chore(deps-dev): bump org.assertj:assertj-core from 3.27.6 to 3.27.7
Closed
Number: #10
Type: Pull Request
State: Closed
Type: Pull Request
State: Closed
Author:
dependabot[bot]
Association: Unknown
Comments: 2
Association: Unknown
Comments: 2
Created:
January 26, 2026 at 01:39 AM UTC
(5 months ago)
(5 months ago)
Updated:
February 09, 2026 at 04:52 AM UTC
(4 months ago)
(4 months ago)
Closed:
February 09, 2026 at 04:52 AM UTC
(4 months ago)
(4 months ago)
Time to Close:
14 days
Labels:
dependencies java
dependencies java
Description:
Bumps org.assertj:assertj-core from 3.27.6 to 3.27.7.
Release notes
Sourced from org.assertj:assertj-core's releases.
v3.27.7
:lock: Security
Core
- Fix XXE vulnerability in
isXmlEqualToassertion (CVE-2026-24400)
- See GHSA-rqfh-9r24-8c9r for details; many thanks to
@wxt201and@Song-Lifor responsibly reporting it!:no_entry_sign: Deprecated
Core
- Deprecate
XmlStringPrettyFormatterwith no replacement:bug: Bug Fixes
Guava
- Navigation to
assertj-coreorguavatypes fromassertj-guavaJavadoc site has unnecessary header #3478:hammer: Dependency Upgrades
Core
- Upgrade to Byte Buddy 1.18.3
- Upgrade to JUnit BOM 5.14.1
Guava
- Upgrade to Guava 33.5.0-jre
Commits
e840716[maven-release-plugin] prepare release assertj-build-3.27.785ca7ebDeprecateXmlStringPrettyFormatter77081dcMerge commit from forkb68fc24Bump github/codeql-action from 4.31.9 to 4.31.10 in the github-actions group ...0cf5bb6Bumpkotlin.versionfrom 2.1.0 to 2.2.21d393ef1Abort tests when symbolic links cannot be created (#3788)2212433Add IntelliJ custom inspection for test class names5717d02Update JetBrains icona8ec20bAdd icon for JetBrains productsc05fb3dBump Maven to 3.9.12 and Wrapper to 3.3.4- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot mergewill merge this PR after your CI passes on it@dependabot squash and mergewill squash and merge this PR after your CI passes on it@dependabot cancel mergewill cancel a previously requested merge and block automerging@dependabot reopenwill reopen this PR if it is closed@dependabot closewill close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Package Dependencies
Package:
org.assertj:assertj-core
Ecosystem:
maven
maven
Version Change:
3.27.6 → 3.27.7
Update Type:
Patch
Patch
Technical Details
| ID: | 13645096 |
| UUID: | 3854199093 |
| Node ID: | PR_kwDOQlqnN86_Rtrk |
| Host: | GitHub |
| Repository: | 63345/java-algorithms |