@​cstamas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/306\"\u003emaveniverse/njord#306\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/maveniverse/njord/compare/release-0.9.6...release-0.9.7\"\u003ehttps://github.com/maveniverse/njord/compare/release-0.9.6...release-0.9.7\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/b1d8216ca4e8634858babb37c2e1474b1de8889f\"\u003e\u003ccode\u003eb1d8216\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release release-0.9.7 [skip ci]\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/2ea8dd7fc5c4e54c12904c6364bd2a0c2bae5814\"\u003e\u003ccode\u003e2ea8dd7\u003c/code\u003e\u003c/a\u003e Deps: parent POM 55 and others (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/306\"\u003e#306\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/1d8212610fc034982dd9f2c2955c77abee27b651\"\u003e\u003ccode\u003e1d82126\u003c/code\u003e\u003c/a\u003e Bump version.maveniverseShared from 0.2.3 to 0.2.4 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/303\"\u003e#303\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/3f90e7e5515846ed5fcc34f62f8c7d8b582cb75f\"\u003e\u003ccode\u003e3f90e7e\u003c/code\u003e\u003c/a\u003e Bump org.json:json from 20251224 to 20260522 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/304\"\u003e#304\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/4084d479efcec09fd0c9140126e76f34e6b5e0f7\"\u003e\u003ccode\u003e4084d47\u003c/code\u003e\u003c/a\u003e Bump org.ow2.asm:asm from 9.10 to 9.10.1 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/305\"\u003e#305\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/e363ff5d85abd697f700547f9664ca55ccd9aa71\"\u003e\u003ccode\u003ee363ff5\u003c/code\u003e\u003c/a\u003e Bump version.maven from 3.9.15 to 3.9.16 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/f861a12563dc553f7568aa813baaa4a42869f8a7\"\u003e\u003ccode\u003ef861a12\u003c/code\u003e\u003c/a\u003e Bump version.mima from 2.4.43 to 2.4.44 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/298\"\u003e#298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/e337af459ea61cbd62de3b4d4276039e143f1aaa\"\u003e\u003ccode\u003ee337af4\u003c/code\u003e\u003c/a\u003e Bump org.junit.jupiter:junit-jupiter-api from 6.0.3 to 6.1.0 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/300\"\u003e#300\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/5dfc3a10fb37c92f5382bd01b94c473e32ffd109\"\u003e\u003ccode\u003e5dfc3a1\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-classworlds from 2.11.0 to 2.12.0 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/301\"\u003e#301\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/495a36dc1602d5c7a766e74a8fc2de48a958e6ca\"\u003e\u003ccode\u003e495a36d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/maveniverse/njord/compare/release-0.9.6...release-0.9.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `eu.maveniverse.maven.plugins:njord` from 0.9.6 to 0.9.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/maveniverse/njord/releases\"\u003eeu.maveniverse.maven.plugins:njord's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.9.7\u003c/h2\u003e\n\u003cp\u003eMaintenance and updates.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump org.codehaus.plexus:plexus-classworlds from 2.11.0 to 2.12.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/301\"\u003emaveniverse/njord#301\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.junit.jupiter:junit-jupiter-api from 6.0.3 to 6.1.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/300\"\u003emaveniverse/njord#300\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.mima from 2.4.43 to 2.4.44 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/298\"\u003emaveniverse/njord#298\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.maven from 3.9.15 to 3.9.16 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/297\"\u003emaveniverse/njord#297\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.ow2.asm:asm from 9.10 to 9.10.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/305\"\u003emaveniverse/njord#305\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.json:json from 20251224 to 20260522 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/304\"\u003emaveniverse/njord#304\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.maveniverseShared from 0.2.3 to 0.2.4 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/303\"\u003emaveniverse/njord#303\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDeps: parent POM 55 and others by \u003ca href=\"https://github.com/cstamas\"\u003e\u003ccode\u003e@​cstamas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/306\"\u003emaveniverse/njord#306\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/maveniverse/njord/compare/release-0.9.6...release-0.9.7\"\u003ehttps://github.com/maveniverse/njord/compare/release-0.9.6...release-0.9.7\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/b1d8216ca4e8634858babb37c2e1474b1de8889f\"\u003e\u003ccode\u003eb1d8216\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release release-0.9.7 [skip ci]\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/2ea8dd7fc5c4e54c12904c6364bd2a0c2bae5814\"\u003e\u003ccode\u003e2ea8dd7\u003c/code\u003e\u003c/a\u003e Deps: parent POM 55 and others (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/306\"\u003e#306\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/1d8212610fc034982dd9f2c2955c77abee27b651\"\u003e\u003ccode\u003e1d82126\u003c/code\u003e\u003c/a\u003e Bump version.maveniverseShared from 0.2.3 to 0.2.4 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/303\"\u003e#303\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/3f90e7e5515846ed5fcc34f62f8c7d8b582cb75f\"\u003e\u003ccode\u003e3f90e7e\u003c/code\u003e\u003c/a\u003e Bump org.json:json from 20251224 to 20260522 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/304\"\u003e#304\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/4084d479efcec09fd0c9140126e76f34e6b5e0f7\"\u003e\u003ccode\u003e4084d47\u003c/code\u003e\u003c/a\u003e Bump org.ow2.asm:asm from 9.10 to 9.10.1 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/305\"\u003e#305\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/e363ff5d85abd697f700547f9664ca55ccd9aa71\"\u003e\u003ccode\u003ee363ff5\u003c/code\u003e\u003c/a\u003e Bump version.maven from 3.9.15 to 3.9.16 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/f861a12563dc553f7568aa813baaa4a42869f8a7\"\u003e\u003ccode\u003ef861a12\u003c/code\u003e\u003c/a\u003e Bump version.mima from 2.4.43 to 2.4.44 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/298\"\u003e#298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/e337af459ea61cbd62de3b4d4276039e143f1aaa\"\u003e\u003ccode\u003ee337af4\u003c/code\u003e\u003c/a\u003e Bump org.junit.jupiter:junit-jupiter-api from 6.0.3 to 6.1.0 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/300\"\u003e#300\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/5dfc3a10fb37c92f5382bd01b94c473e32ffd109\"\u003e\u003ccode\u003e5dfc3a1\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-classworlds from 2.11.0 to 2.12.0 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/301\"\u003e#301\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/495a36dc1602d5c7a766e74a8fc2de48a958e6ca\"\u003e\u003ccode\u003e495a36d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/maveniverse/njord/compare/release-0.9.6...release-0.9.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.maven.extensions:maven-build-cache-extension` from 1.2.2 to 1.2.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/apache/maven-build-cache-extension/releases\"\u003eorg.apache.maven.extensions:maven-build-cache-extension's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.3\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e🚀 New features and improvements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIssue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/336\"\u003e#336\u003c/a\u003e Add command line flag to override maxBuildsCached (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/489\"\u003e#489\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/MBUILDCACHE-73\"\u003e[MBUILDCACHE-73]\u003c/a\u003e - Allow arbitrary expressions as additional reconcilation properties (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/416\"\u003e#416\u003c/a\u003e) \u003ca href=\"https://github.com/pdudits\"\u003e\u003ccode\u003e@​pdudits\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/480\"\u003e#480\u003c/a\u003e - execute blocking hostname resolution asynchronously and implement timeout and caching (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/481\"\u003e#481\u003c/a\u003e) \u003ca href=\"https://github.com/marcuslinke\"\u003e\u003ccode\u003e@​marcuslinke\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDo not read a JAR completely into a byte-array before computing the SHA (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/470\"\u003e#470\u003c/a\u003e) \u003ca href=\"https://github.com/jvdvegt\"\u003e\u003ccode\u003e@​jvdvegt\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Test Only] Comprehensive test coverage (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/462\"\u003e#462\u003c/a\u003e) \u003ca href=\"https://github.com/AlexanderAshitkin\"\u003e\u003ccode\u003e@​AlexanderAshitkin\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOnly set the project artifact if it is the actual JAR (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/453\"\u003e#453\u003c/a\u003e) \u003ca href=\"https://github.com/mensinda\"\u003e\u003ccode\u003e@​mensinda\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/423\"\u003e#423\u003c/a\u003e — include declared input files in cache checksum for pom-packaged modules (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/482\"\u003e#482\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix issue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/463\"\u003e#463\u003c/a\u003e Unexpected cache miss due to previously downloaded remote cache entry with skipTests (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/472\"\u003e#472\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIssue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/345\"\u003e#345\u003c/a\u003e fix possible NPE with Intellij (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/473\"\u003e#473\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTest-jar type dependencies fail to be resolved during checksum calculation with -f builds (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/468\"\u003e#468\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix for issue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/450\"\u003e#450\u003c/a\u003e - fixed CacheUtils.unzip to properly restore unix permissions on file systems that support it (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/451\"\u003e#451\u003c/a\u003e) \u003ca href=\"https://github.com/eyforia\"\u003e\u003ccode\u003e@​eyforia\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📝 Documentation updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocumentation fixes and updates (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/460\"\u003e#460\u003c/a\u003e) \u003ca href=\"https://github.com/AlexanderAshitkin\"\u003e\u003ccode\u003e@​AlexanderAshitkin\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e👻 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFinish breaking dependency on org.apache.http in RemoteCacheRepositoryImpl (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/441\"\u003e#441\u003c/a\u003e) \u003ca href=\"https://github.com/elharo\"\u003e\u003ccode\u003e@​elharo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove undeclared NotNull annotations (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/440\"\u003e#440\u003c/a\u003e) \u003ca href=\"https://github.com/elharo\"\u003e\u003ccode\u003e@​elharo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFill in two more used dependencies SLF4J and sisu.plexus (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/438\"\u003e#438\u003c/a\u003e) \u003ca href=\"https://github.com/elharo\"\u003e\u003ccode\u003e@​elharo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🚦 Tests\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix findFirstMainSourceFile to skip invoker test projects (src/it/) in p12 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/474\"\u003e#474\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Test Only] Comprehensive test coverage (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/462\"\u003e#462\u003c/a\u003e) \u003ca href=\"https://github.com/AlexanderAshitkin\"\u003e\u003ccode\u003e@​AlexanderAshitkin\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📦 Dependency updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate 48 and Maven 3.9.16 (in Maven 3 profile) (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/490\"\u003e#490\u003c/a\u003e) \u003ca href=\"https://github.com/Bukama\"\u003e\u003ccode\u003e@​Bukama\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump com.github.tomakehurst:wiremock-jre8 from 2.35.2 to 3.0.1 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/485\"\u003e#485\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-invoker-plugin from 3.10.0 to 3.10.1 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/484\"\u003e#484\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump com.google.guava:guava from 30.1.1-jre to 32.0.0-jre in /src/test/projects/reference-test-projects/p06-dep-edge-cases/bom-b (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/464\"\u003e#464\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.junit:junit-bom from 5.14.3 to 5.14.4 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/479\"\u003e#479\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.commons:commons-lang3 from 3.14.0 to 3.18.0 in /src/test/projects/reference-test-projects/p18-maven4-native/platform-bom (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/465\"\u003e#465\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-invoker-plugin from 3.9.1 to 3.10.0 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/478\"\u003e#478\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump commons-io:commons-io from 2.21.0 to 2.22.0 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/477\"\u003e#477\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.testcontainers:testcontainers-bom from 2.0.4 to 2.0.5 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/476\"\u003e#476\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump com.fasterxml.jackson.core:jackson-annotations from 2.15.4 to 2.21 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/475\"\u003e#475\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.testcontainers:testcontainers-bom from 2.0.3 to 2.0.4 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/466\"\u003e#466\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump resolverVersion from 1.9.26 to 1.9.27 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/459\"\u003e#459\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump resolverVersion from 1.9.25 to 1.9.26 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/458\"\u003e#458\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.junit:junit-bom from 5.14.2 to 5.14.3 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/457\"\u003e#457\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/f9f25d2f6acd78238471f7f36e1efe93fb8b7e50\"\u003e\u003ccode\u003ef9f25d2\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release maven-build-cache-extension-1.2.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/7bd513b6515e526554067386d2d4b1e67fb7e2cb\"\u003e\u003ccode\u003e7bd513b\u003c/code\u003e\u003c/a\u003e Update 48 and Maven 3.9.16 (in Maven 3 profile) (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/490\"\u003e#490\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/ada66d445c228ba9abe52e42632fc237af38f89f\"\u003e\u003ccode\u003eada66d4\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/336\"\u003e#336\u003c/a\u003e Add command line flag to override maxBuildsCached (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/489\"\u003e#489\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/c915399e169c6c3633b4a12be0fc1e9579114f50\"\u003e\u003ccode\u003ec915399\u003c/code\u003e\u003c/a\u003e [MBUILDCACHE-73] Allow arbitrary expressions as additional reconcilation prop...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/0b7d080ffca2a32c892208bbfafbd18b9dd32a92\"\u003e\u003ccode\u003e0b7d080\u003c/code\u003e\u003c/a\u003e Bump com.github.tomakehurst:wiremock-jre8 from 2.35.2 to 3.0.1 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/485\"\u003e#485\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/051a319a8f063ea59f97709186e8966e2969a1e4\"\u003e\u003ccode\u003e051a319\u003c/code\u003e\u003c/a\u003e Only set the project artifact if it is the actual JAR (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/453\"\u003e#453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/6a48e056a89316d5c3a007098cd32aa9aa5e1a5e\"\u003e\u003ccode\u003e6a48e05\u003c/code\u003e\u003c/a\u003e Bump org.apache.maven.plugins:maven-invoker-plugin from 3.10.0 to 3.10.1 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/484\"\u003e#484\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/5032c5d805f4071d34ecea96f40d80117369654a\"\u003e\u003ccode\u003e5032c5d\u003c/code\u003e\u003c/a\u003e fix: \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/480\"\u003e#480\u003c/a\u003e - execute blocking hostname resolution asynchronously and implement...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/dc7069f9e25acfafa6cc41ebba48bcbe43e5bc4b\"\u003e\u003ccode\u003edc7069f\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/423\"\u003e#423\u003c/a\u003e add an IT and a fix (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/482\"\u003e#482\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/929bed8890bc43128818277c13b6f8c1c05e5f8c\"\u003e\u003ccode\u003e929bed8\u003c/code\u003e\u003c/a\u003e Bump com.google.guava:guava\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/apache/maven-build-cache-extension/compare/maven-build-cache-extension-1.2.2...maven-build-cache-extension-1.2.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `eu.maveniverse.maven.plugins:njord` from 0.9.6 to 0.9.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/maveniverse/njord/releases\"\u003eeu.maveniverse.maven.plugins:njord's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.9.7\u003c/h2\u003e\n\u003cp\u003eMaintenance and updates.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump org.codehaus.plexus:plexus-classworlds from 2.11.0 to 2.12.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/301\"\u003emaveniverse/njord#301\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.junit.jupiter:junit-jupiter-api from 6.0.3 to 6.1.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/300\"\u003emaveniverse/njord#300\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.mima from 2.4.43 to 2.4.44 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/298\"\u003emaveniverse/njord#298\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.maven from 3.9.15 to 3.9.16 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/297\"\u003emaveniverse/njord#297\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.ow2.asm:asm from 9.10 to 9.10.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pul...\n\n_Description has been truncated_","html_url":"https://github.com/jetty/jetty.project/pull/15208","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/jetty%2Fjetty.project/issues/15208","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/15208/packages"},{"uuid":"4544795993","node_id":"PR_kwDOB20KpM7gdL_8","number":2755,"state":"closed","title":"Bump the dependencies group across 1 directory with 12 updates","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-06-01T01:13:35.000Z","author_association":null,"state_reason":null,"created_at":"2026-05-29T00:47:11.000Z","updated_at":"2026-06-01T01:13:37.000Z","time_to_close":260784,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"dependencies","update_count":12,"packages":[{"name":"org.ow2.asm:asm","old_version":"9.10","new_version":"9.10.1"},{"name":"org.ow2.asm:asm-commons","old_version":"9.10","new_version":"9.10.1"},{"name":"org.ow2.asm:asm-tree","old_version":"9.10","new_version":"9.10.1"},{"name":"org.ow2.asm:asm-util","old_version":"9.10","new_version":"9.10.1"},{"name":"com.sun.xml.bind:jaxb-core","old_version":"4.0.8","new_version":"4.0.9"},{"name":"com.sun.xml.bind:jaxb-impl","old_version":"4.0.8","new_version":"4.0.9"},{"name":"com.sun.xml.bind:jaxb-xjc","old_version":"4.0.8","new_version":"4.0.9"},{"name":"org.eclipse.parsson:parsson","old_version":"1.1.7","new_version":"1.1.9","repository_url":"https://github.com/eclipse-ee4j/parsson"},{"name":"org.mongodb:mongodb-driver-sync","old_version":"5.7.0","new_version":"5.8.0","repository_url":"https://github.com/mongodb/mongo-java-driver"},{"name":"com.oracle.nosql.sdk:nosqldriver","old_version":"5.4.21","new_version":"5.4.22","repository_url":"https://github.com/oracle/nosql-java-sdk"},{"name":"ch.qos.logback:logback-core","old_version":"1.5.32","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"},{"name":"ch.qos.logback:logback-classic","old_version":"1.5.32","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"}],"path":null,"ecosystem":"maven"},"body":"Bumps the dependencies group with 12 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| org.ow2.asm:asm | `9.10` | `9.10.1` |\n| org.ow2.asm:asm-commons | `9.10` | `9.10.1` |\n| org.ow2.asm:asm-tree | `9.10` | `9.10.1` |\n| org.ow2.asm:asm-util | `9.10` | `9.10.1` |\n| com.sun.xml.bind:jaxb-core | `4.0.8` | `4.0.9` |\n| com.sun.xml.bind:jaxb-impl | `4.0.8` | `4.0.9` |\n| com.sun.xml.bind:jaxb-xjc | `4.0.8` | `4.0.9` |\n| [org.eclipse.parsson:parsson](https://github.com/eclipse-ee4j/parsson) | `1.1.7` | `1.1.9` |\n| [org.mongodb:mongodb-driver-sync](https://github.com/mongodb/mongo-java-driver) | `5.7.0` | `5.8.0` |\n| [com.oracle.nosql.sdk:nosqldriver](https://github.com/oracle/nosql-java-sdk) | `5.4.21` | `5.4.22` |\n| [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) | `1.5.32` | `1.5.33` |\n| [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) | `1.5.32` | `1.5.33` |\n\n\nUpdates `org.ow2.asm:asm` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-commons` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-tree` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-util` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-commons` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-tree` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-util` from 9.10 to 9.10.1\n\nUpdates `com.sun.xml.bind:jaxb-core` from 4.0.8 to 4.0.9\n\nUpdates `com.sun.xml.bind:jaxb-impl` from 4.0.8 to 4.0.9\n\nUpdates `com.sun.xml.bind:jaxb-xjc` from 4.0.8 to 4.0.9\n\nUpdates `com.sun.xml.bind:jaxb-impl` from 4.0.8 to 4.0.9\n\nUpdates `com.sun.xml.bind:jaxb-xjc` from 4.0.8 to 4.0.9\n\nUpdates `org.eclipse.parsson:parsson` from 1.1.7 to 1.1.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/eclipse-ee4j/parsson/releases\"\u003eorg.eclipse.parsson:parsson's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.1.9\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePublish Central releases automatically by \u003ca href=\"https://github.com/jbescos\"\u003e\u003ccode\u003e@​jbescos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/171\"\u003eeclipse-ee4j/parsson#171\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/eclipse-ee4j/parsson/compare/1.1.8...1.1.9\"\u003ehttps://github.com/eclipse-ee4j/parsson/compare/1.1.8...1.1.9\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.1.8\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate deprecated GH actions by \u003ca href=\"https://github.com/jbescos\"\u003e\u003ccode\u003e@​jbescos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/136\"\u003eeclipse-ee4j/parsson#136\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMake JsonArrayImpl implement RandomAccess by \u003ca href=\"https://github.com/marschall\"\u003e\u003ccode\u003e@​marschall\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/135\"\u003eeclipse-ee4j/parsson#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplement JsonStructureParser.currentEvent() by \u003ca href=\"https://github.com/marschall\"\u003e\u003ccode\u003e@​marschall\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/134\"\u003eeclipse-ee4j/parsson#134\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove unused method by \u003ca href=\"https://github.com/pzygielo\"\u003e\u003ccode\u003e@​pzygielo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/137\"\u003eeclipse-ee4j/parsson#137\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRename parameter to match field by \u003ca href=\"https://github.com/pzygielo\"\u003e\u003ccode\u003e@​pzygielo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/138\"\u003eeclipse-ee4j/parsson#138\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplement JsonStructureParser#getValue methods by \u003ca href=\"https://github.com/marschall\"\u003e\u003ccode\u003e@​marschall\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/140\"\u003eeclipse-ee4j/parsson#140\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse assertThrows by \u003ca href=\"https://github.com/marschall\"\u003e\u003ccode\u003e@​marschall\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/142\"\u003eeclipse-ee4j/parsson#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix compilation failes by \u003ca href=\"https://github.com/marschall\"\u003e\u003ccode\u003e@​marschall\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/144\"\u003eeclipse-ee4j/parsson#144\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdding Dependabot for dependency management by \u003ca href=\"https://github.com/mswatosh\"\u003e\u003ccode\u003e@​mswatosh\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/148\"\u003eeclipse-ee4j/parsson#148\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ejson input size limit by \u003ca href=\"https://github.com/jbescos\"\u003e\u003ccode\u003e@​jbescos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/169\"\u003eeclipse-ee4j/parsson#169\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd Maven Central publishing release profile by \u003ca href=\"https://github.com/jbescos\"\u003e\u003ccode\u003e@​jbescos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/170\"\u003eeclipse-ee4j/parsson#170\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marschall\"\u003e\u003ccode\u003e@​marschall\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/135\"\u003eeclipse-ee4j/parsson#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mswatosh\"\u003e\u003ccode\u003e@​mswatosh\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/148\"\u003eeclipse-ee4j/parsson#148\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/eclipse-ee4j/parsson/compare/1.1.7...1.1.8\"\u003ehttps://github.com/eclipse-ee4j/parsson/compare/1.1.7...1.1.8\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/f7204e83adb07bfe9f722bbd914dc680b1071114\"\u003e\u003ccode\u003ef7204e8\u003c/code\u003e\u003c/a\u003e Prepare release org.eclipse.parsson:project:1.1.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/2d01f006047e05cef49d13abe5ab25d66108f71a\"\u003e\u003ccode\u003e2d01f00\u003c/code\u003e\u003c/a\u003e Publish Central releases automatically (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/171\"\u003e#171\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/10920a209563d8a0ac13ca3d41e3c6066367835f\"\u003e\u003ccode\u003e10920a2\u003c/code\u003e\u003c/a\u003e Add Maven Central publishing release profile (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/170\"\u003e#170\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c\"\u003e\u003ccode\u003e134e8d1\u003c/code\u003e\u003c/a\u003e json input size limit (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/169\"\u003e#169\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/0789993205ee613ad63710bd3eafb96cd97afbde\"\u003e\u003ccode\u003e0789993\u003c/code\u003e\u003c/a\u003e Adding Dependabot for dependency management (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/148\"\u003e#148\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/216b15d0e9231546fa542467f9a3732973619b26\"\u003e\u003ccode\u003e216b15d\u003c/code\u003e\u003c/a\u003e Fix compilation failes (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/144\"\u003e#144\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/34177db697ee56f8e7a41f6b5998404681baf251\"\u003e\u003ccode\u003e34177db\u003c/code\u003e\u003c/a\u003e Use assertThrows (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/142\"\u003e#142\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/9d6796013c7a526c7ac80edd690e16bb4a186dd4\"\u003e\u003ccode\u003e9d67960\u003c/code\u003e\u003c/a\u003e Implement JsonStructureParser#getValue methods (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/140\"\u003e#140\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/7c8c2444c61b6b1f44c2c2f36e6ebf905b2c7624\"\u003e\u003ccode\u003e7c8c244\u003c/code\u003e\u003c/a\u003e Rename parameter to match field (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/138\"\u003e#138\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/4dda2e0195dcde4f11eda1c31c642d84eda50ae5\"\u003e\u003ccode\u003e4dda2e0\u003c/code\u003e\u003c/a\u003e Remove unused method (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/137\"\u003e#137\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/eclipse-ee4j/parsson/compare/1.1.7...1.1.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.mongodb:mongodb-driver-sync` from 5.7.0 to 5.8.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mongodb/mongo-java-driver/releases\"\u003eorg.mongodb:mongodb-driver-sync's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eJava Driver 5.8.0 (May 28, 2026)\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003e🔥 Enhancements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded typed builder API for vector search index definitions \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1960\"\u003e#1960\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003e$rerank\u003c/code\u003e aggregation stage support (MongoDB 8.3 / Atlas) \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1963\"\u003e#1963\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003evectorSearch\u003c/code\u003e operator support for the \u003ccode\u003e$search\u003c/code\u003e pipeline stage \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1962\"\u003e#1962\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003estoredSource\u003c/code\u003e support for vector search indexes and \u003ccode\u003ereturnStoredSource\u003c/code\u003e for \u003ccode\u003e$vectorSearch\u003c/code\u003e queries \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1977\"\u003e#1977\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eBinaryVector\u003c/code\u003e and \u003ccode\u003eVectorSearchQuery\u003c/code\u003e \u003ccode\u003evectorSearch\u003c/code\u003e overloads to the Scala driver \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1986\"\u003e#1986\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eOptimized \u003ccode\u003eRawBsonDocument\u003c/code\u003e encode and decode by eliminating intermediate allocations \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1988\"\u003e#1988\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePreliminary refactoring for backpressure support \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1952\"\u003e#1952\u003c/a\u003e by \u003ca href=\"https://github.com/stIncMale\"\u003e\u003ccode\u003e@​stIncMale\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSmall improvements related to value-based classes \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1964\"\u003e#1964\u003c/a\u003e by \u003ca href=\"https://github.com/stIncMale\"\u003e\u003ccode\u003e@​stIncMale\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🛠 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed OSGi bundle resolution failure when Micrometer is not present \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1982\"\u003e#1982\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded missing Javadoc to \u003ccode\u003eMongodbObservation\u003c/code\u003e and \u003ccode\u003eMongodbObservationContext\u003c/code\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e📦 Dependency Updates\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpgraded \u003ccode\u003elibmongocrypt\u003c/code\u003e to 1.18.1 \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1983\"\u003e#1983\u003c/a\u003e by \u003ca href=\"https://github.com/strogiyotec\"\u003e\u003ccode\u003e@​strogiyotec\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🧪 Testing \u0026amp; CI\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003eAGENTS.md\u003c/code\u003e for AI coding agent support across all modules by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded test cases for new auto-embedding index fields \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1936\"\u003e#1936\u003c/a\u003e by \u003ca href=\"https://github.com/strogiyotec\"\u003e\u003ccode\u003e@​strogiyotec\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded Scala 3 to \u003ccode\u003epublish.sh\u003c/code\u003e \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1958\"\u003e#1958\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eNamespaceExists\u003c/code\u003e test failure \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1956\"\u003e#1956\u003c/a\u003e by \u003ca href=\"https://github.com/nhachicha\"\u003e\u003ccode\u003e@​nhachicha\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSimplified \u003ccode\u003eRetryState\u003c/code\u003e creation as preliminary backpressure work \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1961\"\u003e#1961\u003c/a\u003e by \u003ca href=\"https://github.com/stIncMale\"\u003e\u003ccode\u003e@​stIncMale\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMade \u003ccode\u003eRetryState.isLastAttempt\u003c/code\u003e private and simplified code \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1967\"\u003e#1967\u003c/a\u003e by \u003ca href=\"https://github.com/stIncMale\"\u003e\u003ccode\u003e@​stIncMale\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/techbelle\"\u003e\u003ccode\u003e@​techbelle\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1972\"\u003emongodb/mongo-java-driver#1972\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVerifying artifact signatures\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://www.mongodb.com/docs/drivers/java/sync/current/security/validate-signatures/\"\u003ehttps://www.mongodb.com/docs/drivers/java/sync/current/security/validate-signatures/\u003c/a\u003e for the full procedure.\u003c/p\u003e\n\u003cp\u003eTo download and import the public key for verifying signatures, execute\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003egpg --keyserver hkps://keyserver.ubuntu.com --recv-keys 1a75005e142192223d6a7c3b76e0008d166740a8\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/mongodb/mongo-java-driver/compare/r5.7.0...r5.8.0\"\u003ehttps://github.com/mongodb/mongo-java-driver/compare/r5.7.0...r5.8.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/6024ca9f6ca226cffb7526659b19810707970310\"\u003e\u003ccode\u003e6024ca9\u003c/code\u003e\u003c/a\u003e Version: bump 5.8.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/f3bbdb2701b8c462c64db4c5f3f2c61b23b723e9\"\u003e\u003ccode\u003ef3bbdb2\u003c/code\u003e\u003c/a\u003e Add BinaryVector and VectorSearchQuery vectorSearch overloads to Scala driver...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/966ababa45a5d38a644bc8e8ce8de58eb882dd66\"\u003e\u003ccode\u003e966abab\u003c/code\u003e\u003c/a\u003e Upgrade libmongocrypt version to 1.18.1 (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/1983\"\u003e#1983\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/98e07611f0f0c3e22d89cfb766137e59ab7b2a2f\"\u003e\u003ccode\u003e98e0761\u003c/code\u003e\u003c/a\u003e Optimize RawBsonDocument encode and decode by eliminating intermediate alloca...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/40ee8d511e4541727de2edc4527d209d842fd607\"\u003e\u003ccode\u003e40ee8d5\u003c/code\u003e\u003c/a\u003e Fix NamespaceExists test failure (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/1956\"\u003e#1956\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/541af753642b070a04ec64f54b9af018d297c2d3\"\u003e\u003ccode\u003e541af75\u003c/code\u003e\u003c/a\u003e Mark micrometer OSGi imports as optional and add bundle resolution test (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/1982\"\u003e#1982\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/cd6c045cf866d6d5038fcbcf8825742174a3903a\"\u003e\u003ccode\u003ecd6c045\u003c/code\u003e\u003c/a\u003e Add storedSource support for vector search indexes and returnStoredSource for...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/717da9c63b5531e35e684bc0a8043500b3fa7560\"\u003e\u003ccode\u003e717da9c\u003c/code\u003e\u003c/a\u003e Revert \u0026quot;Resolve TLS channel address before opening socket\u0026quot; (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/1979\"\u003e#1979\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/58122f6b280cda429af25f69e3692132e1eabb60\"\u003e\u003ccode\u003e58122f6\u003c/code\u003e\u003c/a\u003e Add vectorSearch operator for $search pipeline stage (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/1962\"\u003e#1962\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/13d4aef5f58283977042340ee8d7d9af4a1786d4\"\u003e\u003ccode\u003e13d4aef\u003c/code\u003e\u003c/a\u003e Resolve TLS channel address before opening socket\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mongodb/mongo-java-driver/compare/r5.7.0...r5.8.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.oracle.nosql.sdk:nosqldriver` from 5.4.21 to 5.4.22\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/oracle/nosql-java-sdk/releases\"\u003ecom.oracle.nosql.sdk:nosqldriver's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e5.4.22\u003c/h2\u003e\n\u003ch2\u003e[5.4.22] 2026-05-15\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded redaction of sensitive HTTP header values in debug logging by default,\nplus the \u003ccode\u003ecom.oracle.nosql.sdk.nosqldriver.log-sensitive-headers\u003c/code\u003e system\nproperty to allow full header values when needed for debugging.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed bug in handling of empty namespaces in prepared statements.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated Netty version to 4.1.133.Final\u003c/li\u003e\n\u003cli\u003eUpdated Jackson-core to 2.18.7\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/oracle/nosql-java-sdk/blob/main/CHANGELOG.md\"\u003ecom.oracle.nosql.sdk:nosqldriver's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[5.4.22] 2026-05-15\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded redaction of sensitive HTTP header values in debug logging by default,\nplus the \u003ccode\u003ecom.oracle.nosql.sdk.nosqldriver.log-sensitive-headers\u003c/code\u003e system\nproperty to allow full header values when needed for debugging.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed bug in handling of empty namespaces in prepared statements.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated Netty version to 4.1.133.Final\u003c/li\u003e\n\u003cli\u003eUpdated Jackson-core to 2.18.7\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/801ba4070febb5c0e870ab8cdb5ee7938831a545\"\u003e\u003ccode\u003e801ba40\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/oracle/nosql-java-sdk/issues/204\"\u003e#204\u003c/a\u003e from oracle/fix/netty-4.1.133\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/d7c7ed22b8c9437041dc473577d899dcf984db31\"\u003e\u003ccode\u003ed7c7ed2\u003c/code\u003e\u003c/a\u003e additional changes for 5.4.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/e27f8f7c19a457ebdb8cd8130db61f75064ccc43\"\u003e\u003ccode\u003ee27f8f7\u003c/code\u003e\u003c/a\u003e update 3rd parties\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/0c21037e61f44fac98af2e52b2506c3a0bcb9028\"\u003e\u003ccode\u003e0c21037\u003c/code\u003e\u003c/a\u003e Handle null or empty namespace list in prepared statements (\u003ca href=\"https://redirect.github.com/oracle/nosql-java-sdk/issues/200\"\u003e#200\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/b81457b2e65e323c30cda83d6ce7cee8cb771a83\"\u003e\u003ccode\u003eb81457b\u003c/code\u003e\u003c/a\u003e Moving to 5.4.22-SNAPSHOT (\u003ca href=\"https://redirect.github.com/oracle/nosql-java-sdk/issues/199\"\u003e#199\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/6248e8b0d53c269a888bc335faeede7c5619f323\"\u003e\u003ccode\u003e6248e8b\u003c/code\u003e\u003c/a\u003e implemented UNION (and a few other query operators) (\u003ca href=\"https://redirect.github.com/oracle/nosql-java-sdk/issues/184\"\u003e#184\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/d09ae8bbcdd1ae459d80ad269c2ef1ff33ed65cd\"\u003e\u003ccode\u003ed09ae8b\u003c/code\u003e\u003c/a\u003e Cleaned up compiler warnings\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/7f8a40f0c92b0a63e7c2d81f65daa03971b2b38d\"\u003e\u003ccode\u003e7f8a40f\u003c/code\u003e\u003c/a\u003e Redact sensitive HTTP headers in debug logging (\u003ca href=\"https://redirect.github.com/oracle/nosql-java-sdk/issues/198\"\u003e#198\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/4a3e9e5298a11450a9fe85a5857c2a0e75686c2a\"\u003e\u003ccode\u003e4a3e9e5\u003c/code\u003e\u003c/a\u003e Preparing for 5.4.21 release (\u003ca href=\"https://redirect.github.com/oracle/nosql-java-sdk/issues/196\"\u003e#196\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/oracle/nosql-java-sdk/compare/v5.4.21...v5.4.22\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ch.qos.logback:logback-core` from 1.5.32 to 1.5.33\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ch.qos.logback:logback-classic` from 1.5.32 to 1.5.33\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-classic's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ch.qos.logback:logback-classic` from 1.5.32 to 1.5.33\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-classic's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/eclipse-ee4j/eclipselink/pull/2755","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/eclipse-ee4j%2Feclipselink/issues/2755","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2755/packages"},{"uuid":"4538035108","node_id":"PR_kwDOHk7hlc7gHCcO","number":900,"state":"closed","title":"chore(deps): bump ch.qos.logback:logback-core from 1.5.24 to 1.5.33","user":"dependabot[bot]","labels":["dependencies"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-06-04T05:42:22.000Z","author_association":null,"state_reason":null,"created_at":"2026-05-28T05:47:04.000Z","updated_at":"2026-06-04T05:42:24.000Z","time_to_close":604518,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.5.24","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"}],"path":null,"ecosystem":"maven"},"body":"Bumps [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) from 1.5.24 to 1.5.33.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.32\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-16 Release of logback version 1.5.32\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In \u003ccode\u003eDefaultProcessor, \u003c/code\u003efixed incorrect check for dependencies contained within a parent model. Previous only the direct children were scanned. This fixes \u003ca href=\"https://redirect.github.com/qos-ch/logback-access/issues/34\"\u003elogback-access/issues/34\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit e807335a67535b4eacce94e942c0bcb649665d93 associated with the tag v_1.5.32. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback  1.5.31\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback version 1.5.31\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fixed missing META-INF/services directory in logback-classic.jar. This issue rendered logback-classic version 1.5.30 unusable with SLF4J.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 168e42f9f9a18a3ffdf31eb2bfe80a71e33ecd8b associated with the tag v_1.5.31. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.30\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback  version 1.5.30\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003cstrong\u003eIn this version, logback-classic.jar was missing the META-INF/services directory, making it unusable with SLF4J. Version 1.5.31 (released later on the same day) fixes this issue.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fix scanning issue when an included file becomes available at a later time. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1021\"\u003eissues/1021\u003c/a\u003e by Sergey Nazarov.\u003c/p\u003e\n\u003cp\u003e• Standardized code for version checking across modules.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 44164f10ca3fb44ce0e68519f13564b87e3aca61 associated with the tag v_1.5.30. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.29\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-09 Release of logback version 1.5.29\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In response to \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1017\"\u003eissues/1017\u003c/a\u003e, appender names and appender references are once again subject to variable substitution, reverting the change introduced in version 1.5.28.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.28\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-06 Release of logback version 1.5.28\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Appender names or appender references are no longer subject to variable substitution.\u003c/p\u003e\n\u003cp\u003e• Fixed issue with configurations with conditionals encompassing appenders. This was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1016\"\u003eissues/1016\u003c/a\u003e reported by Sergey Sazonov.\u003c/p\u003e\n\u003cp\u003e• The \u003c!-- raw HTML omitted --\u003e element now admits a 'scan' attribute which can be used to override the 'scan' attribute in the \u003c!-- raw HTML omitted --\u003e element.\u003c/p\u003e\n\u003cp\u003e• Fixed NullPointerException thrown by VersionUtil.checkForVersionEquality method occurring with GraalVM Native Images. This issue was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1014\"\u003eissues/1014\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit e7a1855ab562bb102333f754603ff89359bf3cfc associated with the tag v_1.5.28. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.27\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-01-30 Release of logback version 1.5.27\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Updated license to Eclipse Public License version 2.0 from version 1.0, retaining the GPL 2.1 dual-license.\u003c/p\u003e\n\u003cp\u003e• Fixed missing MDC data transmitted by \u003ccode\u003eSocketAppender\u003c/code\u003e reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1010\"\u003eissues/1010\u003c/a\u003e by Lars Vogel.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.24...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=maven\u0026previous-version=1.5.24\u0026new-version=1.5.33)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/wwjiang007/shiro/pull/900","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/wwjiang007%2Fshiro/issues/900","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/900/packages"},{"uuid":"4535692638","node_id":"PR_kwDOAB81F87f_cIU","number":15176,"state":"closed","title":"[12.1.x EE8] Bump the dev-dependencies group across 1 directory with 11 updates","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-05-30T01:02:29.000Z","author_association":null,"state_reason":null,"created_at":"2026-05-27T20:59:03.000Z","updated_at":"2026-05-30T01:02:31.000Z","time_to_close":187406,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"[12.1.x EE8] Bump","group_name":"dev-dependencies","update_count":11,"packages":[{"name":"org.ow2.asm:asm","old_version":"9.10","new_version":"9.10.1"},{"name":"org.ow2.asm:asm-commons","old_version":"9.10","new_version":"9.10.1"},{"name":"org.ow2.asm:asm-bom","old_version":"9.10","new_version":"9.10.1"},{"name":"org.apache.maven.surefire:surefire-junit47","old_version":"3.5.5","new_version":"3.5.6"},{"name":"io.netty:netty-bom","old_version":"4.2.13.Final","new_version":"4.2.14.Final","repository_url":"https://github.com/netty/netty"},{"name":"org.hibernate.search:hibernate-search-bom","old_version":"8.3.1.Final","new_version":"8.4.0.Final","repository_url":"https://github.com/hibernate/hibernate-search"},{"name":"org.junit:junit-bom","old_version":"6.0.3","new_version":"6.1.0","repository_url":"https://github.com/junit-team/junit-framework"},{"name":"ch.qos.logback:logback-core","old_version":"1.5.32","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"},{"name":"org.codehaus.plexus:plexus-classworlds","old_version":"2.11.0","new_version":"2.12.0","repository_url":"https://github.com/codehaus-plexus/plexus-classworlds"},{"name":"org.apache.maven.extensions:maven-build-cache-extension","old_version":"1.2.2","new_version":"1.2.3","repository_url":"https://github.com/apache/maven-build-cache-extension"}],"path":null,"ecosystem":"maven"},"body":"Bumps the dev-dependencies group with 10 updates in the /jetty-ee8 directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| org.ow2.asm:asm | `9.10` | `9.10.1` |\n| org.ow2.asm:asm-commons | `9.10` | `9.10.1` |\n| org.ow2.asm:asm-bom | `9.10` | `9.10.1` |\n| org.apache.maven.surefire:surefire-junit47 | `3.5.5` | `3.5.6` |\n| [io.netty:netty-bom](https://github.com/netty/netty) | `4.2.13.Final` | `4.2.14.Final` |\n| [org.hibernate.search:hibernate-search-bom](https://github.com/hibernate/hibernate-search) | `8.3.1.Final` | `8.4.0.Final` |\n| [org.junit:junit-bom](https://github.com/junit-team/junit-framework) | `6.0.3` | `6.1.0` |\n| [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) | `1.5.32` | `1.5.33` |\n| [org.codehaus.plexus:plexus-classworlds](https://github.com/codehaus-plexus/plexus-classworlds) | `2.11.0` | `2.12.0` |\n| [org.apache.maven.extensions:maven-build-cache-extension](https://github.com/apache/maven-build-cache-extension) | `1.2.2` | `1.2.3` |\n\n\nUpdates `org.ow2.asm:asm` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-commons` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-bom` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-commons` from 9.10 to 9.10.1\n\nUpdates `org.apache.maven.surefire:surefire-junit47` from 3.5.5 to 3.5.6\n\nUpdates `io.netty:netty-bom` from 4.2.13.Final to 4.2.14.Final\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/netty/netty/releases\"\u003eio.netty:netty-bom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003enetty-4.2.14.Final\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHTTP: Fix revapi failure introduced by 84530fa81e12dcd1d42310bb20c1385cb44128d8 by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16748\"\u003enetty/netty#16748\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHTTP: Re-add constructor to HttpProxyHandler that was removed by mistake by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16747\"\u003enetty/netty#16747\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMarshalling: Explicit document security requirements by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16752\"\u003enetty/netty#16752\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix io_uring op completion TRACE logging by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16755\"\u003enetty/netty#16755\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eQuic: Ensure writes are done before notify close promise of QuicheQui… by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16758\"\u003enetty/netty#16758\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid re-parsing openssl key material with non-cached provider by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16759\"\u003enetty/netty#16759\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin HTTP/RTSP version + method normalization to Locale.US by \u003ca href=\"https://github.com/daguimu\"\u003e\u003ccode\u003e@​daguimu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16765\"\u003enetty/netty#16765\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFill MsgHdrMemoryArray#hdrs with null entry on release by \u003ca href=\"https://github.com/tsegismont\"\u003e\u003ccode\u003e@​tsegismont\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16764\"\u003enetty/netty#16764\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRevapi: Use default \u0026quot;oldVersion\u0026quot; by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16774\"\u003enetty/netty#16774\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdaptive: Fix concurrency issue in adaptive allocator by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16767\"\u003enetty/netty#16767\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAuto-port 4.2: Make bulk byte moving in ByteBuf faster by \u003ca href=\"https://github.com/netty-project-bot\"\u003e\u003ccode\u003e@​netty-project-bot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16781\"\u003enetty/netty#16781\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin multipart Content-Type / Content-Transfer-Encoding case folding to Locale.US by \u003ca href=\"https://github.com/daguimu\"\u003e\u003ccode\u003e@​daguimu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16768\"\u003enetty/netty#16768\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove dead native declarations by \u003ca href=\"https://github.com/pandareen\"\u003e\u003ccode\u003e@​pandareen\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16783\"\u003enetty/netty#16783\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIsolate tests that modify available Security providers by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16793\"\u003enetty/netty#16793\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove test annotations from a method that isn't a test by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16792\"\u003enetty/netty#16792\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEnable OpenSslCachingKeyMaterialProvider to evict stale entries after cert rotation by \u003ca href=\"https://github.com/zhangweikop\"\u003e\u003ccode\u003e@​zhangweikop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16523\"\u003enetty/netty#16523\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIoUring: extend user data from short to long by \u003ca href=\"https://github.com/dreamlike-ocean\"\u003e\u003ccode\u003e@​dreamlike-ocean\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16682\"\u003enetty/netty#16682\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRevert CompositeByteBuf component search fast path by \u003ca href=\"https://github.com/yawkat\"\u003e\u003ccode\u003e@​yawkat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16811\"\u003enetty/netty#16811\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHTTP2: Use 100 as default max concurrent streams setting by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16804\"\u003enetty/netty#16804\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix ResumptionController wrapping by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16815\"\u003enetty/netty#16815\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eResolve all localhost addresses without querying DNS servers by \u003ca href=\"https://github.com/JulianVennen\"\u003e\u003ccode\u003e@​JulianVennen\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16749\"\u003enetty/netty#16749\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIpFilter: Fix ClassCastException caused by IpSubnetFilter if only ipv6 rules are configured but remote peer is using ipv4 by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16803\"\u003enetty/netty#16803\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix memoryAddress() for direct ByteBuffers wrapped by Unpooled without Unsafe by \u003ca href=\"https://github.com/dreamlike-ocean\"\u003e\u003ccode\u003e@​dreamlike-ocean\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16788\"\u003enetty/netty#16788\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRoute synchronous onLookupComplete exceptions via fireExceptionCaught by \u003ca href=\"https://github.com/kwondh5217\"\u003e\u003ccode\u003e@​kwondh5217\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16794\"\u003enetty/netty#16794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIoUring: Stop generic FileRegion drain loop when transferred() reaches count() by \u003ca href=\"https://github.com/LuciferYang\"\u003e\u003ccode\u003e@​LuciferYang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16826\"\u003enetty/netty#16826\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMQTT: Allow MQTT 5 CONNECT with password only by \u003ca href=\"https://github.com/shblue21\"\u003e\u003ccode\u003e@​shblue21\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16833\"\u003enetty/netty#16833\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix MQTT decoder size check after variable header replay by \u003ca href=\"https://github.com/daguimu\"\u003e\u003ccode\u003e@​daguimu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16787\"\u003enetty/netty#16787\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pandareen\"\u003e\u003ccode\u003e@​pandareen\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16783\"\u003enetty/netty#16783\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zhangweikop\"\u003e\u003ccode\u003e@​zhangweikop\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16523\"\u003enetty/netty#16523\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JulianVennen\"\u003e\u003ccode\u003e@​JulianVennen\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16749\"\u003enetty/netty#16749\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kwondh5217\"\u003e\u003ccode\u003e@​kwondh5217\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16794\"\u003enetty/netty#16794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/shblue21\"\u003e\u003ccode\u003e@​shblue21\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16833\"\u003enetty/netty#16833\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/netty/netty/compare/netty-4.2.13.Final...netty-4.2.14.Final\"\u003ehttps://github.com/netty/netty/compare/netty-4.2.13.Final...netty-4.2.14.Final\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/0a60b753d5b0de9f58e245538d61c11dc6cfc4b2\"\u003e\u003ccode\u003e0a60b75\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release netty-4.2.14.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/72df658e5fdd1cc6d65bce1e0917ec31a9560269\"\u003e\u003ccode\u003e72df658\u003c/code\u003e\u003c/a\u003e Fix MQTT decoder size check after variable header replay (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16787\"\u003e#16787\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/7125dba6b20822aa72dd8359b350c2f3b9a545d9\"\u003e\u003ccode\u003e7125dba\u003c/code\u003e\u003c/a\u003e MQTT: Allow MQTT 5 CONNECT with password only (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16833\"\u003e#16833\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/9e19320a5855746970d05a5cd785d73a17cc694d\"\u003e\u003ccode\u003e9e19320\u003c/code\u003e\u003c/a\u003e IoUring: Stop generic FileRegion drain loop when transferred() reaches count(...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/4ce9f17f05c67b72c87bc83951800bad245fe162\"\u003e\u003ccode\u003e4ce9f17\u003c/code\u003e\u003c/a\u003e Route synchronous onLookupComplete exceptions via fireExceptionCaught (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16794\"\u003e#16794\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/f7b1b7de625031cc60e6eaecb889c97303588759\"\u003e\u003ccode\u003ef7b1b7d\u003c/code\u003e\u003c/a\u003e Fix memoryAddress() for direct ByteBuffers wrapped by Unpooled without Unsafe...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/0ccb265cadf91b2e09c2f479c9194d193d7a5dbc\"\u003e\u003ccode\u003e0ccb265\u003c/code\u003e\u003c/a\u003e IpFilter: Fix ClassCastException caused by IpSubnetFilter if only ipv6 rules ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/a6aeb6deffda3e45904edd05abc5cdddcd438794\"\u003e\u003ccode\u003ea6aeb6d\u003c/code\u003e\u003c/a\u003e Resolve all localhost addresses without querying DNS servers (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16749\"\u003e#16749\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/c328ba2ab89d2c90c80be1d2de1cfbb8f94c438b\"\u003e\u003ccode\u003ec328ba2\u003c/code\u003e\u003c/a\u003e Fix ResumptionController wrapping (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16815\"\u003e#16815\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/bc5862ba488c569c888d3b82048083041f66e880\"\u003e\u003ccode\u003ebc5862b\u003c/code\u003e\u003c/a\u003e HTTP2: Use 100 as default max concurrent streams setting (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16804\"\u003e#16804\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/netty/netty/compare/netty-4.2.13.Final...netty-4.2.14.Final\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.hibernate.search:hibernate-search-bom` from 8.3.1.Final to 8.4.0.Final\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hibernate/hibernate-search/releases\"\u003eorg.hibernate.search:hibernate-search-bom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 8.4.0.Final\u003c/h2\u003e\n\u003ch1\u003eHibernate Search 8.4.0.Final released\u003c/h1\u003e\n\u003cp\u003eWe are pleased to announce the release of Hibernate Search 8.4: 8.4.0.Final.\u003c/p\u003e\n\u003cp\u003eYou can find the full list of 8.4.0.Final changes \u003ca href=\"https://hibernate.atlassian.net/issues/?jql=project%20%3D%20HSEARCH%20AND%20fixVersion%20%3D%208.4.0.Final\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eWhat's new\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSee the \u003ca href=\"https://hibernate.org/search/releases/8.4\"\u003ewebsite\u003c/a\u003e for requirements and compatibilities.\u003c/li\u003e\n\u003cli\u003eSee the \u003ca href=\"https://docs.hibernate.org/search/8.4/whats-new/en-US/html_single/\"\u003eWhat's New\u003c/a\u003e guide for details about new features and capabilities.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eConclusion\u003c/h2\u003e\n\u003cp\u003eFor additional details, see:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe \u003ca href=\"https://hibernate.org/search/releases/8.4/\"\u003erelease page\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/migration/html_single/\"\u003eMigration Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/getting-started/orm/en-US/html_single/\"\u003eORM Getting Started Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/getting-started/standalone/en-US/html_single/\"\u003eStandalone Getting Started Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/reference/en-US/html_single/\"\u003eReference Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/api\"\u003eAPI docs\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eVisit the \u003ca href=\"https://hibernate.org/community/\"\u003ewebsite\u003c/a\u003e for details on getting in touch with us.\u003c/p\u003e\n\u003ch2\u003eRelease 8.4.0.CR1\u003c/h2\u003e\n\u003ch1\u003eHibernate Search 8.4.0.CR1 released\u003c/h1\u003e\n\u003cp\u003eWe are pleased to announce the release of Hibernate Search 8.4: 8.4.0.CR1.\u003c/p\u003e\n\u003cp\u003eYou can find the full list of 8.4.0.CR1 changes \u003ca href=\"https://hibernate.atlassian.net/issues/?jql=project%20%3D%20HSEARCH%20AND%20fixVersion%20%3D%208.4.0.CR1\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eWhat's new\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSee the \u003ca href=\"https://hibernate.org/search/releases/8.4\"\u003ewebsite\u003c/a\u003e for requirements and compatibilities.\u003c/li\u003e\n\u003cli\u003eSee the \u003ca href=\"https://docs.hibernate.org/search/8.4/whats-new/en-US/html_single/\"\u003eWhat's New\u003c/a\u003e guide for details about new features and capabilities.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eConclusion\u003c/h2\u003e\n\u003cp\u003eFor additional details, see:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe \u003ca href=\"https://hibernate.org/search/releases/8.4/\"\u003erelease page\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/migration/html_single/\"\u003eMigration Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/getting-started/orm/en-US/html_single/\"\u003eORM Getting Started Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/getting-started/standalone/en-US/html_single/\"\u003eStandalone Getting Started Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/reference/en-US/html_single/\"\u003eReference Guide\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hibernate/hibernate-search/blob/main/changelog.txt\"\u003eorg.hibernate.search:hibernate-search-bom's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.4.0.Final (2026-05-27)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://hibernate.atlassian.net/projects/HSEARCH/versions/39072\"\u003ehttps://hibernate.atlassian.net/projects/HSEARCH/versions/39072\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e** Improvement\n* HSEARCH-5630 Update to Hibernate ORM 7.4.0.Final\n* HSEARCH-5629 Use Maven 3.9.16 as a required minimum version for the build\n* HSEARCH-5627 Switch from the Search session holder to a Hibernate ORM session extension\n* HSEARCH-5626 Update Elasticsearch client (elasticsearch-rest-client) to 9.4.1\n* HSEARCH-5625 Test against latest Elasticsearch 9.4.1\n* HSEARCH-5624 Update Elasticsearch client (elasticsearch-rest5-client) to 9.4.1\u003c/p\u003e\n\u003ch2\u003e8.4.0.CR1 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://hibernate.atlassian.net/projects/HSEARCH/versions/37437\"\u003ehttps://hibernate.atlassian.net/projects/HSEARCH/versions/37437\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e** Bug\n* HSEARCH-5595 \u003ccode\u003echeckstyle:check\u003c/code\u003e is not build cache relocatable due to project resources including the workspace root\u003c/p\u003e\n\u003cp\u003e** Improvement\n* HSEARCH-5623 Update to Hibernate ORM 7.4.0.CR1\n* HSEARCH-5622 Update Elasticsearch client (elasticsearch-rest5-client) to 9.4.0\n* HSEARCH-5621 Update Elasticsearch client (elasticsearch-rest-client) to 9.4.0\n* HSEARCH-5620 Add compatibility with Elasticsearch 9.4\n* HSEARCH-5619 Upgrade to GSON 2.14.0\n* HSEARCH-5618 Update Jackson to 2.21.3\n* HSEARCH-5617 Update to AWS SDK 2.44.1\n* HSEARCH-5616 Update Elasticsearch client (elasticsearch-rest-client) to 9.3.4\n* HSEARCH-5613 Use Maven 3.9.15 as a required minimum version for the build\n* HSEARCH-5612 Upgrade to commons-codec 1.22.0\n* HSEARCH-5611 Update Apache HTTP Client components to 5.6.1\n* HSEARCH-5609 Update Elasticsearch client (elasticsearch-rest-client) to 9.3.3\n* HSEARCH-5608 Update Elasticsearch client (elasticsearch-rest5-client) to 9.3.4\n* HSEARCH-5607 Update Elasticsearch rest client (opensearch-rest-client) to 3.6.0\n* HSEARCH-5606 Add compatibility with OpenSearch 3.6\n* HSEARCH-5601 Update to commons-logging to 1.3.6\n* HSEARCH-5600 Update Jackson to 2.21.2\n* HSEARCH-5599 Update Apache HTTP Core client components to 5.4.2\n* HSEARCH-5598 Update Elasticsearch client (elasticsearch-rest-client) to 9.3.2\n* HSEARCH-5597 Update Elasticsearch client (elasticsearch-rest5-client) to 9.3.3\u003c/p\u003e\n\u003cp\u003e** Task\n* HSEARCH-5596 Use changeDetection config option instead of the deprecated overwrite in maven-resources-plugin\n* HSEARCH-5280 Look into \u003ccode\u003eOutboxPollingAutomaticIndexingDynamicShardingRebalancingIT#agentJoined\u003c/code\u003e test\n* HSEARCH-5242 Investigate why building hibernate-search-integrationtest-performance-backend-lucene fails on some envs\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/7369a18fc526aaffba13336fdcdc95a333702b19\"\u003e\u003ccode\u003e7369a18\u003c/code\u003e\u003c/a\u003e [Jenkins release job] Preparing release 8.4.0.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/4e26c085ba83c21cde89022a2f10864b08711e25\"\u003e\u003ccode\u003e4e26c08\u003c/code\u003e\u003c/a\u003e [Jenkins release job] changelog.txt updated by release build 8.4.0.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/fe410d2d5c25d9e05648f67c027441564a32be03\"\u003e\u003ccode\u003efe410d2\u003c/code\u003e\u003c/a\u003e HSEARCH-5630 Add a few migration notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/87335b65fd124493bf91ad83de78f64eafc1155c\"\u003e\u003ccode\u003e87335b6\u003c/code\u003e\u003c/a\u003e HSEARCH-5630 Update to Hibernate ORM 7.4.0.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/58d6af143d22c9ce55872c9f13c51c8dd8e03d32\"\u003e\u003ccode\u003e58d6af1\u003c/code\u003e\u003c/a\u003e HSEARCH-5624 Update Elasticsearch client (elasticsearch-rest5-client) to 9.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/9efe369fcb419ded47b3e77a02b3d84451e64853\"\u003e\u003ccode\u003e9efe369\u003c/code\u003e\u003c/a\u003e Bump the build-dependencies group with 4 updates\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/bc1c18509b22d2b1fa9e41149fbe5cf166d7f663\"\u003e\u003ccode\u003ebc1c185\u003c/code\u003e\u003c/a\u003e Use the ssh URL for updating the website during the release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/311adb00224ab04fc2c397da94cf41a373338801\"\u003e\u003ccode\u003e311adb0\u003c/code\u003e\u003c/a\u003e HSEARCH-5627 Mention limitations of a StatelessSession\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/d429b05110cf6015d70faa6278176c6b3e7defa0\"\u003e\u003ccode\u003ed429b05\u003c/code\u003e\u003c/a\u003e HSEARCH-5627 Better error message for \u0026quot;incompatible\u0026quot; session types\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/2eaeb282d9d9bc136bc32f93ca12634374e249d4\"\u003e\u003ccode\u003e2eaeb28\u003c/code\u003e\u003c/a\u003e HSEARCH-5627 Add a simple StatelessSession test\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hibernate/hibernate-search/compare/8.3.1.Final...8.4.0.Final\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.junit:junit-bom` from 6.0.3 to 6.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/junit-team/junit-framework/releases\"\u003eorg.junit:junit-bom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eJUnit 6.1.0 = Platform 6.1.0 + Jupiter 6.1.0 + Vintage 6.1.0\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0/release-notes.html\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JarvisCraft\"\u003e\u003ccode\u003e@​JarvisCraft\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5633\"\u003ejunit-team/junit-framework#5633\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Maran23\"\u003e\u003ccode\u003e@​Maran23\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5644\"\u003ejunit-team/junit-framework#5644\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eJUnit 6.1.0-RC1 = Platform 6.1.0-RC1 + Jupiter 6.1.0-RC1 + Vintage 6.1.0-RC1\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0-RC1/release-notes/\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mariokhoury4\"\u003e\u003ccode\u003e@​mariokhoury4\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/4574\"\u003ejunit-team/junit-framework#4574\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Ogu1208\"\u003e\u003ccode\u003e@​Ogu1208\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5145\"\u003ejunit-team/junit-framework#5145\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/HyungGeun94\"\u003e\u003ccode\u003e@​HyungGeun94\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5271\"\u003ejunit-team/junit-framework#5271\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yalishevant\"\u003e\u003ccode\u003e@​yalishevant\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5316\"\u003ejunit-team/junit-framework#5316\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JINU-CHANG\"\u003e\u003ccode\u003e@​JINU-CHANG\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5290\"\u003ejunit-team/junit-framework#5290\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jaschdoc\"\u003e\u003ccode\u003e@​jaschdoc\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5427\"\u003ejunit-team/junit-framework#5427\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kawshikbuet17\"\u003e\u003ccode\u003e@​kawshikbuet17\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5561\"\u003ejunit-team/junit-framework#5561\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/msridhar\"\u003e\u003ccode\u003e@​msridhar\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5602\"\u003ejunit-team/junit-framework#5602\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.1.0-M1...r6.1.0-RC1\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.1.0-M1...r6.1.0-RC1\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eJUnit 6.1.0-M1 = Platform 6.1.0-M1 + Jupiter 6.1.0-M1 + Vintage 6.1.0-M1\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0-M1/release-notes/\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vy\"\u003e\u003ccode\u003e@​vy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5041\"\u003ejunit-team/junit-framework#5041\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Pankraz76\"\u003e\u003ccode\u003e@​Pankraz76\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5006\"\u003ejunit-team/junit-framework#5006\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/arukiidou\"\u003e\u003ccode\u003e@​arukiidou\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5066\"\u003ejunit-team/junit-framework#5066\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/laeubi\"\u003e\u003ccode\u003e@​laeubi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5092\"\u003ejunit-team/junit-framework#5092\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jihun4452\"\u003e\u003ccode\u003e@​jihun4452\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5088\"\u003ejunit-team/junit-framework#5088\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TWiStErRob\"\u003e\u003ccode\u003e@​TWiStErRob\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5133\"\u003ejunit-team/junit-framework#5133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.0...r6.1.0-M1\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.0.0...r6.1.0-M1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0dc3af1cb1973d257b5bc75d81e02454d5e4e556\"\u003e\u003ccode\u003e0dc3af1\u003c/code\u003e\u003c/a\u003e Release 6.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/1d130020c85170edcb46ce7ed1f7f78824e37c04\"\u003e\u003ccode\u003e1d13002\u003c/code\u003e\u003c/a\u003e Prepare 6.1.0 release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/072b2175bbd7b0b3b26f5d928550ec7a21e68268\"\u003e\u003ccode\u003e072b217\u003c/code\u003e\u003c/a\u003e Update plugin spotless to v8.5.0 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5668\"\u003e#5668\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/3a53480218f4b752a9ca77506e10632cd483c0f8\"\u003e\u003ccode\u003e3a53480\u003c/code\u003e\u003c/a\u003e Update Gradle to v9.5.1 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5666\"\u003e#5666\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0e18a20a9f98d063ae02b3ba19329143f5c7f034\"\u003e\u003ccode\u003e0e18a20\u003c/code\u003e\u003c/a\u003e Update zizmorcore/zizmor-action action to v0.5.4 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5669\"\u003e#5669\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0a2634fb9cbbd057b02cf629d7d272c16d62be4b\"\u003e\u003ccode\u003e0a2634f\u003c/code\u003e\u003c/a\u003e Update github/codeql-action action to v4.35.5 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5671\"\u003e#5671\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/4dbd5561b00ac761a62c516bfaec51c212a2d60c\"\u003e\u003ccode\u003e4dbd556\u003c/code\u003e\u003c/a\u003e Restructure workflows to have single \u0026quot;status\u0026quot; job (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5670\"\u003e#5670\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/f2194cebe377512cb0ade388c62a881a0bcf5d3e\"\u003e\u003ccode\u003ef2194ce\u003c/code\u003e\u003c/a\u003e Increase timeout to reduce flakiness\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/5c8fdd2df65b763151cccbe669ea9e1c3155efcd\"\u003e\u003ccode\u003e5c8fdd2\u003c/code\u003e\u003c/a\u003e Update dependency org.apache.groovy:groovy to v5.0.6 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5659\"\u003e#5659\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/43c6982324602582902c9bdb213fd5e007f9cf3d\"\u003e\u003ccode\u003e43c6982\u003c/code\u003e\u003c/a\u003e Update dependency org.slf4j:slf4j-jdk14 to v2.0.18 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5667\"\u003e#5667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.ow2.asm:asm-bom` from 9.10 to 9.10.1\n\nUpdates `ch.qos.logback:logback-core` from 1.5.32 to 1.5.33\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.codehaus.plexus:plexus-classworlds` from 2.11.0 to 2.12.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/releases\"\u003eorg.codehaus.plexus:plexus-classworlds's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.12.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cul\u003e\n\u003cli\u003eFix loadGlob using OR instead of AND for glob matching (\u003ca href=\"https://redirect.github.com/codehaus-plexus/plexus-classworlds/pull/147\"\u003e#147\u003c/a\u003e) \u003ca href=\"https://github.com/gnodet\"\u003e\u003ccode\u003e@​gnodet\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/commit/352e533ee33c8bae87b96255ae37f3dfe8b39c21\"\u003e\u003ccode\u003e352e533\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release plexus-classworlds-2.12.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/commit/9d5a694fa806a2c9d5344deba166f8cd3d2dc17d\"\u003e\u003ccode\u003e9d5a694\u003c/code\u003e\u003c/a\u003e Fix test to use File API for glob pattern (Windows compat)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/commit/6cff36d2d2a56c34c5229a0304ee73b1069703b2\"\u003e\u003ccode\u003e6cff36d\u003c/code\u003e\u003c/a\u003e Fix loadGlob using OR instead of AND for glob matching\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/commit/98ef018f4e644e246ef650a8de9a3a1d51103b22\"\u003e\u003ccode\u003e98ef018\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/compare/plexus-classworlds-2.11.0...plexus-classworlds-2.12.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.junit.platform:junit-platform-engine` from 6.0.3 to 6.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/junit-team/junit-framework/releases\"\u003eorg.junit.platform:junit-platform-engine's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eJUnit 6.1.0 = Platform 6.1.0 + Jupiter 6.1.0 + Vintage 6.1.0\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0/release-notes.html\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JarvisCraft\"\u003e\u003ccode\u003e@​JarvisCraft\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5633\"\u003ejunit-team/junit-framework#5633\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Maran23\"\u003e\u003ccode\u003e@​Maran23\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5644\"\u003ejunit-team/junit-framework#5644\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eJUnit 6.1.0-RC1 = Platform 6.1.0-RC1 + Jupiter 6.1.0-RC1 + Vintage 6.1.0-RC1\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0-RC1/release-notes/\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mariokhoury4\"\u003e\u003ccode\u003e@​mariokhoury4\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/4574\"\u003ejunit-team/junit-framework#4574\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Ogu1208\"\u003e\u003ccode\u003e@​Ogu1208\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5145\"\u003ejunit-team/junit-framework#5145\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/HyungGeun94\"\u003e\u003ccode\u003e@​HyungGeun94\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5271\"\u003ejunit-team/junit-framework#5271\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yalishevant\"\u003e\u003ccode\u003e@​yalishevant\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5316\"\u003ejunit-team/junit-framework#5316\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JINU-CHANG\"\u003e\u003ccode\u003e@​JINU-CHANG\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5290\"\u003ejunit-team/junit-framework#5290\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jaschdoc\"\u003e\u003ccode\u003e@​jaschdoc\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5427\"\u003ejunit-team/junit-framework#5427\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kawshikbuet17\"\u003e\u003ccode\u003e@​kawshikbuet17\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5561\"\u003ejunit-team/junit-framework#5561\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/msridhar\"\u003e\u003ccode\u003e@​msridhar\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5602\"\u003ejunit-team/junit-framework#5602\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.1.0-M1...r6.1.0-RC1\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.1.0-M1...r6.1.0-RC1\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eJUnit 6.1.0-M1 = Platform 6.1.0-M1 + Jupiter 6.1.0-M1 + Vintage 6.1.0-M1\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0-M1/release-notes/\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vy\"\u003e\u003ccode\u003e@​vy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5041\"\u003ejunit-team/junit-framework#5041\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Pankraz76\"\u003e\u003ccode\u003e@​Pankraz76\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5006\"\u003ejunit-team/junit-framework#5006\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/arukiidou\"\u003e\u003ccode\u003e@​arukiidou\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5066\"\u003ejunit-team/junit-framework#5066\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/laeubi\"\u003e\u003ccode\u003e@​laeubi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5092\"\u003ejunit-team/junit-framework#5092\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jihun4452\"\u003e\u003ccode\u003e@​jihun4452\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5088\"\u003ejunit-team/junit-framework#5088\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TWiStErRob\"\u003e\u003ccode\u003e@​TWiStErRob\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5133\"\u003ejunit-team/junit-framework#5133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.0...r6.1.0-M1\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.0.0...r6.1.0-M1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0dc3af1cb1973d257b5bc75d81e02454d5e4e556\"\u003e\u003ccode\u003e0dc3af1\u003c/code\u003e\u003c/a\u003e Release 6.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/1d130020c85170edcb46ce7ed1f7f78824e37c04\"\u003e\u003ccode\u003e1d13002\u003c/code\u003e\u003c/a\u003e Prepare 6.1.0 release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/072b2175bbd7b0b3b26f5d928550ec7a21e68268\"\u003e\u003ccode\u003e072b217\u003c/code\u003e\u003c/a\u003e Update plugin spotless to v8.5.0 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5668\"\u003e#5668\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/3a53480218f4b752a9ca77506e10632cd483c0f8\"\u003e\u003ccode\u003e3a53480\u003c/code\u003e\u003c/a\u003e Update Gradle to v9.5.1 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5666\"\u003e#5666\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0e18a20a9f98d063ae02b3ba19329143f5c7f034\"\u003e\u003ccode\u003e0e18a20\u003c/code\u003e\u003c/a\u003e Update zizmorcore/zizmor-action action to v0.5.4 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5669\"\u003e#5669\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0a2634fb9cbbd057b02cf629d7d272c16d62be4b\"\u003e\u003ccode\u003e0a2634f\u003c/code\u003e\u003c/a\u003e Update github/codeql-action action to v4.35.5 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5671\"\u003e#5671\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/4dbd5561b00ac761a62c516bfaec51c212a2d60c\"\u003e\u003ccode\u003e4dbd556\u003c/code\u003e\u003c/a\u003e Restructure workflows to have single \u0026quot;status\u0026quot; job (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5670\"\u003e#5670\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/f2194cebe377512cb0ade388c62a881a0bcf5d3e\"\u003e\u003ccode\u003ef2194ce\u003c/code\u003e\u003c/a\u003e Increase timeout to reduce flakiness\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/5c8fdd2df65b763151cccbe669ea9e1c3155efcd\"\u003e\u003ccode\u003e5c8fdd2\u003c/code\u003e\u003c/a\u003e Update dependency org.apache.groovy:groovy to v5.0.6 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5659\"\u003e#5659\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/43c6982324602582902c9bdb213fd5e007f9cf3d\"\u003e\u003ccode\u003e43c6982\u003c/code\u003e\u003c/a\u003e Update dependency org.slf4j:slf4j-jdk14 to v2.0.18 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5667\"\u003e#5667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.maven.extensions:maven-build-cache-extension` from 1.2.2 to 1.2.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/apache/maven-build-cache-extension/releases\"\u003eorg.apache.maven.extensions:maven-build-cache-extension's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.3\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e🚀 New features and improvements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIssue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/336\"\u003e#336\u003c/a\u003e Add command line flag to override maxBuildsCached (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/489\"\u003e#489\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/MBUILDCACHE-73\"\u003e[MBUILDCACHE-73]\u003c/a\u003e - Allow arbitrary expressions as additional reconcilation properties (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/416\"\u003e#416\u003c/a\u003e) \u003ca href=\"https://github.com/pdudits\"\u003e\u003ccode\u003e@​pdudits\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/480\"\u003e#480\u003c/a\u003e - execute blocking hostname resolution asynchronously and implement timeout and caching (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/481\"\u003e#481\u003c/a\u003e) \u003ca href=\"https://github.com/marcuslinke\"\u003e\u003ccode\u003e@​marcuslinke\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDo not read a JAR completely into a byte-array before computing the SHA (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/470\"\u003e#470\u003c/a\u003e) \u003ca href=\"https://github.com/jvdvegt\"\u003e\u003ccode\u003e@​jvdvegt\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Test Only] Comprehensive test coverage (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/462\"\u003e#462\u003c/a\u003e) \u003ca href=\"https://github.com/AlexanderAshitkin\"\u003e\u003ccode\u003e@​AlexanderAshitkin\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOnly set the project artifact if it is the actual JAR (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/453\"\u003e#453\u003c/a\u003e) \u003ca href=\"https://github.com/mensinda\"\u003e\u003ccode\u003e@​mensinda\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/423\"\u003e#423\u003c/a\u003e — include declared input files in cache checksum for pom-packaged modules (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/482\"\u003e#482\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix issue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/463\"\u003e#463\u003c/a\u003e Unexpected cache miss due to previously downloaded remote cache entry with skipTests (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/472\"\u003e#472\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIssue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/345\"\u003e#345\u003c/a\u003e fix possible NPE with Intellij (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/473\"\u003e#473\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTest-jar type dependencies fail to be resolved during checksum calculation with -f builds (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/468\"\u003e#468\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix for issue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/450\"\u003e#450\u003c/a\u003e - fixed CacheUtils.unzip to properly restore unix permissions on file systems that support it (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/451\"\u003e#451\u003c/a\u003e) \u003ca href=\"https://github.com/eyforia\"\u003e\u003ccode\u003e@​eyforia\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📝 Documentation updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocumentation fixes and updates (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/460\"\u003e#460\u003c/a\u003e) \u003ca href=\"https://github.com/AlexanderAshitkin\"\u003e\u003ccode\u003e@​AlexanderAshitkin\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e👻 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFinish breaking dependency on org.apache.http in RemoteCacheRepositoryImpl (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/441\"\u003e#441\u003c/a\u003e) \u003ca href=\"https://github.com/elharo\"\u003e\u003ccode\u003e@​elharo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove undeclared NotNull annotations (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/440\"\u003e#440\u003c/a\u003e) \u003ca href=\"https://github.com/elharo\"\u003e\u003ccode\u003e@​elharo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFill in two more used dependencies SLF4J and sisu.plexus (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/438\"\u003e#438\u003c/a\u003e) \u003ca href=\"https://github.com/elharo\"\u003e\u003ccode\u003e@​elharo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🚦 Tests\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix findFirstMainSourceFile to skip invoker test projects (src/it/) in p12 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/474\"\u003e#474\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Test Only] Comprehensive test coverage (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/462\"\u003e#462\u003c/a\u003e) \u003ca href=\"https://github.com/AlexanderAshitkin\"\u003e\u003ccode\u003e@​AlexanderAshitkin\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📦 Dependency updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate 48 and Maven 3.9.16 (in Maven 3 profile) (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/490\"\u003e#490\u003c/a\u003e) \u003ca href=\"https://github.com/Bukama\"\u003e\u003ccode\u003e@​Bukama\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump com.github.tomakehurst:wiremock-jre8 from 2.35.2 to 3.0.1 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/485\"\u003e#485\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-invoker-plugin from 3.10.0 to 3.10.1 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/484\"\u003e#484\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump com.google.guava:guava from 30.1.1-jre to 32.0.0-jre in /src/test/projects/reference-test-projects/p06-dep-edge-cases/bom-b (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/464\"\u003e#464\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.junit:junit-bom from 5.14.3 to 5.14.4 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/479\"\u003e#479\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.commons:commons-lang3 from 3.14.0 to 3.18.0 in /src/test/projects/reference-test-projects/p18-maven4-native/platform-bom (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/465\"\u003e#465\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-invoker-plugin from 3.9.1 to 3.10.0 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/478\"\u003e#478\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump commons-io:commons-io from 2.21.0 to 2.22.0 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/477\"\u003e#477\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.testcontainers:testcontainers-bom from 2.0.4 to 2.0.5 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/476\"\u003e#476\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump com.fasterxml.jackson.core:jackson-annotations from 2.15.4 to 2.21 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/475\"\u003e#475\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.testcontainers:testcontainers-bom from 2.0.3 to 2.0.4 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/466\"\u003e#466\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump resolverVersion from 1.9.26 to 1.9.27 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/459\"\u003e#459\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump resolverVersion from 1.9.25 to 1.9.26 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/458\"\u003e#458\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.junit:junit-bom from 5.14.2 to 5.14.3 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/457\"\u003e#457\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/f9f25d2f6acd78238471f7f36e1efe93fb8b7e50\"\u003e\u003ccode\u003ef9f25d2\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release maven-build-cache-extension-1.2.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/7bd513b6515e526554067386d2d4b1e67fb7e2cb\"\u003e\u003ccode\u003e7bd513b\u003c/code\u003e\u003c/a\u003e Update 48 and Maven 3.9.16 (in Maven 3 profile) (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/490\"\u003e#490\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/ada66d445c228ba9abe52e42632fc237af38f89f\"\u003e\u003ccode\u003eada66d4\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/336\"\u003e#336\u003c/a\u003e Add command line flag to override maxBuildsCached (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/489\"\u003e#489\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/c915399e169c6c3633b4a12be0fc1e9579114f50\"\u003e\u003ccode\u003ec915399\u003c/code\u003e\u003c/a\u003e [MBUILDCACHE-73] Allow arbitrary expressions as additional reconcilation prop...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/0b7d080ffca2a32c892208bbfafbd18b9dd32a92\"\u003e\u003ccode\u003e0b7d080\u003c/code\u003e\u003c/a\u003e Bump com.github.tomakehurst:wiremock-jre8 from 2.35.2 to 3.0.1 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/485\"\u003e#485\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/051a319a8f063ea59f97709186e8966e2969a1e4\"\u003e\u003ccode\u003e051a319\u003c/code\u003e\u003c/a\u003e Only set the project artifact if it is the actual JAR (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/453\"\u003e#453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/6a48e056a89316d5c3a007098cd32aa9aa5e1a5e\"\u003e\u003ccode\u003e6a48e05\u003c/code\u003e\u003c/a\u003e Bump org.apache.maven.plugins:maven-invoker-plugin from 3.10.0 to 3.10.1 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/484\"\u003e#484\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/5032c5d805f4071d34ecea96f40d80117369654a\"\u003e\u003ccode\u003e5032c5d\u003c/code\u003e\u003c/a\u003e fix: \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/480\"\u003e#480\u003c/a\u003e - execute blocking hostname resolution asynchronously and implement...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/dc7069f9e25acfafa6cc41ebba48bcbe43e5bc4b\"\u003e\u003ccode\u003edc7069f\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/423\"\u003e#423\u003c/a\u003e add an IT and a fix (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/482\"\u003e#482\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/929bed8890bc43128818277c13b6f8c1c05e5f8c\"\u003e\u003ccode\u003e929bed8\u003c/code\u003e\u003c/a\u003e Bump com.google.guava:guava\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/apache/maven-build-cache-extension/compare/maven-build-cache-extension-1.2.2...maven-build-cache-extension-1.2.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/jetty/jetty.project/pull/15176","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/jetty%2Fjetty.project/issues/15176","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/15176/packages"}],"issue_packages":[{"old_version":"1.5.21","new_version":"1.5.34","update_type":"patch","path":"/its/it-tests","pr_created_at":"2026-07-15T22:36:46.000Z","version_change":"1.5.21 → 1.5.34","issue":{"uuid":"4896866891","node_id":"PR_kwDOAFbEHc7yPm94","number":298,"state":"open","title":"SCANJLIB-320 Bump ch.qos.logback:logback-core from 1.5.21 to 1.5.34 in /its/it-tests","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-07-15T22:36:46.000Z","updated_at":"2026-07-15T22:39:40.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"SCANJLIB-320 Bump","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.5.21","new_version":"1.5.34","repository_url":"https://github.com/qos-ch/logback"}],"path":"/its/it-tests","ecosystem":"maven"},"body":"Bumps [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) from 1.5.21 to 1.5.34.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.34\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-06-01 Release of logback version 1.5.34\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In case certain StackTraceElement values returned by the Throwable.getStackTrace method are null, StackTraceElementProxy substitutes a dummy instance instead of throwing an IllegalArgumentException. This resolves [issues \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003e#1040\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003eqos-ch/logback#1040\u003c/a\u003e), reported by Naotsugu Kobayashi.\u003c/p\u003e\n\u003cp\u003e• HardenedObjectInputStream will now throw an InvalidClassException during deserialization attempts of Proxy classes. This change addresses potential deserialization whitelist bypass vulnerability reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-10532\"\u003eCVE-2026-10532\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bitwise identical binary of this version can be reproduced by building from source code at commit e62272ac152469aec1ede056c3c7d0d7314e7bfe associated with the tag v_1.5.34. This release was built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.32\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-16 Release of logback version 1.5.32\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In \u003ccode\u003eDefaultProcessor, \u003c/code\u003efixed incorrect check for dependencies contained within a parent model. Previous only the direct children were scanned. This fixes \u003ca href=\"https://redirect.github.com/qos-ch/logback-access/issues/34\"\u003elogback-access/issues/34\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit e807335a67535b4eacce94e942c0bcb649665d93 associated with the tag v_1.5.32. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback  1.5.31\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback version 1.5.31\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fixed missing META-INF/services directory in logback-classic.jar. This issue rendered logback-classic version 1.5.30 unusable with SLF4J.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 168e42f9f9a18a3ffdf31eb2bfe80a71e33ecd8b associated with the tag v_1.5.31. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.30\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback  version 1.5.30\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003cstrong\u003eIn this version, logback-classic.jar was missing the META-INF/services directory, making it unusable with SLF4J. Version 1.5.31 (released later on the same day) fixes this issue.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fix scanning issue when an included file becomes available at a later time. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1021\"\u003eissues/1021\u003c/a\u003e by Sergey Nazarov.\u003c/p\u003e\n\u003cp\u003e• Standardized code for version checking across modules.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 44164f10ca3fb44ce0e68519f13564b87e3aca61 associated with the tag v_1.5.30. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.29\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e62272ac152469aec1ede056c3c7d0d7314e7bfe\"\u003e\u003ccode\u003ee62272a\u003c/code\u003e\u003c/a\u003e prepare release 1.5.34\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/1e9e926db1529b729a0e2d29fdee151c2aea0341\"\u003e\u003ccode\u003e1e9e926\u003c/code\u003e\u003c/a\u003e add resolveProxyClassRejectsDynamicProxies unit test\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/2de5cbe90b74fa284685304bc91321313b0d8e2f\"\u003e\u003ccode\u003e2de5cbe\u003c/code\u003e\u003c/a\u003e added StackTraceElementProxyTest, minor edits to AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/0e9b9278b5d3f0b573762cd7b5482ed65244418e\"\u003e\u003ccode\u003e0e9b927\u003c/code\u003e\u003c/a\u003e in case StackTraceElement is null use a substitute, fixing issues/1040\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/f7a0654c2b7e8e1c461e3d9e483e82ef969b5818\"\u003e\u003ccode\u003ef7a0654\u003c/code\u003e\u003c/a\u003e prevent resolveProxyClass bypass\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/249b81f3754f1fb58f8507f244a36c7a940854c0\"\u003e\u003ccode\u003e249b81f\u003c/code\u003e\u003c/a\u003e docs are no longer distributed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/1c3b26a839f05b6bc1769e5a028ef326c711cec8\"\u003e\u003ccode\u003e1c3b26a\u003c/code\u003e\u003c/a\u003e start work on 1.5.34-SNAPSHOT\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.21...v_1.5.34\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=maven\u0026previous-version=1.5.21\u0026new-version=1.5.34)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/SonarSource/sonar-scanner-java-library/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/SonarSource/sonar-scanner-java-library/pull/298","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/SonarSource%2Fsonar-scanner-java-library/issues/298","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/298/packages"}},{"old_version":"1.5.25","new_version":"1.5.35","update_type":"patch","path":null,"pr_created_at":"2026-07-10T21:05:59.000Z","version_change":"1.5.25 → 1.5.35","issue":{"uuid":"4858650370","node_id":"PR_kwDONE4-Kc7wWXrY","number":5,"state":"closed","title":"Bump ch.qos.logback:logback-core from 1.5.25 to 1.5.35","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-07-15T22:37:40.000Z","author_association":null,"state_reason":null,"created_at":"2026-07-10T21:05:59.000Z","updated_at":"2026-07-15T22:37:42.000Z","time_to_close":437501,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.5.25","new_version":"1.5.35","repository_url":"https://github.com/qos-ch/logback"}],"path":null,"ecosystem":"maven"},"body":"Bumps [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) from 1.5.25 to 1.5.35.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.35\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e026-06-23 Release of logback version 1.5.35\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• The 'condition' attribute in \u003ccode\u003e\u0026lt;if\u0026gt;\u003c/code\u003e elements now rejects unicode escape sequences (\\u and \\U). This closes a bypass of the existing prohibition on the new operator in Janino-evaluated conditions. This issue was reported by IcySun (\u003ca href=\"mailto:icysun@qq.com\"\u003eicysun@qq.com\u003c/a\u003e) and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-13006\"\u003eCVE-2026-13006\u003c/a\u003e.  \u003cstrong\u003ePlease note that version 1.5.37 provides the full fix to this vulnerability.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Added \u003ccode\u003eConfiguratorRank.AUTHENTICATING\u003c/code\u003e (rank 100), the highest configurator rank, for certified/authenticating configurators discovered via the ServiceLoader mechanism. \u003ccode\u003eContextInitializer\u003c/code\u003e now requires that at most one such configurator exist on the classpath; if more than one is found, initialization aborts with an error.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eConsoleCharsetPropertyDefiner\u003c/code\u003e is no longer shipped. The Java 21 multi-release compilation of logback-core has been disabled, which removes this class from the published artifact. Configurations that referenced \u003ccode\u003ech.qos.logback.core.property.ConsoleCharsetPropertyDefiner\u003c/code\u003e will need an alternative approach for console charset detection.\u003c/p\u003e\n\u003cp\u003e• The logback-examples module is now included in artifacts published to Maven Central.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eJoranConfigurator.makeAnotherInstance()\u003c/code\u003e and \u003ccode\u003eDefaultJoranConfigurator.performMultiStepConfigurationFileSearch()\u003c/code\u003e are now protected, allowing derived configurators to override these methods.\u003c/p\u003e\n\u003cp\u003e• A bitwise identical binary of this version can be reproduced by building from source code at commit 08bd1598d565d83444f72983935e7da4746783b7 associated with the tag v_1.5.35. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.34\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-06-01 Release of logback version 1.5.34\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In case certain StackTraceElement values returned by the Throwable.getStackTrace method are null, StackTraceElementProxy substitutes a dummy instance instead of throwing an IllegalArgumentException. This resolves [issues \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003e#1040\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003eqos-ch/logback#1040\u003c/a\u003e), reported by Naotsugu Kobayashi.\u003c/p\u003e\n\u003cp\u003e• HardenedObjectInputStream will now throw an InvalidClassException during deserialization attempts of Proxy classes. This change addresses potential deserialization whitelist bypass vulnerability reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-10532\"\u003eCVE-2026-10532\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bitwise identical binary of this version can be reproduced by building from source code at commit e62272ac152469aec1ede056c3c7d0d7314e7bfe associated with the tag v_1.5.34. This release was built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.32\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-16 Release of logback version 1.5.32\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In \u003ccode\u003eDefaultProcessor, \u003c/code\u003efixed incorrect check for dependencies contained within a parent model. Previous only the direct children were scanned. This fixes \u003ca href=\"https://redirect.github.com/qos-ch/logback-access/issues/34\"\u003elogback-access/issues/34\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit e807335a67535b4eacce94e942c0bcb649665d93 associated with the tag v_1.5.32. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback  1.5.31\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback version 1.5.31\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fixed missing META-INF/services directory in logback-classic.jar. This issue rendered logback-classic version 1.5.30 unusable with SLF4J.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/08bd1598d565d83444f72983935e7da4746783b7\"\u003e\u003ccode\u003e08bd159\u003c/code\u003e\u003c/a\u003e preapre release 1.5.35\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/37d256b825fc62b4a3908fa29d8b4e34acf79ed0\"\u003e\u003ccode\u003e37d256b\u003c/code\u003e\u003c/a\u003e indentation changes only\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d3d73078afbb0691423f60a066d77503fdf05fc3\"\u003e\u003ccode\u003ed3d7307\u003c/code\u003e\u003c/a\u003e minor comment\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fa0411a9393282ba69396ce65f122d281c079ac0\"\u003e\u003ccode\u003efa0411a\u003c/code\u003e\u003c/a\u003e radomize file location\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/834fdba8085727f96fc12214ff6dd71ab3ac6a25\"\u003e\u003ccode\u003e834fdba\u003c/code\u003e\u003c/a\u003e disable consoleCharset test\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/42eabc374ad8348e9f74e9cd4b59ae5168dd1c2b\"\u003e\u003ccode\u003e42eabc3\u003c/code\u003e\u003c/a\u003e fix messages in IfModelHandler\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/347efc8ec3f10defafd0cf6d4b9a0c81b3320c3a\"\u003e\u003ccode\u003e347efc8\u003c/code\u003e\u003c/a\u003e add unicode escape prevention\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/1b6ba73679437670b37aa1d9061ca82dfd554afb\"\u003e\u003ccode\u003e1b6ba73\u003c/code\u003e\u003c/a\u003e allow derived classes to override makeAnotherInstance\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/340e8be17c9a43d022c301e00b83601affd1fee5\"\u003e\u003ccode\u003e340e8be\u003c/code\u003e\u003c/a\u003e check for unicode escape codes in Janino conditions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/4468f5e5fb67872a14131a7d4feb736131d17202\"\u003e\u003ccode\u003e4468f5e\u003c/code\u003e\u003c/a\u003e adding support for certifying configurators\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.25...v_1.5.35\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=maven\u0026previous-version=1.5.25\u0026new-version=1.5.35)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Marcelektro/SocksProxyServer/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/Marcelektro/SocksProxyServer/pull/5","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Marcelektro%2FSocksProxyServer/issues/5","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/5/packages"}},{"old_version":"1.2.11","new_version":"1.5.35","update_type":"minor","path":"/java","pr_created_at":"2026-07-10T20:39:24.000Z","version_change":"1.2.11 → 1.5.35","issue":{"uuid":"4858499950","node_id":"PR_kwDOHeGOK87wV47S","number":13,"state":"closed","title":"Bump ch.qos.logback:logback-core from 1.2.11 to 1.5.35 in /java","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-07-15T22:02:50.000Z","author_association":null,"state_reason":null,"created_at":"2026-07-10T20:39:24.000Z","updated_at":"2026-07-15T22:02:52.000Z","time_to_close":437006,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.2.11","new_version":"1.5.35","repository_url":"https://github.com/qos-ch/logback"}],"path":"/java","ecosystem":"maven"},"body":"Bumps [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) from 1.2.11 to 1.5.35.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.35\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e026-06-23 Release of logback version 1.5.35\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• The 'condition' attribute in \u003ccode\u003e\u0026lt;if\u0026gt;\u003c/code\u003e elements now rejects unicode escape sequences (\\u and \\U). This closes a bypass of the existing prohibition on the new operator in Janino-evaluated conditions. This issue was reported by IcySun (\u003ca href=\"mailto:icysun@qq.com\"\u003eicysun@qq.com\u003c/a\u003e) and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-13006\"\u003eCVE-2026-13006\u003c/a\u003e.  \u003cstrong\u003ePlease note that version 1.5.37 provides the full fix to this vulnerability.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Added \u003ccode\u003eConfiguratorRank.AUTHENTICATING\u003c/code\u003e (rank 100), the highest configurator rank, for certified/authenticating configurators discovered via the ServiceLoader mechanism. \u003ccode\u003eContextInitializer\u003c/code\u003e now requires that at most one such configurator exist on the classpath; if more than one is found, initialization aborts with an error.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eConsoleCharsetPropertyDefiner\u003c/code\u003e is no longer shipped. The Java 21 multi-release compilation of logback-core has been disabled, which removes this class from the published artifact. Configurations that referenced \u003ccode\u003ech.qos.logback.core.property.ConsoleCharsetPropertyDefiner\u003c/code\u003e will need an alternative approach for console charset detection.\u003c/p\u003e\n\u003cp\u003e• The logback-examples module is now included in artifacts published to Maven Central.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eJoranConfigurator.makeAnotherInstance()\u003c/code\u003e and \u003ccode\u003eDefaultJoranConfigurator.performMultiStepConfigurationFileSearch()\u003c/code\u003e are now protected, allowing derived configurators to override these methods.\u003c/p\u003e\n\u003cp\u003e• A bitwise identical binary of this version can be reproduced by building from source code at commit 08bd1598d565d83444f72983935e7da4746783b7 associated with the tag v_1.5.35. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.34\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-06-01 Release of logback version 1.5.34\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In case certain StackTraceElement values returned by the Throwable.getStackTrace method are null, StackTraceElementProxy substitutes a dummy instance instead of throwing an IllegalArgumentException. This resolves [issues \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003e#1040\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003eqos-ch/logback#1040\u003c/a\u003e), reported by Naotsugu Kobayashi.\u003c/p\u003e\n\u003cp\u003e• HardenedObjectInputStream will now throw an InvalidClassException during deserialization attempts of Proxy classes. This change addresses potential deserialization whitelist bypass vulnerability reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-10532\"\u003eCVE-2026-10532\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bitwise identical binary of this version can be reproduced by building from source code at commit e62272ac152469aec1ede056c3c7d0d7314e7bfe associated with the tag v_1.5.34. This release was built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.32\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-16 Release of logback version 1.5.32\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In \u003ccode\u003eDefaultProcessor, \u003c/code\u003efixed incorrect check for dependencies contained within a parent model. Previous only the direct children were scanned. This fixes \u003ca href=\"https://redirect.github.com/qos-ch/logback-access/issues/34\"\u003elogback-access/issues/34\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit e807335a67535b4eacce94e942c0bcb649665d93 associated with the tag v_1.5.32. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback  1.5.31\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback version 1.5.31\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fixed missing META-INF/services directory in logback-classic.jar. This issue rendered logback-classic version 1.5.30 unusable with SLF4J.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/08bd1598d565d83444f72983935e7da4746783b7\"\u003e\u003ccode\u003e08bd159\u003c/code\u003e\u003c/a\u003e preapre release 1.5.35\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/37d256b825fc62b4a3908fa29d8b4e34acf79ed0\"\u003e\u003ccode\u003e37d256b\u003c/code\u003e\u003c/a\u003e indentation changes only\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d3d73078afbb0691423f60a066d77503fdf05fc3\"\u003e\u003ccode\u003ed3d7307\u003c/code\u003e\u003c/a\u003e minor comment\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fa0411a9393282ba69396ce65f122d281c079ac0\"\u003e\u003ccode\u003efa0411a\u003c/code\u003e\u003c/a\u003e radomize file location\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/834fdba8085727f96fc12214ff6dd71ab3ac6a25\"\u003e\u003ccode\u003e834fdba\u003c/code\u003e\u003c/a\u003e disable consoleCharset test\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/42eabc374ad8348e9f74e9cd4b59ae5168dd1c2b\"\u003e\u003ccode\u003e42eabc3\u003c/code\u003e\u003c/a\u003e fix messages in IfModelHandler\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/347efc8ec3f10defafd0cf6d4b9a0c81b3320c3a\"\u003e\u003ccode\u003e347efc8\u003c/code\u003e\u003c/a\u003e add unicode escape prevention\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/1b6ba73679437670b37aa1d9061ca82dfd554afb\"\u003e\u003ccode\u003e1b6ba73\u003c/code\u003e\u003c/a\u003e allow derived classes to override makeAnotherInstance\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/340e8be17c9a43d022c301e00b83601affd1fee5\"\u003e\u003ccode\u003e340e8be\u003c/code\u003e\u003c/a\u003e check for unicode escape codes in Janino conditions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/4468f5e5fb67872a14131a7d4feb736131d17202\"\u003e\u003ccode\u003e4468f5e\u003c/code\u003e\u003c/a\u003e adding support for certifying configurators\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.2.11...v_1.5.35\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=maven\u0026previous-version=1.2.11\u0026new-version=1.5.35)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Nortech-ai/tahu/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/Nortech-ai/tahu/pull/13","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Nortech-ai%2Ftahu/issues/13","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/13/packages"}},{"old_version":"1.5.25","new_version":"1.5.33","update_type":"patch","path":null,"pr_created_at":"2026-07-06T03:19:34.000Z","version_change":"1.5.25 → 1.5.33","issue":{"uuid":"4815673816","node_id":"PR_kwDOAWH1ps7uKwyK","number":2963,"state":"open","title":"Bump ch.qos.logback:logback-core from 1.5.25 to 1.5.33","user":"dependabot[bot]","labels":["java","dependencies"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-07-06T03:19:34.000Z","updated_at":"2026-07-06T03:29:13.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.5.25","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"}],"path":null,"ecosystem":"maven"},"body":"Bumps [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) from 1.5.25 to 1.5.33.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.32\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-16 Release of logback version 1.5.32\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In \u003ccode\u003eDefaultProcessor, \u003c/code\u003efixed incorrect check for dependencies contained within a parent model. Previous only the direct children were scanned. This fixes \u003ca href=\"https://redirect.github.com/qos-ch/logback-access/issues/34\"\u003elogback-access/issues/34\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit e807335a67535b4eacce94e942c0bcb649665d93 associated with the tag v_1.5.32. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback  1.5.31\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback version 1.5.31\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fixed missing META-INF/services directory in logback-classic.jar. This issue rendered logback-classic version 1.5.30 unusable with SLF4J.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 168e42f9f9a18a3ffdf31eb2bfe80a71e33ecd8b associated with the tag v_1.5.31. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.30\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback  version 1.5.30\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003cstrong\u003eIn this version, logback-classic.jar was missing the META-INF/services directory, making it unusable with SLF4J. Version 1.5.31 (released later on the same day) fixes this issue.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fix scanning issue when an included file becomes available at a later time. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1021\"\u003eissues/1021\u003c/a\u003e by Sergey Nazarov.\u003c/p\u003e\n\u003cp\u003e• Standardized code for version checking across modules.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 44164f10ca3fb44ce0e68519f13564b87e3aca61 associated with the tag v_1.5.30. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.29\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-09 Release of logback version 1.5.29\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In response to \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1017\"\u003eissues/1017\u003c/a\u003e, appender names and appender references are once again subject to variable substitution, reverting the change introduced in version 1.5.28.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.28\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-06 Release of logback version 1.5.28\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Appender names or appender references are no longer subject to variable substitution.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.25...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=maven\u0026previous-version=1.5.25\u0026new-version=1.5.33)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/DataBiosphere/consent/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/DataBiosphere/consent/pull/2963","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/DataBiosphere%2Fconsent/issues/2963","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2963/packages"}},{"old_version":"1.5.19","new_version":"1.5.33","update_type":"patch","path":"/public/common/buildsupport/logging in the maven group across 1 directory","pr_created_at":"2026-07-06T01:08:45.000Z","version_change":"1.5.19 → 1.5.33","issue":{"uuid":"4815180474","node_id":"PR_kwDOMCQIy87uJR5J","number":254,"state":"open","title":"Bump ch.qos.logback:logback-core from 1.5.19 to 1.5.33 in /public/common/buildsupport/logging in the maven group across 1 directory","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-07-06T01:08:45.000Z","updated_at":"2026-07-06T01:09:23.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.5.19","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"}],"path":"/public/common/buildsupport/logging in the maven group across 1 directory","ecosystem":"maven"},"body":"Bumps the maven group with 1 update in the /public/common/buildsupport/logging directory: [ch.qos.logback:logback-core](https://github.com/qos-ch/logback).\n\nUpdates `ch.qos.logback:logback-core` from 1.5.19 to 1.5.33\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.32\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-16 Release of logback version 1.5.32\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In \u003ccode\u003eDefaultProcessor, \u003c/code\u003efixed incorrect check for dependencies contained within a parent model. Previous only the direct children were scanned. This fixes \u003ca href=\"https://redirect.github.com/qos-ch/logback-access/issues/34\"\u003elogback-access/issues/34\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit e807335a67535b4eacce94e942c0bcb649665d93 associated with the tag v_1.5.32. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback  1.5.31\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback version 1.5.31\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fixed missing META-INF/services directory in logback-classic.jar. This issue rendered logback-classic version 1.5.30 unusable with SLF4J.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 168e42f9f9a18a3ffdf31eb2bfe80a71e33ecd8b associated with the tag v_1.5.31. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.30\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback  version 1.5.30\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003cstrong\u003eIn this version, logback-classic.jar was missing the META-INF/services directory, making it unusable with SLF4J. Version 1.5.31 (released later on the same day) fixes this issue.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fix scanning issue when an included file becomes available at a later time. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1021\"\u003eissues/1021\u003c/a\u003e by Sergey Nazarov.\u003c/p\u003e\n\u003cp\u003e• Standardized code for version checking across modules.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 44164f10ca3fb44ce0e68519f13564b87e3aca61 associated with the tag v_1.5.30. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.29\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-09 Release of logback version 1.5.29\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In response to \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1017\"\u003eissues/1017\u003c/a\u003e, appender names and appender references are once again subject to variable substitution, reverting the change introduced in version 1.5.28.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.28\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-06 Release of logback version 1.5.28\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Appender names or appender references are no longer subject to variable substitution.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.19...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=maven\u0026previous-version=1.5.19\u0026new-version=1.5.33)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/SherfeyInv/nexus-public/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/SherfeyInv/nexus-public/pull/254","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/SherfeyInv%2Fnexus-public/issues/254","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/254/packages"}},{"old_version":"1.5.32","new_version":"1.5.33","update_type":"patch","path":"/bundles/org.openhab.core.test","pr_created_at":"2026-07-05T22:11:06.000Z","version_change":"1.5.32 → 1.5.33","issue":{"uuid":"4814622573","node_id":"PR_kwDOJGOX7c7uHluq","number":126,"state":"closed","title":"Bump ch.qos.logback:logback-core from 1.5.32 to 1.5.33 in /bundles/org.openhab.core.test","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-07-10T21:07:13.000Z","author_association":null,"state_reason":null,"created_at":"2026-07-05T22:11:06.000Z","updated_at":"2026-07-10T21:07:15.000Z","time_to_close":428167,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.5.32","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"}],"path":"/bundles/org.openhab.core.test","ecosystem":"maven"},"body":"Bumps [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) from 1.5.32 to 1.5.33.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=maven\u0026previous-version=1.5.32\u0026new-version=1.5.33)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/holgerfriedrich/openhab-core/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/holgerfriedrich/openhab-core/pull/126","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/holgerfriedrich%2Fopenhab-core/issues/126","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/126/packages"}},{"old_version":"1.5.32","new_version":"1.5.33","update_type":"patch","path":null,"pr_created_at":"2026-07-05T22:05:11.000Z","version_change":"1.5.32 → 1.5.33","issue":{"uuid":"4814605856","node_id":"PR_kwDORTkenM7uHikD","number":47,"state":"open","title":"build(deps): bump ch.qos.logback:logback-core from 1.5.32 to 1.5.33","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-07-05T22:05:11.000Z","updated_at":"2026-07-05T22:07:15.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps)","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.5.32","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"}],"path":null,"ecosystem":"maven"},"body":"Bumps [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) from 1.5.32 to 1.5.33.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=maven\u0026previous-version=1.5.32\u0026new-version=1.5.33)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/KyrieChao/Failure/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/KyrieChao/Failure/pull/47","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/KyrieChao%2FFailure/issues/47","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/47/packages"}},{"old_version":"1.0.9","new_version":"1.5.33","update_type":"minor","path":null,"pr_created_at":"2026-07-05T18:44:54.000Z","version_change":"1.0.9 → 1.5.33","issue":{"uuid":"4814012490","node_id":"PR_kwDOEeHssM7uFxPz","number":25,"state":"closed","title":"Bump ch.qos.logback:logback-core from 1.0.9 to 1.5.33","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-07-10T18:39:35.000Z","author_association":null,"state_reason":null,"created_at":"2026-07-05T18:44:54.000Z","updated_at":"2026-07-10T18:39:37.000Z","time_to_close":431681,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.0.9","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"}],"path":null,"ecosystem":"maven"},"body":"Bumps [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) from 1.0.9 to 1.5.33.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.32\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-16 Release of logback version 1.5.32\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In \u003ccode\u003eDefaultProcessor, \u003c/code\u003efixed incorrect check for dependencies contained within a parent model. Previous only the direct children were scanned. This fixes \u003ca href=\"https://redirect.github.com/qos-ch/logback-access/issues/34\"\u003elogback-access/issues/34\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit e807335a67535b4eacce94e942c0bcb649665d93 associated with the tag v_1.5.32. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback  1.5.31\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback version 1.5.31\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fixed missing META-INF/services directory in logback-classic.jar. This issue rendered logback-classic version 1.5.30 unusable with SLF4J.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 168e42f9f9a18a3ffdf31eb2bfe80a71e33ecd8b associated with the tag v_1.5.31. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.30\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback  version 1.5.30\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003cstrong\u003eIn this version, logback-classic.jar was missing the META-INF/services directory, making it unusable with SLF4J. Version 1.5.31 (released later on the same day) fixes this issue.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fix scanning issue when an included file becomes available at a later time. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1021\"\u003eissues/1021\u003c/a\u003e by Sergey Nazarov.\u003c/p\u003e\n\u003cp\u003e• Standardized code for version checking across modules.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 44164f10ca3fb44ce0e68519f13564b87e3aca61 associated with the tag v_1.5.30. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.29\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-09 Release of logback version 1.5.29\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In response to \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1017\"\u003eissues/1017\u003c/a\u003e, appender names and appender references are once again subject to variable substitution, reverting the change introduced in version 1.5.28.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.28\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-06 Release of logback version 1.5.28\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Appender names or appender references are no longer subject to variable substitution.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.0.9...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=maven\u0026previous-version=1.0.9\u0026new-version=1.5.33)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/data-integrations/hierarchy-plugins/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/data-integrations/hierarchy-plugins/pull/25","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/data-integrations%2Fhierarchy-plugins/issues/25","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/25/packages"}},{"old_version":"1.5.25","new_version":"1.5.33","update_type":"patch","path":"/spring-boot-project/spring-boot-dependencies","pr_created_at":"2026-07-05T17:41:07.000Z","version_change":"1.5.25 → 1.5.33","issue":{"uuid":"4813818836","node_id":"PR_kwDOBpB9J87uFMEH","number":175,"state":"closed","title":"Bump ch.qos.logback:logback-core from 1.5.25 to 1.5.33 in /spring-boot-project/spring-boot-dependencies","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-07-10T15:45:23.000Z","author_association":null,"state_reason":null,"created_at":"2026-07-05T17:41:07.000Z","updated_at":"2026-07-10T15:45:25.000Z","time_to_close":425056,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.5.25","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"}],"path":"/spring-boot-project/spring-boot-dependencies","ecosystem":"maven"},"body":"Bumps [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) from 1.5.25 to 1.5.33.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.32\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-16 Release of logback version 1.5.32\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In \u003ccode\u003eDefaultProcessor, \u003c/code\u003efixed incorrect check for dependencies contained within a parent model. Previous only the direct children were scanned. This fixes \u003ca href=\"https://redirect.github.com/qos-ch/logback-access/issues/34\"\u003elogback-access/issues/34\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit e807335a67535b4eacce94e942c0bcb649665d93 associated with the tag v_1.5.32. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback  1.5.31\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback version 1.5.31\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fixed missing META-INF/services directory in logback-classic.jar. This issue rendered logback-classic version 1.5.30 unusable with SLF4J.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 168e42f9f9a18a3ffdf31eb2bfe80a71e33ecd8b associated with the tag v_1.5.31. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.30\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback  version 1.5.30\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003cstrong\u003eIn this version, logback-classic.jar was missing the META-INF/services directory, making it unusable with SLF4J. Version 1.5.31 (released later on the same day) fixes this issue.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fix scanning issue when an included file becomes available at a later time. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1021\"\u003eissues/1021\u003c/a\u003e by Sergey Nazarov.\u003c/p\u003e\n\u003cp\u003e• Standardized code for version checking across modules.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 44164f10ca3fb44ce0e68519f13564b87e3aca61 associated with the tag v_1.5.30. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.29\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-09 Release of logback version 1.5.29\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In response to \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1017\"\u003eissues/1017\u003c/a\u003e, appender names and appender references are once again subject to variable substitution, reverting the change introduced in version 1.5.28.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.28\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-06 Release of logback version 1.5.28\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Appender names or appender references are no longer subject to variable substitution.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.25...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=maven\u0026previous-version=1.5.25\u0026new-version=1.5.33)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Thoogend1/IDH10-MeerBier/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/Thoogend1/IDH10-MeerBier/pull/175","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Thoogend1%2FIDH10-MeerBier/issues/175","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/175/packages"}},{"old_version":"1.5.13","new_version":"1.5.33","update_type":"patch","path":"/samples/client/petstore/jaxrs-cxf-client","pr_created_at":"2026-07-04T05:43:40.000Z","version_change":"1.5.13 → 1.5.33","issue":{"uuid":"4807816526","node_id":"PR_kwDON2_zC87tzT2e","number":481,"state":"open","title":"Bump ch.qos.logback:logback-core from 1.5.13 to 1.5.33 in /samples/client/petstore/jaxrs-cxf-client","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":6,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-07-04T05:43:40.000Z","updated_at":"2026-07-04T05:46:25.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.5.13","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"}],"path":"/samples/client/petstore/jaxrs-cxf-client","ecosystem":"maven"},"body":"Bumps [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) from 1.5.13 to 1.5.33.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.32\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-16 Release of logback version 1.5.32\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In \u003ccode\u003eDefaultProcessor, \u003c/code\u003efixed incorrect check for dependencies contained within a parent model. Previous only the direct children were scanned. This fixes \u003ca href=\"https://redirect.github.com/qos-ch/logback-access/issues/34\"\u003elogback-access/issues/34\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit e807335a67535b4eacce94e942c0bcb649665d93 associated with the tag v_1.5.32. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback  1.5.31\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback version 1.5.31\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fixed missing META-INF/services directory in logback-classic.jar. This issue rendered logback-classic version 1.5.30 unusable with SLF4J.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 168e42f9f9a18a3ffdf31eb2bfe80a71e33ecd8b associated with the tag v_1.5.31. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.30\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback  version 1.5.30\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003cstrong\u003eIn this version, logback-classic.jar was missing the META-INF/services directory, making it unusable with SLF4J. Version 1.5.31 (released later on the same day) fixes this issue.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fix scanning issue when an included file becomes available at a later time. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1021\"\u003eissues/1021\u003c/a\u003e by Sergey Nazarov.\u003c/p\u003e\n\u003cp\u003e• Standardized code for version checking across modules.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 44164f10ca3fb44ce0e68519f13564b87e3aca61 associated with the tag v_1.5.30. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.29\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-09 Release of logback version 1.5.29\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In response to \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1017\"\u003eissues/1017\u003c/a\u003e, appender names and appender references are once again subject to variable substitution, reverting the change introduced in version 1.5.28.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.28\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-06 Release of logback version 1.5.28\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Appender names or appender references are no longer subject to variable substitution.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.13...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=maven\u0026previous-version=1.5.13\u0026new-version=1.5.33)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Dustin4444/openapi-generator/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/Dustin4444/openapi-generator/pull/481","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Dustin4444%2Fopenapi-generator/issues/481","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/481/packages"}},{"old_version":"1.5.20","new_version":"1.5.35","update_type":"patch","path":null,"pr_created_at":"2026-06-30T14:38:52.000Z","version_change":"1.5.20 → 1.5.35","issue":{"uuid":"4777750847","node_id":"PR_kwDOCWqSlc7sRcGV","number":2263,"state":"open","title":"Bump ch.qos.logback:logback-core from 1.5.20 to 1.5.35","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-06-30T14:38:52.000Z","updated_at":"2026-06-30T14:41:08.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.5.20","new_version":"1.5.35","repository_url":"https://github.com/qos-ch/logback"}],"path":null,"ecosystem":"maven"},"body":"Bumps [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) from 1.5.20 to 1.5.35.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.35\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e026-06-23 Release of logback version 1.5.35\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• The 'condition' attribute in \u003ccode\u003e\u0026lt;if\u0026gt;\u003c/code\u003e elements now rejects unicode escape sequences (\\u and \\U). This closes a bypass of the existing prohibition on the new operator in Janino-evaluated conditions. This issue was reported by IcySun (\u003ca href=\"mailto:icysun@qq.com\"\u003eicysun@qq.com\u003c/a\u003e) and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-13006\"\u003eCVE-2026-13006\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• Added \u003ccode\u003eConfiguratorRank.AUTHENTICATING\u003c/code\u003e (rank 100), the highest configurator rank, for certified/authenticating configurators discovered via the ServiceLoader mechanism. \u003ccode\u003eContextInitializer\u003c/code\u003e now requires that at most one such configurator exist on the classpath; if more than one is found, initialization aborts with an error.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eConsoleCharsetPropertyDefiner\u003c/code\u003e is no longer shipped. The Java 21 multi-release compilation of logback-core has been disabled, which removes this class from the published artifact. Configurations that referenced \u003ccode\u003ech.qos.logback.core.property.ConsoleCharsetPropertyDefiner\u003c/code\u003e will need an alternative approach for console charset detection.\u003c/p\u003e\n\u003cp\u003e• The logback-examples module is now included in artifacts published to Maven Central.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eJoranConfigurator.makeAnotherInstance()\u003c/code\u003e and \u003ccode\u003eDefaultJoranConfigurator.performMultiStepConfigurationFileSearch()\u003c/code\u003e are now protected, allowing derived configurators to override these methods.\u003c/p\u003e\n\u003cp\u003e• A bitwise identical binary of this version can be reproduced by building from source code at commit 08bd1598d565d83444f72983935e7da4746783b7 associated with the tag v_1.5.35. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.34\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-06-01 Release of logback version 1.5.34\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In case certain StackTraceElement values returned by the Throwable.getStackTrace method are null, StackTraceElementProxy substitutes a dummy instance instead of throwing an IllegalArgumentException. This resolves [issues \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003e#1040\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003eqos-ch/logback#1040\u003c/a\u003e), reported by Naotsugu Kobayashi.\u003c/p\u003e\n\u003cp\u003e• HardenedObjectInputStream will now throw an InvalidClassException during deserialization attempts of Proxy classes. This change addresses potential deserialization whitelist bypass vulnerability reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-10532\"\u003eCVE-2026-10532\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bitwise identical binary of this version can be reproduced by building from source code at commit e62272ac152469aec1ede056c3c7d0d7314e7bfe associated with the tag v_1.5.34. This release was built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.32\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-16 Release of logback version 1.5.32\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In \u003ccode\u003eDefaultProcessor, \u003c/code\u003efixed incorrect check for dependencies contained within a parent model. Previous only the direct children were scanned. This fixes \u003ca href=\"https://redirect.github.com/qos-ch/logback-access/issues/34\"\u003elogback-access/issues/34\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit e807335a67535b4eacce94e942c0bcb649665d93 associated with the tag v_1.5.32. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback  1.5.31\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback version 1.5.31\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fixed missing META-INF/services directory in logback-classic.jar. This issue rendered logback-classic version 1.5.30 unusable with SLF4J.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/08bd1598d565d83444f72983935e7da4746783b7\"\u003e\u003ccode\u003e08bd159\u003c/code\u003e\u003c/a\u003e preapre release 1.5.35\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/37d256b825fc62b4a3908fa29d8b4e34acf79ed0\"\u003e\u003ccode\u003e37d256b\u003c/code\u003e\u003c/a\u003e indentation changes only\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d3d73078afbb0691423f60a066d77503fdf05fc3\"\u003e\u003ccode\u003ed3d7307\u003c/code\u003e\u003c/a\u003e minor comment\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fa0411a9393282ba69396ce65f122d281c079ac0\"\u003e\u003ccode\u003efa0411a\u003c/code\u003e\u003c/a\u003e radomize file location\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/834fdba8085727f96fc12214ff6dd71ab3ac6a25\"\u003e\u003ccode\u003e834fdba\u003c/code\u003e\u003c/a\u003e disable consoleCharset test\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/42eabc374ad8348e9f74e9cd4b59ae5168dd1c2b\"\u003e\u003ccode\u003e42eabc3\u003c/code\u003e\u003c/a\u003e fix messages in IfModelHandler\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/347efc8ec3f10defafd0cf6d4b9a0c81b3320c3a\"\u003e\u003ccode\u003e347efc8\u003c/code\u003e\u003c/a\u003e add unicode escape prevention\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/1b6ba73679437670b37aa1d9061ca82dfd554afb\"\u003e\u003ccode\u003e1b6ba73\u003c/code\u003e\u003c/a\u003e allow derived classes to override makeAnotherInstance\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/340e8be17c9a43d022c301e00b83601affd1fee5\"\u003e\u003ccode\u003e340e8be\u003c/code\u003e\u003c/a\u003e check for unicode escape codes in Janino conditions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/4468f5e5fb67872a14131a7d4feb736131d17202\"\u003e\u003ccode\u003e4468f5e\u003c/code\u003e\u003c/a\u003e adding support for certifying configurators\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.20...v_1.5.35\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=maven\u0026previous-version=1.5.20\u0026new-version=1.5.35)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/navikt/veilarbportefolje/pull/2263","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/navikt%2Fveilarbportefolje/issues/2263","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2263/packages"}},{"old_version":"1.3.12","new_version":"1.5.25","update_type":"minor","path":"the gradle group across 1 directory","pr_created_at":"2026-06-25T17:34:27.000Z","version_change":"1.3.12 → 1.5.25","issue":{"uuid":"4746076339","node_id":"PR_kwDOSh_Isc7qrGPx","number":28,"state":"open","title":"chore(deps): bump ch.qos.logback:logback-core from 1.3.12 to 1.5.25 in the gradle group across 1 directory","user":"dependabot[bot]","labels":["dependency-upgrade"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-06-25T17:34:27.000Z","updated_at":"2026-06-25T17:40:53.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.3.12","new_version":"1.5.25","repository_url":"https://github.com/qos-ch/logback"}],"path":"the gradle group across 1 directory","ecosystem":"maven"},"body":"Bumps the gradle group with 1 update in the / directory: [ch.qos.logback:logback-core](https://github.com/qos-ch/logback).\n\nUpdates `ch.qos.logback:logback-core` from 1.3.12 to 1.5.25\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.25\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-01-17 Release of logback version 1.5.25\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• When processing configuration files, logback-core will now only instantiate components compatible with the class expected by the encapsulating class. This fixes an ACE vulnerability recorded as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-1225\"\u003eCVE-2026-1225\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• In configuration files, referencing a single undeclared appender would cause all referenced appenders to be skipped. This issue was discovered in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/997\"\u003eissues/997\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• Added VersionUtil class to logback-core. This utility class checks for version compatibility issues and alerts the user if need be.\u003c/p\u003e\n\u003cp\u003e• Added \u003ca href=\"https://logback.qos.ch/manual/layouts.html#epoch\"\u003eEpochConverter\u003c/a\u003e to output milliseconds/seconds since epoch. This enhancement was requested by Duncan Jauncey in \u003ca href=\"https://redirect.github.com/qos-ch/logback/pull/1000\"\u003eissues/1000\u003c/a\u003e who also provided the relevant implementation PR.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit f426e0002800cfb507f393fcacffe0761a425220 associated with the tag v_1.5.25. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.24\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-01-06 Release of logback version 1.5.24\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Added ExpressionPropertyCondition a PropertyCondition that can evaluate boolean expressions similar to Java. See \u003ca href=\"https://logback.qos.ch/manual/configuration.html#conditionalExp\"\u003ethe relevant documentation\u003c/a\u003e for further details.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 62bc5fc245dd3a52f3dd45e232733f4cefb4806d associated with the tag v_1.5.24. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.23\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2025-12-21 Release of logback version 1.5.23\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In response to \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/959\"\u003eissues/959\u003c/a\u003e file name collisions are detected at configuration time by analyzing the configuration file and no longer at run time. This avoids the \u003ccode\u003eConcurrentModificationException\u003c/code\u003e reported in the issue.\u003c/p\u003e\n\u003cp\u003e• ZIP and XZ compression now use a \u003ccode\u003eBufferedOutputStream\u003c/code\u003e when writing to the compressed file. This issue was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/988\"\u003eissues/988\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 0bcc3feb54a6d99caac70969ee5f8334aad1fbaf associated with the tag v_1.5.23. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.22\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2025-12-11 Release of logback version 1.5.22\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In order to prevent involuntary information leakage, Logback will no longer output the value of a substituted variable, if the variable name contains any of the case-insensitive strings \u0026quot;password\u0026quot;, \u0026quot;secret\u0026quot; or \u0026quot;confidential\u0026quot;. This problem was reported by Chintan Rohila in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/986\"\u003eissues/986\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• Logback now takes the overridden \u003ccode\u003etoString()\u003c/code\u003e method of \u003ccode\u003eThrowable\u003c/code\u003e subclasses into account when  printing stack traces. This issue was reported in \u003ca href=\"https://jira.qos.ch/browse/LOGBACK-543\"\u003eLOGBACK-543\u003c/a\u003e by Alvin Chee, with a fix provided in \u003ca href=\"https://redirect.github.com/qos-ch/logback/pull/404\"\u003ePR 404\u003c/a\u003e by Brett Kail.\u003c/p\u003e\n\u003cp\u003e• Instead of limit-counting guard, Logback now uses a tumbling-window guard to rate limit internal error messages.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 572379aabd2f672b49593e4020696c624541e5b0 associated with the tag v_1.5.22. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.21\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2025-11-10 Release of logback version 1.5.21\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Invocations of turbo filters in isDebugEnabled, isInfoEnabled()... remain as they were, untouched. However, any installed instances of TurboFilter are now invoked also from within the log(LoggingEvent) method of \u003ca href=\"https://github.com/qos-ch/logback/blob/master/logback-classic/src/main/java/ch/qos/logback/classic/Logger.java#L817\"\u003eLogger\u003c/a\u003e with the contents of the LoggingEvent, typically via the fluent API. This fixes \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/871\"\u003eissues/871\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• Removed reentry-guard in most subclasses of \u003ccode\u003eUnsynchronizedAppenderBase\u003c/code\u003e where it was not needed.\u003c/p\u003e\n\u003cp\u003e• \u003ca href=\"https://logback.qos.ch/manual/configuration.html#auto_configuration\"\u003eInitialization procedure\u003c/a\u003e has been simplified by removing the step instantiating a \u003ccode\u003eSerializedModelConfigurator\u003c/code\u003e. However, it is still possible to set up \u003ccode\u003eSerializedModelConfigurator\u003c/code\u003e as a custom configurator.\u003c/p\u003e\n\u003cp\u003e• JsonEncoder is now friendlier to derivation by sub-classes as requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/979\"\u003eissues/979.\u003c/a\u003e\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/f426e0002800cfb507f393fcacffe0761a425220\"\u003e\u003ccode\u003ef426e00\u003c/code\u003e\u003c/a\u003e prepare release of 1.5.25\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d28931f3b9ede954285cd22d44e029142bba52e6\"\u003e\u003ccode\u003ed28931f\u003c/code\u003e\u003c/a\u003e restrict object creation to expected supertype\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/aa264f7ad2bb65c2d5ab046754741e56234c9096\"\u003e\u003ccode\u003eaa264f7\u003c/code\u003e\u003c/a\u003e test default variable values in appender-ref ref attribute\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/8fb403ab6d1a36b351e9095f8ee1c6c3ad8e0405\"\u003e\u003ccode\u003e8fb403a\u003c/code\u003e\u003c/a\u003e adjust copyright year\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b294a12ff9f2bb2f03168590da1c6d7cbfd71cfe\"\u003e\u003ccode\u003eb294a12\u003c/code\u003e\u003c/a\u003e check optionList in start()\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b65040a3b5d844a791bd3cc690ca44e9e024e04d\"\u003e\u003ccode\u003eb65040a\u003c/code\u003e\u003c/a\u003e Add EpochConverter for milliseconds/seconds since epoch (related to issue \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/96\"\u003e#96\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/069017445b41e9c3a23bda2be446663dca3c4453\"\u003e\u003ccode\u003e0690174\u003c/code\u003e\u003c/a\u003e cla for Duncan Jauncey\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/71dc2afc1046e7b7e218dbfbcde3b0c549bc2fba\"\u003e\u003ccode\u003e71dc2af\u003c/code\u003e\u003c/a\u003e Removed email address for Tony.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/1f97ae1844b1be8486e4e9cade98d7123d3eded5\"\u003e\u003ccode\u003e1f97ae1\u003c/code\u003e\u003c/a\u003e check for undeclared by referenced appenders\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b07355e26aaf128c8303393b7e2ed3d4687c7736\"\u003e\u003ccode\u003eb07355e\u003c/code\u003e\u003c/a\u003e Move the artifact version checking code to VersionUtil in logback-core.\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.3.12...v_1.5.25\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=gradle\u0026previous-version=1.3.12\u0026new-version=1.5.25)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/kestra-io/plugin-huawei/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/kestra-io/plugin-huawei/pull/28","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/kestra-io%2Fplugin-huawei/issues/28","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/28/packages"}},{"old_version":"1.5.18","new_version":"1.5.34","update_type":"patch","path":null,"pr_created_at":"2026-06-09T09:33:49.000Z","version_change":"1.5.18 → 1.5.34","issue":{"uuid":"4620762590","node_id":"PR_kwDORpI3ds7kT5Y4","number":134,"state":"closed","title":"build(deps): bump the all-maven group across 1 directory with 115 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-06-14T02:02:27.000Z","author_association":null,"state_reason":null,"created_at":"2026-06-09T09:33:49.000Z","updated_at":"2026-06-14T02:02:36.000Z","time_to_close":404918,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"all-maven","update_count":115,"packages":[{"name":"org.springframework.boot:spring-boot-starter-parent","old_version":"3.5.14","new_version":"4.0.6","repository_url":"https://github.com/spring-projects/spring-boot"},{"name":"org.springframework.ai:spring-ai-bom","old_version":"1.0.0","new_version":"1.1.7","repository_url":"https://github.com/spring-projects/spring-ai"},{"name":"com.squareup.okio:okio-jvm","old_version":"3.6.0","new_version":"3.17.0","repository_url":"https://github.com/square/okio"},{"name":"com.squareup.okio:okio","old_version":"3.4.0","new_version":"3.17.0","repository_url":"https://github.com/square/okio"},{"name":"org.springframework.cloud:spring-cloud-dependencies","old_version":"2025.0.2","new_version":"2025.1.1","repository_url":"https://github.com/spring-cloud/spring-cloud-release"},{"name":"io.opentelemetry.instrumentation:opentelemetry-instrumentation-annotations","old_version":"2.22.0","new_version":"2.28.1","repository_url":"https://github.com/open-telemetry/opentelemetry-java-instrumentation"},{"name":"org.apache.xmlbeans:xmlbeans","old_version":"5.1.1","new_version":"5.3.0"},{"name":"commons-io:commons-io","old_version":"2.19.0","new_version":"2.22.0"},{"name":"org.jsoup:jsoup","old_version":"1.18.1","new_version":"1.22.2","repository_url":"https://github.com/jhy/jsoup"},{"name":"org.jetbrains:annotations","old_version":"24.0.1","new_version":"26.1.0","repository_url":"https://github.com/JetBrains/java-annotations"},{"name":"org.apache.commons:commons-compress","old_version":"1.24.0","new_version":"1.28.0","repository_url":"https://github.com/apache/commons-compress"},{"name":"com.github.pagehelper:pagehelper","old_version":"5.3.3","new_version":"6.1.1","repository_url":"https://github.com/pagehelper/Mybatis-PageHelper"},{"name":"com.iwhaleai.byai:by-framework","old_version":"0.2.6","new_version":"0.2.8"},{"name":"com.fasterxml.woodstox:woodstox-core","old_version":"7.0.0","new_version":"7.2.1","repository_url":"https://github.com/FasterXML/woodstox"},{"name":"org.glassfish.hk2:hk2-api","old_version":"3.1.1","new_version":"4.0.1"},{"name":"org.eclipse.parsson:parsson","old_version":"1.1.7","new_version":"1.1.9","repository_url":"https://github.com/eclipse-ee4j/parsson"},{"name":"com.google.errorprone:error_prone_annotations","old_version":"2.36.0","new_version":"2.49.0"},{"name":"org.opengauss:opengauss-jdbc","old_version":"6.0.0","new_version":"6.0.3"},{"name":"com.alibaba:druid","old_version":"1.2.23","new_version":"1.2.28","repository_url":"https://github.com/alibaba/druid"},{"name":"com.mysql:mysql-connector-j","old_version":"8.4.0","new_version":"9.7.0","repository_url":"https://github.com/mysql/mysql-connector-j"},{"name":"org.mybatis:mybatis","old_version":"3.5.14","new_version":"3.5.19","repository_url":"https://github.com/mybatis/mybatis-3"},{"name":"org.mybatis:mybatis-spring","old_version":"3.0.3","new_version":"4.0.0","repository_url":"https://github.com/mybatis/spring"},{"name":"org.apache.commons:commons-lang3","old_version":"3.13.0","new_version":"3.20.0"},{"name":"org.apache.commons:commons-collections4","old_version":"4.4","new_version":"4.5.0"},{"name":"commons-codec:commons-codec","old_version":"1.16.0","new_version":"1.22.0","repository_url":"https://github.com/apache/commons-codec"},{"name":"jakarta.xml.bind:jakarta.xml.bind-api","old_version":"4.0.0","new_version":"4.0.5","repository_url":"https://github.com/jakartaee/jaxb-api"},{"name":"org.glassfish.jaxb:jaxb-runtime","old_version":"4.0.2","new_version":"4.0.9"},{"name":"jakarta.activation:jakarta.activation-api","old_version":"2.1.1","new_version":"2.1.4","repository_url":"https://github.com/jakartaee/jaf-api"},{"name":"io.github.resilience4j:resilience4j-spring-boot3","old_version":"2.0.2","new_version":"2.4.0"},{"name":"io.github.resilience4j:resilience4j-circuitbreaker","old_version":"2.0.2","new_version":"2.4.0"},{"name":"io.github.resilience4j:resilience4j-ratelimiter","old_version":"2.0.2","new_version":"2.4.0","repository_url":"https://github.com/resilience4j/resilience4j"},{"name":"io.github.resilience4j:resilience4j-retry","old_version":"2.0.2","new_version":"2.4.0","repository_url":"https://github.com/resilience4j/resilience4j"},{"name":"io.github.resilience4j:resilience4j-bulkhead","old_version":"2.0.2","new_version":"2.4.0"},{"name":"io.github.resilience4j:resilience4j-timelimiter","old_version":"2.0.2","new_version":"2.4.0","repository_url":"https://github.com/resilience4j/resilience4j"},{"name":"org.springdoc:springdoc-openapi-starter-webmvc-ui","old_version":"2.8.8","new_version":"3.0.3","repository_url":"https://github.com/springdoc/springdoc-openapi"},{"name":"org.springdoc:springdoc-openapi-starter-common","old_version":"2.8.8","new_version":"3.0.3","repository_url":"https://github.com/springdoc/springdoc-openapi"},{"name":"io.jsonwebtoken:jjwt-api","old_version":"0.11.5","new_version":"0.13.0","repository_url":"https://github.com/jwtk/jjwt"},{"name":"io.jsonwebtoken:jjwt-impl","old_version":"0.11.5","new_version":"0.13.0","repository_url":"https://github.com/jwtk/jjwt"},{"name":"io.jsonwebtoken:jjwt-jackson","old_version":"0.11.5","new_version":"0.13.0"},{"name":"com.alibaba:transmittable-thread-local","old_version":"2.14.2","new_version":"2.14.5","repository_url":"https://github.com/alibaba/transmittable-thread-local"},{"name":"org.junit.jupiter:junit-jupiter","old_version":"5.10.0","new_version":"6.1.0","repository_url":"https://github.com/junit-team/junit-framework"},{"name":"com.alibaba:fastjson","old_version":"2.0.53","new_version":"2.0.62","repository_url":"https://github.com/alibaba/fastjson2"},{"name":"redis.clients:jedis","old_version":"6.0.0","new_version":"7.5.2"},{"name":"com.squareup.okhttp3:okhttp","old_version":"4.12.0","new_version":"5.4.0","repository_url":"https://github.com/square/okhttp"},{"name":"com.squareup.okhttp3:okhttp-sse","old_version":"4.12.0","new_version":"5.4.0","repository_url":"https://github.com/square/okhttp"},{"name":"com.google.protobuf:protobuf-java","old_version":"3.24.4","new_version":"4.35.0"},{"name":"org.apache.poi:poi","old_version":"5.2.4","new_version":"5.5.1"},{"name":"org.apache.poi:poi-ooxml","old_version":"5.2.4","new_version":"5.5.1"},{"name":"org.apache.poi:poi-scratchpad","old_version":"5.2.4","new_version":"5.5.1"},{"name":"fr.opensagres.xdocreport:fr.opensagres.poi.xwpf.converter.pdf","old_version":"2.0.4","new_version":"2.2.0"},{"name":"org.hibernate.validator:hibernate-validator","old_version":"8.0.1.Final","new_version":"9.1.0.Final","repository_url":"https://github.com/hibernate/hibernate-validator"},{"name":"ch.qos.logback:logback-classic","old_version":"1.5.18","new_version":"1.5.34","repository_url":"https://github.com/qos-ch/logback"},{"name":"ch.qos.logback:logback-core","old_version":"1.5.18","new_version":"1.5.34","repository_url":"https://github.com/qos-ch/logback"},{"name":"org.apache.tomcat:tomcat-annotations-api","old_version":"10.1.55","new_version":"11.0.22"},{"name":"org.apache.tomcat.embed:tomcat-embed-el","old_version":"10.1.55","new_version":"11.0.22"},{"name":"com.google.guava:guava","old_version":"33.4.8-jre","new_version":"33.6.0-jre","repository_url":"https://github.com/google/guava"},{"name":"org.springframework.security:spring-security-crypto","old_version":"6.5.9","new_version":"7.0.5","repository_url":"https://github.com/spring-projects/spring-security"},{"name":"org.springframework.security:spring-security-web","old_version":"6.5.9","new_version":"7.0.5","repository_url":"https://github.com/spring-projects/spring-security"},{"name":"org.springframework.security:spring-security-core","old_version":"6.5.9","new_version":"7.0.5","repository_url":"https://github.com/spring-projects/spring-security"},{"name":"org.springframework.security:spring-security-config","old_version":"6.5.9","new_version":"7.0.5","repository_url":"https://github.com/spring-projects/spring-security"},{"name":"org.yaml:snakeyaml","old_version":"2.0","new_version":"2.6"},{"name":"com.itextpdf:itextpdf","old_version":"5.5.13.4","new_version":"5.5.13.5","repository_url":"https://github.com/itext/itextpdf"},{"name":"io.netty:netty-all","old_version":"4.1.133.Final","new_version":"4.2.15.Final","repository_url":"https://github.com/netty/netty"},{"name":"org.apache.kafka:kafka-clients","old_version":"3.9.2","new_version":"4.3.0"},{"name":"com.auth0:java-jwt","old_version":"4.4.0","new_version":"4.5.2"},{"name":"org.apache.httpcomponents:httpclient","old_version":"4.5.13","new_version":"4.5.14"},{"name":"com.alibaba:druid-spring-boot-starter","old_version":"1.1.9","new_version":"1.2.28","repository_url":"https://github.com/alibaba/druid"},{"name":"io.minio:minio","old_version":"8.6.0","new_version":"9.0.1","repository_url":"https://github.com/minio/minio-java"},{"name":"commons-net:commons-net","old_version":"3.9.0","new_version":"3.13.0","repository_url":"https://github.com/apache/commons-net"},{"name":"com.clickhouse:clickhouse-jdbc","old_version":"0.4.6","new_version":"0.9.8","repository_url":"https://github.com/ClickHouse/clickhouse-java"},{"name":"com.vesoft:client","old_version":"3.0.0","new_version":"3.8.4"},{"name":"co.elastic.clients:elasticsearch-java","old_version":"8.15.5","new_version":"9.4.2","repository_url":"https://github.com/elastic/elasticsearch-java"},{"name":"org.elasticsearch.client:elasticsearch-rest-client","old_version":"8.15.5","new_version":"9.4.2","repository_url":"https://github.com/elastic/elasticsearch"},{"name":"org.elasticsearch:elasticsearch","old_version":"8.15.5","new_version":"9.4.2","repository_url":"https://github.com/elastic/elasticsearch"},{"name":"org.elasticsearch:elasticsearch-x-content","old_version":"8.15.5","new_version":"9.4.2","repository_url":"https://github.com/elastic/elasticsearch"},{"name":"com.baomidou:mybatis-plus-extension","old_version":"3.5.5","new_version":"3.5.16","repository_url":"https://github.com/baomidou/mybatis-plus"},{"name":"org.springframework.boot:spring-boot-starter-test","old_version":"3.2.0","new_version":"4.0.6","repository_url":"https://github.com/spring-projects/spring-boot"},{"name":"com.baomidou:mybatis-plus-boot-starter","old_version":"3.5.5","new_version":"3.5.16","repository_url":"https://github.com/baomidou/mybatis-plus"},{"name":"com.github.jsqlparser:jsqlparser","old_version":"4.5","new_version":"5.3","repository_url":"https://github.com/JSQLParser/JSqlParser"},{"name":"com.aliyun:tea","old_version":"1.3.1","new_version":"1.4.2","repository_url":"https://github.com/aliyun/tea-java"},{"name":"commons-logging:commons-logging","old_version":"1.2","new_version":"1.3.6","repository_url":"https://github.com/apache/commons-logging"},{"name":"com.aliyun:tea-util","old_version":"0.2.23","new_version":"0.2.27","repository_url":"https://github.com/aliyun/tea-util"},{"name":"org.jacoco:org.jacoco.agent","old_version":"0.8.8","new_version":"0.8.15","repository_url":"https://github.com/jacoco/jacoco"},{"name":"com.aliyun:tea-openapi","old_version":"0.3.8","new_version":"0.3.15","repository_url":"https://github.com/aliyun/darabonba-openapi"},{"name":"com.github.pagehelper:pagehelper-spring-boot-starter","old_version":"1.4.7","new_version":"4.1.0","repository_url":"https://github.com/pagehelper/pagehelper-spring-boot"},{"name":"com.aliyun:dingtalk","old_version":"2.2.17","new_version":"2.2.53","repository_url":"https://github.com/aliyun/alibabacloud-sdk"},{"name":"com.aliyun:dysmsapi20170525","old_version":"2.0.24","new_version":"4.5.1","repository_url":"https://github.com/aliyun/alibabacloud-sdk"},{"name":"com.aliyun:credentials-java","old_version":"1.0.2","new_version":"1.0.3","repository_url":"https://github.com/aliyun/credentials-java"},{"name":"org.mybatis.spring.boot:mybatis-spring-boot-starter","old_version":"3.0.4","new_version":"4.0.1","repository_url":"https://github.com/mybatis/spring-boot-starter"},{"name":"org.xerial.snappy:snappy-java","old_version":"1.1.10.5","new_version":"1.1.10.8","repository_url":"https://github.com/xerial/snappy-java"},{"name":"joda-time:joda-time","old_version":"2.10.10","new_version":"2.14.2","repository_url":"https://github.com/JodaOrg/joda-time"},{"name":"io.swagger:swagger-annotations","old_version":"1.5.24","new_version":"1.6.16"},{"name":"tools.jackson.core:jackson-core","old_version":"3.1.1","new_version":"3.2.0"},{"name":"tools.jackson.core:jackson-databind","old_version":"3.1.1","new_version":"3.2.0"},{"name":"tools.jackson.dataformat:jackson-dataformat-yaml","old_version":"3.1.1","new_version":"3.2.0"},{"name":"org.projectlombok:lombok","old_version":"1.18.38","new_version":"1.18.46","repository_url":"https://github.com/projectlombok/lombok"},{"name":"jakarta.annotation:jakarta.annotation-api","old_version":"2.1.1","new_version":"3.0.0","repository_url":"https://github.com/jakartaee/common-annotations-api"},{"name":"cn.hutool:hutool-all","old_version":"5.8.38","new_version":"5.8.46","repository_url":"https://github.com/looly/hutool"},{"name":"com.aliyun.oss:aliyun-sdk-oss","old_version":"3.17.2","new_version":"3.18.5","repository_url":"https://github.com/aliyun/aliyun-oss-java-sdk"},{"name":"org.xerial:sqlite-jdbc","old_version":"3.46.1.0","new_version":"3.53.2.0","repository_url":"https://github.com/xerial/sqlite-jdbc"},{"name":"com.google.zxing:core","old_version":"3.3.3","new_version":"3.5.4","repository_url":"https://github.com/zxing/zxing"},{"name":"com.dingtalk.open:app-stream-client","old_version":"1.0.5","new_version":"1.3.12"},{"name":"io.modelcontextprotocol.sdk:mcp","old_version":"1.0.0","new_version":"1.1.3","repository_url":"https://github.com/modelcontextprotocol/java-sdk"},{"name":"dev.langchain4j:langchain4j-mcp","old_version":"1.1.0-beta7","new_version":"1.16.1-beta26","repository_url":"https://github.com/langchain4j/langchain4j"},{"name":"dev.langchain4j:langchain4j-core","old_version":"1.1.0","new_version":"1.16.1","repository_url":"https://github.com/langchain4j/langchain4j"},{"name":"dev.langchain4j:langchain4j","old_version":"1.1.0","new_version":"1.16.1","repository_url":"https://github.com/langchain4j/langchain4j"},{"name":"org.apache.pdfbox:pdfbox","old_version":"3.0.3","new_version":"3.0.7"},{"name":"com.github.librepdf:openpdf","old_version":"1.3.30","new_version":"3.0.5"},{"name":"mysql:mysql-connector-java","old_version":"5.1.26","new_version":"8.0.33"},{"name":"org.apache.maven.plugins:maven-dependency-plugin","old_version":"3.6.1","new_version":"3.11.0","repository_url":"https://github.com/apache/maven-dependency-plugin"},{"name":"org.apache.maven.plugins:maven-compiler-plugin","old_version":"3.11.0","new_version":"3.15.0","repository_url":"https://github.com/apache/maven-compiler-plugin"},{"name":"org.apache.maven.plugins:maven-enforcer-plugin","old_version":"3.4.1","new_version":"3.6.3","repository_url":"https://github.com/apache/maven-enforcer"},{"name":"org.apache.maven.plugins:maven-surefire-plugin","old_version":"3.2.5","new_version":"3.5.6","repository_url":"https://github.com/apache/maven-surefire"},{"name":"org.apache.maven.plugins:maven-help-plugin","old_version":"3.4.1","new_version":"3.5.1","repository_url":"https://github.com/apache/maven-help-plugin"},{"name":"org.mybatis.generator:mybatis-generator-maven-plugin","old_version":"1.3.7","new_version":"2.0.0"}],"path":null,"ecosystem":"maven"},"body":"Bumps the all-maven group with 115 updates in the /byclaw-be directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [org.springframework.boot:spring-boot-starter-parent](https://github.com/spring-projects/spring-boot) | `3.5.14` | `4.0.6` |\n| [org.springframework.ai:spring-ai-bom](https://github.com/spring-projects/spring-ai) | `1.0.0` | `1.1.7` |\n| [com.squareup.okio:okio-jvm](https://github.com/square/okio) | `3.6.0` | `3.17.0` |\n| [com.squareup.okio:okio](https://github.com/square/okio) | `3.4.0` | `3.17.0` |\n| [org.springframework.cloud:spring-cloud-dependencies](https://github.com/spring-cloud/spring-cloud-release) | `2025.0.2` | `2025.1.1` |\n| [io.opentelemetry.instrumentation:opentelemetry-instrumentation-annotations](https://github.com/open-telemetry/opentelemetry-java-instrumentation) | `2.22.0` | `2.28.1` |\n| org.apache.xmlbeans:xmlbeans | `5.1.1` | `5.3.0` |\n| commons-io:commons-io | `2.19.0` | `2.22.0` |\n| [org.jsoup:jsoup](https://github.com/jhy/jsoup) | `1.18.1` | `1.22.2` |\n| [org.jetbrains:annotations](https://github.com/JetBrains/java-annotations) | `24.0.1` | `26.1.0` |\n| [org.apache.commons:commons-compress](https://github.com/apache/commons-compress) | `1.24.0` | `1.28.0` |\n| [com.github.pagehelper:pagehelper](https://github.com/pagehelper/Mybatis-PageHelper) | `5.3.3` | `6.1.1` |\n| com.iwhaleai.byai:by-framework | `0.2.6` | `0.2.8` |\n| [com.fasterxml.woodstox:woodstox-core](https://github.com/FasterXML/woodstox) | `7.0.0` | `7.2.1` |\n| org.glassfish.hk2:hk2-api | `3.1.1` | `4.0.1` |\n| [org.eclipse.parsson:parsson](https://github.com/eclipse-ee4j/parsson) | `1.1.7` | `1.1.9` |\n| com.google.errorprone:error_prone_annotations | `2.36.0` | `2.49.0` |\n| org.opengauss:opengauss-jdbc | `6.0.0` | `6.0.3` |\n| [com.alibaba:druid](https://github.com/alibaba/druid) | `1.2.23` | `1.2.28` |\n| [com.mysql:mysql-connector-j](https://github.com/mysql/mysql-connector-j) | `8.4.0` | `9.7.0` |\n| [org.mybatis:mybatis](https://github.com/mybatis/mybatis-3) | `3.5.14` | `3.5.19` |\n| [org.mybatis:mybatis-spring](https://github.com/mybatis/spring) | `3.0.3` | `4.0.0` |\n| org.apache.commons:commons-lang3 | `3.13.0` | `3.20.0` |\n| org.apache.commons:commons-collections4 | `4.4` | `4.5.0` |\n| [commons-codec:commons-codec](https://github.com/apache/commons-codec) | `1.16.0` | `1.22.0` |\n| [jakarta.xml.bind:jakarta.xml.bind-api](https://github.com/jakartaee/jaxb-api) | `4.0.0` | `4.0.5` |\n| org.glassfish.jaxb:jaxb-runtime | `4.0.2` | `4.0.9` |\n| [jakarta.activation:jakarta.activation-api](https://github.com/jakartaee/jaf-api) | `2.1.1` | `2.1.4` |\n| io.github.resilience4j:resilience4j-spring-boot3 | `2.0.2` | `2.4.0` |\n| io.github.resilience4j:resilience4j-circuitbreaker | `2.0.2` | `2.4.0` |\n| [io.github.resilience4j:resilience4j-ratelimiter](https://github.com/resilience4j/resilience4j) | `2.0.2` | `2.4.0` |\n| [io.github.resilience4j:resilience4j-retry](https://github.com/resilience4j/resilience4j) | `2.0.2` | `2.4.0` |\n| io.github.resilience4j:resilience4j-bulkhead | `2.0.2` | `2.4.0` |\n| [io.github.resilience4j:resilience4j-timelimiter](https://github.com/resilience4j/resilience4j) | `2.0.2` | `2.4.0` |\n| [org.springdoc:springdoc-openapi-starter-webmvc-ui](https://github.com/springdoc/springdoc-openapi) | `2.8.8` | `3.0.3` |\n| [org.springdoc:springdoc-openapi-starter-common](https://github.com/springdoc/springdoc-openapi) | `2.8.8` | `3.0.3` |\n| [io.jsonwebtoken:jjwt-api](https://github.com/jwtk/jjwt) | `0.11.5` | `0.13.0` |\n| [io.jsonwebtoken:jjwt-impl](https://github.com/jwtk/jjwt) | `0.11.5` | `0.13.0` |\n| io.jsonwebtoken:jjwt-jackson | `0.11.5` | `0.13.0` |\n| [com.alibaba:transmittable-thread-local](https://github.com/alibaba/transmittable-thread-local) | `2.14.2` | `2.14.5` |\n| [org.junit.jupiter:junit-jupiter](https://github.com/junit-team/junit-framework) | `5.10.0` | `6.1.0` |\n| [com.alibaba:fastjson](https://github.com/alibaba/fastjson2) | `2.0.53` | `2.0.62` |\n| redis.clients:jedis | `6.0.0` | `7.5.2` |\n| [com.squareup.okhttp3:okhttp](https://github.com/square/okhttp) | `4.12.0` | `5.4.0` |\n| [com.squareup.okhttp3:okhttp-sse](https://github.com/square/okhttp) | `4.12.0` | `5.4.0` |\n| com.google.protobuf:protobuf-java | `3.24.4` | `4.35.0` |\n| org.apache.poi:poi | `5.2.4` | `5.5.1` |\n| org.apache.poi:poi-ooxml | `5.2.4` | `5.5.1` |\n| org.apache.poi:poi-scratchpad | `5.2.4` | `5.5.1` |\n| fr.opensagres.xdocreport:fr.opensagres.poi.xwpf.converter.pdf | `2.0.4` | `2.2.0` |\n| [org.hibernate.validator:hibernate-validator](https://github.com/hibernate/hibernate-validator) | `8.0.1.Final` | `9.1.0.Final` |\n| [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) | `1.5.18` | `1.5.34` |\n| [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) | `1.5.18` | `1.5.34` |\n| org.apache.tomcat:tomcat-annotations-api | `10.1.55` | `11.0.22` |\n| org.apache.tomcat.embed:tomcat-embed-el | `10.1.55` | `11.0.22` |\n| [com.google.guava:guava](https://github.com/google/guava) | `33.4.8-jre` | `33.6.0-jre` |\n| [org.springframework.security:spring-security-crypto](https://github.com/spring-projects/spring-security) | `6.5.9` | `7.0.5` |\n| [org.springframework.security:spring-security-web](https://github.com/spring-projects/spring-security) | `6.5.9` | `7.0.5` |\n| [org.springframework.security:spring-security-core](https://github.com/spring-projects/spring-security) | `6.5.9` | `7.0.5` |\n| [org.springframework.security:spring-security-config](https://github.com/spring-projects/spring-security) | `6.5.9` | `7.0.5` |\n| [org.yaml:snakeyaml](https://bitbucket.org/snakeyaml/snakeyaml) | `2.0` | `2.6` |\n| [com.itextpdf:itextpdf](https://github.com/itext/itextpdf) | `5.5.13.4` | `5.5.13.5` |\n| [io.netty:netty-all](https://github.com/netty/netty) | `4.1.133.Final` | `4.2.15.Final` |\n| org.apache.kafka:kafka-clients | `3.9.2` | `4.3.0` |\n| com.auth0:java-jwt | `4.4.0` | `4.5.2` |\n| org.apache.httpcomponents:httpclient | `4.5.13` | `4.5.14` |\n| [com.alibaba:druid-spring-boot-starter](https://github.com/alibaba/druid) | `1.1.9` | `1.2.28` |\n| [io.minio:minio](https://github.com/minio/minio-java) | `8.6.0` | `9.0.1` |\n| [commons-net:commons-net](https://github.com/apache/commons-net) | `3.9.0` | `3.13.0` |\n| [com.clickhouse:clickhouse-jdbc](https://github.com/ClickHouse/clickhouse-java) | `0.4.6` | `0.9.8` |\n| com.vesoft:client | `3.0.0` | `3.8.4` |\n| [co.elastic.clients:elasticsearch-java](https://github.com/elastic/elasticsearch-java) | `8.15.5` | `9.4.2` |\n| [org.elasticsearch.client:elasticsearch-rest-client](https://github.com/elastic/elasticsearch) | `8.15.5` | `9.4.2` |\n| [org.elasticsearch:elasticsearch](https://github.com/elastic/elasticsearch) | `8.15.5` | `9.4.2` |\n| [org.elasticsearch:elasticsearch-x-content](https://github.com/elastic/elasticsearch) | `8.15.5` | `9.4.2` |\n| [com.baomidou:mybatis-plus-extension](https://github.com/baomidou/mybatis-plus) | `3.5.5` | `3.5.16` |\n| [org.springframework.boot:spring-boot-starter-test](https://github.com/spring-projects/spring-boot) | `3.2.0` | `4.0.6` |\n| [com.baomidou:mybatis-plus-boot-starter](https://github.com/baomidou/mybatis-plus) | `3.5.5` | `3.5.16` |\n| [com.github.jsqlparser:jsqlparser](https://github.com/JSQLParser/JSqlParser) | `4.5` | `5.3` |\n| [com.aliyun:tea](https://github.com/aliyun/tea-java) | `1.3.1` | `1.4.2` |\n| [commons-logging:commons-logging](https://github.com/apache/commons-logging) | `1.2` | `1.3.6` |\n| [com.aliyun:tea-util](https://github.com/aliyun/tea-util) | `0.2.23` | `0.2.27` |\n| [org.jacoco:org.jacoco.agent](https://github.com/jacoco/jacoco) | `0.8.8` | `0.8.15` |\n| [com.aliyun:tea-openapi](https://github.com/aliyun/darabonba-openapi) | `0.3.8` | `0.3.15` |\n| [com.github.pagehelper:pagehelper-spring-boot-starter](https://github.com/pagehelper/pagehelper-spring-boot) | `1.4.7` | `4.1.0` |\n| [com.aliyun:dingtalk](https://github.com/aliyun/alibabacloud-sdk) | `2.2.17` | `2.2.53` |\n| [com.aliyun:dysmsapi20170525](https://github.com/aliyun/alibabacloud-sdk) | `2.0.24` | `4.5.1` |\n| [com.aliyun:credentials-java](https://github.com/aliyun/credentials-java) | `1.0.2` | `1.0.3` |\n| [org.mybatis.spring.boot:mybatis-spring-boot-starter](https://github.com/mybatis/spring-boot-starter) | `3.0.4` | `4.0.1` |\n| [org.xerial.snappy:snappy-java](https://github.com/xerial/snappy-java) | `1.1.10.5` | `1.1.10.8` |\n| [joda-time:joda-time](https://github.com/JodaOrg/joda-time) | `2.10.10` | `2.14.2` |\n| io.swagger:swagger-annotations | `1.5.24` | `1.6.16` |\n| tools.jackson.core:jackson-core | `3.1.1` | `3.2.0` |\n| tools.jackson.core:jackson-databind | `3.1.1` | `3.2.0` |\n| tools.jackson.dataformat:jackson-dataformat-yaml | `3.1.1` | `3.2.0` |\n| [org.projectlombok:lombok](https://github.com/projectlombok/lombok) | `1.18.38` | `1.18.46` |\n| [jakarta.annotation:jakarta.annotation-api](https://github.com/jakartaee/common-annotations-api) | `2.1.1` | `3.0.0` |\n| [cn.hutool:hutool-all](https://github.com/looly/hutool) | `5.8.38` | `5.8.46` |\n| [com.aliyun.oss:aliyun-sdk-oss](https://github.com/aliyun/aliyun-oss-java-sdk) | `3.17.2` | `3.18.5` |\n| [org.xerial:sqlite-jdbc](https://github.com/xerial/sqlite-jdbc) | `3.46.1.0` | `3.53.2.0` |\n| [com.google.zxing:core](https://github.com/zxing/zxing) | `3.3.3` | `3.5.4` |\n| com.dingtalk.open:app-stream-client | `1.0.5` | `1.3.12` |\n| [io.modelcontextprotocol.sdk:mcp](https://github.com/modelcontextprotocol/java-sdk) | `1.0.0` | `1.1.3` |\n| [dev.langchain4j:langchain4j-mcp](https://github.com/langchain4j/langchain4j) | `1.1.0-beta7` | `1.16.1-beta26` |\n| [dev.langchain4j:langchain4j-core](https://github.com/langchain4j/langchain4j) | `1.1.0` | `1.16.1` |\n| [dev.langchain4j:langchain4j](https://github.com/langchain4j/langchain4j) | `1.1.0` | `1.16.1` |\n| org.apache.pdfbox:pdfbox | `3.0.3` | `3.0.7` |\n| com.github.librepdf:openpdf | `1.3.30` | `3.0.5` |\n| mysql:mysql-connector-java | `5.1.26` | `8.0.33` |\n| [org.apache.maven.plugins:maven-dependency-plugin](https://github.com/apache/maven-dependency-plugin) | `3.6.1` | `3.11.0` |\n| [org.apache.maven.plugins:maven-compiler-plugin](https://github.com/apache/maven-compiler-plugin) | `3.11.0` | `3.15.0` |\n| [org.apache.maven.plugins:maven-enforcer-plugin](https://github.com/apache/maven-enforcer) | `3.4.1` | `3.6.3` |\n| [org.apache.maven.plugins:maven-surefire-plugin](https://github.com/apache/maven-surefire) | `3.2.5` | `3.5.6` |\n| [org.apache.maven.plugins:maven-help-plugin](https://github.com/apache/maven-help-plugin) | `3.4.1` | `3.5.1` |\n| org.mybatis.generator:mybatis-generator-maven-plugin | `1.3.7` | `2.0.0` |\n\n\nUpdates `org.springframework.boot:spring-boot-starter-parent` from 3.5.14 to 4.0.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/spring-projects/spring-boot/releases\"\u003eorg.springframework.boot:spring-boot-starter-parent's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.0.6\u003c/h2\u003e\n\u003ch2\u003e:lady_beetle: Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDefault security is misconfigured when spring-boot-actuator-autoconfigure is present and spring-boot-health is not \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50188\"\u003e#50188\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eElasticsearch Rest5Client auto-configuration misconfigures underlying HTTP client \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50187\"\u003e#50187\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eApplicationPidFileWriter does not handle symlinks correctly \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50185\"\u003e#50185\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRandomValuePropertySource is not suitable for secrets \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50183\"\u003e#50183\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCassandra auto-configuration misconfigures CqlSessionBuilder \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50180\"\u003e#50180\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eApplicationTemp does not handle symlinks correctly \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50178\"\u003e#50178\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemote DevTools performs comparison incorrectly \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50176\"\u003e#50176\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003espring.rabbitmq.ssl.verify-hostname is applied inconsistently \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50174\"\u003e#50174\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWhole number values are ignored when configuring min and max expected values and SLO boundaries for a distribution summary meter \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50077\"\u003e#50077\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eClassic starters are missing several modules \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50071\"\u003e#50071\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eModule spring-boot-resttestclient is missing from spring-boot-starter-test-classic \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/pull/50069\"\u003e#50069\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAnnotations like \u003ccode\u003e@Ssl\u003c/code\u003e don't work on \u003ccode\u003e@Bean\u003c/code\u003e methods when using \u003ccode\u003e@ServiceConnection\u003c/code\u003e \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50064\"\u003e#50064\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEnversRevisionRepositoriesRegistrar should reuse \u003ccode\u003e@EnableEnversRepositories\u003c/code\u003e rather than configuring the JPA counterpart \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50039\"\u003e#50039\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWebFlux Cloud Foundry links endpoint includes query string from received request in resolved links \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50017\"\u003e#50017\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImports on a containing test class are ignored when a nested class has imports \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50012\"\u003e#50012\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWith spring.jackson.use-jackson2-defaults set to true, FAIL_ON_UNKNOWN_PROPERTIES is enabled \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/49951\"\u003e#49951\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e500 response from env endpoint when supplied pattern is invalid \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/49946\"\u003e#49946\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReactive MongoDB starter has a transitive dependency on the synchronous MongoDB driver \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/49945\"\u003e#49945\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHTTP method is lost when configuring excludes in EndpointRequest \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/49943\"\u003e#49943\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHonor HttpMethod for reactive additional endpoint paths \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/49880\"\u003e#49880\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDocker Compose support doesn't work with apache/artemis image \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/49869\"\u003e#49869\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDocker Compose support doesn't work with apache/activemq image \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/49866\"\u003e#49866\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSpring Security's PathPatternRequestMatcher.Builder is not auto-configured when using WebMvcTest and spring-boot-security-test \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/49854\"\u003e#49854\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAPI versioning path strategy should be applied path last as it is not meant to yield \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/49800\"\u003e#49800\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e:notebook_with_decorative_cover: Documentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate docs to encourage Java fundamentals for beginners that prefer to learn that way \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50146\"\u003e#50146\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHTTP Service Interface Clients still document that API versioning can be configured via properties \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50126\"\u003e#50126\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eLink to the observability section of the Lettuce documentation is broken \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50097\"\u003e#50097\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJavadoc for StaticResourceLocation.FAVICON doesn't describe icons location \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50085\"\u003e#50085\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMySamlRelyingPartyConfiguration is missing a Kotlin sample \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50024\"\u003e#50024\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIncorrect default value for management.httpexchanges.recording.include in configuration metadata \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50019\"\u003e#50019\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eLink to the Kubernetes documentation when discussing startup probes \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50015\"\u003e#50015\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTypo in JdbcSessionAutoConfiguration Javadoc \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/pull/49873\"\u003e#49873\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eClarify that configuration property default values are not available through the Environment \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/49851\"\u003e#49851\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDocument the need for Liquibase and Flyway starters \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/pull/49839\"\u003e#49839\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eKafka documentation refers to deprecated JSON serializer and deserializer classes \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/pull/49826\"\u003e#49826\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e:hammer: Dependency Upgrades\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to Elasticsearch Client 9.2.8 \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50027\"\u003e#50027\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade to Groovy 5.0.5 \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/49911\"\u003e#49911\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade to Hibernate 7.2.12.Final \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50134\"\u003e#50134\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade to Jackson Bom 3.1.2 \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50051\"\u003e#50051\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade to \u003ca href=\"https://github.com/jaxen-xpath/jaxen/releases/tag/v2.0.1\"\u003eJaxen 2.0.1\u003c/a\u003e \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50104\"\u003e#50104\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpgrade to \u003ca href=\"https://github.com/FirebirdSQL/jaybird/releases/tag/v6.0.5\"\u003eJaybird 6.0.5\u003c/a\u003e \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/49914\"\u003e#49914\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/8821ad2cd381bb4b9615a61479e1de7305a8ba39\"\u003e\u003ccode\u003e8821ad2\u003c/code\u003e\u003c/a\u003e Release v4.0.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/9e4048a03f17adfe78057a3c4d5b4693305c0ae0\"\u003e\u003ccode\u003e9e4048a\u003c/code\u003e\u003c/a\u003e Merge branch '3.5.x' into 4.0.x\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/20bb11c3984802990572ddbeae8b66885a8f2462\"\u003e\u003ccode\u003e20bb11c\u003c/code\u003e\u003c/a\u003e Next development version (v3.5.15-SNAPSHOT)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/98daa8ea30f39a5b0ca6768b5cbc2dc8698ef4e1\"\u003e\u003ccode\u003e98daa8e\u003c/code\u003e\u003c/a\u003e Merge branch '3.5.x' into 4.0.x\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/874f6294b91da18367b8b5ab7b2fad3fa23cfba6\"\u003e\u003ccode\u003e874f629\u003c/code\u003e\u003c/a\u003e Fix default security with actuator but without health\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/e41b3bf731d1134bc18ec1f68ac01e0fe1c54923\"\u003e\u003ccode\u003ee41b3bf\u003c/code\u003e\u003c/a\u003e Enable hostname verification for SSL connections to Elasticsearch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/ef8527bb0ef8f564f4f9c57a7be99a7aa96c6ab0\"\u003e\u003ccode\u003eef8527b\u003c/code\u003e\u003c/a\u003e Merge branch '3.5.x' into 4.0.x\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/4a7bd332b6d19fef1aa4cf28434985f2b03a2e0f\"\u003e\u003ccode\u003e4a7bd33\u003c/code\u003e\u003c/a\u003e Merge branch '3.5.x' into 4.0.x\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/3a9d836621605d39cfd88b677f2c6085aa1a1402\"\u003e\u003ccode\u003e3a9d836\u003c/code\u003e\u003c/a\u003e Merge branch '3.5.x' into 4.0.x\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/8e013b6f909c3882ed87ca78111e4a8bfe33ff72\"\u003e\u003ccode\u003e8e013b6\u003c/code\u003e\u003c/a\u003e Merge branch '3.5.x' into 4.0.x\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/spring-projects/spring-boot/compare/v3.5.14...v4.0.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.springframework.ai:spring-ai-bom` from 1.0.0 to 1.1.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/spring-projects/spring-ai/releases\"\u003eorg.springframework.ai:spring-ai-bom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eSpring AI 1.1.7\u003c/h2\u003e\n\u003ch2\u003e:star: New Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOllama doesnt work in a graalvm native image \u003ca href=\"https://redirect.github.com/spring-projects/spring-ai/issues/6064\"\u003e#6064\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e:lady_beetle: Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOpenAiChatModel streaming drops chunks due to internal switchMap when using buffered concatMap \u003ca href=\"https://redirect.github.com/spring-projects/spring-ai/issues/6122\"\u003e#6122\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eRedisVectorStore#doDelete\u003c/code\u003e only deletes the 10 first messages \u003ca href=\"https://redirect.github.com/spring-projects/spring-ai/issues/6066\"\u003e#6066\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003eSpring AI 1.1.6 Release Notes\u003c/h1\u003e\n\u003ch2\u003e🎯 Highlights\u003c/h2\u003e\n\u003cp\u003eThis release includes 1 new features, 5 bug fixes, 2 documentation improvements, 5 other improvements.\u003c/p\u003e\n\u003ch2\u003e⏪ Breaking Changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eChat memory advisors now require an explicit conversation ID to be supplied. This is a behavioral change that affects how chat memory is scoped and managed. Applications relying on implicit conversation IDs must be updated to supply an explicit ID. \u003ca href=\"https://github.com/spring-projects/spring-ai/commit/13cde419e30042c663706f130dd65b80d92d4667\"\u003e13cde41\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e⚠️ Upgrading Notes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePromptChatMemoryAdvisor is now deprecated and chat memory advisors require an explicit conversation ID. Update your code to: (1) replace PromptChatMemoryAdvisor with the recommended alternative, and (2) ensure an explicit conversation ID is supplied when using any chat memory advisor. \u003ca href=\"https://github.com/spring-projects/spring-ai/commit/917f62ebec13cf01027c094dd36d4106b1c8dc47\"\u003e917f62e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e⭐ New Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMCP auto-configuration now includes the missing \u003ca href=\"https://github.com/ConditionalOnMissingBean\"\u003e\u003ccode\u003e@​ConditionalOnMissingBean\u003c/code\u003e\u003c/a\u003e check, allowing users to provide their own bean definitions and override the auto-configured MCP beans as expected in Spring Boot auto-configuration patterns. \u003ca href=\"https://github.com/spring-projects/spring-ai/commit/d4025e5d8ede18158cbd9b53b1cc4a0ad107af3a\"\u003ed4025e5\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🪲 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed an issue where the MilvusVectorStore's doDelete method incorrectly escaped strings in the ID list, which could cause deletion operations to fail or behave unexpectedly. \u003ca href=\"https://github.com/spring-projects/spring-ai/commit/20206a46408ef8a9609f54afc7c82a0b5fd2e357\"\u003e20206a4\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed the ChatClientAdvisorTests test suite to supply an explicit conversation ID, aligning tests with the new requirement for explicit conversation IDs in chat memory advisors. \u003ca href=\"https://github.com/spring-projects/spring-ai/commit/704e5c6519c150662c7338782639fa84ffe8c9ed\"\u003e704e5c6\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed the MistralAiChatModelObservationIT integration test to ensure observation functionality works correctly with the MistralAI chat model provider. \u003ca href=\"https://github.com/spring-projects/spring-ai/commit/a89145db26831f2f8bf22e0f76155ecebd8d7c5c\"\u003ea89145d\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCorrects an issue where configured options were not being properly included in MistralAI API requests, ensuring all user-defined settings are correctly passed through. \u003ca href=\"https://github.com/spring-projects/spring-ai/commit/7bcf32aa134b3954ba70bed625de4adcbfe8fab4\"\u003e7bcf32a\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eResolves a regression in how AssistantMessage.ToolCall.id is handled when using the Ollama integration, restoring correct tool call identification behavior. \u003ca href=\"https://github.com/spring-projects/spring-ai/commit/bb9d65ea96d3d57cf3c7467fb82e86bc25c9f238\"\u003ebb9d65e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📓 Documentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCorrected typographical errors in the MCP (Model Context Protocol) documentation for improved readability and accuracy. \u003ca href=\"https://github.com/spring-projects/spring-ai/commit/a1ad7f2a4a784432dde61520723fb80119008320\"\u003ea1ad7f2\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed broken xref anchors in the documentation to restore proper cross-reference navigation between documentation sections. \u003ca href=\"https://github.com/spring-projects/spring-ai/commit/f03c104234de47a9e91d0a7f312f458ebeb5cbe9\"\u003ef03c104\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔨 Dependency Upgrades\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated MCP SDK from version 0.17.0 to 0.18.2 and MCP annotations from 0.8.0 to 0.9.0, bringing in the latest MCP protocol improvements and bug fixes. \u003ca href=\"https://redirect.github.com/spring-projects/spring-ai/pull/5961\"\u003e#5961\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🔩 Build Updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated the project build to use JDK 17.0.19, ensuring compatibility and incorporating the latest Java 17 patch release for the build environment. \u003ca href=\"https://github.com/spring-projects/spring-ai/commit/27281e62dec4fd0857ab3d0da79cd3b83105b260\"\u003e27281e6\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReorganizes the project structure by relocating Spring AI starter modules to a dedicated starters/ directory for better maintainability and clarity. \u003ca href=\"https://github.com/spring-projects/spring-ai/commit/22f867673c0d59a4607022d0a5992b5f0c59f6ef\"\u003e22f8676\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🙏 Contributors\u003c/h2\u003e\n\u003cp\u003eThanks to all contributors who made this release possible:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/tzolov\"\u003e\u003ccode\u003eChristian Tzolov (@​tzolov)\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/emileplas\"\u003e\u003ccode\u003eEmile Plas (@​emileplas)\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ilayaperumalg\"\u003e\u003ccode\u003eIlayaperumal Gopinathan (@​ilayaperumalg)\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sobychacko\"\u003e\u003ccode\u003eSoby Chacko (@​sobychacko)\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-ai/commit/d8503868d3e84547db51d8f10379e1a075fe2d99\"\u003e\u003ccode\u003ed850386\u003c/code\u003e\u003c/a\u003e Release version 1.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-ai/commit/5b78fe924eb2327f652cbdae1531999a6a98ba81\"\u003e\u003ccode\u003e5b78fe9\u003c/code\u003e\u003c/a\u003e Harden filename handling in AnthropicSkillsResponseHelper\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-ai/commit/3fc37483ae6b215efc743f41b303820091b05aee\"\u003e\u003ccode\u003e3fc3748\u003c/code\u003e\u003c/a\u003e Fix deprecated model for OpenAI SDK Image model\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-ai/commit/b83d3928cd84f547c094a89d23969b256b567f4b\"\u003e\u003ccode\u003eb83d392\u003c/code\u003e\u003c/a\u003e Fix OpenAI ITs\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-ai/commit/f63fac2a2d968bccd1cbc3c62a7ad78294f16ed5\"\u003e\u003ccode\u003ef63fac2\u003c/code\u003e\u003c/a\u003e Fix deprecated audio models in OpenAI API and OpenAI SDK\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-ai/commit/9a5f2154bdda22949091ffd7ae4f532934d0092f\"\u003e\u003ccode\u003e9a5f215\u003c/code\u003e\u003c/a\u003e fix: update OpenAI image API to gpt-image-1-mini, dropping DALL-E support\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-ai/commit/30c7be9000b8a9afd58e3a580b5424630e6d7509\"\u003e\u003ccode\u003e30c7be9\u003c/code\u003e\u003c/a\u003e fix: Add missing configurations for ChatModel streaming tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-ai/commit/42b9cc72e1d665a417403e403828228bcff254d4\"\u003e\u003ccode\u003e42b9cc7\u003c/code\u003e\u003c/a\u003e Replace switchMap with concatMap/map to prevent streaming data loss (\u003ca href=\"https://redirect.github.com/spring-projects/spring-ai/issues/6106\"\u003e#6106\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-ai/commit/24a89f5555be3d6db006dfb46930b569a28a51ee\"\u003e\u003ccode\u003e24a89f5\u003c/code\u003e\u003c/a\u003e Fix Redis vector store filter delete to paginate search results\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-ai/commit/df99841177c419d09f936d917fb673fb4eecf4ad\"\u003e\u003ccode\u003edf99841\u003c/code\u003e\u003c/a\u003e Add Ollama ThinkOption runtime hints\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/spring-projects/spring-ai/compare/v1.0.0...v1.1.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.squareup.okio:okio-jvm` from 3.6.0 to 3.17.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/square/okio/blob/master/CHANGELOG.md\"\u003ecom.squareup.okio:okio-jvm's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 3.17.0\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003e2026-03-11\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eNew: Adjust down the Kotlin stdlib dependency to [Kotlin 2.1.21][kotlin_2_1_21]. Okio is built\nwith an up-to-date Kotlin compiler (2.2.21), but depends on an older kotlin-stdlib. We're doing\nthis so you can update Okio and Kotlin independently.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix: Return the correct timestamp in \u003ccode\u003eFileMetadata.createdAtMillis\u003c/code\u003e on Kotlin/Native on UNIX\nplatforms. We were incorrectly using the POSIX \u003ccode\u003ectime\u003c/code\u003e (\u003cem\u003echange\u003c/em\u003e time) instead of the\n\u003ccode\u003ebirthtime\u003c/code\u003e. With this fix Okio now prefers \u003ccode\u003estatx()\u003c/code\u003e over \u003ccode\u003estat()\u003c/code\u003e on native platforms. This\nAPI first appeared in Linux in 4.11 (2017) and Android in API 30 (2020).\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.16.4\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003e2025-11-17\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix: Don't delay triggering timeouts. In 3.16.0 we introduced a regression that caused timeouts\nto fire later than they were supposed to.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.16.3\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003e2025-11-14\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eThis release is the same as 3.16.2. We forgot to cherry-pick a commit before we released!\u003c/p\u003e\n\u003ch2\u003eVersion 3.16.2\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003e2025-10-14\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix: \u003ccode\u003eokio-assetfilesystem\u003c/code\u003e APIs now correctly restored as visible to Kotlin.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.16.1\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003e2025-10-09\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix: Don't crash when calling \u003ccode\u003eSocket.shutdownOutput()\u003c/code\u003e or \u003ccode\u003eshutdownInput()\u003c/code\u003e on an \u003ccode\u003eSSLSocket\u003c/code\u003e on\nAndroid API 21. This method throws an \u003ccode\u003eUnsupportedOperationException\u003c/code\u003e, so we now catch that and\nclose the underlying stream instead.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.16.0\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003e2025-07-29\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix: Change \u003ccode\u003eSocket.asOkioSocket()\u003c/code\u003e to resolve its source \u003ccode\u003eInputStream\u003c/code\u003e and \u003ccode\u003eOutputStream\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/80a50234e5edb96041a8168c4754ba9e1ff3625a\"\u003e\u003ccode\u003e80a5023\u003c/code\u003e\u003c/a\u003e Prepare for release 3.17.0.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/65c0c26bb5242b697ffc28f6c666ae0a01197ff6\"\u003e\u003ccode\u003e65c0c26\u003c/code\u003e\u003c/a\u003e Switch to FileMetadata to use statx instead of stat on Linux and Apple platfo...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/b11f17b233601af92ae1fabea3fecdeea0608631\"\u003e\u003ccode\u003eb11f17b\u003c/code\u003e\u003c/a\u003e Remove Kotlin/JS IR default parameter workarounds. (\u003ca href=\"https://redirect.github.com/square/okio/issues/1786\"\u003e#1786\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/b35f473635db8ad9d5a9b096780e960d1b8f7d4d\"\u003e\u003ccode\u003eb35f473\u003c/code\u003e\u003c/a\u003e Update Gradle to v9.4.0 (\u003ca href=\"https://redirect.github.com/square/okio/issues/1785\"\u003e#1785\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/cbcee31f2bcb7e6f606d8eafc45f4c8ea7228cae\"\u003e\u003ccode\u003ecbcee31\u003c/code\u003e\u003c/a\u003e Update actions/upload-artifact action to v7 (\u003ca href=\"https://redirect.github.com/square/okio/issues/1783\"\u003e#1783\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/fc7aecb7f6f7a123f2024ab6397da04311546bf2\"\u003e\u003ccode\u003efc7aecb\u003c/code\u003e\u003c/a\u003e Update dependency com.android.tools.build:gradle to v9.0.1 (\u003ca href=\"https://redirect.github.com/square/okio/issues/1781\"\u003e#1781\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/79aa26755c77df8c4d0233926c7308fd353ad697\"\u003e\u003ccode\u003e79aa267\u003c/code\u003e\u003c/a\u003e Drop \u003ccode\u003eisWasm()\u003c/code\u003e early return workaround for KT-60212. (\u003ca href=\"https://redirect.github.com/square/okio/issues/1777\"\u003e#1777\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/45459dca7d40b4c2df1454a0f363e0b8e153beb5\"\u003e\u003ccode\u003e45459dc\u003c/code\u003e\u003c/a\u003e Fix result of an 'errnoToIOException' call is not thrown. inside `PosixFileSy...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/9fbab0f7ab00b525b0ae331c8c3ac3c645afc8c8\"\u003e\u003ccode\u003e9fbab0f\u003c/code\u003e\u003c/a\u003e Decode env variables in WASI tests (\u003ca href=\"https://redirect.github.com/square/okio/issues/1773\"\u003e#1773\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/50abe8900f2e7bd48d4afc77bda0afd74fc790ac\"\u003e\u003ccode\u003e50abe89\u003c/code\u003e\u003c/a\u003e Stop using AssertJ (\u003ca href=\"https://redirect.github.com/square/okio/issues/1771\"\u003e#1771\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/square/okio/compare/parent-3.6.0...parent-3.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.squareup.okio:okio` from 3.4.0 to 3.17.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/square/okio/blob/master/CHANGELOG.md\"\u003ecom.squareup.okio:okio's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 3.17.0\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003e2026-03-11\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\n\u003cp\u003eNew: Adjust down the Kotlin stdlib dependency to [Kotlin 2.1.21][kotlin_2_1_21]. Okio is built\nwith an up-to-date Kotlin compiler (2.2.21), but depends on an older kotlin-stdlib. We're doing\nthis so you can update Okio and Kotlin independently.\u003c/p\u003e\n\u003c/li\u003e\n\u003cli\u003e\n\u003cp\u003eFix: Return the correct timestamp in \u003ccode\u003eFileMetadata.createdAtMillis\u003c/code\u003e on Kotlin/Native on UNIX\nplatforms. We were incorrectly using the POSIX \u003ccode\u003ectime\u003c/code\u003e (\u003cem\u003echange\u003c/em\u003e time) instead of the\n\u003ccode\u003ebirthtime\u003c/code\u003e. With this fix Okio now prefers \u003ccode\u003estatx()\u003c/code\u003e over \u003ccode\u003estat()\u003c/code\u003e on native platforms. This\nAPI first appeared in Linux in 4.11 (2017) and Android in API 30 (2020).\u003c/p\u003e\n\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.16.4\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003e2025-11-17\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix: Don't delay triggering timeouts. In 3.16.0 we introduced a regression that caused timeouts\nto fire later than they were supposed to.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.16.3\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003e2025-11-14\u003c/em\u003e\u003c/p\u003e\n\u003cp\u003eThis release is the same as 3.16.2. We forgot to cherry-pick a commit before we released!\u003c/p\u003e\n\u003ch2\u003eVersion 3.16.2\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003e2025-10-14\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix: \u003ccode\u003eokio-assetfilesystem\u003c/code\u003e APIs now correctly restored as visible to Kotlin.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.16.1\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003e2025-10-09\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix: Don't crash when calling \u003ccode\u003eSocket.shutdownOutput()\u003c/code\u003e or \u003ccode\u003eshutdownInput()\u003c/code\u003e on an \u003ccode\u003eSSLSocket\u003c/code\u003e on\nAndroid API 21. This method throws an \u003ccode\u003eUnsupportedOperationException\u003c/code\u003e, so we now catch that and\nclose the underlying stream instead.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 3.16.0\u003c/h2\u003e\n\u003cp\u003e\u003cem\u003e2025-07-29\u003c/em\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eFix: Change \u003ccode\u003eSocket.asOkioSocket()\u003c/code\u003e to resolve its source \u003ccode\u003eInputStream\u003c/code\u003e and \u003ccode\u003eOutputStream\u003c/code\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/80a50234e5edb96041a8168c4754ba9e1ff3625a\"\u003e\u003ccode\u003e80a5023\u003c/code\u003e\u003c/a\u003e Prepare for release 3.17.0.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/65c0c26bb5242b697ffc28f6c666ae0a01197ff6\"\u003e\u003ccode\u003e65c0c26\u003c/code\u003e\u003c/a\u003e Switch to FileMetadata to use statx instead of stat on Linux and Apple platfo...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/b11f17b233601af92ae1fabea3fecdeea0608631\"\u003e\u003ccode\u003eb11f17b\u003c/code\u003e\u003c/a\u003e Remove Kotlin/JS IR default parameter workarounds. (\u003ca href=\"https://redirect.github.com/square/okio/issues/1786\"\u003e#1786\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/b35f473635db8ad9d5a9b096780e960d1b8f7d4d\"\u003e\u003ccode\u003eb35f473\u003c/code\u003e\u003c/a\u003e Update Gradle to v9.4.0 (\u003ca href=\"https://redirect.github.com/square/okio/issues/1785\"\u003e#1785\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/cbcee31f2bcb7e6f606d8eafc45f4c8ea7228cae\"\u003e\u003ccode\u003ecbcee31\u003c/code\u003e\u003c/a\u003e Update actions/upload-artifact action to v7 (\u003ca href=\"https://redirect.github.com/square/okio/issues/1783\"\u003e#1783\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/fc7aecb7f6f7a123f2024ab6397da04311546bf2\"\u003e\u003ccode\u003efc7aecb\u003c/code\u003e\u003c/a\u003e Update dependency com.android.tools.build:gradle to v9.0.1 (\u003ca href=\"https://redirect.github.com/square/okio/issues/1781\"\u003e#1781\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/79aa26755c77df8c4d0233926c7308fd353ad697\"\u003e\u003ccode\u003e79aa267\u003c/code\u003e\u003c/a\u003e Drop \u003ccode\u003eisWasm()\u003c/code\u003e early return workaround for KT-60212. (\u003ca href=\"https://redirect.github.com/square/okio/issues/1777\"\u003e#1777\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/45459dca7d40b4c2df1454a0f363e0b8e153beb5\"\u003e\u003ccode\u003e45459dc\u003c/code\u003e\u003c/a\u003e Fix result of an 'errnoToIOException' call is not thrown. inside `PosixFileSy...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/9fbab0f7ab00b525b0ae331c8c3ac3c645afc8c8\"\u003e\u003ccode\u003e9fbab0f\u003c/code\u003e\u003c/a\u003e Decode env variables in WASI tests (\u003ca href=\"https://redirect.github.com/square/okio/issues/1773\"\u003e#1773\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/square/okio/commit/50abe8900f2e7bd48d4afc77bda0afd74fc790ac\"\u003e\u003ccode\u003e50abe89\u003c/code\u003e\u003c/a\u003e Stop using AssertJ (\u003ca href=\"https://redirect.github.com/square/okio/issues/1771\"\u003e#1771\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/square/okio/compare/parent-3.4.0...parent-3.17.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.springframework.cloud:spring-cloud-dependencies` from 2025.0.2 to 2025.1.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/releases\"\u003eorg.springframework.cloud:spring-cloud-dependencies's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev2025.1.1\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump antora from 3.2.0-alpha.10 to 3.2.0-alpha.11 in /docs by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/spring-cloud/spring-cloud-release/pull/447\"\u003espring-cloud/spring-cloud-release#447\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.springframework.cloud:spring-cloud-contract-dependencies from 5.0.1-SNAPSHOT to 5.0.2-SNAPSHOT by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/spring-cloud/spring-cloud-release/pull/454\"\u003espring-cloud/spring-cloud-release#454\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.springframework.cloud:spring-cloud-contract-dependencies from 5.0.1-SNAPSHOT to 5.0.2-SNAPSHOT by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/spring-cloud/spring-cloud-release/pull/453\"\u003espring-cloud/spring-cloud-release#453\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump actions/cache from 4 to 5 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/spring-cloud/spring-cloud-release/pull/456\"\u003espring-cloud/spring-cloud-release#456\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven:maven-model from 3.9.11 to 3.9.12 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/spring-cloud/spring-cloud-release/pull/461\"\u003espring-cloud/spring-cloud-release#461\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven:maven-model from 3.9.11 to 3.9.12 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/spring-cloud/spring-cloud-release/pull/460\"\u003espring-cloud/spring-cloud-release#460\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/compare/v2025.1.0...v2025.1.1\"\u003ehttps://github.com/spring-cloud/spring-cloud-release/compare/v2025.1.0...v2025.1.1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/commit/dbb12bfc2b899fb0845fe4b3c6dc07bc3c1828e2\"\u003e\u003ccode\u003edbb12bf\u003c/code\u003e\u003c/a\u003e Update SNAPSHOT to 2025.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/commit/edc8bcb1d195cb0a9fa96efc82ccb3dfdaf2fd39\"\u003e\u003ccode\u003eedc8bcb\u003c/code\u003e\u003c/a\u003e Bumping versions\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/commit/a9f418316485581438af2fa1db54f7ff5e80b17e\"\u003e\u003ccode\u003ea9f4183\u003c/code\u003e\u003c/a\u003e Use Spring Boot 4.0.2-SNAPSHOT\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/commit/da7ad033005dd53554ad5aea9eeefab9416c1661\"\u003e\u003ccode\u003eda7ad03\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/spring-cloud/spring-cloud-release/issues/460\"\u003e#460\u003c/a\u003e from spring-cloud/dependabot/maven/org.apache.maven-m...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/commit/49b10e643ffdb36873b3abb0bcd0539e0942f0c6\"\u003e\u003ccode\u003e49b10e6\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/spring-cloud/spring-cloud-release/issues/461\"\u003e#461\u003c/a\u003e from spring-cloud/dependabot/maven/main/org.apache.ma...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/commit/59782becdf97cb4db3693fc9d3688e85fde493b5\"\u003e\u003ccode\u003e59782be\u003c/code\u003e\u003c/a\u003e Bump org.apache.maven:maven-model from 3.9.11 to 3.9.12\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/commit/89c8dd1e2610118b12e9d9ccb64945833a0ade22\"\u003e\u003ccode\u003e89c8dd1\u003c/code\u003e\u003c/a\u003e Bump org.apache.maven:maven-model from 3.9.11 to 3.9.12\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/commit/96a5fb078d5eb2d80baec60004f1cb2518290afe\"\u003e\u003ccode\u003e96a5fb0\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/spring-cloud/spring-cloud-release/issues/456\"\u003e#456\u003c/a\u003e from spring-cloud/dependabot/github_actions/main/acti...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/commit/5d22a1d1f65df1f7a8c5bc021f5cc5dc44398072\"\u003e\u003ccode\u003e5d22a1d\u003c/code\u003e\u003c/a\u003e Bump actions/cache from 4 to 5\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/commit/ec45c6d4c7d7e49695e3c6c9fa68abd3823a770d\"\u003e\u003ccode\u003eec45c6d\u003c/code\u003e\u003c/a\u003e Bumping versions\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/spring-cloud/spring-cloud-release/compare/v2025.0.2...v2025.1.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `io.opentelemetry.instrumentation:opentelemetry-instrumentation-annotations` from 2.22.0 to 2.28.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/releases\"\u003eio.opentelemetry.instrumentation:opentelemetry-instrumentation-annotations's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 2.28.1\u003c/h2\u003e\n\u003cp\u003eThis release targets the OpenTelemetry SDK 1.62.0.\u003c/p\u003e\n\u003cp\u003eNote that many artifacts have the \u003ccode\u003e-alpha\u003c/code\u003e suffix attached to their version number, reflecting that they will continue to have breaking changes. Please see \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/blob/main/VERSIONING.md#opentelemetry-java-instrumentation-versioning\"\u003eVERSIONING.md\u003c/a\u003e for more details.\u003c/p\u003e\n\u003ch3\u003e🛠️ Bug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix javaagent startup failures when declarative configuration uses bundled contrib components, such as the rule-based routing sampler. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18813\"\u003e#18813\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 2.28.0\u003c/h2\u003e\n\u003cp\u003eThis release targets the OpenTelemetry SDK 1.62.0.\u003c/p\u003e\n\u003cp\u003eNote that many artifacts have the \u003ccode\u003e-alpha\u003c/code\u003e suffix attached to their version number, reflecting that they will continue to have breaking changes. Please see \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/blob/main/VERSIONING.md#opentelemetry-java-instrumentation-versioning\"\u003eVERSIONING.md\u003c/a\u003e for more details.\u003c/p\u003e\n\u003ch3\u003e⚠️ Breaking changes to non-stable APIs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved the obsolete internal \u003ccode\u003eClassInjector\u003c/code\u003e/\u003ccode\u003eProxyInjectionBuilder\u003c/code\u003e API used by the old \u003ccode\u003eExperimentalInstrumentationModule.injectClasses(ClassInjector)\u003c/code\u003e path; use \u003ccode\u003eExperimentalInstrumentationModule.exposedClassNames()\u003c/code\u003e instead. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18112\"\u003e#18112\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemoved previously deprecated non-stable API methods and the deprecated \u003ccode\u003eopentelemetry-runtime-telemetry-java8\u003c/code\u003e and \u003ccode\u003eopentelemetry-runtime-telemetry-java17\u003c/code\u003e library aliases. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18136\"\u003e#18136\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemoved the previously deprecated \u003ccode\u003ecaptureEventName\u003c/code\u003e library builder setting from the logback-appender-1.0 and log4j-appender-2.17 \u003ccode\u003eOpenTelemetryAppender\u003c/code\u003e, and the corresponding \u003ccode\u003eotel.instrumentation.{logback-appender,log4j-appender,jboss-logmanager}.experimental.capture-event-name\u003c/code\u003e javaagent properties. Use the \u003ccode\u003eotel.event.name\u003c/code\u003e key in MDC / context data / key-value pairs / Logstash markers / structured arguments instead. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18223\"\u003e#18223\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemoved previously deprecated experimental config properties \u003ccode\u003eotel.instrumentation.http.client.experimental.redact-query-parameters\u003c/code\u003e and \u003ccode\u003eotel.instrumentation.common.experimental.db-sqlcommenter.enabled\u003c/code\u003e; use \u003ccode\u003eotel.instrumentation.sanitization.url.experimental.sensitive-query-parameters\u003c/code\u003e and \u003ccode\u003eotel.instrumentation.common.db.experimental.sqlcommenter.enabled\u003c/code\u003e instead. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18229\"\u003e#18229\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemoved the deprecated \u003ccode\u003eotel.instrumentation.servlet.experimental.add-trace-id-request-attribute\u003c/code\u003e property; use \u003ccode\u003eotel.instrumentation.servlet.experimental.trace-id-request-attribute.enabled\u003c/code\u003e instead. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18237\"\u003e#18237\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReshaped the ktor \u003ccode\u003eExperimental\u003c/code\u003e helper from a class with a \u003ccode\u003ecompanion object\u003c/code\u003e to a top-level \u003ccode\u003eobject\u003c/code\u003e. Kotlin source callers (\u003ccode\u003eExperimental.emitExperimentalTelemetry(...)\u003c/code\u003e) are unaffected, but pre-compiled consumers must be recompiled against the new artifact. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18343\"\u003e#18343\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🚫 Deprecations\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eotel.instrumentation.jaxws-cxf-3.0.enabled\u003c/code\u003e in favor of \u003ccode\u003eotel.instrumentation.jaxws-2.0-cxf-3.0.enabled\u003c/code\u003e, and \u003ccode\u003eotel.instrumentation.jaxws-metro-2.2.enabled\u003c/code\u003e in favor of \u003ccode\u003eotel.instrumentation.jaxws-2.0-metro-2.2.enabled\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18184\"\u003e#18184\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🌟 New javaagent instrumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Apache Thrift 0.13 instrumentation for RPC client and server spans and metrics. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18405\"\u003e#18405\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🌟 New library instrumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Apache Thrift 0.13 library instrumentation for RPC client and server spans and metrics. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18405\"\u003e#18405\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e📈 Enhancements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eCouchbase 3.1 javaagent instrumentation now emits the more conventional instrumentation scope name \u003ccode\u003eio.opentelemetry.couchbase-3.1\u003c/code\u003e instead of \u003ccode\u003eio.opentelemetry.javaagent.couchbase-3.1\u003c/code\u003e when \u003ccode\u003eotel.instrumentation.common.v3-preview\u003c/code\u003e is enabled. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18426\"\u003e#18426\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eWicket resource requests now use the resource reference class name in the server span name when \u003ccode\u003eotel.instrumentation.common.v3-preview\u003c/code\u003e is enabled. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18312\"\u003e#18312\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18775\"\u003e#18775\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDecide whether javaagent helper classes are injected into the application class loader or isolated based on the advice classes used by an instrumentation. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/17815\"\u003e#17815\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eImprove cgroup v2 container ID detection for Podman by supporting additional \u003ccode\u003emountinfo\u003c/code\u003e layouts and warning when multiple candidate IDs are found. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18272\"\u003e#18272\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🛠️ Bug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix Pekko HTTP and Tapir server route tracking so server span names and \u003ccode\u003ehttp.route\u003c/code\u003e preserve the most specific matched route across nested directives, exceptions, and timeouts; this may change span names and \u003ccode\u003ehttp.route\u003c/code\u003e values for affected routes. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/16390\"\u003e#16390\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix context loss in Finagle HTTP instrumentation across Netty-to-Finagle request conversion and \u003ccode\u003etwitter-util\u003c/code\u003e Future/Promise asynchronous boundaries. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/17867\"\u003e#17867\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix virtual-thread pinning caused by weak-map stale-entry cleanup running on virtual threads; cleanup now runs from the background thread instead. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18113\"\u003e#18113\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAvoid linking batch consumer spans to the ambient consumer span when records or messages have no propagation headers. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18154\"\u003e#18154\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eresetOnEachOperator()\u003c/code\u003e for Reactor 3.1 so it also removes the scheduler hook when instrumentation is disabled. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18258\"\u003e#18258\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eEnd spans when RxJava 1.0 subscriptions throw synchronously. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18265\"\u003e#18265\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/blob/main/CHANGELOG.md\"\u003eio.opentelemetry.instrumentation:opentelemetry-instrumentation-annotations's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 2.28.1 (2026-05-20)\u003c/h2\u003e\n\u003cp\u003eThis release targets the OpenTelemetry SDK 1.62.0.\u003c/p\u003e\n\u003cp\u003eNote that many artifacts have the \u003ccode\u003e-alpha\u003c/code\u003e suffix attached to their version\nnumber, reflecting that they will continue to have breaking changes. Please see\n\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/blob/main/VERSIONING.md#opentelemetry-java-instrumentation-versioning\"\u003eVERSIONING.md\u003c/a\u003e\nfor more details.\u003c/p\u003e\n\u003ch3\u003e🛠️ Bug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix javaagent startup failures when declarative configuration uses bundled contrib components,\nsuch as the rule-based routing sampler.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18813\"\u003e#18813\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 2.28.0 (2026-05-19)\u003c/h2\u003e\n\u003cp\u003eThis release targets the OpenTelemetry SDK 1.62.0.\u003c/p\u003e\n\u003cp\u003eNote that many artifacts have the \u003ccode\u003e-alpha\u003c/code\u003e suffix attached to their version\nnumber, reflecting that they will continue to have breaking changes. Please see\n\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/blob/main/VERSIONING.md#opentelemetry-java-instrumentation-versioning\"\u003eVERSIONING.md\u003c/a\u003e\nfor more details.\u003c/p\u003e\n\u003ch3\u003e⚠️ Breaking changes to non-stable APIs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemoved the obsolete internal \u003ccode\u003eClassInjector\u003c/code\u003e/\u003ccode\u003eProxyInjectionBuilder\u003c/code\u003e API used by the old\n\u003ccode\u003eExperimentalInstrumentationModule.injectClasses(ClassInjector)\u003c/code\u003e path; use\n\u003ccode\u003eExperimentalInstrumentationModule.exposedClassNames()\u003c/code\u003e instead.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18112\"\u003e#18112\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemoved previously deprecated non-stable API methods and the deprecated\n\u003ccode\u003eopentelemetry-runtime-telemetry-java8\u003c/code\u003e and \u003ccode\u003eopentelemetry-runtime-telemetry-java17\u003c/code\u003e library\naliases.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18136\"\u003e#18136\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemoved the previously deprecated \u003ccode\u003ecaptureEventName\u003c/code\u003e library builder setting from the\nlogback-appender-1.0 and log4j-appender-2.17 \u003ccode\u003eOpenTelemetryAppender\u003c/code\u003e, and the corresponding\n\u003ccode\u003eotel.instrumentation.{logback-appender,log4j-appender,jboss-logmanager}.experimental.capture-event-name\u003c/code\u003e\njavaagent properties. Use the \u003ccode\u003eotel.event.name\u003c/code\u003e key in MDC / context data / key-value pairs /\nLogstash markers / structured arguments instead.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18223\"\u003e#18223\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemoved previously deprecated experimental config properties\n\u003ccode\u003eotel.instrumentation.http.client.experimental.redact-query-parameters\u003c/code\u003e and\n\u003ccode\u003eotel.instrumentation.common.experimental.db-sqlcommenter.enabled\u003c/code\u003e; use\n\u003ccode\u003eotel.instrumentation.sanitization.url.experimental.sensitive-query-parameters\u003c/code\u003e and\n\u003ccode\u003eotel.instrumentation.common.db.experimental.sqlcommenter.enabled\u003c/code\u003e instead.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18229\"\u003e#18229\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eRemoved the deprecated \u003ccode\u003eotel.instrumentation.servlet.experimental.add-trace-id-request-attribute\u003c/code\u003e\nproperty; use \u003ccode\u003eotel.instrumentation.servlet.experimental.trace-id-request-attribute.enabled\u003c/code\u003e\ninstead.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18237\"\u003e#18237\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/7ad453a58de282ea04fd88f4178d70a65468b93c\"\u003e\u003ccode\u003e7ad453a\u003c/code\u003e\u003c/a\u003e [release/v2.28.x] Prepare release 2.28.1 (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/18818\"\u003e#18818\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/1f0b4b27c6e3c96d3098fa7a4ece9404ba7c55bd\"\u003e\u003ccode\u003e1f0b4b2\u003c/code\u003e\u003c/a\u003e Prepare change log for upcoming patch release (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/18816\"\u003e#18816\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/f4b9d76e1c8425b53bd1f22a1e5f8612e30659fc\"\u003e\u003ccode\u003ef4b9d76\u003c/code\u003e\u003c/a\u003e [release/v2.28.x] fix(deps): update opentelemetry-java-contrib monorepo to v1...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/9ef68e6b114b2d1fc1f6a3fbc576cb37fc71e893\"\u003e\u003ccode\u003e9ef68e6\u003c/code\u003e\u003c/a\u003e [release/v2.28.x] Prepare release 2.28.0 (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/18791\"\u003e#18791\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/5d26f13fa3a9c8d67d336649796620d65733fc09\"\u003e\u003ccode\u003e5d26f13\u003c/code\u003e\u003c/a\u003e Draft release notes (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/18774\"\u003e#18774\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/37540625c9d7928152a4fe3e52ed255255f6d895\"\u003e\u003ccode\u003e3754062\u003c/code\u003e\u003c/a\u003e Gate Wicket resource span names on v3 preview (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/18775\"\u003e#18775\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/f6f123d374986c34b3e2eee412551de7f6aec58b\"\u003e\u003ccode\u003ef6f123d\u003c/code\u003e\u003c/a\u003e Preserve Spring resource provider class names (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/18785\"\u003e#18785\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/4c6155a89b5abe035197a4a87375cbebbcce8d04\"\u003e\u003ccode\u003e4c6155a\u003c/code\u003e\u003c/a\u003e Normalize internal and resource javaagent packages (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/18746\"\u003e#18746\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/d7b88cef8d7dcc75745520bff25a3ac38a949c75\"\u003e\u003ccode\u003ed7b88ce\u003c/code\u003e\u003c/a\u003e Rename servlet common root package (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/18778\"\u003e#18778\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/d52a5ff2c5aaeb8e5eb2a7149d05a998c7815fdc\"\u003e\u003ccode\u003ed52a5ff\u003c/code\u003e\u003c/a\u003e Rename servlet common snippet package (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/18777\"\u003e#18777\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/compare/v2.22.0...v2.28.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.xmlbeans:xmlbeans` from 5.1.1 to 5.3.0\n\nUpdates `commons-io:commons-io` from 2.19.0 to 2.22.0\n\nUpdates `org.jsoup:jsoup` from 1.18.1 to 1.22.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jhy/jsoup/releases\"\u003eorg.jsoup:jsoup's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ejsoup Java HTML Parser release 1.22.2\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003ejsoup 1.22.2\u003c/strong\u003e is out now, with fixes and refinements across the library. It makes editing the DOM during traversal more predictable, refreshes the default HTML tag definitions with newer elements and better text boundaries, and improves reliability in parsing and HTTP transport. The release also fixes a number of edge cases in cleaning, stream parsing, XML doctype handling, and Android packaging.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003ejsoup\u003c/strong\u003e is a Java library for working with real-world HTML and XML. It provides a very convenient API for extracting and manipulating data, using the best of HTML5 DOM methods and CSS selectors.\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/jhy/jsoup/blob/HEAD/download\"\u003e\u003cstrong\u003eDownload\u003c/strong\u003e\u003c/a\u003e jsoup now.\u003c/p\u003e\n\u003ch2\u003eImprovements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eExpanded and clarified \u003ccode\u003eNodeTraversor\u003c/code\u003e support for in-place DOM rewrites during \u003ccode\u003eNodeVisitor.head()\u003c/code\u003e. Current-node edits such as \u003ccode\u003eremove\u003c/code\u003e, \u003ccode\u003ereplace\u003c/code\u003e, and \u003ccode\u003eunwrap\u003c/code\u003e now recover more predictably, while traversal stays within the original root subtree. This makes single-pass tree cleanup and normalization visitors easier to write, for example when unwrapping presentational elements or replacing text nodes as you walk the DOM. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2472\"\u003e#2472\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eDocumentation: clarified that a configured \u003ccode\u003eCleaner\u003c/code\u003e may be reused across concurrent threads, and that shared \u003ccode\u003eSafelist\u003c/code\u003e instances should not be mutated while in use. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2473\"\u003e#2473\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eUpdated the default HTML \u003ccode\u003eTagSet\u003c/code\u003e for current HTML elements: added \u003ccode\u003edialog\u003c/code\u003e, \u003ccode\u003esearch\u003c/code\u003e, \u003ccode\u003epicture\u003c/code\u003e, and \u003ccode\u003eslot\u003c/code\u003e; made \u003ccode\u003eins\u003c/code\u003e, \u003ccode\u003edel\u003c/code\u003e, \u003ccode\u003ebutton\u003c/code\u003e, \u003ccode\u003eaudio\u003c/code\u003e, \u003ccode\u003evideo\u003c/code\u003e, and \u003ccode\u003ecanvas\u003c/code\u003e inline by default (\u003ccode\u003eTag#isInline()\u003c/code\u003e, aligned to phrasing content in the spec); and added readable \u003ccode\u003eElement.text()\u003c/code\u003e boundaries for controls and embedded objects via the new \u003ccode\u003eTag.TextBoundary\u003c/code\u003e option. This improves pretty-printing and keeps normalized text from running adjacent words together. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2493\"\u003e#2493\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAndroid (R8/ProGuard): added a rule to ignore the optional \u003ccode\u003ere2j\u003c/code\u003e dependency when not present. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2459\"\u003e#2459\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eFixed a \u003ccode\u003eNodeTraversor\u003c/code\u003e regression in 1.21.2 where removing or replacing the current node during \u003ccode\u003ehead()\u003c/code\u003e could revisit the replacement node and loop indefinitely. The traversal docs now also clarify which inserted nodes are visited in the current pass. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2472\"\u003e#2472\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eParsing during charset sniffing no longer fails if an advisory \u003ccode\u003eavailable()\u003c/code\u003e call throws \u003ccode\u003eIOException\u003c/code\u003e, as seen on JDK 8 \u003ccode\u003eHttpURLConnection\u003c/code\u003e. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2474\"\u003e#2474\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eCleaner\u003c/code\u003e no longer makes relative URL attributes in the input document absolute when cleaning or validating a \u003ccode\u003eDocument\u003c/code\u003e. URL normalization now applies only to the cleaned output, and \u003ccode\u003eSafelist.isSafeAttribute()\u003c/code\u003e is side effect free. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2475\"\u003e#2475\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eCleaner\u003c/code\u003e no longer duplicates enforced attributes when the input \u003ccode\u003eDocument\u003c/code\u003e preserves attribute case. A case-variant source attribute is now replaced by the enforced attribute in the cleaned output. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2476\"\u003e#2476\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eIf a per-request SOCKS proxy is configured, jsoup now avoids using the JDK \u003ccode\u003eHttpClient\u003c/code\u003e, because the JDK would silently ignore that proxy and attempt to connect directly. Those requests now fall back to the legacy \u003ccode\u003eHttpURLConnection\u003c/code\u003e transport instead, which does support SOCKS. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2468\"\u003e#2468\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eConnection.Response.streamParser()\u003c/code\u003e and \u003ccode\u003eDataUtil.streamParser(Path, ...)\u003c/code\u003e could fail on small inputs without a declared charset, if the initial 5 KB charset sniff fully consumed the input and closed it before the stream parse began. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2483\"\u003e#2483\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eIn XML mode, doctypes with an internal subset, such as \u003ccode\u003e\u0026lt;!DOCTYPE root [\u0026lt;!ENTITY name \u0026quot;value\u0026quot;\u0026gt;]\u0026gt;\u003c/code\u003e, now round-trip correctly. The subset is preserved as raw text only; entities are not expanded and external DTDs are not loaded. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2486\"\u003e#2486\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBuild Changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMigrated the integration test server from Jetty to Netty, which actively maintains support for our minimum JDK target (8). \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2491\"\u003e#2491\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003cp\u003eMy sincere thanks to everyone who contributed to this release!\nIf you have any suggestions for the next release, I would love to hear them; please get in touch via \u003ca href=\"https://github.com/jhy/jsoup/discussions\"\u003ejsoup discussions\u003c/a\u003e, or with me \u003ca href=\"https://jhedley.com/\"\u003edirectly\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eYou can also \u003c!-- raw HTML omitted --\u003efollow me\u003c!-- raw HTML omitted --\u003e (\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e@\u003ca href=\"mailto:jhy@tilde.zone\"\u003ejhy@tilde.zone\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e) on Mastodon / Fediverse to receive occasional notes about jsoup releases.\u003c/p\u003e\n\u003ch2\u003ejsoup Java HTML Parser release 1.22.1\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003ejsoup 1.22.1\u003c/strong\u003e is out now, adding support for the \u003ccode\u003ere2j\u003c/code\u003e regular expression engine for regex-based CSS selectors, a configurable maximum parser depth, and numerous bug fixes and improvements.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003ejsoup\u003c/strong\u003e is a Java library for working with real-world HTML and XML. It provides a very convenient API for extracting and manipulating data, using the best of HTML5 DOM methods and CSS selectors.\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://jsoup.org/download\"\u003e\u003cstrong\u003eDownload\u003c/strong\u003e\u003c/a\u003e jsoup now.\u003c/p\u003e\n\u003ch3\u003eImprovements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded support for using the \u003ccode\u003ere2j\u003c/code\u003e regular expression engine for regex-based CSS selectors (e.g. \u003ccode\u003e[attr~=regex]\u003c/code\u003e, \u003ccode\u003e:matches(regex)\u003c/code\u003e), which ensures linear-time performance for regex evaluation. This allows safer handling of arbitrary user-supplied query regexes. To enable, add the \u003ccode\u003ecom.google.re2j\u003c/code\u003e dependency to your classpath, e.g.:\u003c/li\u003e\n\u003c/ul\u003e\n\u003cpre lang=\"xml\"\u003e\u003ccode\u003e  \u0026lt;dependency\u0026gt;\r\n    \u0026lt;groupId\u0026gt;com.google.re2j\u0026lt;/groupId\u0026gt;\r\n    \u0026lt;artifactId\u0026gt;re2j\u0026lt;/artifactId\u0026gt;\r\n    \u0026lt;version\u0026gt;1.8\u0026lt;/version\u0026gt;\r\n  \u0026lt;/dependency\u0026gt;\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003e(If you already have that dependency in your classpath, but you want to keep using the Java regex engine, you can disable re2j via \u003ccode\u003eSystem.setProperty(\u0026quot;jsoup.useRe2j\u0026quot;, \u0026quot;false\u0026quot;)\u003c/code\u003e.) You can confirm that the re2j engine has been enable...\n\n_Description has been truncated_","html_url":"https://github.com/beyonai/ByClaw/pull/134","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/beyonai%2FByClaw/issues/134","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/134/packages"}},{"old_version":"1.5.32","new_version":"1.5.34","update_type":"patch","path":null,"pr_created_at":"2026-06-08T00:35:52.000Z","version_change":"1.5.32 → 1.5.34","issue":{"uuid":"4609245594","node_id":"PR_kwDOB20KpM7jtzlL","number":2763,"state":"closed","title":"Bump the dependencies group across 1 directory with 14 updates","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-06-09T00:35:45.000Z","author_association":null,"state_reason":null,"created_at":"2026-06-08T00:35:52.000Z","updated_at":"2026-06-09T00:35:47.000Z","time_to_close":86393,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"dependencies","update_count":14,"packages":[{"name":"com.puppycrawl.tools:checkstyle","old_version":"13.4.2","new_version":"13.5.0","repository_url":"https://github.com/checkstyle/checkstyle"},{"name":"org.ow2.asm:asm","old_version":"9.10","new_version":"9.10.1"},{"name":"org.ow2.asm:asm-commons","old_version":"9.10","new_version":"9.10.1"},{"name":"org.ow2.asm:asm-tree","old_version":"9.10","new_version":"9.10.1"},{"name":"org.ow2.asm:asm-util","old_version":"9.10","new_version":"9.10.1"},{"name":"com.sun.xml.bind:jaxb-core","old_version":"4.0.8","new_version":"4.0.9"},{"name":"com.sun.xml.bind:jaxb-impl","old_version":"4.0.8","new_version":"4.0.9"},{"name":"com.sun.xml.bind:jaxb-xjc","old_version":"4.0.8","new_version":"4.0.9"},{"name":"com.sun.xml.ws:jaxws-rt","old_version":"4.0.4","new_version":"4.0.5"},{"name":"org.eclipse.parsson:parsson","old_version":"1.1.7","new_version":"1.1.9","repository_url":"https://github.com/eclipse-ee4j/parsson"},{"name":"org.mongodb:mongodb-driver-sync","old_version":"5.7.0","new_version":"5.8.0","repository_url":"https://github.com/mongodb/mongo-java-driver"},{"name":"com.oracle.nosql.sdk:nosqldriver","old_version":"5.4.21","new_version":"5.4.22","repository_url":"https://github.com/oracle/nosql-java-sdk"},{"name":"ch.qos.logback:logback-core","old_version":"1.5.32","new_version":"1.5.34","repository_url":"https://github.com/qos-ch/logback"},{"name":"ch.qos.logback:logback-classic","old_version":"1.5.32","new_version":"1.5.34","repository_url":"https://github.com/qos-ch/logback"}],"path":null,"ecosystem":"maven"},"body":"Bumps the dependencies group with 14 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [com.puppycrawl.tools:checkstyle](https://github.com/checkstyle/checkstyle) | `13.4.2` | `13.5.0` |\n| org.ow2.asm:asm | `9.10` | `9.10.1` |\n| org.ow2.asm:asm-commons | `9.10` | `9.10.1` |\n| org.ow2.asm:asm-tree | `9.10` | `9.10.1` |\n| org.ow2.asm:asm-util | `9.10` | `9.10.1` |\n| com.sun.xml.bind:jaxb-core | `4.0.8` | `4.0.9` |\n| com.sun.xml.bind:jaxb-impl | `4.0.8` | `4.0.9` |\n| com.sun.xml.bind:jaxb-xjc | `4.0.8` | `4.0.9` |\n| com.sun.xml.ws:jaxws-rt | `4.0.4` | `4.0.5` |\n| [org.eclipse.parsson:parsson](https://github.com/eclipse-ee4j/parsson) | `1.1.7` | `1.1.9` |\n| [org.mongodb:mongodb-driver-sync](https://github.com/mongodb/mongo-java-driver) | `5.7.0` | `5.8.0` |\n| [com.oracle.nosql.sdk:nosqldriver](https://github.com/oracle/nosql-java-sdk) | `5.4.21` | `5.4.22` |\n| [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) | `1.5.32` | `1.5.34` |\n| [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) | `1.5.32` | `1.5.34` |\n\n\nUpdates `com.puppycrawl.tools:checkstyle` from 13.4.2 to 13.5.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/checkstyle/checkstyle/releases\"\u003ecom.puppycrawl.tools:checkstyle's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003echeckstyle-13.5.0\u003c/h2\u003e\n\u003cp\u003eCheckstyle 13.5.0 - \u003ca href=\"https://checkstyle.org/releasenotes.html#Release_13.5.0\"\u003ehttps://checkstyle.org/releasenotes.html#Release_13.5.0\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eNew:\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19496\"\u003e#19496\u003c/a\u003e - AvoidStarImport: new property maxAllowedStarImports to allow atmost one star import in a file.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/14782\"\u003e#14782\u003c/a\u003e - LITERAL_DEFAULT token support in RightCurlyCheck.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/15484\"\u003e#15484\u003c/a\u003e - New Check UnusedTryResourceShouldBeUnnamed.\u003c/p\u003e\n\u003cp\u003eBug fixes:\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/17697\"\u003e#17697\u003c/a\u003e - Google style: Disallow comments enclosed in boxes.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19641\"\u003e#19641\u003c/a\u003e - Add checks for OpenJDK Style §3.10 - Variable Declarations.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19640\"\u003e#19640\u003c/a\u003e - Add checks for OpenJDK Style §4.1 - Package Names.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/18227\"\u003e#18227\u003c/a\u003e - Extend TextBlockGoogleStyleFormatting to check indentation of each line in the blocks.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19770\"\u003e#19770\u003c/a\u003e - JavadocTypeCheck incorrectly matches record component \u003ccode\u003e@\u003c/code\u003eparam tags using prefix instead of exact match.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/17052\"\u003e#17052\u003c/a\u003e - Add support for flexible constructor bodies (JEP 513) targeted for JDK25.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/17464\"\u003e#17464\u003c/a\u003e - RequireThis false positive inside annotation definition.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19623\"\u003e#19623\u003c/a\u003e - Add checks for OpenJDK Style  §3.3 - Import statements.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/17203\"\u003e#17203\u003c/a\u003e - PatternVariableAssignment check false negative when pattern variable extends beyond the statement of introduction.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19716\"\u003e#19716\u003c/a\u003e - False Negative: SimplifyBooleanExpression does not report with paranthesized boolean literals in ternary operators.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19617\"\u003e#19617\u003c/a\u003e - Add checks for OpenJDK Style §2 - Java Source Files.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/17253\"\u003e#17253\u003c/a\u003e - Google-style: Illegal to break the line before or after the lambda arrow.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19149\"\u003e#19149\u003c/a\u003e - update MissingJavadocTypeCheck to use AST of javadoc.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/2629\"\u003e#2629\u003c/a\u003e - IndentationCheck: incorrect validation for class definition.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/5685\"\u003e#5685\u003c/a\u003e - Indentation: false positive for try child on the same line.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/11822\"\u003e#11822\u003c/a\u003e - RequireThisCheck giving multiple violation for classes nested in lambdas.\n\u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19622\"\u003e#19622\u003c/a\u003e - Add checks for OpenJDK Style §3.2 - Package declaration.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/checkstyle/checkstyle/commit/110e63eee6e634b5ebcdf21b1cd1c96c518007d8\"\u003e\u003ccode\u003e110e63e\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release checkstyle-13.5.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/checkstyle/checkstyle/commit/47d9268a1fb45beb3a67be12ff934b80a9d2f10b\"\u003e\u003ccode\u003e47d9268\u003c/code\u003e\u003c/a\u003e doc: release notes for 13.5.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/checkstyle/checkstyle/commit/2ae101f6a70ffd4a232b2d30a4bb0a2dc42d9b9e\"\u003e\u003ccode\u003e2ae101f\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19793\"\u003e#19793\u003c/a\u003e: Anchor IndentationCheck regex in google_checks.xml SuppressWith...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/checkstyle/checkstyle/commit/fb3c9e949e61b3573202b5884d54b4d598400743\"\u003e\u003ccode\u003efb3c9e9\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19827\"\u003e#19827\u003c/a\u003e: Complete removal of chapter numbers\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/checkstyle/checkstyle/commit/e2b04118c7103e5564518edfa770e0b8d786b7aa\"\u003e\u003ccode\u003ee2b0411\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/18435\"\u003e#18435\u003c/a\u003e: Fix xdocs Examples AST Consistency Test - nowhitespacebefore\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/checkstyle/checkstyle/commit/096df1df3554905130a45b4af4fb05512bc10a50\"\u003e\u003ccode\u003e096df1d\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19764\"\u003e#19764\u003c/a\u003e: Move violation comment out of Javadoc\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/checkstyle/checkstyle/commit/4d69a3f4e3abf67f960703eae7fe3212dc2694e3\"\u003e\u003ccode\u003e4d69a3f\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/19993\"\u003e#19993\u003c/a\u003e: Regexp check for unnecessary // ok comments is configured under...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/checkstyle/checkstyle/commit/035297e75b576c07316070e092576674b72ef3f5\"\u003e\u003ccode\u003e035297e\u003c/code\u003e\u003c/a\u003e dependency: bump org.pitest:pitest-maven from 1.25.2 to 1.25.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/checkstyle/checkstyle/commit/6b827897c8cc3f2414a0543bd97b3704a6e5aaa0\"\u003e\u003ccode\u003e6b82789\u003c/code\u003e\u003c/a\u003e supplemental: Fixes Overloaded Methods Order\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/checkstyle/checkstyle/commit/d9306dab50c1a267c03595acbedbc8f0650a79b4\"\u003e\u003ccode\u003ed9306da\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/checkstyle/checkstyle/issues/18435\"\u003e#18435\u003c/a\u003e: Fix xdocs Examples AST Consistency Test - linelength\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/checkstyle/checkstyle/compare/checkstyle-13.4.2...checkstyle-13.5.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.ow2.asm:asm` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-commons` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-tree` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-util` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-commons` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-tree` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-util` from 9.10 to 9.10.1\n\nUpdates `com.sun.xml.bind:jaxb-core` from 4.0.8 to 4.0.9\n\nUpdates `com.sun.xml.bind:jaxb-impl` from 4.0.8 to 4.0.9\n\nUpdates `com.sun.xml.bind:jaxb-xjc` from 4.0.8 to 4.0.9\n\nUpdates `com.sun.xml.bind:jaxb-impl` from 4.0.8 to 4.0.9\n\nUpdates `com.sun.xml.bind:jaxb-xjc` from 4.0.8 to 4.0.9\n\nUpdates `com.sun.xml.ws:jaxws-rt` from 4.0.4 to 4.0.5\n\nUpdates `org.eclipse.parsson:parsson` from 1.1.7 to 1.1.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/eclipse-ee4j/parsson/releases\"\u003eorg.eclipse.parsson:parsson's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.1.9\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePublish Central releases automatically by \u003ca href=\"https://github.com/jbescos\"\u003e\u003ccode\u003e@​jbescos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/171\"\u003eeclipse-ee4j/parsson#171\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/eclipse-ee4j/parsson/compare/1.1.8...1.1.9\"\u003ehttps://github.com/eclipse-ee4j/parsson/compare/1.1.8...1.1.9\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.1.8\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate deprecated GH actions by \u003ca href=\"https://github.com/jbescos\"\u003e\u003ccode\u003e@​jbescos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/136\"\u003eeclipse-ee4j/parsson#136\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMake JsonArrayImpl implement RandomAccess by \u003ca href=\"https://github.com/marschall\"\u003e\u003ccode\u003e@​marschall\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/135\"\u003eeclipse-ee4j/parsson#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplement JsonStructureParser.currentEvent() by \u003ca href=\"https://github.com/marschall\"\u003e\u003ccode\u003e@​marschall\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/134\"\u003eeclipse-ee4j/parsson#134\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove unused method by \u003ca href=\"https://github.com/pzygielo\"\u003e\u003ccode\u003e@​pzygielo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/137\"\u003eeclipse-ee4j/parsson#137\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRename parameter to match field by \u003ca href=\"https://github.com/pzygielo\"\u003e\u003ccode\u003e@​pzygielo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/138\"\u003eeclipse-ee4j/parsson#138\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplement JsonStructureParser#getValue methods by \u003ca href=\"https://github.com/marschall\"\u003e\u003ccode\u003e@​marschall\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/140\"\u003eeclipse-ee4j/parsson#140\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse assertThrows by \u003ca href=\"https://github.com/marschall\"\u003e\u003ccode\u003e@​marschall\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/142\"\u003eeclipse-ee4j/parsson#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix compilation failes by \u003ca href=\"https://github.com/marschall\"\u003e\u003ccode\u003e@​marschall\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/144\"\u003eeclipse-ee4j/parsson#144\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdding Dependabot for dependency management by \u003ca href=\"https://github.com/mswatosh\"\u003e\u003ccode\u003e@​mswatosh\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/148\"\u003eeclipse-ee4j/parsson#148\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ejson input size limit by \u003ca href=\"https://github.com/jbescos\"\u003e\u003ccode\u003e@​jbescos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/169\"\u003eeclipse-ee4j/parsson#169\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd Maven Central publishing release profile by \u003ca href=\"https://github.com/jbescos\"\u003e\u003ccode\u003e@​jbescos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/170\"\u003eeclipse-ee4j/parsson#170\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marschall\"\u003e\u003ccode\u003e@​marschall\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/135\"\u003eeclipse-ee4j/parsson#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mswatosh\"\u003e\u003ccode\u003e@​mswatosh\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/148\"\u003eeclipse-ee4j/parsson#148\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/eclipse-ee4j/parsson/compare/1.1.7...1.1.8\"\u003ehttps://github.com/eclipse-ee4j/parsson/compare/1.1.7...1.1.8\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/f7204e83adb07bfe9f722bbd914dc680b1071114\"\u003e\u003ccode\u003ef7204e8\u003c/code\u003e\u003c/a\u003e Prepare release org.eclipse.parsson:project:1.1.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/2d01f006047e05cef49d13abe5ab25d66108f71a\"\u003e\u003ccode\u003e2d01f00\u003c/code\u003e\u003c/a\u003e Publish Central releases automatically (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/171\"\u003e#171\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/10920a209563d8a0ac13ca3d41e3c6066367835f\"\u003e\u003ccode\u003e10920a2\u003c/code\u003e\u003c/a\u003e Add Maven Central publishing release profile (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/170\"\u003e#170\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c\"\u003e\u003ccode\u003e134e8d1\u003c/code\u003e\u003c/a\u003e json input size limit (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/169\"\u003e#169\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/0789993205ee613ad63710bd3eafb96cd97afbde\"\u003e\u003ccode\u003e0789993\u003c/code\u003e\u003c/a\u003e Adding Dependabot for dependency management (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/148\"\u003e#148\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/216b15d0e9231546fa542467f9a3732973619b26\"\u003e\u003ccode\u003e216b15d\u003c/code\u003e\u003c/a\u003e Fix compilation failes (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/144\"\u003e#144\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/34177db697ee56f8e7a41f6b5998404681baf251\"\u003e\u003ccode\u003e34177db\u003c/code\u003e\u003c/a\u003e Use assertThrows (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/142\"\u003e#142\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/9d6796013c7a526c7ac80edd690e16bb4a186dd4\"\u003e\u003ccode\u003e9d67960\u003c/code\u003e\u003c/a\u003e Implement JsonStructureParser#getValue methods (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/140\"\u003e#140\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/7c8c2444c61b6b1f44c2c2f36e6ebf905b2c7624\"\u003e\u003ccode\u003e7c8c244\u003c/code\u003e\u003c/a\u003e Rename parameter to match field (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/138\"\u003e#138\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/4dda2e0195dcde4f11eda1c31c642d84eda50ae5\"\u003e\u003ccode\u003e4dda2e0\u003c/code\u003e\u003c/a\u003e Remove unused method (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/137\"\u003e#137\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/eclipse-ee4j/parsson/compare/1.1.7...1.1.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.mongodb:mongodb-driver-sync` from 5.7.0 to 5.8.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mongodb/mongo-java-driver/releases\"\u003eorg.mongodb:mongodb-driver-sync's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eJava Driver 5.8.0 (May 28, 2026)\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003e🔥 Enhancements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded typed builder API for vector search index definitions \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1960\"\u003e#1960\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003e$rerank\u003c/code\u003e aggregation stage support (MongoDB 8.3 / Atlas) \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1963\"\u003e#1963\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003evectorSearch\u003c/code\u003e operator support for the \u003ccode\u003e$search\u003c/code\u003e pipeline stage \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1962\"\u003e#1962\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003estoredSource\u003c/code\u003e support for vector search indexes and \u003ccode\u003ereturnStoredSource\u003c/code\u003e for \u003ccode\u003e$vectorSearch\u003c/code\u003e queries \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1977\"\u003e#1977\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eBinaryVector\u003c/code\u003e and \u003ccode\u003eVectorSearchQuery\u003c/code\u003e \u003ccode\u003evectorSearch\u003c/code\u003e overloads to the Scala driver \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1986\"\u003e#1986\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eOptimized \u003ccode\u003eRawBsonDocument\u003c/code\u003e encode and decode by eliminating intermediate allocations \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1988\"\u003e#1988\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePreliminary refactoring for backpressure support \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1952\"\u003e#1952\u003c/a\u003e by \u003ca href=\"https://github.com/stIncMale\"\u003e\u003ccode\u003e@​stIncMale\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSmall improvements related to value-based classes \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1964\"\u003e#1964\u003c/a\u003e by \u003ca href=\"https://github.com/stIncMale\"\u003e\u003ccode\u003e@​stIncMale\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🛠 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed OSGi bundle resolution failure when Micrometer is not present \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1982\"\u003e#1982\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded missing Javadoc to \u003ccode\u003eMongodbObservation\u003c/code\u003e and \u003ccode\u003eMongodbObservationContext\u003c/code\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e📦 Dependency Updates\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpgraded \u003ccode\u003elibmongocrypt\u003c/code\u003e to 1.18.1 \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1983\"\u003e#1983\u003c/a\u003e by \u003ca href=\"https://github.com/strogiyotec\"\u003e\u003ccode\u003e@​strogiyotec\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🧪 Testing \u0026amp; CI\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003eAGENTS.md\u003c/code\u003e for AI coding agent support across all modules by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded test cases for new auto-embedding index fields \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1936\"\u003e#1936\u003c/a\u003e by \u003ca href=\"https://github.com/strogiyotec\"\u003e\u003ccode\u003e@​strogiyotec\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded Scala 3 to \u003ccode\u003epublish.sh\u003c/code\u003e \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1958\"\u003e#1958\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eNamespaceExists\u003c/code\u003e test failure \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1956\"\u003e#1956\u003c/a\u003e by \u003ca href=\"https://github.com/nhachicha\"\u003e\u003ccode\u003e@​nhachicha\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSimplified \u003ccode\u003eRetryState\u003c/code\u003e creation as preliminary backpressure work \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1961\"\u003e#1961\u003c/a\u003e by \u003ca href=\"https://github.com/stIncMale\"\u003e\u003ccode\u003e@​stIncMale\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMade \u003ccode\u003eRetryState.isLastAttempt\u003c/code\u003e private and simplified code \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1967\"\u003e#1967\u003c/a\u003e by \u003ca href=\"https://github.com/stIncMale\"\u003e\u003ccode\u003e@​stIncMale\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/techbelle\"\u003e\u003ccode\u003e@​techbelle\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1972\"\u003emongodb/mongo-java-driver#1972\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVerifying artifact signatures\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://www.mongodb.com/docs/drivers/java/sync/current/security/validate-signatures/\"\u003ehttps://www.mongodb.com/docs/drivers/java/sync/current/security/validate-signatures/\u003c/a\u003e for the full procedure.\u003c/p\u003e\n\u003cp\u003eTo download and import the public key for verifying signatures, execute\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003egpg --keyserver hkps://keyserver.ubuntu.com --recv-keys 1a75005e142192223d6a7c3b76e0008d166740a8\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/mongodb/mongo-java-driver/compare/r5.7.0...r5.8.0\"\u003ehttps://github.com/mongodb/mongo-java-driver/compare/r5.7.0...r5.8.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/6024ca9f6ca226cffb7526659b19810707970310\"\u003e\u003ccode\u003e6024ca9\u003c/code\u003e\u003c/a\u003e Version: bump 5.8.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/f3bbdb2701b8c462c64db4c5f3f2c61b23b723e9\"\u003e\u003ccode\u003ef3bbdb2\u003c/code\u003e\u003c/a\u003e Add BinaryVector and VectorSearchQuery vectorSearch overloads to Scala driver...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/966ababa45a5d38a644bc8e8ce8de58eb882dd66\"\u003e\u003ccode\u003e966abab\u003c/code\u003e\u003c/a\u003e Upgrade libmongocrypt version to 1.18.1 (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/1983\"\u003e#1983\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/98e07611f0f0c3e22d89cfb766137e59ab7b2a2f\"\u003e\u003ccode\u003e98e0761\u003c/code\u003e\u003c/a\u003e Optimize RawBsonDocument encode and decode by eliminating intermediate alloca...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/40ee8d511e4541727de2edc4527d209d842fd607\"\u003e\u003ccode\u003e40ee8d5\u003c/code\u003e\u003c/a\u003e Fix NamespaceExists test failure (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/1956\"\u003e#1956\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/541af753642b070a04ec64f54b9af018d297c2d3\"\u003e\u003ccode\u003e541af75\u003c/code\u003e\u003c/a\u003e Mark micrometer OSGi imports as optional and add bundle resolution test (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/1982\"\u003e#1982\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/cd6c045cf866d6d5038fcbcf8825742174a3903a\"\u003e\u003ccode\u003ecd6c045\u003c/code\u003e\u003c/a\u003e Add storedSource support for vector search indexes and returnStoredSource for...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/717da9c63b5531e35e684bc0a8043500b3fa7560\"\u003e\u003ccode\u003e717da9c\u003c/code\u003e\u003c/a\u003e Revert \u0026quot;Resolve TLS channel address before opening socket\u0026quot; (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/1979\"\u003e#1979\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/58122f6b280cda429af25f69e3692132e1eabb60\"\u003e\u003ccode\u003e58122f6\u003c/code\u003e\u003c/a\u003e Add vectorSearch operator for $search pipeline stage (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/1962\"\u003e#1962\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/13d4aef5f58283977042340ee8d7d9af4a1786d4\"\u003e\u003ccode\u003e13d4aef\u003c/code\u003e\u003c/a\u003e Resolve TLS channel address before opening socket\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mongodb/mongo-java-driver/compare/r5.7.0...r5.8.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.oracle.nosql.sdk:nosqldriver` from 5.4.21 to 5.4.22\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/oracle/nosql-java-sdk/releases\"\u003ecom.oracle.nosql.sdk:nosqldriver's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e5.4.22\u003c/h2\u003e\n\u003ch2\u003e[5.4.22] 2026-05-15\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded redaction of sensitive HTTP header values in debug logging by default,\nplus the \u003ccode\u003ecom.oracle.nosql.sdk.nosqldriver.log-sensitive-headers\u003c/code\u003e system\nproperty to allow full header values when needed for debugging.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed bug in handling of empty namespaces in prepared statements.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated Netty version to 4.1.133.Final\u003c/li\u003e\n\u003cli\u003eUpdated Jackson-core to 2.18.7\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/oracle/nosql-java-sdk/blob/main/CHANGELOG.md\"\u003ecom.oracle.nosql.sdk:nosqldriver's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[5.4.22] 2026-05-15\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded redaction of sensitive HTTP header values in debug logging by default,\nplus the \u003ccode\u003ecom.oracle.nosql.sdk.nosqldriver.log-sensitive-headers\u003c/code\u003e system\nproperty to allow full header values when needed for debugging.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed bug in handling of empty namespaces in prepared statements.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated Netty version to 4.1.133.Final\u003c/li\u003e\n\u003cli\u003eUpdated Jackson-core to 2.18.7\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/801ba4070febb5c0e870ab8cdb5ee7938831a545\"\u003e\u003ccode\u003e801ba40\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/oracle/nosql-java-sdk/issues/204\"\u003e#204\u003c/a\u003e from oracle/fix/netty-4.1.133\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/d7c7ed22b8c9437041dc473577d899dcf984db31\"\u003e\u003ccode\u003ed7c7ed2\u003c/code\u003e\u003c/a\u003e additional changes for 5.4.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/e27f8f7c19a457ebdb8cd8130db61f75064ccc43\"\u003e\u003ccode\u003ee27f8f7\u003c/code\u003e\u003c/a\u003e update 3rd parties\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/0c21037e61f44fac98af2e52b2506c3a0bcb9028\"\u003e\u003ccode\u003e0c21037\u003c/code\u003e\u003c/a\u003e Handle null or empty namespace list in prepared statements (\u003ca href=\"https://redirect.github.com/oracle/nosql-java-sdk/issues/200\"\u003e#200\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/b81457b2e65e323c30cda83d6ce7cee8cb771a83\"\u003e\u003ccode\u003eb81457b\u003c/code\u003e\u003c/a\u003e Moving to 5.4.22-SNAPSHOT (\u003ca href=\"https://redirect.github.com/oracle/nosql-java-sdk/issues/199\"\u003e#199\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/6248e8b0d53c269a888bc335faeede7c5619f323\"\u003e\u003ccode\u003e6248e8b\u003c/code\u003e\u003c/a\u003e implemented UNION (and a few other query operators) (\u003ca href=\"https://redirect.github.com/oracle/nosql-java-sdk/issues/184\"\u003e#184\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/d09ae8bbcdd1ae459d80ad269c2ef1ff33ed65cd\"\u003e\u003ccode\u003ed09ae8b\u003c/code\u003e\u003c/a\u003e Cleaned up compiler warnings\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/7f8a40f0c92b0a63e7c2d81f65daa03971b2b38d\"\u003e\u003ccode\u003e7f8a40f\u003c/code\u003e\u003c/a\u003e Redact sensitive HTTP headers in debug logging (\u003ca href=\"https://redirect.github.com/oracle/nosql-java-sdk/issues/198\"\u003e#198\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/4a3e9e5298a11450a9fe85a5857c2a0e75686c2a\"\u003e\u003ccode\u003e4a3e9e5\u003c/code\u003e\u003c/a\u003e Preparing for 5.4.21 release (\u003ca href=\"https://redirect.github.com/oracle/nosql-java-sdk/issues/196\"\u003e#196\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/oracle/nosql-java-sdk/compare/v5.4.21...v5.4.22\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ch.qos.logback:logback-core` from 1.5.32 to 1.5.34\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.34\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-06-01 Release of logback version 1.5.34\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In case certain StackTraceElement values returned by the Throwable.getStackTrace method are null, StackTraceElementProxy substitutes a dummy instance instead of throwing an IllegalArgumentException. This resolves [issues \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003e#1040\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003eqos-ch/logback#1040\u003c/a\u003e), reported by Naotsugu Kobayashi.\u003c/p\u003e\n\u003cp\u003e• HardenedObjectInputStream will now throw an InvalidClassException during deserialization attempts of Proxy classes. This change addresses potential deserialization whitelist bypass vulnerability reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-10532\"\u003eCVE-2026-10532\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bitwise identical binary of this version can be reproduced by building from source code at commit e62272ac152469aec1ede056c3c7d0d7314e7bfe associated with the tag v_1.5.34. This release was built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e62272ac152469aec1ede056c3c7d0d7314e7bfe\"\u003e\u003ccode\u003ee62272a\u003c/code\u003e\u003c/a\u003e prepare release 1.5.34\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/1e9e926db1529b729a0e2d29fdee151c2aea0341\"\u003e\u003ccode\u003e1e9e926\u003c/code\u003e\u003c/a\u003e add resolveProxyClassRejectsDynamicProxies unit test\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/2de5cbe90b74fa284685304bc91321313b0d8e2f\"\u003e\u003ccode\u003e2de5cbe\u003c/code\u003e\u003c/a\u003e added StackTraceElementProxyTest, minor edits to AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/0e9b9278b5d3f0b573762cd7b5482ed65244418e\"\u003e\u003ccode\u003e0e9b927\u003c/code\u003e\u003c/a\u003e in case StackTraceElement is null use a substitute, fixing issues/1040\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/f7a0654c2b7e8e1c461e3d9e483e82ef969b5818\"\u003e\u003ccode\u003ef7a0654\u003c/code\u003e\u003c/a\u003e prevent resolveProxyClass bypass\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/249b81f3754f1fb58f8507f244a36c7a940854c0\"\u003e\u003ccode\u003e249b81f\u003c/code\u003e\u003c/a\u003e docs are no longer distributed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/1c3b26a839f05b6bc1769e5a028ef326c711cec8\"\u003e\u003ccode\u003e1c3b26a\u003c/code\u003e\u003c/a\u003e start work on 1.5.34-SNAPSHOT\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.34\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ch.qos.logback:logback-classic` from 1.5.32 to 1.5.34\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-classic's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.34\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-06-01 Release of logback version 1.5.34\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In case certain StackTraceElement values returned by the Throwable.getStackTrace method are null, StackTraceElementProxy substitutes a dummy instance instead of throwing an IllegalArgumentException. This resolves [issues \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003e#1040\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003eqos-ch/logback#1040\u003c/a\u003e), reported by Naotsugu Kobayashi.\u003c/p\u003e\n\u003cp\u003e• HardenedObjectInputStream will now throw an InvalidClassException during deserialization attempts of Proxy classes. This change addresses potential deserialization whitelist bypass vulnerability reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-10532\"\u003eCVE-2026-10532\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bitwise identical binary of this version can be reproduced by building from source code at commit e62272ac152469aec1ede056c3c7d0d7314e7bfe associated with the tag v_1.5.34. This release was built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e62272ac152469aec1ede056c3c7d0d7314e7bfe\"\u003e\u003ccode\u003ee62272a\u003c/code\u003e\u003c/a\u003e prepare release 1.5.34\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/1e9e926db1529b729a0e2d29fdee151c2aea0341\"\u003e\u003ccode\u003e1e9e926\u003c/code\u003e\u003c/a\u003e add resolveProxyClassRejectsDynamicProxies unit test\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/2de5cbe90b74fa284685304bc91321313b0d8e2f\"\u003e\u003ccode\u003e2de5cbe\u003c/code\u003e\u003c/a\u003e added StackTraceElementProxyTest, minor edits to AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/0e9b9278b5d3f0b573762cd7b5482ed65244418e\"\u003e\u003ccode\u003e0e9b927\u003c/code\u003e\u003c/a\u003e in case StackTraceElement is null use a substitute, fixing issues/1040\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/f7a0654c2b7e8e1c461e3d9e483e82ef969b5818\"\u003e\u003ccode\u003ef7a0654\u003c/code\u003e\u003c/a\u003e prevent resolveProxyClass bypass\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/249b81f3754f1fb58f8507f244a36c7a940854c0\"\u003e\u003ccode\u003e249b81f\u003c/code\u003e\u003c/a\u003e docs are no longer distributed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/1c3b26a839f05b6bc1769e5a028ef326c711cec8\"\u003e\u003ccode\u003e1c3b26a\u003c/code\u003e\u003c/a\u003e start work on 1.5.34-SNAPSHOT\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.34\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ch.qos.logback:logback-classic` from 1.5.32 to 1.5.34\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-classic's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.34\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-06-01 Release of logback version 1.5.34\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In case certain StackTraceElement values returned by the Throwable.getStackTrace method are null, StackTraceElementProxy substitutes a dummy instance instead of throwing an IllegalArgumentException. This resolves [issues \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003e#1040\u003c/a\u003e](\u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1040\"\u003eqos-ch/logback#1040\u003c/a\u003e), reported by Naotsugu Kobayashi.\u003c/p\u003e\n\u003cp\u003e• HardenedObjectInputStream will now throw an InvalidClassException during deserialization attempts of Proxy classes. This change addresses potential deserialization whitelist bypass vulnerability reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-10532\"\u003eCVE-2026-10532\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bitwise identical binary of this version can be reproduced by building from source code at commit e62272ac152469aec1ede056c3c7d0d7314e7bfe associated with the tag v_1.5.34. This release was built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e62272ac152469aec1ede056c3c7d0d7314e7bfe\"\u003e\u003ccode\u003ee62272a\u003c/code\u003e\u003c/a\u003e prepare release 1.5.34\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/1e9e926db1529b729a0e2d29fdee151c2aea0341\"\u003e\u003ccode\u003e1e9e926\u003c/code\u003e\u003c/a\u003e add resolveProxyClassRejectsDynamicProxies unit test\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/2de5cbe90b74fa284685304bc91321313b0d8e2f\"\u003e\u003ccode\u003e2de5cbe\u003c/code\u003e\u003c/a\u003e added StackTraceElementProxyTest, minor edits to AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/0e9b9278b5d3f0b573762cd7b5482ed65244418e\"\u003e\u003ccode\u003e0e9b927\u003c/code\u003e\u003c/a\u003e in case StackTraceElement is null use a substitute, fixing issues/1040\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/f7a0654c2b7e8e1c461e3d9e483e82ef969b5818\"\u003e\u003ccode\u003ef7a0654\u003c/code\u003e\u003c/a\u003e prevent resolveProxyClass bypass\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/249b81f3754f1fb58f8507f244a36c7a940854c0\"\u003e\u003ccode\u003e249b81f\u003c/code\u003e\u003c/a\u003e docs are no longer distributed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/1c3b26a839f05b6bc1769e5a028ef326c711cec8\"\u003e\u003ccode\u003e1c3b26a\u003c/code\u003e\u003c/a\u003e start work on 1.5.34-SNAPSHOT\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.34\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/eclipse-ee4j/eclipselink/pull/2763","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/eclipse-ee4j%2Feclipselink/issues/2763","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2763/packages"}},{"old_version":"1.5.32","new_version":"1.5.33","update_type":"patch","path":null,"pr_created_at":"2026-05-31T04:13:17.000Z","version_change":"1.5.32 → 1.5.33","issue":{"uuid":"4556533413","node_id":"PR_kwDOP2l8iM7hCp0D","number":104,"state":"open","title":"chore(deps): bump the maven-minor-patch group across 1 directory with 9 updates","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-05-31T04:13:17.000Z","updated_at":"2026-05-31T04:13:29.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): bump","group_name":"maven-minor-patch","update_count":9,"packages":[{"name":"ch.qos.logback:logback-classic","old_version":"1.5.32","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"},{"name":"ch.qos.logback:logback-core","old_version":"1.5.32","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"},{"name":"org.flywaydb:flyway-core","old_version":"12.4.0","new_version":"12.7.0"},{"name":"com.auth0:java-jwt","old_version":"4.5.1","new_version":"4.5.2","repository_url":"https://github.com/auth0/java-jwt"},{"name":"com.fasterxml.jackson.core:jackson-core","old_version":"2.21.2","new_version":"2.21.4","repository_url":"https://github.com/FasterXML/jackson-core"},{"name":"org.flywaydb:flyway-maven-plugin","old_version":"12.4.0","new_version":"12.7.0"},{"name":"org.apache.maven.plugins:maven-surefire-plugin","old_version":"3.5.5","new_version":"3.5.6","repository_url":"https://github.com/apache/maven-surefire"},{"name":"org.apache.maven.plugins:maven-failsafe-plugin","old_version":"3.5.5","new_version":"3.5.6","repository_url":"https://github.com/apache/maven-surefire"},{"name":"org.sonarsource.scanner.maven:sonar-maven-plugin","old_version":"5.6.0.6792","new_version":"5.7.0.6970","repository_url":"https://github.com/SonarSource/sonar-scanner-maven"}],"path":null,"ecosystem":"maven"},"body":"Bumps the maven-minor-patch group with 9 updates in the /backend directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) | `1.5.32` | `1.5.33` |\n| [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) | `1.5.32` | `1.5.33` |\n| org.flywaydb:flyway-core | `12.4.0` | `12.7.0` |\n| [com.auth0:java-jwt](https://github.com/auth0/java-jwt) | `4.5.1` | `4.5.2` |\n| [com.fasterxml.jackson.core:jackson-core](https://github.com/FasterXML/jackson-core) | `2.21.2` | `2.21.4` |\n| org.flywaydb:flyway-maven-plugin | `12.4.0` | `12.7.0` |\n| [org.apache.maven.plugins:maven-surefire-plugin](https://github.com/apache/maven-surefire) | `3.5.5` | `3.5.6` |\n| [org.apache.maven.plugins:maven-failsafe-plugin](https://github.com/apache/maven-surefire) | `3.5.5` | `3.5.6` |\n| [org.sonarsource.scanner.maven:sonar-maven-plugin](https://github.com/SonarSource/sonar-scanner-maven) | `5.6.0.6792` | `5.7.0.6970` |\n\n\nUpdates `ch.qos.logback:logback-classic` from 1.5.32 to 1.5.33\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-classic's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ch.qos.logback:logback-core` from 1.5.32 to 1.5.33\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ch.qos.logback:logback-core` from 1.5.32 to 1.5.33\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.flywaydb:flyway-core` from 12.4.0 to 12.7.0\n\nUpdates `com.auth0:java-jwt` from 4.5.1 to 4.5.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/auth0/java-jwt/releases\"\u003ecom.auth0:java-jwt's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e4.5.2\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003eAdded\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eChore: Bump update commons-beanutils dependency \u003ca href=\"https://redirect.github.com/auth0/java-jwt/pull/761\"\u003e#761\u003c/a\u003e (\u003ca href=\"https://github.com/tanya732\"\u003etanya732\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChore: Update Readme with Java 21 \u003ca href=\"https://redirect.github.com/auth0/java-jwt/pull/760\"\u003e#760\u003c/a\u003e (\u003ca href=\"https://github.com/tanya732\"\u003etanya732\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/auth0/java-jwt/blob/master/CHANGELOG.md\"\u003ecom.auth0:java-jwt's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e\u003ca href=\"https://github.com/auth0/java-jwt/tree/4.5.2\"\u003e4.5.2\u003c/a\u003e (2026-04-29)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://github.com/auth0/java-jwt/compare/4.5.1...4.5.2\"\u003eFull Changelog\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eAdded\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eChore: Bump update commons-beanutils dependency \u003ca href=\"https://redirect.github.com/auth0/java-jwt/pull/761\"\u003e#761\u003c/a\u003e (\u003ca href=\"https://github.com/tanya732\"\u003etanya732\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eChore: Update Readme with Java 21 \u003ca href=\"https://redirect.github.com/auth0/java-jwt/pull/760\"\u003e#760\u003c/a\u003e (\u003ca href=\"https://github.com/tanya732\"\u003etanya732\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/auth0/java-jwt/commit/695fd2bea64b8466b872a9d0c2e7019fee7ac86f\"\u003e\u003ccode\u003e695fd2b\u003c/code\u003e\u003c/a\u003e Release 4.5.2 (\u003ca href=\"https://redirect.github.com/auth0/java-jwt/issues/765\"\u003e#765\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/auth0/java-jwt/commit/4ac31787e2bb264d346ddb51b54ce4893d51eb18\"\u003e\u003ccode\u003e4ac3178\u003c/code\u003e\u003c/a\u003e Release 4.5.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/auth0/java-jwt/commit/d056a79e402d6d6c667a1d5fe9233dd87240da1c\"\u003e\u003ccode\u003ed056a79\u003c/code\u003e\u003c/a\u003e Bump com.fasterxml.jackson.core:jackson-databind from 2.21.2 to 2.21.3 in /li...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/auth0/java-jwt/commit/37f195a954cce32abd4b4eb212e8b7695781c2bb\"\u003e\u003ccode\u003e37f195a\u003c/code\u003e\u003c/a\u003e Bump com.fasterxml.jackson.core:jackson-databind in /lib\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/auth0/java-jwt/commit/dba4c93e2ef37b82b45776d41f8dcbc24df8335a\"\u003e\u003ccode\u003edba4c93\u003c/code\u003e\u003c/a\u003e Chore: Bump update commons-beanutils dependency (\u003ca href=\"https://redirect.github.com/auth0/java-jwt/issues/761\"\u003e#761\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/auth0/java-jwt/commit/84d4c8f383ae7c06e0e53f5bd7d84324ad3bcad9\"\u003e\u003ccode\u003e84d4c8f\u003c/code\u003e\u003c/a\u003e Merge branch 'master' into chore/bump-commons-beanutils\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/auth0/java-jwt/commit/5c923d4981ba39c18d530ba3e155c314b6cfd4e1\"\u003e\u003ccode\u003e5c923d4\u003c/code\u003e\u003c/a\u003e Chore: Add SCA scan workflow (\u003ca href=\"https://redirect.github.com/auth0/java-jwt/issues/762\"\u003e#762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/auth0/java-jwt/commit/09a4da58242a52bd937c7ac1b2914adc8a80e73c\"\u003e\u003ccode\u003e09a4da5\u003c/code\u003e\u003c/a\u003e Merge branch 'master' into chore/add-sca-scan\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/auth0/java-jwt/commit/ef47e64ba46e5bb39abc68ddbfcd49f61cac4ec7\"\u003e\u003ccode\u003eef47e64\u003c/code\u003e\u003c/a\u003e Chore: Add SCA scan workflow\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/auth0/java-jwt/commit/3fcfbcb3bed8a66ddb37be63bb3cfea7b873312b\"\u003e\u003ccode\u003e3fcfbcb\u003c/code\u003e\u003c/a\u003e Chore: Bump update commons-beanutils dependency\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/auth0/java-jwt/compare/4.5.1...4.5.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.core:jackson-core` from 2.21.2 to 2.21.4\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/f17a4f7a7ffe895be367ce91afc6b06632643126\"\u003e\u003ccode\u003ef17a4f7\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-core-2.21.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/c6411e17ced5463d93fc6577f7bd5a76a43fd1e5\"\u003e\u003ccode\u003ec6411e1\u003c/code\u003e\u003c/a\u003e Prep for 2.21.4 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/52633da4cc57d73d149af203b145b221af08257f\"\u003e\u003ccode\u003e52633da\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/1fa7bb9c536fa64d63e790747a4e8c1d41e77fe0\"\u003e\u003ccode\u003e1fa7bb9\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/6dea8a80278a46a26880c3a9964b848da8ce78d8\"\u003e\u003ccode\u003e6dea8a8\u003c/code\u003e\u003c/a\u003e Merge branch '2.18' into 2.19\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/ada244d0a1df6fbd318fd813fff444a2cbcf2398\"\u003e\u003ccode\u003eada244d\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/52f69d357431805db816c1f11e2403143dea49e6\"\u003e\u003ccode\u003e52f69d3\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/899d70ae7ddf5bb42db09bfe3c384b7fe4b68808\"\u003e\u003ccode\u003e899d70a\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-core-2.18.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/a006b52ed5de9ac8e94a0074e7e0c09317b5c15d\"\u003e\u003ccode\u003ea006b52\u003c/code\u003e\u003c/a\u003e Prep for 2.18.8 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/4c058160d03fcf6b66d9a270e1a1b1451c8108f3\"\u003e\u003ccode\u003e4c05816\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-core/compare/jackson-core-2.21.2...jackson-core-2.21.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.flywaydb:flyway-maven-plugin` from 12.4.0 to 12.7.0\n\nUpdates `org.apache.maven.plugins:maven-surefire-plugin` from 3.5.5 to 3.5.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/apache/maven-surefire/releases\"\u003eorg.apache.maven.plugins:maven-surefire-plugin's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.5.6\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e🚀 New features and improvements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIntroduce reportTestTimestamp option and include timestamp for test sets and test cases (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3261\"\u003e#3261\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3302\"\u003e#3302\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIssue \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/2613\"\u003e#2613\u003c/a\u003e Debugging failsafe tests: Message 'Listening for transport dt_socket at address' is not displayed anymore when using maven.surefire.debug (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3353\"\u003e#3353\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3354\"\u003e#3354\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEnsure that the statistics filename is calculated only once. (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3326\"\u003e#3326\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3327\"\u003e#3327\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eflakes\u003c/code\u003e attribute to use in \u003ccode\u003etestsuite\u003c/code\u003e report (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3306\"\u003e#3306\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3308\"\u003e#3308\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[BACKPORT 3.5.x] \u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-2049\"\u003e[SUREFIRE-2049]\u003c/a\u003e - Fix SHUTDOWN type lost during command serialization. (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3270\"\u003e#3270\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3289\"\u003e#3289\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: null guard for context map (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3269\"\u003e#3269\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3272\"\u003e#3272\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e👻 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e3.5.x/bug/cherry pick embedded mode its (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3328\"\u003e#3328\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse surefire 3.5.5 by project itself for testing (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3324\"\u003e#3324\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFollow Oracle javadoc guidelines (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3177\"\u003e#3177\u003c/a\u003e) \u003ca href=\"https://github.com/elharo\"\u003e\u003ccode\u003e@​elharo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📦 Dependency updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump org.fusesource.jansi:jansi from 2.4.2 to 2.4.3 (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3334\"\u003e#3334\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump commons-io:commons-io from 2.21.0 to 2.22.0 (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3350\"\u003e#3350\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/25ea054860a5c1e5932b360d8aa0a31944c2b841\"\u003e\u003ccode\u003e25ea054\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release surefire-3.5.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/e5f374ccdefd5b40d75e0072a754708183d9ec5e\"\u003e\u003ccode\u003ee5f374c\u003c/code\u003e\u003c/a\u003e Bump org.fusesource.jansi:jansi from 2.4.2 to 2.4.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/dadd55b7a6a3a0336c253413f68c4f08092328c2\"\u003e\u003ccode\u003edadd55b\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/2613\"\u003e#2613\u003c/a\u003e Debugging failsafe tests: Message 'Listening for transport dt_soc...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/39dd250a44f1f2f1f18ea1881d78ac341222ea97\"\u003e\u003ccode\u003e39dd250\u003c/code\u003e\u003c/a\u003e Bump commons-io:commons-io from 2.21.0 to 2.22.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/27742739c8cc6e4676611ac4bfe42870f74fd0f3\"\u003e\u003ccode\u003e2774273\u003c/code\u003e\u003c/a\u003e Ensure that the statistics filename is calculated only once. (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3326\"\u003e#3326\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3327\"\u003e#3327\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/0d5df8a3b4606622a67922405488d4b182409893\"\u003e\u003ccode\u003e0d5df8a\u003c/code\u003e\u003c/a\u003e 3.5.x/bug/cherry pick embedded mode its (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3328\"\u003e#3328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/04ad9a293f5cee5e95c5cd5a2e751723be66deff\"\u003e\u003ccode\u003e04ad9a2\u003c/code\u003e\u003c/a\u003e Use surefire 3.5.5 by project itself for testing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/37e8f694c18ca664a8e45e934a43d4870e799c45\"\u003e\u003ccode\u003e37e8f69\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003eflakes\u003c/code\u003e attribute to use in \u003ccode\u003etestsuite\u003c/code\u003e report (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3306\"\u003e#3306\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3308\"\u003e#3308\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/a970fefe4dbc173acacf79389d812f91f6ef027a\"\u003e\u003ccode\u003ea970fef\u003c/code\u003e\u003c/a\u003e Introduce reportTestTimestamp option and include timestamp for test sets and ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/e838393bbb127a7798d13283b9af7cfa0afec3a8\"\u003e\u003ccode\u003ee838393\u003c/code\u003e\u003c/a\u003e deploy 3.5.x branch to nexus\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/apache/maven-surefire/compare/surefire-3.5.5...surefire-3.5.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.maven.plugins:maven-failsafe-plugin` from 3.5.5 to 3.5.6\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/apache/maven-surefire/releases\"\u003eorg.apache.maven.plugins:maven-failsafe-plugin's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.5.6\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e🚀 New features and improvements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIntroduce reportTestTimestamp option and include timestamp for test sets and test cases (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3261\"\u003e#3261\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3302\"\u003e#3302\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIssue \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/2613\"\u003e#2613\u003c/a\u003e Debugging failsafe tests: Message 'Listening for transport dt_socket at address' is not displayed anymore when using maven.surefire.debug (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3353\"\u003e#3353\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3354\"\u003e#3354\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEnsure that the statistics filename is calculated only once. (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3326\"\u003e#3326\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3327\"\u003e#3327\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003eflakes\u003c/code\u003e attribute to use in \u003ccode\u003etestsuite\u003c/code\u003e report (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3306\"\u003e#3306\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3308\"\u003e#3308\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[BACKPORT 3.5.x] \u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-2049\"\u003e[SUREFIRE-2049]\u003c/a\u003e - Fix SHUTDOWN type lost during command serialization. (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3270\"\u003e#3270\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3289\"\u003e#3289\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: null guard for context map (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3269\"\u003e#3269\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3272\"\u003e#3272\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e👻 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e3.5.x/bug/cherry pick embedded mode its (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3328\"\u003e#3328\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse surefire 3.5.5 by project itself for testing (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3324\"\u003e#3324\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFollow Oracle javadoc guidelines (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3177\"\u003e#3177\u003c/a\u003e) \u003ca href=\"https://github.com/elharo\"\u003e\u003ccode\u003e@​elharo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📦 Dependency updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump org.fusesource.jansi:jansi from 2.4.2 to 2.4.3 (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3334\"\u003e#3334\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump commons-io:commons-io from 2.21.0 to 2.22.0 (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3350\"\u003e#3350\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/25ea054860a5c1e5932b360d8aa0a31944c2b841\"\u003e\u003ccode\u003e25ea054\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release surefire-3.5.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/e5f374ccdefd5b40d75e0072a754708183d9ec5e\"\u003e\u003ccode\u003ee5f374c\u003c/code\u003e\u003c/a\u003e Bump org.fusesource.jansi:jansi from 2.4.2 to 2.4.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/dadd55b7a6a3a0336c253413f68c4f08092328c2\"\u003e\u003ccode\u003edadd55b\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/2613\"\u003e#2613\u003c/a\u003e Debugging failsafe tests: Message 'Listening for transport dt_soc...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/39dd250a44f1f2f1f18ea1881d78ac341222ea97\"\u003e\u003ccode\u003e39dd250\u003c/code\u003e\u003c/a\u003e Bump commons-io:commons-io from 2.21.0 to 2.22.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/27742739c8cc6e4676611ac4bfe42870f74fd0f3\"\u003e\u003ccode\u003e2774273\u003c/code\u003e\u003c/a\u003e Ensure that the statistics filename is calculated only once. (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3326\"\u003e#3326\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3327\"\u003e#3327\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/0d5df8a3b4606622a67922405488d4b182409893\"\u003e\u003ccode\u003e0d5df8a\u003c/code\u003e\u003c/a\u003e 3.5.x/bug/cherry pick embedded mode its (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3328\"\u003e#3328\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/04ad9a293f5cee5e95c5cd5a2e751723be66deff\"\u003e\u003ccode\u003e04ad9a2\u003c/code\u003e\u003c/a\u003e Use surefire 3.5.5 by project itself for testing\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/37e8f694c18ca664a8e45e934a43d4870e799c45\"\u003e\u003ccode\u003e37e8f69\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003eflakes\u003c/code\u003e attribute to use in \u003ccode\u003etestsuite\u003c/code\u003e report (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3306\"\u003e#3306\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3308\"\u003e#3308\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/a970fefe4dbc173acacf79389d812f91f6ef027a\"\u003e\u003ccode\u003ea970fef\u003c/code\u003e\u003c/a\u003e Introduce reportTestTimestamp option and include timestamp for test sets and ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/e838393bbb127a7798d13283b9af7cfa0afec3a8\"\u003e\u003ccode\u003ee838393\u003c/code\u003e\u003c/a\u003e deploy 3.5.x branch to nexus\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/apache/maven-surefire/compare/surefire-3.5.5...surefire-3.5.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.sonarsource.scanner.maven:sonar-maven-plugin` from 5.6.0.6792 to 5.7.0.6970\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/SonarSource/sonar-scanner-maven/releases\"\u003eorg.sonarsource.scanner.maven:sonar-maven-plugin's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e5.7.0.6970\u003c/h2\u003e\n\u003ch1\u003eRelease notes - Sonar Scanner for Maven - 5.7\u003c/h1\u003e\n\u003ch3\u003eFeature\u003c/h3\u003e\n\u003cp\u003e\u003ca href=\"https://sonarsource.atlassian.net/browse/SCANMAVEN-317\"\u003eSCANMAVEN-317\u003c/a\u003e Support encryption of sonar.token, and other new secure properties\n\u003ca href=\"https://sonarsource.atlassian.net/browse/SCANMAVEN-332\"\u003eSCANMAVEN-332\u003c/a\u003e support \u003ccode\u003emodular-jar\u003c/code\u003e artifact type\n\u003ca href=\"https://sonarsource.atlassian.net/browse/SCANMAVEN-341\"\u003eSCANMAVEN-341\u003c/a\u003e Rework the support of encrypted properties\u003c/p\u003e\n\u003ch3\u003eMaintenance\u003c/h3\u003e\n\u003cp\u003e\u003ca href=\"https://sonarsource.atlassian.net/browse/SCANMAVEN-370\"\u003eSCANMAVEN-370\u003c/a\u003e Prepare next development iteration 5.7.0\n\u003ca href=\"https://sonarsource.atlassian.net/browse/SCANMAVEN-372\"\u003eSCANMAVEN-372\u003c/a\u003e Configure Renovate for sonar-scanner-maven\n\u003ca href=\"https://sonarsource.atlassian.net/browse/SCANMAVEN-373\"\u003eSCANMAVEN-373\u003c/a\u003e SubmitReview: Use Vault token\n\u003ca href=\"https://sonarsource.atlassian.net/browse/SCANMAVEN-374\"\u003eSCANMAVEN-374\u003c/a\u003e Unpin internal GitHub actions\n\u003ca href=\"https://sonarsource.atlassian.net/browse/SCANMAVEN-376\"\u003eSCANMAVEN-376\u003c/a\u003e Use SonarSource/.../sonar-update-center-release@v1 instead of \u003ca href=\"https://github.com/master\"\u003e\u003ccode\u003e@​master\u003c/code\u003e\u003c/a\u003e\n\u003ca href=\"https://sonarsource.atlassian.net/browse/SCANMAVEN-377\"\u003eSCANMAVEN-377\u003c/a\u003e Update dependency org.assertj:assertj-core to v3.27.7 [SECURITY]\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SonarSource/sonar-scanner-maven/commit/9e114d74155442c40a927a7491718dde472b43fc\"\u003e\u003ccode\u003e9e114d7\u003c/code\u003e\u003c/a\u003e SCANMAVEN-332 Support modular-jar (\u003ca href=\"https://redirect.github.com/SonarSource/sonar-scanner-maven/issues/402\"\u003e#402\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SonarSource/sonar-scanner-maven/commit/7424fe56eeaabf1d9abd4d43bec6eff694c18c55\"\u003e\u003ccode\u003e7424fe5\u003c/code\u003e\u003c/a\u003e SCANMAVEN-317 - Support encryption of sonar.token, and other new secure prope...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SonarSource/sonar-scanner-maven/commit/b8ff39f9c72f56cac1e302ac8ec9854b5a8f25cd\"\u003e\u003ccode\u003eb8ff39f\u003c/code\u003e\u003c/a\u003e SCANMAVEN-341 Fix regex for encrypted property filtering for mvn4 and add tes...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SonarSource/sonar-scanner-maven/commit/b4c0b4ae8638e87874786fdf055e8ac904eadeab\"\u003e\u003ccode\u003eb4c0b4a\u003c/code\u003e\u003c/a\u003e SCANMAVEN-377 Update dependency org.assertj:assertj-core to v3.27.7 [SECURITY...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SonarSource/sonar-scanner-maven/commit/cd195065d088e8fade81b59c3c78068dc393a291\"\u003e\u003ccode\u003ecd19506\u003c/code\u003e\u003c/a\u003e SCANMAVEN-372 Configure Renovate (\u003ca href=\"https://redirect.github.com/SonarSource/sonar-scanner-maven/issues/393\"\u003e#393\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SonarSource/sonar-scanner-maven/commit/944f55249fb64c3fa7bf2258974ca281375af257\"\u003e\u003ccode\u003e944f552\u003c/code\u003e\u003c/a\u003e SCANMAVEN-376 Use SonarSource/.../sonar-update-center-release@v1 instead of @...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SonarSource/sonar-scanner-maven/commit/2832b8a069e8e9ac83ece6b0111f723f653dbda2\"\u003e\u003ccode\u003e2832b8a\u003c/code\u003e\u003c/a\u003e SCANMAVEN-374 Unpin internal GitHub actions (\u003ca href=\"https://redirect.github.com/SonarSource/sonar-scanner-maven/issues/396\"\u003e#396\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SonarSource/sonar-scanner-maven/commit/81caeeb11b25dd0ca8aafc0aefc46390350d3e9e\"\u003e\u003ccode\u003e81caeeb\u003c/code\u003e\u003c/a\u003e SCANMAVEN-373 SubmitReview: Use Vault token (\u003ca href=\"https://redirect.github.com/SonarSource/sonar-scanner-maven/issues/395\"\u003e#395\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/SonarSource/sonar-scanner-maven/commit/c62dd7423fb4b2b7dffe457849e51c38dcc779cc\"\u003e\u003ccode\u003ec62dd74\u003c/code\u003e\u003c/a\u003e SCANMAVEN-370 Prepare next development iteration 5.7.0 (\u003ca href=\"https://redirect.github.com/SonarSource/sonar-scanner-maven/issues/392\"\u003e#392\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/SonarSource/sonar-scanner-maven/compare/5.6.0.6792...5.7.0.6970\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/Pololac/PowerMe/pull/104","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Pololac%2FPowerMe/issues/104","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/104/packages"}},{"old_version":"1.5.32","new_version":"1.5.33","update_type":"patch","path":null,"pr_created_at":"2026-05-30T01:03:05.000Z","version_change":"1.5.32 → 1.5.33","issue":{"uuid":"4552613454","node_id":"PR_kwDOAB81F87g2zOl","number":15211,"state":"closed","title":"[12.1.x EE11] Bump the dev-dependencies group across 1 directory with 14 updates","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-06-06T00:11:37.000Z","author_association":null,"state_reason":null,"created_at":"2026-05-30T01:03:05.000Z","updated_at":"2026-06-06T00:11:39.000Z","time_to_close":601712,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"[12.1.x EE11] Bump","group_name":"dev-dependencies","update_count":14,"packages":[{"name":"org.ow2.asm:asm","old_version":"9.10","new_version":"9.10.1"},{"name":"org.ow2.asm:asm-commons","old_version":"9.10","new_version":"9.10.1"},{"name":"org.ow2.asm:asm-bom","old_version":"9.10","new_version":"9.10.1"},{"name":"org.apache.maven.surefire:surefire-junit47","old_version":"3.5.5","new_version":"3.5.6"},{"name":"com.fasterxml.jackson:jackson-bom","old_version":"2.21.3","new_version":"2.21.4","repository_url":"https://github.com/FasterXML/jackson-bom"},{"name":"io.netty:netty-bom","old_version":"4.2.13.Final","new_version":"4.2.14.Final","repository_url":"https://github.com/netty/netty"},{"name":"org.hibernate.search:hibernate-search-bom","old_version":"8.3.1.Final","new_version":"8.4.0.Final","repository_url":"https://github.com/hibernate/hibernate-search"},{"name":"org.junit:junit-bom","old_version":"6.0.3","new_version":"6.1.0","repository_url":"https://github.com/junit-team/junit-framework"},{"name":"ch.qos.logback:logback-core","old_version":"1.5.32","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"},{"name":"org.codehaus.plexus:plexus-classworlds","old_version":"2.11.0","new_version":"2.12.0","repository_url":"https://github.com/codehaus-plexus/plexus-classworlds"},{"name":"eu.maveniverse.maven.njord:extension3","old_version":"0.9.6","new_version":"0.9.7","repository_url":"https://github.com/maveniverse/njord"},{"name":"eu.maveniverse.maven.plugins:njord","old_version":"0.9.6","new_version":"0.9.7","repository_url":"https://github.com/maveniverse/njord"},{"name":"org.apache.maven.extensions:maven-build-cache-extension","old_version":"1.2.2","new_version":"1.2.3","repository_url":"https://github.com/apache/maven-build-cache-extension"}],"path":null,"ecosystem":"maven"},"body":"Bumps the dev-dependencies group with 13 updates in the /jetty-ee11 directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| org.ow2.asm:asm | `9.10` | `9.10.1` |\n| org.ow2.asm:asm-commons | `9.10` | `9.10.1` |\n| org.ow2.asm:asm-bom | `9.10` | `9.10.1` |\n| org.apache.maven.surefire:surefire-junit47 | `3.5.5` | `3.5.6` |\n| [com.fasterxml.jackson:jackson-bom](https://github.com/FasterXML/jackson-bom) | `2.21.3` | `2.21.4` |\n| [io.netty:netty-bom](https://github.com/netty/netty) | `4.2.13.Final` | `4.2.14.Final` |\n| [org.hibernate.search:hibernate-search-bom](https://github.com/hibernate/hibernate-search) | `8.3.1.Final` | `8.4.0.Final` |\n| [org.junit:junit-bom](https://github.com/junit-team/junit-framework) | `6.0.3` | `6.1.0` |\n| [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) | `1.5.32` | `1.5.33` |\n| [org.codehaus.plexus:plexus-classworlds](https://github.com/codehaus-plexus/plexus-classworlds) | `2.11.0` | `2.12.0` |\n| [eu.maveniverse.maven.njord:extension3](https://github.com/maveniverse/njord) | `0.9.6` | `0.9.7` |\n| [eu.maveniverse.maven.plugins:njord](https://github.com/maveniverse/njord) | `0.9.6` | `0.9.7` |\n| [org.apache.maven.extensions:maven-build-cache-extension](https://github.com/apache/maven-build-cache-extension) | `1.2.2` | `1.2.3` |\n\n\nUpdates `org.ow2.asm:asm` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-commons` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-bom` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-commons` from 9.10 to 9.10.1\n\nUpdates `org.apache.maven.surefire:surefire-junit47` from 3.5.5 to 3.5.6\n\nUpdates `com.fasterxml.jackson:jackson-bom` from 2.21.3 to 2.21.4\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-bom/commit/d1abd31e4fec3035965d57a05a6256171ea8d980\"\u003e\u003ccode\u003ed1abd31\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-bom-2.21.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-bom/commit/2aaea43db8480aa7d405ebc0de503cffc864f6f6\"\u003e\u003ccode\u003e2aaea43\u003c/code\u003e\u003c/a\u003e Prep for 2.21.4 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-bom/commit/9d3a9d54e40312ef0ac9192d599b59b541f65fb8\"\u003e\u003ccode\u003e9d3a9d5\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-bom/commit/84bcf7f5b268bc2b47a92bd08391f75e9d956793\"\u003e\u003ccode\u003e84bcf7f\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/FasterXML/jackson-bom/compare/jackson-bom-2.21.3...jackson-bom-2.21.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `io.netty:netty-bom` from 4.2.13.Final to 4.2.14.Final\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/netty/netty/releases\"\u003eio.netty:netty-bom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003enetty-4.2.14.Final\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHTTP: Fix revapi failure introduced by 84530fa81e12dcd1d42310bb20c1385cb44128d8 by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16748\"\u003enetty/netty#16748\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHTTP: Re-add constructor to HttpProxyHandler that was removed by mistake by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16747\"\u003enetty/netty#16747\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMarshalling: Explicit document security requirements by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16752\"\u003enetty/netty#16752\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix io_uring op completion TRACE logging by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16755\"\u003enetty/netty#16755\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eQuic: Ensure writes are done before notify close promise of QuicheQui… by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16758\"\u003enetty/netty#16758\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid re-parsing openssl key material with non-cached provider by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16759\"\u003enetty/netty#16759\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin HTTP/RTSP version + method normalization to Locale.US by \u003ca href=\"https://github.com/daguimu\"\u003e\u003ccode\u003e@​daguimu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16765\"\u003enetty/netty#16765\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFill MsgHdrMemoryArray#hdrs with null entry on release by \u003ca href=\"https://github.com/tsegismont\"\u003e\u003ccode\u003e@​tsegismont\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16764\"\u003enetty/netty#16764\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRevapi: Use default \u0026quot;oldVersion\u0026quot; by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16774\"\u003enetty/netty#16774\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdaptive: Fix concurrency issue in adaptive allocator by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16767\"\u003enetty/netty#16767\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAuto-port 4.2: Make bulk byte moving in ByteBuf faster by \u003ca href=\"https://github.com/netty-project-bot\"\u003e\u003ccode\u003e@​netty-project-bot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16781\"\u003enetty/netty#16781\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin multipart Content-Type / Content-Transfer-Encoding case folding to Locale.US by \u003ca href=\"https://github.com/daguimu\"\u003e\u003ccode\u003e@​daguimu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16768\"\u003enetty/netty#16768\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove dead native declarations by \u003ca href=\"https://github.com/pandareen\"\u003e\u003ccode\u003e@​pandareen\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16783\"\u003enetty/netty#16783\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIsolate tests that modify available Security providers by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16793\"\u003enetty/netty#16793\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove test annotations from a method that isn't a test by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16792\"\u003enetty/netty#16792\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEnable OpenSslCachingKeyMaterialProvider to evict stale entries after cert rotation by \u003ca href=\"https://github.com/zhangweikop\"\u003e\u003ccode\u003e@​zhangweikop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16523\"\u003enetty/netty#16523\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIoUring: extend user data from short to long by \u003ca href=\"https://github.com/dreamlike-ocean\"\u003e\u003ccode\u003e@​dreamlike-ocean\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16682\"\u003enetty/netty#16682\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRevert CompositeByteBuf component search fast path by \u003ca href=\"https://github.com/yawkat\"\u003e\u003ccode\u003e@​yawkat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16811\"\u003enetty/netty#16811\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHTTP2: Use 100 as default max concurrent streams setting by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16804\"\u003enetty/netty#16804\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix ResumptionController wrapping by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16815\"\u003enetty/netty#16815\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eResolve all localhost addresses without querying DNS servers by \u003ca href=\"https://github.com/JulianVennen\"\u003e\u003ccode\u003e@​JulianVennen\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16749\"\u003enetty/netty#16749\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIpFilter: Fix ClassCastException caused by IpSubnetFilter if only ipv6 rules are configured but remote peer is using ipv4 by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16803\"\u003enetty/netty#16803\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix memoryAddress() for direct ByteBuffers wrapped by Unpooled without Unsafe by \u003ca href=\"https://github.com/dreamlike-ocean\"\u003e\u003ccode\u003e@​dreamlike-ocean\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16788\"\u003enetty/netty#16788\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRoute synchronous onLookupComplete exceptions via fireExceptionCaught by \u003ca href=\"https://github.com/kwondh5217\"\u003e\u003ccode\u003e@​kwondh5217\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16794\"\u003enetty/netty#16794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIoUring: Stop generic FileRegion drain loop when transferred() reaches count() by \u003ca href=\"https://github.com/LuciferYang\"\u003e\u003ccode\u003e@​LuciferYang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16826\"\u003enetty/netty#16826\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMQTT: Allow MQTT 5 CONNECT with password only by \u003ca href=\"https://github.com/shblue21\"\u003e\u003ccode\u003e@​shblue21\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16833\"\u003enetty/netty#16833\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix MQTT decoder size check after variable header replay by \u003ca href=\"https://github.com/daguimu\"\u003e\u003ccode\u003e@​daguimu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16787\"\u003enetty/netty#16787\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pandareen\"\u003e\u003ccode\u003e@​pandareen\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16783\"\u003enetty/netty#16783\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zhangweikop\"\u003e\u003ccode\u003e@​zhangweikop\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16523\"\u003enetty/netty#16523\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JulianVennen\"\u003e\u003ccode\u003e@​JulianVennen\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16749\"\u003enetty/netty#16749\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kwondh5217\"\u003e\u003ccode\u003e@​kwondh5217\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16794\"\u003enetty/netty#16794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/shblue21\"\u003e\u003ccode\u003e@​shblue21\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16833\"\u003enetty/netty#16833\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/netty/netty/compare/netty-4.2.13.Final...netty-4.2.14.Final\"\u003ehttps://github.com/netty/netty/compare/netty-4.2.13.Final...netty-4.2.14.Final\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/0a60b753d5b0de9f58e245538d61c11dc6cfc4b2\"\u003e\u003ccode\u003e0a60b75\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release netty-4.2.14.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/72df658e5fdd1cc6d65bce1e0917ec31a9560269\"\u003e\u003ccode\u003e72df658\u003c/code\u003e\u003c/a\u003e Fix MQTT decoder size check after variable header replay (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16787\"\u003e#16787\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/7125dba6b20822aa72dd8359b350c2f3b9a545d9\"\u003e\u003ccode\u003e7125dba\u003c/code\u003e\u003c/a\u003e MQTT: Allow MQTT 5 CONNECT with password only (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16833\"\u003e#16833\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/9e19320a5855746970d05a5cd785d73a17cc694d\"\u003e\u003ccode\u003e9e19320\u003c/code\u003e\u003c/a\u003e IoUring: Stop generic FileRegion drain loop when transferred() reaches count(...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/4ce9f17f05c67b72c87bc83951800bad245fe162\"\u003e\u003ccode\u003e4ce9f17\u003c/code\u003e\u003c/a\u003e Route synchronous onLookupComplete exceptions via fireExceptionCaught (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16794\"\u003e#16794\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/f7b1b7de625031cc60e6eaecb889c97303588759\"\u003e\u003ccode\u003ef7b1b7d\u003c/code\u003e\u003c/a\u003e Fix memoryAddress() for direct ByteBuffers wrapped by Unpooled without Unsafe...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/0ccb265cadf91b2e09c2f479c9194d193d7a5dbc\"\u003e\u003ccode\u003e0ccb265\u003c/code\u003e\u003c/a\u003e IpFilter: Fix ClassCastException caused by IpSubnetFilter if only ipv6 rules ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/a6aeb6deffda3e45904edd05abc5cdddcd438794\"\u003e\u003ccode\u003ea6aeb6d\u003c/code\u003e\u003c/a\u003e Resolve all localhost addresses without querying DNS servers (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16749\"\u003e#16749\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/c328ba2ab89d2c90c80be1d2de1cfbb8f94c438b\"\u003e\u003ccode\u003ec328ba2\u003c/code\u003e\u003c/a\u003e Fix ResumptionController wrapping (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16815\"\u003e#16815\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/bc5862ba488c569c888d3b82048083041f66e880\"\u003e\u003ccode\u003ebc5862b\u003c/code\u003e\u003c/a\u003e HTTP2: Use 100 as default max concurrent streams setting (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16804\"\u003e#16804\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/netty/netty/compare/netty-4.2.13.Final...netty-4.2.14.Final\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.hibernate.search:hibernate-search-bom` from 8.3.1.Final to 8.4.0.Final\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hibernate/hibernate-search/releases\"\u003eorg.hibernate.search:hibernate-search-bom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 8.4.0.Final\u003c/h2\u003e\n\u003ch1\u003eHibernate Search 8.4.0.Final released\u003c/h1\u003e\n\u003cp\u003eWe are pleased to announce the release of Hibernate Search 8.4: 8.4.0.Final.\u003c/p\u003e\n\u003cp\u003eYou can find the full list of 8.4.0.Final changes \u003ca href=\"https://hibernate.atlassian.net/issues/?jql=project%20%3D%20HSEARCH%20AND%20fixVersion%20%3D%208.4.0.Final\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eWhat's new\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSee the \u003ca href=\"https://hibernate.org/search/releases/8.4\"\u003ewebsite\u003c/a\u003e for requirements and compatibilities.\u003c/li\u003e\n\u003cli\u003eSee the \u003ca href=\"https://docs.hibernate.org/search/8.4/whats-new/en-US/html_single/\"\u003eWhat's New\u003c/a\u003e guide for details about new features and capabilities.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eConclusion\u003c/h2\u003e\n\u003cp\u003eFor additional details, see:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe \u003ca href=\"https://hibernate.org/search/releases/8.4/\"\u003erelease page\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/migration/html_single/\"\u003eMigration Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/getting-started/orm/en-US/html_single/\"\u003eORM Getting Started Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/getting-started/standalone/en-US/html_single/\"\u003eStandalone Getting Started Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/reference/en-US/html_single/\"\u003eReference Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/api\"\u003eAPI docs\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eVisit the \u003ca href=\"https://hibernate.org/community/\"\u003ewebsite\u003c/a\u003e for details on getting in touch with us.\u003c/p\u003e\n\u003ch2\u003eRelease 8.4.0.CR1\u003c/h2\u003e\n\u003ch1\u003eHibernate Search 8.4.0.CR1 released\u003c/h1\u003e\n\u003cp\u003eWe are pleased to announce the release of Hibernate Search 8.4: 8.4.0.CR1.\u003c/p\u003e\n\u003cp\u003eYou can find the full list of 8.4.0.CR1 changes \u003ca href=\"https://hibernate.atlassian.net/issues/?jql=project%20%3D%20HSEARCH%20AND%20fixVersion%20%3D%208.4.0.CR1\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eWhat's new\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSee the \u003ca href=\"https://hibernate.org/search/releases/8.4\"\u003ewebsite\u003c/a\u003e for requirements and compatibilities.\u003c/li\u003e\n\u003cli\u003eSee the \u003ca href=\"https://docs.hibernate.org/search/8.4/whats-new/en-US/html_single/\"\u003eWhat's New\u003c/a\u003e guide for details about new features and capabilities.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eConclusion\u003c/h2\u003e\n\u003cp\u003eFor additional details, see:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe \u003ca href=\"https://hibernate.org/search/releases/8.4/\"\u003erelease page\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/migration/html_single/\"\u003eMigration Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/getting-started/orm/en-US/html_single/\"\u003eORM Getting Started Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/getting-started/standalone/en-US/html_single/\"\u003eStandalone Getting Started Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/reference/en-US/html_single/\"\u003eReference Guide\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hibernate/hibernate-search/blob/main/changelog.txt\"\u003eorg.hibernate.search:hibernate-search-bom's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.4.0.Final (2026-05-27)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://hibernate.atlassian.net/projects/HSEARCH/versions/39072\"\u003ehttps://hibernate.atlassian.net/projects/HSEARCH/versions/39072\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e** Improvement\n* HSEARCH-5630 Update to Hibernate ORM 7.4.0.Final\n* HSEARCH-5629 Use Maven 3.9.16 as a required minimum version for the build\n* HSEARCH-5627 Switch from the Search session holder to a Hibernate ORM session extension\n* HSEARCH-5626 Update Elasticsearch client (elasticsearch-rest-client) to 9.4.1\n* HSEARCH-5625 Test against latest Elasticsearch 9.4.1\n* HSEARCH-5624 Update Elasticsearch client (elasticsearch-rest5-client) to 9.4.1\u003c/p\u003e\n\u003ch2\u003e8.4.0.CR1 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://hibernate.atlassian.net/projects/HSEARCH/versions/37437\"\u003ehttps://hibernate.atlassian.net/projects/HSEARCH/versions/37437\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e** Bug\n* HSEARCH-5595 \u003ccode\u003echeckstyle:check\u003c/code\u003e is not build cache relocatable due to project resources including the workspace root\u003c/p\u003e\n\u003cp\u003e** Improvement\n* HSEARCH-5623 Update to Hibernate ORM 7.4.0.CR1\n* HSEARCH-5622 Update Elasticsearch client (elasticsearch-rest5-client) to 9.4.0\n* HSEARCH-5621 Update Elasticsearch client (elasticsearch-rest-client) to 9.4.0\n* HSEARCH-5620 Add compatibility with Elasticsearch 9.4\n* HSEARCH-5619 Upgrade to GSON 2.14.0\n* HSEARCH-5618 Update Jackson to 2.21.3\n* HSEARCH-5617 Update to AWS SDK 2.44.1\n* HSEARCH-5616 Update Elasticsearch client (elasticsearch-rest-client) to 9.3.4\n* HSEARCH-5613 Use Maven 3.9.15 as a required minimum version for the build\n* HSEARCH-5612 Upgrade to commons-codec 1.22.0\n* HSEARCH-5611 Update Apache HTTP Client components to 5.6.1\n* HSEARCH-5609 Update Elasticsearch client (elasticsearch-rest-client) to 9.3.3\n* HSEARCH-5608 Update Elasticsearch client (elasticsearch-rest5-client) to 9.3.4\n* HSEARCH-5607 Update Elasticsearch rest client (opensearch-rest-client) to 3.6.0\n* HSEARCH-5606 Add compatibility with OpenSearch 3.6\n* HSEARCH-5601 Update to commons-logging to 1.3.6\n* HSEARCH-5600 Update Jackson to 2.21.2\n* HSEARCH-5599 Update Apache HTTP Core client components to 5.4.2\n* HSEARCH-5598 Update Elasticsearch client (elasticsearch-rest-client) to 9.3.2\n* HSEARCH-5597 Update Elasticsearch client (elasticsearch-rest5-client) to 9.3.3\u003c/p\u003e\n\u003cp\u003e** Task\n* HSEARCH-5596 Use changeDetection config option instead of the deprecated overwrite in maven-resources-plugin\n* HSEARCH-5280 Look into \u003ccode\u003eOutboxPollingAutomaticIndexingDynamicShardingRebalancingIT#agentJoined\u003c/code\u003e test\n* HSEARCH-5242 Investigate why building hibernate-search-integrationtest-performance-backend-lucene fails on some envs\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/7369a18fc526aaffba13336fdcdc95a333702b19\"\u003e\u003ccode\u003e7369a18\u003c/code\u003e\u003c/a\u003e [Jenkins release job] Preparing release 8.4.0.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/4e26c085ba83c21cde89022a2f10864b08711e25\"\u003e\u003ccode\u003e4e26c08\u003c/code\u003e\u003c/a\u003e [Jenkins release job] changelog.txt updated by release build 8.4.0.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/fe410d2d5c25d9e05648f67c027441564a32be03\"\u003e\u003ccode\u003efe410d2\u003c/code\u003e\u003c/a\u003e HSEARCH-5630 Add a few migration notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/87335b65fd124493bf91ad83de78f64eafc1155c\"\u003e\u003ccode\u003e87335b6\u003c/code\u003e\u003c/a\u003e HSEARCH-5630 Update to Hibernate ORM 7.4.0.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/58d6af143d22c9ce55872c9f13c51c8dd8e03d32\"\u003e\u003ccode\u003e58d6af1\u003c/code\u003e\u003c/a\u003e HSEARCH-5624 Update Elasticsearch client (elasticsearch-rest5-client) to 9.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/9efe369fcb419ded47b3e77a02b3d84451e64853\"\u003e\u003ccode\u003e9efe369\u003c/code\u003e\u003c/a\u003e Bump the build-dependencies group with 4 updates\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/bc1c18509b22d2b1fa9e41149fbe5cf166d7f663\"\u003e\u003ccode\u003ebc1c185\u003c/code\u003e\u003c/a\u003e Use the ssh URL for updating the website during the release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/311adb00224ab04fc2c397da94cf41a373338801\"\u003e\u003ccode\u003e311adb0\u003c/code\u003e\u003c/a\u003e HSEARCH-5627 Mention limitations of a StatelessSession\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/d429b05110cf6015d70faa6278176c6b3e7defa0\"\u003e\u003ccode\u003ed429b05\u003c/code\u003e\u003c/a\u003e HSEARCH-5627 Better error message for \u0026quot;incompatible\u0026quot; session types\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/2eaeb282d9d9bc136bc32f93ca12634374e249d4\"\u003e\u003ccode\u003e2eaeb28\u003c/code\u003e\u003c/a\u003e HSEARCH-5627 Add a simple StatelessSession test\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hibernate/hibernate-search/compare/8.3.1.Final...8.4.0.Final\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.junit:junit-bom` from 6.0.3 to 6.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/junit-team/junit-framework/releases\"\u003eorg.junit:junit-bom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eJUnit 6.1.0 = Platform 6.1.0 + Jupiter 6.1.0 + Vintage 6.1.0\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0/release-notes.html\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JarvisCraft\"\u003e\u003ccode\u003e@​JarvisCraft\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5633\"\u003ejunit-team/junit-framework#5633\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Maran23\"\u003e\u003ccode\u003e@​Maran23\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5644\"\u003ejunit-team/junit-framework#5644\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eJUnit 6.1.0-RC1 = Platform 6.1.0-RC1 + Jupiter 6.1.0-RC1 + Vintage 6.1.0-RC1\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0-RC1/release-notes/\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mariokhoury4\"\u003e\u003ccode\u003e@​mariokhoury4\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/4574\"\u003ejunit-team/junit-framework#4574\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Ogu1208\"\u003e\u003ccode\u003e@​Ogu1208\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5145\"\u003ejunit-team/junit-framework#5145\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/HyungGeun94\"\u003e\u003ccode\u003e@​HyungGeun94\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5271\"\u003ejunit-team/junit-framework#5271\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yalishevant\"\u003e\u003ccode\u003e@​yalishevant\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5316\"\u003ejunit-team/junit-framework#5316\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JINU-CHANG\"\u003e\u003ccode\u003e@​JINU-CHANG\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5290\"\u003ejunit-team/junit-framework#5290\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jaschdoc\"\u003e\u003ccode\u003e@​jaschdoc\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5427\"\u003ejunit-team/junit-framework#5427\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kawshikbuet17\"\u003e\u003ccode\u003e@​kawshikbuet17\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5561\"\u003ejunit-team/junit-framework#5561\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/msridhar\"\u003e\u003ccode\u003e@​msridhar\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5602\"\u003ejunit-team/junit-framework#5602\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.1.0-M1...r6.1.0-RC1\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.1.0-M1...r6.1.0-RC1\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eJUnit 6.1.0-M1 = Platform 6.1.0-M1 + Jupiter 6.1.0-M1 + Vintage 6.1.0-M1\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0-M1/release-notes/\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vy\"\u003e\u003ccode\u003e@​vy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5041\"\u003ejunit-team/junit-framework#5041\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Pankraz76\"\u003e\u003ccode\u003e@​Pankraz76\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5006\"\u003ejunit-team/junit-framework#5006\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/arukiidou\"\u003e\u003ccode\u003e@​arukiidou\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5066\"\u003ejunit-team/junit-framework#5066\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/laeubi\"\u003e\u003ccode\u003e@​laeubi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5092\"\u003ejunit-team/junit-framework#5092\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jihun4452\"\u003e\u003ccode\u003e@​jihun4452\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5088\"\u003ejunit-team/junit-framework#5088\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TWiStErRob\"\u003e\u003ccode\u003e@​TWiStErRob\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5133\"\u003ejunit-team/junit-framework#5133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.0...r6.1.0-M1\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.0.0...r6.1.0-M1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0dc3af1cb1973d257b5bc75d81e02454d5e4e556\"\u003e\u003ccode\u003e0dc3af1\u003c/code\u003e\u003c/a\u003e Release 6.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/1d130020c85170edcb46ce7ed1f7f78824e37c04\"\u003e\u003ccode\u003e1d13002\u003c/code\u003e\u003c/a\u003e Prepare 6.1.0 release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/072b2175bbd7b0b3b26f5d928550ec7a21e68268\"\u003e\u003ccode\u003e072b217\u003c/code\u003e\u003c/a\u003e Update plugin spotless to v8.5.0 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5668\"\u003e#5668\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/3a53480218f4b752a9ca77506e10632cd483c0f8\"\u003e\u003ccode\u003e3a53480\u003c/code\u003e\u003c/a\u003e Update Gradle to v9.5.1 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5666\"\u003e#5666\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0e18a20a9f98d063ae02b3ba19329143f5c7f034\"\u003e\u003ccode\u003e0e18a20\u003c/code\u003e\u003c/a\u003e Update zizmorcore/zizmor-action action to v0.5.4 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5669\"\u003e#5669\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0a2634fb9cbbd057b02cf629d7d272c16d62be4b\"\u003e\u003ccode\u003e0a2634f\u003c/code\u003e\u003c/a\u003e Update github/codeql-action action to v4.35.5 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5671\"\u003e#5671\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/4dbd5561b00ac761a62c516bfaec51c212a2d60c\"\u003e\u003ccode\u003e4dbd556\u003c/code\u003e\u003c/a\u003e Restructure workflows to have single \u0026quot;status\u0026quot; job (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5670\"\u003e#5670\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/f2194cebe377512cb0ade388c62a881a0bcf5d3e\"\u003e\u003ccode\u003ef2194ce\u003c/code\u003e\u003c/a\u003e Increase timeout to reduce flakiness\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/5c8fdd2df65b763151cccbe669ea9e1c3155efcd\"\u003e\u003ccode\u003e5c8fdd2\u003c/code\u003e\u003c/a\u003e Update dependency org.apache.groovy:groovy to v5.0.6 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5659\"\u003e#5659\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/43c6982324602582902c9bdb213fd5e007f9cf3d\"\u003e\u003ccode\u003e43c6982\u003c/code\u003e\u003c/a\u003e Update dependency org.slf4j:slf4j-jdk14 to v2.0.18 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5667\"\u003e#5667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.ow2.asm:asm-bom` from 9.10 to 9.10.1\n\nUpdates `ch.qos.logback:logback-core` from 1.5.32 to 1.5.33\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.codehaus.plexus:plexus-classworlds` from 2.11.0 to 2.12.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/releases\"\u003eorg.codehaus.plexus:plexus-classworlds's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.12.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cul\u003e\n\u003cli\u003eFix loadGlob using OR instead of AND for glob matching (\u003ca href=\"https://redirect.github.com/codehaus-plexus/plexus-classworlds/pull/147\"\u003e#147\u003c/a\u003e) \u003ca href=\"https://github.com/gnodet\"\u003e\u003ccode\u003e@​gnodet\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/commit/352e533ee33c8bae87b96255ae37f3dfe8b39c21\"\u003e\u003ccode\u003e352e533\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release plexus-classworlds-2.12.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/commit/9d5a694fa806a2c9d5344deba166f8cd3d2dc17d\"\u003e\u003ccode\u003e9d5a694\u003c/code\u003e\u003c/a\u003e Fix test to use File API for glob pattern (Windows compat)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/commit/6cff36d2d2a56c34c5229a0304ee73b1069703b2\"\u003e\u003ccode\u003e6cff36d\u003c/code\u003e\u003c/a\u003e Fix loadGlob using OR instead of AND for glob matching\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/commit/98ef018f4e644e246ef650a8de9a3a1d51103b22\"\u003e\u003ccode\u003e98ef018\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/compare/plexus-classworlds-2.11.0...plexus-classworlds-2.12.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.junit.platform:junit-platform-engine` from 6.0.3 to 6.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/junit-team/junit-framework/releases\"\u003eorg.junit.platform:junit-platform-engine's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eJUnit 6.1.0 = Platform 6.1.0 + Jupiter 6.1.0 + Vintage 6.1.0\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0/release-notes.html\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JarvisCraft\"\u003e\u003ccode\u003e@​JarvisCraft\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5633\"\u003ejunit-team/junit-framework#5633\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Maran23\"\u003e\u003ccode\u003e@​Maran23\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5644\"\u003ejunit-team/junit-framework#5644\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eJUnit 6.1.0-RC1 = Platform 6.1.0-RC1 + Jupiter 6.1.0-RC1 + Vintage 6.1.0-RC1\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0-RC1/release-notes/\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mariokhoury4\"\u003e\u003ccode\u003e@​mariokhoury4\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/4574\"\u003ejunit-team/junit-framework#4574\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Ogu1208\"\u003e\u003ccode\u003e@​Ogu1208\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5145\"\u003ejunit-team/junit-framework#5145\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/HyungGeun94\"\u003e\u003ccode\u003e@​HyungGeun94\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5271\"\u003ejunit-team/junit-framework#5271\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yalishevant\"\u003e\u003ccode\u003e@​yalishevant\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5316\"\u003ejunit-team/junit-framework#5316\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JINU-CHANG\"\u003e\u003ccode\u003e@​JINU-CHANG\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5290\"\u003ejunit-team/junit-framework#5290\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jaschdoc\"\u003e\u003ccode\u003e@​jaschdoc\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5427\"\u003ejunit-team/junit-framework#5427\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kawshikbuet17\"\u003e\u003ccode\u003e@​kawshikbuet17\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5561\"\u003ejunit-team/junit-framework#5561\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/msridhar\"\u003e\u003ccode\u003e@​msridhar\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5602\"\u003ejunit-team/junit-framework#5602\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.1.0-M1...r6.1.0-RC1\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.1.0-M1...r6.1.0-RC1\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eJUnit 6.1.0-M1 = Platform 6.1.0-M1 + Jupiter 6.1.0-M1 + Vintage 6.1.0-M1\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0-M1/release-notes/\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vy\"\u003e\u003ccode\u003e@​vy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5041\"\u003ejunit-team/junit-framework#5041\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Pankraz76\"\u003e\u003ccode\u003e@​Pankraz76\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5006\"\u003ejunit-team/junit-framework#5006\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/arukiidou\"\u003e\u003ccode\u003e@​arukiidou\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5066\"\u003ejunit-team/junit-framework#5066\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/laeubi\"\u003e\u003ccode\u003e@​laeubi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5092\"\u003ejunit-team/junit-framework#5092\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jihun4452\"\u003e\u003ccode\u003e@​jihun4452\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5088\"\u003ejunit-team/junit-framework#5088\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TWiStErRob\"\u003e\u003ccode\u003e@​TWiStErRob\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5133\"\u003ejunit-team/junit-framework#5133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.0...r6.1.0-M1\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.0.0...r6.1.0-M1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0dc3af1cb1973d257b5bc75d81e02454d5e4e556\"\u003e\u003ccode\u003e0dc3af1\u003c/code\u003e\u003c/a\u003e Release 6.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/1d130020c85170edcb46ce7ed1f7f78824e37c04\"\u003e\u003ccode\u003e1d13002\u003c/code\u003e\u003c/a\u003e Prepare 6.1.0 release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/072b2175bbd7b0b3b26f5d928550ec7a21e68268\"\u003e\u003ccode\u003e072b217\u003c/code\u003e\u003c/a\u003e Update plugin spotless to v8.5.0 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5668\"\u003e#5668\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/3a53480218f4b752a9ca77506e10632cd483c0f8\"\u003e\u003ccode\u003e3a53480\u003c/code\u003e\u003c/a\u003e Update Gradle to v9.5.1 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5666\"\u003e#5666\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0e18a20a9f98d063ae02b3ba19329143f5c7f034\"\u003e\u003ccode\u003e0e18a20\u003c/code\u003e\u003c/a\u003e Update zizmorcore/zizmor-action action to v0.5.4 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5669\"\u003e#5669\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0a2634fb9cbbd057b02cf629d7d272c16d62be4b\"\u003e\u003ccode\u003e0a2634f\u003c/code\u003e\u003c/a\u003e Update github/codeql-action action to v4.35.5 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5671\"\u003e#5671\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/4dbd5561b00ac761a62c516bfaec51c212a2d60c\"\u003e\u003ccode\u003e4dbd556\u003c/code\u003e\u003c/a\u003e Restructure workflows to have single \u0026quot;status\u0026quot; job (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5670\"\u003e#5670\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/f2194cebe377512cb0ade388c62a881a0bcf5d3e\"\u003e\u003ccode\u003ef2194ce\u003c/code\u003e\u003c/a\u003e Increase timeout to reduce flakiness\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/5c8fdd2df65b763151cccbe669ea9e1c3155efcd\"\u003e\u003ccode\u003e5c8fdd2\u003c/code\u003e\u003c/a\u003e Update dependency org.apache.groovy:groovy to v5.0.6 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5659\"\u003e#5659\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/43c6982324602582902c9bdb213fd5e007f9cf3d\"\u003e\u003ccode\u003e43c6982\u003c/code\u003e\u003c/a\u003e Update dependency org.slf4j:slf4j-jdk14 to v2.0.18 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5667\"\u003e#5667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `eu.maveniverse.maven.njord:extension3` from 0.9.6 to 0.9.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/maveniverse/njord/releases\"\u003eeu.maveniverse.maven.njord:extension3's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.9.7\u003c/h2\u003e\n\u003cp\u003eMaintenance and updates.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump org.codehaus.plexus:plexus-classworlds from 2.11.0 to 2.12.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/301\"\u003emaveniverse/njord#301\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.junit.jupiter:junit-jupiter-api from 6.0.3 to 6.1.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/300\"\u003emaveniverse/njord#300\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.mima from 2.4.43 to 2.4.44 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/298\"\u003emaveniverse/njord#298\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.maven from 3.9.15 to 3.9.16 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/297\"\u003emaveniverse/njord#297\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.ow2.asm:asm from 9.10 to 9.10.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/305\"\u003emaveniverse/njord#305\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.json:json from 20251224 to 20260522 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/304\"\u003emaveniverse/njord#304\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.maveniverseShared from 0.2.3 to 0.2.4 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/303\"\u003emaveniverse/njord#303\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDeps: parent POM 55 and others by \u003ca href=\"https://github.com/cstamas\"\u003e\u003ccode\u003e@​cstamas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/306\"\u003emaveniverse/njord#306\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/maveniverse/njord/compare/release-0.9.6...release-0.9.7\"\u003ehttps://github.com/maveniverse/njord/compare/release-0.9.6...release-0.9.7\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/b1d8216ca4e8634858babb37c2e1474b1de8889f\"\u003e\u003ccode\u003eb1d8216\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release release-0.9.7 [skip ci]\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/2ea8dd7fc5c4e54c12904c6364bd2a0c2bae5814\"\u003e\u003ccode\u003e2ea8dd7\u003c/code\u003e\u003c/a\u003e Deps: parent POM 55 and others (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/306\"\u003e#306\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/1d8212610fc034982dd9f2c2955c77abee27b651\"\u003e\u003ccode\u003e1d82126\u003c/code\u003e\u003c/a\u003e Bump version.maveniverseShared from 0.2.3 to 0.2.4 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/303\"\u003e#303\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/3f90e7e5515846ed5fcc34f62f8c7d8b582cb75f\"\u003e\u003ccode\u003e3f90e7e\u003c/code\u003e\u003c/a\u003e Bump org.json:json from 20251224 to 20260522 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/304\"\u003e#304\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/4084d479efcec09fd0c9140126e76f34e6b5e0f7\"\u003e\u003ccode\u003e4084d47\u003c/code\u003e\u003c/a\u003e Bump org.ow2.asm:asm from 9.10 to 9.10.1 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/305\"\u003e#305\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/e363ff5d85abd697f700547f9664ca55ccd9aa71\"\u003e\u003ccode\u003ee363ff5\u003c/code\u003e\u003c/a\u003e Bump version.maven from 3.9.15 to 3.9.16 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/f861a12563dc553f7568aa813baaa4a42869f8a7\"\u003e\u003ccode\u003ef861a12\u003c/code\u003e\u003c/a\u003e Bump version.mima from 2.4.43 to 2.4.44 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/298\"\u003e#298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/e337af459ea61cbd62de3b4d4276039e143f1aaa\"\u003e\u003ccode\u003ee337af4\u003c/code\u003e\u003c/a\u003e Bump org.junit.jupiter:junit-jupiter-api from 6.0.3 to 6.1.0 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/300\"\u003e#300\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/5dfc3a10fb37c92f5382bd01b94c473e32ffd109\"\u003e\u003ccode\u003e5dfc3a1\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-classworlds from 2.11.0 to 2.12.0 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/301\"\u003e#301\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/495a36dc1602d5c7a766e74a8fc2de48a958e6ca\"\u003e\u003ccode\u003e495a36d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/maveniverse/njord/compare/release-0.9.6...release-0.9.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `eu.maveniverse.maven.plugins:njord` from 0.9.6 to 0.9.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/maveniverse/njord/releases\"\u003eeu.maveniverse.maven.plugins:njord's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.9.7\u003c/h2\u003e\n\u003cp\u003eMaintenance and updates.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump org.codehaus.plexus:plexus-classworlds from 2.11.0 to 2.12.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/301\"\u003emaveniverse/njord#301\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.junit.jupiter:junit-jupiter-api from 6.0.3 to 6.1.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/300\"\u003emaveniverse/njord#300\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.mima from 2.4.43 to 2.4.44 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/298\"\u003emaveniverse/njord#298\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.maven from 3.9.15 to 3.9.16 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/297\"\u003emaveniverse/njord#297\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.ow2.asm:asm from 9.10 to 9.10.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/305\"\u003emaveniverse/njord#305\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.json:json from 20251224 to 20260522 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/304\"\u003emaveniverse/njord#304\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.maveniverseShared from 0.2.3 to 0.2.4 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/303\"\u003emaveniverse/njord#303\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDeps: parent POM 55 and others by \u003ca href=\"https://github.com/cstamas\"\u003e\u003ccode\u003e@​cstamas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/306\"\u003emaveniverse/njord#306\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/maveniverse/njord/compare/release-0.9.6...release-0.9.7\"\u003ehttps://github.com/maveniverse/njord/compare/release-0.9.6...release-0.9.7\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/b1d8216ca4e8634858babb37c2e1474b1de8889f\"\u003e\u003ccode\u003eb1d8216\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release release-0.9.7 [skip ci]\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/2ea8dd7fc5c4e54c12904c6364bd2a0c2bae5814\"\u003e\u003ccode\u003e2ea8dd7\u003c/code\u003e\u003c/a\u003e Deps: parent POM 55 and others (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/306\"\u003e#306\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/1d8212610fc034982dd9f2c2955c77abee27b651\"\u003e\u003ccode\u003e1d82126\u003c/code\u003e\u003c/a\u003e Bump version.maveniverseShared from 0.2.3 to 0.2.4 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/303\"\u003e#303\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/3f90e7e5515846ed5fcc34f62f8c7d8b582cb75f\"\u003e\u003ccode\u003e3f90e7e\u003c/code\u003e\u003c/a\u003e Bump org.json:json from 20251224 to 20260522 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/304\"\u003e#304\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/4084d479efcec09fd0c9140126e76f34e6b5e0f7\"\u003e\u003ccode\u003e4084d47\u003c/code\u003e\u003c/a\u003e Bump org.ow2.asm:asm from 9.10 to 9.10.1 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/305\"\u003e#305\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/e363ff5d85abd697f700547f9664ca55ccd9aa71\"\u003e\u003ccode\u003ee363ff5\u003c/code\u003e\u003c/a\u003e Bump version.maven from 3.9.15 to 3.9.16 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/f861a12563dc553f7568aa813baaa4a42869f8a7\"\u003e\u003ccode\u003ef861a12\u003c/code\u003e\u003c/a\u003e Bump version.mima from 2.4.43 to 2.4.44 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/298\"\u003e#298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/e337af459ea61cbd62de3b4d4276039e143f1aaa\"\u003e\u003ccode\u003ee337af4\u003c/code\u003e\u003c/a\u003e Bump org.junit.jupiter:junit-jupiter-api from 6.0.3 to 6.1.0 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/300\"\u003e#300\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/5dfc3a10fb37c92f5382bd01b94c473e32ffd109\"\u003e\u003ccode\u003e5dfc3a1\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-classworlds from 2.11.0 to 2.12.0 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/301\"\u003e#301\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/495a36dc1602d5c7a766e74a8fc2de48a958e6ca\"\u003e\u003ccode\u003e495a36d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/maveniverse/njord/compare/release-0.9.6...release-0.9.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.maven.extensions:maven-build-cache-extension` from 1.2.2 to 1.2.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/apache/maven-build-cache-extension/releases\"\u003eorg.apache.maven.extensions:maven-build-cache-extension's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.3\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e🚀 New features and improvements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIssue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/336\"\u003e#336\u003c/a\u003e Add command line flag to override maxBuildsCached (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/489\"\u003e#489\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/MBUILDCACHE-73\"\u003e[MBUILDCACHE-73]\u003c/a\u003e - Allow arbitrary expressions as additional reconcilation properties (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/416\"\u003e#416\u003c/a\u003e) \u003ca href=\"https://github.com/pdudits\"\u003e\u003ccode\u003e@​pdudits\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/480\"\u003e#480\u003c/a\u003e - execute blocking hostname resolution asynchronously and implement timeout and caching (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/481\"\u003e#481\u003c/a\u003e) \u003ca href=\"https://github.com/marcuslinke\"\u003e\u003ccode\u003e@​marcuslinke\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDo not read a JAR completely into a byte-array before computing the SHA (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/470\"\u003e#470\u003c/a\u003e) \u003ca href=\"https://github.com/jvdvegt\"\u003e\u003ccode\u003e@​jvdvegt\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Test Only] Comprehensive test coverage (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/462\"\u003e#462\u003c/a\u003e) \u003ca href=\"https://github.com/AlexanderAshitkin\"\u003e\u003ccode\u003e@​AlexanderAshitkin\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOnly set the project artifact if it is the actual JAR (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/453\"\u003e#453\u003c/a\u003e) \u003ca href=\"https://github.com/mensinda\"\u003e\u003ccode\u003e@​mensinda\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/423\"\u003e#423\u003c/a\u003e — include declared input files in cache checksum for pom-packaged modules (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/482\"\u003e#482\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix issue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/463\"\u003e#463\u003c/a\u003e Unexpected cache miss due to previously downloaded remote cache entry with skipTests (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/472\"\u003e#472\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIssue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/345\"\u003e#345\u003c/a\u003e fix possible NPE with Intellij (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/473\"\u003e#473\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTest-jar type dependencies fail to be resolved during checksum calculation with -f builds (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/468\"\u003e#468\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix for issue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/450\"\u003e#450\u003c/a\u003e - fixed CacheUtils.unzip to properly restore unix permissions on file systems that support it (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/451\"\u003e#451\u003c/a\u003e) \u003ca href=\"https://github.com/eyforia\"\u003e\u003ccode\u003e@​eyforia\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📝 Documentation updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocumentation fixes and updates (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/460\"\u003e#460\u003c/a\u003e) \u003ca href=\"https://github.com/AlexanderAshitkin\"\u003e\u003ccode\u003e@​AlexanderAshitkin\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e👻 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFinish breaking dependency on org.apache.http in RemoteCacheRepositoryImpl (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/441\"\u003e#441\u003c/a\u003e) \u003ca href=\"https://github.com/elharo\"\u003e\u003ccode\u003e@​elharo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove undeclared NotNull annotations (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/440\"\u003e#440\u003c/a\u003e) \u003ca href=\"https://github.com/elharo\"\u003e\u003ccode\u003e@​elharo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFill in two more used dependencies SLF4J and sisu.plexus (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/438\"\u003e#438\u003c/a\u003e) \u003ca href=\"https://github.com/elharo\"\u003e\u003ccode\u003e@​elharo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🚦 Tests\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix findFirstMainSourceFile to skip invoker test projects (src/it/) in p12 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/474\"\u003e#474\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Test Only] Comprehensive test coverage (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/462\"\u003e#462\u003c/a\u003e) \u003ca href=\"https://github.com/AlexanderAshitkin\"\u003e\u003ccode\u003e@​AlexanderAshitkin\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📦 Dependency updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate 48 and Maven 3.9.16 (in Maven 3 profile) (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/490\"\u003e#490\u003c/a\u003e) \u003ca href=\"https://github.com/Bukama\"\u003e\u003ccode\u003e@​Bukama\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump com.github.tomakehurst:wiremock-jre8 from 2.35.2 to 3.0.1 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/485\"\u003e#485\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-invoker-plugin from 3.10.0 to 3.10.1 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/484\"\u003e#484\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump com.google.guava:guava from 30.1.1-jre to 32.0.0-jre in /src/test/projects/reference-test-projects/p06-dep-edge-cases/bom-b (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/464\"\u003e#464\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.junit:junit-bom from 5.14.3 to 5.14.4 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/479\"\u003e#479\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.commons:commons-lang3 from 3.14.0 to 3.18.0 in /src/test/projects/reference-test-projects/p18-maven4-native/platform-bom (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/465\"\u003e#465\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-invoker-plugin from 3.9.1 to 3.10.0 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/478\"\u003e#478\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump commons-io:commons-io from 2.21.0 to 2.22.0 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/477\"\u003e#477\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.testcontainers:testcontainers-bom from 2.0.4 to 2.0.5 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/476\"\u003e#476\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump com.fasterxml.jackson.core:jackson-annotations from 2.15.4 to 2.21 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/475\"\u003e#475\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.testcontainers:testcontainers-bom from 2.0.3 to 2.0.4 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/466\"\u003e#466\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump resolverVersion from 1.9.26 to 1.9.27 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/459\"\u003e#459\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump resolverVersion from 1.9.25 to 1.9.26 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/458\"\u003e#458\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.junit:junit-bom from 5.14.2 to 5.14.3 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/457\"\u003e#457\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/f9f25d2f6acd78238471f7f36e1efe93fb8b7e50\"\u003e\u003ccode\u003ef9f25d2\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release maven-build-cache-extension-1.2.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/7bd513b6515e526554067386d2d4b1e67fb7e2cb\"\u003e\u003ccode\u003e7bd513b\u003c/code\u003e\u003c/a\u003e Update 48 and Maven 3.9.16 (in Maven 3 profile) (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/490\"\u003e#490\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/ada66d445c228ba9abe52e42632fc237af38f89f\"\u003e\u003ccode\u003eada66d4\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/336\"\u003e#336\u003c/a\u003e Add command line flag to override maxBuildsCached (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/489\"\u003e#489\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/c915399e169c6c3633b4a12be0fc1e9579114f50\"\u003e\u003ccode\u003ec915399\u003c/code\u003e\u003c/a\u003e [MBUILDCACHE-73] Allow arbitrary expressions as additional reconcilation prop...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/0b7d080ffca2a32c892208bbfafbd18b9dd32a92\"\u003e\u003ccode\u003e0b7d080\u003c/code\u003e\u003c/a\u003e Bump com.github.tomakehurst:wiremock-jre8 from 2.35.2 to 3.0.1 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/485\"\u003e#485\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/051a319a8f063ea59f97709186e8966e2969a1e4\"\u003e\u003ccode\u003e051a319\u003c/code\u003e\u003c/a\u003e Only set the project artifact if it is the actual JAR (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/453\"\u003e#453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/6a48e056a89316d5c3a007098cd32aa9aa5e1a5e\"\u003e\u003ccode\u003e6a48e05\u003c/code\u003e\u003c/a\u003e Bump org.apache.maven.plugins:maven-invoker-plugin from 3.10.0 to 3.10.1 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/484\"\u003e#484\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/5032c5d805f4071d34ecea96f40d80117369654a\"\u003e\u003ccode\u003e5032c5d\u003c/code\u003e\u003c/a\u003e fix: \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/480\"\u003e#480\u003c/a\u003e - execute blocking hostname resolution asynchronously and implement...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/dc7069f9e25acfafa6cc41ebba48bcbe43e5bc4b\"\u003e\u003ccode\u003edc7069f\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/423\"\u003e#423\u003c/a\u003e add an IT and a fix (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/482\"\u003e#482\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/929bed8890bc43128818277c13b6f8c1c05e5f8c\"\u003e\u003ccode\u003e929bed8\u003c/code\u003e\u003c/a\u003e Bump com.google.guava:guava\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/apache/maven-build-cache-extension/compare/maven-build-cache-extension-1.2.2...maven-build-cache-extension-1.2.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `eu.maveniverse.maven.plugins:njord` from 0.9.6 to 0.9.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/maveniverse/njord/releases\"\u003eeu.maveniverse.maven.plugins:njord's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.9.7\u003c/h2\u003e\n\u003cp\u003eMaintenance and updates.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump org.codehaus.plexus:plexus-classworlds from 2.11.0 to 2.12.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/301\"\u003emaveniverse/njord#301\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.junit.jupiter:junit-jupiter-api from 6.0.3 to 6.1.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/300\"\u003emaveniverse/njord#300\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.mima from 2.4.43 to 2.4.44 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/298\"\u003emaveniverse/njord#298\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.maven from 3.9.15 to 3.9.16 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/297\"\u003emaveniverse/njord#297\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.ow2.asm:asm from 9.10 to 9.10.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pul...\n\n_Description has been truncated_","html_url":"https://github.com/jetty/jetty.project/pull/15211","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/jetty%2Fjetty.project/issues/15211","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/15211/packages"}},{"old_version":"1.5.32","new_version":"1.5.33","update_type":"patch","path":null,"pr_created_at":"2026-05-30T01:02:12.000Z","version_change":"1.5.32 → 1.5.33","issue":{"uuid":"4552609919","node_id":"PR_kwDOAB81F87g2ye7","number":15208,"state":"closed","title":"[12.1.x EE10] Bump the dev-dependencies group across 1 directory with 14 updates","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-06-06T00:11:29.000Z","author_association":null,"state_reason":null,"created_at":"2026-05-30T01:02:12.000Z","updated_at":"2026-06-06T00:11:31.000Z","time_to_close":601757,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"[12.1.x EE10] Bump","group_name":"dev-dependencies","update_count":14,"packages":[{"name":"org.ow2.asm:asm","old_version":"9.10","new_version":"9.10.1"},{"name":"org.ow2.asm:asm-commons","old_version":"9.10","new_version":"9.10.1"},{"name":"org.ow2.asm:asm-bom","old_version":"9.10","new_version":"9.10.1"},{"name":"org.apache.maven.surefire:surefire-junit47","old_version":"3.5.5","new_version":"3.5.6"},{"name":"com.fasterxml.jackson:jackson-bom","old_version":"2.21.3","new_version":"2.21.4","repository_url":"https://github.com/FasterXML/jackson-bom"},{"name":"io.netty:netty-bom","old_version":"4.2.13.Final","new_version":"4.2.14.Final","repository_url":"https://github.com/netty/netty"},{"name":"org.hibernate.search:hibernate-search-bom","old_version":"8.3.1.Final","new_version":"8.4.0.Final","repository_url":"https://github.com/hibernate/hibernate-search"},{"name":"org.junit:junit-bom","old_version":"6.0.3","new_version":"6.1.0","repository_url":"https://github.com/junit-team/junit-framework"},{"name":"ch.qos.logback:logback-core","old_version":"1.5.32","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"},{"name":"org.codehaus.plexus:plexus-classworlds","old_version":"2.11.0","new_version":"2.12.0","repository_url":"https://github.com/codehaus-plexus/plexus-classworlds"},{"name":"eu.maveniverse.maven.njord:extension3","old_version":"0.9.6","new_version":"0.9.7","repository_url":"https://github.com/maveniverse/njord"},{"name":"eu.maveniverse.maven.plugins:njord","old_version":"0.9.6","new_version":"0.9.7","repository_url":"https://github.com/maveniverse/njord"},{"name":"org.apache.maven.extensions:maven-build-cache-extension","old_version":"1.2.2","new_version":"1.2.3","repository_url":"https://github.com/apache/maven-build-cache-extension"}],"path":null,"ecosystem":"maven"},"body":"Bumps the dev-dependencies group with 13 updates in the /jetty-ee10 directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| org.ow2.asm:asm | `9.10` | `9.10.1` |\n| org.ow2.asm:asm-commons | `9.10` | `9.10.1` |\n| org.ow2.asm:asm-bom | `9.10` | `9.10.1` |\n| org.apache.maven.surefire:surefire-junit47 | `3.5.5` | `3.5.6` |\n| [com.fasterxml.jackson:jackson-bom](https://github.com/FasterXML/jackson-bom) | `2.21.3` | `2.21.4` |\n| [io.netty:netty-bom](https://github.com/netty/netty) | `4.2.13.Final` | `4.2.14.Final` |\n| [org.hibernate.search:hibernate-search-bom](https://github.com/hibernate/hibernate-search) | `8.3.1.Final` | `8.4.0.Final` |\n| [org.junit:junit-bom](https://github.com/junit-team/junit-framework) | `6.0.3` | `6.1.0` |\n| [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) | `1.5.32` | `1.5.33` |\n| [org.codehaus.plexus:plexus-classworlds](https://github.com/codehaus-plexus/plexus-classworlds) | `2.11.0` | `2.12.0` |\n| [eu.maveniverse.maven.njord:extension3](https://github.com/maveniverse/njord) | `0.9.6` | `0.9.7` |\n| [eu.maveniverse.maven.plugins:njord](https://github.com/maveniverse/njord) | `0.9.6` | `0.9.7` |\n| [org.apache.maven.extensions:maven-build-cache-extension](https://github.com/apache/maven-build-cache-extension) | `1.2.2` | `1.2.3` |\n\n\nUpdates `org.ow2.asm:asm` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-commons` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-bom` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-commons` from 9.10 to 9.10.1\n\nUpdates `org.apache.maven.surefire:surefire-junit47` from 3.5.5 to 3.5.6\n\nUpdates `com.fasterxml.jackson:jackson-bom` from 2.21.3 to 2.21.4\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-bom/commit/d1abd31e4fec3035965d57a05a6256171ea8d980\"\u003e\u003ccode\u003ed1abd31\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-bom-2.21.4\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-bom/commit/2aaea43db8480aa7d405ebc0de503cffc864f6f6\"\u003e\u003ccode\u003e2aaea43\u003c/code\u003e\u003c/a\u003e Prep for 2.21.4 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-bom/commit/9d3a9d54e40312ef0ac9192d599b59b541f65fb8\"\u003e\u003ccode\u003e9d3a9d5\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-bom/commit/84bcf7f5b268bc2b47a92bd08391f75e9d956793\"\u003e\u003ccode\u003e84bcf7f\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/FasterXML/jackson-bom/compare/jackson-bom-2.21.3...jackson-bom-2.21.4\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `io.netty:netty-bom` from 4.2.13.Final to 4.2.14.Final\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/netty/netty/releases\"\u003eio.netty:netty-bom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003enetty-4.2.14.Final\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHTTP: Fix revapi failure introduced by 84530fa81e12dcd1d42310bb20c1385cb44128d8 by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16748\"\u003enetty/netty#16748\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHTTP: Re-add constructor to HttpProxyHandler that was removed by mistake by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16747\"\u003enetty/netty#16747\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMarshalling: Explicit document security requirements by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16752\"\u003enetty/netty#16752\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix io_uring op completion TRACE logging by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16755\"\u003enetty/netty#16755\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eQuic: Ensure writes are done before notify close promise of QuicheQui… by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16758\"\u003enetty/netty#16758\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid re-parsing openssl key material with non-cached provider by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16759\"\u003enetty/netty#16759\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin HTTP/RTSP version + method normalization to Locale.US by \u003ca href=\"https://github.com/daguimu\"\u003e\u003ccode\u003e@​daguimu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16765\"\u003enetty/netty#16765\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFill MsgHdrMemoryArray#hdrs with null entry on release by \u003ca href=\"https://github.com/tsegismont\"\u003e\u003ccode\u003e@​tsegismont\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16764\"\u003enetty/netty#16764\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRevapi: Use default \u0026quot;oldVersion\u0026quot; by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16774\"\u003enetty/netty#16774\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdaptive: Fix concurrency issue in adaptive allocator by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16767\"\u003enetty/netty#16767\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAuto-port 4.2: Make bulk byte moving in ByteBuf faster by \u003ca href=\"https://github.com/netty-project-bot\"\u003e\u003ccode\u003e@​netty-project-bot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16781\"\u003enetty/netty#16781\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin multipart Content-Type / Content-Transfer-Encoding case folding to Locale.US by \u003ca href=\"https://github.com/daguimu\"\u003e\u003ccode\u003e@​daguimu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16768\"\u003enetty/netty#16768\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove dead native declarations by \u003ca href=\"https://github.com/pandareen\"\u003e\u003ccode\u003e@​pandareen\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16783\"\u003enetty/netty#16783\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIsolate tests that modify available Security providers by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16793\"\u003enetty/netty#16793\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove test annotations from a method that isn't a test by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16792\"\u003enetty/netty#16792\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEnable OpenSslCachingKeyMaterialProvider to evict stale entries after cert rotation by \u003ca href=\"https://github.com/zhangweikop\"\u003e\u003ccode\u003e@​zhangweikop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16523\"\u003enetty/netty#16523\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIoUring: extend user data from short to long by \u003ca href=\"https://github.com/dreamlike-ocean\"\u003e\u003ccode\u003e@​dreamlike-ocean\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16682\"\u003enetty/netty#16682\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRevert CompositeByteBuf component search fast path by \u003ca href=\"https://github.com/yawkat\"\u003e\u003ccode\u003e@​yawkat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16811\"\u003enetty/netty#16811\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHTTP2: Use 100 as default max concurrent streams setting by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16804\"\u003enetty/netty#16804\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix ResumptionController wrapping by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16815\"\u003enetty/netty#16815\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eResolve all localhost addresses without querying DNS servers by \u003ca href=\"https://github.com/JulianVennen\"\u003e\u003ccode\u003e@​JulianVennen\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16749\"\u003enetty/netty#16749\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIpFilter: Fix ClassCastException caused by IpSubnetFilter if only ipv6 rules are configured but remote peer is using ipv4 by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16803\"\u003enetty/netty#16803\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix memoryAddress() for direct ByteBuffers wrapped by Unpooled without Unsafe by \u003ca href=\"https://github.com/dreamlike-ocean\"\u003e\u003ccode\u003e@​dreamlike-ocean\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16788\"\u003enetty/netty#16788\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRoute synchronous onLookupComplete exceptions via fireExceptionCaught by \u003ca href=\"https://github.com/kwondh5217\"\u003e\u003ccode\u003e@​kwondh5217\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16794\"\u003enetty/netty#16794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIoUring: Stop generic FileRegion drain loop when transferred() reaches count() by \u003ca href=\"https://github.com/LuciferYang\"\u003e\u003ccode\u003e@​LuciferYang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16826\"\u003enetty/netty#16826\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMQTT: Allow MQTT 5 CONNECT with password only by \u003ca href=\"https://github.com/shblue21\"\u003e\u003ccode\u003e@​shblue21\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16833\"\u003enetty/netty#16833\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix MQTT decoder size check after variable header replay by \u003ca href=\"https://github.com/daguimu\"\u003e\u003ccode\u003e@​daguimu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16787\"\u003enetty/netty#16787\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pandareen\"\u003e\u003ccode\u003e@​pandareen\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16783\"\u003enetty/netty#16783\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zhangweikop\"\u003e\u003ccode\u003e@​zhangweikop\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16523\"\u003enetty/netty#16523\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JulianVennen\"\u003e\u003ccode\u003e@​JulianVennen\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16749\"\u003enetty/netty#16749\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kwondh5217\"\u003e\u003ccode\u003e@​kwondh5217\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16794\"\u003enetty/netty#16794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/shblue21\"\u003e\u003ccode\u003e@​shblue21\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16833\"\u003enetty/netty#16833\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/netty/netty/compare/netty-4.2.13.Final...netty-4.2.14.Final\"\u003ehttps://github.com/netty/netty/compare/netty-4.2.13.Final...netty-4.2.14.Final\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/0a60b753d5b0de9f58e245538d61c11dc6cfc4b2\"\u003e\u003ccode\u003e0a60b75\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release netty-4.2.14.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/72df658e5fdd1cc6d65bce1e0917ec31a9560269\"\u003e\u003ccode\u003e72df658\u003c/code\u003e\u003c/a\u003e Fix MQTT decoder size check after variable header replay (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16787\"\u003e#16787\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/7125dba6b20822aa72dd8359b350c2f3b9a545d9\"\u003e\u003ccode\u003e7125dba\u003c/code\u003e\u003c/a\u003e MQTT: Allow MQTT 5 CONNECT with password only (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16833\"\u003e#16833\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/9e19320a5855746970d05a5cd785d73a17cc694d\"\u003e\u003ccode\u003e9e19320\u003c/code\u003e\u003c/a\u003e IoUring: Stop generic FileRegion drain loop when transferred() reaches count(...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/4ce9f17f05c67b72c87bc83951800bad245fe162\"\u003e\u003ccode\u003e4ce9f17\u003c/code\u003e\u003c/a\u003e Route synchronous onLookupComplete exceptions via fireExceptionCaught (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16794\"\u003e#16794\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/f7b1b7de625031cc60e6eaecb889c97303588759\"\u003e\u003ccode\u003ef7b1b7d\u003c/code\u003e\u003c/a\u003e Fix memoryAddress() for direct ByteBuffers wrapped by Unpooled without Unsafe...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/0ccb265cadf91b2e09c2f479c9194d193d7a5dbc\"\u003e\u003ccode\u003e0ccb265\u003c/code\u003e\u003c/a\u003e IpFilter: Fix ClassCastException caused by IpSubnetFilter if only ipv6 rules ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/a6aeb6deffda3e45904edd05abc5cdddcd438794\"\u003e\u003ccode\u003ea6aeb6d\u003c/code\u003e\u003c/a\u003e Resolve all localhost addresses without querying DNS servers (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16749\"\u003e#16749\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/c328ba2ab89d2c90c80be1d2de1cfbb8f94c438b\"\u003e\u003ccode\u003ec328ba2\u003c/code\u003e\u003c/a\u003e Fix ResumptionController wrapping (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16815\"\u003e#16815\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/bc5862ba488c569c888d3b82048083041f66e880\"\u003e\u003ccode\u003ebc5862b\u003c/code\u003e\u003c/a\u003e HTTP2: Use 100 as default max concurrent streams setting (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16804\"\u003e#16804\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/netty/netty/compare/netty-4.2.13.Final...netty-4.2.14.Final\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.hibernate.search:hibernate-search-bom` from 8.3.1.Final to 8.4.0.Final\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hibernate/hibernate-search/releases\"\u003eorg.hibernate.search:hibernate-search-bom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 8.4.0.Final\u003c/h2\u003e\n\u003ch1\u003eHibernate Search 8.4.0.Final released\u003c/h1\u003e\n\u003cp\u003eWe are pleased to announce the release of Hibernate Search 8.4: 8.4.0.Final.\u003c/p\u003e\n\u003cp\u003eYou can find the full list of 8.4.0.Final changes \u003ca href=\"https://hibernate.atlassian.net/issues/?jql=project%20%3D%20HSEARCH%20AND%20fixVersion%20%3D%208.4.0.Final\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eWhat's new\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSee the \u003ca href=\"https://hibernate.org/search/releases/8.4\"\u003ewebsite\u003c/a\u003e for requirements and compatibilities.\u003c/li\u003e\n\u003cli\u003eSee the \u003ca href=\"https://docs.hibernate.org/search/8.4/whats-new/en-US/html_single/\"\u003eWhat's New\u003c/a\u003e guide for details about new features and capabilities.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eConclusion\u003c/h2\u003e\n\u003cp\u003eFor additional details, see:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe \u003ca href=\"https://hibernate.org/search/releases/8.4/\"\u003erelease page\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/migration/html_single/\"\u003eMigration Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/getting-started/orm/en-US/html_single/\"\u003eORM Getting Started Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/getting-started/standalone/en-US/html_single/\"\u003eStandalone Getting Started Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/reference/en-US/html_single/\"\u003eReference Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/api\"\u003eAPI docs\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eVisit the \u003ca href=\"https://hibernate.org/community/\"\u003ewebsite\u003c/a\u003e for details on getting in touch with us.\u003c/p\u003e\n\u003ch2\u003eRelease 8.4.0.CR1\u003c/h2\u003e\n\u003ch1\u003eHibernate Search 8.4.0.CR1 released\u003c/h1\u003e\n\u003cp\u003eWe are pleased to announce the release of Hibernate Search 8.4: 8.4.0.CR1.\u003c/p\u003e\n\u003cp\u003eYou can find the full list of 8.4.0.CR1 changes \u003ca href=\"https://hibernate.atlassian.net/issues/?jql=project%20%3D%20HSEARCH%20AND%20fixVersion%20%3D%208.4.0.CR1\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eWhat's new\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSee the \u003ca href=\"https://hibernate.org/search/releases/8.4\"\u003ewebsite\u003c/a\u003e for requirements and compatibilities.\u003c/li\u003e\n\u003cli\u003eSee the \u003ca href=\"https://docs.hibernate.org/search/8.4/whats-new/en-US/html_single/\"\u003eWhat's New\u003c/a\u003e guide for details about new features and capabilities.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eConclusion\u003c/h2\u003e\n\u003cp\u003eFor additional details, see:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe \u003ca href=\"https://hibernate.org/search/releases/8.4/\"\u003erelease page\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/migration/html_single/\"\u003eMigration Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/getting-started/orm/en-US/html_single/\"\u003eORM Getting Started Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/getting-started/standalone/en-US/html_single/\"\u003eStandalone Getting Started Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/reference/en-US/html_single/\"\u003eReference Guide\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hibernate/hibernate-search/blob/main/changelog.txt\"\u003eorg.hibernate.search:hibernate-search-bom's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.4.0.Final (2026-05-27)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://hibernate.atlassian.net/projects/HSEARCH/versions/39072\"\u003ehttps://hibernate.atlassian.net/projects/HSEARCH/versions/39072\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e** Improvement\n* HSEARCH-5630 Update to Hibernate ORM 7.4.0.Final\n* HSEARCH-5629 Use Maven 3.9.16 as a required minimum version for the build\n* HSEARCH-5627 Switch from the Search session holder to a Hibernate ORM session extension\n* HSEARCH-5626 Update Elasticsearch client (elasticsearch-rest-client) to 9.4.1\n* HSEARCH-5625 Test against latest Elasticsearch 9.4.1\n* HSEARCH-5624 Update Elasticsearch client (elasticsearch-rest5-client) to 9.4.1\u003c/p\u003e\n\u003ch2\u003e8.4.0.CR1 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://hibernate.atlassian.net/projects/HSEARCH/versions/37437\"\u003ehttps://hibernate.atlassian.net/projects/HSEARCH/versions/37437\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e** Bug\n* HSEARCH-5595 \u003ccode\u003echeckstyle:check\u003c/code\u003e is not build cache relocatable due to project resources including the workspace root\u003c/p\u003e\n\u003cp\u003e** Improvement\n* HSEARCH-5623 Update to Hibernate ORM 7.4.0.CR1\n* HSEARCH-5622 Update Elasticsearch client (elasticsearch-rest5-client) to 9.4.0\n* HSEARCH-5621 Update Elasticsearch client (elasticsearch-rest-client) to 9.4.0\n* HSEARCH-5620 Add compatibility with Elasticsearch 9.4\n* HSEARCH-5619 Upgrade to GSON 2.14.0\n* HSEARCH-5618 Update Jackson to 2.21.3\n* HSEARCH-5617 Update to AWS SDK 2.44.1\n* HSEARCH-5616 Update Elasticsearch client (elasticsearch-rest-client) to 9.3.4\n* HSEARCH-5613 Use Maven 3.9.15 as a required minimum version for the build\n* HSEARCH-5612 Upgrade to commons-codec 1.22.0\n* HSEARCH-5611 Update Apache HTTP Client components to 5.6.1\n* HSEARCH-5609 Update Elasticsearch client (elasticsearch-rest-client) to 9.3.3\n* HSEARCH-5608 Update Elasticsearch client (elasticsearch-rest5-client) to 9.3.4\n* HSEARCH-5607 Update Elasticsearch rest client (opensearch-rest-client) to 3.6.0\n* HSEARCH-5606 Add compatibility with OpenSearch 3.6\n* HSEARCH-5601 Update to commons-logging to 1.3.6\n* HSEARCH-5600 Update Jackson to 2.21.2\n* HSEARCH-5599 Update Apache HTTP Core client components to 5.4.2\n* HSEARCH-5598 Update Elasticsearch client (elasticsearch-rest-client) to 9.3.2\n* HSEARCH-5597 Update Elasticsearch client (elasticsearch-rest5-client) to 9.3.3\u003c/p\u003e\n\u003cp\u003e** Task\n* HSEARCH-5596 Use changeDetection config option instead of the deprecated overwrite in maven-resources-plugin\n* HSEARCH-5280 Look into \u003ccode\u003eOutboxPollingAutomaticIndexingDynamicShardingRebalancingIT#agentJoined\u003c/code\u003e test\n* HSEARCH-5242 Investigate why building hibernate-search-integrationtest-performance-backend-lucene fails on some envs\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/7369a18fc526aaffba13336fdcdc95a333702b19\"\u003e\u003ccode\u003e7369a18\u003c/code\u003e\u003c/a\u003e [Jenkins release job] Preparing release 8.4.0.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/4e26c085ba83c21cde89022a2f10864b08711e25\"\u003e\u003ccode\u003e4e26c08\u003c/code\u003e\u003c/a\u003e [Jenkins release job] changelog.txt updated by release build 8.4.0.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/fe410d2d5c25d9e05648f67c027441564a32be03\"\u003e\u003ccode\u003efe410d2\u003c/code\u003e\u003c/a\u003e HSEARCH-5630 Add a few migration notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/87335b65fd124493bf91ad83de78f64eafc1155c\"\u003e\u003ccode\u003e87335b6\u003c/code\u003e\u003c/a\u003e HSEARCH-5630 Update to Hibernate ORM 7.4.0.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/58d6af143d22c9ce55872c9f13c51c8dd8e03d32\"\u003e\u003ccode\u003e58d6af1\u003c/code\u003e\u003c/a\u003e HSEARCH-5624 Update Elasticsearch client (elasticsearch-rest5-client) to 9.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/9efe369fcb419ded47b3e77a02b3d84451e64853\"\u003e\u003ccode\u003e9efe369\u003c/code\u003e\u003c/a\u003e Bump the build-dependencies group with 4 updates\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/bc1c18509b22d2b1fa9e41149fbe5cf166d7f663\"\u003e\u003ccode\u003ebc1c185\u003c/code\u003e\u003c/a\u003e Use the ssh URL for updating the website during the release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/311adb00224ab04fc2c397da94cf41a373338801\"\u003e\u003ccode\u003e311adb0\u003c/code\u003e\u003c/a\u003e HSEARCH-5627 Mention limitations of a StatelessSession\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/d429b05110cf6015d70faa6278176c6b3e7defa0\"\u003e\u003ccode\u003ed429b05\u003c/code\u003e\u003c/a\u003e HSEARCH-5627 Better error message for \u0026quot;incompatible\u0026quot; session types\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/2eaeb282d9d9bc136bc32f93ca12634374e249d4\"\u003e\u003ccode\u003e2eaeb28\u003c/code\u003e\u003c/a\u003e HSEARCH-5627 Add a simple StatelessSession test\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hibernate/hibernate-search/compare/8.3.1.Final...8.4.0.Final\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.junit:junit-bom` from 6.0.3 to 6.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/junit-team/junit-framework/releases\"\u003eorg.junit:junit-bom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eJUnit 6.1.0 = Platform 6.1.0 + Jupiter 6.1.0 + Vintage 6.1.0\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0/release-notes.html\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JarvisCraft\"\u003e\u003ccode\u003e@​JarvisCraft\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5633\"\u003ejunit-team/junit-framework#5633\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Maran23\"\u003e\u003ccode\u003e@​Maran23\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5644\"\u003ejunit-team/junit-framework#5644\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eJUnit 6.1.0-RC1 = Platform 6.1.0-RC1 + Jupiter 6.1.0-RC1 + Vintage 6.1.0-RC1\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0-RC1/release-notes/\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mariokhoury4\"\u003e\u003ccode\u003e@​mariokhoury4\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/4574\"\u003ejunit-team/junit-framework#4574\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Ogu1208\"\u003e\u003ccode\u003e@​Ogu1208\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5145\"\u003ejunit-team/junit-framework#5145\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/HyungGeun94\"\u003e\u003ccode\u003e@​HyungGeun94\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5271\"\u003ejunit-team/junit-framework#5271\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yalishevant\"\u003e\u003ccode\u003e@​yalishevant\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5316\"\u003ejunit-team/junit-framework#5316\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JINU-CHANG\"\u003e\u003ccode\u003e@​JINU-CHANG\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5290\"\u003ejunit-team/junit-framework#5290\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jaschdoc\"\u003e\u003ccode\u003e@​jaschdoc\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5427\"\u003ejunit-team/junit-framework#5427\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kawshikbuet17\"\u003e\u003ccode\u003e@​kawshikbuet17\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5561\"\u003ejunit-team/junit-framework#5561\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/msridhar\"\u003e\u003ccode\u003e@​msridhar\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5602\"\u003ejunit-team/junit-framework#5602\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.1.0-M1...r6.1.0-RC1\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.1.0-M1...r6.1.0-RC1\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eJUnit 6.1.0-M1 = Platform 6.1.0-M1 + Jupiter 6.1.0-M1 + Vintage 6.1.0-M1\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0-M1/release-notes/\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vy\"\u003e\u003ccode\u003e@​vy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5041\"\u003ejunit-team/junit-framework#5041\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Pankraz76\"\u003e\u003ccode\u003e@​Pankraz76\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5006\"\u003ejunit-team/junit-framework#5006\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/arukiidou\"\u003e\u003ccode\u003e@​arukiidou\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5066\"\u003ejunit-team/junit-framework#5066\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/laeubi\"\u003e\u003ccode\u003e@​laeubi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5092\"\u003ejunit-team/junit-framework#5092\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jihun4452\"\u003e\u003ccode\u003e@​jihun4452\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5088\"\u003ejunit-team/junit-framework#5088\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TWiStErRob\"\u003e\u003ccode\u003e@​TWiStErRob\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5133\"\u003ejunit-team/junit-framework#5133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.0...r6.1.0-M1\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.0.0...r6.1.0-M1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0dc3af1cb1973d257b5bc75d81e02454d5e4e556\"\u003e\u003ccode\u003e0dc3af1\u003c/code\u003e\u003c/a\u003e Release 6.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/1d130020c85170edcb46ce7ed1f7f78824e37c04\"\u003e\u003ccode\u003e1d13002\u003c/code\u003e\u003c/a\u003e Prepare 6.1.0 release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/072b2175bbd7b0b3b26f5d928550ec7a21e68268\"\u003e\u003ccode\u003e072b217\u003c/code\u003e\u003c/a\u003e Update plugin spotless to v8.5.0 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5668\"\u003e#5668\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/3a53480218f4b752a9ca77506e10632cd483c0f8\"\u003e\u003ccode\u003e3a53480\u003c/code\u003e\u003c/a\u003e Update Gradle to v9.5.1 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5666\"\u003e#5666\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0e18a20a9f98d063ae02b3ba19329143f5c7f034\"\u003e\u003ccode\u003e0e18a20\u003c/code\u003e\u003c/a\u003e Update zizmorcore/zizmor-action action to v0.5.4 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5669\"\u003e#5669\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0a2634fb9cbbd057b02cf629d7d272c16d62be4b\"\u003e\u003ccode\u003e0a2634f\u003c/code\u003e\u003c/a\u003e Update github/codeql-action action to v4.35.5 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5671\"\u003e#5671\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/4dbd5561b00ac761a62c516bfaec51c212a2d60c\"\u003e\u003ccode\u003e4dbd556\u003c/code\u003e\u003c/a\u003e Restructure workflows to have single \u0026quot;status\u0026quot; job (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5670\"\u003e#5670\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/f2194cebe377512cb0ade388c62a881a0bcf5d3e\"\u003e\u003ccode\u003ef2194ce\u003c/code\u003e\u003c/a\u003e Increase timeout to reduce flakiness\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/5c8fdd2df65b763151cccbe669ea9e1c3155efcd\"\u003e\u003ccode\u003e5c8fdd2\u003c/code\u003e\u003c/a\u003e Update dependency org.apache.groovy:groovy to v5.0.6 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5659\"\u003e#5659\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/43c6982324602582902c9bdb213fd5e007f9cf3d\"\u003e\u003ccode\u003e43c6982\u003c/code\u003e\u003c/a\u003e Update dependency org.slf4j:slf4j-jdk14 to v2.0.18 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5667\"\u003e#5667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.ow2.asm:asm-bom` from 9.10 to 9.10.1\n\nUpdates `ch.qos.logback:logback-core` from 1.5.32 to 1.5.33\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.codehaus.plexus:plexus-classworlds` from 2.11.0 to 2.12.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/releases\"\u003eorg.codehaus.plexus:plexus-classworlds's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.12.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cul\u003e\n\u003cli\u003eFix loadGlob using OR instead of AND for glob matching (\u003ca href=\"https://redirect.github.com/codehaus-plexus/plexus-classworlds/pull/147\"\u003e#147\u003c/a\u003e) \u003ca href=\"https://github.com/gnodet\"\u003e\u003ccode\u003e@​gnodet\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/commit/352e533ee33c8bae87b96255ae37f3dfe8b39c21\"\u003e\u003ccode\u003e352e533\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release plexus-classworlds-2.12.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/commit/9d5a694fa806a2c9d5344deba166f8cd3d2dc17d\"\u003e\u003ccode\u003e9d5a694\u003c/code\u003e\u003c/a\u003e Fix test to use File API for glob pattern (Windows compat)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/commit/6cff36d2d2a56c34c5229a0304ee73b1069703b2\"\u003e\u003ccode\u003e6cff36d\u003c/code\u003e\u003c/a\u003e Fix loadGlob using OR instead of AND for glob matching\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/commit/98ef018f4e644e246ef650a8de9a3a1d51103b22\"\u003e\u003ccode\u003e98ef018\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/compare/plexus-classworlds-2.11.0...plexus-classworlds-2.12.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.junit.platform:junit-platform-engine` from 6.0.3 to 6.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/junit-team/junit-framework/releases\"\u003eorg.junit.platform:junit-platform-engine's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eJUnit 6.1.0 = Platform 6.1.0 + Jupiter 6.1.0 + Vintage 6.1.0\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0/release-notes.html\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JarvisCraft\"\u003e\u003ccode\u003e@​JarvisCraft\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5633\"\u003ejunit-team/junit-framework#5633\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Maran23\"\u003e\u003ccode\u003e@​Maran23\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5644\"\u003ejunit-team/junit-framework#5644\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eJUnit 6.1.0-RC1 = Platform 6.1.0-RC1 + Jupiter 6.1.0-RC1 + Vintage 6.1.0-RC1\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0-RC1/release-notes/\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mariokhoury4\"\u003e\u003ccode\u003e@​mariokhoury4\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/4574\"\u003ejunit-team/junit-framework#4574\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Ogu1208\"\u003e\u003ccode\u003e@​Ogu1208\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5145\"\u003ejunit-team/junit-framework#5145\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/HyungGeun94\"\u003e\u003ccode\u003e@​HyungGeun94\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5271\"\u003ejunit-team/junit-framework#5271\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yalishevant\"\u003e\u003ccode\u003e@​yalishevant\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5316\"\u003ejunit-team/junit-framework#5316\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JINU-CHANG\"\u003e\u003ccode\u003e@​JINU-CHANG\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5290\"\u003ejunit-team/junit-framework#5290\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jaschdoc\"\u003e\u003ccode\u003e@​jaschdoc\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5427\"\u003ejunit-team/junit-framework#5427\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kawshikbuet17\"\u003e\u003ccode\u003e@​kawshikbuet17\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5561\"\u003ejunit-team/junit-framework#5561\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/msridhar\"\u003e\u003ccode\u003e@​msridhar\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5602\"\u003ejunit-team/junit-framework#5602\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.1.0-M1...r6.1.0-RC1\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.1.0-M1...r6.1.0-RC1\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eJUnit 6.1.0-M1 = Platform 6.1.0-M1 + Jupiter 6.1.0-M1 + Vintage 6.1.0-M1\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0-M1/release-notes/\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vy\"\u003e\u003ccode\u003e@​vy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5041\"\u003ejunit-team/junit-framework#5041\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Pankraz76\"\u003e\u003ccode\u003e@​Pankraz76\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5006\"\u003ejunit-team/junit-framework#5006\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/arukiidou\"\u003e\u003ccode\u003e@​arukiidou\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5066\"\u003ejunit-team/junit-framework#5066\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/laeubi\"\u003e\u003ccode\u003e@​laeubi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5092\"\u003ejunit-team/junit-framework#5092\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jihun4452\"\u003e\u003ccode\u003e@​jihun4452\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5088\"\u003ejunit-team/junit-framework#5088\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TWiStErRob\"\u003e\u003ccode\u003e@​TWiStErRob\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5133\"\u003ejunit-team/junit-framework#5133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.0...r6.1.0-M1\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.0.0...r6.1.0-M1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0dc3af1cb1973d257b5bc75d81e02454d5e4e556\"\u003e\u003ccode\u003e0dc3af1\u003c/code\u003e\u003c/a\u003e Release 6.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/1d130020c85170edcb46ce7ed1f7f78824e37c04\"\u003e\u003ccode\u003e1d13002\u003c/code\u003e\u003c/a\u003e Prepare 6.1.0 release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/072b2175bbd7b0b3b26f5d928550ec7a21e68268\"\u003e\u003ccode\u003e072b217\u003c/code\u003e\u003c/a\u003e Update plugin spotless to v8.5.0 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5668\"\u003e#5668\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/3a53480218f4b752a9ca77506e10632cd483c0f8\"\u003e\u003ccode\u003e3a53480\u003c/code\u003e\u003c/a\u003e Update Gradle to v9.5.1 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5666\"\u003e#5666\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0e18a20a9f98d063ae02b3ba19329143f5c7f034\"\u003e\u003ccode\u003e0e18a20\u003c/code\u003e\u003c/a\u003e Update zizmorcore/zizmor-action action to v0.5.4 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5669\"\u003e#5669\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0a2634fb9cbbd057b02cf629d7d272c16d62be4b\"\u003e\u003ccode\u003e0a2634f\u003c/code\u003e\u003c/a\u003e Update github/codeql-action action to v4.35.5 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5671\"\u003e#5671\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/4dbd5561b00ac761a62c516bfaec51c212a2d60c\"\u003e\u003ccode\u003e4dbd556\u003c/code\u003e\u003c/a\u003e Restructure workflows to have single \u0026quot;status\u0026quot; job (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5670\"\u003e#5670\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/f2194cebe377512cb0ade388c62a881a0bcf5d3e\"\u003e\u003ccode\u003ef2194ce\u003c/code\u003e\u003c/a\u003e Increase timeout to reduce flakiness\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/5c8fdd2df65b763151cccbe669ea9e1c3155efcd\"\u003e\u003ccode\u003e5c8fdd2\u003c/code\u003e\u003c/a\u003e Update dependency org.apache.groovy:groovy to v5.0.6 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5659\"\u003e#5659\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/43c6982324602582902c9bdb213fd5e007f9cf3d\"\u003e\u003ccode\u003e43c6982\u003c/code\u003e\u003c/a\u003e Update dependency org.slf4j:slf4j-jdk14 to v2.0.18 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5667\"\u003e#5667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `eu.maveniverse.maven.njord:extension3` from 0.9.6 to 0.9.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/maveniverse/njord/releases\"\u003eeu.maveniverse.maven.njord:extension3's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.9.7\u003c/h2\u003e\n\u003cp\u003eMaintenance and updates.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump org.codehaus.plexus:plexus-classworlds from 2.11.0 to 2.12.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/301\"\u003emaveniverse/njord#301\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.junit.jupiter:junit-jupiter-api from 6.0.3 to 6.1.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/300\"\u003emaveniverse/njord#300\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.mima from 2.4.43 to 2.4.44 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/298\"\u003emaveniverse/njord#298\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.maven from 3.9.15 to 3.9.16 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/297\"\u003emaveniverse/njord#297\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.ow2.asm:asm from 9.10 to 9.10.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/305\"\u003emaveniverse/njord#305\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.json:json from 20251224 to 20260522 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/304\"\u003emaveniverse/njord#304\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.maveniverseShared from 0.2.3 to 0.2.4 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/303\"\u003emaveniverse/njord#303\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDeps: parent POM 55 and others by \u003ca href=\"https://github.com/cstamas\"\u003e\u003ccode\u003e@​cstamas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/306\"\u003emaveniverse/njord#306\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/maveniverse/njord/compare/release-0.9.6...release-0.9.7\"\u003ehttps://github.com/maveniverse/njord/compare/release-0.9.6...release-0.9.7\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/b1d8216ca4e8634858babb37c2e1474b1de8889f\"\u003e\u003ccode\u003eb1d8216\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release release-0.9.7 [skip ci]\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/2ea8dd7fc5c4e54c12904c6364bd2a0c2bae5814\"\u003e\u003ccode\u003e2ea8dd7\u003c/code\u003e\u003c/a\u003e Deps: parent POM 55 and others (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/306\"\u003e#306\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/1d8212610fc034982dd9f2c2955c77abee27b651\"\u003e\u003ccode\u003e1d82126\u003c/code\u003e\u003c/a\u003e Bump version.maveniverseShared from 0.2.3 to 0.2.4 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/303\"\u003e#303\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/3f90e7e5515846ed5fcc34f62f8c7d8b582cb75f\"\u003e\u003ccode\u003e3f90e7e\u003c/code\u003e\u003c/a\u003e Bump org.json:json from 20251224 to 20260522 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/304\"\u003e#304\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/4084d479efcec09fd0c9140126e76f34e6b5e0f7\"\u003e\u003ccode\u003e4084d47\u003c/code\u003e\u003c/a\u003e Bump org.ow2.asm:asm from 9.10 to 9.10.1 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/305\"\u003e#305\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/e363ff5d85abd697f700547f9664ca55ccd9aa71\"\u003e\u003ccode\u003ee363ff5\u003c/code\u003e\u003c/a\u003e Bump version.maven from 3.9.15 to 3.9.16 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/f861a12563dc553f7568aa813baaa4a42869f8a7\"\u003e\u003ccode\u003ef861a12\u003c/code\u003e\u003c/a\u003e Bump version.mima from 2.4.43 to 2.4.44 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/298\"\u003e#298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/e337af459ea61cbd62de3b4d4276039e143f1aaa\"\u003e\u003ccode\u003ee337af4\u003c/code\u003e\u003c/a\u003e Bump org.junit.jupiter:junit-jupiter-api from 6.0.3 to 6.1.0 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/300\"\u003e#300\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/5dfc3a10fb37c92f5382bd01b94c473e32ffd109\"\u003e\u003ccode\u003e5dfc3a1\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-classworlds from 2.11.0 to 2.12.0 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/301\"\u003e#301\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/495a36dc1602d5c7a766e74a8fc2de48a958e6ca\"\u003e\u003ccode\u003e495a36d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/maveniverse/njord/compare/release-0.9.6...release-0.9.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `eu.maveniverse.maven.plugins:njord` from 0.9.6 to 0.9.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/maveniverse/njord/releases\"\u003eeu.maveniverse.maven.plugins:njord's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.9.7\u003c/h2\u003e\n\u003cp\u003eMaintenance and updates.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump org.codehaus.plexus:plexus-classworlds from 2.11.0 to 2.12.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/301\"\u003emaveniverse/njord#301\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.junit.jupiter:junit-jupiter-api from 6.0.3 to 6.1.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/300\"\u003emaveniverse/njord#300\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.mima from 2.4.43 to 2.4.44 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/298\"\u003emaveniverse/njord#298\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.maven from 3.9.15 to 3.9.16 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/297\"\u003emaveniverse/njord#297\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.ow2.asm:asm from 9.10 to 9.10.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/305\"\u003emaveniverse/njord#305\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.json:json from 20251224 to 20260522 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/304\"\u003emaveniverse/njord#304\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.maveniverseShared from 0.2.3 to 0.2.4 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/303\"\u003emaveniverse/njord#303\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDeps: parent POM 55 and others by \u003ca href=\"https://github.com/cstamas\"\u003e\u003ccode\u003e@​cstamas\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/306\"\u003emaveniverse/njord#306\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/maveniverse/njord/compare/release-0.9.6...release-0.9.7\"\u003ehttps://github.com/maveniverse/njord/compare/release-0.9.6...release-0.9.7\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/b1d8216ca4e8634858babb37c2e1474b1de8889f\"\u003e\u003ccode\u003eb1d8216\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release release-0.9.7 [skip ci]\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/2ea8dd7fc5c4e54c12904c6364bd2a0c2bae5814\"\u003e\u003ccode\u003e2ea8dd7\u003c/code\u003e\u003c/a\u003e Deps: parent POM 55 and others (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/306\"\u003e#306\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/1d8212610fc034982dd9f2c2955c77abee27b651\"\u003e\u003ccode\u003e1d82126\u003c/code\u003e\u003c/a\u003e Bump version.maveniverseShared from 0.2.3 to 0.2.4 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/303\"\u003e#303\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/3f90e7e5515846ed5fcc34f62f8c7d8b582cb75f\"\u003e\u003ccode\u003e3f90e7e\u003c/code\u003e\u003c/a\u003e Bump org.json:json from 20251224 to 20260522 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/304\"\u003e#304\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/4084d479efcec09fd0c9140126e76f34e6b5e0f7\"\u003e\u003ccode\u003e4084d47\u003c/code\u003e\u003c/a\u003e Bump org.ow2.asm:asm from 9.10 to 9.10.1 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/305\"\u003e#305\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/e363ff5d85abd697f700547f9664ca55ccd9aa71\"\u003e\u003ccode\u003ee363ff5\u003c/code\u003e\u003c/a\u003e Bump version.maven from 3.9.15 to 3.9.16 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/297\"\u003e#297\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/f861a12563dc553f7568aa813baaa4a42869f8a7\"\u003e\u003ccode\u003ef861a12\u003c/code\u003e\u003c/a\u003e Bump version.mima from 2.4.43 to 2.4.44 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/298\"\u003e#298\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/e337af459ea61cbd62de3b4d4276039e143f1aaa\"\u003e\u003ccode\u003ee337af4\u003c/code\u003e\u003c/a\u003e Bump org.junit.jupiter:junit-jupiter-api from 6.0.3 to 6.1.0 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/300\"\u003e#300\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/5dfc3a10fb37c92f5382bd01b94c473e32ffd109\"\u003e\u003ccode\u003e5dfc3a1\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-classworlds from 2.11.0 to 2.12.0 (\u003ca href=\"https://redirect.github.com/maveniverse/njord/issues/301\"\u003e#301\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/maveniverse/njord/commit/495a36dc1602d5c7a766e74a8fc2de48a958e6ca\"\u003e\u003ccode\u003e495a36d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/maveniverse/njord/compare/release-0.9.6...release-0.9.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.maven.extensions:maven-build-cache-extension` from 1.2.2 to 1.2.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/apache/maven-build-cache-extension/releases\"\u003eorg.apache.maven.extensions:maven-build-cache-extension's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.3\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e🚀 New features and improvements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIssue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/336\"\u003e#336\u003c/a\u003e Add command line flag to override maxBuildsCached (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/489\"\u003e#489\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/MBUILDCACHE-73\"\u003e[MBUILDCACHE-73]\u003c/a\u003e - Allow arbitrary expressions as additional reconcilation properties (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/416\"\u003e#416\u003c/a\u003e) \u003ca href=\"https://github.com/pdudits\"\u003e\u003ccode\u003e@​pdudits\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/480\"\u003e#480\u003c/a\u003e - execute blocking hostname resolution asynchronously and implement timeout and caching (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/481\"\u003e#481\u003c/a\u003e) \u003ca href=\"https://github.com/marcuslinke\"\u003e\u003ccode\u003e@​marcuslinke\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDo not read a JAR completely into a byte-array before computing the SHA (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/470\"\u003e#470\u003c/a\u003e) \u003ca href=\"https://github.com/jvdvegt\"\u003e\u003ccode\u003e@​jvdvegt\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Test Only] Comprehensive test coverage (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/462\"\u003e#462\u003c/a\u003e) \u003ca href=\"https://github.com/AlexanderAshitkin\"\u003e\u003ccode\u003e@​AlexanderAshitkin\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOnly set the project artifact if it is the actual JAR (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/453\"\u003e#453\u003c/a\u003e) \u003ca href=\"https://github.com/mensinda\"\u003e\u003ccode\u003e@​mensinda\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/423\"\u003e#423\u003c/a\u003e — include declared input files in cache checksum for pom-packaged modules (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/482\"\u003e#482\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix issue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/463\"\u003e#463\u003c/a\u003e Unexpected cache miss due to previously downloaded remote cache entry with skipTests (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/472\"\u003e#472\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIssue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/345\"\u003e#345\u003c/a\u003e fix possible NPE with Intellij (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/473\"\u003e#473\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTest-jar type dependencies fail to be resolved during checksum calculation with -f builds (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/468\"\u003e#468\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix for issue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/450\"\u003e#450\u003c/a\u003e - fixed CacheUtils.unzip to properly restore unix permissions on file systems that support it (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/451\"\u003e#451\u003c/a\u003e) \u003ca href=\"https://github.com/eyforia\"\u003e\u003ccode\u003e@​eyforia\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📝 Documentation updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocumentation fixes and updates (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/460\"\u003e#460\u003c/a\u003e) \u003ca href=\"https://github.com/AlexanderAshitkin\"\u003e\u003ccode\u003e@​AlexanderAshitkin\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e👻 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFinish breaking dependency on org.apache.http in RemoteCacheRepositoryImpl (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/441\"\u003e#441\u003c/a\u003e) \u003ca href=\"https://github.com/elharo\"\u003e\u003ccode\u003e@​elharo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove undeclared NotNull annotations (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/440\"\u003e#440\u003c/a\u003e) \u003ca href=\"https://github.com/elharo\"\u003e\u003ccode\u003e@​elharo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFill in two more used dependencies SLF4J and sisu.plexus (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/438\"\u003e#438\u003c/a\u003e) \u003ca href=\"https://github.com/elharo\"\u003e\u003ccode\u003e@​elharo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🚦 Tests\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix findFirstMainSourceFile to skip invoker test projects (src/it/) in p12 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/474\"\u003e#474\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Test Only] Comprehensive test coverage (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/462\"\u003e#462\u003c/a\u003e) \u003ca href=\"https://github.com/AlexanderAshitkin\"\u003e\u003ccode\u003e@​AlexanderAshitkin\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📦 Dependency updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate 48 and Maven 3.9.16 (in Maven 3 profile) (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/490\"\u003e#490\u003c/a\u003e) \u003ca href=\"https://github.com/Bukama\"\u003e\u003ccode\u003e@​Bukama\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump com.github.tomakehurst:wiremock-jre8 from 2.35.2 to 3.0.1 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/485\"\u003e#485\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-invoker-plugin from 3.10.0 to 3.10.1 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/484\"\u003e#484\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump com.google.guava:guava from 30.1.1-jre to 32.0.0-jre in /src/test/projects/reference-test-projects/p06-dep-edge-cases/bom-b (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/464\"\u003e#464\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.junit:junit-bom from 5.14.3 to 5.14.4 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/479\"\u003e#479\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.commons:commons-lang3 from 3.14.0 to 3.18.0 in /src/test/projects/reference-test-projects/p18-maven4-native/platform-bom (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/465\"\u003e#465\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-invoker-plugin from 3.9.1 to 3.10.0 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/478\"\u003e#478\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump commons-io:commons-io from 2.21.0 to 2.22.0 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/477\"\u003e#477\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.testcontainers:testcontainers-bom from 2.0.4 to 2.0.5 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/476\"\u003e#476\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump com.fasterxml.jackson.core:jackson-annotations from 2.15.4 to 2.21 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/475\"\u003e#475\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.testcontainers:testcontainers-bom from 2.0.3 to 2.0.4 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/466\"\u003e#466\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump resolverVersion from 1.9.26 to 1.9.27 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/459\"\u003e#459\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump resolverVersion from 1.9.25 to 1.9.26 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/458\"\u003e#458\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.junit:junit-bom from 5.14.2 to 5.14.3 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/457\"\u003e#457\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/f9f25d2f6acd78238471f7f36e1efe93fb8b7e50\"\u003e\u003ccode\u003ef9f25d2\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release maven-build-cache-extension-1.2.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/7bd513b6515e526554067386d2d4b1e67fb7e2cb\"\u003e\u003ccode\u003e7bd513b\u003c/code\u003e\u003c/a\u003e Update 48 and Maven 3.9.16 (in Maven 3 profile) (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/490\"\u003e#490\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/ada66d445c228ba9abe52e42632fc237af38f89f\"\u003e\u003ccode\u003eada66d4\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/336\"\u003e#336\u003c/a\u003e Add command line flag to override maxBuildsCached (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/489\"\u003e#489\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/c915399e169c6c3633b4a12be0fc1e9579114f50\"\u003e\u003ccode\u003ec915399\u003c/code\u003e\u003c/a\u003e [MBUILDCACHE-73] Allow arbitrary expressions as additional reconcilation prop...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/0b7d080ffca2a32c892208bbfafbd18b9dd32a92\"\u003e\u003ccode\u003e0b7d080\u003c/code\u003e\u003c/a\u003e Bump com.github.tomakehurst:wiremock-jre8 from 2.35.2 to 3.0.1 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/485\"\u003e#485\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/051a319a8f063ea59f97709186e8966e2969a1e4\"\u003e\u003ccode\u003e051a319\u003c/code\u003e\u003c/a\u003e Only set the project artifact if it is the actual JAR (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/453\"\u003e#453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/6a48e056a89316d5c3a007098cd32aa9aa5e1a5e\"\u003e\u003ccode\u003e6a48e05\u003c/code\u003e\u003c/a\u003e Bump org.apache.maven.plugins:maven-invoker-plugin from 3.10.0 to 3.10.1 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/484\"\u003e#484\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/5032c5d805f4071d34ecea96f40d80117369654a\"\u003e\u003ccode\u003e5032c5d\u003c/code\u003e\u003c/a\u003e fix: \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/480\"\u003e#480\u003c/a\u003e - execute blocking hostname resolution asynchronously and implement...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/dc7069f9e25acfafa6cc41ebba48bcbe43e5bc4b\"\u003e\u003ccode\u003edc7069f\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/423\"\u003e#423\u003c/a\u003e add an IT and a fix (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/482\"\u003e#482\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/929bed8890bc43128818277c13b6f8c1c05e5f8c\"\u003e\u003ccode\u003e929bed8\u003c/code\u003e\u003c/a\u003e Bump com.google.guava:guava\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/apache/maven-build-cache-extension/compare/maven-build-cache-extension-1.2.2...maven-build-cache-extension-1.2.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `eu.maveniverse.maven.plugins:njord` from 0.9.6 to 0.9.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/maveniverse/njord/releases\"\u003eeu.maveniverse.maven.plugins:njord's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.9.7\u003c/h2\u003e\n\u003cp\u003eMaintenance and updates.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump org.codehaus.plexus:plexus-classworlds from 2.11.0 to 2.12.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/301\"\u003emaveniverse/njord#301\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.junit.jupiter:junit-jupiter-api from 6.0.3 to 6.1.0 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/300\"\u003emaveniverse/njord#300\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.mima from 2.4.43 to 2.4.44 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/298\"\u003emaveniverse/njord#298\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump version.maven from 3.9.15 to 3.9.16 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pull/297\"\u003emaveniverse/njord#297\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.ow2.asm:asm from 9.10 to 9.10.1 by \u003ca href=\"https://github.com/dependabot\"\u003e\u003ccode\u003e@​dependabot\u003c/code\u003e\u003c/a\u003e[bot] in \u003ca href=\"https://redirect.github.com/maveniverse/njord/pul...\n\n_Description has been truncated_","html_url":"https://github.com/jetty/jetty.project/pull/15208","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/jetty%2Fjetty.project/issues/15208","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/15208/packages"}},{"old_version":"1.5.32","new_version":"1.5.33","update_type":"patch","path":null,"pr_created_at":"2026-05-29T00:47:11.000Z","version_change":"1.5.32 → 1.5.33","issue":{"uuid":"4544795993","node_id":"PR_kwDOB20KpM7gdL_8","number":2755,"state":"closed","title":"Bump the dependencies group across 1 directory with 12 updates","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-06-01T01:13:35.000Z","author_association":null,"state_reason":null,"created_at":"2026-05-29T00:47:11.000Z","updated_at":"2026-06-01T01:13:37.000Z","time_to_close":260784,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"dependencies","update_count":12,"packages":[{"name":"org.ow2.asm:asm","old_version":"9.10","new_version":"9.10.1"},{"name":"org.ow2.asm:asm-commons","old_version":"9.10","new_version":"9.10.1"},{"name":"org.ow2.asm:asm-tree","old_version":"9.10","new_version":"9.10.1"},{"name":"org.ow2.asm:asm-util","old_version":"9.10","new_version":"9.10.1"},{"name":"com.sun.xml.bind:jaxb-core","old_version":"4.0.8","new_version":"4.0.9"},{"name":"com.sun.xml.bind:jaxb-impl","old_version":"4.0.8","new_version":"4.0.9"},{"name":"com.sun.xml.bind:jaxb-xjc","old_version":"4.0.8","new_version":"4.0.9"},{"name":"org.eclipse.parsson:parsson","old_version":"1.1.7","new_version":"1.1.9","repository_url":"https://github.com/eclipse-ee4j/parsson"},{"name":"org.mongodb:mongodb-driver-sync","old_version":"5.7.0","new_version":"5.8.0","repository_url":"https://github.com/mongodb/mongo-java-driver"},{"name":"com.oracle.nosql.sdk:nosqldriver","old_version":"5.4.21","new_version":"5.4.22","repository_url":"https://github.com/oracle/nosql-java-sdk"},{"name":"ch.qos.logback:logback-core","old_version":"1.5.32","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"},{"name":"ch.qos.logback:logback-classic","old_version":"1.5.32","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"}],"path":null,"ecosystem":"maven"},"body":"Bumps the dependencies group with 12 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| org.ow2.asm:asm | `9.10` | `9.10.1` |\n| org.ow2.asm:asm-commons | `9.10` | `9.10.1` |\n| org.ow2.asm:asm-tree | `9.10` | `9.10.1` |\n| org.ow2.asm:asm-util | `9.10` | `9.10.1` |\n| com.sun.xml.bind:jaxb-core | `4.0.8` | `4.0.9` |\n| com.sun.xml.bind:jaxb-impl | `4.0.8` | `4.0.9` |\n| com.sun.xml.bind:jaxb-xjc | `4.0.8` | `4.0.9` |\n| [org.eclipse.parsson:parsson](https://github.com/eclipse-ee4j/parsson) | `1.1.7` | `1.1.9` |\n| [org.mongodb:mongodb-driver-sync](https://github.com/mongodb/mongo-java-driver) | `5.7.0` | `5.8.0` |\n| [com.oracle.nosql.sdk:nosqldriver](https://github.com/oracle/nosql-java-sdk) | `5.4.21` | `5.4.22` |\n| [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) | `1.5.32` | `1.5.33` |\n| [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) | `1.5.32` | `1.5.33` |\n\n\nUpdates `org.ow2.asm:asm` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-commons` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-tree` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-util` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-commons` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-tree` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-util` from 9.10 to 9.10.1\n\nUpdates `com.sun.xml.bind:jaxb-core` from 4.0.8 to 4.0.9\n\nUpdates `com.sun.xml.bind:jaxb-impl` from 4.0.8 to 4.0.9\n\nUpdates `com.sun.xml.bind:jaxb-xjc` from 4.0.8 to 4.0.9\n\nUpdates `com.sun.xml.bind:jaxb-impl` from 4.0.8 to 4.0.9\n\nUpdates `com.sun.xml.bind:jaxb-xjc` from 4.0.8 to 4.0.9\n\nUpdates `org.eclipse.parsson:parsson` from 1.1.7 to 1.1.9\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/eclipse-ee4j/parsson/releases\"\u003eorg.eclipse.parsson:parsson's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.1.9\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePublish Central releases automatically by \u003ca href=\"https://github.com/jbescos\"\u003e\u003ccode\u003e@​jbescos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/171\"\u003eeclipse-ee4j/parsson#171\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/eclipse-ee4j/parsson/compare/1.1.8...1.1.9\"\u003ehttps://github.com/eclipse-ee4j/parsson/compare/1.1.8...1.1.9\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e1.1.8\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate deprecated GH actions by \u003ca href=\"https://github.com/jbescos\"\u003e\u003ccode\u003e@​jbescos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/136\"\u003eeclipse-ee4j/parsson#136\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMake JsonArrayImpl implement RandomAccess by \u003ca href=\"https://github.com/marschall\"\u003e\u003ccode\u003e@​marschall\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/135\"\u003eeclipse-ee4j/parsson#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplement JsonStructureParser.currentEvent() by \u003ca href=\"https://github.com/marschall\"\u003e\u003ccode\u003e@​marschall\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/134\"\u003eeclipse-ee4j/parsson#134\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove unused method by \u003ca href=\"https://github.com/pzygielo\"\u003e\u003ccode\u003e@​pzygielo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/137\"\u003eeclipse-ee4j/parsson#137\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRename parameter to match field by \u003ca href=\"https://github.com/pzygielo\"\u003e\u003ccode\u003e@​pzygielo\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/138\"\u003eeclipse-ee4j/parsson#138\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImplement JsonStructureParser#getValue methods by \u003ca href=\"https://github.com/marschall\"\u003e\u003ccode\u003e@​marschall\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/140\"\u003eeclipse-ee4j/parsson#140\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse assertThrows by \u003ca href=\"https://github.com/marschall\"\u003e\u003ccode\u003e@​marschall\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/142\"\u003eeclipse-ee4j/parsson#142\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix compilation failes by \u003ca href=\"https://github.com/marschall\"\u003e\u003ccode\u003e@​marschall\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/144\"\u003eeclipse-ee4j/parsson#144\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdding Dependabot for dependency management by \u003ca href=\"https://github.com/mswatosh\"\u003e\u003ccode\u003e@​mswatosh\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/148\"\u003eeclipse-ee4j/parsson#148\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ejson input size limit by \u003ca href=\"https://github.com/jbescos\"\u003e\u003ccode\u003e@​jbescos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/169\"\u003eeclipse-ee4j/parsson#169\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd Maven Central publishing release profile by \u003ca href=\"https://github.com/jbescos\"\u003e\u003ccode\u003e@​jbescos\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/170\"\u003eeclipse-ee4j/parsson#170\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/marschall\"\u003e\u003ccode\u003e@​marschall\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/135\"\u003eeclipse-ee4j/parsson#135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mswatosh\"\u003e\u003ccode\u003e@​mswatosh\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/pull/148\"\u003eeclipse-ee4j/parsson#148\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/eclipse-ee4j/parsson/compare/1.1.7...1.1.8\"\u003ehttps://github.com/eclipse-ee4j/parsson/compare/1.1.7...1.1.8\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/f7204e83adb07bfe9f722bbd914dc680b1071114\"\u003e\u003ccode\u003ef7204e8\u003c/code\u003e\u003c/a\u003e Prepare release org.eclipse.parsson:project:1.1.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/2d01f006047e05cef49d13abe5ab25d66108f71a\"\u003e\u003ccode\u003e2d01f00\u003c/code\u003e\u003c/a\u003e Publish Central releases automatically (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/171\"\u003e#171\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/10920a209563d8a0ac13ca3d41e3c6066367835f\"\u003e\u003ccode\u003e10920a2\u003c/code\u003e\u003c/a\u003e Add Maven Central publishing release profile (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/170\"\u003e#170\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/134e8d101aa74c8b9302d0cb62f6ccb4912a9d0c\"\u003e\u003ccode\u003e134e8d1\u003c/code\u003e\u003c/a\u003e json input size limit (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/169\"\u003e#169\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/0789993205ee613ad63710bd3eafb96cd97afbde\"\u003e\u003ccode\u003e0789993\u003c/code\u003e\u003c/a\u003e Adding Dependabot for dependency management (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/148\"\u003e#148\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/216b15d0e9231546fa542467f9a3732973619b26\"\u003e\u003ccode\u003e216b15d\u003c/code\u003e\u003c/a\u003e Fix compilation failes (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/144\"\u003e#144\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/34177db697ee56f8e7a41f6b5998404681baf251\"\u003e\u003ccode\u003e34177db\u003c/code\u003e\u003c/a\u003e Use assertThrows (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/142\"\u003e#142\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/9d6796013c7a526c7ac80edd690e16bb4a186dd4\"\u003e\u003ccode\u003e9d67960\u003c/code\u003e\u003c/a\u003e Implement JsonStructureParser#getValue methods (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/140\"\u003e#140\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/7c8c2444c61b6b1f44c2c2f36e6ebf905b2c7624\"\u003e\u003ccode\u003e7c8c244\u003c/code\u003e\u003c/a\u003e Rename parameter to match field (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/138\"\u003e#138\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/eclipse-ee4j/parsson/commit/4dda2e0195dcde4f11eda1c31c642d84eda50ae5\"\u003e\u003ccode\u003e4dda2e0\u003c/code\u003e\u003c/a\u003e Remove unused method (\u003ca href=\"https://redirect.github.com/eclipse-ee4j/parsson/issues/137\"\u003e#137\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/eclipse-ee4j/parsson/compare/1.1.7...1.1.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.mongodb:mongodb-driver-sync` from 5.7.0 to 5.8.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mongodb/mongo-java-driver/releases\"\u003eorg.mongodb:mongodb-driver-sync's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eJava Driver 5.8.0 (May 28, 2026)\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003e🔥 Enhancements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded typed builder API for vector search index definitions \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1960\"\u003e#1960\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003e$rerank\u003c/code\u003e aggregation stage support (MongoDB 8.3 / Atlas) \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1963\"\u003e#1963\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003evectorSearch\u003c/code\u003e operator support for the \u003ccode\u003e$search\u003c/code\u003e pipeline stage \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1962\"\u003e#1962\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003estoredSource\u003c/code\u003e support for vector search indexes and \u003ccode\u003ereturnStoredSource\u003c/code\u003e for \u003ccode\u003e$vectorSearch\u003c/code\u003e queries \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1977\"\u003e#1977\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eBinaryVector\u003c/code\u003e and \u003ccode\u003eVectorSearchQuery\u003c/code\u003e \u003ccode\u003evectorSearch\u003c/code\u003e overloads to the Scala driver \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1986\"\u003e#1986\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eOptimized \u003ccode\u003eRawBsonDocument\u003c/code\u003e encode and decode by eliminating intermediate allocations \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1988\"\u003e#1988\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePreliminary refactoring for backpressure support \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1952\"\u003e#1952\u003c/a\u003e by \u003ca href=\"https://github.com/stIncMale\"\u003e\u003ccode\u003e@​stIncMale\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSmall improvements related to value-based classes \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1964\"\u003e#1964\u003c/a\u003e by \u003ca href=\"https://github.com/stIncMale\"\u003e\u003ccode\u003e@​stIncMale\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🛠 Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed OSGi bundle resolution failure when Micrometer is not present \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1982\"\u003e#1982\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded missing Javadoc to \u003ccode\u003eMongodbObservation\u003c/code\u003e and \u003ccode\u003eMongodbObservationContext\u003c/code\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e📦 Dependency Updates\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpgraded \u003ccode\u003elibmongocrypt\u003c/code\u003e to 1.18.1 \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1983\"\u003e#1983\u003c/a\u003e by \u003ca href=\"https://github.com/strogiyotec\"\u003e\u003ccode\u003e@​strogiyotec\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🧪 Testing \u0026amp; CI\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003eAGENTS.md\u003c/code\u003e for AI coding agent support across all modules by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded test cases for new auto-embedding index fields \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1936\"\u003e#1936\u003c/a\u003e by \u003ca href=\"https://github.com/strogiyotec\"\u003e\u003ccode\u003e@​strogiyotec\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded Scala 3 to \u003ccode\u003epublish.sh\u003c/code\u003e \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1958\"\u003e#1958\u003c/a\u003e by \u003ca href=\"https://github.com/rozza\"\u003e\u003ccode\u003e@​rozza\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eNamespaceExists\u003c/code\u003e test failure \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1956\"\u003e#1956\u003c/a\u003e by \u003ca href=\"https://github.com/nhachicha\"\u003e\u003ccode\u003e@​nhachicha\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSimplified \u003ccode\u003eRetryState\u003c/code\u003e creation as preliminary backpressure work \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1961\"\u003e#1961\u003c/a\u003e by \u003ca href=\"https://github.com/stIncMale\"\u003e\u003ccode\u003e@​stIncMale\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMade \u003ccode\u003eRetryState.isLastAttempt\u003c/code\u003e private and simplified code \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1967\"\u003e#1967\u003c/a\u003e by \u003ca href=\"https://github.com/stIncMale\"\u003e\u003ccode\u003e@​stIncMale\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/techbelle\"\u003e\u003ccode\u003e@​techbelle\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/1972\"\u003emongodb/mongo-java-driver#1972\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVerifying artifact signatures\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://www.mongodb.com/docs/drivers/java/sync/current/security/validate-signatures/\"\u003ehttps://www.mongodb.com/docs/drivers/java/sync/current/security/validate-signatures/\u003c/a\u003e for the full procedure.\u003c/p\u003e\n\u003cp\u003eTo download and import the public key for verifying signatures, execute\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003egpg --keyserver hkps://keyserver.ubuntu.com --recv-keys 1a75005e142192223d6a7c3b76e0008d166740a8\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/mongodb/mongo-java-driver/compare/r5.7.0...r5.8.0\"\u003ehttps://github.com/mongodb/mongo-java-driver/compare/r5.7.0...r5.8.0\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/6024ca9f6ca226cffb7526659b19810707970310\"\u003e\u003ccode\u003e6024ca9\u003c/code\u003e\u003c/a\u003e Version: bump 5.8.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/f3bbdb2701b8c462c64db4c5f3f2c61b23b723e9\"\u003e\u003ccode\u003ef3bbdb2\u003c/code\u003e\u003c/a\u003e Add BinaryVector and VectorSearchQuery vectorSearch overloads to Scala driver...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/966ababa45a5d38a644bc8e8ce8de58eb882dd66\"\u003e\u003ccode\u003e966abab\u003c/code\u003e\u003c/a\u003e Upgrade libmongocrypt version to 1.18.1 (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/1983\"\u003e#1983\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/98e07611f0f0c3e22d89cfb766137e59ab7b2a2f\"\u003e\u003ccode\u003e98e0761\u003c/code\u003e\u003c/a\u003e Optimize RawBsonDocument encode and decode by eliminating intermediate alloca...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/40ee8d511e4541727de2edc4527d209d842fd607\"\u003e\u003ccode\u003e40ee8d5\u003c/code\u003e\u003c/a\u003e Fix NamespaceExists test failure (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/1956\"\u003e#1956\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/541af753642b070a04ec64f54b9af018d297c2d3\"\u003e\u003ccode\u003e541af75\u003c/code\u003e\u003c/a\u003e Mark micrometer OSGi imports as optional and add bundle resolution test (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/1982\"\u003e#1982\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/cd6c045cf866d6d5038fcbcf8825742174a3903a\"\u003e\u003ccode\u003ecd6c045\u003c/code\u003e\u003c/a\u003e Add storedSource support for vector search indexes and returnStoredSource for...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/717da9c63b5531e35e684bc0a8043500b3fa7560\"\u003e\u003ccode\u003e717da9c\u003c/code\u003e\u003c/a\u003e Revert \u0026quot;Resolve TLS channel address before opening socket\u0026quot; (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/1979\"\u003e#1979\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/58122f6b280cda429af25f69e3692132e1eabb60\"\u003e\u003ccode\u003e58122f6\u003c/code\u003e\u003c/a\u003e Add vectorSearch operator for $search pipeline stage (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/1962\"\u003e#1962\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/13d4aef5f58283977042340ee8d7d9af4a1786d4\"\u003e\u003ccode\u003e13d4aef\u003c/code\u003e\u003c/a\u003e Resolve TLS channel address before opening socket\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mongodb/mongo-java-driver/compare/r5.7.0...r5.8.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.oracle.nosql.sdk:nosqldriver` from 5.4.21 to 5.4.22\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/oracle/nosql-java-sdk/releases\"\u003ecom.oracle.nosql.sdk:nosqldriver's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e5.4.22\u003c/h2\u003e\n\u003ch2\u003e[5.4.22] 2026-05-15\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded redaction of sensitive HTTP header values in debug logging by default,\nplus the \u003ccode\u003ecom.oracle.nosql.sdk.nosqldriver.log-sensitive-headers\u003c/code\u003e system\nproperty to allow full header values when needed for debugging.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed bug in handling of empty namespaces in prepared statements.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated Netty version to 4.1.133.Final\u003c/li\u003e\n\u003cli\u003eUpdated Jackson-core to 2.18.7\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/oracle/nosql-java-sdk/blob/main/CHANGELOG.md\"\u003ecom.oracle.nosql.sdk:nosqldriver's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e[5.4.22] 2026-05-15\u003c/h2\u003e\n\u003ch3\u003eAdded\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded redaction of sensitive HTTP header values in debug logging by default,\nplus the \u003ccode\u003ecom.oracle.nosql.sdk.nosqldriver.log-sensitive-headers\u003c/code\u003e system\nproperty to allow full header values when needed for debugging.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eFixed\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed bug in handling of empty namespaces in prepared statements.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanged\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eUpdated Netty version to 4.1.133.Final\u003c/li\u003e\n\u003cli\u003eUpdated Jackson-core to 2.18.7\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/801ba4070febb5c0e870ab8cdb5ee7938831a545\"\u003e\u003ccode\u003e801ba40\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/oracle/nosql-java-sdk/issues/204\"\u003e#204\u003c/a\u003e from oracle/fix/netty-4.1.133\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/d7c7ed22b8c9437041dc473577d899dcf984db31\"\u003e\u003ccode\u003ed7c7ed2\u003c/code\u003e\u003c/a\u003e additional changes for 5.4.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/e27f8f7c19a457ebdb8cd8130db61f75064ccc43\"\u003e\u003ccode\u003ee27f8f7\u003c/code\u003e\u003c/a\u003e update 3rd parties\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/0c21037e61f44fac98af2e52b2506c3a0bcb9028\"\u003e\u003ccode\u003e0c21037\u003c/code\u003e\u003c/a\u003e Handle null or empty namespace list in prepared statements (\u003ca href=\"https://redirect.github.com/oracle/nosql-java-sdk/issues/200\"\u003e#200\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/b81457b2e65e323c30cda83d6ce7cee8cb771a83\"\u003e\u003ccode\u003eb81457b\u003c/code\u003e\u003c/a\u003e Moving to 5.4.22-SNAPSHOT (\u003ca href=\"https://redirect.github.com/oracle/nosql-java-sdk/issues/199\"\u003e#199\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/6248e8b0d53c269a888bc335faeede7c5619f323\"\u003e\u003ccode\u003e6248e8b\u003c/code\u003e\u003c/a\u003e implemented UNION (and a few other query operators) (\u003ca href=\"https://redirect.github.com/oracle/nosql-java-sdk/issues/184\"\u003e#184\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/d09ae8bbcdd1ae459d80ad269c2ef1ff33ed65cd\"\u003e\u003ccode\u003ed09ae8b\u003c/code\u003e\u003c/a\u003e Cleaned up compiler warnings\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/7f8a40f0c92b0a63e7c2d81f65daa03971b2b38d\"\u003e\u003ccode\u003e7f8a40f\u003c/code\u003e\u003c/a\u003e Redact sensitive HTTP headers in debug logging (\u003ca href=\"https://redirect.github.com/oracle/nosql-java-sdk/issues/198\"\u003e#198\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/oracle/nosql-java-sdk/commit/4a3e9e5298a11450a9fe85a5857c2a0e75686c2a\"\u003e\u003ccode\u003e4a3e9e5\u003c/code\u003e\u003c/a\u003e Preparing for 5.4.21 release (\u003ca href=\"https://redirect.github.com/oracle/nosql-java-sdk/issues/196\"\u003e#196\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/oracle/nosql-java-sdk/compare/v5.4.21...v5.4.22\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ch.qos.logback:logback-core` from 1.5.32 to 1.5.33\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ch.qos.logback:logback-classic` from 1.5.32 to 1.5.33\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-classic's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `ch.qos.logback:logback-classic` from 1.5.32 to 1.5.33\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-classic's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.33\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-05-27 Release of logback version 1.5.33\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003ePropertiesConfiguratorModelHandler\u003c/code\u003e now registers properties file URLs to the \u003ccode\u003eConfigurationWatchList\u003c/code\u003e when scan is enabled (via local scan=\u0026quot;true\u0026quot; attribute or top-level configuration scan), ensuring changes are detected and reconfiguration occurs. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1034\"\u003eissues/1034\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• When processing \u003ccode\u003e\u0026lt;conversionRule\u0026gt;\u003c/code\u003e elements and both \u003ccode\u003eclass\u003c/code\u003e and \u003ccode\u003econverterClass\u003c/code\u003e attributes are specified, silently use the class attribute without issuing a warning. However, if the attribute values differ, a warning will be issued. This change was requested in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1031\"\u003eissues/1031\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• \u003ccode\u003eHardenedModelInputStream\u003c/code\u003e will no longer accept to deserialize all classes located under the \u0026quot;java.lang\u0026quot; and \u0026quot;java.util\u0026quot; packages but a limited number of explicitly authorized classes in those packages. This potential deserialization whitelist bypass vulnerability was reported by \u003ca href=\"https://github.com/york-shen\"\u003eYork Shen\u003c/a\u003e and registered as \u003ca href=\"https://www.cve.org/cverecord?id=CVE-2026-9828\"\u003eCVE-2026-9828\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• SSL parameters for \u003ccode\u003eSSLSocketAppender\u003c/code\u003e now enable hostname verification by default. Moreover, the default protocol is now \u0026quot;TLSv1.2\u0026quot;. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• When printing the status message field, \u003ccode\u003eViewStatusMessagesServletBase\u003c/code\u003e now escapes special characters such as \u0026quot;\u0026amp;\u0026quot; as character entities. This potential vulnerability was reported by York Shen.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 124e8b49b55ac34d08743a0646bd463410192647 associated with the tag v_1.5.33. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/eclipse-ee4j/eclipselink/pull/2755","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/eclipse-ee4j%2Feclipselink/issues/2755","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2755/packages"}},{"old_version":"1.5.24","new_version":"1.5.33","update_type":"patch","path":null,"pr_created_at":"2026-05-28T05:47:04.000Z","version_change":"1.5.24 → 1.5.33","issue":{"uuid":"4538035108","node_id":"PR_kwDOHk7hlc7gHCcO","number":900,"state":"closed","title":"chore(deps): bump ch.qos.logback:logback-core from 1.5.24 to 1.5.33","user":"dependabot[bot]","labels":["dependencies"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-06-04T05:42:22.000Z","author_association":null,"state_reason":null,"created_at":"2026-05-28T05:47:04.000Z","updated_at":"2026-06-04T05:42:24.000Z","time_to_close":604518,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"ch.qos.logback:logback-core","old_version":"1.5.24","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"}],"path":null,"ecosystem":"maven"},"body":"Bumps [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) from 1.5.24 to 1.5.33.\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/qos-ch/logback/releases\"\u003ech.qos.logback:logback-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eLogback 1.5.32\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-16 Release of logback version 1.5.32\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In \u003ccode\u003eDefaultProcessor, \u003c/code\u003efixed incorrect check for dependencies contained within a parent model. Previous only the direct children were scanned. This fixes \u003ca href=\"https://redirect.github.com/qos-ch/logback-access/issues/34\"\u003elogback-access/issues/34\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit e807335a67535b4eacce94e942c0bcb649665d93 associated with the tag v_1.5.32. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback  1.5.31\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback version 1.5.31\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fixed missing META-INF/services directory in logback-classic.jar. This issue rendered logback-classic version 1.5.30 unusable with SLF4J.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 168e42f9f9a18a3ffdf31eb2bfe80a71e33ecd8b associated with the tag v_1.5.31. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.30\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-14 Release of logback  version 1.5.30\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• \u003cstrong\u003eIn this version, logback-classic.jar was missing the META-INF/services directory, making it unusable with SLF4J. Version 1.5.31 (released later on the same day) fixes this issue.\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Fix scanning issue when an included file becomes available at a later time. This problem was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1021\"\u003eissues/1021\u003c/a\u003e by Sergey Nazarov.\u003c/p\u003e\n\u003cp\u003e• Standardized code for version checking across modules.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit 44164f10ca3fb44ce0e68519f13564b87e3aca61 associated with the tag v_1.5.30. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.29\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-09 Release of logback version 1.5.29\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• In response to \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1017\"\u003eissues/1017\u003c/a\u003e, appender names and appender references are once again subject to variable substitution, reverting the change introduced in version 1.5.28.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.28\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-02-06 Release of logback version 1.5.28\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Appender names or appender references are no longer subject to variable substitution.\u003c/p\u003e\n\u003cp\u003e• Fixed issue with configurations with conditionals encompassing appenders. This was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1016\"\u003eissues/1016\u003c/a\u003e reported by Sergey Sazonov.\u003c/p\u003e\n\u003cp\u003e• The \u003c!-- raw HTML omitted --\u003e element now admits a 'scan' attribute which can be used to override the 'scan' attribute in the \u003c!-- raw HTML omitted --\u003e element.\u003c/p\u003e\n\u003cp\u003e• Fixed NullPointerException thrown by VersionUtil.checkForVersionEquality method occurring with GraalVM Native Images. This issue was reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1014\"\u003eissues/1014\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003e• A bit-wise identical binary of this version can be reproduced by building from source code at commit e7a1855ab562bb102333f754603ff89359bf3cfc associated with the tag v_1.5.28. Release built using Java \u0026quot;21\u0026quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.\u003c/p\u003e\n\u003ch2\u003eLogback 1.5.27\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003e2026-01-30 Release of logback version 1.5.27\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e• Updated license to Eclipse Public License version 2.0 from version 1.0, retaining the GPL 2.1 dual-license.\u003c/p\u003e\n\u003cp\u003e• Fixed missing MDC data transmitted by \u003ccode\u003eSocketAppender\u003c/code\u003e reported in \u003ca href=\"https://redirect.github.com/qos-ch/logback/issues/1010\"\u003eissues/1010\u003c/a\u003e by Lars Vogel.\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.24...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-core\u0026package-manager=maven\u0026previous-version=1.5.24\u0026new-version=1.5.33)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/wwjiang007/shiro/pull/900","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/wwjiang007%2Fshiro/issues/900","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/900/packages"}},{"old_version":"1.5.32","new_version":"1.5.33","update_type":"patch","path":null,"pr_created_at":"2026-05-27T20:59:03.000Z","version_change":"1.5.32 → 1.5.33","issue":{"uuid":"4535692638","node_id":"PR_kwDOAB81F87f_cIU","number":15176,"state":"closed","title":"[12.1.x EE8] Bump the dev-dependencies group across 1 directory with 11 updates","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-05-30T01:02:29.000Z","author_association":null,"state_reason":null,"created_at":"2026-05-27T20:59:03.000Z","updated_at":"2026-05-30T01:02:31.000Z","time_to_close":187406,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"[12.1.x EE8] Bump","group_name":"dev-dependencies","update_count":11,"packages":[{"name":"org.ow2.asm:asm","old_version":"9.10","new_version":"9.10.1"},{"name":"org.ow2.asm:asm-commons","old_version":"9.10","new_version":"9.10.1"},{"name":"org.ow2.asm:asm-bom","old_version":"9.10","new_version":"9.10.1"},{"name":"org.apache.maven.surefire:surefire-junit47","old_version":"3.5.5","new_version":"3.5.6"},{"name":"io.netty:netty-bom","old_version":"4.2.13.Final","new_version":"4.2.14.Final","repository_url":"https://github.com/netty/netty"},{"name":"org.hibernate.search:hibernate-search-bom","old_version":"8.3.1.Final","new_version":"8.4.0.Final","repository_url":"https://github.com/hibernate/hibernate-search"},{"name":"org.junit:junit-bom","old_version":"6.0.3","new_version":"6.1.0","repository_url":"https://github.com/junit-team/junit-framework"},{"name":"ch.qos.logback:logback-core","old_version":"1.5.32","new_version":"1.5.33","repository_url":"https://github.com/qos-ch/logback"},{"name":"org.codehaus.plexus:plexus-classworlds","old_version":"2.11.0","new_version":"2.12.0","repository_url":"https://github.com/codehaus-plexus/plexus-classworlds"},{"name":"org.apache.maven.extensions:maven-build-cache-extension","old_version":"1.2.2","new_version":"1.2.3","repository_url":"https://github.com/apache/maven-build-cache-extension"}],"path":null,"ecosystem":"maven"},"body":"Bumps the dev-dependencies group with 10 updates in the /jetty-ee8 directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| org.ow2.asm:asm | `9.10` | `9.10.1` |\n| org.ow2.asm:asm-commons | `9.10` | `9.10.1` |\n| org.ow2.asm:asm-bom | `9.10` | `9.10.1` |\n| org.apache.maven.surefire:surefire-junit47 | `3.5.5` | `3.5.6` |\n| [io.netty:netty-bom](https://github.com/netty/netty) | `4.2.13.Final` | `4.2.14.Final` |\n| [org.hibernate.search:hibernate-search-bom](https://github.com/hibernate/hibernate-search) | `8.3.1.Final` | `8.4.0.Final` |\n| [org.junit:junit-bom](https://github.com/junit-team/junit-framework) | `6.0.3` | `6.1.0` |\n| [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) | `1.5.32` | `1.5.33` |\n| [org.codehaus.plexus:plexus-classworlds](https://github.com/codehaus-plexus/plexus-classworlds) | `2.11.0` | `2.12.0` |\n| [org.apache.maven.extensions:maven-build-cache-extension](https://github.com/apache/maven-build-cache-extension) | `1.2.2` | `1.2.3` |\n\n\nUpdates `org.ow2.asm:asm` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-commons` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-bom` from 9.10 to 9.10.1\n\nUpdates `org.ow2.asm:asm-commons` from 9.10 to 9.10.1\n\nUpdates `org.apache.maven.surefire:surefire-junit47` from 3.5.5 to 3.5.6\n\nUpdates `io.netty:netty-bom` from 4.2.13.Final to 4.2.14.Final\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/netty/netty/releases\"\u003eio.netty:netty-bom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003enetty-4.2.14.Final\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eHTTP: Fix revapi failure introduced by 84530fa81e12dcd1d42310bb20c1385cb44128d8 by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16748\"\u003enetty/netty#16748\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHTTP: Re-add constructor to HttpProxyHandler that was removed by mistake by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16747\"\u003enetty/netty#16747\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMarshalling: Explicit document security requirements by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16752\"\u003enetty/netty#16752\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix io_uring op completion TRACE logging by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16755\"\u003enetty/netty#16755\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eQuic: Ensure writes are done before notify close promise of QuicheQui… by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16758\"\u003enetty/netty#16758\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAvoid re-parsing openssl key material with non-cached provider by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16759\"\u003enetty/netty#16759\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin HTTP/RTSP version + method normalization to Locale.US by \u003ca href=\"https://github.com/daguimu\"\u003e\u003ccode\u003e@​daguimu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16765\"\u003enetty/netty#16765\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFill MsgHdrMemoryArray#hdrs with null entry on release by \u003ca href=\"https://github.com/tsegismont\"\u003e\u003ccode\u003e@​tsegismont\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16764\"\u003enetty/netty#16764\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRevapi: Use default \u0026quot;oldVersion\u0026quot; by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16774\"\u003enetty/netty#16774\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdaptive: Fix concurrency issue in adaptive allocator by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16767\"\u003enetty/netty#16767\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAuto-port 4.2: Make bulk byte moving in ByteBuf faster by \u003ca href=\"https://github.com/netty-project-bot\"\u003e\u003ccode\u003e@​netty-project-bot\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16781\"\u003enetty/netty#16781\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin multipart Content-Type / Content-Transfer-Encoding case folding to Locale.US by \u003ca href=\"https://github.com/daguimu\"\u003e\u003ccode\u003e@​daguimu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16768\"\u003enetty/netty#16768\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove dead native declarations by \u003ca href=\"https://github.com/pandareen\"\u003e\u003ccode\u003e@​pandareen\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16783\"\u003enetty/netty#16783\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIsolate tests that modify available Security providers by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16793\"\u003enetty/netty#16793\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove test annotations from a method that isn't a test by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16792\"\u003enetty/netty#16792\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eEnable OpenSslCachingKeyMaterialProvider to evict stale entries after cert rotation by \u003ca href=\"https://github.com/zhangweikop\"\u003e\u003ccode\u003e@​zhangweikop\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16523\"\u003enetty/netty#16523\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIoUring: extend user data from short to long by \u003ca href=\"https://github.com/dreamlike-ocean\"\u003e\u003ccode\u003e@​dreamlike-ocean\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16682\"\u003enetty/netty#16682\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRevert CompositeByteBuf component search fast path by \u003ca href=\"https://github.com/yawkat\"\u003e\u003ccode\u003e@​yawkat\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16811\"\u003enetty/netty#16811\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHTTP2: Use 100 as default max concurrent streams setting by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16804\"\u003enetty/netty#16804\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix ResumptionController wrapping by \u003ca href=\"https://github.com/chrisvest\"\u003e\u003ccode\u003e@​chrisvest\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16815\"\u003enetty/netty#16815\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eResolve all localhost addresses without querying DNS servers by \u003ca href=\"https://github.com/JulianVennen\"\u003e\u003ccode\u003e@​JulianVennen\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16749\"\u003enetty/netty#16749\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIpFilter: Fix ClassCastException caused by IpSubnetFilter if only ipv6 rules are configured but remote peer is using ipv4 by \u003ca href=\"https://github.com/normanmaurer\"\u003e\u003ccode\u003e@​normanmaurer\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16803\"\u003enetty/netty#16803\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix memoryAddress() for direct ByteBuffers wrapped by Unpooled without Unsafe by \u003ca href=\"https://github.com/dreamlike-ocean\"\u003e\u003ccode\u003e@​dreamlike-ocean\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16788\"\u003enetty/netty#16788\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRoute synchronous onLookupComplete exceptions via fireExceptionCaught by \u003ca href=\"https://github.com/kwondh5217\"\u003e\u003ccode\u003e@​kwondh5217\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16794\"\u003enetty/netty#16794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIoUring: Stop generic FileRegion drain loop when transferred() reaches count() by \u003ca href=\"https://github.com/LuciferYang\"\u003e\u003ccode\u003e@​LuciferYang\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16826\"\u003enetty/netty#16826\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMQTT: Allow MQTT 5 CONNECT with password only by \u003ca href=\"https://github.com/shblue21\"\u003e\u003ccode\u003e@​shblue21\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16833\"\u003enetty/netty#16833\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix MQTT decoder size check after variable header replay by \u003ca href=\"https://github.com/daguimu\"\u003e\u003ccode\u003e@​daguimu\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16787\"\u003enetty/netty#16787\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pandareen\"\u003e\u003ccode\u003e@​pandareen\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16783\"\u003enetty/netty#16783\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/zhangweikop\"\u003e\u003ccode\u003e@​zhangweikop\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16523\"\u003enetty/netty#16523\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JulianVennen\"\u003e\u003ccode\u003e@​JulianVennen\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16749\"\u003enetty/netty#16749\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kwondh5217\"\u003e\u003ccode\u003e@​kwondh5217\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16794\"\u003enetty/netty#16794\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/shblue21\"\u003e\u003ccode\u003e@​shblue21\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/netty/netty/pull/16833\"\u003enetty/netty#16833\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/netty/netty/compare/netty-4.2.13.Final...netty-4.2.14.Final\"\u003ehttps://github.com/netty/netty/compare/netty-4.2.13.Final...netty-4.2.14.Final\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/0a60b753d5b0de9f58e245538d61c11dc6cfc4b2\"\u003e\u003ccode\u003e0a60b75\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release netty-4.2.14.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/72df658e5fdd1cc6d65bce1e0917ec31a9560269\"\u003e\u003ccode\u003e72df658\u003c/code\u003e\u003c/a\u003e Fix MQTT decoder size check after variable header replay (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16787\"\u003e#16787\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/7125dba6b20822aa72dd8359b350c2f3b9a545d9\"\u003e\u003ccode\u003e7125dba\u003c/code\u003e\u003c/a\u003e MQTT: Allow MQTT 5 CONNECT with password only (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16833\"\u003e#16833\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/9e19320a5855746970d05a5cd785d73a17cc694d\"\u003e\u003ccode\u003e9e19320\u003c/code\u003e\u003c/a\u003e IoUring: Stop generic FileRegion drain loop when transferred() reaches count(...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/4ce9f17f05c67b72c87bc83951800bad245fe162\"\u003e\u003ccode\u003e4ce9f17\u003c/code\u003e\u003c/a\u003e Route synchronous onLookupComplete exceptions via fireExceptionCaught (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16794\"\u003e#16794\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/f7b1b7de625031cc60e6eaecb889c97303588759\"\u003e\u003ccode\u003ef7b1b7d\u003c/code\u003e\u003c/a\u003e Fix memoryAddress() for direct ByteBuffers wrapped by Unpooled without Unsafe...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/0ccb265cadf91b2e09c2f479c9194d193d7a5dbc\"\u003e\u003ccode\u003e0ccb265\u003c/code\u003e\u003c/a\u003e IpFilter: Fix ClassCastException caused by IpSubnetFilter if only ipv6 rules ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/a6aeb6deffda3e45904edd05abc5cdddcd438794\"\u003e\u003ccode\u003ea6aeb6d\u003c/code\u003e\u003c/a\u003e Resolve all localhost addresses without querying DNS servers (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16749\"\u003e#16749\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/c328ba2ab89d2c90c80be1d2de1cfbb8f94c438b\"\u003e\u003ccode\u003ec328ba2\u003c/code\u003e\u003c/a\u003e Fix ResumptionController wrapping (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16815\"\u003e#16815\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/netty/netty/commit/bc5862ba488c569c888d3b82048083041f66e880\"\u003e\u003ccode\u003ebc5862b\u003c/code\u003e\u003c/a\u003e HTTP2: Use 100 as default max concurrent streams setting (\u003ca href=\"https://redirect.github.com/netty/netty/issues/16804\"\u003e#16804\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/netty/netty/compare/netty-4.2.13.Final...netty-4.2.14.Final\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.hibernate.search:hibernate-search-bom` from 8.3.1.Final to 8.4.0.Final\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hibernate/hibernate-search/releases\"\u003eorg.hibernate.search:hibernate-search-bom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 8.4.0.Final\u003c/h2\u003e\n\u003ch1\u003eHibernate Search 8.4.0.Final released\u003c/h1\u003e\n\u003cp\u003eWe are pleased to announce the release of Hibernate Search 8.4: 8.4.0.Final.\u003c/p\u003e\n\u003cp\u003eYou can find the full list of 8.4.0.Final changes \u003ca href=\"https://hibernate.atlassian.net/issues/?jql=project%20%3D%20HSEARCH%20AND%20fixVersion%20%3D%208.4.0.Final\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eWhat's new\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSee the \u003ca href=\"https://hibernate.org/search/releases/8.4\"\u003ewebsite\u003c/a\u003e for requirements and compatibilities.\u003c/li\u003e\n\u003cli\u003eSee the \u003ca href=\"https://docs.hibernate.org/search/8.4/whats-new/en-US/html_single/\"\u003eWhat's New\u003c/a\u003e guide for details about new features and capabilities.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eConclusion\u003c/h2\u003e\n\u003cp\u003eFor additional details, see:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe \u003ca href=\"https://hibernate.org/search/releases/8.4/\"\u003erelease page\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/migration/html_single/\"\u003eMigration Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/getting-started/orm/en-US/html_single/\"\u003eORM Getting Started Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/getting-started/standalone/en-US/html_single/\"\u003eStandalone Getting Started Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/reference/en-US/html_single/\"\u003eReference Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/api\"\u003eAPI docs\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eVisit the \u003ca href=\"https://hibernate.org/community/\"\u003ewebsite\u003c/a\u003e for details on getting in touch with us.\u003c/p\u003e\n\u003ch2\u003eRelease 8.4.0.CR1\u003c/h2\u003e\n\u003ch1\u003eHibernate Search 8.4.0.CR1 released\u003c/h1\u003e\n\u003cp\u003eWe are pleased to announce the release of Hibernate Search 8.4: 8.4.0.CR1.\u003c/p\u003e\n\u003cp\u003eYou can find the full list of 8.4.0.CR1 changes \u003ca href=\"https://hibernate.atlassian.net/issues/?jql=project%20%3D%20HSEARCH%20AND%20fixVersion%20%3D%208.4.0.CR1\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eWhat's new\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSee the \u003ca href=\"https://hibernate.org/search/releases/8.4\"\u003ewebsite\u003c/a\u003e for requirements and compatibilities.\u003c/li\u003e\n\u003cli\u003eSee the \u003ca href=\"https://docs.hibernate.org/search/8.4/whats-new/en-US/html_single/\"\u003eWhat's New\u003c/a\u003e guide for details about new features and capabilities.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eConclusion\u003c/h2\u003e\n\u003cp\u003eFor additional details, see:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe \u003ca href=\"https://hibernate.org/search/releases/8.4/\"\u003erelease page\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/migration/html_single/\"\u003eMigration Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/getting-started/orm/en-US/html_single/\"\u003eORM Getting Started Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/getting-started/standalone/en-US/html_single/\"\u003eStandalone Getting Started Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/search/8.4/reference/en-US/html_single/\"\u003eReference Guide\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hibernate/hibernate-search/blob/main/changelog.txt\"\u003eorg.hibernate.search:hibernate-search-bom's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e8.4.0.Final (2026-05-27)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://hibernate.atlassian.net/projects/HSEARCH/versions/39072\"\u003ehttps://hibernate.atlassian.net/projects/HSEARCH/versions/39072\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e** Improvement\n* HSEARCH-5630 Update to Hibernate ORM 7.4.0.Final\n* HSEARCH-5629 Use Maven 3.9.16 as a required minimum version for the build\n* HSEARCH-5627 Switch from the Search session holder to a Hibernate ORM session extension\n* HSEARCH-5626 Update Elasticsearch client (elasticsearch-rest-client) to 9.4.1\n* HSEARCH-5625 Test against latest Elasticsearch 9.4.1\n* HSEARCH-5624 Update Elasticsearch client (elasticsearch-rest5-client) to 9.4.1\u003c/p\u003e\n\u003ch2\u003e8.4.0.CR1 (2026-05-11)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://hibernate.atlassian.net/projects/HSEARCH/versions/37437\"\u003ehttps://hibernate.atlassian.net/projects/HSEARCH/versions/37437\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003e** Bug\n* HSEARCH-5595 \u003ccode\u003echeckstyle:check\u003c/code\u003e is not build cache relocatable due to project resources including the workspace root\u003c/p\u003e\n\u003cp\u003e** Improvement\n* HSEARCH-5623 Update to Hibernate ORM 7.4.0.CR1\n* HSEARCH-5622 Update Elasticsearch client (elasticsearch-rest5-client) to 9.4.0\n* HSEARCH-5621 Update Elasticsearch client (elasticsearch-rest-client) to 9.4.0\n* HSEARCH-5620 Add compatibility with Elasticsearch 9.4\n* HSEARCH-5619 Upgrade to GSON 2.14.0\n* HSEARCH-5618 Update Jackson to 2.21.3\n* HSEARCH-5617 Update to AWS SDK 2.44.1\n* HSEARCH-5616 Update Elasticsearch client (elasticsearch-rest-client) to 9.3.4\n* HSEARCH-5613 Use Maven 3.9.15 as a required minimum version for the build\n* HSEARCH-5612 Upgrade to commons-codec 1.22.0\n* HSEARCH-5611 Update Apache HTTP Client components to 5.6.1\n* HSEARCH-5609 Update Elasticsearch client (elasticsearch-rest-client) to 9.3.3\n* HSEARCH-5608 Update Elasticsearch client (elasticsearch-rest5-client) to 9.3.4\n* HSEARCH-5607 Update Elasticsearch rest client (opensearch-rest-client) to 3.6.0\n* HSEARCH-5606 Add compatibility with OpenSearch 3.6\n* HSEARCH-5601 Update to commons-logging to 1.3.6\n* HSEARCH-5600 Update Jackson to 2.21.2\n* HSEARCH-5599 Update Apache HTTP Core client components to 5.4.2\n* HSEARCH-5598 Update Elasticsearch client (elasticsearch-rest-client) to 9.3.2\n* HSEARCH-5597 Update Elasticsearch client (elasticsearch-rest5-client) to 9.3.3\u003c/p\u003e\n\u003cp\u003e** Task\n* HSEARCH-5596 Use changeDetection config option instead of the deprecated overwrite in maven-resources-plugin\n* HSEARCH-5280 Look into \u003ccode\u003eOutboxPollingAutomaticIndexingDynamicShardingRebalancingIT#agentJoined\u003c/code\u003e test\n* HSEARCH-5242 Investigate why building hibernate-search-integrationtest-performance-backend-lucene fails on some envs\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/7369a18fc526aaffba13336fdcdc95a333702b19\"\u003e\u003ccode\u003e7369a18\u003c/code\u003e\u003c/a\u003e [Jenkins release job] Preparing release 8.4.0.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/4e26c085ba83c21cde89022a2f10864b08711e25\"\u003e\u003ccode\u003e4e26c08\u003c/code\u003e\u003c/a\u003e [Jenkins release job] changelog.txt updated by release build 8.4.0.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/fe410d2d5c25d9e05648f67c027441564a32be03\"\u003e\u003ccode\u003efe410d2\u003c/code\u003e\u003c/a\u003e HSEARCH-5630 Add a few migration notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/87335b65fd124493bf91ad83de78f64eafc1155c\"\u003e\u003ccode\u003e87335b6\u003c/code\u003e\u003c/a\u003e HSEARCH-5630 Update to Hibernate ORM 7.4.0.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/58d6af143d22c9ce55872c9f13c51c8dd8e03d32\"\u003e\u003ccode\u003e58d6af1\u003c/code\u003e\u003c/a\u003e HSEARCH-5624 Update Elasticsearch client (elasticsearch-rest5-client) to 9.4.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/9efe369fcb419ded47b3e77a02b3d84451e64853\"\u003e\u003ccode\u003e9efe369\u003c/code\u003e\u003c/a\u003e Bump the build-dependencies group with 4 updates\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/bc1c18509b22d2b1fa9e41149fbe5cf166d7f663\"\u003e\u003ccode\u003ebc1c185\u003c/code\u003e\u003c/a\u003e Use the ssh URL for updating the website during the release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/311adb00224ab04fc2c397da94cf41a373338801\"\u003e\u003ccode\u003e311adb0\u003c/code\u003e\u003c/a\u003e HSEARCH-5627 Mention limitations of a StatelessSession\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/d429b05110cf6015d70faa6278176c6b3e7defa0\"\u003e\u003ccode\u003ed429b05\u003c/code\u003e\u003c/a\u003e HSEARCH-5627 Better error message for \u0026quot;incompatible\u0026quot; session types\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-search/commit/2eaeb282d9d9bc136bc32f93ca12634374e249d4\"\u003e\u003ccode\u003e2eaeb28\u003c/code\u003e\u003c/a\u003e HSEARCH-5627 Add a simple StatelessSession test\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hibernate/hibernate-search/compare/8.3.1.Final...8.4.0.Final\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.junit:junit-bom` from 6.0.3 to 6.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/junit-team/junit-framework/releases\"\u003eorg.junit:junit-bom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eJUnit 6.1.0 = Platform 6.1.0 + Jupiter 6.1.0 + Vintage 6.1.0\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0/release-notes.html\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JarvisCraft\"\u003e\u003ccode\u003e@​JarvisCraft\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5633\"\u003ejunit-team/junit-framework#5633\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Maran23\"\u003e\u003ccode\u003e@​Maran23\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5644\"\u003ejunit-team/junit-framework#5644\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eJUnit 6.1.0-RC1 = Platform 6.1.0-RC1 + Jupiter 6.1.0-RC1 + Vintage 6.1.0-RC1\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0-RC1/release-notes/\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mariokhoury4\"\u003e\u003ccode\u003e@​mariokhoury4\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/4574\"\u003ejunit-team/junit-framework#4574\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Ogu1208\"\u003e\u003ccode\u003e@​Ogu1208\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5145\"\u003ejunit-team/junit-framework#5145\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/HyungGeun94\"\u003e\u003ccode\u003e@​HyungGeun94\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5271\"\u003ejunit-team/junit-framework#5271\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yalishevant\"\u003e\u003ccode\u003e@​yalishevant\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5316\"\u003ejunit-team/junit-framework#5316\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JINU-CHANG\"\u003e\u003ccode\u003e@​JINU-CHANG\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5290\"\u003ejunit-team/junit-framework#5290\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jaschdoc\"\u003e\u003ccode\u003e@​jaschdoc\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5427\"\u003ejunit-team/junit-framework#5427\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kawshikbuet17\"\u003e\u003ccode\u003e@​kawshikbuet17\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5561\"\u003ejunit-team/junit-framework#5561\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/msridhar\"\u003e\u003ccode\u003e@​msridhar\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5602\"\u003ejunit-team/junit-framework#5602\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.1.0-M1...r6.1.0-RC1\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.1.0-M1...r6.1.0-RC1\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eJUnit 6.1.0-M1 = Platform 6.1.0-M1 + Jupiter 6.1.0-M1 + Vintage 6.1.0-M1\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0-M1/release-notes/\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vy\"\u003e\u003ccode\u003e@​vy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5041\"\u003ejunit-team/junit-framework#5041\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Pankraz76\"\u003e\u003ccode\u003e@​Pankraz76\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5006\"\u003ejunit-team/junit-framework#5006\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/arukiidou\"\u003e\u003ccode\u003e@​arukiidou\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5066\"\u003ejunit-team/junit-framework#5066\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/laeubi\"\u003e\u003ccode\u003e@​laeubi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5092\"\u003ejunit-team/junit-framework#5092\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jihun4452\"\u003e\u003ccode\u003e@​jihun4452\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5088\"\u003ejunit-team/junit-framework#5088\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TWiStErRob\"\u003e\u003ccode\u003e@​TWiStErRob\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5133\"\u003ejunit-team/junit-framework#5133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.0...r6.1.0-M1\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.0.0...r6.1.0-M1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0dc3af1cb1973d257b5bc75d81e02454d5e4e556\"\u003e\u003ccode\u003e0dc3af1\u003c/code\u003e\u003c/a\u003e Release 6.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/1d130020c85170edcb46ce7ed1f7f78824e37c04\"\u003e\u003ccode\u003e1d13002\u003c/code\u003e\u003c/a\u003e Prepare 6.1.0 release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/072b2175bbd7b0b3b26f5d928550ec7a21e68268\"\u003e\u003ccode\u003e072b217\u003c/code\u003e\u003c/a\u003e Update plugin spotless to v8.5.0 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5668\"\u003e#5668\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/3a53480218f4b752a9ca77506e10632cd483c0f8\"\u003e\u003ccode\u003e3a53480\u003c/code\u003e\u003c/a\u003e Update Gradle to v9.5.1 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5666\"\u003e#5666\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0e18a20a9f98d063ae02b3ba19329143f5c7f034\"\u003e\u003ccode\u003e0e18a20\u003c/code\u003e\u003c/a\u003e Update zizmorcore/zizmor-action action to v0.5.4 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5669\"\u003e#5669\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0a2634fb9cbbd057b02cf629d7d272c16d62be4b\"\u003e\u003ccode\u003e0a2634f\u003c/code\u003e\u003c/a\u003e Update github/codeql-action action to v4.35.5 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5671\"\u003e#5671\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/4dbd5561b00ac761a62c516bfaec51c212a2d60c\"\u003e\u003ccode\u003e4dbd556\u003c/code\u003e\u003c/a\u003e Restructure workflows to have single \u0026quot;status\u0026quot; job (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5670\"\u003e#5670\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/f2194cebe377512cb0ade388c62a881a0bcf5d3e\"\u003e\u003ccode\u003ef2194ce\u003c/code\u003e\u003c/a\u003e Increase timeout to reduce flakiness\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/5c8fdd2df65b763151cccbe669ea9e1c3155efcd\"\u003e\u003ccode\u003e5c8fdd2\u003c/code\u003e\u003c/a\u003e Update dependency org.apache.groovy:groovy to v5.0.6 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5659\"\u003e#5659\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/43c6982324602582902c9bdb213fd5e007f9cf3d\"\u003e\u003ccode\u003e43c6982\u003c/code\u003e\u003c/a\u003e Update dependency org.slf4j:slf4j-jdk14 to v2.0.18 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5667\"\u003e#5667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.ow2.asm:asm-bom` from 9.10 to 9.10.1\n\nUpdates `ch.qos.logback:logback-core` from 1.5.32 to 1.5.33\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/124e8b49b55ac34d08743a0646bd463410192647\"\u003e\u003ccode\u003e124e8b4\u003c/code\u003e\u003c/a\u003e prepare release 1.5.33\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/d8fd6f25c7f12282871164911fe423c86e2ef8f3\"\u003e\u003ccode\u003ed8fd6f2\u003c/code\u003e\u003c/a\u003e escapeTags in message field when printing status messages\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/95edbeb8dbf53494f36324aeb7bef1825aff6cc4\"\u003e\u003ccode\u003e95edbeb\u003c/code\u003e\u003c/a\u003e hostnameVerification default to true in SSLParametersConfiguration, SSL.DEFAU...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/b768a96e191bf0d15aeff207a5b160e5c0c8dba2\"\u003e\u003ccode\u003eb768a96\u003c/code\u003e\u003c/a\u003e remove spurious java.swing.* import\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/12cf2c5a150ee3ff4a720789bcfc6e047e836b0c\"\u003e\u003ccode\u003e12cf2c5\u003c/code\u003e\u003c/a\u003e classes in java.lang and java.util are now whitelisted individually\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/e9133edbe58a20927f88cef609e0436f77bb8a96\"\u003e\u003ccode\u003ee9133ed\u003c/code\u003e\u003c/a\u003e fix typo\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/47089a2f88785a72387d86d463c5bbe751fe6750\"\u003e\u003ccode\u003e47089a2\u003c/code\u003e\u003c/a\u003e added Filip Egeric icla\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/85735f7a097a78729bd3d29d8ea2f4b80da1a0e6\"\u003e\u003ccode\u003e85735f7\u003c/code\u003e\u003c/a\u003e Modified ConversionRuleAction.java: Updated validPreconditions() to\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/614f7a726a5b2e71e8c5fb174967c7d1069721f2\"\u003e\u003ccode\u003e614f7a7\u003c/code\u003e\u003c/a\u003e the official name for initial instructions file foe coding agents is AGENTS.md\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/qos-ch/logback/commit/fe50bb56abddd6d68ac1e31ff8851c306bf736c4\"\u003e\u003ccode\u003efe50bb5\u003c/code\u003e\u003c/a\u003e fix: do not warn when both converterClass and class attributes are specified ...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/qos-ch/logback/compare/v_1.5.32...v_1.5.33\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.codehaus.plexus:plexus-classworlds` from 2.11.0 to 2.12.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/releases\"\u003eorg.codehaus.plexus:plexus-classworlds's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.12.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cul\u003e\n\u003cli\u003eFix loadGlob using OR instead of AND for glob matching (\u003ca href=\"https://redirect.github.com/codehaus-plexus/plexus-classworlds/pull/147\"\u003e#147\u003c/a\u003e) \u003ca href=\"https://github.com/gnodet\"\u003e\u003ccode\u003e@​gnodet\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/commit/352e533ee33c8bae87b96255ae37f3dfe8b39c21\"\u003e\u003ccode\u003e352e533\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release plexus-classworlds-2.12.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/commit/9d5a694fa806a2c9d5344deba166f8cd3d2dc17d\"\u003e\u003ccode\u003e9d5a694\u003c/code\u003e\u003c/a\u003e Fix test to use File API for glob pattern (Windows compat)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/commit/6cff36d2d2a56c34c5229a0304ee73b1069703b2\"\u003e\u003ccode\u003e6cff36d\u003c/code\u003e\u003c/a\u003e Fix loadGlob using OR instead of AND for glob matching\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/commit/98ef018f4e644e246ef650a8de9a3a1d51103b22\"\u003e\u003ccode\u003e98ef018\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/codehaus-plexus/plexus-classworlds/compare/plexus-classworlds-2.11.0...plexus-classworlds-2.12.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.junit.platform:junit-platform-engine` from 6.0.3 to 6.1.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/junit-team/junit-framework/releases\"\u003eorg.junit.platform:junit-platform-engine's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eJUnit 6.1.0 = Platform 6.1.0 + Jupiter 6.1.0 + Vintage 6.1.0\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0/release-notes.html\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JarvisCraft\"\u003e\u003ccode\u003e@​JarvisCraft\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5633\"\u003ejunit-team/junit-framework#5633\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Maran23\"\u003e\u003ccode\u003e@​Maran23\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5644\"\u003ejunit-team/junit-framework#5644\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eJUnit 6.1.0-RC1 = Platform 6.1.0-RC1 + Jupiter 6.1.0-RC1 + Vintage 6.1.0-RC1\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0-RC1/release-notes/\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mariokhoury4\"\u003e\u003ccode\u003e@​mariokhoury4\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/4574\"\u003ejunit-team/junit-framework#4574\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Ogu1208\"\u003e\u003ccode\u003e@​Ogu1208\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5145\"\u003ejunit-team/junit-framework#5145\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/HyungGeun94\"\u003e\u003ccode\u003e@​HyungGeun94\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5271\"\u003ejunit-team/junit-framework#5271\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/yalishevant\"\u003e\u003ccode\u003e@​yalishevant\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5316\"\u003ejunit-team/junit-framework#5316\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/JINU-CHANG\"\u003e\u003ccode\u003e@​JINU-CHANG\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5290\"\u003ejunit-team/junit-framework#5290\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jaschdoc\"\u003e\u003ccode\u003e@​jaschdoc\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5427\"\u003ejunit-team/junit-framework#5427\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/kawshikbuet17\"\u003e\u003ccode\u003e@​kawshikbuet17\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5561\"\u003ejunit-team/junit-framework#5561\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/msridhar\"\u003e\u003ccode\u003e@​msridhar\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5602\"\u003ejunit-team/junit-framework#5602\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.1.0-M1...r6.1.0-RC1\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.1.0-M1...r6.1.0-RC1\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eJUnit 6.1.0-M1 = Platform 6.1.0-M1 + Jupiter 6.1.0-M1 + Vintage 6.1.0-M1\u003c/p\u003e\n\u003cp\u003eSee \u003ca href=\"https://docs.junit.org/6.1.0-M1/release-notes/\"\u003eRelease Notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/vy\"\u003e\u003ccode\u003e@​vy\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5041\"\u003ejunit-team/junit-framework#5041\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Pankraz76\"\u003e\u003ccode\u003e@​Pankraz76\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5006\"\u003ejunit-team/junit-framework#5006\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/arukiidou\"\u003e\u003ccode\u003e@​arukiidou\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5066\"\u003ejunit-team/junit-framework#5066\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/laeubi\"\u003e\u003ccode\u003e@​laeubi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5092\"\u003ejunit-team/junit-framework#5092\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jihun4452\"\u003e\u003ccode\u003e@​jihun4452\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5088\"\u003ejunit-team/junit-framework#5088\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TWiStErRob\"\u003e\u003ccode\u003e@​TWiStErRob\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/junit-team/junit-framework/pull/5133\"\u003ejunit-team/junit-framework#5133\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.0...r6.1.0-M1\"\u003ehttps://github.com/junit-team/junit-framework/compare/r6.0.0...r6.1.0-M1\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0dc3af1cb1973d257b5bc75d81e02454d5e4e556\"\u003e\u003ccode\u003e0dc3af1\u003c/code\u003e\u003c/a\u003e Release 6.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/1d130020c85170edcb46ce7ed1f7f78824e37c04\"\u003e\u003ccode\u003e1d13002\u003c/code\u003e\u003c/a\u003e Prepare 6.1.0 release notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/072b2175bbd7b0b3b26f5d928550ec7a21e68268\"\u003e\u003ccode\u003e072b217\u003c/code\u003e\u003c/a\u003e Update plugin spotless to v8.5.0 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5668\"\u003e#5668\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/3a53480218f4b752a9ca77506e10632cd483c0f8\"\u003e\u003ccode\u003e3a53480\u003c/code\u003e\u003c/a\u003e Update Gradle to v9.5.1 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5666\"\u003e#5666\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0e18a20a9f98d063ae02b3ba19329143f5c7f034\"\u003e\u003ccode\u003e0e18a20\u003c/code\u003e\u003c/a\u003e Update zizmorcore/zizmor-action action to v0.5.4 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5669\"\u003e#5669\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/0a2634fb9cbbd057b02cf629d7d272c16d62be4b\"\u003e\u003ccode\u003e0a2634f\u003c/code\u003e\u003c/a\u003e Update github/codeql-action action to v4.35.5 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5671\"\u003e#5671\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/4dbd5561b00ac761a62c516bfaec51c212a2d60c\"\u003e\u003ccode\u003e4dbd556\u003c/code\u003e\u003c/a\u003e Restructure workflows to have single \u0026quot;status\u0026quot; job (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5670\"\u003e#5670\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/f2194cebe377512cb0ade388c62a881a0bcf5d3e\"\u003e\u003ccode\u003ef2194ce\u003c/code\u003e\u003c/a\u003e Increase timeout to reduce flakiness\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/5c8fdd2df65b763151cccbe669ea9e1c3155efcd\"\u003e\u003ccode\u003e5c8fdd2\u003c/code\u003e\u003c/a\u003e Update dependency org.apache.groovy:groovy to v5.0.6 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5659\"\u003e#5659\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/junit-team/junit-framework/commit/43c6982324602582902c9bdb213fd5e007f9cf3d\"\u003e\u003ccode\u003e43c6982\u003c/code\u003e\u003c/a\u003e Update dependency org.slf4j:slf4j-jdk14 to v2.0.18 (\u003ca href=\"https://redirect.github.com/junit-team/junit-framework/issues/5667\"\u003e#5667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/junit-team/junit-framework/compare/r6.0.3...r6.1.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.maven.extensions:maven-build-cache-extension` from 1.2.2 to 1.2.3\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/apache/maven-build-cache-extension/releases\"\u003eorg.apache.maven.extensions:maven-build-cache-extension's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.2.3\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e🚀 New features and improvements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIssue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/336\"\u003e#336\u003c/a\u003e Add command line flag to override maxBuildsCached (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/489\"\u003e#489\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/MBUILDCACHE-73\"\u003e[MBUILDCACHE-73]\u003c/a\u003e - Allow arbitrary expressions as additional reconcilation properties (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/416\"\u003e#416\u003c/a\u003e) \u003ca href=\"https://github.com/pdudits\"\u003e\u003ccode\u003e@​pdudits\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/480\"\u003e#480\u003c/a\u003e - execute blocking hostname resolution asynchronously and implement timeout and caching (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/481\"\u003e#481\u003c/a\u003e) \u003ca href=\"https://github.com/marcuslinke\"\u003e\u003ccode\u003e@​marcuslinke\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDo not read a JAR completely into a byte-array before computing the SHA (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/470\"\u003e#470\u003c/a\u003e) \u003ca href=\"https://github.com/jvdvegt\"\u003e\u003ccode\u003e@​jvdvegt\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Test Only] Comprehensive test coverage (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/462\"\u003e#462\u003c/a\u003e) \u003ca href=\"https://github.com/AlexanderAshitkin\"\u003e\u003ccode\u003e@​AlexanderAshitkin\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eOnly set the project artifact if it is the actual JAR (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/453\"\u003e#453\u003c/a\u003e) \u003ca href=\"https://github.com/mensinda\"\u003e\u003ccode\u003e@​mensinda\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/423\"\u003e#423\u003c/a\u003e — include declared input files in cache checksum for pom-packaged modules (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/482\"\u003e#482\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix issue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/463\"\u003e#463\u003c/a\u003e Unexpected cache miss due to previously downloaded remote cache entry with skipTests (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/472\"\u003e#472\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIssue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/345\"\u003e#345\u003c/a\u003e fix possible NPE with Intellij (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/473\"\u003e#473\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTest-jar type dependencies fail to be resolved during checksum calculation with -f builds (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/468\"\u003e#468\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix for issue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/450\"\u003e#450\u003c/a\u003e - fixed CacheUtils.unzip to properly restore unix permissions on file systems that support it (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/451\"\u003e#451\u003c/a\u003e) \u003ca href=\"https://github.com/eyforia\"\u003e\u003ccode\u003e@​eyforia\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📝 Documentation updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003edocumentation fixes and updates (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/460\"\u003e#460\u003c/a\u003e) \u003ca href=\"https://github.com/AlexanderAshitkin\"\u003e\u003ccode\u003e@​AlexanderAshitkin\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e👻 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFinish breaking dependency on org.apache.http in RemoteCacheRepositoryImpl (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/441\"\u003e#441\u003c/a\u003e) \u003ca href=\"https://github.com/elharo\"\u003e\u003ccode\u003e@​elharo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove undeclared NotNull annotations (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/440\"\u003e#440\u003c/a\u003e) \u003ca href=\"https://github.com/elharo\"\u003e\u003ccode\u003e@​elharo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFill in two more used dependencies SLF4J and sisu.plexus (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/438\"\u003e#438\u003c/a\u003e) \u003ca href=\"https://github.com/elharo\"\u003e\u003ccode\u003e@​elharo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🚦 Tests\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix findFirstMainSourceFile to skip invoker test projects (src/it/) in p12 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/474\"\u003e#474\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Test Only] Comprehensive test coverage (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/462\"\u003e#462\u003c/a\u003e) \u003ca href=\"https://github.com/AlexanderAshitkin\"\u003e\u003ccode\u003e@​AlexanderAshitkin\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📦 Dependency updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate 48 and Maven 3.9.16 (in Maven 3 profile) (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/490\"\u003e#490\u003c/a\u003e) \u003ca href=\"https://github.com/Bukama\"\u003e\u003ccode\u003e@​Bukama\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump com.github.tomakehurst:wiremock-jre8 from 2.35.2 to 3.0.1 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/485\"\u003e#485\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-invoker-plugin from 3.10.0 to 3.10.1 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/484\"\u003e#484\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump com.google.guava:guava from 30.1.1-jre to 32.0.0-jre in /src/test/projects/reference-test-projects/p06-dep-edge-cases/bom-b (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/464\"\u003e#464\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.junit:junit-bom from 5.14.3 to 5.14.4 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/479\"\u003e#479\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.commons:commons-lang3 from 3.14.0 to 3.18.0 in /src/test/projects/reference-test-projects/p18-maven4-native/platform-bom (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/465\"\u003e#465\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-invoker-plugin from 3.9.1 to 3.10.0 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/478\"\u003e#478\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump commons-io:commons-io from 2.21.0 to 2.22.0 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/477\"\u003e#477\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.testcontainers:testcontainers-bom from 2.0.4 to 2.0.5 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/476\"\u003e#476\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump com.fasterxml.jackson.core:jackson-annotations from 2.15.4 to 2.21 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/475\"\u003e#475\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.testcontainers:testcontainers-bom from 2.0.3 to 2.0.4 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/466\"\u003e#466\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump resolverVersion from 1.9.26 to 1.9.27 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/459\"\u003e#459\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump resolverVersion from 1.9.25 to 1.9.26 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/458\"\u003e#458\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.junit:junit-bom from 5.14.2 to 5.14.3 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/pull/457\"\u003e#457\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/f9f25d2f6acd78238471f7f36e1efe93fb8b7e50\"\u003e\u003ccode\u003ef9f25d2\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release maven-build-cache-extension-1.2.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/7bd513b6515e526554067386d2d4b1e67fb7e2cb\"\u003e\u003ccode\u003e7bd513b\u003c/code\u003e\u003c/a\u003e Update 48 and Maven 3.9.16 (in Maven 3 profile) (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/490\"\u003e#490\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/ada66d445c228ba9abe52e42632fc237af38f89f\"\u003e\u003ccode\u003eada66d4\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/336\"\u003e#336\u003c/a\u003e Add command line flag to override maxBuildsCached (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/489\"\u003e#489\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/c915399e169c6c3633b4a12be0fc1e9579114f50\"\u003e\u003ccode\u003ec915399\u003c/code\u003e\u003c/a\u003e [MBUILDCACHE-73] Allow arbitrary expressions as additional reconcilation prop...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/0b7d080ffca2a32c892208bbfafbd18b9dd32a92\"\u003e\u003ccode\u003e0b7d080\u003c/code\u003e\u003c/a\u003e Bump com.github.tomakehurst:wiremock-jre8 from 2.35.2 to 3.0.1 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/485\"\u003e#485\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/051a319a8f063ea59f97709186e8966e2969a1e4\"\u003e\u003ccode\u003e051a319\u003c/code\u003e\u003c/a\u003e Only set the project artifact if it is the actual JAR (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/453\"\u003e#453\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/6a48e056a89316d5c3a007098cd32aa9aa5e1a5e\"\u003e\u003ccode\u003e6a48e05\u003c/code\u003e\u003c/a\u003e Bump org.apache.maven.plugins:maven-invoker-plugin from 3.10.0 to 3.10.1 (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/484\"\u003e#484\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/5032c5d805f4071d34ecea96f40d80117369654a\"\u003e\u003ccode\u003e5032c5d\u003c/code\u003e\u003c/a\u003e fix: \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/480\"\u003e#480\u003c/a\u003e - execute blocking hostname resolution asynchronously and implement...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/dc7069f9e25acfafa6cc41ebba48bcbe43e5bc4b\"\u003e\u003ccode\u003edc7069f\u003c/code\u003e\u003c/a\u003e Issue \u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/423\"\u003e#423\u003c/a\u003e add an IT and a fix (\u003ca href=\"https://redirect.github.com/apache/maven-build-cache-extension/issues/482\"\u003e#482\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-build-cache-extension/commit/929bed8890bc43128818277c13b6f8c1c05e5f8c\"\u003e\u003ccode\u003e929bed8\u003c/code\u003e\u003c/a\u003e Bump com.google.guava:guava\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/apache/maven-build-cache-extension/compare/maven-build-cache-extension-1.2.2...maven-build-cache-extension-1.2.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/jetty/jetty.project/pull/15176","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/jetty%2Fjetty.project/issues/15176","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/15176/packages"}}]}