chore: bump org.assertj:assertj-core from 3.27.6 to 3.27.7 in /powertools-tracing
Open
Number: #2417
Type: Pull Request
State: Open
Type: Pull Request
State: Open
Author:
dependabot[bot]
Association: Unknown
Comments: 1
Association: Unknown
Comments: 1
Created:
March 17, 2026 at 10:54 AM UTC
(3 months ago)
(3 months ago)
Updated:
March 17, 2026 at 10:56 AM UTC
(3 months ago)
(3 months ago)
Labels:
dependencies size/XS java
dependencies size/XS java
Description:
Bumps org.assertj:assertj-core from 3.27.6 to 3.27.7.
Release notes
Sourced from org.assertj:assertj-core's releases.
v3.27.7
:lock: Security
Core
- Fix XXE vulnerability in
isXmlEqualToassertion (CVE-2026-24400):no_entry_sign: Deprecated
Core
- Deprecate
XmlStringPrettyFormatterwith no replacement:bug: Bug Fixes
Guava
- Navigation to
assertj-coreorguavatypes fromassertj-guavaJavadoc site has unnecessary header #3478:hammer: Dependency Upgrades
Core
- Upgrade to Byte Buddy 1.18.3
- Upgrade to JUnit BOM 5.14.1
Guava
- Upgrade to Guava 33.5.0-jre
Commits
e840716[maven-release-plugin] prepare release assertj-build-3.27.785ca7ebDeprecateXmlStringPrettyFormatter77081dcMerge commit from forkb68fc24Bump github/codeql-action from 4.31.9 to 4.31.10 in the github-actions group ...0cf5bb6Bumpkotlin.versionfrom 2.1.0 to 2.2.21d393ef1Abort tests when symbolic links cannot be created (#3788)2212433Add IntelliJ custom inspection for test class names5717d02Update JetBrains icona8ec20bAdd icon for JetBrains productsc05fb3dBump Maven to 3.9.12 and Wrapper to 3.3.4- Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
You can disable automated security fix PRs for this repo from the Security Alerts page.
Package Dependencies
Package:
org.assertj:assertj-core
Ecosystem:
maven
maven
Version Change:
3.27.6 → 3.27.7
Update Type:
Patch
Patch
Path:
/powertools-tracing
Technical Details
| ID: | 14664765 |
| UUID: | 4087758148 |
| Node ID: | PR_kwDOEKdwoM7LL-T- |
| Host: | GitHub |
| Repository: | aws-powertools/powertools-lambda-java |