{"id":2959,"name":"com.fasterxml.jackson.core:jackson-databind","ecosystem":"maven","repository_url":"https://github.com/FasterXML/jackson-databind","issues_count":2929,"created_at":"2025-06-06T15:02:15.790Z","updated_at":"2025-06-06T15:02:15.790Z","purl":"pkg:maven/com.fasterxml.jackson.core:jackson-databind","metadata":{"id":4762525,"name":"com.fasterxml.jackson.core:jackson-databind","ecosystem":"maven","description":"General data-binding functionality for Jackson: works on core streaming API","homepage":"https://github.com/FasterXML/jackson","licenses":"The Apache Software License, Version 2.0","normalized_licenses":["Apache-2.0"],"repository_url":"https://github.com/FasterXML/jackson-databind","keywords_array":[],"namespace":"com.fasterxml.jackson.core","versions_count":206,"first_release_published_at":"2012-02-19T08:05:22.000Z","latest_release_published_at":"2025-04-24T23:41:58.000Z","latest_release_number":"2.19.0","last_synced_at":"2025-05-31T16:09:24.541Z","created_at":"2022-07-26T04:07:55.792Z","updated_at":"2025-06-05T02:02:54.681Z","registry_url":"https://central.sonatype.com/artifact/com.fasterxml.jackson.core/jackson-databind/","install_command":null,"documentation_url":"https://appdoc.app/artifact/com.fasterxml.jackson.core/jackson-databind/","metadata":{},"repo_metadata":{"uuid":"3038937","full_name":"FasterXML/jackson-databind","owner":"FasterXML","description":"General data-binding package for Jackson (2.x): works on streaming API (core) implementation(s)","archived":false,"fork":false,"pushed_at":"2023-03-14T03:53:17.000Z","size":76873,"stargazers_count":3234,"open_issues_count":467,"forks_count":1274,"subscribers_count":166,"default_branch":"2.15","last_synced_at":"2023-03-14T05:10:14.916Z","etag":null,"topics":["hacktoberfest","jackson","jackson-databind","json"],"latest_commit_sha":null,"homepage":"","language":"Java","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"apache-2.0","status":null,"scm":"git","pull_requests_enabled":true,"logo_url":null,"metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":".github/FUNDING.yml","license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null},"funding":{"tidelift":"maven/com.fasterxml.jackson.core:jackson-databind","github":"cowtowncoder"}},"created_at":"2011-12-23T07:17:41.000Z","updated_at":"2023-03-13T07:42:01.000Z","dependencies_parsed_at":"2023-01-16T18:30:50.391Z","dependency_job_id":null,"html_url":"https://github.com/FasterXML/jackson-databind","commit_stats":null,"repository_url":"http://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/FasterXML%2Fjackson-databind","tags_url":"http://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/FasterXML%2Fjackson-databind/tags","manifests_url":"http://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/FasterXML%2Fjackson-databind/manifests","owner_url":"http://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/FasterXML","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":108921946,"host_url":"http://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"http://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"http://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names"},"owner_record":{"login":"FasterXML","name":"FasterXML, LLC","uuid":"382692","kind":"organization","description":null,"email":"info@fasterxml.com","website":"http://fasterxml.com","location":"Seattle, WA","twitter":null,"company":null,"avatar_url":"https://avatars.githubusercontent.com/u/382692?v=4","repositories_count":59,"last_synced_at":"2023-02-20T10:48:03.431Z","metadata":{"has_sponsors_listing":false},"owner_url":"http://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/FasterXML"},"tags":[{"name":"jackson-databind-2.7.9.2","sha":"9e170e1a28221cf273e8a63e01f1731a9fcd11bc","kind":"tag","published_at":"2017-12-20T03:24:32.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.7.9.2","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.7.9.2"},{"name":"jackson-databind-2.9.3","sha":"d4f5fc1b1e53774b85188da1b4ebd5ed09ff6aa5","kind":"tag","published_at":"2017-12-09T03:04:27.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.9.3","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.9.3"},{"name":"jackson-databind-2.9.2","sha":"eb137011061187975deedbf56342224e5fce7f5e","kind":"tag","published_at":"2017-10-14T03:28:24.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.9.2","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.9.2"},{"name":"jackson-databind-2.9.1","sha":"db38beac4658c7f7e197ca8fc2d2e681907d911e","kind":"tag","published_at":"2017-09-08T01:09:04.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.9.1","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.9.1"},{"name":"jackson-databind-2.8.10","sha":"0b6e589c1c0ee20854ac0efeafacbf2782fc9f1c","kind":"tag","published_at":"2017-08-24T04:26:49.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.8.10","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.8.10"},{"name":"jackson-databind-2.9.0","sha":"e969f0a31b781f5dfb74e16ddd5ee4b4fa36e8d8","kind":"tag","published_at":"2017-07-30T04:21:11.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.9.0","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.9.0"},{"name":"jackson-databind-2.6.7.1","sha":"f7abd682a7b2f8145ecff1c4e205073949f1e623","kind":"tag","published_at":"2017-07-11T04:11:01.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.6.7.1","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.6.7.1"},{"name":"jackson-databind-2.9.0.pr4","sha":"822ca4a7db3c3653cea1d0b493e4dfc53d56e15a","kind":"tag","published_at":"2017-06-17T01:19:35.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.9.0.pr4","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.9.0.pr4"},{"name":"jackson-databind-2.8.9","sha":"c45ed8c4cbf6c29317bf4cf562558884fa698eec","kind":"tag","published_at":"2017-06-12T00:52:44.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.8.9","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.8.9"},{"name":"jackson-databind-2.9.0.pr3","sha":"7541ac546f49d61182d0262df7ca617ef3063bf1","kind":"tag","published_at":"2017-04-25T05:46:00.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.9.0.pr3","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.9.0.pr3"},{"name":"jackson-databind-2.8.8.1","sha":"bb89b518edcc29b6d4ba2a12f5d215abd2bf20e1","kind":"tag","published_at":"2017-04-19T15:33:39.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.8.8.1","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.8.8.1"},{"name":"jackson-databind-2.7.9.1","sha":"8419c81fad9c7b884b6a02de7b5f1ce5700cbf32","kind":"tag","published_at":"2017-04-18T05:10:57.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.7.9.1","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.7.9.1"},{"name":"jackson-databind-2.8.8","sha":"2f93aedf142c98484e0627815e833dc680b88de1","kind":"tag","published_at":"2017-04-05T03:27:53.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.8.8","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.8.8"},{"name":"jackson-databind-2.9.0.pr2","sha":"418ee6e0a91401365982794cc9b18a55b26655e5","kind":"tag","published_at":"2017-03-22T03:27:28.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.9.0.pr2","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.9.0.pr2"},{"name":"jackson-databind-2.9.0.pr1","sha":"d90fe4c654d1c1d54e24b15deae3ad0443b0f8f6","kind":"tag","published_at":"2017-03-02T18:44:40.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.9.0.pr1","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.9.0.pr1"},{"name":"jackson-databind-2.8.7","sha":"b30845f718d50e1fe74d8d040d2a2ef08118371d","kind":"tag","published_at":"2017-02-21T01:06:10.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.8.7","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.8.7"},{"name":"jackson-databind-2.7.9","sha":"904b087a7d1075b65cfa30ea1e10ddc49f68d4fb","kind":"tag","published_at":"2017-02-04T19:21:14.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.7.9","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.7.9"},{"name":"jackson-databind-2.8.6","sha":"9dbe3d2dbe218d96a20681ef1d6c7ee78b065dcf","kind":"tag","published_at":"2017-01-12T04:39:11.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.8.6","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.8.6"},{"name":"jackson-databind-2.8.5","sha":"a9c018137ef2e7be5dad0f10d319475f16e976e8","kind":"tag","published_at":"2016-11-14T06:13:03.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.8.5","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.8.5"},{"name":"jackson-databind-2.8.4","sha":"e913b10a67910ee5084cba9c226816c728a1f376","kind":"tag","published_at":"2016-10-14T03:50:59.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.8.4","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.8.4"},{"name":"jackson-databind-2.7.8","sha":"753f460191133f5623ee3e24eac0dea6f20406ff","kind":"tag","published_at":"2016-09-26T14:50:00.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.7.8","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.7.8"},{"name":"jackson-databind-2.8.3","sha":"46ea49151b44cad33a8021ed2e8ce655089b2235","kind":"tag","published_at":"2016-09-18T01:29:37.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.8.3","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.8.3"},{"name":"jackson-databind-2.8.2","sha":"761d563caacd5affbc6dddf137332e96da6b9ab6","kind":"tag","published_at":"2016-08-30T00:43:14.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.8.2","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.8.2"},{"name":"jackson-databind-2.7.7","sha":"9fc02765ca4338d6ffe4334421cdc5034ecf9959","kind":"tag","published_at":"2016-08-26T21:52:59.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.7.7","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.7.7"},{"name":"jackson-databind-2.7.6","sha":"cca37af655ae31317b0aa8663f0dcddb3473bbcc","kind":"tag","published_at":"2016-07-23T02:36:54.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.7.6","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.7.6"},{"name":"jackson-databind-2.8.1","sha":"111e86d18cf460fff06292c3eb2c140475dd9308","kind":"tag","published_at":"2016-07-19T23:23:07.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.8.1","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.8.1"},{"name":"jackson-databind-2.8.0","sha":"81929fad84189ce59ef82e7a6d0df795eb0c7cdb","kind":"tag","published_at":"2016-07-04T05:49:20.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.8.0","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.8.0"},{"name":"jackson-databind-2.7.5","sha":"096314fb2f5ee0d69d207783710156d680fc96ff","kind":"tag","published_at":"2016-06-11T02:12:30.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.7.5","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.7.5"},{"name":"jackson-databind-2.6.7","sha":"4ef3de0d1b393f2e4dbe655b4684c0b31e96a5b1","kind":"tag","published_at":"2016-06-05T21:08:16.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.6.7","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.6.7"},{"name":"jackson-databind-2.7.4","sha":"ed6c4262324e0024f3d016b11307e4821b758f37","kind":"tag","published_at":"2016-04-29T15:45:13.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.7.4","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.7.4"},{"name":"jackson-databind-2.6.6","sha":"6c76749cad9d3e414e187d5d5880fa015fbf8bf7","kind":"tag","published_at":"2016-04-05T01:22:29.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.6.6","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.6.6"},{"name":"jackson-databind-2.7.3","sha":"ec8db26e537c32ec6b1f5535c48116cd54ea6c70","kind":"tag","published_at":"2016-03-16T01:26:28.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.7.3","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.7.3"},{"name":"jackson-databind-2.7.2","sha":"4069c66ca378cce5f78193057640d08029ffeba4","kind":"tag","published_at":"2016-02-27T04:35:41.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.7.2","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.7.2"},{"name":"jackson-databind-2.7.1-1","sha":"7be8815590d097f32eadaef017b6de2ebb2030b1","kind":"tag","published_at":"2016-02-04T00:30:41.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.7.1-1","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.7.1-1"},{"name":"jackson-databind-2.7.1","sha":"ce9dc07af83f77568a613fd45a86f58c93ba1a02","kind":"tag","published_at":"2016-02-02T06:14:40.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.7.1","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.7.1"},{"name":"jackson-databind-2.6.5","sha":"55980bc9133c2d9e2a7a36b08a4392a31be17320","kind":"tag","published_at":"2016-01-19T04:54:02.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.6.5","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.6.5"},{"name":"jackson-databind-2.7.0","sha":"50791cc7856376949287e0be3e96147665ab8f68","kind":"tag","published_at":"2016-01-10T06:08:19.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.7.0","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.7.0"},{"name":"jackson-databind-2.7.0-rc3","sha":"97b469461c495ca3a85dfcac423ea1866c7ddb09","kind":"tag","published_at":"2016-01-06T06:22:42.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.7.0-rc3","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.7.0-rc3"},{"name":"jackson-databind-2.7.0-rc2","sha":"4a066c67a771934496bc7020fbb18b32307f829c","kind":"tag","published_at":"2015-12-12T01:57:49.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.7.0-rc2","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.7.0-rc2"},{"name":"jackson-databind-2.5.5","sha":"1e3d3ca4e74bbdd0240e14e71655fdb400bb51a3","kind":"tag","published_at":"2015-12-08T02:41:49.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.5.5","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.5.5"},{"name":"jackson-databind-2.6.4","sha":"1160115bf551da1a50081d701c716a5150cd87d2","kind":"tag","published_at":"2015-12-08T02:31:20.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.6.4","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.6.4"},{"name":"jackson-databind-2.7.0-rc1","sha":"02450fc97b9d3c7ce1f5256181abbaaa463005a4","kind":"tag","published_at":"2015-11-26T21:34:55.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.7.0-rc1","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.7.0-rc1"},{"name":"jackson-databind-2.6.3","sha":"547ba8e7d2c1ed686b095c5253f96b038d39f87b","kind":"tag","published_at":"2015-10-12T18:30:25.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.6.3","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.6.3"},{"name":"jackson-databind-2.6.2","sha":"3739d9dfbf24b6822b90274ba346ad209eb289fd","kind":"tag","published_at":"2015-09-15T04:59:38.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.6.2","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.6.2"},{"name":"jackson-databind-2.6.1","sha":"060726b011b008496cd8bb0997ee94a6b73530d1","kind":"tag","published_at":"2015-08-10T05:25:49.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.6.1","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.6.1"},{"name":"jackson-databind-2.6.0","sha":"21f90cf247018c1286cc20544029782450dc270a","kind":"tag","published_at":"2015-07-19T18:37:46.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.6.0","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.6.0"},{"name":"jackson-databind-2.6.0-rc4","sha":"521515d6fb96f68e2049d8bedbfb2117770bfcc0","kind":"tag","published_at":"2015-07-11T03:42:03.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.6.0-rc4","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.6.0-rc4"},{"name":"2.6.0-rc3b","sha":"485d444d9d26c2e1a12ad0697ce79066cdb5b8b3","kind":"tag","published_at":"2015-06-25T03:28:54.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/2.6.0-rc3b","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/2.6.0-rc3b"},{"name":"jackson-databind-2.5.4","sha":"f693ae583c7777478872da59ff473e58fda3434f","kind":"tag","published_at":"2015-06-10T01:42:29.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.5.4","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.5.4"},{"name":"jackson-databind-2.4.6.1","sha":"e21d7a73d57de235ee4d3718f9f9dede87715e72","kind":"tag","published_at":"2015-06-10T00:38:23.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.4.6.1","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.4.6.1"},{"name":"jackson-databind-2.6.0-rc2","sha":"b9a552cf9c89aaa8dc26895cb2ef72b738301870","kind":"tag","published_at":"2015-06-09T01:42:49.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.6.0-rc2","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.6.0-rc2"},{"name":"jackson-databind-2.6.0-rc1","sha":"5286441eecb890778d7c524482bd41d583452d92","kind":"tag","published_at":"2015-05-19T03:15:08.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.6.0-rc1","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.6.0-rc1"},{"name":"jackson-databind-2.5.3","sha":"a29cb29501ac6b3e6c8ca6fed876a4d7d52a7faa","kind":"tag","published_at":"2015-04-24T17:23:25.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.5.3","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.5.3"},{"name":"jackson-databind-2.4.6","sha":"ed7b0c3ac0b163c3cf9d71a5af10bc396655c233","kind":"tag","published_at":"2015-04-24T01:40:58.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.4.6","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.4.6"},{"name":"jackson-databind-2.5.2","sha":"636018b11cf7c23cc9647f0c11aaca1ba11a1935","kind":"tag","published_at":"2015-03-29T23:50:52.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.5.2","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.5.2"},{"name":"jackson-databind-2.4.5.1","sha":"19ac8a4aff21d5f2f57765b684675f21786771d3","kind":"tag","published_at":"2015-03-27T02:57:27.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.4.5.1","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.4.5.1"},{"name":"jackson-databind-2.5.1","sha":"bc5b910e790e5cbf460a60751127b647656e0cb7","kind":"tag","published_at":"2015-02-07T00:09:20.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.5.1","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.5.1"},{"name":"jackson-databind-2.3.5","sha":"c971ef156e231aea59ab3a1561761cef89bd9fd1","kind":"tag","published_at":"2015-01-14T06:27:42.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.3.5","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.3.5"},{"name":"jackson-databind-2.4.5","sha":"fe0462745d12cb6ca135a2d1bda26e1c68d6b687","kind":"tag","published_at":"2015-01-14T04:24:05.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.4.5","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.4.5"},{"name":"jackson-databind-2.5.0","sha":"9efc4abb22c664c492271bc9907bbfbf4f70889c","kind":"tag","published_at":"2015-01-02T01:44:08.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.5.0","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.5.0"},{"name":"jackson-databind-2.5.0-rc1","sha":"cd4381f08082b66115a7dbc39dae33a30ceb150a","kind":"tag","published_at":"2014-12-20T01:50:37.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.5.0-rc1","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.5.0-rc1"},{"name":"jackson-databind-2.4.4","sha":"ecfe3f46aff79f6f51600841920010200b923d83","kind":"tag","published_at":"2014-11-25T02:26:47.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.4.4","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.4.4"},{"name":"jackson-databind-2.4.3","sha":"1f5dc0a4f67598266cd77f389ee808e15990477a","kind":"tag","published_at":"2014-10-03T06:23:10.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.4.3","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.4.3"},{"name":"jackson-databind-2.4.2","sha":"824bd1e3ca9d69e6490d9ce99e541663ceb3664b","kind":"tag","published_at":"2014-08-14T04:22:02.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.4.2","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.4.2"},{"name":"jackson-databind-2.3.4","sha":"27a2dcecebcb2b6a26868e4c321434643a601a19","kind":"tag","published_at":"2014-07-17T22:46:41.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.3.4","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.3.4"},{"name":"jackson-databind-2.4.1.3","sha":"1e6c8b0a442a124e6bbcc9267463a58f48c7876f","kind":"tag","published_at":"2014-07-15T05:31:48.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.4.1.3","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.4.1.3"},{"name":"jackson-databind-2.4.1.2","sha":"735b88abc3dea908bc59f7373f22d58a6cbb6d35","kind":"tag","published_at":"2014-07-12T22:26:10.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.4.1.2","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.4.1.2"},{"name":"jackson-databind-2.4.1.1","sha":"cbd3f169e8e32d130ac64c8853310577e766713c","kind":"tag","published_at":"2014-06-18T22:30:11.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.4.1.1","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.4.1.1"},{"name":"jackson-databind-2.4.1","sha":"7a095bcc66b228ea48e37c57eafd7d78ce5c090c","kind":"tag","published_at":"2014-06-18T02:10:46.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.4.1","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.4.1"},{"name":"jackson-databind-2.2.4","sha":"9dea88f68707f358f7b27cce97381b00112eb343","kind":"tag","published_at":"2014-06-11T00:29:12.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.2.4","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.2.4"},{"name":"jackson-databind-2.4.0","sha":"a5807c566af27b184731dd4eb7dfcc420962db32","kind":"tag","published_at":"2014-06-03T00:49:06.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.4.0","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.4.0"},{"name":"jackson-databind-2.4.0-rc3","sha":"1790b1b43c2575033ecca0817e2aae5fb607f3ce","kind":"tag","published_at":"2014-05-08T21:13:28.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.4.0-rc3","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.4.0-rc3"},{"name":"jackson-databind-2.4.0-rc2","sha":"c48dd6fcdea43aefafa813979afb0c4835532db8","kind":"tag","published_at":"2014-04-30T15:31:10.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.4.0-rc2","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.4.0-rc2"},{"name":"jackson-databind-2.4.0-rc1","sha":"75b97b8519f0d50c62523ad85170d80a197a2c86","kind":"tag","published_at":"2014-04-26T19:28:20.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.4.0-rc1","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.4.0-rc1"},{"name":"jackson-databind-2.3.3","sha":"f685aac3469bc32db751990c40884f9370b904cc","kind":"tag","published_at":"2014-04-10T16:53:48.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.3.3","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.3.3"},{"name":"jackson-databind-2.3.2","sha":"2a2932873c70758628f445f53b11077650ac9e6d","kind":"tag","published_at":"2014-03-02T03:11:26.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.3.2","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.3.2"},{"name":"jackson-databind-2.3.1","sha":"8ec79ecf31523184c0062e1c69f6ca8da13009bf","kind":"tag","published_at":"2013-12-28T02:23:18.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.3.1","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.3.1"},{"name":"jackson-databind-2.3.0","sha":"0db57763dd4fca9a8adad1bbf2e96969df11abee","kind":"tag","published_at":"2013-11-14T05:19:56.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.3.0","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.3.0"},{"name":"jackson-databind-2.3.0-rc1","sha":"e2d273ec394f02a0e8d5d962f7d45821cc44aaef","kind":"tag","published_at":"2013-10-26T02:59:58.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.3.0-rc1","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.3.0-rc1"},{"name":"jackson-databind-2.2.3","sha":"22a9ec205e4f400a4adfde76db75fe3c6c33f794","kind":"tag","published_at":"2013-08-23T03:22:41.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.2.3","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.2.3"},{"name":"jackson-databind-2.2.2","sha":"b8d01a7df1c1f3c682200fdefe99f5a7291f729d","kind":"tag","published_at":"2013-05-27T05:22:09.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.2.2","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.2.2"},{"name":"jackson-databind-2.2.1","sha":"1cb7e91cc8114b7ea2b584707cd021f44aeea5e3","kind":"tag","published_at":"2013-05-04T01:16:46.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.2.1","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.2.1"},{"name":"jackson-databind-2.1.5","sha":"4652fb9ec3c45a232a65272e0f50b324bcd24249","kind":"tag","published_at":"2013-05-03T03:08:15.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.1.5","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.1.5"},{"name":"2.2.0c","sha":"c63a436a43333cb4a0c385e6fab2401d77e69378","kind":"tag","published_at":"2013-04-23T04:02:21.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/2.2.0c","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/2.2.0c"},{"name":"jackson-databind-2.2.0","sha":"f03eb1d4f9b9e1841d65f57191f971d7425d8274","kind":"tag","published_at":"2013-04-23T02:51:20.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.2.0","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.2.0"},{"name":"jackson-databind-2.2.0-rc1","sha":"84785f8658a28adf30fbb55e55906ac55d874e22","kind":"tag","published_at":"2013-04-18T01:55:38.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.2.0-rc1","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.2.0-rc1"},{"name":"jackson-databind-2.1.4","sha":"90f3125c222668255db99bcbb7fb2a6cb5d886e6","kind":"tag","published_at":"2013-02-26T23:13:55.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.1.4","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.1.4"},{"name":"jackson-databind-2.1.3","sha":"fef1a9992f3c314a9672a952d8dfd394959f9d6e","kind":"tag","published_at":"2013-01-19T21:10:37.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.1.3","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.1.3"},{"name":"jackson-databind-2.1.2","sha":"88d0b78c0a94a02bdba778da298968085db8a164","kind":"tag","published_at":"2012-12-04T06:05:33.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.1.2","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.1.2"},{"name":"jackson-databind-2.1.1","sha":"e2455c786aa361b725f5cb14e246c32469c8efa5","kind":"tag","published_at":"2012-11-11T23:51:13.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.1.1","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.1.1"},{"name":"jackson-databind-2.1.0","sha":"e997f1270f6c3d5c1443755e51ecc580eaf943c6","kind":"tag","published_at":"2012-10-10T00:13:39.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.1.0","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.1.0"},{"name":"jackson-databind-2.0.6","sha":"391d11353cd8a5fb6f84d001105a37234a457a71","kind":"tag","published_at":"2012-09-06T03:19:05.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.0.6","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.0.6"},{"name":"jackson-databind-2.0.5","sha":"d82198dafdb99fe52e96f50c07046e43836a73e1","kind":"tag","published_at":"2012-07-27T22:58:16.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.0.5","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.0.5"},{"name":"jackson-databind-2.0.4","sha":"67cd09aba9f75f1ebbc664d7e929a6105ac3413b","kind":"tag","published_at":"2012-06-27T05:14:45.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.0.4","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.0.4"},{"name":"jackson-databind-2.0.2","sha":"3f186e18ad8bd349b28aacd7fb1fb34957b5b71e","kind":"tag","published_at":"2012-05-15T02:14:37.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.0.2","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.0.2"},{"name":"jackson-databind-2.0.1","sha":"a253fd38e6b975ce4e10ab6470dd8f57838a553c","kind":"tag","published_at":"2012-04-24T01:57:11.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.0.1","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.0.1"},{"name":"jackson-databind-2.0.0","sha":"e8df0987e3034d102ee6d704d30a05a2e3ac7089","kind":"tag","published_at":"2012-03-25T19:09:14.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.0.0","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.0.0"},{"name":"jackson-databind-2.0.0-RC3","sha":"f04929a744b10694a8af73cf1f33dfbb0226bbc4","kind":"tag","published_at":"2012-03-23T00:15:59.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.0.0-RC3","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.0.0-RC3"},{"name":"jackson-databind-2.0.0-RC2","sha":"ab22e8281836fd197bc6943e277f4aa0d0c953e3","kind":"tag","published_at":"2012-03-06T07:00:25.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.0.0-RC2","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.0.0-RC2"},{"name":"jackson-databind-2.0.0-RC1","sha":"9af5904b805fa07a00757fe2d24c1f931b502254","kind":"tag","published_at":"2012-02-19T08:03:58.000Z","download_url":"https://codeload.github.com/FasterXML/jackson-databind/tar.gz/jackson-databind-2.0.0-RC1","html_url":"https://github.com/FasterXML/jackson-databind/releases/tag/jackson-databind-2.0.0-RC1"}]},"repo_metadata_updated_at":"2023-03-21T21:47:17.173Z","dependent_packages_count":23566,"downloads":null,"downloads_period":null,"dependent_repos_count":244221,"rankings":{"downloads":null,"dependent_repos_count":0.0024044241404183697,"dependent_packages_count":0.0012022120702091848,"stargazers_count":5.802877294221368,"forks_count":4.350805482087041,"docker_downloads_count":0.00080147471347279,"average":2.031618177446502},"purl":"pkg:maven/com.fasterxml.jackson.core/jackson-databind","advisories":[{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWYzajUtcm1tcC0zZmM1","url":"https://github.com/advisories/GHSA-f3j5-rmmp-3fc5","title":"Improper Input Validation in jackson-databind","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10 and 2.8.11.5. It is related to net.sf.ehcache.hibernate.EhcacheJtaTransactionManagerLookup.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2020-06-15T18:44:48.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2019-17267","https://github.com/FasterXML/jackson-databind/issues/2460","https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.3...jackson-databind-2.9.10","https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r9d727fc681fb3828794acbefcaee31393742b4d73a29461ccd9597a8@%3Cdev.skywalking.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/12/msg00013.html","https://security.netapp.com/advisory/ntap-20191017-0006/","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/FasterXML/jackson-databind/commit/191a4cdf87b56d2ddddb77edd895ee756b7f75eb","https://github.com/advisories/GHSA-f3j5-rmmp-3fc5"],"source_kind":"github","identifiers":["GHSA-f3j5-rmmp-3fc5","CVE-2019-17267"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.8.11.5","vulnerable_version_range":"\u003c 2.8.11.5"},{"first_patched_version":"2.9.10","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.10"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:24.114Z","updated_at":"2023-09-13T18:28:29.000Z","epss_percentage":0.01357,"epss_percentile":0.79016},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXYzeHctYzk2My1mNWhj","url":"https://github.com/advisories/GHSA-v3xw-c963-f5hc","title":"jackson-databind mishandles the interaction between serialization gadgets and typing","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, and activemq-pool-jms).","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2020-05-15T18:58:50.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-11111","https://github.com/FasterXML/jackson-databind/issues/2664","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200403-0002/","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/advisories/GHSA-v3xw-c963-f5hc"],"source_kind":"github","identifiers":["GHSA-v3xw-c963-f5hc","CVE-2020-11111"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.10.4","vulnerable_version_range":"\u003e= 2.9.0, \u003c= 2.9.10.3"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:25.112Z","updated_at":"2023-02-01T05:03:05.000Z","epss_percentage":0.02196,"epss_percentile":0.83504},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTVyNXItNmhwai04Z2c5","url":"https://github.com/advisories/GHSA-5r5r-6hpj-8gg9","title":"Serialization gadget exploit in jackson-databind","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to com.oracle.wls.shaded.org.apache.xalan.lib.sql.JNDIConnectionPool (aka embedded Xalan in org.glassfish.web/javax.servlet.jsp.jstl).","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2021-12-09T19:15:24.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-35728","https://github.com/FasterXML/jackson-databind/issues/2999","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210129-0007/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/1ca0388c2fb37ac6a06f1c188ae89c41e3e15e84","https://github.com/advisories/GHSA-5r5r-6hpj-8gg9"],"source_kind":"github","identifiers":["GHSA-5r5r-6hpj-8gg9","CVE-2020-35728"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.10.8","vulnerable_version_range":"\u003e= 2.0.0, \u003c= 2.9.10.7"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:08.114Z","updated_at":"2023-11-21T11:40:53.000Z","epss_percentage":0.41431,"epss_percentile":0.97183},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXdycjctMzNmeC1yY3Zq","url":"https://github.com/advisories/GHSA-wrr7-33fx-rcvj","title":"Deserialization of Untrusted Data in jackson-databind","description":"**Withdrawn:** Duplicate of GHSA-cjjf-94ff-43w7","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2020-06-15T18:44:56.000Z","withdrawn_at":"2020-06-16T20:28:06.000Z","classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2018-12022","https://github.com/FasterXML/jackson-databind/issues/2052","https://github.com/FasterXML/jackson-databind/commit/28badf7ef60ac3e7ef151cd8e8ec010b8479226a","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0782","https://access.redhat.com/errata/RHSA-2019:0877","https://access.redhat.com/errata/RHSA-2019:1106","https://access.redhat.com/errata/RHSA-2019:1107","https://access.redhat.com/errata/RHSA-2019:1108","https://access.redhat.com/errata/RHSA-2019:1140","https://access.redhat.com/errata/RHSA-2019:1782","https://access.redhat.com/errata/RHSA-2019:1797","https://access.redhat.com/errata/RHSA-2019:1822","https://access.redhat.com/errata/RHSA-2019:1823","https://access.redhat.com/errata/RHSA-2019:2804","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3002","https://access.redhat.com/errata/RHSA-2019:3140","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://access.redhat.com/errata/RHSA-2019:4037","https://bugzilla.redhat.com/show_bug.cgi?id=1671098","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/7fcf88aff0d1deaa5c3c7be8d58c05ad7ad5da94b59065d8e7c50c5d@%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZEDLDUYBSTDY4GWDBUXGJNS2RFYTFVRC/","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://seclists.org/bugtraq/2019/May/68","https://security.netapp.com/advisory/ntap-20190530-0003/","https://www.blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE.pdf","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","http://www.securityfocus.com/bid/107585","https://github.com/advisories/GHSA-wrr7-33fx-rcvj"],"source_kind":"github","identifiers":["GHSA-wrr7-33fx-rcvj"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.6","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.6"},{"first_patched_version":"2.8.11.2","vulnerable_version_range":"\u003e= 2.8.0, \u003c= 2.8.11.1"},{"first_patched_version":"2.7.9.4","vulnerable_version_range":"\u003e= 2.7.0, \u003c= 2.7.9.3"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:24.140Z","updated_at":"2023-01-09T05:02:25.000Z","epss_percentage":null,"epss_percentile":null},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTk1Y20tODhmNS1mMmM3","url":"https://github.com/advisories/GHSA-95cm-88f5-f2c7","title":"jackson-databind mishandles the interaction between serialization gadgets and typing","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka aries.transaction.jms).","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2020-04-23T16:32:59.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-10672","https://github.com/FasterXML/jackson-databind/issues/2659","https://lists.debian.org/debian-lts-announce/2020/03/msg00027.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88","https://github.com/FasterXML/jackson-databind/commit/592872f4235c7f2a3280725278da55544032f72d","https://security.netapp.com/advisory/ntap-20200403-0002","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://github.com/advisories/GHSA-95cm-88f5-f2c7"],"source_kind":"github","identifiers":["GHSA-95cm-88f5-f2c7","CVE-2020-10672"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.10.4","vulnerable_version_range":"\u003e= 2.9.0, \u003c= 2.9.10.3"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:25.185Z","updated_at":"2024-07-03T21:10:50.000Z","epss_percentage":0.4007,"epss_percentile":0.97046},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWg0cmMtMzg2Zy02bTg1","url":"https://github.com/advisories/GHSA-h4rc-386g-6m85","title":"jackson-databind mishandles the interaction between serialization gadgets and typing","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.jelly.impl.Embedded (aka commons-jelly).","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2020-04-23T20:19:02.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-11620","https://github.com/FasterXML/jackson-databind/issues/2682","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88","https://github.com/FasterXML/jackson-databind/commit/77040d85e3eb6710508e6445640ae1a3d5e60c22","https://security.netapp.com/advisory/ntap-20200511-0004","https://github.com/advisories/GHSA-h4rc-386g-6m85"],"source_kind":"github","identifiers":["GHSA-h4rc-386g-6m85","CVE-2020-11620"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.10.4","vulnerable_version_range":"\u003e= 2.9.0, \u003c= 2.9.10.3"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:25.176Z","updated_at":"2024-03-15T00:41:35.000Z","epss_percentage":0.02796,"epss_percentile":0.84836},{"uuid":"GSA_kwCzR0hTQS12NTg1LTIzaGMtYzY0N80WqA","url":"https://github.com/advisories/GHSA-v585-23hc-c647","title":"Unsafe Deserialization in jackson-databind","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to `org.apache.tomcat.dbcp.dbcp.datasources.PerUserPoolDataSource`.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2021-11-19T20:13:06.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-36186","https://github.com/FasterXML/jackson-databind/issues/2997","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://security.netapp.com/advisory/ntap-20210205-0005/","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/3e8fa3beea49ea62109df9e643c9cb678dabdde1","https://github.com/advisories/GHSA-v585-23hc-c647"],"source_kind":"github","identifiers":["GHSA-v585-23hc-c647","CVE-2020-36186"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.10.8","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.9.10.8"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:12:44.323Z","updated_at":"2023-09-14T15:59:33.000Z","epss_percentage":0.02039,"epss_percentile":0.82754},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTI4OGMtY3E0aC04OGdx","url":"https://github.com/advisories/GHSA-288c-cq4h-88gq","title":"XML External Entity (XXE) Injection in Jackson Databind","description":"A flaw was found in FasterXML Jackson Databind, where it did not have entity expansion secured properly. This flaw allows vulnerability to XML external entity (XXE) attacks. The highest threat from this vulnerability is data integrity.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2021-02-18T20:51:54.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-25649","https://github.com/FasterXML/jackson-databind/issues/2589","https://bugzilla.redhat.com/show_bug.cgi?id=1887664","https://lists.apache.org/thread.html/r04529cedaca40c2ff90af4880493f9c88a8ebf4d1d6c861d23108a5a@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r0b8dc3acd4503e4ecb6fbd6ea7d95f59941168d8452ac0ab1d1d96bb@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r1b7ed0c4b6c4301d4dfd6fdbc5581b0a789d3240cab55d766f33c6c6@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r2882fc1f3032cd7be66e28787f04ec6f1874ac68d47e310e30ff7eb1@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r2b6ddb3a4f4cd11d8f6305011e1b7438ba813511f2e3ab3180c7ffda@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r31f4ee7d561d56a0c2c2c6eb1d6ce3e05917ff9654fdbfec05dc2b83@%3Ccommits.servicecomb.apache.org%3E","https://lists.apache.org/thread.html/r3e6ae311842de4e64c5d560a475b7f9cc7e0a9a8649363c6cf7537eb@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r45e7350dfc92bb192f3f88e9971c11ab2be0953cc375be3dda5170bd@%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/r5f8a1608d758936bd6bbc5eed980777437b611537bf6fff40663fc71@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r63c87aab97155f3f3cbe11d030c4a184ea0de440ee714977db02e956@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r68d029ee74ab0f3b0569d0c05f5688cb45dd3abe96a6534735252805@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r6b11eca1d646f45eb0d35d174e6b1e47cfae5295b92000856bfb6304@%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r6b11eca1d646f45eb0d35d174e6b1e47cfae5295b92000856bfb6304@%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/r6e3d4f7991542119a4ca6330271d7fbf7b9fb3abab24ada82ddf1ee4@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r78d53a0a269c18394daf5940105dc8c7f9a2399503c2e78be20abe7e@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r86c78bf7656fdb2dab69cbf17f3d7492300f771025f1a3a65d5e5ce5@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r8937a7160717fe8b2221767163c4de4f65bc5466405cb1c5310f9080@%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r8937a7160717fe8b2221767163c4de4f65bc5466405cb1c5310f9080@%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/r900d4408c4189b376d1ec580ea7740ea6f8710dc2f0b7e9c9eeb5ae0@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r90d1e97b0a743cf697d89a792a9b669909cc5a1692d1e0083a22e66c@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r91722ecfba688b0c565675f8bf380269fde8ec62b54d6161db544c22@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r94c7e86e546120f157264ba5ba61fd29b3a8d530ed325a9b4fa334d7@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r95a297eb5fd1f2d3a2281f15340e2413f952e9d5503296c3adc7201a@%3Ccommits.tomee.apache.org%3E","https://lists.apache.org/thread.html/r98bfe3b90ea9408f12c4b447edcb5638703d80bc782430aa0c210a54@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra1157e57a01d25e36b0dc17959ace758fc21ba36746de29ba1d8b130@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/ra95faf968f3463acb3f31a6fbec31453fc5045325f99f396961886d3@%3Cissues.flink.apache.org%3E","https://lists.apache.org/thread.html/raf13235de6df1d47a717199e1ecd700dff3236632f5c9a1488d9845b@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/rb674520b9f6c808c1bf263b1369e14048ec3243615f35cfd24e33604@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rc15e90bbef196a5c6c01659e015249d6c9a73581ca9afb8aeecf00d2@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/rc88f2fa2b7bd6443921727aeee7704a1fb02433e722e2abf677e0d3d@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rc959cdb57c4fe198316130ff4a5ecbf9d680e356032ff2e9f4f05d54@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/rd317f15a675d114dbf5b488d27eeb2467b4424356b16116eb18a652d@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/rd6f6bf848c2d47fa4a85c27d011d948778b8f7e58ba495968435a0b3@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdf9a34726482222c90d50ae1b9847881de67dde8cfde4999633d2cdc@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/re16f81d3ad49a93dd2f0cba9f8fc88e5fb89f30bf9a2ad7b6f3e69c1@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/re96dc7a13e13e56190a5d80f9e5440a0d0c83aeec6467b562fbf2dca@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/rf1809a1374041a969d77afab21fc38925de066bc97e86157d3ac3402@%3Ccommits.karaf.apache.org%3E","https://lists.apache.org/thread.html/r0881e23bd9034c8f51fdccdc8f4d085ba985dcd738f8520569ca5c3d@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r2eb66c182853c69ecfb52f63d3dec09495e9b65be829fd889a081ae1@%3Cdev.hive.apache.org%3E","https://lists.apache.org/thread.html/r5b130fe668503c4b7e2caf1b16f86b7f2070fd1b7ef8f26195a2ffbd@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/rd57c7582adc90e233f23f3727db3df9115b27a823b92374f11453f34@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r011d1430e8f40dff9550c3bc5d0f48b14c01ba8aecabd91d5e495386@%3Ccommits.turbine.apache.org%3E","https://lists.apache.org/thread.html/r2f5c5479f99398ef344b7ebd4d90bc3316236c45d0f3bc42090efcd7@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r407538adec3185dd35a05c9a26ae2f74425b15132470cf540f41d85b@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r605764e05e201db33b3e9c2e66ff620658f07ad74f296abe483f7042@%3Creviews.iotdb.apache.org%3E","https://lists.apache.org/thread.html/r765283e145049df9b8998f14dcd444345555aae02b1610cfb3188bf8@%3Cnotifications.iotdb.apache.org%3E","https://lists.apache.org/thread.html/r7cb5b4b3e4bd41a8042e5725b7285877a17bcbf07f4eb3f7b316af60@%3Creviews.iotdb.apache.org%3E","https://lists.apache.org/thread.html/r6cbd599b80e787f02ff7a1391d9278a03f37d6a6f4f943f0f01a62fb@%3Creviews.iotdb.apache.org%3E","https://lists.apache.org/thread.html/r73bef1bb601a9f093f915f8075eb49fcca51efade57b817afd5def07@%3Ccommits.iotdb.apache.org%3E","https://lists.apache.org/thread.html/ra409f798a1e5a6652b7097429b388650ccd65fd958cee0b6f69bba00@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/rdca8711bb7aa5d47a44682606cd0ea3497e2e922f22b7ee83e81e6c1@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r8ae961c80930e2717c75025414ce48a432cea1137c02f648b1fb9524@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r6a4f3ef6edfed2e0884269d84798f766779bbbc1005f7884e0800d61@%3Cdev.knox.apache.org%3E","https://lists.apache.org/thread.html/rc82ff47853289e9cd17f5cfbb053c04cafc75ee32e3d7223963f83bb@%3Cdev.knox.apache.org%3E","https://www.oracle.com/security-alerts/cpuApr2021.html","https://lists.apache.org/thread.html/r8764bb835bcb8e311c882ff91dd3949c9824e905e880930be56f6ba3@%3Cuser.spark.apache.org%3E","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc@%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r61db8e7dcb56dc000a5387a88f7a473bacec5ee01b9ff3f55308aacc@%3Cusers.kafka.apache.org%3E","https://www.oracle.com//security-alerts/cpujul2021.html","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7@%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/rbf4ce74b0d1fa9810dec50ba3ace0caeea677af7c27a97111c06ccb7@%3Cusers.kafka.apache.org%3E","https://lists.apache.org/thread.html/r024b7bda9c43c5560d81238748775c5ecfe01b57280f90df1f773949@%3Cissues.hive.apache.org%3E","https://lists.apache.org/thread.html/r6a6df5647583541e3cb71c75141008802f7025cee1c430d4ed78f4cc@%3Cissues.hive.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/3d932709abd0b5390efe67451653fc9efa9db677","https://github.com/FasterXML/jackson-databind/commit/612f971b78c60202e9cd75a299050c8f2d724a59","https://security.netapp.com/advisory/ntap-20210108-0007","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6X2UT4X6M7DLQYBOOHMXBWGYJ65RL2CT","https://github.com/advisories/GHSA-288c-cq4h-88gq"],"source_kind":"github","identifiers":["GHSA-288c-cq4h-88gq","CVE-2020-25649"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.6.7.4","vulnerable_version_range":"\u003e= 2.6.0, \u003c= 2.6.7.3"},{"first_patched_version":"2.10.5.1","vulnerable_version_range":"\u003e= 2.10.0.0, \u003c= 2.10.5.0"},{"first_patched_version":"2.9.10.7","vulnerable_version_range":"\u003e= 2.7.0.0, \u003c= 2.9.10.6"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:11.444Z","updated_at":"2024-03-15T00:31:24.000Z","epss_percentage":0.00011,"epss_percentile":0.01063},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZ3cXAtdjR2Ni1jODdj","url":"https://github.com/advisories/GHSA-6wqp-v4v6-c87c","title":"Deserialization of Untrusted Data","description":"An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Oracle JDBC jar in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2020-06-15T18:44:51.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2018-12023","https://github.com/FasterXML/jackson-databind/issues/2058","https://github.com/FasterXML/jackson-databind/commit/28badf7ef60ac3e7ef151cd8e8ec010b8479226a","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0782","https://access.redhat.com/errata/RHSA-2019:0877","https://access.redhat.com/errata/RHSA-2019:1106","https://access.redhat.com/errata/RHSA-2019:1107","https://access.redhat.com/errata/RHSA-2019:1108","https://access.redhat.com/errata/RHSA-2019:1140","https://access.redhat.com/errata/RHSA-2019:1782","https://access.redhat.com/errata/RHSA-2019:1797","https://access.redhat.com/errata/RHSA-2019:1822","https://access.redhat.com/errata/RHSA-2019:1823","https://access.redhat.com/errata/RHSA-2019:2804","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3002","https://access.redhat.com/errata/RHSA-2019:3140","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://access.redhat.com/errata/RHSA-2019:4037","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/7fcf88aff0d1deaa5c3c7be8d58c05ad7ad5da94b59065d8e7c50c5d@%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://seclists.org/bugtraq/2019/May/68","https://www.blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE.pdf","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html","http://www.securityfocus.com/bid/105659","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/FasterXML/jackson-databind/commit/7487cf7eb14be2f65a1eb108e8629c07ef45e0a","https://github.com/FasterXML/jackson-databind/commit/bf261d404c2f79fd3406237710d40ebb03c99d84","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZEDLDUYBSTDY4GWDBUXGJNS2RFYTFVRC","https://security.netapp.com/advisory/ntap-20190530-0003","https://github.com/advisories/GHSA-6wqp-v4v6-c87c"],"source_kind":"github","identifiers":["GHSA-6wqp-v4v6-c87c","CVE-2018-12023"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.6","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.6"},{"first_patched_version":"2.8.11.2","vulnerable_version_range":"\u003e= 2.8.0, \u003c= 2.8.11.1"},{"first_patched_version":"2.7.9.4","vulnerable_version_range":"\u003e= 2.7.0, \u003c= 2.7.9.3"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:24.131Z","updated_at":"2024-03-01T21:50:31.000Z","epss_percentage":0.049,"epss_percentile":0.88598},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWNmNnItM3dnYy1oODYz","url":"https://github.com/advisories/GHSA-cf6r-3wgc-h863","title":"Polymorphic deserialization of malicious object in jackson-databind","description":"A flaw was discovered in jackson-databind in versions before 2.9.10, 2.8.11.5, and 2.6.7.3, where it would permit polymorphic deserialization of a malicious object using commons-configuration 1 and 2 JNDI classes. An attacker could use this flaw to execute arbitrary code.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2020-05-15T18:58:58.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2019-14892","https://github.com/FasterXML/jackson-databind/issues/2462","https://github.com/FasterXML/jackson-databind/commit/41b7f9b90149e9d44a65a8261a8deedc7186f6af","https://github.com/FasterXML/jackson-databind/commit/819cdbcab51c6da9fb896380f2d46e9b7d4fdc3b","https://access.redhat.com/errata/RHSA-2020:0729","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14892","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://security.netapp.com/advisory/ntap-20200904-0005/","https://github.com/advisories/GHSA-cf6r-3wgc-h863"],"source_kind":"github","identifiers":["GHSA-cf6r-3wgc-h863","CVE-2019-14892"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.8.11.5","vulnerable_version_range":"\u003e= 2.7.0, \u003c= 2.8.11.4"},{"first_patched_version":"2.9.10","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.10"},{"first_patched_version":"2.6.7.3","vulnerable_version_range":"\u003c= 2.6.7.2"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:25.137Z","updated_at":"2023-09-14T15:07:14.000Z","epss_percentage":0.00873,"epss_percentile":0.74214},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTI3eGotcnF4NS0yMjU1","url":"https://github.com/advisories/GHSA-27xj-rqx5-2255","title":"jackson-databind mishandles the interaction between serialization gadgets and typing","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.springframework.aop.config.MethodLocatingFactoryBean (aka spring-aop).","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2020-05-15T18:58:44.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-11619","https://github.com/FasterXML/jackson-databind/issues/2680","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200511-0004/","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/advisories/GHSA-27xj-rqx5-2255"],"source_kind":"github","identifiers":["GHSA-27xj-rqx5-2255","CVE-2020-11619"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.10.4","vulnerable_version_range":"\u003e= 2.9.0, \u003c= 2.9.10.3"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:25.093Z","updated_at":"2023-02-01T05:02:59.000Z","epss_percentage":0.01826,"epss_percentile":0.81832},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTVwMzQtNW02cC1wNThn","url":"https://github.com/advisories/GHSA-5p34-5m6p-p58g","title":"jackson-databind mishandles the interaction between serialization gadgets and typing","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.hadoop.shaded.com.zaxxer.hikari.HikariConfig (aka shaded hikari-config).","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2020-04-23T21:08:40.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-9546","https://github.com/FasterXML/jackson-databind/issues/2631","https://lists.apache.org/thread.html/r35d30db00440ef63b791c4b7f7acb036e14d4a23afa2a249cb66c0fd@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r893a0104e50c1c2559eb9a5812add28ae8c3e5f43712947a9847ec18@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r9464a40d25c3ba1a55622db72f113eb494a889656962d098c70c5bb1@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb6fecb5e96a6d61e175ff49f33f2713798dd05cf03067c169d195596@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd49ab9565bec436a896bc00c4b9fc9dce1598e106c318524fbdfec6@%3Cissues.zookeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/03/msg00008.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.apache.org/thread.html/r98c9b6e4c9e17792e2cd1ec3e4aa20b61a791939046d3f10888176bb@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd5a4457be4623038c3989294429bc063eec433a2e55995d81591e2ca@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd4df698d5d8e635144d2994922bf0842e933809eae259521f3b5097@%3Cissues.zookeeper.apache.org%3E","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://security.netapp.com/advisory/ntap-20200904-0006/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/advisories/GHSA-5p34-5m6p-p58g"],"source_kind":"github","identifiers":["GHSA-5p34-5m6p-p58g","CVE-2020-9546"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.10.4","vulnerable_version_range":"\u003e= 2.9.0, \u003c= 2.9.10.3"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:25.156Z","updated_at":"2023-02-01T05:02:59.000Z","epss_percentage":0.02327,"epss_percentile":0.83854},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLThjNGotMzRyNC14cjhn","url":"https://github.com/advisories/GHSA-8c4j-34r4-xr8g","title":"Unsafe Deserialization in jackson-databind","description":"FasterXML jackson-databind 2.x before 2.9.10.8 and 2.6.7.5 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.cpdsadapter.DriverAdapterCPDS.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2021-12-09T19:16:18.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-36180","https://github.com/FasterXML/jackson-databind/issues/3004","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/3ded28aece694d0df39c9f0fa1ff385b14a8656b","https://github.com/advisories/GHSA-8c4j-34r4-xr8g"],"source_kind":"github","identifiers":["GHSA-8c4j-34r4-xr8g","CVE-2020-36180"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.6.7.5","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.6.7.5"},{"first_patched_version":"2.9.10.8","vulnerable_version_range":"\u003e= 2.7.0, \u003c 2.9.10.8"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:10.441Z","updated_at":"2023-09-14T16:13:01.000Z","epss_percentage":0.01957,"epss_percentile":0.82508},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTg5cXItMzY5Zi01bTV4","url":"https://github.com/advisories/GHSA-89qr-369f-5m5x","title":"Unsafe Deserialization in jackson-databind","description":"FasterXML jackson-databind 2.x before 2.9.10.8 and 2.6.7.5 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.cpdsadapter.DriverAdapterCPDS.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2021-12-09T19:15:46.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-36182","https://github.com/FasterXML/jackson-databind/issues/3004","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/3ded28aece694d0df39c9f0fa1ff385b14a8656b","https://github.com/advisories/GHSA-89qr-369f-5m5x"],"source_kind":"github","identifiers":["GHSA-89qr-369f-5m5x","CVE-2020-36182"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.6.7.5","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.6.7.5"},{"first_patched_version":"2.9.10.8","vulnerable_version_range":"\u003e= 2.7.0, \u003c 2.9.10.8"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:10.404Z","updated_at":"2023-09-14T16:08:37.000Z","epss_percentage":0.01957,"epss_percentile":0.82508},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTh3MjYtNmYyNS1jbTl4","url":"https://github.com/advisories/GHSA-8w26-6f25-cm9x","title":"Unsafe Deserialization in jackson-databind","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to `org.apache.tomcat.dbcp.dbcp2.datasources.SharedPoolDataSource`.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2021-12-09T19:16:02.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-36185","https://github.com/FasterXML/jackson-databind/issues/2998","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/567194c53ae91f0a14dc27239afb739b1c10448a","https://github.com/advisories/GHSA-8w26-6f25-cm9x"],"source_kind":"github","identifiers":["GHSA-8w26-6f25-cm9x","CVE-2020-36185"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.10.8","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.9.10.8"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:10.423Z","updated_at":"2023-09-14T15:52:49.000Z","epss_percentage":0.01957,"epss_percentile":0.82508},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTlncGgtMjJ4aC04eDk4","url":"https://github.com/advisories/GHSA-9gph-22xh-8x98","title":"Unsafe Deserialization in jackson-databind","description":"FasterXML jackson-databind 2.x before 2.9.10.8 and 2.6.7.5 mishandles the interaction between serialization gadgets and typing, related to `oadd.org.apache.commons.dbcp.cpdsadapter.DriverAdapterCPDS`.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2021-12-09T19:15:54.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-36179","https://github.com/FasterXML/jackson-databind/issues/3004","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.apache.org/thread.html/rc255f41d9a61d3dc79a51fb5c713de4ae10e71e3673feeb0b180b436@%3Cissues.spark.apache.org%3E","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/3ded28aece694d0df39c9f0fa1ff385b14a8656b","https://github.com/advisories/GHSA-9gph-22xh-8x98"],"source_kind":"github","identifiers":["GHSA-9gph-22xh-8x98","CVE-2020-36179"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.6.7.5","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.6.7.5"},{"first_patched_version":"2.9.10.8","vulnerable_version_range":"\u003e= 2.7.0, \u003c 2.9.10.8"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:10.414Z","updated_at":"2023-09-14T16:07:40.000Z","epss_percentage":0.61296,"epss_percentile":0.98175},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXA0M3gteGZqZi01amhy","url":"https://github.com/advisories/GHSA-p43x-xfjf-5jhr","title":"jackson-databind mishandles the interaction between serialization gadgets and typing","description":"FasterXML jackson-databind 2.x before 2.9.10.4, 2.8.11.6, and 2.7.9.7 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPConfig (aka anteros-core).","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2020-05-15T18:59:01.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-9548","https://github.com/FasterXML/jackson-databind/issues/2634","https://lists.apache.org/thread.html/r35d30db00440ef63b791c4b7f7acb036e14d4a23afa2a249cb66c0fd@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r9464a40d25c3ba1a55622db72f113eb494a889656962d098c70c5bb1@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb6fecb5e96a6d61e175ff49f33f2713798dd05cf03067c169d195596@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd49ab9565bec436a896bc00c4b9fc9dce1598e106c318524fbdfec6@%3Cissues.zookeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/03/msg00008.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.apache.org/thread.html/r98c9b6e4c9e17792e2cd1ec3e4aa20b61a791939046d3f10888176bb@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd5a4457be4623038c3989294429bc063eec433a2e55995d81591e2ca@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd4df698d5d8e635144d2994922bf0842e933809eae259521f3b5097@%3Cissues.zookeeper.apache.org%3E","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/9f4e97019fb0dd836533d0b6198c88787e235ae2","https://github.com/FasterXML/jackson-databind/commit/1e64db6a2fad331f96c7363fda3bc5f3dffa25bb","https://security.netapp.com/advisory/ntap-20200904-0006","https://github.com/advisories/GHSA-p43x-xfjf-5jhr"],"source_kind":"github","identifiers":["GHSA-p43x-xfjf-5jhr","CVE-2020-9548"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.7.9.7","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.7.9.7"},{"first_patched_version":"2.8.11.6","vulnerable_version_range":"\u003e= 2.8.0, \u003c 2.8.11.6"},{"first_patched_version":"2.9.10.4","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.10.4"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:25.166Z","updated_at":"2024-03-15T00:20:09.000Z","epss_percentage":0.13945,"epss_percentile":0.9372},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXFyN2otaDZnZy1qbWdj","url":"https://github.com/advisories/GHSA-qr7j-h6gg-jmgc","title":"Deserialization of Untrusted Data in jackson-databind","description":"An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2019-07-16T17:42:21.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2018-11307","https://access.redhat.com/errata/RHSA-2019:0782","https://github.com/FasterXML/jackson-databind/issues/2032","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://nvd.nist.gov/vuln/detail/CVE-2017-7525","https://access.redhat.com/errata/RHSA-2019:1822","https://access.redhat.com/errata/RHSA-2019:1823","https://access.redhat.com/errata/RHSA-2019:2804","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3002","https://access.redhat.com/errata/RHSA-2019:3140","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://access.redhat.com/errata/RHSA-2019:4037","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/7fcf88aff0d1deaa5c3c7be8d58c05ad7ad5da94b59065d8e7c50c5d@%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://github.com/FasterXML/jackson-databind/commit/051bd5e447fbc9539e12a4fe90eb989dba0c656","https://github.com/FasterXML/jackson-databind/commit/27b4defc270454dea6842bd9279f17387eceb73","https://github.com/FasterXML/jackson-databind/commit/78e78738d69adcb59fdac9fc12d9053ce8809f3d","https://github.com/advisories/GHSA-qr7j-h6gg-jmgc"],"source_kind":"github","identifiers":["GHSA-qr7j-h6gg-jmgc","CVE-2018-11307"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.8.11.2","vulnerable_version_range":"\u003e= 2.8.0, \u003c= 2.8.11.1"},{"first_patched_version":"2.7.9.4","vulnerable_version_range":"\u003e= 2.0.0, \u003c= 2.7.9.3"},{"first_patched_version":"2.9.6","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.6"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:06.122Z","updated_at":"2024-03-01T21:46:20.000Z","epss_percentage":0.12636,"epss_percentile":0.93533},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTY0NXAtODhxaC13Mzk4","url":"https://github.com/advisories/GHSA-645p-88qh-w398","title":"Arbitrary Code Execution in jackson-databind","description":"FasterXML jackson-databind 2.x before 2.9.7, 2.8.11.3, 2.7.9.5, and 2.6.7.3 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2019-01-04T19:06:55.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2018-14718","https://github.com/FasterXML/jackson-databind/issues/2097","https://github.com/FasterXML/jackson-databind/commit/87d29af25e82a249ea15858e2d4ecbf64091db44","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0782","https://access.redhat.com/errata/RHSA-2019:0877","https://access.redhat.com/errata/RHSA-2019:1782","https://access.redhat.com/errata/RHSA-2019:1797","https://access.redhat.com/errata/RHSA-2019:1822","https://access.redhat.com/errata/RHSA-2019:1823","https://access.redhat.com/errata/RHSA-2019:2804","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3002","https://access.redhat.com/errata/RHSA-2019:3140","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://access.redhat.com/errata/RHSA-2019:4037","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.7","https://github.com/advisories/GHSA-645p-88qh-w398","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/6a78f88716c3c57aa74ec05764a37ab3874769a347805903b393b286@%3Cdev.lucene.apache.org%3E","https://lists.apache.org/thread.html/82b01bfb6787097427ce97cec6a7127e93718bc05d1efd5eaffc228f@%3Cdev.lucene.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/ba973114605d936be276ee6ce09dfbdbf78aa56f6cdc6e79bfa7b8df@%3Cdev.lucene.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r1d4a247329a8478073163567bbc8c8cb6b49c6bfc2bf58153a857af1@%3Ccommits.druid.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/03/msg00005.html","https://seclists.org/bugtraq/2019/May/68","https://security.netapp.com/advisory/ntap-20190530-0003/","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","http://www.securityfocus.com/bid/106601"],"source_kind":"github","identifiers":["GHSA-645p-88qh-w398","CVE-2018-14718"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.6.7.3","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.6.7.3"},{"first_patched_version":"2.7.9.5","vulnerable_version_range":"\u003e= 2.7.0, \u003c= 2.7.9.4"},{"first_patched_version":"2.8.11.3","vulnerable_version_range":"\u003e= 2.8.0, \u003c= 2.8.11.2"},{"first_patched_version":"2.9.7","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.7"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:12:59.028Z","updated_at":"2023-09-14T14:00:56.000Z","epss_percentage":0.13036,"epss_percentile":0.93735},{"uuid":"GSA_kwCzR0hTQS1yZ3Y5LXE1NDMtcnFnNM4AAvJu","url":"https://github.com/advisories/GHSA-rgv9-q543-rqg4","title":"Uncontrolled Resource Consumption in FasterXML jackson-databind","description":"In FasterXML jackson-databind before 2.12.7.1 and in 2.13.x before 2.13.4, resource exhaustion can occur because of a lack of a check in BeanDeserializer._deserializeFromArray to prevent use of deeply nested arrays. This issue can only happen when the `UNWRAP_SINGLE_VALUE_ARRAYS` feature is explicitly enabled.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-10-03T00:00:31.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":8.2,"cvss_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","references":["https://nvd.nist.gov/vuln/detail/CVE-2022-42004","https://github.com/FasterXML/jackson-databind/issues/3582","https://github.com/FasterXML/jackson-databind/commit/063183589218fec19a9293ed2f17ec53ea80ba88","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=50490","https://security.gentoo.org/glsa/202210-21","https://www.debian.org/security/2022/dsa-5283","https://lists.debian.org/debian-lts-announce/2022/11/msg00035.html","https://github.com/FasterXML/jackson-databind/commit/35de19e7144c4df8ab178b800ba86e80c3d84252","https://github.com/FasterXML/jackson-databind/commit/cd090979b7ea78c75e4de8a4aed04f7e9fa8deea","https://security.netapp.com/advisory/ntap-20221118-0008","https://github.com/advisories/GHSA-rgv9-q543-rqg4"],"source_kind":"github","identifiers":["GHSA-rgv9-q543-rqg4","CVE-2022-42004"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":44.17982064259438,"packages":[{"versions":[{"first_patched_version":"2.13.4","vulnerable_version_range":"\u003e= 2.13.0, \u003c 2.13.4"},{"first_patched_version":"2.12.7.1","vulnerable_version_range":"\u003c 2.12.7.1"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:11:50.357Z","updated_at":"2025-06-05T01:14:08.856Z","epss_percentage":0.00219,"epss_percentile":0.44791},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXdoOGctM2oyYy1ycWo1","url":"https://github.com/advisories/GHSA-wh8g-3j2c-rqj5","title":"Serialization gadgets exploit in jackson-databind","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.PerUserPoolDataSource.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2021-12-09T19:15:00.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-35490","https://github.com/FasterXML/jackson-databind/issues/2986","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/41b8bdb5ccc1d8edb71acf1c8234da235a24249d","https://security.netapp.com/advisory/ntap-20210122-0005","https://github.com/advisories/GHSA-wh8g-3j2c-rqj5"],"source_kind":"github","identifiers":["GHSA-wh8g-3j2c-rqj5","CVE-2020-35490"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.10.8","vulnerable_version_range":"\u003e= 2.0.0, \u003c= 2.9.10.7"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:07.948Z","updated_at":"2025-06-05T01:14:10.784Z","epss_percentage":0.04749,"epss_percentile":0.88888},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWNnZ2otZnZ2My1jcXd2","url":"https://github.com/advisories/GHSA-cggj-fvv3-cqwv","title":"FasterXML jackson-databind allows unauthenticated remote code execution ","description":"FasterXML jackson-databind before before 2.6.7.5, 2.7.x before 2.7.9.3, 2.8.x before 2.8.11.1, and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the c3p0 libraries are available in the classpath.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2018-10-16T17:45:18.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2018-7489","https://github.com/FasterXML/jackson-databind/issues/1931","https://access.redhat.com/errata/RHSA-2018:1447","https://access.redhat.com/errata/RHSA-2018:1448","https://access.redhat.com/errata/RHSA-2018:1449","https://access.redhat.com/errata/RHSA-2018:1450","https://access.redhat.com/errata/RHSA-2018:1451","https://access.redhat.com/errata/RHSA-2018:1786","https://access.redhat.com/errata/RHSA-2018:2088","https://access.redhat.com/errata/RHSA-2018:2089","https://access.redhat.com/errata/RHSA-2018:2090","https://access.redhat.com/errata/RHSA-2018:2938","https://access.redhat.com/errata/RHSA-2018:2939","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3149","https://github.com/advisories/GHSA-cggj-fvv3-cqwv","https://lists.apache.org/thread.html/r1d4a247329a8478073163567bbc8c8cb6b49c6bfc2bf58153a857af1@%3Ccommits.druid.apache.org%3E","https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US\u0026docId=emr_na-hpesbhf03902en_us","https://www.debian.org/security/2018/dsa-4190","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html","http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html","http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html","https://github.com/FasterXML/jackson-databind/commit/6799f8f10cc78e9af6d443ed6982d00a13f2e7d2","https://github.com/FasterXML/jackson-databind/commit/c921f0935d5e41bf206e702d8077a275ba1a6efc","https://github.com/FasterXML/jackson-databind/commit/ca2bfc86af82a1479112004b663ba74c760752e6","https://github.com/FasterXML/jackson-databind/commit/e66c0a9d3c926ff1b63bf586c824ead1d02f2a3d","https://security.netapp.com/advisory/ntap-20180328-0001","https://github.com/FasterXML/jackson-databind/commit/bc22f90eb7f896ace9567598a99cb1ff6e0f9d9d"],"source_kind":"github","identifiers":["GHSA-cggj-fvv3-cqwv","CVE-2018-7489"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.6.7.5","vulnerable_version_range":"\u003c 2.6.7.5"},{"first_patched_version":"2.7.9.3","vulnerable_version_range":"\u003e= 2.7.0, \u003c 2.7.9.3"},{"first_patched_version":"2.8.11.1","vulnerable_version_range":"\u003e= 2.8.0, \u003c= 2.8.11.0"},{"first_patched_version":"2.9.5","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.5"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:12:59.280Z","updated_at":"2025-06-05T01:14:14.767Z","epss_percentage":0.4268,"epss_percentile":0.9729},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJmeDYtdnA5Zy1yaDd2","url":"https://github.com/advisories/GHSA-rfx6-vp9g-rh7v","title":"jackson-databind vulnerable to remote code execution due to incorrect deserialization and blocklist bypass","description":"FasterXML jackson-databind through 2.8.10 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafted JSON input to the readValue method of the ObjectMapper, bypassing a blacklist that is ineffective if the Spring libraries are available in the classpath.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2018-10-18T17:42:48.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2017-17485","https://github.com/FasterXML/jackson-databind/issues/1855","https://access.redhat.com/errata/RHSA-2018:0116","https://access.redhat.com/errata/RHSA-2018:0342","https://access.redhat.com/errata/RHSA-2018:0478","https://access.redhat.com/errata/RHSA-2018:0479","https://access.redhat.com/errata/RHSA-2018:0480","https://access.redhat.com/errata/RHSA-2018:0481","https://access.redhat.com/errata/RHSA-2018:1447","https://access.redhat.com/errata/RHSA-2018:1448","https://access.redhat.com/errata/RHSA-2018:1449","https://access.redhat.com/errata/RHSA-2018:1450","https://access.redhat.com/errata/RHSA-2018:1451","https://access.redhat.com/errata/RHSA-2018:2930","https://access.redhat.com/errata/RHSA-2019:1782","https://access.redhat.com/errata/RHSA-2019:1797","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US\u0026docId=emr_na-hpesbhf03902en_us","https://www.debian.org/security/2018/dsa-4114","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/FasterXML/jackson-databind/commit/10fe7f17ea7c8da2a71e7a0c774b420a1d5c1b50","https://github.com/FasterXML/jackson-databind/commit/2235894210c75f624a3d0cd60bfb0434a20a18bf","https://github.com/FasterXML/jackson-databind/commit/459107dccc9b3ea991af3e6ad0953e54b01ef7c1","https://github.com/FasterXML/jackson-databind/commit/4f16f67ebd22c7522fdbb8a7eb87e3026a807d61","https://github.com/FasterXML/jackson-databind/commit/978798382ceb72229e5036aa1442943933d6d171","https://github.com/FasterXML/jackson-databind/commit/bb45fb16709018842f858f1a6e1118676aaa34bd","https://github.com/FasterXML/jackson-databind/commit/eb217dd0f87c5fb471e0668575644aa7eba9a3d3","https://github.com/FasterXML/jackson-databind/commit/f031f27a31625d07922bdd090664c69544200a5d","https://github.com/irsl/jackson-rce-via-spel","https://security.netapp.com/advisory/ntap-20180201-0003","https://web.archive.org/web/20200927162225/http://www.securityfocus.com/archive/1/541652/100/0/threaded","https://github.com/advisories/GHSA-rfx6-vp9g-rh7v"],"source_kind":"github","identifiers":["GHSA-rfx6-vp9g-rh7v","CVE-2017-17485"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.7.9.2","vulnerable_version_range":"\u003c 2.7.9.2"},{"first_patched_version":"2.8.11","vulnerable_version_range":"\u003e= 2.8.0, \u003c 2.8.11"},{"first_patched_version":"2.9.4","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.4"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:34.335Z","updated_at":"2025-06-05T01:14:14.861Z","epss_percentage":0.77043,"epss_percentile":0.98893},{"uuid":"GSA_kwCzR0hTQS1ycHIzLWN3MzktM3B4aM4AAtZ7","url":"https://github.com/advisories/GHSA-rpr3-cw39-3pxh","title":"jackson-databind vulnerable to unsafe deserialization","description":"The com.fasterxml.jackson.core:jackson-databind library before version 2.9.10.4 is vulnerable to an Unsafe Deserialization vulnerability when handling interactions related to the class `ignite-jta`.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-07-15T19:41:47.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-10650","https://github.com/FasterXML/jackson-databind/issues/2658","https://github.com/luisgarciacheckmarx/LGV_onefile/issues/19","https://github.com/FasterXML/jackson-databind/pull/2864","https://github.com/FasterXML/jackson-databind/commit/a424c038ba0c0d65e579e22001dec925902ac0ef","https://www.oracle.com/security-alerts/cpujan2021.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://www.oracle.com/security-alerts/cpuoct2022.html","https://lists.debian.org/debian-lts-announce/2023/04/msg00032.html","https://security.netapp.com/advisory/ntap-20230818-0007","https://github.com/advisories/GHSA-rpr3-cw39-3pxh"],"source_kind":"github","identifiers":["GHSA-rpr3-cw39-3pxh","CVE-2020-10650"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.10.4","vulnerable_version_range":"\u003c= 2.9.10.3"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:12:10.583Z","updated_at":"2025-06-05T01:15:59.516Z","epss_percentage":0.05253,"epss_percentile":0.89475},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTU4cHAtOWM3Ni01NjI1","url":"https://github.com/advisories/GHSA-58pp-9c76-5625","title":"jackson-databind mishandles the interaction between serialization gadgets and typing","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/commons-proxy).","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2020-06-10T21:12:41.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-11112","https://github.com/FasterXML/jackson-databind/issues/2666","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200403-0002/","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/advisories/GHSA-58pp-9c76-5625"],"source_kind":"github","identifiers":["GHSA-58pp-9c76-5625","CVE-2020-11112"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.10.4","vulnerable_version_range":"\u003e= 2.9.0, \u003c= 2.9.10.3"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:24.225Z","updated_at":"2023-02-01T05:03:03.000Z","epss_percentage":0.11418,"epss_percentile":0.92941},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWd3cDQtaGZ2Ni1wN2h3","url":"https://github.com/advisories/GHSA-gwp4-hfv6-p7hw","title":"Deserialization of untrusted data in FasterXML jackson-databind","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9.2, 2.8.11.4, 2.7.9.6, and 2.6.7.3. This occurs when Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the logback jar in the classpath.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2019-08-01T19:18:06.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2019-14439","https://github.com/FasterXML/jackson-databind/commit/ad418eeb974e357f2797aef64aa0e3ffaaa6125b","https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.1...jackson-databind-2.9.9.2","https://github.com/FasterXML/jackson-databind/issues/2389","https://access.redhat.com/errata/RHSA-2019:3200","https://lists.apache.org/thread.html/0d4b630d9ee724aee50703397d9d1afa2b2befc9395ba7797d0ccea9@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/2d2a76440becb610b9a9cb49b15eac3934b02c2dbcaacde1000353e4@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/34717424b4d08b74f65c09a083d6dd1cb0763f37a15d6de135998c1d@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/3f99ae8dcdbd69438cb733d745ee3ad5e852068490719a66509b4592@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/56c8042873595b8c863054c7bfccab4bf2c01c6f5abedae249d914b9@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5ecc333113b139429f4f05000d4aa2886974d4df3269c1dd990bb319@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5fc0e16b7af2590bf1e97c76c136291c4fdb244ee63c65c485c9a7a1@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/87e46591de8925f719664a845572d184027258c5a7af0a471b53c77b@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef@%3Cdev.struts.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/ee0a051428d2c719acfa297d0854a189ea5e284ef3ed491fa672f4be@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/08/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544/","https://seclists.org/bugtraq/2019/Oct/6","https://security.netapp.com/advisory/ntap-20190814-0001/","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://github.com/advisories/GHSA-gwp4-hfv6-p7hw"],"source_kind":"github","identifiers":["GHSA-gwp4-hfv6-p7hw","CVE-2019-14439"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.8.11.4","vulnerable_version_range":"\u003e= 2.8.0, \u003c 2.8.11.4"},{"first_patched_version":"2.6.7.3","vulnerable_version_range":"\u003c 2.6.7.3"},{"first_patched_version":"2.7.9.6","vulnerable_version_range":"\u003e= 2.7.0, \u003c 2.7.9.6"},{"first_patched_version":"2.9.9.2","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.9.2"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:07.671Z","updated_at":"2023-11-27T23:03:29.000Z","epss_percentage":0.10318,"epss_percentile":0.92687},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTlteGYtZzN4Ni13djc0","url":"https://github.com/advisories/GHSA-9mxf-g3x6-wv74","title":"Server-Side Request Forgery (SSRF) in jackson-databind","description":"FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2019-01-04T19:07:06.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2018-14721","https://github.com/FasterXML/jackson-databind/issues/2097","https://github.com/FasterXML/jackson-databind/commit/87d29af25e82a249ea15858e2d4ecbf64091db44","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0782","https://access.redhat.com/errata/RHSA-2019:1106","https://access.redhat.com/errata/RHSA-2019:1107","https://access.redhat.com/errata/RHSA-2019:1108","https://access.redhat.com/errata/RHSA-2019:1140","https://access.redhat.com/errata/RHSA-2019:1822","https://access.redhat.com/errata/RHSA-2019:1823","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://access.redhat.com/errata/RHSA-2019:4037","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.7","https://github.com/advisories/GHSA-9mxf-g3x6-wv74","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/03/msg00005.html","https://seclists.org/bugtraq/2019/May/68","https://security.netapp.com/advisory/ntap-20190530-0003/","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"source_kind":"github","identifiers":["GHSA-9mxf-g3x6-wv74","CVE-2018-14721"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.7.9.5","vulnerable_version_range":"\u003e= 2.7.0, \u003c= 2.7.9.4"},{"first_patched_version":"2.8.11.3","vulnerable_version_range":"\u003e= 2.8.0, \u003c= 2.8.11.2"},{"first_patched_version":"2.9.7","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.7"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:12:59.254Z","updated_at":"2025-06-05T01:18:10.986Z","epss_percentage":0.09895,"epss_percentile":0.92586},{"uuid":"GSA_kwCzR0hTQS1qampoLWpqeHAtd3BmZs4AAvJv","url":"https://github.com/advisories/GHSA-jjjh-jjxp-wpff","title":"Uncontrolled Resource Consumption in Jackson-databind","description":"In FasterXML jackson-databind 2.4.0-rc1 until 2.12.7.1 and in 2.13.x before 2.13.4.2 resource exhaustion can occur because of a lack of a check in primitive value deserializers to avoid deep wrapper array nesting, when the UNWRAP_SINGLE_VALUE_ARRAYS feature is enabled. This was patched in 2.12.7.1, 2.13.4.2, and 2.14.0.\n\nCommits that introduced vulnerable code are \nhttps://github.com/FasterXML/jackson-databind/commit/d499f2e7bbc5ebd63af11e1f5cf1989fa323aa45, https://github.com/FasterXML/jackson-databind/commit/0e37a39502439ecbaa1a5b5188387c01bf7f7fa1, and https://github.com/FasterXML/jackson-databind/commit/7ba9ac5b87a9d6ac0d2815158ecbeb315ad4dcdc.\n\nFix commits are https://github.com/FasterXML/jackson-databind/commit/cd090979b7ea78c75e4de8a4aed04f7e9fa8deea and https://github.com/FasterXML/jackson-databind/commit/d78d00ee7b5245b93103fef3187f70543d67ca33.\n\nThe `2.13.4.1` release does fix this issue, however it also references a non-existent jackson-bom which causes build failures for gradle users. See https://github.com/FasterXML/jackson-databind/issues/3627#issuecomment-1277957548 for details. This is fixed in `2.13.4.2` which is listed in the advisory metadata so that users are not subjected to unnecessary build failures","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-10-03T00:00:31.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2022-42003","https://github.com/FasterXML/jackson-databind/issues/3590","https://github.com/FasterXML/jackson-databind/commit/d78d00ee7b5245b93103fef3187f70543d67ca33","https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=51020","https://github.com/FasterXML/jackson-databind/blob/2.13/release-notes/VERSION-2.x","https://security.gentoo.org/glsa/202210-21","https://github.com/FasterXML/jackson-databind/issues/3627","https://github.com/FasterXML/jackson-databind/commit/cd090979b7ea78c75e4de8a4aed04f7e9fa8deea","https://www.debian.org/security/2022/dsa-5283","https://lists.debian.org/debian-lts-announce/2022/11/msg00035.html","https://github.com/FasterXML/jackson-databind/commit/7ba9ac5b87a9d6ac0d2815158ecbeb315ad4dcdc","https://github.com/FasterXML/jackson-databind/commit/0e37a39502439ecbaa1a5b5188387c01bf7f7fa1","https://github.com/FasterXML/jackson-databind/commit/d499f2e7bbc5ebd63af11e1f5cf1989fa323aa45","https://github.com/FasterXML/jackson-databind/commits/jackson-databind-2.4.0-rc1?after=75b97b8519f0d50c62523ad85170d80a197a2c86+174\u0026branch=jackson-databind-2.4.0-rc1\u0026qualified_name=refs%2Ftags%2Fjackson-databind-2.4.0-rc1","https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.13.4.1...jackson-databind-2.13.4.2","https://github.com/FasterXML/jackson-databind/commit/2c4a601c626f7790cad9d3c322d244e182838288","https://security.netapp.com/advisory/ntap-20221124-0004","https://github.com/advisories/GHSA-jjjh-jjxp-wpff"],"source_kind":"github","identifiers":["GHSA-jjjh-jjxp-wpff","CVE-2022-42003"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.13.4.2","vulnerable_version_range":"\u003e= 2.13.0, \u003c 2.13.4.2"},{"first_patched_version":"2.12.7.1","vulnerable_version_range":"\u003e= 2.4.0-rc1, \u003c 2.12.7.1"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:11:51.356Z","updated_at":"2024-09-13T18:29:14.000Z","epss_percentage":0.00168,"epss_percentile":0.38955},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTltNmYtN3hjcS04dmY4","url":"https://github.com/advisories/GHSA-9m6f-7xcq-8vf8","title":"Unsafe Deserialization in jackson-databind","description":"FasterXML jackson-databind 2.x before 2.9.10.8 and 2.6.7.5 mishandles the interaction between serialization gadgets and typing, related to org.docx4j.org.apache.xalan.lib.sql.JNDIConnectionPool.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2021-12-09T19:16:34.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-36183","https://github.com/FasterXML/jackson-databind/issues/3003","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/12e23c962ffb4cf1857c5461d72ae54cc8008f29","https://github.com/advisories/GHSA-9m6f-7xcq-8vf8"],"source_kind":"github","identifiers":["GHSA-9m6f-7xcq-8vf8","CVE-2020-36183"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.6.7.5","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.6.7.5"},{"first_patched_version":"2.9.10.8","vulnerable_version_range":"\u003e= 2.7.00, \u003c 2.9.10.8"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:10.459Z","updated_at":"2023-09-14T16:15:44.000Z","epss_percentage":0.02421,"epss_percentile":0.83686},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWg4MjItcjRyNS12OGpn","url":"https://github.com/advisories/GHSA-h822-r4r5-v8jg","title":"Polymorphic Typing issue in FasterXML jackson-databind","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10, 2.8.11.5, and 2.6.7.3. It is related to `com.zaxxer.hikari.HikariConfig`.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2019-09-23T18:33:25.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2019-14540","https://github.com/FasterXML/jackson-databind/blob/master/release-notes/VERSION-2.x","https://github.com/FasterXML/jackson-databind/issues/2410","https://github.com/FasterXML/jackson-databind/issues/2449","https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://lists.apache.org/thread.html/0fcef7321095ce0bc597d468d150cff3d647f4cb3aef3bd4d20e1c69@%3Ccommits.tinkerpop.apache.org%3E","https://lists.apache.org/thread.html/40c00861b53bb611dee7d6f35f864aa7d1c1bd77df28db597cbf27e1@%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/a360b46061c91c5cad789b6c3190aef9b9f223a2b75c9c9f046fe016@%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/a4f2c9fb36642a48912cdec6836ec00e497427717c5d377f8d7ccce6@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ad0d238e97a7da5eca47a014f0f7e81f440ed6bf74a93183825e18b9@%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/dc6b5cad721a4f6b3b62ed1163894941140d9d5656140fb757505ca0@%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/e90c3feb21702e68a8c08afce37045adb3870f2bf8223fa403fb93fb@%3Ccommits.hbase.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r8aaf4ee16bbaf6204731d4770d96ebb34b258cd79b491f9cdd7f2540@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html","https://seclists.org/bugtraq/2019/Oct/6","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/FasterXML/jackson-databind/commit/d4983c740fec7d5576b207a8c30a63d3ea7443de","https://github.com/FasterXML/jackson-databind/commit/73c1c2cc76e6cdd7f3a5615cbe3207fe96e4d3db","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT","https://security.netapp.com/advisory/ntap-20191004-0002","https://github.com/advisories/GHSA-h822-r4r5-v8jg"],"source_kind":"github","identifiers":["GHSA-h822-r4r5-v8jg","CVE-2019-14540"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.6.7.3","vulnerable_version_range":"\u003c 2.6.7.3"},{"first_patched_version":"2.8.11.5","vulnerable_version_range":"\u003e= 2.7.0, \u003c 2.8.11.5"},{"first_patched_version":"2.9.10","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.10"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:28.073Z","updated_at":"2024-03-15T00:58:38.000Z","epss_percentage":0.07082,"epss_percentile":0.9064},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWM4aG0tN2hwcS03amhn","url":"https://github.com/advisories/GHSA-c8hm-7hpq-7jhg","title":"com.fasterxml.jackson.core:jackson-databind vulnerable to Deserialization of Untrusted Data","description":"FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2019-01-04T19:07:03.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2018-19362","https://github.com/FasterXML/jackson-databind/issues/2186","https://github.com/FasterXML/jackson-databind/commit/42912cac4753f3f718ece875e4d486f8264c2f2b","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0782","https://access.redhat.com/errata/RHSA-2019:0877","https://access.redhat.com/errata/RHSA-2019:1782","https://access.redhat.com/errata/RHSA-2019:1797","https://access.redhat.com/errata/RHSA-2019:1822","https://access.redhat.com/errata/RHSA-2019:1823","https://access.redhat.com/errata/RHSA-2019:2804","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3002","https://access.redhat.com/errata/RHSA-2019:3140","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://access.redhat.com/errata/RHSA-2019:4037","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.8","https://github.com/advisories/GHSA-c8hm-7hpq-7jhg","https://issues.apache.org/jira/browse/TINKERPOP-2121","https://lists.apache.org/thread.html/37e1ed724a1b0e5d191d98c822c426670bdfde83804567131847d2a3@%3Cdevnull.infra.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/c70da3cb6e3f03e0ad8013e38b6959419d866c4a7c80fdd34b73f25c@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/03/msg00005.html","https://seclists.org/bugtraq/2019/May/68","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","http://www.securityfocus.com/bid/107985","https://github.com/FasterXML/jackson-databind/commit/72cd4025a229fb28ec133235003dd4616f70afaa","https://security.netapp.com/advisory/ntap-20190530-0003"],"source_kind":"github","identifiers":["GHSA-c8hm-7hpq-7jhg","CVE-2018-19362"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.6.7.3","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.6.7.3"},{"first_patched_version":"2.7.9.5","vulnerable_version_range":"\u003e= 2.7.0, \u003c= 2.7.9.4"},{"first_patched_version":"2.8.11.3","vulnerable_version_range":"\u003e= 2.8.0, \u003c= 2.8.11.2"},{"first_patched_version":"2.9.8","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.8"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:12:59.271Z","updated_at":"2024-03-15T01:11:22.000Z","epss_percentage":0.07602,"epss_percentile":0.91401},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW14OXYtZ21oNC1tZ3F3","url":"https://github.com/advisories/GHSA-mx9v-gmh4-mgqw","title":"Deserialization of Untrusted Data in jackson-databind","description":"FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2019-01-04T19:07:01.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2018-19361","https://github.com/FasterXML/jackson-databind/issues/2186","https://github.com/FasterXML/jackson-databind/commit/42912cac4753f3f718ece875e4d486f8264c2f2b","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0782","https://access.redhat.com/errata/RHSA-2019:0877","https://access.redhat.com/errata/RHSA-2019:1782","https://access.redhat.com/errata/RHSA-2019:1797","https://access.redhat.com/errata/RHSA-2019:1822","https://access.redhat.com/errata/RHSA-2019:1823","https://access.redhat.com/errata/RHSA-2019:2804","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3002","https://access.redhat.com/errata/RHSA-2019:3140","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://access.redhat.com/errata/RHSA-2019:4037","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.8","https://github.com/advisories/GHSA-mx9v-gmh4-mgqw","https://issues.apache.org/jira/browse/TINKERPOP-2121","https://lists.apache.org/thread.html/37e1ed724a1b0e5d191d98c822c426670bdfde83804567131847d2a3@%3Cdevnull.infra.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/c70da3cb6e3f03e0ad8013e38b6959419d866c4a7c80fdd34b73f25c@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/03/msg00005.html","https://seclists.org/bugtraq/2019/May/68","https://security.netapp.com/advisory/ntap-20190530-0003/","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","http://www.securityfocus.com/bid/107985"],"source_kind":"github","identifiers":["GHSA-mx9v-gmh4-mgqw","CVE-2018-19361"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.8.11.3","vulnerable_version_range":"\u003e= 2.8.0, \u003c= 2.8.11.2"},{"first_patched_version":"2.7.9.5","vulnerable_version_range":"\u003e= 2.7.0, \u003c= 2.7.9.4"},{"first_patched_version":"2.9.8","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.8"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:12:59.419Z","updated_at":"2025-06-05T01:18:11.361Z","epss_percentage":0.04063,"epss_percentile":0.87964},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXJmNnItMmM0cS0ydndn","url":"https://github.com/advisories/GHSA-rf6r-2c4q-2vwg","title":"jackson-databind mishandles the interaction between serialization gadgets and typing","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2020-05-15T18:58:54.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-10968","https://github.com/FasterXML/jackson-databind/issues/2662","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/05d7e0e13f43e12db6a51726df12c8b4d8040676","https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88","https://security.netapp.com/advisory/ntap-20200403-0002","https://github.com/advisories/GHSA-rf6r-2c4q-2vwg"],"source_kind":"github","identifiers":["GHSA-rf6r-2c4q-2vwg","CVE-2020-10968"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.10.4","vulnerable_version_range":"\u003e= 2.9.0, \u003c= 2.9.10.3"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:25.121Z","updated_at":"2024-03-15T00:50:18.000Z","epss_percentage":0.06632,"epss_percentile":0.90685},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWMyNjUtMzd2ai1jd2Nj","url":"https://github.com/advisories/GHSA-c265-37vj-cwcc","title":"Deserialization of untrusted data in Jackson Databind","description":"FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to com.sun.org.apache.xalan.internal.lib.sql.JNDIConnectionPool (aka xalan2).","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2020-06-18T14:44:48.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-14062","https://github.com/FasterXML/jackson-databind/issues/2704","https://github.com/FasterXML/jackson-databind/commit/99001cdb6807b5c7b170ec6a9092ecbb618ae79c","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-570625","https://lists.debian.org/debian-lts-announce/2020/07/msg00001.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/840eae2ca81c597a0010b2126f32dce17d384b70","https://security.netapp.com/advisory/ntap-20200702-0003","https://github.com/advisories/GHSA-c265-37vj-cwcc"],"source_kind":"github","identifiers":["GHSA-c265-37vj-cwcc","CVE-2020-14062"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.10.5","vulnerable_version_range":"\u003e= 2.9.0, \u003c= 2.9.10.4"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:23.993Z","updated_at":"2024-06-25T13:46:04.000Z","epss_percentage":0.07706,"epss_percentile":0.9143},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWN2bTktZmptOS0zNTcy","url":"https://github.com/advisories/GHSA-cvm9-fjm9-3572","title":"Unsafe Deserialization in jackson-databind","description":"FasterXML jackson-databind 2.x before 2.9.10.8 and 2.6.7.5 mishandles the interaction between serialization gadgets and typing, related to `org.apache.tomcat.dbcp.dbcp.cpdsadapter.DriverAdapterCPDS`.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2021-12-09T19:16:10.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-36181","https://github.com/FasterXML/jackson-databind/issues/3004","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/3ded28aece694d0df39c9f0fa1ff385b14a8656b","https://github.com/advisories/GHSA-cvm9-fjm9-3572"],"source_kind":"github","identifiers":["GHSA-cvm9-fjm9-3572","CVE-2020-36181"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.6.7.5","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.6.7.5"},{"first_patched_version":"2.9.10.8","vulnerable_version_range":"\u003e= 2.7.0, \u003c 2.9.10.8"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:10.432Z","updated_at":"2023-09-14T16:07:00.000Z","epss_percentage":0.06306,"epss_percentile":0.90001},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXZmcXgtMzNxbS1nODY5","url":"https://github.com/advisories/GHSA-vfqx-33qm-g869","title":"Unsafe Deserialization in jackson-databind","description":"FasterXML jackson-databind 2.x before 2.9.10.8 an 2.6.7.5 mishandles the interaction between serialization gadgets and typing, related to com.newrelic.agent.deps.ch.qos.logback.core.db.DriverManagerConnectionSource.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2021-12-09T19:16:59.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-36189","https://github.com/FasterXML/jackson-databind/issues/2996","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/33d96c13fe18a2dad01b19ce195548c9acea9da4","https://github.com/advisories/GHSA-vfqx-33qm-g869"],"source_kind":"github","identifiers":["GHSA-vfqx-33qm-g869","CVE-2020-36189"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.6.7.5","vulnerable_version_range":"\u003c 2.6.7.5"},{"first_patched_version":"2.9.10.8","vulnerable_version_range":"\u003e= 2.7.0, \u003c 2.9.10.8"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:10.488Z","updated_at":"2023-09-14T16:04:22.000Z","epss_percentage":0.02635,"epss_percentile":0.84823},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWY5eGgtMnFncC1jcTU3","url":"https://github.com/advisories/GHSA-f9xh-2qgp-cq57","title":"Unsafe Deserialization in jackson-databind","description":"FasterXML jackson-databind 2.x before 2.9.10.8 and 2.6.7.5 mishandles the interaction between serialization gadgets and typing, related to `com.newrelic.agent.deps.ch.qos.logback.core.db.JNDIConnectionSource`.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2021-12-09T19:16:42.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-36188","https://github.com/FasterXML/jackson-databind/issues/2996","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/33d96c13fe18a2dad01b19ce195548c9acea9da4","https://github.com/advisories/GHSA-f9xh-2qgp-cq57"],"source_kind":"github","identifiers":["GHSA-f9xh-2qgp-cq57","CVE-2020-36188"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.6.7.5","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.6.7.5"},{"first_patched_version":"2.9.10.8","vulnerable_version_range":"\u003e= 2.7.0, \u003c 2.9.10.8"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:10.469Z","updated_at":"2023-09-14T16:04:22.000Z","epss_percentage":0.0698,"epss_percentile":0.90564},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW02eDQtOTd3eC00cTI3","url":"https://github.com/advisories/GHSA-m6x4-97wx-4q27","title":"Unsafe Deserialization in jackson-databind","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp2.datasources.PerUserPoolDataSource.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2021-12-09T19:16:26.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-36184","https://github.com/FasterXML/jackson-databind/issues/2998","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/567194c53ae91f0a14dc27239afb739b1c10448a","https://github.com/advisories/GHSA-m6x4-97wx-4q27"],"source_kind":"github","identifiers":["GHSA-m6x4-97wx-4q27","CVE-2020-36184"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.10.8","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.9.10.8"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:10.450Z","updated_at":"2023-09-14T15:53:30.000Z","epss_percentage":0.05061,"epss_percentile":0.88784},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXFqdzItaHI5OC1xZ2Zo","url":"https://github.com/advisories/GHSA-qjw2-hr98-qgfh","title":"Unsafe Deserialization in jackson-databind","description":"FasterXML jackson-databind 2.x before 2.6.7.5 and from 2.7.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to com.pastdev.httpcomponents.configuration.JndiConfiguration.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2021-12-09T19:15:36.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-24750","https://github.com/FasterXML/jackson-databind/issues/2798","https://github.com/FasterXML/jackson-databind/commit/ad5a630174f08d279504bc51ebba8772fd71b86b","https://security.netapp.com/advisory/ntap-20201009-0003/","https://www.oracle.com/security-alerts/cpujan2021.html","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://github.com/FasterXML/jackson-databind/commit/2118e71325486c68f089a9761c9d8a11b4ddd1cb","https://www.oracle.com/security-alerts/cpuapr2022.html","https://github.com/FasterXML/jackson-databind/commit/6cc9f1a1af323cd156f5668a47e43bab324ae16f","https://github.com/advisories/GHSA-qjw2-hr98-qgfh"],"source_kind":"github","identifiers":["GHSA-qjw2-hr98-qgfh","CVE-2020-24750"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.10.6","vulnerable_version_range":"\u003e= 2.7.0, \u003c= 2.9.10.5"},{"first_patched_version":"2.6.7.5","vulnerable_version_range":"\u003e= 2.0, \u003c= 2.6.7.4"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:12:30.537Z","updated_at":"2023-09-14T15:47:50.000Z","epss_percentage":0.02107,"epss_percentile":0.82538},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZxd2YtcGp3Zi03dnF2","url":"https://github.com/advisories/GHSA-fqwf-pjwf-7vqv","title":"jackson-databind mishandles the interaction between serialization gadgets and typing","description":"FasterXML jackson-databind 2.x before 2.9.10.4 and 2.6.7.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2020-05-15T18:59:04.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-10673","https://github.com/FasterXML/jackson-databind/issues/2660","https://lists.debian.org/debian-lts-announce/2020/03/msg00027.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/1645efbd392989cf015f459a91c999e59c921b15","https://medium.com/%40cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200403-0002","https://github.com/advisories/GHSA-fqwf-pjwf-7vqv"],"source_kind":"github","identifiers":["GHSA-fqwf-pjwf-7vqv","CVE-2020-10673"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.6.7.4","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.6.7.4"},{"first_patched_version":"2.9.10.4","vulnerable_version_range":"\u003e= 2.7.0, \u003c 2.9.10.4"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:25.214Z","updated_at":"2024-07-03T21:10:31.000Z","epss_percentage":0.20473,"epss_percentile":0.95074},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXE5M2gtamM0OS03OGdn","url":"https://github.com/advisories/GHSA-q93h-jc49-78gg","title":"jackson-databind mishandles the interaction between serialization gadgets and typing","description":"FasterXML jackson-databind 2.x before 2.9.10.4, 2.8.11.6, and 2.7.9.7 mishandles the interaction between serialization gadgets and typing, related to `com.ibatis.sqlmap.engine.transaction.jta.JtaTransactionConfig` (aka `ibatis-sqlmap`).","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2020-05-15T18:59:10.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-9547","https://github.com/FasterXML/jackson-databind/issues/2634","https://lists.apache.org/thread.html/r35d30db00440ef63b791c4b7f7acb036e14d4a23afa2a249cb66c0fd@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r742ef70d126548dcf7de5be5779355c9d76a9aec71d7a9ef02c6398a@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r893a0104e50c1c2559eb9a5812add28ae8c3e5f43712947a9847ec18@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r9464a40d25c3ba1a55622db72f113eb494a889656962d098c70c5bb1@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra3e90712f2d59f8cef03fa796f5adf163d32b81fe7b95385f21790e6@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb6fecb5e96a6d61e175ff49f33f2713798dd05cf03067c169d195596@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd0e958d6d5c5ee16efed73314cd0e445c8dbb4bdcc80fc9d1d6c11fc@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd49ab9565bec436a896bc00c4b9fc9dce1598e106c318524fbdfec6@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/redbe4f1e21bf080f637cf9fbec47729750a2f443a919765360337428@%3Cnotifications.zookeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/03/msg00008.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.apache.org/thread.html/r4accb2e0de9679174efd3d113a059bab71ff3ec53e882790d21c1cc1@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r98c9b6e4c9e17792e2cd1ec3e4aa20b61a791939046d3f10888176bb@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rc0d5d0f72da1ed6fc5e438b1ddb3fa090c73006b55f873cf845375ab@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd5a4457be4623038c3989294429bc063eec433a2e55995d81591e2ca@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdd4df698d5d8e635144d2994922bf0842e933809eae259521f3b5097@%3Cissues.zookeeper.apache.org%3E","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://security.netapp.com/advisory/ntap-20200904-0006/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/9f4e97019fb0dd836533d0b6198c88787e235ae2","https://github.com/advisories/GHSA-q93h-jc49-78gg"],"source_kind":"github","identifiers":["GHSA-q93h-jc49-78gg","CVE-2020-9547"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.7.9.7","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.7.9.7"},{"first_patched_version":"2.8.11.6","vulnerable_version_range":"\u003e= 2.8.0, \u003c 2.8.11.6"},{"first_patched_version":"2.9.10.4","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.10.4"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:25.194Z","updated_at":"2023-09-14T15:09:40.000Z","epss_percentage":0.06229,"epss_percentile":0.89939},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWZtbWMtNzQycS1qZzc1","url":"https://github.com/advisories/GHSA-fmmc-742q-jg75","title":"jackson-databind polymorphic typing issue","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 prior to 2.9.10.1, 2.8.11.5, and 2.6.7.3. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the p6spy (3.8.6) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of com.p6spy.engine.spy.P6DataSource mishandling.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2019-11-13T00:32:27.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2019-16943","https://github.com/FasterXML/jackson-databind/issues/2478","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/5ec8d8d485c2c8ac55ea425f4cd96596ef37312532712639712ebcdd@%3Ccommits.iceberg.apache.org%3E","https://lists.apache.org/thread.html/6788e4c991f75b89d290ad06b463fcd30bcae99fee610345a35b7bc6@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f@%3Ccommits.druid.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/","https://seclists.org/bugtraq/2019/Oct/6","https://security.netapp.com/advisory/ntap-20191017-0006/","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://github.com/FasterXML/jackson-databind/commit/328a0f833daf6baa443ac3b37c818a0204714b0b","https://github.com/FasterXML/jackson-databind/commit/bc67eb11a7cf57561f861ff16f879f1fceb5779f","https://github.com/advisories/GHSA-fmmc-742q-jg75"],"source_kind":"github","identifiers":["GHSA-fmmc-742q-jg75","CVE-2019-16943"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.6.7.3","vulnerable_version_range":"\u003c 2.6.7.3"},{"first_patched_version":"2.8.11.5","vulnerable_version_range":"\u003e= 2.7.0, \u003c 2.8.11.5"},{"first_patched_version":"2.9.10.1","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.10.1"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:06.104Z","updated_at":"2023-09-14T14:55:20.000Z","epss_percentage":0.01841,"epss_percentile":0.81908},{"uuid":"GSA_kwCzR0hTQS01N2oyLXc0Y3gtNjJoMs0ybA","url":"https://github.com/advisories/GHSA-57j2-w4cx-62h2","title":"Deeply nested json in jackson-databind","description":"jackson-databind is a data-binding package for the Jackson Data Processor. jackson-databind allows a Java stack overflow exception and denial of service via a large depth of nested objects.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2022-03-12T00:00:36.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-36518","https://github.com/FasterXML/jackson-databind/issues/2816","https://github.com/FasterXML/jackson-databind/commit/fcfc4998ec23f0b1f7f8a9521c2b317b6c25892b","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.12","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.13","https://lists.debian.org/debian-lts-announce/2022/05/msg00001.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://lists.debian.org/debian-lts-announce/2022/11/msg00035.html","https://www.debian.org/security/2022/dsa-5283","https://github.com/FasterXML/jackson-databind/commit/0a8157c6ca478b1bc7be4ba7dccdb3863275f0de","https://github.com/FasterXML/jackson-databind/commit/3cc52f82ecf943e06c1d7c3b078e405fb3923d2b","https://github.com/FasterXML/jackson-databind/commit/8238ab41d0350fb915797c89d46777b4496b74fd","https://github.com/FasterXML/jackson-databind/commit/b3587924ee5d8695942f364d0d404d48d0ea6126","https://security.netapp.com/advisory/ntap-20220506-0004","https://github.com/advisories/GHSA-57j2-w4cx-62h2"],"source_kind":"github","identifiers":["GHSA-57j2-w4cx-62h2","CVE-2020-36518"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.12.6.1","vulnerable_version_range":"\u003c= 2.12.6.0"},{"first_patched_version":"2.13.2.1","vulnerable_version_range":"\u003e= 2.13.0, \u003c= 2.13.2.0"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:12:31.754Z","updated_at":"2024-03-15T00:24:56.000Z","epss_percentage":0.00314,"epss_percentile":0.54056},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWo4MjMtNHFjaC0zcmdt","url":"https://github.com/advisories/GHSA-j823-4qch-3rgm","title":"Deserialization of untrusted data in Jackson Databind","description":"FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oadd.org.apache.xalan.lib.sql.JNDIConnectionPool (aka apache/drill).","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2020-06-18T14:44:46.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-14060","https://github.com/FasterXML/jackson-databind/issues/2688","https://github.com/FasterXML/jackson-databind/commit/d1c67a0396e84c08d0558fbb843b5bd1f26e1921","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572314","https://lists.debian.org/debian-lts-announce/2020/07/msg00001.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88","https://github.com/FasterXML/jackson-databind/commit/ac7232e3f9004bdb4f11dcb5bc6c1fadf074f5f7","https://security.netapp.com/advisory/ntap-20200702-0003","https://github.com/advisories/GHSA-j823-4qch-3rgm"],"source_kind":"github","identifiers":["GHSA-j823-4qch-3rgm","CVE-2020-14060"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.10.5","vulnerable_version_range":"\u003e= 2.9.0, \u003c= 2.9.10.4"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:24.002Z","updated_at":"2024-03-15T00:39:55.000Z","epss_percentage":0.08718,"epss_percentile":0.92009},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZmcHAtcmdqOS04cndj","url":"https://github.com/advisories/GHSA-6fpp-rgj9-8rwc","title":"Deserialization of untrusted data in FasterXML jackson-databind","description":"SubTypeValidator.java in FasterXML jackson-databind before 2.9.9.2, 2.8.11.4, and 2.7.9.6 mishandles default typing when ehcache is used (because of net.sf.ehcache.transaction.manager.DefaultTransactionManagerLookup), leading to remote code execution.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2019-08-01T19:18:00.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2019-14379","https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.9.1...jackson-databind-2.9.9.2","https://github.com/FasterXML/jackson-databind/issues/2387","https://access.redhat.com/errata/RHBA-2019:2824","https://access.redhat.com/errata/RHSA-2019:2743","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:2935","https://access.redhat.com/errata/RHSA-2019:2936","https://access.redhat.com/errata/RHSA-2019:2937","https://access.redhat.com/errata/RHSA-2019:2938","https://access.redhat.com/errata/RHSA-2019:2998","https://lists.apache.org/thread.html/0d4b630d9ee724aee50703397d9d1afa2b2befc9395ba7797d0ccea9@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/0fcef7321095ce0bc597d468d150cff3d647f4cb3aef3bd4d20e1c69@%3Ccommits.tinkerpop.apache.org%3E","https://lists.apache.org/thread.html/2766188be238a446a250ef76801037d452979152d85bce5e46805815@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/2d2a76440becb610b9a9cb49b15eac3934b02c2dbcaacde1000353e4@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/34717424b4d08b74f65c09a083d6dd1cb0763f37a15d6de135998c1d@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/525bcf949a4b0da87a375cbad2680b8beccde749522f24c49befe7fb@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/56c8042873595b8c863054c7bfccab4bf2c01c6f5abedae249d914b9@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5ecc333113b139429f4f05000d4aa2886974d4df3269c1dd990bb319@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5fc0e16b7af2590bf1e97c76c136291c4fdb244ee63c65c485c9a7a1@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/689c6bcc6c7612eee71e453a115a4c8581e7b718537025d4b265783d@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/75f482fdc84abe6d0c8f438a76437c335a7bbeb5cddd4d70b4bc0cbf@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/859815b2e9f1575acbb2b260b73861c16ca49bca627fa0c46419051f@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/8723b52c2544e6cb804bc8a36622c584acd1bd6c53f2b6034c9fea54@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/87e46591de8925f719664a845572d184027258c5a7af0a471b53c77b@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef@%3Cdev.struts.apache.org%3E","https://lists.apache.org/thread.html/99944f86abefde389da9b4040ea2327c6aa0b53a2ff9352bd4cfec17@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/d161ff3d59c5a8213400dd6afb1cce1fac4f687c32d1e0c0bfbfaa2d@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/e25e734c315f70d8876a846926cfe3bfa1a4888044f146e844caf72f@%3Ccommits.ambari.apache.org%3E","https://lists.apache.org/thread.html/ee0a051428d2c719acfa297d0854a189ea5e284ef3ed491fa672f4be@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/f17f63b0f8a57e4a5759e01d25cffc0548f0b61ff5c6bfd704ad2f2a@%3Ccommits.ambari.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/08/msg00011.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UKUALE2TUCKEKOHE2D342PQXN4MWCSLC/","https://security.netapp.com/advisory/ntap-20190814-0001/","https://access.redhat.com/errata/RHSA-2019:3044","https://access.redhat.com/errata/RHSA-2019:3045","https://access.redhat.com/errata/RHSA-2019:3046","https://access.redhat.com/errata/RHSA-2019:3050","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2019:3292","https://access.redhat.com/errata/RHSA-2019:3297","https://access.redhat.com/errata/RHSA-2019:3901","https://access.redhat.com/errata/RHSA-2020:0727","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/6788e4c991f75b89d290ad06b463fcd30bcae99fee610345a35b7bc6@%3Cissues.iceberg.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://support.apple.com/kb/HT213189","http://seclists.org/fulldisclosure/2022/Mar/23","https://github.com/FasterXML/jackson-databind/commit/ad418eeb974e357f2797aef64aa0e3ffaaa6125b","https://github.com/advisories/GHSA-6fpp-rgj9-8rwc"],"source_kind":"github","identifiers":["GHSA-6fpp-rgj9-8rwc","CVE-2019-14379"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.7.9.6","vulnerable_version_range":"\u003c 2.7.9.6"},{"first_patched_version":"2.8.11.4","vulnerable_version_range":"\u003e= 2.8.0, \u003c 2.8.11.4"},{"first_patched_version":"2.9.9.2","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.9.2"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:06.085Z","updated_at":"2023-09-13T17:18:25.000Z","epss_percentage":0.01455,"epss_percentile":0.79758},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXFtcWMteDNyNC02djM5","url":"https://github.com/advisories/GHSA-qmqc-x3r4-6v39","title":"Polymorphic deserialization of malicious object in jackson-databind","description":"A flaw was discovered in FasterXML jackson-databind in all versions before 2.9.10 and 2.10.0, where it would permit polymorphic deserialization of malicious objects using the xalan JNDI gadget when used in conjunction with polymorphic type handling methods such as `enableDefaultTyping()` or when @JsonTypeInfo is using `Id.CLASS` or `Id.MINIMAL_CLASS` or in any other way which ObjectMapper.readValue might instantiate objects from unsafe sources. An attacker could use this flaw to execute arbitrary code.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2020-05-15T18:59:07.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2019-14893","https://github.com/FasterXML/jackson-databind/issues/2469","https://github.com/FasterXML/jackson-databind/commit/998efd708284778f29d83d7962a9bd935c228317","https://access.redhat.com/errata/RHSA-2020:0729","https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2019-14893","https://security.netapp.com/advisory/ntap-20200327-0006/","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/advisories/GHSA-qmqc-x3r4-6v39"],"source_kind":"github","identifiers":["GHSA-qmqc-x3r4-6v39","CVE-2019-14893"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.10","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.10"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:25.205Z","updated_at":"2023-02-01T05:02:58.000Z","epss_percentage":0.00794,"epss_percentile":0.72767},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWd3dzctcDV3NC13cmZ2","url":"https://github.com/advisories/GHSA-gww7-p5w4-wrfv","title":"Deserialization of Untrusted Data in jackson-databind","description":"FasterXML jackson-databind 2.x before 2.6.7.4, 2.7.x before 2.7.9.7, 2.8.x before 2.8.11.5, and 2.9.x before 2.9.10.2 lacks certain `net.sf.ehcache` blocking.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2020-03-04T20:52:11.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2019-20330","https://github.com/FasterXML/jackson-databind/issues/2526","https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.9.10.1...jackson-databind-2.9.10.2","https://lists.apache.org/thread.html/r107c8737db39ec9ec4f4e7147b249e29be79170b9ef4b80528105a2d@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r2c77dd6ab8344285bd8e481b57cf3029965a4b0036eefccef74cdd44@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r3f8180d0d25a7c6473ebb9714b0c1d19a73f455ae70d0c5fefc17e6c@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r428735963bee7cb99877b88d3228e28ec28af64646455c4f3e7a3c94@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r50f513772f12e1babf65c7c2b9c16425bac2d945351879e2e267517f@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r5c14fdcabdeaba258857bcb67198652e4dce1d33ddc590cd81d82393@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r5c3644c97f0434d1ceb48ff48897a67bdbf3baf7efbe7d04625425b3@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r5d3d10fdf28110da3f9ac1b7d08d7e252f98d7d37ce0a6bd139a2e4f@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r67f4d4c48197454b83d62afbed8bebbda3764e6e3a6e26a848961764@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r707d23bb9ee245f50aa909add0da6e8d8f24719b1278ddd99d2428b2@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r7a0821b44247a1e6c6fe5f2943b90ebc4f80a8d1fb0aa9a8b29a59a2@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r7fb123e7dad49af5886cfec7135c0fd5b74e4c67af029e1dc91ba744@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r8831b7fa5ca87a1cf23ee08d6dedb7877a964c1d2bd869af24056a63@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r909c822409a276ba04dc2ae31179b16f6864ba02c4f9911bdffebf95@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra2e572f568de8df5ba151e6aebb225a0629faaf0476bf7c7ed877af8@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra5ce96faec37c26b0aa15b4b6a8b1cbb145a748653e56ae83e9685d0@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/ra8a80dbc7319916946397823aec0d893d24713cbf7b5aee0e957298c@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb532fed78d031fff477fd840b81946f6d1200f93a63698dae65aa528@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/rd1f346227e11fc515914f3a7b20d81543e51e5822ba71baa0452634a@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd49cfa41bbb71ef33b53736a6af2aa8ba88c2106e30f2a34902a87d2@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rd6c6fef14944f3dcfb58d35f9317eb1c32a700e86c1b5231e45d3d0b@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/rfa57d9c2a27d3af14c69607fb1a3da00e758b2092aa88eb6a51b6e99@%3Cissues.zookeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/02/msg00020.html","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://github.com/FasterXML/jackson-databind/commit/eb254813cc822d0af015ce8fe05febf50721dc53","https://github.com/FasterXML/jackson-databind/commit/fc4214a883dc087070f25da738ef0d49c2f3387e","https://security.netapp.com/advisory/ntap-20200127-0004","https://github.com/advisories/GHSA-gww7-p5w4-wrfv"],"source_kind":"github","identifiers":["GHSA-gww7-p5w4-wrfv","CVE-2019-20330"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.6.7.4","vulnerable_version_range":"\u003e= 2.0.0, \u003c= 2.6.7.3"},{"first_patched_version":"2.9.10.2","vulnerable_version_range":"\u003e= 2.9.0, \u003c= 2.9.10.1"},{"first_patched_version":"2.8.11.5","vulnerable_version_range":"\u003e= 2.8.0, \u003c= 2.8.11.4"},{"first_patched_version":"2.7.9.7","vulnerable_version_range":"\u003e= 2.7.0, \u003c= 2.7.9.6"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:12:30.758Z","updated_at":"2024-03-15T00:52:59.000Z","epss_percentage":0.01612,"epss_percentile":0.80942},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXI2OTUtN3ZyOS1qZ2My","url":"https://github.com/advisories/GHSA-r695-7vr9-jgc2","title":"Unsafe Deserialization in jackson-databind","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.tomcat.dbcp.dbcp.datasources.SharedPoolDataSource.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2021-12-09T19:16:51.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-36187","https://github.com/FasterXML/jackson-databind/issues/2997","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20210205-0005/","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/3e8fa3beea49ea62109df9e643c9cb678dabdde1","https://github.com/advisories/GHSA-r695-7vr9-jgc2"],"source_kind":"github","identifiers":["GHSA-r695-7vr9-jgc2","CVE-2020-36187"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.10.8","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.9.10.8"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:10.478Z","updated_at":"2023-09-14T16:01:31.000Z","epss_percentage":0.02039,"epss_percentile":0.82754},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW1jNmgtNHFncC0zN3Fo","url":"https://github.com/advisories/GHSA-mc6h-4qgp-37qh","title":"Deserialization of untrusted data in Jackson Databind","description":"FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to org.jsecurity.realm.jndi.JndiRealmFactory (aka org.jsecurity).","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2020-06-18T14:44:43.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-14195","https://github.com/FasterXML/jackson-databind/issues/2765","https://github.com/FasterXML/jackson-databind/commit/f6d9c664f6d481703138319f6a0f1fdbddb3a259","https://lists.debian.org/debian-lts-announce/2020/07/msg00001.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88","https://security.netapp.com/advisory/ntap-20200702-0003","https://github.com/advisories/GHSA-mc6h-4qgp-37qh"],"source_kind":"github","identifiers":["GHSA-mc6h-4qgp-37qh","CVE-2020-14195"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.10.5","vulnerable_version_range":"\u003e= 2.9.0, \u003c= 2.9.10.4"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:24.012Z","updated_at":"2024-03-15T00:37:17.000Z","epss_percentage":0.09511,"epss_percentile":0.92082},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTR3ODItcjMyOS0zcTY3","url":"https://github.com/advisories/GHSA-4w82-r329-3q67","title":"Deserialization of Untrusted Data in jackson-databind","description":"FasterXML jackson-databind 2.x before 2.6.7.4, 2.7.x before 2.7.9.7, 2.8.x before 2.8.11.5 and 2.9.x before 2.9.10.2 lacks certain xbean-reflect/JNDI blocking, as demonstrated by org.apache.xbean.propertyeditor.JndiConverter.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2020-03-04T20:52:14.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-8840","https://github.com/FasterXML/jackson-databind/issues/2620","https://github.com/FasterXML/jackson-databind/commit/914e7c9f2cb8ce66724bf26a72adc7e958992497","https://lists.apache.org/thread.html/r078e68a926ea6be12e8404e47f45aabf04bb4668e8265c0de41db6db@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r319f19c74e06c201b9d4e8b282a4e4b2da6dcda022fb46f007dd00d3@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r3539bd3a377991217d724879d239e16e86001c54160076408574e1da@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r3d20a2660b36551fd8257d479941782af4a7169582449fac1704bde2@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/r428d068b2a4923f1a5a4f5fc6381b95205cfe7620169d16db78e9c71@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r46bebdeb59b8b7212d63a010ca445a9f5c4e9d64dcf693cab6f399d3@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r6fdd4c61a09a0c89f581b4ddb3dc6f154ab0c705fcfd0a7358b2e4e5@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r8170007fd9b263d65b37d92a7b5d7bc357aedbb113a32838bc4a9485@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r9ecf211c22760b00967ebe158c6ed7dba9142078e2a630ab8904a5b7@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rac5ee5d686818be7e7c430d35108ee01a88aae54f832d32f62431fd1@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb43f9a65150948a6bebd3cb77ee3e105d40db2820fd547528f4e7f89@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rb5eedf90ba3633e171a2ffdfe484651c9490dc5df74c8a29244cbc0e@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/rdf8d389271a291dde3b2f99c36918d6cb1e796958af626cc140fee23@%3Ccommits.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/re7326b8655eab931f2a9ce074fd9a1a51b5db11456bee9b48e1e170c@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/re8ae2670ec456ef1c5a2a661a2838ab2cd00e9efa1e88c069f546f21@%3Ccommits.zookeeper.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/02/msg00020.html","https://lists.apache.org/thread.html/r65ee95fa09c831843bac81eaa582fdddc2b6119912a72d1c83a9b882@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/r1c09b9551f6953dbeca190a4c4b78198cdbb9825fce36f96fe3d8218@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/r1efc776fc6ce3387593deaa94bbdd296733b1b01408a39c8d1ab9e0e@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r2fa8046bd47fb407ca09b5107a80fa6147ba4ebe879caae5c98b7657@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r446646c5588b10f5e02409ad580b12f314869009cdfbf844ca395cec@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r5d8bea8e9d17b6efcf4a0e4e194e91ef46a99f505777a31a60da2b38@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r7762d69e85c58d6948823424017ef4c08f47de077644277fa18cc116@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r7e5c10534ed06bf805473ac85e8412fe3908a8fa4cabf5027bf11220@%3Cdev.kafka.apache.org%3E","https://lists.apache.org/thread.html/r8e96c340004b7898cad3204ea51280ef6e4b553a684e1452bf1b18b1@%3Cjira.kafka.apache.org%3E","https://lists.apache.org/thread.html/r94930e39b60fff236160c1c4110fe884dc093044b067aa5fc98d7ee1@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/r9e59ebaf76fd00b2fa3ff5ebf18fe075ca9f4376216612c696f76718@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/ra275f29615f35d5b40106d1582a41e5388b2a5131564e9e01a572987@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rb73708bf714ed6dbc1212da082e7703e586077f0c92f3940b2e82caf@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rb99c7321eba5d4c907beec46675d52827528b738cfafd48eb4d862f1@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rc068e824654c4b8bd4f2490bec869e29edbfcd5dfe02d47cbf7433b2@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rc717fd6c65190f4e592345713f9ef0723fb7d71f624caa2a17caa26a@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rcc72b497e3dff2dc62ec9b89ceb90bc4e1b14fc56c3c252a6fcbb013@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rdea588d4a0ebf9cb7ce8c3a8f18d0d306507c4f8ba178dd3d20207b8@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/rdf311f13e6356297e0ffe74397fdd25a3687b0a16e687c3ff5b834d8@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rf28ab6f224b48452afd567dfffb705fbda0fdbbf6535f6bc69d47e91@%3Cdev.ranger.apache.org%3E","https://lists.apache.org/thread.html/rfc1ccfe89332155b72ce17f13a2701d3e7b9ec213324ceb90e79a28a@%3Cdev.ranger.apache.org%3E","https://security.netapp.com/advisory/ntap-20200327-0002/","https://www.oracle.com/security-alerts/cpuapr2020.html","http://www.huawei.com/en/psirt/security-advisories/huawei-sa-20200610-01-fastjason-en","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/FasterXML/jackson-databind/commit/74aba4042fce35ee0b91bd2847e788c10040d78b","https://github.com/FasterXML/jackson-databind/commit/9bb52c7122271df75435ec7e66ecf6b02b1ee14f","https://github.com/advisories/GHSA-4w82-r329-3q67"],"source_kind":"github","identifiers":["GHSA-4w82-r329-3q67","CVE-2020-8840"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.6.7.4","vulnerable_version_range":"\u003e= 2.0.0, \u003c= 2.6.7.3"},{"first_patched_version":"2.7.9.7","vulnerable_version_range":"\u003e= 2.7.0, \u003c= 2.7.9.6"},{"first_patched_version":"2.9.10.3","vulnerable_version_range":"\u003e= 2.9.0, \u003c= 2.9.10.2"},{"first_patched_version":"2.8.11.5","vulnerable_version_range":"\u003e= 2.8.0, \u003c= 2.8.11.4"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:12:30.631Z","updated_at":"2025-06-05T01:17:39.801Z","epss_percentage":0.08164,"epss_percentile":0.91721},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWY5aHYtbWc1aC14Y3c5","url":"https://github.com/advisories/GHSA-f9hv-mg5h-xcw9","title":"Deserialization of Untrusted Data in jackson-databind due to polymorphic deserialization","description":"FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2019-01-04T19:06:57.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2018-19360","https://github.com/FasterXML/jackson-databind/issues/2186","https://github.com/FasterXML/jackson-databind/commit/42912cac4753f3f718ece875e4d486f8264c2f2b","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0782","https://access.redhat.com/errata/RHSA-2019:0877","https://access.redhat.com/errata/RHSA-2019:1782","https://access.redhat.com/errata/RHSA-2019:1797","https://access.redhat.com/errata/RHSA-2019:1822","https://access.redhat.com/errata/RHSA-2019:1823","https://access.redhat.com/errata/RHSA-2019:2804","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3002","https://access.redhat.com/errata/RHSA-2019:3140","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://access.redhat.com/errata/RHSA-2019:4037","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.8","https://github.com/advisories/GHSA-f9hv-mg5h-xcw9","https://issues.apache.org/jira/browse/TINKERPOP-2121","https://lists.apache.org/thread.html/37e1ed724a1b0e5d191d98c822c426670bdfde83804567131847d2a3@%3Cdevnull.infra.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/c70da3cb6e3f03e0ad8013e38b6959419d866c4a7c80fdd34b73f25c@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/03/msg00005.html","https://seclists.org/bugtraq/2019/May/68","https://security.netapp.com/advisory/ntap-20190530-0003/","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","http://www.securityfocus.com/bid/107985"],"source_kind":"github","identifiers":["GHSA-f9hv-mg5h-xcw9","CVE-2018-19360"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.7.9.5","vulnerable_version_range":"\u003e= 2.7.0, \u003c= 2.7.9.4"},{"first_patched_version":"2.8.11.3","vulnerable_version_range":"\u003e= 2.8.0, \u003c= 2.8.11.2"},{"first_patched_version":"2.9.8","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.8"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:12:59.288Z","updated_at":"2025-06-05T01:18:11.016Z","epss_percentage":0.06777,"epss_percentile":0.90805},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXgydzUtNW0yZy03aDVt","url":"https://github.com/advisories/GHSA-x2w5-5m2g-7h5m","title":"XML External Entity Reference (XXE) in jackson-databind","description":"FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2019-01-04T19:09:46.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2018-14720","https://github.com/FasterXML/jackson-databind/issues/2097","https://github.com/FasterXML/jackson-databind/commit/87d29af25e82a249ea15858e2d4ecbf64091db44","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0782","https://access.redhat.com/errata/RHSA-2019:1106","https://access.redhat.com/errata/RHSA-2019:1107","https://access.redhat.com/errata/RHSA-2019:1108","https://access.redhat.com/errata/RHSA-2019:1140","https://access.redhat.com/errata/RHSA-2019:1822","https://access.redhat.com/errata/RHSA-2019:1823","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://access.redhat.com/errata/RHSA-2019:4037","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.7","https://github.com/advisories/GHSA-x2w5-5m2g-7h5m","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/6a78f88716c3c57aa74ec05764a37ab3874769a347805903b393b286@%3Cdev.lucene.apache.org%3E","https://lists.apache.org/thread.html/82b01bfb6787097427ce97cec6a7127e93718bc05d1efd5eaffc228f@%3Cdev.lucene.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/ba973114605d936be276ee6ce09dfbdbf78aa56f6cdc6e79bfa7b8df@%3Cdev.lucene.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/03/msg00005.html","https://seclists.org/bugtraq/2019/May/68","https://security.netapp.com/advisory/ntap-20190530-0003/","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html"],"source_kind":"github","identifiers":["GHSA-x2w5-5m2g-7h5m","CVE-2018-14720"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.7.9.5","vulnerable_version_range":"\u003e= 2.7.0, \u003c= 2.7.9.2"},{"first_patched_version":"2.8.11.3","vulnerable_version_range":"\u003e= 2.8.0, \u003c= 2.8.11.2"},{"first_patched_version":"2.9.7","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.7"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:12:59.586Z","updated_at":"2025-06-05T01:18:11.747Z","epss_percentage":0.0341,"epss_percentile":0.86859},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTRncTUtY2g1Ny1jMm1n","url":"https://github.com/advisories/GHSA-4gq5-ch57-c2mg","title":"Arbitrary Code Execution in jackson-databind","description":"FasterXML jackson-databind 2.x before 2.9.7, 2.8.11.3, and 2.7.9.5 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2019-01-04T19:09:49.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2018-14719","https://github.com/FasterXML/jackson-databind/issues/2097","https://github.com/FasterXML/jackson-databind/commit/87d29af25e82a249ea15858e2d4ecbf64091db44","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0782","https://access.redhat.com/errata/RHSA-2019:0877","https://access.redhat.com/errata/RHSA-2019:1782","https://access.redhat.com/errata/RHSA-2019:1797","https://access.redhat.com/errata/RHSA-2019:1822","https://access.redhat.com/errata/RHSA-2019:1823","https://access.redhat.com/errata/RHSA-2019:2804","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3002","https://access.redhat.com/errata/RHSA-2019:3140","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://access.redhat.com/errata/RHSA-2019:4037","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.7","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/ff8dcfe29377088ab655fda9d585dccd5b1f07fabd94ae84fd60a7f8@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/03/msg00005.html","https://seclists.org/bugtraq/2019/May/68","https://security.netapp.com/advisory/ntap-20190530-0003/","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://github.com/advisories/GHSA-4gq5-ch57-c2mg"],"source_kind":"github","identifiers":["GHSA-4gq5-ch57-c2mg","CVE-2018-14719"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.7.9.5","vulnerable_version_range":"\u003e= 2.0.0, \u003c= 2.7.9.4"},{"first_patched_version":"2.8.11.3","vulnerable_version_range":"\u003e= 2.8.0, \u003c= 2.8.11.2"},{"first_patched_version":"2.9.7","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.7"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:12:59.037Z","updated_at":"2025-06-05T01:15:34.459Z","epss_percentage":0.03526,"epss_percentile":0.87075},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW14N3AtNjY3OS04ZzNx","url":"https://github.com/advisories/GHSA-mx7p-6679-8g3q","title":"Polymorphic Typing in FasterXML jackson-databind","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible to make the service execute a malicious payload. This issue exists because of org.apache.commons.dbcp.datasources.SharedPoolDataSource and org.apache.commons.dbcp.datasources.PerUserPoolDataSource mishandling.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2019-10-28T20:51:15.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2019-16942","https://github.com/FasterXML/jackson-databind/issues/2478","https://issues.apache.org/jira/browse/GEODE-7255","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://access.redhat.com/errata/RHSA-2019:3901","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/7782a937c9259a58337ee36b2961f00e2d744feafc13084e176d0df5@%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/a430dbc9be874c41314cc69e697384567a9a24025e819d9485547954@%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b2e23c94f9dfef53e04c492e5d02e5c75201734be7adc73a49ef2370@%3Cissues.geode.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html","https://seclists.org/bugtraq/2019/Oct/6","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://github.com/FasterXML/jackson-databind/commit/328a0f833daf6baa443ac3b37c818a0204714b0b","https://github.com/FasterXML/jackson-databind/commit/54aa38d87dcffa5ccc23e64922e9536c82c1b9c8","https://github.com/FasterXML/jackson-databind/commit/9593e16cf5a3d289a9c584f7123639655de9ddac","https://github.com/FasterXML/jackson-databind/commit/bc67eb11a7cf57561f861ff16f879f1fceb5779f","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT","https://security.netapp.com/advisory/ntap-20191017-0006","https://github.com/advisories/GHSA-mx7p-6679-8g3q"],"source_kind":"github","identifiers":["GHSA-mx7p-6679-8g3q","CVE-2019-16942"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.8.11.5","vulnerable_version_range":"\u003e= 2.7.0, \u003c 2.8.11.5"},{"first_patched_version":"2.6.7.3","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.6.7.3"},{"first_patched_version":"2.9.10.1","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.10.1"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:06.095Z","updated_at":"2024-03-15T00:57:37.000Z","epss_percentage":0.00438,"epss_percentile":0.61784},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXczZjQtM3E2ai1yaDgy","url":"https://github.com/advisories/GHSA-w3f4-3q6j-rh82","title":"Deserialization of Untrusted Data in jackson-databind","description":"FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2020-06-30T20:40:50.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2018-5968","https://github.com/FasterXML/jackson-databind/issues/1899","https://github.com/GulajavaMinistudio/jackson-databind/pull/92/commits/038b471e2efde2e8f96b4e0be958d3e5a1ff1d05","https://access.redhat.com/errata/RHSA-2018:0478","https://access.redhat.com/errata/RHSA-2018:0479","https://access.redhat.com/errata/RHSA-2018:0480","https://access.redhat.com/errata/RHSA-2018:0481","https://access.redhat.com/errata/RHSA-2018:1525","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3149","https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US\u0026docId=emr_na-hpesbhf03902en_us","https://www.debian.org/security/2018/dsa-4114","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/FasterXML/jackson-databind/commit/038b471e2efde2e8f96b4e0be958d3e5a1ff1d0","https://github.com/FasterXML/jackson-databind/commit/03ea0bec6293d4330b5ad19d1d62aca0e3cb6381","https://github.com/FasterXML/jackson-databind/commit/454be8bb8c913be18298327a84ca45a280b61605","https://security.netapp.com/advisory/ntap-20180423-0002","https://github.com/advisories/GHSA-w3f4-3q6j-rh82"],"source_kind":"github","identifiers":["GHSA-w3f4-3q6j-rh82","CVE-2018-5968"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.7.9.5","vulnerable_version_range":"\u003c 2.7.9.5"},{"first_patched_version":"2.8.11.1","vulnerable_version_range":"\u003e= 2.8.0, \u003c 2.8.11"},{"first_patched_version":"2.9.4","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.4"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:23.844Z","updated_at":"2024-03-01T21:56:34.000Z","epss_percentage":0.02582,"epss_percentile":0.84685},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXIzZ3ItY3hyZi1oZzI1","url":"https://github.com/advisories/GHSA-r3gr-cxrf-hg25","title":"Serialization gadgets exploit in jackson-databind","description":"FasterXML jackson-databind 2.x before 2.9.10.8 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.dbcp2.datasources.SharedPoolDataSource.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2021-12-09T19:15:11.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-35491","https://github.com/FasterXML/jackson-databind/issues/2986","https://cowtowncoder.medium.com/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://www.oracle.com/security-alerts/cpujul2022.html","https://github.com/FasterXML/jackson-databind/commit/41b8bdb5ccc1d8edb71acf1c8234da235a24249d","https://security.netapp.com/advisory/ntap-20210122-0005","https://github.com/advisories/GHSA-r3gr-cxrf-hg25"],"source_kind":"github","identifiers":["GHSA-r3gr-cxrf-hg25","CVE-2020-35491"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.10.8","vulnerable_version_range":"\u003e= 2.0.0, \u003c= 2.9.10.7"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:07.957Z","updated_at":"2025-06-05T01:13:29.331Z","epss_percentage":0.06892,"epss_percentile":0.90886},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWg1OTItMzhjbS00Z2dw","url":"https://github.com/advisories/GHSA-h592-38cm-4ggp","title":"jackson-databind vulnerable to deserialization flaw leading to unauthenticated remote code execution","description":"jackson-databind in versions prior to 2.8.11 and 2.9.4 contain a deserialization flaw which allows an unauthenticated user to perform code execution by sending maliciously crafted input to the readValue method of the ObjectMapper. This issue extends the previous flaw CVE-2017-7525, blacklisting additonal vulnerable classes.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2018-10-18T17:42:34.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2017-15095","https://github.com/FasterXML/jackson-databind/issues/1680","https://github.com/FasterXML/jackson-databind/issues/1737","https://access.redhat.com/errata/RHSA-2017:3189","https://access.redhat.com/errata/RHSA-2017:3190","https://access.redhat.com/errata/RHSA-2018:0342","https://access.redhat.com/errata/RHSA-2018:0478","https://access.redhat.com/errata/RHSA-2018:0479","https://access.redhat.com/errata/RHSA-2018:0480","https://access.redhat.com/errata/RHSA-2018:0481","https://access.redhat.com/errata/RHSA-2018:0576","https://access.redhat.com/errata/RHSA-2018:0577","https://access.redhat.com/errata/RHSA-2018:1447","https://access.redhat.com/errata/RHSA-2018:1448","https://access.redhat.com/errata/RHSA-2018:1449","https://access.redhat.com/errata/RHSA-2018:1450","https://access.redhat.com/errata/RHSA-2018:1451","https://access.redhat.com/errata/RHSA-2018:2927","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://lists.apache.org/thread.html/f095a791bda6c0595f691eddd0febb2d396987eec5cbd29120d8c629@%3Csolr-user.lucene.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/01/msg00037.html","https://www.debian.org/security/2017/dsa-4037","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html","http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html","http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html","https://github.com/FasterXML/jackson-databind/commit/a3939d36edcc755c8af55bdc1969e0fa8438f9db","https://github.com/FasterXML/jackson-databind/commit/ddfddfba6414adbecaff99684ef66eebd3a92e92","https://github.com/FasterXML/jackson-databind/commit/e865a7a4464da63ded9f4b1a2328ad85c9ded78b","https://github.com/FasterXML/jackson-databind/commit/e8f043d1aac9b82eee907e0f0c3abbdea723a935","https://web.archive.org/web/20200401000000*/http://www.securityfocus.com/bid/103880","https://web.archive.org/web/20201221192044/http://www.securitytracker.com/id/1039769","https://github.com/FasterXML/jackson-databind/commit/a054585e2175ad0882f07bcafedecfac86230f1b","https://github.com/tolbertam/jackson-databind/commit/80566a0f96b2003863f9d8f9ccc3b562001e147b","https://security.netapp.com/advisory/ntap-20171214-0003","https://github.com/advisories/GHSA-h592-38cm-4ggp"],"source_kind":"github","identifiers":["GHSA-h592-38cm-4ggp","CVE-2017-15095"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.7.9.2","vulnerable_version_range":"\u003e= 2.7.0, \u003c 2.7.9.2"},{"first_patched_version":"2.6.7.3","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.6.7.3"},{"first_patched_version":"2.8.11","vulnerable_version_range":"\u003e= 2.8.0, \u003c 2.8.11"},{"first_patched_version":"2.9.4","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.4"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:34.344Z","updated_at":"2025-06-05T01:14:10.598Z","epss_percentage":0.07411,"epss_percentile":0.91245},{"uuid":"GSA_kwCzR0hTQS0zeDh4LTc5bTItM3cyd84AAyLf","url":"https://github.com/advisories/GHSA-3x8x-79m2-3w2w","title":"jackson-databind possible Denial of Service if using JDK serialization to serialize JsonNode","description":"jackson-databind 2.10.x through 2.12.x before 2.12.6 and 2.13.x before 2.13.1 allows attackers to cause a denial of service (2 GB transient heap usage per read) in uncommon situations involving JsonNode JDK serialization.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2023-03-19T00:30:25.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2021-46877","https://github.com/FasterXML/jackson-databind/issues/3328","https://groups.google.com/g/jackson-user/c/OsBsirPM_Vw","https://github.com/FasterXML/jackson-databind/commit/3ccde7d938fea547e598fdefe9a82cff37fed5cb","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.12.6","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.13.1","https://github.com/advisories/GHSA-3x8x-79m2-3w2w"],"source_kind":"github","identifiers":["GHSA-3x8x-79m2-3w2w","CVE-2021-46877"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.13.1","vulnerable_version_range":"\u003e= 2.13.0, \u003c 2.13.1"},{"first_patched_version":"2.12.6","vulnerable_version_range":"\u003e= 2.10.0, \u003c 2.12.6"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2023-03-20T22:03:07.536Z","updated_at":"2025-02-26T22:17:22.000Z","epss_percentage":0.00097,"epss_percentile":0.28275},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWNqamYtOTRmZi00M3c3","url":"https://github.com/advisories/GHSA-cjjf-94ff-43w7","title":"jackson-databind Deserialization of Untrusted Data vulnerability","description":"An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2019-03-25T18:03:09.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2018-12022","https://github.com/FasterXML/jackson-databind/issues/2052","https://github.com/FasterXML/jackson-databind/commit/28badf7ef60ac3e7ef151cd8e8ec010b8479226a","https://access.redhat.com/errata/RHBA-2019:0959","https://access.redhat.com/errata/RHSA-2019:0782","https://access.redhat.com/errata/RHSA-2019:0877","https://access.redhat.com/errata/RHSA-2019:1106","https://access.redhat.com/errata/RHSA-2019:1107","https://access.redhat.com/errata/RHSA-2019:1108","https://access.redhat.com/errata/RHSA-2019:1140","https://access.redhat.com/errata/RHSA-2019:1782","https://access.redhat.com/errata/RHSA-2019:1797","https://access.redhat.com/errata/RHSA-2019:1822","https://access.redhat.com/errata/RHSA-2019:1823","https://access.redhat.com/errata/RHSA-2019:2804","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3002","https://access.redhat.com/errata/RHSA-2019:3140","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3892","https://access.redhat.com/errata/RHSA-2019:4037","https://bugzilla.redhat.com/show_bug.cgi?id=1671098","https://github.com/advisories/GHSA-cjjf-94ff-43w7","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/7fcf88aff0d1deaa5c3c7be8d58c05ad7ad5da94b59065d8e7c50c5d@%3Cissues.lucene.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://seclists.org/bugtraq/2019/May/68","https://www.blackhat.com/docs/us-16/materials/us-16-Munoz-A-Journey-From-JNDI-LDAP-Manipulation-To-RCE.pdf","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","http://www.securityfocus.com/bid/107585","https://github.com/FasterXML/jackson-databind/commit/bf261d404c2f79fd3406237710d40ebb03c99d84","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZEDLDUYBSTDY4GWDBUXGJNS2RFYTFVRC","https://security.netapp.com/advisory/ntap-20190530-0003","https://github.com/FasterXML/jackson-databind/commit/7487cf7eb14be2f65a1eb108e8629c07ef45e0a"],"source_kind":"github","identifiers":["GHSA-cjjf-94ff-43w7","CVE-2018-12022"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.8.11.2","vulnerable_version_range":"\u003e= 2.8.0, \u003c= 2.8.11.1"},{"first_patched_version":"2.7.9.4","vulnerable_version_range":"\u003c= 2.7.9.3"},{"first_patched_version":"2.9.6","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.6"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:12:59.019Z","updated_at":"2024-03-01T21:49:05.000Z","epss_percentage":0.03093,"epss_percentile":0.85601},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTg1Y3ctaGo2NS1xcXY5","url":"https://github.com/advisories/GHSA-85cw-hj65-qqv9","title":"Polymorphic Typing issue in FasterXML jackson-databind","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind before 2.9.10, 2.8.11.5, and 2.6.7.3. It is related to com.zaxxer.hikari.HikariDataSource. This is a different vulnerability than CVE-2019-14540.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2019-09-23T18:33:45.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2019-16335","https://github.com/FasterXML/jackson-databind/issues/2449","https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://access.redhat.com/errata/RHSA-2020:0729","https://lists.apache.org/thread.html/0fcef7321095ce0bc597d468d150cff3d647f4cb3aef3bd4d20e1c69@%3Ccommits.tinkerpop.apache.org%3E","https://lists.apache.org/thread.html/40c00861b53bb611dee7d6f35f864aa7d1c1bd77df28db597cbf27e1@%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/a360b46061c91c5cad789b6c3190aef9b9f223a2b75c9c9f046fe016@%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/ad0d238e97a7da5eca47a014f0f7e81f440ed6bf74a93183825e18b9@%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/dc6b5cad721a4f6b3b62ed1163894941140d9d5656140fb757505ca0@%3Cissues.hbase.apache.org%3E","https://lists.apache.org/thread.html/e90c3feb21702e68a8c08afce37045adb3870f2bf8223fa403fb93fb@%3Ccommits.hbase.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/10/msg00001.html","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/Q7CANA7KV53JROZDX5Z5P26UG5VN2K43/","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TH5VFUN4P7CCIP7KSEXYA5MUTFCUDUJT/","https://seclists.org/bugtraq/2019/Oct/6","https://security.netapp.com/advisory/ntap-20191004-0002/","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/FasterXML/jackson-databind/commit/73c1c2cc76e6cdd7f3a5615cbe3207fe96e4d3db","https://github.com/advisories/GHSA-85cw-hj65-qqv9"],"source_kind":"github","identifiers":["GHSA-85cw-hj65-qqv9","CVE-2019-16335"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.6.7.3","vulnerable_version_range":"\u003c 2.6.7.3"},{"first_patched_version":"2.8.11.5","vulnerable_version_range":"\u003e= 2.7.0, \u003c 2.8.11.5"},{"first_patched_version":"2.9.10","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.10"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:28.082Z","updated_at":"2023-09-13T18:22:47.000Z","epss_percentage":0.0074,"epss_percentile":0.71567},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTc1OG0tdjU2di1ncmo0","url":"https://github.com/advisories/GHSA-758m-v56v-grj4","title":"jackson-databind mishandles the interaction between serialization gadgets and typing","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2020-04-23T21:36:03.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-10969","https://github.com/FasterXML/jackson-databind/issues/2642","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/6ba48457984943df0de92c54144f7dcae01b1221","https://security.netapp.com/advisory/ntap-20200403-0002","https://github.com/advisories/GHSA-758m-v56v-grj4"],"source_kind":"github","identifiers":["GHSA-758m-v56v-grj4","CVE-2020-10969"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.10.4","vulnerable_version_range":"\u003e= 2.9.0, \u003c= 2.9.10.3"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:25.146Z","updated_at":"2024-06-25T13:46:45.000Z","epss_percentage":0.01478,"epss_percentile":0.79845},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWNtZmctODd2cS1nNWc0","url":"https://github.com/advisories/GHSA-cmfg-87vq-g5g4","title":"Deserialization of untrusted data in FasterXML jackson-databind","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x through 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has JDOM 1.x or 2.x jar in the classpath, an attacker can send a specifically crafted JSON message that allows them to read arbitrary local files on the server.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2019-07-17T15:26:12.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2019-12814","https://github.com/FasterXML/jackson-databind/issues/2341","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:2935","https://access.redhat.com/errata/RHSA-2019:2936","https://access.redhat.com/errata/RHSA-2019:2937","https://access.redhat.com/errata/RHSA-2019:2938","https://access.redhat.com/errata/RHSA-2019:3044","https://access.redhat.com/errata/RHSA-2019:3045","https://access.redhat.com/errata/RHSA-2019:3046","https://access.redhat.com/errata/RHSA-2019:3050","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2019:3292","https://access.redhat.com/errata/RHSA-2019:3297","https://lists.apache.org/thread.html/0d4b630d9ee724aee50703397d9d1afa2b2befc9395ba7797d0ccea9@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/129da0204c876f746636018751a086cc581e0e07bcdeb3ee22ff5731@%3Cdev.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/15a55e1d837fa686db493137cc0330c7ee1089ed9a9eea7ae7151ef1@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/1e04d9381c801b31ab28dec813c31c304b2a596b2a3707fa5462c5c0@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/28be28ffd6471d230943a255c36fe196a54ef5afc494a4781d16e37c@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/2d2a76440becb610b9a9cb49b15eac3934b02c2dbcaacde1000353e4@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/2ff264b6a94c5363a35c4c88fa93216f60ec54d1d973ed6b76a9f560@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/34717424b4d08b74f65c09a083d6dd1cb0763f37a15d6de135998c1d@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/3f99ae8dcdbd69438cb733d745ee3ad5e852068490719a66509b4592@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/4b832d1327703d6b287a6d223307f8f884d798821209a10647e93324@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/56c8042873595b8c863054c7bfccab4bf2c01c6f5abedae249d914b9@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5ecc333113b139429f4f05000d4aa2886974d4df3269c1dd990bb319@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5fc0e16b7af2590bf1e97c76c136291c4fdb244ee63c65c485c9a7a1@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/71f9ffd92410a889e27b95a219eaa843fd820f8550898633d85d4ea3@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/87e46591de8925f719664a845572d184027258c5a7af0a471b53c77b@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/8fe2983f6d9fee0aa737e4bd24483f8f5cf9b938b9adad0c4e79b2a4@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef@%3Cdev.struts.apache.org%3E","https://lists.apache.org/thread.html/a3ae8a8c5e32c413cd27071d3a204166050bf79ce7f1299f6866338f@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/a62aa2706105d68f1c02023fe24aaa3c13b4d8a1826181fed07d9682@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/a78239b1f11cddfa86e4edee19064c40b6272214630bfef070c37957@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/b0a2b2cca072650dbd5882719976c3d353972c44f6736ddf0ba95209@%3Cissues.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/b148fa2e9ef468c4de00de255dd728b74e2a97d935f8ced31eb41ba2@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/bf20574dbc2db255f1fd489942b5720f675e32a2c4f44eb6a36060cd@%3Ccommits.accumulo.apache.org%3E","https://lists.apache.org/thread.html/e0733058c0366b703e6757d8d2a7a04b943581f659e9c271f0841dfe@%3Cnotifications.geode.apache.org%3E","https://lists.apache.org/thread.html/ee0a051428d2c719acfa297d0854a189ea5e284ef3ed491fa672f4be@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/eff7280055fc717ea8129cd28a9dd57b8446d00b36260c1caee10b87@%3Cnotifications.zookeeper.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/06/msg00019.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/FasterXML/jackson-databind/commit/5f7c69bba07a7155adde130d9dee2e54a54f1fa5","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UKUALE2TUCKEKOHE2D342PQXN4MWCSLC","https://security.netapp.com/advisory/ntap-20190625-0006","https://github.com/advisories/GHSA-cmfg-87vq-g5g4"],"source_kind":"github","identifiers":["GHSA-cmfg-87vq-g5g4","CVE-2019-12814"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.6.7.3","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.6.7.3"},{"first_patched_version":"2.7.9.6","vulnerable_version_range":"\u003e= 2.7.0, \u003c 2.7.9.6"},{"first_patched_version":"2.8.11.4","vulnerable_version_range":"\u003e= 2.8.0, \u003c 2.8.11.4"},{"first_patched_version":"2.9.9.1","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.9.1"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:06.256Z","updated_at":"2024-03-15T01:01:08.000Z","epss_percentage":0.22914,"epss_percentile":0.95611},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW1waDQtdmhyeC1tdjY3","url":"https://github.com/advisories/GHSA-mph4-vhrx-mv67","title":"Deserialization of Untrusted Data in FasterXML jackson-databind","description":"FasterXML jackson-databind 2.x before 2.9.9.1 might allow attackers to have a variety of impacts by leveraging failure to block the logback-core class from polymorphic deserialization. Depending on the classpath content, remote code execution may be possible.","origin":"UNSPECIFIED","severity":"MODERATE","published_at":"2019-07-05T21:07:27.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2019-12384","https://doyensec.com/research.html","https://github.com/FasterXML/jackson-databind/compare/74b90a4...a977aad","https://lists.debian.org/debian-lts-announce/2019/06/msg00019.html","https://access.redhat.com/errata/RHSA-2019:1820","https://access.redhat.com/errata/RHSA-2019:2720","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:2935","https://access.redhat.com/errata/RHSA-2019:2936","https://access.redhat.com/errata/RHSA-2019:2937","https://access.redhat.com/errata/RHSA-2019:2938","https://access.redhat.com/errata/RHSA-2019:2998","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3200","https://access.redhat.com/errata/RHSA-2019:3292","https://access.redhat.com/errata/RHSA-2019:3297","https://access.redhat.com/errata/RHSA-2019:3901","https://access.redhat.com/errata/RHSA-2019:4352","https://blog.doyensec.com/2019/07/22/jackson-gadgets.html","https://lists.apache.org/thread.html/0d4b630d9ee724aee50703397d9d1afa2b2befc9395ba7797d0ccea9@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/2d2a76440becb610b9a9cb49b15eac3934b02c2dbcaacde1000353e4@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/34717424b4d08b74f65c09a083d6dd1cb0763f37a15d6de135998c1d@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/3f99ae8dcdbd69438cb733d745ee3ad5e852068490719a66509b4592@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/56c8042873595b8c863054c7bfccab4bf2c01c6f5abedae249d914b9@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5ecc333113b139429f4f05000d4aa2886974d4df3269c1dd990bb319@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/5fc0e16b7af2590bf1e97c76c136291c4fdb244ee63c65c485c9a7a1@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/87e46591de8925f719664a845572d184027258c5a7af0a471b53c77b@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/940b4c3fef002461b89a050935337056d4a036a65ef68e0bbd4621ef@%3Cdev.struts.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/e0733058c0366b703e6757d8d2a7a04b943581f659e9c271f0841dfe@%3Cnotifications.geode.apache.org%3E","https://lists.apache.org/thread.html/ee0a051428d2c719acfa297d0854a189ea5e284ef3ed491fa672f4be@%3Cdev.tomee.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://seclists.org/bugtraq/2019/Oct/6","https://www.debian.org/security/2019/dsa-4542","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://github.com/FasterXML/jackson-databind/issues/2334","https://github.com/FasterXML/jackson-databind/commit/c9ef4a10d6f6633cf470d6a469514b68fa2be234","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UKUALE2TUCKEKOHE2D342PQXN4MWCSLC","https://security.netapp.com/advisory/ntap-20190703-0002","https://github.com/advisories/GHSA-mph4-vhrx-mv67"],"source_kind":"github","identifiers":["GHSA-mph4-vhrx-mv67","CVE-2019-12384"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.6.7.3","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.6.7.3"},{"first_patched_version":"2.7.9.6","vulnerable_version_range":"\u003e= 2.7.0, \u003c 2.7.9.6"},{"first_patched_version":"2.8.11.4","vulnerable_version_range":"\u003e= 2.8.0, \u003c 2.8.11.4"},{"first_patched_version":"2.9.9.1","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.9.1"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:06.245Z","updated_at":"2024-03-15T01:04:01.000Z","epss_percentage":0.45313,"epss_percentile":0.97456},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWgzY3ctZzRtcS1jNXgy","url":"https://github.com/advisories/GHSA-h3cw-g4mq-c5x2","title":"Code Injection in jackson-databind","description":"This project contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. FasterXML jackson-databind 2.x before 2.9.10.6 mishandles the interaction between serialization gadgets and typing, related to br.com.anteros.dbcp.AnterosDBCPDataSource (aka Anteros-DBCP).","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2021-12-09T19:14:51.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-24616","https://github.com/FasterXML/jackson-databind/issues/2814","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://security.netapp.com/advisory/ntap-20200904-0006/","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://www.oracle.com/security-alerts/cpujan2022.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://github.com/FasterXML/jackson-databind/commit/3d97153944f7de9c19c1b3637b33d3cf1fbbe4d7","https://github.com/advisories/GHSA-h3cw-g4mq-c5x2"],"source_kind":"github","identifiers":["GHSA-h3cw-g4mq-c5x2","CVE-2020-24616"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.10.6","vulnerable_version_range":"\u003e= 2.0.0, \u003c= 2.9.10.5"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:06.076Z","updated_at":"2023-09-14T15:44:55.000Z","epss_percentage":0.03783,"epss_percentile":0.87561},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXF4eHgtMnBwNy01aG14","url":"https://github.com/advisories/GHSA-qxxx-2pp7-5hmx","title":"jackson-databind is vulnerable to a deserialization flaw","description":"A deserialization flaw was discovered in the jackson-databind, versions before 2.6.7.1, 2.7.9.1 and 2.8.9, which could allow an unauthenticated user to perform code execution by sending the maliciously crafted input to the readValue method of the ObjectMapper.","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2018-10-16T17:21:35.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2017-7525","https://github.com/FasterXML/jackson-databind/issues/1599","https://github.com/FasterXML/jackson-databind/issues/1723","https://access.redhat.com/errata/RHSA-2017:1834","https://access.redhat.com/errata/RHSA-2017:1835","https://access.redhat.com/errata/RHSA-2017:1836","https://access.redhat.com/errata/RHSA-2017:1837","https://access.redhat.com/errata/RHSA-2017:1839","https://access.redhat.com/errata/RHSA-2017:1840","https://access.redhat.com/errata/RHSA-2017:2477","https://access.redhat.com/errata/RHSA-2017:2546","https://access.redhat.com/errata/RHSA-2017:2547","https://access.redhat.com/errata/RHSA-2017:2633","https://access.redhat.com/errata/RHSA-2017:2635","https://access.redhat.com/errata/RHSA-2017:2636","https://access.redhat.com/errata/RHSA-2017:2637","https://access.redhat.com/errata/RHSA-2017:2638","https://access.redhat.com/errata/RHSA-2017:3141","https://access.redhat.com/errata/RHSA-2017:3454","https://access.redhat.com/errata/RHSA-2017:3455","https://access.redhat.com/errata/RHSA-2017:3456","https://access.redhat.com/errata/RHSA-2017:3458","https://access.redhat.com/errata/RHSA-2018:0294","https://access.redhat.com/errata/RHSA-2018:0342","https://access.redhat.com/errata/RHSA-2018:1449","https://access.redhat.com/errata/RHSA-2018:1450","https://access.redhat.com/errata/RHSA-2019:0910","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:3149","https://bugzilla.redhat.com/show_bug.cgi?id=1462702","https://cwiki.apache.org/confluence/display/WW/S2-055","https://github.com/advisories/GHSA-qxxx-2pp7-5hmx","https://lists.apache.org/thread.html/3c87dc8bca99a2b3b4743713b33d1de05b1d6b761fdf316224e9c81f@%3Cdev.lucene.apache.org%3E","https://lists.apache.org/thread.html/4641ed8616ccc2c1fbddac2c3dc9900c96387bc226eaf0232d61909b@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/5008bcbd45ee65ce39e4220b6ac53d28a24d6bc67d5804e9773a7399@%3Csolr-user.lucene.apache.org%3E","https://lists.apache.org/thread.html/708d94141126eac03011144a971a6411fcac16d9c248d1d535a39451@%3Csolr-user.lucene.apache.org%3E","https://lists.apache.org/thread.html/9317fd092b257a0815434b116a8af8daea6e920b6673f4fd5583d5fe@%3Ccommits.druid.apache.org%3E","https://lists.apache.org/thread.html/b1f33fe5ade396bb903fdcabe9f243f7692c7dfce5418d3743c2d346@%3Cdev.lucene.apache.org%3E","https://lists.apache.org/thread.html/c10a2bf0fdc3d25faf17bd191d6ec46b29a353fa9c97bebd7c4e5913@%3Cdev.lucene.apache.org%3E","https://lists.apache.org/thread.html/c2ed4c0126b43e324cf740012a0edd371fd36096fd777be7bfe7a2a6@%3Cdev.lucene.apache.org%3E","https://lists.apache.org/thread.html/c9d5ff20929e8a3c8794facf4c4b326a9c10618812eec356caa20b87@%3Csolr-user.lucene.apache.org%3E","https://lists.apache.org/thread.html/f095a791bda6c0595f691eddd0febb2d396987eec5cbd29120d8c629@%3Csolr-user.lucene.apache.org%3E","https://lists.apache.org/thread.html/f60afd3c7e9ebaaf70fad4a4beb75cf8740ac959017a31e7006c7486@%3Cdev.lucene.apache.org%3E","https://lists.apache.org/thread.html/r68acf97f4526ba59a33cc6e592261ea4f85d890f99e79c82d57dd589@%3Cissues.spark.apache.org%3E","https://lists.debian.org/debian-lts-announce/2020/01/msg00037.html","https://lists.debian.org/debian-lts-announce/2020/08/msg00039.html","https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US\u0026docId=emr_na-hpesbhf03902en_us","https://www.debian.org/security/2017/dsa-4004","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html","https://www.oracle.com/technetwork/security-advisory/cpujan2019-5072801.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html","http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html","http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html","https://lists.apache.org/thread.html/r42ac3e39e6265db12d9fc6ae1cd4b5fea7aed9830dc6f6d58228fed7@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/rf7f87810c38dc9abf9f93989f76008f504cbf7c1a355214640b2d04c@%3Ccommits.cassandra.apache.org%3E","https://github.com/FasterXML/jackson-databind/commit/3bfbb835e530055c1941ddf87fde0b08d08dcd38","https://github.com/FasterXML/jackson-databind/commit/60d459cedcf079c6106ae7da2ac562bc32dcabe1","https://github.com/FasterXML/jackson-databind/commit/680d75b011edd67a2d2a2e9980998a968194c2ef","https://github.com/FasterXML/jackson-databind/commit/6ce32ffd18facac6abdbbf559c817b47fcb622c1","https://github.com/FasterXML/jackson-databind/commit/90042692085deeb05ae75c569c9909f7dba24415","https://github.com/FasterXML/jackson-databind/commit/fa87c1ddbe803ebb7295f5c2ebfe38e12f6e6162","https://github.com/FasterXML/jackson-databind/commit/fd8dec2c7fab8b4b4bd60502a0f1d63ec23c24da","https://security.netapp.com/advisory/ntap-20171214-0002"],"source_kind":"github","identifiers":["GHSA-qxxx-2pp7-5hmx","CVE-2017-7525"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.7.9.1","vulnerable_version_range":"\u003e= 2.7.0, \u003c= 2.7.9.0"},{"first_patched_version":"2.6.7.1","vulnerable_version_range":"\u003c= 2.6.7.0"},{"first_patched_version":"2.8.9","vulnerable_version_range":"\u003e= 2.8.0, \u003c 2.8.9"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:12:59.529Z","updated_at":"2025-06-05T01:15:54.637Z","epss_percentage":0.77336,"epss_percentile":0.9891},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTU5NDktcnc3Zy13eDd3","url":"https://github.com/advisories/GHSA-5949-rw7g-wx7w","title":"Deserialization of untrusted data in jackson-databind","description":"A flaw was found in jackson-databind before 2.9.10.7 and 2.6.7.5. FasterXML mishandles the interaction between serialization gadgets and typing. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2021-01-20T21:20:15.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2021-20190","https://github.com/FasterXML/jackson-databind/issues/2854","https://github.com/FasterXML/jackson-databind/commit/7dbf51bf78d157098074a20bd9da39bd48c18e4a","https://bugzilla.redhat.com/show_bug.cgi?id=1916633","https://lists.apache.org/thread.html/r380e9257bacb8551ee6fcf2c59890ae9477b2c78e553fa9ea08e9d9a@%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2021/04/msg00025.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88","https://security.netapp.com/advisory/ntap-20210219-0008","https://github.com/advisories/GHSA-5949-rw7g-wx7w"],"source_kind":"github","identifiers":["GHSA-5949-rw7g-wx7w","CVE-2021-20190"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.6.7.5","vulnerable_version_range":"\u003c 2.6.7.5"},{"first_patched_version":"2.9.10.7","vulnerable_version_range":"\u003e= 2.7.0, \u003c 2.9.10.7"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:11.950Z","updated_at":"2024-03-15T00:16:04.000Z","epss_percentage":0.00625,"epss_percentile":0.69188},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTV3dzktajgzbS1xN3F4","url":"https://github.com/advisories/GHSA-5ww9-j83m-q7qx","title":"Information exposure in FasterXML jackson-databind","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.x before 2.9.9. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint, the service has the mysql-connector-java jar (8.0.14 or earlier) in the classpath, and an attacker can host a crafted MySQL server reachable by the victim, an attacker can send a crafted JSON message that allows them to read arbitrary local files on the server. This occurs because of missing com.mysql.cj.jdbc.admin.MiniAdmin validation.","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2019-05-23T09:32:24.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2019-12086","https://github.com/FasterXML/jackson-databind/issues/2326","https://github.com/FasterXML/jackson/wiki/Jackson-Release-2.9.9","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://access.redhat.com/errata/RHSA-2019:2858","https://access.redhat.com/errata/RHSA-2019:2935","https://access.redhat.com/errata/RHSA-2019:2936","https://access.redhat.com/errata/RHSA-2019:2937","https://access.redhat.com/errata/RHSA-2019:2938","https://access.redhat.com/errata/RHSA-2019:2998","https://access.redhat.com/errata/RHSA-2019:3044","https://access.redhat.com/errata/RHSA-2019:3045","https://access.redhat.com/errata/RHSA-2019:3046","https://access.redhat.com/errata/RHSA-2019:3050","https://access.redhat.com/errata/RHSA-2019:3149","https://access.redhat.com/errata/RHSA-2019:3200","https://lists.apache.org/thread.html/3f99ae8dcdbd69438cb733d745ee3ad5e852068490719a66509b4592@%3Ccommits.cassandra.apache.org%3E","https://lists.apache.org/thread.html/519eb0fd45642dcecd9ff74cb3e71c20a4753f7d82e2f07864b5108f@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/88cd25375805950ae7337e669b0cb0eeda98b9604c1b8d806dccbad2@%3Creviews.spark.apache.org%3E","https://lists.apache.org/thread.html/b0656d359c7d40ec9f39c8cc61bca66802ef9a2a12ee199f5b0c1442@%3Cdev.drill.apache.org%3E","https://lists.apache.org/thread.html/bcce5a9c532b386c68dab2f6b3ce8b0cc9b950ec551766e76391caa3@%3Ccommits.nifi.apache.org%3E","https://lists.apache.org/thread.html/f9bc3e55f4e28d1dcd1a69aae6d53e609a758e34d2869b4d798e13cc@%3Cissues.drill.apache.org%3E","https://lists.apache.org/thread.html/r204ba2a9ea750f38d789d2bb429cc0925ad6133deea7cbc3001d96b5@%3Csolr-user.lucene.apache.org%3E","https://lists.apache.org/thread.html/rca37935d661f4689cb4119f1b3b224413b22be161b678e6e6ce0c69b@%3Ccommits.nifi.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/05/msg00030.html","https://seclists.org/bugtraq/2019/May/68","https://www.debian.org/security/2019/dsa-4452","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html","https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html","https://lists.apache.org/thread.html/rda99599896c3667f2cc9e9d34c7b6ef5d2bbed1f4801e1d75a2b0679@%3Ccommits.nifi.apache.org%3E","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuapr2022.html","https://web.archive.org/web/20200227030031/http://www.securityfocus.com/bid/109227","https://github.com/FasterXML/jackson-databind/commit/efc3c0d02f4743dbaa6d1b9c466772a2f13d966b","https://github.com/FasterXML/jackson-databind/commit/dda513bd7251b4f32b7b60b1c13740e3b5a43024","https://github.com/FasterXML/jackson-databind/commit/d30f036208ab1c60bd5ce429cb4f7f1a3e5682e8","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/OVRZDN2T6AZ6DJCZJ3VSIQIVHBVMVWBL","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/TXRVXNRFHJSQWFHPRJQRI5UPMZ63B544","https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/UKUALE2TUCKEKOHE2D342PQXN4MWCSLC","https://security.netapp.com/advisory/ntap-20190530-0003","https://web.archive.org/web/20200808181049/http://russiansecurity.expert/2016/04/20/mysql-connect-file-read","https://github.com/advisories/GHSA-5ww9-j83m-q7qx"],"source_kind":"github","identifiers":["GHSA-5ww9-j83m-q7qx","CVE-2019-12086"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.6.7.3","vulnerable_version_range":"\u003e= 2.0.0, \u003c 2.6.7.3"},{"first_patched_version":"2.7.9.6","vulnerable_version_range":"\u003e= 2.7.0, \u003c 2.7.9.6"},{"first_patched_version":"2.8.11.4","vulnerable_version_range":"\u003e= 2.8.0, \u003c 2.8.11.4"},{"first_patched_version":"2.9.9","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.9"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:30.093Z","updated_at":"2024-03-15T01:06:42.000Z","epss_percentage":0.15745,"epss_percentile":0.94152},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTl2dnAtZnh3Ni1qY3hy","url":"https://github.com/advisories/GHSA-9vvp-fxw6-jcxr","title":"jackson-databind mishandles the interaction between serialization gadgets and typing","description":"FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2020-05-15T18:58:47.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-11113","https://github.com/FasterXML/jackson-databind/issues/2670","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://lists.debian.org/debian-lts-announce/2020/04/msg00012.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/FasterXML/jackson-databind/commit/08fbfacf89a4a4c026a6227a1b470ab7a13e2e88","https://github.com/FasterXML/jackson-databind/commit/e2ba12d5d60715d95105e3e790fc234cfb59893d","https://security.netapp.com/advisory/ntap-20200403-0002","https://github.com/advisories/GHSA-9vvp-fxw6-jcxr"],"source_kind":"github","identifiers":["GHSA-9vvp-fxw6-jcxr","CVE-2020-11113"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.10.4","vulnerable_version_range":"\u003e= 2.9.0, \u003c= 2.9.10.3"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:25.103Z","updated_at":"2024-03-15T00:48:55.000Z","epss_percentage":0.5882,"epss_percentile":0.98039},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWdqbXctdmY5aC1nMjV2","url":"https://github.com/advisories/GHSA-gjmw-vf9h-g25v","title":"jackson-databind polymorphic typing issue","description":"A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 prior to 2.9.10.1, 2.8.11.5, and 2.6.7.3. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the apache-log4j-extra (version 1.2.x) jar in the classpath, and an attacker can provide a JNDI service to access, it is possible to make the service execute a malicious payload. ","origin":"UNSPECIFIED","severity":"CRITICAL","published_at":"2019-11-13T00:32:38.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2019-17531","https://github.com/FasterXML/jackson-databind/issues/2498","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://access.redhat.com/errata/RHSA-2019:4192","https://access.redhat.com/errata/RHSA-2020:0159","https://access.redhat.com/errata/RHSA-2020:0160","https://access.redhat.com/errata/RHSA-2020:0161","https://access.redhat.com/errata/RHSA-2020:0164","https://access.redhat.com/errata/RHSA-2020:0445","https://lists.apache.org/thread.html/b3c90d38f99db546de60fea65f99a924d540fae2285f014b79606ca5@%3Ccommits.pulsar.apache.org%3E","https://lists.apache.org/thread.html/r392099ed2757ff2e383b10440594e914d080511d7da1c8fed0612c1f@%3Ccommits.druid.apache.org%3E","https://lists.debian.org/debian-lts-announce/2019/12/msg00013.html","https://security.netapp.com/advisory/ntap-20191024-0005/","https://www.oracle.com/security-alerts/cpuapr2020.html","https://www.oracle.com/security-alerts/cpujan2020.html","https://www.oracle.com/security-alerts/cpujul2020.html","https://lists.apache.org/thread.html/r1b103833cb5bc8466e24ff0ecc5e75b45a705334ab6a444e64e840a0@%3Cissues.bookkeeper.apache.org%3E","https://lists.apache.org/thread.html/rf1bbc0ea4a9f014cf94df9a12a6477d24a27f52741dbc87f2fd52ff2@%3Cissues.geode.apache.org%3E","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://github.com/FasterXML/jackson-databind/commit/b5a304a98590b6bb766134f9261e6566dcbbb6d0","https://github.com/advisories/GHSA-gjmw-vf9h-g25v"],"source_kind":"github","identifiers":["GHSA-gjmw-vf9h-g25v","CVE-2019-17531"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.6.7.3","vulnerable_version_range":"\u003c 2.6.7.3"},{"first_patched_version":"2.8.11.5","vulnerable_version_range":"\u003e= 2.7.0, \u003c 2.8.11.5"},{"first_patched_version":"2.9.10.1","vulnerable_version_range":"\u003e= 2.9.0, \u003c 2.9.10.1"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:06.113Z","updated_at":"2023-09-14T14:55:25.000Z","epss_percentage":0.0119,"epss_percentile":0.77612},{"uuid":"MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLWMycTMtNHFyaC1mbTQ4","url":"https://github.com/advisories/GHSA-c2q3-4qrh-fm48","title":"Deserialization of untrusted data in Jackson Databind","description":"FasterXML jackson-databind 2.x before 2.9.10.5 mishandles the interaction between serialization gadgets and typing, related to oracle.jms.AQjmsQueueConnectionFactory, oracle.jms.AQjmsXATopicConnectionFactory, oracle.jms.AQjmsTopicConnectionFactory, oracle.jms.AQjmsXAQueueConnectionFactory, and oracle.jms.AQjmsXAConnectionFactory (aka weblogic/oracle-aqjms).","origin":"UNSPECIFIED","severity":"HIGH","published_at":"2020-06-18T14:44:50.000Z","withdrawn_at":null,"classification":"GENERAL","cvss_score":0.0,"cvss_vector":null,"references":["https://nvd.nist.gov/vuln/detail/CVE-2020-14061","https://github.com/FasterXML/jackson-databind/issues/2698","https://github.com/FasterXML/jackson-databind/commit/5c8642aeae9c756b438ab7637c90ef3c77966e6e","https://medium.com/@cowtowncoder/on-jackson-cves-dont-panic-here-is-what-you-need-to-know-54cd0d6e8062","https://snyk.io/vuln/SNYK-JAVA-COMFASTERXMLJACKSONCORE-572316","https://lists.debian.org/debian-lts-announce/2020/07/msg00001.html","https://security.netapp.com/advisory/ntap-20200702-0003/","https://www.oracle.com/security-alerts/cpuApr2021.html","https://www.oracle.com/security-alerts/cpujan2021.html","https://www.oracle.com/security-alerts/cpuoct2020.html","https://www.oracle.com//security-alerts/cpujul2021.html","https://www.oracle.com/security-alerts/cpuoct2021.html","https://github.com/advisories/GHSA-c2q3-4qrh-fm48"],"source_kind":"github","identifiers":["GHSA-c2q3-4qrh-fm48","CVE-2020-14061"],"repository_url":"https://github.com/FasterXML/jackson-databind","blast_radius":0.0,"packages":[{"versions":[{"first_patched_version":"2.9.10.5","vulnerable_version_range":"\u003e= 2.9.0, \u003c= 2.9.10.4"}],"ecosystem":"maven","package_name":"com.fasterxml.jackson.core:jackson-databind"}],"created_at":"2022-12-21T16:13:23.984Z","updated_at":"2023-02-01T05:04:14.000Z","epss_percentage":0.0615,"epss_percentile":0.90365}],"docker_usage_url":"https://docker.ecosyste.ms/usage/maven/com.fasterxml.jackson.core:jackson-databind","docker_dependents_count":44228,"docker_downloads_count":16203456674,"usage_url":"https://repos.ecosyste.ms/usage/maven/com.fasterxml.jackson.core:jackson-databind","dependent_repositories_url":"https://repos.ecosyste.ms/api/v1/usage/maven/com.fasterxml.jackson.core:jackson-databind/dependencies","status":null,"funding_links":["https://tidelift.com/funding/github/maven/com.fasterxml.jackson.core:jackson-databind","https://github.com/sponsors/cowtowncoder"],"critical":true,"versions_url":"https://packages.ecosyste.ms/api/v1/registries/repo1.maven.org/packages/com.fasterxml.jackson.core:jackson-databind/versions","version_numbers_url":"https://packages.ecosyste.ms/api/v1/registries/repo1.maven.org/packages/com.fasterxml.jackson.core:jackson-databind/version_numbers","dependent_packages_url":"https://packages.ecosyste.ms/api/v1/registries/repo1.maven.org/packages/com.fasterxml.jackson.core:jackson-databind/dependent_packages","related_packages_url":"https://packages.ecosyste.ms/api/v1/registries/repo1.maven.org/packages/com.fasterxml.jackson.core:jackson-databind/related_packages","maintainers":[],"registry":{"name":"repo1.maven.org","url":"https://repo.maven.apache.org/maven2","ecosystem":"maven","default":true,"packages_count":517653,"maintainers_count":0,"namespaces_count":68787,"keywords_count":32037,"github":"maven-central","metadata":{"funded_packages_count":24975},"icon_url":"https://github.com/maven-central.png","created_at":"2022-07-21T16:40:13.074Z","updated_at":"2025-06-06T05:59:03.422Z","packages_url":"https://packages.ecosyste.ms/api/v1/registries/repo1.maven.org/packages","maintainers_url":"https://packages.ecosyste.ms/api/v1/registries/repo1.maven.org/maintainers","namespaces_url":"https://packages.ecosyste.ms/api/v1/registries/repo1.maven.org/namespaces"}},"unique_repositories_count":1126,"unique_repositories_count_past_30_days":41,"recent_issues":[{"uuid":"5628165229","node_id":"PR_kwDOBErimM8AAAABFqiiig","number":9081,"state":"closed","title":"Bump the all-gradle-deps group across 1 directory with 32 updates","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-09-30T01:51:10.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-29T09:15:39.000Z","updated_at":"2026-09-30T01:51:19.000Z","time_to_close":59731,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"all-gradle-deps","update_count":32,"packages":[{"name":"gradle-wrapper","old_version":"9.7.1","new_version":"9.8.0","repository_url":"https://github.com/gradle/gradle"},{"name":"org.slf4j:slf4j-api","old_version":"2.0.19","new_version":"2.0.20"},{"name":"org.slf4j:slf4j-simple","old_version":"2.0.19","new_version":"2.0.20"},{"name":"org.slf4j:jcl-over-slf4j","old_version":"2.0.19","new_version":"2.0.20"},{"name":"org.slf4j:slf4j-simple","old_version":"2.0.19","new_version":"2.0.20"},{"name":"org.slf4j:jcl-over-slf4j","old_version":"2.0.19","new_version":"2.0.20"},{"name":"software.amazon.awssdk:s3","old_version":"2.55.1","new_version":"2.55.6"},{"name":"software.amazon.awssdk:s3-transfer-manager","old_version":"2.55.1","new_version":"2.55.6"},{"name":"software.amazon.awssdk:sts","old_version":"2.55.1","new_version":"2.55.6"},{"name":"software.amazon.awssdk:sso","old_version":"2.55.1","new_version":"2.55.6"},{"name":"software.amazon.awssdk:ssooidc","old_version":"2.55.1","new_version":"2.55.6"},{"name":"software.amazon.awssdk:cloudfront","old_version":"2.55.1","new_version":"2.55.6"},{"name":"software.amazon.awssdk:cloudformation","old_version":"2.55.1","new_version":"2.55.6"},{"name":"software.amazon.awssdk:mediaconvert","old_version":"2.55.1","new_version":"2.55.6"},{"name":"software.amazon.awssdk:s3-transfer-manager","old_version":"2.55.1","new_version":"2.55.6"},{"name":"org.mongodb:bson","old_version":"5.12.0","new_version":"5.13.0","repository_url":"https://github.com/mongodb/mongo-java-driver"},{"name":"org.mongodb:mongodb-driver-sync","old_version":"5.12.0","new_version":"5.13.0","repository_url":"https://github.com/mongodb/mongo-java-driver"},{"name":"org.mongodb:mongodb-driver-legacy","old_version":"5.12.0","new_version":"5.13.0","repository_url":"https://github.com/mongodb/mongo-java-driver"},{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-databind"},{"name":"com.fasterxml.jackson.core:jackson-core","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-core"},{"name":"com.fasterxml.jackson.dataformat:jackson-dataformat-cbor","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-dataformats-binary"},{"name":"com.fasterxml.jackson.dataformat:jackson-dataformat-xml","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-dataformat-xml"},{"name":"com.fasterxml.jackson.datatype:jackson-datatype-jsr310","old_version":"2.22.2","new_version":"2.22.3"},{"name":"com.fasterxml.jackson.dataformat:jackson-dataformat-smile","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-dataformats-binary"},{"name":"com.fasterxml.jackson.dataformat:jackson-dataformat-yaml","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-dataformats-text"},{"name":"tools.jackson.core:jackson-databind","old_version":"3.2.2","new_version":"3.2.3","repository_url":"https://github.com/FasterXML/jackson-databind"},{"name":"com.fasterxml.jackson.core:jackson-core","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-core"},{"name":"com.fasterxml.jackson.dataformat:jackson-dataformat-cbor","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-dataformats-binary"},{"name":"com.fasterxml.jackson.dataformat:jackson-dataformat-xml","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-dataformat-xml"},{"name":"org.apache.groovy:groovy","old_version":"5.1.3","new_version":"6.0.0","repository_url":"https://github.com/apache/groovy"},{"name":"org.apache.groovy:groovy-sql","old_version":"5.1.3","new_version":"6.0.0","repository_url":"https://github.com/apache/groovy"},{"name":"org.apache.groovy:groovy-all","old_version":"5.1.3","new_version":"6.0.0","repository_url":"https://github.com/apache/groovy"},{"name":"org.apache.groovy:groovy-sql","old_version":"5.1.3","new_version":"6.0.0","repository_url":"https://github.com/apache/groovy"},{"name":"com.github.ben-manes.caffeine:caffeine","old_version":"3.2.4","new_version":"3.3.0","repository_url":"https://github.com/ben-manes/caffeine"},{"name":"org.mockito:mockito-core","old_version":"5.23.0","new_version":"5.24.0","repository_url":"https://github.com/mockito/mockito"},{"name":"org.hibernate.validator:hibernate-validator","old_version":"9.1.3.Final","new_version":"9.1.4.Final","repository_url":"https://github.com/hibernate/hibernate-validator"},{"name":"org.mongodb:mongodb-driver-sync","old_version":"5.12.0","new_version":"5.13.0","repository_url":"https://github.com/mongodb/mongo-java-driver"},{"name":"org.mongodb:mongodb-driver-legacy","old_version":"5.12.0","new_version":"5.13.0","repository_url":"https://github.com/mongodb/mongo-java-driver"},{"name":"joda-time:joda-time","old_version":"2.14.3","new_version":"2.14.4","repository_url":"https://github.com/JodaOrg/joda-time"},{"name":"com.fasterxml.jackson.datatype:jackson-datatype-jsr310","old_version":"2.22.2","new_version":"2.22.3"},{"name":"org.apache.groovy:groovy-all","old_version":"5.1.3","new_version":"6.0.0","repository_url":"https://github.com/apache/groovy"},{"name":"com.fasterxml.jackson.dataformat:jackson-dataformat-smile","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-dataformats-binary"},{"name":"com.fasterxml.jackson.dataformat:jackson-dataformat-yaml","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-dataformats-text"},{"name":"software.amazon.awssdk:sts","old_version":"2.55.1","new_version":"2.55.6"},{"name":"software.amazon.awssdk:sso","old_version":"2.55.1","new_version":"2.55.6"},{"name":"software.amazon.awssdk:ssooidc","old_version":"2.55.1","new_version":"2.55.6"},{"name":"com.icegreen:greenmail","old_version":"2.1.13","new_version":"2.1.14","repository_url":"https://github.com/greenmail-mail-test/greenmail"},{"name":"com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer","old_version":"20260313.1","new_version":"20260924.2","repository_url":"https://github.com/OWASP/java-html-sanitizer"},{"name":"software.amazon.awssdk:cloudfront","old_version":"2.55.1","new_version":"2.55.6"},{"name":"software.amazon.awssdk:cloudformation","old_version":"2.55.1","new_version":"2.55.6"},{"name":"software.amazon.awssdk:mediaconvert","old_version":"2.55.1","new_version":"2.55.6"}],"path":null,"ecosystem":"maven"},"body":"Bumps the all-gradle-deps group with 32 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [gradle-wrapper](https://github.com/gradle/gradle) | `9.7.1` | `9.8.0` |\n| org.slf4j:slf4j-api | `2.0.19` | `2.0.20` |\n| org.slf4j:slf4j-simple | `2.0.19` | `2.0.20` |\n| org.slf4j:jcl-over-slf4j | `2.0.19` | `2.0.20` |\n| org.slf4j:slf4j-simple | `2.0.19` | `2.0.20` |\n| org.slf4j:jcl-over-slf4j | `2.0.19` | `2.0.20` |\n| software.amazon.awssdk:s3 | `2.55.1` | `2.55.6` |\n| software.amazon.awssdk:s3-transfer-manager | `2.55.1` | `2.55.6` |\n| software.amazon.awssdk:sts | `2.55.1` | `2.55.6` |\n| software.amazon.awssdk:sso | `2.55.1` | `2.55.6` |\n| software.amazon.awssdk:ssooidc | `2.55.1` | `2.55.6` |\n| software.amazon.awssdk:cloudfront | `2.55.1` | `2.55.6` |\n| software.amazon.awssdk:cloudformation | `2.55.1` | `2.55.6` |\n| software.amazon.awssdk:mediaconvert | `2.55.1` | `2.55.6` |\n| software.amazon.awssdk:s3-transfer-manager | `2.55.1` | `2.55.6` |\n| [org.mongodb:bson](https://github.com/mongodb/mongo-java-driver) | `5.12.0` | `5.13.0` |\n| [org.mongodb:mongodb-driver-sync](https://github.com/mongodb/mongo-java-driver) | `5.12.0` | `5.13.0` |\n| [org.mongodb:mongodb-driver-legacy](https://github.com/mongodb/mongo-java-driver) | `5.12.0` | `5.13.0` |\n| [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) | `2.22.2` | `2.22.3` |\n| [com.fasterxml.jackson.core:jackson-core](https://github.com/FasterXML/jackson-core) | `2.22.2` | `2.22.3` |\n| [com.fasterxml.jackson.dataformat:jackson-dataformat-cbor](https://github.com/FasterXML/jackson-dataformats-binary) | `2.22.2` | `2.22.3` |\n| [com.fasterxml.jackson.dataformat:jackson-dataformat-xml](https://github.com/FasterXML/jackson-dataformat-xml) | `2.22.2` | `2.22.3` |\n| com.fasterxml.jackson.datatype:jackson-datatype-jsr310 | `2.22.2` | `2.22.3` |\n| [com.fasterxml.jackson.dataformat:jackson-dataformat-smile](https://github.com/FasterXML/jackson-dataformats-binary) | `2.22.2` | `2.22.3` |\n| [com.fasterxml.jackson.dataformat:jackson-dataformat-yaml](https://github.com/FasterXML/jackson-dataformats-text) | `2.22.2` | `2.22.3` |\n| [tools.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) | `3.2.2` | `3.2.3` |\n| [com.fasterxml.jackson.core:jackson-core](https://github.com/FasterXML/jackson-core) | `2.22.2` | `2.22.3` |\n| [com.fasterxml.jackson.dataformat:jackson-dataformat-cbor](https://github.com/FasterXML/jackson-dataformats-binary) | `2.22.2` | `2.22.3` |\n| [com.fasterxml.jackson.dataformat:jackson-dataformat-xml](https://github.com/FasterXML/jackson-dataformat-xml) | `2.22.2` | `2.22.3` |\n| [org.apache.groovy:groovy](https://github.com/apache/groovy) | `5.1.3` | `6.0.0` |\n| [org.apache.groovy:groovy-sql](https://github.com/apache/groovy) | `5.1.3` | `6.0.0` |\n| [org.apache.groovy:groovy-all](https://github.com/apache/groovy) | `5.1.3` | `6.0.0` |\n| [org.apache.groovy:groovy-sql](https://github.com/apache/groovy) | `5.1.3` | `6.0.0` |\n| [com.github.ben-manes.caffeine:caffeine](https://github.com/ben-manes/caffeine) | `3.2.4` | `3.3.0` |\n| [org.mockito:mockito-core](https://github.com/mockito/mockito) | `5.23.0` | `5.24.0` |\n| [org.hibernate.validator:hibernate-validator](https://github.com/hibernate/hibernate-validator) | `9.1.3.Final` | `9.1.4.Final` |\n| [org.mongodb:mongodb-driver-sync](https://github.com/mongodb/mongo-java-driver) | `5.12.0` | `5.13.0` |\n| [org.mongodb:mongodb-driver-legacy](https://github.com/mongodb/mongo-java-driver) | `5.12.0` | `5.13.0` |\n| [joda-time:joda-time](https://github.com/JodaOrg/joda-time) | `2.14.3` | `2.14.4` |\n| com.fasterxml.jackson.datatype:jackson-datatype-jsr310 | `2.22.2` | `2.22.3` |\n| [org.apache.groovy:groovy-all](https://github.com/apache/groovy) | `5.1.3` | `6.0.0` |\n| [com.fasterxml.jackson.dataformat:jackson-dataformat-smile](https://github.com/FasterXML/jackson-dataformats-binary) | `2.22.2` | `2.22.3` |\n| [com.fasterxml.jackson.dataformat:jackson-dataformat-yaml](https://github.com/FasterXML/jackson-dataformats-text) | `2.22.2` | `2.22.3` |\n| software.amazon.awssdk:sts | `2.55.1` | `2.55.6` |\n| software.amazon.awssdk:sso | `2.55.1` | `2.55.6` |\n| software.amazon.awssdk:ssooidc | `2.55.1` | `2.55.6` |\n| [com.icegreen:greenmail](https://github.com/greenmail-mail-test/greenmail) | `2.1.13` | `2.1.14` |\n| [com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer](https://github.com/OWASP/java-html-sanitizer) | `20260313.1` | `20260924.2` |\n| software.amazon.awssdk:cloudfront | `2.55.1` | `2.55.6` |\n| software.amazon.awssdk:cloudformation | `2.55.1` | `2.55.6` |\n| software.amazon.awssdk:mediaconvert | `2.55.1` | `2.55.6` |\n\n\nUpdates `gradle-wrapper` from 9.7.1 to 9.8.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/gradle/gradle/releases\"\u003egradle-wrapper's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e9.8.0\u003c/h2\u003e\n\u003cp\u003eThe Gradle team is excited to announce Gradle 9.8.0.\u003c/p\u003e\n\u003cp\u003eHere are the highlights of this release:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eJava 27 support\u003c/li\u003e\n\u003cli\u003eMaven mirror settings reuse\u003c/li\u003e\n\u003cli\u003eLinked problem locations in build output\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://docs.gradle.org/9.8.0/release-notes.html\"\u003eRead the Release Notes\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eWe would like to thank the following community members for their contributions to this release of Gradle:\n\u003ca href=\"https://github.com/Gautam-aman\"\u003eAman Gautam\u003c/a\u003e,\n\u003ca href=\"https://github.com/Vampire\"\u003eBjörn Kautler\u003c/a\u003e,\n\u003ca href=\"https://github.com/Juneezee\"\u003eEng Zer Jun\u003c/a\u003e,\n\u003ca href=\"https://github.com/Hashim1999164\"\u003eHashim Khan\u003c/a\u003e,\n\u003ca href=\"https://github.com/jkrannich\"\u003eJulian Krannich\u003c/a\u003e,\n\u003ca href=\"https://github.com/youdie006\"\u003eKBS\u003c/a\u003e,\n\u003ca href=\"https://github.com/itsCodeTide\"\u003eLabh R Jethe\u003c/a\u003e,\n\u003ca href=\"https://github.com/doddi\"\u003eMark Dodgson\u003c/a\u003e,\n\u003ca href=\"https://github.com/kroune\"\u003eMaxim\u003c/a\u003e,\n\u003ca href=\"https://github.com/Develop-KIM\"\u003emonkey\u003c/a\u003e,\n\u003ca href=\"https://github.com/nataphon-ktsystems\"\u003enataphon-ktsystems\u003c/a\u003e,\n\u003ca href=\"https://github.com/paulk-asert\"\u003ePaul King\u003c/a\u003e,\n\u003ca href=\"https://github.com/qiu-tiandev\"\u003eQiu Tian\u003c/a\u003e,\n\u003ca href=\"https://github.com/sandeshgorde\"\u003erg_sandesh\u003c/a\u003e,\n\u003ca href=\"https://github.com/rpalcolea\"\u003eRoberto Perez Alcolea\u003c/a\u003e,\n\u003ca href=\"https://github.com/seanxuu\"\u003eSean\u003c/a\u003e,\n\u003ca href=\"https://github.com/Goooler\"\u003eZongle Wang\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eUpgrade instructions\u003c/h2\u003e\n\u003cp\u003eSwitch your build to use Gradle 9.8.0 by updating your wrapper:\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e./gradlew :wrapper --gradle-version=9.8.0 \u0026amp;\u0026amp; ./gradlew :wrapper\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eSee the Gradle \u003ca href=\"https://docs.gradle.org/9.8.0/userguide/upgrading_version_9.html\"\u003e9.x upgrade guide\u003c/a\u003e to learn about deprecations, breaking changes and other considerations when upgrading.\u003c/p\u003e\n\u003cp\u003eFor Java, Groovy, Kotlin and Android compatibility, see the \u003ca href=\"https://docs.gradle.org/9.8.0/userguide/compatibility.html\"\u003efull compatibility notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eReporting problems\u003c/h2\u003e\n\u003cp\u003eIf you find a problem with this release, please file a bug on \u003ca href=\"https://github.com/gradle/gradle/issues\"\u003eGitHub Issues\u003c/a\u003e adhering to our issue guidelines.\nIf you're not sure you're encountering a bug, please use the \u003ca href=\"https://discuss.gradle.org/c/help-discuss\"\u003eforum\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eWe hope you will build happiness with Gradle, and we look forward to your feedback via \u003ca href=\"https://twitter.com/gradle\"\u003eTwitter\u003c/a\u003e or on \u003ca href=\"https://github.com/gradle\"\u003eGitHub\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003e9.8.0 RC3\u003c/h2\u003e\n\u003cp\u003eThe Gradle team is excited to announce Gradle 9.8.0 RC3.\u003c/p\u003e\n\u003cp\u003eHere are the highlights of this release:\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/a927be5e08efe79e0b87ada06c762dde6bb9f8b8\"\u003e\u003ccode\u003ea927be5\u003c/code\u003e\u003c/a\u003e Add the Develocity plugin back to the Android smoke tests (\u003ca href=\"https://redirect.github.com/gradle/gradle/issues/39273\"\u003e#39273\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/eaee500e6a2fff583b9d2b81039fc15ad887462d\"\u003e\u003ccode\u003eeaee500\u003c/code\u003e\u003c/a\u003e Add the Develocity plugin back to the Android smoke tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/189b672308d1e997fae46412673d04683d76b35a\"\u003e\u003ccode\u003e189b672\u003c/code\u003e\u003c/a\u003e Route everything still hitting Maven Central through the mirror (\u003ca href=\"https://redirect.github.com/gradle/gradle/issues/39257\"\u003e#39257\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/36b181477307fc6db0e16582f11daaeb7e34fc8e\"\u003e\u003ccode\u003e36b1814\u003c/code\u003e\u003c/a\u003e Add back mavenCentral to doc snippets\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/2740c2d9cd0a9ab42813be77241fdc264217b2ba\"\u003e\u003ccode\u003e2740c2d\u003c/code\u003e\u003c/a\u003e Update Gradle wrapper to version 9.8.0-rc-3 (\u003ca href=\"https://redirect.github.com/gradle/gradle/issues/39264\"\u003e#39264\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/209938316e373c847aa1a251ec14eeded3da468e\"\u003e\u003ccode\u003e2099383\u003c/code\u003e\u003c/a\u003e Update Gradle wrapper to version 9.8.0-rc-3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/c80202fbd1cc457d7f45f31fc488391c4a2e7984\"\u003e\u003ccode\u003ec80202f\u003c/code\u003e\u003c/a\u003e Route everything still hitting Maven Central through the mirror\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/3f6a53434a2cf4f33486af2ae5eabd1fc830352d\"\u003e\u003ccode\u003e3f6a534\u003c/code\u003e\u003c/a\u003e Fix when a best practice was introduced (\u003ca href=\"https://redirect.github.com/gradle/gradle/issues/39253\"\u003e#39253\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/9efc9eddac43f0795194e407c0ab2177a1d23cf9\"\u003e\u003ccode\u003e9efc9ed\u003c/code\u003e\u003c/a\u003e Fix when a best practice was introduced\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/459e1433c60e4a604dd39ffe2c49e3606f70acda\"\u003e\u003ccode\u003e459e143\u003c/code\u003e\u003c/a\u003e Route integration test dependencies through the repository mirror (\u003ca href=\"https://redirect.github.com/gradle/gradle/issues/39239\"\u003e#39239\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/gradle/gradle/compare/v9.7.1...v9.8.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.slf4j:slf4j-api` from 2.0.19 to 2.0.20\n\nUpdates `org.slf4j:slf4j-simple` from 2.0.19 to 2.0.20\n\nUpdates `org.slf4j:jcl-over-slf4j` from 2.0.19 to 2.0.20\n\nUpdates `org.slf4j:slf4j-simple` from 2.0.19 to 2.0.20\n\nUpdates `org.slf4j:jcl-over-slf4j` from 2.0.19 to 2.0.20\n\nUpdates `software.amazon.awssdk:s3` from 2.55.1 to 2.55.6\n\nUpdates `software.amazon.awssdk:s3-transfer-manager` from 2.55.1 to 2.55.6\n\nUpdates `software.amazon.awssdk:sts` from 2.55.1 to 2.55.6\n\nUpdates `software.amazon.awssdk:sso` from 2.55.1 to 2.55.6\n\nUpdates `software.amazon.awssdk:ssooidc` from 2.55.1 to 2.55.6\n\nUpdates `software.amazon.awssdk:cloudfront` from 2.55.1 to 2.55.6\n\nUpdates `software.amazon.awssdk:cloudformation` from 2.55.1 to 2.55.6\n\nUpdates `software.amazon.awssdk:mediaconvert` from 2.55.1 to 2.55.6\n\nUpdates `software.amazon.awssdk:s3-transfer-manager` from 2.55.1 to 2.55.6\n\nUpdates `org.mongodb:bson` from 5.12.0 to 5.13.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mongodb/mongo-java-driver/releases\"\u003eorg.mongodb:bson's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eJava Driver 5.13.0 (September 25, 2026)\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps): bump testing/resources/specifications from \u003ccode\u003e92b3c0b\u003c/code\u003e to \u003ccode\u003e529a2dd\u003c/code\u003e by \u003ca href=\"https://github.com/apmasell\"\u003e\u003ccode\u003e@​apmasell\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2061\"\u003emongodb/mongo-java-driver#2061\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJAVA-6312 Increase testConnectionPoolBackpressure completion time on CI by \u003ca href=\"https://github.com/nhachicha\"\u003e\u003ccode\u003e@​nhachicha\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2062\"\u003emongodb/mongo-java-driver#2062\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJAVA-6235: Configurable DNS domain validation for SRV records by \u003ca href=\"https://github.com/apmasell\"\u003e\u003ccode\u003e@​apmasell\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2054\"\u003emongodb/mongo-java-driver#2054\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJAVA-6235 Add SRV allow hosts option to legacy driver by \u003ca href=\"https://github.com/apmasell\"\u003e\u003ccode\u003e@​apmasell\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2065\"\u003emongodb/mongo-java-driver#2065\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apmasell\"\u003e\u003ccode\u003e@​apmasell\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2061\"\u003emongodb/mongo-java-driver#2061\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/mongodb/mongo-java-driver/compare/r5.12.0...r5.13.0\"\u003ehttps://github.com/mongodb/mongo-java-driver/compare/r5.12.0...r5.13.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVerifying artifact signatures\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://www.mongodb.com/docs/languages/java/mongodb-hibernate/upcoming/security/validate-signatures/\"\u003ehttps://www.mongodb.com/docs/languages/java/mongodb-hibernate/upcoming/security/validate-signatures/\u003c/a\u003e for the full procedure.\u003c/p\u003e\n\u003cp\u003eTo download and import the public key for verifying signatures, execute\u003c/p\u003e\n\u003cpre lang=\"bash\"\u003e\u003ccode\u003egpg --keyserver hkps://keyserver.ubuntu.com --recv-keys 1a75005e142192223d6a7c3b76e0008d166740a8\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/f949913b29b5b94f49d83dadeecd29e61ec0ea56\"\u003e\u003ccode\u003ef949913\u003c/code\u003e\u003c/a\u003e Version: bump 5.13.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/917421419d3bc8123f3933efba869571cdf7bdf4\"\u003e\u003ccode\u003e9174214\u003c/code\u003e\u003c/a\u003e JAVA-6235 Add SRV allow hosts option to legacy driver (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/2065\"\u003e#2065\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/ee2c0ba8250da6642be5806929b44b1efc4472c6\"\u003e\u003ccode\u003eee2c0ba\u003c/code\u003e\u003c/a\u003e JAVA-6235: Configurable DNS domain validation for SRV records (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/2054\"\u003e#2054\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/551f88ba48d98d074834cf032b9fe1dd7b14e973\"\u003e\u003ccode\u003e551f88b\u003c/code\u003e\u003c/a\u003e JAVA-6312 Increase testConnectionPoolBackpressure completion time on CI (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/2062\"\u003e#2062\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/ff74470144f9c5ea98a5ab0881edbbfb1be2ca80\"\u003e\u003ccode\u003eff74470\u003c/code\u003e\u003c/a\u003e build(deps): bump testing/resources/specifications from \u003ccode\u003e92b3c0b\u003c/code\u003e to `529a2dd...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/3e757081a5c40f7527c7c607c1eaa258a245d548\"\u003e\u003ccode\u003e3e75708\u003c/code\u003e\u003c/a\u003e Version: bump 5.13.0-SNAPSHOT\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/mongodb/mongo-java-driver/compare/r5.12.0...r5.13.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.mongodb:mongodb-driver-sync` from 5.12.0 to 5.13.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mongodb/mongo-java-driver/releases\"\u003eorg.mongodb:mongodb-driver-sync's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eJava Driver 5.13.0 (September 25, 2026)\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps): bump testing/resources/specifications from \u003ccode\u003e92b3c0b\u003c/code\u003e to \u003ccode\u003e529a2dd\u003c/code\u003e by \u003ca href=\"https://github.com/apmasell\"\u003e\u003ccode\u003e@​apmasell\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2061\"\u003emongodb/mongo-java-driver#2061\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJAVA-6312 Increase testConnectionPoolBackpressure completion time on CI by \u003ca href=\"https://github.com/nhachicha\"\u003e\u003ccode\u003e@​nhachicha\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2062\"\u003emongodb/mongo-java-driver#2062\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJAVA-6235: Configurable DNS domain validation for SRV records by \u003ca href=\"https://github.com/apmasell\"\u003e\u003ccode\u003e@​apmasell\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2054\"\u003emongodb/mongo-java-driver#2054\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJAVA-6235 Add SRV allow hosts option to legacy driver by \u003ca href=\"https://github.com/apmasell\"\u003e\u003ccode\u003e@​apmasell\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2065\"\u003emongodb/mongo-java-driver#2065\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apmasell\"\u003e\u003ccode\u003e@​apmasell\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2061\"\u003emongodb/mongo-java-driver#2061\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/mongodb/mongo-java-driver/compare/r5.12.0...r5.13.0\"\u003ehttps://github.com/mongodb/mongo-java-driver/compare/r5.12.0...r5.13.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVerifying artifact signatures\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://www.mongodb.com/docs/languages/java/mongodb-hibernate/upcoming/security/validate-signatures/\"\u003ehttps://www.mongodb.com/docs/languages/java/mongodb-hibernate/upcoming/security/validate-signatures/\u003c/a\u003e for the full procedure.\u003c/p\u003e\n\u003cp\u003eTo download and import the public key for verifying signatures, execute\u003c/p\u003e\n\u003cpre lang=\"bash\"\u003e\u003ccode\u003egpg --keyserver hkps://keyserver.ubuntu.com --recv-keys 1a75005e142192223d6a7c3b76e0008d166740a8\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/f949913b29b5b94f49d83dadeecd29e61ec0ea56\"\u003e\u003ccode\u003ef949913\u003c/code\u003e\u003c/a\u003e Version: bump 5.13.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/917421419d3bc8123f3933efba869571cdf7bdf4\"\u003e\u003ccode\u003e9174214\u003c/code\u003e\u003c/a\u003e JAVA-6235 Add SRV allow hosts option to legacy driver (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/2065\"\u003e#2065\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/ee2c0ba8250da6642be5806929b44b1efc4472c6\"\u003e\u003ccode\u003eee2c0ba\u003c/code\u003e\u003c/a\u003e JAVA-6235: Configurable DNS domain validation for SRV records (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/2054\"\u003e#2054\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/551f88ba48d98d074834cf032b9fe1dd7b14e973\"\u003e\u003ccode\u003e551f88b\u003c/code\u003e\u003c/a\u003e JAVA-6312 Increase testConnectionPoolBackpressure completion time on CI (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/2062\"\u003e#2062\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/ff74470144f9c5ea98a5ab0881edbbfb1be2ca80\"\u003e\u003ccode\u003eff74470\u003c/code\u003e\u003c/a\u003e build(deps): bump testing/resources/specifications from \u003ccode\u003e92b3c0b\u003c/code\u003e to `529a2dd...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/3e757081a5c40f7527c7c607c1eaa258a245d548\"\u003e\u003ccode\u003e3e75708\u003c/code\u003e\u003c/a\u003e Version: bump 5.13.0-SNAPSHOT\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/mongodb/mongo-java-driver/compare/r5.12.0...r5.13.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.mongodb:mongodb-driver-legacy` from 5.12.0 to 5.13.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mongodb/mongo-java-driver/releases\"\u003eorg.mongodb:mongodb-driver-legacy's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eJava Driver 5.13.0 (September 25, 2026)\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps): bump testing/resources/specifications from \u003ccode\u003e92b3c0b\u003c/code\u003e to \u003ccode\u003e529a2dd\u003c/code\u003e by \u003ca href=\"https://github.com/apmasell\"\u003e\u003ccode\u003e@​apmasell\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2061\"\u003emongodb/mongo-java-driver#2061\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJAVA-6312 Increase testConnectionPoolBackpressure completion time on CI by \u003ca href=\"https://github.com/nhachicha\"\u003e\u003ccode\u003e@​nhachicha\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2062\"\u003emongodb/mongo-java-driver#2062\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJAVA-6235: Configurable DNS domain validation for SRV records by \u003ca href=\"https://github.com/apmasell\"\u003e\u003ccode\u003e@​apmasell\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2054\"\u003emongodb/mongo-java-driver#2054\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJAVA-6235 Add SRV allow hosts option to legacy driver by \u003ca href=\"https://github.com/apmasell\"\u003e\u003ccode\u003e@​apmasell\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2065\"\u003emongodb/mongo-java-driver#2065\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apmasell\"\u003e\u003ccode\u003e@​apmasell\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2061\"\u003emongodb/mongo-java-driver#2061\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/mongodb/mongo-java-driver/compare/r5.12.0...r5.13.0\"\u003ehttps://github.com/mongodb/mongo-java-driver/compare/r5.12.0...r5.13.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVerifying artifact signatures\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://www.mongodb.com/docs/languages/java/mongodb-hibernate/upcoming/security/validate-signatures/\"\u003ehttps://www.mongodb.com/docs/languages/java/mongodb-hibernate/upcoming/security/validate-signatures/\u003c/a\u003e for the full procedure.\u003c/p\u003e\n\u003cp\u003eTo download and import the public key for verifying signatures, execute\u003c/p\u003e\n\u003cpre lang=\"bash\"\u003e\u003ccode\u003egpg --keyserver hkps://keyserver.ubuntu.com --recv-keys 1a75005e142192223d6a7c3b76e0008d166740a8\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/f949913b29b5b94f49d83dadeecd29e61ec0ea56\"\u003e\u003ccode\u003ef949913\u003c/code\u003e\u003c/a\u003e Version: bump 5.13.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/917421419d3bc8123f3933efba869571cdf7bdf4\"\u003e\u003ccode\u003e9174214\u003c/code\u003e\u003c/a\u003e JAVA-6235 Add SRV allow hosts option to legacy driver (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/2065\"\u003e#2065\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/ee2c0ba8250da6642be5806929b44b1efc4472c6\"\u003e\u003ccode\u003eee2c0ba\u003c/code\u003e\u003c/a\u003e JAVA-6235: Configurable DNS domain validation for SRV records (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/2054\"\u003e#2054\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/551f88ba48d98d074834cf032b9fe1dd7b14e973\"\u003e\u003ccode\u003e551f88b\u003c/code\u003e\u003c/a\u003e JAVA-6312 Increase testConnectionPoolBackpressure completion time on CI (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/2062\"\u003e#2062\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/ff74470144f9c5ea98a5ab0881edbbfb1be2ca80\"\u003e\u003ccode\u003eff74470\u003c/code\u003e\u003c/a\u003e build(deps): bump testing/resources/specifications from \u003ccode\u003e92b3c0b\u003c/code\u003e to `529a2dd...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/3e757081a5c40f7527c7c607c1eaa258a245d548\"\u003e\u003ccode\u003e3e75708\u003c/code\u003e\u003c/a\u003e Version: bump 5.13.0-SNAPSHOT\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/mongodb/mongo-java-driver/compare/r5.12.0...r5.13.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.core:jackson-databind` from 2.22.2 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/4385c5f7d51426f66fb24c3777308acc8ae7ea6c\"\u003e\u003ccode\u003e4385c5f\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ccb4fd0158cd20800f6014496dccf7332e5b18ce\"\u003e\u003ccode\u003eccb4fd0\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/2958412f1817a0ad95c34066b7eb85781dd2d4f1\"\u003e\u003ccode\u003e2958412\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1215b94c2f7a8c4ce3863afbc38275a19c682a54\"\u003e\u003ccode\u003e1215b94\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1f0df621449e5de7dd13a1538e0343f65f0e6bb3\"\u003e\u003ccode\u003e1f0df62\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/13a9ff4c4ef982cda23b99fea89d2a4e87af9019\"\u003e\u003ccode\u003e13a9ff4\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/d168f9679ad575cdc2df8d53a8474ec481c7b5a7\"\u003e\u003ccode\u003ed168f96\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/eaf5c76b8e0a538729a1bf922061abf73b13f89b\"\u003e\u003ccode\u003eeaf5c76\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/e05ef4cbb4d534a82948f8ba84350e55493bc72e\"\u003e\u003ccode\u003ee05ef4c\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/f6d4000c1eb6d34e2ae24685a9790b1e833d4bcb\"\u003e\u003ccode\u003ef6d4000\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.22.2...jackson-databind-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.core:jackson-core` from 2.22.2 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/eee4b9e30d62dedf9c84beb6ae6e3c5ebf46920d\"\u003e\u003ccode\u003eeee4b9e\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-core-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/31ee7ebd641d352e96484da4c37b234c8ce29070\"\u003e\u003ccode\u003e31ee7eb\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/9fef13fa0c31abd5ce15e2f25581c560261ade8b\"\u003e\u003ccode\u003e9fef13f\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/9160f4068bb433afa91f51c4808b622b329f6e46\"\u003e\u003ccode\u003e9160f40\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/1169cb6515603220eb50a60b473590eecdef476a\"\u003e\u003ccode\u003e1169cb6\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/b33f4559759023567e808e732ebf9b4dfa3d9027\"\u003e\u003ccode\u003eb33f455\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-core-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/ce8b7dc7ee207fb1481dd8fb535cfbbea6db3bc8\"\u003e\u003ccode\u003ece8b7dc\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/b69555e65e4efcc4c728a70b793c3c232d43f1ea\"\u003e\u003ccode\u003eb69555e\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/53df608d2eca49f7e3817c81fa0a8387835a5ba4\"\u003e\u003ccode\u003e53df608\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/892f7577fe61c6381ba94bb7531f554241221e18\"\u003e\u003ccode\u003e892f757\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-core/compare/jackson-core-2.22.2...jackson-core-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.dataformat:jackson-dataformat-cbor` from 2.22.2 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/e302f7e0b23b077e85c7b7662cb518853528d114\"\u003e\u003ccode\u003ee302f7e\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-dataformats-binary-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/753fb32524c9feb01ddbf620ba4524ed6937217e\"\u003e\u003ccode\u003e753fb32\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/e7fdadb36545da8bbebb72ad39c0c09a860b82b9\"\u003e\u003ccode\u003ee7fdadb\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/e576e509b2309c2fa9bddceeaea482ffeb6c2f80\"\u003e\u003ccode\u003ee576e50\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/b386d544a1b470c3ff0a9651da354dce268f5ea4\"\u003e\u003ccode\u003eb386d54\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/a56180dc0720fcc3616264546fa0a610ababecc2\"\u003e\u003ccode\u003ea56180d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-dataformats-binary-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/6ac61803dbf9d9f39008b72ee1b7240d5194a252\"\u003e\u003ccode\u003e6ac6180\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/a85932fb25cac5fdbdc7ef94faf48aaace713500\"\u003e\u003ccode\u003ea85932f\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/110002c6eaaf832bbc52db7472d15c30e8b4792b\"\u003e\u003ccode\u003e110002c\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/f09bc9efed5f98ee66c8a13c815a9976469a9e65\"\u003e\u003ccode\u003ef09bc9e\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/compare/jackson-dataformats-binary-2.22.2...jackson-dataformats-binary-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.dataformat:jackson-dataformat-xml` from 2.22.2 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/6a183d08ebe1afa9153a496681a94c3aed445fb0\"\u003e\u003ccode\u003e6a183d0\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-dataformat-xml-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/45290b73b29d79799552f191adf6025aad95b4cb\"\u003e\u003ccode\u003e45290b7\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/0e9bd255c027599fc2767c0870ff1258a22f63de\"\u003e\u003ccode\u003e0e9bd25\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/4dc38dfcfe5b907e89b226ed937207f40424f615\"\u003e\u003ccode\u003e4dc38df\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/bac56109caef812ea2e9aa65d9a2e324b4a9b675\"\u003e\u003ccode\u003ebac5610\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/a7cfc97b90512d65117e68f3f09b10a076d9c28a\"\u003e\u003ccode\u003ea7cfc97\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-dataformat-xml-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/bf55a64caf624ce95e4d9538b41406e4a7d8de48\"\u003e\u003ccode\u003ebf55a64\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/d515706a64e0a21ddd461bbfd3e3f146d1d63035\"\u003e\u003ccode\u003ed515706\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/7a536e56717eb35f5bb54dd6cadddd78f2977559\"\u003e\u003ccode\u003e7a536e5\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/79037dda707dfed0b1429ab822341947f48b2b4b\"\u003e\u003ccode\u003e79037dd\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/compare/jackson-dataformat-xml-2.22.2...jackson-dataformat-xml-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.datatype:jackson-datatype-jsr310` from 2.22.2 to 2.22.3\n\nUpdates `com.fasterxml.jackson.dataformat:jackson-dataformat-smile` from 2.22.2 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/e302f7e0b23b077e85c7b7662cb518853528d114\"\u003e\u003ccode\u003ee302f7e\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-dataformats-binary-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/753fb32524c9feb01ddbf620ba4524ed6937217e\"\u003e\u003ccode\u003e753fb32\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/e7fdadb36545da8bbebb72ad39c0c09a860b82b9\"\u003e\u003ccode\u003ee7fdadb\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/e576e509b2309c2fa9bddceeaea482ffeb6c2f80\"\u003e\u003ccode\u003ee576e50\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/b386d544a1b470c3ff0a9651da354dce268f5ea4\"\u003e\u003ccode\u003eb386d54\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/a56180dc0720fcc3616264546fa0a610ababecc2\"\u003e\u003ccode\u003ea56180d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-dataformats-binary-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/6ac61803dbf9d9f39008b72ee1b7240d5194a252\"\u003e\u003ccode\u003e6ac6180\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/a85932fb25cac5fdbdc7ef94faf48aaace713500\"\u003e\u003ccode\u003ea85932f\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/110002c6eaaf832bbc52db7472d15c30e8b4792b\"\u003e\u003ccode\u003e110002c\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/f09bc9efed5f98ee66c8a13c815a9976469a9e65\"\u003e\u003ccode\u003ef09bc9e\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/compare/jackson-dataformats-binary-2.22.2...jackson-dataformats-binary-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.dataformat:jackson-dataformat-yaml` from 2.22.2 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-text/commit/e793b5fcca4a976d4179fb1b8a7d34ab0236556f\"\u003e\u003ccode\u003ee793b5f\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-dataformats-text-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-text/commit/e8e9ece5e8bc28337aaa6206f43a54024a4a08d1\"\u003e\u003ccode\u003ee8e9ece\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-text/commit/2ea3d0c8e1c3e8540d0860c791b6de37ff55523a\"\u003e\u003ccode\u003e2ea3d0c\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-text/commit/8e88b8564a51986d37f0f97bfbe18192b4525ea8\"\u003e\u003ccode\u003e8e88b85\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-text/commit/806abc907d38104274bf1a18f5be9dfb5327a4c5\"\u003e\u003ccode\u003e806abc9\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-text/commit/a11273cb00535298b79c2878d009f6c1b93ba502\"\u003e\u003ccode\u003ea11273c\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-dataformats-text-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-text/commit/5d16624914c08ee4fa76dad6a1f496c6f67a989d\"\u003e\u003ccode\u003e5d16624\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-text/commit/f047dd5e84cbeb4aa42b956947d1282a838b09c5\"\u003e\u003ccode\u003ef047dd5\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-text/commit/0f801646596d391f21f0a7e90a720b32c0db5676\"\u003e\u003ccode\u003e0f80164\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-text/commit/4dcc3dab188c6e5af20cd7e45c98a1d5a1d7c136\"\u003e\u003ccode\u003e4dcc3da\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-dataformats-text/compare/jackson-dataformats-text-2.22.2...jackson-dataformats-text-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tools.jackson.core:jackson-databind` from 3.2.2 to 3.2.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/4179a66668017f3dcd7f7f3f22dbc48f0bf88ae5\"\u003e\u003ccode\u003e4179a66\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-3.2.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/37c8a723a0540dbb642bd8f05b21ecba23e3894e\"\u003e\u003ccode\u003e37c8a72\u003c/code\u003e\u003c/a\u003e Prep for 3.2.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/5fa7881c637ac59f09d6c2b7c4d85b8661633b6c\"\u003e\u003ccode\u003e5fa7881\u003c/code\u003e\u003c/a\u003e Merge branch '3.1' into 3.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/c9f17a2e0d4efc6cf7757b663bc845a602104410\"\u003e\u003ccode\u003ec9f17a2\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1ea1c401fe64829affcd330221189aa1f766b0bf\"\u003e\u003ccode\u003e1ea1c40\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/2968e8f656f4b5f3eed7b55118293ee2284eecd0\"\u003e\u003ccode\u003e2968e8f\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/d61810b4817cbeca22c6a2118dfcfaa863210da9\"\u003e\u003ccode\u003ed61810b\u003c/code\u003e\u003c/a\u003e Prep for 3.1.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/e065a090dbb81a84acc7b479609e79887e397b3a\"\u003e\u003ccode\u003ee065a09\u003c/code\u003e\u003c/a\u003e Merge branch '2.x' into 3.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/fd189a7c73fdf563bc6b2f9bff190822a494a2f4\"\u003e\u003ccode\u003efd189a7\u003c/code\u003e\u003c/a\u003e Merge branch '2.22' into 2.x\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/211faf7c27ac57bcbbd7ec757f15cd3c64de6e9f\"\u003e\u003ccode\u003e211faf7\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-3.2.2...jackson-databind-3.2.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.core:jackson-core` from 2.22.2 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/eee4b9e30d62dedf9c84beb6ae6e3c5ebf46920d\"\u003e\u003ccode\u003eeee4b9e\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-core-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/31ee7ebd641d352e96484da4c37b234c8ce29070\"\u003e\u003ccode\u003e31ee7eb\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/9fef13fa0c31abd5ce15e2f25581c560261ade8b\"\u003e\u003ccode\u003e9fef13f\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/9160f4068bb433afa91f51c4808b622b329f6e46\"\u003e\u003ccode\u003e9160f40\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/1169cb6515603220eb50a60b473590eecdef476a\"\u003e\u003ccode\u003e1169cb6\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/b33f4559759023567e808e732ebf9b4dfa3d9027\"\u003e\u003ccode\u003eb33f455\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-core-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/ce8b7dc7ee207fb1481dd8fb535cfbbea6db3bc8\"\u003e\u003ccode\u003ece8b7dc\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/b69555e65e4efcc4c728a70b793c3c232d43f1ea\"\u003e\u003ccode\u003eb69555e\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/53df608d2eca49f7e3817c81fa0a8387835a5ba4\"\u003e\u003ccode\u003e53df608\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/892f7577fe61c6381ba94bb7531f554241221e18\"\u003e\u003ccode\u003e892f757\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-core/compare/jackson-core-2.22.2...jackson-core-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.dataformat:jackson-dataformat-cbor` from 2.22.2 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/e302f7e0b23b077e85c7b7662cb518853528d114\"\u003e\u003ccode\u003ee302f7e\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-dataformats-binary-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/753fb32524c9feb01ddbf620ba4524ed6937217e\"\u003e\u003ccode\u003e753fb32\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/e7fdadb36545da8bbebb72ad39c0c09a860b82b9\"\u003e\u003ccode\u003ee7fdadb\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/e576e509b2309c2fa9bddceeaea482ffeb6c2f80\"\u003e\u003ccode\u003ee576e50\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/b386d544a1b470c3ff0a9651da354dce268f5ea4\"\u003e\u003ccode\u003eb386d54\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/a56180dc0720fcc3616264546fa0a610ababecc2\"\u003e\u003ccode\u003ea56180d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-dataformats-binary-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/6ac61803dbf9d9f39008b72ee1b7240d5194a252\"\u003e\u003ccode\u003e6ac6180\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/a85932fb25cac5fdbdc7ef94faf48aaace713500\"\u003e\u003ccode\u003ea85932f\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/110002c6eaaf832bbc52db7472d15c30e8b4792b\"\u003e\u003ccode\u003e110002c\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/f09bc9efed5f98ee66c8a13c815a9976469a9e65\"\u003e\u003ccode\u003ef09bc9e\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/compare/jackson-dataformats-binary-2.22.2...jackson-dataformats-binary-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.dataformat:jackson-dataformat-xml` from 2.22.2 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/6a183d08ebe1afa9153a496681a94c3aed445fb0\"\u003e\u003ccode\u003e6a183d0\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-dataformat-xml-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/45290b73b29d79799552f191adf6025aad95b4cb\"\u003e\u003ccode\u003e45290b7\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/0e9bd255c027599fc2767c0870ff1258a22f63de\"\u003e\u003ccode\u003e0e9bd25\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/4dc38dfcfe5b907e89b226ed937207f40424f615\"\u003e\u003ccode\u003e4dc38df\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/bac56109caef812ea2e9aa65d9a2e324b4a9b675\"\u003e\u003ccode\u003ebac5610\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/a7cfc97b90512d65117e68f3f09b10a076d9c28a\"\u003e\u003ccode\u003ea7cfc97\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-dataformat-xml-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/bf55a64caf624ce95e4d9538b41406e4a7d8de48\"\u003e\u003ccode\u003ebf55a64\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/d515706a64e0a21ddd461bbfd3e3f146d1d63035\"\u003e\u003ccode\u003ed515706\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/7a536e56717eb35f5bb54dd6cadddd78f2977559\"\u003e\u003ccode\u003e7a536e5\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/79037dda707dfed0b1429ab822341947f48b2b4b\"\u003e\u003ccode\u003e79037dd\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/compare/jackson-dataformat-xml-2.22.2...jackson-dataformat-xml-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.groovy:groovy` from 5.1.3 to 6.0.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/apache/groovy/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.groovy:groovy-sql` from 5.1.3 to 6.0.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/apache/groovy/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.groovy:groovy-all` from 5.1.3 to 6.0.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/apache/groovy/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.groovy:groovy-sql` from 5.1.3 to 6.0.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/apache/groovy/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.github.ben-manes.caffeine:caffeine` from 3.2.4 to 3.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ben-manes/caffeine/releases\"\u003ecom.github.ben-manes.caffeine:caffeine's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved read performance by avoiding false sharing in the fast-path check\u003c/li\u003e\n\u003cli\u003eImproved \u003ca href=\"https://ben-manes.github.io/caffeine/wiki/adaptive-window.html\"\u003eadaptive climber\u003c/a\u003e for small caches and shifting workloads\u003c/li\u003e\n\u003cli\u003eFixed various minor issues found using AI audits\u003c/li\u003e\n\u003cli\u003eFixed over-aggressive refresh discard (\u003ca href=\"https://redirect.github.com/ben-manes/caffeine/issues/1970\"\u003e#1970\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ben-manes/caffeine/commit/af860110a4b1e158d30ef0ccdd78a1600bdbde0d\"\u003e\u003ccode\u003eaf86011\u003c/code\u003e\u003c/a\u003e fix jcache audit triage\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ben-manes/caffeine/commit/f063e56a0edb0369b29fc37a9c283cd317f303f2\"\u003e\u003ccode\u003ef063e56\u003c/code\u003e\u003c/a\u003e Prevent overflow in snapshot durations\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ben-manes/caffeine/commit/5b6fbd94f0e0d5727b0ffba52ba0365f5e793eb5\"\u003e\u003ccode\u003e5b6fbd9\u003c/code\u003e\u003c/a\u003e Saturate the audit stillness counter\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ben-manes/caffeine/commit/48cb4083684d6decb4841e9502f419d08128f6dc\"\u003e\u003ccode\u003e48cb408\u003c/code\u003e\u003c/a\u003e Read lazy cache views and policies once\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ben-manes/caffeine/commit/4978d1835234114a0a8568b1000be5a4de6360b7\"\u003e\u003ccode\u003e4978d18\u003c/code\u003e\u003c/a\u003e Normalize JCache processor loader failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ben-manes/caffeine/commit/c9038d8fa3084bfc45ac9f5d222dfe2de7ba548a\"\u003e\u003ccode\u003ec9038d8\u003c/code\u003e\u003c/a\u003e Consume JCache iterator removals before listener failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ben-manes/caffeine/commit/0b0afd2470294cae0b2a66b914e65c7733941ed6\"\u003e\u003ccode\u003e0b0afd2\u003c/code\u003e\u003c/a\u003e polish\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ben-manes/caffeine/commit/c0edd00bb6063e59ee1e7a7db5588fac7a6524f5\"\u003e\u003ccode\u003ec0edd00\u003c/code\u003e\u003c/a\u003e restore coverage lost to recent fixes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ben-manes/caffeine/commit/5283c96dce60552f898af471b00a3cf54b69fa3e\"\u003e\u003ccode\u003e5283c96\u003c/code\u003e\u003c/a\u003e make CLOCK-Pro's cold hand a setting\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ben-manes/caffeine/commit/d15c2052ecbf51c15981a3e4f61f8885d093ad0a\"\u003e\u003ccode\u003ed15c205\u003c/code\u003e\u003c/a\u003e make the bulk cache loaders serializable\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ben-manes/caffeine/compare/v3.2.4...v3.3.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.mockito:mockito-core` from 5.23.0 to 5.24.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mockito/mockito/releases\"\u003eorg.mockito:mockito-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.24.0\u003c/h2\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003cem\u003eChangelog generated by \u003ca href=\"https://github.com/shipkit/shipkit-changelog\"\u003eShipkit Changelog Gradle Plugin\u003c/a\u003e\u003c/em\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch4\u003e5.24.0\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e2026-09-23 - \u003ca href=\"https://github.com/mockito/mockito/compare/v5.23.0...v5.24.0\"\u003e27 commit(s)\u003c/a\u003e by Andrei Solntsev, DragonFSKY, Hünkar Can Tunç, Joshua Selbo, M. Minot, Markus Gaisbauer, Mirko Alicastro, Vinod Kumar M ( codingkiddo ), dependabot[bot]\u003c/li\u003e\n\u003cli\u003eFix Mockito docs for -javaagent flag with Gradle [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3866\"\u003e#3866\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3866\"\u003emockito/mockito#3866\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eKotlin example for adding Mockito as an agent is incorrect [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3864\"\u003e#3864\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3864\"\u003emockito/mockito#3864\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump graalvm/setup-graalvm from 1.6.3 to 1.6.6 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3862\"\u003e#3862\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3862\"\u003emockito/mockito#3862\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump gradle/actions from 6.2.0 to 6.3.0 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3852\"\u003e#3852\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3852\"\u003emockito/mockito#3852\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump gradle/actions from 5 to 6.2.0 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3851\"\u003e#3851\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3851\"\u003emockito/mockito#3851\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve method parameters when clearing inline mocks [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3847\"\u003e#3847\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3847\"\u003emockito/mockito#3847\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump graalvm/setup-graalvm from 1.6.0 to 1.6.3 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3845\"\u003e#3845\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3845\"\u003emockito/mockito#3845\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrint object fields via reflection when \u003ccode\u003etoString()\u003c/code\u003e is not implemented [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3844\"\u003e#3844\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3844\"\u003emockito/mockito#3844\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMigrate extensions-tests to JUnit Jupiter [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3840\"\u003e#3840\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3840\"\u003emockito/mockito#3840\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump graalvm/setup-graalvm from 1.5.6 to 1.6.0 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3839\"\u003e#3839\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3839\"\u003emockito/mockito#3839\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edocs(when-verify): fixes to explanations about redundancy [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3838\"\u003e#3838\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3838\"\u003emockito/mockito#3838\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eConfusing inconsistency in example method calls in “stubbing and verifying is redundant” note of “when” and “verify” Javadoc [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3837\"\u003e#3837\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3837\"\u003emockito/mockito#3837\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump actions/checkout from 6 to 7 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3836\"\u003e#3836\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3836\"\u003emockito/mockito#3836\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixes \u003ca href=\"https://redirect.github.com/mockito/mockito/issues/2740\"\u003e#2740\u003c/a\u003e : Add mockMaker option to \u003ccode\u003e@Spy\u003c/code\u003e annotation [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3835\"\u003e#3835\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3835\"\u003emockito/mockito#3835\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump graalvm/setup-graalvm from 1.5.5 to 1.5.6 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3834\"\u003e#3834\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3834\"\u003emockito/mockito#3834\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump graalvm/setup-graalvm from 1.5.4 to 1.5.5 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3833\"\u003e#3833\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3833\"\u003emockito/mockito#3833\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump codecov/codecov-action from 6 to 7 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3831\"\u003e#3831\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3831\"\u003emockito/mockito#3831\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump graalvm/setup-graalvm from 1.4.5 to 1.5.4 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3830\"\u003e#3830\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3830\"\u003emockito/mockito#3830\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix clearInlineMocks not de-registering singleton mocks [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3829\"\u003e#3829\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3829\"\u003emockito/mockito#3829\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix NotAMockException when using mockSingleton with MockitoJUnit [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3827\"\u003e#3827\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3827\"\u003emockito/mockito#3827\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNotAMockException when using mockSingleton with MockitoSession or MockitoJUnit [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3826\"\u003e#3826\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3826\"\u003emockito/mockito#3826\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eImprove Gradle agent docs for configuration cache [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3823\"\u003e#3823\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3823\"\u003emockito/mockito#3823\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eGradle documentation for setting up instrumentation with Gradle configuration cache [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3822\"\u003e#3822\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3822\"\u003emockito/mockito#3822\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixes \u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3818\"\u003e#3818\u003c/a\u003e : Fix data race in InvocationContainerImpl.invocationForStubbing [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3819\"\u003e#3819\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3819\"\u003emockito/mockito#3819\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eData race on invocationForPotentialStubbing [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3818\"\u003e#3818\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3818\"\u003emockito/mockito#3818\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixes \u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3814\"\u003e#3814\u003c/a\u003e : implement package-level clinit suppression [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3815\"\u003e#3815\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3815\"\u003emockito/mockito#3815\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePackage-level clinit suppression [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3814\"\u003e#3814\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3814\"\u003emockito/mockito#3814\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUpgrade Android Gradle Plugin to 8.13.2 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3812\"\u003e#3812\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3812\"\u003emockito/mockito#3812\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReplaces raw generic types with type parameters [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3806\"\u003e#3806\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3806\"\u003emockito/mockito#3806\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixes \u003ca href=\"https://redirect.github.com/mockito/mockito/issues/2398\"\u003e#2398\u003c/a\u003e : Implement global suppress static initialization leveraging java agent [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3801\"\u003e#3801\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3801\"\u003emockito/mockito#3801\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump codecov/codecov-action from 5 to 6 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3800\"\u003e#3800\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3800\"\u003emockito/mockito#3800\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix non-deterministic AssertionError when using MockMakers.SUBCLASS (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3406\"\u003e#3406\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/mockito/mockito/issues/2823\"\u003e#2823\u003c/a\u003e) [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3795\"\u003e#3795\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3795\"\u003emockito/mockito#3795\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixes \u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3536\"\u003e#3536\u003c/a\u003e : Implement SpyStatic API [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3794\"\u003e#3794\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3794\"\u003emockito/mockito#3794\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eThe class's MethodParameters are removed after clearAllCaches is invoked [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3763\"\u003e#3763\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3763\"\u003emockito/mockito#3763\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[FeatureRequest / Idea] Create Mockito.spyStatic [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3536\"\u003e#3536\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3536\"\u003emockito/mockito#3536\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd option to specify mockmaker for \u003ccode\u003e@Spy\u003c/code\u003e [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/2740\"\u003e#2740\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/2740\"\u003emockito/mockito#2740\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHow can I suppress static initializer? [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/2398\"\u003e#2398\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/2398\"\u003emockito/mockito#2398\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/5a2f0f81cdafc9b34ddb4520db7f8866c787dac0\"\u003e\u003ccode\u003e5a2f0f8\u003c/code\u003e\u003c/a\u003e Fix Mockito docs for -javaagent flag with Gradle (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3866\"\u003e#3866\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/9c5f36fb9f2ad89fbaab828d33d144cd398a4079\"\u003e\u003ccode\u003e9c5f36f\u003c/code\u003e\u003c/a\u003e Bump graalvm/setup-graalvm from 1.6.3 to 1.6.6 (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3862\"\u003e#3862\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/e7fd06dda31daf0c71ad1dedc76ffc9f8ecf6973\"\u003e\u003ccode\u003ee7fd06d\u003c/code\u003e\u003c/a\u003e Preserve method parameters when clearing inline mocks (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3847\"\u003e#3847\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/5a676bcd9ef9a10db46e1dc34e190eb46faa2687\"\u003e\u003ccode\u003e5a676bc\u003c/code\u003e\u003c/a\u003e Bump gradle/actions from 6.2.0 to 6.3.0 (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3852\"\u003e#3852\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/508f8e78f5ac5ed9f23f7b92b01de76752120a67\"\u003e\u003ccode\u003e508f8e7\u003c/code\u003e\u003c/a\u003e Bump gradle/actions from 5 to 6.2.0 (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3851\"\u003e#3851\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/ee8a330da0218f32d5964acdeaa3ac39e2c6ce14\"\u003e\u003ccode\u003eee8a330\u003c/code\u003e\u003c/a\u003e Print object fields via reflection when \u003ccode\u003etoString()\u003c/code\u003e is not implemented (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3844\"\u003e#3844\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/39b1aba6e6cc92d8ad3c812dcc16ed357c9fbc85\"\u003e\u003ccode\u003e39b1aba\u003c/code\u003e\u003c/a\u003e Bump graalvm/setup-graalvm from 1.6.0 to 1.6.3 (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3845\"\u003e#3845\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/d8638e1a8b67b4acea63c80dc85d62eda4ef57f5\"\u003e\u003ccode\u003ed8638e1\u003c/code\u003e\u003c/a\u003e Migrate extensions-tests to JUnit Jupiter (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3840\"\u003e#3840\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/0aab922fa4c8967e50613671f58c707a69606c62\"\u003e\u003ccode\u003e0aab922\u003c/code\u003e\u003c/a\u003e Bump graalvm/setup-graalvm from 1.5.6 to 1.6.0 (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3839\"\u003e#3839\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/f3cf74c7e1106f7d32299001ca0ecf2c492c468c\"\u003e\u003ccode\u003ef3cf74c\u003c/code\u003e\u003c/a\u003e docs(when-verify): fixes to explanations about redundancy (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3838\"\u003e#3838\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mockito/mockito/compare/v5.23.0...v5.24.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.hibernate.validator:hibernate-validator` from 9.1.3.Final to 9.1.4.Final\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hibernate/hibernate-validator/releases\"\u003eorg.hibernate.validator:hibernate-validator's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 9.1.4.Final\u003c/h2\u003e\n\u003ch1\u003eHibernate Validator 9.1.4.Final released\u003c/h1\u003e\n\u003cp\u003eWe are pleased to announce the release of Hibernate Validator 9.1: 9.1.4.Final.\u003c/p\u003e\n\u003cp\u003eYou can find the full list of 9.1.4.Final changes \u003ca href=\"https://hibernate.atlassian.net/issues/?jql=project%20%3D%20HV%20AND%20fixVersion%20%3D%209.1.4.Final\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eWhat's new\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSee the \u003ca href=\"https://hibernate.org/validator/releases/9.1\"\u003ewebsite\u003c/a\u003e for requirements and compatibilities.\u003c/li\u003e\n\u003cli\u003eSee the \u003ca href=\"https://docs.hibernate.org/validator/9.1/whats-new/en-US/html_single/\"\u003eWhat's New\u003c/a\u003e guide for details about new features and capabilities.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eConclusion\u003c/h2\u003e\n\u003cp\u003eFor additional details, see:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe \u003ca href=\"https://hibernate.org/validator/releases/9.1/\"\u003erelease page\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/validator/9.1/migration-guide/\"\u003eMigration Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/validator/9.1/reference/en-US/html_single/#validator-gettingstarted\"\u003eGetting started\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/validator/9.1/reference/en-US/html_single/\"\u003eReference Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/validator/9.1/api\"\u003eAPI docs\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eVisit the \u003ca href=\"https://hibernate.org/community/\"\u003ewebsite\u003c/a\u003e for details on getting in touch with us.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hibernate/hibernate-validator/blob/9.1.4.Final/changelog.md\"\u003eorg.hibernate.validator:hibernate-validator's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e9.1.4.Final (2026-09-20)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://hibernate.atlassian.net/projects/HV/versions/40268\"\u003eFull changelog\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eBug\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://hibernate.atlassian.net/browse/HV-2253\"\u003eHV-2253\u003c/a\u003e - ClassNotFoundException thrown when an EL implementation and OSGi are not on the class path\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eImprovement\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://hibernate.atlassian.net/browse/HV-2243\"\u003eHV-2243\u003c/a\u003e - Bump joda-time to 2.14.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://hibernate.atlassian.net/browse/HV-2242\"\u003eHV-2242\u003c/a\u003e - Update to OpenJFX to 17.0.20\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eTask\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://hibernate.atlassian.net/browse/HV-2244\"\u003eHV-2244\u003c/a\u003e - Tune the content of javadoc jars to reduce the size of files published to Maven Central\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/5504b0c343888d2d179e502e9d78cccf6a6d1830\"\u003e\u003ccode\u003e5504b0c\u003c/code\u003e\u003c/a\u003e [Jenkins release job] Preparing release 9.1.4.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/1306aab453b1658f2fefc2f6f994cfe71b7ba94a\"\u003e\u003ccode\u003e1306aab\u003c/code\u003e\u003c/a\u003e [Jenkins release job] changelog.md updated by release build 9.1.4.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/715cbdbbf7429d1cf4499a45e0fe32011d7d32c1\"\u003e\u003ccode\u003e715cbdb\u003c/code\u003e\u003c/a\u003e [Jenkins release job] README.md updated by release build 9.1.4.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/84e8d2eff9576c437c404b31a85804b7dbee7c2d\"\u003e\u003ccode\u003e84e8d2e\u003c/code\u003e\u003c/a\u003e HV-2253 When determining the Jakarta Expression Language implementation, igno...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/f3002a3c0e1ae8abf3b849bb6d677e9497225f96\"\u003e\u003ccode\u003ef3002a3\u003c/code\u003e\u003c/a\u003e [9.1] Bump org.codehaus.mojo:build-helper-maven-plugin\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/971d85b8b293b68d86f18899dbf736b4a8402eab\"\u003e\u003ccode\u003e971d85b\u003c/code\u003e\u003c/a\u003e [9.1] Bump the build-dependencies group with 3 updates\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/dcb1305b8a4a28dc942985f87500a6a6dc3ed3ee\"\u003e\u003ccode\u003edcb1305\u003c/code\u003e\u003c/a\u003e Tune the content of javadoc jars to reduce the size of files published to Mav...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/d01ed37bd4a2cdc129560488b167c74f80192855\"\u003e\u003ccode\u003ed01ed37\u003c/code\u003e\u003c/a\u003e [9.1] Bump version.org.apache.groovy from 5.0.7 to 5.0.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/6023258142c95208b22affcccf37506a4443cb5d\"\u003e\u003ccode\u003e6023258\u003c/code\u003e\u003c/a\u003e Bump joda-time to 2.14.3 HV-2243\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/3db152e2bc5b007a1162a8911523880517cf3940\"\u003e\u003ccode\u003e3db152e\u003c/code\u003e\u003c/a\u003e Update to OpenJFX to 17.0.20 HV-2242\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hibernate/hibernate-validator/compare/9.1.3.Final...9.1.4.Final\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n...\n\n_Description has been truncated_","html_url":"https://github.com/craftersoftware/craftercms/pull/9081","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/craftersoftware%2Fcraftercms/issues/9081","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/9081/packages"},{"uuid":"5625080335","node_id":"PR_kwDON2_zC88AAAABFoDxWg","number":561,"state":"open","title":"Bump com.fasterxml.jackson.core:jackson-databind from 2.18.6 to 2.18.10 in /samples/client/petstore/java/webclient","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":11,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-29T04:24:53.000Z","updated_at":"2026-09-29T04:25:55.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.18.6","new_version":"2.18.10","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":"/samples/client/petstore/java/webclient","ecosystem":"maven"},"body":"Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.18.6 to 2.18.10.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/176df1d48b256ced412c65293ad4e09393e24bd3\"\u003e\u003ccode\u003e176df1d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.18.10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7785f5f9ed24127e004115472c47b26ea4cf2774\"\u003e\u003ccode\u003e7785f5f\u003c/code\u003e\u003c/a\u003e Prep for 2.18.10 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0ccf3241c72d324df711f092ab4fa8f5635272cf\"\u003e\u003ccode\u003e0ccf324\u003c/code\u003e\u003c/a\u003e Backport \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6165\"\u003e#6165\u003c/a\u003e to 2.18: apply number length limits to BigDecimal/BigInteger/D...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bb18488020df1228580be5024ae8c6e9f06d9226\"\u003e\u003ccode\u003ebb18488\u003c/code\u003e\u003c/a\u003e Fix CREDITS class name wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1b1bb192a8560a3139287ce69295e10c1c5c81b2\"\u003e\u003ccode\u003e1b1bb19\u003c/code\u003e\u003c/a\u003e Fix release notes wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f\"\u003e\u003ccode\u003eeb3b7fc\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003ejava.lang.Comparable\u003c/code\u003e as an \u0026quot;unsafe\u0026quot; polymorphic base type (\u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6155\"\u003e#6155\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/65947556b62ee935a85aa5edaebf409813fd2456\"\u003e\u003ccode\u003e6594755\u003c/code\u003e\u003c/a\u003e One more minor tweak wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ba6fa2529df26d10fb57c44e1133ee786ebb82b9\"\u003e\u003ccode\u003eba6fa25\u003c/code\u003e\u003c/a\u003e Refactoring wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e part 2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/858a03b01028bc0131a0cb001473f215c2fe057d\"\u003e\u003ccode\u003e858a03b\u003c/code\u003e\u003c/a\u003e Refactoring wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/8de6a61f5d659249a41f85753a970992f46bbf98\"\u003e\u003ccode\u003e8de6a61\u003c/code\u003e\u003c/a\u003e Remove GHSA ids from CREDITS entries for \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6129\"\u003e#6129\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.18.6...jackson-databind-2.18.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.18.6\u0026new-version=2.18.10)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Dustin4444/openapi-generator/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/Dustin4444/openapi-generator/pull/561","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Dustin4444%2Fopenapi-generator/issues/561","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/561/packages"},{"uuid":"5625075397","node_id":"PR_kwDOFkL42M8AAAABFoDhcw","number":251,"state":"open","title":"Bump com.fasterxml.jackson.core:jackson-databind from 2.18.9 to 2.18.10","user":"dependabot[bot]","labels":["dependencies","patch","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-29T04:24:15.000Z","updated_at":"2026-09-29T04:27:24.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.18.9","new_version":"2.18.10","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":null,"ecosystem":"maven"},"body":"Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.18.9 to 2.18.10.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/176df1d48b256ced412c65293ad4e09393e24bd3\"\u003e\u003ccode\u003e176df1d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.18.10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7785f5f9ed24127e004115472c47b26ea4cf2774\"\u003e\u003ccode\u003e7785f5f\u003c/code\u003e\u003c/a\u003e Prep for 2.18.10 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0ccf3241c72d324df711f092ab4fa8f5635272cf\"\u003e\u003ccode\u003e0ccf324\u003c/code\u003e\u003c/a\u003e Backport \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6165\"\u003e#6165\u003c/a\u003e to 2.18: apply number length limits to BigDecimal/BigInteger/D...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bb18488020df1228580be5024ae8c6e9f06d9226\"\u003e\u003ccode\u003ebb18488\u003c/code\u003e\u003c/a\u003e Fix CREDITS class name wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1b1bb192a8560a3139287ce69295e10c1c5c81b2\"\u003e\u003ccode\u003e1b1bb19\u003c/code\u003e\u003c/a\u003e Fix release notes wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f\"\u003e\u003ccode\u003eeb3b7fc\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003ejava.lang.Comparable\u003c/code\u003e as an \u0026quot;unsafe\u0026quot; polymorphic base type (\u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6155\"\u003e#6155\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/65947556b62ee935a85aa5edaebf409813fd2456\"\u003e\u003ccode\u003e6594755\u003c/code\u003e\u003c/a\u003e One more minor tweak wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ba6fa2529df26d10fb57c44e1133ee786ebb82b9\"\u003e\u003ccode\u003eba6fa25\u003c/code\u003e\u003c/a\u003e Refactoring wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e part 2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/858a03b01028bc0131a0cb001473f215c2fe057d\"\u003e\u003ccode\u003e858a03b\u003c/code\u003e\u003c/a\u003e Refactoring wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/8de6a61f5d659249a41f85753a970992f46bbf98\"\u003e\u003ccode\u003e8de6a61\u003c/code\u003e\u003c/a\u003e Remove GHSA ids from CREDITS entries for \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6129\"\u003e#6129\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.18.9...jackson-databind-2.18.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.18.9\u0026new-version=2.18.10)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/ONSdigital/ssdc-rm-ddl/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/ONSdigital/ssdc-rm-ddl/pull/251","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/ONSdigital%2Fssdc-rm-ddl/issues/251","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/251/packages"},{"uuid":"5624922250","node_id":"PR_kwDOC2Uyf88AAAABFn7wsg","number":15,"state":"open","title":"Bump com.fasterxml.jackson.core:jackson-databind from 2.18.9 to 2.18.10","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-29T04:05:21.000Z","updated_at":"2026-09-29T04:05:29.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.18.9","new_version":"2.18.10","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":null,"ecosystem":"maven"},"body":"Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.18.9 to 2.18.10.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/176df1d48b256ced412c65293ad4e09393e24bd3\"\u003e\u003ccode\u003e176df1d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.18.10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7785f5f9ed24127e004115472c47b26ea4cf2774\"\u003e\u003ccode\u003e7785f5f\u003c/code\u003e\u003c/a\u003e Prep for 2.18.10 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0ccf3241c72d324df711f092ab4fa8f5635272cf\"\u003e\u003ccode\u003e0ccf324\u003c/code\u003e\u003c/a\u003e Backport \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6165\"\u003e#6165\u003c/a\u003e to 2.18: apply number length limits to BigDecimal/BigInteger/D...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bb18488020df1228580be5024ae8c6e9f06d9226\"\u003e\u003ccode\u003ebb18488\u003c/code\u003e\u003c/a\u003e Fix CREDITS class name wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1b1bb192a8560a3139287ce69295e10c1c5c81b2\"\u003e\u003ccode\u003e1b1bb19\u003c/code\u003e\u003c/a\u003e Fix release notes wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f\"\u003e\u003ccode\u003eeb3b7fc\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003ejava.lang.Comparable\u003c/code\u003e as an \u0026quot;unsafe\u0026quot; polymorphic base type (\u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6155\"\u003e#6155\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/65947556b62ee935a85aa5edaebf409813fd2456\"\u003e\u003ccode\u003e6594755\u003c/code\u003e\u003c/a\u003e One more minor tweak wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ba6fa2529df26d10fb57c44e1133ee786ebb82b9\"\u003e\u003ccode\u003eba6fa25\u003c/code\u003e\u003c/a\u003e Refactoring wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e part 2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/858a03b01028bc0131a0cb001473f215c2fe057d\"\u003e\u003ccode\u003e858a03b\u003c/code\u003e\u003c/a\u003e Refactoring wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/8de6a61f5d659249a41f85753a970992f46bbf98\"\u003e\u003ccode\u003e8de6a61\u003c/code\u003e\u003c/a\u003e Remove GHSA ids from CREDITS entries for \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6129\"\u003e#6129\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.18.9...jackson-databind-2.18.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.18.9\u0026new-version=2.18.10)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/PRIDE-Archive/archive-integration/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/PRIDE-Archive/archive-integration/pull/15","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/PRIDE-Archive%2Farchive-integration/issues/15","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/15/packages"},{"uuid":"5624455927","node_id":"PR_kwDOCfzDTM8AAAABFnkCXw","number":4202,"state":"open","title":"[4.3] Bump com.fasterxml.jackson.core:jackson-databind from 2.22.2 to 2.22.3 in the testcontainers group","user":"dependabot[bot]","labels":["dependencies","java","4.3"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-29T03:08:12.000Z","updated_at":"2026-09-29T04:34:59.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"[4.3] Bump","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":"the testcontainers group","ecosystem":"maven"},"body":"Bumps the testcontainers group with 1 update: [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind).\n\nUpdates `com.fasterxml.jackson.core:jackson-databind` from 2.22.2 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/4385c5f7d51426f66fb24c3777308acc8ae7ea6c\"\u003e\u003ccode\u003e4385c5f\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ccb4fd0158cd20800f6014496dccf7332e5b18ce\"\u003e\u003ccode\u003eccb4fd0\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/2958412f1817a0ad95c34066b7eb85781dd2d4f1\"\u003e\u003ccode\u003e2958412\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1215b94c2f7a8c4ce3863afbc38275a19c682a54\"\u003e\u003ccode\u003e1215b94\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1f0df621449e5de7dd13a1538e0343f65f0e6bb3\"\u003e\u003ccode\u003e1f0df62\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/13a9ff4c4ef982cda23b99fea89d2a4e87af9019\"\u003e\u003ccode\u003e13a9ff4\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/d168f9679ad575cdc2df8d53a8474ec481c7b5a7\"\u003e\u003ccode\u003ed168f96\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/eaf5c76b8e0a538729a1bf922061abf73b13f89b\"\u003e\u003ccode\u003eeaf5c76\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/e05ef4cbb4d534a82948f8ba84350e55493bc72e\"\u003e\u003ccode\u003ee05ef4c\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/f6d4000c1eb6d34e2ae24685a9790b1e833d4bcb\"\u003e\u003ccode\u003ef6d4000\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.22.2...jackson-databind-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=gradle\u0026previous-version=2.22.2\u0026new-version=2.22.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/hibernate/hibernate-reactive/pull/4202","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/hibernate%2Fhibernate-reactive/issues/4202","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/4202/packages"},{"uuid":"5623602329","node_id":"PR_kwDOSePpfM8AAAABFm5L5A","number":208,"state":"open","title":"build(deps): bump com.fasterxml.jackson.core:jackson-databind from 2.17.0 to 2.18.10 in /java","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":9,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-29T01:22:53.000Z","updated_at":"2026-09-29T01:24:22.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps)","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.17.0","new_version":"2.18.10","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":"/java","ecosystem":"maven"},"body":"Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.17.0 to 2.18.10.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/176df1d48b256ced412c65293ad4e09393e24bd3\"\u003e\u003ccode\u003e176df1d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.18.10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7785f5f9ed24127e004115472c47b26ea4cf2774\"\u003e\u003ccode\u003e7785f5f\u003c/code\u003e\u003c/a\u003e Prep for 2.18.10 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0ccf3241c72d324df711f092ab4fa8f5635272cf\"\u003e\u003ccode\u003e0ccf324\u003c/code\u003e\u003c/a\u003e Backport \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6165\"\u003e#6165\u003c/a\u003e to 2.18: apply number length limits to BigDecimal/BigInteger/D...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bb18488020df1228580be5024ae8c6e9f06d9226\"\u003e\u003ccode\u003ebb18488\u003c/code\u003e\u003c/a\u003e Fix CREDITS class name wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1b1bb192a8560a3139287ce69295e10c1c5c81b2\"\u003e\u003ccode\u003e1b1bb19\u003c/code\u003e\u003c/a\u003e Fix release notes wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f\"\u003e\u003ccode\u003eeb3b7fc\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003ejava.lang.Comparable\u003c/code\u003e as an \u0026quot;unsafe\u0026quot; polymorphic base type (\u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6155\"\u003e#6155\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/65947556b62ee935a85aa5edaebf409813fd2456\"\u003e\u003ccode\u003e6594755\u003c/code\u003e\u003c/a\u003e One more minor tweak wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ba6fa2529df26d10fb57c44e1133ee786ebb82b9\"\u003e\u003ccode\u003eba6fa25\u003c/code\u003e\u003c/a\u003e Refactoring wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e part 2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/858a03b01028bc0131a0cb001473f215c2fe057d\"\u003e\u003ccode\u003e858a03b\u003c/code\u003e\u003c/a\u003e Refactoring wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/8de6a61f5d659249a41f85753a970992f46bbf98\"\u003e\u003ccode\u003e8de6a61\u003c/code\u003e\u003c/a\u003e Remove GHSA ids from CREDITS entries for \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6129\"\u003e#6129\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.17.0...jackson-databind-2.18.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.17.0\u0026new-version=2.18.10)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Dustin4444/x402/network/alerts).\n\n\u003c/details\u003e\n\n\u003c!-- Reviewable:start --\u003e\n- - -\nThis change is [\u003cimg src=\"https://reviewable.io/review_button.svg\" height=\"34\" align=\"absmiddle\" alt=\"Reviewable\"/\u003e](https://reviewable.io/reviews/Dustin4444/x402/208)\n\u003c!-- Reviewable:end --\u003e\n","html_url":"https://github.com/Dustin4444/x402/pull/208","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Dustin4444%2Fx402/issues/208","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/208/packages"},{"uuid":"5622952790","node_id":"PR_kwDOJqMqPM8AAAABFmYZcg","number":647,"state":"open","title":"build(deps): bump com.fasterxml.jackson.core:jackson-databind from 2.16.0 to 2.18.10 in /test/providers/tst_manifests/maven/pom_with_multiple_modules/module4","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-29T00:02:31.000Z","updated_at":"2026-09-29T08:00:46.452Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps)","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.16.0","new_version":"2.18.10","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":"/test/providers/tst_manifests/maven/pom_with_multiple_modules/module4","ecosystem":"maven"},"body":"Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.16.0 to 2.18.10.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/176df1d48b256ced412c65293ad4e09393e24bd3\"\u003e\u003ccode\u003e176df1d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.18.10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7785f5f9ed24127e004115472c47b26ea4cf2774\"\u003e\u003ccode\u003e7785f5f\u003c/code\u003e\u003c/a\u003e Prep for 2.18.10 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0ccf3241c72d324df711f092ab4fa8f5635272cf\"\u003e\u003ccode\u003e0ccf324\u003c/code\u003e\u003c/a\u003e Backport \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6165\"\u003e#6165\u003c/a\u003e to 2.18: apply number length limits to BigDecimal/BigInteger/D...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bb18488020df1228580be5024ae8c6e9f06d9226\"\u003e\u003ccode\u003ebb18488\u003c/code\u003e\u003c/a\u003e Fix CREDITS class name wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1b1bb192a8560a3139287ce69295e10c1c5c81b2\"\u003e\u003ccode\u003e1b1bb19\u003c/code\u003e\u003c/a\u003e Fix release notes wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f\"\u003e\u003ccode\u003eeb3b7fc\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003ejava.lang.Comparable\u003c/code\u003e as an \u0026quot;unsafe\u0026quot; polymorphic base type (\u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6155\"\u003e#6155\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/65947556b62ee935a85aa5edaebf409813fd2456\"\u003e\u003ccode\u003e6594755\u003c/code\u003e\u003c/a\u003e One more minor tweak wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ba6fa2529df26d10fb57c44e1133ee786ebb82b9\"\u003e\u003ccode\u003eba6fa25\u003c/code\u003e\u003c/a\u003e Refactoring wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e part 2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/858a03b01028bc0131a0cb001473f215c2fe057d\"\u003e\u003ccode\u003e858a03b\u003c/code\u003e\u003c/a\u003e Refactoring wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/8de6a61f5d659249a41f85753a970992f46bbf98\"\u003e\u003ccode\u003e8de6a61\u003c/code\u003e\u003c/a\u003e Remove GHSA ids from CREDITS entries for \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6129\"\u003e#6129\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.16.0...jackson-databind-2.18.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.16.0\u0026new-version=2.18.10)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/guacsec/trustify-da-javascript-client/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/guacsec/trustify-da-javascript-client/pull/647","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/guacsec%2Ftrustify-da-javascript-client/issues/647","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/647/packages"},{"uuid":"5621291873","node_id":"PR_kwDOBXext88AAAABFlDPYA","number":2292,"state":"open","title":"Build(deps): bump com.fasterxml.jackson.core:jackson-databind from 2.22.1 to 2.22.2 in /examples/sts-metrics","user":"dependabot[bot]","labels":["size/XS","dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-28T21:11:05.000Z","updated_at":"2026-09-29T18:57:30.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Build(deps)","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.22.1","new_version":"2.22.2","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":"/examples/sts-metrics","ecosystem":"maven"},"body":"Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.22.1 to 2.22.2.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/25b2a221f9aa4107e455065a74635e209418cf55\"\u003e\u003ccode\u003e25b2a22\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.22.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bab1c1a702a941f8805ee6698e8fa4fdbfbec54a\"\u003e\u003ccode\u003ebab1c1a\u003c/code\u003e\u003c/a\u003e Prep for 2.22.2 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bc03cf83d74cf0e5944dce33a63ee59ddc344b64\"\u003e\u003ccode\u003ebc03cf8\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/83379fb6409075336edf3d8d88744e95911a43f8\"\u003e\u003ccode\u003e83379fb\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0d400c9dc586fdd460d0c6a40db21ebbe22106d8\"\u003e\u003ccode\u003e0d400c9\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ce36a279f8b078bef2d9d44a1d01034c3634f91a\"\u003e\u003ccode\u003ece36a27\u003c/code\u003e\u003c/a\u003e Merge branch '2.18' into 2.19\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7a209e1fa97033746db50fd7bcd1e3dbab077599\"\u003e\u003ccode\u003e7a209e1\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/a432707afe6b7569243d1c2d8052a1bf33d9279c\"\u003e\u003ccode\u003ea432707\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/176df1d48b256ced412c65293ad4e09393e24bd3\"\u003e\u003ccode\u003e176df1d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.18.10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7785f5f9ed24127e004115472c47b26ea4cf2774\"\u003e\u003ccode\u003e7785f5f\u003c/code\u003e\u003c/a\u003e Prep for 2.18.10 release\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.22.1...jackson-databind-2.22.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.22.1\u0026new-version=2.22.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/GoogleCloudPlatform/professional-services/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/GoogleCloudPlatform/professional-services/pull/2292","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/GoogleCloudPlatform%2Fprofessional-services/issues/2292","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2292/packages"},{"uuid":"5621228630","node_id":"PR_kwDOAmLhj88AAAABFk_-Pg","number":83,"state":"closed","title":"Bump com.fasterxml.jackson.core:jackson-databind from 2.21.4 to 2.21.6 in /nimble-orm","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-30T02:47:35.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-28T21:05:42.000Z","updated_at":"2026-09-30T02:47:37.000Z","time_to_close":106913,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.21.4","new_version":"2.21.6","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":"/nimble-orm","ecosystem":"maven"},"body":"Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.21.4 to 2.21.6.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/5cf4246e1be4a579dbb64c83ef06a961381ca1a2\"\u003e\u003ccode\u003e5cf4246\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.21.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/b07e30e2183612d1ef14c5dce900dcc69688c240\"\u003e\u003ccode\u003eb07e30e\u003c/code\u003e\u003c/a\u003e Prep for 2.21.6 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/5bd046635388b90dd78749a9e50fad07a98d91dd\"\u003e\u003ccode\u003e5bd0466\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/d0f58e61281ad9912d3fa442f4b5ee65eb24e9f2\"\u003e\u003ccode\u003ed0f58e6\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0816b7c7ddb1a89fee5ff44c204531ee051a58ff\"\u003e\u003ccode\u003e0816b7c\u003c/code\u003e\u003c/a\u003e Merge branch '2.18' into 2.19\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0ccf3241c72d324df711f092ab4fa8f5635272cf\"\u003e\u003ccode\u003e0ccf324\u003c/code\u003e\u003c/a\u003e Backport \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6165\"\u003e#6165\u003c/a\u003e to 2.18: apply number length limits to BigDecimal/BigInteger/D...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0a0195d32b01bb1a039b81e36a4b6f28a51bfa82\"\u003e\u003ccode\u003e0a0195d\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/64f7e09ae991a4b55edd93960260f18c529120aa\"\u003e\u003ccode\u003e64f7e09\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/4edb753847293add6b0b46895334e0902b3c0154\"\u003e\u003ccode\u003e4edb753\u003c/code\u003e\u003c/a\u003e Merge branch '2.18' into 2.19\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bb18488020df1228580be5024ae8c6e9f06d9226\"\u003e\u003ccode\u003ebb18488\u003c/code\u003e\u003c/a\u003e Fix CREDITS class name wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.21.4...jackson-databind-2.21.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.21.4\u0026new-version=2.21.6)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/pugwoo/nimble-orm/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/pugwoo/nimble-orm/pull/83","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/pugwoo%2Fnimble-orm/issues/83","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/83/packages"},{"uuid":"5620809803","node_id":"PR_kwDOBElMp88AAAABFkqRjQ","number":31,"state":"open","title":"⬆️ Bump com.fasterxml.jackson.core:jackson-databind from 2.22.1 to 2.22.2","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-28T20:31:32.000Z","updated_at":"2026-09-28T20:32:06.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"⬆️ Bump","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.22.1","new_version":"2.22.2","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":null,"ecosystem":"maven"},"body":"Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.22.1 to 2.22.2.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/25b2a221f9aa4107e455065a74635e209418cf55\"\u003e\u003ccode\u003e25b2a22\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.22.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bab1c1a702a941f8805ee6698e8fa4fdbfbec54a\"\u003e\u003ccode\u003ebab1c1a\u003c/code\u003e\u003c/a\u003e Prep for 2.22.2 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bc03cf83d74cf0e5944dce33a63ee59ddc344b64\"\u003e\u003ccode\u003ebc03cf8\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/83379fb6409075336edf3d8d88744e95911a43f8\"\u003e\u003ccode\u003e83379fb\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0d400c9dc586fdd460d0c6a40db21ebbe22106d8\"\u003e\u003ccode\u003e0d400c9\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ce36a279f8b078bef2d9d44a1d01034c3634f91a\"\u003e\u003ccode\u003ece36a27\u003c/code\u003e\u003c/a\u003e Merge branch '2.18' into 2.19\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7a209e1fa97033746db50fd7bcd1e3dbab077599\"\u003e\u003ccode\u003e7a209e1\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/a432707afe6b7569243d1c2d8052a1bf33d9279c\"\u003e\u003ccode\u003ea432707\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/176df1d48b256ced412c65293ad4e09393e24bd3\"\u003e\u003ccode\u003e176df1d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.18.10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7785f5f9ed24127e004115472c47b26ea4cf2774\"\u003e\u003ccode\u003e7785f5f\u003c/code\u003e\u003c/a\u003e Prep for 2.18.10 release\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.22.1...jackson-databind-2.22.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.22.1\u0026new-version=2.22.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/binarywang/weixin-java-mp-multi-demo/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/binarywang/weixin-java-mp-multi-demo/pull/31","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/binarywang%2Fweixin-java-mp-multi-demo/issues/31","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/31/packages"},{"uuid":"5620688559","node_id":"PR_kwDOE8Qh388AAAABFkkAqA","number":2686,"state":"open","title":"chore(deps): bump com.fasterxml.jackson.core:jackson-databind from 2.22.0 to 2.22.2 in /examples/integrate-with-maven/maven-project","user":"dependabot[bot]","labels":["dependencies","autoapproved","autoupdate","java"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-28T20:21:32.000Z","updated_at":"2026-09-28T20:22:20.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.22.0","new_version":"2.22.2","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":"/examples/integrate-with-maven/maven-project","ecosystem":"maven"},"body":"Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.22.0 to 2.22.2.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/25b2a221f9aa4107e455065a74635e209418cf55\"\u003e\u003ccode\u003e25b2a22\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.22.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bab1c1a702a941f8805ee6698e8fa4fdbfbec54a\"\u003e\u003ccode\u003ebab1c1a\u003c/code\u003e\u003c/a\u003e Prep for 2.22.2 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bc03cf83d74cf0e5944dce33a63ee59ddc344b64\"\u003e\u003ccode\u003ebc03cf8\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/83379fb6409075336edf3d8d88744e95911a43f8\"\u003e\u003ccode\u003e83379fb\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0d400c9dc586fdd460d0c6a40db21ebbe22106d8\"\u003e\u003ccode\u003e0d400c9\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ce36a279f8b078bef2d9d44a1d01034c3634f91a\"\u003e\u003ccode\u003ece36a27\u003c/code\u003e\u003c/a\u003e Merge branch '2.18' into 2.19\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7a209e1fa97033746db50fd7bcd1e3dbab077599\"\u003e\u003ccode\u003e7a209e1\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/a432707afe6b7569243d1c2d8052a1bf33d9279c\"\u003e\u003ccode\u003ea432707\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/176df1d48b256ced412c65293ad4e09393e24bd3\"\u003e\u003ccode\u003e176df1d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.18.10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7785f5f9ed24127e004115472c47b26ea4cf2774\"\u003e\u003ccode\u003e7785f5f\u003c/code\u003e\u003c/a\u003e Prep for 2.18.10 release\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.22.0...jackson-databind-2.22.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.22.0\u0026new-version=2.22.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/asyncapi/modelina/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/asyncapi/modelina/pull/2686","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/asyncapi%2Fmodelina/issues/2686","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2686/packages"},{"uuid":"5593945962","node_id":"PR_kwDOUGgVCc8AAAABFPuOHA","number":6,"state":"closed","title":"build(deps): bump the maven group in /gateways/pingaccess/authzen-pdp with 7 updates","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-27T00:21:46.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-26T12:24:02.000Z","updated_at":"2026-09-27T00:21:48.000Z","time_to_close":43064,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"maven","update_count":7,"packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.21.1","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-databind"},{"name":"org.bitbucket.b_c:jose4j","old_version":"0.9.6","new_version":"0.9.7"},{"name":"org.mockito:mockito-core","old_version":"5.14.2","new_version":"5.23.0","repository_url":"https://github.com/mockito/mockito"},{"name":"org.apache.maven.plugins:maven-compiler-plugin","old_version":"3.13.0","new_version":"3.16.0","repository_url":"https://github.com/apache/maven-compiler-plugin"},{"name":"org.apache.maven.plugins:maven-surefire-plugin","old_version":"3.2.5","new_version":"3.6.0","repository_url":"https://github.com/apache/maven-surefire"},{"name":"org.apache.maven.plugins:maven-jar-plugin","old_version":"3.4.1","new_version":"3.5.1","repository_url":"https://github.com/apache/maven-jar-plugin"},{"name":"org.jacoco:jacoco-maven-plugin","old_version":"0.8.12","new_version":"0.8.15","repository_url":"https://github.com/jacoco/jacoco"}],"path":"/gateways/pingaccess/authzen-pdp","ecosystem":"maven"},"body":"[//]: # (dependabot-start)\n⚠️  **Dependabot is rebasing this PR** ⚠️ \n\nRebasing might not happen immediately, so don't worry if this takes some time.\n\nNote: if you make any changes to this PR yourself, they will take precedence over the rebase.\n\n---\n\n[//]: # (dependabot-end)\n\nBumps the maven group in /gateways/pingaccess/authzen-pdp with 7 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) | `2.21.1` | `2.22.3` |\n| [org.bitbucket.b_c:jose4j](https://bitbucket.org/b_c/jose4j) | `0.9.6` | `0.9.7` |\n| [org.mockito:mockito-core](https://github.com/mockito/mockito) | `5.14.2` | `5.23.0` |\n| [org.apache.maven.plugins:maven-compiler-plugin](https://github.com/apache/maven-compiler-plugin) | `3.13.0` | `3.16.0` |\n| [org.apache.maven.plugins:maven-surefire-plugin](https://github.com/apache/maven-surefire) | `3.2.5` | `3.6.0` |\n| [org.apache.maven.plugins:maven-jar-plugin](https://github.com/apache/maven-jar-plugin) | `3.4.1` | `3.5.1` |\n| [org.jacoco:jacoco-maven-plugin](https://github.com/jacoco/jacoco) | `0.8.12` | `0.8.15` |\n\nUpdates `com.fasterxml.jackson.core:jackson-databind` from 2.21.1 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/4385c5f7d51426f66fb24c3777308acc8ae7ea6c\"\u003e\u003ccode\u003e4385c5f\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ccb4fd0158cd20800f6014496dccf7332e5b18ce\"\u003e\u003ccode\u003eccb4fd0\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/2958412f1817a0ad95c34066b7eb85781dd2d4f1\"\u003e\u003ccode\u003e2958412\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1215b94c2f7a8c4ce3863afbc38275a19c682a54\"\u003e\u003ccode\u003e1215b94\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1f0df621449e5de7dd13a1538e0343f65f0e6bb3\"\u003e\u003ccode\u003e1f0df62\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/13a9ff4c4ef982cda23b99fea89d2a4e87af9019\"\u003e\u003ccode\u003e13a9ff4\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/d168f9679ad575cdc2df8d53a8474ec481c7b5a7\"\u003e\u003ccode\u003ed168f96\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/eaf5c76b8e0a538729a1bf922061abf73b13f89b\"\u003e\u003ccode\u003eeaf5c76\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/e05ef4cbb4d534a82948f8ba84350e55493bc72e\"\u003e\u003ccode\u003ee05ef4c\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/f6d4000c1eb6d34e2ae24685a9790b1e833d4bcb\"\u003e\u003ccode\u003ef6d4000\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.21.1...jackson-databind-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.bitbucket.b_c:jose4j` from 0.9.6 to 0.9.7\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from [org.bitbucket.b_c:jose4j's changelog](\u003ca href=\"https://bitbucket.org/b_c/jose4j/src/master/Release\"\u003ehttps://bitbucket.org/b_c/jose4j/src/master/Release\u003c/a\u003e Notes.md).\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch5\u003ejose4j-0.9.7 - September 9, 2026\u003c/h5\u003e\n\u003cul\u003e\n\u003cli\u003eupdate test dependencies\u003c/li\u003e\n\u003cli\u003ecap the size of numbers for better resource utilization in JSON processing (hat tip to Mike Read for the tip)\u003c/li\u003e\n\u003cli\u003efix some typos and other issues in javadoc and log messages\u003c/li\u003e\n\u003cli\u003eupdates for newer maven central publishing\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://bitbucket.org/b_c/jose4j/commits/756257eb92352600d5dde08c2b8ed25db13a8952\"\u003e\u003ccode\u003e756257e\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://bitbucket.org/b_c/jose4j/commits/5db177b550d355365ebf5c63d86376766e3ed6d8\"\u003e\u003ccode\u003e5db177b\u003c/code\u003e\u003c/a\u003e Look for Tag mismatch with no \u0026quot;!\u0026quot; b/c apparently maybe that changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://bitbucket.org/b_c/jose4j/commits/71a6650cee92e4c7fd91e860a42ddc533c902e40\"\u003e\u003ccode\u003e71a6650\u003c/code\u003e\u003c/a\u003e Merged in strict-aud-validation (pull request \u003ca href=\"https://bitbucket.org/b_c/jose4j/issues/26\"\u003e#26\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://bitbucket.org/b_c/jose4j/commits/05ce8870e1b7e37ef4bb53d138c95746c4dd0e28\"\u003e\u003ccode\u003e05ce887\u003c/code\u003e\u003c/a\u003e Compiler source and target to 1.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://bitbucket.org/b_c/jose4j/commits/f7c6da83b7f8097be7d3391b4eca9a7dec4e765f\"\u003e\u003ccode\u003ef7c6da8\u003c/code\u003e\u003c/a\u003e Update slf4j, bouncycastle, and mockito dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://bitbucket.org/b_c/jose4j/commits/3ac5eb47145d8d63bb640020fd9a0c22435ed932\"\u003e\u003ccode\u003e3ac5eb4\u003c/code\u003e\u003c/a\u003e Merged in fix-comment-typos (pull request \u003ca href=\"https://bitbucket.org/b_c/jose4j/issues/27\"\u003e#27\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://bitbucket.org/b_c/jose4j/commits/a87874c53748cb92002fcefd32df27413e14f4c2\"\u003e\u003ccode\u003ea87874c\u003c/code\u003e\u003c/a\u003e Fix stated default in Get.setResponseBodySizeLimit javadoc\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://bitbucket.org/b_c/jose4j/commits/51bdce2c95183cd11937b11190b306fe2a32ff59\"\u003e\u003ccode\u003e51bdce2\u003c/code\u003e\u003c/a\u003e fix log message arg number missmatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://bitbucket.org/b_c/jose4j/commits/7d8c47016f77686844288576b133f23d6e75e83b\"\u003e\u003ccode\u003e7d8c470\u003c/code\u003e\u003c/a\u003e Another log message arg number mismatch with a different fix\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://bitbucket.org/b_c/jose4j/commits/908a55ebf58b908e9e91a01aa86d8e5ae9f37dce\"\u003e\u003ccode\u003e908a55e\u003c/code\u003e\u003c/a\u003e cap the size of numbers for better resource utilization in JSON processing (h...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://bitbucket.org/b_c/jose4j/branches/compare/jose4j-0.9.7..jose4j-0.9.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.mockito:mockito-core` from 5.14.2 to 5.23.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mockito/mockito/releases\"\u003eorg.mockito:mockito-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.23.0\u003c/h2\u003e\n\u003ch2\u003eNOTE: Breaking change for Android\u003c/h2\u003e\n\u003cp\u003eThe \u003ccode\u003emockito-android\u003c/code\u003e artifact has a breaking change: tests now require a device or emulator based on API 28+ (Android P). This is to enable new support for mocking Kotlin classes. See \u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3788\"\u003e#3788\u003c/a\u003e for more details.\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003cem\u003eChangelog generated by \u003ca href=\"https://github.com/shipkit/shipkit-changelog\"\u003eShipkit Changelog Gradle Plugin\u003c/a\u003e\u003c/em\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch4\u003e5.23.0\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e2026-03-11 - \u003ca href=\"https://github.com/mockito/mockito/compare/v5.22.0...v5.23.0\"\u003e6 commit(s)\u003c/a\u003e by Brice Dutheil, Joshua Selbo, Philippe Kernevez\u003c/li\u003e\n\u003cli\u003eReplace mockito-android mock maker implementation with dexmaker-mockito-inline [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3792\"\u003e#3792\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3792\"\u003emockito/mockito#3792\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix StackOverflowError with AbstractList after using mockSingleton [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3790\"\u003e#3790\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3790\"\u003emockito/mockito#3790\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMark parameters of \u003ccode\u003eMockito.when\u003c/code\u003e \u003ccode\u003e@Nullable\u003c/code\u003e [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3503\"\u003e#3503\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3503\"\u003emockito/mockito#3503\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev5.22.0\u003c/h2\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003cem\u003eChangelog generated by \u003ca href=\"https://github.com/shipkit/shipkit-changelog\"\u003eShipkit Changelog Gradle Plugin\u003c/a\u003e\u003c/em\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch4\u003e5.22.0\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e2026-02-27 - \u003ca href=\"https://github.com/mockito/mockito/compare/v5.21.0...v5.22.0\"\u003e6 commit(s)\u003c/a\u003e by Joshua Selbo, NiMv1, Rafael Winterhalter, dependabot[bot], eunbin son\u003c/li\u003e\n\u003cli\u003eAvoid mocking of internal static utilities [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3785\"\u003e#3785\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3785\"\u003emockito/mockito#3785\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump graalvm/setup-graalvm from 1.4.4 to 1.4.5 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3780\"\u003e#3780\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3780\"\u003emockito/mockito#3780\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eStatic mocking of UUID.class corrupted under JDK 25 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3778\"\u003e#3778\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3778\"\u003emockito/mockito#3778\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump actions/upload-artifact from 5 to 6 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3774\"\u003e#3774\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3774\"\u003emockito/mockito#3774\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edocs: clarify RETURNS_MOCKS behavior with sealed abstract enums (Java 15+) [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3773\"\u003e#3773\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3773\"\u003emockito/mockito#3773\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd tests for Sets utility class [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3771\"\u003e#3771\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3771\"\u003emockito/mockito#3771\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd core API to enable Kotlin singleton mocking [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3762\"\u003e#3762\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3762\"\u003emockito/mockito#3762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eStubbing Kotlin \u003ccode\u003eobject\u003c/code\u003e singletons [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3652\"\u003e#3652\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3652\"\u003emockito/mockito#3652\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eIncorrect documentation for RETURNS_MOCKS [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3285\"\u003e#3285\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3285\"\u003emockito/mockito#3285\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev5.21.0\u003c/h2\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003cem\u003eChangelog generated by \u003ca href=\"https://github.com/shipkit/shipkit-changelog\"\u003eShipkit Changelog Gradle Plugin\u003c/a\u003e\u003c/em\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch4\u003e5.21.0\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e2025-12-09 - \u003ca href=\"https://github.com/mockito/mockito/compare/v5.20.0...v5.21.0\"\u003e17 commit(s)\u003c/a\u003e by Giulio Longfils, Joshua Selbo, Woongi9, Zylox, dependabot[bot]\u003c/li\u003e\n\u003cli\u003eBump graalvm/setup-graalvm from 1.4.3 to 1.4.4 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3768\"\u003e#3768\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3768\"\u003emockito/mockito#3768\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump graalvm/setup-graalvm from 1.4.2 to 1.4.3 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3767\"\u003e#3767\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3767\"\u003emockito/mockito#3767\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump actions/checkout from 5 to 6 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3765\"\u003e#3765\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3765\"\u003emockito/mockito#3765\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdds output of matchers to potential mismatch; Fixes \u003ca href=\"https://redirect.github.com/mockito/mockito/issues/2468\"\u003e#2468\u003c/a\u003e [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3760\"\u003e#3760\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3760\"\u003emockito/mockito#3760\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eForbid mocking WeakReference with inline mock maker [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3759\"\u003e#3759\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3759\"\u003emockito/mockito#3759\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eStackOverflowError when mocking WeakReference [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3758\"\u003e#3758\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3758\"\u003emockito/mockito#3758\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump actions/upload-artifact from 4 to 5 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3756\"\u003e#3756\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3756\"\u003emockito/mockito#3756\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump graalvm/setup-graalvm from 1.4.1 to 1.4.2 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3755\"\u003e#3755\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3755\"\u003emockito/mockito#3755\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSupport primitives in GenericArrayReturnType. [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3753\"\u003e#3753\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3753\"\u003emockito/mockito#3753\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eClassNotFoundException when stubbing array of primitive type on Android [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3752\"\u003e#3752\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3752\"\u003emockito/mockito#3752\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump graalvm/setup-graalvm from 1.4.0 to 1.4.1 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3744\"\u003e#3744\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3744\"\u003emockito/mockito#3744\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump gradle/actions from 4 to 5 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3743\"\u003e#3743\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3743\"\u003emockito/mockito#3743\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump org.graalvm.buildtools.native from 0.11.0 to 0.11.1 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3738\"\u003e#3738\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3738\"\u003emockito/mockito#3738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump com.diffplug.spotless:spotless-plugin-gradle from 7.2.1 to 8.0.0 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3735\"\u003e#3735\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3735\"\u003emockito/mockito#3735\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump graalvm/setup-graalvm from 1.3.7 to 1.4.0 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3734\"\u003e#3734\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3734\"\u003emockito/mockito#3734\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump org.assertj:assertj-core from 3.27.5 to 3.27.6 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3733\"\u003e#3733\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3733\"\u003emockito/mockito#3733\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/a231205b240e7884a63bf0f63440012867a4da21\"\u003e\u003ccode\u003ea231205\u003c/code\u003e\u003c/a\u003e Fix StackOverflowError with AbstractList after using mockSingleton (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3790\"\u003e#3790\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/f6a91a6a6138c776fa8b41ffb3fd078c64802044\"\u003e\u003ccode\u003ef6a91a6\u003c/code\u003e\u003c/a\u003e Replace mockito-android mock maker implementation with dexmaker-mockito-inlin...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/aa2298a627ab2c0bce07f648e444477d8e2e05ba\"\u003e\u003ccode\u003eaa2298a\u003c/code\u003e\u003c/a\u003e fix: make spotless happy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/a6729d657e232ca64da81d9801d7b8f3be6fc49a\"\u003e\u003ccode\u003ea6729d6\u003c/code\u003e\u003c/a\u003e chore: update BDDMockito with jspecify annotation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/bb83c922484cfd3693d61549b5d6ef39a9c02c2b\"\u003e\u003ccode\u003ebb83c92\u003c/code\u003e\u003c/a\u003e chore: move jspecify as a compile only dependency\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/47a46954cd1c0f8ef64ec63d43da9b71081d74e6\"\u003e\u003ccode\u003e47a4695\u003c/code\u003e\u003c/a\u003e chore: add jspecify with minimal change. Fixes \u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3503\"\u003e#3503\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/25f13951d35ca391ee50207e6c564f3e869f3d91\"\u003e\u003ccode\u003e25f1395\u003c/code\u003e\u003c/a\u003e Add core API to enable Kotlin singleton mocking (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3762\"\u003e#3762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/ef9ee5529853d96028b520f84a41ffd41afc9a1d\"\u003e\u003ccode\u003eef9ee55\u003c/code\u003e\u003c/a\u003e Avoids mocking private static methods, as well as package-private static meth...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/d16fcfc274d7ca03a2b4bdc22dd7c3ec6dac8690\"\u003e\u003ccode\u003ed16fcfc\u003c/code\u003e\u003c/a\u003e Bump graalvm/setup-graalvm from 1.4.4 to 1.4.5 (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3780\"\u003e#3780\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/27eb8a3acdd9c9eb3ff788a71b22777026874439\"\u003e\u003ccode\u003e27eb8a3\u003c/code\u003e\u003c/a\u003e Clarify \u003ccode\u003eRETURNS_MOCKS\u003c/code\u003e behavior with sealed abstract enums (Java 15+) (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3773\"\u003e#3773\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mockito/mockito/compare/v5.14.2...v5.23.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.maven.plugins:maven-compiler-plugin` from 3.13.0 to 3.16.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/apache/maven-compiler-plugin/releases\"\u003eorg.apache.maven.plugins:maven-compiler-plugin's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.16.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e🚀 New features and improvements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRecompile when dependencies change (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1102\"\u003e#1102\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix incremental detection of empty sources, 3.x (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1075\"\u003e#1075\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/MCOMPILER-578\"\u003e[MCOMPILER-578]\u003c/a\u003e - Track outputs across compiler executions (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1091\"\u003e#1091\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBuild fails when annotation processor list is empty (but present) (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1077\"\u003e#1077\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/MCOMPILER-374\"\u003e[MCOMPILER-374]\u003c/a\u003e - Unable to compile MR-JAR code against older directories when module-info.java is present (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1093\"\u003e#1093\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMake mcompiler-120 IT locale independent (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1063\"\u003e#1063\u003c/a\u003e) \u003ca href=\"https://github.com/anilvdl\"\u003e\u003ccode\u003e@​anilvdl\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📝 Documentation updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/MCOMPILER-569\"\u003e[MCOMPILER-569]\u003c/a\u003e - Document implicitly compiled excluded sources (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1092\"\u003e#1092\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1074\"\u003e#1074\u003c/a\u003e) \u003ca href=\"https://github.com/potiuk\"\u003e\u003ccode\u003e@​potiuk\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e👻 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid using deprecated method CompilerConfiguration.setCompilerVersion (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1121\"\u003e#1121\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReplace adopt-openj9 by semeru JDK distribution on GH (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1122\"\u003e#1122\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePort the site documentation from APT to Markdown (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1110\"\u003e#1110\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eVerify against Maven 4.0.0-rc-6 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1105\"\u003e#1105\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix tests on Jenkins (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1100\"\u003e#1100\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1074\"\u003e#1074\u003c/a\u003e) \u003ca href=\"https://github.com/potiuk\"\u003e\u003ccode\u003e@​potiuk\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRefactor compiler mojo to use dependency injection and improve string… (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1066\"\u003e#1066\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix ITs for Maven 3.10.x (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1061\"\u003e#1061\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate maven-surefire-plugin version to 3.x in the MCOMPILER-481 IT (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1035\"\u003e#1035\u003c/a\u003e) \u003ca href=\"https://github.com/cdouillard\"\u003e\u003ccode\u003e@​cdouillard\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📦 Dependency updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump plexusCompilerVersion from 2.16.2 to 2.17.0 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1112\"\u003e#1112\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.codehaus.plexus:plexus-java from 1.5.2 to 1.6.0 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1113\"\u003e#1113\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003euse latest Maven 4 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1045\"\u003e#1045\u003c/a\u003e) \u003ca href=\"https://github.com/hboutemy\"\u003e\u003ccode\u003e@​hboutemy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump apache/maven-gh-actions-shared/.github/workflows/release-drafter.yml from 4 to 5 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1083\"\u003e#1083\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump apache/maven-gh-actions-shared/.github/workflows/pr-automation.yml from 4 to 5 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1082\"\u003e#1082\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump apache/maven-gh-actions-shared/.github/workflows/maven-verify.yml from 4 to 5 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1084\"\u003e#1084\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-plugins from 48 to 49 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1068\"\u003e#1068\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-invoker-plugin from 3.9.1 to 3.10.1 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1047\"\u003e#1047\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-plugins from 47 to 48 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1050\"\u003e#1050\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump mavenVersion from 3.9.14 to 3.9.16 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1054\"\u003e#1054\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.ow2.asm:asm from 9.10 to 9.10.1 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1059\"\u003e#1059\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.ow2.asm:asm from 9.9.1 to 9.10 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1053\"\u003e#1053\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump mavenVersion from 3.9.13 to 3.9.14 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1041\"\u003e#1041\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump mavenVersion from 3.9.12 to 3.9.13 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1038\"\u003e#1038\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugin-testing:maven-plugin-testing-harness from 3.5.0 to 3.5.1 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1032\"\u003e#1032\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.15.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/e7bba6ed5f9c17003d5c5d1413144bb214177408\"\u003e\u003ccode\u003ee7bba6e\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release maven-compiler-plugin-3.16.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/c906809e0c0b2c79e8a03165cb942f152a911416\"\u003e\u003ccode\u003ec906809\u003c/code\u003e\u003c/a\u003e Avoid using deprecated method CompilerConfiguration.setCompilerVersion\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/ad74fee36865d7a1752c9b96ff9a9e702565fdb3\"\u003e\u003ccode\u003ead74fee\u003c/code\u003e\u003c/a\u003e Replace adopt-openj9 by semeru JDK distribution on GH\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/beb0eda2100e77d3f01bf4cc89edd5b721411f63\"\u003e\u003ccode\u003ebeb0eda\u003c/code\u003e\u003c/a\u003e Recompile when dependencies change (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/issues/1102\"\u003e#1102\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/a0b689e0e7f13d3a7dded7847a807fe6453e0358\"\u003e\u003ccode\u003ea0b689e\u003c/code\u003e\u003c/a\u003e [MCOMPILER-578] Track outputs across compiler executions (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/issues/1091\"\u003e#1091\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/2e8122841d9b10d2d83a90cc07530d7a09eebc47\"\u003e\u003ccode\u003e2e81228\u003c/code\u003e\u003c/a\u003e Fix incremental detection of empty sources, 3.x (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/issues/1075\"\u003e#1075\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/2132f5bf0cbfcde26301084c4833f1a9420f1baf\"\u003e\u003ccode\u003e2132f5b\u003c/code\u003e\u003c/a\u003e configure ATR project\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/5992b772033a7488767c4b3aa806f080eba96593\"\u003e\u003ccode\u003e5992b77\u003c/code\u003e\u003c/a\u003e Build fails when annotation processor list is empty (but present) (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/issues/1077\"\u003e#1077\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/acccef703e5491c29c6dd9e8381677d3e7927589\"\u003e\u003ccode\u003eacccef7\u003c/code\u003e\u003c/a\u003e Bump plexusCompilerVersion from 2.16.2 to 2.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/72bc4454dfdcd1c3551137e5b27560f88b4480ae\"\u003e\u003ccode\u003e72bc445\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-java from 1.5.2 to 1.6.0\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/apache/maven-compiler-plugin/compare/maven-compiler-plugin-3.13.0...maven-compiler-plugin-3.16.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.maven.plugins:maven-surefire-plugin` from 3.2.5 to 3.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/apache/maven-surefire/releases\"\u003eorg.apache.maven.plugins:maven-surefire-plugin's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.6.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003ePlease refer to the main page for what's new \u003ca href=\"https://maven.apache.org/surefire/\"\u003ehttps://maven.apache.org/surefire/\u003c/a\u003e\nAnd the migration page \u003ca href=\"https://maven.apache.org/surefire/maven-surefire-plugin/whats-new-3-6-0.html\"\u003ehttps://maven.apache.org/surefire/maven-surefire-plugin/whats-new-3-6-0.html\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e🚀 New features and improvements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3303\"\u003e#3303\u003c/a\u003e: distinguish JUnit 6 ParameterizedClass invocations (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3432\"\u003e#3432\u003c/a\u003e) \u003ca href=\"https://github.com/AzazelSensei\"\u003e\u003ccode\u003e@​AzazelSensei\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-1639\"\u003e[SUREFIRE-1639]\u003c/a\u003e - Add ability to configure JUnit 5 TestExecutionListener (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3438\"\u003e#3438\u003c/a\u003e) \u003ca href=\"https://github.com/pan3793\"\u003e\u003ccode\u003e@​pan3793\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIssue \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/838\"\u003e#838\u003c/a\u003e Implement extension point to run diagnosis tools when forked JVM times out (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3372\"\u003e#3372\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-2148\"\u003e[SUREFIRE-2148]\u003c/a\u003e - Verify recovered BeforeAll does not fail build (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3419\"\u003e#3419\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-823\"\u003e[SUREFIRE-823]\u003c/a\u003e - Decouple -DskipTests from Failsafe plugin (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3371\"\u003e#3371\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse StackWalker in StackTraceProvider when available (Java 9+) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3374\"\u003e#3374\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Issue-3380] Send sourceQualifiedName to forked clients (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3380\"\u003e#3380\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3381\"\u003e#3381\u003c/a\u003e) \u003ca href=\"https://github.com/fabriciorby\"\u003e\u003ccode\u003e@​fabriciorby\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-523\"\u003e[SUREFIRE-523]\u003c/a\u003e - Link all reported tests to source XRef (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3445\"\u003e#3445\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-3446\"\u003e[SUREFIRE-3446]\u003c/a\u003e - Fix direct selection of JUnit Jupiter \u003ca href=\"https://github.com/Nested\"\u003e\u003ccode\u003e@​Nested\u003c/code\u003e\u003c/a\u003e classes (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3447\"\u003e#3447\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDiscover tests in a fork when a toolchain JDK is used (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3444\"\u003e#3444\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[SUREFIRE-2239, SUREFIRE-2241, SUREFIRE-2260, SUREFIRE-2274, SUREFIRE-2300] Preserve JUnit Platform test identity across reruns (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3418\"\u003e#3418\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3428\"\u003e#3428\u003c/a\u003e: resolve parents via TestPlan.getParent for pre-1.8 platforms (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3429\"\u003e#3429\u003c/a\u003e) \u003ca href=\"https://github.com/kalayciburak\"\u003e\u003ccode\u003e@​kalayciburak\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-859\"\u003e[SUREFIRE-859]\u003c/a\u003e - Make random test order reproducible (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3421\"\u003e#3421\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[SUREFIRE-862, SUREFIRE-3178] Handle missing Failsafe summary files (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3417\"\u003e#3417\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: report AfterAll/AfterClass exceptions as errors again (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3412\"\u003e#3412\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3413\"\u003e#3413\u003c/a\u003e) \u003ca href=\"https://github.com/arimu1\"\u003e\u003ccode\u003e@​arimu1\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixes \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3264\"\u003e#3264\u003c/a\u003e : tests inside \u003ca href=\"https://github.com/Suite\"\u003e\u003ccode\u003e@​Suite\u003c/code\u003e\u003c/a\u003e incorrectly classified as flakes (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3342\"\u003e#3342\u003c/a\u003e) \u003ca href=\"https://github.com/mirkoalicastro\"\u003e\u003ccode\u003e@​mirkoalicastro\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix Windows flake in CommandChannelDecoderTest (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3400\"\u003e#3400\u003c/a\u003e) \u003ca href=\"https://github.com/ascheman\"\u003e\u003ccode\u003e@​ascheman\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix reportNameSuffix in XML testcase classname (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3379\"\u003e#3379\u003c/a\u003e) \u003ca href=\"https://github.com/goutamadwant\"\u003e\u003ccode\u003e@​goutamadwant\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix: resolve relative classpath elements against the fork's working dir (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3333\"\u003e#3333\u003c/a\u003e) \u003ca href=\"https://github.com/cwegener-79\"\u003e\u003ccode\u003e@​cwegener-79\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📝 Documentation updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMagnify the home, well at least have something rather than nothing :) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3377\"\u003e#3377\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRestore the straight quotes the FAQ conversion turned typographic (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3425\"\u003e#3425\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRestore the table borders lost in the APT conversion (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3424\"\u003e#3424\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eConvert the FAQ from FML to Markdown (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3423\"\u003e#3423\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eConvert the remaining site documentation from APT to Markdown (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3422\"\u003e#3422\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ejavadoc: clarify statelessTestsetReporter, consoleOutputReporter, (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3410\"\u003e#3410\u003c/a\u003e) \u003ca href=\"https://github.com/joshinii\"\u003e\u003ccode\u003e@​joshinii\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3387\"\u003e#3387\u003c/a\u003e) \u003ca href=\"https://github.com/potiuk\"\u003e\u003ccode\u003e@​potiuk\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate documentation we support Junit 6 as well :) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3370\"\u003e#3370\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e👻 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eStop dependabot from updating test fixtures (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3440\"\u003e#3440\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMigrate legacy plugin Javadoc annotations (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3416\"\u003e#3416\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse the resolver's own HTTP transport in the report plugin tests (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3414\"\u003e#3414\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin maven-jar-plugin 3.5.1 in modular IT fixtures (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3398\"\u003e#3398\u003c/a\u003e) \u003ca href=\"https://github.com/ascheman\"\u003e\u003ccode\u003e@​ascheman\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3387\"\u003e#3387\u003c/a\u003e) \u003ca href=\"https://github.com/potiuk\"\u003e\u003ccode\u003e@​potiuk\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/0ff622b160253f362511a72d29a1f8067631f9d3\"\u003e\u003ccode\u003e0ff622b\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release surefire-3.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/bb3932a10a9706df70cf8095e2402348b7a64f0b\"\u003e\u003ccode\u003ebb3932a\u003c/code\u003e\u003c/a\u003e Let's go for 3.6.0 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/3002a1648cc8092dbd80492aa00509c825fd58e7\"\u003e\u003ccode\u003e3002a16\u003c/code\u003e\u003c/a\u003e Bump mavenVersion from 3.9.14 to 3.9.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/61a531d5981b0e70f8e88a329150f75501bb73e4\"\u003e\u003ccode\u003e61a531d\u003c/code\u003e\u003c/a\u003e Bump Maven parent version from 47 to 49 (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3449\"\u003e#3449\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/e52ead4cf5075f519578d0053c1ff878dff238f5\"\u003e\u003ccode\u003ee52ead4\u003c/code\u003e\u003c/a\u003e [SUREFIRE-523] Link all reported tests to source XRef (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3445\"\u003e#3445\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/45102fa9f2dfc5bc3d2909798e67358ae33e2d49\"\u003e\u003ccode\u003e45102fa\u003c/code\u003e\u003c/a\u003e [SUREFIRE-3446] Fix direct selection of JUnit Jupiter \u003ca href=\"https://github.com/Nested\"\u003e\u003ccode\u003e@​Nested\u003c/code\u003e\u003c/a\u003e classes (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3447\"\u003e#3447\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/b2e1f70b24df2d8a6cf1583ca955311184e68022\"\u003e\u003ccode\u003eb2e1f70\u003c/code\u003e\u003c/a\u003e Fix \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3303\"\u003e#3303\u003c/a\u003e: distinguish JUnit 6 ParameterizedClass invocations (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3432\"\u003e#3432\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/c051938593a29d654b3c1c20d454b9062c3fa3f4\"\u003e\u003ccode\u003ec051938\u003c/code\u003e\u003c/a\u003e Discover tests in a fork when a toolchain JDK is used (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3444\"\u003e#3444\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/db75df85a76abf35346f559fe7f7f020cf6435b6\"\u003e\u003ccode\u003edb75df8\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-java from 1.5.2 to 1.6.0 (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3441\"\u003e#3441\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/77f2759d895a4460f917bdaaff7a025454afebe4\"\u003e\u003ccode\u003e77f2759\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-interpolation from 1.29 to 1.30.0\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/apache/maven-surefire/compare/surefire-3.2.5...surefire-3.6.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.maven.plugins:maven-jar-plugin` from 3.4.1 to 3.5.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/apache/maven-jar-plugin/releases\"\u003eorg.apache.maven.plugins:maven-jar-plugin's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.5.1\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e📝 Documentation updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/550\"\u003e#550\u003c/a\u003e) \u003ca href=\"https://github.com/potiuk\"\u003e\u003ccode\u003e@​potiuk\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e👻 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/550\"\u003e#550\u003c/a\u003e) \u003ca href=\"https://github.com/potiuk\"\u003e\u003ccode\u003e@​potiuk\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse plugin version properties (3.x) (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/535\"\u003e#535\u003c/a\u003e) \u003ca href=\"https://github.com/Bukama\"\u003e\u003ccode\u003e@​Bukama\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📦 Dependency updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-plugins from 48 to 49 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/547\"\u003e#547\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.codehaus.plexus:plexus-archiver from 4.11.0 to 4.12.0 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/538\"\u003e#538\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump mavenVersion from 3.9.15 to 3.9.16 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/536\"\u003e#536\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-plugins from 47 to 48 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/534\"\u003e#534\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump commons-io:commons-io from 2.21.0 to 2.22.0 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/529\"\u003e#529\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump mavenVersion from 3.9.14 to 3.9.15 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/528\"\u003e#528\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump mavenVersion from 3.9.12 to 3.9.14 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/526\"\u003e#526\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugin-testing:maven-plugin-testing-harness from 3.5.0 to 3.5.1 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/523\"\u003e#523\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-plugins from 46 to 47 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/519\"\u003e#519\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.codehaus.plexus:plexus-archiver from 4.10.4 to 4.11.0 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/516\"\u003e#516\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugin-testing:maven-plugin-testing-harness from 3.4.0 to 3.5.0 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/517\"\u003e#517\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-plugins from 45 to 46 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/514\"\u003e#514\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven:maven-archiver from 3.6.5 to 3.6.6 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/511\"\u003e#511\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump mavenVersion from 3.9.11 to 3.9.12 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/509\"\u003e#509\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.5.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e🚀 New features and improvements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd new \u0026quot;attach\u0026quot; configuration parameter (3.x port of \u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/issues/482\"\u003e#482\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/483\"\u003e#483\u003c/a\u003e) \u003ca href=\"https://github.com/hgschmie\"\u003e\u003ccode\u003e@​hgschmie\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eadd Java-Version to MANIFEST.MF (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/465\"\u003e#465\u003c/a\u003e) \u003ca href=\"https://github.com/hboutemy\"\u003e\u003ccode\u003e@​hboutemy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix detecting java version for toolchains and JDK 1.8 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/500\"\u003e#500\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIgnore stderr when parsing javac version from toolchain (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/471\"\u003e#471\u003c/a\u003e) \u003ca href=\"https://github.com/jaredstehler\"\u003e\u003ccode\u003e@​jaredstehler\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e👻 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate site descriptor to 2.0.0 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/501\"\u003e#501\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: remove junit3 references (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/494\"\u003e#494\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMigrate component injection to JSR-330 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/492\"\u003e#492\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd PR Automation to 3.x (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/132\"\u003e#132\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImprove release-drafter configuration (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/128\"\u003e#128\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix for Maven 4.0.0-rc-3 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/130\"\u003e#130\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/MNGSITE-529\"\u003e[MNGSITE-529]\u003c/a\u003e - Rename \u0026quot;Goals\u0026quot; to \u0026quot;Plugin Documentation\u0026quot; (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/119\"\u003e#119\u003c/a\u003e) \u003ca href=\"https://github.com/Bukama\"\u003e\u003ccode\u003e@​Bukama\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-jar-plugin/commit/b0cd63d0ad544aa552f06e4492faf984bf2c85c1\"\u003e\u003ccode\u003eb0cd63d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release maven-jar-plugin-3.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-jar-plugin/commit/5318a4feaf529d6fa22c4622fff2d54fefe7f7dd\"\u003e\u003ccode\u003e5318a4f\u003c/code\u003e\u003c/a\u003e Add AGENTS.md + SECURITY.md security-model pointer for scanner discoverability\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-jar-plugin/commit/8e0b9bb307fc29b8d267f18eca9d47be0a7f16e0\"\u003e\u003ccode\u003e8e0b9bb\u003c/code\u003e\u003c/a\u003e Bump org.apache.maven.plugins:maven-plugins from 48 to 49 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/issues/547\"\u003e#547\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-jar-plugin/commit/d5a438b6add9a9115f5a2c9b27db67e0d962bb74\"\u003e\u003ccode\u003ed5a438b\u003c/code\u003e\u003c/a\u003e Fix javadoc\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-jar-plugin/commit/774fac9215d92bfac67ece082872b00475580b21\"\u003e\u003ccode\u003e774fac9\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-archiver from 4.11.0 to 4.12.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-jar-plugin/commit/b71f40368edc878b3dcaa9840d950bd7d297d4c4\"\u003e\u003ccode\u003eb71f403\u003c/code\u003e\u003c/a\u003e Bump mavenVersion from 3.9.15 to 3.9.16 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/issues/536\"\u003e#536\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-jar-plugin/commit/9f2a001a00fcbb0408219a11f62b48c4dfde78d3\"\u003e\u003ccode\u003e9f2a001\u003c/code\u003e\u003c/a\u003e Use plugin version properties (3.x) (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/issues/535\"\u003e#535\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-jar-plugin/commit/68a978f952ba510f7378fd287c5172dc560079e3\"\u003e\u003ccode\u003e68a978f\u003c/code\u003e\u003c/a\u003e Bump org.apache.maven.plugins:maven-plugins from 47 to 48 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/issues/534\"\u003e#534\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-jar-plugin/commit/e1058217f657691a3e50b0c7e0620fd13c8e83c3\"\u003e\u003ccode\u003ee105821\u003c/code\u003e\u003c/a\u003e Bump commons-io:commons-io from 2.21.0 to 2.22.0 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/issues/529\"\u003e#529\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-jar-plugin/commit/953dc1abbb527b8128657f2aeadfdca0557d974d\"\u003e\u003ccode\u003e953dc1a\u003c/code\u003e\u003c/a\u003e Bump mavenVersion from 3.9.14 to 3.9.15 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/issues/528\"\u003e#528\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/apache/maven-jar-plugin/compare/maven-jar-plugin-3.4.1...maven-jar-plugin-3.5.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.jacoco:jacoco-maven-plugin` from 0.8.12 to 0.8.15\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jacoco/jacoco/releases\"\u003eorg.jacoco:jacoco-maven-plugin's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.8.15\u003c/h2\u003e\n\u003ch2\u003eNew Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eJaCoCo now officially supports Java 26 (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2076\"\u003e#2076\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eExperimental support for Java 27 class files (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2004\"\u003e#2004\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCompatibility methods generated by Kotlin compiler for functions defined in interfaces are filtered out during generation of report (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1905\"\u003e#1905\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCompatibility methods generated by Kotlin compiler for exposed boxed inline value classes (JvmExposeBoxed annotation) are filtered out during generation of report (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1944\"\u003e#1944\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eMethods generated by the Kotlin compiler for functions with JvmStatic annotation are filtered out during generation of report (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2097\"\u003e#2097\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImproved filtering of bytecode generated by Kotlin compiler for when expressions and statements with kotlin.String subject where first branch condition contains string with largest hash (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2098\"\u003e#2098\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePart of bytecode that javac versions from 24 to 26 generate for switch statements and expressions with selector expression of type java.lang.String inside lambdas is filtered out during generation of report (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2023\"\u003e#2023\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImproved performance of Kotlin files analysis by parsing SMAPs only once per class (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2114\"\u003e#2114\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFor better performance agent output methods tcpclient and tcpserver use BufferedOutputStream to write execution data to socket. Maven plugin, Ant tasks, CLI, API usage examples, and ExecDumpClient API use BufferedInputStream to read execution data from socket. Third-party integrations should do the same to benefit from this change in agent (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2089\"\u003e#2089\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eFixed bugs\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed processing of Kotlin SMAP in synthetic classes (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1985\"\u003e#1985\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eMultiple JaCoCo runtimes within one JVM writing to the same output file should not cause data corruption when running on JDK versions from 6 to 10 affected by \u003ca href=\"https://bugs.openjdk.org/browse/JDK-8166253\"\u003eJDK-8166253\u003c/a\u003e (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2065\"\u003e#2065\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2074\"\u003e#2074\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFor better performance agent writes to output file via BufferedOutputStream, this fixes regression introduced in version 0.6.2 (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2073\"\u003e#2073\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed NullPointerException when JaCoCo agent is loaded by non system class loader, for example when loaded by JBoss Modules (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1651\"\u003e#1651\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNon-functional Changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eJaCoCo now depends on ASM 9.10.1 (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2134\"\u003e#2134\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.8.14\u003c/h2\u003e\n\u003ch2\u003eNew Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eJaCoCo now officially supports Java 25 (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1950\"\u003e#1950\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eExperimental support for Java 26 class files (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1807\"\u003e#1870\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eBranches added by the Kotlin compiler for default argument number 33 or higher are filtered out during generation of report (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1655\"\u003e#1655\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePart of bytecode generated by the Kotlin compiler for elvis operator that follows safe call operator is filtered out during generation of report (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1814\"\u003e#1814\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1954\"\u003e#1954\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePart of bytecode generated by the Kotlin compiler for more cases of chained safe call operators is filtered out during generation of report (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1956\"\u003e#1956\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePart of bytecode generated by the Kotlin compiler for invocations of suspendCoroutineUninterceptedOrReturn intrinsic is filtered out during generation of report (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1929\"\u003e#1929\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePart of bytecode generated by the Kotlin compiler for suspending lambdas with parameters is filtered out during generation of report (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1945\"\u003e#1945\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePart of bytecode generated by the Kotlin compiler for suspending functions and lambdas with suspension points that return inline value class is filtered out during generation of report (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1871\"\u003e#1871\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePart of bytecode generated by the Kotlin Compose compiler plugin for pausable composition is filtered out during generation of report (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1911\"\u003e#1911\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eMethods generated by the Kotlin serialization compiler plugin are filtered out (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1885\"\u003e#1885\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1970\"\u003e#1970\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1971\"\u003e#1971\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eFixed bugs\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed handling of implicit else clause of when with String subject in Kotlin (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1813\"\u003e#1813\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1940\"\u003e#1940\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed handling of implicit default clause of switch by String in Java when compiled by ECJ (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1813\"\u003e#1813\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1940\"\u003e#1940\u003c/a\u003e).\nFixed handling of exceptions in chains of safe call operators in Kotlin (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1819\"\u003e#1819\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNon-functional Changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eJaCoCo now depends on ASM 9.9 (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1965\"\u003e#1965\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.8.13\u003c/h2\u003e\n\u003ch2\u003eNew Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eJaCoCo now officially supports Java 23 and Java 24 (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1757\"\u003e#1757\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1631\"\u003e#1631\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1867\"\u003e#1867\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eExperimental support for Java 25 class files (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1807\"\u003e#1807\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCalculation of line coverage for Kotlin \u003ccode\u003einline\u003c/code\u003e functions (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1670\"\u003e#1670\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCalculation of line coverage for Kotlin \u003ccode\u003einline\u003c/code\u003e functions with \u003ccode\u003ereified\u003c/code\u003e type parameter (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1670\"\u003e#1670\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1700\"\u003e#1700\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCalculation of coverage for Kotlin \u003ccode\u003eJvmSynthetic\u003c/code\u003e functions (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1700\"\u003e#1700\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePart of bytecode generated by the Kotlin Compose compiler plugin is filtered out during generation of report (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1616\"\u003e#1616\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jacoco/jacoco/commit/6c5260a192eaa535e4a519771d530781cbac9136\"\u003e\u003ccode\u003e6c5260a\u003c/code\u003e\u003c/a\u003e Prepare release v0.8.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jacoco/jacoco/commit/5c05141431a7f064a804a923fbae11271241f116\"\u003e\u003ccode\u003e5c05141\u003c/code\u003e\u003c/a\u003e Transfer of execution data through socket should use buffered stream (\u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2089\"\u003e#2089\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jacoco/jacoco/commit/ab5efa9d63c06899b2aec1d4a6099fc856132a22\"\u003e\u003ccode\u003eab5efa9\u003c/code\u003e\u003c/a\u003e Remove from Azure Pipelines all builds except with JDK 5 and JDK EA (\u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2148\"\u003e#2148\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jacoco/jacoco/commit/5f6ea38f20ff4583deb4ab976571c853231f97c2\"\u003e\u003ccode\u003e5f6ea38\u003c/code\u003e\u003c/a\u003e Use Windows 2025 image in GitHub Actions (\u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2130\"\u003e#2130\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jacoco/jacoco/commit/35a8af2cfc168ce51f2a3ea2d55d65f31e61c513\"\u003e\u003ccode\u003e35a8af2\u003c/code\u003e\u003c/a\u003e Use Renovate instead of Dependabot for updates of ASM (\u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2137\"\u003e#2137\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jacoco/jacoco/commit/85b8ddf530821f75b3b26f5f96d03252286b3ad6\"\u003e\u003ccode\u003e85b8ddf\u003c/code\u003e\u003c/a\u003e Upgrade ASM to 9.10.1 (\u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2134\"\u003e#2134\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jacoco/jacoco/commit/2988647ac37c3ad35a77b51d01b10a916b85627b\"\u003e\u003ccode\u003e2988647\u003c/code\u003e\u003c/a\u003e AgentModule should use ClassLoader of agent instead of SystemClassLoader (\u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1651\"\u003e#1651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jacoco/jacoco/commit/75a4e31fed32f180fbe4593ad91ec5c176c0535b\"\u003e\u003ccode\u003e75a4e31\u003c/code\u003e\u003c/a\u003e Add filter for Kotlin \u003ccode\u003e@JvmExposeBoxed\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1944\"\u003e#1944\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jacoco/jacoco/commit/691fa1d6a0dffa91f45daf0714f28bfdaa367fc0\"\u003e\u003ccode\u003e691fa1d\u003c/code\u003e\u003c/a\u003e Use Renovate instead of Dependabot for updates of GitHub Actions (\u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2132\"\u003e#2132\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jacoco/jacoco/commit/3e18f17207bca0203b726ace460aa6be8d0f3dd4\"\u003e\u003ccode\u003e3e18f17\u003c/code\u003e\u003c/a\u003e Require at least JDK 21 for build (\u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2128\"\u003e#2128\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/jacoco/jacoco/compare/v0.8.12...v0.8.15\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/ID-Partners/idp-auth-peps/pull/6","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/ID-Partners%2Fidp-auth-peps/issues/6","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/6/packages"},{"uuid":"5581208041","node_id":"PR_kwDOTxnlA88AAAABFF2mtw","number":36,"state":"open","title":"build(deps): bump com.fasterxml.jackson.core:jackson-databind from 2.22.2 to 2.22.3 in /services/transaction-service","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-25T09:55:43.000Z","updated_at":"2026-09-25T09:57:30.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps)","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":"/services/transaction-service","ecosystem":"maven"},"body":"Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.22.2 to 2.22.3.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/4385c5f7d51426f66fb24c3777308acc8ae7ea6c\"\u003e\u003ccode\u003e4385c5f\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ccb4fd0158cd20800f6014496dccf7332e5b18ce\"\u003e\u003ccode\u003eccb4fd0\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/2958412f1817a0ad95c34066b7eb85781dd2d4f1\"\u003e\u003ccode\u003e2958412\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1215b94c2f7a8c4ce3863afbc38275a19c682a54\"\u003e\u003ccode\u003e1215b94\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1f0df621449e5de7dd13a1538e0343f65f0e6bb3\"\u003e\u003ccode\u003e1f0df62\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/13a9ff4c4ef982cda23b99fea89d2a4e87af9019\"\u003e\u003ccode\u003e13a9ff4\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/d168f9679ad575cdc2df8d53a8474ec481c7b5a7\"\u003e\u003ccode\u003ed168f96\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/eaf5c76b8e0a538729a1bf922061abf73b13f89b\"\u003e\u003ccode\u003eeaf5c76\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/e05ef4cbb4d534a82948f8ba84350e55493bc72e\"\u003e\u003ccode\u003ee05ef4c\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/f6d4000c1eb6d34e2ae24685a9790b1e833d4bcb\"\u003e\u003ccode\u003ef6d4000\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.22.2...jackson-databind-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.22.2\u0026new-version=2.22.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/wep1980/wepdev-financas/pull/36","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/wep1980%2Fwepdev-financas/issues/36","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/36/packages"},{"uuid":"5576282180","node_id":"PR_kwDOARYPw88AAAABFB65PQ","number":736,"state":"closed","title":"Bump com.fasterxml.jackson.core:jackson-databind from 2.22.2 to 2.22.3 in the jackson group","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-25T00:27:29.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-25T00:22:23.000Z","updated_at":"2026-09-25T00:27:30.000Z","time_to_close":306,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":"the jackson group","ecosystem":"maven"},"body":"Bumps the jackson group with 1 update: [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind).\n\nUpdates `com.fasterxml.jackson.core:jackson-databind` from 2.22.2 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/4385c5f7d51426f66fb24c3777308acc8ae7ea6c\"\u003e\u003ccode\u003e4385c5f\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ccb4fd0158cd20800f6014496dccf7332e5b18ce\"\u003e\u003ccode\u003eccb4fd0\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/2958412f1817a0ad95c34066b7eb85781dd2d4f1\"\u003e\u003ccode\u003e2958412\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1215b94c2f7a8c4ce3863afbc38275a19c682a54\"\u003e\u003ccode\u003e1215b94\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1f0df621449e5de7dd13a1538e0343f65f0e6bb3\"\u003e\u003ccode\u003e1f0df62\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/13a9ff4c4ef982cda23b99fea89d2a4e87af9019\"\u003e\u003ccode\u003e13a9ff4\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/d168f9679ad575cdc2df8d53a8474ec481c7b5a7\"\u003e\u003ccode\u003ed168f96\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/eaf5c76b8e0a538729a1bf922061abf73b13f89b\"\u003e\u003ccode\u003eeaf5c76\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/e05ef4cbb4d534a82948f8ba84350e55493bc72e\"\u003e\u003ccode\u003ee05ef4c\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/f6d4000c1eb6d34e2ae24685a9790b1e833d4bcb\"\u003e\u003ccode\u003ef6d4000\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.22.2...jackson-databind-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.22.2\u0026new-version=2.22.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/s4u/pgpverify-maven-plugin/pull/736","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/s4u%2Fpgpverify-maven-plugin/issues/736","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/736/packages"},{"uuid":"5559967044","node_id":"PR_kwDOUTDGgM8AAAABE1DgVA","number":22,"state":"closed","title":"Bump the minor-and-patch group with 3 updates","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-09-30T03:54:18.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-23T21:50:07.000Z","updated_at":"2026-09-30T03:54:20.000Z","time_to_close":540251,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"minor-and-patch","update_count":3,"packages":[{"name":"org.jetbrains.kotlinx:kotlinx-serialization-json","old_version":"1.7.3","new_version":"1.11.0","repository_url":"https://github.com/Kotlin/kotlinx.serialization"},{"name":"org.jetbrains.kotlinx:kotlinx-coroutines-core","old_version":"1.9.0","new_version":"1.11.0","repository_url":"https://github.com/Kotlin/kotlinx.coroutines"},{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.18.2","new_version":"2.22.2","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":null,"ecosystem":"maven"},"body":"Bumps the minor-and-patch group with 3 updates: [org.jetbrains.kotlinx:kotlinx-serialization-json](https://github.com/Kotlin/kotlinx.serialization), [org.jetbrains.kotlinx:kotlinx-coroutines-core](https://github.com/Kotlin/kotlinx.coroutines) and [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind).\n\nUpdates `org.jetbrains.kotlinx:kotlinx-serialization-json` from 1.7.3 to 1.11.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/releases\"\u003eorg.jetbrains.kotlinx:kotlinx-serialization-json's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.11.0\u003c/h2\u003e\n\u003cp\u003eThis release is based on Kotlin 2.3.20 and provides a new Json exceptions API and some bugfixes and improvements.\u003c/p\u003e\n\u003ch2\u003eExpose Json exceptions structure\u003c/h2\u003e\n\u003cp\u003eTo make working with exceptions easier and providing proper error codes in e.g., REST APIs,\nclasses \u003ccode\u003eJsonException\u003c/code\u003e, \u003ccode\u003eJsonDecodingException\u003c/code\u003e, and \u003ccode\u003eJsonEncodingException\u003c/code\u003e are now public.\nThey have relevant public properties, such as \u003ccode\u003eshortMessage\u003c/code\u003e, \u003ccode\u003epath\u003c/code\u003e, \u003ccode\u003eoffset\u003c/code\u003e, and others.\nThis API is currently experimental, and we're going to improve it further in the subsequent releases.\nSee the linked issues for the details: \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/1930\"\u003e#1930\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/1877\"\u003e#1877\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eAbility to hide user input from exception messages for security/privacy reasons.\u003c/h2\u003e\n\u003cp\u003eHistorically, exception messages in kotlinx.serialization often included the input Json itself for debuggability reason.\nSuch behavior may pose additional challenges for logging, analytics, and other systems, since\na system is not always allowed to store user data due to privacy/security reasons, which imposes additional sanitation logic.\nTo address this issue, a new property \u003ccode\u003eexceptionsWithDebugInfo\u003c/code\u003e is added to \u003ccode\u003eJsonConfiguration\u003c/code\u003e.\nDisable it to hide user input from exception messages.\nIMPORTANT: This behavior will be enabled by default when this property becomes stable.\nSee \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/2590\"\u003e#2590\u003c/a\u003e for more details.\u003c/p\u003e\n\u003ch2\u003eBugfixes and improvements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCBOR: Relax value range check when decoding numbers (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3167\"\u003e#3167\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUse a specialized writeDecimalLong method for IO stream integrations in Json (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3152\"\u003e#3152\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.10.0\u003c/h2\u003e\n\u003cp\u003eThis release is based on Kotlin 2.3.0 and contains all of the changes from 1.10.0-RC.\nThe only additional change is a fix for ProtoBuf packing of Kotlin unsigned types (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3079\"\u003e#3079\u003c/a\u003e).\nBig thanks to \u003ca href=\"https://github.com/KosmX\"\u003eKosmX\u003c/a\u003e for contributing the fix.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eFor your convenience, the changelog for 1.10.0-RC is duplicated below:\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003eStabilization of APIs\u003c/h2\u003e\n\u003cp\u003ekotlinx-serialization 1.10 and subsequent releases will be focused on stabilization of existing APIs.\nThe following APIs and configuration options are no longer experimental because they're widely used without any known major issues:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eJson\u003c/code\u003e configuration options: \u003ccode\u003edecodeEnumsCaseInsensitive\u003c/code\u003e, \u003ccode\u003eallowTrailingComma\u003c/code\u003e, \u003ccode\u003eallowComments\u003c/code\u003e, and \u003ccode\u003eprettyPrintIndent\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3100\"\u003e#3100\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@EncodeDefault\u003c/code\u003e annotation and its modes. (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3106\"\u003e#3106\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eJsonUnquotedLiteral\u003c/code\u003e constructor function (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/2900\"\u003e#2900\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eJsonPrimitive\u003c/code\u003e constructor function overloads that accept unsigned types. (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3117\"\u003e#3117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eJSON DSL functions on \u003ccode\u003eJsonElement\u003c/code\u003e with \u003ccode\u003eNothing?\u003c/code\u003e overloads. (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3117\"\u003e#3117\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eReadiness for return value checker\u003c/h2\u003e\n\u003cp\u003eKotlin 2.3.0 \u003ca href=\"https://kotlinlang.org/docs/whatsnew23.html#unused-return-value-checker\"\u003eintroduces a new feature\u003c/a\u003e aimed at helping you to catch bugs related to the accidentally ignored return value of the function.\nkotlinx-serialization 1.10.0-RC code is fully marked for this feature, meaning that you can get warnings for unused function calls like \u003ccode\u003eJson.encodeToString(...)\u003c/code\u003e. To get the warnings, the feature has to be enabled in your project as \u003ca href=\"https://kotlinlang.org/docs/unused-return-value-checker.html#configure-the-unused-return-value-checker\"\u003edescribed here\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003ePolymorphism improvements\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/blob/master/CHANGELOG.md\"\u003eorg.jetbrains.kotlinx:kotlinx-serialization-json's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e1.11.0 / 2026-04-10\u003c/h1\u003e\n\u003cp\u003eThis release is based on Kotlin 2.3.20 and provides new Json exceptions API and some bugfixes and improvements.\u003c/p\u003e\n\u003ch2\u003eExpose Json exceptions structure\u003c/h2\u003e\n\u003cp\u003eTo make working with exceptions easier and providing proper error codes in e.g., REST APIs,\nclasses \u003ccode\u003eJsonException\u003c/code\u003e, \u003ccode\u003eJsonDecodingException\u003c/code\u003e, and \u003ccode\u003eJsonEncodingException\u003c/code\u003e are now public.\nThey have relevant public properties, such as \u003ccode\u003eshortMessage\u003c/code\u003e, \u003ccode\u003epath\u003c/code\u003e, \u003ccode\u003eoffset\u003c/code\u003e, and others.\nThis API is currently experimental, and we're going to improve it further in the subsequent releases.\nSee the linked issues for the details: \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/1930\"\u003e#1930\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/1877\"\u003e#1877\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eAbility to hide user input from exception messages for security/privacy reasons.\u003c/h2\u003e\n\u003cp\u003eHistorically, exception messages in kotlinx.serialization often included the input Json itself for debuggability reason.\nSuch behavior may pose additional challenges for logging, analytics, and other systems, since\na system is not always allowed to store user data due to privacy/security reasons, which imposes additional sanitation logic.\nTo address this issue, a new property \u003ccode\u003eexceptionsWithDebugInfo\u003c/code\u003e is added to \u003ccode\u003eJsonConfiguration\u003c/code\u003e.\nDisable it to hide user input from exception messages.\nIMPORTANT: This behavior will be enabled by default when this property becomes stable.\nSee \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/2590\"\u003e#2590\u003c/a\u003e for more details.\u003c/p\u003e\n\u003ch2\u003eBugfixes and improvements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCBOR: Relax value range check when decoding numbers (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3167\"\u003e#3167\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUse a specialized writeDecimalLong method for IO stream integrations in Json (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3152\"\u003e#3152\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e1.10.0 / 2026-01-21\u003c/h1\u003e\n\u003cp\u003eThis release is based on Kotlin 2.3.0 and contains all of the changes from 1.10.0-RC.\nThe only additional change is a fix for ProtoBuf packing of Kotlin unsigned types (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3079\"\u003e#3079\u003c/a\u003e).\nBig thanks to \u003ca href=\"https://github.com/KosmX\"\u003eKosmX\u003c/a\u003e for contributing the fix.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eFor your convenience, the changelog for 1.10.0-RC is duplicated below:\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003eStabilization of APIs\u003c/h2\u003e\n\u003cp\u003ekotlinx-serialization 1.10 and subsequent releases will be focused on stabilization of existing APIs.\nThe following APIs and configuration options are no longer experimental because they're widely used without any known major issues:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eJson\u003c/code\u003e configuration options: \u003ccode\u003edecodeEnumsCaseInsensitive\u003c/code\u003e, \u003ccode\u003eallowTrailingComma\u003c/code\u003e, \u003ccode\u003eallowComments\u003c/code\u003e, and \u003ccode\u003eprettyPrintIndent\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3100\"\u003e#3100\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@EncodeDefault\u003c/code\u003e annotation and its modes. (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3106\"\u003e#3106\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eJsonUnquotedLiteral\u003c/code\u003e constructor function (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/2900\"\u003e#2900\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eJsonPrimitive\u003c/code\u003e constructor function overloads that accept unsigned types. (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3117\"\u003e#3117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eJSON DSL functions on \u003ccode\u003eJsonElement\u003c/code\u003e with \u003ccode\u003eNothing?\u003c/code\u003e overloads. (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3117\"\u003e#3117\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eReadiness for return value checker\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/commit/6956af2e6073347c7832c3c5b374fa3b5a345956\"\u003e\u003ccode\u003e6956af2\u003c/code\u003e\u003c/a\u003e Prepare 1.11 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/commit/390d84c68a19cbf7fa453dec22a333648bde49b4\"\u003e\u003ccode\u003e390d84c\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'origin/master' into dev\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/commit/431fe2dc0a144300b33038820d24fc30302c8abc\"\u003e\u003ccode\u003e431fe2d\u003c/code\u003e\u003c/a\u003e Use local repo for publishing (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3171\"\u003e#3171\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/commit/05c12b60a6717b99053fb82e1f94d2f859727374\"\u003e\u003ccode\u003e05c12b6\u003c/code\u003e\u003c/a\u003e Add usage attribute to \u0026quot;testRepositories\u0026quot; configuration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/commit/a4e1f082ef2e72caa139b474c05657de6015da20\"\u003e\u003ccode\u003ea4e1f08\u003c/code\u003e\u003c/a\u003e Bump Kover version to 0.9.8 release (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3174\"\u003e#3174\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/commit/304e858ccc7066854637d86ab80056f5f2bcc094\"\u003e\u003ccode\u003e304e858\u003c/code\u003e\u003c/a\u003e Expose Json exceptions structure (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3145\"\u003e#3145\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/commit/4a0338ef5093d765138151bc30282e909ca459e4\"\u003e\u003ccode\u003e4a0338e\u003c/code\u003e\u003c/a\u003e Included G Play SDK verification file for core-jvm (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3169\"\u003e#3169\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/commit/421f64c74f0ea6d4a3cdc8dd483505366e3f6c8f\"\u003e\u003ccode\u003e421f64c\u003c/code\u003e\u003c/a\u003e CBOR: Relax value range check when decoding numbers (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3167\"\u003e#3167\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/commit/85a4f126ec491c77e2b3686cc22c1bae27a20783\"\u003e\u003ccode\u003e85a4f12\u003c/code\u003e\u003c/a\u003e KT-84955: mark apple x64 tagets as deprecated error\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/commit/bd38b0e49bce38d1a55576e89856bc63990167ed\"\u003e\u003ccode\u003ebd38b0e\u003c/code\u003e\u003c/a\u003e Remove dead code\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/compare/v1.7.3...v1.11.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.jetbrains.kotlinx:kotlinx-coroutines-core` from 1.9.0 to 1.11.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/releases\"\u003eorg.jetbrains.kotlinx:kotlinx-coroutines-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.11.0\u003c/h2\u003e\n\u003ch3\u003eVarious\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eKotlin was updated to 2.2.20 (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4545\"\u003e#4545\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImproved the published jar files (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/3842\"\u003e#3842\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4599\"\u003e#4599\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eVarious documentation improvements, including complete rewrites of structured concurrency and error handling-related KDoc (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4433\"\u003e#4433\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4596\"\u003e#4596\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBreaking changes and deprecations\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003ePromise\u003c/code\u003e-related functions from JS and Wasm/JS to the new \u003ccode\u003eweb\u003c/code\u003e target. On Wasm/JS, this is a breaking change. Before the change, \u003ccode\u003ePromise\u003c/code\u003e on Wasm/JS could work with arbitrary Kotlin types, but now, only \u003ccode\u003eJsAny\u003c/code\u003e subtypes are accepted (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4563\"\u003e#4563\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eChanged handling of coroutine exceptions that can't be propagated on JS and Wasm/JS. B\nefore, exceptions were logged, but now, they are reported to the JS runtime (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4451\"\u003e#4451\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4631\"\u003e#4631\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eDeprecated using \u003ccode\u003eCoroutineDispatcher\u003c/code\u003e as the coroutine context key; now, \u003ccode\u003eContinuationInterceptor\u003c/code\u003e has to be used instead (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4333\"\u003e#4333\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdvanced the deprecation levels on \u003ccode\u003ekotlinx-coroutines-test\u003c/code\u003e APIs (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4604\"\u003e#4604\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded lint functions that mark passing a \u003ccode\u003eJob\u003c/code\u003e to coroutine builders as deprecated (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4435\"\u003e#4435\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug fixes and improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded a \u003ccode\u003ecallsInPlace(EXACTLY_ONCE)\u003c/code\u003e contract to \u003ccode\u003erunBlocking\u003c/code\u003e in code shared between JVM and Native (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4368\"\u003e#4368\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded a \u003ccode\u003ecallsInPlace(EXACTLY_ONCE)\u003c/code\u003e contract to \u003ccode\u003esuspendCancellableCoroutine\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4574\"\u003e#4574\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eflowOn\u003c/code\u003e incorrectly handling \u003ccode\u003eThreadContextElement\u003c/code\u003e updates (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4403\"\u003e#4403\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed exceptions in user-supplied \u003ccode\u003eThread.UncaughtExceptionHandler\u003c/code\u003e instances causing the internal coroutines machinery to fail (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4516\"\u003e#4516\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eCoroutineDispatcher.asScheduler\u003c/code\u003e in the RxJava integration not cancelling outstanding work when a \u003ccode\u003eWorker\u003c/code\u003e gets cancelled, which led to memory leaks in some scenarios (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4615\"\u003e#4615\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eSharedFlow\u003c/code\u003e entering an invalid state when a subscriber and an emitter are cancelled simultaneously (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4583\"\u003e#4583\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed an R8 optimization leading to \u003ccode\u003eshareIn\u003c/code\u003e/\u003ccode\u003estateIn\u003c/code\u003e coroutines getting garbage-collected (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4646\"\u003e#4646\u003c/a\u003e). Thanks, \u003ca href=\"https://github.com/solevic\"\u003e\u003ccode\u003e@​solevic\u003c/code\u003e\u003c/a\u003e!\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSmall additions\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003eCompletableDeferred.asDeferred\u003c/code\u003e for obtaining a read-only \u003ccode\u003eDeferred\u003c/code\u003e view (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4408\"\u003e#4408\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eSharedFlow.asFlow\u003c/code\u003e for obtaining a \u003ccode\u003eFlow\u003c/code\u003e view with hidden hot flow semantics (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4530\"\u003e#4530\u003c/a\u003e). Thanks, \u003ca href=\"https://github.com/g000sha256\"\u003e\u003ccode\u003e@​g000sha256\u003c/code\u003e\u003c/a\u003e!\u003c/li\u003e\n\u003cli\u003eAdded a \u003ccode\u003eStateFlow.collectLatest\u003c/code\u003e overload returning \u003ccode\u003eNothing\u003c/code\u003e to assist with finding unreachable code (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4454\"\u003e#4454\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eReceiveChannel.consumeTo\u003c/code\u003e for consuming a \u003ccode\u003eReceiveChannel\u003c/code\u003e into a \u003ccode\u003eMutableCollection\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4520\"\u003e#4520\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded a \u003ccode\u003eStateFlow\u0026lt;T\u0026gt;.onSubscription\u003c/code\u003e overload returning a \u003ccode\u003eStateFlow\u0026lt;T\u0026gt;\u003c/code\u003e, similar to \u003ccode\u003eSharedFlow\u0026lt;T\u0026gt;.onSubscription\u003c/code\u003e returning \u003ccode\u003eSharedFlow\u0026lt;T\u0026gt;\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4275\"\u003e#4275\u003c/a\u003e). Thanks, \u003ca href=\"https://github.com/xit0c\"\u003e\u003ccode\u003e@​xit0c\u003c/code\u003e\u003c/a\u003e!\u003c/li\u003e\n\u003cli\u003eAdded terminal \u003ccode\u003eFlow\u003c/code\u003e operators for collecting a \u003ccode\u003eFlow\u003c/code\u003e to a \u003ccode\u003eMap\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/1541\"\u003e#1541\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChangelog relative to version 1.11.0\u003c/h3\u003e\n\u003cp\u003eNo changes, only the version is increased.\u003c/p\u003e\n\u003ch2\u003e1.11.0-rc02\u003c/h2\u003e\n\u003cp\u003eRestored binary compatibility with 1.10.2 and older versions on Wasm/JS for usages of \u003ccode\u003ePromise\u003c/code\u003e-related functions (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4661\"\u003e#4661\u003c/a\u003e).\u003c/p\u003e\n\u003ch2\u003e1.11.0-rc01\u003c/h2\u003e\n\u003ch3\u003eVarious\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eKotlin was updated to 2.2.20 (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4545\"\u003e#4545\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImproved the published jar files (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/3842\"\u003e#3842\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4599\"\u003e#4599\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eVarious documentation improvements, including complete rewrites of structured concurrency and error handling-related KDoc (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4433\"\u003e#4433\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4596\"\u003e#4596\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBreaking changes and deprecations\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/blob/master/CHANGES.md\"\u003eorg.jetbrains.kotlinx:kotlinx-coroutines-core's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 1.11.0\u003c/h2\u003e\n\u003ch3\u003eVarious\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eKotlin was updated to 2.2.20 (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4545\"\u003e#4545\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImproved the published jar files (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/3842\"\u003e#3842\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4599\"\u003e#4599\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eVarious documentation improvements, including complete rewrites of structured concurrency and error handling-related KDoc (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4433\"\u003e#4433\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4596\"\u003e#4596\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBreaking changes and deprecations\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003ePromise\u003c/code\u003e-related functions from JS and Wasm/JS to the new \u003ccode\u003eweb\u003c/code\u003e target. On Wasm/JS, this is a breaking change. Before the change, \u003ccode\u003ePromise\u003c/code\u003e on Wasm/JS could work with arbitrary Kotlin types, but now, only \u003ccode\u003eJsAny\u003c/code\u003e subtypes are accepted (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4563\"\u003e#4563\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eChanged handling of coroutine exceptions that can't be propagated on JS and Wasm/JS. Before, exceptions were logged, but now, they are reported to the JS runtime (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4451\"\u003e#4451\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4631\"\u003e#4631\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eDeprecated using \u003ccode\u003eCoroutineDispatcher\u003c/code\u003e as the coroutine context key; now, \u003ccode\u003eContinuationInterceptor\u003c/code\u003e has to be used instead (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4333\"\u003e#4333\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdvanced the deprecation levels on \u003ccode\u003ekotlinx-coroutines-test\u003c/code\u003e APIs (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4604\"\u003e#4604\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded lint functions that mark passing a \u003ccode\u003eJob\u003c/code\u003e to coroutine builders as deprecated (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4435\"\u003e#4435\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug fixes and improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded a \u003ccode\u003ecallsInPlace(EXACTLY_ONCE)\u003c/code\u003e contract to \u003ccode\u003erunBlocking\u003c/code\u003e in code shared between JVM and Native (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4368\"\u003e#4368\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded a \u003ccode\u003ecallsInPlace(EXACTLY_ONCE)\u003c/code\u003e contract to \u003ccode\u003esuspendCancellableCoroutine\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4574\"\u003e#4574\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eflowOn\u003c/code\u003e incorrectly handling \u003ccode\u003eThreadContextElement\u003c/code\u003e updates (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4403\"\u003e#4403\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed exceptions in user-supplied \u003ccode\u003eThread.UncaughtExceptionHandler\u003c/code\u003e instances causing the internal coroutines machinery to fail (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4516\"\u003e#4516\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eCoroutineDispatcher.asScheduler\u003c/code\u003e in the RxJava integration not cancelling outstanding work when a \u003ccode\u003eWorker\u003c/code\u003e gets cancelled, which led to memory leaks in some scenarios (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4615\"\u003e#4615\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eSharedFlow\u003c/code\u003e entering an invalid state when a subscriber and an emitter are cancelled simultaneously (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4583\"\u003e#4583\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed an R8 optimization leading to \u003ccode\u003eshareIn\u003c/code\u003e/\u003ccode\u003estateIn\u003c/code\u003e coroutines getting garbage-collected (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4646\"\u003e#4646\u003c/a\u003e). Thanks, \u003ca href=\"https://github.com/solevic\"\u003e\u003ccode\u003e@​solevic\u003c/code\u003e\u003c/a\u003e!\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSmall additions\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003eCompletableDeferred.asDeferred\u003c/code\u003e for obtaining a read-only \u003ccode\u003eDeferred\u003c/code\u003e view (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4408\"\u003e#4408\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eSharedFlow.asFlow\u003c/code\u003e for obtaining a \u003ccode\u003eFlow\u003c/code\u003e view with hidden hot flow semantics (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4530\"\u003e#4530\u003c/a\u003e). Thanks, \u003ca href=\"https://github.com/g000sha256\"\u003e\u003ccode\u003e@​g000sha256\u003c/code\u003e\u003c/a\u003e!\u003c/li\u003e\n\u003cli\u003eAdded a \u003ccode\u003eStateFlow.collectLatest\u003c/code\u003e overload returning \u003ccode\u003eNothing\u003c/code\u003e to assist with finding unreachable code (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4454\"\u003e#4454\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eReceiveChannel.consumeTo\u003c/code\u003e for consuming a \u003ccode\u003eReceiveChannel\u003c/code\u003e into a \u003ccode\u003eMutableCollection\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4520\"\u003e#4520\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded a \u003ccode\u003eStateFlow\u0026lt;T\u0026gt;.onSubscription\u003c/code\u003e overload returning a \u003ccode\u003eStateFlow\u0026lt;T\u0026gt;\u003c/code\u003e, similar to \u003ccode\u003eSharedFlow\u0026lt;T\u0026gt;.onSubscription\u003c/code\u003e returning \u003ccode\u003eSharedFlow\u0026lt;T\u0026gt;\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4275\"\u003e#4275\u003c/a\u003e). Thanks, \u003ca href=\"https://github.com/xit0c\"\u003e\u003ccode\u003e@​xit0c\u003c/code\u003e\u003c/a\u003e!\u003c/li\u003e\n\u003cli\u003eAdded terminal \u003ccode\u003eFlow\u003c/code\u003e operators for collecting a \u003ccode\u003eFlow\u003c/code\u003e to a \u003ccode\u003eMap\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/1541\"\u003e#1541\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChangelog relative to version 1.11.0\u003c/h3\u003e\n\u003cp\u003eNo changes, only the version is increased.\u003c/p\u003e\n\u003ch2\u003eVersion 1.11.0-rc02\u003c/h2\u003e\n\u003cp\u003eRestored binary compatibility with 1.10.2 and older versions on Wasm/JS for usages of \u003ccode\u003ePromise\u003c/code\u003e-related functions (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4661\"\u003e#4661\u003c/a\u003e).\u003c/p\u003e\n\u003ch2\u003eVersion 1.11.0-rc01\u003c/h2\u003e\n\u003ch3\u003eVarious\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eKotlin was updated to 2.2.20 (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4545\"\u003e#4545\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImproved the published jar files (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/3842\"\u003e#3842\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4599\"\u003e#4599\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eVarious documentation improvements, including complete rewrites of structured concurrency and error handling-related KDoc (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4433\"\u003e#4433\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4596\"\u003e#4596\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/commit/8564f65764d3d05893cec026c6e94250e2b23874\"\u003e\u003ccode\u003e8564f65\u003c/code\u003e\u003c/a\u003e Version 1.11.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/commit/a4c6af96c15fe30f5d4e8b810ea74f8babd5805c\"\u003e\u003ccode\u003ea4c6af9\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'origin/master' into develop\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/commit/ef917b460aa741691fbf991ee1b813049cae18c9\"\u003e\u003ccode\u003eef917b4\u003c/code\u003e\u003c/a\u003e KT-84955: mark apple x64 tagets as deprecated error (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4645\"\u003e#4645\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/commit/5ebc421e341bf2ddce734d369da87df1985e80bd\"\u003e\u003ccode\u003e5ebc421\u003c/code\u003e\u003c/a\u003e Update the release procedure description (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4670\"\u003e#4670\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/commit/95f46a073bc4a1230352108cea1835fd22219a80\"\u003e\u003ccode\u003e95f46a0\u003c/code\u003e\u003c/a\u003e Remove old maven repository settings (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4672\"\u003e#4672\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/commit/b4f4f0aa6acb692f3fbcadd70e4958e3e9d370fc\"\u003e\u003ccode\u003eb4f4f0a\u003c/code\u003e\u003c/a\u003e Fix package name of \u003ccode\u003eToMapCollectionSamplesTest\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4674\"\u003e#4674\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/commit/86738dca7dc9ac82249abc8206263fa0065ee631\"\u003e\u003ccode\u003e86738dc\u003c/code\u003e\u003c/a\u003e Added templates to the issue creation wizard (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4654\"\u003e#4654\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/commit/330fcc221fb583f0b119f34191f735a73b827378\"\u003e\u003ccode\u003e330fcc2\u003c/code\u003e\u003c/a\u003e Version 1.11.0-rc02\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/commit/e31cef6e9f2d26794be7d75ecbf3033b6432d582\"\u003e\u003ccode\u003ee31cef6\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'origin/master' into develop\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/commit/dc6e9f61eaf3a67f4bf474a7987aedc3f16cef37\"\u003e\u003ccode\u003edc6e9f6\u003c/code\u003e\u003c/a\u003e Restore Promise-related functions on Wasm/JS as HIDDEN (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4661\"\u003e#4661\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/compare/1.9.0...1.11.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.core:jackson-databind` from 2.18.2 to 2.22.2\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/25b2a221f9aa4107e455065a74635e209418cf55\"\u003e\u003ccode\u003e25b2a22\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.22.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bab1c1a702a941f8805ee6698e8fa4fdbfbec54a\"\u003e\u003ccode\u003ebab1c1a\u003c/code\u003e\u003c/a\u003e Prep for 2.22.2 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bc03cf83d74cf0e5944dce33a63ee59ddc344b64\"\u003e\u003ccode\u003ebc03cf8\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/83379fb6409075336edf3d8d88744e95911a43f8\"\u003e\u003ccode\u003e83379fb\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0d400c9dc586fdd460d0c6a40db21ebbe22106d8\"\u003e\u003ccode\u003e0d400c9\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ce36a279f8b078bef2d9d44a1d01034c3634f91a\"\u003e\u003ccode\u003ece36a27\u003c/code\u003e\u003c/a\u003e Merge branch '2.18' into 2.19\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7a209e1fa97033746db50fd7bcd1e3dbab077599\"\u003e\u003ccode\u003e7a209e1\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/a432707afe6b7569243d1c2d8052a1bf33d9279c\"\u003e\u003ccode\u003ea432707\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/176df1d48b256ced412c65293ad4e09393e24bd3\"\u003e\u003ccode\u003e176df1d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.18.10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7785f5f9ed24127e004115472c47b26ea4cf2774\"\u003e\u003ccode\u003e7785f5f\u003c/code\u003e\u003c/a\u003e Prep for 2.18.10 release\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.18.2...jackson-databind-2.22.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/tesser-payments/sdk-java/pull/22","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/tesser-payments%2Fsdk-java/issues/22","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/22/packages"},{"uuid":"5508754393","node_id":"PR_kwDOUhG-vM8AAAABEMhOdA","number":104,"state":"closed","title":"deps: bump com.fasterxml.jackson.core:jackson-databind from 2.18.2 to 2.22.2 in /langchain4j/18-ollama","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-19T08:47:15.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-19T08:13:41.000Z","updated_at":"2026-09-19T08:47:24.000Z","time_to_close":2014,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"deps","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.18.2","new_version":"2.22.2","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":"/langchain4j/18-ollama","ecosystem":"maven"},"body":"Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.18.2 to 2.22.2.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/25b2a221f9aa4107e455065a74635e209418cf55\"\u003e\u003ccode\u003e25b2a22\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.22.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bab1c1a702a941f8805ee6698e8fa4fdbfbec54a\"\u003e\u003ccode\u003ebab1c1a\u003c/code\u003e\u003c/a\u003e Prep for 2.22.2 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bc03cf83d74cf0e5944dce33a63ee59ddc344b64\"\u003e\u003ccode\u003ebc03cf8\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/83379fb6409075336edf3d8d88744e95911a43f8\"\u003e\u003ccode\u003e83379fb\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0d400c9dc586fdd460d0c6a40db21ebbe22106d8\"\u003e\u003ccode\u003e0d400c9\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ce36a279f8b078bef2d9d44a1d01034c3634f91a\"\u003e\u003ccode\u003ece36a27\u003c/code\u003e\u003c/a\u003e Merge branch '2.18' into 2.19\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7a209e1fa97033746db50fd7bcd1e3dbab077599\"\u003e\u003ccode\u003e7a209e1\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/a432707afe6b7569243d1c2d8052a1bf33d9279c\"\u003e\u003ccode\u003ea432707\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/176df1d48b256ced412c65293ad4e09393e24bd3\"\u003e\u003ccode\u003e176df1d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.18.10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7785f5f9ed24127e004115472c47b26ea4cf2774\"\u003e\u003ccode\u003e7785f5f\u003c/code\u003e\u003c/a\u003e Prep for 2.18.10 release\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.18.2...jackson-databind-2.22.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.18.2\u0026new-version=2.22.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/alxkm/java-ai-cookbook/pull/104","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/alxkm%2Fjava-ai-cookbook/issues/104","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/104/packages"},{"uuid":"5488468705","node_id":"PR_kwDOSO-pI88AAAABD8Jb4g","number":171,"state":"closed","title":"chore(deps): Bump the gradle-dependencies group across 1 directory with 9 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":"2026-09-29T19:36:51.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-17T14:06:36.000Z","updated_at":"2026-09-29T19:36:53.000Z","time_to_close":1056615,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): Bump","group_name":"gradle-dependencies","update_count":9,"packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.17.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-databind"},{"name":"org.jsoup:jsoup","old_version":"1.17.2","new_version":"1.23.2","repository_url":"https://github.com/jhy/jsoup"},{"name":"jakarta.persistence:jakarta.persistence-api","old_version":"3.1.0","new_version":"3.2.0","repository_url":"https://github.com/jakartaee/persistence"},{"name":"com.h2database:h2","old_version":"2.4.240","new_version":"2.5.252","repository_url":"https://github.com/h2database/h2database"},{"name":"software.amazon.awssdk:bom","old_version":"2.28.11","new_version":"2.55.6"},{"name":"jakarta.servlet:jakarta.servlet-api","old_version":"6.0.0","new_version":"6.1.0","repository_url":"https://github.com/eclipse-ee4j/servlet-api"},{"name":"com.fasterxml.jackson.datatype:jackson-datatype-jsr310","old_version":"2.17.2","new_version":"2.22.3"},{"name":"com.tngtech.archunit:archunit-junit5","old_version":"1.3.0","new_version":"1.5.1","repository_url":"https://github.com/TNG/ArchUnit"},{"name":"gradle-wrapper","old_version":"9.5.1","new_version":"9.8.0","repository_url":"https://github.com/gradle/gradle"}],"path":null,"ecosystem":"maven"},"body":"Bumps the gradle-dependencies group with 9 updates in the /NPDevGenerator directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) | `2.17.2` | `2.22.3` |\n| [org.jsoup:jsoup](https://github.com/jhy/jsoup) | `1.17.2` | `1.23.2` |\n| [jakarta.persistence:jakarta.persistence-api](https://github.com/jakartaee/persistence) | `3.1.0` | `3.2.0` |\n| [com.h2database:h2](https://github.com/h2database/h2database) | `2.4.240` | `2.5.252` |\n| software.amazon.awssdk:bom | `2.28.11` | `2.55.6` |\n| [jakarta.servlet:jakarta.servlet-api](https://github.com/eclipse-ee4j/servlet-api) | `6.0.0` | `6.1.0` |\n| com.fasterxml.jackson.datatype:jackson-datatype-jsr310 | `2.17.2` | `2.22.3` |\n| [com.tngtech.archunit:archunit-junit5](https://github.com/TNG/ArchUnit) | `1.3.0` | `1.5.1` |\n| [gradle-wrapper](https://github.com/gradle/gradle) | `9.5.1` | `9.8.0` |\n\n\nUpdates `com.fasterxml.jackson.core:jackson-databind` from 2.17.2 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/4385c5f7d51426f66fb24c3777308acc8ae7ea6c\"\u003e\u003ccode\u003e4385c5f\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ccb4fd0158cd20800f6014496dccf7332e5b18ce\"\u003e\u003ccode\u003eccb4fd0\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/2958412f1817a0ad95c34066b7eb85781dd2d4f1\"\u003e\u003ccode\u003e2958412\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1215b94c2f7a8c4ce3863afbc38275a19c682a54\"\u003e\u003ccode\u003e1215b94\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1f0df621449e5de7dd13a1538e0343f65f0e6bb3\"\u003e\u003ccode\u003e1f0df62\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/13a9ff4c4ef982cda23b99fea89d2a4e87af9019\"\u003e\u003ccode\u003e13a9ff4\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/d168f9679ad575cdc2df8d53a8474ec481c7b5a7\"\u003e\u003ccode\u003ed168f96\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/eaf5c76b8e0a538729a1bf922061abf73b13f89b\"\u003e\u003ccode\u003eeaf5c76\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/e05ef4cbb4d534a82948f8ba84350e55493bc72e\"\u003e\u003ccode\u003ee05ef4c\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/f6d4000c1eb6d34e2ae24685a9790b1e833d4bcb\"\u003e\u003ccode\u003ef6d4000\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.17.2...jackson-databind-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.jsoup:jsoup` from 1.17.2 to 1.23.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jhy/jsoup/releases\"\u003eorg.jsoup:jsoup's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ejsoup 1.23.2\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003ejsoup 1.23.2\u003c/strong\u003e is out now. This release focuses largely on bug fixes, specification correctness, and performance improvements.\u003c/p\u003e\n\u003cp\u003eIt brings closer alignment with the HTML, XML, URL, and form submission specifications; improves XML and W3C DOM conversion; and makes HTTP workloads more efficient through streamed request bodies and broader JDK \u003ccode\u003eHttpClient\u003c/code\u003e reuse.\u003c/p\u003e\n\u003cp\u003eThis version also includes new node insertion methods for \u003ccode\u003eElements\u003c/code\u003e, and DOM mutations now reject operations that would create a cycle.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003ejsoup\u003c/strong\u003e is a Java library for working with real-world HTML and XML. It provides a very convenient API for extracting and manipulating data, using the best of HTML5 DOM methods and CSS selectors.\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://jsoup.org/download\"\u003e\u003cstrong\u003eDownload\u003c/strong\u003e\u003c/a\u003e jsoup now.\u003c/p\u003e\n\u003ch2\u003eImprovements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved consecutive \u003ccode\u003eStreamParser.selectFirst()\u003c/code\u003e calls during progressive parsing, so later matches are returned with their parsed contents when earlier selections had left them as parser lookahead. E.g., given \u003ccode\u003e\u0026lt;title\u0026gt;One\u0026lt;/title\u0026gt;\u0026lt;p id=hit\u0026gt;Full\u0026lt;/p\u0026gt;\u0026lt;p\u0026gt;Next\u0026lt;/p\u0026gt;\u003c/code\u003e, selecting \u003ccode\u003etitle\u003c/code\u003e and then \u003ccode\u003e#hit\u003c/code\u003e now advances the partial lookahead and returns \u003ccode\u003e\u0026lt;p id=\u0026quot;hit\u0026quot;\u0026gt;Full\u0026lt;/p\u0026gt;\u003c/code\u003e, rather than returning an empty \u003ccode\u003e\u0026lt;p id=\u0026quot;hit\u0026quot;\u0026gt;\u0026lt;/p\u0026gt;\u003c/code\u003e before its content is parsed. The updated readiness tracking follows StreamParser's normal emission order across implicit HTML structure and parser recovery. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2551\"\u003e#2551\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eImproved XML parser performance and memory use for documents with many nested namespace declarations by recording namespace changes within each element scope. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2556\"\u003e#2556\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eImproved \u003ccode\u003eW3CDom\u003c/code\u003e conversion performance for documents with many nested namespace declarations. The W3C converter now uses the same optimized namespace tracking as the XML parser. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2559\"\u003e#2559\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eImproved \u003ccode\u003eW3CDom\u003c/code\u003e XML conversion to retain processing instructions, comments outside the root element, and CDATA sections, which were previously dropped or converted to text. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2572\"\u003e#2572\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eDOM mutation methods, including child insertion and replacement, now reject operations that would create a cycle, such as making a node its own child or moving an ancestor beneath a descendant. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2552\"\u003e#2552\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eElements#before(Node)\u003c/code\u003e, \u003ccode\u003eafter(Node)\u003c/code\u003e, \u003ccode\u003eprepend(Node)\u003c/code\u003e, and \u003ccode\u003eappend(Node)\u003c/code\u003e to match the existing HTML string methods. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/953\"\u003e#953\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eLarge file-backed uploads through \u003ccode\u003eConnection.requestBodyStream(InputStream)\u003c/code\u003e now stream directly with the JDK \u003ccode\u003eHttpClient\u003c/code\u003e on Java 11+, rather than being loaded fully into memory first. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2576\"\u003e#2575\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eExtended Java 11+ HTTP client reuse from requests sharing a \u003ccode\u003eJsoup.newSession()\u003c/code\u003e to ordinary \u003ccode\u003eJsoup.connect()\u003c/code\u003e calls, reducing transport thread and connection setup churn under sustained request loads. Sessions with custom authentication or SSL contexts continue to use their own client. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2584\"\u003e#2584\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eChanges\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAligned the XML parser stack depth and lookups to the configured maximum, which now defaults to 512 for both HTML and XML. Use \u003ccode\u003eParser#setMaxDepth(int)\u003c/code\u003e to configure. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2570\"\u003e#2570\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eW3CDom\u003c/code\u003e namespace conversion in several cases: \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2559\"\u003e#2559\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\n\u003cul\u003e\n\u003cli\u003eNamespace declarations and prefixed attributes now carry the correct namespace URI, so namespace-aware DOM lookups work as expected.\u003c/li\u003e\n\u003cli\u003eAttributes added after parsing, or included through subtree conversion, now use inherited prefix declarations.\u003c/li\u003e\n\u003cli\u003eNamespace declarations now apply regardless of attribute order, and an empty declaration shadows an inherited binding only within its scope.\u003c/li\u003e\n\u003cli\u003eWith namespace awareness disabled, inherited and undeclared prefixes now receive the declarations needed for XML serialization.\u003c/li\u003e\n\u003cli\u003eValid HTML names that are not XML QNames, such as \u003ccode\u003ea:b:c\u003c/code\u003e, are normalized. Attributes that still cannot be represented are skipped, and unrepresentable elements no longer change the surrounding tree.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eW3CDom\u003c/code\u003e conversion of programmatically created or renamed elements whose names can be represented in a jsoup HTML DOM but are not valid XML names, such as \u003ccode\u003e1abc\u003c/code\u003e. These names are now normalized (e.g. \u003ccode\u003e_1abc\u003c/code\u003e) instead of causing a \u003ccode\u003eNullPointerException\u003c/code\u003e. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2560\"\u003e#2560\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eFixed XML doctype serialization when a system identifier contains a double quote, which could otherwise produce invalid XML. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2571\"\u003e#2571\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eXML serialization now repairs element and attribute names that start with an invalid character, rather than outputting \u003ccode\u003enull\u003c/code\u003e elements or dropping attributes. For example, an attribute named \u003ccode\u003e1a\u003c/code\u003e is written as \u003ccode\u003e_1a\u003c/code\u003e. Additional leading underscores keep repaired attribute names unique if they conflict with another attribute. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2573\"\u003e#2573\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eSupplementary Unicode characters are now escaped correctly when serializing with non-UTF, non-ASCII output charsets such as ISO-8859-1. Previously, characters could be emitted unescaped when their low 16-bit value was representable by the configured charset, causing replacement or corruption when the output was encoded. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2578\"\u003e#2578\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eFixed the JDK \u003ccode\u003eHttpClient\u003c/code\u003e implementation to accept responses missing a \u003ccode\u003eContent-Type\u003c/code\u003e header, matching the \u003ccode\u003eHttpURLConnection\u003c/code\u003e implementation. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2549\"\u003e#2549\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eFixed HTTP response content-type matching to handle media types case-insensitively and recognize structured \u003ccode\u003e+xml\u003c/code\u003e suffixes, including vendor-specific media types. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2550\"\u003e#2550\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eHTTP request URL normalization now percent-encodes ASCII control characters, DEL, and embedded fragment delimiters, keeping normalized URLs valid for HTTP requests while preserving existing escapes. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2585\"\u003e#2585\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eCorrected multipart form encoding to percent-escape CR and LF in field names and filenames, matching the HTML form submission specification. Multipart file content-types containing CR or LF are now rejected with a \u003ccode\u003eValidationException\u003c/code\u003e. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2555\"\u003e#2555\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eAligned trailing comment placement with the HTML specification: comments after \u003ccode\u003e\u0026lt;/body\u0026gt;\u003c/code\u003e remain children of the \u003ccode\u003ehtml\u003c/code\u003e element, while comments after \u003ccode\u003e\u0026lt;/html\u0026gt;\u003c/code\u003e remain children of the document. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2557\"\u003e#2557\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eWhen using the optional \u003ccode\u003ere2j\u003c/code\u003e regular expression engine, memory allocation errors caused by complex selector patterns at match time are now normalized to a \u003ccode\u003eValidationException\u003c/code\u003e with a \u003ccode\u003ePattern complexity error\u003c/code\u003e message.\u003c/li\u003e\n\u003cli\u003eFixed parsing of malformed SVG and MathML content so that breakout HTML tags are placed according to the HTML specification. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2562\"\u003e#2562\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eFixed deeply nested malformed HTML parsing that could lose the document body because stack lookups did not align to the configured maximum parser depth. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2569\"\u003e#2569\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eAligned RCDATA, RAWTEXT, and script-data parsing with the HTML specification: malformed end tags no longer consume following markup, unclosed \u003ccode\u003etitle\u003c/code\u003e/\u003ccode\u003etextarea\u003c/code\u003e content stays text through EOF, and custom text tags match exact names. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2577\"\u003e#2577\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eImproved URL validation during HTTP/HTTPS URL resolution and cleaning; resolved URLs without a host are now rejected instead of being accepted based only on their scheme prefix, aligning to RFC 9110. Valid relative links and non-HTTP(S) schemes are unchanged. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2579\"\u003e#2579\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eRedirects with malformed single-slash HTTP locations now use standard URL resolution to align with browsers. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2580\"\u003e#2580\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eTemplate fragment parsing now handles unmatched \u003ccode\u003e\u0026lt;/template\u0026gt;\u003c/code\u003e tags without throwing a \u003ccode\u003eValidationException\u003c/code\u003e. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2581\"\u003e#2581\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eImproved source tracking for adopted formatting elements and malformed markup ending at EOF. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2582\"\u003e#2582\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jhy/jsoup/blob/master/CHANGES.md\"\u003eorg.jsoup:jsoup's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.23.2 (2026-Aug-26)\u003c/h2\u003e\n\u003ch3\u003eImprovements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImproved consecutive \u003ccode\u003eStreamParser.selectFirst(...)\u003c/code\u003e calls during progressive parsing, so later matches are returned with their parsed contents when earlier selections had left them as parser lookahead. E.g., given \u003ccode\u003e\u0026lt;title\u0026gt;One\u0026lt;/title\u0026gt;\u0026lt;p id=hit\u0026gt;Full\u0026lt;/p\u0026gt;\u0026lt;p\u0026gt;Next\u0026lt;/p\u0026gt;\u003c/code\u003e, selecting \u003ccode\u003etitle\u003c/code\u003e and then \u003ccode\u003e#hit\u003c/code\u003e now advances the partial lookahead and returns \u003ccode\u003e\u0026lt;p id=\u0026quot;hit\u0026quot;\u0026gt;Full\u0026lt;/p\u0026gt;\u003c/code\u003e, rather than returning an empty \u003ccode\u003e\u0026lt;p id=\u0026quot;hit\u0026quot;\u0026gt;\u0026lt;/p\u0026gt;\u003c/code\u003e before its content is parsed. The updated readiness tracking follows StreamParser's normal emission order across implicit HTML structure and parser recovery. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2551\"\u003e#2551\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved XML parser performance and memory use for documents with many nested namespace declarations by recording namespace changes within each element scope. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2556\"\u003e#2556\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved \u003ccode\u003eW3CDom\u003c/code\u003e conversion performance for documents with many nested namespace declarations. The W3C converter now uses the same optimized namespace tracking as the XML parser. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2559\"\u003e#2559\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved \u003ccode\u003eW3CDom\u003c/code\u003e XML conversion to retain processing instructions, comments outside the root element, and CDATA sections, which were previously dropped or converted to text. \u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2572\"\u003e#2572\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDOM mutation methods, including child insertion and replacement, now reject operations that would create a cycle, such as making a node its own child or moving an ancestor beneath a descendant. \u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2552\"\u003e#2552\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eElements#before(Node)\u003c/code\u003e, \u003ccode\u003eafter(Node)\u003c/code\u003e, \u003ccode\u003eprepend(Node)\u003c/code\u003e, and \u003ccode\u003eappend(Node)\u003c/code\u003e to match the existing HTML string methods. \u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/953\"\u003e#953\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eLarge file-backed uploads through \u003ccode\u003eConnection.requestBodyStream(InputStream)\u003c/code\u003e now stream directly with the JDK \u003ccode\u003eHttpClient\u003c/code\u003e on Java 11+, rather than being loaded fully into memory first. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2576\"\u003e#2575\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExtended Java 11+ HTTP client reuse from requests sharing a \u003ccode\u003eJsoup.newSession()\u003c/code\u003e to ordinary \u003ccode\u003eJsoup.connect(...)\u003c/code\u003e calls, reducing transport thread and connection setup churn under sustained request loads. Sessions with custom authentication or SSL contexts continue to use their own client. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2584\"\u003e#2584\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanges\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAligned the XML parser stack depth and lookups to the configured maximum, which now defaults to 512 for both HTML and XML. Use \u003ccode\u003eParser#setMaxDepth(int)\u003c/code\u003e to configure. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2570\"\u003e#2570\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eW3CDom\u003c/code\u003e namespace conversion in several cases: \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2559\"\u003e#2559\u003c/a\u003e\n\u003cul\u003e\n\u003cli\u003eNamespace declarations and prefixed attributes now carry the correct namespace URI, so namespace-aware DOM lookups work as expected.\u003c/li\u003e\n\u003cli\u003eAttributes added after parsing, or included through subtree conversion, now use inherited prefix declarations.\u003c/li\u003e\n\u003cli\u003eNamespace declarations now apply regardless of attribute order, and an empty declaration shadows an inherited binding only within its scope.\u003c/li\u003e\n\u003cli\u003eWith namespace awareness disabled, inherited and undeclared prefixes now receive the declarations needed for XML serialization.\u003c/li\u003e\n\u003cli\u003eValid HTML names that are not XML QNames, such as \u003ccode\u003ea:b:c\u003c/code\u003e, are normalized. Attributes that still cannot be represented are skipped, and unrepresentable elements no longer change the surrounding tree.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eW3CDom\u003c/code\u003e conversion of programmatically created or renamed elements whose names can be represented in a jsoup HTML DOM but are not valid XML names, such as \u003ccode\u003e1abc\u003c/code\u003e. These names are now normalized (e.g. \u003ccode\u003e_1abc\u003c/code\u003e) instead of causing a \u003ccode\u003eNullPointerException\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2560\"\u003e#2560\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed XML doctype serialization when a system identifier contains a double quote, which could otherwise produce invalid XML. \u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2571\"\u003e#2571\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eXML serialization now repairs element and attribute names that start with an invalid character, rather than outputting \u003ccode\u003enull\u003c/code\u003e elements or dropping attributes. For example, an attribute named \u003ccode\u003e1a\u003c/code\u003e is written as \u003ccode\u003e_1a\u003c/code\u003e. Additional leading underscores keep repaired attribute names unique if they conflict with another attribute. \u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2573\"\u003e#2573\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupplementary Unicode characters are now escaped correctly when serializing with non-UTF, non-ASCII output charsets such as ISO-8859-1. Previously, characters could be emitted unescaped when their low 16-bit value was representable by the configured charset, causing replacement or corruption when the output was encoded. \u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2578\"\u003e#2578\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed the JDK \u003ccode\u003eHttpClient\u003c/code\u003e implementation to accept responses missing a \u003ccode\u003eContent-Type\u003c/code\u003e header, matching the \u003ccode\u003eHttpURLConnection\u003c/code\u003e implementation. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2549\"\u003e#2549\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed HTTP response content-type matching to handle media types case-insensitively and recognize structured \u003ccode\u003e+xml\u003c/code\u003e suffixes, including vendor-specific media types. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2550\"\u003e#2550\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHTTP request URL normalization now percent-encodes ASCII control characters, DEL, and embedded fragment delimiters, keeping normalized URLs valid for HTTP requests while preserving existing escapes. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2585\"\u003e#2585\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCorrected multipart form encoding to percent-escape CR and LF in field names and filenames, matching the HTML form submission specification. Multipart file content-types containing CR or LF are now rejected with a \u003ccode\u003eValidationException\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2555\"\u003e#2555\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAligned trailing comment placement with the HTML specification: comments after \u003ccode\u003e\u0026lt;/body\u0026gt;\u003c/code\u003e remain children of the \u003ccode\u003ehtml\u003c/code\u003e element, while comments after \u003ccode\u003e\u0026lt;/html\u0026gt;\u003c/code\u003e remain children of the document. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2557\"\u003e#2557\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWhen using the optional \u003ccode\u003ere2j\u003c/code\u003e regular expression engine, memory allocation errors caused by complex selector patterns at match time are now normalized to a \u003ccode\u003eValidationException\u003c/code\u003e with a \u003ccode\u003ePattern complexity error\u003c/code\u003e message.\u003c/li\u003e\n\u003cli\u003eFixed parsing of malformed SVG and MathML content so that breakout HTML tags are placed according to the HTML specification. \u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2562\"\u003e#2562\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed deeply nested malformed HTML parsing that could lose the document body because stack lookups did not align to the configured maximum parser depth. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2569\"\u003e#2569\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAligned RCDATA, RAWTEXT, and script-data parsing with the HTML specification: malformed end tags no longer consume following markup, unclosed \u003ccode\u003etitle\u003c/code\u003e/\u003ccode\u003etextarea\u003c/code\u003e content stays text through EOF, and custom text tags match exact names. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2577\"\u003e#2577\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved URL validation during HTTP/HTTPS URL resolution and cleaning; resolved URLs without a host are now rejected instead of being accepted based only on their scheme prefix, aligning to RFC 9110. Valid relative links and non-HTTP(S) schemes are unchanged. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2579\"\u003e#2579\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRedirects with malformed single-slash HTTP locations now use standard URL resolution to align with browsers. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2580\"\u003e#2580\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTemplate fragment parsing now handles unmatched \u003ccode\u003e\u0026lt;/template\u0026gt;\u003c/code\u003e tags without throwing a \u003ccode\u003eValidationException\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2581\"\u003e#2581\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved source tracking for adopted formatting elements and malformed markup ending at EOF. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2582\"\u003e#2582\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.23.1 (2026-Jul-30)\u003c/h2\u003e\n\u003ch3\u003eImprovements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReduced retained memory when parsing with source position tracking enabled (\u003ccode\u003eParser#setTrackPosition(true)\u003c/code\u003e). Source ranges are now stored in compact parser-owned span records instead of node and attribute user data, and \u003ccode\u003ePosition\u003c/code\u003e objects are created lazily when source ranges are read. This cuts tracked DOM retained size by about 50-60% on representative benchmark documents, while keeping \u003ccode\u003eNode#sourceRange()\u003c/code\u003e, \u003ccode\u003eElement#endSourceRange()\u003c/code\u003e, and \u003ccode\u003eAttribute#sourceRange()\u003c/code\u003e behavior intact. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2498\"\u003e#2498\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eElement#classList()\u003c/code\u003e, an immutable snapshot of an element's class names in attribute order. Use \u003ccode\u003ehasClass()\u003c/code\u003e when you just need to test for one class, \u003ccode\u003eclassList()\u003c/code\u003e when you want to read or iterate classes without needing a mutable result, and \u003ccode\u003eclassNames()\u003c/code\u003e when you want the existing mutable, deduplicated set that can be written back with \u003ccode\u003eclassNames(Set)\u003c/code\u003e. The class APIs now share an HTML-whitespace scanner, which also makes \u003ccode\u003eclassNames()\u003c/code\u003e faster and lighter on allocation, especially when walking many elements without class names. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2500\"\u003e#2500\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAligned HTML parser scope classification with the current HTML spec for \u003ccode\u003eselect\u003c/code\u003e, \u003ccode\u003eforeignObject\u003c/code\u003e, and \u003ccode\u003etemplate\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2501\"\u003e#2501\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSimplified the HTML tree builder's scope, implied-end-tag, and special-element checks by caching parser-only options on Tag. That improves HTML parser throughput by about 10% on small inputs and up to about 30% on larger inputs in the benchmark fixtures. \u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2502\"\u003e#2502\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved HTML parser throughput stability by making hot tokeniser scan paths compile more predictably. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2507\"\u003e#2507\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e\u0026lt;noscript\u0026gt;\u003c/code\u003e fallback markup is now parsed into an inspectable DOM subtree in both the document head and body. The fallback acts as a contained parsing island, so malformed markup cannot disrupt the surrounding document structure, while normal HTML tokenization still applies within it. This also improves round-trip serialization. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2537\"\u003e#2537\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved redirect credential handling as a defense-in-depth measure: explicit authorization headers and request cookies are no longer forwarded across origins, reducing exposure through open redirects and aligning with HTTP guidance. Cookies managed by a \u003ccode\u003eCookieStore\u003c/code\u003e continue to follow their configured scope. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2540\"\u003e#2540\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jhy/jsoup/commit/fbc7775c462f5b023d8db54c9a73d7ec17d53300\"\u003e\u003ccode\u003efbc7775\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jsoup-1.23.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jhy/jsoup/commit/133ebde65afda061ea12818e1e65a53f5d822ea4\"\u003e\u003ccode\u003e133ebde\u003c/code\u003e\u003c/a\u003e Release 1.23.2 notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jhy/jsoup/commit/be2a74a1f6b3ad9cf2d3aeaac3f68b6c39929bc5\"\u003e\u003ccode\u003ebe2a74a\u003c/code\u003e\u003c/a\u003e Encode control chars during request URL normalization (\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2585\"\u003e#2585\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jhy/jsoup/commit/868f2eb1e6c9a2b826cd56f92b336fdbd616b241\"\u003e\u003ccode\u003e868f2eb\u003c/code\u003e\u003c/a\u003e Java 11 HTTP client reuse covers ordinary connections (\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2584\"\u003e#2584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jhy/jsoup/commit/19c758e2e4abc6a1f52193ceab09c22a7c010f8b\"\u003e\u003ccode\u003e19c758e\u003c/code\u003e\u003c/a\u003e Get Animal Sniffer to run over test code as well.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jhy/jsoup/commit/17bb839aa5aa1519c729d78656d18adefee730cf\"\u003e\u003ccode\u003e17bb839\u003c/code\u003e\u003c/a\u003e Fix source tracking through HTML repair and malformed EOF (\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2582\"\u003e#2582\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jhy/jsoup/commit/cad054a61f3ae241a741b6658c50d6f962dfd43c\"\u003e\u003ccode\u003ecad054a\u003c/code\u003e\u003c/a\u003e Template stack checks need to exclude the fragment context (\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2581\"\u003e#2581\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jhy/jsoup/commit/46b620860af930eedc193a705eaf7cea5aec89a6\"\u003e\u003ccode\u003e46b6208\u003c/code\u003e\u003c/a\u003e Paranoimia\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jhy/jsoup/commit/66be2da4e2bd7a207700a4cc9c867d15ae74a587\"\u003e\u003ccode\u003e66be2da\u003c/code\u003e\u003c/a\u003e HTTP redirects use standard URL resolution for single-slash locations (\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2580\"\u003e#2580\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jhy/jsoup/commit/b035b623d3d1d0c50d84056d2946ba1a90f7f665\"\u003e\u003ccode\u003eb035b62\u003c/code\u003e\u003c/a\u003e Make hostless HTTP(S) URLs fail resolution and cleaning (\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2579\"\u003e#2579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/jhy/jsoup/compare/jsoup-1.17.2...jsoup-1.23.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `jakarta.persistence:jakarta.persistence-api` from 3.1.0 to 3.2.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jakartaee/persistence/releases\"\u003ejakarta.persistence:jakarta.persistence-api's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eJakarta Persistence 3.2.0-M01\u003c/h2\u003e\n\u003cp\u003eThis release contains following changes:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdds factory-level access to named queries and named entity graphs\u003c/li\u003e\n\u003cli\u003eUpdates orm schema for 3.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/jakartaee/persistence/compare/3.2-DRAFT01-3.2.0-B02-RELEASE...3.2-M1-3.2.0-M1-RELEASE\"\u003ehttps://github.com/jakartaee/persistence/compare/3.2-DRAFT01-3.2.0-B02-RELEASE...3.2-M1-3.2.0-M1-RELEASE\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eJakarta Persistence 3.1.0 API\u003c/h2\u003e\n\u003cp\u003eThis release contains following changes:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eEntityManagerFactory and EntityManager interfaces extends java.lang.AutoCloseable interface\u003c/li\u003e\n\u003cli\u003eFixes ClassTransformer.transform to throw Persistence API specific exception\u003c/li\u003e\n\u003cli\u003eAdds support for java.util.UUID and GenerationType.UUID\u003c/li\u003e\n\u003cli\u003eAdds CEILING, EXP, FLOOR, LN, POWER, ROUND, and SIGN numeric functions to Jakarta Persistence QL and ceiling(), exp(), floor(), ln(), power(),  round(), and sign() to Criteria API\u003c/li\u003e\n\u003cli\u003eAdds LOCAL DATE, LOCAL DATETIME, and LOCAL TIME functions to Jakarta Persistence QL and corresponding localDate(), localDateTime(), and localTime() to Criteria API\u003c/li\u003e\n\u003cli\u003eAdds EXTRACT function to Jakarta Persistence QL\u003c/li\u003e\n\u003cli\u003eAdds support for Expressions as conditions in Criteria CASE expressions\u003c/li\u003e\n\u003cli\u003eAdds missing definition of single_valued_embeddable_object_field in Jakarta Persistence QL BNF\u003c/li\u003e\n\u003cli\u003eClarifies mixing types of query input parameters\u003c/li\u003e\n\u003cli\u003eClarifies definition of the Basic type\u003c/li\u003e\n\u003cli\u003eClarifies the order of parameters in the LOCATE function\u003c/li\u003e\n\u003cli\u003eClarifies SqlResultSetMapping with multiple EntityResults and conflicting aliases\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/scottmarlow\"\u003e\u003ccode\u003e@​scottmarlow\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/m0mus\"\u003e\u003ccode\u003e@​m0mus\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pzygielo\"\u003e\u003ccode\u003e@​pzygielo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hebo6\"\u003e\u003ccode\u003e@​hebo6\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/moghaddam\"\u003e\u003ccode\u003e@​moghaddam\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/manouti\"\u003e\u003ccode\u003e@​manouti\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jbescos\"\u003e\u003ccode\u003e@​jbescos\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gavinking\"\u003e\u003ccode\u003e@​gavinking\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/dazey3\"\u003e\u003ccode\u003e@​dazey3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/DmitriGit\"\u003e\u003ccode\u003e@​DmitriGit\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sebersole\"\u003e\u003ccode\u003e@​sebersole\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eProject Board\u003c/strong\u003e: \u003ca href=\"https://github.com/eclipse-ee4j/jpa-api/projects/2\"\u003ehttps://github.com/eclipse-ee4j/jpa-api/projects/2\u003c/a\u003e\n\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/eclipse-ee4j/jpa-api/commits/3.1-3.1.0-RELEASE\"\u003ehttps://github.com/eclipse-ee4j/jpa-api/commits/3.1-3.1.0-RELEASE\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/jakartaee/persistence/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.h2database:h2` from 2.4.240 to 2.5.252\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/h2database/h2database/releases\"\u003ecom.h2database:h2's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 2.5.252\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eversion-2.5.250\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/h2database/h2database/commit/f986838bbbf4941d2edcd5298b18c9936d1b7359\"\u003e\u003ccode\u003ef986838\u003c/code\u003e\u003c/a\u003e in preparation for a release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/h2database/h2database/commit/06c34a7fa288208ecabb5d670555fd807270bb2a\"\u003e\u003ccode\u003e06c34a7\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/h2database/h2database/issues/4418\"\u003e#4418\u003c/a\u003e from andreitokar/issues-4380-4376\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/h2database/h2database/commit/1aef3e0692b7379402b2a1a14e5223a8911e31ec\"\u003e\u003ccode\u003e1aef3e0\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://redirect.github.com/h2database/h2database/issues/4376\"\u003e#4376\u003c/a\u003e: Reading INFORMATION_SCHEMA.COLUMNS fails with a NPE while any material...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/h2database/h2database/commit/4bb8aee6bf4305a83e79b6a93e9e3781f904fed9\"\u003e\u003ccode\u003e4bb8aee\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://redirect.github.com/h2database/h2database/issues/4380\"\u003e#4380\u003c/a\u003e: creating a MATERIALIZED VIEW makes a persistent database permanently u...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/h2database/h2database/commit/95b6af03b8768d770e5dac1ae829b7c15301b38e\"\u003e\u003ccode\u003e95b6af0\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/h2database/h2database/issues/4417\"\u003e#4417\u003c/a\u003e from andreitokar/issue-4395\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/h2database/h2database/commit/6ec30b66b68a298d6cfc424aa77fec90ebf05199\"\u003e\u003ccode\u003e6ec30b6\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://redirect.github.com/h2database/h2database/issues/4395\"\u003e#4395\u003c/a\u003e disallow constraints between temporary and permanent tables\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/h2database/h2database/commit/0f0f85605084bd4eaad8f6a467ff802161048b60\"\u003e\u003ccode\u003e0f0f856\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/h2database/h2database/issues/4416\"\u003e#4416\u003c/a\u003e from andreitokar/issue-4405\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/h2database/h2database/commit/f718b764c6d53e160f94d05003eae81d554ec253\"\u003e\u003ccode\u003ef718b76\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://redirect.github.com/h2database/h2database/issues/4405\"\u003e#4405\u003c/a\u003e SecureFileStore.readFully() may skip decryption\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/h2database/h2database/commit/e231ff7def4c280ffb845cb0b6e92fb9686867d1\"\u003e\u003ccode\u003ee231ff7\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://redirect.github.com/h2database/h2database/issues/4405\"\u003e#4405\u003c/a\u003e SecureFileStore.readFully() may skip\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/h2database/h2database/commit/4da0d1d02b4e860d6c2e68ff2de0c11c0a19011c\"\u003e\u003ccode\u003e4da0d1d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/h2database/h2database/issues/4415\"\u003e#4415\u003c/a\u003e from jjh75607/fix/log-sql-aarch64\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/h2database/h2database/compare/version-2.4.240...version-2.5.252\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `software.amazon.awssdk:bom` from 2.28.11 to 2.55.6\n\nUpdates `jakarta.servlet:jakarta.servlet-api` from 6.0.0 to 6.1.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/eclipse-ee4j/servlet-api/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.datatype:jackson-datatype-jsr310` from 2.17.2 to 2.22.3\n\nUpdates `com.tngtech.archunit:archunit-junit5` from 1.3.0 to 1.5.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/TNG/ArchUnit/releases\"\u003ecom.tngtech.archunit:archunit-junit5's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eArchUnit 1.5.1\u003c/h2\u003e\n\u003ch1\u003eBug fixes\u003c/h1\u003e\n\u003ch2\u003eCore\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: include java.lang.IO in ACCESS_STANDARD_STREAMS (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1687\"\u003e#1687\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/arimu1\"\u003e\u003ccode\u003e@​arimu1\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003cli\u003eCount caught exception types as type dependencies (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1725\"\u003e#1725\u003c/a\u003e; by \u003ca href=\"https://github.com/schulzjo-tng\"\u003e\u003ccode\u003e@​schulzjo-tng\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003eInternal Improvements\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003epublish archunit-junit-relocation (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1684\"\u003e#1684\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/hankem\"\u003e\u003ccode\u003e@​hankem\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eArchUnit 1.5.0\u003c/h2\u003e\n\u003ch1\u003eEnhancements\u003c/h1\u003e\n\u003ch2\u003eCore\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSupport Java 27 / class file major version 71 (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1618\"\u003e#1618\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eImprove descriptions of \u003ccode\u003eJavaAccess.Predicates.originOwner\u003c/code\u003e and \u003ccode\u003eJavaAccess.Predicates.targetOwner\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1603\"\u003e#1603\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/StefanGraeber\"\u003e\u003ccode\u003e@​StefanGraeber\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003cli\u003eExpose information on sealed classes via \u003ccode\u003eJavaClass\u003c/code\u003e: \u003ccode\u003eisSealed()\u003c/code\u003e and \u003ccode\u003egetPermittedSubclasses()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1677\"\u003e#1677\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eConsider dependencies from caught exceptions (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1555\"\u003e#1555\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/bannmann\"\u003e\u003ccode\u003e@​bannmann\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eImportOption.DoNotIncludeTests\u003c/code\u003e and \u003ccode\u003eOnlyIncludeTests\u003c/code\u003e consider tests in custom Gradle source sets (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1660\"\u003e#1660\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/Develop-KIM\"\u003e\u003ccode\u003e@​Develop-KIM\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eLang\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eArchConditions\u003c/code\u003e offers new \u003ccode\u003eArchCondition\u0026lt;JavaClass\u0026gt; haveAnyDependenciesThat(DescribedPredicate\u0026lt;Dependency\u0026gt;)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1580\"\u003e#1580\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/wakingrufus\"\u003e\u003ccode\u003e@​wakingrufus\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eLibrary\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eArchitectureMetrics.lakosMetrics\u003c/code\u003e is computed much more performantly (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1629\"\u003e#1629\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/ThanosTsiamis\"\u003e\u003ccode\u003e@​ThanosTsiamis\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eTextFileBasedViolationStore\u003c/code\u003e is now thread-safe under parallel test execution (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1656\"\u003e#1656\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/kelunik\"\u003e\u003ccode\u003e@​kelunik\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eModuleDependency\u003c/code\u003e now provides stable descriptions (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1648\"\u003e#1648\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/DragonFSKY\"\u003e\u003ccode\u003e@​DragonFSKY\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eJUnit\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003earchunit-junit6\u003c/code\u003e supports ArchUnit with JUnit 6 (\u003cdel\u003e\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1556\"\u003e#1556\u003c/a\u003e\u003c/del\u003e, \u003cdel\u003e\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1658\"\u003e#1658\u003c/a\u003e\u003c/del\u003e, \u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1659\"\u003e#1659\u003c/a\u003e; many thanks to \u003ca href=\"https://github.com/arukiidou\"\u003e\u003ccode\u003e@​arukiidou\u003c/code\u003e\u003c/a\u003e \u0026amp; \u003ca href=\"https://github.com/schulzjo-tng\"\u003e\u003ccode\u003e@​schulzjo-tng\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eAnalyzeClasses\u003c/code\u003e supports individual classes (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1569\"\u003e#1569\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/TheManWhoStaresAtCode\"\u003e\u003ccode\u003e@​TheManWhoStaresAtCode\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003cli\u003e\u003cem\u003ePreparation:\u003c/em\u003e \u003ccode\u003earchunit-junit:0.9.0\u003c/code\u003e (which was renamed with \u003ca href=\"https://github.com/TNG/ArchUnit/releases/tag/v0.9.0\"\u003eArchUnit 0.9.0\u003c/a\u003e) now relocates to \u003ccode\u003earchunit-junit4:0.9.0\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1673\"\u003e#1673\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/schulzjo-tng\"\u003e\u003ccode\u003e@​schulzjo-tng\u003c/code\u003e\u003c/a\u003e 👋) – will be published after \u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1684\"\u003e#1684\u003c/a\u003e 🙈\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDocument \u003ccode\u003ePriority\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1671\"\u003e#1671\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/TheManWhoStaresAtCode\"\u003e\u003ccode\u003e@​TheManWhoStaresAtCode\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003cli\u003eDocument Package Identifiers in User Guide (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1672\"\u003e#1672\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/TheManWhoStaresAtCode\"\u003e\u003ccode\u003e@​TheManWhoStaresAtCode\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003eInternal Improvements\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eText files now use UNIX line breaks (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1602\"\u003e#1602\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1611\"\u003e#1611\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/StefanGraeber\"\u003e\u003ccode\u003e@​StefanGraeber\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003cli\u003eUpdate Gradle from 8 to 9; build \u0026amp; test with JDK 25 (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1550\"\u003e#1550\u003c/a\u003e, and also \u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1612\"\u003e#1612\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1619\"\u003e#1619\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSeparate integration tests by JUnit version (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1636\"\u003e#1636\u003c/a\u003e; many thanks to \u003ca href=\"https://github.com/schulzjo-tng\"\u003e\u003ccode\u003e@​schulzjo-tng\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003cli\u003eReplace \u003ccode\u003ejunit-dataprovider\u003c/code\u003e with \u003ccode\u003ejunit-jupiter-params\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1655\"\u003e#1655\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eArchUnit releases now update Maven examples (and Gradle wrapper) of \u003ca href=\"https://github.com/TNG/ArchUnit-Examples\"\u003eArchUnit-Examples\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1450\"\u003e#1450\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAvoid managing hamcrest dependency (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1467\"\u003e#1467\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/TheManWhoStaresAtCode\"\u003e\u003ccode\u003e@​TheManWhoStaresAtCode\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eArchUnit 1.4.2\u003c/h2\u003e\n\u003ch1\u003eEnhancements\u003c/h1\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TNG/ArchUnit/commit/6c2d659e5681b50541930d236a8c46aed5e44a5c\"\u003e\u003ccode\u003e6c2d659\u003c/code\u003e\u003c/a\u003e prepare release 1.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TNG/ArchUnit/commit/d5ff41705236bcf28e9a7d5cce6b13be0db57f12\"\u003e\u003ccode\u003ed5ff417\u003c/code\u003e\u003c/a\u003e set snapshot version to 1.5.1 in preparation of release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TNG/ArchUnit/commit/aee04c59826199d0b78ab8ea90faac075dae19a8\"\u003e\u003ccode\u003eaee04c5\u003c/code\u003e\u003c/a\u003e Update Gradle Wrapper from 9.7.1 to 9.8.0 (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1727\"\u003e#1727\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TNG/ArchUnit/commit/73535afce1abf70d758148ba507d2695080167ae\"\u003e\u003ccode\u003e73535af\u003c/code\u003e\u003c/a\u003e Update Gradle Wrapper from 9.7.1 to 9.8.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TNG/ArchUnit/commit/058f709a1579daca48b7d052ace91dc92f0d2055\"\u003e\u003ccode\u003e058f709\u003c/code\u003e\u003c/a\u003e Count caught exception types as type dependencies (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1732\"\u003e#1732\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1725\"\u003e#1725\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TNG/ArchUnit/commit/fbcc47c56d6461d0bb096324bfb4b7a277bf7fcf\"\u003e\u003ccode\u003efbcc47c\u003c/code\u003e\u003c/a\u003e Count caught exception types as type dependencies (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1732\"\u003e#1732\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TNG/ArchUnit/commit/e78e136dd8df91d4dcdcd9aa082c0fd6b925d8cc\"\u003e\u003ccode\u003ee78e136\u003c/code\u003e\u003c/a\u003e Bump io.github.ben-manes.versions from 0.63.0 to 0.64.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TNG/ArchUnit/commit/a0a8aff514d948615e7de2ed067e9f651a466a44\"\u003e\u003ccode\u003ea0a8aff\u003c/code\u003e\u003c/a\u003e Bump io.github.ben-manes.versions from 0.62.0 to 0.63.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TNG/ArchUnit/commit/d30f80da632d38ceb1bf24239579d1b2da803173\"\u003e\u003ccode\u003ed30f80d\u003c/code\u003e\u003c/a\u003e Bump io.github.ben-manes.versions from 0.61.0 to 0.62.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TNG/ArchUnit/commit/22c0f6a5eebfa79ab24c376938d69af41d3e7cbd\"\u003e\u003ccode\u003e22c0f6a\u003c/code\u003e\u003c/a\u003e Bump actions/setup-java from 6.0.0 to 6.0.1\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/TNG/ArchUnit/compare/v1.3.0...v1.5.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `gradle-wrapper` from 9.5.1 to 9.8.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/gradle/gradle/releases\"\u003egradle-wrapper's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e9.8.0\u003c/h2\u003e\n\u003cp\u003eThe Gradle team is excited to announce Gradle 9.8.0.\u003c/p\u003e\n\u003cp\u003eHere are the highlights of this release:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eJava 27 support\u003c/li\u003e\n\u003cli\u003eMaven mirror settings reuse\u003c/li\u003e\n\u003cli\u003eLinked problem locations in build output\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://docs.gradle.org/9.8.0/release-notes.html\"\u003eRead the Release Notes\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eWe would like to thank the following community members for their contributions to this release of Gradle:\n\u003ca href=\"https://github.com/Gautam-aman\"\u003eAman Gautam\u003c/a\u003e,\n\u003ca href=\"https://github.com/Vampire\"\u003eBjörn Kautler\u003c/a\u003e,\n\u003ca href=\"https://github.com/Juneezee\"\u003eEng Zer Jun\u003c/a\u003e,\n\u003ca href=\"https://github.com/Hashim1999164\"\u003eHashim Khan\u003c/a\u003e,\n\u003ca href=\"https://github.com/jkrannich\"\u003eJulian Krannich\u003c/a\u003e,\n\u003ca href=\"https://github.com/youdie006\"\u003eKBS\u003c/a\u003e,\n\u003ca href=\"https://github.com/itsCodeTide\"\u003eLabh R Jethe\u003c/a\u003e,\n\u003ca href=\"https://github.com/doddi\"\u003eMark Dodgson\u003c/a\u003e,\n\u003ca href=\"https://github.com/kroune\"\u003eMaxim\u003c/a\u003e,\n\u003ca href=\"https://github.com/Develop-KIM\"\u003emonkey\u003c/a\u003e,\n\u003ca href=\"https://github.com/nataphon-ktsystems\"\u003enataphon-ktsystems\u003c/a\u003e,\n\u003ca href=\"https://github.com/paulk-asert\"\u003ePaul King\u003c/a\u003e,\n\u003ca href=\"https://github.com/qiu-tiandev\"\u003eQiu Tian\u003c/a\u003e,\n\u003ca href=\"https://github.com/sandeshgorde\"\u003erg_sandesh\u003c/a\u003e,\n\u003ca href=\"https://github.com/rpalcolea\"\u003eRoberto Perez Alcolea\u003c/a\u003e,\n\u003ca href=\"https://github.com/seanxuu\"\u003eSean\u003c/a\u003e,\n\u003ca href=\"https://github.com/Goooler\"\u003eZongle Wang\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eUpgrade instructions\u003c/h2\u003e\n\u003cp\u003eSwitch your build to use Gradle 9.8.0 by updating your wrapper:\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e./gradlew :wrapper --gradle-version=9.8.0 \u0026amp;\u0026amp; ./gradlew :wrapper\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eSee the Gradle \u003ca href=\"https://docs.gradle.org/9.8.0/userguide/upgrading_version_9.html\"\u003e9.x upgrade guide\u003c/a\u003e to learn about deprecations, breaking changes and other considerations when upgrading.\u003c/p\u003e\n\u003cp\u003eFor Java, Groovy, Kotlin and Android compatibility, see the \u003ca href=\"https://docs.gradle.org/9.8.0/userguide/compatibility.html\"\u003efull compatibility notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eReporting problems\u003c/h2\u003e\n\u003cp\u003eIf you find a problem with this release, please file a bug on \u003ca href=\"https://github.com/gradle/gradle/issues\"\u003eGitHub Issues\u003c/a\u003e adhering to our issue guidelines.\nIf you're not sure you're encountering a bug, please use the \u003ca href=\"https://discuss.gradle.org/c/help-discuss\"\u003eforum\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eWe hope you will build happiness with Gradle, and we look forward to your feedback via \u003ca href=\"https://twitter.com/gradle\"\u003eTwitter\u003c/a\u003e or on \u003ca href=\"https://github.com/gradle\"\u003eGitHub\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003e9.8.0 RC3\u003c/h2\u003e\n\u003cp\u003eThe Gradle team is excited to announce Gradle 9.8.0 RC3.\u003c/p\u003e\n\u003cp\u003eHere are the highlights of this release:\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/a927be5e08efe79e0b87ada06c762dde6bb9f8b8\"\u003e\u003ccode\u003ea927be5\u003c/code\u003e\u003c/a\u003e Add the Develocity plugin back to the Android smoke tests (\u003ca href=\"https://redirect.github.com/gradle/gradle/issues/39273\"\u003e#39273\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/eaee500e6a2fff583b9d2b81039fc15ad887462d\"\u003e\u003ccode\u003eeaee500\u003c/code\u003e\u003c/a\u003e Add the Develocity plugin back to the Android smoke tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/189b672308d1e997fae46412673d04683d76b35a\"\u003e\u003ccode\u003e189b672\u003c/code\u003e\u003c/a\u003e Route everything still hitting Maven Central through the mirror (\u003ca href=\"https://redirect.github.com/gradle/gradle/issues/39257\"\u003e#39257\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/36b181477307fc6db0e16582f11daaeb7e34fc8e\"\u003e\u003ccode\u003e36b1814\u003c/code\u003e\u003c/a\u003e Add back mavenCentral to doc snippets\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/2740c2d9cd0a9ab42813be77241fdc264217b2ba\"\u003e\u003ccode\u003e2740c2d\u003c/code\u003e\u003c/a\u003e Update Gradle wrapper to version 9.8.0-rc-3 (\u003ca href=\"https://redirect.github.com/gradle/gradle/issues/39264\"\u003e#39264\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/209938316e373c847aa1a251ec14eeded3da468e\"\u003e\u003ccode\u003e2099383\u003c/code\u003e\u003c/a\u003e Update Gradle wrapper to version 9.8.0-rc-3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/c80202fbd1cc457d7f45f31fc488391c4a2e7984\"\u003e\u003ccode\u003ec80202f\u003c/code\u003e\u003c/a\u003e Route everything still hitting Maven Central through the mirror\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/3f6a53434a2cf4f33486af2ae5eabd1fc830352d\"\u003e\u003ccode\u003e3f6a534\u003c/code\u003e\u003c/a\u003e Fix when a best practice was introduced (\u003ca href=\"https://redirect.github.com/gradle/gradle/issues/39253\"\u003e#39253\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/9efc9eddac43f0795194e407c0ab2177a1d23cf9\"\u003e\u003ccode\u003e9efc9ed\u003c/code\u003e\u003c/a\u003e Fix when a best practice was introduced\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/459e1433c60e4a604dd39ffe2c49e3606f70acda\"\u003e\u003ccode\u003e459e143\u003c/code\u003e\u003c/a\u003e Route integration test dependencies through the repository mirror (\u003ca href=\"https://redirect.github.com/gradle/gradle/issues/39239\"\u003e#39239\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/gradle/gradle/compare/v9.5.1...v9.8.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n","html_url":"https://github.com/MarceloGiazzon/NPDevGeneral/pull/171","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/MarceloGiazzon%2FNPDevGeneral/issues/171","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/171/packages"},{"uuid":"5481940218","node_id":"PR_kwDOPeN7rM8AAAABD25YmQ","number":438,"state":"closed","title":"build(deps): bump the gradle-production-dependencies group across 3 directories with 25 updates","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-18T02:07:20.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-17T02:06:50.000Z","updated_at":"2026-09-18T02:07:22.000Z","time_to_close":86430,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"gradle-production-dependencies","update_count":25,"packages":[{"name":"io.opentelemetry:opentelemetry-bom","old_version":"1.53.0","new_version":"1.66.0","repository_url":"https://github.com/open-telemetry/opentelemetry-java"},{"name":"io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom","old_version":"2.18.1","new_version":"2.31.1","repository_url":"https://github.com/open-telemetry/opentelemetry-java-instrumentation"},{"name":"com.google.api.grpc:proto-google-common-protos","old_version":"2.60.0","new_version":"2.76.0","repository_url":"https://github.com/googleapis/google-cloud-java"},{"name":"com.google.protobuf:protobuf-java","old_version":"4.31.1","new_version":"4.36.1","repository_url":"https://github.com/protocolbuffers/protobuf"},{"name":"com.google.protobuf:protoc","old_version":"4.31.1","new_version":"4.36.1","repository_url":"https://github.com/protocolbuffers/protobuf"},{"name":"io.grpc:grpc-protobuf","old_version":"1.74.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc-java"},{"name":"io.grpc:grpc-stub","old_version":"1.74.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc-java"},{"name":"io.grpc:grpc-netty","old_version":"1.74.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc-java"},{"name":"io.grpc:grpc-services","old_version":"1.74.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc-java"},{"name":"io.grpc:protoc-gen-grpc-java","old_version":"1.74.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc-java"},{"name":"io.grpc:grpc-stub","old_version":"1.74.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc-java"},{"name":"io.grpc:grpc-netty","old_version":"1.74.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc-java"},{"name":"io.grpc:grpc-services","old_version":"1.74.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc-java"},{"name":"org.apache.logging.log4j:log4j-core","old_version":"2.25.1","new_version":"2.26.1"},{"name":"dev.openfeature.contrib.providers:flagd","old_version":"0.11.14","new_version":"0.14.1","repository_url":"https://github.com/open-feature/java-sdk-contrib"},{"name":"dev.openfeature:sdk","old_version":"1.17.0","new_version":"1.22.1","repository_url":"https://github.com/open-feature/java-sdk"},{"name":"com.fasterxml.jackson.core:jackson-core","old_version":"2.19.2","new_version":"2.22.2","repository_url":"https://github.com/FasterXML/jackson-core"},{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.19.2","new_version":"2.22.2","repository_url":"https://github.com/FasterXML/jackson-databind"},{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.19.2","new_version":"2.22.2","repository_url":"https://github.com/FasterXML/jackson-databind"},{"name":"io.netty:netty-tcnative-boringssl-static","old_version":"2.0.72.Final","new_version":"2.0.84.Final","repository_url":"https://github.com/netty/netty-tcnative"},{"name":"com.google.protobuf:protoc","old_version":"4.31.1","new_version":"4.36.1","repository_url":"https://github.com/protocolbuffers/protobuf"},{"name":"io.grpc:protoc-gen-grpc-java","old_version":"1.74.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc-java"},{"name":"com.google.protobuf","old_version":"0.9.5","new_version":"0.10.0"},{"name":"com.github.ben-manes.versions","old_version":"0.52.0","new_version":"0.62.0"},{"name":"gradle-wrapper","old_version":"8.12.1","new_version":"9.7.1","repository_url":"https://github.com/gradle/gradle"}],"path":null,"ecosystem":"maven"},"body":"Bumps the gradle-production-dependencies group with 19 updates in the /src/ad directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [io.opentelemetry:opentelemetry-bom](https://github.com/open-telemetry/opentelemetry-java) | `1.53.0` | `1.66.0` |\n| [io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom](https://github.com/open-telemetry/opentelemetry-java-instrumentation) | `2.18.1` | `2.31.1` |\n| [com.google.api.grpc:proto-google-common-protos](https://github.com/googleapis/google-cloud-java) | `2.60.0` | `2.76.0` |\n| [com.google.protobuf:protobuf-java](https://github.com/protocolbuffers/protobuf) | `4.31.1` | `4.36.1` |\n| [com.google.protobuf:protoc](https://github.com/protocolbuffers/protobuf) | `4.31.1` | `4.36.1` |\n| [io.grpc:grpc-protobuf](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:grpc-stub](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:grpc-netty](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:grpc-services](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:protoc-gen-grpc-java](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:grpc-stub](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:grpc-netty](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:grpc-services](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| org.apache.logging.log4j:log4j-core | `2.25.1` | `2.26.1` |\n| [dev.openfeature.contrib.providers:flagd](https://github.com/open-feature/java-sdk-contrib) | `0.11.14` | `0.14.1` |\n| [dev.openfeature:sdk](https://github.com/open-feature/java-sdk) | `1.17.0` | `1.22.1` |\n| [com.fasterxml.jackson.core:jackson-core](https://github.com/FasterXML/jackson-core) | `2.19.2` | `2.22.2` |\n| [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) | `2.19.2` | `2.22.2` |\n| [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) | `2.19.2` | `2.22.2` |\n| [io.netty:netty-tcnative-boringssl-static](https://github.com/netty/netty-tcnative) | `2.0.72.Final` | `2.0.84.Final` |\n| [com.google.protobuf:protoc](https://github.com/protocolbuffers/protobuf) | `4.31.1` | `4.36.1` |\n| [io.grpc:protoc-gen-grpc-java](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| com.google.protobuf | `0.9.5` | `0.10.0` |\n| com.github.ben-manes.versions | `0.52.0` | `0.62.0` |\n| [gradle-wrapper](https://github.com/gradle/gradle) | `8.12.1` | `9.7.1` |\n\nBumps the gradle-production-dependencies group with 19 updates in the /src/fraud-detection directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [com.google.api.grpc:proto-google-common-protos](https://github.com/googleapis/google-cloud-java) | `2.60.0` | `2.76.0` |\n| [com.google.protobuf:protobuf-java](https://github.com/protocolbuffers/protobuf) | `4.31.1` | `4.36.1` |\n| com.google.protobuf:protobuf-kotlin | `4.31.1` | `4.36.1` |\n| [com.google.protobuf:protoc](https://github.com/protocolbuffers/protobuf) | `4.31.1` | `4.36.1` |\n| [io.grpc:grpc-protobuf](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:grpc-stub](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:grpc-netty](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:grpc-services](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:protoc-gen-grpc-java](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:grpc-stub](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:grpc-netty](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:grpc-services](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| org.apache.logging.log4j:log4j-core | `2.25.1` | `2.26.1` |\n| [dev.openfeature.contrib.providers:flagd](https://github.com/open-feature/java-sdk-contrib) | `0.11.14` | `0.14.1` |\n| [dev.openfeature:sdk](https://github.com/open-feature/java-sdk) | `1.17.0` | `1.22.1` |\n| [com.google.protobuf:protoc](https://github.com/protocolbuffers/protobuf) | `4.31.1` | `4.36.1` |\n| [io.grpc:protoc-gen-grpc-java](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| com.google.protobuf | `0.9.5` | `0.10.0` |\n| [gradle-wrapper](https://github.com/gradle/gradle) | `8.12.1` | `9.7.1` |\n| org.apache.kafka:kafka-clients | `4.0.0` | `4.3.1` |\n| [io.opentelemetry:opentelemetry-api](https://github.com/open-telemetry/opentelemetry-java) | `1.53.0` | `1.66.0` |\n| [io.opentelemetry:opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-java) | `1.53.0` | `1.66.0` |\n| org.slf4j:slf4j-api | `2.0.17` | `2.0.19` |\n| com.google.protobuf:protobuf-kotlin | `4.31.1` | `4.36.1` |\n| jvm | `2.2.10` | `2.4.20` |\n\nBumps the gradle-production-dependencies group with 1 update in the /src/react-native-app/android directory: [gradle-wrapper](https://github.com/gradle/gradle).\n\nUpdates `io.opentelemetry:opentelemetry-bom` from 1.53.0 to 1.66.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/releases\"\u003eio.opentelemetry:opentelemetry-bom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 1.66.0\u003c/h2\u003e\n\u003ch3\u003eAPI\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eBaggage.fromContext()\u003c/code\u003e and \u003ccode\u003eBaggage.fromContextOrNull()\u003c/code\u003e to handle a \u003ccode\u003enull\u003c/code\u003e context (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8667\"\u003e#8667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDo not percent-encode W3C baggage metadata (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8682\"\u003e#8682\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eArrayIndexOutOfBoundsException\u003c/code\u003e in \u003ccode\u003eOtelEncodingUtils\u003c/code\u003e for invalid hex characters (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8748\"\u003e#8748\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSDK\u003c/h3\u003e\n\u003ch4\u003eTraces\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eRecord processed spans before export completes and reject new spans on shutdown in \u003ccode\u003eSpanProcessor\u003c/code\u003e self-observability instrumentation (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8735\"\u003e#8735\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eMetrics\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eImprove explicit bucket histogram contention performance (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8717\"\u003e#8717\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eLogs\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eRecord processed logs before export completes and reject new logs on shutdown in \u003ccode\u003eLogRecordProcessor\u003c/code\u003e self-observability instrumentation (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8698\"\u003e#8698\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eExporters\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eOTLP: Respect \u003ccode\u003eRetry-After\u003c/code\u003e in OTLP HTTP senders (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8633\"\u003e#8633\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Add \u003ccode\u003esetEnabledProtocols\u003c/code\u003e option to OTLP HTTP exporter builders (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8610\"\u003e#8610\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Reject mixing \u003ccode\u003ekeyManager\u003c/code\u003e and \u003ccode\u003esslContext\u003c/code\u003e in \u003ccode\u003eTlsConfigHelper\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8710\"\u003e#8710\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Fix \u003ccode\u003eOkHttpGrpcSender\u003c/code\u003e mTLS when using the platform default trust store (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8758\"\u003e#8758\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Suppress instrumentation of exporter requests in \u003ccode\u003eJdkHttpSender\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8757\"\u003e#8757\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Accept RFC 1123 hostnames in \u003ccode\u003eEndpointUtil.validateEndpoint\u003c/code\u003e for OkHttp senders (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8746\"\u003e#8746\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Include the number of affected items in exporter error logging (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8780\"\u003e#8780\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Add \u003ccode\u003etoString\u003c/code\u003e to \u003ccode\u003eOtlpJsonLogging{Span,Metric,LogRecord}Exporter\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8725\"\u003e#8725\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP Profiles: Improve JFR export example and align \u003ccode\u003eLinkData\u003c/code\u003e null-element handling with the spec (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8349\"\u003e#8349\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrometheus: Remove default host log warning in \u003ccode\u003ePrometheusHttpServerBuilder\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8679\"\u003e#8679\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrometheus: Align UCUM byte unit conversions with the specification table (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8752\"\u003e#8752\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eExtensions\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eBREAKING\u003c/strong\u003e Declarative config: Rename generated model POJO setters from \u003ccode\u003ewith\u0026lt;Prop\u0026gt;\u003c/code\u003e to \u003ccode\u003eset\u0026lt;Prop\u0026gt;\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8742\"\u003e#8742\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeclarative config: Resolve experimental properties on stable APIs in generated model POJOs (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8654\"\u003e#8654\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeclarative config: Fix inverted \u003ccode\u003escope_info_enabled\u003c/code\u003e and \u003ccode\u003etarget_info_enabled\u003c/code\u003e flags in the Prometheus component provider (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8750\"\u003e#8750\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeclarative config: Support \u003ccode\u003eoutput_stream\u003c/code\u003e in \u003ccode\u003eotlp_file/development\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8676\"\u003e#8676\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eIncubator: Add \u003ccode\u003etoString\u003c/code\u003e to \u003ccode\u003eComposableAnnotatingSampler\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8645\"\u003e#8645\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eProject tooling\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemediate \u003ccode\u003ezizmor\u003c/code\u003e findings in GitHub Actions workflows (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8592\"\u003e#8592\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🙇 Thank you\u003c/h3\u003e\n\u003cp\u003eThis release was possible thanks to the following contributors who shared their brilliant ideas and awesome pull requests:\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/blob/main/CHANGELOG.md\"\u003eio.opentelemetry:opentelemetry-bom's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 1.66.0 (2026-09-11)\u003c/h2\u003e\n\u003ch3\u003eAPI\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eBaggage.fromContext()\u003c/code\u003e and \u003ccode\u003eBaggage.fromContextOrNull()\u003c/code\u003e to handle a \u003ccode\u003enull\u003c/code\u003e context\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8667\"\u003e#8667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDo not percent-encode W3C baggage metadata\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8682\"\u003e#8682\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eArrayIndexOutOfBoundsException\u003c/code\u003e in \u003ccode\u003eOtelEncodingUtils\u003c/code\u003e for invalid hex characters\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8748\"\u003e#8748\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSDK\u003c/h3\u003e\n\u003ch4\u003eTraces\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eRecord processed spans before export completes and reject new spans on shutdown in\n\u003ccode\u003eSpanProcessor\u003c/code\u003e self-observability instrumentation\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8735\"\u003e#8735\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eMetrics\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eImprove explicit bucket histogram contention performance\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8717\"\u003e#8717\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eLogs\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eRecord processed logs before export completes and reject new logs on shutdown in\n\u003ccode\u003eLogRecordProcessor\u003c/code\u003e self-observability instrumentation\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8698\"\u003e#8698\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eExporters\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eOTLP: Respect \u003ccode\u003eRetry-After\u003c/code\u003e in OTLP HTTP senders\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8633\"\u003e#8633\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Add \u003ccode\u003esetEnabledProtocols\u003c/code\u003e option to OTLP HTTP exporter builders\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8610\"\u003e#8610\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Reject mixing \u003ccode\u003ekeyManager\u003c/code\u003e and \u003ccode\u003esslContext\u003c/code\u003e in \u003ccode\u003eTlsConfigHelper\u003c/code\u003e\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8710\"\u003e#8710\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Fix \u003ccode\u003eOkHttpGrpcSender\u003c/code\u003e mTLS when using the platform default trust store\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8758\"\u003e#8758\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Suppress instrumentation of exporter requests in \u003ccode\u003eJdkHttpSender\u003c/code\u003e\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8757\"\u003e#8757\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Accept RFC 1123 hostnames in \u003ccode\u003eEndpointUtil.validateEndpoint\u003c/code\u003e for OkHttp senders\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8746\"\u003e#8746\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Include the number of affected items in exporter error logging\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8780\"\u003e#8780\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Add \u003ccode\u003etoString\u003c/code\u003e to \u003ccode\u003eOtlpJsonLogging{Span,Metric,LogRecord}Exporter\u003c/code\u003e\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8725\"\u003e#8725\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP Profiles: Improve JFR export example and align \u003ccode\u003eLinkData\u003c/code\u003e null-element handling with the\nspec (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8349\"\u003e#8349\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/commit/300a35830e29f94a173479c3c91dff72ae37c5fc\"\u003e\u003ccode\u003e300a358\u003c/code\u003e\u003c/a\u003e [release/v1.66.x] Prepare release 1.66.0 (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/issues/8799\"\u003e#8799\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/commit/dd711061cc7b1a5343168b43c112d7c687321fa4\"\u003e\u003ccode\u003edd71106\u003c/code\u003e\u003c/a\u003e Prepare for 1.66.0 release (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/issues/8795\"\u003e#8795\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/commit/9284265a4c059cb224f34f0bd58cb31fc6465d60\"\u003e\u003ccode\u003e9284265\u003c/code\u003e\u003c/a\u003e Manual 1.65.0 post release (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/issues/8794\"\u003e#8794\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/commit/10c7338cc9b10e29579fc4321408c3f6aa788c9a\"\u003e\u003ccode\u003e10c7338\u003c/code\u003e\u003c/a\u003e Align UCUM byte unit conversions with the specification table (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/issues/8752\"\u003e#8752\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/commit/bf1a64c3039a850900a02e47c0b599324af11b94\"\u003e\u003ccode\u003ebf1a64c\u003c/code\u003e\u003c/a\u003e Accept RFC 1123 hostnames in EndpointUtil.validateEndpoint (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/issues/8746\"\u003e#8746\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/commit/ab72956777e6f63e2ca44924b282838d7ca38220\"\u003e\u003ccode\u003eab72956\u003c/code\u003e\u003c/a\u003e Add number of affected items to Exporter error logging (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/issues/8780\"\u003e#8780\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/commit/275fe927de1ec59471d006fea23372474471eeb1\"\u003e\u003ccode\u003e275fe92\u003c/code\u003e\u003c/a\u003e Update dependency com.squareup.wire:wire-bom to v7 (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/issues/8793\"\u003e#8793\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/commit/050f481512b4850c5b539aac50bf1ba2b0cbfa5b\"\u003e\u003ccode\u003e050f481\u003c/code\u003e\u003c/a\u003e Remove unused parameter from B3 propagation integration tests (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/issues/8791\"\u003e#8791\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/commit/8d7bd65e03d5e1c5846b5c20d1c89a36899a7a97\"\u003e\u003ccode\u003e8d7bd65\u003c/code\u003e\u003c/a\u003e Improve explicit histogram contention performance (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/issues/8717\"\u003e#8717\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/commit/2c880d9dcd30798660f8ad8d55ed4c6d31092863\"\u003e\u003ccode\u003e2c880d9\u003c/code\u003e\u003c/a\u003e Rename inverted grpc detection test in GrpcJavaOtlpIntegrationTest (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/issues/8790\"\u003e#8790\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/compare/v1.53.0...v1.66.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom` from 2.18.1 to 2.31.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/releases\"\u003eio.opentelemetry.instrumentation:opentelemetry-instrumentation-bom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 2.31.1\u003c/h2\u003e\n\u003cp\u003eThis release targets the OpenTelemetry SDK 1.65.0.\u003c/p\u003e\n\u003cp\u003eNote that many artifacts have the \u003ccode\u003e-alpha\u003c/code\u003e suffix attached to their version number, reflecting that they will continue to have breaking changes. Please see \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/blob/main/VERSIONING.md#opentelemetry-java-instrumentation-versioning\"\u003eVERSIONING.md\u003c/a\u003e for more details.\u003c/p\u003e\n\u003ch3\u003e🛠️ Bug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRestore stable semantic convention APIs to the compile classpaths of the Spring Boot autoconfigure and starter artifacts. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19754\"\u003e#19754\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 2.31.0\u003c/h2\u003e\n\u003cp\u003eThis release targets the OpenTelemetry SDK 1.65.0.\u003c/p\u003e\n\u003cp\u003eNote that many artifacts have the \u003ccode\u003e-alpha\u003c/code\u003e suffix attached to their version number, reflecting that they will continue to have breaking changes. Please see \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/blob/main/VERSIONING.md#opentelemetry-java-instrumentation-versioning\"\u003eVERSIONING.md\u003c/a\u003e for more details.\u003c/p\u003e\n\u003ch3\u003e⚠️ Breaking changes to non-stable APIs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemove the deprecated \u003ccode\u003eConfigPropertiesBackedConfigProvider\u003c/code\u003e and its \u003ccode\u003ecreate(ConfigProperties)\u003c/code\u003e compatibility API from the declarative config bridge. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19305\"\u003e#19305\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eStop exposing \u003ccode\u003eopentelemetry-instrumentation-api-incubator\u003c/code\u003e on library instrumentation compile classpaths. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19612\"\u003e#19612\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🚫 Deprecations\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eotel.instrumentation.experimental.span-suppression-strategy\u003c/code\u003e in favor of \u003ccode\u003eExperimental.setSpanSuppressionStrategy(...)\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19180\"\u003e#19180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eHostIdResource.REGISTRY_QUERY\u003c/code\u003e in favor of the absolute-path \u003ccode\u003ereg.exe\u003c/code\u003e lookup used by \u003ccode\u003eHostIdResource\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19293\"\u003e#19293\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eMessageOperation\u003c/code\u003e in favor of \u003ccode\u003eMessagingOperationType\u003c/code\u003e, and the \u003ccode\u003eMessageOperation\u003c/code\u003e overloads of \u003ccode\u003eMessagingAttributesExtractor\u003c/code\u003e, \u003ccode\u003eMessagingConsumerMetrics\u003c/code\u003e, \u003ccode\u003eMessagingProducerMetrics\u003c/code\u003e, \u003ccode\u003eMessagingSpanKindExtractor\u003c/code\u003e, and \u003ccode\u003eMessagingSpanNameExtractor\u003c/code\u003e in favor of the corresponding \u003ccode\u003eMessagingOperationType\u003c/code\u003e APIs. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19357\"\u003e#19357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eotel.traces.exporter=zipkin\u003c/code\u003e in favor of \u003ccode\u003eotel.traces.exporter=otlp\u003c/code\u003e, and \u003ccode\u003eotel.exporter.zipkin.endpoint\u003c/code\u003e in favor of \u003ccode\u003eotel.exporter.otlp.traces.endpoint\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19400\"\u003e#19400\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eOpenTelemetryMeterRegistryBuilder#setMicrometerHistogramGaugesEnabled(boolean)\u003c/code\u003e in favor of \u003ccode\u003eExperimental#setMicrometerHistogramGaugesEnabled(OpenTelemetryMeterRegistryBuilder, boolean)\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19404\"\u003e#19404\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate legacy gRPC metadata, messaging header, and servlet request-parameter capture properties and APIs in favor of selector-based \u003ccode\u003e.included\u003c/code\u003e / \u003ccode\u003e.excluded\u003c/code\u003e configuration and \u003ccode\u003eIncludeExclude\u003c/code\u003e APIs. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19494\"\u003e#19494\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19522\"\u003e#19522\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19523\"\u003e#19523\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19638\"\u003e#19638\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eotel.instrumentation.runtime-telemetry.experimental.prefer-jfr\u003c/code\u003e in favor of \u003ccode\u003eotel.instrumentation.runtime-telemetry.experimental.jfr-metrics.included\u003c/code\u003e, and \u003ccode\u003esetPreferJfrMetrics(...)\u003c/code\u003e in favor of \u003ccode\u003esetJfrMetrics(RuntimeTelemetryBuilder, IncludeExclude)\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19495\"\u003e#19495\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate boolean and capture-list configuration for MDC/context data, map messages, key-value pairs, logger context, Logstash markers, and structured arguments in favor of \u003ccode\u003e.included\u003c/code\u003e / \u003ccode\u003e.excluded\u003c/code\u003e selectors and \u003ccode\u003eIncludeExclude\u003c/code\u003e APIs. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19519\"\u003e#19519\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19520\"\u003e#19520\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19521\"\u003e#19521\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19599\"\u003e#19599\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19600\"\u003e#19600\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19605\"\u003e#19605\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19609\"\u003e#19609\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19610\"\u003e#19610\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate the declarative configuration field \u003ccode\u003egeneral.semconv_stability.opt_in\u003c/code\u003e in favor of \u003ccode\u003egeneral.stability_opt_in_list\u003c/code\u003e, and \u003ccode\u003egeneral.sanitization.url.sensitive_query_parameters/development\u003c/code\u003e in favor of \u003ccode\u003egeneral.sanitization.url.sensitive_query_parameters\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19561\"\u003e#19561\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eotel.instrumentation.graphql.add-operation-name-to-span-name.enabled\u003c/code\u003e in favor of \u003ccode\u003eotel.instrumentation.graphql.operation-name-in-span-name.enabled\u003c/code\u003e, and \u003ccode\u003eotel.instrumentation.runtime-telemetry.package-emitter.enabled\u003c/code\u003e / \u003ccode\u003ejars-per-second\u003c/code\u003e in favor of \u003ccode\u003eotel.instrumentation.runtime-telemetry.experimental.package-emitter.enabled\u003c/code\u003e / \u003ccode\u003ejars-per-second\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19573\"\u003e#19573\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate captured request and response header builder methods across HTTP library instrumentations in favor of selector-based \u003ccode\u003erequestHeaders(IncludeExclude)\u003c/code\u003e and \u003ccode\u003eresponseHeaders(IncludeExclude)\u003c/code\u003e APIs. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19598\"\u003e#19598\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19601\"\u003e#19601\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19602\"\u003e#19602\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19603\"\u003e#19603\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19604\"\u003e#19604\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19606\"\u003e#19606\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19607\"\u003e#19607\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19608\"\u003e#19608\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eotel.instrumentation.micrometer.histogram-gauges.enabled\u003c/code\u003e in favor of \u003ccode\u003eotel.instrumentation.micrometer.experimental.histogram-gauges.enabled\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19613\"\u003e#19613\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🌟 New javaagent instrumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Apache Commons Pool 2 instrumentation for object pool metrics. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19091\"\u003e#19091\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd Apache HBase client 1.0 javaagent instrumentation. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19243\"\u003e#19243\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd Redisson connection pool metrics for 3.26+. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19392\"\u003e#19392\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd support for OpenTelemetry API 1.65 incubator metrics in the Java agent. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19456\"\u003e#19456\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd Tomcat DBCP 8.0 javaagent instrumentation for database pool metrics. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19472\"\u003e#19472\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e📈 Enhancements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd opt-in OSGi bundle metadata for selected instrumentation, API, and SDK extension artifacts so they can be consumed directly in OSGi runtimes. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18995\"\u003e#18995\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003ecassandra.compaction.progress.completed\u003c/code\u003e and \u003ccode\u003ecassandra.compaction.progress.size\u003c/code\u003e gauges for in-flight Cassandra compactions. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19290\"\u003e#19290\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreview the upcoming 3.0 messaging semantic conventions behind \u003ccode\u003eotel.semconv-stability.opt-in=messaging\u003c/code\u003e across AWS SQS and Lambda, JMS, Kafka, NATS, Pulsar, RabbitMQ, RocketMQ, Spring Integration, and Spring messaging instrumentations. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19347\"\u003e#19347\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19348\"\u003e#19348\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19349\"\u003e#19349\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19350\"\u003e#19350\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19351\"\u003e#19351\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19353\"\u003e#19353\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19354\"\u003e#19354\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19355\"\u003e#19355\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19356\"\u003e#19356\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19476\"\u003e#19476\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19477\"\u003e#19477\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19478\"\u003e#19478\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19479\"\u003e#19479\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19480\"\u003e#19480\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19481\"\u003e#19481\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19482\"\u003e#19482\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19486\"\u003e#19486\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19487\"\u003e#19487\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19499\"\u003e#19499\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19500\"\u003e#19500\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19504\"\u003e#19504\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19505\"\u003e#19505\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19507\"\u003e#19507\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19508\"\u003e#19508\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19535\"\u003e#19535\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19544\"\u003e#19544\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19565\"\u003e#19565\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19567\"\u003e#19567\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19639\"\u003e#19639\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19640\"\u003e#19640\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUnder the upcoming 3.0 RPC semantic conventions behind \u003ccode\u003eotel.semconv-stability.opt-in=rpc\u003c/code\u003e, Dubbo requests to unknown services emit server spans even when decoding fails before \u003ccode\u003eDubboProtocol.getInvoker()\u003c/code\u003e, and record the original method in \u003ccode\u003erpc.method_original\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/16668\"\u003e#16668\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eLog4j context data now includes \u003ccode\u003ebaggage.*\u003c/code\u003e entries even when there is no current span. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19378\"\u003e#19378\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eWhen \u003ccode\u003eotel.instrumentation.common.v3-preview=true\u003c/code\u003e, the Micrometer bridge no longer exports \u003ccode\u003e.max\u003c/code\u003e gauges for \u003ccode\u003eTimer\u003c/code\u003e and \u003ccode\u003eDistributionSummary\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19397\"\u003e#19397\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/blob/main/CHANGELOG.md\"\u003eio.opentelemetry.instrumentation:opentelemetry-instrumentation-bom's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 2.31.1 (2026-08-23)\u003c/h2\u003e\n\u003cp\u003eThis release targets the OpenTelemetry SDK 1.65.0.\u003c/p\u003e\n\u003cp\u003eNote that many artifacts have the \u003ccode\u003e-alpha\u003c/code\u003e suffix attached to their version\nnumber, reflecting that they will continue to have breaking changes. Please see\n\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/blob/main/VERSIONING.md#opentelemetry-java-instrumentation-versioning\"\u003eVERSIONING.md\u003c/a\u003e\nfor more details.\u003c/p\u003e\n\u003ch3\u003e🛠️ Bug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRestore stable semantic convention APIs to the compile classpaths of the Spring Boot\nautoconfigure and starter artifacts.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19754\"\u003e#19754\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 2.31.0 (2026-08-20)\u003c/h2\u003e\n\u003cp\u003eThis release targets the OpenTelemetry SDK 1.65.0.\u003c/p\u003e\n\u003cp\u003eNote that many artifacts have the \u003ccode\u003e-alpha\u003c/code\u003e suffix attached to their version\nnumber, reflecting that they will continue to have breaking changes. Please see\n\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/blob/main/VERSIONING.md#opentelemetry-java-instrumentation-versioning\"\u003eVERSIONING.md\u003c/a\u003e\nfor more details.\u003c/p\u003e\n\u003ch3\u003e⚠️ Breaking changes to non-stable APIs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemove the deprecated \u003ccode\u003eConfigPropertiesBackedConfigProvider\u003c/code\u003e and its \u003ccode\u003ecreate(ConfigProperties)\u003c/code\u003e\ncompatibility API from the declarative config bridge.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19305\"\u003e#19305\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eStop exposing \u003ccode\u003eopentelemetry-instrumentation-api-incubator\u003c/code\u003e on library instrumentation compile\nclasspaths.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19612\"\u003e#19612\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🚫 Deprecations\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eotel.instrumentation.experimental.span-suppression-strategy\u003c/code\u003e in favor of\n\u003ccode\u003eExperimental.setSpanSuppressionStrategy(...)\u003c/code\u003e.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19180\"\u003e#19180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eHostIdResource.REGISTRY_QUERY\u003c/code\u003e in favor of the absolute-path \u003ccode\u003ereg.exe\u003c/code\u003e lookup used by\n\u003ccode\u003eHostIdResource\u003c/code\u003e.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19293\"\u003e#19293\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eMessageOperation\u003c/code\u003e in favor of \u003ccode\u003eMessagingOperationType\u003c/code\u003e, and the \u003ccode\u003eMessageOperation\u003c/code\u003e\noverloads of \u003ccode\u003eMessagingAttributesExtractor\u003c/code\u003e, \u003ccode\u003eMessagingConsumerMetrics\u003c/code\u003e,\n\u003ccode\u003eMessagingProducerMetrics\u003c/code\u003e, \u003ccode\u003eMessagingSpanKindExtractor\u003c/code\u003e, and \u003ccode\u003eMessagingSpanNameExtractor\u003c/code\u003e in\nfavor of the corresponding \u003ccode\u003eMessagingOperationType\u003c/code\u003e APIs.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19357\"\u003e#19357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eotel.traces.exporter=zipkin\u003c/code\u003e in favor of \u003ccode\u003eotel.traces.exporter=otlp\u003c/code\u003e, and\n\u003ccode\u003eotel.exporter.zipkin.endpoint\u003c/code\u003e in favor of \u003ccode\u003eotel.exporter.otlp.traces.endpoint\u003c/code\u003e.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19400\"\u003e#19400\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eOpenTelemetryMeterRegistryBuilder#setMicrometerHistogramGaugesEnabled(boolean)\u003c/code\u003e in\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/8ad06a082e051f366f19c16ad95a7b68edf30afd\"\u003e\u003ccode\u003e8ad06a0\u003c/code\u003e\u003c/a\u003e [release/v2.31.x] Prepare release 2.31.1 (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/19765\"\u003e#19765\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/e0306a2645a21a4506941b8e32370e985b11d5af\"\u003e\u003ccode\u003ee0306a2\u003c/code\u003e\u003c/a\u003e [release/v2.31.x] Prepare changelog for 2.31.1 (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/19760\"\u003e#19760\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/75576d4dc361ba4c36fc8eac57452cb8c6e8e5fe\"\u003e\u003ccode\u003e75576d4\u003c/code\u003e\u003c/a\u003e [release/v2.31.x] Retain semconv API for Spring artifacts until 3.0 (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/19754\"\u003e#19754\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/18da99bef6a5f1becdeb8091136f12c43742b9b7\"\u003e\u003ccode\u003e18da99b\u003c/code\u003e\u003c/a\u003e [release/v2.31.x] Prepare release 2.31.0 (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/19731\"\u003e#19731\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/dbe5c09ae9a2ab4709bdc2a87b1c90c1edd7b0d6\"\u003e\u003ccode\u003edbe5c09\u003c/code\u003e\u003c/a\u003e chore: update instrumentation list [automated] (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/19701\"\u003e#19701\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/1035b5ba36cd6fc1e81d6688c0f4306e708d9435\"\u003e\u003ccode\u003e1035b5b\u003c/code\u003e\u003c/a\u003e Change log for upcoming release + Improve automated release note drafting (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/1\"\u003e#1\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/64310fcbf8d0fae48578bdb5df07d404b30b96a6\"\u003e\u003ccode\u003e64310fc\u003c/code\u003e\u003c/a\u003e [jmx] add recommendation for naming percentile metrics (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/19727\"\u003e#19727\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/4225fbe18e61704e521473c54621a9634404d296\"\u003e\u003ccode\u003e4225fbe\u003c/code\u003e\u003c/a\u003e Update pinned latest dep versions (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/19720\"\u003e#19720\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/26c08ace6c3dcd3402498db10cb4dcf037cb2906\"\u003e\u003ccode\u003e26c08ac\u003c/code\u003e\u003c/a\u003e fix redisson connection pool leak on cancellation (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/19340\"\u003e#19340\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/200efaef8b90b67227a4dc0058d665dd61392c23\"\u003e\u003ccode\u003e200efae\u003c/code\u003e\u003c/a\u003e Emit db.namespace for jedis 2.0 and 3.0 (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/19707\"\u003e#19707\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/compare/v2.18.1...v2.31.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.google.api.grpc:proto-google-common-protos` from 2.60.0 to 2.76.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/googleapis/google-cloud-java/blob/main/java-document-ai/CHANGELOG.md\"\u003ecom.google.api.grpc:proto-google-common-protos's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.76.0 (2025-08-13)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eNo change\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.75.0 (2025-08-08)\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eupdate dependency com.google.cloud:sdk-platform-java-config to v3.51.0 (\u003ca href=\"https://redirect.github.com/googleapis/google-cloud-java/issues/11695\"\u003e#11695\u003c/a\u003e) (\u003ca href=\"https://github.com/googleapis/google-cloud-java/commit/b82ce005c30551b8714099b7219b71bda85aa3a5\"\u003eb82ce00\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.74.0 (2025-07-30)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eNo change\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.73.0 (2025-07-28)\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eupdate dependency com.google.cloud:sdk-platform-java-config to v3.50.2 (\u003ca href=\"https://redirect.github.com/googleapis/google-cloud-java/issues/11680\"\u003e#11680\u003c/a\u003e) (\u003ca href=\"https://github.com/googleapis/google-cloud-java/commit/d1b99a706daa10c487b56edbb5170b41530628ca\"\u003ed1b99a7\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.72.0 (2025-07-11)\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eupdate dependency com.google.cloud:sdk-platform-java-config to v3.50.1 (\u003ca href=\"https://redirect.github.com/googleapis/google-cloud-java/issues/11655\"\u003e#11655\u003c/a\u003e) (\u003ca href=\"https://github.com/googleapis/google-cloud-java/commit/9b34528f85043049e3349fffc30bb2dbfe01836c\"\u003e9b34528\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.71.0 (2025-06-25)\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eupdate dependency com.google.cloud:sdk-platform-java-config to v3.50.0 (\u003ca href=\"https://redirect.github.com/googleapis/google-cloud-java/issues/11624\"\u003e#11624\u003c/a\u003e) (\u003ca href=\"https://github.com/googleapis/google-cloud-java/commit/a19f457d10f15437ac26ce379048ff8b3cc6be5d\"\u003ea19f457\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.69.0 (2025-06-16)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eNo change\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.68.0 (2025-06-04)\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eupdate dependency com.google.cloud:sdk-platform-java-config to v3.49.0 (\u003ca href=\"https://redirect.github.com/googleapis/google-cloud-java/issues/11603\"\u003e#11603\u003c/a\u003e) (\u003ca href=\"https://github.com/googleapis/google-cloud-java/commit/3ea506d86a54fae209e9971af7b4a8aa1f5997b9\"\u003e3ea506d\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/googleapis/google-cloud-java/commits/gapic-generator-java/v2.76.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.google.protobuf:protobuf-java` from 4.31.1 to 4.36.1\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/protocolbuffers/protobuf/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.google.protobuf:protoc` from 4.31.1 to 4.36.1\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/protocolbuffers/protobuf/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `io.grpc:grpc-protobuf` from 1.74.0 to 1.84.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/grpc/grpc-java/releases\"\u003eio.grpc:grpc-protobuf's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eV1.84.0\u003c/h2\u003e\n\u003cp\u003eIn this release we drop support for Android API level 23 or lower (Marshmallow or earlier), following \u003ca href=\"https://support.google.com/googleplay/answer/9037938?hl=en\"\u003eGoogle Play Service’s now requiring a minimum of API level 24\u003c/a\u003e (Android 7.0 Nougat).\u003c/p\u003e\n\u003ch3\u003eAPI Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003exds: Supports injecting custom LDS Resource Name Resolvers (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12925\"\u003e#12925\u003c/a\u003e) (ac02c6f37)\u003c/li\u003e\n\u003cli\u003exds: Add support for creating \u003ccode\u003eXdsServerBuilder\u003c/code\u003e with \u003ccode\u003eSocketAddress\u003c/code\u003ees (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12925\"\u003e#12925\u003c/a\u003e) (ac02c6f37)\u003c/li\u003e\n\u003cli\u003eapi: Add a Supplier overload to Context (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12935\"\u003e#12935\u003c/a\u003e) (696653600)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBehavior Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecore: update SPIFFE certificate extraction to comply with X509-SVID spec (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12961\"\u003e#12961\u003c/a\u003e) (96807d898)\u003cbr /\u003e\nIgnore all but the first certificate if the x5c JWK parameter contains multiple values.\u003cbr /\u003e\nSkip the JWK entry instead of stopping execution or throwing when x5c is missing or contains an empty list, complying with the requirement that entries without x5c must be ignored.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecore: reference-count shared transport factory for OOB channels (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12985\"\u003e#12985\u003c/a\u003e) (72c6e5f91)\u003cbr /\u003e\nFixes a bug whereby an OOB channel shutdown incorrectly shut down the shared transport factory with the main channel, and the main channel was unable to create subchannels anymore and faced an exception in doing so.\u003c/li\u003e\n\u003cli\u003exds: Fix \u003ccode\u003eshutdownNow()\u003c/code\u003e becoming a no-op after \u003ccode\u003eshutdown()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12982\"\u003e#12982\u003c/a\u003e) (3cb700719)\u003c/li\u003e\n\u003cli\u003exds: Add Http11ProxyUpstreamTransport to MessagePrinter (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12971\"\u003e#12971\u003c/a\u003e) (d49a589f4)\u003c/li\u003e\n\u003cli\u003ecore, xds: Append child channel configurators instead of overwriting (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/pull/12921\"\u003e#12921\u003c/a\u003e) (296c007c1) Chains multiple childChannelConfigurator() calls instead of overwriting them in ManagedChannelImplBuilder and XdsServerBuilder, ensuring all configurators are preserved and executed when child channels are created.\u003c/li\u003e\n\u003cli\u003erls: Implement stale_header_data caching and propagation in RLS (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/pull/12972\"\u003e#12972\u003c/a\u003e) (7843bd437) Caches header_data received in RouteLookupResponse and sends it back as stale_header_data in RouteLookupRequest when refreshing stale cache entries, complying with the RLS specification.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eImprovements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003enetty: Fix client-initiated stream limit bypass in NettyServerHandler (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12933\"\u003e#12933\u003c/a\u003e) (56205f91c) Configure max active streams limit directly upon \u003ccode\u003eDefaultHttp2Connection\u003c/code\u003e initialization. Because \u003ccode\u003eNettyServerHandler\u003c/code\u003e instantiates \u003ccode\u003eDefaultHttp2Connection\u003c/code\u003e directly rather than using Netty's \u003ccode\u003eAbstractHttp2ConnectionHandlerBuilder\u003c/code\u003e, it missed Netty's built-in \u003ca href=\"https://github.com/advisories/GHSA-5x3r-wrvg-rp6q\"\u003eCVE-2026-47244\u003c/a\u003e patch. This left a pre-handshake window where the server's local connection allowed up to Integer.MAX_VALUE active client-initiated streams until a SETTINGS_ACK was received. Enforcing the limit proactively at startup closes this vulnerability window and prevents client-initiated stream floods / resource exhaustion.\u003c/li\u003e\n\u003cli\u003eservlet: \u003ccode\u003eAsyncServletOutputStreamWriter\u003c/code\u003e detect and handle write when not ready (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12732\"\u003e#12732\u003c/a\u003e) (46f308051) In highly concurrent scenarios, cached servlet container ready to write state can become  stale. The servlet container may have already transitioned to a 'not ready' state, but the corresponding callback has not yet updated gRPC's internal state. This fix makes the ready state to be evaluated explicitly before attempting to write directly to the servlet output stream.\u003c/li\u003e\n\u003cli\u003eokhttp: Move connection window update before stream termination logic (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12990\"\u003e#12990\u003c/a\u003e) (0f859c3bb) By RFC 9113, section 6.9, receivers must take frames into account for flow control even if they're errored. This change moves the stream error response logic after connection window updates\u003c/li\u003e\n\u003cli\u003ecore: Coalesce Contiguous Small Buffers for ReadableBuffer to prevent OOM (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12924\"\u003e#12924\u003c/a\u003e) (0585d481a)\u003c/li\u003e\n\u003cli\u003es2a: Default to Post Quantum Cryptography key exchange group (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12894\"\u003e#12894\u003c/a\u003e) (bc01994b7)\u003c/li\u003e\n\u003cli\u003ebinder: Let servers load their SecurityPolicy asynchronously (9fdef96dc)\u003c/li\u003e\n\u003cli\u003ebinder: normalize failed auth future status message (9ffa1e1b7)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecompiler: Update maximum supported edition to EDITION_2026 (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12945\"\u003e#12945\u003c/a\u003e) (6ccd0658e). Update the maximum supported edition in the Java gRPC compiler plugin to EDITION_2026 when compiling against Protobuf version 7.35.0 (v35.0) or later.\u003c/li\u003e\n\u003cli\u003eapi: Bump Context to JDK 8 (5d0a012fa)\u003c/li\u003e\n\u003cli\u003enetty: Upgrade Netty to 4.2.16 and netty-tcnative to 2.0.81 (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/pull/12969\"\u003e#12969\u003c/a\u003e) (1bc2f5a34)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eapi: Better explain the executors and how to configure them (ee08f5337)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNew Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecore, opentelemetry: Implement LB Delay Observability (Proposal A121) (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/pull/12807\"\u003e#12807\u003c/a\u003e) (073fd5ea1) Implements attempt-level RPC delay observability across the core delayed transport, built-in load balancers (pick_first, round_robin), RLS, and xDS policies, aligned with \u003ca href=\"https://redirect.github.com/grpc/proposal/pull/556\"\u003egRFC A121\u003c/a\u003e. Adds LoadBalancer.PickResult.withNoResult(delayType, delayReason) and delay tracing callbacks on ClientStreamTracer. Records attempt delay duration metrics (grpc.client.attempt.delay.duration) and child tracing spans (\u0026quot;Attempt Delay\u0026quot;) via the OpenTelemetry plugin.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eThanks to\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/b3838c0ce83152138aff3979c832225280d7a8d6\"\u003e\u003ccode\u003eb3838c0\u003c/code\u003e\u003c/a\u003e Bump version to 1.84.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/eb21854905d7e35c5e633543e39f46d9590fc327\"\u003e\u003ccode\u003eeb21854\u003c/code\u003e\u003c/a\u003e Update README etc to reference 1.84.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/118cb68ed152ab1c203137a6c2eb91c3075ddfcb\"\u003e\u003ccode\u003e118cb68\u003c/code\u003e\u003c/a\u003e xds: Make RawMessageClientInterceptor conditional on ext_proc flags (v1.84.x ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/e9cfe32b929be82adbe2f05d64e9cf1f28225ad9\"\u003e\u003ccode\u003ee9cfe32\u003c/code\u003e\u003c/a\u003e Revert \u0026quot;Implement gRFC A97: xDS JWT Call Credentials (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12951\"\u003e#12951\u003c/a\u003e)\u0026quot; (v1.84.x backp...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/cb66582711b2b4196b6a6135a13c746f56d0b9b1\"\u003e\u003ccode\u003ecb66582\u003c/code\u003e\u003c/a\u003e build: Remove global setting to allow empty checksums for Choco (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12993\"\u003e#12993\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/0f859c3bb69bbf229c39194ff433a095c630e31c\"\u003e\u003ccode\u003e0f859c3\u003c/code\u003e\u003c/a\u003e okhttp: Move connection window update before stream termination logic (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12990\"\u003e#12990\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/292a361472e0afe317cdfa190dcf77c649bb6338\"\u003e\u003ccode\u003e292a361\u003c/code\u003e\u003c/a\u003e binder,cronet: Handle double-ClientTransportFactory.close()\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/7843bd437a38e85c2a3a40a8b9e61fc42d65edbc\"\u003e\u003ccode\u003e7843bd4\u003c/code\u003e\u003c/a\u003e rls: implement stale_header_data caching and propagation in RLS (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12972\"\u003e#12972\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/3cb7007194443a2fb303cc72fca7b9274b7a29f0\"\u003e\u003ccode\u003e3cb7007\u003c/code\u003e\u003c/a\u003e xds: Fix \u003ccode\u003eshutdownNow()\u003c/code\u003e becoming a no-op after \u003ccode\u003eshutdown()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12982\"\u003e#12982\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/ab104f8b3f610b588ecc7bafa0502b3b69abfc62\"\u003e\u003ccode\u003eab104f8\u003c/code\u003e\u003c/a\u003e compiler: add retry loop and enable allowEmptyChecksums on Windows (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12962\"\u003e#12962\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/grpc/grpc-java/compare/v1.74.0...v1.84.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `io.grpc:grpc-stub` from 1.74.0 to 1.84.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/grpc/grpc-java/releases\"\u003eio.grpc:grpc-stub's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eV1.84.0\u003c/h2\u003e\n\u003cp\u003eIn this release we drop support for Android API level 23 or lower (Marshmallow or earlier), following \u003ca href=\"https://support.google.com/googleplay/answer/9037938?hl=en\"\u003eGoogle Play Service’s now requiring a minimum of API level 24\u003c/a\u003e (Android 7.0 Nougat).\u003c/p\u003e\n\u003ch3\u003eAPI Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003exds: Supports injecting custom LDS Resource Name Resolvers (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12925\"\u003e#12925\u003c/a\u003e) (ac02c6f37)\u003c/li\u003e\n\u003cli\u003exds: Add support for creating \u003ccode\u003eXdsServerBuilder\u003c/code\u003e with \u003ccode\u003eSocketAddress\u003c/code\u003ees (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12925\"\u003e#12925\u003c/a\u003e) (ac02c6f37)\u003c/li\u003e\n\u003cli\u003eapi: Add a Supplier overload to Context (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12935\"\u003e#12935\u003c/a\u003e) (696653600)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBehavior Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecore: update SPIFFE certificate extraction to comply with X509-SVID spec (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12961\"\u003e#12961\u003c/a\u003e) (96807d898)\u003cbr /\u003e\nIgnore all but the first certificate if the x5c JWK parameter contains multiple values.\u003cbr /\u003e\nSkip the JWK entry instead of stopping execution or throwing when x5c is missing or contains an empty list, complying with the requirement that entries without x5c must be ignored.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecore: reference-count shared transport factory for OOB channels (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12985\"\u003e#12985\u003c/a\u003e) (72c6e5f91)\u003cbr /\u003e\nFixes a bug whereby an OOB channel shutdown incorrectly shut down the shared transport factory with the main channel, and the main channel was unable to create subchannels anymore and faced an exception in doing so.\u003c/li\u003e\n\u003cli\u003exds: Fix \u003ccode\u003eshutdownNow()\u003c/code\u003e becoming a no-op after \u003ccode\u003eshutdown()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12982\"\u003e#12982\u003c/a\u003e) (3cb700719)\u003c/li\u003e\n\u003cli\u003exds: Add Http11ProxyUpstreamTransport to MessagePrinter (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12971\"\u003e#12971\u003c/a\u003e) (d49a589f4)\u003c/li\u003e\n\u003cli\u003ecore, xds: Append child channel configurators instead of overwriting (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/pull/12921\"\u003e#12921\u003c/a\u003e) (296c007c1) Chains multiple childChannelConfigurator() calls instead of overwriting them in ManagedChannelImplBuilder and XdsServerBuilder, ensuring all configurators are preserved and executed when child channels are created.\u003c/li\u003e\n\u003cli\u003erls: Implement stale_header_data caching and propagation in RLS (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/pull/12972\"\u003e#12972\u003c/a\u003e) (7843bd437) Caches header_data received in RouteLookupResponse and sends it back as stale_header_data in RouteLookupRequest when refreshing stale cache entries, complying with the RLS specification.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eImprovements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003enetty: Fix client-initiated stream limit bypass in NettyServerHandler (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12933\"\u003e#12933\u003c/a\u003e) (56205f91c) Configure max active streams limit directly upon \u003ccode\u003eDefaultHttp2Connection\u003c/code\u003e initialization. Because \u003ccode\u003eNettyServerHandler\u003c/code\u003e instantiates \u003ccode\u003eDefaultHttp2Connection\u003c/code\u003e directly rather than using Netty's \u003ccode\u003eAbstractHttp2ConnectionHandlerBuilder\u003c/code\u003e, it missed Netty's built-in \u003ca href=\"https://github.com/advisories/GHSA-5x3r-wrvg-rp6q\"\u003eCVE-2026-47244\u003c/a\u003e patch. This left a pre-handshake window where the server's local connection allowed up to Integer.MAX_VALUE active client-initiated streams until a SETTINGS_ACK was received. Enforcing the limit proactively at startup closes this vulnerability window and prevents client-initiated stream floods / resource exhaustion.\u003c/li\u003e\n\u003cli\u003eservlet: \u003ccode\u003eAsyncServletOutputStreamWriter\u003c/code\u003e detect and handle write when not ready (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12732\"\u003e#12732\u003c/a\u003e) (46f308051) In highly concurrent scenarios, cached servlet container ready to write state can become  stale. The servlet container may have already transitioned to a 'not ready' state, but the corresponding callback has not yet updated gRPC's internal state. This fix makes the ready state to be evaluated explicitly before attempting to write directly to the servlet output stream.\u003c/li\u003e\n\u003cli\u003eokhttp: Move connection window update before stream termination logic (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12990\"\u003e#12990\u003c/a\u003e) (0f859c3bb) By RFC 9113, section 6.9, receivers must take frames into account for flow control even if they're errored. This change moves the stream error response logic after connection window updates\u003c/li\u003e\n\u003cli\u003ecore: Coalesce Contiguous Small Buffers for ReadableBuffer to prevent OOM (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12924\"\u003e#12924\u003c/a\u003e) (0585d481a)\u003c/li\u003e\n\u003cli\u003es2a: Default to Post Quantum Cryptography key exchange group (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12894\"\u003e#12894\u003c/a\u003e) (bc01994b7)\u003c/li\u003e\n\u003cli\u003ebinder: Let servers load their SecurityPolicy asynchronously (9fdef96dc)\u003c/li\u003e\n\u003cli\u003ebinder: normalize failed auth future status message (9ffa1e1b7)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecompiler: Update maximum supported edition to EDITION_2026 (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12945\"\u003e#12945\u003c/a\u003e) (6ccd0658e). Update the maximum supported edition in the Java gRPC compiler plugin to EDITION_2026 when compiling against Protobuf version 7.35.0 (v35.0) or later.\u003c/li\u003e\n\u003cli\u003eapi: Bump Context to JDK 8 (5d0a012fa)\u003c/li\u003e\n\u003cli\u003enetty: Upgrade Netty to 4.2.16 and netty-tcnative to 2.0.81 (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/pull/12969\"\u003e#12969\u003c/a\u003e) (1bc2f5a34)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eapi: Better explain the executors and how to configure them (ee08f5337)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNew Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecore, opentelemetry: Implement LB Delay Observability (Proposal A121) (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/pull/12807\"\u003e#12807\u003c/a\u003e) (073fd5ea1) Implements attempt-level RPC delay observability across the core delayed transport, built-in load balancers (pick_first, round_robin), RLS, and xDS policies, aligned with \u003ca href=\"https://redirect.github.com/grpc/proposal/pull/556\"\u003egRFC A121\u003c/a\u003e. Adds LoadBalancer.PickResult.withNoResult(delayType, delayReason) and delay tracing callbacks on ClientStreamTracer. Records attempt delay duration metrics (grpc.client.attempt.delay.duration) and child tracing spans (\u0026quot;Attempt Delay\u0026quot;) via the OpenTelemetry plugin.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eThanks to\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/b3838c0ce83152138aff3979c832225280d7a8d6\"\u003e\u003ccode\u003eb3838c0\u003c/code\u003e\u003c/a\u003e Bump version to 1.84.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/eb21854905d7e35c5e633543e39f46d9590fc327\"\u003e\u003ccode\u003eeb21854\u003c/code\u003e\u003c/a\u003e Update README etc to reference 1.84.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/118cb68ed152ab1c203137a6c2eb91c3075ddfcb\"\u003e\u003ccode\u003e118cb68\u003c/code\u003e\u003c/a\u003e xds: Make RawMessageClientInterceptor conditional on ext_proc flags (v1.84.x ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/e9cfe32b929be82adbe2f05d64e9cf1f28225ad9\"\u003e\u003ccode\u003ee9cfe32\u003c/code\u003e\u003c/a\u003e Revert \u0026quot;Implement gRFC A97: xDS JWT Call Credentials (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12951\"\u003e#12951\u003c/a\u003e)\u0026quot; (v1.84.x backp...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/cb66582711b2b4196b6a6135a13c746f56d0b9b1\"\u003e\u003ccode\u003ecb66582\u003c/code\u003e\u003c/a\u003e build: Remove global setting to allow empty checksums for Choco (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12993\"\u003e#12993\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/0f859c3bb69bbf229c39194ff433a095c630e31c\"\u003e\u003ccode\u003e0f859c3\u003c/code\u003e\u003c/a\u003e okhttp: Move connection window update before stream termination logic (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12990\"\u003e#12990\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/292a361472e0afe317cdfa190dcf77c649bb6338\"\u003e\u003ccode\u003e292a361\u003c/code\u003e\u003c/a\u003e binder,cronet: Handle double-ClientTransportFactory.close()\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/7843bd437a38e85c2a3a40a8b9e61fc42d65edbc\"\u003e\u003ccode\u003e7843bd4\u003c/code\u003e\u003c/a\u003e rls: implement stale_header_data caching and propagation in RLS (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12972\"\u003e#12972\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/3cb7007194443a2fb303cc72fca7b9274b7a29f0\"\u003e\u003ccode\u003e3cb7007\u003c/code\u003e\u003c/a\u003e xds: Fix \u003ccode\u003eshutdownNow()\u003c/code\u003e becoming a no-op after \u003ccode\u003eshutdown()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12982\"\u003e#12982\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/ab104f8b3f610b588ecc7bafa0502b3b69abfc62\"\u003e\u003ccode\u003eab104f8\u003c/code\u003e\u003c/a\u003e compiler: add retry loop and enable allowEmptyChecksums on Windows (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12962\"\u003e#12962\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/grpc/grpc-java/compare/v1.74.0...v1.84.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `io.grpc:grpc-netty` from 1.74.0 to 1.84.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/grpc/grpc-java/releases\"\u003eio.grpc:grpc-netty's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eV1.84.0\u003c/h2\u003e\n\u003cp\u003eIn this release we drop support for Android API level 23 or lower (Marshmallow or earlier), following \u003ca href=\"https://support.google.com/googleplay/answer/9037938?hl=en\"\u003eGoogle Play Service’s now requiring a minimum of API level 24\u003c/a\u003e (Android 7.0 Nougat).\u003c/p\u003e\n\u003ch3\u003eAPI Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003exds: Supports injecting custom LDS Resource Name Resolvers (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12925\"\u003e#12925\u003c/a\u003e) (ac02c6f37)\u003c/li\u003e\n\u003cli\u003exds: Add support for creating \u003ccode\u003eXdsServerBuilder\u003c/code\u003e with \u003ccode\u003eSocketAddress\u003c/code\u003ees (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12925\"\u003e#12925\u003c/a\u003e) (ac02c6f37)\u003c/li\u003e\n\u003cli\u003eapi: Add a Supplier overload to Context (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12935\"\u003e#12935\u003c/a\u003e) (696653600)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBehavior Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecore: update SPIFFE certificate extraction to comply with X509-SVID spec (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12961\"\u003e#12961\u003c/a\u003e) (96807d898)\u003cbr /\u003e\nIgnore all but the first certificate if the x5c JWK parameter contains multiple values.\u003cbr /\u003e\nSkip the JWK entry instead of stopping execution or throwing when x5c is missing or contains an empty list, complying with the requirement that entries without x5c must be ignored.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecore: reference-count shared transport factory for OOB channels (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12985\"\u003e#12985\u003c/a\u003e) (72c6e5f91)\u003cbr /\u003e\nFixes a bug whereby an OOB channel shutdown incorrectly shut down the shared transport factory with the main channel, and the main channel was unable to create subchannels anymore and faced an exception in doing so.\u003c/li\u003e\n\u003cli\u003exds: Fix \u003ccode\u003eshutdownNow()\u003c/code\u003e becoming a no-op after \u003ccode\u003eshutdown()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12982\"\u003e#12982\u003c/a\u003e) (3cb700719)\u003c/li\u003e\n\u003cli\u003exds: Add Http11ProxyUpstreamTransport to MessagePrinter (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12971\"\u003e#12971\u003c/a\u003e) (d49a589f4)\u003c/li\u003e\n\u003cli\u003ecore, xds: Append child channel configurators instead of overwriting (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/pull/12921\"\u003e#12921\u003c/a\u003e) (296c007c1) Chains multiple childChannelConfigurator() calls instead of overwriting them in ManagedChannelImplBuilder and XdsServerBuilder, ensuring all configurators are preserved and executed when child channels are created.\u003c/li\u003e\n\u003cli\u003erls: Implement stale_header_data caching and propagation in RLS (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/pull/12972\"\u003e#12972\u003c/a\u003e) (7843bd437) Caches header_data received in RouteLookupResponse and sends it back as stale_header_data in RouteLookupRequest when refreshing stale cache entries, complying with the RLS specification.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eImprovements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003enetty: Fix client-initiated stream limit bypass in NettyServerHandler (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12933\"\u003e#12933\u003c/a\u003e) (56205f91c) Configure max active streams limit directly upon \u003ccode\u003eDefaultHttp2Connection\u003c/code\u003e initialization. Because \u003ccode\u003eNettyServerHandler\u003c/code\u003e instantiates \u003ccode\u003eDefaultHttp2Connection\u003c/code\u003e directly rather than using Netty's \u003ccode\u003eAbstractHttp2ConnectionHandlerBuilder\u003c/code\u003e, it missed Netty's built-in \u003ca href=\"https://github.com/advisories/GHSA-5x3r-wrvg-rp6q\"\u003eCVE-2026-47244\u003c/a\u003e patch. This left a pre-handshake window where the server's local connection allowed up to Integer.MAX_VALUE active client-initiated streams until a SETTINGS_ACK was received. Enforcing the limit proactively at startup closes this vulnerability window and prevents client-initiated stream floods / resource exhaustion.\u003c/li\u003e\n\u003cli\u003eservlet: \u003ccode\u003eAsyncServletOutputStreamWriter\u003c/code\u003e detect and handle write when not ready (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12732\"\u003e#12732\u003c/a\u003e) (46f308051) In highly concurrent scenarios, cached servlet container ready to write state can become  stale. The servlet container may have already transitioned to a 'not ready' state, but the corresponding callback has not yet updated gRPC's internal state. This fix makes the ready state to be evaluated explicitly before attempting to write directly to the servlet output stream.\u003c/li\u003e\n\u003cli\u003eokhttp: Move connection window update before stream termination logic (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12990\"\u003e#12990\u003c/a\u003e) (0f859c3bb) By RFC 9113, section 6.9, receivers must take frames into account for flow control even if they're errored. This change moves the stream error response logic after connection window updates\u003c/li\u003e\n\u003cli\u003ecore: Coalesce Contiguous Small Buffers for ReadableBuffer to prevent OOM (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12924\"\u003e#12924\u003c/a\u003e) (0585d481a)\u003c/li\u003e\n\u003cli\u003es2a: Default to Post Quantum Cryptography key exchange gr...\n\n_Description has been truncated_","html_url":"https://github.com/ychrono/yc-otel-demo/pull/438","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/ychrono%2Fyc-otel-demo/issues/438","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/438/packages"},{"uuid":"5459475287","node_id":"PR_kwDOSQDhc88AAAABDk0AiQ","number":5,"state":"closed","title":"Bump com.fasterxml.jackson.core:jackson-databind from 2.18.2 to 2.18.9 in /combo2-advanced-agentic-engineering/java/tiny-agent-java","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-15T11:24:16.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-15T08:22:38.000Z","updated_at":"2026-09-15T11:24:18.000Z","time_to_close":10898,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.18.2","new_version":"2.18.9","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":"/combo2-advanced-agentic-engineering/java/tiny-agent-java","ecosystem":"maven"},"body":"Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.18.2 to 2.18.9.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/f7b3266eb21a232b35520d31ce5e304beb8f1c7c\"\u003e\u003ccode\u003ef7b3266\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.18.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/55e3028d920333fd46dbcebe074017ea0d0bd6e3\"\u003e\u003ccode\u003e55e3028\u003c/code\u003e\u003c/a\u003e Prep for 2.18.9 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/59abdc4d61203962eebf11a46977d253601da76e\"\u003e\u003ccode\u003e59abdc4\u003c/code\u003e\u003c/a\u003e ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/2fc7bd9057dd051d7dea0e5fcad89822d0fa5ebd\"\u003e\u003ccode\u003e2fc7bd9\u003c/code\u003e\u003c/a\u003e Do not allow DNS resolution when deserializing \u003ccode\u003eInetAddress\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6058\"\u003e#6058\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/c628b357ed143d8492756d5c1458cfb9fbeb29ed\"\u003e\u003ccode\u003ec628b35\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003e@JsonView\u003c/code\u003e for external-type-id (\u003ccode\u003eEXTERNAL_PROPERTY\u003c/code\u003e) properties [GHSA...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/d627a8a86fcb062429282f79f3f256f181ed2c7b\"\u003e\u003ccode\u003ed627a8a\u003c/code\u003e\u003c/a\u003e Fix \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6060\"\u003e#6060\u003c/a\u003e -- \u003ccode\u003e@JsonView\u003c/code\u003e skipped for Setter/Field properties with `@JsonUnwra...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bc1613c765704703ec7385e314fa8b19448e1ddd\"\u003e\u003ccode\u003ebc1613c\u003c/code\u003e\u003c/a\u003e Backport PR \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/5964\"\u003e#5964\u003c/a\u003e into 2.18 to fix \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/5962\"\u003e#5962\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6039\"\u003e#6039\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ff5d313269f5bf8ce4caa66096e3567fc72fe910\"\u003e\u003ccode\u003eff5d313\u003c/code\u003e\u003c/a\u003e Add CVE id for \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/5971\"\u003e#5971\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/f95549d66222b3002df05e09c41d693497552b2e\"\u003e\u003ccode\u003ef95549d\u003c/code\u003e\u003c/a\u003e Update CVE id for \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/5969\"\u003e#5969\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/6d6bfea1c3a52790af3370a8a1c466633816737d\"\u003e\u003ccode\u003e6d6bfea\u003c/code\u003e\u003c/a\u003e Update CVE info for \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/5951\"\u003e#5951\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.18.2...jackson-databind-2.18.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.18.2\u0026new-version=2.18.9)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Octoco-AI/ai-course-exercises/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/Octoco-AI/ai-course-exercises/pull/5","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Octoco-AI%2Fai-course-exercises/issues/5","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/5/packages"},{"uuid":"5457492621","node_id":"PR_kwDOBNevYc8AAAABDjNTWQ","number":494,"state":"open","title":"chore(deps): Bump the maven-minor-patch group across 1 directory with 27 updates","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-15T04:25:39.000Z","updated_at":"2026-09-15T04:26:54.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): Bump","group_name":"maven-minor-patch","update_count":27,"packages":[{"name":"org.projectlombok:lombok","old_version":"1.18.46","new_version":"1.18.48","repository_url":"https://github.com/projectlombok/lombok"},{"name":"io.smallrye.common:smallrye-common-function","old_version":"2.19.0","new_version":"2.20.0","repository_url":"https://github.com/smallrye/smallrye-common"},{"name":"org.hibernate.validator:hibernate-validator","old_version":"9.1.2.Final","new_version":"9.1.3.Final","repository_url":"https://github.com/hibernate/hibernate-validator"},{"name":"org.springframework.boot:spring-boot-starter-parent","old_version":"4.1.0","new_version":"4.1.1","repository_url":"https://github.com/spring-projects/spring-boot"},{"name":"org.apache.maven.plugins:maven-surefire-plugin","old_version":"3.5.6","new_version":"3.6.0","repository_url":"https://github.com/apache/maven-surefire"},{"name":"org.apache.maven.plugins:maven-compiler-plugin","old_version":"3.15.0","new_version":"3.16.0","repository_url":"https://github.com/apache/maven-compiler-plugin"},{"name":"org.codehaus.mojo:build-helper-maven-plugin","old_version":"3.6.1","new_version":"3.6.2","repository_url":"https://github.com/mojohaus/build-helper-maven-plugin"},{"name":"io.projectreactor:reactor-core","old_version":"3.8.6","new_version":"3.8.7","repository_url":"https://github.com/reactor/reactor-core"},{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.22.1","new_version":"2.22.2","repository_url":"https://github.com/FasterXML/jackson-databind"},{"name":"io.swagger.core.v3:swagger-annotations","old_version":"2.2.52","new_version":"2.2.55"},{"name":"org.freemarker:freemarker","old_version":"2.3.34","new_version":"2.3.35"},{"name":"net.bytebuddy:byte-buddy-agent","old_version":"1.18.11","new_version":"1.18.13","repository_url":"https://github.com/raphw/byte-buddy"},{"name":"net.bytebuddy:byte-buddy","old_version":"1.18.11","new_version":"1.18.13","repository_url":"https://github.com/raphw/byte-buddy"},{"name":"com.google.guava:guava","old_version":"33.6.0-jre","new_version":"33.7.1-jre","repository_url":"https://github.com/google/guava"},{"name":"org.slf4j:slf4j-api","old_version":"2.0.18","new_version":"2.0.19"},{"name":"com.fasterxml.jackson.datatype:jackson-datatype-jsr310","old_version":"2.22.1","new_version":"2.22.2"},{"name":"com.fasterxml.jackson.dataformat:jackson-dataformat-yaml","old_version":"2.22.1","new_version":"2.22.2","repository_url":"https://github.com/FasterXML/jackson-dataformats-text"},{"name":"com.auth0:java-jwt","old_version":"4.6.0","new_version":"4.6.1","repository_url":"https://github.com/auth0/java-jwt"},{"name":"io.smallrye:jandex-maven-plugin","old_version":"3.2.7","new_version":"3.6.0","repository_url":"https://github.com/smallrye/jandex"},{"name":"io.projectreactor:reactor-test","old_version":"3.8.6","new_version":"3.8.7","repository_url":"https://github.com/reactor/reactor-core"},{"name":"io.quarkus:quarkus-rest","old_version":"3.38.0","new_version":"3.39.3"},{"name":"io.quarkus:quarkus-spring-di","old_version":"3.38.0","new_version":"3.39.3"},{"name":"io.helidon.webserver:helidon-webserver","old_version":"4.5.1","new_version":"4.5.4"},{"name":"org.apache.maven:maven-plugin-api","old_version":"3.9.9","new_version":"3.9.16","repository_url":"https://github.com/apache/maven"},{"name":"org.apache.maven:maven-core","old_version":"3.9.9","new_version":"3.9.16"},{"name":"org.apache.maven.plugin-tools:maven-plugin-annotations","old_version":"3.13.1","new_version":"3.16.0","repository_url":"https://github.com/apache/maven-plugin-tools"},{"name":"org.apache.maven.plugins:maven-plugin-plugin","old_version":"3.13.1","new_version":"3.16.0","repository_url":"https://github.com/apache/maven-plugin-tools"}],"path":null,"ecosystem":"maven"},"body":"Bumps the maven-minor-patch group with 27 updates in the /backend directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [org.projectlombok:lombok](https://github.com/projectlombok/lombok) | `1.18.46` | `1.18.48` |\n| [io.smallrye.common:smallrye-common-function](https://github.com/smallrye/smallrye-common) | `2.19.0` | `2.20.0` |\n| [org.hibernate.validator:hibernate-validator](https://github.com/hibernate/hibernate-validator) | `9.1.2.Final` | `9.1.3.Final` |\n| [org.springframework.boot:spring-boot-starter-parent](https://github.com/spring-projects/spring-boot) | `4.1.0` | `4.1.1` |\n| [org.apache.maven.plugins:maven-surefire-plugin](https://github.com/apache/maven-surefire) | `3.5.6` | `3.6.0` |\n| [org.apache.maven.plugins:maven-compiler-plugin](https://github.com/apache/maven-compiler-plugin) | `3.15.0` | `3.16.0` |\n| [org.codehaus.mojo:build-helper-maven-plugin](https://github.com/mojohaus/build-helper-maven-plugin) | `3.6.1` | `3.6.2` |\n| [io.projectreactor:reactor-core](https://github.com/reactor/reactor-core) | `3.8.6` | `3.8.7` |\n| [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) | `2.22.1` | `2.22.2` |\n| io.swagger.core.v3:swagger-annotations | `2.2.52` | `2.2.55` |\n| org.freemarker:freemarker | `2.3.34` | `2.3.35` |\n| [net.bytebuddy:byte-buddy-agent](https://github.com/raphw/byte-buddy) | `1.18.11` | `1.18.13` |\n| [net.bytebuddy:byte-buddy](https://github.com/raphw/byte-buddy) | `1.18.11` | `1.18.13` |\n| [com.google.guava:guava](https://github.com/google/guava) | `33.6.0-jre` | `33.7.1-jre` |\n| org.slf4j:slf4j-api | `2.0.18` | `2.0.19` |\n| com.fasterxml.jackson.datatype:jackson-datatype-jsr310 | `2.22.1` | `2.22.2` |\n| [com.fasterxml.jackson.dataformat:jackson-dataformat-yaml](https://github.com/FasterXML/jackson-dataformats-text) | `2.22.1` | `2.22.2` |\n| [com.auth0:java-jwt](https://github.com/auth0/java-jwt) | `4.6.0` | `4.6.1` |\n| [io.smallrye:jandex-maven-plugin](https://github.com/smallrye/jandex) | `3.2.7` | `3.6.0` |\n| [io.projectreactor:reactor-test](https://github.com/reactor/reactor-core) | `3.8.6` | `3.8.7` |\n| io.quarkus:quarkus-rest | `3.38.0` | `3.39.3` |\n| io.quarkus:quarkus-spring-di | `3.38.0` | `3.39.3` |\n| io.helidon.webserver:helidon-webserver | `4.5.1` | `4.5.4` |\n| [org.apache.maven:maven-plugin-api](https://github.com/apache/maven) | `3.9.9` | `3.9.16` |\n| org.apache.maven:maven-core | `3.9.9` | `3.9.16` |\n| [org.apache.maven.plugin-tools:maven-plugin-annotations](https://github.com/apache/maven-plugin-tools) | `3.13.1` | `3.16.0` |\n| [org.apache.maven.plugins:maven-plugin-plugin](https://github.com/apache/maven-plugin-tools) | `3.13.1` | `3.16.0` |\n\n\nUpdates `org.projectlombok:lombok` from 1.18.46 to 1.18.48\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/projectlombok/lombok/blob/master/doc/changelog.markdown\"\u003eorg.projectlombok:lombok's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch3\u003ev1.18.48 (September 1st, 2026)\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBREAKING CHANGE/BUGFIX: \u003ccode\u003e@Builder(builderClassName = \u0026quot;Builder\u0026quot;)\u003c/code\u003e now generates an error, because the type names collide. \u003ca href=\"https://redirect.github.com/projectlombok/lombok/issues/3857\"\u003e#3857\u003c/a\u003e  (found after release)\u003c/li\u003e\n\u003cli\u003ePLATFORM: JDK27 support added \u003ca href=\"https://redirect.github.com/projectlombok/lombok/issues/4072\"\u003e#4072\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eBUGFIX: \u003ccode\u003e@SneakyThrows\u003c/code\u003e usage on JDK26 no longer results in class files that require \u003ccode\u003elombok.jar\u003c/code\u003e to be on the runtime classpath (which should not be neccessary). \u003ca href=\"https://redirect.github.com/projectlombok/lombok/issues/4040\"\u003e#4040\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFEATURE: New \u003ca href=\"https://projectlombok.org/features/configuration\"\u003econfig key\u003c/a\u003e \u003ccode\u003elombok.checkReturnValueAnnotation\u003c/code\u003e (values: \u003ccode\u003enone\u003c/code\u003e, \u003ccode\u003elombok\u003c/code\u003e; default: \u003ccode\u003enone\u003c/code\u003e) lets lombok generate \u003ccode\u003e@lombok.CheckReturnValue\u003c/code\u003e on generated methods where the return value should not be ignored, such as \u003ccode\u003e@With\u003c/code\u003e methods and \u003ccode\u003e@Builder.build()\u003c/code\u003e. A future lombok release may flip the default to \u003ccode\u003elombok\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/projectlombok/lombok/pull/4013\"\u003e#4013\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003ePROMOTION: \u003ccode\u003e@SuperBuilder\u003c/code\u003e has been promoted to the main package. Otherwise, no changes have been made to the annotation. The old experimental annotation will remain for a few versions, at which point it will be marked as a deprecated annotation. Eventually it'll be removed. If you had \u003ccode\u003elombok.config\u003c/code\u003e configuration for this annotation, the configuration keys for this feature have been renamed. \u003ca href=\"https://redirect.github.com/projectlombok/lombok/issues/2209\"\u003e#2209\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eOLD-CRUFT: \u003ccode\u003elombok.experimental.Wither\u003c/code\u003e and \u003ccode\u003elombok.Delegate\u003c/code\u003e are deprecated remnants; these features were moved (to respectively \u003ccode\u003elombok.With\u003c/code\u003e and \u003ccode\u003elombok.experimental.Delegate\u003c/code\u003e over 5 years ago. They are now removed entirely. If your project is dependent on an older version of lombok which still has those; fret not, lombok still processes these annotations. It just no longer includes them in the jar.\u003c/li\u003e\n\u003cli\u003eFEATURE: CheckerFramework: Lombok now adds \u003ccode\u003e@SideEffectFree\u003c/code\u003e to constructors it makes if you have enabled checker framework via \u003ccode\u003elombok.config\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eBUGFIX: CheckerFramework: Lombok would add \u003ccode\u003e@SideEffectFree\u003c/code\u003e to the \u003ccode\u003ebuild()\u003c/code\u003e method of any generated builder, even if it is a builder for invoking a method; in that case, the side-effect-free nature of \u003ccode\u003ebuild()\u003c/code\u003e mirrors the side-effect-free nature of the method invocation you've built. Lombok now checks if the method it generated a builder for is side effect free / 'check return type'.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/projectlombok/lombok/commit/b48657c83ce44d027984f539bd36048293ce5e8e\"\u003e\u003ccode\u003eb48657c\u003c/code\u003e\u003c/a\u003e [version] pre-release version bump v1.18.48\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/projectlombok/lombok/commit/d1d003945f864d32bb3115cf81fa363e1c7bc6bb\"\u003e\u003ccode\u003ed1d0039\u003c/code\u003e\u003c/a\u003e Merge branch 'jdk27'\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/projectlombok/lombok/commit/1a23dad52c01e7b18892573549841e36d6e4abde\"\u003e\u003ccode\u003e1a23dad\u003c/code\u003e\u003c/a\u003e [review][refactor] No meaningful changes: Improved comments, javadoc, and cle...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/projectlombok/lombok/commit/40cdde815038a4bddc2bc31afce80c4c62e75e67\"\u003e\u003ccode\u003e40cdde8\u003c/code\u003e\u003c/a\u003e [changelog] JDK27 support\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/projectlombok/lombok/commit/25eae29093410cba53e3f91e2da4ba1fbf1953f4\"\u003e\u003ccode\u003e25eae29\u003c/code\u003e\u003c/a\u003e Add Danish Nawab to AUTHORS\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/projectlombok/lombok/commit/10ab92b5d9eb852ccac7295d8017203e7efd7449\"\u003e\u003ccode\u003e10ab92b\u003c/code\u003e\u003c/a\u003e Support JDK27: end positions moved from EndPosTable to JCTree.endpos\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/projectlombok/lombok/commit/af01b7a27b469b723e88de508480186113569185\"\u003e\u003ccode\u003eaf01b7a\u003c/code\u003e\u003c/a\u003e Document the new configuration syntax for listy things\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/projectlombok/lombok/commit/1be3857dfef96cde703012a43ec649a4c3f7eea9\"\u003e\u003ccode\u003e1be3857\u003c/code\u003e\u003c/a\u003e There is no more HtAccess\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/projectlombok/lombok/commit/405985dd2512786439448e43f390c359e7595269\"\u003e\u003ccode\u003e405985d\u003c/code\u003e\u003c/a\u003e Semantic sections for website\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/projectlombok/lombok/commit/04b73406d04a279401b43a74314aa1dcbadbc143\"\u003e\u003ccode\u003e04b7340\u003c/code\u003e\u003c/a\u003e [trivial] fixing some outdated tests (tests were broken, not lombok).\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/projectlombok/lombok/compare/v1.18.46...v1.18.48\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `io.smallrye.common:smallrye-common-function` from 2.19.0 to 2.20.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/smallrye/smallrye-common/commit/defd310a881f1c168e958f8f73fc7c6518499a4e\"\u003e\u003ccode\u003edefd310\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release 2.20.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/smallrye/smallrye-common/commit/ffc98f68f60160620b1156b233dd650104f09862\"\u003e\u003ccode\u003effc98f6\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/smallrye/smallrye-common/issues/581\"\u003e#581\u003c/a\u003e from smallrye/release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/smallrye/smallrye-common/commit/7cf7fcc86bddc8a9e96f14a34ac292e617d0202b\"\u003e\u003ccode\u003e7cf7fcc\u003c/code\u003e\u003c/a\u003e Release 2.20.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/smallrye/smallrye-common/commit/e6f3c592559944617e16f008f1d1ac3285fcef75\"\u003e\u003ccode\u003ee6f3c59\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/smallrye/smallrye-common/issues/579\"\u003e#579\u003c/a\u003e from smallrye/dependabot/maven/version.vertx4-4.5.30\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/smallrye/smallrye-common/commit/232049fc7397665ed85ed6a57ae57574a7a2b84f\"\u003e\u003ccode\u003e232049f\u003c/code\u003e\u003c/a\u003e Bump version.vertx4 from 4.5.29 to 4.5.30\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/smallrye/smallrye-common/commit/b89fee46677f6d62fa10cfb67adb16fbe9fe767a\"\u003e\u003ccode\u003eb89fee4\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/smallrye/smallrye-common/issues/576\"\u003e#576\u003c/a\u003e from smallrye/dependabot/maven/org.graalvm.sdk-native...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/smallrye/smallrye-common/commit/d2c6a36fce245cb95cf3a08f8268c530f6eceeff\"\u003e\u003ccode\u003ed2c6a36\u003c/code\u003e\u003c/a\u003e Bump org.graalvm.sdk:nativeimage from 25.0.3 to 25.1.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/smallrye/smallrye-common/commit/dc378965bead25b95112ee86c264ff88b41fd7e4\"\u003e\u003ccode\u003edc37896\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/smallrye/smallrye-common/issues/578\"\u003e#578\u003c/a\u003e from smallrye/dependabot/maven/version.vertx4-4.5.29\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/smallrye/smallrye-common/commit/3d73326ea1c881fad45e48db7a67383359be1f35\"\u003e\u003ccode\u003e3d73326\u003c/code\u003e\u003c/a\u003e Bump version.vertx4 from 4.5.28 to 4.5.29\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/smallrye/smallrye-common/commit/bdb9f0b6c1089eddb54a3959905d0316aa49db37\"\u003e\u003ccode\u003ebdb9f0b\u003c/code\u003e\u003c/a\u003e Bump io.smallrye:smallrye-parent from 50 to 51 (\u003ca href=\"https://redirect.github.com/smallrye/smallrye-common/issues/577\"\u003e#577\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/smallrye/smallrye-common/compare/2.19.0...2.20.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.hibernate.validator:hibernate-validator` from 9.1.2.Final to 9.1.3.Final\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hibernate/hibernate-validator/releases\"\u003eorg.hibernate.validator:hibernate-validator's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 9.1.3.Final\u003c/h2\u003e\n\u003ch1\u003eHibernate Validator 9.1.3.Final released\u003c/h1\u003e\n\u003cp\u003eWe are pleased to announce the release of Hibernate Validator 9.1: 9.1.3.Final.\u003c/p\u003e\n\u003cp\u003eYou can find the full list of 9.1.3.Final changes \u003ca href=\"https://hibernate.atlassian.net/issues/?jql=project%20%3D%20HV%20AND%20fixVersion%20%3D%209.1.3.Final\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eWhat's new\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSee the \u003ca href=\"https://hibernate.org/validator/releases/9.1\"\u003ewebsite\u003c/a\u003e for requirements and compatibilities.\u003c/li\u003e\n\u003cli\u003eSee the \u003ca href=\"https://docs.hibernate.org/validator/9.1/whats-new/en-US/html_single/\"\u003eWhat's New\u003c/a\u003e guide for details about new features and capabilities.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eConclusion\u003c/h2\u003e\n\u003cp\u003eFor additional details, see:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe \u003ca href=\"https://hibernate.org/validator/releases/9.1/\"\u003erelease page\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/validator/9.1/migration-guide/\"\u003eMigration Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/validator/9.1/reference/en-US/html_single/#validator-gettingstarted\"\u003eGetting started\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/validator/9.1/reference/en-US/html_single/\"\u003eReference Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/validator/9.1/api\"\u003eAPI docs\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eVisit the \u003ca href=\"https://hibernate.org/community/\"\u003ewebsite\u003c/a\u003e for details on getting in touch with us.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hibernate/hibernate-validator/blob/9.1.3.Final/changelog.md\"\u003eorg.hibernate.validator:hibernate-validator's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e9.1.3.Final (2026-07-26)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://hibernate.atlassian.net/projects/HV/versions/40065\"\u003eFull changelog\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eBug\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://hibernate.atlassian.net/browse/HV-2231\"\u003eHV-2231\u003c/a\u003e - RegexpURLValidator throws NPE when URL has no authority component\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/8ab68bcc99e0727065e194693f5c3b03395fa87e\"\u003e\u003ccode\u003e8ab68bc\u003c/code\u003e\u003c/a\u003e [Jenkins release job] Preparing release 9.1.3.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/36a8551a92d42ae8ece6e2f534fa1d16df088943\"\u003e\u003ccode\u003e36a8551\u003c/code\u003e\u003c/a\u003e [Jenkins release job] changelog.md updated by release build 9.1.3.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/e8b4ebd670356e58c14d11a569044a228f63e09a\"\u003e\u003ccode\u003ee8b4ebd\u003c/code\u003e\u003c/a\u003e [Jenkins release job] README.md updated by release build 9.1.3.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/8ba5072bc668fc14d71d169c1897e11112a9e084\"\u003e\u003ccode\u003e8ba5072\u003c/code\u003e\u003c/a\u003e HV-2231 Fix NPE in RegexpURLValidator when URL has no host\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/e9d4856774aae38431feb9569e4fe58af02806f6\"\u003e\u003ccode\u003ee9d4856\u003c/code\u003e\u003c/a\u003e [9.1] Bump the build-dependencies group with 3 updates\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/7793c80bfa0d99390229863bc5a7b95dab8d34a7\"\u003e\u003ccode\u003e7793c80\u003c/code\u003e\u003c/a\u003e Use correct env var name for additional arguments in the release script\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/8cffdd8f9ca4a0d869772ff11686507b0fc0726e\"\u003e\u003ccode\u003e8cffdd8\u003c/code\u003e\u003c/a\u003e [Jenkins release job] Preparing next development iteration\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/hibernate/hibernate-validator/compare/9.1.2.Final...9.1.3.Final\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.springframework.boot:spring-boot-starter-parent` from 4.1.0 to 4.1.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/spring-projects/spring-boot/releases\"\u003eorg.springframework.boot:spring-boot-starter-parent's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.1.1\u003c/h2\u003e\n\u003ch2\u003e:warning: Attention Required\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSpring Boot's Gradle plugin no longer automatically configures gRPC when the Protobuf plugin is applied. This behavior caused problems for those using Protobuf without gRPC. To opt in to the configuration of gRPC, configure the \u003ccode\u003eprotobuf\u003c/code\u003e extension with the \u003ccode\u003egrpc\u003c/code\u003e plugin using an empty block. The Spring Boot Gradle plugin will then automatically configure the use of \u003ccode\u003eprotoc-gen-grpc-java\u003c/code\u003e as before. \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50822\"\u003e#50822\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e:lady_beetle: Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eKafka consumer-specific security protocol is not taken into account \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/51369\"\u003e#51369\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eStructured logging: a failed JSON encode corrupts the next log event written on the same thread \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/pull/51156\"\u003e#51156\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMicrometer registries pin the application context \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/51135\"\u003e#51135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTemporary file is not deleted when ExportedImageTar construction fails \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/51132\"\u003e#51132\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMetadata annotation processor ignores getter-level \u003ccode\u003e@NestedConfigurationProperty\u003c/code\u003e for records \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/51098\"\u003e#51098\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003espring-boot-h2-console pulls servlet-api as transitive dependency \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/51095\"\u003e#51095\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePropertiesLauncher does not log nested archive paths \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/51089\"\u003e#51089\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMethods that return the result of Map#remove are not declared with a \u003ccode\u003e@Nullable\u003c/code\u003e return type \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/51087\"\u003e#51087\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eNativeImageResourceProvider flattens Flyway migration paths in subdirectories \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50964\"\u003e#50964\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix ordering of Kotlinx Serialization CodecCustomizer \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50961\"\u003e#50961\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJarFile is not closed when finding main class from archive \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50959\"\u003e#50959\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eApplication-managed JUL bridge handler should only be removed if installed \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50950\"\u003e#50950\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCloudFoundry reactive auto-configuration should not require a WebClient.Builder bean to be defined \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50944\"\u003e#50944\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eContext refresh fails on reactive Cloud Foundry when using Actuator without spring-boot-health \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50942\"\u003e#50942\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eResources are not cleaned up when resolving an image that is not yet present in the builder \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50941\"\u003e#50941\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eGraphQlWebMvcAutoConfiguration should apply customizers in order \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50914\"\u003e#50914\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAuto-configured RedisMessageListenerContainer does not use virtual threads when spring.threads.virtual.enabled is true \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50884\"\u003e#50884\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eContext refresh fails when using Actuator on Jersey without spring-boot-health \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50872\"\u003e#50872\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eContext refresh fails on Cloud Foundry when using Actuator without spring-boot-health \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50871\"\u003e#50871\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIllegalStateException when binding properties to a \u003ccode\u003e@Validated\u003c/code\u003e class that contains a map whose value type is a wildcard \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50856\"\u003e#50856\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHigh number of connections due to Mongo health indicator \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50852\"\u003e#50852\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eInconsistent handling of empty string values of spring.security.oauth2.resourceserver.jwt issuer-uri and jwk-set-uri \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50849\"\u003e#50849\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReturn type nullability of ApplicationContextAssert's getBean methods does not indicate that bean may be null \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50845\"\u003e#50845\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePropertiesWebClientHttpServiceGroupConfigurer has highest precedence, preventing other configurers from being ordered ahead of it \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50843\"\u003e#50843\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExposing gRPC test server port should backoff if gRPC is not present \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50825\"\u003e#50825\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJpaBaseConfiguration#entityManagerConfiguration can cause a dependency loop on beans declaring AsyncTaskExecutor \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/pull/50801\"\u003e#50801\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003espring.grpc.server.health.include-overall-health is not taken into account \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/pull/50799\"\u003e#50799\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSetting 'server.servlet.session.cookie.partitioned' to false still emits the 'Partitioned' cookie attribute \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50790\"\u003e#50790\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eManaged version of Prometheus Client is not aligned with Micrometer's micrometer-registry-prometheus \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50780\"\u003e#50780\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMap properties bound from empty strings fail with ConverterNotFoundException \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/pull/50773\"\u003e#50773\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eProtobuf Common Protos should not be a managed dependency \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50772\"\u003e#50772\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAn application that depends on spring-boot-security-oauth2-resource-server may fail to start with a ClassNotFoundException when Reactor is on the classpath but WebFlux is not \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50764\"\u003e#50764\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eW3CHeaderParser's decoding is not compliant with RFC 3986 \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/pull/50650\"\u003e#50650\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e:notebook_with_decorative_cover: Documentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDescription of spring.graphql.websocket.connection-init-timeout does not render correctly in the reference guide \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/pull/51348\"\u003e#51348\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003espring.profiles.group should have a 'spring-profile-name' hint provider \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/51284\"\u003e#51284\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove reference to removed InfluxDB auto-configuration \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/51176\"\u003e#51176\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse JacksonJsonSerde in Kafka Streams documentation \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/51161\"\u003e#51161\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDocument alternatives to HttpMessageConverters \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/51129\"\u003e#51129\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix stale type reference for OTLP logging transport metadata \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/pull/51119\"\u003e#51119\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMetadata for spring.test.mockmvc.htmlunit.url declares the wrong type \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/51115\"\u003e#51115\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/6fdf67ea1552691e932604d4bf67a5e08ff0b0ea\"\u003e\u003ccode\u003e6fdf67e\u003c/code\u003e\u003c/a\u003e Release 4.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/fde599b28b40932e4ea6194399d89245923a01e7\"\u003e\u003ccode\u003efde599b\u003c/code\u003e\u003c/a\u003e Upgrade to Spring Pulsar 2.0.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/9daa58f7d98b82bf16febcb91943ce267c220a50\"\u003e\u003ccode\u003e9daa58f\u003c/code\u003e\u003c/a\u003e Upgrade to Spring HATEOAS 3.1.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/353993ebc1d7b1ceccbb981b0439a42ba122a816\"\u003e\u003ccode\u003e353993e\u003c/code\u003e\u003c/a\u003e Upgrade to Spring Data Bom 2026.0.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/24ba596bc4fa000614834016452435c834fdeda2\"\u003e\u003ccode\u003e24ba596\u003c/code\u003e\u003c/a\u003e Upgrade to Spring Session 4.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/5cb5c294d1f4780e78d010a964049e47c074e4d6\"\u003e\u003ccode\u003e5cb5c29\u003c/code\u003e\u003c/a\u003e Upgrade to Spring Security 7.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/4adc8eb130c4e0c688ed85316f385f4e04d47679\"\u003e\u003ccode\u003e4adc8eb\u003c/code\u003e\u003c/a\u003e Upgrade to Spring LDAP 4.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/4d9c19cbc0589f57a7265052b507bf4b961082ac\"\u003e\u003ccode\u003e4d9c19c\u003c/code\u003e\u003c/a\u003e Upgrade to Spring Kafka 4.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/f30f6120c4f6f8f873ac56cba478ae1f011c276c\"\u003e\u003ccode\u003ef30f612\u003c/code\u003e\u003c/a\u003e Upgrade to Spring Integration 7.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/b930283d97e92eb24da1de3721cdd41625266dea\"\u003e\u003ccode\u003eb930283\u003c/code\u003e\u003c/a\u003e Upgrade to Spring gRPC 1.1.1\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/spring-projects/spring-boot/compare/v4.1.0...v4.1.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.maven.plugins:maven-surefire-plugin` from 3.5.6 to 3.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/apache/maven-surefire/releases\"\u003eorg.apache.maven.plugins:maven-surefire-plugin's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.6.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003ePlease refer to the main page for what's new \u003ca href=\"https://maven.apache.org/surefire/\"\u003ehttps://maven.apache.org/surefire/\u003c/a\u003e\nAnd the migration page \u003ca href=\"https://maven.apache.org/surefire/maven-surefire-plugin/whats-new-3-6-0.html\"\u003ehttps://maven.apache.org/surefire/maven-surefire-plugin/whats-new-3-6-0.html\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e🚀 New features and improvements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3303\"\u003e#3303\u003c/a\u003e: distinguish JUnit 6 ParameterizedClass invocations (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3432\"\u003e#3432\u003c/a\u003e) \u003ca href=\"https://github.com/AzazelSensei\"\u003e\u003ccode\u003e@​AzazelSensei\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-1639\"\u003e[SUREFIRE-1639]\u003c/a\u003e - Add ability to configure JUnit 5 TestExecutionListener (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3438\"\u003e#3438\u003c/a\u003e) \u003ca href=\"https://github.com/pan3793\"\u003e\u003ccode\u003e@​pan3793\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIssue \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/838\"\u003e#838\u003c/a\u003e Implement extension point to run diagnosis tools when forked JVM times out (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3372\"\u003e#3372\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-2148\"\u003e[SUREFIRE-2148]\u003c/a\u003e - Verify recovered BeforeAll does not fail build (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3419\"\u003e#3419\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-823\"\u003e[SUREFIRE-823]\u003c/a\u003e - Decouple -DskipTests from Failsafe plugin (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3371\"\u003e#3371\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse StackWalker in StackTraceProvider when available (Java 9+) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3374\"\u003e#3374\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Issue-3380] Send sourceQualifiedName to forked clients (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3380\"\u003e#3380\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3381\"\u003e#3381\u003c/a\u003e) \u003ca href=\"https://github.com/fabriciorby\"\u003e\u003ccode\u003e@​fabriciorby\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-523\"\u003e[SUREFIRE-523]\u003c/a\u003e - Link all reported tests to source XRef (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3445\"\u003e#3445\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-3446\"\u003e[SUREFIRE-3446]\u003c/a\u003e - Fix direct selection of JUnit Jupiter \u003ca href=\"https://github.com/Nested\"\u003e\u003ccode\u003e@​Nested\u003c/code\u003e\u003c/a\u003e classes (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3447\"\u003e#3447\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDiscover tests in a fork when a toolchain JDK is used (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3444\"\u003e#3444\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[SUREFIRE-2239, SUREFIRE-2241, SUREFIRE-2260, SUREFIRE-2274, SUREFIRE-2300] Preserve JUnit Platform test identity across reruns (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3418\"\u003e#3418\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3428\"\u003e#3428\u003c/a\u003e: resolve parents via TestPlan.getParent for pre-1.8 platforms (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3429\"\u003e#3429\u003c/a\u003e) \u003ca href=\"https://github.com/kalayciburak\"\u003e\u003ccode\u003e@​kalayciburak\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-859\"\u003e[SUREFIRE-859]\u003c/a\u003e - Make random test order reproducible (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3421\"\u003e#3421\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[SUREFIRE-862, SUREFIRE-3178] Handle missing Failsafe summary files (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3417\"\u003e#3417\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: report AfterAll/AfterClass exceptions as errors again (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3412\"\u003e#3412\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3413\"\u003e#3413\u003c/a\u003e) \u003ca href=\"https://github.com/arimu1\"\u003e\u003ccode\u003e@​arimu1\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixes \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3264\"\u003e#3264\u003c/a\u003e : tests inside \u003ca href=\"https://github.com/Suite\"\u003e\u003ccode\u003e@​Suite\u003c/code\u003e\u003c/a\u003e incorrectly classified as flakes (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3342\"\u003e#3342\u003c/a\u003e) \u003ca href=\"https://github.com/mirkoalicastro\"\u003e\u003ccode\u003e@​mirkoalicastro\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix Windows flake in CommandChannelDecoderTest (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3400\"\u003e#3400\u003c/a\u003e) \u003ca href=\"https://github.com/ascheman\"\u003e\u003ccode\u003e@​ascheman\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix reportNameSuffix in XML testcase classname (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3379\"\u003e#3379\u003c/a\u003e) \u003ca href=\"https://github.com/goutamadwant\"\u003e\u003ccode\u003e@​goutamadwant\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix: resolve relative classpath elements against the fork's working dir (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3333\"\u003e#3333\u003c/a\u003e) \u003ca href=\"https://github.com/cwegener-79\"\u003e\u003ccode\u003e@​cwegener-79\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📝 Documentation updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMagnify the home, well at least have something rather than nothing :) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3377\"\u003e#3377\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRestore the straight quotes the FAQ conversion turned typographic (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3425\"\u003e#3425\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRestore the table borders lost in the APT conversion (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3424\"\u003e#3424\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eConvert the FAQ from FML to Markdown (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3423\"\u003e#3423\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eConvert the remaining site documentation from APT to Markdown (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3422\"\u003e#3422\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ejavadoc: clarify statelessTestsetReporter, consoleOutputReporter, (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3410\"\u003e#3410\u003c/a\u003e) \u003ca href=\"https://github.com/joshinii\"\u003e\u003ccode\u003e@​joshinii\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3387\"\u003e#3387\u003c/a\u003e) \u003ca href=\"https://github.com/potiuk\"\u003e\u003ccode\u003e@​potiuk\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate documentation we support Junit 6 as well :) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3370\"\u003e#3370\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e👻 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eStop dependabot from updating test fixtures (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3440\"\u003e#3440\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMigrate legacy plugin Javadoc annotations (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3416\"\u003e#3416\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse the resolver's own HTTP transport in the report plugin tests (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3414\"\u003e#3414\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin maven-jar-plugin 3.5.1 in modular IT fixtures (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3398\"\u003e#3398\u003c/a\u003e) \u003ca href=\"https://github.com/ascheman\"\u003e\u003ccode\u003e@​ascheman\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3387\"\u003e#3387\u003c/a\u003e) \u003ca href=\"https://github.com/potiuk\"\u003e\u003ccode\u003e@​potiuk\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/0ff622b160253f362511a72d29a1f8067631f9d3\"\u003e\u003ccode\u003e0ff622b\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release surefire-3.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/bb3932a10a9706df70cf8095e2402348b7a64f0b\"\u003e\u003ccode\u003ebb3932a\u003c/code\u003e\u003c/a\u003e Let's go for 3.6.0 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/3002a1648cc8092dbd80492aa00509c825fd58e7\"\u003e\u003ccode\u003e3002a16\u003c/code\u003e\u003c/a\u003e Bump mavenVersion from 3.9.14 to 3.9.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/61a531d5981b0e70f8e88a329150f75501bb73e4\"\u003e\u003ccode\u003e61a531d\u003c/code\u003e\u003c/a\u003e Bump Maven parent version from 47 to 49 (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3449\"\u003e#3449\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/e52ead4cf5075f519578d0053c1ff878dff238f5\"\u003e\u003ccode\u003ee52ead4\u003c/code\u003e\u003c/a\u003e [SUREFIRE-523] Link all reported tests to source XRef (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3445\"\u003e#3445\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/45102fa9f2dfc5bc3d2909798e67358ae33e2d49\"\u003e\u003ccode\u003e45102fa\u003c/code\u003e\u003c/a\u003e [SUREFIRE-3446] Fix direct selection of JUnit Jupiter \u003ca href=\"https://github.com/Nested\"\u003e\u003ccode\u003e@​Nested\u003c/code\u003e\u003c/a\u003e classes (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3447\"\u003e#3447\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/b2e1f70b24df2d8a6cf1583ca955311184e68022\"\u003e\u003ccode\u003eb2e1f70\u003c/code\u003e\u003c/a\u003e Fix \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3303\"\u003e#3303\u003c/a\u003e: distinguish JUnit 6 ParameterizedClass invocations (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3432\"\u003e#3432\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/c051938593a29d654b3c1c20d454b9062c3fa3f4\"\u003e\u003ccode\u003ec051938\u003c/code\u003e\u003c/a\u003e Discover tests in a fork when a toolchain JDK is used (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3444\"\u003e#3444\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/db75df85a76abf35346f559fe7f7f020cf6435b6\"\u003e\u003ccode\u003edb75df8\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-java from 1.5.2 to 1.6.0 (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3441\"\u003e#3441\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/77f2759d895a4460f917bdaaff7a025454afebe4\"\u003e\u003ccode\u003e77f2759\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-interpolation from 1.29 to 1.30.0\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/apache/maven-surefire/compare/surefire-3.5.6...surefire-3.6.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.maven.plugins:maven-compiler-plugin` from 3.15.0 to 3.16.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/apache/maven-compiler-plugin/releases\"\u003eorg.apache.maven.plugins:maven-compiler-plugin's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.16.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e🚀 New features and improvements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRecompile when dependencies change (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1102\"\u003e#1102\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix incremental detection of empty sources, 3.x (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1075\"\u003e#1075\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/MCOMPILER-578\"\u003e[MCOMPILER-578]\u003c/a\u003e - Track outputs across compiler executions (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1091\"\u003e#1091\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBuild fails when annotation processor list is empty (but present) (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1077\"\u003e#1077\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/MCOMPILER-374\"\u003e[MCOMPILER-374]\u003c/a\u003e - Unable to compile MR-JAR code against older directories when module-info.java is present (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1093\"\u003e#1093\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMake mcompiler-120 IT locale independent (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1063\"\u003e#1063\u003c/a\u003e) \u003ca href=\"https://github.com/anilvdl\"\u003e\u003ccode\u003e@​anilvdl\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📝 Documentation updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/MCOMPILER-569\"\u003e[MCOMPILER-569]\u003c/a\u003e - Document implicitly compiled excluded sources (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1092\"\u003e#1092\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1074\"\u003e#1074\u003c/a\u003e) \u003ca href=\"https://github.com/potiuk\"\u003e\u003ccode\u003e@​potiuk\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e👻 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid using deprecated method CompilerConfiguration.setCompilerVersion (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1121\"\u003e#1121\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReplace adopt-openj9 by semeru JDK distribution on GH (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1122\"\u003e#1122\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePort the site documentation from APT to Markdown (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1110\"\u003e#1110\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eVerify against Maven 4.0.0-rc-6 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1105\"\u003e#1105\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix tests on Jenkins (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1100\"\u003e#1100\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1074\"\u003e#1074\u003c/a\u003e) \u003ca href=\"https://github.com/potiuk\"\u003e\u003ccode\u003e@​potiuk\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRefactor compiler mojo to use dependency injection and improve string… (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1066\"\u003e#1066\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix ITs for Maven 3.10.x (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1061\"\u003e#1061\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate maven-surefire-plugin version to 3.x in the MCOMPILER-481 IT (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1035\"\u003e#1035\u003c/a\u003e) \u003ca href=\"https://github.com/cdouillard\"\u003e\u003ccode\u003e@​cdouillard\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📦 Dependency updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump plexusCompilerVersion from 2.16.2 to 2.17.0 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1112\"\u003e#1112\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.codehaus.plexus:plexus-java from 1.5.2 to 1.6.0 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1113\"\u003e#1113\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003euse latest Maven 4 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1045\"\u003e#1045\u003c/a\u003e) \u003ca href=\"https://github.com/hboutemy\"\u003e\u003ccode\u003e@​hboutemy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump apache/maven-gh-actions-shared/.github/workflows/release-drafter.yml from 4 to 5 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1083\"\u003e#1083\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump apache/maven-gh-actions-shared/.github/workflows/pr-automation.yml from 4 to 5 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1082\"\u003e#1082\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump apache/maven-gh-actions-shared/.github/workflows/maven-verify.yml from 4 to 5 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1084\"\u003e#1084\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-plugins from 48 to 49 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1068\"\u003e#1068\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-invoker-plugin from 3.9.1 to 3.10.1 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1047\"\u003e#1047\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-plugins from 47 to 48 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1050\"\u003e#1050\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump mavenVersion from 3.9.14 to 3.9.16 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1054\"\u003e#1054\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.ow2.asm:asm from 9.10 to 9.10.1 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1059\"\u003e#1059\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.ow2.asm:asm from 9.9.1 to 9.10 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1053\"\u003e#1053\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump mavenVersion from 3.9.13 to 3.9.14 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1041\"\u003e#1041\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump mavenVersion from 3.9.12 to 3.9.13 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1038\"\u003e#1038\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugin-testing:maven-plugin-testing-harness from 3.5.0 to 3.5.1 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1032\"\u003e#1032\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/e7bba6ed5f9c17003d5c5d1413144bb214177408\"\u003e\u003ccode\u003ee7bba6e\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release maven-compiler-plugin-3.16.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/c906809e0c0b2c79e8a03165cb942f152a911416\"\u003e\u003ccode\u003ec906809\u003c/code\u003e\u003c/a\u003e Avoid using deprecated method CompilerConfiguration.setCompilerVersion\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/ad74fee36865d7a1752c9b96ff9a9e702565fdb3\"\u003e\u003ccode\u003ead74fee\u003c/code\u003e\u003c/a\u003e Replace adopt-openj9 by semeru JDK distribution on GH\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/beb0eda2100e77d3f01bf4cc89edd5b721411f63\"\u003e\u003ccode\u003ebeb0eda\u003c/code\u003e\u003c/a\u003e Recompile when dependencies change (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/issues/1102\"\u003e#1102\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/a0b689e0e7f13d3a7dded7847a807fe6453e0358\"\u003e\u003ccode\u003ea0b689e\u003c/code\u003e\u003c/a\u003e [MCOMPILER-578] Track outputs across compiler executions (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/issues/1091\"\u003e#1091\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/2e8122841d9b10d2d83a90cc07530d7a09eebc47\"\u003e\u003ccode\u003e2e81228\u003c/code\u003e\u003c/a\u003e Fix incremental detection of empty sources, 3.x (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/issues/1075\"\u003e#1075\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/2132f5bf0cbfcde26301084c4833f1a9420f1baf\"\u003e\u003ccode\u003e2132f5b\u003c/code\u003e\u003c/a\u003e configure ATR project\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/5992b772033a7488767c4b3aa806f080eba96593\"\u003e\u003ccode\u003e5992b77\u003c/code\u003e\u003c/a\u003e Build fails when annotation processor list is empty (but present) (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/issues/1077\"\u003e#1077\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/acccef703e5491c29c6dd9e8381677d3e7927589\"\u003e\u003ccode\u003eacccef7\u003c/code\u003e\u003c/a\u003e Bump plexusCompilerVersion from 2.16.2 to 2.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/72bc4454dfdcd1c3551137e5b27560f88b4480ae\"\u003e\u003ccode\u003e72bc445\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-java from 1.5.2 to 1.6.0\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/apache/maven-compiler-plugin/compare/maven-compiler-plugin-3.15.0...maven-compiler-plugin-3.16.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.codehaus.mojo:build-helper-maven-plugin` from 3.6.1 to 3.6.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mojohaus/build-helper-maven-plugin/releases\"\u003eorg.codehaus.mojo:build-helper-maven-plugin's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.6.2\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReplace raw \u003ccode\u003eNPEx\u003c/code\u003e with customized exception message (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/239\"\u003e#239\u003c/a\u003e) \u003ca href=\"https://github.com/pzygielo\"\u003e\u003ccode\u003e@​pzygielo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e👻 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove redundant maven-resolver-api dependency and ignore Resolver/SLF4J 2.x in Dependabot (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/248\"\u003e#248\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📦 Dependency updates\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cul\u003e\n\u003cli\u003eRemove redundant maven-resolver-api dependency and ignore Resolver/SLF4J 2.x in Dependabot (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/248\"\u003e#248\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.codehaus.plexus:plexus-utils from 4.0.3 to 4.1.0 (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/247\"\u003e#247\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump apache/maven-gh-actions-shared/.github/workflows/release-drafter.yml from 4 to 5 (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/244\"\u003e#244\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.codehaus.mojo:mojo-parent from 96 to 97 (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/246\"\u003e#246\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump apache/maven-gh-actions-shared/.github/workflows/maven-verify.yml from 4 to 5 (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/245\"\u003e#245\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.codehaus.plexus:plexus-utils from 4.0.2 to 4.0.3 (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/241\"\u003e#241\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.codehaus.mojo:mojo-parent from 95 to 96 (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/240\"\u003e#240\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.codehaus.mojo:mojo-parent from 94 to 95 (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/235\"\u003e#235\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.codehaus.mojo:mojo-parent from 93 to 94 (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/233\"\u003e#233\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.codehaus.mojo:mojo-parent from 92 to 93 (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/232\"\u003e#232\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.codehaus.mojo:mojo-parent from 91 to 92 (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/231\"\u003e#231\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mojohaus/build-helper-maven-plugin/commit/813bc7d2f03f2c9975de1f079cf7a7334211e0b6\"\u003e\u003ccode\u003e813bc7d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release 3.6.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mojohaus/build-helper-maven-plugin/commit/07d91091b06db894178bcb6e71bc55f857546f46\"\u003e\u003ccode\u003e07d9109\u003c/code\u003e\u003c/a\u003e Remove redundant maven-resolver-api and ignore Resolver/SLF4J 2.x in Dependabot\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mojohaus/build-helper-maven-plugin/commit/9abd552f324e429beb586407139eb4d43127344a\"\u003e\u003ccode\u003e9abd552\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-utils from 4.0.3 to 4.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mojohaus/build-helper-maven-plugin/commit/3c15526bf151e28d6ce651197b36958164da4d4a\"\u003e\u003ccode\u003e3c15526\u003c/code\u003e\u003c/a\u003e Bump apache/maven-gh-actions-shared/.github/workflows/release-drafter.yml\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mojohaus/build-helper-maven-plugin/commit/3b1f104096756ce33e8fc3e4c3062b1ccd8cf227\"\u003e\u003ccode\u003e3b1f104\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.mojo:mojo-parent from 96 to 97\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mojohaus/build-helper-maven-plugin/commit/1749855c90317f651eed427e45cb27c52cf8a542\"\u003e\u003ccode\u003e1749855\u003c/code\u003e\u003c/a\u003e Bump apache/maven-gh-actions-shared/.github/workflows/maven-verify.yml\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mojohaus/build-helper-maven-plugin/commit/52300415d70e84a20924c06c26d9375b152e5409\"\u003e\u003ccode\u003e5230041\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-utils from 4.0.2 to 4.0.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mojohaus/build-helper-maven-plugin/commit/c0e937567a4604534e32cf3cc4c3abb43bfa243c\"\u003e\u003ccode\u003ec0e9375\u003c/code\u003e\u003c/a\u003e Delete .github/release-drafter.yml\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mojohaus/build-helper-maven-plugin/commit/84a839e4cb9b84b3afbbeef7f6c950ba5b478b31\"\u003e\u003ccode\u003e84a839e\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.mojo:mojo-parent from 95 to 96\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mojohaus/build-helper-maven-plugin/commit/a85c668b83334b423844fc448709b1d6e53cb32c\"\u003e\u003ccode\u003ea85c668\u003c/code\u003e\u003c/a\u003e Replace raw \u003ccode\u003eNPEx\u003c/code\u003e with customized exception message\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mojohaus/build-helper-maven-plugin/compare/3.6.1...3.6.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `io.projectreactor:reactor-core` from 3.8.6 to 3.8.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/reactor/reactor-core/releases\"\u003eio.projectreactor:reactor-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.8.7\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003ccode\u003eReactor Core\u003c/code\u003e \u003ccode\u003e3.8.7\u003c/code\u003e is part of the \u003ccode\u003e2025.0.7\u003c/code\u003e and \u003ccode\u003e2026.0.0-M1\u003c/code\u003e \u003cstrong\u003eRelease Trains\u003c/strong\u003e.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003e:lady_beetle: Bug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix elapsed time computation in \u003ccode\u003eOptimisticEmitFailureHandler\u003c/code\u003e by \u003ca href=\"https://github.com/bjmi\"\u003e\u003ccode\u003e@​bjmi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/reactor/reactor-core/issues/4112\"\u003e#4112\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003ewindowTimeout\u003c/code\u003e fair-backpressure index wraparound by \u003ca href=\"https://github.com/chemicL\"\u003e\u003ccode\u003e@​chemicL\u003c/code\u003e\u003c/a\u003e in 9fdb2cf7108d738fe80e65d010571982610b7eb8\u003c/li\u003e\n\u003cli\u003eGuard against flush-state update in \u003ccode\u003eFluxBufferTimeout\u003c/code\u003e by \u003ca href=\"https://github.com/Sage-Pierce\"\u003e\u003ccode\u003e@​Sage-Pierce\u003c/code\u003e\u003c/a\u003e in 1791421affc59e0a551ba8596e4122c069e782ba\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bjmi\"\u003e\u003ccode\u003e@​bjmi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/reactor/reactor-core/issues/4112\"\u003e#4112\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/reactor/reactor-core/compare/v3.8.6...v3.8.7\"\u003ehttps://github.com/reactor/reactor-core/compare/v3.8.6...v3.8.7\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/reactor/reactor-core/commit/cda5359710de9a9b70ff432efe0062190a4014d3\"\u003e\u003ccode\u003ecda5359\u003c/code\u003e\u003c/a\u003e [release] Prepare and release 3.8.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/reactor/reactor-core/commit/c2b3afd7fb1cdc11b84010b5425ef5827391a3d1\"\u003e\u003ccode\u003ec2b3afd\u003c/code\u003e\u003c/a\u003e Prepare release/3.8.7 branch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/reactor/reactor-core/commit/1791421affc59e0a551ba8596e4122c069e782ba\"\u003e\u003ccode\u003e1791421\u003c/code\u003e\u003c/a\u003e Guard against flush-state update in FluxBufferTimeout\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/reactor/reactor-core/commit/9fdb2cf7108d738fe80e65d010571982610b7eb8\"\u003e\u003ccode\u003e9fdb2cf\u003c/code\u003e\u003c/a\u003e Fix windowTimeout fair-backpressure index wraparound\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/reactor/reactor-core/commit/200db94c591322c27ef972b3ca9356af77176641\"\u003e\u003ccode\u003e200db94\u003c/code\u003e\u003c/a\u003e Prepare main-internal branch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/reactor/reactor-core/commit/a794eae1d1aacc684133e5124883e922467b8aab\"\u003e\u003ccode\u003ea794eae\u003c/code\u003e\u003c/a\u003e Bump github/codeql-action from 4.37.5 to 4.37.6 in /.github/workflows (\u003ca href=\"https://redirect.github.com/reactor/reactor-core/issues/4353\"\u003e#4353\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/reactor/reactor-core/commit/87cdb28749a3dc76a808ca3f0bc065d97d80b841\"\u003e\u003ccode\u003e87cdb28\u003c/code\u003e\u003c/a\u003e Bump github/codeql-action from 4.37.4 to 4.37.5 in /.github/workflows (\u003ca href=\"https://redirect.github.com/reactor/reactor-core/issues/4351\"\u003e#4351\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/reactor/reactor-core/commit/ed121c4f7201a1c247b2cd85e6ffef31aeb5de68\"\u003e\u003ccode\u003eed121c4\u003c/code\u003e\u003c/a\u003e Bump gradle/actions/wrapper-validation from 6.2.0 to 6.3.0 in /.github/workfl...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/reactor/reactor-core/commit/869b950f6fe2844af08c43b97b00ec76ee021a97\"\u003e\u003ccode\u003e869b950\u003c/code\u003e\u003c/a\u003e Bump gradle/actions/setup-gradle from 6.2.0 to 6.3.0 in /.github/workflows (#...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/reactor/reactor-core/commit/4f160faaf9ee50575ada93cf2f789b6e8747d7ed\"\u003e\u003ccode\u003e4f160fa\u003c/code\u003e\u003c/a\u003e Bump \u003ccode\u003e@​antora/pdf-extension\u003c/code\u003e from 1.0.0-rc.6 to 1.0.0-rc.7 in /docs (\u003ca href=\"https://redirect.github.com/reactor/reactor-core/issues/4348\"\u003e#4348\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/reactor/reactor-core/compare/v3.8.6...v3.8.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.core:jackson-databind` from 2.22.1 to 2.22.2\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/25b2a221f9aa4107e455065a74635e209418cf55\"\u003e\u003ccode\u003e25b2a22\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.22.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bab1c1a702a941f8805ee6698e8fa4fdbfbec54a\"\u003e\u003ccode\u003ebab1c1a\u003c/code\u003e\u003c/a\u003e Prep for 2.22.2 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bc03cf83d74cf0e5944dce33a63ee59ddc344b64\"\u003e\u003ccode\u003ebc03cf8\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/83379fb6409075336edf3d8d88744e95911a43f8\"\u003e\u003ccode\u003e83379fb\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0d400c9dc586fdd460d0c6a40db21ebbe22106d8\"\u003e\u003ccode\u003e0d400c9\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ce36a279f8b078bef2d9d44a1d01034c3634f91a\"\u003e\u003ccode\u003ece36a27\u003c/code\u003e\u003c/a\u003e Merge branch '2.18' into 2.19\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7a209e1fa97033746db50fd7bcd1e3dbab077599\"\u003e\u003ccode\u003e7a209e1\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/a432707afe6b7569243d1c2d8052a1bf33d9279c\"\u003e\u003ccode\u003ea432707\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/176df1d48b256ced412c65293ad4e09393e24bd3\"\u003e\u003ccode\u003e176df1d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.18.10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7785f5f9ed24127e004115472c47b26ea4cf2774\"\u003e\u003ccode\u003e7785f5f\u003c/code\u003e\u003c/a\u003e Prep for 2.18.10 release\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.22.1...jackson-databind-2.22.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `io.swagger.core.v3:swagger-annotations` from 2.2.52 to 2.2.55\n\nUpdates `org.freemarker:freemarker` from 2.3.34 to 2.3.35\n\nUpdates `net.bytebuddy:byte-buddy-agent` from 1.18.11 to 1.18.13\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/raphw/byte-buddy/releases\"\u003enet.bytebuddy:byte-buddy-agent's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eByte Buddy 1.18.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eActually include the SBOM within the published artifacts.\u003c/li\u003e\n\u003cli\u003eAvoid propagation of path traversals that are contained in jar files which are copied without transformation.\u003c/li\u003e\n\u003cli\u003eAvoid repeated traversal of previously visited type hierarchies to improve performance.\u003c/li\u003e\n\u003cli\u003eCorrect Kotlin support of the Gradle plugin to redirect the classes directory of a source set while retaining support for legacy Gradle versions.\u003c/li\u003e\n\u003cli\u003eCreate Gradle tasks using Gradle's task registration API if available.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eByte Buddy 1.18.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAutomatically support Kotlin in Gradle plugin.\u003c/li\u003e\n\u003cli\u003eAdd support for native attach on Windows for ARM64.\u003c/li\u003e\n\u003cli\u003eCorrect JNA injector which accidentally created on based on Unsafe.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/raphw/byte-buddy/blob/master/release-notes.md\"\u003enet.bytebuddy:byte-buddy-agent's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch3\u003e2. September 2026: version 1.18.13\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eActually include the SBOM within the published artifacts.\u003c/li\u003e\n\u003cli\u003eAvoid propagation of path traversals that are contained in jar files which are copied without transformation.\u003c/li\u003e\n\u003cli\u003eAvoid repeated traversal of previously visited type hierarchies to improve performance.\u003c/li\u003e\n\u003cli\u003eCorrect Kotlin support of the Gradle plugin to redirect the classes directory of a source set while retaining support for legacy Gradle versions.\u003c/li\u003e\n\u003cli\u003eCreate Gradle tasks using Gradle's task registration API if available.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e17. July 2026: version 1.18.12\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAutomatically support Kotlin in Gradle plugin.\u003c/li\u003e\n\u003cli\u003eCorrect JNA injector which accidentally created on based on Unsafe.\u003c/li\u003e\n\u003cli\u003eSupport dynamic attach on Windows ARM64 by shipping a native \u003ccode\u003eattach_hotspot_windows\u003c/code\u003e library for \u003ccode\u003ewin32-aarch64\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raphw/byte-buddy/commit/d4da51578490c841b56b38c9c8fc9d3e8815f046\"\u003e\u003ccode\u003ed4da515\u003c/code\u003e\u003c/a\u003e [publish] Releasing Byte Buddy 1.18.13\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raphw/byte-buddy/commit/bb914e33837267c05704f167179ba31abe3bf787\"\u003e\u003ccode\u003ebb914e3\u003c/code\u003e\u003c/a\u003e [release] Release new version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raphw/byte-buddy/commit/af2034b8c55c2596f6430e63152586e02d06fd0e\"\u003e\u003ccode\u003eaf2034b\u003c/code\u003e\u003c/a\u003e Create Gradle tasks via the task registration API if available to avoid the u...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raphw/byte-buddy/commit/30aca5581534d52570a60ffd524109adb3671759\"\u003e\u003ccode\u003e30aca55\u003c/code\u003e\u003c/a\u003e Shortcut traversal of previously visited type hierarchies and harden 1-1 tran...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raphw/byte-buddy/commit/debd527b31bb095c26ff6943545cfe01a9045f32\"\u003e\u003ccode\u003edebd527\u003c/code\u003e\u003c/a\u003e Bump actions/checkout from 6.0.2 to 7.0.1 (\u003ca href=\"https://redirect.github.com/raphw/byte-buddy/issues/1910\"\u003e#1910\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raphw/byte-buddy/commit/8315af6acb72b5e0d913ad65c4112e828f01d735\"\u003e\u003ccode\u003e8315af6\u003c/code\u003e\u003c/a\u003e Bump step-security/harden-runner from 2.16.1 to 2.19.4 (\u003ca href=\"https://redirect.github.com/raphw/byte-buddy/issues/1909\"\u003e#1909\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raphw/byte-buddy/commit/e30e24f4106f6be28b97a34c81bf6d5dccfa34bb\"\u003e\u003ccode\u003ee30e24f\u003c/code\u003e\u003c/a\u003e Bump actions/cache from 5.0.3 to 5.0.5 (\u003ca href=\"https://redirect.github.com/raphw/byte-buddy/issues/1914\"\u003e#1914\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raphw/byte-buddy/commit/1885f2a1e77d70d3cc57ff935e2b5a4b675cde85\"\u003e\u003ccode\u003e1885f2a\u003c/code\u003e\u003c/a\u003e Bump github/codeql-action from 3.27.6 to 4.36.2 (\u003ca href=\"https://redirect.github.com/raphw/byte-buddy/issues/1916\"\u003e#1916\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raphw/byte-buddy/commit/de4ed85e1e4e1e83dcfd90fc791684e3607459fa\"\u003e\u003ccode\u003ede4ed85\u003c/code\u003e\u003c/a\u003e Correct Javadoc of Gradle plugin to avoid errors and warnings during generation.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raphw/byte-buddy/commit/5d3a3129ceb66ec0c168c9648757cbffccf18aec\"\u003e\u003ccode\u003e5d3a312\u003c/code\u003e\u003c/a\u003e Bump actions/setup-java from 5.2.0 to 5.4.0 (\u003ca href=\"https://redirect.github.com/raphw/byte-buddy/issues/1918\"\u003e#1918\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/raphw/byte-buddy/compare/byte-buddy-1.18.11...byte-buddy-1.18.13\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `net.bytebuddy:byte-buddy` from 1.18.11 to 1.18.13\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/raphw/byte-buddy/releases\"\u003enet.bytebuddy:byte-buddy's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eByte Buddy 1.18.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eActually include the SBOM within the published artifacts.\u003c/li\u003e\n\u003cli\u003eAvoid propagation of path traversals that are contained in jar files which are copied without transformation.\u003c/li\u003e\n\u003cli\u003eAvoid repeated traversal of previously visited type hierarchies to improve performance.\u003c/li\u003e\n\u003cli\u003eCorrect Kotlin support of the Gradle plugin to redirect the classes directory of a source set while retaining support for legacy Gradle versions.\u003c/li\u003e\n\u003cli\u003eCreate Gradle tasks using Gradle's task registration API if available.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eByte Buddy 1.18.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAutomatically support Kotlin in Gradle plugin.\u003c/li\u003e\n\u003cli\u003eAdd support for native attach on Windows for ARM64.\u003c/li\u003e\n\u003cli\u003eCorrect JNA injector which accidentally created on based on Unsafe.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/raphw/byte-buddy/blob/master/release-notes.md\"\u003enet.bytebuddy:byte-buddy's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch3\u003e2. September 2026: version 1.18.13\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eActually include the SBOM within the published artifacts.\u003c/li\u003e\n\u003cli\u003eAvoid propagation of path traversals that are contained in jar files which are copied without transformation.\u003c/li\u003e\n\u003cli\u003eAvoid repeated traversal of previously visited type hierarchies to improve performance.\u003c/li\u003e\n\u003cli\u003eCorrect Kotlin support of the Gradle plugin to redirect the classes directory of a source set while retaining support for legacy Gradle versions.\u003c/li\u003e\n\u003cli\u003eCreate Gradle tasks using Gradle's task registration API if available.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e17. July 2026: version 1.18.12\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAutomatically support Kotlin in Gradle plugin.\u003c/li\u003e\n\u003cli\u003eCorrect JNA injector which accidentally created on based on Unsafe.\u003c/li\u003e\n\u003cli\u003eSupport dynamic attach on Windows ARM64 by shipping a native \u003ccode\u003eattach_hotspot_windows\u003c/code\u003e library for \u003ccode\u003ewin32-aarch64\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raphw/byte-buddy/commit/d4da51578490c841b56b38c9c8fc9d3e8815f046\"\u003e\u003ccode\u003ed4da515\u003c/code\u003e\u003c/a\u003e [publish] Releasing Byte Buddy 1.18.13\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raphw/byte-buddy/commit/bb914e33837267c0...\n\n_Description has been truncated_","html_url":"https://github.com/miguelperezcolom/mateu/pull/494","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/miguelperezcolom%2Fmateu/issues/494","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/494/packages"}],"issue_packages":[{"old_version":"2.22.2","new_version":"2.22.3","update_type":"patch","path":null,"pr_created_at":"2026-09-29T09:15:39.000Z","version_change":"2.22.2 → 2.22.3","issue":{"uuid":"5628165229","node_id":"PR_kwDOBErimM8AAAABFqiiig","number":9081,"state":"closed","title":"Bump the all-gradle-deps group across 1 directory with 32 updates","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-09-30T01:51:10.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-29T09:15:39.000Z","updated_at":"2026-09-30T01:51:19.000Z","time_to_close":59731,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"all-gradle-deps","update_count":32,"packages":[{"name":"gradle-wrapper","old_version":"9.7.1","new_version":"9.8.0","repository_url":"https://github.com/gradle/gradle"},{"name":"org.slf4j:slf4j-api","old_version":"2.0.19","new_version":"2.0.20"},{"name":"org.slf4j:slf4j-simple","old_version":"2.0.19","new_version":"2.0.20"},{"name":"org.slf4j:jcl-over-slf4j","old_version":"2.0.19","new_version":"2.0.20"},{"name":"org.slf4j:slf4j-simple","old_version":"2.0.19","new_version":"2.0.20"},{"name":"org.slf4j:jcl-over-slf4j","old_version":"2.0.19","new_version":"2.0.20"},{"name":"software.amazon.awssdk:s3","old_version":"2.55.1","new_version":"2.55.6"},{"name":"software.amazon.awssdk:s3-transfer-manager","old_version":"2.55.1","new_version":"2.55.6"},{"name":"software.amazon.awssdk:sts","old_version":"2.55.1","new_version":"2.55.6"},{"name":"software.amazon.awssdk:sso","old_version":"2.55.1","new_version":"2.55.6"},{"name":"software.amazon.awssdk:ssooidc","old_version":"2.55.1","new_version":"2.55.6"},{"name":"software.amazon.awssdk:cloudfront","old_version":"2.55.1","new_version":"2.55.6"},{"name":"software.amazon.awssdk:cloudformation","old_version":"2.55.1","new_version":"2.55.6"},{"name":"software.amazon.awssdk:mediaconvert","old_version":"2.55.1","new_version":"2.55.6"},{"name":"software.amazon.awssdk:s3-transfer-manager","old_version":"2.55.1","new_version":"2.55.6"},{"name":"org.mongodb:bson","old_version":"5.12.0","new_version":"5.13.0","repository_url":"https://github.com/mongodb/mongo-java-driver"},{"name":"org.mongodb:mongodb-driver-sync","old_version":"5.12.0","new_version":"5.13.0","repository_url":"https://github.com/mongodb/mongo-java-driver"},{"name":"org.mongodb:mongodb-driver-legacy","old_version":"5.12.0","new_version":"5.13.0","repository_url":"https://github.com/mongodb/mongo-java-driver"},{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-databind"},{"name":"com.fasterxml.jackson.core:jackson-core","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-core"},{"name":"com.fasterxml.jackson.dataformat:jackson-dataformat-cbor","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-dataformats-binary"},{"name":"com.fasterxml.jackson.dataformat:jackson-dataformat-xml","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-dataformat-xml"},{"name":"com.fasterxml.jackson.datatype:jackson-datatype-jsr310","old_version":"2.22.2","new_version":"2.22.3"},{"name":"com.fasterxml.jackson.dataformat:jackson-dataformat-smile","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-dataformats-binary"},{"name":"com.fasterxml.jackson.dataformat:jackson-dataformat-yaml","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-dataformats-text"},{"name":"tools.jackson.core:jackson-databind","old_version":"3.2.2","new_version":"3.2.3","repository_url":"https://github.com/FasterXML/jackson-databind"},{"name":"com.fasterxml.jackson.core:jackson-core","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-core"},{"name":"com.fasterxml.jackson.dataformat:jackson-dataformat-cbor","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-dataformats-binary"},{"name":"com.fasterxml.jackson.dataformat:jackson-dataformat-xml","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-dataformat-xml"},{"name":"org.apache.groovy:groovy","old_version":"5.1.3","new_version":"6.0.0","repository_url":"https://github.com/apache/groovy"},{"name":"org.apache.groovy:groovy-sql","old_version":"5.1.3","new_version":"6.0.0","repository_url":"https://github.com/apache/groovy"},{"name":"org.apache.groovy:groovy-all","old_version":"5.1.3","new_version":"6.0.0","repository_url":"https://github.com/apache/groovy"},{"name":"org.apache.groovy:groovy-sql","old_version":"5.1.3","new_version":"6.0.0","repository_url":"https://github.com/apache/groovy"},{"name":"com.github.ben-manes.caffeine:caffeine","old_version":"3.2.4","new_version":"3.3.0","repository_url":"https://github.com/ben-manes/caffeine"},{"name":"org.mockito:mockito-core","old_version":"5.23.0","new_version":"5.24.0","repository_url":"https://github.com/mockito/mockito"},{"name":"org.hibernate.validator:hibernate-validator","old_version":"9.1.3.Final","new_version":"9.1.4.Final","repository_url":"https://github.com/hibernate/hibernate-validator"},{"name":"org.mongodb:mongodb-driver-sync","old_version":"5.12.0","new_version":"5.13.0","repository_url":"https://github.com/mongodb/mongo-java-driver"},{"name":"org.mongodb:mongodb-driver-legacy","old_version":"5.12.0","new_version":"5.13.0","repository_url":"https://github.com/mongodb/mongo-java-driver"},{"name":"joda-time:joda-time","old_version":"2.14.3","new_version":"2.14.4","repository_url":"https://github.com/JodaOrg/joda-time"},{"name":"com.fasterxml.jackson.datatype:jackson-datatype-jsr310","old_version":"2.22.2","new_version":"2.22.3"},{"name":"org.apache.groovy:groovy-all","old_version":"5.1.3","new_version":"6.0.0","repository_url":"https://github.com/apache/groovy"},{"name":"com.fasterxml.jackson.dataformat:jackson-dataformat-smile","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-dataformats-binary"},{"name":"com.fasterxml.jackson.dataformat:jackson-dataformat-yaml","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-dataformats-text"},{"name":"software.amazon.awssdk:sts","old_version":"2.55.1","new_version":"2.55.6"},{"name":"software.amazon.awssdk:sso","old_version":"2.55.1","new_version":"2.55.6"},{"name":"software.amazon.awssdk:ssooidc","old_version":"2.55.1","new_version":"2.55.6"},{"name":"com.icegreen:greenmail","old_version":"2.1.13","new_version":"2.1.14","repository_url":"https://github.com/greenmail-mail-test/greenmail"},{"name":"com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer","old_version":"20260313.1","new_version":"20260924.2","repository_url":"https://github.com/OWASP/java-html-sanitizer"},{"name":"software.amazon.awssdk:cloudfront","old_version":"2.55.1","new_version":"2.55.6"},{"name":"software.amazon.awssdk:cloudformation","old_version":"2.55.1","new_version":"2.55.6"},{"name":"software.amazon.awssdk:mediaconvert","old_version":"2.55.1","new_version":"2.55.6"}],"path":null,"ecosystem":"maven"},"body":"Bumps the all-gradle-deps group with 32 updates in the / directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [gradle-wrapper](https://github.com/gradle/gradle) | `9.7.1` | `9.8.0` |\n| org.slf4j:slf4j-api | `2.0.19` | `2.0.20` |\n| org.slf4j:slf4j-simple | `2.0.19` | `2.0.20` |\n| org.slf4j:jcl-over-slf4j | `2.0.19` | `2.0.20` |\n| org.slf4j:slf4j-simple | `2.0.19` | `2.0.20` |\n| org.slf4j:jcl-over-slf4j | `2.0.19` | `2.0.20` |\n| software.amazon.awssdk:s3 | `2.55.1` | `2.55.6` |\n| software.amazon.awssdk:s3-transfer-manager | `2.55.1` | `2.55.6` |\n| software.amazon.awssdk:sts | `2.55.1` | `2.55.6` |\n| software.amazon.awssdk:sso | `2.55.1` | `2.55.6` |\n| software.amazon.awssdk:ssooidc | `2.55.1` | `2.55.6` |\n| software.amazon.awssdk:cloudfront | `2.55.1` | `2.55.6` |\n| software.amazon.awssdk:cloudformation | `2.55.1` | `2.55.6` |\n| software.amazon.awssdk:mediaconvert | `2.55.1` | `2.55.6` |\n| software.amazon.awssdk:s3-transfer-manager | `2.55.1` | `2.55.6` |\n| [org.mongodb:bson](https://github.com/mongodb/mongo-java-driver) | `5.12.0` | `5.13.0` |\n| [org.mongodb:mongodb-driver-sync](https://github.com/mongodb/mongo-java-driver) | `5.12.0` | `5.13.0` |\n| [org.mongodb:mongodb-driver-legacy](https://github.com/mongodb/mongo-java-driver) | `5.12.0` | `5.13.0` |\n| [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) | `2.22.2` | `2.22.3` |\n| [com.fasterxml.jackson.core:jackson-core](https://github.com/FasterXML/jackson-core) | `2.22.2` | `2.22.3` |\n| [com.fasterxml.jackson.dataformat:jackson-dataformat-cbor](https://github.com/FasterXML/jackson-dataformats-binary) | `2.22.2` | `2.22.3` |\n| [com.fasterxml.jackson.dataformat:jackson-dataformat-xml](https://github.com/FasterXML/jackson-dataformat-xml) | `2.22.2` | `2.22.3` |\n| com.fasterxml.jackson.datatype:jackson-datatype-jsr310 | `2.22.2` | `2.22.3` |\n| [com.fasterxml.jackson.dataformat:jackson-dataformat-smile](https://github.com/FasterXML/jackson-dataformats-binary) | `2.22.2` | `2.22.3` |\n| [com.fasterxml.jackson.dataformat:jackson-dataformat-yaml](https://github.com/FasterXML/jackson-dataformats-text) | `2.22.2` | `2.22.3` |\n| [tools.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) | `3.2.2` | `3.2.3` |\n| [com.fasterxml.jackson.core:jackson-core](https://github.com/FasterXML/jackson-core) | `2.22.2` | `2.22.3` |\n| [com.fasterxml.jackson.dataformat:jackson-dataformat-cbor](https://github.com/FasterXML/jackson-dataformats-binary) | `2.22.2` | `2.22.3` |\n| [com.fasterxml.jackson.dataformat:jackson-dataformat-xml](https://github.com/FasterXML/jackson-dataformat-xml) | `2.22.2` | `2.22.3` |\n| [org.apache.groovy:groovy](https://github.com/apache/groovy) | `5.1.3` | `6.0.0` |\n| [org.apache.groovy:groovy-sql](https://github.com/apache/groovy) | `5.1.3` | `6.0.0` |\n| [org.apache.groovy:groovy-all](https://github.com/apache/groovy) | `5.1.3` | `6.0.0` |\n| [org.apache.groovy:groovy-sql](https://github.com/apache/groovy) | `5.1.3` | `6.0.0` |\n| [com.github.ben-manes.caffeine:caffeine](https://github.com/ben-manes/caffeine) | `3.2.4` | `3.3.0` |\n| [org.mockito:mockito-core](https://github.com/mockito/mockito) | `5.23.0` | `5.24.0` |\n| [org.hibernate.validator:hibernate-validator](https://github.com/hibernate/hibernate-validator) | `9.1.3.Final` | `9.1.4.Final` |\n| [org.mongodb:mongodb-driver-sync](https://github.com/mongodb/mongo-java-driver) | `5.12.0` | `5.13.0` |\n| [org.mongodb:mongodb-driver-legacy](https://github.com/mongodb/mongo-java-driver) | `5.12.0` | `5.13.0` |\n| [joda-time:joda-time](https://github.com/JodaOrg/joda-time) | `2.14.3` | `2.14.4` |\n| com.fasterxml.jackson.datatype:jackson-datatype-jsr310 | `2.22.2` | `2.22.3` |\n| [org.apache.groovy:groovy-all](https://github.com/apache/groovy) | `5.1.3` | `6.0.0` |\n| [com.fasterxml.jackson.dataformat:jackson-dataformat-smile](https://github.com/FasterXML/jackson-dataformats-binary) | `2.22.2` | `2.22.3` |\n| [com.fasterxml.jackson.dataformat:jackson-dataformat-yaml](https://github.com/FasterXML/jackson-dataformats-text) | `2.22.2` | `2.22.3` |\n| software.amazon.awssdk:sts | `2.55.1` | `2.55.6` |\n| software.amazon.awssdk:sso | `2.55.1` | `2.55.6` |\n| software.amazon.awssdk:ssooidc | `2.55.1` | `2.55.6` |\n| [com.icegreen:greenmail](https://github.com/greenmail-mail-test/greenmail) | `2.1.13` | `2.1.14` |\n| [com.googlecode.owasp-java-html-sanitizer:owasp-java-html-sanitizer](https://github.com/OWASP/java-html-sanitizer) | `20260313.1` | `20260924.2` |\n| software.amazon.awssdk:cloudfront | `2.55.1` | `2.55.6` |\n| software.amazon.awssdk:cloudformation | `2.55.1` | `2.55.6` |\n| software.amazon.awssdk:mediaconvert | `2.55.1` | `2.55.6` |\n\n\nUpdates `gradle-wrapper` from 9.7.1 to 9.8.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/gradle/gradle/releases\"\u003egradle-wrapper's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e9.8.0\u003c/h2\u003e\n\u003cp\u003eThe Gradle team is excited to announce Gradle 9.8.0.\u003c/p\u003e\n\u003cp\u003eHere are the highlights of this release:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eJava 27 support\u003c/li\u003e\n\u003cli\u003eMaven mirror settings reuse\u003c/li\u003e\n\u003cli\u003eLinked problem locations in build output\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://docs.gradle.org/9.8.0/release-notes.html\"\u003eRead the Release Notes\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eWe would like to thank the following community members for their contributions to this release of Gradle:\n\u003ca href=\"https://github.com/Gautam-aman\"\u003eAman Gautam\u003c/a\u003e,\n\u003ca href=\"https://github.com/Vampire\"\u003eBjörn Kautler\u003c/a\u003e,\n\u003ca href=\"https://github.com/Juneezee\"\u003eEng Zer Jun\u003c/a\u003e,\n\u003ca href=\"https://github.com/Hashim1999164\"\u003eHashim Khan\u003c/a\u003e,\n\u003ca href=\"https://github.com/jkrannich\"\u003eJulian Krannich\u003c/a\u003e,\n\u003ca href=\"https://github.com/youdie006\"\u003eKBS\u003c/a\u003e,\n\u003ca href=\"https://github.com/itsCodeTide\"\u003eLabh R Jethe\u003c/a\u003e,\n\u003ca href=\"https://github.com/doddi\"\u003eMark Dodgson\u003c/a\u003e,\n\u003ca href=\"https://github.com/kroune\"\u003eMaxim\u003c/a\u003e,\n\u003ca href=\"https://github.com/Develop-KIM\"\u003emonkey\u003c/a\u003e,\n\u003ca href=\"https://github.com/nataphon-ktsystems\"\u003enataphon-ktsystems\u003c/a\u003e,\n\u003ca href=\"https://github.com/paulk-asert\"\u003ePaul King\u003c/a\u003e,\n\u003ca href=\"https://github.com/qiu-tiandev\"\u003eQiu Tian\u003c/a\u003e,\n\u003ca href=\"https://github.com/sandeshgorde\"\u003erg_sandesh\u003c/a\u003e,\n\u003ca href=\"https://github.com/rpalcolea\"\u003eRoberto Perez Alcolea\u003c/a\u003e,\n\u003ca href=\"https://github.com/seanxuu\"\u003eSean\u003c/a\u003e,\n\u003ca href=\"https://github.com/Goooler\"\u003eZongle Wang\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eUpgrade instructions\u003c/h2\u003e\n\u003cp\u003eSwitch your build to use Gradle 9.8.0 by updating your wrapper:\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e./gradlew :wrapper --gradle-version=9.8.0 \u0026amp;\u0026amp; ./gradlew :wrapper\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eSee the Gradle \u003ca href=\"https://docs.gradle.org/9.8.0/userguide/upgrading_version_9.html\"\u003e9.x upgrade guide\u003c/a\u003e to learn about deprecations, breaking changes and other considerations when upgrading.\u003c/p\u003e\n\u003cp\u003eFor Java, Groovy, Kotlin and Android compatibility, see the \u003ca href=\"https://docs.gradle.org/9.8.0/userguide/compatibility.html\"\u003efull compatibility notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eReporting problems\u003c/h2\u003e\n\u003cp\u003eIf you find a problem with this release, please file a bug on \u003ca href=\"https://github.com/gradle/gradle/issues\"\u003eGitHub Issues\u003c/a\u003e adhering to our issue guidelines.\nIf you're not sure you're encountering a bug, please use the \u003ca href=\"https://discuss.gradle.org/c/help-discuss\"\u003eforum\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eWe hope you will build happiness with Gradle, and we look forward to your feedback via \u003ca href=\"https://twitter.com/gradle\"\u003eTwitter\u003c/a\u003e or on \u003ca href=\"https://github.com/gradle\"\u003eGitHub\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003e9.8.0 RC3\u003c/h2\u003e\n\u003cp\u003eThe Gradle team is excited to announce Gradle 9.8.0 RC3.\u003c/p\u003e\n\u003cp\u003eHere are the highlights of this release:\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/a927be5e08efe79e0b87ada06c762dde6bb9f8b8\"\u003e\u003ccode\u003ea927be5\u003c/code\u003e\u003c/a\u003e Add the Develocity plugin back to the Android smoke tests (\u003ca href=\"https://redirect.github.com/gradle/gradle/issues/39273\"\u003e#39273\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/eaee500e6a2fff583b9d2b81039fc15ad887462d\"\u003e\u003ccode\u003eeaee500\u003c/code\u003e\u003c/a\u003e Add the Develocity plugin back to the Android smoke tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/189b672308d1e997fae46412673d04683d76b35a\"\u003e\u003ccode\u003e189b672\u003c/code\u003e\u003c/a\u003e Route everything still hitting Maven Central through the mirror (\u003ca href=\"https://redirect.github.com/gradle/gradle/issues/39257\"\u003e#39257\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/36b181477307fc6db0e16582f11daaeb7e34fc8e\"\u003e\u003ccode\u003e36b1814\u003c/code\u003e\u003c/a\u003e Add back mavenCentral to doc snippets\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/2740c2d9cd0a9ab42813be77241fdc264217b2ba\"\u003e\u003ccode\u003e2740c2d\u003c/code\u003e\u003c/a\u003e Update Gradle wrapper to version 9.8.0-rc-3 (\u003ca href=\"https://redirect.github.com/gradle/gradle/issues/39264\"\u003e#39264\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/209938316e373c847aa1a251ec14eeded3da468e\"\u003e\u003ccode\u003e2099383\u003c/code\u003e\u003c/a\u003e Update Gradle wrapper to version 9.8.0-rc-3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/c80202fbd1cc457d7f45f31fc488391c4a2e7984\"\u003e\u003ccode\u003ec80202f\u003c/code\u003e\u003c/a\u003e Route everything still hitting Maven Central through the mirror\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/3f6a53434a2cf4f33486af2ae5eabd1fc830352d\"\u003e\u003ccode\u003e3f6a534\u003c/code\u003e\u003c/a\u003e Fix when a best practice was introduced (\u003ca href=\"https://redirect.github.com/gradle/gradle/issues/39253\"\u003e#39253\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/9efc9eddac43f0795194e407c0ab2177a1d23cf9\"\u003e\u003ccode\u003e9efc9ed\u003c/code\u003e\u003c/a\u003e Fix when a best practice was introduced\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/459e1433c60e4a604dd39ffe2c49e3606f70acda\"\u003e\u003ccode\u003e459e143\u003c/code\u003e\u003c/a\u003e Route integration test dependencies through the repository mirror (\u003ca href=\"https://redirect.github.com/gradle/gradle/issues/39239\"\u003e#39239\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/gradle/gradle/compare/v9.7.1...v9.8.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.slf4j:slf4j-api` from 2.0.19 to 2.0.20\n\nUpdates `org.slf4j:slf4j-simple` from 2.0.19 to 2.0.20\n\nUpdates `org.slf4j:jcl-over-slf4j` from 2.0.19 to 2.0.20\n\nUpdates `org.slf4j:slf4j-simple` from 2.0.19 to 2.0.20\n\nUpdates `org.slf4j:jcl-over-slf4j` from 2.0.19 to 2.0.20\n\nUpdates `software.amazon.awssdk:s3` from 2.55.1 to 2.55.6\n\nUpdates `software.amazon.awssdk:s3-transfer-manager` from 2.55.1 to 2.55.6\n\nUpdates `software.amazon.awssdk:sts` from 2.55.1 to 2.55.6\n\nUpdates `software.amazon.awssdk:sso` from 2.55.1 to 2.55.6\n\nUpdates `software.amazon.awssdk:ssooidc` from 2.55.1 to 2.55.6\n\nUpdates `software.amazon.awssdk:cloudfront` from 2.55.1 to 2.55.6\n\nUpdates `software.amazon.awssdk:cloudformation` from 2.55.1 to 2.55.6\n\nUpdates `software.amazon.awssdk:mediaconvert` from 2.55.1 to 2.55.6\n\nUpdates `software.amazon.awssdk:s3-transfer-manager` from 2.55.1 to 2.55.6\n\nUpdates `org.mongodb:bson` from 5.12.0 to 5.13.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mongodb/mongo-java-driver/releases\"\u003eorg.mongodb:bson's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eJava Driver 5.13.0 (September 25, 2026)\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps): bump testing/resources/specifications from \u003ccode\u003e92b3c0b\u003c/code\u003e to \u003ccode\u003e529a2dd\u003c/code\u003e by \u003ca href=\"https://github.com/apmasell\"\u003e\u003ccode\u003e@​apmasell\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2061\"\u003emongodb/mongo-java-driver#2061\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJAVA-6312 Increase testConnectionPoolBackpressure completion time on CI by \u003ca href=\"https://github.com/nhachicha\"\u003e\u003ccode\u003e@​nhachicha\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2062\"\u003emongodb/mongo-java-driver#2062\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJAVA-6235: Configurable DNS domain validation for SRV records by \u003ca href=\"https://github.com/apmasell\"\u003e\u003ccode\u003e@​apmasell\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2054\"\u003emongodb/mongo-java-driver#2054\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJAVA-6235 Add SRV allow hosts option to legacy driver by \u003ca href=\"https://github.com/apmasell\"\u003e\u003ccode\u003e@​apmasell\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2065\"\u003emongodb/mongo-java-driver#2065\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apmasell\"\u003e\u003ccode\u003e@​apmasell\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2061\"\u003emongodb/mongo-java-driver#2061\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/mongodb/mongo-java-driver/compare/r5.12.0...r5.13.0\"\u003ehttps://github.com/mongodb/mongo-java-driver/compare/r5.12.0...r5.13.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVerifying artifact signatures\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://www.mongodb.com/docs/languages/java/mongodb-hibernate/upcoming/security/validate-signatures/\"\u003ehttps://www.mongodb.com/docs/languages/java/mongodb-hibernate/upcoming/security/validate-signatures/\u003c/a\u003e for the full procedure.\u003c/p\u003e\n\u003cp\u003eTo download and import the public key for verifying signatures, execute\u003c/p\u003e\n\u003cpre lang=\"bash\"\u003e\u003ccode\u003egpg --keyserver hkps://keyserver.ubuntu.com --recv-keys 1a75005e142192223d6a7c3b76e0008d166740a8\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/f949913b29b5b94f49d83dadeecd29e61ec0ea56\"\u003e\u003ccode\u003ef949913\u003c/code\u003e\u003c/a\u003e Version: bump 5.13.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/917421419d3bc8123f3933efba869571cdf7bdf4\"\u003e\u003ccode\u003e9174214\u003c/code\u003e\u003c/a\u003e JAVA-6235 Add SRV allow hosts option to legacy driver (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/2065\"\u003e#2065\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/ee2c0ba8250da6642be5806929b44b1efc4472c6\"\u003e\u003ccode\u003eee2c0ba\u003c/code\u003e\u003c/a\u003e JAVA-6235: Configurable DNS domain validation for SRV records (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/2054\"\u003e#2054\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/551f88ba48d98d074834cf032b9fe1dd7b14e973\"\u003e\u003ccode\u003e551f88b\u003c/code\u003e\u003c/a\u003e JAVA-6312 Increase testConnectionPoolBackpressure completion time on CI (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/2062\"\u003e#2062\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/ff74470144f9c5ea98a5ab0881edbbfb1be2ca80\"\u003e\u003ccode\u003eff74470\u003c/code\u003e\u003c/a\u003e build(deps): bump testing/resources/specifications from \u003ccode\u003e92b3c0b\u003c/code\u003e to `529a2dd...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/3e757081a5c40f7527c7c607c1eaa258a245d548\"\u003e\u003ccode\u003e3e75708\u003c/code\u003e\u003c/a\u003e Version: bump 5.13.0-SNAPSHOT\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/mongodb/mongo-java-driver/compare/r5.12.0...r5.13.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.mongodb:mongodb-driver-sync` from 5.12.0 to 5.13.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mongodb/mongo-java-driver/releases\"\u003eorg.mongodb:mongodb-driver-sync's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eJava Driver 5.13.0 (September 25, 2026)\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps): bump testing/resources/specifications from \u003ccode\u003e92b3c0b\u003c/code\u003e to \u003ccode\u003e529a2dd\u003c/code\u003e by \u003ca href=\"https://github.com/apmasell\"\u003e\u003ccode\u003e@​apmasell\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2061\"\u003emongodb/mongo-java-driver#2061\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJAVA-6312 Increase testConnectionPoolBackpressure completion time on CI by \u003ca href=\"https://github.com/nhachicha\"\u003e\u003ccode\u003e@​nhachicha\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2062\"\u003emongodb/mongo-java-driver#2062\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJAVA-6235: Configurable DNS domain validation for SRV records by \u003ca href=\"https://github.com/apmasell\"\u003e\u003ccode\u003e@​apmasell\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2054\"\u003emongodb/mongo-java-driver#2054\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJAVA-6235 Add SRV allow hosts option to legacy driver by \u003ca href=\"https://github.com/apmasell\"\u003e\u003ccode\u003e@​apmasell\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2065\"\u003emongodb/mongo-java-driver#2065\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apmasell\"\u003e\u003ccode\u003e@​apmasell\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2061\"\u003emongodb/mongo-java-driver#2061\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/mongodb/mongo-java-driver/compare/r5.12.0...r5.13.0\"\u003ehttps://github.com/mongodb/mongo-java-driver/compare/r5.12.0...r5.13.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVerifying artifact signatures\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://www.mongodb.com/docs/languages/java/mongodb-hibernate/upcoming/security/validate-signatures/\"\u003ehttps://www.mongodb.com/docs/languages/java/mongodb-hibernate/upcoming/security/validate-signatures/\u003c/a\u003e for the full procedure.\u003c/p\u003e\n\u003cp\u003eTo download and import the public key for verifying signatures, execute\u003c/p\u003e\n\u003cpre lang=\"bash\"\u003e\u003ccode\u003egpg --keyserver hkps://keyserver.ubuntu.com --recv-keys 1a75005e142192223d6a7c3b76e0008d166740a8\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/f949913b29b5b94f49d83dadeecd29e61ec0ea56\"\u003e\u003ccode\u003ef949913\u003c/code\u003e\u003c/a\u003e Version: bump 5.13.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/917421419d3bc8123f3933efba869571cdf7bdf4\"\u003e\u003ccode\u003e9174214\u003c/code\u003e\u003c/a\u003e JAVA-6235 Add SRV allow hosts option to legacy driver (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/2065\"\u003e#2065\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/ee2c0ba8250da6642be5806929b44b1efc4472c6\"\u003e\u003ccode\u003eee2c0ba\u003c/code\u003e\u003c/a\u003e JAVA-6235: Configurable DNS domain validation for SRV records (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/2054\"\u003e#2054\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/551f88ba48d98d074834cf032b9fe1dd7b14e973\"\u003e\u003ccode\u003e551f88b\u003c/code\u003e\u003c/a\u003e JAVA-6312 Increase testConnectionPoolBackpressure completion time on CI (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/2062\"\u003e#2062\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/ff74470144f9c5ea98a5ab0881edbbfb1be2ca80\"\u003e\u003ccode\u003eff74470\u003c/code\u003e\u003c/a\u003e build(deps): bump testing/resources/specifications from \u003ccode\u003e92b3c0b\u003c/code\u003e to `529a2dd...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/3e757081a5c40f7527c7c607c1eaa258a245d548\"\u003e\u003ccode\u003e3e75708\u003c/code\u003e\u003c/a\u003e Version: bump 5.13.0-SNAPSHOT\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/mongodb/mongo-java-driver/compare/r5.12.0...r5.13.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.mongodb:mongodb-driver-legacy` from 5.12.0 to 5.13.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mongodb/mongo-java-driver/releases\"\u003eorg.mongodb:mongodb-driver-legacy's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eJava Driver 5.13.0 (September 25, 2026)\u003c/h2\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ebuild(deps): bump testing/resources/specifications from \u003ccode\u003e92b3c0b\u003c/code\u003e to \u003ccode\u003e529a2dd\u003c/code\u003e by \u003ca href=\"https://github.com/apmasell\"\u003e\u003ccode\u003e@​apmasell\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2061\"\u003emongodb/mongo-java-driver#2061\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJAVA-6312 Increase testConnectionPoolBackpressure completion time on CI by \u003ca href=\"https://github.com/nhachicha\"\u003e\u003ccode\u003e@​nhachicha\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2062\"\u003emongodb/mongo-java-driver#2062\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJAVA-6235: Configurable DNS domain validation for SRV records by \u003ca href=\"https://github.com/apmasell\"\u003e\u003ccode\u003e@​apmasell\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2054\"\u003emongodb/mongo-java-driver#2054\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJAVA-6235 Add SRV allow hosts option to legacy driver by \u003ca href=\"https://github.com/apmasell\"\u003e\u003ccode\u003e@​apmasell\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2065\"\u003emongodb/mongo-java-driver#2065\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apmasell\"\u003e\u003ccode\u003e@​apmasell\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/pull/2061\"\u003emongodb/mongo-java-driver#2061\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/mongodb/mongo-java-driver/compare/r5.12.0...r5.13.0\"\u003ehttps://github.com/mongodb/mongo-java-driver/compare/r5.12.0...r5.13.0\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eVerifying artifact signatures\u003c/h2\u003e\n\u003cp\u003ePlease refer to \u003ca href=\"https://www.mongodb.com/docs/languages/java/mongodb-hibernate/upcoming/security/validate-signatures/\"\u003ehttps://www.mongodb.com/docs/languages/java/mongodb-hibernate/upcoming/security/validate-signatures/\u003c/a\u003e for the full procedure.\u003c/p\u003e\n\u003cp\u003eTo download and import the public key for verifying signatures, execute\u003c/p\u003e\n\u003cpre lang=\"bash\"\u003e\u003ccode\u003egpg --keyserver hkps://keyserver.ubuntu.com --recv-keys 1a75005e142192223d6a7c3b76e0008d166740a8\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/f949913b29b5b94f49d83dadeecd29e61ec0ea56\"\u003e\u003ccode\u003ef949913\u003c/code\u003e\u003c/a\u003e Version: bump 5.13.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/917421419d3bc8123f3933efba869571cdf7bdf4\"\u003e\u003ccode\u003e9174214\u003c/code\u003e\u003c/a\u003e JAVA-6235 Add SRV allow hosts option to legacy driver (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/2065\"\u003e#2065\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/ee2c0ba8250da6642be5806929b44b1efc4472c6\"\u003e\u003ccode\u003eee2c0ba\u003c/code\u003e\u003c/a\u003e JAVA-6235: Configurable DNS domain validation for SRV records (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/2054\"\u003e#2054\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/551f88ba48d98d074834cf032b9fe1dd7b14e973\"\u003e\u003ccode\u003e551f88b\u003c/code\u003e\u003c/a\u003e JAVA-6312 Increase testConnectionPoolBackpressure completion time on CI (\u003ca href=\"https://redirect.github.com/mongodb/mongo-java-driver/issues/2062\"\u003e#2062\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/ff74470144f9c5ea98a5ab0881edbbfb1be2ca80\"\u003e\u003ccode\u003eff74470\u003c/code\u003e\u003c/a\u003e build(deps): bump testing/resources/specifications from \u003ccode\u003e92b3c0b\u003c/code\u003e to `529a2dd...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mongodb/mongo-java-driver/commit/3e757081a5c40f7527c7c607c1eaa258a245d548\"\u003e\u003ccode\u003e3e75708\u003c/code\u003e\u003c/a\u003e Version: bump 5.13.0-SNAPSHOT\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/mongodb/mongo-java-driver/compare/r5.12.0...r5.13.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.core:jackson-databind` from 2.22.2 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/4385c5f7d51426f66fb24c3777308acc8ae7ea6c\"\u003e\u003ccode\u003e4385c5f\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ccb4fd0158cd20800f6014496dccf7332e5b18ce\"\u003e\u003ccode\u003eccb4fd0\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/2958412f1817a0ad95c34066b7eb85781dd2d4f1\"\u003e\u003ccode\u003e2958412\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1215b94c2f7a8c4ce3863afbc38275a19c682a54\"\u003e\u003ccode\u003e1215b94\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1f0df621449e5de7dd13a1538e0343f65f0e6bb3\"\u003e\u003ccode\u003e1f0df62\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/13a9ff4c4ef982cda23b99fea89d2a4e87af9019\"\u003e\u003ccode\u003e13a9ff4\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/d168f9679ad575cdc2df8d53a8474ec481c7b5a7\"\u003e\u003ccode\u003ed168f96\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/eaf5c76b8e0a538729a1bf922061abf73b13f89b\"\u003e\u003ccode\u003eeaf5c76\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/e05ef4cbb4d534a82948f8ba84350e55493bc72e\"\u003e\u003ccode\u003ee05ef4c\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/f6d4000c1eb6d34e2ae24685a9790b1e833d4bcb\"\u003e\u003ccode\u003ef6d4000\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.22.2...jackson-databind-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.core:jackson-core` from 2.22.2 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/eee4b9e30d62dedf9c84beb6ae6e3c5ebf46920d\"\u003e\u003ccode\u003eeee4b9e\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-core-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/31ee7ebd641d352e96484da4c37b234c8ce29070\"\u003e\u003ccode\u003e31ee7eb\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/9fef13fa0c31abd5ce15e2f25581c560261ade8b\"\u003e\u003ccode\u003e9fef13f\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/9160f4068bb433afa91f51c4808b622b329f6e46\"\u003e\u003ccode\u003e9160f40\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/1169cb6515603220eb50a60b473590eecdef476a\"\u003e\u003ccode\u003e1169cb6\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/b33f4559759023567e808e732ebf9b4dfa3d9027\"\u003e\u003ccode\u003eb33f455\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-core-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/ce8b7dc7ee207fb1481dd8fb535cfbbea6db3bc8\"\u003e\u003ccode\u003ece8b7dc\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/b69555e65e4efcc4c728a70b793c3c232d43f1ea\"\u003e\u003ccode\u003eb69555e\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/53df608d2eca49f7e3817c81fa0a8387835a5ba4\"\u003e\u003ccode\u003e53df608\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/892f7577fe61c6381ba94bb7531f554241221e18\"\u003e\u003ccode\u003e892f757\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-core/compare/jackson-core-2.22.2...jackson-core-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.dataformat:jackson-dataformat-cbor` from 2.22.2 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/e302f7e0b23b077e85c7b7662cb518853528d114\"\u003e\u003ccode\u003ee302f7e\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-dataformats-binary-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/753fb32524c9feb01ddbf620ba4524ed6937217e\"\u003e\u003ccode\u003e753fb32\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/e7fdadb36545da8bbebb72ad39c0c09a860b82b9\"\u003e\u003ccode\u003ee7fdadb\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/e576e509b2309c2fa9bddceeaea482ffeb6c2f80\"\u003e\u003ccode\u003ee576e50\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/b386d544a1b470c3ff0a9651da354dce268f5ea4\"\u003e\u003ccode\u003eb386d54\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/a56180dc0720fcc3616264546fa0a610ababecc2\"\u003e\u003ccode\u003ea56180d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-dataformats-binary-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/6ac61803dbf9d9f39008b72ee1b7240d5194a252\"\u003e\u003ccode\u003e6ac6180\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/a85932fb25cac5fdbdc7ef94faf48aaace713500\"\u003e\u003ccode\u003ea85932f\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/110002c6eaaf832bbc52db7472d15c30e8b4792b\"\u003e\u003ccode\u003e110002c\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/f09bc9efed5f98ee66c8a13c815a9976469a9e65\"\u003e\u003ccode\u003ef09bc9e\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/compare/jackson-dataformats-binary-2.22.2...jackson-dataformats-binary-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.dataformat:jackson-dataformat-xml` from 2.22.2 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/6a183d08ebe1afa9153a496681a94c3aed445fb0\"\u003e\u003ccode\u003e6a183d0\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-dataformat-xml-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/45290b73b29d79799552f191adf6025aad95b4cb\"\u003e\u003ccode\u003e45290b7\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/0e9bd255c027599fc2767c0870ff1258a22f63de\"\u003e\u003ccode\u003e0e9bd25\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/4dc38dfcfe5b907e89b226ed937207f40424f615\"\u003e\u003ccode\u003e4dc38df\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/bac56109caef812ea2e9aa65d9a2e324b4a9b675\"\u003e\u003ccode\u003ebac5610\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/a7cfc97b90512d65117e68f3f09b10a076d9c28a\"\u003e\u003ccode\u003ea7cfc97\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-dataformat-xml-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/bf55a64caf624ce95e4d9538b41406e4a7d8de48\"\u003e\u003ccode\u003ebf55a64\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/d515706a64e0a21ddd461bbfd3e3f146d1d63035\"\u003e\u003ccode\u003ed515706\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/7a536e56717eb35f5bb54dd6cadddd78f2977559\"\u003e\u003ccode\u003e7a536e5\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/79037dda707dfed0b1429ab822341947f48b2b4b\"\u003e\u003ccode\u003e79037dd\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/compare/jackson-dataformat-xml-2.22.2...jackson-dataformat-xml-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.datatype:jackson-datatype-jsr310` from 2.22.2 to 2.22.3\n\nUpdates `com.fasterxml.jackson.dataformat:jackson-dataformat-smile` from 2.22.2 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/e302f7e0b23b077e85c7b7662cb518853528d114\"\u003e\u003ccode\u003ee302f7e\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-dataformats-binary-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/753fb32524c9feb01ddbf620ba4524ed6937217e\"\u003e\u003ccode\u003e753fb32\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/e7fdadb36545da8bbebb72ad39c0c09a860b82b9\"\u003e\u003ccode\u003ee7fdadb\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/e576e509b2309c2fa9bddceeaea482ffeb6c2f80\"\u003e\u003ccode\u003ee576e50\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/b386d544a1b470c3ff0a9651da354dce268f5ea4\"\u003e\u003ccode\u003eb386d54\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/a56180dc0720fcc3616264546fa0a610ababecc2\"\u003e\u003ccode\u003ea56180d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-dataformats-binary-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/6ac61803dbf9d9f39008b72ee1b7240d5194a252\"\u003e\u003ccode\u003e6ac6180\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/a85932fb25cac5fdbdc7ef94faf48aaace713500\"\u003e\u003ccode\u003ea85932f\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/110002c6eaaf832bbc52db7472d15c30e8b4792b\"\u003e\u003ccode\u003e110002c\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/f09bc9efed5f98ee66c8a13c815a9976469a9e65\"\u003e\u003ccode\u003ef09bc9e\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/compare/jackson-dataformats-binary-2.22.2...jackson-dataformats-binary-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.dataformat:jackson-dataformat-yaml` from 2.22.2 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-text/commit/e793b5fcca4a976d4179fb1b8a7d34ab0236556f\"\u003e\u003ccode\u003ee793b5f\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-dataformats-text-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-text/commit/e8e9ece5e8bc28337aaa6206f43a54024a4a08d1\"\u003e\u003ccode\u003ee8e9ece\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-text/commit/2ea3d0c8e1c3e8540d0860c791b6de37ff55523a\"\u003e\u003ccode\u003e2ea3d0c\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-text/commit/8e88b8564a51986d37f0f97bfbe18192b4525ea8\"\u003e\u003ccode\u003e8e88b85\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-text/commit/806abc907d38104274bf1a18f5be9dfb5327a4c5\"\u003e\u003ccode\u003e806abc9\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-text/commit/a11273cb00535298b79c2878d009f6c1b93ba502\"\u003e\u003ccode\u003ea11273c\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-dataformats-text-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-text/commit/5d16624914c08ee4fa76dad6a1f496c6f67a989d\"\u003e\u003ccode\u003e5d16624\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-text/commit/f047dd5e84cbeb4aa42b956947d1282a838b09c5\"\u003e\u003ccode\u003ef047dd5\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-text/commit/0f801646596d391f21f0a7e90a720b32c0db5676\"\u003e\u003ccode\u003e0f80164\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-text/commit/4dcc3dab188c6e5af20cd7e45c98a1d5a1d7c136\"\u003e\u003ccode\u003e4dcc3da\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-dataformats-text/compare/jackson-dataformats-text-2.22.2...jackson-dataformats-text-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `tools.jackson.core:jackson-databind` from 3.2.2 to 3.2.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/4179a66668017f3dcd7f7f3f22dbc48f0bf88ae5\"\u003e\u003ccode\u003e4179a66\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-3.2.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/37c8a723a0540dbb642bd8f05b21ecba23e3894e\"\u003e\u003ccode\u003e37c8a72\u003c/code\u003e\u003c/a\u003e Prep for 3.2.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/5fa7881c637ac59f09d6c2b7c4d85b8661633b6c\"\u003e\u003ccode\u003e5fa7881\u003c/code\u003e\u003c/a\u003e Merge branch '3.1' into 3.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/c9f17a2e0d4efc6cf7757b663bc845a602104410\"\u003e\u003ccode\u003ec9f17a2\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1ea1c401fe64829affcd330221189aa1f766b0bf\"\u003e\u003ccode\u003e1ea1c40\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/2968e8f656f4b5f3eed7b55118293ee2284eecd0\"\u003e\u003ccode\u003e2968e8f\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-3.1.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/d61810b4817cbeca22c6a2118dfcfaa863210da9\"\u003e\u003ccode\u003ed61810b\u003c/code\u003e\u003c/a\u003e Prep for 3.1.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/e065a090dbb81a84acc7b479609e79887e397b3a\"\u003e\u003ccode\u003ee065a09\u003c/code\u003e\u003c/a\u003e Merge branch '2.x' into 3.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/fd189a7c73fdf563bc6b2f9bff190822a494a2f4\"\u003e\u003ccode\u003efd189a7\u003c/code\u003e\u003c/a\u003e Merge branch '2.22' into 2.x\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/211faf7c27ac57bcbbd7ec757f15cd3c64de6e9f\"\u003e\u003ccode\u003e211faf7\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-3.2.2...jackson-databind-3.2.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.core:jackson-core` from 2.22.2 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/eee4b9e30d62dedf9c84beb6ae6e3c5ebf46920d\"\u003e\u003ccode\u003eeee4b9e\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-core-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/31ee7ebd641d352e96484da4c37b234c8ce29070\"\u003e\u003ccode\u003e31ee7eb\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/9fef13fa0c31abd5ce15e2f25581c560261ade8b\"\u003e\u003ccode\u003e9fef13f\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/9160f4068bb433afa91f51c4808b622b329f6e46\"\u003e\u003ccode\u003e9160f40\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/1169cb6515603220eb50a60b473590eecdef476a\"\u003e\u003ccode\u003e1169cb6\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/b33f4559759023567e808e732ebf9b4dfa3d9027\"\u003e\u003ccode\u003eb33f455\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-core-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/ce8b7dc7ee207fb1481dd8fb535cfbbea6db3bc8\"\u003e\u003ccode\u003ece8b7dc\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/b69555e65e4efcc4c728a70b793c3c232d43f1ea\"\u003e\u003ccode\u003eb69555e\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/53df608d2eca49f7e3817c81fa0a8387835a5ba4\"\u003e\u003ccode\u003e53df608\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-core/commit/892f7577fe61c6381ba94bb7531f554241221e18\"\u003e\u003ccode\u003e892f757\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-core/compare/jackson-core-2.22.2...jackson-core-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.dataformat:jackson-dataformat-cbor` from 2.22.2 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/e302f7e0b23b077e85c7b7662cb518853528d114\"\u003e\u003ccode\u003ee302f7e\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-dataformats-binary-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/753fb32524c9feb01ddbf620ba4524ed6937217e\"\u003e\u003ccode\u003e753fb32\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/e7fdadb36545da8bbebb72ad39c0c09a860b82b9\"\u003e\u003ccode\u003ee7fdadb\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/e576e509b2309c2fa9bddceeaea482ffeb6c2f80\"\u003e\u003ccode\u003ee576e50\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/b386d544a1b470c3ff0a9651da354dce268f5ea4\"\u003e\u003ccode\u003eb386d54\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/a56180dc0720fcc3616264546fa0a610ababecc2\"\u003e\u003ccode\u003ea56180d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-dataformats-binary-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/6ac61803dbf9d9f39008b72ee1b7240d5194a252\"\u003e\u003ccode\u003e6ac6180\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/a85932fb25cac5fdbdc7ef94faf48aaace713500\"\u003e\u003ccode\u003ea85932f\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/110002c6eaaf832bbc52db7472d15c30e8b4792b\"\u003e\u003ccode\u003e110002c\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/commit/f09bc9efed5f98ee66c8a13c815a9976469a9e65\"\u003e\u003ccode\u003ef09bc9e\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-dataformats-binary/compare/jackson-dataformats-binary-2.22.2...jackson-dataformats-binary-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.dataformat:jackson-dataformat-xml` from 2.22.2 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/6a183d08ebe1afa9153a496681a94c3aed445fb0\"\u003e\u003ccode\u003e6a183d0\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-dataformat-xml-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/45290b73b29d79799552f191adf6025aad95b4cb\"\u003e\u003ccode\u003e45290b7\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/0e9bd255c027599fc2767c0870ff1258a22f63de\"\u003e\u003ccode\u003e0e9bd25\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/4dc38dfcfe5b907e89b226ed937207f40424f615\"\u003e\u003ccode\u003e4dc38df\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/bac56109caef812ea2e9aa65d9a2e324b4a9b675\"\u003e\u003ccode\u003ebac5610\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/a7cfc97b90512d65117e68f3f09b10a076d9c28a\"\u003e\u003ccode\u003ea7cfc97\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-dataformat-xml-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/bf55a64caf624ce95e4d9538b41406e4a7d8de48\"\u003e\u003ccode\u003ebf55a64\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/d515706a64e0a21ddd461bbfd3e3f146d1d63035\"\u003e\u003ccode\u003ed515706\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/7a536e56717eb35f5bb54dd6cadddd78f2977559\"\u003e\u003ccode\u003e7a536e5\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/commit/79037dda707dfed0b1429ab822341947f48b2b4b\"\u003e\u003ccode\u003e79037dd\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-dataformat-xml/compare/jackson-dataformat-xml-2.22.2...jackson-dataformat-xml-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.groovy:groovy` from 5.1.3 to 6.0.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/apache/groovy/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.groovy:groovy-sql` from 5.1.3 to 6.0.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/apache/groovy/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.groovy:groovy-all` from 5.1.3 to 6.0.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/apache/groovy/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.groovy:groovy-sql` from 5.1.3 to 6.0.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/apache/groovy/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.github.ben-manes.caffeine:caffeine` from 3.2.4 to 3.3.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/ben-manes/caffeine/releases\"\u003ecom.github.ben-manes.caffeine:caffeine's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.3.0\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved read performance by avoiding false sharing in the fast-path check\u003c/li\u003e\n\u003cli\u003eImproved \u003ca href=\"https://ben-manes.github.io/caffeine/wiki/adaptive-window.html\"\u003eadaptive climber\u003c/a\u003e for small caches and shifting workloads\u003c/li\u003e\n\u003cli\u003eFixed various minor issues found using AI audits\u003c/li\u003e\n\u003cli\u003eFixed over-aggressive refresh discard (\u003ca href=\"https://redirect.github.com/ben-manes/caffeine/issues/1970\"\u003e#1970\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ben-manes/caffeine/commit/af860110a4b1e158d30ef0ccdd78a1600bdbde0d\"\u003e\u003ccode\u003eaf86011\u003c/code\u003e\u003c/a\u003e fix jcache audit triage\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ben-manes/caffeine/commit/f063e56a0edb0369b29fc37a9c283cd317f303f2\"\u003e\u003ccode\u003ef063e56\u003c/code\u003e\u003c/a\u003e Prevent overflow in snapshot durations\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ben-manes/caffeine/commit/5b6fbd94f0e0d5727b0ffba52ba0365f5e793eb5\"\u003e\u003ccode\u003e5b6fbd9\u003c/code\u003e\u003c/a\u003e Saturate the audit stillness counter\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ben-manes/caffeine/commit/48cb4083684d6decb4841e9502f419d08128f6dc\"\u003e\u003ccode\u003e48cb408\u003c/code\u003e\u003c/a\u003e Read lazy cache views and policies once\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ben-manes/caffeine/commit/4978d1835234114a0a8568b1000be5a4de6360b7\"\u003e\u003ccode\u003e4978d18\u003c/code\u003e\u003c/a\u003e Normalize JCache processor loader failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ben-manes/caffeine/commit/c9038d8fa3084bfc45ac9f5d222dfe2de7ba548a\"\u003e\u003ccode\u003ec9038d8\u003c/code\u003e\u003c/a\u003e Consume JCache iterator removals before listener failures\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ben-manes/caffeine/commit/0b0afd2470294cae0b2a66b914e65c7733941ed6\"\u003e\u003ccode\u003e0b0afd2\u003c/code\u003e\u003c/a\u003e polish\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ben-manes/caffeine/commit/c0edd00bb6063e59ee1e7a7db5588fac7a6524f5\"\u003e\u003ccode\u003ec0edd00\u003c/code\u003e\u003c/a\u003e restore coverage lost to recent fixes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ben-manes/caffeine/commit/5283c96dce60552f898af471b00a3cf54b69fa3e\"\u003e\u003ccode\u003e5283c96\u003c/code\u003e\u003c/a\u003e make CLOCK-Pro's cold hand a setting\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/ben-manes/caffeine/commit/d15c2052ecbf51c15981a3e4f61f8885d093ad0a\"\u003e\u003ccode\u003ed15c205\u003c/code\u003e\u003c/a\u003e make the bulk cache loaders serializable\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/ben-manes/caffeine/compare/v3.2.4...v3.3.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.mockito:mockito-core` from 5.23.0 to 5.24.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mockito/mockito/releases\"\u003eorg.mockito:mockito-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.24.0\u003c/h2\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003cem\u003eChangelog generated by \u003ca href=\"https://github.com/shipkit/shipkit-changelog\"\u003eShipkit Changelog Gradle Plugin\u003c/a\u003e\u003c/em\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch4\u003e5.24.0\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e2026-09-23 - \u003ca href=\"https://github.com/mockito/mockito/compare/v5.23.0...v5.24.0\"\u003e27 commit(s)\u003c/a\u003e by Andrei Solntsev, DragonFSKY, Hünkar Can Tunç, Joshua Selbo, M. Minot, Markus Gaisbauer, Mirko Alicastro, Vinod Kumar M ( codingkiddo ), dependabot[bot]\u003c/li\u003e\n\u003cli\u003eFix Mockito docs for -javaagent flag with Gradle [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3866\"\u003e#3866\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3866\"\u003emockito/mockito#3866\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eKotlin example for adding Mockito as an agent is incorrect [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3864\"\u003e#3864\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3864\"\u003emockito/mockito#3864\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump graalvm/setup-graalvm from 1.6.3 to 1.6.6 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3862\"\u003e#3862\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3862\"\u003emockito/mockito#3862\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump gradle/actions from 6.2.0 to 6.3.0 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3852\"\u003e#3852\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3852\"\u003emockito/mockito#3852\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump gradle/actions from 5 to 6.2.0 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3851\"\u003e#3851\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3851\"\u003emockito/mockito#3851\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreserve method parameters when clearing inline mocks [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3847\"\u003e#3847\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3847\"\u003emockito/mockito#3847\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump graalvm/setup-graalvm from 1.6.0 to 1.6.3 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3845\"\u003e#3845\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3845\"\u003emockito/mockito#3845\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrint object fields via reflection when \u003ccode\u003etoString()\u003c/code\u003e is not implemented [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3844\"\u003e#3844\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3844\"\u003emockito/mockito#3844\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMigrate extensions-tests to JUnit Jupiter [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3840\"\u003e#3840\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3840\"\u003emockito/mockito#3840\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump graalvm/setup-graalvm from 1.5.6 to 1.6.0 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3839\"\u003e#3839\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3839\"\u003emockito/mockito#3839\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edocs(when-verify): fixes to explanations about redundancy [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3838\"\u003e#3838\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3838\"\u003emockito/mockito#3838\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eConfusing inconsistency in example method calls in “stubbing and verifying is redundant” note of “when” and “verify” Javadoc [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3837\"\u003e#3837\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3837\"\u003emockito/mockito#3837\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump actions/checkout from 6 to 7 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3836\"\u003e#3836\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3836\"\u003emockito/mockito#3836\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixes \u003ca href=\"https://redirect.github.com/mockito/mockito/issues/2740\"\u003e#2740\u003c/a\u003e : Add mockMaker option to \u003ccode\u003e@Spy\u003c/code\u003e annotation [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3835\"\u003e#3835\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3835\"\u003emockito/mockito#3835\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump graalvm/setup-graalvm from 1.5.5 to 1.5.6 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3834\"\u003e#3834\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3834\"\u003emockito/mockito#3834\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump graalvm/setup-graalvm from 1.5.4 to 1.5.5 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3833\"\u003e#3833\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3833\"\u003emockito/mockito#3833\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump codecov/codecov-action from 6 to 7 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3831\"\u003e#3831\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3831\"\u003emockito/mockito#3831\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump graalvm/setup-graalvm from 1.4.5 to 1.5.4 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3830\"\u003e#3830\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3830\"\u003emockito/mockito#3830\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix clearInlineMocks not de-registering singleton mocks [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3829\"\u003e#3829\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3829\"\u003emockito/mockito#3829\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix NotAMockException when using mockSingleton with MockitoJUnit [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3827\"\u003e#3827\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3827\"\u003emockito/mockito#3827\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eNotAMockException when using mockSingleton with MockitoSession or MockitoJUnit [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3826\"\u003e#3826\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3826\"\u003emockito/mockito#3826\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eImprove Gradle agent docs for configuration cache [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3823\"\u003e#3823\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3823\"\u003emockito/mockito#3823\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eGradle documentation for setting up instrumentation with Gradle configuration cache [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3822\"\u003e#3822\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3822\"\u003emockito/mockito#3822\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixes \u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3818\"\u003e#3818\u003c/a\u003e : Fix data race in InvocationContainerImpl.invocationForStubbing [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3819\"\u003e#3819\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3819\"\u003emockito/mockito#3819\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eData race on invocationForPotentialStubbing [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3818\"\u003e#3818\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3818\"\u003emockito/mockito#3818\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixes \u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3814\"\u003e#3814\u003c/a\u003e : implement package-level clinit suppression [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3815\"\u003e#3815\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3815\"\u003emockito/mockito#3815\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePackage-level clinit suppression [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3814\"\u003e#3814\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3814\"\u003emockito/mockito#3814\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUpgrade Android Gradle Plugin to 8.13.2 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3812\"\u003e#3812\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3812\"\u003emockito/mockito#3812\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eReplaces raw generic types with type parameters [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3806\"\u003e#3806\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3806\"\u003emockito/mockito#3806\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixes \u003ca href=\"https://redirect.github.com/mockito/mockito/issues/2398\"\u003e#2398\u003c/a\u003e : Implement global suppress static initialization leveraging java agent [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3801\"\u003e#3801\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3801\"\u003emockito/mockito#3801\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump codecov/codecov-action from 5 to 6 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3800\"\u003e#3800\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3800\"\u003emockito/mockito#3800\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix non-deterministic AssertionError when using MockMakers.SUBCLASS (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3406\"\u003e#3406\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/mockito/mockito/issues/2823\"\u003e#2823\u003c/a\u003e) [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3795\"\u003e#3795\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3795\"\u003emockito/mockito#3795\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFixes \u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3536\"\u003e#3536\u003c/a\u003e : Implement SpyStatic API [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3794\"\u003e#3794\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3794\"\u003emockito/mockito#3794\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eThe class's MethodParameters are removed after clearAllCaches is invoked [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3763\"\u003e#3763\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3763\"\u003emockito/mockito#3763\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e[FeatureRequest / Idea] Create Mockito.spyStatic [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3536\"\u003e#3536\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3536\"\u003emockito/mockito#3536\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd option to specify mockmaker for \u003ccode\u003e@Spy\u003c/code\u003e [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/2740\"\u003e#2740\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/2740\"\u003emockito/mockito#2740\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eHow can I suppress static initializer? [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/2398\"\u003e#2398\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/2398\"\u003emockito/mockito#2398\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/5a2f0f81cdafc9b34ddb4520db7f8866c787dac0\"\u003e\u003ccode\u003e5a2f0f8\u003c/code\u003e\u003c/a\u003e Fix Mockito docs for -javaagent flag with Gradle (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3866\"\u003e#3866\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/9c5f36fb9f2ad89fbaab828d33d144cd398a4079\"\u003e\u003ccode\u003e9c5f36f\u003c/code\u003e\u003c/a\u003e Bump graalvm/setup-graalvm from 1.6.3 to 1.6.6 (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3862\"\u003e#3862\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/e7fd06dda31daf0c71ad1dedc76ffc9f8ecf6973\"\u003e\u003ccode\u003ee7fd06d\u003c/code\u003e\u003c/a\u003e Preserve method parameters when clearing inline mocks (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3847\"\u003e#3847\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/5a676bcd9ef9a10db46e1dc34e190eb46faa2687\"\u003e\u003ccode\u003e5a676bc\u003c/code\u003e\u003c/a\u003e Bump gradle/actions from 6.2.0 to 6.3.0 (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3852\"\u003e#3852\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/508f8e78f5ac5ed9f23f7b92b01de76752120a67\"\u003e\u003ccode\u003e508f8e7\u003c/code\u003e\u003c/a\u003e Bump gradle/actions from 5 to 6.2.0 (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3851\"\u003e#3851\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/ee8a330da0218f32d5964acdeaa3ac39e2c6ce14\"\u003e\u003ccode\u003eee8a330\u003c/code\u003e\u003c/a\u003e Print object fields via reflection when \u003ccode\u003etoString()\u003c/code\u003e is not implemented (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3844\"\u003e#3844\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/39b1aba6e6cc92d8ad3c812dcc16ed357c9fbc85\"\u003e\u003ccode\u003e39b1aba\u003c/code\u003e\u003c/a\u003e Bump graalvm/setup-graalvm from 1.6.0 to 1.6.3 (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3845\"\u003e#3845\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/d8638e1a8b67b4acea63c80dc85d62eda4ef57f5\"\u003e\u003ccode\u003ed8638e1\u003c/code\u003e\u003c/a\u003e Migrate extensions-tests to JUnit Jupiter (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3840\"\u003e#3840\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/0aab922fa4c8967e50613671f58c707a69606c62\"\u003e\u003ccode\u003e0aab922\u003c/code\u003e\u003c/a\u003e Bump graalvm/setup-graalvm from 1.5.6 to 1.6.0 (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3839\"\u003e#3839\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/f3cf74c7e1106f7d32299001ca0ecf2c492c468c\"\u003e\u003ccode\u003ef3cf74c\u003c/code\u003e\u003c/a\u003e docs(when-verify): fixes to explanations about redundancy (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3838\"\u003e#3838\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mockito/mockito/compare/v5.23.0...v5.24.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.hibernate.validator:hibernate-validator` from 9.1.3.Final to 9.1.4.Final\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hibernate/hibernate-validator/releases\"\u003eorg.hibernate.validator:hibernate-validator's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 9.1.4.Final\u003c/h2\u003e\n\u003ch1\u003eHibernate Validator 9.1.4.Final released\u003c/h1\u003e\n\u003cp\u003eWe are pleased to announce the release of Hibernate Validator 9.1: 9.1.4.Final.\u003c/p\u003e\n\u003cp\u003eYou can find the full list of 9.1.4.Final changes \u003ca href=\"https://hibernate.atlassian.net/issues/?jql=project%20%3D%20HV%20AND%20fixVersion%20%3D%209.1.4.Final\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eWhat's new\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSee the \u003ca href=\"https://hibernate.org/validator/releases/9.1\"\u003ewebsite\u003c/a\u003e for requirements and compatibilities.\u003c/li\u003e\n\u003cli\u003eSee the \u003ca href=\"https://docs.hibernate.org/validator/9.1/whats-new/en-US/html_single/\"\u003eWhat's New\u003c/a\u003e guide for details about new features and capabilities.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eConclusion\u003c/h2\u003e\n\u003cp\u003eFor additional details, see:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe \u003ca href=\"https://hibernate.org/validator/releases/9.1/\"\u003erelease page\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/validator/9.1/migration-guide/\"\u003eMigration Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/validator/9.1/reference/en-US/html_single/#validator-gettingstarted\"\u003eGetting started\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/validator/9.1/reference/en-US/html_single/\"\u003eReference Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/validator/9.1/api\"\u003eAPI docs\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eVisit the \u003ca href=\"https://hibernate.org/community/\"\u003ewebsite\u003c/a\u003e for details on getting in touch with us.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hibernate/hibernate-validator/blob/9.1.4.Final/changelog.md\"\u003eorg.hibernate.validator:hibernate-validator's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e9.1.4.Final (2026-09-20)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://hibernate.atlassian.net/projects/HV/versions/40268\"\u003eFull changelog\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eBug\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://hibernate.atlassian.net/browse/HV-2253\"\u003eHV-2253\u003c/a\u003e - ClassNotFoundException thrown when an EL implementation and OSGi are not on the class path\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eImprovement\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://hibernate.atlassian.net/browse/HV-2243\"\u003eHV-2243\u003c/a\u003e - Bump joda-time to 2.14.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://hibernate.atlassian.net/browse/HV-2242\"\u003eHV-2242\u003c/a\u003e - Update to OpenJFX to 17.0.20\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eTask\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://hibernate.atlassian.net/browse/HV-2244\"\u003eHV-2244\u003c/a\u003e - Tune the content of javadoc jars to reduce the size of files published to Maven Central\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/5504b0c343888d2d179e502e9d78cccf6a6d1830\"\u003e\u003ccode\u003e5504b0c\u003c/code\u003e\u003c/a\u003e [Jenkins release job] Preparing release 9.1.4.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/1306aab453b1658f2fefc2f6f994cfe71b7ba94a\"\u003e\u003ccode\u003e1306aab\u003c/code\u003e\u003c/a\u003e [Jenkins release job] changelog.md updated by release build 9.1.4.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/715cbdbbf7429d1cf4499a45e0fe32011d7d32c1\"\u003e\u003ccode\u003e715cbdb\u003c/code\u003e\u003c/a\u003e [Jenkins release job] README.md updated by release build 9.1.4.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/84e8d2eff9576c437c404b31a85804b7dbee7c2d\"\u003e\u003ccode\u003e84e8d2e\u003c/code\u003e\u003c/a\u003e HV-2253 When determining the Jakarta Expression Language implementation, igno...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/f3002a3c0e1ae8abf3b849bb6d677e9497225f96\"\u003e\u003ccode\u003ef3002a3\u003c/code\u003e\u003c/a\u003e [9.1] Bump org.codehaus.mojo:build-helper-maven-plugin\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/971d85b8b293b68d86f18899dbf736b4a8402eab\"\u003e\u003ccode\u003e971d85b\u003c/code\u003e\u003c/a\u003e [9.1] Bump the build-dependencies group with 3 updates\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/dcb1305b8a4a28dc942985f87500a6a6dc3ed3ee\"\u003e\u003ccode\u003edcb1305\u003c/code\u003e\u003c/a\u003e Tune the content of javadoc jars to reduce the size of files published to Mav...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/d01ed37bd4a2cdc129560488b167c74f80192855\"\u003e\u003ccode\u003ed01ed37\u003c/code\u003e\u003c/a\u003e [9.1] Bump version.org.apache.groovy from 5.0.7 to 5.0.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/6023258142c95208b22affcccf37506a4443cb5d\"\u003e\u003ccode\u003e6023258\u003c/code\u003e\u003c/a\u003e Bump joda-time to 2.14.3 HV-2243\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/3db152e2bc5b007a1162a8911523880517cf3940\"\u003e\u003ccode\u003e3db152e\u003c/code\u003e\u003c/a\u003e Update to OpenJFX to 17.0.20 HV-2242\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/hibernate/hibernate-validator/compare/9.1.3.Final...9.1.4.Final\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n...\n\n_Description has been truncated_","html_url":"https://github.com/craftersoftware/craftercms/pull/9081","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/craftersoftware%2Fcraftercms/issues/9081","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/9081/packages"}},{"old_version":"2.18.6","new_version":"2.18.10","update_type":"patch","path":"/samples/client/petstore/java/webclient","pr_created_at":"2026-09-29T04:24:53.000Z","version_change":"2.18.6 → 2.18.10","issue":{"uuid":"5625080335","node_id":"PR_kwDON2_zC88AAAABFoDxWg","number":561,"state":"open","title":"Bump com.fasterxml.jackson.core:jackson-databind from 2.18.6 to 2.18.10 in /samples/client/petstore/java/webclient","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":11,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-29T04:24:53.000Z","updated_at":"2026-09-29T04:25:55.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.18.6","new_version":"2.18.10","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":"/samples/client/petstore/java/webclient","ecosystem":"maven"},"body":"Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.18.6 to 2.18.10.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/176df1d48b256ced412c65293ad4e09393e24bd3\"\u003e\u003ccode\u003e176df1d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.18.10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7785f5f9ed24127e004115472c47b26ea4cf2774\"\u003e\u003ccode\u003e7785f5f\u003c/code\u003e\u003c/a\u003e Prep for 2.18.10 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0ccf3241c72d324df711f092ab4fa8f5635272cf\"\u003e\u003ccode\u003e0ccf324\u003c/code\u003e\u003c/a\u003e Backport \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6165\"\u003e#6165\u003c/a\u003e to 2.18: apply number length limits to BigDecimal/BigInteger/D...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bb18488020df1228580be5024ae8c6e9f06d9226\"\u003e\u003ccode\u003ebb18488\u003c/code\u003e\u003c/a\u003e Fix CREDITS class name wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1b1bb192a8560a3139287ce69295e10c1c5c81b2\"\u003e\u003ccode\u003e1b1bb19\u003c/code\u003e\u003c/a\u003e Fix release notes wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f\"\u003e\u003ccode\u003eeb3b7fc\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003ejava.lang.Comparable\u003c/code\u003e as an \u0026quot;unsafe\u0026quot; polymorphic base type (\u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6155\"\u003e#6155\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/65947556b62ee935a85aa5edaebf409813fd2456\"\u003e\u003ccode\u003e6594755\u003c/code\u003e\u003c/a\u003e One more minor tweak wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ba6fa2529df26d10fb57c44e1133ee786ebb82b9\"\u003e\u003ccode\u003eba6fa25\u003c/code\u003e\u003c/a\u003e Refactoring wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e part 2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/858a03b01028bc0131a0cb001473f215c2fe057d\"\u003e\u003ccode\u003e858a03b\u003c/code\u003e\u003c/a\u003e Refactoring wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/8de6a61f5d659249a41f85753a970992f46bbf98\"\u003e\u003ccode\u003e8de6a61\u003c/code\u003e\u003c/a\u003e Remove GHSA ids from CREDITS entries for \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6129\"\u003e#6129\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.18.6...jackson-databind-2.18.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.18.6\u0026new-version=2.18.10)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Dustin4444/openapi-generator/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/Dustin4444/openapi-generator/pull/561","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Dustin4444%2Fopenapi-generator/issues/561","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/561/packages"}},{"old_version":"2.18.9","new_version":"2.18.10","update_type":"patch","path":null,"pr_created_at":"2026-09-29T04:24:15.000Z","version_change":"2.18.9 → 2.18.10","issue":{"uuid":"5625075397","node_id":"PR_kwDOFkL42M8AAAABFoDhcw","number":251,"state":"open","title":"Bump com.fasterxml.jackson.core:jackson-databind from 2.18.9 to 2.18.10","user":"dependabot[bot]","labels":["dependencies","patch","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-29T04:24:15.000Z","updated_at":"2026-09-29T04:27:24.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.18.9","new_version":"2.18.10","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":null,"ecosystem":"maven"},"body":"Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.18.9 to 2.18.10.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/176df1d48b256ced412c65293ad4e09393e24bd3\"\u003e\u003ccode\u003e176df1d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.18.10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7785f5f9ed24127e004115472c47b26ea4cf2774\"\u003e\u003ccode\u003e7785f5f\u003c/code\u003e\u003c/a\u003e Prep for 2.18.10 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0ccf3241c72d324df711f092ab4fa8f5635272cf\"\u003e\u003ccode\u003e0ccf324\u003c/code\u003e\u003c/a\u003e Backport \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6165\"\u003e#6165\u003c/a\u003e to 2.18: apply number length limits to BigDecimal/BigInteger/D...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bb18488020df1228580be5024ae8c6e9f06d9226\"\u003e\u003ccode\u003ebb18488\u003c/code\u003e\u003c/a\u003e Fix CREDITS class name wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1b1bb192a8560a3139287ce69295e10c1c5c81b2\"\u003e\u003ccode\u003e1b1bb19\u003c/code\u003e\u003c/a\u003e Fix release notes wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f\"\u003e\u003ccode\u003eeb3b7fc\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003ejava.lang.Comparable\u003c/code\u003e as an \u0026quot;unsafe\u0026quot; polymorphic base type (\u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6155\"\u003e#6155\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/65947556b62ee935a85aa5edaebf409813fd2456\"\u003e\u003ccode\u003e6594755\u003c/code\u003e\u003c/a\u003e One more minor tweak wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ba6fa2529df26d10fb57c44e1133ee786ebb82b9\"\u003e\u003ccode\u003eba6fa25\u003c/code\u003e\u003c/a\u003e Refactoring wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e part 2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/858a03b01028bc0131a0cb001473f215c2fe057d\"\u003e\u003ccode\u003e858a03b\u003c/code\u003e\u003c/a\u003e Refactoring wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/8de6a61f5d659249a41f85753a970992f46bbf98\"\u003e\u003ccode\u003e8de6a61\u003c/code\u003e\u003c/a\u003e Remove GHSA ids from CREDITS entries for \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6129\"\u003e#6129\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.18.9...jackson-databind-2.18.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.18.9\u0026new-version=2.18.10)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/ONSdigital/ssdc-rm-ddl/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/ONSdigital/ssdc-rm-ddl/pull/251","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/ONSdigital%2Fssdc-rm-ddl/issues/251","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/251/packages"}},{"old_version":"2.18.9","new_version":"2.18.10","update_type":"patch","path":null,"pr_created_at":"2026-09-29T04:05:21.000Z","version_change":"2.18.9 → 2.18.10","issue":{"uuid":"5624922250","node_id":"PR_kwDOC2Uyf88AAAABFn7wsg","number":15,"state":"open","title":"Bump com.fasterxml.jackson.core:jackson-databind from 2.18.9 to 2.18.10","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-29T04:05:21.000Z","updated_at":"2026-09-29T04:05:29.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.18.9","new_version":"2.18.10","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":null,"ecosystem":"maven"},"body":"Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.18.9 to 2.18.10.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/176df1d48b256ced412c65293ad4e09393e24bd3\"\u003e\u003ccode\u003e176df1d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.18.10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7785f5f9ed24127e004115472c47b26ea4cf2774\"\u003e\u003ccode\u003e7785f5f\u003c/code\u003e\u003c/a\u003e Prep for 2.18.10 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0ccf3241c72d324df711f092ab4fa8f5635272cf\"\u003e\u003ccode\u003e0ccf324\u003c/code\u003e\u003c/a\u003e Backport \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6165\"\u003e#6165\u003c/a\u003e to 2.18: apply number length limits to BigDecimal/BigInteger/D...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bb18488020df1228580be5024ae8c6e9f06d9226\"\u003e\u003ccode\u003ebb18488\u003c/code\u003e\u003c/a\u003e Fix CREDITS class name wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1b1bb192a8560a3139287ce69295e10c1c5c81b2\"\u003e\u003ccode\u003e1b1bb19\u003c/code\u003e\u003c/a\u003e Fix release notes wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f\"\u003e\u003ccode\u003eeb3b7fc\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003ejava.lang.Comparable\u003c/code\u003e as an \u0026quot;unsafe\u0026quot; polymorphic base type (\u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6155\"\u003e#6155\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/65947556b62ee935a85aa5edaebf409813fd2456\"\u003e\u003ccode\u003e6594755\u003c/code\u003e\u003c/a\u003e One more minor tweak wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ba6fa2529df26d10fb57c44e1133ee786ebb82b9\"\u003e\u003ccode\u003eba6fa25\u003c/code\u003e\u003c/a\u003e Refactoring wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e part 2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/858a03b01028bc0131a0cb001473f215c2fe057d\"\u003e\u003ccode\u003e858a03b\u003c/code\u003e\u003c/a\u003e Refactoring wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/8de6a61f5d659249a41f85753a970992f46bbf98\"\u003e\u003ccode\u003e8de6a61\u003c/code\u003e\u003c/a\u003e Remove GHSA ids from CREDITS entries for \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6129\"\u003e#6129\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.18.9...jackson-databind-2.18.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.18.9\u0026new-version=2.18.10)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/PRIDE-Archive/archive-integration/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/PRIDE-Archive/archive-integration/pull/15","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/PRIDE-Archive%2Farchive-integration/issues/15","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/15/packages"}},{"old_version":"2.22.2","new_version":"2.22.3","update_type":"patch","path":"the testcontainers group","pr_created_at":"2026-09-29T03:08:12.000Z","version_change":"2.22.2 → 2.22.3","issue":{"uuid":"5624455927","node_id":"PR_kwDOCfzDTM8AAAABFnkCXw","number":4202,"state":"open","title":"[4.3] Bump com.fasterxml.jackson.core:jackson-databind from 2.22.2 to 2.22.3 in the testcontainers group","user":"dependabot[bot]","labels":["dependencies","java","4.3"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-29T03:08:12.000Z","updated_at":"2026-09-29T04:34:59.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"[4.3] Bump","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":"the testcontainers group","ecosystem":"maven"},"body":"Bumps the testcontainers group with 1 update: [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind).\n\nUpdates `com.fasterxml.jackson.core:jackson-databind` from 2.22.2 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/4385c5f7d51426f66fb24c3777308acc8ae7ea6c\"\u003e\u003ccode\u003e4385c5f\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ccb4fd0158cd20800f6014496dccf7332e5b18ce\"\u003e\u003ccode\u003eccb4fd0\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/2958412f1817a0ad95c34066b7eb85781dd2d4f1\"\u003e\u003ccode\u003e2958412\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1215b94c2f7a8c4ce3863afbc38275a19c682a54\"\u003e\u003ccode\u003e1215b94\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1f0df621449e5de7dd13a1538e0343f65f0e6bb3\"\u003e\u003ccode\u003e1f0df62\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/13a9ff4c4ef982cda23b99fea89d2a4e87af9019\"\u003e\u003ccode\u003e13a9ff4\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/d168f9679ad575cdc2df8d53a8474ec481c7b5a7\"\u003e\u003ccode\u003ed168f96\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/eaf5c76b8e0a538729a1bf922061abf73b13f89b\"\u003e\u003ccode\u003eeaf5c76\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/e05ef4cbb4d534a82948f8ba84350e55493bc72e\"\u003e\u003ccode\u003ee05ef4c\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/f6d4000c1eb6d34e2ae24685a9790b1e833d4bcb\"\u003e\u003ccode\u003ef6d4000\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.22.2...jackson-databind-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=gradle\u0026previous-version=2.22.2\u0026new-version=2.22.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/hibernate/hibernate-reactive/pull/4202","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/hibernate%2Fhibernate-reactive/issues/4202","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/4202/packages"}},{"old_version":"2.17.0","new_version":"2.18.10","update_type":"minor","path":"/java","pr_created_at":"2026-09-29T01:22:53.000Z","version_change":"2.17.0 → 2.18.10","issue":{"uuid":"5623602329","node_id":"PR_kwDOSePpfM8AAAABFm5L5A","number":208,"state":"open","title":"build(deps): bump com.fasterxml.jackson.core:jackson-databind from 2.17.0 to 2.18.10 in /java","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":9,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-29T01:22:53.000Z","updated_at":"2026-09-29T01:24:22.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps)","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.17.0","new_version":"2.18.10","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":"/java","ecosystem":"maven"},"body":"Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.17.0 to 2.18.10.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/176df1d48b256ced412c65293ad4e09393e24bd3\"\u003e\u003ccode\u003e176df1d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.18.10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7785f5f9ed24127e004115472c47b26ea4cf2774\"\u003e\u003ccode\u003e7785f5f\u003c/code\u003e\u003c/a\u003e Prep for 2.18.10 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0ccf3241c72d324df711f092ab4fa8f5635272cf\"\u003e\u003ccode\u003e0ccf324\u003c/code\u003e\u003c/a\u003e Backport \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6165\"\u003e#6165\u003c/a\u003e to 2.18: apply number length limits to BigDecimal/BigInteger/D...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bb18488020df1228580be5024ae8c6e9f06d9226\"\u003e\u003ccode\u003ebb18488\u003c/code\u003e\u003c/a\u003e Fix CREDITS class name wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1b1bb192a8560a3139287ce69295e10c1c5c81b2\"\u003e\u003ccode\u003e1b1bb19\u003c/code\u003e\u003c/a\u003e Fix release notes wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f\"\u003e\u003ccode\u003eeb3b7fc\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003ejava.lang.Comparable\u003c/code\u003e as an \u0026quot;unsafe\u0026quot; polymorphic base type (\u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6155\"\u003e#6155\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/65947556b62ee935a85aa5edaebf409813fd2456\"\u003e\u003ccode\u003e6594755\u003c/code\u003e\u003c/a\u003e One more minor tweak wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ba6fa2529df26d10fb57c44e1133ee786ebb82b9\"\u003e\u003ccode\u003eba6fa25\u003c/code\u003e\u003c/a\u003e Refactoring wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e part 2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/858a03b01028bc0131a0cb001473f215c2fe057d\"\u003e\u003ccode\u003e858a03b\u003c/code\u003e\u003c/a\u003e Refactoring wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/8de6a61f5d659249a41f85753a970992f46bbf98\"\u003e\u003ccode\u003e8de6a61\u003c/code\u003e\u003c/a\u003e Remove GHSA ids from CREDITS entries for \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6129\"\u003e#6129\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.17.0...jackson-databind-2.18.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.17.0\u0026new-version=2.18.10)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Dustin4444/x402/network/alerts).\n\n\u003c/details\u003e\n\n\u003c!-- Reviewable:start --\u003e\n- - -\nThis change is [\u003cimg src=\"https://reviewable.io/review_button.svg\" height=\"34\" align=\"absmiddle\" alt=\"Reviewable\"/\u003e](https://reviewable.io/reviews/Dustin4444/x402/208)\n\u003c!-- Reviewable:end --\u003e\n","html_url":"https://github.com/Dustin4444/x402/pull/208","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Dustin4444%2Fx402/issues/208","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/208/packages"}},{"old_version":"2.16.0","new_version":"2.18.10","update_type":"minor","path":"/test/providers/tst_manifests/maven/pom_with_multiple_modules/module4","pr_created_at":"2026-09-29T00:02:31.000Z","version_change":"2.16.0 → 2.18.10","issue":{"uuid":"5622952790","node_id":"PR_kwDOJqMqPM8AAAABFmYZcg","number":647,"state":"open","title":"build(deps): bump com.fasterxml.jackson.core:jackson-databind from 2.16.0 to 2.18.10 in /test/providers/tst_manifests/maven/pom_with_multiple_modules/module4","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-29T00:02:31.000Z","updated_at":"2026-09-29T08:00:46.452Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps)","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.16.0","new_version":"2.18.10","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":"/test/providers/tst_manifests/maven/pom_with_multiple_modules/module4","ecosystem":"maven"},"body":"Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.16.0 to 2.18.10.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/176df1d48b256ced412c65293ad4e09393e24bd3\"\u003e\u003ccode\u003e176df1d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.18.10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7785f5f9ed24127e004115472c47b26ea4cf2774\"\u003e\u003ccode\u003e7785f5f\u003c/code\u003e\u003c/a\u003e Prep for 2.18.10 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0ccf3241c72d324df711f092ab4fa8f5635272cf\"\u003e\u003ccode\u003e0ccf324\u003c/code\u003e\u003c/a\u003e Backport \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6165\"\u003e#6165\u003c/a\u003e to 2.18: apply number length limits to BigDecimal/BigInteger/D...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bb18488020df1228580be5024ae8c6e9f06d9226\"\u003e\u003ccode\u003ebb18488\u003c/code\u003e\u003c/a\u003e Fix CREDITS class name wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1b1bb192a8560a3139287ce69295e10c1c5c81b2\"\u003e\u003ccode\u003e1b1bb19\u003c/code\u003e\u003c/a\u003e Fix release notes wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/eb3b7fc0f9c0d27f471550ac3316b17d1987388f\"\u003e\u003ccode\u003eeb3b7fc\u003c/code\u003e\u003c/a\u003e Add \u003ccode\u003ejava.lang.Comparable\u003c/code\u003e as an \u0026quot;unsafe\u0026quot; polymorphic base type (\u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6155\"\u003e#6155\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/65947556b62ee935a85aa5edaebf409813fd2456\"\u003e\u003ccode\u003e6594755\u003c/code\u003e\u003c/a\u003e One more minor tweak wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ba6fa2529df26d10fb57c44e1133ee786ebb82b9\"\u003e\u003ccode\u003eba6fa25\u003c/code\u003e\u003c/a\u003e Refactoring wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e part 2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/858a03b01028bc0131a0cb001473f215c2fe057d\"\u003e\u003ccode\u003e858a03b\u003c/code\u003e\u003c/a\u003e Refactoring wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/8de6a61f5d659249a41f85753a970992f46bbf98\"\u003e\u003ccode\u003e8de6a61\u003c/code\u003e\u003c/a\u003e Remove GHSA ids from CREDITS entries for \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6129\"\u003e#6129\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.16.0...jackson-databind-2.18.10\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.16.0\u0026new-version=2.18.10)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/guacsec/trustify-da-javascript-client/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/guacsec/trustify-da-javascript-client/pull/647","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/guacsec%2Ftrustify-da-javascript-client/issues/647","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/647/packages"}},{"old_version":"2.22.1","new_version":"2.22.2","update_type":"patch","path":"/examples/sts-metrics","pr_created_at":"2026-09-28T21:11:05.000Z","version_change":"2.22.1 → 2.22.2","issue":{"uuid":"5621291873","node_id":"PR_kwDOBXext88AAAABFlDPYA","number":2292,"state":"open","title":"Build(deps): bump com.fasterxml.jackson.core:jackson-databind from 2.22.1 to 2.22.2 in /examples/sts-metrics","user":"dependabot[bot]","labels":["size/XS","dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-28T21:11:05.000Z","updated_at":"2026-09-29T18:57:30.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Build(deps)","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.22.1","new_version":"2.22.2","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":"/examples/sts-metrics","ecosystem":"maven"},"body":"Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.22.1 to 2.22.2.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/25b2a221f9aa4107e455065a74635e209418cf55\"\u003e\u003ccode\u003e25b2a22\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.22.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bab1c1a702a941f8805ee6698e8fa4fdbfbec54a\"\u003e\u003ccode\u003ebab1c1a\u003c/code\u003e\u003c/a\u003e Prep for 2.22.2 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bc03cf83d74cf0e5944dce33a63ee59ddc344b64\"\u003e\u003ccode\u003ebc03cf8\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/83379fb6409075336edf3d8d88744e95911a43f8\"\u003e\u003ccode\u003e83379fb\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0d400c9dc586fdd460d0c6a40db21ebbe22106d8\"\u003e\u003ccode\u003e0d400c9\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ce36a279f8b078bef2d9d44a1d01034c3634f91a\"\u003e\u003ccode\u003ece36a27\u003c/code\u003e\u003c/a\u003e Merge branch '2.18' into 2.19\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7a209e1fa97033746db50fd7bcd1e3dbab077599\"\u003e\u003ccode\u003e7a209e1\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/a432707afe6b7569243d1c2d8052a1bf33d9279c\"\u003e\u003ccode\u003ea432707\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/176df1d48b256ced412c65293ad4e09393e24bd3\"\u003e\u003ccode\u003e176df1d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.18.10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7785f5f9ed24127e004115472c47b26ea4cf2774\"\u003e\u003ccode\u003e7785f5f\u003c/code\u003e\u003c/a\u003e Prep for 2.18.10 release\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.22.1...jackson-databind-2.22.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.22.1\u0026new-version=2.22.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/GoogleCloudPlatform/professional-services/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/GoogleCloudPlatform/professional-services/pull/2292","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/GoogleCloudPlatform%2Fprofessional-services/issues/2292","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2292/packages"}},{"old_version":"2.21.4","new_version":"2.21.6","update_type":"patch","path":"/nimble-orm","pr_created_at":"2026-09-28T21:05:42.000Z","version_change":"2.21.4 → 2.21.6","issue":{"uuid":"5621228630","node_id":"PR_kwDOAmLhj88AAAABFk_-Pg","number":83,"state":"closed","title":"Bump com.fasterxml.jackson.core:jackson-databind from 2.21.4 to 2.21.6 in /nimble-orm","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-30T02:47:35.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-28T21:05:42.000Z","updated_at":"2026-09-30T02:47:37.000Z","time_to_close":106913,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.21.4","new_version":"2.21.6","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":"/nimble-orm","ecosystem":"maven"},"body":"Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.21.4 to 2.21.6.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/5cf4246e1be4a579dbb64c83ef06a961381ca1a2\"\u003e\u003ccode\u003e5cf4246\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.21.6\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/b07e30e2183612d1ef14c5dce900dcc69688c240\"\u003e\u003ccode\u003eb07e30e\u003c/code\u003e\u003c/a\u003e Prep for 2.21.6 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/5bd046635388b90dd78749a9e50fad07a98d91dd\"\u003e\u003ccode\u003e5bd0466\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/d0f58e61281ad9912d3fa442f4b5ee65eb24e9f2\"\u003e\u003ccode\u003ed0f58e6\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0816b7c7ddb1a89fee5ff44c204531ee051a58ff\"\u003e\u003ccode\u003e0816b7c\u003c/code\u003e\u003c/a\u003e Merge branch '2.18' into 2.19\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0ccf3241c72d324df711f092ab4fa8f5635272cf\"\u003e\u003ccode\u003e0ccf324\u003c/code\u003e\u003c/a\u003e Backport \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6165\"\u003e#6165\u003c/a\u003e to 2.18: apply number length limits to BigDecimal/BigInteger/D...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0a0195d32b01bb1a039b81e36a4b6f28a51bfa82\"\u003e\u003ccode\u003e0a0195d\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/64f7e09ae991a4b55edd93960260f18c529120aa\"\u003e\u003ccode\u003e64f7e09\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/4edb753847293add6b0b46895334e0902b3c0154\"\u003e\u003ccode\u003e4edb753\u003c/code\u003e\u003c/a\u003e Merge branch '2.18' into 2.19\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bb18488020df1228580be5024ae8c6e9f06d9226\"\u003e\u003ccode\u003ebb18488\u003c/code\u003e\u003c/a\u003e Fix CREDITS class name wrt \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6127\"\u003e#6127\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.21.4...jackson-databind-2.21.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.21.4\u0026new-version=2.21.6)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/pugwoo/nimble-orm/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/pugwoo/nimble-orm/pull/83","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/pugwoo%2Fnimble-orm/issues/83","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/83/packages"}},{"old_version":"2.22.1","new_version":"2.22.2","update_type":"patch","path":null,"pr_created_at":"2026-09-28T20:31:32.000Z","version_change":"2.22.1 → 2.22.2","issue":{"uuid":"5620809803","node_id":"PR_kwDOBElMp88AAAABFkqRjQ","number":31,"state":"open","title":"⬆️ Bump com.fasterxml.jackson.core:jackson-databind from 2.22.1 to 2.22.2","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-28T20:31:32.000Z","updated_at":"2026-09-28T20:32:06.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"⬆️ Bump","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.22.1","new_version":"2.22.2","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":null,"ecosystem":"maven"},"body":"Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.22.1 to 2.22.2.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/25b2a221f9aa4107e455065a74635e209418cf55\"\u003e\u003ccode\u003e25b2a22\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.22.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bab1c1a702a941f8805ee6698e8fa4fdbfbec54a\"\u003e\u003ccode\u003ebab1c1a\u003c/code\u003e\u003c/a\u003e Prep for 2.22.2 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bc03cf83d74cf0e5944dce33a63ee59ddc344b64\"\u003e\u003ccode\u003ebc03cf8\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/83379fb6409075336edf3d8d88744e95911a43f8\"\u003e\u003ccode\u003e83379fb\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0d400c9dc586fdd460d0c6a40db21ebbe22106d8\"\u003e\u003ccode\u003e0d400c9\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ce36a279f8b078bef2d9d44a1d01034c3634f91a\"\u003e\u003ccode\u003ece36a27\u003c/code\u003e\u003c/a\u003e Merge branch '2.18' into 2.19\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7a209e1fa97033746db50fd7bcd1e3dbab077599\"\u003e\u003ccode\u003e7a209e1\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/a432707afe6b7569243d1c2d8052a1bf33d9279c\"\u003e\u003ccode\u003ea432707\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/176df1d48b256ced412c65293ad4e09393e24bd3\"\u003e\u003ccode\u003e176df1d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.18.10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7785f5f9ed24127e004115472c47b26ea4cf2774\"\u003e\u003ccode\u003e7785f5f\u003c/code\u003e\u003c/a\u003e Prep for 2.18.10 release\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.22.1...jackson-databind-2.22.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.22.1\u0026new-version=2.22.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/binarywang/weixin-java-mp-multi-demo/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/binarywang/weixin-java-mp-multi-demo/pull/31","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/binarywang%2Fweixin-java-mp-multi-demo/issues/31","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/31/packages"}},{"old_version":"2.22.0","new_version":"2.22.2","update_type":"patch","path":"/examples/integrate-with-maven/maven-project","pr_created_at":"2026-09-28T20:21:32.000Z","version_change":"2.22.0 → 2.22.2","issue":{"uuid":"5620688559","node_id":"PR_kwDOE8Qh388AAAABFkkAqA","number":2686,"state":"open","title":"chore(deps): bump com.fasterxml.jackson.core:jackson-databind from 2.22.0 to 2.22.2 in /examples/integrate-with-maven/maven-project","user":"dependabot[bot]","labels":["dependencies","autoapproved","autoupdate","java"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-28T20:21:32.000Z","updated_at":"2026-09-28T20:22:20.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps)","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.22.0","new_version":"2.22.2","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":"/examples/integrate-with-maven/maven-project","ecosystem":"maven"},"body":"Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.22.0 to 2.22.2.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/25b2a221f9aa4107e455065a74635e209418cf55\"\u003e\u003ccode\u003e25b2a22\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.22.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bab1c1a702a941f8805ee6698e8fa4fdbfbec54a\"\u003e\u003ccode\u003ebab1c1a\u003c/code\u003e\u003c/a\u003e Prep for 2.22.2 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bc03cf83d74cf0e5944dce33a63ee59ddc344b64\"\u003e\u003ccode\u003ebc03cf8\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/83379fb6409075336edf3d8d88744e95911a43f8\"\u003e\u003ccode\u003e83379fb\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0d400c9dc586fdd460d0c6a40db21ebbe22106d8\"\u003e\u003ccode\u003e0d400c9\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ce36a279f8b078bef2d9d44a1d01034c3634f91a\"\u003e\u003ccode\u003ece36a27\u003c/code\u003e\u003c/a\u003e Merge branch '2.18' into 2.19\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7a209e1fa97033746db50fd7bcd1e3dbab077599\"\u003e\u003ccode\u003e7a209e1\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/a432707afe6b7569243d1c2d8052a1bf33d9279c\"\u003e\u003ccode\u003ea432707\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/176df1d48b256ced412c65293ad4e09393e24bd3\"\u003e\u003ccode\u003e176df1d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.18.10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7785f5f9ed24127e004115472c47b26ea4cf2774\"\u003e\u003ccode\u003e7785f5f\u003c/code\u003e\u003c/a\u003e Prep for 2.18.10 release\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.22.0...jackson-databind-2.22.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.22.0\u0026new-version=2.22.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/asyncapi/modelina/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/asyncapi/modelina/pull/2686","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/asyncapi%2Fmodelina/issues/2686","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/2686/packages"}},{"old_version":"2.21.1","new_version":"2.22.3","update_type":"minor","path":"/gateways/pingaccess/authzen-pdp","pr_created_at":"2026-09-26T12:24:02.000Z","version_change":"2.21.1 → 2.22.3","issue":{"uuid":"5593945962","node_id":"PR_kwDOUGgVCc8AAAABFPuOHA","number":6,"state":"closed","title":"build(deps): bump the maven group in /gateways/pingaccess/authzen-pdp with 7 updates","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-27T00:21:46.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-26T12:24:02.000Z","updated_at":"2026-09-27T00:21:48.000Z","time_to_close":43064,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"maven","update_count":7,"packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.21.1","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-databind"},{"name":"org.bitbucket.b_c:jose4j","old_version":"0.9.6","new_version":"0.9.7"},{"name":"org.mockito:mockito-core","old_version":"5.14.2","new_version":"5.23.0","repository_url":"https://github.com/mockito/mockito"},{"name":"org.apache.maven.plugins:maven-compiler-plugin","old_version":"3.13.0","new_version":"3.16.0","repository_url":"https://github.com/apache/maven-compiler-plugin"},{"name":"org.apache.maven.plugins:maven-surefire-plugin","old_version":"3.2.5","new_version":"3.6.0","repository_url":"https://github.com/apache/maven-surefire"},{"name":"org.apache.maven.plugins:maven-jar-plugin","old_version":"3.4.1","new_version":"3.5.1","repository_url":"https://github.com/apache/maven-jar-plugin"},{"name":"org.jacoco:jacoco-maven-plugin","old_version":"0.8.12","new_version":"0.8.15","repository_url":"https://github.com/jacoco/jacoco"}],"path":"/gateways/pingaccess/authzen-pdp","ecosystem":"maven"},"body":"[//]: # (dependabot-start)\n⚠️  **Dependabot is rebasing this PR** ⚠️ \n\nRebasing might not happen immediately, so don't worry if this takes some time.\n\nNote: if you make any changes to this PR yourself, they will take precedence over the rebase.\n\n---\n\n[//]: # (dependabot-end)\n\nBumps the maven group in /gateways/pingaccess/authzen-pdp with 7 updates:\n\n| Package | From | To |\n| --- | --- | --- |\n| [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) | `2.21.1` | `2.22.3` |\n| [org.bitbucket.b_c:jose4j](https://bitbucket.org/b_c/jose4j) | `0.9.6` | `0.9.7` |\n| [org.mockito:mockito-core](https://github.com/mockito/mockito) | `5.14.2` | `5.23.0` |\n| [org.apache.maven.plugins:maven-compiler-plugin](https://github.com/apache/maven-compiler-plugin) | `3.13.0` | `3.16.0` |\n| [org.apache.maven.plugins:maven-surefire-plugin](https://github.com/apache/maven-surefire) | `3.2.5` | `3.6.0` |\n| [org.apache.maven.plugins:maven-jar-plugin](https://github.com/apache/maven-jar-plugin) | `3.4.1` | `3.5.1` |\n| [org.jacoco:jacoco-maven-plugin](https://github.com/jacoco/jacoco) | `0.8.12` | `0.8.15` |\n\nUpdates `com.fasterxml.jackson.core:jackson-databind` from 2.21.1 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/4385c5f7d51426f66fb24c3777308acc8ae7ea6c\"\u003e\u003ccode\u003e4385c5f\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ccb4fd0158cd20800f6014496dccf7332e5b18ce\"\u003e\u003ccode\u003eccb4fd0\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/2958412f1817a0ad95c34066b7eb85781dd2d4f1\"\u003e\u003ccode\u003e2958412\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1215b94c2f7a8c4ce3863afbc38275a19c682a54\"\u003e\u003ccode\u003e1215b94\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1f0df621449e5de7dd13a1538e0343f65f0e6bb3\"\u003e\u003ccode\u003e1f0df62\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/13a9ff4c4ef982cda23b99fea89d2a4e87af9019\"\u003e\u003ccode\u003e13a9ff4\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/d168f9679ad575cdc2df8d53a8474ec481c7b5a7\"\u003e\u003ccode\u003ed168f96\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/eaf5c76b8e0a538729a1bf922061abf73b13f89b\"\u003e\u003ccode\u003eeaf5c76\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/e05ef4cbb4d534a82948f8ba84350e55493bc72e\"\u003e\u003ccode\u003ee05ef4c\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/f6d4000c1eb6d34e2ae24685a9790b1e833d4bcb\"\u003e\u003ccode\u003ef6d4000\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.21.1...jackson-databind-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.bitbucket.b_c:jose4j` from 0.9.6 to 0.9.7\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from [org.bitbucket.b_c:jose4j's changelog](\u003ca href=\"https://bitbucket.org/b_c/jose4j/src/master/Release\"\u003ehttps://bitbucket.org/b_c/jose4j/src/master/Release\u003c/a\u003e Notes.md).\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch5\u003ejose4j-0.9.7 - September 9, 2026\u003c/h5\u003e\n\u003cul\u003e\n\u003cli\u003eupdate test dependencies\u003c/li\u003e\n\u003cli\u003ecap the size of numbers for better resource utilization in JSON processing (hat tip to Mike Read for the tip)\u003c/li\u003e\n\u003cli\u003efix some typos and other issues in javadoc and log messages\u003c/li\u003e\n\u003cli\u003eupdates for newer maven central publishing\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://bitbucket.org/b_c/jose4j/commits/756257eb92352600d5dde08c2b8ed25db13a8952\"\u003e\u003ccode\u003e756257e\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://bitbucket.org/b_c/jose4j/commits/5db177b550d355365ebf5c63d86376766e3ed6d8\"\u003e\u003ccode\u003e5db177b\u003c/code\u003e\u003c/a\u003e Look for Tag mismatch with no \u0026quot;!\u0026quot; b/c apparently maybe that changed\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://bitbucket.org/b_c/jose4j/commits/71a6650cee92e4c7fd91e860a42ddc533c902e40\"\u003e\u003ccode\u003e71a6650\u003c/code\u003e\u003c/a\u003e Merged in strict-aud-validation (pull request \u003ca href=\"https://bitbucket.org/b_c/jose4j/issues/26\"\u003e#26\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://bitbucket.org/b_c/jose4j/commits/05ce8870e1b7e37ef4bb53d138c95746c4dd0e28\"\u003e\u003ccode\u003e05ce887\u003c/code\u003e\u003c/a\u003e Compiler source and target to 1.8\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://bitbucket.org/b_c/jose4j/commits/f7c6da83b7f8097be7d3391b4eca9a7dec4e765f\"\u003e\u003ccode\u003ef7c6da8\u003c/code\u003e\u003c/a\u003e Update slf4j, bouncycastle, and mockito dependencies\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://bitbucket.org/b_c/jose4j/commits/3ac5eb47145d8d63bb640020fd9a0c22435ed932\"\u003e\u003ccode\u003e3ac5eb4\u003c/code\u003e\u003c/a\u003e Merged in fix-comment-typos (pull request \u003ca href=\"https://bitbucket.org/b_c/jose4j/issues/27\"\u003e#27\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://bitbucket.org/b_c/jose4j/commits/a87874c53748cb92002fcefd32df27413e14f4c2\"\u003e\u003ccode\u003ea87874c\u003c/code\u003e\u003c/a\u003e Fix stated default in Get.setResponseBodySizeLimit javadoc\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://bitbucket.org/b_c/jose4j/commits/51bdce2c95183cd11937b11190b306fe2a32ff59\"\u003e\u003ccode\u003e51bdce2\u003c/code\u003e\u003c/a\u003e fix log message arg number missmatch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://bitbucket.org/b_c/jose4j/commits/7d8c47016f77686844288576b133f23d6e75e83b\"\u003e\u003ccode\u003e7d8c470\u003c/code\u003e\u003c/a\u003e Another log message arg number mismatch with a different fix\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://bitbucket.org/b_c/jose4j/commits/908a55ebf58b908e9e91a01aa86d8e5ae9f37dce\"\u003e\u003ccode\u003e908a55e\u003c/code\u003e\u003c/a\u003e cap the size of numbers for better resource utilization in JSON processing (h...\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://bitbucket.org/b_c/jose4j/branches/compare/jose4j-0.9.7..jose4j-0.9.6\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.mockito:mockito-core` from 5.14.2 to 5.23.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mockito/mockito/releases\"\u003eorg.mockito:mockito-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev5.23.0\u003c/h2\u003e\n\u003ch2\u003eNOTE: Breaking change for Android\u003c/h2\u003e\n\u003cp\u003eThe \u003ccode\u003emockito-android\u003c/code\u003e artifact has a breaking change: tests now require a device or emulator based on API 28+ (Android P). This is to enable new support for mocking Kotlin classes. See \u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3788\"\u003e#3788\u003c/a\u003e for more details.\u003c/p\u003e\n\u003chr /\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003cem\u003eChangelog generated by \u003ca href=\"https://github.com/shipkit/shipkit-changelog\"\u003eShipkit Changelog Gradle Plugin\u003c/a\u003e\u003c/em\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch4\u003e5.23.0\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e2026-03-11 - \u003ca href=\"https://github.com/mockito/mockito/compare/v5.22.0...v5.23.0\"\u003e6 commit(s)\u003c/a\u003e by Brice Dutheil, Joshua Selbo, Philippe Kernevez\u003c/li\u003e\n\u003cli\u003eReplace mockito-android mock maker implementation with dexmaker-mockito-inline [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3792\"\u003e#3792\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3792\"\u003emockito/mockito#3792\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix StackOverflowError with AbstractList after using mockSingleton [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3790\"\u003e#3790\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3790\"\u003emockito/mockito#3790\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eMark parameters of \u003ccode\u003eMockito.when\u003c/code\u003e \u003ccode\u003e@Nullable\u003c/code\u003e [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3503\"\u003e#3503\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3503\"\u003emockito/mockito#3503\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev5.22.0\u003c/h2\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003cem\u003eChangelog generated by \u003ca href=\"https://github.com/shipkit/shipkit-changelog\"\u003eShipkit Changelog Gradle Plugin\u003c/a\u003e\u003c/em\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch4\u003e5.22.0\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e2026-02-27 - \u003ca href=\"https://github.com/mockito/mockito/compare/v5.21.0...v5.22.0\"\u003e6 commit(s)\u003c/a\u003e by Joshua Selbo, NiMv1, Rafael Winterhalter, dependabot[bot], eunbin son\u003c/li\u003e\n\u003cli\u003eAvoid mocking of internal static utilities [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3785\"\u003e#3785\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3785\"\u003emockito/mockito#3785\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump graalvm/setup-graalvm from 1.4.4 to 1.4.5 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3780\"\u003e#3780\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3780\"\u003emockito/mockito#3780\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eStatic mocking of UUID.class corrupted under JDK 25 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3778\"\u003e#3778\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3778\"\u003emockito/mockito#3778\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump actions/upload-artifact from 5 to 6 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3774\"\u003e#3774\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3774\"\u003emockito/mockito#3774\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003edocs: clarify RETURNS_MOCKS behavior with sealed abstract enums (Java 15+) [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3773\"\u003e#3773\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3773\"\u003emockito/mockito#3773\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd tests for Sets utility class [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3771\"\u003e#3771\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3771\"\u003emockito/mockito#3771\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd core API to enable Kotlin singleton mocking [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3762\"\u003e#3762\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3762\"\u003emockito/mockito#3762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eStubbing Kotlin \u003ccode\u003eobject\u003c/code\u003e singletons [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3652\"\u003e#3652\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3652\"\u003emockito/mockito#3652\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eIncorrect documentation for RETURNS_MOCKS [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3285\"\u003e#3285\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3285\"\u003emockito/mockito#3285\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003ev5.21.0\u003c/h2\u003e\n\u003cp\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003cem\u003eChangelog generated by \u003ca href=\"https://github.com/shipkit/shipkit-changelog\"\u003eShipkit Changelog Gradle Plugin\u003c/a\u003e\u003c/em\u003e\u003c!-- raw HTML omitted --\u003e\u003c!-- raw HTML omitted --\u003e\u003c/p\u003e\n\u003ch4\u003e5.21.0\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e2025-12-09 - \u003ca href=\"https://github.com/mockito/mockito/compare/v5.20.0...v5.21.0\"\u003e17 commit(s)\u003c/a\u003e by Giulio Longfils, Joshua Selbo, Woongi9, Zylox, dependabot[bot]\u003c/li\u003e\n\u003cli\u003eBump graalvm/setup-graalvm from 1.4.3 to 1.4.4 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3768\"\u003e#3768\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3768\"\u003emockito/mockito#3768\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump graalvm/setup-graalvm from 1.4.2 to 1.4.3 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3767\"\u003e#3767\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3767\"\u003emockito/mockito#3767\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump actions/checkout from 5 to 6 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3765\"\u003e#3765\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3765\"\u003emockito/mockito#3765\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdds output of matchers to potential mismatch; Fixes \u003ca href=\"https://redirect.github.com/mockito/mockito/issues/2468\"\u003e#2468\u003c/a\u003e [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3760\"\u003e#3760\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3760\"\u003emockito/mockito#3760\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eForbid mocking WeakReference with inline mock maker [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3759\"\u003e#3759\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3759\"\u003emockito/mockito#3759\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eStackOverflowError when mocking WeakReference [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3758\"\u003e#3758\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3758\"\u003emockito/mockito#3758\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump actions/upload-artifact from 4 to 5 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3756\"\u003e#3756\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3756\"\u003emockito/mockito#3756\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump graalvm/setup-graalvm from 1.4.1 to 1.4.2 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3755\"\u003e#3755\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3755\"\u003emockito/mockito#3755\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSupport primitives in GenericArrayReturnType. [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3753\"\u003e#3753\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3753\"\u003emockito/mockito#3753\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eClassNotFoundException when stubbing array of primitive type on Android [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3752\"\u003e#3752\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3752\"\u003emockito/mockito#3752\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump graalvm/setup-graalvm from 1.4.0 to 1.4.1 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3744\"\u003e#3744\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3744\"\u003emockito/mockito#3744\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump gradle/actions from 4 to 5 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3743\"\u003e#3743\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3743\"\u003emockito/mockito#3743\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump org.graalvm.buildtools.native from 0.11.0 to 0.11.1 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3738\"\u003e#3738\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3738\"\u003emockito/mockito#3738\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump com.diffplug.spotless:spotless-plugin-gradle from 7.2.1 to 8.0.0 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3735\"\u003e#3735\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3735\"\u003emockito/mockito#3735\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump graalvm/setup-graalvm from 1.3.7 to 1.4.0 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3734\"\u003e#3734\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3734\"\u003emockito/mockito#3734\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eBump org.assertj:assertj-core from 3.27.5 to 3.27.6 [(\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3733\"\u003e#3733\u003c/a\u003e)](\u003ca href=\"https://redirect.github.com/mockito/mockito/pull/3733\"\u003emockito/mockito#3733\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/a231205b240e7884a63bf0f63440012867a4da21\"\u003e\u003ccode\u003ea231205\u003c/code\u003e\u003c/a\u003e Fix StackOverflowError with AbstractList after using mockSingleton (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3790\"\u003e#3790\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/f6a91a6a6138c776fa8b41ffb3fd078c64802044\"\u003e\u003ccode\u003ef6a91a6\u003c/code\u003e\u003c/a\u003e Replace mockito-android mock maker implementation with dexmaker-mockito-inlin...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/aa2298a627ab2c0bce07f648e444477d8e2e05ba\"\u003e\u003ccode\u003eaa2298a\u003c/code\u003e\u003c/a\u003e fix: make spotless happy\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/a6729d657e232ca64da81d9801d7b8f3be6fc49a\"\u003e\u003ccode\u003ea6729d6\u003c/code\u003e\u003c/a\u003e chore: update BDDMockito with jspecify annotation\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/bb83c922484cfd3693d61549b5d6ef39a9c02c2b\"\u003e\u003ccode\u003ebb83c92\u003c/code\u003e\u003c/a\u003e chore: move jspecify as a compile only dependency\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/47a46954cd1c0f8ef64ec63d43da9b71081d74e6\"\u003e\u003ccode\u003e47a4695\u003c/code\u003e\u003c/a\u003e chore: add jspecify with minimal change. Fixes \u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3503\"\u003e#3503\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/25f13951d35ca391ee50207e6c564f3e869f3d91\"\u003e\u003ccode\u003e25f1395\u003c/code\u003e\u003c/a\u003e Add core API to enable Kotlin singleton mocking (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3762\"\u003e#3762\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/ef9ee5529853d96028b520f84a41ffd41afc9a1d\"\u003e\u003ccode\u003eef9ee55\u003c/code\u003e\u003c/a\u003e Avoids mocking private static methods, as well as package-private static meth...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/d16fcfc274d7ca03a2b4bdc22dd7c3ec6dac8690\"\u003e\u003ccode\u003ed16fcfc\u003c/code\u003e\u003c/a\u003e Bump graalvm/setup-graalvm from 1.4.4 to 1.4.5 (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3780\"\u003e#3780\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mockito/mockito/commit/27eb8a3acdd9c9eb3ff788a71b22777026874439\"\u003e\u003ccode\u003e27eb8a3\u003c/code\u003e\u003c/a\u003e Clarify \u003ccode\u003eRETURNS_MOCKS\u003c/code\u003e behavior with sealed abstract enums (Java 15+) (\u003ca href=\"https://redirect.github.com/mockito/mockito/issues/3773\"\u003e#3773\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mockito/mockito/compare/v5.14.2...v5.23.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.maven.plugins:maven-compiler-plugin` from 3.13.0 to 3.16.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/apache/maven-compiler-plugin/releases\"\u003eorg.apache.maven.plugins:maven-compiler-plugin's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.16.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e🚀 New features and improvements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRecompile when dependencies change (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1102\"\u003e#1102\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix incremental detection of empty sources, 3.x (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1075\"\u003e#1075\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/MCOMPILER-578\"\u003e[MCOMPILER-578]\u003c/a\u003e - Track outputs across compiler executions (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1091\"\u003e#1091\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBuild fails when annotation processor list is empty (but present) (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1077\"\u003e#1077\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/MCOMPILER-374\"\u003e[MCOMPILER-374]\u003c/a\u003e - Unable to compile MR-JAR code against older directories when module-info.java is present (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1093\"\u003e#1093\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMake mcompiler-120 IT locale independent (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1063\"\u003e#1063\u003c/a\u003e) \u003ca href=\"https://github.com/anilvdl\"\u003e\u003ccode\u003e@​anilvdl\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📝 Documentation updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/MCOMPILER-569\"\u003e[MCOMPILER-569]\u003c/a\u003e - Document implicitly compiled excluded sources (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1092\"\u003e#1092\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1074\"\u003e#1074\u003c/a\u003e) \u003ca href=\"https://github.com/potiuk\"\u003e\u003ccode\u003e@​potiuk\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e👻 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid using deprecated method CompilerConfiguration.setCompilerVersion (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1121\"\u003e#1121\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReplace adopt-openj9 by semeru JDK distribution on GH (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1122\"\u003e#1122\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePort the site documentation from APT to Markdown (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1110\"\u003e#1110\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eVerify against Maven 4.0.0-rc-6 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1105\"\u003e#1105\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix tests on Jenkins (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1100\"\u003e#1100\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1074\"\u003e#1074\u003c/a\u003e) \u003ca href=\"https://github.com/potiuk\"\u003e\u003ccode\u003e@​potiuk\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRefactor compiler mojo to use dependency injection and improve string… (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1066\"\u003e#1066\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix ITs for Maven 3.10.x (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1061\"\u003e#1061\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate maven-surefire-plugin version to 3.x in the MCOMPILER-481 IT (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1035\"\u003e#1035\u003c/a\u003e) \u003ca href=\"https://github.com/cdouillard\"\u003e\u003ccode\u003e@​cdouillard\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📦 Dependency updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump plexusCompilerVersion from 2.16.2 to 2.17.0 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1112\"\u003e#1112\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.codehaus.plexus:plexus-java from 1.5.2 to 1.6.0 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1113\"\u003e#1113\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003euse latest Maven 4 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1045\"\u003e#1045\u003c/a\u003e) \u003ca href=\"https://github.com/hboutemy\"\u003e\u003ccode\u003e@​hboutemy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump apache/maven-gh-actions-shared/.github/workflows/release-drafter.yml from 4 to 5 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1083\"\u003e#1083\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump apache/maven-gh-actions-shared/.github/workflows/pr-automation.yml from 4 to 5 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1082\"\u003e#1082\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump apache/maven-gh-actions-shared/.github/workflows/maven-verify.yml from 4 to 5 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1084\"\u003e#1084\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-plugins from 48 to 49 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1068\"\u003e#1068\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-invoker-plugin from 3.9.1 to 3.10.1 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1047\"\u003e#1047\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-plugins from 47 to 48 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1050\"\u003e#1050\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump mavenVersion from 3.9.14 to 3.9.16 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1054\"\u003e#1054\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.ow2.asm:asm from 9.10 to 9.10.1 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1059\"\u003e#1059\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.ow2.asm:asm from 9.9.1 to 9.10 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1053\"\u003e#1053\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump mavenVersion from 3.9.13 to 3.9.14 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1041\"\u003e#1041\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump mavenVersion from 3.9.12 to 3.9.13 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1038\"\u003e#1038\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugin-testing:maven-plugin-testing-harness from 3.5.0 to 3.5.1 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1032\"\u003e#1032\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.15.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/e7bba6ed5f9c17003d5c5d1413144bb214177408\"\u003e\u003ccode\u003ee7bba6e\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release maven-compiler-plugin-3.16.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/c906809e0c0b2c79e8a03165cb942f152a911416\"\u003e\u003ccode\u003ec906809\u003c/code\u003e\u003c/a\u003e Avoid using deprecated method CompilerConfiguration.setCompilerVersion\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/ad74fee36865d7a1752c9b96ff9a9e702565fdb3\"\u003e\u003ccode\u003ead74fee\u003c/code\u003e\u003c/a\u003e Replace adopt-openj9 by semeru JDK distribution on GH\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/beb0eda2100e77d3f01bf4cc89edd5b721411f63\"\u003e\u003ccode\u003ebeb0eda\u003c/code\u003e\u003c/a\u003e Recompile when dependencies change (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/issues/1102\"\u003e#1102\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/a0b689e0e7f13d3a7dded7847a807fe6453e0358\"\u003e\u003ccode\u003ea0b689e\u003c/code\u003e\u003c/a\u003e [MCOMPILER-578] Track outputs across compiler executions (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/issues/1091\"\u003e#1091\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/2e8122841d9b10d2d83a90cc07530d7a09eebc47\"\u003e\u003ccode\u003e2e81228\u003c/code\u003e\u003c/a\u003e Fix incremental detection of empty sources, 3.x (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/issues/1075\"\u003e#1075\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/2132f5bf0cbfcde26301084c4833f1a9420f1baf\"\u003e\u003ccode\u003e2132f5b\u003c/code\u003e\u003c/a\u003e configure ATR project\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/5992b772033a7488767c4b3aa806f080eba96593\"\u003e\u003ccode\u003e5992b77\u003c/code\u003e\u003c/a\u003e Build fails when annotation processor list is empty (but present) (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/issues/1077\"\u003e#1077\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/acccef703e5491c29c6dd9e8381677d3e7927589\"\u003e\u003ccode\u003eacccef7\u003c/code\u003e\u003c/a\u003e Bump plexusCompilerVersion from 2.16.2 to 2.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/72bc4454dfdcd1c3551137e5b27560f88b4480ae\"\u003e\u003ccode\u003e72bc445\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-java from 1.5.2 to 1.6.0\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/apache/maven-compiler-plugin/compare/maven-compiler-plugin-3.13.0...maven-compiler-plugin-3.16.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.maven.plugins:maven-surefire-plugin` from 3.2.5 to 3.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/apache/maven-surefire/releases\"\u003eorg.apache.maven.plugins:maven-surefire-plugin's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.6.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003ePlease refer to the main page for what's new \u003ca href=\"https://maven.apache.org/surefire/\"\u003ehttps://maven.apache.org/surefire/\u003c/a\u003e\nAnd the migration page \u003ca href=\"https://maven.apache.org/surefire/maven-surefire-plugin/whats-new-3-6-0.html\"\u003ehttps://maven.apache.org/surefire/maven-surefire-plugin/whats-new-3-6-0.html\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e🚀 New features and improvements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3303\"\u003e#3303\u003c/a\u003e: distinguish JUnit 6 ParameterizedClass invocations (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3432\"\u003e#3432\u003c/a\u003e) \u003ca href=\"https://github.com/AzazelSensei\"\u003e\u003ccode\u003e@​AzazelSensei\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-1639\"\u003e[SUREFIRE-1639]\u003c/a\u003e - Add ability to configure JUnit 5 TestExecutionListener (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3438\"\u003e#3438\u003c/a\u003e) \u003ca href=\"https://github.com/pan3793\"\u003e\u003ccode\u003e@​pan3793\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIssue \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/838\"\u003e#838\u003c/a\u003e Implement extension point to run diagnosis tools when forked JVM times out (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3372\"\u003e#3372\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-2148\"\u003e[SUREFIRE-2148]\u003c/a\u003e - Verify recovered BeforeAll does not fail build (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3419\"\u003e#3419\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-823\"\u003e[SUREFIRE-823]\u003c/a\u003e - Decouple -DskipTests from Failsafe plugin (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3371\"\u003e#3371\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse StackWalker in StackTraceProvider when available (Java 9+) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3374\"\u003e#3374\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Issue-3380] Send sourceQualifiedName to forked clients (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3380\"\u003e#3380\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3381\"\u003e#3381\u003c/a\u003e) \u003ca href=\"https://github.com/fabriciorby\"\u003e\u003ccode\u003e@​fabriciorby\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-523\"\u003e[SUREFIRE-523]\u003c/a\u003e - Link all reported tests to source XRef (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3445\"\u003e#3445\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-3446\"\u003e[SUREFIRE-3446]\u003c/a\u003e - Fix direct selection of JUnit Jupiter \u003ca href=\"https://github.com/Nested\"\u003e\u003ccode\u003e@​Nested\u003c/code\u003e\u003c/a\u003e classes (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3447\"\u003e#3447\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDiscover tests in a fork when a toolchain JDK is used (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3444\"\u003e#3444\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[SUREFIRE-2239, SUREFIRE-2241, SUREFIRE-2260, SUREFIRE-2274, SUREFIRE-2300] Preserve JUnit Platform test identity across reruns (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3418\"\u003e#3418\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3428\"\u003e#3428\u003c/a\u003e: resolve parents via TestPlan.getParent for pre-1.8 platforms (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3429\"\u003e#3429\u003c/a\u003e) \u003ca href=\"https://github.com/kalayciburak\"\u003e\u003ccode\u003e@​kalayciburak\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-859\"\u003e[SUREFIRE-859]\u003c/a\u003e - Make random test order reproducible (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3421\"\u003e#3421\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[SUREFIRE-862, SUREFIRE-3178] Handle missing Failsafe summary files (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3417\"\u003e#3417\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: report AfterAll/AfterClass exceptions as errors again (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3412\"\u003e#3412\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3413\"\u003e#3413\u003c/a\u003e) \u003ca href=\"https://github.com/arimu1\"\u003e\u003ccode\u003e@​arimu1\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixes \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3264\"\u003e#3264\u003c/a\u003e : tests inside \u003ca href=\"https://github.com/Suite\"\u003e\u003ccode\u003e@​Suite\u003c/code\u003e\u003c/a\u003e incorrectly classified as flakes (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3342\"\u003e#3342\u003c/a\u003e) \u003ca href=\"https://github.com/mirkoalicastro\"\u003e\u003ccode\u003e@​mirkoalicastro\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix Windows flake in CommandChannelDecoderTest (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3400\"\u003e#3400\u003c/a\u003e) \u003ca href=\"https://github.com/ascheman\"\u003e\u003ccode\u003e@​ascheman\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix reportNameSuffix in XML testcase classname (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3379\"\u003e#3379\u003c/a\u003e) \u003ca href=\"https://github.com/goutamadwant\"\u003e\u003ccode\u003e@​goutamadwant\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix: resolve relative classpath elements against the fork's working dir (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3333\"\u003e#3333\u003c/a\u003e) \u003ca href=\"https://github.com/cwegener-79\"\u003e\u003ccode\u003e@​cwegener-79\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📝 Documentation updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMagnify the home, well at least have something rather than nothing :) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3377\"\u003e#3377\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRestore the straight quotes the FAQ conversion turned typographic (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3425\"\u003e#3425\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRestore the table borders lost in the APT conversion (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3424\"\u003e#3424\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eConvert the FAQ from FML to Markdown (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3423\"\u003e#3423\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eConvert the remaining site documentation from APT to Markdown (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3422\"\u003e#3422\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ejavadoc: clarify statelessTestsetReporter, consoleOutputReporter, (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3410\"\u003e#3410\u003c/a\u003e) \u003ca href=\"https://github.com/joshinii\"\u003e\u003ccode\u003e@​joshinii\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3387\"\u003e#3387\u003c/a\u003e) \u003ca href=\"https://github.com/potiuk\"\u003e\u003ccode\u003e@​potiuk\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate documentation we support Junit 6 as well :) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3370\"\u003e#3370\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e👻 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eStop dependabot from updating test fixtures (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3440\"\u003e#3440\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMigrate legacy plugin Javadoc annotations (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3416\"\u003e#3416\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse the resolver's own HTTP transport in the report plugin tests (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3414\"\u003e#3414\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin maven-jar-plugin 3.5.1 in modular IT fixtures (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3398\"\u003e#3398\u003c/a\u003e) \u003ca href=\"https://github.com/ascheman\"\u003e\u003ccode\u003e@​ascheman\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3387\"\u003e#3387\u003c/a\u003e) \u003ca href=\"https://github.com/potiuk\"\u003e\u003ccode\u003e@​potiuk\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/0ff622b160253f362511a72d29a1f8067631f9d3\"\u003e\u003ccode\u003e0ff622b\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release surefire-3.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/bb3932a10a9706df70cf8095e2402348b7a64f0b\"\u003e\u003ccode\u003ebb3932a\u003c/code\u003e\u003c/a\u003e Let's go for 3.6.0 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/3002a1648cc8092dbd80492aa00509c825fd58e7\"\u003e\u003ccode\u003e3002a16\u003c/code\u003e\u003c/a\u003e Bump mavenVersion from 3.9.14 to 3.9.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/61a531d5981b0e70f8e88a329150f75501bb73e4\"\u003e\u003ccode\u003e61a531d\u003c/code\u003e\u003c/a\u003e Bump Maven parent version from 47 to 49 (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3449\"\u003e#3449\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/e52ead4cf5075f519578d0053c1ff878dff238f5\"\u003e\u003ccode\u003ee52ead4\u003c/code\u003e\u003c/a\u003e [SUREFIRE-523] Link all reported tests to source XRef (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3445\"\u003e#3445\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/45102fa9f2dfc5bc3d2909798e67358ae33e2d49\"\u003e\u003ccode\u003e45102fa\u003c/code\u003e\u003c/a\u003e [SUREFIRE-3446] Fix direct selection of JUnit Jupiter \u003ca href=\"https://github.com/Nested\"\u003e\u003ccode\u003e@​Nested\u003c/code\u003e\u003c/a\u003e classes (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3447\"\u003e#3447\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/b2e1f70b24df2d8a6cf1583ca955311184e68022\"\u003e\u003ccode\u003eb2e1f70\u003c/code\u003e\u003c/a\u003e Fix \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3303\"\u003e#3303\u003c/a\u003e: distinguish JUnit 6 ParameterizedClass invocations (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3432\"\u003e#3432\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/c051938593a29d654b3c1c20d454b9062c3fa3f4\"\u003e\u003ccode\u003ec051938\u003c/code\u003e\u003c/a\u003e Discover tests in a fork when a toolchain JDK is used (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3444\"\u003e#3444\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/db75df85a76abf35346f559fe7f7f020cf6435b6\"\u003e\u003ccode\u003edb75df8\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-java from 1.5.2 to 1.6.0 (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3441\"\u003e#3441\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/77f2759d895a4460f917bdaaff7a025454afebe4\"\u003e\u003ccode\u003e77f2759\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-interpolation from 1.29 to 1.30.0\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/apache/maven-surefire/compare/surefire-3.2.5...surefire-3.6.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.maven.plugins:maven-jar-plugin` from 3.4.1 to 3.5.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/apache/maven-jar-plugin/releases\"\u003eorg.apache.maven.plugins:maven-jar-plugin's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.5.1\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e📝 Documentation updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/550\"\u003e#550\u003c/a\u003e) \u003ca href=\"https://github.com/potiuk\"\u003e\u003ccode\u003e@​potiuk\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e👻 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/550\"\u003e#550\u003c/a\u003e) \u003ca href=\"https://github.com/potiuk\"\u003e\u003ccode\u003e@​potiuk\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse plugin version properties (3.x) (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/535\"\u003e#535\u003c/a\u003e) \u003ca href=\"https://github.com/Bukama\"\u003e\u003ccode\u003e@​Bukama\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📦 Dependency updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-plugins from 48 to 49 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/547\"\u003e#547\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.codehaus.plexus:plexus-archiver from 4.11.0 to 4.12.0 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/538\"\u003e#538\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump mavenVersion from 3.9.15 to 3.9.16 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/536\"\u003e#536\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-plugins from 47 to 48 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/534\"\u003e#534\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump commons-io:commons-io from 2.21.0 to 2.22.0 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/529\"\u003e#529\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump mavenVersion from 3.9.14 to 3.9.15 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/528\"\u003e#528\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump mavenVersion from 3.9.12 to 3.9.14 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/526\"\u003e#526\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugin-testing:maven-plugin-testing-harness from 3.5.0 to 3.5.1 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/523\"\u003e#523\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-plugins from 46 to 47 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/519\"\u003e#519\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.codehaus.plexus:plexus-archiver from 4.10.4 to 4.11.0 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/516\"\u003e#516\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugin-testing:maven-plugin-testing-harness from 3.4.0 to 3.5.0 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/517\"\u003e#517\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-plugins from 45 to 46 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/514\"\u003e#514\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven:maven-archiver from 3.6.5 to 3.6.6 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/511\"\u003e#511\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump mavenVersion from 3.9.11 to 3.9.12 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/509\"\u003e#509\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e3.5.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e🚀 New features and improvements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAdd new \u0026quot;attach\u0026quot; configuration parameter (3.x port of \u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/issues/482\"\u003e#482\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/483\"\u003e#483\u003c/a\u003e) \u003ca href=\"https://github.com/hgschmie\"\u003e\u003ccode\u003e@​hgschmie\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eadd Java-Version to MANIFEST.MF (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/465\"\u003e#465\u003c/a\u003e) \u003ca href=\"https://github.com/hboutemy\"\u003e\u003ccode\u003e@​hboutemy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix detecting java version for toolchains and JDK 1.8 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/500\"\u003e#500\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIgnore stderr when parsing javac version from toolchain (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/471\"\u003e#471\u003c/a\u003e) \u003ca href=\"https://github.com/jaredstehler\"\u003e\u003ccode\u003e@​jaredstehler\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e👻 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate site descriptor to 2.0.0 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/501\"\u003e#501\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003echore: remove junit3 references (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/494\"\u003e#494\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMigrate component injection to JSR-330 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/492\"\u003e#492\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd PR Automation to 3.x (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/132\"\u003e#132\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImprove release-drafter configuration (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/128\"\u003e#128\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix for Maven 4.0.0-rc-3 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/130\"\u003e#130\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/MNGSITE-529\"\u003e[MNGSITE-529]\u003c/a\u003e - Rename \u0026quot;Goals\u0026quot; to \u0026quot;Plugin Documentation\u0026quot; (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/pull/119\"\u003e#119\u003c/a\u003e) \u003ca href=\"https://github.com/Bukama\"\u003e\u003ccode\u003e@​Bukama\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-jar-plugin/commit/b0cd63d0ad544aa552f06e4492faf984bf2c85c1\"\u003e\u003ccode\u003eb0cd63d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release maven-jar-plugin-3.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-jar-plugin/commit/5318a4feaf529d6fa22c4622fff2d54fefe7f7dd\"\u003e\u003ccode\u003e5318a4f\u003c/code\u003e\u003c/a\u003e Add AGENTS.md + SECURITY.md security-model pointer for scanner discoverability\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-jar-plugin/commit/8e0b9bb307fc29b8d267f18eca9d47be0a7f16e0\"\u003e\u003ccode\u003e8e0b9bb\u003c/code\u003e\u003c/a\u003e Bump org.apache.maven.plugins:maven-plugins from 48 to 49 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/issues/547\"\u003e#547\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-jar-plugin/commit/d5a438b6add9a9115f5a2c9b27db67e0d962bb74\"\u003e\u003ccode\u003ed5a438b\u003c/code\u003e\u003c/a\u003e Fix javadoc\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-jar-plugin/commit/774fac9215d92bfac67ece082872b00475580b21\"\u003e\u003ccode\u003e774fac9\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-archiver from 4.11.0 to 4.12.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-jar-plugin/commit/b71f40368edc878b3dcaa9840d950bd7d297d4c4\"\u003e\u003ccode\u003eb71f403\u003c/code\u003e\u003c/a\u003e Bump mavenVersion from 3.9.15 to 3.9.16 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/issues/536\"\u003e#536\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-jar-plugin/commit/9f2a001a00fcbb0408219a11f62b48c4dfde78d3\"\u003e\u003ccode\u003e9f2a001\u003c/code\u003e\u003c/a\u003e Use plugin version properties (3.x) (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/issues/535\"\u003e#535\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-jar-plugin/commit/68a978f952ba510f7378fd287c5172dc560079e3\"\u003e\u003ccode\u003e68a978f\u003c/code\u003e\u003c/a\u003e Bump org.apache.maven.plugins:maven-plugins from 47 to 48 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/issues/534\"\u003e#534\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-jar-plugin/commit/e1058217f657691a3e50b0c7e0620fd13c8e83c3\"\u003e\u003ccode\u003ee105821\u003c/code\u003e\u003c/a\u003e Bump commons-io:commons-io from 2.21.0 to 2.22.0 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/issues/529\"\u003e#529\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-jar-plugin/commit/953dc1abbb527b8128657f2aeadfdca0557d974d\"\u003e\u003ccode\u003e953dc1a\u003c/code\u003e\u003c/a\u003e Bump mavenVersion from 3.9.14 to 3.9.15 (\u003ca href=\"https://redirect.github.com/apache/maven-jar-plugin/issues/528\"\u003e#528\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/apache/maven-jar-plugin/compare/maven-jar-plugin-3.4.1...maven-jar-plugin-3.5.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.jacoco:jacoco-maven-plugin` from 0.8.12 to 0.8.15\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jacoco/jacoco/releases\"\u003eorg.jacoco:jacoco-maven-plugin's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e0.8.15\u003c/h2\u003e\n\u003ch2\u003eNew Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eJaCoCo now officially supports Java 26 (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2076\"\u003e#2076\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eExperimental support for Java 27 class files (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2004\"\u003e#2004\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCompatibility methods generated by Kotlin compiler for functions defined in interfaces are filtered out during generation of report (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1905\"\u003e#1905\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCompatibility methods generated by Kotlin compiler for exposed boxed inline value classes (JvmExposeBoxed annotation) are filtered out during generation of report (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1944\"\u003e#1944\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eMethods generated by the Kotlin compiler for functions with JvmStatic annotation are filtered out during generation of report (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2097\"\u003e#2097\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImproved filtering of bytecode generated by Kotlin compiler for when expressions and statements with kotlin.String subject where first branch condition contains string with largest hash (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2098\"\u003e#2098\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePart of bytecode that javac versions from 24 to 26 generate for switch statements and expressions with selector expression of type java.lang.String inside lambdas is filtered out during generation of report (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2023\"\u003e#2023\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImproved performance of Kotlin files analysis by parsing SMAPs only once per class (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2114\"\u003e#2114\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFor better performance agent output methods tcpclient and tcpserver use BufferedOutputStream to write execution data to socket. Maven plugin, Ant tasks, CLI, API usage examples, and ExecDumpClient API use BufferedInputStream to read execution data from socket. Third-party integrations should do the same to benefit from this change in agent (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2089\"\u003e#2089\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eFixed bugs\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed processing of Kotlin SMAP in synthetic classes (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1985\"\u003e#1985\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eMultiple JaCoCo runtimes within one JVM writing to the same output file should not cause data corruption when running on JDK versions from 6 to 10 affected by \u003ca href=\"https://bugs.openjdk.org/browse/JDK-8166253\"\u003eJDK-8166253\u003c/a\u003e (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2065\"\u003e#2065\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2074\"\u003e#2074\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFor better performance agent writes to output file via BufferedOutputStream, this fixes regression introduced in version 0.6.2 (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2073\"\u003e#2073\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed NullPointerException when JaCoCo agent is loaded by non system class loader, for example when loaded by JBoss Modules (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1651\"\u003e#1651\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNon-functional Changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eJaCoCo now depends on ASM 9.10.1 (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2134\"\u003e#2134\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.8.14\u003c/h2\u003e\n\u003ch2\u003eNew Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eJaCoCo now officially supports Java 25 (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1950\"\u003e#1950\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eExperimental support for Java 26 class files (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1807\"\u003e#1870\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eBranches added by the Kotlin compiler for default argument number 33 or higher are filtered out during generation of report (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1655\"\u003e#1655\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePart of bytecode generated by the Kotlin compiler for elvis operator that follows safe call operator is filtered out during generation of report (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1814\"\u003e#1814\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1954\"\u003e#1954\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePart of bytecode generated by the Kotlin compiler for more cases of chained safe call operators is filtered out during generation of report (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1956\"\u003e#1956\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePart of bytecode generated by the Kotlin compiler for invocations of suspendCoroutineUninterceptedOrReturn intrinsic is filtered out during generation of report (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1929\"\u003e#1929\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePart of bytecode generated by the Kotlin compiler for suspending lambdas with parameters is filtered out during generation of report (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1945\"\u003e#1945\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePart of bytecode generated by the Kotlin compiler for suspending functions and lambdas with suspension points that return inline value class is filtered out during generation of report (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1871\"\u003e#1871\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePart of bytecode generated by the Kotlin Compose compiler plugin for pausable composition is filtered out during generation of report (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1911\"\u003e#1911\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eMethods generated by the Kotlin serialization compiler plugin are filtered out (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1885\"\u003e#1885\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1970\"\u003e#1970\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1971\"\u003e#1971\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eFixed bugs\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed handling of implicit else clause of when with String subject in Kotlin (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1813\"\u003e#1813\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1940\"\u003e#1940\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed handling of implicit default clause of switch by String in Java when compiled by ECJ (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1813\"\u003e#1813\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1940\"\u003e#1940\u003c/a\u003e).\nFixed handling of exceptions in chains of safe call operators in Kotlin (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1819\"\u003e#1819\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNon-functional Changes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eJaCoCo now depends on ASM 9.9 (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1965\"\u003e#1965\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e0.8.13\u003c/h2\u003e\n\u003ch2\u003eNew Features\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eJaCoCo now officially supports Java 23 and Java 24 (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1757\"\u003e#1757\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1631\"\u003e#1631\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1867\"\u003e#1867\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eExperimental support for Java 25 class files (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1807\"\u003e#1807\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCalculation of line coverage for Kotlin \u003ccode\u003einline\u003c/code\u003e functions (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1670\"\u003e#1670\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCalculation of line coverage for Kotlin \u003ccode\u003einline\u003c/code\u003e functions with \u003ccode\u003ereified\u003c/code\u003e type parameter (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1670\"\u003e#1670\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1700\"\u003e#1700\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eCalculation of coverage for Kotlin \u003ccode\u003eJvmSynthetic\u003c/code\u003e functions (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1700\"\u003e#1700\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003ePart of bytecode generated by the Kotlin Compose compiler plugin is filtered out during generation of report (GitHub \u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1616\"\u003e#1616\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jacoco/jacoco/commit/6c5260a192eaa535e4a519771d530781cbac9136\"\u003e\u003ccode\u003e6c5260a\u003c/code\u003e\u003c/a\u003e Prepare release v0.8.15\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jacoco/jacoco/commit/5c05141431a7f064a804a923fbae11271241f116\"\u003e\u003ccode\u003e5c05141\u003c/code\u003e\u003c/a\u003e Transfer of execution data through socket should use buffered stream (\u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2089\"\u003e#2089\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jacoco/jacoco/commit/ab5efa9d63c06899b2aec1d4a6099fc856132a22\"\u003e\u003ccode\u003eab5efa9\u003c/code\u003e\u003c/a\u003e Remove from Azure Pipelines all builds except with JDK 5 and JDK EA (\u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2148\"\u003e#2148\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jacoco/jacoco/commit/5f6ea38f20ff4583deb4ab976571c853231f97c2\"\u003e\u003ccode\u003e5f6ea38\u003c/code\u003e\u003c/a\u003e Use Windows 2025 image in GitHub Actions (\u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2130\"\u003e#2130\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jacoco/jacoco/commit/35a8af2cfc168ce51f2a3ea2d55d65f31e61c513\"\u003e\u003ccode\u003e35a8af2\u003c/code\u003e\u003c/a\u003e Use Renovate instead of Dependabot for updates of ASM (\u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2137\"\u003e#2137\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jacoco/jacoco/commit/85b8ddf530821f75b3b26f5f96d03252286b3ad6\"\u003e\u003ccode\u003e85b8ddf\u003c/code\u003e\u003c/a\u003e Upgrade ASM to 9.10.1 (\u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2134\"\u003e#2134\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jacoco/jacoco/commit/2988647ac37c3ad35a77b51d01b10a916b85627b\"\u003e\u003ccode\u003e2988647\u003c/code\u003e\u003c/a\u003e AgentModule should use ClassLoader of agent instead of SystemClassLoader (\u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1651\"\u003e#1651\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jacoco/jacoco/commit/75a4e31fed32f180fbe4593ad91ec5c176c0535b\"\u003e\u003ccode\u003e75a4e31\u003c/code\u003e\u003c/a\u003e Add filter for Kotlin \u003ccode\u003e@JvmExposeBoxed\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/1944\"\u003e#1944\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jacoco/jacoco/commit/691fa1d6a0dffa91f45daf0714f28bfdaa367fc0\"\u003e\u003ccode\u003e691fa1d\u003c/code\u003e\u003c/a\u003e Use Renovate instead of Dependabot for updates of GitHub Actions (\u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2132\"\u003e#2132\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jacoco/jacoco/commit/3e18f17207bca0203b726ace460aa6be8d0f3dd4\"\u003e\u003ccode\u003e3e18f17\u003c/code\u003e\u003c/a\u003e Require at least JDK 21 for build (\u003ca href=\"https://redirect.github.com/jacoco/jacoco/issues/2128\"\u003e#2128\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/jacoco/jacoco/compare/v0.8.12...v0.8.15\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/ID-Partners/idp-auth-peps/pull/6","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/ID-Partners%2Fidp-auth-peps/issues/6","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/6/packages"}},{"old_version":"2.22.2","new_version":"2.22.3","update_type":"patch","path":"/services/transaction-service","pr_created_at":"2026-09-25T09:55:43.000Z","version_change":"2.22.2 → 2.22.3","issue":{"uuid":"5581208041","node_id":"PR_kwDOTxnlA88AAAABFF2mtw","number":36,"state":"open","title":"build(deps): bump com.fasterxml.jackson.core:jackson-databind from 2.22.2 to 2.22.3 in /services/transaction-service","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-25T09:55:43.000Z","updated_at":"2026-09-25T09:57:30.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps)","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":"/services/transaction-service","ecosystem":"maven"},"body":"Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.22.2 to 2.22.3.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/4385c5f7d51426f66fb24c3777308acc8ae7ea6c\"\u003e\u003ccode\u003e4385c5f\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ccb4fd0158cd20800f6014496dccf7332e5b18ce\"\u003e\u003ccode\u003eccb4fd0\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/2958412f1817a0ad95c34066b7eb85781dd2d4f1\"\u003e\u003ccode\u003e2958412\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1215b94c2f7a8c4ce3863afbc38275a19c682a54\"\u003e\u003ccode\u003e1215b94\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1f0df621449e5de7dd13a1538e0343f65f0e6bb3\"\u003e\u003ccode\u003e1f0df62\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/13a9ff4c4ef982cda23b99fea89d2a4e87af9019\"\u003e\u003ccode\u003e13a9ff4\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/d168f9679ad575cdc2df8d53a8474ec481c7b5a7\"\u003e\u003ccode\u003ed168f96\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/eaf5c76b8e0a538729a1bf922061abf73b13f89b\"\u003e\u003ccode\u003eeaf5c76\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/e05ef4cbb4d534a82948f8ba84350e55493bc72e\"\u003e\u003ccode\u003ee05ef4c\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/f6d4000c1eb6d34e2ae24685a9790b1e833d4bcb\"\u003e\u003ccode\u003ef6d4000\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.22.2...jackson-databind-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.22.2\u0026new-version=2.22.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/wep1980/wepdev-financas/pull/36","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/wep1980%2Fwepdev-financas/issues/36","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/36/packages"}},{"old_version":"2.22.2","new_version":"2.22.3","update_type":"patch","path":"the jackson group","pr_created_at":"2026-09-25T00:22:23.000Z","version_change":"2.22.2 → 2.22.3","issue":{"uuid":"5576282180","node_id":"PR_kwDOARYPw88AAAABFB65PQ","number":736,"state":"closed","title":"Bump com.fasterxml.jackson.core:jackson-databind from 2.22.2 to 2.22.3 in the jackson group","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-25T00:27:29.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-25T00:22:23.000Z","updated_at":"2026-09-25T00:27:30.000Z","time_to_close":306,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.22.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":"the jackson group","ecosystem":"maven"},"body":"Bumps the jackson group with 1 update: [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind).\n\nUpdates `com.fasterxml.jackson.core:jackson-databind` from 2.22.2 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/4385c5f7d51426f66fb24c3777308acc8ae7ea6c\"\u003e\u003ccode\u003e4385c5f\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ccb4fd0158cd20800f6014496dccf7332e5b18ce\"\u003e\u003ccode\u003eccb4fd0\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/2958412f1817a0ad95c34066b7eb85781dd2d4f1\"\u003e\u003ccode\u003e2958412\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1215b94c2f7a8c4ce3863afbc38275a19c682a54\"\u003e\u003ccode\u003e1215b94\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1f0df621449e5de7dd13a1538e0343f65f0e6bb3\"\u003e\u003ccode\u003e1f0df62\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/13a9ff4c4ef982cda23b99fea89d2a4e87af9019\"\u003e\u003ccode\u003e13a9ff4\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/d168f9679ad575cdc2df8d53a8474ec481c7b5a7\"\u003e\u003ccode\u003ed168f96\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/eaf5c76b8e0a538729a1bf922061abf73b13f89b\"\u003e\u003ccode\u003eeaf5c76\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/e05ef4cbb4d534a82948f8ba84350e55493bc72e\"\u003e\u003ccode\u003ee05ef4c\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/f6d4000c1eb6d34e2ae24685a9790b1e833d4bcb\"\u003e\u003ccode\u003ef6d4000\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.22.2...jackson-databind-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.22.2\u0026new-version=2.22.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/s4u/pgpverify-maven-plugin/pull/736","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/s4u%2Fpgpverify-maven-plugin/issues/736","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/736/packages"}},{"old_version":"2.18.2","new_version":"2.22.2","update_type":"minor","path":null,"pr_created_at":"2026-09-23T21:50:07.000Z","version_change":"2.18.2 → 2.22.2","issue":{"uuid":"5559967044","node_id":"PR_kwDOUTDGgM8AAAABE1DgVA","number":22,"state":"closed","title":"Bump the minor-and-patch group with 3 updates","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":2,"pull_request":true,"closed_at":"2026-09-30T03:54:18.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-23T21:50:07.000Z","updated_at":"2026-09-30T03:54:20.000Z","time_to_close":540251,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","group_name":"minor-and-patch","update_count":3,"packages":[{"name":"org.jetbrains.kotlinx:kotlinx-serialization-json","old_version":"1.7.3","new_version":"1.11.0","repository_url":"https://github.com/Kotlin/kotlinx.serialization"},{"name":"org.jetbrains.kotlinx:kotlinx-coroutines-core","old_version":"1.9.0","new_version":"1.11.0","repository_url":"https://github.com/Kotlin/kotlinx.coroutines"},{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.18.2","new_version":"2.22.2","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":null,"ecosystem":"maven"},"body":"Bumps the minor-and-patch group with 3 updates: [org.jetbrains.kotlinx:kotlinx-serialization-json](https://github.com/Kotlin/kotlinx.serialization), [org.jetbrains.kotlinx:kotlinx-coroutines-core](https://github.com/Kotlin/kotlinx.coroutines) and [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind).\n\nUpdates `org.jetbrains.kotlinx:kotlinx-serialization-json` from 1.7.3 to 1.11.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/releases\"\u003eorg.jetbrains.kotlinx:kotlinx-serialization-json's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.11.0\u003c/h2\u003e\n\u003cp\u003eThis release is based on Kotlin 2.3.20 and provides a new Json exceptions API and some bugfixes and improvements.\u003c/p\u003e\n\u003ch2\u003eExpose Json exceptions structure\u003c/h2\u003e\n\u003cp\u003eTo make working with exceptions easier and providing proper error codes in e.g., REST APIs,\nclasses \u003ccode\u003eJsonException\u003c/code\u003e, \u003ccode\u003eJsonDecodingException\u003c/code\u003e, and \u003ccode\u003eJsonEncodingException\u003c/code\u003e are now public.\nThey have relevant public properties, such as \u003ccode\u003eshortMessage\u003c/code\u003e, \u003ccode\u003epath\u003c/code\u003e, \u003ccode\u003eoffset\u003c/code\u003e, and others.\nThis API is currently experimental, and we're going to improve it further in the subsequent releases.\nSee the linked issues for the details: \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/1930\"\u003e#1930\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/1877\"\u003e#1877\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eAbility to hide user input from exception messages for security/privacy reasons.\u003c/h2\u003e\n\u003cp\u003eHistorically, exception messages in kotlinx.serialization often included the input Json itself for debuggability reason.\nSuch behavior may pose additional challenges for logging, analytics, and other systems, since\na system is not always allowed to store user data due to privacy/security reasons, which imposes additional sanitation logic.\nTo address this issue, a new property \u003ccode\u003eexceptionsWithDebugInfo\u003c/code\u003e is added to \u003ccode\u003eJsonConfiguration\u003c/code\u003e.\nDisable it to hide user input from exception messages.\nIMPORTANT: This behavior will be enabled by default when this property becomes stable.\nSee \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/2590\"\u003e#2590\u003c/a\u003e for more details.\u003c/p\u003e\n\u003ch2\u003eBugfixes and improvements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCBOR: Relax value range check when decoding numbers (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3167\"\u003e#3167\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUse a specialized writeDecimalLong method for IO stream integrations in Json (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3152\"\u003e#3152\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.10.0\u003c/h2\u003e\n\u003cp\u003eThis release is based on Kotlin 2.3.0 and contains all of the changes from 1.10.0-RC.\nThe only additional change is a fix for ProtoBuf packing of Kotlin unsigned types (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3079\"\u003e#3079\u003c/a\u003e).\nBig thanks to \u003ca href=\"https://github.com/KosmX\"\u003eKosmX\u003c/a\u003e for contributing the fix.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eFor your convenience, the changelog for 1.10.0-RC is duplicated below:\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003eStabilization of APIs\u003c/h2\u003e\n\u003cp\u003ekotlinx-serialization 1.10 and subsequent releases will be focused on stabilization of existing APIs.\nThe following APIs and configuration options are no longer experimental because they're widely used without any known major issues:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eJson\u003c/code\u003e configuration options: \u003ccode\u003edecodeEnumsCaseInsensitive\u003c/code\u003e, \u003ccode\u003eallowTrailingComma\u003c/code\u003e, \u003ccode\u003eallowComments\u003c/code\u003e, and \u003ccode\u003eprettyPrintIndent\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3100\"\u003e#3100\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@EncodeDefault\u003c/code\u003e annotation and its modes. (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3106\"\u003e#3106\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eJsonUnquotedLiteral\u003c/code\u003e constructor function (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/2900\"\u003e#2900\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eJsonPrimitive\u003c/code\u003e constructor function overloads that accept unsigned types. (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3117\"\u003e#3117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eJSON DSL functions on \u003ccode\u003eJsonElement\u003c/code\u003e with \u003ccode\u003eNothing?\u003c/code\u003e overloads. (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3117\"\u003e#3117\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eReadiness for return value checker\u003c/h2\u003e\n\u003cp\u003eKotlin 2.3.0 \u003ca href=\"https://kotlinlang.org/docs/whatsnew23.html#unused-return-value-checker\"\u003eintroduces a new feature\u003c/a\u003e aimed at helping you to catch bugs related to the accidentally ignored return value of the function.\nkotlinx-serialization 1.10.0-RC code is fully marked for this feature, meaning that you can get warnings for unused function calls like \u003ccode\u003eJson.encodeToString(...)\u003c/code\u003e. To get the warnings, the feature has to be enabled in your project as \u003ca href=\"https://kotlinlang.org/docs/unused-return-value-checker.html#configure-the-unused-return-value-checker\"\u003edescribed here\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003ePolymorphism improvements\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/blob/master/CHANGELOG.md\"\u003eorg.jetbrains.kotlinx:kotlinx-serialization-json's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch1\u003e1.11.0 / 2026-04-10\u003c/h1\u003e\n\u003cp\u003eThis release is based on Kotlin 2.3.20 and provides new Json exceptions API and some bugfixes and improvements.\u003c/p\u003e\n\u003ch2\u003eExpose Json exceptions structure\u003c/h2\u003e\n\u003cp\u003eTo make working with exceptions easier and providing proper error codes in e.g., REST APIs,\nclasses \u003ccode\u003eJsonException\u003c/code\u003e, \u003ccode\u003eJsonDecodingException\u003c/code\u003e, and \u003ccode\u003eJsonEncodingException\u003c/code\u003e are now public.\nThey have relevant public properties, such as \u003ccode\u003eshortMessage\u003c/code\u003e, \u003ccode\u003epath\u003c/code\u003e, \u003ccode\u003eoffset\u003c/code\u003e, and others.\nThis API is currently experimental, and we're going to improve it further in the subsequent releases.\nSee the linked issues for the details: \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/1930\"\u003e#1930\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/1877\"\u003e#1877\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eAbility to hide user input from exception messages for security/privacy reasons.\u003c/h2\u003e\n\u003cp\u003eHistorically, exception messages in kotlinx.serialization often included the input Json itself for debuggability reason.\nSuch behavior may pose additional challenges for logging, analytics, and other systems, since\na system is not always allowed to store user data due to privacy/security reasons, which imposes additional sanitation logic.\nTo address this issue, a new property \u003ccode\u003eexceptionsWithDebugInfo\u003c/code\u003e is added to \u003ccode\u003eJsonConfiguration\u003c/code\u003e.\nDisable it to hide user input from exception messages.\nIMPORTANT: This behavior will be enabled by default when this property becomes stable.\nSee \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/2590\"\u003e#2590\u003c/a\u003e for more details.\u003c/p\u003e\n\u003ch2\u003eBugfixes and improvements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eCBOR: Relax value range check when decoding numbers (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3167\"\u003e#3167\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUse a specialized writeDecimalLong method for IO stream integrations in Json (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3152\"\u003e#3152\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003e1.10.0 / 2026-01-21\u003c/h1\u003e\n\u003cp\u003eThis release is based on Kotlin 2.3.0 and contains all of the changes from 1.10.0-RC.\nThe only additional change is a fix for ProtoBuf packing of Kotlin unsigned types (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3079\"\u003e#3079\u003c/a\u003e).\nBig thanks to \u003ca href=\"https://github.com/KosmX\"\u003eKosmX\u003c/a\u003e for contributing the fix.\u003c/p\u003e\n\u003cblockquote\u003e\n\u003cp\u003eFor your convenience, the changelog for 1.10.0-RC is duplicated below:\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003ch2\u003eStabilization of APIs\u003c/h2\u003e\n\u003cp\u003ekotlinx-serialization 1.10 and subsequent releases will be focused on stabilization of existing APIs.\nThe following APIs and configuration options are no longer experimental because they're widely used without any known major issues:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eJson\u003c/code\u003e configuration options: \u003ccode\u003edecodeEnumsCaseInsensitive\u003c/code\u003e, \u003ccode\u003eallowTrailingComma\u003c/code\u003e, \u003ccode\u003eallowComments\u003c/code\u003e, and \u003ccode\u003eprettyPrintIndent\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3100\"\u003e#3100\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e@EncodeDefault\u003c/code\u003e annotation and its modes. (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3106\"\u003e#3106\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eJsonUnquotedLiteral\u003c/code\u003e constructor function (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/2900\"\u003e#2900\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eJsonPrimitive\u003c/code\u003e constructor function overloads that accept unsigned types. (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3117\"\u003e#3117\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eJSON DSL functions on \u003ccode\u003eJsonElement\u003c/code\u003e with \u003ccode\u003eNothing?\u003c/code\u003e overloads. (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3117\"\u003e#3117\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eReadiness for return value checker\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/commit/6956af2e6073347c7832c3c5b374fa3b5a345956\"\u003e\u003ccode\u003e6956af2\u003c/code\u003e\u003c/a\u003e Prepare 1.11 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/commit/390d84c68a19cbf7fa453dec22a333648bde49b4\"\u003e\u003ccode\u003e390d84c\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'origin/master' into dev\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/commit/431fe2dc0a144300b33038820d24fc30302c8abc\"\u003e\u003ccode\u003e431fe2d\u003c/code\u003e\u003c/a\u003e Use local repo for publishing (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3171\"\u003e#3171\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/commit/05c12b60a6717b99053fb82e1f94d2f859727374\"\u003e\u003ccode\u003e05c12b6\u003c/code\u003e\u003c/a\u003e Add usage attribute to \u0026quot;testRepositories\u0026quot; configuration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/commit/a4e1f082ef2e72caa139b474c05657de6015da20\"\u003e\u003ccode\u003ea4e1f08\u003c/code\u003e\u003c/a\u003e Bump Kover version to 0.9.8 release (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3174\"\u003e#3174\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/commit/304e858ccc7066854637d86ab80056f5f2bcc094\"\u003e\u003ccode\u003e304e858\u003c/code\u003e\u003c/a\u003e Expose Json exceptions structure (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3145\"\u003e#3145\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/commit/4a0338ef5093d765138151bc30282e909ca459e4\"\u003e\u003ccode\u003e4a0338e\u003c/code\u003e\u003c/a\u003e Included G Play SDK verification file for core-jvm (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3169\"\u003e#3169\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/commit/421f64c74f0ea6d4a3cdc8dd483505366e3f6c8f\"\u003e\u003ccode\u003e421f64c\u003c/code\u003e\u003c/a\u003e CBOR: Relax value range check when decoding numbers (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.serialization/issues/3167\"\u003e#3167\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/commit/85a4f126ec491c77e2b3686cc22c1bae27a20783\"\u003e\u003ccode\u003e85a4f12\u003c/code\u003e\u003c/a\u003e KT-84955: mark apple x64 tagets as deprecated error\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/commit/bd38b0e49bce38d1a55576e89856bc63990167ed\"\u003e\u003ccode\u003ebd38b0e\u003c/code\u003e\u003c/a\u003e Remove dead code\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/Kotlin/kotlinx.serialization/compare/v1.7.3...v1.11.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.jetbrains.kotlinx:kotlinx-coroutines-core` from 1.9.0 to 1.11.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/releases\"\u003eorg.jetbrains.kotlinx:kotlinx-coroutines-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.11.0\u003c/h2\u003e\n\u003ch3\u003eVarious\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eKotlin was updated to 2.2.20 (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4545\"\u003e#4545\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImproved the published jar files (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/3842\"\u003e#3842\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4599\"\u003e#4599\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eVarious documentation improvements, including complete rewrites of structured concurrency and error handling-related KDoc (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4433\"\u003e#4433\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4596\"\u003e#4596\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBreaking changes and deprecations\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003ePromise\u003c/code\u003e-related functions from JS and Wasm/JS to the new \u003ccode\u003eweb\u003c/code\u003e target. On Wasm/JS, this is a breaking change. Before the change, \u003ccode\u003ePromise\u003c/code\u003e on Wasm/JS could work with arbitrary Kotlin types, but now, only \u003ccode\u003eJsAny\u003c/code\u003e subtypes are accepted (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4563\"\u003e#4563\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eChanged handling of coroutine exceptions that can't be propagated on JS and Wasm/JS. B\nefore, exceptions were logged, but now, they are reported to the JS runtime (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4451\"\u003e#4451\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4631\"\u003e#4631\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eDeprecated using \u003ccode\u003eCoroutineDispatcher\u003c/code\u003e as the coroutine context key; now, \u003ccode\u003eContinuationInterceptor\u003c/code\u003e has to be used instead (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4333\"\u003e#4333\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdvanced the deprecation levels on \u003ccode\u003ekotlinx-coroutines-test\u003c/code\u003e APIs (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4604\"\u003e#4604\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded lint functions that mark passing a \u003ccode\u003eJob\u003c/code\u003e to coroutine builders as deprecated (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4435\"\u003e#4435\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug fixes and improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded a \u003ccode\u003ecallsInPlace(EXACTLY_ONCE)\u003c/code\u003e contract to \u003ccode\u003erunBlocking\u003c/code\u003e in code shared between JVM and Native (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4368\"\u003e#4368\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded a \u003ccode\u003ecallsInPlace(EXACTLY_ONCE)\u003c/code\u003e contract to \u003ccode\u003esuspendCancellableCoroutine\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4574\"\u003e#4574\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eflowOn\u003c/code\u003e incorrectly handling \u003ccode\u003eThreadContextElement\u003c/code\u003e updates (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4403\"\u003e#4403\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed exceptions in user-supplied \u003ccode\u003eThread.UncaughtExceptionHandler\u003c/code\u003e instances causing the internal coroutines machinery to fail (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4516\"\u003e#4516\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eCoroutineDispatcher.asScheduler\u003c/code\u003e in the RxJava integration not cancelling outstanding work when a \u003ccode\u003eWorker\u003c/code\u003e gets cancelled, which led to memory leaks in some scenarios (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4615\"\u003e#4615\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eSharedFlow\u003c/code\u003e entering an invalid state when a subscriber and an emitter are cancelled simultaneously (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4583\"\u003e#4583\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed an R8 optimization leading to \u003ccode\u003eshareIn\u003c/code\u003e/\u003ccode\u003estateIn\u003c/code\u003e coroutines getting garbage-collected (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4646\"\u003e#4646\u003c/a\u003e). Thanks, \u003ca href=\"https://github.com/solevic\"\u003e\u003ccode\u003e@​solevic\u003c/code\u003e\u003c/a\u003e!\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSmall additions\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003eCompletableDeferred.asDeferred\u003c/code\u003e for obtaining a read-only \u003ccode\u003eDeferred\u003c/code\u003e view (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4408\"\u003e#4408\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eSharedFlow.asFlow\u003c/code\u003e for obtaining a \u003ccode\u003eFlow\u003c/code\u003e view with hidden hot flow semantics (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4530\"\u003e#4530\u003c/a\u003e). Thanks, \u003ca href=\"https://github.com/g000sha256\"\u003e\u003ccode\u003e@​g000sha256\u003c/code\u003e\u003c/a\u003e!\u003c/li\u003e\n\u003cli\u003eAdded a \u003ccode\u003eStateFlow.collectLatest\u003c/code\u003e overload returning \u003ccode\u003eNothing\u003c/code\u003e to assist with finding unreachable code (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4454\"\u003e#4454\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eReceiveChannel.consumeTo\u003c/code\u003e for consuming a \u003ccode\u003eReceiveChannel\u003c/code\u003e into a \u003ccode\u003eMutableCollection\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4520\"\u003e#4520\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded a \u003ccode\u003eStateFlow\u0026lt;T\u0026gt;.onSubscription\u003c/code\u003e overload returning a \u003ccode\u003eStateFlow\u0026lt;T\u0026gt;\u003c/code\u003e, similar to \u003ccode\u003eSharedFlow\u0026lt;T\u0026gt;.onSubscription\u003c/code\u003e returning \u003ccode\u003eSharedFlow\u0026lt;T\u0026gt;\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4275\"\u003e#4275\u003c/a\u003e). Thanks, \u003ca href=\"https://github.com/xit0c\"\u003e\u003ccode\u003e@​xit0c\u003c/code\u003e\u003c/a\u003e!\u003c/li\u003e\n\u003cli\u003eAdded terminal \u003ccode\u003eFlow\u003c/code\u003e operators for collecting a \u003ccode\u003eFlow\u003c/code\u003e to a \u003ccode\u003eMap\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/1541\"\u003e#1541\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChangelog relative to version 1.11.0\u003c/h3\u003e\n\u003cp\u003eNo changes, only the version is increased.\u003c/p\u003e\n\u003ch2\u003e1.11.0-rc02\u003c/h2\u003e\n\u003cp\u003eRestored binary compatibility with 1.10.2 and older versions on Wasm/JS for usages of \u003ccode\u003ePromise\u003c/code\u003e-related functions (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4661\"\u003e#4661\u003c/a\u003e).\u003c/p\u003e\n\u003ch2\u003e1.11.0-rc01\u003c/h2\u003e\n\u003ch3\u003eVarious\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eKotlin was updated to 2.2.20 (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4545\"\u003e#4545\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImproved the published jar files (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/3842\"\u003e#3842\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4599\"\u003e#4599\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eVarious documentation improvements, including complete rewrites of structured concurrency and error handling-related KDoc (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4433\"\u003e#4433\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4596\"\u003e#4596\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBreaking changes and deprecations\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/blob/master/CHANGES.md\"\u003eorg.jetbrains.kotlinx:kotlinx-coroutines-core's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 1.11.0\u003c/h2\u003e\n\u003ch3\u003eVarious\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eKotlin was updated to 2.2.20 (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4545\"\u003e#4545\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImproved the published jar files (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/3842\"\u003e#3842\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4599\"\u003e#4599\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eVarious documentation improvements, including complete rewrites of structured concurrency and error handling-related KDoc (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4433\"\u003e#4433\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4596\"\u003e#4596\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBreaking changes and deprecations\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eMoved \u003ccode\u003ePromise\u003c/code\u003e-related functions from JS and Wasm/JS to the new \u003ccode\u003eweb\u003c/code\u003e target. On Wasm/JS, this is a breaking change. Before the change, \u003ccode\u003ePromise\u003c/code\u003e on Wasm/JS could work with arbitrary Kotlin types, but now, only \u003ccode\u003eJsAny\u003c/code\u003e subtypes are accepted (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4563\"\u003e#4563\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eChanged handling of coroutine exceptions that can't be propagated on JS and Wasm/JS. Before, exceptions were logged, but now, they are reported to the JS runtime (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4451\"\u003e#4451\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4631\"\u003e#4631\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eDeprecated using \u003ccode\u003eCoroutineDispatcher\u003c/code\u003e as the coroutine context key; now, \u003ccode\u003eContinuationInterceptor\u003c/code\u003e has to be used instead (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4333\"\u003e#4333\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdvanced the deprecation levels on \u003ccode\u003ekotlinx-coroutines-test\u003c/code\u003e APIs (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4604\"\u003e#4604\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded lint functions that mark passing a \u003ccode\u003eJob\u003c/code\u003e to coroutine builders as deprecated (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4435\"\u003e#4435\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug fixes and improvements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded a \u003ccode\u003ecallsInPlace(EXACTLY_ONCE)\u003c/code\u003e contract to \u003ccode\u003erunBlocking\u003c/code\u003e in code shared between JVM and Native (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4368\"\u003e#4368\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded a \u003ccode\u003ecallsInPlace(EXACTLY_ONCE)\u003c/code\u003e contract to \u003ccode\u003esuspendCancellableCoroutine\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4574\"\u003e#4574\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eflowOn\u003c/code\u003e incorrectly handling \u003ccode\u003eThreadContextElement\u003c/code\u003e updates (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4403\"\u003e#4403\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed exceptions in user-supplied \u003ccode\u003eThread.UncaughtExceptionHandler\u003c/code\u003e instances causing the internal coroutines machinery to fail (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4516\"\u003e#4516\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eCoroutineDispatcher.asScheduler\u003c/code\u003e in the RxJava integration not cancelling outstanding work when a \u003ccode\u003eWorker\u003c/code\u003e gets cancelled, which led to memory leaks in some scenarios (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4615\"\u003e#4615\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eSharedFlow\u003c/code\u003e entering an invalid state when a subscriber and an emitter are cancelled simultaneously (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4583\"\u003e#4583\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eFixed an R8 optimization leading to \u003ccode\u003eshareIn\u003c/code\u003e/\u003ccode\u003estateIn\u003c/code\u003e coroutines getting garbage-collected (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4646\"\u003e#4646\u003c/a\u003e). Thanks, \u003ca href=\"https://github.com/solevic\"\u003e\u003ccode\u003e@​solevic\u003c/code\u003e\u003c/a\u003e!\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSmall additions\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdded \u003ccode\u003eCompletableDeferred.asDeferred\u003c/code\u003e for obtaining a read-only \u003ccode\u003eDeferred\u003c/code\u003e view (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4408\"\u003e#4408\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eSharedFlow.asFlow\u003c/code\u003e for obtaining a \u003ccode\u003eFlow\u003c/code\u003e view with hidden hot flow semantics (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4530\"\u003e#4530\u003c/a\u003e). Thanks, \u003ca href=\"https://github.com/g000sha256\"\u003e\u003ccode\u003e@​g000sha256\u003c/code\u003e\u003c/a\u003e!\u003c/li\u003e\n\u003cli\u003eAdded a \u003ccode\u003eStateFlow.collectLatest\u003c/code\u003e overload returning \u003ccode\u003eNothing\u003c/code\u003e to assist with finding unreachable code (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4454\"\u003e#4454\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eReceiveChannel.consumeTo\u003c/code\u003e for consuming a \u003ccode\u003eReceiveChannel\u003c/code\u003e into a \u003ccode\u003eMutableCollection\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4520\"\u003e#4520\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eAdded a \u003ccode\u003eStateFlow\u0026lt;T\u0026gt;.onSubscription\u003c/code\u003e overload returning a \u003ccode\u003eStateFlow\u0026lt;T\u0026gt;\u003c/code\u003e, similar to \u003ccode\u003eSharedFlow\u0026lt;T\u0026gt;.onSubscription\u003c/code\u003e returning \u003ccode\u003eSharedFlow\u0026lt;T\u0026gt;\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4275\"\u003e#4275\u003c/a\u003e). Thanks, \u003ca href=\"https://github.com/xit0c\"\u003e\u003ccode\u003e@​xit0c\u003c/code\u003e\u003c/a\u003e!\u003c/li\u003e\n\u003cli\u003eAdded terminal \u003ccode\u003eFlow\u003c/code\u003e operators for collecting a \u003ccode\u003eFlow\u003c/code\u003e to a \u003ccode\u003eMap\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/1541\"\u003e#1541\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChangelog relative to version 1.11.0\u003c/h3\u003e\n\u003cp\u003eNo changes, only the version is increased.\u003c/p\u003e\n\u003ch2\u003eVersion 1.11.0-rc02\u003c/h2\u003e\n\u003cp\u003eRestored binary compatibility with 1.10.2 and older versions on Wasm/JS for usages of \u003ccode\u003ePromise\u003c/code\u003e-related functions (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4661\"\u003e#4661\u003c/a\u003e).\u003c/p\u003e\n\u003ch2\u003eVersion 1.11.0-rc01\u003c/h2\u003e\n\u003ch3\u003eVarious\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eKotlin was updated to 2.2.20 (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4545\"\u003e#4545\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eImproved the published jar files (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/3842\"\u003e#3842\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4599\"\u003e#4599\u003c/a\u003e).\u003c/li\u003e\n\u003cli\u003eVarious documentation improvements, including complete rewrites of structured concurrency and error handling-related KDoc (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4433\"\u003e#4433\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4596\"\u003e#4596\u003c/a\u003e).\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/commit/8564f65764d3d05893cec026c6e94250e2b23874\"\u003e\u003ccode\u003e8564f65\u003c/code\u003e\u003c/a\u003e Version 1.11.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/commit/a4c6af96c15fe30f5d4e8b810ea74f8babd5805c\"\u003e\u003ccode\u003ea4c6af9\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'origin/master' into develop\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/commit/ef917b460aa741691fbf991ee1b813049cae18c9\"\u003e\u003ccode\u003eef917b4\u003c/code\u003e\u003c/a\u003e KT-84955: mark apple x64 tagets as deprecated error (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4645\"\u003e#4645\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/commit/5ebc421e341bf2ddce734d369da87df1985e80bd\"\u003e\u003ccode\u003e5ebc421\u003c/code\u003e\u003c/a\u003e Update the release procedure description (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4670\"\u003e#4670\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/commit/95f46a073bc4a1230352108cea1835fd22219a80\"\u003e\u003ccode\u003e95f46a0\u003c/code\u003e\u003c/a\u003e Remove old maven repository settings (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4672\"\u003e#4672\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/commit/b4f4f0aa6acb692f3fbcadd70e4958e3e9d370fc\"\u003e\u003ccode\u003eb4f4f0a\u003c/code\u003e\u003c/a\u003e Fix package name of \u003ccode\u003eToMapCollectionSamplesTest\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4674\"\u003e#4674\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/commit/86738dca7dc9ac82249abc8206263fa0065ee631\"\u003e\u003ccode\u003e86738dc\u003c/code\u003e\u003c/a\u003e Added templates to the issue creation wizard (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4654\"\u003e#4654\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/commit/330fcc221fb583f0b119f34191f735a73b827378\"\u003e\u003ccode\u003e330fcc2\u003c/code\u003e\u003c/a\u003e Version 1.11.0-rc02\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/commit/e31cef6e9f2d26794be7d75ecbf3033b6432d582\"\u003e\u003ccode\u003ee31cef6\u003c/code\u003e\u003c/a\u003e Merge remote-tracking branch 'origin/master' into develop\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/commit/dc6e9f61eaf3a67f4bf474a7987aedc3f16cef37\"\u003e\u003ccode\u003edc6e9f6\u003c/code\u003e\u003c/a\u003e Restore Promise-related functions on Wasm/JS as HIDDEN (\u003ca href=\"https://redirect.github.com/Kotlin/kotlinx.coroutines/issues/4661\"\u003e#4661\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/Kotlin/kotlinx.coroutines/compare/1.9.0...1.11.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.core:jackson-databind` from 2.18.2 to 2.22.2\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/25b2a221f9aa4107e455065a74635e209418cf55\"\u003e\u003ccode\u003e25b2a22\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.22.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bab1c1a702a941f8805ee6698e8fa4fdbfbec54a\"\u003e\u003ccode\u003ebab1c1a\u003c/code\u003e\u003c/a\u003e Prep for 2.22.2 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bc03cf83d74cf0e5944dce33a63ee59ddc344b64\"\u003e\u003ccode\u003ebc03cf8\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/83379fb6409075336edf3d8d88744e95911a43f8\"\u003e\u003ccode\u003e83379fb\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0d400c9dc586fdd460d0c6a40db21ebbe22106d8\"\u003e\u003ccode\u003e0d400c9\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ce36a279f8b078bef2d9d44a1d01034c3634f91a\"\u003e\u003ccode\u003ece36a27\u003c/code\u003e\u003c/a\u003e Merge branch '2.18' into 2.19\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7a209e1fa97033746db50fd7bcd1e3dbab077599\"\u003e\u003ccode\u003e7a209e1\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/a432707afe6b7569243d1c2d8052a1bf33d9279c\"\u003e\u003ccode\u003ea432707\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/176df1d48b256ced412c65293ad4e09393e24bd3\"\u003e\u003ccode\u003e176df1d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.18.10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7785f5f9ed24127e004115472c47b26ea4cf2774\"\u003e\u003ccode\u003e7785f5f\u003c/code\u003e\u003c/a\u003e Prep for 2.18.10 release\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.18.2...jackson-databind-2.22.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore \u003cdependency name\u003e major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)\n- `@dependabot ignore \u003cdependency name\u003e` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)\n- `@dependabot unignore \u003cdependency name\u003e` will remove all of the ignore conditions of the specified dependency\n- `@dependabot unignore \u003cdependency name\u003e \u003cignore condition\u003e` will remove the ignore condition of the specified dependency and ignore conditions\n\n\n\u003c/details\u003e","html_url":"https://github.com/tesser-payments/sdk-java/pull/22","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/tesser-payments%2Fsdk-java/issues/22","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/22/packages"}},{"old_version":"2.18.2","new_version":"2.22.2","update_type":"minor","path":"/langchain4j/18-ollama","pr_created_at":"2026-09-19T08:13:41.000Z","version_change":"2.18.2 → 2.22.2","issue":{"uuid":"5508754393","node_id":"PR_kwDOUhG-vM8AAAABEMhOdA","number":104,"state":"closed","title":"deps: bump com.fasterxml.jackson.core:jackson-databind from 2.18.2 to 2.22.2 in /langchain4j/18-ollama","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-19T08:47:15.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-19T08:13:41.000Z","updated_at":"2026-09-19T08:47:24.000Z","time_to_close":2014,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"deps","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.18.2","new_version":"2.22.2","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":"/langchain4j/18-ollama","ecosystem":"maven"},"body":"Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.18.2 to 2.22.2.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/25b2a221f9aa4107e455065a74635e209418cf55\"\u003e\u003ccode\u003e25b2a22\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.22.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bab1c1a702a941f8805ee6698e8fa4fdbfbec54a\"\u003e\u003ccode\u003ebab1c1a\u003c/code\u003e\u003c/a\u003e Prep for 2.22.2 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bc03cf83d74cf0e5944dce33a63ee59ddc344b64\"\u003e\u003ccode\u003ebc03cf8\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/83379fb6409075336edf3d8d88744e95911a43f8\"\u003e\u003ccode\u003e83379fb\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0d400c9dc586fdd460d0c6a40db21ebbe22106d8\"\u003e\u003ccode\u003e0d400c9\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ce36a279f8b078bef2d9d44a1d01034c3634f91a\"\u003e\u003ccode\u003ece36a27\u003c/code\u003e\u003c/a\u003e Merge branch '2.18' into 2.19\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7a209e1fa97033746db50fd7bcd1e3dbab077599\"\u003e\u003ccode\u003e7a209e1\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/a432707afe6b7569243d1c2d8052a1bf33d9279c\"\u003e\u003ccode\u003ea432707\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/176df1d48b256ced412c65293ad4e09393e24bd3\"\u003e\u003ccode\u003e176df1d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.18.10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7785f5f9ed24127e004115472c47b26ea4cf2774\"\u003e\u003ccode\u003e7785f5f\u003c/code\u003e\u003c/a\u003e Prep for 2.18.10 release\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.18.2...jackson-databind-2.22.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.18.2\u0026new-version=2.22.2)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\n\n\n\u003c/details\u003e","html_url":"https://github.com/alxkm/java-ai-cookbook/pull/104","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/alxkm%2Fjava-ai-cookbook/issues/104","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/104/packages"}},{"old_version":"2.17.2","new_version":"2.22.3","update_type":"minor","path":null,"pr_created_at":"2026-09-17T14:06:36.000Z","version_change":"2.17.2 → 2.22.3","issue":{"uuid":"5488468705","node_id":"PR_kwDOSO-pI88AAAABD8Jb4g","number":171,"state":"closed","title":"chore(deps): Bump the gradle-dependencies group across 1 directory with 9 updates","user":"dependabot[bot]","labels":[],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":"2026-09-29T19:36:51.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-17T14:06:36.000Z","updated_at":"2026-09-29T19:36:53.000Z","time_to_close":1056615,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): Bump","group_name":"gradle-dependencies","update_count":9,"packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.17.2","new_version":"2.22.3","repository_url":"https://github.com/FasterXML/jackson-databind"},{"name":"org.jsoup:jsoup","old_version":"1.17.2","new_version":"1.23.2","repository_url":"https://github.com/jhy/jsoup"},{"name":"jakarta.persistence:jakarta.persistence-api","old_version":"3.1.0","new_version":"3.2.0","repository_url":"https://github.com/jakartaee/persistence"},{"name":"com.h2database:h2","old_version":"2.4.240","new_version":"2.5.252","repository_url":"https://github.com/h2database/h2database"},{"name":"software.amazon.awssdk:bom","old_version":"2.28.11","new_version":"2.55.6"},{"name":"jakarta.servlet:jakarta.servlet-api","old_version":"6.0.0","new_version":"6.1.0","repository_url":"https://github.com/eclipse-ee4j/servlet-api"},{"name":"com.fasterxml.jackson.datatype:jackson-datatype-jsr310","old_version":"2.17.2","new_version":"2.22.3"},{"name":"com.tngtech.archunit:archunit-junit5","old_version":"1.3.0","new_version":"1.5.1","repository_url":"https://github.com/TNG/ArchUnit"},{"name":"gradle-wrapper","old_version":"9.5.1","new_version":"9.8.0","repository_url":"https://github.com/gradle/gradle"}],"path":null,"ecosystem":"maven"},"body":"Bumps the gradle-dependencies group with 9 updates in the /NPDevGenerator directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) | `2.17.2` | `2.22.3` |\n| [org.jsoup:jsoup](https://github.com/jhy/jsoup) | `1.17.2` | `1.23.2` |\n| [jakarta.persistence:jakarta.persistence-api](https://github.com/jakartaee/persistence) | `3.1.0` | `3.2.0` |\n| [com.h2database:h2](https://github.com/h2database/h2database) | `2.4.240` | `2.5.252` |\n| software.amazon.awssdk:bom | `2.28.11` | `2.55.6` |\n| [jakarta.servlet:jakarta.servlet-api](https://github.com/eclipse-ee4j/servlet-api) | `6.0.0` | `6.1.0` |\n| com.fasterxml.jackson.datatype:jackson-datatype-jsr310 | `2.17.2` | `2.22.3` |\n| [com.tngtech.archunit:archunit-junit5](https://github.com/TNG/ArchUnit) | `1.3.0` | `1.5.1` |\n| [gradle-wrapper](https://github.com/gradle/gradle) | `9.5.1` | `9.8.0` |\n\n\nUpdates `com.fasterxml.jackson.core:jackson-databind` from 2.17.2 to 2.22.3\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/4385c5f7d51426f66fb24c3777308acc8ae7ea6c\"\u003e\u003ccode\u003e4385c5f\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.22.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ccb4fd0158cd20800f6014496dccf7332e5b18ce\"\u003e\u003ccode\u003eccb4fd0\u003c/code\u003e\u003c/a\u003e Prep for 2.22.3 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/2958412f1817a0ad95c34066b7eb85781dd2d4f1\"\u003e\u003ccode\u003e2958412\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1215b94c2f7a8c4ce3863afbc38275a19c682a54\"\u003e\u003ccode\u003e1215b94\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/1f0df621449e5de7dd13a1538e0343f65f0e6bb3\"\u003e\u003ccode\u003e1f0df62\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/13a9ff4c4ef982cda23b99fea89d2a4e87af9019\"\u003e\u003ccode\u003e13a9ff4\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.21.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/d168f9679ad575cdc2df8d53a8474ec481c7b5a7\"\u003e\u003ccode\u003ed168f96\u003c/code\u003e\u003c/a\u003e Prep for 2.21.7 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/eaf5c76b8e0a538729a1bf922061abf73b13f89b\"\u003e\u003ccode\u003eeaf5c76\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/e05ef4cbb4d534a82948f8ba84350e55493bc72e\"\u003e\u003ccode\u003ee05ef4c\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/f6d4000c1eb6d34e2ae24685a9790b1e833d4bcb\"\u003e\u003ccode\u003ef6d4000\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.17.2...jackson-databind-2.22.3\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.jsoup:jsoup` from 1.17.2 to 1.23.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jhy/jsoup/releases\"\u003eorg.jsoup:jsoup's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ejsoup 1.23.2\u003c/h2\u003e\n\u003cp\u003e\u003cstrong\u003ejsoup 1.23.2\u003c/strong\u003e is out now. This release focuses largely on bug fixes, specification correctness, and performance improvements.\u003c/p\u003e\n\u003cp\u003eIt brings closer alignment with the HTML, XML, URL, and form submission specifications; improves XML and W3C DOM conversion; and makes HTTP workloads more efficient through streamed request bodies and broader JDK \u003ccode\u003eHttpClient\u003c/code\u003e reuse.\u003c/p\u003e\n\u003cp\u003eThis version also includes new node insertion methods for \u003ccode\u003eElements\u003c/code\u003e, and DOM mutations now reject operations that would create a cycle.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003ejsoup\u003c/strong\u003e is a Java library for working with real-world HTML and XML. It provides a very convenient API for extracting and manipulating data, using the best of HTML5 DOM methods and CSS selectors.\u003c/p\u003e\n\u003cp\u003e\u003ca href=\"https://jsoup.org/download\"\u003e\u003cstrong\u003eDownload\u003c/strong\u003e\u003c/a\u003e jsoup now.\u003c/p\u003e\n\u003ch2\u003eImprovements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImproved consecutive \u003ccode\u003eStreamParser.selectFirst()\u003c/code\u003e calls during progressive parsing, so later matches are returned with their parsed contents when earlier selections had left them as parser lookahead. E.g., given \u003ccode\u003e\u0026lt;title\u0026gt;One\u0026lt;/title\u0026gt;\u0026lt;p id=hit\u0026gt;Full\u0026lt;/p\u0026gt;\u0026lt;p\u0026gt;Next\u0026lt;/p\u0026gt;\u003c/code\u003e, selecting \u003ccode\u003etitle\u003c/code\u003e and then \u003ccode\u003e#hit\u003c/code\u003e now advances the partial lookahead and returns \u003ccode\u003e\u0026lt;p id=\u0026quot;hit\u0026quot;\u0026gt;Full\u0026lt;/p\u0026gt;\u003c/code\u003e, rather than returning an empty \u003ccode\u003e\u0026lt;p id=\u0026quot;hit\u0026quot;\u0026gt;\u0026lt;/p\u0026gt;\u003c/code\u003e before its content is parsed. The updated readiness tracking follows StreamParser's normal emission order across implicit HTML structure and parser recovery. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2551\"\u003e#2551\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eImproved XML parser performance and memory use for documents with many nested namespace declarations by recording namespace changes within each element scope. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2556\"\u003e#2556\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eImproved \u003ccode\u003eW3CDom\u003c/code\u003e conversion performance for documents with many nested namespace declarations. The W3C converter now uses the same optimized namespace tracking as the XML parser. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2559\"\u003e#2559\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eImproved \u003ccode\u003eW3CDom\u003c/code\u003e XML conversion to retain processing instructions, comments outside the root element, and CDATA sections, which were previously dropped or converted to text. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2572\"\u003e#2572\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eDOM mutation methods, including child insertion and replacement, now reject operations that would create a cycle, such as making a node its own child or moving an ancestor beneath a descendant. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2552\"\u003e#2552\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eElements#before(Node)\u003c/code\u003e, \u003ccode\u003eafter(Node)\u003c/code\u003e, \u003ccode\u003eprepend(Node)\u003c/code\u003e, and \u003ccode\u003eappend(Node)\u003c/code\u003e to match the existing HTML string methods. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/953\"\u003e#953\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eLarge file-backed uploads through \u003ccode\u003eConnection.requestBodyStream(InputStream)\u003c/code\u003e now stream directly with the JDK \u003ccode\u003eHttpClient\u003c/code\u003e on Java 11+, rather than being loaded fully into memory first. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2576\"\u003e#2575\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eExtended Java 11+ HTTP client reuse from requests sharing a \u003ccode\u003eJsoup.newSession()\u003c/code\u003e to ordinary \u003ccode\u003eJsoup.connect()\u003c/code\u003e calls, reducing transport thread and connection setup churn under sustained request loads. Sessions with custom authentication or SSL contexts continue to use their own client. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2584\"\u003e#2584\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eChanges\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAligned the XML parser stack depth and lookups to the configured maximum, which now defaults to 512 for both HTML and XML. Use \u003ccode\u003eParser#setMaxDepth(int)\u003c/code\u003e to configure. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2570\"\u003e#2570\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eBug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eW3CDom\u003c/code\u003e namespace conversion in several cases: \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2559\"\u003e#2559\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\n\u003cul\u003e\n\u003cli\u003eNamespace declarations and prefixed attributes now carry the correct namespace URI, so namespace-aware DOM lookups work as expected.\u003c/li\u003e\n\u003cli\u003eAttributes added after parsing, or included through subtree conversion, now use inherited prefix declarations.\u003c/li\u003e\n\u003cli\u003eNamespace declarations now apply regardless of attribute order, and an empty declaration shadows an inherited binding only within its scope.\u003c/li\u003e\n\u003cli\u003eWith namespace awareness disabled, inherited and undeclared prefixes now receive the declarations needed for XML serialization.\u003c/li\u003e\n\u003cli\u003eValid HTML names that are not XML QNames, such as \u003ccode\u003ea:b:c\u003c/code\u003e, are normalized. Attributes that still cannot be represented are skipped, and unrepresentable elements no longer change the surrounding tree.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eW3CDom\u003c/code\u003e conversion of programmatically created or renamed elements whose names can be represented in a jsoup HTML DOM but are not valid XML names, such as \u003ccode\u003e1abc\u003c/code\u003e. These names are now normalized (e.g. \u003ccode\u003e_1abc\u003c/code\u003e) instead of causing a \u003ccode\u003eNullPointerException\u003c/code\u003e. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2560\"\u003e#2560\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eFixed XML doctype serialization when a system identifier contains a double quote, which could otherwise produce invalid XML. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2571\"\u003e#2571\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eXML serialization now repairs element and attribute names that start with an invalid character, rather than outputting \u003ccode\u003enull\u003c/code\u003e elements or dropping attributes. For example, an attribute named \u003ccode\u003e1a\u003c/code\u003e is written as \u003ccode\u003e_1a\u003c/code\u003e. Additional leading underscores keep repaired attribute names unique if they conflict with another attribute. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2573\"\u003e#2573\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eSupplementary Unicode characters are now escaped correctly when serializing with non-UTF, non-ASCII output charsets such as ISO-8859-1. Previously, characters could be emitted unescaped when their low 16-bit value was representable by the configured charset, causing replacement or corruption when the output was encoded. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2578\"\u003e#2578\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eFixed the JDK \u003ccode\u003eHttpClient\u003c/code\u003e implementation to accept responses missing a \u003ccode\u003eContent-Type\u003c/code\u003e header, matching the \u003ccode\u003eHttpURLConnection\u003c/code\u003e implementation. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2549\"\u003e#2549\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eFixed HTTP response content-type matching to handle media types case-insensitively and recognize structured \u003ccode\u003e+xml\u003c/code\u003e suffixes, including vendor-specific media types. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2550\"\u003e#2550\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eHTTP request URL normalization now percent-encodes ASCII control characters, DEL, and embedded fragment delimiters, keeping normalized URLs valid for HTTP requests while preserving existing escapes. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2585\"\u003e#2585\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eCorrected multipart form encoding to percent-escape CR and LF in field names and filenames, matching the HTML form submission specification. Multipart file content-types containing CR or LF are now rejected with a \u003ccode\u003eValidationException\u003c/code\u003e. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2555\"\u003e#2555\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eAligned trailing comment placement with the HTML specification: comments after \u003ccode\u003e\u0026lt;/body\u0026gt;\u003c/code\u003e remain children of the \u003ccode\u003ehtml\u003c/code\u003e element, while comments after \u003ccode\u003e\u0026lt;/html\u0026gt;\u003c/code\u003e remain children of the document. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2557\"\u003e#2557\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eWhen using the optional \u003ccode\u003ere2j\u003c/code\u003e regular expression engine, memory allocation errors caused by complex selector patterns at match time are now normalized to a \u003ccode\u003eValidationException\u003c/code\u003e with a \u003ccode\u003ePattern complexity error\u003c/code\u003e message.\u003c/li\u003e\n\u003cli\u003eFixed parsing of malformed SVG and MathML content so that breakout HTML tags are placed according to the HTML specification. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2562\"\u003e#2562\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eFixed deeply nested malformed HTML parsing that could lose the document body because stack lookups did not align to the configured maximum parser depth. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2569\"\u003e#2569\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eAligned RCDATA, RAWTEXT, and script-data parsing with the HTML specification: malformed end tags no longer consume following markup, unclosed \u003ccode\u003etitle\u003c/code\u003e/\u003ccode\u003etextarea\u003c/code\u003e content stays text through EOF, and custom text tags match exact names. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2577\"\u003e#2577\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eImproved URL validation during HTTP/HTTPS URL resolution and cleaning; resolved URLs without a host are now rejected instead of being accepted based only on their scheme prefix, aligning to RFC 9110. Valid relative links and non-HTTP(S) schemes are unchanged. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2579\"\u003e#2579\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eRedirects with malformed single-slash HTTP locations now use standard URL resolution to align with browsers. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2580\"\u003e#2580\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eTemplate fragment parsing now handles unmatched \u003ccode\u003e\u0026lt;/template\u0026gt;\u003c/code\u003e tags without throwing a \u003ccode\u003eValidationException\u003c/code\u003e. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2581\"\u003e#2581\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003cli\u003eImproved source tracking for adopted formatting elements and malformed markup ending at EOF. \u003c!-- raw HTML omitted --\u003e\u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2582\"\u003e#2582\u003c/a\u003e\u003c!-- raw HTML omitted --\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003chr /\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jhy/jsoup/blob/master/CHANGES.md\"\u003eorg.jsoup:jsoup's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e1.23.2 (2026-Aug-26)\u003c/h2\u003e\n\u003ch3\u003eImprovements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eImproved consecutive \u003ccode\u003eStreamParser.selectFirst(...)\u003c/code\u003e calls during progressive parsing, so later matches are returned with their parsed contents when earlier selections had left them as parser lookahead. E.g., given \u003ccode\u003e\u0026lt;title\u0026gt;One\u0026lt;/title\u0026gt;\u0026lt;p id=hit\u0026gt;Full\u0026lt;/p\u0026gt;\u0026lt;p\u0026gt;Next\u0026lt;/p\u0026gt;\u003c/code\u003e, selecting \u003ccode\u003etitle\u003c/code\u003e and then \u003ccode\u003e#hit\u003c/code\u003e now advances the partial lookahead and returns \u003ccode\u003e\u0026lt;p id=\u0026quot;hit\u0026quot;\u0026gt;Full\u0026lt;/p\u0026gt;\u003c/code\u003e, rather than returning an empty \u003ccode\u003e\u0026lt;p id=\u0026quot;hit\u0026quot;\u0026gt;\u0026lt;/p\u0026gt;\u003c/code\u003e before its content is parsed. The updated readiness tracking follows StreamParser's normal emission order across implicit HTML structure and parser recovery. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2551\"\u003e#2551\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved XML parser performance and memory use for documents with many nested namespace declarations by recording namespace changes within each element scope. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2556\"\u003e#2556\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved \u003ccode\u003eW3CDom\u003c/code\u003e conversion performance for documents with many nested namespace declarations. The W3C converter now uses the same optimized namespace tracking as the XML parser. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2559\"\u003e#2559\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved \u003ccode\u003eW3CDom\u003c/code\u003e XML conversion to retain processing instructions, comments outside the root element, and CDATA sections, which were previously dropped or converted to text. \u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2572\"\u003e#2572\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDOM mutation methods, including child insertion and replacement, now reject operations that would create a cycle, such as making a node its own child or moving an ancestor beneath a descendant. \u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2552\"\u003e#2552\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eElements#before(Node)\u003c/code\u003e, \u003ccode\u003eafter(Node)\u003c/code\u003e, \u003ccode\u003eprepend(Node)\u003c/code\u003e, and \u003ccode\u003eappend(Node)\u003c/code\u003e to match the existing HTML string methods. \u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/953\"\u003e#953\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eLarge file-backed uploads through \u003ccode\u003eConnection.requestBodyStream(InputStream)\u003c/code\u003e now stream directly with the JDK \u003ccode\u003eHttpClient\u003c/code\u003e on Java 11+, rather than being loaded fully into memory first. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2576\"\u003e#2575\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExtended Java 11+ HTTP client reuse from requests sharing a \u003ccode\u003eJsoup.newSession()\u003c/code\u003e to ordinary \u003ccode\u003eJsoup.connect(...)\u003c/code\u003e calls, reducing transport thread and connection setup churn under sustained request loads. Sessions with custom authentication or SSL contexts continue to use their own client. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2584\"\u003e#2584\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eChanges\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAligned the XML parser stack depth and lookups to the configured maximum, which now defaults to 512 for both HTML and XML. Use \u003ccode\u003eParser#setMaxDepth(int)\u003c/code\u003e to configure. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2570\"\u003e#2570\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFixed \u003ccode\u003eW3CDom\u003c/code\u003e namespace conversion in several cases: \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2559\"\u003e#2559\u003c/a\u003e\n\u003cul\u003e\n\u003cli\u003eNamespace declarations and prefixed attributes now carry the correct namespace URI, so namespace-aware DOM lookups work as expected.\u003c/li\u003e\n\u003cli\u003eAttributes added after parsing, or included through subtree conversion, now use inherited prefix declarations.\u003c/li\u003e\n\u003cli\u003eNamespace declarations now apply regardless of attribute order, and an empty declaration shadows an inherited binding only within its scope.\u003c/li\u003e\n\u003cli\u003eWith namespace awareness disabled, inherited and undeclared prefixes now receive the declarations needed for XML serialization.\u003c/li\u003e\n\u003cli\u003eValid HTML names that are not XML QNames, such as \u003ccode\u003ea:b:c\u003c/code\u003e, are normalized. Attributes that still cannot be represented are skipped, and unrepresentable elements no longer change the surrounding tree.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/li\u003e\n\u003cli\u003eFixed \u003ccode\u003eW3CDom\u003c/code\u003e conversion of programmatically created or renamed elements whose names can be represented in a jsoup HTML DOM but are not valid XML names, such as \u003ccode\u003e1abc\u003c/code\u003e. These names are now normalized (e.g. \u003ccode\u003e_1abc\u003c/code\u003e) instead of causing a \u003ccode\u003eNullPointerException\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2560\"\u003e#2560\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed XML doctype serialization when a system identifier contains a double quote, which could otherwise produce invalid XML. \u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2571\"\u003e#2571\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eXML serialization now repairs element and attribute names that start with an invalid character, rather than outputting \u003ccode\u003enull\u003c/code\u003e elements or dropping attributes. For example, an attribute named \u003ccode\u003e1a\u003c/code\u003e is written as \u003ccode\u003e_1a\u003c/code\u003e. Additional leading underscores keep repaired attribute names unique if they conflict with another attribute. \u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2573\"\u003e#2573\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSupplementary Unicode characters are now escaped correctly when serializing with non-UTF, non-ASCII output charsets such as ISO-8859-1. Previously, characters could be emitted unescaped when their low 16-bit value was representable by the configured charset, causing replacement or corruption when the output was encoded. \u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2578\"\u003e#2578\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed the JDK \u003ccode\u003eHttpClient\u003c/code\u003e implementation to accept responses missing a \u003ccode\u003eContent-Type\u003c/code\u003e header, matching the \u003ccode\u003eHttpURLConnection\u003c/code\u003e implementation. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2549\"\u003e#2549\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed HTTP response content-type matching to handle media types case-insensitively and recognize structured \u003ccode\u003e+xml\u003c/code\u003e suffixes, including vendor-specific media types. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2550\"\u003e#2550\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHTTP request URL normalization now percent-encodes ASCII control characters, DEL, and embedded fragment delimiters, keeping normalized URLs valid for HTTP requests while preserving existing escapes. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2585\"\u003e#2585\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCorrected multipart form encoding to percent-escape CR and LF in field names and filenames, matching the HTML form submission specification. Multipart file content-types containing CR or LF are now rejected with a \u003ccode\u003eValidationException\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2555\"\u003e#2555\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAligned trailing comment placement with the HTML specification: comments after \u003ccode\u003e\u0026lt;/body\u0026gt;\u003c/code\u003e remain children of the \u003ccode\u003ehtml\u003c/code\u003e element, while comments after \u003ccode\u003e\u0026lt;/html\u0026gt;\u003c/code\u003e remain children of the document. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2557\"\u003e#2557\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eWhen using the optional \u003ccode\u003ere2j\u003c/code\u003e regular expression engine, memory allocation errors caused by complex selector patterns at match time are now normalized to a \u003ccode\u003eValidationException\u003c/code\u003e with a \u003ccode\u003ePattern complexity error\u003c/code\u003e message.\u003c/li\u003e\n\u003cli\u003eFixed parsing of malformed SVG and MathML content so that breakout HTML tags are placed according to the HTML specification. \u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2562\"\u003e#2562\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixed deeply nested malformed HTML parsing that could lose the document body because stack lookups did not align to the configured maximum parser depth. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2569\"\u003e#2569\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAligned RCDATA, RAWTEXT, and script-data parsing with the HTML specification: malformed end tags no longer consume following markup, unclosed \u003ccode\u003etitle\u003c/code\u003e/\u003ccode\u003etextarea\u003c/code\u003e content stays text through EOF, and custom text tags match exact names. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2577\"\u003e#2577\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved URL validation during HTTP/HTTPS URL resolution and cleaning; resolved URLs without a host are now rejected instead of being accepted based only on their scheme prefix, aligning to RFC 9110. Valid relative links and non-HTTP(S) schemes are unchanged. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2579\"\u003e#2579\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRedirects with malformed single-slash HTTP locations now use standard URL resolution to align with browsers. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2580\"\u003e#2580\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTemplate fragment parsing now handles unmatched \u003ccode\u003e\u0026lt;/template\u0026gt;\u003c/code\u003e tags without throwing a \u003ccode\u003eValidationException\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2581\"\u003e#2581\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved source tracking for adopted formatting elements and malformed markup ending at EOF. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2582\"\u003e#2582\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e1.23.1 (2026-Jul-30)\u003c/h2\u003e\n\u003ch3\u003eImprovements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eReduced retained memory when parsing with source position tracking enabled (\u003ccode\u003eParser#setTrackPosition(true)\u003c/code\u003e). Source ranges are now stored in compact parser-owned span records instead of node and attribute user data, and \u003ccode\u003ePosition\u003c/code\u003e objects are created lazily when source ranges are read. This cuts tracked DOM retained size by about 50-60% on representative benchmark documents, while keeping \u003ccode\u003eNode#sourceRange()\u003c/code\u003e, \u003ccode\u003eElement#endSourceRange()\u003c/code\u003e, and \u003ccode\u003eAttribute#sourceRange()\u003c/code\u003e behavior intact. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2498\"\u003e#2498\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdded \u003ccode\u003eElement#classList()\u003c/code\u003e, an immutable snapshot of an element's class names in attribute order. Use \u003ccode\u003ehasClass()\u003c/code\u003e when you just need to test for one class, \u003ccode\u003eclassList()\u003c/code\u003e when you want to read or iterate classes without needing a mutable result, and \u003ccode\u003eclassNames()\u003c/code\u003e when you want the existing mutable, deduplicated set that can be written back with \u003ccode\u003eclassNames(Set)\u003c/code\u003e. The class APIs now share an HTML-whitespace scanner, which also makes \u003ccode\u003eclassNames()\u003c/code\u003e faster and lighter on allocation, especially when walking many elements without class names. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2500\"\u003e#2500\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAligned HTML parser scope classification with the current HTML spec for \u003ccode\u003eselect\u003c/code\u003e, \u003ccode\u003eforeignObject\u003c/code\u003e, and \u003ccode\u003etemplate\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2501\"\u003e#2501\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSimplified the HTML tree builder's scope, implied-end-tag, and special-element checks by caching parser-only options on Tag. That improves HTML parser throughput by about 10% on small inputs and up to about 30% on larger inputs in the benchmark fixtures. \u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2502\"\u003e#2502\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved HTML parser throughput stability by making hot tokeniser scan paths compile more predictably. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2507\"\u003e#2507\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003e\u0026lt;noscript\u0026gt;\u003c/code\u003e fallback markup is now parsed into an inspectable DOM subtree in both the document head and body. The fallback acts as a contained parsing island, so malformed markup cannot disrupt the surrounding document structure, while normal HTML tokenization still applies within it. This also improves round-trip serialization. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2537\"\u003e#2537\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eImproved redirect credential handling as a defense-in-depth measure: explicit authorization headers and request cookies are no longer forwarded across origins, reducing exposure through open redirects and aligning with HTTP guidance. Cookies managed by a \u003ccode\u003eCookieStore\u003c/code\u003e continue to follow their configured scope. \u003ca href=\"https://redirect.github.com/jhy/jsoup/pull/2540\"\u003e#2540\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jhy/jsoup/commit/fbc7775c462f5b023d8db54c9a73d7ec17d53300\"\u003e\u003ccode\u003efbc7775\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jsoup-1.23.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jhy/jsoup/commit/133ebde65afda061ea12818e1e65a53f5d822ea4\"\u003e\u003ccode\u003e133ebde\u003c/code\u003e\u003c/a\u003e Release 1.23.2 notes\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jhy/jsoup/commit/be2a74a1f6b3ad9cf2d3aeaac3f68b6c39929bc5\"\u003e\u003ccode\u003ebe2a74a\u003c/code\u003e\u003c/a\u003e Encode control chars during request URL normalization (\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2585\"\u003e#2585\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jhy/jsoup/commit/868f2eb1e6c9a2b826cd56f92b336fdbd616b241\"\u003e\u003ccode\u003e868f2eb\u003c/code\u003e\u003c/a\u003e Java 11 HTTP client reuse covers ordinary connections (\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2584\"\u003e#2584\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jhy/jsoup/commit/19c758e2e4abc6a1f52193ceab09c22a7c010f8b\"\u003e\u003ccode\u003e19c758e\u003c/code\u003e\u003c/a\u003e Get Animal Sniffer to run over test code as well.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jhy/jsoup/commit/17bb839aa5aa1519c729d78656d18adefee730cf\"\u003e\u003ccode\u003e17bb839\u003c/code\u003e\u003c/a\u003e Fix source tracking through HTML repair and malformed EOF (\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2582\"\u003e#2582\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jhy/jsoup/commit/cad054a61f3ae241a741b6658c50d6f962dfd43c\"\u003e\u003ccode\u003ecad054a\u003c/code\u003e\u003c/a\u003e Template stack checks need to exclude the fragment context (\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2581\"\u003e#2581\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jhy/jsoup/commit/46b620860af930eedc193a705eaf7cea5aec89a6\"\u003e\u003ccode\u003e46b6208\u003c/code\u003e\u003c/a\u003e Paranoimia\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jhy/jsoup/commit/66be2da4e2bd7a207700a4cc9c867d15ae74a587\"\u003e\u003ccode\u003e66be2da\u003c/code\u003e\u003c/a\u003e HTTP redirects use standard URL resolution for single-slash locations (\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2580\"\u003e#2580\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jhy/jsoup/commit/b035b623d3d1d0c50d84056d2946ba1a90f7f665\"\u003e\u003ccode\u003eb035b62\u003c/code\u003e\u003c/a\u003e Make hostless HTTP(S) URLs fail resolution and cleaning (\u003ca href=\"https://redirect.github.com/jhy/jsoup/issues/2579\"\u003e#2579\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/jhy/jsoup/compare/jsoup-1.17.2...jsoup-1.23.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `jakarta.persistence:jakarta.persistence-api` from 3.1.0 to 3.2.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/jakartaee/persistence/releases\"\u003ejakarta.persistence:jakarta.persistence-api's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eJakarta Persistence 3.2.0-M01\u003c/h2\u003e\n\u003cp\u003eThis release contains following changes:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eAdds factory-level access to named queries and named entity graphs\u003c/li\u003e\n\u003cli\u003eUpdates orm schema for 3.2\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/jakartaee/persistence/compare/3.2-DRAFT01-3.2.0-B02-RELEASE...3.2-M1-3.2.0-M1-RELEASE\"\u003ehttps://github.com/jakartaee/persistence/compare/3.2-DRAFT01-3.2.0-B02-RELEASE...3.2-M1-3.2.0-M1-RELEASE\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003eJakarta Persistence 3.1.0 API\u003c/h2\u003e\n\u003cp\u003eThis release contains following changes:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eEntityManagerFactory and EntityManager interfaces extends java.lang.AutoCloseable interface\u003c/li\u003e\n\u003cli\u003eFixes ClassTransformer.transform to throw Persistence API specific exception\u003c/li\u003e\n\u003cli\u003eAdds support for java.util.UUID and GenerationType.UUID\u003c/li\u003e\n\u003cli\u003eAdds CEILING, EXP, FLOOR, LN, POWER, ROUND, and SIGN numeric functions to Jakarta Persistence QL and ceiling(), exp(), floor(), ln(), power(),  round(), and sign() to Criteria API\u003c/li\u003e\n\u003cli\u003eAdds LOCAL DATE, LOCAL DATETIME, and LOCAL TIME functions to Jakarta Persistence QL and corresponding localDate(), localDateTime(), and localTime() to Criteria API\u003c/li\u003e\n\u003cli\u003eAdds EXTRACT function to Jakarta Persistence QL\u003c/li\u003e\n\u003cli\u003eAdds support for Expressions as conditions in Criteria CASE expressions\u003c/li\u003e\n\u003cli\u003eAdds missing definition of single_valued_embeddable_object_field in Jakarta Persistence QL BNF\u003c/li\u003e\n\u003cli\u003eClarifies mixing types of query input parameters\u003c/li\u003e\n\u003cli\u003eClarifies definition of the Basic type\u003c/li\u003e\n\u003cli\u003eClarifies the order of parameters in the LOCATE function\u003c/li\u003e\n\u003cli\u003eClarifies SqlResultSetMapping with multiple EntityResults and conflicting aliases\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/scottmarlow\"\u003e\u003ccode\u003e@​scottmarlow\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/m0mus\"\u003e\u003ccode\u003e@​m0mus\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/pzygielo\"\u003e\u003ccode\u003e@​pzygielo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hebo6\"\u003e\u003ccode\u003e@​hebo6\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/moghaddam\"\u003e\u003ccode\u003e@​moghaddam\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/manouti\"\u003e\u003ccode\u003e@​manouti\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/jbescos\"\u003e\u003ccode\u003e@​jbescos\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gavinking\"\u003e\u003ccode\u003e@​gavinking\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/dazey3\"\u003e\u003ccode\u003e@​dazey3\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/DmitriGit\"\u003e\u003ccode\u003e@​DmitriGit\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/sebersole\"\u003e\u003ccode\u003e@​sebersole\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eProject Board\u003c/strong\u003e: \u003ca href=\"https://github.com/eclipse-ee4j/jpa-api/projects/2\"\u003ehttps://github.com/eclipse-ee4j/jpa-api/projects/2\u003c/a\u003e\n\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/eclipse-ee4j/jpa-api/commits/3.1-3.1.0-RELEASE\"\u003ehttps://github.com/eclipse-ee4j/jpa-api/commits/3.1-3.1.0-RELEASE\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/jakartaee/persistence/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.h2database:h2` from 2.4.240 to 2.5.252\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/h2database/h2database/releases\"\u003ecom.h2database:h2's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 2.5.252\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003eversion-2.5.250\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/h2database/h2database/commit/f986838bbbf4941d2edcd5298b18c9936d1b7359\"\u003e\u003ccode\u003ef986838\u003c/code\u003e\u003c/a\u003e in preparation for a release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/h2database/h2database/commit/06c34a7fa288208ecabb5d670555fd807270bb2a\"\u003e\u003ccode\u003e06c34a7\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/h2database/h2database/issues/4418\"\u003e#4418\u003c/a\u003e from andreitokar/issues-4380-4376\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/h2database/h2database/commit/1aef3e0692b7379402b2a1a14e5223a8911e31ec\"\u003e\u003ccode\u003e1aef3e0\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://redirect.github.com/h2database/h2database/issues/4376\"\u003e#4376\u003c/a\u003e: Reading INFORMATION_SCHEMA.COLUMNS fails with a NPE while any material...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/h2database/h2database/commit/4bb8aee6bf4305a83e79b6a93e9e3781f904fed9\"\u003e\u003ccode\u003e4bb8aee\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://redirect.github.com/h2database/h2database/issues/4380\"\u003e#4380\u003c/a\u003e: creating a MATERIALIZED VIEW makes a persistent database permanently u...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/h2database/h2database/commit/95b6af03b8768d770e5dac1ae829b7c15301b38e\"\u003e\u003ccode\u003e95b6af0\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/h2database/h2database/issues/4417\"\u003e#4417\u003c/a\u003e from andreitokar/issue-4395\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/h2database/h2database/commit/6ec30b66b68a298d6cfc424aa77fec90ebf05199\"\u003e\u003ccode\u003e6ec30b6\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://redirect.github.com/h2database/h2database/issues/4395\"\u003e#4395\u003c/a\u003e disallow constraints between temporary and permanent tables\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/h2database/h2database/commit/0f0f85605084bd4eaad8f6a467ff802161048b60\"\u003e\u003ccode\u003e0f0f856\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/h2database/h2database/issues/4416\"\u003e#4416\u003c/a\u003e from andreitokar/issue-4405\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/h2database/h2database/commit/f718b764c6d53e160f94d05003eae81d554ec253\"\u003e\u003ccode\u003ef718b76\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://redirect.github.com/h2database/h2database/issues/4405\"\u003e#4405\u003c/a\u003e SecureFileStore.readFully() may skip decryption\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/h2database/h2database/commit/e231ff7def4c280ffb845cb0b6e92fb9686867d1\"\u003e\u003ccode\u003ee231ff7\u003c/code\u003e\u003c/a\u003e \u003ca href=\"https://redirect.github.com/h2database/h2database/issues/4405\"\u003e#4405\u003c/a\u003e SecureFileStore.readFully() may skip\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/h2database/h2database/commit/4da0d1d02b4e860d6c2e68ff2de0c11c0a19011c\"\u003e\u003ccode\u003e4da0d1d\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/h2database/h2database/issues/4415\"\u003e#4415\u003c/a\u003e from jjh75607/fix/log-sql-aarch64\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/h2database/h2database/compare/version-2.4.240...version-2.5.252\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `software.amazon.awssdk:bom` from 2.28.11 to 2.55.6\n\nUpdates `jakarta.servlet:jakarta.servlet-api` from 6.0.0 to 6.1.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/eclipse-ee4j/servlet-api/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.datatype:jackson-datatype-jsr310` from 2.17.2 to 2.22.3\n\nUpdates `com.tngtech.archunit:archunit-junit5` from 1.3.0 to 1.5.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/TNG/ArchUnit/releases\"\u003ecom.tngtech.archunit:archunit-junit5's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eArchUnit 1.5.1\u003c/h2\u003e\n\u003ch1\u003eBug fixes\u003c/h1\u003e\n\u003ch2\u003eCore\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003efix: include java.lang.IO in ACCESS_STANDARD_STREAMS (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1687\"\u003e#1687\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/arimu1\"\u003e\u003ccode\u003e@​arimu1\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003cli\u003eCount caught exception types as type dependencies (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1725\"\u003e#1725\u003c/a\u003e; by \u003ca href=\"https://github.com/schulzjo-tng\"\u003e\u003ccode\u003e@​schulzjo-tng\u003c/code\u003e\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003eInternal Improvements\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003epublish archunit-junit-relocation (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1684\"\u003e#1684\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/hankem\"\u003e\u003ccode\u003e@​hankem\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eArchUnit 1.5.0\u003c/h2\u003e\n\u003ch1\u003eEnhancements\u003c/h1\u003e\n\u003ch2\u003eCore\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSupport Java 27 / class file major version 71 (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1618\"\u003e#1618\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eImprove descriptions of \u003ccode\u003eJavaAccess.Predicates.originOwner\u003c/code\u003e and \u003ccode\u003eJavaAccess.Predicates.targetOwner\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1603\"\u003e#1603\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/StefanGraeber\"\u003e\u003ccode\u003e@​StefanGraeber\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003cli\u003eExpose information on sealed classes via \u003ccode\u003eJavaClass\u003c/code\u003e: \u003ccode\u003eisSealed()\u003c/code\u003e and \u003ccode\u003egetPermittedSubclasses()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1677\"\u003e#1677\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eConsider dependencies from caught exceptions (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1555\"\u003e#1555\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/bannmann\"\u003e\u003ccode\u003e@​bannmann\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eImportOption.DoNotIncludeTests\u003c/code\u003e and \u003ccode\u003eOnlyIncludeTests\u003c/code\u003e consider tests in custom Gradle source sets (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1660\"\u003e#1660\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/Develop-KIM\"\u003e\u003ccode\u003e@​Develop-KIM\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eLang\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eArchConditions\u003c/code\u003e offers new \u003ccode\u003eArchCondition\u0026lt;JavaClass\u0026gt; haveAnyDependenciesThat(DescribedPredicate\u0026lt;Dependency\u0026gt;)\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1580\"\u003e#1580\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/wakingrufus\"\u003e\u003ccode\u003e@​wakingrufus\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eLibrary\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003eArchitectureMetrics.lakosMetrics\u003c/code\u003e is computed much more performantly (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1629\"\u003e#1629\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/ThanosTsiamis\"\u003e\u003ccode\u003e@​ThanosTsiamis\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eTextFileBasedViolationStore\u003c/code\u003e is now thread-safe under parallel test execution (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1656\"\u003e#1656\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/kelunik\"\u003e\u003ccode\u003e@​kelunik\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eModuleDependency\u003c/code\u003e now provides stable descriptions (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1648\"\u003e#1648\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/DragonFSKY\"\u003e\u003ccode\u003e@​DragonFSKY\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eJUnit\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ccode\u003earchunit-junit6\u003c/code\u003e supports ArchUnit with JUnit 6 (\u003cdel\u003e\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1556\"\u003e#1556\u003c/a\u003e\u003c/del\u003e, \u003cdel\u003e\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1658\"\u003e#1658\u003c/a\u003e\u003c/del\u003e, \u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1659\"\u003e#1659\u003c/a\u003e; many thanks to \u003ca href=\"https://github.com/arukiidou\"\u003e\u003ccode\u003e@​arukiidou\u003c/code\u003e\u003c/a\u003e \u0026amp; \u003ca href=\"https://github.com/schulzjo-tng\"\u003e\u003ccode\u003e@​schulzjo-tng\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003cli\u003e\u003ccode\u003eAnalyzeClasses\u003c/code\u003e supports individual classes (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1569\"\u003e#1569\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/TheManWhoStaresAtCode\"\u003e\u003ccode\u003e@​TheManWhoStaresAtCode\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003cli\u003e\u003cem\u003ePreparation:\u003c/em\u003e \u003ccode\u003earchunit-junit:0.9.0\u003c/code\u003e (which was renamed with \u003ca href=\"https://github.com/TNG/ArchUnit/releases/tag/v0.9.0\"\u003eArchUnit 0.9.0\u003c/a\u003e) now relocates to \u003ccode\u003earchunit-junit4:0.9.0\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1673\"\u003e#1673\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/schulzjo-tng\"\u003e\u003ccode\u003e@​schulzjo-tng\u003c/code\u003e\u003c/a\u003e 👋) – will be published after \u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1684\"\u003e#1684\u003c/a\u003e 🙈\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eDocumentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDocument \u003ccode\u003ePriority\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1671\"\u003e#1671\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/TheManWhoStaresAtCode\"\u003e\u003ccode\u003e@​TheManWhoStaresAtCode\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003cli\u003eDocument Package Identifiers in User Guide (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1672\"\u003e#1672\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/TheManWhoStaresAtCode\"\u003e\u003ccode\u003e@​TheManWhoStaresAtCode\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch1\u003eInternal Improvements\u003c/h1\u003e\n\u003cul\u003e\n\u003cli\u003eText files now use UNIX line breaks (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1602\"\u003e#1602\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1611\"\u003e#1611\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/StefanGraeber\"\u003e\u003ccode\u003e@​StefanGraeber\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003cli\u003eUpdate Gradle from 8 to 9; build \u0026amp; test with JDK 25 (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1550\"\u003e#1550\u003c/a\u003e, and also \u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1612\"\u003e#1612\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1619\"\u003e#1619\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eSeparate integration tests by JUnit version (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1636\"\u003e#1636\u003c/a\u003e; many thanks to \u003ca href=\"https://github.com/schulzjo-tng\"\u003e\u003ccode\u003e@​schulzjo-tng\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003cli\u003eReplace \u003ccode\u003ejunit-dataprovider\u003c/code\u003e with \u003ccode\u003ejunit-jupiter-params\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1655\"\u003e#1655\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eArchUnit releases now update Maven examples (and Gradle wrapper) of \u003ca href=\"https://github.com/TNG/ArchUnit-Examples\"\u003eArchUnit-Examples\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1450\"\u003e#1450\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAvoid managing hamcrest dependency (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1467\"\u003e#1467\u003c/a\u003e; thanks to \u003ca href=\"https://github.com/TheManWhoStaresAtCode\"\u003e\u003ccode\u003e@​TheManWhoStaresAtCode\u003c/code\u003e\u003c/a\u003e 👋)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eArchUnit 1.4.2\u003c/h2\u003e\n\u003ch1\u003eEnhancements\u003c/h1\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TNG/ArchUnit/commit/6c2d659e5681b50541930d236a8c46aed5e44a5c\"\u003e\u003ccode\u003e6c2d659\u003c/code\u003e\u003c/a\u003e prepare release 1.5.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TNG/ArchUnit/commit/d5ff41705236bcf28e9a7d5cce6b13be0db57f12\"\u003e\u003ccode\u003ed5ff417\u003c/code\u003e\u003c/a\u003e set snapshot version to 1.5.1 in preparation of release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TNG/ArchUnit/commit/aee04c59826199d0b78ab8ea90faac075dae19a8\"\u003e\u003ccode\u003eaee04c5\u003c/code\u003e\u003c/a\u003e Update Gradle Wrapper from 9.7.1 to 9.8.0 (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1727\"\u003e#1727\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TNG/ArchUnit/commit/73535afce1abf70d758148ba507d2695080167ae\"\u003e\u003ccode\u003e73535af\u003c/code\u003e\u003c/a\u003e Update Gradle Wrapper from 9.7.1 to 9.8.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TNG/ArchUnit/commit/058f709a1579daca48b7d052ace91dc92f0d2055\"\u003e\u003ccode\u003e058f709\u003c/code\u003e\u003c/a\u003e Count caught exception types as type dependencies (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1732\"\u003e#1732\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1725\"\u003e#1725\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TNG/ArchUnit/commit/fbcc47c56d6461d0bb096324bfb4b7a277bf7fcf\"\u003e\u003ccode\u003efbcc47c\u003c/code\u003e\u003c/a\u003e Count caught exception types as type dependencies (\u003ca href=\"https://redirect.github.com/TNG/ArchUnit/issues/1732\"\u003e#1732\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TNG/ArchUnit/commit/e78e136dd8df91d4dcdcd9aa082c0fd6b925d8cc\"\u003e\u003ccode\u003ee78e136\u003c/code\u003e\u003c/a\u003e Bump io.github.ben-manes.versions from 0.63.0 to 0.64.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TNG/ArchUnit/commit/a0a8aff514d948615e7de2ed067e9f651a466a44\"\u003e\u003ccode\u003ea0a8aff\u003c/code\u003e\u003c/a\u003e Bump io.github.ben-manes.versions from 0.62.0 to 0.63.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TNG/ArchUnit/commit/d30f80da632d38ceb1bf24239579d1b2da803173\"\u003e\u003ccode\u003ed30f80d\u003c/code\u003e\u003c/a\u003e Bump io.github.ben-manes.versions from 0.61.0 to 0.62.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/TNG/ArchUnit/commit/22c0f6a5eebfa79ab24c376938d69af41d3e7cbd\"\u003e\u003ccode\u003e22c0f6a\u003c/code\u003e\u003c/a\u003e Bump actions/setup-java from 6.0.0 to 6.0.1\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/TNG/ArchUnit/compare/v1.3.0...v1.5.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `gradle-wrapper` from 9.5.1 to 9.8.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/gradle/gradle/releases\"\u003egradle-wrapper's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e9.8.0\u003c/h2\u003e\n\u003cp\u003eThe Gradle team is excited to announce Gradle 9.8.0.\u003c/p\u003e\n\u003cp\u003eHere are the highlights of this release:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eJava 27 support\u003c/li\u003e\n\u003cli\u003eMaven mirror settings reuse\u003c/li\u003e\n\u003cli\u003eLinked problem locations in build output\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003ca href=\"https://docs.gradle.org/9.8.0/release-notes.html\"\u003eRead the Release Notes\u003c/a\u003e\u003c/p\u003e\n\u003cp\u003eWe would like to thank the following community members for their contributions to this release of Gradle:\n\u003ca href=\"https://github.com/Gautam-aman\"\u003eAman Gautam\u003c/a\u003e,\n\u003ca href=\"https://github.com/Vampire\"\u003eBjörn Kautler\u003c/a\u003e,\n\u003ca href=\"https://github.com/Juneezee\"\u003eEng Zer Jun\u003c/a\u003e,\n\u003ca href=\"https://github.com/Hashim1999164\"\u003eHashim Khan\u003c/a\u003e,\n\u003ca href=\"https://github.com/jkrannich\"\u003eJulian Krannich\u003c/a\u003e,\n\u003ca href=\"https://github.com/youdie006\"\u003eKBS\u003c/a\u003e,\n\u003ca href=\"https://github.com/itsCodeTide\"\u003eLabh R Jethe\u003c/a\u003e,\n\u003ca href=\"https://github.com/doddi\"\u003eMark Dodgson\u003c/a\u003e,\n\u003ca href=\"https://github.com/kroune\"\u003eMaxim\u003c/a\u003e,\n\u003ca href=\"https://github.com/Develop-KIM\"\u003emonkey\u003c/a\u003e,\n\u003ca href=\"https://github.com/nataphon-ktsystems\"\u003enataphon-ktsystems\u003c/a\u003e,\n\u003ca href=\"https://github.com/paulk-asert\"\u003ePaul King\u003c/a\u003e,\n\u003ca href=\"https://github.com/qiu-tiandev\"\u003eQiu Tian\u003c/a\u003e,\n\u003ca href=\"https://github.com/sandeshgorde\"\u003erg_sandesh\u003c/a\u003e,\n\u003ca href=\"https://github.com/rpalcolea\"\u003eRoberto Perez Alcolea\u003c/a\u003e,\n\u003ca href=\"https://github.com/seanxuu\"\u003eSean\u003c/a\u003e,\n\u003ca href=\"https://github.com/Goooler\"\u003eZongle Wang\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eUpgrade instructions\u003c/h2\u003e\n\u003cp\u003eSwitch your build to use Gradle 9.8.0 by updating your wrapper:\u003c/p\u003e\n\u003cpre\u003e\u003ccode\u003e./gradlew :wrapper --gradle-version=9.8.0 \u0026amp;\u0026amp; ./gradlew :wrapper\r\n\u003c/code\u003e\u003c/pre\u003e\n\u003cp\u003eSee the Gradle \u003ca href=\"https://docs.gradle.org/9.8.0/userguide/upgrading_version_9.html\"\u003e9.x upgrade guide\u003c/a\u003e to learn about deprecations, breaking changes and other considerations when upgrading.\u003c/p\u003e\n\u003cp\u003eFor Java, Groovy, Kotlin and Android compatibility, see the \u003ca href=\"https://docs.gradle.org/9.8.0/userguide/compatibility.html\"\u003efull compatibility notes\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eReporting problems\u003c/h2\u003e\n\u003cp\u003eIf you find a problem with this release, please file a bug on \u003ca href=\"https://github.com/gradle/gradle/issues\"\u003eGitHub Issues\u003c/a\u003e adhering to our issue guidelines.\nIf you're not sure you're encountering a bug, please use the \u003ca href=\"https://discuss.gradle.org/c/help-discuss\"\u003eforum\u003c/a\u003e.\u003c/p\u003e\n\u003cp\u003eWe hope you will build happiness with Gradle, and we look forward to your feedback via \u003ca href=\"https://twitter.com/gradle\"\u003eTwitter\u003c/a\u003e or on \u003ca href=\"https://github.com/gradle\"\u003eGitHub\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003e9.8.0 RC3\u003c/h2\u003e\n\u003cp\u003eThe Gradle team is excited to announce Gradle 9.8.0 RC3.\u003c/p\u003e\n\u003cp\u003eHere are the highlights of this release:\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/a927be5e08efe79e0b87ada06c762dde6bb9f8b8\"\u003e\u003ccode\u003ea927be5\u003c/code\u003e\u003c/a\u003e Add the Develocity plugin back to the Android smoke tests (\u003ca href=\"https://redirect.github.com/gradle/gradle/issues/39273\"\u003e#39273\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/eaee500e6a2fff583b9d2b81039fc15ad887462d\"\u003e\u003ccode\u003eeaee500\u003c/code\u003e\u003c/a\u003e Add the Develocity plugin back to the Android smoke tests\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/189b672308d1e997fae46412673d04683d76b35a\"\u003e\u003ccode\u003e189b672\u003c/code\u003e\u003c/a\u003e Route everything still hitting Maven Central through the mirror (\u003ca href=\"https://redirect.github.com/gradle/gradle/issues/39257\"\u003e#39257\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/36b181477307fc6db0e16582f11daaeb7e34fc8e\"\u003e\u003ccode\u003e36b1814\u003c/code\u003e\u003c/a\u003e Add back mavenCentral to doc snippets\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/2740c2d9cd0a9ab42813be77241fdc264217b2ba\"\u003e\u003ccode\u003e2740c2d\u003c/code\u003e\u003c/a\u003e Update Gradle wrapper to version 9.8.0-rc-3 (\u003ca href=\"https://redirect.github.com/gradle/gradle/issues/39264\"\u003e#39264\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/209938316e373c847aa1a251ec14eeded3da468e\"\u003e\u003ccode\u003e2099383\u003c/code\u003e\u003c/a\u003e Update Gradle wrapper to version 9.8.0-rc-3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/c80202fbd1cc457d7f45f31fc488391c4a2e7984\"\u003e\u003ccode\u003ec80202f\u003c/code\u003e\u003c/a\u003e Route everything still hitting Maven Central through the mirror\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/3f6a53434a2cf4f33486af2ae5eabd1fc830352d\"\u003e\u003ccode\u003e3f6a534\u003c/code\u003e\u003c/a\u003e Fix when a best practice was introduced (\u003ca href=\"https://redirect.github.com/gradle/gradle/issues/39253\"\u003e#39253\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/9efc9eddac43f0795194e407c0ab2177a1d23cf9\"\u003e\u003ccode\u003e9efc9ed\u003c/code\u003e\u003c/a\u003e Fix when a best practice was introduced\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/gradle/gradle/commit/459e1433c60e4a604dd39ffe2c49e3606f70acda\"\u003e\u003ccode\u003e459e143\u003c/code\u003e\u003c/a\u003e Route integration test dependencies through the repository mirror (\u003ca href=\"https://redirect.github.com/gradle/gradle/issues/39239\"\u003e#39239\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/gradle/gradle/compare/v9.5.1...v9.8.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n","html_url":"https://github.com/MarceloGiazzon/NPDevGeneral/pull/171","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/MarceloGiazzon%2FNPDevGeneral/issues/171","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/171/packages"}},{"old_version":"2.19.2","new_version":"2.22.2","update_type":"minor","path":null,"pr_created_at":"2026-09-17T02:06:50.000Z","version_change":"2.19.2 → 2.22.2","issue":{"uuid":"5481940218","node_id":"PR_kwDOPeN7rM8AAAABD25YmQ","number":438,"state":"closed","title":"build(deps): bump the gradle-production-dependencies group across 3 directories with 25 updates","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-18T02:07:20.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-17T02:06:50.000Z","updated_at":"2026-09-18T02:07:22.000Z","time_to_close":86430,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"build(deps): bump","group_name":"gradle-production-dependencies","update_count":25,"packages":[{"name":"io.opentelemetry:opentelemetry-bom","old_version":"1.53.0","new_version":"1.66.0","repository_url":"https://github.com/open-telemetry/opentelemetry-java"},{"name":"io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom","old_version":"2.18.1","new_version":"2.31.1","repository_url":"https://github.com/open-telemetry/opentelemetry-java-instrumentation"},{"name":"com.google.api.grpc:proto-google-common-protos","old_version":"2.60.0","new_version":"2.76.0","repository_url":"https://github.com/googleapis/google-cloud-java"},{"name":"com.google.protobuf:protobuf-java","old_version":"4.31.1","new_version":"4.36.1","repository_url":"https://github.com/protocolbuffers/protobuf"},{"name":"com.google.protobuf:protoc","old_version":"4.31.1","new_version":"4.36.1","repository_url":"https://github.com/protocolbuffers/protobuf"},{"name":"io.grpc:grpc-protobuf","old_version":"1.74.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc-java"},{"name":"io.grpc:grpc-stub","old_version":"1.74.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc-java"},{"name":"io.grpc:grpc-netty","old_version":"1.74.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc-java"},{"name":"io.grpc:grpc-services","old_version":"1.74.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc-java"},{"name":"io.grpc:protoc-gen-grpc-java","old_version":"1.74.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc-java"},{"name":"io.grpc:grpc-stub","old_version":"1.74.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc-java"},{"name":"io.grpc:grpc-netty","old_version":"1.74.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc-java"},{"name":"io.grpc:grpc-services","old_version":"1.74.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc-java"},{"name":"org.apache.logging.log4j:log4j-core","old_version":"2.25.1","new_version":"2.26.1"},{"name":"dev.openfeature.contrib.providers:flagd","old_version":"0.11.14","new_version":"0.14.1","repository_url":"https://github.com/open-feature/java-sdk-contrib"},{"name":"dev.openfeature:sdk","old_version":"1.17.0","new_version":"1.22.1","repository_url":"https://github.com/open-feature/java-sdk"},{"name":"com.fasterxml.jackson.core:jackson-core","old_version":"2.19.2","new_version":"2.22.2","repository_url":"https://github.com/FasterXML/jackson-core"},{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.19.2","new_version":"2.22.2","repository_url":"https://github.com/FasterXML/jackson-databind"},{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.19.2","new_version":"2.22.2","repository_url":"https://github.com/FasterXML/jackson-databind"},{"name":"io.netty:netty-tcnative-boringssl-static","old_version":"2.0.72.Final","new_version":"2.0.84.Final","repository_url":"https://github.com/netty/netty-tcnative"},{"name":"com.google.protobuf:protoc","old_version":"4.31.1","new_version":"4.36.1","repository_url":"https://github.com/protocolbuffers/protobuf"},{"name":"io.grpc:protoc-gen-grpc-java","old_version":"1.74.0","new_version":"1.84.0","repository_url":"https://github.com/grpc/grpc-java"},{"name":"com.google.protobuf","old_version":"0.9.5","new_version":"0.10.0"},{"name":"com.github.ben-manes.versions","old_version":"0.52.0","new_version":"0.62.0"},{"name":"gradle-wrapper","old_version":"8.12.1","new_version":"9.7.1","repository_url":"https://github.com/gradle/gradle"}],"path":null,"ecosystem":"maven"},"body":"Bumps the gradle-production-dependencies group with 19 updates in the /src/ad directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [io.opentelemetry:opentelemetry-bom](https://github.com/open-telemetry/opentelemetry-java) | `1.53.0` | `1.66.0` |\n| [io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom](https://github.com/open-telemetry/opentelemetry-java-instrumentation) | `2.18.1` | `2.31.1` |\n| [com.google.api.grpc:proto-google-common-protos](https://github.com/googleapis/google-cloud-java) | `2.60.0` | `2.76.0` |\n| [com.google.protobuf:protobuf-java](https://github.com/protocolbuffers/protobuf) | `4.31.1` | `4.36.1` |\n| [com.google.protobuf:protoc](https://github.com/protocolbuffers/protobuf) | `4.31.1` | `4.36.1` |\n| [io.grpc:grpc-protobuf](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:grpc-stub](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:grpc-netty](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:grpc-services](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:protoc-gen-grpc-java](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:grpc-stub](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:grpc-netty](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:grpc-services](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| org.apache.logging.log4j:log4j-core | `2.25.1` | `2.26.1` |\n| [dev.openfeature.contrib.providers:flagd](https://github.com/open-feature/java-sdk-contrib) | `0.11.14` | `0.14.1` |\n| [dev.openfeature:sdk](https://github.com/open-feature/java-sdk) | `1.17.0` | `1.22.1` |\n| [com.fasterxml.jackson.core:jackson-core](https://github.com/FasterXML/jackson-core) | `2.19.2` | `2.22.2` |\n| [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) | `2.19.2` | `2.22.2` |\n| [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) | `2.19.2` | `2.22.2` |\n| [io.netty:netty-tcnative-boringssl-static](https://github.com/netty/netty-tcnative) | `2.0.72.Final` | `2.0.84.Final` |\n| [com.google.protobuf:protoc](https://github.com/protocolbuffers/protobuf) | `4.31.1` | `4.36.1` |\n| [io.grpc:protoc-gen-grpc-java](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| com.google.protobuf | `0.9.5` | `0.10.0` |\n| com.github.ben-manes.versions | `0.52.0` | `0.62.0` |\n| [gradle-wrapper](https://github.com/gradle/gradle) | `8.12.1` | `9.7.1` |\n\nBumps the gradle-production-dependencies group with 19 updates in the /src/fraud-detection directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [com.google.api.grpc:proto-google-common-protos](https://github.com/googleapis/google-cloud-java) | `2.60.0` | `2.76.0` |\n| [com.google.protobuf:protobuf-java](https://github.com/protocolbuffers/protobuf) | `4.31.1` | `4.36.1` |\n| com.google.protobuf:protobuf-kotlin | `4.31.1` | `4.36.1` |\n| [com.google.protobuf:protoc](https://github.com/protocolbuffers/protobuf) | `4.31.1` | `4.36.1` |\n| [io.grpc:grpc-protobuf](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:grpc-stub](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:grpc-netty](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:grpc-services](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:protoc-gen-grpc-java](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:grpc-stub](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:grpc-netty](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| [io.grpc:grpc-services](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| org.apache.logging.log4j:log4j-core | `2.25.1` | `2.26.1` |\n| [dev.openfeature.contrib.providers:flagd](https://github.com/open-feature/java-sdk-contrib) | `0.11.14` | `0.14.1` |\n| [dev.openfeature:sdk](https://github.com/open-feature/java-sdk) | `1.17.0` | `1.22.1` |\n| [com.google.protobuf:protoc](https://github.com/protocolbuffers/protobuf) | `4.31.1` | `4.36.1` |\n| [io.grpc:protoc-gen-grpc-java](https://github.com/grpc/grpc-java) | `1.74.0` | `1.84.0` |\n| com.google.protobuf | `0.9.5` | `0.10.0` |\n| [gradle-wrapper](https://github.com/gradle/gradle) | `8.12.1` | `9.7.1` |\n| org.apache.kafka:kafka-clients | `4.0.0` | `4.3.1` |\n| [io.opentelemetry:opentelemetry-api](https://github.com/open-telemetry/opentelemetry-java) | `1.53.0` | `1.66.0` |\n| [io.opentelemetry:opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-java) | `1.53.0` | `1.66.0` |\n| org.slf4j:slf4j-api | `2.0.17` | `2.0.19` |\n| com.google.protobuf:protobuf-kotlin | `4.31.1` | `4.36.1` |\n| jvm | `2.2.10` | `2.4.20` |\n\nBumps the gradle-production-dependencies group with 1 update in the /src/react-native-app/android directory: [gradle-wrapper](https://github.com/gradle/gradle).\n\nUpdates `io.opentelemetry:opentelemetry-bom` from 1.53.0 to 1.66.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/releases\"\u003eio.opentelemetry:opentelemetry-bom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 1.66.0\u003c/h2\u003e\n\u003ch3\u003eAPI\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eBaggage.fromContext()\u003c/code\u003e and \u003ccode\u003eBaggage.fromContextOrNull()\u003c/code\u003e to handle a \u003ccode\u003enull\u003c/code\u003e context (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8667\"\u003e#8667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDo not percent-encode W3C baggage metadata (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8682\"\u003e#8682\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eArrayIndexOutOfBoundsException\u003c/code\u003e in \u003ccode\u003eOtelEncodingUtils\u003c/code\u003e for invalid hex characters (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8748\"\u003e#8748\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSDK\u003c/h3\u003e\n\u003ch4\u003eTraces\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eRecord processed spans before export completes and reject new spans on shutdown in \u003ccode\u003eSpanProcessor\u003c/code\u003e self-observability instrumentation (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8735\"\u003e#8735\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eMetrics\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eImprove explicit bucket histogram contention performance (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8717\"\u003e#8717\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eLogs\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eRecord processed logs before export completes and reject new logs on shutdown in \u003ccode\u003eLogRecordProcessor\u003c/code\u003e self-observability instrumentation (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8698\"\u003e#8698\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eExporters\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eOTLP: Respect \u003ccode\u003eRetry-After\u003c/code\u003e in OTLP HTTP senders (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8633\"\u003e#8633\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Add \u003ccode\u003esetEnabledProtocols\u003c/code\u003e option to OTLP HTTP exporter builders (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8610\"\u003e#8610\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Reject mixing \u003ccode\u003ekeyManager\u003c/code\u003e and \u003ccode\u003esslContext\u003c/code\u003e in \u003ccode\u003eTlsConfigHelper\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8710\"\u003e#8710\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Fix \u003ccode\u003eOkHttpGrpcSender\u003c/code\u003e mTLS when using the platform default trust store (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8758\"\u003e#8758\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Suppress instrumentation of exporter requests in \u003ccode\u003eJdkHttpSender\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8757\"\u003e#8757\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Accept RFC 1123 hostnames in \u003ccode\u003eEndpointUtil.validateEndpoint\u003c/code\u003e for OkHttp senders (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8746\"\u003e#8746\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Include the number of affected items in exporter error logging (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8780\"\u003e#8780\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Add \u003ccode\u003etoString\u003c/code\u003e to \u003ccode\u003eOtlpJsonLogging{Span,Metric,LogRecord}Exporter\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8725\"\u003e#8725\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP Profiles: Improve JFR export example and align \u003ccode\u003eLinkData\u003c/code\u003e null-element handling with the spec (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8349\"\u003e#8349\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrometheus: Remove default host log warning in \u003ccode\u003ePrometheusHttpServerBuilder\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8679\"\u003e#8679\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePrometheus: Align UCUM byte unit conversions with the specification table (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8752\"\u003e#8752\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eExtensions\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eBREAKING\u003c/strong\u003e Declarative config: Rename generated model POJO setters from \u003ccode\u003ewith\u0026lt;Prop\u0026gt;\u003c/code\u003e to \u003ccode\u003eset\u0026lt;Prop\u0026gt;\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8742\"\u003e#8742\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeclarative config: Resolve experimental properties on stable APIs in generated model POJOs (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8654\"\u003e#8654\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeclarative config: Fix inverted \u003ccode\u003escope_info_enabled\u003c/code\u003e and \u003ccode\u003etarget_info_enabled\u003c/code\u003e flags in the Prometheus component provider (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8750\"\u003e#8750\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeclarative config: Support \u003ccode\u003eoutput_stream\u003c/code\u003e in \u003ccode\u003eotlp_file/development\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8676\"\u003e#8676\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eIncubator: Add \u003ccode\u003etoString\u003c/code\u003e to \u003ccode\u003eComposableAnnotatingSampler\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8645\"\u003e#8645\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eProject tooling\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemediate \u003ccode\u003ezizmor\u003c/code\u003e findings in GitHub Actions workflows (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8592\"\u003e#8592\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🙇 Thank you\u003c/h3\u003e\n\u003cp\u003eThis release was possible thanks to the following contributors who shared their brilliant ideas and awesome pull requests:\u003c/p\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/blob/main/CHANGELOG.md\"\u003eio.opentelemetry:opentelemetry-bom's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 1.66.0 (2026-09-11)\u003c/h2\u003e\n\u003ch3\u003eAPI\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ccode\u003eBaggage.fromContext()\u003c/code\u003e and \u003ccode\u003eBaggage.fromContextOrNull()\u003c/code\u003e to handle a \u003ccode\u003enull\u003c/code\u003e context\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8667\"\u003e#8667\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDo not percent-encode W3C baggage metadata\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8682\"\u003e#8682\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003eArrayIndexOutOfBoundsException\u003c/code\u003e in \u003ccode\u003eOtelEncodingUtils\u003c/code\u003e for invalid hex characters\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8748\"\u003e#8748\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eSDK\u003c/h3\u003e\n\u003ch4\u003eTraces\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eRecord processed spans before export completes and reject new spans on shutdown in\n\u003ccode\u003eSpanProcessor\u003c/code\u003e self-observability instrumentation\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8735\"\u003e#8735\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eMetrics\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eImprove explicit bucket histogram contention performance\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8717\"\u003e#8717\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eLogs\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eRecord processed logs before export completes and reject new logs on shutdown in\n\u003ccode\u003eLogRecordProcessor\u003c/code\u003e self-observability instrumentation\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8698\"\u003e#8698\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch4\u003eExporters\u003c/h4\u003e\n\u003cul\u003e\n\u003cli\u003eOTLP: Respect \u003ccode\u003eRetry-After\u003c/code\u003e in OTLP HTTP senders\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8633\"\u003e#8633\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Add \u003ccode\u003esetEnabledProtocols\u003c/code\u003e option to OTLP HTTP exporter builders\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8610\"\u003e#8610\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Reject mixing \u003ccode\u003ekeyManager\u003c/code\u003e and \u003ccode\u003esslContext\u003c/code\u003e in \u003ccode\u003eTlsConfigHelper\u003c/code\u003e\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8710\"\u003e#8710\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Fix \u003ccode\u003eOkHttpGrpcSender\u003c/code\u003e mTLS when using the platform default trust store\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8758\"\u003e#8758\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Suppress instrumentation of exporter requests in \u003ccode\u003eJdkHttpSender\u003c/code\u003e\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8757\"\u003e#8757\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Accept RFC 1123 hostnames in \u003ccode\u003eEndpointUtil.validateEndpoint\u003c/code\u003e for OkHttp senders\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8746\"\u003e#8746\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Include the number of affected items in exporter error logging\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8780\"\u003e#8780\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP: Add \u003ccode\u003etoString\u003c/code\u003e to \u003ccode\u003eOtlpJsonLogging{Span,Metric,LogRecord}Exporter\u003c/code\u003e\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8725\"\u003e#8725\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eOTLP Profiles: Improve JFR export example and align \u003ccode\u003eLinkData\u003c/code\u003e null-element handling with the\nspec (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/pull/8349\"\u003e#8349\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/commit/300a35830e29f94a173479c3c91dff72ae37c5fc\"\u003e\u003ccode\u003e300a358\u003c/code\u003e\u003c/a\u003e [release/v1.66.x] Prepare release 1.66.0 (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/issues/8799\"\u003e#8799\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/commit/dd711061cc7b1a5343168b43c112d7c687321fa4\"\u003e\u003ccode\u003edd71106\u003c/code\u003e\u003c/a\u003e Prepare for 1.66.0 release (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/issues/8795\"\u003e#8795\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/commit/9284265a4c059cb224f34f0bd58cb31fc6465d60\"\u003e\u003ccode\u003e9284265\u003c/code\u003e\u003c/a\u003e Manual 1.65.0 post release (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/issues/8794\"\u003e#8794\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/commit/10c7338cc9b10e29579fc4321408c3f6aa788c9a\"\u003e\u003ccode\u003e10c7338\u003c/code\u003e\u003c/a\u003e Align UCUM byte unit conversions with the specification table (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/issues/8752\"\u003e#8752\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/commit/bf1a64c3039a850900a02e47c0b599324af11b94\"\u003e\u003ccode\u003ebf1a64c\u003c/code\u003e\u003c/a\u003e Accept RFC 1123 hostnames in EndpointUtil.validateEndpoint (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/issues/8746\"\u003e#8746\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/commit/ab72956777e6f63e2ca44924b282838d7ca38220\"\u003e\u003ccode\u003eab72956\u003c/code\u003e\u003c/a\u003e Add number of affected items to Exporter error logging (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/issues/8780\"\u003e#8780\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/commit/275fe927de1ec59471d006fea23372474471eeb1\"\u003e\u003ccode\u003e275fe92\u003c/code\u003e\u003c/a\u003e Update dependency com.squareup.wire:wire-bom to v7 (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/issues/8793\"\u003e#8793\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/commit/050f481512b4850c5b539aac50bf1ba2b0cbfa5b\"\u003e\u003ccode\u003e050f481\u003c/code\u003e\u003c/a\u003e Remove unused parameter from B3 propagation integration tests (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/issues/8791\"\u003e#8791\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/commit/8d7bd65e03d5e1c5846b5c20d1c89a36899a7a97\"\u003e\u003ccode\u003e8d7bd65\u003c/code\u003e\u003c/a\u003e Improve explicit histogram contention performance (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/issues/8717\"\u003e#8717\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/commit/2c880d9dcd30798660f8ad8d55ed4c6d31092863\"\u003e\u003ccode\u003e2c880d9\u003c/code\u003e\u003c/a\u003e Rename inverted grpc detection test in GrpcJavaOtlpIntegrationTest (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java/issues/8790\"\u003e#8790\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java/compare/v1.53.0...v1.66.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom` from 2.18.1 to 2.31.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/releases\"\u003eio.opentelemetry.instrumentation:opentelemetry-instrumentation-bom's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 2.31.1\u003c/h2\u003e\n\u003cp\u003eThis release targets the OpenTelemetry SDK 1.65.0.\u003c/p\u003e\n\u003cp\u003eNote that many artifacts have the \u003ccode\u003e-alpha\u003c/code\u003e suffix attached to their version number, reflecting that they will continue to have breaking changes. Please see \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/blob/main/VERSIONING.md#opentelemetry-java-instrumentation-versioning\"\u003eVERSIONING.md\u003c/a\u003e for more details.\u003c/p\u003e\n\u003ch3\u003e🛠️ Bug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRestore stable semantic convention APIs to the compile classpaths of the Spring Boot autoconfigure and starter artifacts. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19754\"\u003e#19754\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 2.31.0\u003c/h2\u003e\n\u003cp\u003eThis release targets the OpenTelemetry SDK 1.65.0.\u003c/p\u003e\n\u003cp\u003eNote that many artifacts have the \u003ccode\u003e-alpha\u003c/code\u003e suffix attached to their version number, reflecting that they will continue to have breaking changes. Please see \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/blob/main/VERSIONING.md#opentelemetry-java-instrumentation-versioning\"\u003eVERSIONING.md\u003c/a\u003e for more details.\u003c/p\u003e\n\u003ch3\u003e⚠️ Breaking changes to non-stable APIs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemove the deprecated \u003ccode\u003eConfigPropertiesBackedConfigProvider\u003c/code\u003e and its \u003ccode\u003ecreate(ConfigProperties)\u003c/code\u003e compatibility API from the declarative config bridge. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19305\"\u003e#19305\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eStop exposing \u003ccode\u003eopentelemetry-instrumentation-api-incubator\u003c/code\u003e on library instrumentation compile classpaths. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19612\"\u003e#19612\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🚫 Deprecations\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eotel.instrumentation.experimental.span-suppression-strategy\u003c/code\u003e in favor of \u003ccode\u003eExperimental.setSpanSuppressionStrategy(...)\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19180\"\u003e#19180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eHostIdResource.REGISTRY_QUERY\u003c/code\u003e in favor of the absolute-path \u003ccode\u003ereg.exe\u003c/code\u003e lookup used by \u003ccode\u003eHostIdResource\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19293\"\u003e#19293\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eMessageOperation\u003c/code\u003e in favor of \u003ccode\u003eMessagingOperationType\u003c/code\u003e, and the \u003ccode\u003eMessageOperation\u003c/code\u003e overloads of \u003ccode\u003eMessagingAttributesExtractor\u003c/code\u003e, \u003ccode\u003eMessagingConsumerMetrics\u003c/code\u003e, \u003ccode\u003eMessagingProducerMetrics\u003c/code\u003e, \u003ccode\u003eMessagingSpanKindExtractor\u003c/code\u003e, and \u003ccode\u003eMessagingSpanNameExtractor\u003c/code\u003e in favor of the corresponding \u003ccode\u003eMessagingOperationType\u003c/code\u003e APIs. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19357\"\u003e#19357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eotel.traces.exporter=zipkin\u003c/code\u003e in favor of \u003ccode\u003eotel.traces.exporter=otlp\u003c/code\u003e, and \u003ccode\u003eotel.exporter.zipkin.endpoint\u003c/code\u003e in favor of \u003ccode\u003eotel.exporter.otlp.traces.endpoint\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19400\"\u003e#19400\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eOpenTelemetryMeterRegistryBuilder#setMicrometerHistogramGaugesEnabled(boolean)\u003c/code\u003e in favor of \u003ccode\u003eExperimental#setMicrometerHistogramGaugesEnabled(OpenTelemetryMeterRegistryBuilder, boolean)\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19404\"\u003e#19404\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate legacy gRPC metadata, messaging header, and servlet request-parameter capture properties and APIs in favor of selector-based \u003ccode\u003e.included\u003c/code\u003e / \u003ccode\u003e.excluded\u003c/code\u003e configuration and \u003ccode\u003eIncludeExclude\u003c/code\u003e APIs. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19494\"\u003e#19494\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19522\"\u003e#19522\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19523\"\u003e#19523\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19638\"\u003e#19638\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eotel.instrumentation.runtime-telemetry.experimental.prefer-jfr\u003c/code\u003e in favor of \u003ccode\u003eotel.instrumentation.runtime-telemetry.experimental.jfr-metrics.included\u003c/code\u003e, and \u003ccode\u003esetPreferJfrMetrics(...)\u003c/code\u003e in favor of \u003ccode\u003esetJfrMetrics(RuntimeTelemetryBuilder, IncludeExclude)\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19495\"\u003e#19495\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate boolean and capture-list configuration for MDC/context data, map messages, key-value pairs, logger context, Logstash markers, and structured arguments in favor of \u003ccode\u003e.included\u003c/code\u003e / \u003ccode\u003e.excluded\u003c/code\u003e selectors and \u003ccode\u003eIncludeExclude\u003c/code\u003e APIs. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19519\"\u003e#19519\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19520\"\u003e#19520\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19521\"\u003e#19521\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19599\"\u003e#19599\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19600\"\u003e#19600\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19605\"\u003e#19605\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19609\"\u003e#19609\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19610\"\u003e#19610\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate the declarative configuration field \u003ccode\u003egeneral.semconv_stability.opt_in\u003c/code\u003e in favor of \u003ccode\u003egeneral.stability_opt_in_list\u003c/code\u003e, and \u003ccode\u003egeneral.sanitization.url.sensitive_query_parameters/development\u003c/code\u003e in favor of \u003ccode\u003egeneral.sanitization.url.sensitive_query_parameters\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19561\"\u003e#19561\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eotel.instrumentation.graphql.add-operation-name-to-span-name.enabled\u003c/code\u003e in favor of \u003ccode\u003eotel.instrumentation.graphql.operation-name-in-span-name.enabled\u003c/code\u003e, and \u003ccode\u003eotel.instrumentation.runtime-telemetry.package-emitter.enabled\u003c/code\u003e / \u003ccode\u003ejars-per-second\u003c/code\u003e in favor of \u003ccode\u003eotel.instrumentation.runtime-telemetry.experimental.package-emitter.enabled\u003c/code\u003e / \u003ccode\u003ejars-per-second\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19573\"\u003e#19573\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate captured request and response header builder methods across HTTP library instrumentations in favor of selector-based \u003ccode\u003erequestHeaders(IncludeExclude)\u003c/code\u003e and \u003ccode\u003eresponseHeaders(IncludeExclude)\u003c/code\u003e APIs. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19598\"\u003e#19598\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19601\"\u003e#19601\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19602\"\u003e#19602\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19603\"\u003e#19603\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19604\"\u003e#19604\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19606\"\u003e#19606\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19607\"\u003e#19607\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19608\"\u003e#19608\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eotel.instrumentation.micrometer.histogram-gauges.enabled\u003c/code\u003e in favor of \u003ccode\u003eotel.instrumentation.micrometer.experimental.histogram-gauges.enabled\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19613\"\u003e#19613\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🌟 New javaagent instrumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd Apache Commons Pool 2 instrumentation for object pool metrics. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19091\"\u003e#19091\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd Apache HBase client 1.0 javaagent instrumentation. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19243\"\u003e#19243\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd Redisson connection pool metrics for 3.26+. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19392\"\u003e#19392\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd support for OpenTelemetry API 1.65 incubator metrics in the Java agent. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19456\"\u003e#19456\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd Tomcat DBCP 8.0 javaagent instrumentation for database pool metrics. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19472\"\u003e#19472\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e📈 Enhancements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAdd opt-in OSGi bundle metadata for selected instrumentation, API, and SDK extension artifacts so they can be consumed directly in OSGi runtimes. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/18995\"\u003e#18995\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdd \u003ccode\u003ecassandra.compaction.progress.completed\u003c/code\u003e and \u003ccode\u003ecassandra.compaction.progress.size\u003c/code\u003e gauges for in-flight Cassandra compactions. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19290\"\u003e#19290\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003ePreview the upcoming 3.0 messaging semantic conventions behind \u003ccode\u003eotel.semconv-stability.opt-in=messaging\u003c/code\u003e across AWS SQS and Lambda, JMS, Kafka, NATS, Pulsar, RabbitMQ, RocketMQ, Spring Integration, and Spring messaging instrumentations. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19347\"\u003e#19347\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19348\"\u003e#19348\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19349\"\u003e#19349\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19350\"\u003e#19350\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19351\"\u003e#19351\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19353\"\u003e#19353\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19354\"\u003e#19354\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19355\"\u003e#19355\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19356\"\u003e#19356\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19476\"\u003e#19476\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19477\"\u003e#19477\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19478\"\u003e#19478\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19479\"\u003e#19479\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19480\"\u003e#19480\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19481\"\u003e#19481\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19482\"\u003e#19482\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19486\"\u003e#19486\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19487\"\u003e#19487\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19499\"\u003e#19499\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19500\"\u003e#19500\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19504\"\u003e#19504\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19505\"\u003e#19505\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19507\"\u003e#19507\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19508\"\u003e#19508\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19535\"\u003e#19535\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19544\"\u003e#19544\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19565\"\u003e#19565\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19567\"\u003e#19567\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19639\"\u003e#19639\u003c/a\u003e, \u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19640\"\u003e#19640\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eUnder the upcoming 3.0 RPC semantic conventions behind \u003ccode\u003eotel.semconv-stability.opt-in=rpc\u003c/code\u003e, Dubbo requests to unknown services emit server spans even when decoding fails before \u003ccode\u003eDubboProtocol.getInvoker()\u003c/code\u003e, and record the original method in \u003ccode\u003erpc.method_original\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/16668\"\u003e#16668\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eLog4j context data now includes \u003ccode\u003ebaggage.*\u003c/code\u003e entries even when there is no current span. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19378\"\u003e#19378\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eWhen \u003ccode\u003eotel.instrumentation.common.v3-preview=true\u003c/code\u003e, the Micrometer bridge no longer exports \u003ccode\u003e.max\u003c/code\u003e gauges for \u003ccode\u003eTimer\u003c/code\u003e and \u003ccode\u003eDistributionSummary\u003c/code\u003e. (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19397\"\u003e#19397\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/blob/main/CHANGELOG.md\"\u003eio.opentelemetry.instrumentation:opentelemetry-instrumentation-bom's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eVersion 2.31.1 (2026-08-23)\u003c/h2\u003e\n\u003cp\u003eThis release targets the OpenTelemetry SDK 1.65.0.\u003c/p\u003e\n\u003cp\u003eNote that many artifacts have the \u003ccode\u003e-alpha\u003c/code\u003e suffix attached to their version\nnumber, reflecting that they will continue to have breaking changes. Please see\n\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/blob/main/VERSIONING.md#opentelemetry-java-instrumentation-versioning\"\u003eVERSIONING.md\u003c/a\u003e\nfor more details.\u003c/p\u003e\n\u003ch3\u003e🛠️ Bug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRestore stable semantic convention APIs to the compile classpaths of the Spring Boot\nautoconfigure and starter artifacts.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19754\"\u003e#19754\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eVersion 2.31.0 (2026-08-20)\u003c/h2\u003e\n\u003cp\u003eThis release targets the OpenTelemetry SDK 1.65.0.\u003c/p\u003e\n\u003cp\u003eNote that many artifacts have the \u003ccode\u003e-alpha\u003c/code\u003e suffix attached to their version\nnumber, reflecting that they will continue to have breaking changes. Please see\n\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/blob/main/VERSIONING.md#opentelemetry-java-instrumentation-versioning\"\u003eVERSIONING.md\u003c/a\u003e\nfor more details.\u003c/p\u003e\n\u003ch3\u003e⚠️ Breaking changes to non-stable APIs\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eRemove the deprecated \u003ccode\u003eConfigPropertiesBackedConfigProvider\u003c/code\u003e and its \u003ccode\u003ecreate(ConfigProperties)\u003c/code\u003e\ncompatibility API from the declarative config bridge.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19305\"\u003e#19305\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eStop exposing \u003ccode\u003eopentelemetry-instrumentation-api-incubator\u003c/code\u003e on library instrumentation compile\nclasspaths.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19612\"\u003e#19612\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e🚫 Deprecations\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eotel.instrumentation.experimental.span-suppression-strategy\u003c/code\u003e in favor of\n\u003ccode\u003eExperimental.setSpanSuppressionStrategy(...)\u003c/code\u003e.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19180\"\u003e#19180\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eHostIdResource.REGISTRY_QUERY\u003c/code\u003e in favor of the absolute-path \u003ccode\u003ereg.exe\u003c/code\u003e lookup used by\n\u003ccode\u003eHostIdResource\u003c/code\u003e.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19293\"\u003e#19293\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eMessageOperation\u003c/code\u003e in favor of \u003ccode\u003eMessagingOperationType\u003c/code\u003e, and the \u003ccode\u003eMessageOperation\u003c/code\u003e\noverloads of \u003ccode\u003eMessagingAttributesExtractor\u003c/code\u003e, \u003ccode\u003eMessagingConsumerMetrics\u003c/code\u003e,\n\u003ccode\u003eMessagingProducerMetrics\u003c/code\u003e, \u003ccode\u003eMessagingSpanKindExtractor\u003c/code\u003e, and \u003ccode\u003eMessagingSpanNameExtractor\u003c/code\u003e in\nfavor of the corresponding \u003ccode\u003eMessagingOperationType\u003c/code\u003e APIs.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19357\"\u003e#19357\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eotel.traces.exporter=zipkin\u003c/code\u003e in favor of \u003ccode\u003eotel.traces.exporter=otlp\u003c/code\u003e, and\n\u003ccode\u003eotel.exporter.zipkin.endpoint\u003c/code\u003e in favor of \u003ccode\u003eotel.exporter.otlp.traces.endpoint\u003c/code\u003e.\n(\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/pull/19400\"\u003e#19400\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eDeprecate \u003ccode\u003eOpenTelemetryMeterRegistryBuilder#setMicrometerHistogramGaugesEnabled(boolean)\u003c/code\u003e in\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/8ad06a082e051f366f19c16ad95a7b68edf30afd\"\u003e\u003ccode\u003e8ad06a0\u003c/code\u003e\u003c/a\u003e [release/v2.31.x] Prepare release 2.31.1 (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/19765\"\u003e#19765\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/e0306a2645a21a4506941b8e32370e985b11d5af\"\u003e\u003ccode\u003ee0306a2\u003c/code\u003e\u003c/a\u003e [release/v2.31.x] Prepare changelog for 2.31.1 (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/19760\"\u003e#19760\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/75576d4dc361ba4c36fc8eac57452cb8c6e8e5fe\"\u003e\u003ccode\u003e75576d4\u003c/code\u003e\u003c/a\u003e [release/v2.31.x] Retain semconv API for Spring artifacts until 3.0 (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/19754\"\u003e#19754\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/18da99bef6a5f1becdeb8091136f12c43742b9b7\"\u003e\u003ccode\u003e18da99b\u003c/code\u003e\u003c/a\u003e [release/v2.31.x] Prepare release 2.31.0 (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/19731\"\u003e#19731\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/dbe5c09ae9a2ab4709bdc2a87b1c90c1edd7b0d6\"\u003e\u003ccode\u003edbe5c09\u003c/code\u003e\u003c/a\u003e chore: update instrumentation list [automated] (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/19701\"\u003e#19701\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/1035b5ba36cd6fc1e81d6688c0f4306e708d9435\"\u003e\u003ccode\u003e1035b5b\u003c/code\u003e\u003c/a\u003e Change log for upcoming release + Improve automated release note drafting (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/1\"\u003e#1\u003c/a\u003e...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/64310fcbf8d0fae48578bdb5df07d404b30b96a6\"\u003e\u003ccode\u003e64310fc\u003c/code\u003e\u003c/a\u003e [jmx] add recommendation for naming percentile metrics (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/19727\"\u003e#19727\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/4225fbe18e61704e521473c54621a9634404d296\"\u003e\u003ccode\u003e4225fbe\u003c/code\u003e\u003c/a\u003e Update pinned latest dep versions (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/19720\"\u003e#19720\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/26c08ace6c3dcd3402498db10cb4dcf037cb2906\"\u003e\u003ccode\u003e26c08ac\u003c/code\u003e\u003c/a\u003e fix redisson connection pool leak on cancellation (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/19340\"\u003e#19340\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/commit/200efaef8b90b67227a4dc0058d665dd61392c23\"\u003e\u003ccode\u003e200efae\u003c/code\u003e\u003c/a\u003e Emit db.namespace for jedis 2.0 and 3.0 (\u003ca href=\"https://redirect.github.com/open-telemetry/opentelemetry-java-instrumentation/issues/19707\"\u003e#19707\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/open-telemetry/opentelemetry-java-instrumentation/compare/v2.18.1...v2.31.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.google.api.grpc:proto-google-common-protos` from 2.60.0 to 2.76.0\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/googleapis/google-cloud-java/blob/main/java-document-ai/CHANGELOG.md\"\u003ecom.google.api.grpc:proto-google-common-protos's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e2.76.0 (2025-08-13)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eNo change\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.75.0 (2025-08-08)\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eupdate dependency com.google.cloud:sdk-platform-java-config to v3.51.0 (\u003ca href=\"https://redirect.github.com/googleapis/google-cloud-java/issues/11695\"\u003e#11695\u003c/a\u003e) (\u003ca href=\"https://github.com/googleapis/google-cloud-java/commit/b82ce005c30551b8714099b7219b71bda85aa3a5\"\u003eb82ce00\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.74.0 (2025-07-30)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eNo change\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.73.0 (2025-07-28)\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eupdate dependency com.google.cloud:sdk-platform-java-config to v3.50.2 (\u003ca href=\"https://redirect.github.com/googleapis/google-cloud-java/issues/11680\"\u003e#11680\u003c/a\u003e) (\u003ca href=\"https://github.com/googleapis/google-cloud-java/commit/d1b99a706daa10c487b56edbb5170b41530628ca\"\u003ed1b99a7\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.72.0 (2025-07-11)\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eupdate dependency com.google.cloud:sdk-platform-java-config to v3.50.1 (\u003ca href=\"https://redirect.github.com/googleapis/google-cloud-java/issues/11655\"\u003e#11655\u003c/a\u003e) (\u003ca href=\"https://github.com/googleapis/google-cloud-java/commit/9b34528f85043049e3349fffc30bb2dbfe01836c\"\u003e9b34528\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.71.0 (2025-06-25)\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eupdate dependency com.google.cloud:sdk-platform-java-config to v3.50.0 (\u003ca href=\"https://redirect.github.com/googleapis/google-cloud-java/issues/11624\"\u003e#11624\u003c/a\u003e) (\u003ca href=\"https://github.com/googleapis/google-cloud-java/commit/a19f457d10f15437ac26ce379048ff8b3cc6be5d\"\u003ea19f457\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.69.0 (2025-06-16)\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eNo change\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e2.68.0 (2025-06-04)\u003c/h2\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eupdate dependency com.google.cloud:sdk-platform-java-config to v3.49.0 (\u003ca href=\"https://redirect.github.com/googleapis/google-cloud-java/issues/11603\"\u003e#11603\u003c/a\u003e) (\u003ca href=\"https://github.com/googleapis/google-cloud-java/commit/3ea506d86a54fae209e9971af7b4a8aa1f5997b9\"\u003e3ea506d\u003c/a\u003e)\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/googleapis/google-cloud-java/commits/gapic-generator-java/v2.76.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.google.protobuf:protobuf-java` from 4.31.1 to 4.36.1\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/protocolbuffers/protobuf/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.google.protobuf:protoc` from 4.31.1 to 4.36.1\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/protocolbuffers/protobuf/commits\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `io.grpc:grpc-protobuf` from 1.74.0 to 1.84.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/grpc/grpc-java/releases\"\u003eio.grpc:grpc-protobuf's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eV1.84.0\u003c/h2\u003e\n\u003cp\u003eIn this release we drop support for Android API level 23 or lower (Marshmallow or earlier), following \u003ca href=\"https://support.google.com/googleplay/answer/9037938?hl=en\"\u003eGoogle Play Service’s now requiring a minimum of API level 24\u003c/a\u003e (Android 7.0 Nougat).\u003c/p\u003e\n\u003ch3\u003eAPI Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003exds: Supports injecting custom LDS Resource Name Resolvers (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12925\"\u003e#12925\u003c/a\u003e) (ac02c6f37)\u003c/li\u003e\n\u003cli\u003exds: Add support for creating \u003ccode\u003eXdsServerBuilder\u003c/code\u003e with \u003ccode\u003eSocketAddress\u003c/code\u003ees (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12925\"\u003e#12925\u003c/a\u003e) (ac02c6f37)\u003c/li\u003e\n\u003cli\u003eapi: Add a Supplier overload to Context (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12935\"\u003e#12935\u003c/a\u003e) (696653600)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBehavior Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecore: update SPIFFE certificate extraction to comply with X509-SVID spec (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12961\"\u003e#12961\u003c/a\u003e) (96807d898)\u003cbr /\u003e\nIgnore all but the first certificate if the x5c JWK parameter contains multiple values.\u003cbr /\u003e\nSkip the JWK entry instead of stopping execution or throwing when x5c is missing or contains an empty list, complying with the requirement that entries without x5c must be ignored.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecore: reference-count shared transport factory for OOB channels (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12985\"\u003e#12985\u003c/a\u003e) (72c6e5f91)\u003cbr /\u003e\nFixes a bug whereby an OOB channel shutdown incorrectly shut down the shared transport factory with the main channel, and the main channel was unable to create subchannels anymore and faced an exception in doing so.\u003c/li\u003e\n\u003cli\u003exds: Fix \u003ccode\u003eshutdownNow()\u003c/code\u003e becoming a no-op after \u003ccode\u003eshutdown()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12982\"\u003e#12982\u003c/a\u003e) (3cb700719)\u003c/li\u003e\n\u003cli\u003exds: Add Http11ProxyUpstreamTransport to MessagePrinter (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12971\"\u003e#12971\u003c/a\u003e) (d49a589f4)\u003c/li\u003e\n\u003cli\u003ecore, xds: Append child channel configurators instead of overwriting (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/pull/12921\"\u003e#12921\u003c/a\u003e) (296c007c1) Chains multiple childChannelConfigurator() calls instead of overwriting them in ManagedChannelImplBuilder and XdsServerBuilder, ensuring all configurators are preserved and executed when child channels are created.\u003c/li\u003e\n\u003cli\u003erls: Implement stale_header_data caching and propagation in RLS (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/pull/12972\"\u003e#12972\u003c/a\u003e) (7843bd437) Caches header_data received in RouteLookupResponse and sends it back as stale_header_data in RouteLookupRequest when refreshing stale cache entries, complying with the RLS specification.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eImprovements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003enetty: Fix client-initiated stream limit bypass in NettyServerHandler (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12933\"\u003e#12933\u003c/a\u003e) (56205f91c) Configure max active streams limit directly upon \u003ccode\u003eDefaultHttp2Connection\u003c/code\u003e initialization. Because \u003ccode\u003eNettyServerHandler\u003c/code\u003e instantiates \u003ccode\u003eDefaultHttp2Connection\u003c/code\u003e directly rather than using Netty's \u003ccode\u003eAbstractHttp2ConnectionHandlerBuilder\u003c/code\u003e, it missed Netty's built-in \u003ca href=\"https://github.com/advisories/GHSA-5x3r-wrvg-rp6q\"\u003eCVE-2026-47244\u003c/a\u003e patch. This left a pre-handshake window where the server's local connection allowed up to Integer.MAX_VALUE active client-initiated streams until a SETTINGS_ACK was received. Enforcing the limit proactively at startup closes this vulnerability window and prevents client-initiated stream floods / resource exhaustion.\u003c/li\u003e\n\u003cli\u003eservlet: \u003ccode\u003eAsyncServletOutputStreamWriter\u003c/code\u003e detect and handle write when not ready (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12732\"\u003e#12732\u003c/a\u003e) (46f308051) In highly concurrent scenarios, cached servlet container ready to write state can become  stale. The servlet container may have already transitioned to a 'not ready' state, but the corresponding callback has not yet updated gRPC's internal state. This fix makes the ready state to be evaluated explicitly before attempting to write directly to the servlet output stream.\u003c/li\u003e\n\u003cli\u003eokhttp: Move connection window update before stream termination logic (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12990\"\u003e#12990\u003c/a\u003e) (0f859c3bb) By RFC 9113, section 6.9, receivers must take frames into account for flow control even if they're errored. This change moves the stream error response logic after connection window updates\u003c/li\u003e\n\u003cli\u003ecore: Coalesce Contiguous Small Buffers for ReadableBuffer to prevent OOM (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12924\"\u003e#12924\u003c/a\u003e) (0585d481a)\u003c/li\u003e\n\u003cli\u003es2a: Default to Post Quantum Cryptography key exchange group (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12894\"\u003e#12894\u003c/a\u003e) (bc01994b7)\u003c/li\u003e\n\u003cli\u003ebinder: Let servers load their SecurityPolicy asynchronously (9fdef96dc)\u003c/li\u003e\n\u003cli\u003ebinder: normalize failed auth future status message (9ffa1e1b7)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecompiler: Update maximum supported edition to EDITION_2026 (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12945\"\u003e#12945\u003c/a\u003e) (6ccd0658e). Update the maximum supported edition in the Java gRPC compiler plugin to EDITION_2026 when compiling against Protobuf version 7.35.0 (v35.0) or later.\u003c/li\u003e\n\u003cli\u003eapi: Bump Context to JDK 8 (5d0a012fa)\u003c/li\u003e\n\u003cli\u003enetty: Upgrade Netty to 4.2.16 and netty-tcnative to 2.0.81 (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/pull/12969\"\u003e#12969\u003c/a\u003e) (1bc2f5a34)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eapi: Better explain the executors and how to configure them (ee08f5337)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNew Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecore, opentelemetry: Implement LB Delay Observability (Proposal A121) (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/pull/12807\"\u003e#12807\u003c/a\u003e) (073fd5ea1) Implements attempt-level RPC delay observability across the core delayed transport, built-in load balancers (pick_first, round_robin), RLS, and xDS policies, aligned with \u003ca href=\"https://redirect.github.com/grpc/proposal/pull/556\"\u003egRFC A121\u003c/a\u003e. Adds LoadBalancer.PickResult.withNoResult(delayType, delayReason) and delay tracing callbacks on ClientStreamTracer. Records attempt delay duration metrics (grpc.client.attempt.delay.duration) and child tracing spans (\u0026quot;Attempt Delay\u0026quot;) via the OpenTelemetry plugin.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eThanks to\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/b3838c0ce83152138aff3979c832225280d7a8d6\"\u003e\u003ccode\u003eb3838c0\u003c/code\u003e\u003c/a\u003e Bump version to 1.84.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/eb21854905d7e35c5e633543e39f46d9590fc327\"\u003e\u003ccode\u003eeb21854\u003c/code\u003e\u003c/a\u003e Update README etc to reference 1.84.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/118cb68ed152ab1c203137a6c2eb91c3075ddfcb\"\u003e\u003ccode\u003e118cb68\u003c/code\u003e\u003c/a\u003e xds: Make RawMessageClientInterceptor conditional on ext_proc flags (v1.84.x ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/e9cfe32b929be82adbe2f05d64e9cf1f28225ad9\"\u003e\u003ccode\u003ee9cfe32\u003c/code\u003e\u003c/a\u003e Revert \u0026quot;Implement gRFC A97: xDS JWT Call Credentials (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12951\"\u003e#12951\u003c/a\u003e)\u0026quot; (v1.84.x backp...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/cb66582711b2b4196b6a6135a13c746f56d0b9b1\"\u003e\u003ccode\u003ecb66582\u003c/code\u003e\u003c/a\u003e build: Remove global setting to allow empty checksums for Choco (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12993\"\u003e#12993\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/0f859c3bb69bbf229c39194ff433a095c630e31c\"\u003e\u003ccode\u003e0f859c3\u003c/code\u003e\u003c/a\u003e okhttp: Move connection window update before stream termination logic (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12990\"\u003e#12990\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/292a361472e0afe317cdfa190dcf77c649bb6338\"\u003e\u003ccode\u003e292a361\u003c/code\u003e\u003c/a\u003e binder,cronet: Handle double-ClientTransportFactory.close()\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/7843bd437a38e85c2a3a40a8b9e61fc42d65edbc\"\u003e\u003ccode\u003e7843bd4\u003c/code\u003e\u003c/a\u003e rls: implement stale_header_data caching and propagation in RLS (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12972\"\u003e#12972\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/3cb7007194443a2fb303cc72fca7b9274b7a29f0\"\u003e\u003ccode\u003e3cb7007\u003c/code\u003e\u003c/a\u003e xds: Fix \u003ccode\u003eshutdownNow()\u003c/code\u003e becoming a no-op after \u003ccode\u003eshutdown()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12982\"\u003e#12982\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/ab104f8b3f610b588ecc7bafa0502b3b69abfc62\"\u003e\u003ccode\u003eab104f8\u003c/code\u003e\u003c/a\u003e compiler: add retry loop and enable allowEmptyChecksums on Windows (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12962\"\u003e#12962\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/grpc/grpc-java/compare/v1.74.0...v1.84.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `io.grpc:grpc-stub` from 1.74.0 to 1.84.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/grpc/grpc-java/releases\"\u003eio.grpc:grpc-stub's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eV1.84.0\u003c/h2\u003e\n\u003cp\u003eIn this release we drop support for Android API level 23 or lower (Marshmallow or earlier), following \u003ca href=\"https://support.google.com/googleplay/answer/9037938?hl=en\"\u003eGoogle Play Service’s now requiring a minimum of API level 24\u003c/a\u003e (Android 7.0 Nougat).\u003c/p\u003e\n\u003ch3\u003eAPI Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003exds: Supports injecting custom LDS Resource Name Resolvers (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12925\"\u003e#12925\u003c/a\u003e) (ac02c6f37)\u003c/li\u003e\n\u003cli\u003exds: Add support for creating \u003ccode\u003eXdsServerBuilder\u003c/code\u003e with \u003ccode\u003eSocketAddress\u003c/code\u003ees (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12925\"\u003e#12925\u003c/a\u003e) (ac02c6f37)\u003c/li\u003e\n\u003cli\u003eapi: Add a Supplier overload to Context (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12935\"\u003e#12935\u003c/a\u003e) (696653600)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBehavior Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecore: update SPIFFE certificate extraction to comply with X509-SVID spec (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12961\"\u003e#12961\u003c/a\u003e) (96807d898)\u003cbr /\u003e\nIgnore all but the first certificate if the x5c JWK parameter contains multiple values.\u003cbr /\u003e\nSkip the JWK entry instead of stopping execution or throwing when x5c is missing or contains an empty list, complying with the requirement that entries without x5c must be ignored.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecore: reference-count shared transport factory for OOB channels (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12985\"\u003e#12985\u003c/a\u003e) (72c6e5f91)\u003cbr /\u003e\nFixes a bug whereby an OOB channel shutdown incorrectly shut down the shared transport factory with the main channel, and the main channel was unable to create subchannels anymore and faced an exception in doing so.\u003c/li\u003e\n\u003cli\u003exds: Fix \u003ccode\u003eshutdownNow()\u003c/code\u003e becoming a no-op after \u003ccode\u003eshutdown()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12982\"\u003e#12982\u003c/a\u003e) (3cb700719)\u003c/li\u003e\n\u003cli\u003exds: Add Http11ProxyUpstreamTransport to MessagePrinter (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12971\"\u003e#12971\u003c/a\u003e) (d49a589f4)\u003c/li\u003e\n\u003cli\u003ecore, xds: Append child channel configurators instead of overwriting (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/pull/12921\"\u003e#12921\u003c/a\u003e) (296c007c1) Chains multiple childChannelConfigurator() calls instead of overwriting them in ManagedChannelImplBuilder and XdsServerBuilder, ensuring all configurators are preserved and executed when child channels are created.\u003c/li\u003e\n\u003cli\u003erls: Implement stale_header_data caching and propagation in RLS (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/pull/12972\"\u003e#12972\u003c/a\u003e) (7843bd437) Caches header_data received in RouteLookupResponse and sends it back as stale_header_data in RouteLookupRequest when refreshing stale cache entries, complying with the RLS specification.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eImprovements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003enetty: Fix client-initiated stream limit bypass in NettyServerHandler (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12933\"\u003e#12933\u003c/a\u003e) (56205f91c) Configure max active streams limit directly upon \u003ccode\u003eDefaultHttp2Connection\u003c/code\u003e initialization. Because \u003ccode\u003eNettyServerHandler\u003c/code\u003e instantiates \u003ccode\u003eDefaultHttp2Connection\u003c/code\u003e directly rather than using Netty's \u003ccode\u003eAbstractHttp2ConnectionHandlerBuilder\u003c/code\u003e, it missed Netty's built-in \u003ca href=\"https://github.com/advisories/GHSA-5x3r-wrvg-rp6q\"\u003eCVE-2026-47244\u003c/a\u003e patch. This left a pre-handshake window where the server's local connection allowed up to Integer.MAX_VALUE active client-initiated streams until a SETTINGS_ACK was received. Enforcing the limit proactively at startup closes this vulnerability window and prevents client-initiated stream floods / resource exhaustion.\u003c/li\u003e\n\u003cli\u003eservlet: \u003ccode\u003eAsyncServletOutputStreamWriter\u003c/code\u003e detect and handle write when not ready (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12732\"\u003e#12732\u003c/a\u003e) (46f308051) In highly concurrent scenarios, cached servlet container ready to write state can become  stale. The servlet container may have already transitioned to a 'not ready' state, but the corresponding callback has not yet updated gRPC's internal state. This fix makes the ready state to be evaluated explicitly before attempting to write directly to the servlet output stream.\u003c/li\u003e\n\u003cli\u003eokhttp: Move connection window update before stream termination logic (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12990\"\u003e#12990\u003c/a\u003e) (0f859c3bb) By RFC 9113, section 6.9, receivers must take frames into account for flow control even if they're errored. This change moves the stream error response logic after connection window updates\u003c/li\u003e\n\u003cli\u003ecore: Coalesce Contiguous Small Buffers for ReadableBuffer to prevent OOM (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12924\"\u003e#12924\u003c/a\u003e) (0585d481a)\u003c/li\u003e\n\u003cli\u003es2a: Default to Post Quantum Cryptography key exchange group (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12894\"\u003e#12894\u003c/a\u003e) (bc01994b7)\u003c/li\u003e\n\u003cli\u003ebinder: Let servers load their SecurityPolicy asynchronously (9fdef96dc)\u003c/li\u003e\n\u003cli\u003ebinder: normalize failed auth future status message (9ffa1e1b7)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDependencies\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecompiler: Update maximum supported edition to EDITION_2026 (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12945\"\u003e#12945\u003c/a\u003e) (6ccd0658e). Update the maximum supported edition in the Java gRPC compiler plugin to EDITION_2026 when compiling against Protobuf version 7.35.0 (v35.0) or later.\u003c/li\u003e\n\u003cli\u003eapi: Bump Context to JDK 8 (5d0a012fa)\u003c/li\u003e\n\u003cli\u003enetty: Upgrade Netty to 4.2.16 and netty-tcnative to 2.0.81 (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/pull/12969\"\u003e#12969\u003c/a\u003e) (1bc2f5a34)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eDocumentation\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eapi: Better explain the executors and how to configure them (ee08f5337)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eNew Features\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecore, opentelemetry: Implement LB Delay Observability (Proposal A121) (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/pull/12807\"\u003e#12807\u003c/a\u003e) (073fd5ea1) Implements attempt-level RPC delay observability across the core delayed transport, built-in load balancers (pick_first, round_robin), RLS, and xDS policies, aligned with \u003ca href=\"https://redirect.github.com/grpc/proposal/pull/556\"\u003egRFC A121\u003c/a\u003e. Adds LoadBalancer.PickResult.withNoResult(delayType, delayReason) and delay tracing callbacks on ClientStreamTracer. Records attempt delay duration metrics (grpc.client.attempt.delay.duration) and child tracing spans (\u0026quot;Attempt Delay\u0026quot;) via the OpenTelemetry plugin.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eThanks to\u003c/h3\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/b3838c0ce83152138aff3979c832225280d7a8d6\"\u003e\u003ccode\u003eb3838c0\u003c/code\u003e\u003c/a\u003e Bump version to 1.84.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/eb21854905d7e35c5e633543e39f46d9590fc327\"\u003e\u003ccode\u003eeb21854\u003c/code\u003e\u003c/a\u003e Update README etc to reference 1.84.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/118cb68ed152ab1c203137a6c2eb91c3075ddfcb\"\u003e\u003ccode\u003e118cb68\u003c/code\u003e\u003c/a\u003e xds: Make RawMessageClientInterceptor conditional on ext_proc flags (v1.84.x ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/e9cfe32b929be82adbe2f05d64e9cf1f28225ad9\"\u003e\u003ccode\u003ee9cfe32\u003c/code\u003e\u003c/a\u003e Revert \u0026quot;Implement gRFC A97: xDS JWT Call Credentials (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12951\"\u003e#12951\u003c/a\u003e)\u0026quot; (v1.84.x backp...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/cb66582711b2b4196b6a6135a13c746f56d0b9b1\"\u003e\u003ccode\u003ecb66582\u003c/code\u003e\u003c/a\u003e build: Remove global setting to allow empty checksums for Choco (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12993\"\u003e#12993\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/0f859c3bb69bbf229c39194ff433a095c630e31c\"\u003e\u003ccode\u003e0f859c3\u003c/code\u003e\u003c/a\u003e okhttp: Move connection window update before stream termination logic (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12990\"\u003e#12990\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/292a361472e0afe317cdfa190dcf77c649bb6338\"\u003e\u003ccode\u003e292a361\u003c/code\u003e\u003c/a\u003e binder,cronet: Handle double-ClientTransportFactory.close()\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/7843bd437a38e85c2a3a40a8b9e61fc42d65edbc\"\u003e\u003ccode\u003e7843bd4\u003c/code\u003e\u003c/a\u003e rls: implement stale_header_data caching and propagation in RLS (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12972\"\u003e#12972\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/3cb7007194443a2fb303cc72fca7b9274b7a29f0\"\u003e\u003ccode\u003e3cb7007\u003c/code\u003e\u003c/a\u003e xds: Fix \u003ccode\u003eshutdownNow()\u003c/code\u003e becoming a no-op after \u003ccode\u003eshutdown()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12982\"\u003e#12982\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/grpc/grpc-java/commit/ab104f8b3f610b588ecc7bafa0502b3b69abfc62\"\u003e\u003ccode\u003eab104f8\u003c/code\u003e\u003c/a\u003e compiler: add retry loop and enable allowEmptyChecksums on Windows (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12962\"\u003e#12962\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/grpc/grpc-java/compare/v1.74.0...v1.84.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `io.grpc:grpc-netty` from 1.74.0 to 1.84.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/grpc/grpc-java/releases\"\u003eio.grpc:grpc-netty's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eV1.84.0\u003c/h2\u003e\n\u003cp\u003eIn this release we drop support for Android API level 23 or lower (Marshmallow or earlier), following \u003ca href=\"https://support.google.com/googleplay/answer/9037938?hl=en\"\u003eGoogle Play Service’s now requiring a minimum of API level 24\u003c/a\u003e (Android 7.0 Nougat).\u003c/p\u003e\n\u003ch3\u003eAPI Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003exds: Supports injecting custom LDS Resource Name Resolvers (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12925\"\u003e#12925\u003c/a\u003e) (ac02c6f37)\u003c/li\u003e\n\u003cli\u003exds: Add support for creating \u003ccode\u003eXdsServerBuilder\u003c/code\u003e with \u003ccode\u003eSocketAddress\u003c/code\u003ees (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12925\"\u003e#12925\u003c/a\u003e) (ac02c6f37)\u003c/li\u003e\n\u003cli\u003eapi: Add a Supplier overload to Context (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12935\"\u003e#12935\u003c/a\u003e) (696653600)\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBehavior Changes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecore: update SPIFFE certificate extraction to comply with X509-SVID spec (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12961\"\u003e#12961\u003c/a\u003e) (96807d898)\u003cbr /\u003e\nIgnore all but the first certificate if the x5c JWK parameter contains multiple values.\u003cbr /\u003e\nSkip the JWK entry instead of stopping execution or throwing when x5c is missing or contains an empty list, complying with the requirement that entries without x5c must be ignored.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eBug Fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003ecore: reference-count shared transport factory for OOB channels (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12985\"\u003e#12985\u003c/a\u003e) (72c6e5f91)\u003cbr /\u003e\nFixes a bug whereby an OOB channel shutdown incorrectly shut down the shared transport factory with the main channel, and the main channel was unable to create subchannels anymore and faced an exception in doing so.\u003c/li\u003e\n\u003cli\u003exds: Fix \u003ccode\u003eshutdownNow()\u003c/code\u003e becoming a no-op after \u003ccode\u003eshutdown()\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12982\"\u003e#12982\u003c/a\u003e) (3cb700719)\u003c/li\u003e\n\u003cli\u003exds: Add Http11ProxyUpstreamTransport to MessagePrinter (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12971\"\u003e#12971\u003c/a\u003e) (d49a589f4)\u003c/li\u003e\n\u003cli\u003ecore, xds: Append child channel configurators instead of overwriting (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/pull/12921\"\u003e#12921\u003c/a\u003e) (296c007c1) Chains multiple childChannelConfigurator() calls instead of overwriting them in ManagedChannelImplBuilder and XdsServerBuilder, ensuring all configurators are preserved and executed when child channels are created.\u003c/li\u003e\n\u003cli\u003erls: Implement stale_header_data caching and propagation in RLS (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/pull/12972\"\u003e#12972\u003c/a\u003e) (7843bd437) Caches header_data received in RouteLookupResponse and sends it back as stale_header_data in RouteLookupRequest when refreshing stale cache entries, complying with the RLS specification.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003eImprovements\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003enetty: Fix client-initiated stream limit bypass in NettyServerHandler (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12933\"\u003e#12933\u003c/a\u003e) (56205f91c) Configure max active streams limit directly upon \u003ccode\u003eDefaultHttp2Connection\u003c/code\u003e initialization. Because \u003ccode\u003eNettyServerHandler\u003c/code\u003e instantiates \u003ccode\u003eDefaultHttp2Connection\u003c/code\u003e directly rather than using Netty's \u003ccode\u003eAbstractHttp2ConnectionHandlerBuilder\u003c/code\u003e, it missed Netty's built-in \u003ca href=\"https://github.com/advisories/GHSA-5x3r-wrvg-rp6q\"\u003eCVE-2026-47244\u003c/a\u003e patch. This left a pre-handshake window where the server's local connection allowed up to Integer.MAX_VALUE active client-initiated streams until a SETTINGS_ACK was received. Enforcing the limit proactively at startup closes this vulnerability window and prevents client-initiated stream floods / resource exhaustion.\u003c/li\u003e\n\u003cli\u003eservlet: \u003ccode\u003eAsyncServletOutputStreamWriter\u003c/code\u003e detect and handle write when not ready (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12732\"\u003e#12732\u003c/a\u003e) (46f308051) In highly concurrent scenarios, cached servlet container ready to write state can become  stale. The servlet container may have already transitioned to a 'not ready' state, but the corresponding callback has not yet updated gRPC's internal state. This fix makes the ready state to be evaluated explicitly before attempting to write directly to the servlet output stream.\u003c/li\u003e\n\u003cli\u003eokhttp: Move connection window update before stream termination logic (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12990\"\u003e#12990\u003c/a\u003e) (0f859c3bb) By RFC 9113, section 6.9, receivers must take frames into account for flow control even if they're errored. This change moves the stream error response logic after connection window updates\u003c/li\u003e\n\u003cli\u003ecore: Coalesce Contiguous Small Buffers for ReadableBuffer to prevent OOM (\u003ca href=\"https://redirect.github.com/grpc/grpc-java/issues/12924\"\u003e#12924\u003c/a\u003e) (0585d481a)\u003c/li\u003e\n\u003cli\u003es2a: Default to Post Quantum Cryptography key exchange gr...\n\n_Description has been truncated_","html_url":"https://github.com/ychrono/yc-otel-demo/pull/438","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/ychrono%2Fyc-otel-demo/issues/438","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/438/packages"}},{"old_version":"2.18.2","new_version":"2.18.9","update_type":"patch","path":"/combo2-advanced-agentic-engineering/java/tiny-agent-java","pr_created_at":"2026-09-15T08:22:38.000Z","version_change":"2.18.2 → 2.18.9","issue":{"uuid":"5459475287","node_id":"PR_kwDOSQDhc88AAAABDk0AiQ","number":5,"state":"closed","title":"Bump com.fasterxml.jackson.core:jackson-databind from 2.18.2 to 2.18.9 in /combo2-advanced-agentic-engineering/java/tiny-agent-java","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":1,"pull_request":true,"closed_at":"2026-09-15T11:24:16.000Z","author_association":null,"state_reason":null,"created_at":"2026-09-15T08:22:38.000Z","updated_at":"2026-09-15T11:24:18.000Z","time_to_close":10898,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"Bump","packages":[{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.18.2","new_version":"2.18.9","repository_url":"https://github.com/FasterXML/jackson-databind"}],"path":"/combo2-advanced-agentic-engineering/java/tiny-agent-java","ecosystem":"maven"},"body":"Bumps [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) from 2.18.2 to 2.18.9.\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/f7b3266eb21a232b35520d31ce5e304beb8f1c7c\"\u003e\u003ccode\u003ef7b3266\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.18.9\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/55e3028d920333fd46dbcebe074017ea0d0bd6e3\"\u003e\u003ccode\u003e55e3028\u003c/code\u003e\u003c/a\u003e Prep for 2.18.9 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/59abdc4d61203962eebf11a46977d253601da76e\"\u003e\u003ccode\u003e59abdc4\u003c/code\u003e\u003c/a\u003e ...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/2fc7bd9057dd051d7dea0e5fcad89822d0fa5ebd\"\u003e\u003ccode\u003e2fc7bd9\u003c/code\u003e\u003c/a\u003e Do not allow DNS resolution when deserializing \u003ccode\u003eInetAddress\u003c/code\u003e (\u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6058\"\u003e#6058\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/c628b357ed143d8492756d5c1458cfb9fbeb29ed\"\u003e\u003ccode\u003ec628b35\u003c/code\u003e\u003c/a\u003e Honor \u003ccode\u003e@JsonView\u003c/code\u003e for external-type-id (\u003ccode\u003eEXTERNAL_PROPERTY\u003c/code\u003e) properties [GHSA...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/d627a8a86fcb062429282f79f3f256f181ed2c7b\"\u003e\u003ccode\u003ed627a8a\u003c/code\u003e\u003c/a\u003e Fix \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6060\"\u003e#6060\u003c/a\u003e -- \u003ccode\u003e@JsonView\u003c/code\u003e skipped for Setter/Field properties with `@JsonUnwra...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bc1613c765704703ec7385e314fa8b19448e1ddd\"\u003e\u003ccode\u003ebc1613c\u003c/code\u003e\u003c/a\u003e Backport PR \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/5964\"\u003e#5964\u003c/a\u003e into 2.18 to fix \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/5962\"\u003e#5962\u003c/a\u003e (\u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/6039\"\u003e#6039\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ff5d313269f5bf8ce4caa66096e3567fc72fe910\"\u003e\u003ccode\u003eff5d313\u003c/code\u003e\u003c/a\u003e Add CVE id for \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/5971\"\u003e#5971\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/f95549d66222b3002df05e09c41d693497552b2e\"\u003e\u003ccode\u003ef95549d\u003c/code\u003e\u003c/a\u003e Update CVE id for \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/5969\"\u003e#5969\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/6d6bfea1c3a52790af3370a8a1c466633816737d\"\u003e\u003ccode\u003e6d6bfea\u003c/code\u003e\u003c/a\u003e Update CVE info for \u003ca href=\"https://redirect.github.com/FasterXML/jackson-databind/issues/5951\"\u003e#5951\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.18.2...jackson-databind-2.18.9\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\n\n[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.fasterxml.jackson.core:jackson-databind\u0026package-manager=maven\u0026previous-version=2.18.2\u0026new-version=2.18.9)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)\n\nDependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.\n\n[//]: # (dependabot-automerge-start)\n[//]: # (dependabot-automerge-end)\n\n---\n\n\u003cdetails\u003e\n\u003csummary\u003eDependabot commands and options\u003c/summary\u003e\n\u003cbr /\u003e\n\nYou can trigger Dependabot actions by commenting on this PR:\n- `@dependabot rebase` will rebase this PR\n- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it\n- `@dependabot show \u003cdependency name\u003e ignore conditions` will show all of the ignore conditions of the specified dependency\n- `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)\n- `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)\nYou can disable automated security fix PRs for this repo from the [Security Alerts page](https://github.com/Octoco-AI/ai-course-exercises/network/alerts).\n\n\u003c/details\u003e","html_url":"https://github.com/Octoco-AI/ai-course-exercises/pull/5","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/Octoco-AI%2Fai-course-exercises/issues/5","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/5/packages"}},{"old_version":"2.22.1","new_version":"2.22.2","update_type":"patch","path":null,"pr_created_at":"2026-09-15T04:25:39.000Z","version_change":"2.22.1 → 2.22.2","issue":{"uuid":"5457492621","node_id":"PR_kwDOBNevYc8AAAABDjNTWQ","number":494,"state":"open","title":"chore(deps): Bump the maven-minor-patch group across 1 directory with 27 updates","user":"dependabot[bot]","labels":["dependencies","java"],"assignees":[],"locked":false,"comments_count":3,"pull_request":true,"closed_at":null,"author_association":null,"state_reason":null,"created_at":"2026-09-15T04:25:39.000Z","updated_at":"2026-09-15T04:26:54.000Z","time_to_close":null,"merged_at":null,"merged_by":null,"closed_by":null,"dependency_metadata":{"prefix":"chore(deps): Bump","group_name":"maven-minor-patch","update_count":27,"packages":[{"name":"org.projectlombok:lombok","old_version":"1.18.46","new_version":"1.18.48","repository_url":"https://github.com/projectlombok/lombok"},{"name":"io.smallrye.common:smallrye-common-function","old_version":"2.19.0","new_version":"2.20.0","repository_url":"https://github.com/smallrye/smallrye-common"},{"name":"org.hibernate.validator:hibernate-validator","old_version":"9.1.2.Final","new_version":"9.1.3.Final","repository_url":"https://github.com/hibernate/hibernate-validator"},{"name":"org.springframework.boot:spring-boot-starter-parent","old_version":"4.1.0","new_version":"4.1.1","repository_url":"https://github.com/spring-projects/spring-boot"},{"name":"org.apache.maven.plugins:maven-surefire-plugin","old_version":"3.5.6","new_version":"3.6.0","repository_url":"https://github.com/apache/maven-surefire"},{"name":"org.apache.maven.plugins:maven-compiler-plugin","old_version":"3.15.0","new_version":"3.16.0","repository_url":"https://github.com/apache/maven-compiler-plugin"},{"name":"org.codehaus.mojo:build-helper-maven-plugin","old_version":"3.6.1","new_version":"3.6.2","repository_url":"https://github.com/mojohaus/build-helper-maven-plugin"},{"name":"io.projectreactor:reactor-core","old_version":"3.8.6","new_version":"3.8.7","repository_url":"https://github.com/reactor/reactor-core"},{"name":"com.fasterxml.jackson.core:jackson-databind","old_version":"2.22.1","new_version":"2.22.2","repository_url":"https://github.com/FasterXML/jackson-databind"},{"name":"io.swagger.core.v3:swagger-annotations","old_version":"2.2.52","new_version":"2.2.55"},{"name":"org.freemarker:freemarker","old_version":"2.3.34","new_version":"2.3.35"},{"name":"net.bytebuddy:byte-buddy-agent","old_version":"1.18.11","new_version":"1.18.13","repository_url":"https://github.com/raphw/byte-buddy"},{"name":"net.bytebuddy:byte-buddy","old_version":"1.18.11","new_version":"1.18.13","repository_url":"https://github.com/raphw/byte-buddy"},{"name":"com.google.guava:guava","old_version":"33.6.0-jre","new_version":"33.7.1-jre","repository_url":"https://github.com/google/guava"},{"name":"org.slf4j:slf4j-api","old_version":"2.0.18","new_version":"2.0.19"},{"name":"com.fasterxml.jackson.datatype:jackson-datatype-jsr310","old_version":"2.22.1","new_version":"2.22.2"},{"name":"com.fasterxml.jackson.dataformat:jackson-dataformat-yaml","old_version":"2.22.1","new_version":"2.22.2","repository_url":"https://github.com/FasterXML/jackson-dataformats-text"},{"name":"com.auth0:java-jwt","old_version":"4.6.0","new_version":"4.6.1","repository_url":"https://github.com/auth0/java-jwt"},{"name":"io.smallrye:jandex-maven-plugin","old_version":"3.2.7","new_version":"3.6.0","repository_url":"https://github.com/smallrye/jandex"},{"name":"io.projectreactor:reactor-test","old_version":"3.8.6","new_version":"3.8.7","repository_url":"https://github.com/reactor/reactor-core"},{"name":"io.quarkus:quarkus-rest","old_version":"3.38.0","new_version":"3.39.3"},{"name":"io.quarkus:quarkus-spring-di","old_version":"3.38.0","new_version":"3.39.3"},{"name":"io.helidon.webserver:helidon-webserver","old_version":"4.5.1","new_version":"4.5.4"},{"name":"org.apache.maven:maven-plugin-api","old_version":"3.9.9","new_version":"3.9.16","repository_url":"https://github.com/apache/maven"},{"name":"org.apache.maven:maven-core","old_version":"3.9.9","new_version":"3.9.16"},{"name":"org.apache.maven.plugin-tools:maven-plugin-annotations","old_version":"3.13.1","new_version":"3.16.0","repository_url":"https://github.com/apache/maven-plugin-tools"},{"name":"org.apache.maven.plugins:maven-plugin-plugin","old_version":"3.13.1","new_version":"3.16.0","repository_url":"https://github.com/apache/maven-plugin-tools"}],"path":null,"ecosystem":"maven"},"body":"Bumps the maven-minor-patch group with 27 updates in the /backend directory:\n\n| Package | From | To |\n| --- | --- | --- |\n| [org.projectlombok:lombok](https://github.com/projectlombok/lombok) | `1.18.46` | `1.18.48` |\n| [io.smallrye.common:smallrye-common-function](https://github.com/smallrye/smallrye-common) | `2.19.0` | `2.20.0` |\n| [org.hibernate.validator:hibernate-validator](https://github.com/hibernate/hibernate-validator) | `9.1.2.Final` | `9.1.3.Final` |\n| [org.springframework.boot:spring-boot-starter-parent](https://github.com/spring-projects/spring-boot) | `4.1.0` | `4.1.1` |\n| [org.apache.maven.plugins:maven-surefire-plugin](https://github.com/apache/maven-surefire) | `3.5.6` | `3.6.0` |\n| [org.apache.maven.plugins:maven-compiler-plugin](https://github.com/apache/maven-compiler-plugin) | `3.15.0` | `3.16.0` |\n| [org.codehaus.mojo:build-helper-maven-plugin](https://github.com/mojohaus/build-helper-maven-plugin) | `3.6.1` | `3.6.2` |\n| [io.projectreactor:reactor-core](https://github.com/reactor/reactor-core) | `3.8.6` | `3.8.7` |\n| [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) | `2.22.1` | `2.22.2` |\n| io.swagger.core.v3:swagger-annotations | `2.2.52` | `2.2.55` |\n| org.freemarker:freemarker | `2.3.34` | `2.3.35` |\n| [net.bytebuddy:byte-buddy-agent](https://github.com/raphw/byte-buddy) | `1.18.11` | `1.18.13` |\n| [net.bytebuddy:byte-buddy](https://github.com/raphw/byte-buddy) | `1.18.11` | `1.18.13` |\n| [com.google.guava:guava](https://github.com/google/guava) | `33.6.0-jre` | `33.7.1-jre` |\n| org.slf4j:slf4j-api | `2.0.18` | `2.0.19` |\n| com.fasterxml.jackson.datatype:jackson-datatype-jsr310 | `2.22.1` | `2.22.2` |\n| [com.fasterxml.jackson.dataformat:jackson-dataformat-yaml](https://github.com/FasterXML/jackson-dataformats-text) | `2.22.1` | `2.22.2` |\n| [com.auth0:java-jwt](https://github.com/auth0/java-jwt) | `4.6.0` | `4.6.1` |\n| [io.smallrye:jandex-maven-plugin](https://github.com/smallrye/jandex) | `3.2.7` | `3.6.0` |\n| [io.projectreactor:reactor-test](https://github.com/reactor/reactor-core) | `3.8.6` | `3.8.7` |\n| io.quarkus:quarkus-rest | `3.38.0` | `3.39.3` |\n| io.quarkus:quarkus-spring-di | `3.38.0` | `3.39.3` |\n| io.helidon.webserver:helidon-webserver | `4.5.1` | `4.5.4` |\n| [org.apache.maven:maven-plugin-api](https://github.com/apache/maven) | `3.9.9` | `3.9.16` |\n| org.apache.maven:maven-core | `3.9.9` | `3.9.16` |\n| [org.apache.maven.plugin-tools:maven-plugin-annotations](https://github.com/apache/maven-plugin-tools) | `3.13.1` | `3.16.0` |\n| [org.apache.maven.plugins:maven-plugin-plugin](https://github.com/apache/maven-plugin-tools) | `3.13.1` | `3.16.0` |\n\n\nUpdates `org.projectlombok:lombok` from 1.18.46 to 1.18.48\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/projectlombok/lombok/blob/master/doc/changelog.markdown\"\u003eorg.projectlombok:lombok's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch3\u003ev1.18.48 (September 1st, 2026)\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eBREAKING CHANGE/BUGFIX: \u003ccode\u003e@Builder(builderClassName = \u0026quot;Builder\u0026quot;)\u003c/code\u003e now generates an error, because the type names collide. \u003ca href=\"https://redirect.github.com/projectlombok/lombok/issues/3857\"\u003e#3857\u003c/a\u003e  (found after release)\u003c/li\u003e\n\u003cli\u003ePLATFORM: JDK27 support added \u003ca href=\"https://redirect.github.com/projectlombok/lombok/issues/4072\"\u003e#4072\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eBUGFIX: \u003ccode\u003e@SneakyThrows\u003c/code\u003e usage on JDK26 no longer results in class files that require \u003ccode\u003elombok.jar\u003c/code\u003e to be on the runtime classpath (which should not be neccessary). \u003ca href=\"https://redirect.github.com/projectlombok/lombok/issues/4040\"\u003e#4040\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eFEATURE: New \u003ca href=\"https://projectlombok.org/features/configuration\"\u003econfig key\u003c/a\u003e \u003ccode\u003elombok.checkReturnValueAnnotation\u003c/code\u003e (values: \u003ccode\u003enone\u003c/code\u003e, \u003ccode\u003elombok\u003c/code\u003e; default: \u003ccode\u003enone\u003c/code\u003e) lets lombok generate \u003ccode\u003e@lombok.CheckReturnValue\u003c/code\u003e on generated methods where the return value should not be ignored, such as \u003ccode\u003e@With\u003c/code\u003e methods and \u003ccode\u003e@Builder.build()\u003c/code\u003e. A future lombok release may flip the default to \u003ccode\u003elombok\u003c/code\u003e. \u003ca href=\"https://redirect.github.com/projectlombok/lombok/pull/4013\"\u003e#4013\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003ePROMOTION: \u003ccode\u003e@SuperBuilder\u003c/code\u003e has been promoted to the main package. Otherwise, no changes have been made to the annotation. The old experimental annotation will remain for a few versions, at which point it will be marked as a deprecated annotation. Eventually it'll be removed. If you had \u003ccode\u003elombok.config\u003c/code\u003e configuration for this annotation, the configuration keys for this feature have been renamed. \u003ca href=\"https://redirect.github.com/projectlombok/lombok/issues/2209\"\u003e#2209\u003c/a\u003e.\u003c/li\u003e\n\u003cli\u003eOLD-CRUFT: \u003ccode\u003elombok.experimental.Wither\u003c/code\u003e and \u003ccode\u003elombok.Delegate\u003c/code\u003e are deprecated remnants; these features were moved (to respectively \u003ccode\u003elombok.With\u003c/code\u003e and \u003ccode\u003elombok.experimental.Delegate\u003c/code\u003e over 5 years ago. They are now removed entirely. If your project is dependent on an older version of lombok which still has those; fret not, lombok still processes these annotations. It just no longer includes them in the jar.\u003c/li\u003e\n\u003cli\u003eFEATURE: CheckerFramework: Lombok now adds \u003ccode\u003e@SideEffectFree\u003c/code\u003e to constructors it makes if you have enabled checker framework via \u003ccode\u003elombok.config\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eBUGFIX: CheckerFramework: Lombok would add \u003ccode\u003e@SideEffectFree\u003c/code\u003e to the \u003ccode\u003ebuild()\u003c/code\u003e method of any generated builder, even if it is a builder for invoking a method; in that case, the side-effect-free nature of \u003ccode\u003ebuild()\u003c/code\u003e mirrors the side-effect-free nature of the method invocation you've built. Lombok now checks if the method it generated a builder for is side effect free / 'check return type'.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/projectlombok/lombok/commit/b48657c83ce44d027984f539bd36048293ce5e8e\"\u003e\u003ccode\u003eb48657c\u003c/code\u003e\u003c/a\u003e [version] pre-release version bump v1.18.48\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/projectlombok/lombok/commit/d1d003945f864d32bb3115cf81fa363e1c7bc6bb\"\u003e\u003ccode\u003ed1d0039\u003c/code\u003e\u003c/a\u003e Merge branch 'jdk27'\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/projectlombok/lombok/commit/1a23dad52c01e7b18892573549841e36d6e4abde\"\u003e\u003ccode\u003e1a23dad\u003c/code\u003e\u003c/a\u003e [review][refactor] No meaningful changes: Improved comments, javadoc, and cle...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/projectlombok/lombok/commit/40cdde815038a4bddc2bc31afce80c4c62e75e67\"\u003e\u003ccode\u003e40cdde8\u003c/code\u003e\u003c/a\u003e [changelog] JDK27 support\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/projectlombok/lombok/commit/25eae29093410cba53e3f91e2da4ba1fbf1953f4\"\u003e\u003ccode\u003e25eae29\u003c/code\u003e\u003c/a\u003e Add Danish Nawab to AUTHORS\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/projectlombok/lombok/commit/10ab92b5d9eb852ccac7295d8017203e7efd7449\"\u003e\u003ccode\u003e10ab92b\u003c/code\u003e\u003c/a\u003e Support JDK27: end positions moved from EndPosTable to JCTree.endpos\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/projectlombok/lombok/commit/af01b7a27b469b723e88de508480186113569185\"\u003e\u003ccode\u003eaf01b7a\u003c/code\u003e\u003c/a\u003e Document the new configuration syntax for listy things\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/projectlombok/lombok/commit/1be3857dfef96cde703012a43ec649a4c3f7eea9\"\u003e\u003ccode\u003e1be3857\u003c/code\u003e\u003c/a\u003e There is no more HtAccess\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/projectlombok/lombok/commit/405985dd2512786439448e43f390c359e7595269\"\u003e\u003ccode\u003e405985d\u003c/code\u003e\u003c/a\u003e Semantic sections for website\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/projectlombok/lombok/commit/04b73406d04a279401b43a74314aa1dcbadbc143\"\u003e\u003ccode\u003e04b7340\u003c/code\u003e\u003c/a\u003e [trivial] fixing some outdated tests (tests were broken, not lombok).\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/projectlombok/lombok/compare/v1.18.46...v1.18.48\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `io.smallrye.common:smallrye-common-function` from 2.19.0 to 2.20.0\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/smallrye/smallrye-common/commit/defd310a881f1c168e958f8f73fc7c6518499a4e\"\u003e\u003ccode\u003edefd310\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release 2.20.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/smallrye/smallrye-common/commit/ffc98f68f60160620b1156b233dd650104f09862\"\u003e\u003ccode\u003effc98f6\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/smallrye/smallrye-common/issues/581\"\u003e#581\u003c/a\u003e from smallrye/release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/smallrye/smallrye-common/commit/7cf7fcc86bddc8a9e96f14a34ac292e617d0202b\"\u003e\u003ccode\u003e7cf7fcc\u003c/code\u003e\u003c/a\u003e Release 2.20.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/smallrye/smallrye-common/commit/e6f3c592559944617e16f008f1d1ac3285fcef75\"\u003e\u003ccode\u003ee6f3c59\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/smallrye/smallrye-common/issues/579\"\u003e#579\u003c/a\u003e from smallrye/dependabot/maven/version.vertx4-4.5.30\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/smallrye/smallrye-common/commit/232049fc7397665ed85ed6a57ae57574a7a2b84f\"\u003e\u003ccode\u003e232049f\u003c/code\u003e\u003c/a\u003e Bump version.vertx4 from 4.5.29 to 4.5.30\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/smallrye/smallrye-common/commit/b89fee46677f6d62fa10cfb67adb16fbe9fe767a\"\u003e\u003ccode\u003eb89fee4\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/smallrye/smallrye-common/issues/576\"\u003e#576\u003c/a\u003e from smallrye/dependabot/maven/org.graalvm.sdk-native...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/smallrye/smallrye-common/commit/d2c6a36fce245cb95cf3a08f8268c530f6eceeff\"\u003e\u003ccode\u003ed2c6a36\u003c/code\u003e\u003c/a\u003e Bump org.graalvm.sdk:nativeimage from 25.0.3 to 25.1.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/smallrye/smallrye-common/commit/dc378965bead25b95112ee86c264ff88b41fd7e4\"\u003e\u003ccode\u003edc37896\u003c/code\u003e\u003c/a\u003e Merge pull request \u003ca href=\"https://redirect.github.com/smallrye/smallrye-common/issues/578\"\u003e#578\u003c/a\u003e from smallrye/dependabot/maven/version.vertx4-4.5.29\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/smallrye/smallrye-common/commit/3d73326ea1c881fad45e48db7a67383359be1f35\"\u003e\u003ccode\u003e3d73326\u003c/code\u003e\u003c/a\u003e Bump version.vertx4 from 4.5.28 to 4.5.29\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/smallrye/smallrye-common/commit/bdb9f0b6c1089eddb54a3959905d0316aa49db37\"\u003e\u003ccode\u003ebdb9f0b\u003c/code\u003e\u003c/a\u003e Bump io.smallrye:smallrye-parent from 50 to 51 (\u003ca href=\"https://redirect.github.com/smallrye/smallrye-common/issues/577\"\u003e#577\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/smallrye/smallrye-common/compare/2.19.0...2.20.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.hibernate.validator:hibernate-validator` from 9.1.2.Final to 9.1.3.Final\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hibernate/hibernate-validator/releases\"\u003eorg.hibernate.validator:hibernate-validator's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eRelease 9.1.3.Final\u003c/h2\u003e\n\u003ch1\u003eHibernate Validator 9.1.3.Final released\u003c/h1\u003e\n\u003cp\u003eWe are pleased to announce the release of Hibernate Validator 9.1: 9.1.3.Final.\u003c/p\u003e\n\u003cp\u003eYou can find the full list of 9.1.3.Final changes \u003ca href=\"https://hibernate.atlassian.net/issues/?jql=project%20%3D%20HV%20AND%20fixVersion%20%3D%209.1.3.Final\"\u003ehere\u003c/a\u003e.\u003c/p\u003e\n\u003ch2\u003eWhat's new\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSee the \u003ca href=\"https://hibernate.org/validator/releases/9.1\"\u003ewebsite\u003c/a\u003e for requirements and compatibilities.\u003c/li\u003e\n\u003cli\u003eSee the \u003ca href=\"https://docs.hibernate.org/validator/9.1/whats-new/en-US/html_single/\"\u003eWhat's New\u003c/a\u003e guide for details about new features and capabilities.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eConclusion\u003c/h2\u003e\n\u003cp\u003eFor additional details, see:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003ethe \u003ca href=\"https://hibernate.org/validator/releases/9.1/\"\u003erelease page\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/validator/9.1/migration-guide/\"\u003eMigration Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/validator/9.1/reference/en-US/html_single/#validator-gettingstarted\"\u003eGetting started\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/validator/9.1/reference/en-US/html_single/\"\u003eReference Guide\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ethe \u003ca href=\"https://docs.hibernate.org/validator/9.1/api\"\u003eAPI docs\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eVisit the \u003ca href=\"https://hibernate.org/community/\"\u003ewebsite\u003c/a\u003e for details on getting in touch with us.\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/hibernate/hibernate-validator/blob/9.1.3.Final/changelog.md\"\u003eorg.hibernate.validator:hibernate-validator's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e9.1.3.Final (2026-07-26)\u003c/h2\u003e\n\u003cp\u003e\u003ca href=\"https://hibernate.atlassian.net/projects/HV/versions/40065\"\u003eFull changelog\u003c/a\u003e\u003c/p\u003e\n\u003ch3\u003eBug\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://hibernate.atlassian.net/browse/HV-2231\"\u003eHV-2231\u003c/a\u003e - RegexpURLValidator throws NPE when URL has no authority component\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/8ab68bcc99e0727065e194693f5c3b03395fa87e\"\u003e\u003ccode\u003e8ab68bc\u003c/code\u003e\u003c/a\u003e [Jenkins release job] Preparing release 9.1.3.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/36a8551a92d42ae8ece6e2f534fa1d16df088943\"\u003e\u003ccode\u003e36a8551\u003c/code\u003e\u003c/a\u003e [Jenkins release job] changelog.md updated by release build 9.1.3.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/e8b4ebd670356e58c14d11a569044a228f63e09a\"\u003e\u003ccode\u003ee8b4ebd\u003c/code\u003e\u003c/a\u003e [Jenkins release job] README.md updated by release build 9.1.3.Final\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/8ba5072bc668fc14d71d169c1897e11112a9e084\"\u003e\u003ccode\u003e8ba5072\u003c/code\u003e\u003c/a\u003e HV-2231 Fix NPE in RegexpURLValidator when URL has no host\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/e9d4856774aae38431feb9569e4fe58af02806f6\"\u003e\u003ccode\u003ee9d4856\u003c/code\u003e\u003c/a\u003e [9.1] Bump the build-dependencies group with 3 updates\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/7793c80bfa0d99390229863bc5a7b95dab8d34a7\"\u003e\u003ccode\u003e7793c80\u003c/code\u003e\u003c/a\u003e Use correct env var name for additional arguments in the release script\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/hibernate/hibernate-validator/commit/8cffdd8f9ca4a0d869772ff11686507b0fc0726e\"\u003e\u003ccode\u003e8cffdd8\u003c/code\u003e\u003c/a\u003e [Jenkins release job] Preparing next development iteration\u003c/li\u003e\n\u003cli\u003eSee full diff in \u003ca href=\"https://github.com/hibernate/hibernate-validator/compare/9.1.2.Final...9.1.3.Final\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.springframework.boot:spring-boot-starter-parent` from 4.1.0 to 4.1.1\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/spring-projects/spring-boot/releases\"\u003eorg.springframework.boot:spring-boot-starter-parent's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev4.1.1\u003c/h2\u003e\n\u003ch2\u003e:warning: Attention Required\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eSpring Boot's Gradle plugin no longer automatically configures gRPC when the Protobuf plugin is applied. This behavior caused problems for those using Protobuf without gRPC. To opt in to the configuration of gRPC, configure the \u003ccode\u003eprotobuf\u003c/code\u003e extension with the \u003ccode\u003egrpc\u003c/code\u003e plugin using an empty block. The Spring Boot Gradle plugin will then automatically configure the use of \u003ccode\u003eprotoc-gen-grpc-java\u003c/code\u003e as before. \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50822\"\u003e#50822\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e:lady_beetle: Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eKafka consumer-specific security protocol is not taken into account \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/51369\"\u003e#51369\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eStructured logging: a failed JSON encode corrupts the next log event written on the same thread \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/pull/51156\"\u003e#51156\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMicrometer registries pin the application context \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/51135\"\u003e#51135\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eTemporary file is not deleted when ExportedImageTar construction fails \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/51132\"\u003e#51132\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMetadata annotation processor ignores getter-level \u003ccode\u003e@NestedConfigurationProperty\u003c/code\u003e for records \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/51098\"\u003e#51098\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003espring-boot-h2-console pulls servlet-api as transitive dependency \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/51095\"\u003e#51095\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePropertiesLauncher does not log nested archive paths \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/51089\"\u003e#51089\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMethods that return the result of Map#remove are not declared with a \u003ccode\u003e@Nullable\u003c/code\u003e return type \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/51087\"\u003e#51087\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eNativeImageResourceProvider flattens Flyway migration paths in subdirectories \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50964\"\u003e#50964\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix ordering of Kotlinx Serialization CodecCustomizer \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50961\"\u003e#50961\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJarFile is not closed when finding main class from archive \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50959\"\u003e#50959\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eApplication-managed JUL bridge handler should only be removed if installed \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50950\"\u003e#50950\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eCloudFoundry reactive auto-configuration should not require a WebClient.Builder bean to be defined \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50944\"\u003e#50944\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eContext refresh fails on reactive Cloud Foundry when using Actuator without spring-boot-health \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50942\"\u003e#50942\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eResources are not cleaned up when resolving an image that is not yet present in the builder \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50941\"\u003e#50941\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eGraphQlWebMvcAutoConfiguration should apply customizers in order \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50914\"\u003e#50914\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAuto-configured RedisMessageListenerContainer does not use virtual threads when spring.threads.virtual.enabled is true \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50884\"\u003e#50884\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eContext refresh fails when using Actuator on Jersey without spring-boot-health \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50872\"\u003e#50872\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eContext refresh fails on Cloud Foundry when using Actuator without spring-boot-health \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50871\"\u003e#50871\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIllegalStateException when binding properties to a \u003ccode\u003e@Validated\u003c/code\u003e class that contains a map whose value type is a wildcard \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50856\"\u003e#50856\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eHigh number of connections due to Mongo health indicator \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50852\"\u003e#50852\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eInconsistent handling of empty string values of spring.security.oauth2.resourceserver.jwt issuer-uri and jwk-set-uri \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50849\"\u003e#50849\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReturn type nullability of ApplicationContextAssert's getBean methods does not indicate that bean may be null \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50845\"\u003e#50845\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePropertiesWebClientHttpServiceGroupConfigurer has highest precedence, preventing other configurers from being ordered ahead of it \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50843\"\u003e#50843\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eExposing gRPC test server port should backoff if gRPC is not present \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50825\"\u003e#50825\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eJpaBaseConfiguration#entityManagerConfiguration can cause a dependency loop on beans declaring AsyncTaskExecutor \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/pull/50801\"\u003e#50801\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003espring.grpc.server.health.include-overall-health is not taken into account \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/pull/50799\"\u003e#50799\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eSetting 'server.servlet.session.cookie.partitioned' to false still emits the 'Partitioned' cookie attribute \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50790\"\u003e#50790\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eManaged version of Prometheus Client is not aligned with Micrometer's micrometer-registry-prometheus \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50780\"\u003e#50780\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMap properties bound from empty strings fail with ConverterNotFoundException \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/pull/50773\"\u003e#50773\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eProtobuf Common Protos should not be a managed dependency \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50772\"\u003e#50772\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAn application that depends on spring-boot-security-oauth2-resource-server may fail to start with a ClassNotFoundException when Reactor is on the classpath but WebFlux is not \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/50764\"\u003e#50764\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eW3CHeaderParser's decoding is not compliant with RFC 3986 \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/pull/50650\"\u003e#50650\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e:notebook_with_decorative_cover: Documentation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eDescription of spring.graphql.websocket.connection-init-timeout does not render correctly in the reference guide \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/pull/51348\"\u003e#51348\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003espring.profiles.group should have a 'spring-profile-name' hint provider \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/51284\"\u003e#51284\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRemove reference to removed InfluxDB auto-configuration \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/51176\"\u003e#51176\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse JacksonJsonSerde in Kafka Streams documentation \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/51161\"\u003e#51161\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDocument alternatives to HttpMessageConverters \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/51129\"\u003e#51129\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix stale type reference for OTLP logging transport metadata \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/pull/51119\"\u003e#51119\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMetadata for spring.test.mockmvc.htmlunit.url declares the wrong type \u003ca href=\"https://redirect.github.com/spring-projects/spring-boot/issues/51115\"\u003e#51115\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/6fdf67ea1552691e932604d4bf67a5e08ff0b0ea\"\u003e\u003ccode\u003e6fdf67e\u003c/code\u003e\u003c/a\u003e Release 4.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/fde599b28b40932e4ea6194399d89245923a01e7\"\u003e\u003ccode\u003efde599b\u003c/code\u003e\u003c/a\u003e Upgrade to Spring Pulsar 2.0.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/9daa58f7d98b82bf16febcb91943ce267c220a50\"\u003e\u003ccode\u003e9daa58f\u003c/code\u003e\u003c/a\u003e Upgrade to Spring HATEOAS 3.1.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/353993ebc1d7b1ceccbb981b0439a42ba122a816\"\u003e\u003ccode\u003e353993e\u003c/code\u003e\u003c/a\u003e Upgrade to Spring Data Bom 2026.0.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/24ba596bc4fa000614834016452435c834fdeda2\"\u003e\u003ccode\u003e24ba596\u003c/code\u003e\u003c/a\u003e Upgrade to Spring Session 4.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/5cb5c294d1f4780e78d010a964049e47c074e4d6\"\u003e\u003ccode\u003e5cb5c29\u003c/code\u003e\u003c/a\u003e Upgrade to Spring Security 7.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/4adc8eb130c4e0c688ed85316f385f4e04d47679\"\u003e\u003ccode\u003e4adc8eb\u003c/code\u003e\u003c/a\u003e Upgrade to Spring LDAP 4.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/4d9c19cbc0589f57a7265052b507bf4b961082ac\"\u003e\u003ccode\u003e4d9c19c\u003c/code\u003e\u003c/a\u003e Upgrade to Spring Kafka 4.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/f30f6120c4f6f8f873ac56cba478ae1f011c276c\"\u003e\u003ccode\u003ef30f612\u003c/code\u003e\u003c/a\u003e Upgrade to Spring Integration 7.1.1\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/spring-projects/spring-boot/commit/b930283d97e92eb24da1de3721cdd41625266dea\"\u003e\u003ccode\u003eb930283\u003c/code\u003e\u003c/a\u003e Upgrade to Spring gRPC 1.1.1\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/spring-projects/spring-boot/compare/v4.1.0...v4.1.1\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.maven.plugins:maven-surefire-plugin` from 3.5.6 to 3.6.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/apache/maven-surefire/releases\"\u003eorg.apache.maven.plugins:maven-surefire-plugin's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.6.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003ePlease refer to the main page for what's new \u003ca href=\"https://maven.apache.org/surefire/\"\u003ehttps://maven.apache.org/surefire/\u003c/a\u003e\nAnd the migration page \u003ca href=\"https://maven.apache.org/surefire/maven-surefire-plugin/whats-new-3-6-0.html\"\u003ehttps://maven.apache.org/surefire/maven-surefire-plugin/whats-new-3-6-0.html\u003c/a\u003e\u003c/p\u003e\n\u003ch2\u003e🚀 New features and improvements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eFix \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3303\"\u003e#3303\u003c/a\u003e: distinguish JUnit 6 ParameterizedClass invocations (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3432\"\u003e#3432\u003c/a\u003e) \u003ca href=\"https://github.com/AzazelSensei\"\u003e\u003ccode\u003e@​AzazelSensei\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-1639\"\u003e[SUREFIRE-1639]\u003c/a\u003e - Add ability to configure JUnit 5 TestExecutionListener (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3438\"\u003e#3438\u003c/a\u003e) \u003ca href=\"https://github.com/pan3793\"\u003e\u003ccode\u003e@​pan3793\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eIssue \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/838\"\u003e#838\u003c/a\u003e Implement extension point to run diagnosis tools when forked JVM times out (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3372\"\u003e#3372\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-2148\"\u003e[SUREFIRE-2148]\u003c/a\u003e - Verify recovered BeforeAll does not fail build (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3419\"\u003e#3419\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-823\"\u003e[SUREFIRE-823]\u003c/a\u003e - Decouple -DskipTests from Failsafe plugin (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3371\"\u003e#3371\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse StackWalker in StackTraceProvider when available (Java 9+) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3374\"\u003e#3374\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[Issue-3380] Send sourceQualifiedName to forked clients (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3380\"\u003e#3380\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3381\"\u003e#3381\u003c/a\u003e) \u003ca href=\"https://github.com/fabriciorby\"\u003e\u003ccode\u003e@​fabriciorby\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-523\"\u003e[SUREFIRE-523]\u003c/a\u003e - Link all reported tests to source XRef (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3445\"\u003e#3445\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-3446\"\u003e[SUREFIRE-3446]\u003c/a\u003e - Fix direct selection of JUnit Jupiter \u003ca href=\"https://github.com/Nested\"\u003e\u003ccode\u003e@​Nested\u003c/code\u003e\u003c/a\u003e classes (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3447\"\u003e#3447\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eDiscover tests in a fork when a toolchain JDK is used (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3444\"\u003e#3444\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[SUREFIRE-2239, SUREFIRE-2241, SUREFIRE-2260, SUREFIRE-2274, SUREFIRE-2300] Preserve JUnit Platform test identity across reruns (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3418\"\u003e#3418\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3428\"\u003e#3428\u003c/a\u003e: resolve parents via TestPlan.getParent for pre-1.8 platforms (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3429\"\u003e#3429\u003c/a\u003e) \u003ca href=\"https://github.com/kalayciburak\"\u003e\u003ccode\u003e@​kalayciburak\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/SUREFIRE-859\"\u003e[SUREFIRE-859]\u003c/a\u003e - Make random test order reproducible (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3421\"\u003e#3421\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e[SUREFIRE-862, SUREFIRE-3178] Handle missing Failsafe summary files (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3417\"\u003e#3417\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003efix: report AfterAll/AfterClass exceptions as errors again (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3412\"\u003e#3412\u003c/a\u003e) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3413\"\u003e#3413\u003c/a\u003e) \u003ca href=\"https://github.com/arimu1\"\u003e\u003ccode\u003e@​arimu1\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFixes \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3264\"\u003e#3264\u003c/a\u003e : tests inside \u003ca href=\"https://github.com/Suite\"\u003e\u003ccode\u003e@​Suite\u003c/code\u003e\u003c/a\u003e incorrectly classified as flakes (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3342\"\u003e#3342\u003c/a\u003e) \u003ca href=\"https://github.com/mirkoalicastro\"\u003e\u003ccode\u003e@​mirkoalicastro\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix Windows flake in CommandChannelDecoderTest (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3400\"\u003e#3400\u003c/a\u003e) \u003ca href=\"https://github.com/ascheman\"\u003e\u003ccode\u003e@​ascheman\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix reportNameSuffix in XML testcase classname (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3379\"\u003e#3379\u003c/a\u003e) \u003ca href=\"https://github.com/goutamadwant\"\u003e\u003ccode\u003e@​goutamadwant\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix: resolve relative classpath elements against the fork's working dir (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3333\"\u003e#3333\u003c/a\u003e) \u003ca href=\"https://github.com/cwegener-79\"\u003e\u003ccode\u003e@​cwegener-79\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📝 Documentation updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eMagnify the home, well at least have something rather than nothing :) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3377\"\u003e#3377\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRestore the straight quotes the FAQ conversion turned typographic (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3425\"\u003e#3425\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRestore the table borders lost in the APT conversion (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3424\"\u003e#3424\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eConvert the FAQ from FML to Markdown (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3423\"\u003e#3423\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eConvert the remaining site documentation from APT to Markdown (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3422\"\u003e#3422\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ejavadoc: clarify statelessTestsetReporter, consoleOutputReporter, (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3410\"\u003e#3410\u003c/a\u003e) \u003ca href=\"https://github.com/joshinii\"\u003e\u003ccode\u003e@​joshinii\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3387\"\u003e#3387\u003c/a\u003e) \u003ca href=\"https://github.com/potiuk\"\u003e\u003ccode\u003e@​potiuk\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate documentation we support Junit 6 as well :) (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3370\"\u003e#3370\u003c/a\u003e) \u003ca href=\"https://github.com/olamy\"\u003e\u003ccode\u003e@​olamy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e👻 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eStop dependabot from updating test fixtures (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3440\"\u003e#3440\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMigrate legacy plugin Javadoc annotations (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3416\"\u003e#3416\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUse the resolver's own HTTP transport in the report plugin tests (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3414\"\u003e#3414\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePin maven-jar-plugin 3.5.1 in modular IT fixtures (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3398\"\u003e#3398\u003c/a\u003e) \u003ca href=\"https://github.com/ascheman\"\u003e\u003ccode\u003e@​ascheman\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/pull/3387\"\u003e#3387\u003c/a\u003e) \u003ca href=\"https://github.com/potiuk\"\u003e\u003ccode\u003e@​potiuk\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003cp\u003e... (truncated)\u003c/p\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/0ff622b160253f362511a72d29a1f8067631f9d3\"\u003e\u003ccode\u003e0ff622b\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release surefire-3.6.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/bb3932a10a9706df70cf8095e2402348b7a64f0b\"\u003e\u003ccode\u003ebb3932a\u003c/code\u003e\u003c/a\u003e Let's go for 3.6.0 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/3002a1648cc8092dbd80492aa00509c825fd58e7\"\u003e\u003ccode\u003e3002a16\u003c/code\u003e\u003c/a\u003e Bump mavenVersion from 3.9.14 to 3.9.16\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/61a531d5981b0e70f8e88a329150f75501bb73e4\"\u003e\u003ccode\u003e61a531d\u003c/code\u003e\u003c/a\u003e Bump Maven parent version from 47 to 49 (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3449\"\u003e#3449\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/e52ead4cf5075f519578d0053c1ff878dff238f5\"\u003e\u003ccode\u003ee52ead4\u003c/code\u003e\u003c/a\u003e [SUREFIRE-523] Link all reported tests to source XRef (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3445\"\u003e#3445\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/45102fa9f2dfc5bc3d2909798e67358ae33e2d49\"\u003e\u003ccode\u003e45102fa\u003c/code\u003e\u003c/a\u003e [SUREFIRE-3446] Fix direct selection of JUnit Jupiter \u003ca href=\"https://github.com/Nested\"\u003e\u003ccode\u003e@​Nested\u003c/code\u003e\u003c/a\u003e classes (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3447\"\u003e#3447\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/b2e1f70b24df2d8a6cf1583ca955311184e68022\"\u003e\u003ccode\u003eb2e1f70\u003c/code\u003e\u003c/a\u003e Fix \u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3303\"\u003e#3303\u003c/a\u003e: distinguish JUnit 6 ParameterizedClass invocations (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3432\"\u003e#3432\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/c051938593a29d654b3c1c20d454b9062c3fa3f4\"\u003e\u003ccode\u003ec051938\u003c/code\u003e\u003c/a\u003e Discover tests in a fork when a toolchain JDK is used (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3444\"\u003e#3444\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/db75df85a76abf35346f559fe7f7f020cf6435b6\"\u003e\u003ccode\u003edb75df8\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-java from 1.5.2 to 1.6.0 (\u003ca href=\"https://redirect.github.com/apache/maven-surefire/issues/3441\"\u003e#3441\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-surefire/commit/77f2759d895a4460f917bdaaff7a025454afebe4\"\u003e\u003ccode\u003e77f2759\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-interpolation from 1.29 to 1.30.0\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/apache/maven-surefire/compare/surefire-3.5.6...surefire-3.6.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.apache.maven.plugins:maven-compiler-plugin` from 3.15.0 to 3.16.0\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/apache/maven-compiler-plugin/releases\"\u003eorg.apache.maven.plugins:maven-compiler-plugin's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.16.0\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e🚀 New features and improvements\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRecompile when dependencies change (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1102\"\u003e#1102\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix incremental detection of empty sources, 3.x (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1075\"\u003e#1075\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/MCOMPILER-578\"\u003e[MCOMPILER-578]\u003c/a\u003e - Track outputs across compiler executions (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1091\"\u003e#1091\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBuild fails when annotation processor list is empty (but present) (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1077\"\u003e#1077\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/MCOMPILER-374\"\u003e[MCOMPILER-374]\u003c/a\u003e - Unable to compile MR-JAR code against older directories when module-info.java is present (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1093\"\u003e#1093\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eMake mcompiler-120 IT locale independent (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1063\"\u003e#1063\u003c/a\u003e) \u003ca href=\"https://github.com/anilvdl\"\u003e\u003ccode\u003e@​anilvdl\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📝 Documentation updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://issues.apache.org/jira/browse/MCOMPILER-569\"\u003e[MCOMPILER-569]\u003c/a\u003e - Document implicitly compiled excluded sources (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1092\"\u003e#1092\u003c/a\u003e) \u003ca href=\"https://github.com/wilx\"\u003e\u003ccode\u003e@​wilx\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1074\"\u003e#1074\u003c/a\u003e) \u003ca href=\"https://github.com/potiuk\"\u003e\u003ccode\u003e@​potiuk\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e👻 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAvoid using deprecated method CompilerConfiguration.setCompilerVersion (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1121\"\u003e#1121\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eReplace adopt-openj9 by semeru JDK distribution on GH (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1122\"\u003e#1122\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003ePort the site documentation from APT to Markdown (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1110\"\u003e#1110\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eVerify against Maven 4.0.0-rc-6 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1105\"\u003e#1105\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix tests on Jenkins (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1100\"\u003e#1100\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eAdd AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1074\"\u003e#1074\u003c/a\u003e) \u003ca href=\"https://github.com/potiuk\"\u003e\u003ccode\u003e@​potiuk\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eRefactor compiler mojo to use dependency injection and improve string… (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1066\"\u003e#1066\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix ITs for Maven 3.10.x (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1061\"\u003e#1061\u003c/a\u003e) \u003ca href=\"https://github.com/slawekjaranowski\"\u003e\u003ccode\u003e@​slawekjaranowski\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eUpdate maven-surefire-plugin version to 3.x in the MCOMPILER-481 IT (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1035\"\u003e#1035\u003c/a\u003e) \u003ca href=\"https://github.com/cdouillard\"\u003e\u003ccode\u003e@​cdouillard\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📦 Dependency updates\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eBump plexusCompilerVersion from 2.16.2 to 2.17.0 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1112\"\u003e#1112\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.codehaus.plexus:plexus-java from 1.5.2 to 1.6.0 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1113\"\u003e#1113\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003euse latest Maven 4 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1045\"\u003e#1045\u003c/a\u003e) \u003ca href=\"https://github.com/hboutemy\"\u003e\u003ccode\u003e@​hboutemy\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump apache/maven-gh-actions-shared/.github/workflows/release-drafter.yml from 4 to 5 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1083\"\u003e#1083\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump apache/maven-gh-actions-shared/.github/workflows/pr-automation.yml from 4 to 5 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1082\"\u003e#1082\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump apache/maven-gh-actions-shared/.github/workflows/maven-verify.yml from 4 to 5 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1084\"\u003e#1084\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-plugins from 48 to 49 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1068\"\u003e#1068\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-invoker-plugin from 3.9.1 to 3.10.1 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1047\"\u003e#1047\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugins:maven-plugins from 47 to 48 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1050\"\u003e#1050\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump mavenVersion from 3.9.14 to 3.9.16 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1054\"\u003e#1054\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.ow2.asm:asm from 9.10 to 9.10.1 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1059\"\u003e#1059\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.ow2.asm:asm from 9.9.1 to 9.10 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1053\"\u003e#1053\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump mavenVersion from 3.9.13 to 3.9.14 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1041\"\u003e#1041\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump mavenVersion from 3.9.12 to 3.9.13 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1038\"\u003e#1038\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.apache.maven.plugin-testing:maven-plugin-testing-harness from 3.5.0 to 3.5.1 (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/pull/1032\"\u003e#1032\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/e7bba6ed5f9c17003d5c5d1413144bb214177408\"\u003e\u003ccode\u003ee7bba6e\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release maven-compiler-plugin-3.16.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/c906809e0c0b2c79e8a03165cb942f152a911416\"\u003e\u003ccode\u003ec906809\u003c/code\u003e\u003c/a\u003e Avoid using deprecated method CompilerConfiguration.setCompilerVersion\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/ad74fee36865d7a1752c9b96ff9a9e702565fdb3\"\u003e\u003ccode\u003ead74fee\u003c/code\u003e\u003c/a\u003e Replace adopt-openj9 by semeru JDK distribution on GH\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/beb0eda2100e77d3f01bf4cc89edd5b721411f63\"\u003e\u003ccode\u003ebeb0eda\u003c/code\u003e\u003c/a\u003e Recompile when dependencies change (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/issues/1102\"\u003e#1102\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/a0b689e0e7f13d3a7dded7847a807fe6453e0358\"\u003e\u003ccode\u003ea0b689e\u003c/code\u003e\u003c/a\u003e [MCOMPILER-578] Track outputs across compiler executions (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/issues/1091\"\u003e#1091\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/2e8122841d9b10d2d83a90cc07530d7a09eebc47\"\u003e\u003ccode\u003e2e81228\u003c/code\u003e\u003c/a\u003e Fix incremental detection of empty sources, 3.x (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/issues/1075\"\u003e#1075\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/2132f5bf0cbfcde26301084c4833f1a9420f1baf\"\u003e\u003ccode\u003e2132f5b\u003c/code\u003e\u003c/a\u003e configure ATR project\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/5992b772033a7488767c4b3aa806f080eba96593\"\u003e\u003ccode\u003e5992b77\u003c/code\u003e\u003c/a\u003e Build fails when annotation processor list is empty (but present) (\u003ca href=\"https://redirect.github.com/apache/maven-compiler-plugin/issues/1077\"\u003e#1077\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/acccef703e5491c29c6dd9e8381677d3e7927589\"\u003e\u003ccode\u003eacccef7\u003c/code\u003e\u003c/a\u003e Bump plexusCompilerVersion from 2.16.2 to 2.17.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/apache/maven-compiler-plugin/commit/72bc4454dfdcd1c3551137e5b27560f88b4480ae\"\u003e\u003ccode\u003e72bc445\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-java from 1.5.2 to 1.6.0\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/apache/maven-compiler-plugin/compare/maven-compiler-plugin-3.15.0...maven-compiler-plugin-3.16.0\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `org.codehaus.mojo:build-helper-maven-plugin` from 3.6.1 to 3.6.2\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/mojohaus/build-helper-maven-plugin/releases\"\u003eorg.codehaus.mojo:build-helper-maven-plugin's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003e3.6.2\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003ch2\u003e🐛 Bug Fixes\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eReplace raw \u003ccode\u003eNPEx\u003c/code\u003e with customized exception message (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/239\"\u003e#239\u003c/a\u003e) \u003ca href=\"https://github.com/pzygielo\"\u003e\u003ccode\u003e@​pzygielo\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e👻 Maintenance\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eRemove redundant maven-resolver-api dependency and ignore Resolver/SLF4J 2.x in Dependabot (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/248\"\u003e#248\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003e📦 Dependency updates\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cul\u003e\n\u003cli\u003eRemove redundant maven-resolver-api dependency and ignore Resolver/SLF4J 2.x in Dependabot (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/248\"\u003e#248\u003c/a\u003e) \u003ca href=\"https://github.com/slachiewicz\"\u003e\u003ccode\u003e@​slachiewicz\u003c/code\u003e\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.codehaus.plexus:plexus-utils from 4.0.3 to 4.1.0 (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/247\"\u003e#247\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump apache/maven-gh-actions-shared/.github/workflows/release-drafter.yml from 4 to 5 (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/244\"\u003e#244\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.codehaus.mojo:mojo-parent from 96 to 97 (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/246\"\u003e#246\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump apache/maven-gh-actions-shared/.github/workflows/maven-verify.yml from 4 to 5 (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/245\"\u003e#245\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.codehaus.plexus:plexus-utils from 4.0.2 to 4.0.3 (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/241\"\u003e#241\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.codehaus.mojo:mojo-parent from 95 to 96 (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/240\"\u003e#240\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.codehaus.mojo:mojo-parent from 94 to 95 (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/235\"\u003e#235\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.codehaus.mojo:mojo-parent from 93 to 94 (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/233\"\u003e#233\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.codehaus.mojo:mojo-parent from 92 to 93 (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/232\"\u003e#232\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eBump org.codehaus.mojo:mojo-parent from 91 to 92 (\u003ca href=\"https://redirect.github.com/mojohaus/build-helper-maven-plugin/pull/231\"\u003e#231\u003c/a\u003e) @\u003ca href=\"https://github.com/apps/dependabot\"\u003edependabot[bot]\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mojohaus/build-helper-maven-plugin/commit/813bc7d2f03f2c9975de1f079cf7a7334211e0b6\"\u003e\u003ccode\u003e813bc7d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release 3.6.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mojohaus/build-helper-maven-plugin/commit/07d91091b06db894178bcb6e71bc55f857546f46\"\u003e\u003ccode\u003e07d9109\u003c/code\u003e\u003c/a\u003e Remove redundant maven-resolver-api and ignore Resolver/SLF4J 2.x in Dependabot\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mojohaus/build-helper-maven-plugin/commit/9abd552f324e429beb586407139eb4d43127344a\"\u003e\u003ccode\u003e9abd552\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-utils from 4.0.3 to 4.1.0\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mojohaus/build-helper-maven-plugin/commit/3c15526bf151e28d6ce651197b36958164da4d4a\"\u003e\u003ccode\u003e3c15526\u003c/code\u003e\u003c/a\u003e Bump apache/maven-gh-actions-shared/.github/workflows/release-drafter.yml\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mojohaus/build-helper-maven-plugin/commit/3b1f104096756ce33e8fc3e4c3062b1ccd8cf227\"\u003e\u003ccode\u003e3b1f104\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.mojo:mojo-parent from 96 to 97\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mojohaus/build-helper-maven-plugin/commit/1749855c90317f651eed427e45cb27c52cf8a542\"\u003e\u003ccode\u003e1749855\u003c/code\u003e\u003c/a\u003e Bump apache/maven-gh-actions-shared/.github/workflows/maven-verify.yml\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mojohaus/build-helper-maven-plugin/commit/52300415d70e84a20924c06c26d9375b152e5409\"\u003e\u003ccode\u003e5230041\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.plexus:plexus-utils from 4.0.2 to 4.0.3\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mojohaus/build-helper-maven-plugin/commit/c0e937567a4604534e32cf3cc4c3abb43bfa243c\"\u003e\u003ccode\u003ec0e9375\u003c/code\u003e\u003c/a\u003e Delete .github/release-drafter.yml\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mojohaus/build-helper-maven-plugin/commit/84a839e4cb9b84b3afbbeef7f6c950ba5b478b31\"\u003e\u003ccode\u003e84a839e\u003c/code\u003e\u003c/a\u003e Bump org.codehaus.mojo:mojo-parent from 95 to 96\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/mojohaus/build-helper-maven-plugin/commit/a85c668b83334b423844fc448709b1d6e53cb32c\"\u003e\u003ccode\u003ea85c668\u003c/code\u003e\u003c/a\u003e Replace raw \u003ccode\u003eNPEx\u003c/code\u003e with customized exception message\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/mojohaus/build-helper-maven-plugin/compare/3.6.1...3.6.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `io.projectreactor:reactor-core` from 3.8.6 to 3.8.7\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/reactor/reactor-core/releases\"\u003eio.projectreactor:reactor-core's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003ev3.8.7\u003c/h2\u003e\n\u003c!-- raw HTML omitted --\u003e\n\u003cp\u003e\u003ccode\u003eReactor Core\u003c/code\u003e \u003ccode\u003e3.8.7\u003c/code\u003e is part of the \u003ccode\u003e2025.0.7\u003c/code\u003e and \u003ccode\u003e2026.0.0-M1\u003c/code\u003e \u003cstrong\u003eRelease Trains\u003c/strong\u003e.\u003c/p\u003e\n\u003ch2\u003eWhat's Changed\u003c/h2\u003e\n\u003ch3\u003e:lady_beetle: Bug fixes\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eFix elapsed time computation in \u003ccode\u003eOptimisticEmitFailureHandler\u003c/code\u003e by \u003ca href=\"https://github.com/bjmi\"\u003e\u003ccode\u003e@​bjmi\u003c/code\u003e\u003c/a\u003e in \u003ca href=\"https://redirect.github.com/reactor/reactor-core/issues/4112\"\u003e#4112\u003c/a\u003e\u003c/li\u003e\n\u003cli\u003eFix \u003ccode\u003ewindowTimeout\u003c/code\u003e fair-backpressure index wraparound by \u003ca href=\"https://github.com/chemicL\"\u003e\u003ccode\u003e@​chemicL\u003c/code\u003e\u003c/a\u003e in 9fdb2cf7108d738fe80e65d010571982610b7eb8\u003c/li\u003e\n\u003cli\u003eGuard against flush-state update in \u003ccode\u003eFluxBufferTimeout\u003c/code\u003e by \u003ca href=\"https://github.com/Sage-Pierce\"\u003e\u003ccode\u003e@​Sage-Pierce\u003c/code\u003e\u003c/a\u003e in 1791421affc59e0a551ba8596e4122c069e782ba\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eNew Contributors\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/bjmi\"\u003e\u003ccode\u003e@​bjmi\u003c/code\u003e\u003c/a\u003e made their first contribution in \u003ca href=\"https://redirect.github.com/reactor/reactor-core/issues/4112\"\u003e#4112\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eFull Changelog\u003c/strong\u003e: \u003ca href=\"https://github.com/reactor/reactor-core/compare/v3.8.6...v3.8.7\"\u003ehttps://github.com/reactor/reactor-core/compare/v3.8.6...v3.8.7\u003c/a\u003e\u003c/p\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/reactor/reactor-core/commit/cda5359710de9a9b70ff432efe0062190a4014d3\"\u003e\u003ccode\u003ecda5359\u003c/code\u003e\u003c/a\u003e [release] Prepare and release 3.8.7\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/reactor/reactor-core/commit/c2b3afd7fb1cdc11b84010b5425ef5827391a3d1\"\u003e\u003ccode\u003ec2b3afd\u003c/code\u003e\u003c/a\u003e Prepare release/3.8.7 branch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/reactor/reactor-core/commit/1791421affc59e0a551ba8596e4122c069e782ba\"\u003e\u003ccode\u003e1791421\u003c/code\u003e\u003c/a\u003e Guard against flush-state update in FluxBufferTimeout\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/reactor/reactor-core/commit/9fdb2cf7108d738fe80e65d010571982610b7eb8\"\u003e\u003ccode\u003e9fdb2cf\u003c/code\u003e\u003c/a\u003e Fix windowTimeout fair-backpressure index wraparound\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/reactor/reactor-core/commit/200db94c591322c27ef972b3ca9356af77176641\"\u003e\u003ccode\u003e200db94\u003c/code\u003e\u003c/a\u003e Prepare main-internal branch\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/reactor/reactor-core/commit/a794eae1d1aacc684133e5124883e922467b8aab\"\u003e\u003ccode\u003ea794eae\u003c/code\u003e\u003c/a\u003e Bump github/codeql-action from 4.37.5 to 4.37.6 in /.github/workflows (\u003ca href=\"https://redirect.github.com/reactor/reactor-core/issues/4353\"\u003e#4353\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/reactor/reactor-core/commit/87cdb28749a3dc76a808ca3f0bc065d97d80b841\"\u003e\u003ccode\u003e87cdb28\u003c/code\u003e\u003c/a\u003e Bump github/codeql-action from 4.37.4 to 4.37.5 in /.github/workflows (\u003ca href=\"https://redirect.github.com/reactor/reactor-core/issues/4351\"\u003e#4351\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/reactor/reactor-core/commit/ed121c4f7201a1c247b2cd85e6ffef31aeb5de68\"\u003e\u003ccode\u003eed121c4\u003c/code\u003e\u003c/a\u003e Bump gradle/actions/wrapper-validation from 6.2.0 to 6.3.0 in /.github/workfl...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/reactor/reactor-core/commit/869b950f6fe2844af08c43b97b00ec76ee021a97\"\u003e\u003ccode\u003e869b950\u003c/code\u003e\u003c/a\u003e Bump gradle/actions/setup-gradle from 6.2.0 to 6.3.0 in /.github/workflows (#...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/reactor/reactor-core/commit/4f160faaf9ee50575ada93cf2f789b6e8747d7ed\"\u003e\u003ccode\u003e4f160fa\u003c/code\u003e\u003c/a\u003e Bump \u003ccode\u003e@​antora/pdf-extension\u003c/code\u003e from 1.0.0-rc.6 to 1.0.0-rc.7 in /docs (\u003ca href=\"https://redirect.github.com/reactor/reactor-core/issues/4348\"\u003e#4348\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/reactor/reactor-core/compare/v3.8.6...v3.8.7\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `com.fasterxml.jackson.core:jackson-databind` from 2.22.1 to 2.22.2\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/25b2a221f9aa4107e455065a74635e209418cf55\"\u003e\u003ccode\u003e25b2a22\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.22.2\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bab1c1a702a941f8805ee6698e8fa4fdbfbec54a\"\u003e\u003ccode\u003ebab1c1a\u003c/code\u003e\u003c/a\u003e Prep for 2.22.2 release\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/bc03cf83d74cf0e5944dce33a63ee59ddc344b64\"\u003e\u003ccode\u003ebc03cf8\u003c/code\u003e\u003c/a\u003e Merge branch '2.21' into 2.22\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/83379fb6409075336edf3d8d88744e95911a43f8\"\u003e\u003ccode\u003e83379fb\u003c/code\u003e\u003c/a\u003e Merge branch '2.20' into 2.21\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/0d400c9dc586fdd460d0c6a40db21ebbe22106d8\"\u003e\u003ccode\u003e0d400c9\u003c/code\u003e\u003c/a\u003e Merge branch '2.19' into 2.20\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/ce36a279f8b078bef2d9d44a1d01034c3634f91a\"\u003e\u003ccode\u003ece36a27\u003c/code\u003e\u003c/a\u003e Merge branch '2.18' into 2.19\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7a209e1fa97033746db50fd7bcd1e3dbab077599\"\u003e\u003ccode\u003e7a209e1\u003c/code\u003e\u003c/a\u003e Post-release dep version bump\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/a432707afe6b7569243d1c2d8052a1bf33d9279c\"\u003e\u003ccode\u003ea432707\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare for next development iteration\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/176df1d48b256ced412c65293ad4e09393e24bd3\"\u003e\u003ccode\u003e176df1d\u003c/code\u003e\u003c/a\u003e [maven-release-plugin] prepare release jackson-databind-2.18.10\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/FasterXML/jackson-databind/commit/7785f5f9ed24127e004115472c47b26ea4cf2774\"\u003e\u003ccode\u003e7785f5f\u003c/code\u003e\u003c/a\u003e Prep for 2.18.10 release\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/FasterXML/jackson-databind/compare/jackson-databind-2.22.1...jackson-databind-2.22.2\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `io.swagger.core.v3:swagger-annotations` from 2.2.52 to 2.2.55\n\nUpdates `org.freemarker:freemarker` from 2.3.34 to 2.3.35\n\nUpdates `net.bytebuddy:byte-buddy-agent` from 1.18.11 to 1.18.13\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/raphw/byte-buddy/releases\"\u003enet.bytebuddy:byte-buddy-agent's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eByte Buddy 1.18.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eActually include the SBOM within the published artifacts.\u003c/li\u003e\n\u003cli\u003eAvoid propagation of path traversals that are contained in jar files which are copied without transformation.\u003c/li\u003e\n\u003cli\u003eAvoid repeated traversal of previously visited type hierarchies to improve performance.\u003c/li\u003e\n\u003cli\u003eCorrect Kotlin support of the Gradle plugin to redirect the classes directory of a source set while retaining support for legacy Gradle versions.\u003c/li\u003e\n\u003cli\u003eCreate Gradle tasks using Gradle's task registration API if available.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eByte Buddy 1.18.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAutomatically support Kotlin in Gradle plugin.\u003c/li\u003e\n\u003cli\u003eAdd support for native attach on Windows for ARM64.\u003c/li\u003e\n\u003cli\u003eCorrect JNA injector which accidentally created on based on Unsafe.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/raphw/byte-buddy/blob/master/release-notes.md\"\u003enet.bytebuddy:byte-buddy-agent's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch3\u003e2. September 2026: version 1.18.13\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eActually include the SBOM within the published artifacts.\u003c/li\u003e\n\u003cli\u003eAvoid propagation of path traversals that are contained in jar files which are copied without transformation.\u003c/li\u003e\n\u003cli\u003eAvoid repeated traversal of previously visited type hierarchies to improve performance.\u003c/li\u003e\n\u003cli\u003eCorrect Kotlin support of the Gradle plugin to redirect the classes directory of a source set while retaining support for legacy Gradle versions.\u003c/li\u003e\n\u003cli\u003eCreate Gradle tasks using Gradle's task registration API if available.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e17. July 2026: version 1.18.12\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAutomatically support Kotlin in Gradle plugin.\u003c/li\u003e\n\u003cli\u003eCorrect JNA injector which accidentally created on based on Unsafe.\u003c/li\u003e\n\u003cli\u003eSupport dynamic attach on Windows ARM64 by shipping a native \u003ccode\u003eattach_hotspot_windows\u003c/code\u003e library for \u003ccode\u003ewin32-aarch64\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raphw/byte-buddy/commit/d4da51578490c841b56b38c9c8fc9d3e8815f046\"\u003e\u003ccode\u003ed4da515\u003c/code\u003e\u003c/a\u003e [publish] Releasing Byte Buddy 1.18.13\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raphw/byte-buddy/commit/bb914e33837267c05704f167179ba31abe3bf787\"\u003e\u003ccode\u003ebb914e3\u003c/code\u003e\u003c/a\u003e [release] Release new version\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raphw/byte-buddy/commit/af2034b8c55c2596f6430e63152586e02d06fd0e\"\u003e\u003ccode\u003eaf2034b\u003c/code\u003e\u003c/a\u003e Create Gradle tasks via the task registration API if available to avoid the u...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raphw/byte-buddy/commit/30aca5581534d52570a60ffd524109adb3671759\"\u003e\u003ccode\u003e30aca55\u003c/code\u003e\u003c/a\u003e Shortcut traversal of previously visited type hierarchies and harden 1-1 tran...\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raphw/byte-buddy/commit/debd527b31bb095c26ff6943545cfe01a9045f32\"\u003e\u003ccode\u003edebd527\u003c/code\u003e\u003c/a\u003e Bump actions/checkout from 6.0.2 to 7.0.1 (\u003ca href=\"https://redirect.github.com/raphw/byte-buddy/issues/1910\"\u003e#1910\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raphw/byte-buddy/commit/8315af6acb72b5e0d913ad65c4112e828f01d735\"\u003e\u003ccode\u003e8315af6\u003c/code\u003e\u003c/a\u003e Bump step-security/harden-runner from 2.16.1 to 2.19.4 (\u003ca href=\"https://redirect.github.com/raphw/byte-buddy/issues/1909\"\u003e#1909\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raphw/byte-buddy/commit/e30e24f4106f6be28b97a34c81bf6d5dccfa34bb\"\u003e\u003ccode\u003ee30e24f\u003c/code\u003e\u003c/a\u003e Bump actions/cache from 5.0.3 to 5.0.5 (\u003ca href=\"https://redirect.github.com/raphw/byte-buddy/issues/1914\"\u003e#1914\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raphw/byte-buddy/commit/1885f2a1e77d70d3cc57ff935e2b5a4b675cde85\"\u003e\u003ccode\u003e1885f2a\u003c/code\u003e\u003c/a\u003e Bump github/codeql-action from 3.27.6 to 4.36.2 (\u003ca href=\"https://redirect.github.com/raphw/byte-buddy/issues/1916\"\u003e#1916\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raphw/byte-buddy/commit/de4ed85e1e4e1e83dcfd90fc791684e3607459fa\"\u003e\u003ccode\u003ede4ed85\u003c/code\u003e\u003c/a\u003e Correct Javadoc of Gradle plugin to avoid errors and warnings during generation.\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raphw/byte-buddy/commit/5d3a3129ceb66ec0c168c9648757cbffccf18aec\"\u003e\u003ccode\u003e5d3a312\u003c/code\u003e\u003c/a\u003e Bump actions/setup-java from 5.2.0 to 5.4.0 (\u003ca href=\"https://redirect.github.com/raphw/byte-buddy/issues/1918\"\u003e#1918\u003c/a\u003e)\u003c/li\u003e\n\u003cli\u003eAdditional commits viewable in \u003ca href=\"https://github.com/raphw/byte-buddy/compare/byte-buddy-1.18.11...byte-buddy-1.18.13\"\u003ecompare view\u003c/a\u003e\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/details\u003e\n\u003cbr /\u003e\n\nUpdates `net.bytebuddy:byte-buddy` from 1.18.11 to 1.18.13\n\u003cdetails\u003e\n\u003csummary\u003eRelease notes\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/raphw/byte-buddy/releases\"\u003enet.bytebuddy:byte-buddy's releases\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch2\u003eByte Buddy 1.18.13\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eActually include the SBOM within the published artifacts.\u003c/li\u003e\n\u003cli\u003eAvoid propagation of path traversals that are contained in jar files which are copied without transformation.\u003c/li\u003e\n\u003cli\u003eAvoid repeated traversal of previously visited type hierarchies to improve performance.\u003c/li\u003e\n\u003cli\u003eCorrect Kotlin support of the Gradle plugin to redirect the classes directory of a source set while retaining support for legacy Gradle versions.\u003c/li\u003e\n\u003cli\u003eCreate Gradle tasks using Gradle's task registration API if available.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch2\u003eByte Buddy 1.18.12\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eAutomatically support Kotlin in Gradle plugin.\u003c/li\u003e\n\u003cli\u003eAdd support for native attach on Windows for ARM64.\u003c/li\u003e\n\u003cli\u003eCorrect JNA injector which accidentally created on based on Unsafe.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eChangelog\u003c/summary\u003e\n\u003cp\u003e\u003cem\u003eSourced from \u003ca href=\"https://github.com/raphw/byte-buddy/blob/master/release-notes.md\"\u003enet.bytebuddy:byte-buddy's changelog\u003c/a\u003e.\u003c/em\u003e\u003c/p\u003e\n\u003cblockquote\u003e\n\u003ch3\u003e2. September 2026: version 1.18.13\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eActually include the SBOM within the published artifacts.\u003c/li\u003e\n\u003cli\u003eAvoid propagation of path traversals that are contained in jar files which are copied without transformation.\u003c/li\u003e\n\u003cli\u003eAvoid repeated traversal of previously visited type hierarchies to improve performance.\u003c/li\u003e\n\u003cli\u003eCorrect Kotlin support of the Gradle plugin to redirect the classes directory of a source set while retaining support for legacy Gradle versions.\u003c/li\u003e\n\u003cli\u003eCreate Gradle tasks using Gradle's task registration API if available.\u003c/li\u003e\n\u003c/ul\u003e\n\u003ch3\u003e17. July 2026: version 1.18.12\u003c/h3\u003e\n\u003cul\u003e\n\u003cli\u003eAutomatically support Kotlin in Gradle plugin.\u003c/li\u003e\n\u003cli\u003eCorrect JNA injector which accidentally created on based on Unsafe.\u003c/li\u003e\n\u003cli\u003eSupport dynamic attach on Windows ARM64 by shipping a native \u003ccode\u003eattach_hotspot_windows\u003c/code\u003e library for \u003ccode\u003ewin32-aarch64\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/blockquote\u003e\n\u003c/details\u003e\n\u003cdetails\u003e\n\u003csummary\u003eCommits\u003c/summary\u003e\n\u003cul\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raphw/byte-buddy/commit/d4da51578490c841b56b38c9c8fc9d3e8815f046\"\u003e\u003ccode\u003ed4da515\u003c/code\u003e\u003c/a\u003e [publish] Releasing Byte Buddy 1.18.13\u003c/li\u003e\n\u003cli\u003e\u003ca href=\"https://github.com/raphw/byte-buddy/commit/bb914e33837267c0...\n\n_Description has been truncated_","html_url":"https://github.com/miguelperezcolom/mateu/pull/494","url":"https://dependabot.ecosyste.ms/api/v1/hosts/GitHub/repositories/miguelperezcolom%2Fmateu/issues/494","packages_url":"https://dependabot.ecosyste.ms/api/v1/issues/494/packages"}}]}