An open index of dependabot pull requests across open source projects.

Bump the all-maven-dependencies group across 2 directories with 4 updates

Open
Number: #527
Type: Pull Request
State: Open
Author: dependabot[bot] dependabot[bot]
Association: Contributor
Comments: 0
Created: August 11, 2025 at 04:36 PM UTC
(12 months ago)
Updated: August 20, 2025 at 10:54 AM UTC
(11 months ago)
Labels:
dependencies java
Description:

Bumps the all-maven-dependencies group with 4 updates in the / directory: com.sap.cloud.sdk:sdk-modules-bom, com.sap.cloud.security:java-bom, com.sap.hcp.cf.logging:cf-java-logging-support-servlet-jakarta and com.sap.hcp.cf.logging:cf-java-logging-support-logback.
Bumps the all-maven-dependencies group with 4 updates in the /srv directory: com.sap.cloud.sdk:sdk-modules-bom, com.sap.cloud.security:java-bom, com.sap.hcp.cf.logging:cf-java-logging-support-servlet-jakarta and com.sap.hcp.cf.logging:cf-java-logging-support-logback.

Updates com.sap.cloud.sdk:sdk-modules-bom from 5.20.0 to 5.21.0

Release notes

Sourced from com.sap.cloud.sdk:sdk-modules-bom's releases.

Release 5.21.0

What's Changed

Full Changelog: https://github.com/SAP/cloud-sdk-java/commits/rel/5.21.0

Commits
  • 8ac54bb Update to version 5.21.0
  • 75f4b25 chore: "Release 5.21.0 (#875)" (#877)
  • 568a610 chore: Fix release of bom/pom.xml (#876)
  • e85463a Release 5.21.0 (#875)
  • e47be24 [BlackDuck] Fix CVE-2024-7254 (#873)
  • 08f2777 fix: (odata-client) Move disable-buffer toggle from result object to request ...
  • d283f4c chore: bump org.apache.commons:commons-lang3 from 3.17.0 to 3.18.0 in /depend...
  • f4e4284 chore: Migrate release process to maven central (#866)
  • f0be91a feat: [Connectivity] Introduce OAuth2Option for token cache parameters (#860)
  • 213c929 fix: [Connectivity] Change default token cache duration to 1hr (#861)
  • Additional commits viewable in compare view

Updates com.sap.cloud.security:java-bom from 3.6.1 to 3.6.2

Release notes

Sourced from com.sap.cloud.security:java-bom's releases.

3.6.2

  • Improve logging before token key retrieval fallback
  • remove repository config for old sonatype plugin
  • added version references to POMs and other minor informations
  • Update README.md for using correct path to SpringTokenClientConfigura…
  • Maven central preparation

Dependency upgrades

  • Bump com.github.spotbugs:spotbugs-maven-plugin from 4.9.3.1 to 4.9.3.2
  • Bump io.github.hakky54:logcaptor from 2.11.0 to 2.12.0
  • Bump org.eclipse.jetty.version from 12.0.22 to 12.0.24
  • Bump org.apache.maven.plugins:maven-gpg-plugin from 3.2.7 to 3.2.8
  • Bump log4j2.version from 2.25.0 to 2.25.1
  • Bump commons-io:commons-io from 2.19.0 to 2.20.0
  • Bump reactor.version from 3.7.7 to 3.7.8
  • Bump spring.core.version from 6.2.8 to 6.2.9
  • Bump spring.security.version from 6.5.1 to 6.5.2
  • Bump spring.boot.version from 3.5.3 to 3.5.4
  • Bump com.github.spotbugs:spotbugs-maven-plugin from 4.9.3.0 to 4.9.3.1
  • Bump org.apache.maven.plugins:maven-pmd-plugin from 3.26.0 to 3.27.0
  • Bump spring.security.version from 6.5.0 to 6.5.1
  • Bump spring.boot.version from 3.5.0 to 3.5.3
Changelog

Sourced from com.sap.cloud.security:java-bom's changelog.

3.6.2

  • Improve logging before token key retrieval fallback
  • remove repository config for old sonatype plugin
  • added version references to POMs and other minor informations
  • Update README.md for using correct path to SpringTokenClientConfigura…
  • Maven central preparation

Dependency upgrades

  • Bump com.github.spotbugs:spotbugs-maven-plugin from 4.9.3.1 to 4.9.3.2
  • Bump io.github.hakky54:logcaptor from 2.11.0 to 2.12.0
  • Bump org.eclipse.jetty.version from 12.0.22 to 12.0.24
  • Bump org.apache.maven.plugins:maven-gpg-plugin from 3.2.7 to 3.2.8
  • Bump log4j2.version from 2.25.0 to 2.25.1
  • Bump commons-io:commons-io from 2.19.0 to 2.20.0
  • Bump reactor.version from 3.7.7 to 3.7.8
  • Bump spring.core.version from 6.2.8 to 6.2.9
  • Bump spring.security.version from 6.5.1 to 6.5.2
  • Bump spring.boot.version from 3.5.3 to 3.5.4
  • Bump com.github.spotbugs:spotbugs-maven-plugin from 4.9.3.0 to 4.9.3.1
  • Bump org.apache.maven.plugins:maven-pmd-plugin from 3.26.0 to 3.27.0
  • Bump spring.security.version from 6.5.0 to 6.5.1
  • Bump spring.boot.version from 3.5.0 to 3.5.3
Commits
  • bbb1046 Release 3.6.2 (#1827)
  • 8c621a0 Bump com.github.spotbugs:spotbugs-maven-plugin from 4.9.3.1 to 4.9.3.2 (#1801)
  • 1802602 Bump io.github.hakky54:logcaptor from 2.11.0 to 2.12.0 (#1825)
  • 2de9652 Bump org.eclipse.jetty.version from 12.0.22 to 12.0.24 (#1826)
  • f3302ef Bump org.apache.maven.plugins:maven-gpg-plugin from 3.2.7 to 3.2.8 (#1804)
  • 647ff9e Bump log4j2.version from 2.25.0 to 2.25.1 (#1805)
  • 0b119f1 Bump commons-io:commons-io from 2.19.0 to 2.20.0 (#1809)
  • 02c1fef Bump reactor.version from 3.7.7 to 3.7.8 (#1820)
  • d89a04e Bump spring.core.version from 6.2.8 to 6.2.9 (#1816)
  • ab4a352 Bump spring.security.version from 6.5.1 to 6.5.2 (#1817)
  • Additional commits viewable in compare view

Updates com.sap.hcp.cf.logging:cf-java-logging-support-servlet-jakarta from 3.8.5 to 3.8.6

Release notes

Sourced from com.sap.hcp.cf.logging:cf-java-logging-support-servlet-jakarta's releases.

v3.8.6

What's Changed

This is a minor upgrade of dependencies. The OTel SDK is required to be compatible with newer releases of the OTel SDK. It contains code changes that fix compile errors because of removed or now restricted functions.

Full Changelog: https://github.com/SAP/cf-java-logging-support/compare/v3.8.5...v3.8.6

Commits
  • edca148 Adjust Maven Central Deployment after OSSRH sunset
  • 639d3b3 Release 3.8.6
  • 518e35a Merge pull request #211 from SAP/dependabot/maven/cf-java-logging-support-cor...
  • a5312b2 Bump org.apache.commons:commons-lang3 in /cf-java-logging-support-core
  • 0e5a58e Merge pull request #212 from SAP/otel-sdk-upgrade
  • 36d66d2 Upgrade OTel SDK Dependency
  • 7e4983e Update README.md
  • See full diff in compare view

Updates com.sap.hcp.cf.logging:cf-java-logging-support-logback from 3.8.5 to 3.8.6

Release notes

Sourced from com.sap.hcp.cf.logging:cf-java-logging-support-logback's releases.

v3.8.6

What's Changed

This is a minor upgrade of dependencies. The OTel SDK is required to be compatible with newer releases of the OTel SDK. It contains code changes that fix compile errors because of removed or now restricted functions.

Full Changelog: https://github.com/SAP/cf-java-logging-support/compare/v3.8.5...v3.8.6

Commits
  • edca148 Adjust Maven Central Deployment after OSSRH sunset
  • 639d3b3 Release 3.8.6
  • 518e35a Merge pull request #211 from SAP/dependabot/maven/cf-java-logging-support-cor...
  • a5312b2 Bump org.apache.commons:commons-lang3 in /cf-java-logging-support-core
  • 0e5a58e Merge pull request #212 from SAP/otel-sdk-upgrade
  • 36d66d2 Upgrade OTel SDK Dependency
  • 7e4983e Update README.md
  • See full diff in compare view

Updates com.sap.hcp.cf.logging:cf-java-logging-support-logback from 3.8.5 to 3.8.6

Release notes

Sourced from com.sap.hcp.cf.logging:cf-java-logging-support-logback's releases.

v3.8.6

What's Changed

This is a minor upgrade of dependencies. The OTel SDK is required to be compatible with newer releases of the OTel SDK. It contains code changes that fix compile errors because of removed or now restricted functions.

Full Changelog: https://github.com/SAP/cf-java-logging-support/compare/v3.8.5...v3.8.6

Commits
  • edca148 Adjust Maven Central Deployment after OSSRH sunset
  • 639d3b3 Release 3.8.6
  • 518e35a Merge pull request #211 from SAP/dependabot/maven/cf-java-logging-support-cor...
  • a5312b2 Bump org.apache.commons:commons-lang3 in /cf-java-logging-support-core
  • 0e5a58e Merge pull request #212 from SAP/otel-sdk-upgrade
  • 36d66d2 Upgrade OTel SDK Dependency
  • 7e4983e Update README.md
  • See full diff in compare view

Updates com.sap.cloud.sdk:sdk-modules-bom from 5.20.0 to 5.21.0

Release notes

Sourced from com.sap.cloud.sdk:sdk-modules-bom's releases.

Release 5.21.0

What's Changed

Full Changelog: https://github.com/SAP/cloud-sdk-java/commits/rel/5.21.0

Commits
  • 8ac54bb Update to version 5.21.0
  • 75f4b25 chore: "Release 5.21.0 (#875)" (#877)
  • 568a610 chore: Fix release of bom/pom.xml (#876)
  • e85463a Release 5.21.0 (#875)
  • e47be24 [BlackDuck] Fix CVE-2024-7254 (#873)
  • 08f2777 fix: (odata-client) Move disable-buffer toggle from result object to request ...
  • d283f4c chore: bump org.apache.commons:commons-lang3 from 3.17.0 to 3.18.0 in /depend...
  • f4e4284 chore: Migrate release process to maven central (#866)
  • f0be91a feat: [Connectivity] Introduce OAuth2Option for token cache parameters (#860)
  • 213c929 fix: [Connectivity] Change default token cache duration to 1hr (#861)
  • Additional commits viewable in compare view

Updates com.sap.cloud.security:java-bom from 3.6.1 to 3.6.2

Release notes

Sourced from com.sap.cloud.security:java-bom's releases.

3.6.2

  • Improve logging before token key retrieval fallback
  • remove repository config for old sonatype plugin
  • added version references to POMs and other minor informations
  • Update README.md for using correct path to SpringTokenClientConfigura…
  • Maven central preparation

Dependency upgrades

  • Bump com.github.spotbugs:spotbugs-maven-plugin from 4.9.3.1 to 4.9.3.2
  • Bump io.github.hakky54:logcaptor from 2.11.0 to 2.12.0
  • Bump org.eclipse.jetty.version from 12.0.22 to 12.0.24
  • Bump org.apache.maven.plugins:maven-gpg-plugin from 3.2.7 to 3.2.8
  • Bump log4j2.version from 2.25.0 to 2.25.1
  • Bump commons-io:commons-io from 2.19.0 to 2.20.0
  • Bump reactor.version from 3.7.7 to 3.7.8
  • Bump spring.core.version from 6.2.8 to 6.2.9
  • Bump spring.security.version from 6.5.1 to 6.5.2
  • Bump spring.boot.version from 3.5.3 to 3.5.4
  • Bump com.github.spotbugs:spotbugs-maven-plugin from 4.9.3.0 to 4.9.3.1
  • Bump org.apache.maven.plugins:maven-pmd-plugin from 3.26.0 to 3.27.0
  • Bump spring.security.version from 6.5.0 to 6.5.1
  • Bump spring.boot.version from 3.5.0 to 3.5.3
Changelog

Sourced from com.sap.cloud.security:java-bom's changelog.

3.6.2

  • Improve logging before token key retrieval fallback
  • remove repository config for old sonatype plugin
  • added version references to POMs and other minor informations
  • Update README.md for using correct path to SpringTokenClientConfigura…
  • Maven central preparation

Dependency upgrades

  • Bump com.github.spotbugs:spotbugs-maven-plugin from 4.9.3.1 to 4.9.3.2
  • Bump io.github.hakky54:logcaptor from 2.11.0 to 2.12.0
  • Bump org.eclipse.jetty.version from 12.0.22 to 12.0.24
  • Bump org.apache.maven.plugins:maven-gpg-plugin from 3.2.7 to 3.2.8
  • Bump log4j2.version from 2.25.0 to 2.25.1
  • Bump commons-io:commons-io from 2.19.0 to 2.20.0
  • Bump reactor.version from 3.7.7 to 3.7.8
  • Bump spring.core.version from 6.2.8 to 6.2.9
  • Bump spring.security.version from 6.5.1 to 6.5.2
  • Bump spring.boot.version from 3.5.3 to 3.5.4
  • Bump com.github.spotbugs:spotbugs-maven-plugin from 4.9.3.0 to 4.9.3.1
  • Bump org.apache.maven.plugins:maven-pmd-plugin from 3.26.0 to 3.27.0
  • Bump spring.security.version from 6.5.0 to 6.5.1
  • Bump spring.boot.version from 3.5.0 to 3.5.3
Commits
  • bbb1046 Release 3.6.2 (#1827)
  • 8c621a0 Bump com.github.spotbugs:spotbugs-maven-plugin from 4.9.3.1 to 4.9.3.2 (#1801)
  • 1802602 Bump io.github.hakky54:logcaptor from 2.11.0 to 2.12.0 (#1825)
  • 2de9652 Bump org.eclipse.jetty.version from 12.0.22 to 12.0.24 (#1826)
  • f3302ef Bump org.apache.maven.plugins:maven-gpg-plugin from 3.2.7 to 3.2.8 (#1804)
  • 647ff9e Bump log4j2.version from 2.25.0 to 2.25.1 (#1805)
  • 0b119f1 Bump commons-io:commons-io from 2.19.0 to 2.20.0 (#1809)
  • 02c1fef Bump reactor.version from 3.7.7 to 3.7.8 (#1820)
  • d89a04e Bump spring.core.version from 6.2.8 to 6.2.9 (#1816)
  • ab4a352 Bump spring.security.version from 6.5.1 to 6.5.2 (#1817)
  • Additional commits viewable in compare view

Updates com.sap.hcp.cf.logging:cf-java-logging-support-servlet-jakarta from 3.8.5 to 3.8.6

Release notes

Sourced from com.sap.hcp.cf.logging:cf-java-logging-support-servlet-jakarta's releases.

v3.8.6

What's Changed

This is a minor upgrade of dependencies. The OTel SDK is required to be compatible with newer releases of the OTel SDK. It contains code changes that fix compile errors because of removed or now restricted functions.

Full Changelog: https://github.com/SAP/cf-java-logging-support/compare/v3.8.5...v3.8.6

Commits
  • edca148 Adjust Maven Central Deployment after OSSRH sunset
  • 639d3b3 Release 3.8.6
  • 518e35a Merge pull request #211 from SAP/dependabot/maven/cf-java-logging-support-cor...
  • a5312b2 Bump org.apache.commons:commons-lang3 in /cf-java-logging-support-core
  • 0e5a58e Merge pull request #212 from SAP/otel-sdk-upgrade
  • 36d66d2 Upgrade OTel SDK Dependency
  • 7e4983e Update README.md
  • See full diff in compare view

Updates com.sap.hcp.cf.logging:cf-java-logging-support-logback from 3.8.5 to 3.8.6

Release notes

Sourced from com.sap.hcp.cf.logging:cf-java-logging-support-logback's releases.

v3.8.6

What's Changed

This is a minor upgrade of dependencies. The OTel SDK is required to be compatible with newer releases of the OTel SDK. It contains code changes that fix compile errors because of removed or now restricted functions.

Full Changelog: https://github.com/SAP/cf-java-logging-support/compare/v3.8.5...v3.8.6

Commits
  • edca148 Adjust Maven Central Deployment after OSSRH sunset
  • 639d3b3 Release 3.8.6
  • 518e35a Merge pull request #211 from SAP/dependabot/maven/cf-java-logging-support-cor...
  • a5312b2 Bump org.apache.commons:commons-lang3 in /cf-java-logging-support-core
  • 0e5a58e Merge pull request #212 from SAP/otel-sdk-upgrade
  • 36d66d2 Upgrade OTel SDK Dependency
  • 7e4983e Update README.md
  • See full diff in compare view

Updates com.sap.hcp.cf.logging:cf-java-logging-support-logback from 3.8.5 to 3.8.6

Release notes

Sourced from com.sap.hcp.cf.logging:cf-java-logging-support-logback's releases.

v3.8.6

What's Changed

This is a minor upgrade of dependencies. The OTel SDK is required to be compatible with newer releases of the OTel SDK. It contains code changes that fix compile errors because of removed or now restricted functions.

Full Changelog: https://github.com/SAP/cf-java-logging-support/compare/v3.8.5...v3.8.6

Commits
  • edca148 Adjust Maven Central Deployment after OSSRH sunset
  • 639d3b3 Release 3.8.6
  • 518e35a Merge pull request #211 from SAP/dependabot/maven/cf-java-logging-support-cor...
  • a5312b2 Bump org.apache.commons:commons-lang3 in /cf-java-logging-support-core
  • 0e5a58e Merge pull request #212 from SAP/otel-sdk-upgrade
  • 36d66d2 Upgrade OTel SDK Dependency
  • 7e4983e Update README.md
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
Pull Request Statistics
Commits:
1
Files Changed:
1
Additions:
+3
Deletions:
-3
Package Dependencies
Ecosystem:
maven
Version Change:
3.8.5 → 3.8.6
Update Type:
Patch
Ecosystem:
maven
Version Change:
3.8.5 → 3.8.6
Update Type:
Patch
Ecosystem:
maven
Version Change:
5.20.0 → 5.21.0
Update Type:
Minor
Ecosystem:
maven
Version Change:
3.6.1 → 3.6.2
Update Type:
Patch
Technical Details
ID: 4902186
UUID: 2736170480
Node ID: PR_kwDOD4OiKs6jFqXw
Host: GitHub
Repository: SAP-samples/cloud-cap-samples-java
Merge State: Unknown