Skip to content

Bump the maven-dependencies group across 1 directory with 15 updates - #4374

Merged
evanchooly merged 1 commit into
masterfrom
dependabot/maven/maven-dependencies-759d958508
Oct 8, 2026
Merged

evanchooly merged 1 commit into
masterfrom
dependabot/maven/maven-dependencies-759d958508

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the maven-dependencies group with 15 updates in the / directory:

Package From To
org.junit:junit-bom 6.1.0 6.1.3
org.slf4j:slf4j-api 2.0.18 2.0.20
org.slf4j:slf4j-simple 2.0.18 2.0.20
org.slf4j:slf4j-simple 2.0.18 2.0.20
ch.qos.logback:logback-classic 1.5.36 1.6.5
org.apache.maven:maven-model 4.0.0-rc-6 4.0.0-rc-7
io.smallrye.config:smallrye-config 3.17.2 4.0.0
org.zeroturnaround:zt-exec 1.12 1.13.0
com.github.spotbugs:spotbugs-annotations 4.10.2 4.10.4
net.bytebuddy:byte-buddy 1.18.10 1.18.14
io.github.classgraph:classgraph 4.8.184 4.8.196
com.google.devtools.ksp:symbol-processing-api 2.3.9 2.3.12
com.google.devtools.ksp:symbol-processing-common-deps 2.3.9 2.3.12
com.google.devtools.ksp:symbol-processing-aa-embeddable 2.3.9 2.3.12
com.google.devtools.ksp:symbol-processing-common-deps 2.3.9 2.3.12
com.google.devtools.ksp:symbol-processing-aa-embeddable 2.3.9 2.3.12
org.apache.maven.plugins:maven-compiler-plugin 3.15.0 3.16.0
org.apache.maven.plugins:maven-jar-plugin 3.5.0 3.5.1

Updates org.junit:junit-bom from 6.1.0 to 6.1.3

Release notes

Sourced from org.junit:junit-bom's releases.

JUnit 6.1.3 = Platform 6.1.3 + Jupiter 6.1.3 + Vintage 6.1.3

See Release Notes.

Full Changelog: junit-team/junit-framework@r6.1.2...r6.1.3

JUnit 6.1.2 = Platform 6.1.2 + Jupiter 6.1.2 + Vintage 6.1.2

See Release Notes.

Full Changelog: junit-team/junit-framework@r6.1.1...r6.1.2

JUnit 6.1.1 = Platform 6.1.1 + Jupiter 6.1.1 + Vintage 6.1.1

See Release Notes.

Full Changelog: junit-team/junit-framework@r6.1.0...r6.1.1

Commits
  • f59f60d Release 6.1.3
  • cd8ec92 Finalize 6.1.3 release notes
  • c8729f2 Restore compatibility with GraalVM 25 (#5901)
  • ddc9e74 Update graalvm/setup-graalvm action to v1.6.4 (#5959)
  • fe2c52a Update plugin org.graalvm.buildtools.native to v1.1.7 (#5923)
  • 62afc02 Delay GraalVM plugin updates for 3 days
  • 0cc2902 Skip graalVmTest task if GraalVM env vars are not set
  • f6bbfc5 Move GraalVM tests to separate test task (#5903)
  • e87e052 Update plugin org.graalvm.buildtools.native to v1.1.6 (#5899)
  • 1cd56df Update plugin org.graalvm.buildtools.native to v1.1.5 (#5880)
  • Additional commits viewable in compare view

Updates org.slf4j:slf4j-api from 2.0.18 to 2.0.20

Updates org.slf4j:slf4j-simple from 2.0.18 to 2.0.20

Updates org.slf4j:slf4j-simple from 2.0.18 to 2.0.20

Updates ch.qos.logback:logback-classic from 1.5.36 to 1.6.5

Release notes

Sourced from ch.qos.logback:logback-classic's releases.

Logback 1.6.5

2026-09-30 Release of logback version 1.6.5

• Fixed a vulnerability CVE-2026-104721 closely related to CVE-2026-19880. The fix in version 1.6.3, which strips forward and backward slashes from MDC values, was insufficient. An MDC value could still contain relative path components such as .., variable references such as /, or characters that are special in file name patterns and email addresses. This latest vulnerability was found and reported by François Martin (GitHub: @​martinfrancois, https://github.com/martinfrancois).

MDCBasedDiscriminator, used by SiftingAppender, now rejects MDC values instead of stripping characters from them. An MDC value is rejected if it is empty, if it is longer than 64 characters, if it contains the sequence .., or if it contains any of the following characters: / \ $ { } [ ] ( ) | ? * + % , @. When an MDC value is rejected, the discriminator returns the value of its DefaultValue property. A warning is emitted for each rejected value. These warnings are rate-limited.

• When compression is enabled, TimeBasedRollingPolicy and SizeAndTimeBasedRollingPolicy now also remove old log files that were never compressed, for example because the application was not running at rollover time. Previously, such files were ignored by maxHistory and accumulated indefinitely. This issue was discussed in discussions/1032. See TimeBasedRollingPolicy.

• SimpleInvocationGate, deprecated in version 1.6.3, is now marked for removal. Use FixedIntervalInvocationGate instead.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit d1b829dcdb9fd98511c64401beb1419a9c9384aa associated with the tag v_1.6.5. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Logback 1.6.4

2026-09-24 Release of logback version 1.6.4

• Variable substitution is again applied to the scan attribute of the <configuration> element. The scanning refactoring in version 1.5.27 had dropped substitution, so values such as ${logback.scan.enabled:-true} were no longer resolved. As before version 1.5.27, an unrecognized non-empty value turns scanning on. The same substitution now applies to the scan attribute of <propertiesConfigurator>. This regression was reported in issues/1065 by vaibhavjain2.

• OutputStreamAppender and FileAppender now handle stateful encoders. The Encoder interface has a new default method called isStateful(), which returns false. An encoder that keeps state between calls to encode() can return true. For such encoders, the appender holds its write lock while encoding and while writing, so the output of concurrent appends cannot interleave. Stateless encoders still encode outside the lock, so their performance does not change. Existing encoders need no changes.

• Several race conditions in OutputStreamAppender and FileAppender were fixed. The appender is now marked started and the encoder header is written while the same lock is held, so a concurrent append can no longer write an event before the header. After acquiring the lock, the appender checks again whether it has been stopped, so no event is written after the footer. In prudent mode, FileAppender now encodes and writes each event while holding the lock.

• Fixed a data race on the logger count in LoggerContext. Loggers are created under the lock of their parent logger, so loggers with different parents could be created at the same time and increments of the shared counter could be lost. As a result, LoggerContext.size() could return a value lower than the actual number of loggers. The counter is now an AtomicInteger. This issue was reported in issues/1038 by hcantunc. The fix was contributed in PR #1055 by seonwoo_jung.

• TimeBasedRollingPolicy now supports half-day periods. Date patterns with the AM/PM marker, for example %d{yyyy-MM-dd-a}, used to be detected as daily and rolled over only at midnight. They now roll over at both 00:00 and 12:00. This issue was reported in issues/976 by shakthifuture. The fix was contributed in PR #1051 by seonwoo_jung. See TimeBasedRollingPolicy.

• If org.jline.jansi.AnsiConsole cannot be found on the class path, JansiConsoleAppender now emits warnings that explain how to add org.jline:jansi-core and then writes to the plain console stream. See codes.html#missingJlineJansi.

• The unused ch.qos.logback.classic.util.LogbackMDCAdapterSimple class was removed. LogbackMDCAdapter remains the default MDC adapter.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit 07d291ca0d280bc5da934ec9ff5f1da634fd7937 associated with the tag v_1.6.4. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Full Changelog: qos-ch/logback@v_1.6.3...v_1.6.4

Logback 1.6.3

2026-08-14 Release of logback version 1.6.3

  • In response CVE-2026-19880, MDCBasedDiscriminator (used by SiftingAppender) now strips forward and backward slashes (/, \) from MDC values before they are used as discriminating keys. This prevents path segments from escaping into destinations controlled by an attacker. When sanitisation actually changes a value, a warning is emitted; the warning is rate-limited (a small batch, then a lull of about ten minutes).

  • Colour console support is split out into a dedicated JansiConsoleAppender. It wraps stdout or stderr with Jansi so ANSI escape sequences (for example coloured patterns) render correctly on terminals that need it, notably Windows. Prefer this class over the older path described next. See the appenders documentation.

  • The withJansi property on ConsoleAppender is deprecated. Existing configurations that still set <withJansi>true</withJansi> continue to work for compatibility, but new setups should use JansiConsoleAppender instead.

  • ConsoleAppender no longer treats the process console as an exclusive resource: stopping it does not close System.out / System.err. JansiConsoleAppender pairs each AnsiConsole.systemInstall() with systemUninstall() on stop, so repeated start/stop cycles do not leave Jansi installed or tear down streams shared with the rest of the JVM. Related behavior is covered by tests for issues/1063.

  • Invocation throttling helpers were reworked: SimpleInvocationGate is renamed FixedIntervalInvocationGate, and BatchedFixedIntervalInvocationGate allows a short burst of invocations before applying a fixed lull. The sanitisation warning above uses the batched gate.

  • The JPMS module-info for logback-core now exports the ch.qos.logback.core.property package, which had been missing from the module descriptor.

... (truncated)

Commits
  • d1b829d prepare release 1.6.5
  • 065b9b2 enhance protectin against mischievious MDC values in MDCBasedDiscriminator
  • b69beab complete commit in relation to discussion_1032
  • 7266c0b fix intermittently failing SocketAppenderMessageLossTest rest condition
  • a633bb0 fix intermittently failing SocketAppenderMessageLossTest rest condition
  • 2bc5bcc renamed tbrp and eclosingTBRP, other minor changes
  • 2cd8762 fix typo in AGENTS.md
  • 647846c fix errors when running tests under intellij IDEA
  • 1048917 removed ConsoleCharsetPropertyDefiner.java
  • 39b5002 added 'since' and 'forRemoval' attributes to SimpleInvocationGate @​Deprecatio...
  • Additional commits viewable in compare view

Updates org.apache.maven:maven-model from 4.0.0-rc-6 to 4.0.0-rc-7

Updates io.smallrye.config:smallrye-config from 3.17.2 to 4.0.0

Release notes

Sourced from io.smallrye.config:smallrye-config's releases.

4.0.0

  • #1594 Release 4.0.0
  • #1593 Update to SmallRye Parent 52
  • #1592 Prefer AtomicReference instead of a Holder object

4.0.0.CR3

  • #1591 Release 4.0.0.CR3
  • #1589 Use ClassValue to cache ConfigMappingInterface and ConfigMappingClass

4.0.0.CR2

  • #1588 Release 4.0.0.CR2
  • #1587 Remove cache of implicit Converters due to memory leaks
  • #1583 Bump version.smallrye.testing from 2.5.0 to 2.5.1

4.0.0.CR1

  • #1582 Release 4.0.0.CR1
  • #1581 Add a Spring module to support Spring @ConfigurationProperties
  • #1580 Warn on mapping ambiguous single segment quoted / unquoted Map keys
  • #1579 Rewrite PropertyName equals to a segment by segment matching engine and cover missing cases
  • #1576 Register profile names with SecretKeys
  • #1575 Remove KeyMap
  • #1574 Update to Surefire 3.6.0 for the TCK
  • #1573 Bump io.sundr:sundr-maven-plugin from 0.300.0 to 0.400.0
  • #1571 Bump mkdocs-material from 9.7.6 to 9.7.7 in /documentation
  • #1570 Bump org.yaml:snakeyaml from 2.6 to 2.7
  • #1569 Remove deprecated SmallRyeConfig#getRawValue
  • #1568 Use backslash escaping for property expressions
  • #1566 Simplify CDI injection of Collections and Maps
  • #1565 Remove the generation of a comma separated value name for Collections in the YamlConfigSource
  • #1564 Remove CDI config-source-injection and config-events modules
  • #1563 Remove deprecated methods
  • #1562 Fix documentations inaccuracies and missing features
  • #1561 Bump actions/setup-java from 5 to 6
  • #1560 Consolidate Converter management into Converters
  • #1556 Refactor ConfigMappings to unify metadata model and clearly separate introspection, generation and loading
  • #1542 Add ConfigSource for TOML format
  • #1194 Remove SecurityManager
  • #1021 Config instance builder

3.18.3

  • #1578 Release 3.18.3
  • #1577 Make FileSystemConfigSource take into account Win line endings

3.18.2

  • #1558 Release 3.18.2
  • #1557 Preserve multiline file content in FileSystemConfigSource
  • #1555 Bump io.fabric8:docker-maven-plugin from 0.48.1 to 0.49.0
  • #1553 Bump pymdown-extensions from 10.21.3 to 11.0.1 in /documentation
  • #1551 Collect nested ConfigMappingClass entries in getConfigMappingsMetadata
  • #1550 Ignore @​WithDefault on Map and Collection with nested group values

... (truncated)

Commits
  • fa21e03 [maven-release-plugin] prepare release 4.0.0
  • dcf37d2 Release 4.0.0 (#1594)
  • bcfab87 Update to SmallRye Parent 52 (#1593)
  • 179e175 Prefer AtomicReference instead of a Holder object (#1592)
  • 11ac402 [maven-release-plugin] prepare for next development iteration
  • 83fbdf4 [maven-release-plugin] prepare release 4.0.0.CR3
  • 6d923f4 Release 4.0.0.CR3 (#1591)
  • 19e23e5 Use ClassValue to cache ConfigMappingInterface and ConfigMappingClass (#1589)
  • b251e6d [maven-release-plugin] prepare for next development iteration
  • d28b1e2 [maven-release-plugin] prepare release 4.0.0.CR2
  • Additional commits viewable in compare view

Updates org.zeroturnaround:zt-exec from 1.12 to 1.13.0

Release notes

Sourced from org.zeroturnaround:zt-exec's releases.

v1.13.0

What's Changed

New Contributors

Full Changelog: https://github.com/zeroturnaround/zt-exec/commits/v1.13.0

Changelog

Sourced from org.zeroturnaround:zt-exec's changelog.

[1.13.0] - 2026-07-10

Added

  • LogOutputStream.create(LineConsumer) to build a LogOutputStream from a lambda (#107).
  • LogOutputStream.setOutputCharset(String) to control the charset used to decode the process output (#89).
  • An OSGi bundle manifest (Bundle-SymbolicName, Export-Package) in the published jar (#85).
  • A JPMS module descriptor for module org.zeroturnaround.exec, shipped as a Java 9 multi-release entry (#106).

Changed

  • Raised the minimum Java runtime from 6 to 8 (bytecode target moved from 1.6 to 1.8).
  • Upgraded the slf4j-api dependency from 1.7.2 to 1.7.32.
  • Migrated the build from Maven to Gradle; releases now publish to Maven Central through the Sonatype Central Portal.
Commits
  • f71a22a Release 1.13.0
  • 13ca7bd List all consumer-facing changes since 1.12 in the changelog
  • a614f50 Bump the minor-and-patch group across 1 directory with 4 updates
  • d20fae7 Bump org.apache.commons:commons-lang3 from 3.12.0 to 3.18.0
  • f16fd4e Bump commons-io:commons-io from 2.11.0 to 2.14.0
  • 09612ed Suppress automatic-module warning on the slf4j requires directive
  • 38f6ee9 Add CHANGELOG.md, security policy, and changelog release automation
  • 1711820 Adopt vMAJOR.MINOR.PATCH release tags
  • 6e8e4a6 Bump build tooling to current versions
  • 5e0b895 Drop defunct ZeroTurnaround references from POM metadata
  • Additional commits viewable in compare view

Updates com.github.spotbugs:spotbugs-annotations from 4.10.2 to 4.10.4

Release notes

Sourced from com.github.spotbugs:spotbugs-annotations's releases.

4.10.4

SpotBugs 4.10.4

CHANGELOG

Fixed

  • Fix NN_NAKED_NOTIFY false negatives when a field read is stored in a local variable before notify() or notifyAll() (#3884)
  • Fix ASE_ASSERTION_WITH_SIDE_EFFECT and ASE_ASSERTION_WITH_SIDE_EFFECT_METHOD false positives in every method analysed after a method that reads $assertionsDisabled without throwing an AssertionError (#3483)
  • Fix INT_BAD_COMPARISON_WITH_SIGNED_BYTE false positive for meaningful comparisons of a signed byte with 127 (b < 127, b >= 127) (#4201)
  • Fix EI_EXPOSE_REP false negative for public getters in anonymous classes (#4237)
  • Fix missing class report for java.util.Collections$EmptyNavigableSet and java.util.Collections$EmptyNavigableMap when the result of Collections.emptySortedSet(), emptyNavigableSet(), emptySortedMap() or emptyNavigableMap() is stored (#4244)
  • Fix URF_UNREAD_FIELD false negative for unread instance fields declared in enums (#4246)
  • Stop publishing global dependency-management constraints to consumer POMs. (#4223)

CHECKSUM

file checksum (sha256)
spotbugs-4.10.4-javadoc.jar 06bfc9ccdcfb9b594b5053817199b9489dff6312dc35c8864faa9b9357cf5be4
spotbugs-4.10.4-sources.jar d087c11e3b0714e8445b29f2bef9bb4c62b4ee13ad67caf7a4b64d61e82ea400
spotbugs-4.10.4.tgz 72bc0d4edd686e462c0f71f42a049b27bf4da6708797ff7b2b56dd202714b4e5
spotbugs-4.10.4.zip 771c8702beb2b4b6aa20df87ea85f22fda7280c7ce36fce4077b7b3c076d1e14
spotbugs-annotations-4.10.4-javadoc.jar 0fc9d3c529c6ee93aeddf9cfbd4b1438708e37fd53b5157aa47070446fbc7303
spotbugs-annotations-4.10.4-sources.jar 87974d23caffbc8c6e66c567747627267b5ed06573cee966d7af6d236b8d65bd
spotbugs-annotations.jar 28fa4befaddce5d7b79b07c68e7c12fa27c5d9282c4229528717971606661ea3
spotbugs-ant-4.10.4-javadoc.jar eaa1ee0a4e004b7b12e2dfc65290c6324effff6ffc0e7b7ee94c98875997e51c
spotbugs-ant-4.10.4-sources.jar af1c78c8e194c2f82ea3e0517ab38a5eb6ba608c8d0e776c9097605d6b7efca6
spotbugs-ant.jar 9ec240477b7c87270be7dfe3196180cd3763f04c369e5691feeb12e66110a065
spotbugs.jar a88cad2e0ea9bb74b908ce82ae89416c61fa8f8ea5cfcc9368b1baac2da878d2
test-harness-4.10.4-javadoc.jar c1ff7bcd0c4f61f4356ae9734be34567df680175651a3104fdee241e324d6df7
test-harness-4.10.4-sources.jar 805d2d124b0d4ea513ee9262d4ad6027c3471d45defd80fd7d20e23425d17df7
test-harness-4.10.4.jar bd10d1f11a1b93e4ca4db4d27772f611bd3407f9452dbbd2d1ba62584ddc171f
test-harness-core-4.10.4-javadoc.jar ac735a1508609001d122a91e43f6dfb10c4c691cf555d5ba386f216df904ac9b
test-harness-core-4.10.4-sources.jar 043a55d99a517c0d9cf702b0c183b4afd3f03af9eff4a86d59bb37df1b35b532
test-harness-core-4.10.4.jar 1f9a0ee8f150dd71f960ca4f59dcf7912a45d0e9e6aefc4585fd44b975454bc0
test-harness-jupiter-4.10.4-javadoc.jar c9554b4a6509d0d24c6436b6e01171eb8e71fca96df6edf8f80c7b51ab5bda16
test-harness-jupiter-4.10.4-sources.jar 17144f315686bfd01c02fa4ae7c916060c41de8eed58d5b8470416fa08f46ced
test-harness-jupiter-4.10.4.jar a91146da3e993479cfefd2690781cbd102c6360ecc63a96d88995be3bd60fcbb

4.10.3

SpotBugs 4.10.3

CHANGELOG

Fixed

  • Fix LI_LAZY_INIT_STATIC false negative when the null guard is written in yoda-style (null == field) (#4144)
  • Fix DC_DOUBLECHECK, NP_SYNC_AND_NULL_CHECK_FIELD and SP_SPIN_ON_FIELD false negatives when the null guard is written in yoda-style (null == field) (#4144)
  • Fix message for UNS_UNSAFE_CALL bug pattern
  • Restore CLI plugin loading by fixing DetectorFactoryCollection bootstrap ordering (#4191)
  • Fix UWF_NULL_FIELD false negative for fields initialized with cast null values (#4034)
  • Fix UMAC_UNCALLABLE_METHOD_OF_ANONYMOUS_CLASS false positive for methods reached only through method references (#4059)

... (truncated)

Changelog

Sourced from com.github.spotbugs:spotbugs-annotations's changelog.

4.10.4 - 2026-08-19

Fixed

  • Fix NN_NAKED_NOTIFY false negatives when a field read is stored in a local variable before notify() or notifyAll() (#3884)
  • Fix ASE_ASSERTION_WITH_SIDE_EFFECT and ASE_ASSERTION_WITH_SIDE_EFFECT_METHOD false positives in every method analysed after a method that reads $assertionsDisabled without throwing an AssertionError (#3483)
  • Fix INT_BAD_COMPARISON_WITH_SIGNED_BYTE false positive for meaningful comparisons of a signed byte with 127 (b < 127, b >= 127) (#4201)
  • Fix EI_EXPOSE_REP false negative for public getters in anonymous classes (#4237)
  • Fix missing class report for java.util.Collections$EmptyNavigableSet and java.util.Collections$EmptyNavigableMap when the result of Collections.emptySortedSet(), emptyNavigableSet(), emptySortedMap() or emptyNavigableMap() is stored (#4244)
  • Fix URF_UNREAD_FIELD false negative for unread instance fields declared in enums (#4246)
  • Stop publishing global dependency-management constraints to consumer POMs. (#4223)

4.10.3 - 2026-07-12

Fixed

  • Fix LI_LAZY_INIT_STATIC false negative when the null guard is written in yoda-style (null == field) (#4144)
  • Fix DC_DOUBLECHECK, NP_SYNC_AND_NULL_CHECK_FIELD and SP_SPIN_ON_FIELD false negatives when the null guard is written in yoda-style (null == field) (#4144)
  • Fix message for UNS_UNSAFE_CALL bug pattern
  • Restore CLI plugin loading by fixing DetectorFactoryCollection bootstrap ordering (#4191)
  • Fix UWF_NULL_FIELD false negative for fields initialized with cast null values (#4034)
  • Fix UMAC_UNCALLABLE_METHOD_OF_ANONYMOUS_CLASS false positive for methods reached only through method references (#4059)

Changed

  • Ant FindBugsViewerTask: use default look and feel by default. (#4165)

Refactor

  • Ant FindBugsViewerTask: extend AbstractFindBugsTask to reduce duplicate code. (#4165)
Commits
  • 1a58a48 release v4.10.4
  • 160d4a6 Gradle build cleanup (#4255)
  • 2354168 Fix EI_EXPOSE_REP not reported for anonymous-class getters (#4237)
  • 4895bce Fix naked notify detection after local stores (#4245)
  • 28348e5 Fixes #3955 : Fix URF_UNREAD_FIELD false negative for unread fields i… (#4246)
  • 3ec259e chore(build): Add changelog regarding dependency management constraints remov...
  • 33075ce Remove eclipse table latest as noted version 3.1 that is long retired and dis...
  • 1bf27d8 Update Gradle to v9.7.1 (#4252)
  • ee61d5b Update dependency com.google.guava:guava to v33.7.1-jre (#4250)
  • f352226 Update plugin com.diffplug.spotless to v8.10.0 (#4249)
  • Additional commits viewable in compare view

Updates net.bytebuddy:byte-buddy from 1.18.10 to 1.18.14

Release notes

Sourced from net.bytebuddy:byte-buddy's releases.

Byte Buddy 1.18.14

  • Avoid exposure of the agent argument on the command line of the process that is spawned for an external attachment.
  • Avoid the resolution of symbolic links when the Gradle plugin deletes a folder recursively.
  • Limit the nesting depth that is accepted when parsing a generic type signature to avoid an exhaustion of the stack for a malformed class file.
  • Sign all deployed files using sigstore, in addition to the existing GPG signature.
  • Validate entry names when the Android plugin retains a file to avoid the propagation of path traversals.

Byte Buddy 1.18.13

  • Actually include the SBOM within the published artifacts.
  • Avoid propagation of path traversals that are contained in jar files which are copied without transformation.
  • Avoid repeated traversal of previously visited type hierarchies to improve performance.
  • Correct Kotlin support of the Gradle plugin to redirect the classes directory of a source set while retaining support for legacy Gradle versions.
  • Create Gradle tasks using Gradle's task registration API if available.

Byte Buddy 1.18.12

  • Automatically support Kotlin in Gradle plugin.
  • Add support for native attach on Windows for ARM64.
  • Correct JNA injector which accidentally created on based on Unsafe.

Byte Buddy 1.18.11

  • Add SBOM to published artifacts.
  • Check for traversable paths injected into class files as a rather hypothetical attack vector.
Changelog

Sourced from net.bytebuddy:byte-buddy's changelog.

14. September 2026: version 1.18.14

  • Avoid exposure of the agent argument on the command line of the process that is spawned for an external attachment.
  • Avoid the resolution of symbolic links when the Gradle plugin deletes a folder recursively.
  • Limit the nesting depth that is accepted when parsing a generic type signature to avoid an exhaustion of the stack for a malformed class file.
  • Sign all deployed files using sigstore, in addition to the existing GPG signature.
  • Validate entry names when the Android plugin retains a file to avoid the propagation of path traversals.

2. September 2026: version 1.18.13

  • Actually include the SBOM within the published artifacts.
  • Avoid propagation of path traversals that are contained in jar files which are copied without transformation.
  • Avoid repeated traversal of previously visited type hierarchies to improve performance.
  • Correct Kotlin support of the Gradle plugin to redirect the classes directory of a source set while retaining support for legacy Gradle versions.
  • Create Gradle tasks using Gradle's task registration API if available.

17. July 2026: version 1.18.12

  • Automatically support Kotlin in Gradle plugin.
  • Correct JNA injector which accidentally created on based on Unsafe.
  • Support dynamic attach on Windows ARM64 by shipping a native attach_hotspot_windows library for win32-aarch64.

2. July 2026: version 1.18.11

  • Add SBOM to published artifacts.
  • Check for traversable paths injected into class files as a rather hypothetical attack vector.
Commits
  • 92846cb [publish] Releasing Byte Buddy 1.18.14
  • a8a9f14 [release] Release new version
  • b0fe006 Skip the signature creation for artifacts that are not deployed.
  • c610783 Resolve the signed POM file by the path of the project file.
  • caab321 Sign the deployed POM file and allow for a sigstore dry run.
  • c68a9c1 Supply the agent argument to the attacher process as an environment variable.
  • 3ac9ded Avoid symbolic link resolution on recursive deletion and validate Android ent...
  • 8dbae60 Sign deployed files using sigstore.
  • 5d83cd4 Disable semantic versioning check for protected constructor in abstract class...
  • 172e0f4 Move to method to apply suppression.
  • Additional commits viewable in compare view

Updates io.github.classgraph:classgraph from 4.8.184 to 4.8.196

Release notes

Sourced from io.github.classgraph:classgraph's releases.

ClassGraph 4.8.196

ClassGraph 5.0.0 is coming shortly, and requires JDK 17 or newer. 4.8.196 is a bugfix release on the 4.x maintenance branch, and continues the file-by-file audit that produced 4.8.190 through 4.8.195. As before, most of the bugs listed here were found by Claude through careful code analysis, and were fixed on the v5 branch and backported to v4.

Mocking the list classes with mockk works again (#945)

Since 4.8.185, mockk failed to mock ResourceList, ClassInfoList and the other list classes, with "class redefinition failed: attempted to add a method". These classes extend a package-private class, and releases since 4.8.185 were built with JDK 8, whose javac does not emit public bridge methods in the public subclass for add(T), add(int, T), remove(int) and set(int, T). The list classes now declare these methods themselves, so they are present whichever JDK builds the release.

Bug fixes: classpath elements and jarfiles

  • The context classloader could be moved behind the application classloader. The classloaders found in the environment were sorted by descending delegation depth, so that a classloader is searched before its ancestors. That also put any classloader with more ancestors ahead of an unrelated one with fewer -- the application classloader ahead of a context classloader with no parent, for example -- although the context classloader is meant to be tried first. Each classloader is now inserted just ahead of the first of its ancestors that is already listed, which keeps descendants ahead of ancestors and otherwise keeps the preference order.

  • Class-Path and Bundle-ClassPath manifest attributes are now read with their specified syntax. A Class-Path entry is a relative URL, so its percent encoding is now decoded, as the JVM's own classloader decodes it. Before, a jarfile written as my%20lib.jar was looked for under that literal name, so a jarfile with a space in its name could not be named at all. Bundle-ClassPath paths are now trimmed, unquoted and separated from their parameters, following the OSGi header syntax. Before, . , inner.jar named inner.jar, and a quoted path or one with a parameter named nothing that exists.

  • When a zipfile has two entries with the same name, the last one is now used, as the JDK does. ClassGraph kept the first, so a scan could report a different resource, and open a different nested jarfile, than the JVM would load.

  • META-INF/versions/09/ is no longer read as multi-release version 9. The JDK looks up versioned entries only under the plain decimal version number, so ClassGraph could report a class that the JVM never loads.

  • The file of a nested jarfile is now always the outermost jarfile. It was the outer jarfile if the nested jarfile was stored, but null or a temporary file if it was deflated. ScanResult#getClasspathFiles() lists the outer jarfile once, however many jarfiles are nested within it.

  • A zipfile with an Info-ZIP Unicode path extra field of a version other than 1 could not be read. java.util.zip.ZipFile opens such a file, since the JDK does not read that field. The field is now logged and ignored.

  • A large nested jar with a long name could not be opened. A nested jar too large to hold in RAM is written to a temporary file named after its zip entry, and a long entry name made File.createTempFile fail with "File name too long". The name is now cut to its last 64 characters.

  • A jarfile URL that redirected from http to https failed with "Got response code 301", since HttpURLConnection only follows a redirect that keeps the same scheme. Redirects are now followed, up to 20 times. A redirect from https to http, or to a scheme that has not been enabled, is refused.

  • A SecurityManager that refused to let ClassGraph read a file's attributes stopped the scan of the rest of that directory. Only that file is now skipped.

  • The Quarkus classloader handler failed the whole scan when a field it reads held a null or unexpected value. Such elements are now skipped.

  • normalizePath did not collapse // in a path that did not end with a separator, so a//b stayed a//b while a//b/ became a/b.

Bug fixes: memory, file handles and temporary files

  • A file is no longer memory-mapped when it could not be unmapped again. A SecurityManager that denied access to the buffer cleaner made new ClassGraph() throw "Cannot get buffer cleaner method". Now, below JDK 22, a file is only memory-mapped when the cleaner is available, since otherwise the mapping, and on Windows the file lock, would last until the buffer was garbage collected.

  • A canceled scanAsync future leaked its ScanResult. A result that arrived after the future was canceled was never handed to anyone, so nothing closed it. It is now closed. The call stack and context classloader are still read on the calling thread, but the jarfiles are now opened when the task runs, so a task that is canceled before it starts opens nothing.

  • Temporary files no longer use deleteOnExit(). Closing the scan already deletes every temporary file, so deleteOnExit() only made the JDK hold every temporary path until the JVM exited.

  • A module reader could be left open if it was returned to its pool at the same moment the pool was being force-closed.

  • Reading a stream of declared length allocated a buffer of that whole length up front, up to the maximum buffered jar size. The first buffer is now at most 16MB, and grows as data arrives. A related method doubled its buffer whenever a read returned zero bytes, even when the buffer was not full; no scan was affected, since the streams it is given never return zero.

  • A refused unmap of a buffer view was logged as "Could not unmap ByteBuffer: java.lang.reflect.InvocationTargetException". Such a view is now refused without a log entry, and any other failure is logged with its real cause.

Bug fixes: the class graph

  • ClassInfo#isAnonymousInnerClass() returned true for named local classes. It now agrees with Class#isAnonymousClass(). getFullyQualifiedDefiningMethodName() returned <clinit> for a class declared in an instance initializer or an instance field initializer, which javac compiles into the constructors; it now returns null for these, as Class#getEnclosingMethod() does.

  • A local record, enum or interface was reported as not static.

... (truncated)

Commits
  • 8f16afe [maven-release-plugin] prepare release classgraph-4.8.196
  • f0f3d2d Declare the element methods in the public list classes, so mockk can mock the...
  • a4d872d [maven-release-plugin] prepare for next development iteration
  • 495b196 [maven-release-plugin] prepare release classgraph-4.8.196
  • 4d08ea2 Keep a '$' after a '.' in a class reference as part of the nested class name
  • 67c7d33 Follow an http to https redirect when downloading a jarfile
  • b8d2225 Check in the LocalRecordTest classfile fixtures, which .gitignore excluded
  • 1eb2fb2 Make AnnotationParameterValue.equals and hashCode agree with compareTo for un...

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Oct 8, 2026
@dependabot
dependabot Bot force-pushed the dependabot/maven/maven-dependencies-759d958508 branch from 97e6ed1 to a5d6c57 Compare October 8, 2026 04:15
evanchooly added a commit that referenced this pull request Oct 8, 2026
Moves the Maven wrapper from `4.0.0-rc-6` to `4.0.0-rc-7`.

#4374 bumps `maven.version` to `4.0.0-rc-7`. `build-plugins` compiles
against that version, so the plugin then requires Maven rc-7. The
wrapper still runs rc-6, which fails every build on that PR:

```
The plugin dev.morphia.morphia:build-plugins:3.0.0-SNAPSHOT has unmet prerequisites:
    Required Maven version 4.0.0-rc-7 is not met by current version 4.0.0-rc-6
```

Once this is merged, comment `@dependabot rebase` on #4374.

Checked locally: `./mvnw install -DskipTests` passes on rc-7 with the
current `maven.version` (rc-6).
@evanchooly

Copy link
Copy Markdown
Member

@dependabot rebase

Bumps the maven-dependencies group with 15 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [org.junit:junit-bom](https://github.com/junit-team/junit-framework) | `6.1.0` | `6.1.3` |
| org.slf4j:slf4j-api | `2.0.18` | `2.0.20` |
| org.slf4j:slf4j-simple | `2.0.18` | `2.0.20` |
| org.slf4j:slf4j-simple | `2.0.18` | `2.0.20` |
| [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) | `1.5.36` | `1.6.5` |
| org.apache.maven:maven-model | `4.0.0-rc-6` | `4.0.0-rc-7` |
| [io.smallrye.config:smallrye-config](https://github.com/smallrye/smallrye-config) | `3.17.2` | `4.0.0` |
| [org.zeroturnaround:zt-exec](https://github.com/zeroturnaround/zt-exec) | `1.12` | `1.13.0` |
| [com.github.spotbugs:spotbugs-annotations](https://github.com/spotbugs/spotbugs) | `4.10.2` | `4.10.4` |
| [net.bytebuddy:byte-buddy](https://github.com/raphw/byte-buddy) | `1.18.10` | `1.18.14` |
| [io.github.classgraph:classgraph](https://github.com/classgraph/classgraph) | `4.8.184` | `4.8.196` |
| [com.google.devtools.ksp:symbol-processing-api](https://github.com/google/ksp) | `2.3.9` | `2.3.12` |
| [com.google.devtools.ksp:symbol-processing-common-deps](https://github.com/google/ksp) | `2.3.9` | `2.3.12` |
| [com.google.devtools.ksp:symbol-processing-aa-embeddable](https://github.com/google/ksp) | `2.3.9` | `2.3.12` |
| [com.google.devtools.ksp:symbol-processing-common-deps](https://github.com/google/ksp) | `2.3.9` | `2.3.12` |
| [com.google.devtools.ksp:symbol-processing-aa-embeddable](https://github.com/google/ksp) | `2.3.9` | `2.3.12` |
| [org.apache.maven.plugins:maven-compiler-plugin](https://github.com/apache/maven-compiler-plugin) | `3.15.0` | `3.16.0` |
| [org.apache.maven.plugins:maven-jar-plugin](https://github.com/apache/maven-jar-plugin) | `3.5.0` | `3.5.1` |



Updates `org.junit:junit-bom` from 6.1.0 to 6.1.3
- [Release notes](https://github.com/junit-team/junit-framework/releases)
- [Commits](junit-team/junit-framework@r6.1.0...r6.1.3)

Updates `org.slf4j:slf4j-api` from 2.0.18 to 2.0.20

Updates `org.slf4j:slf4j-simple` from 2.0.18 to 2.0.20

Updates `org.slf4j:slf4j-simple` from 2.0.18 to 2.0.20

Updates `ch.qos.logback:logback-classic` from 1.5.36 to 1.6.5
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.5.36...v_1.6.5)

Updates `org.apache.maven:maven-model` from 4.0.0-rc-6 to 4.0.0-rc-7

Updates `io.smallrye.config:smallrye-config` from 3.17.2 to 4.0.0
- [Release notes](https://github.com/smallrye/smallrye-config/releases)
- [Commits](smallrye/smallrye-config@3.17.2...4.0.0)

Updates `org.zeroturnaround:zt-exec` from 1.12 to 1.13.0
- [Release notes](https://github.com/zeroturnaround/zt-exec/releases)
- [Changelog](https://github.com/zeroturnaround/zt-exec/blob/main/CHANGELOG.md)
- [Commits](zeroturnaround/zt-exec@zt-exec-1.12...v1.13.0)

Updates `com.github.spotbugs:spotbugs-annotations` from 4.10.2 to 4.10.4
- [Release notes](https://github.com/spotbugs/spotbugs/releases)
- [Changelog](https://github.com/spotbugs/spotbugs/blob/master/CHANGELOG.md)
- [Commits](spotbugs/spotbugs@4.10.2...4.10.4)

Updates `net.bytebuddy:byte-buddy` from 1.18.10 to 1.18.14
- [Release notes](https://github.com/raphw/byte-buddy/releases)
- [Changelog](https://github.com/raphw/byte-buddy/blob/master/release-notes.md)
- [Commits](raphw/byte-buddy@byte-buddy-1.18.10...byte-buddy-1.18.14)

Updates `io.github.classgraph:classgraph` from 4.8.184 to 4.8.196
- [Release notes](https://github.com/classgraph/classgraph/releases)
- [Commits](classgraph/classgraph@classgraph-4.8.184...classgraph-4.8.196)

Updates `com.google.devtools.ksp:symbol-processing-api` from 2.3.9 to 2.3.12
- [Release notes](https://github.com/google/ksp/releases)
- [Commits](google/ksp@2.3.9...2.3.12)

Updates `com.google.devtools.ksp:symbol-processing-common-deps` from 2.3.9 to 2.3.12
- [Release notes](https://github.com/google/ksp/releases)
- [Commits](google/ksp@2.3.9...2.3.12)

Updates `com.google.devtools.ksp:symbol-processing-aa-embeddable` from 2.3.9 to 2.3.12
- [Release notes](https://github.com/google/ksp/releases)
- [Commits](google/ksp@2.3.9...2.3.12)

Updates `com.google.devtools.ksp:symbol-processing-common-deps` from 2.3.9 to 2.3.12
- [Release notes](https://github.com/google/ksp/releases)
- [Commits](google/ksp@2.3.9...2.3.12)

Updates `com.google.devtools.ksp:symbol-processing-aa-embeddable` from 2.3.9 to 2.3.12
- [Release notes](https://github.com/google/ksp/releases)
- [Commits](google/ksp@2.3.9...2.3.12)

Updates `org.apache.maven.plugins:maven-compiler-plugin` from 3.15.0 to 3.16.0
- [Release notes](https://github.com/apache/maven-compiler-plugin/releases)
- [Commits](apache/maven-compiler-plugin@maven-compiler-plugin-3.15.0...maven-compiler-plugin-3.16.0)

Updates `org.apache.maven.plugins:maven-jar-plugin` from 3.5.0 to 3.5.1
- [Release notes](https://github.com/apache/maven-jar-plugin/releases)
- [Commits](apache/maven-jar-plugin@maven-jar-plugin-3.5.0...maven-jar-plugin-3.5.1)

---
updated-dependencies:
- dependency-name: ch.qos.logback:logback-classic
  dependency-version: 1.6.5
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: com.github.spotbugs:spotbugs-annotations
  dependency-version: 4.10.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: com.google.devtools.ksp:symbol-processing-aa-embeddable
  dependency-version: 2.3.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: com.google.devtools.ksp:symbol-processing-aa-embeddable
  dependency-version: 2.3.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: com.google.devtools.ksp:symbol-processing-api
  dependency-version: 2.3.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: com.google.devtools.ksp:symbol-processing-common-deps
  dependency-version: 2.3.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: com.google.devtools.ksp:symbol-processing-common-deps
  dependency-version: 2.3.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: io.github.classgraph:classgraph
  dependency-version: 4.8.196
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: io.smallrye.config:smallrye-config
  dependency-version: 4.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: maven-dependencies
- dependency-name: net.bytebuddy:byte-buddy
  dependency-version: 1.18.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.maven.plugins:maven-compiler-plugin
  dependency-version: 3.16.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: org.apache.maven.plugins:maven-jar-plugin
  dependency-version: 3.5.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.maven:maven-model
  dependency-version: 4.0.0-rc-7
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.junit:junit-bom
  dependency-version: 6.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.slf4j:slf4j-api
  dependency-version: 2.0.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.slf4j:slf4j-simple
  dependency-version: 2.0.20
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.slf4j:slf4j-simple
  dependency-version: 2.0.20
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.zeroturnaround:zt-exec
  dependency-version: 1.13.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/maven/maven-dependencies-759d958508 branch from a5d6c57 to 863b0c5 Compare October 8, 2026 04:33
@evanchooly
evanchooly merged commit 34badee into master Oct 8, 2026
4 checks passed
@evanchooly
evanchooly deleted the dependabot/maven/maven-dependencies-759d958508 branch October 8, 2026 04:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant