Skip to content

chore(deps): bump the all group with 4 updates - #1999

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/all-b6b13d0294
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/all-b6b13d0294

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the all group with 4 updates: org.slf4j:slf4j-simple, org.apache.maven.plugins:maven-install-plugin, org.apache.maven.plugins:maven-deploy-plugin and com.uber.nullaway:nullaway.

Updates org.slf4j:slf4j-simple from 2.0.18 to 2.0.20

Updates org.apache.maven.plugins:maven-install-plugin from 3.1.4 to 3.2.0

Release notes

Sourced from org.apache.maven.plugins:maven-install-plugin's releases.

3.2.0

🚀 New features and improvements

🐛 Bug Fixes

  • chore: harden embedded-POM trust boundary in install:install-file (3.x backport) (#447) @​gnodet

📝 Documentation updates

  • Restore the common wording on the download page (#438) @​slachiewicz
  • Add AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (#416) @​potiuk

👻 Maintenance

📦 Dependency updates

Commits
  • bcf484d [maven-release-plugin] prepare release maven-install-plugin-3.2.0
  • 5703691 chore: harden embedded-POM trust boundary in install:install-file (3.x backpo...
  • 9148a8f Cache projectsUsingPlugin to fix O(N²) reactor scan
  • 7465779 Fix workflow_dispatch indentation in release-drafter configuration
  • 7d4334d Use JSR-330 for component injection
  • bbcb1e7 Restore the common wording on the download page
  • 11f7073 Restore the document metadata dropped when the pages were ported
  • 9b34ac2 Port the site documentation from APT to Markdown
  • 510f48f Rename the site documents ahead of converting them
  • 26e0afc Bump apache/maven-gh-actions-shared/.github/workflows/pr-automation.yml
  • Additional commits viewable in compare view

Updates org.apache.maven.plugins:maven-deploy-plugin from 3.1.4 to 3.2.0

Release notes

Sourced from org.apache.maven.plugins:maven-deploy-plugin's releases.

3.2.0

🚀 New features and improvements

🐛 Bug Fixes

  • Backport security audit fixes to 3.x (f004-f008, f010, f012) (#701) @​gnodet

📝 Documentation updates

👻 Maintenance

🔧 Build

📦 Dependency updates

... (truncated)

Commits
  • 7aab9fb [maven-release-plugin] prepare release maven-deploy-plugin-3.2.0
  • 1f3eef5 Backport security audit fixes to 3.x (f004-f008, f010, f012)
  • 307f328 Simplify remote repository creation
  • 7b1bbc4 Cache projectsWithDeployExecution to fix O(N²) reactor scan
  • a9177c6 Clarify deploy without editing this projects POM
  • 7c40513 Restore the plain form of the ASF licence header
  • 5969234 Update Release Drafter configuration to use custom tag template and remove un...
  • df7b3fa Bump apache/maven-gh-actions-shared/.github/workflows/release-drafter.yml
  • b4e8aed work around Maven 4 CLI lack of interpolation
  • d634bb4 enable build with Maven 4
  • Additional commits viewable in compare view

Updates com.uber.nullaway:nullaway from 0.14.1 to 0.14.2

Release notes

Sourced from com.uber.nullaway:nullaway's releases.

NullAway 0.14.2

This release adds JSpecifyUnrecognizedAnnotationLocation, an opt-in check that reports nullness annotations in locations JSpecify does not recognize. See further documentation on the wiki: https://github.com/uber/NullAway/wiki/JSpecify-Support#jspecifyunrecognizedannotationlocation-checker

Not packaged in the release, but we have also added a script to remove unnecessary NullAway suppressions to the repo: https://github.com/uber/NullAway/tree/master/scripts/nullaway-suppression-remover We expect this to be a useful script to run after NullAway updates, to check if NullAway improvements make some suppressions unnecessary.

Also of note, NullAway now more precisely detects whether the JDK used for the build properly supports reading type use annotations from bytecode, particularly important for JSpecify mode. This may lead NullAway to crash on certain build configurations that were unsupported before but we were not detecting precisely.

Beyond the above, this release includes further fixes for JSpecify mode and JSpecifyExperimental, especially for wildcard bounds and multi-dimensional arrays, along with other bug fixes.

Finally, we have re-enabled pushing snapshot builds to the Sonatype snapshots repository, which should ease testing NullAway versions between releases.

  • Small optimization for stream handlers (#1774)
  • Check wildcard generics handling flag for enhanced for loops (#1786)
  • Cover anonymous class type arguments and modeled call-site returns by @​vlsi (#1777)
  • Write the full encoded byte array when serializing TSV/XML rows #1788 by @​AzazelSensei (#1798)
  • Fix @​RequiresNonNull override error message to list the extra fields added by the child method by @​Beluomini (#1751)
  • Model Stream.takeWhile (+ reactive equivalents) like .filter by @​jeffrey-easyesi (#1809)
  • Add JSpecifyUnrecognizedAnnotationLocation, an opt-in check that reports nullness annotations in locations JSpecify does not recognize by @​vlsi (#1787)
  • Detect support for the addTypeAnnotationsToSymbol flag on JDK 17 / 21 (#1794)
  • Fix RequireExplicitNullMarking diagnostics repeating the check name, so a report no longer begins with [RequireExplicitNullMarking] [RequireExplicitNullMarking] by @​vlsi (#1815)
  • Less conservative handling of raw array types (#1807)
  • Fix crasher example from Caffeine (#1820)
  • Add a script to remove unnecessary NullAway suppressions (#1803)
  • Use LinkedHashMap / LinkedHashSet for determinism (#1796)
  • Prevent classloader closure from interrupting stubx reads (#1830)
  • Preserve non-null type variables through wildcard capture (#1837)
  • Treat Maven plugin parameters as externally initialized by @​ZedingZhang (#1848)
  • Do not treat type variables from the caller as inference variables (#1824)
  • Prevent recursion on self-referential wildcard bounds during inference by @​adityaanikam (#1843)
  • Avoid stale wildcard bounds after javac supertype inspection (#1849)
  • Preserve contextual bounds for recursive wildcard captures (#1853)
  • Restore effective wildcard upper bounds for invocation types (#1855)
  • Preserve wildcard component types for array element assignments (#1857)
  • Lazily allocate maps to detect wildcard cycles (#1888)
  • Preserve all dimensions of multi-dimensional array creation expressions in JSpecify mode by @​dbwiddis (#1711)
  • Fix false positives for Spring SpEL expressions using null in comparisons by @​Beluomini (#1750)
  • Apply covariant array subtyping at every dimension by @​dbwiddis (#1889)
  • Maintenance
    • Remove outdated Spark test (#1772)

... (truncated)

Changelog

Sourced from com.uber.nullaway:nullaway's changelog.

Version 0.14.2

This release adds JSpecifyUnrecognizedAnnotationLocation, an opt-in check that reports nullness annotations in locations JSpecify does not recognize. See further documentation on the wiki: https://github.com/uber/NullAway/wiki/JSpecify-Support#jspecifyunrecognizedannotationlocation-checker

Not packaged in the release, but we have also added a script to remove unnecessary NullAway suppressions to the repo: https://github.com/uber/NullAway/tree/master/scripts/nullaway-suppression-remover We expect this to be a useful script to run after NullAway updates, to check if NullAway improvements make some suppressions unnecessary.

Also of note, NullAway now more precisely detects whether the JDK used for the build properly supports reading type use annotations from bytecode, particularly important for JSpecify mode. This may lead NullAway to crash on certain build configurations that were unsupported before but we were not detecting precisely.

Beyond the above, this release includes further fixes for JSpecify mode and JSpecifyExperimental, especially for wildcard bounds and multi-dimensional arrays, along with other bug fixes.

Finally, we have re-enabled pushing snapshot builds to the Sonatype snapshots repository, which should ease testing NullAway versions between releases.

  • Small optimization for stream handlers (#1774)
  • Check wildcard generics handling flag for enhanced for loops (#1786)
  • Cover anonymous class type arguments and modeled call-site returns by @​vlsi (#1777)
  • Write the full encoded byte array when serializing TSV/XML rows #1788 by @​AzazelSensei (#1798)
  • Fix @​RequiresNonNull override error message to list the extra fields added by the child method by @​Beluomini (#1751)
  • Model Stream.takeWhile (+ reactive equivalents) like .filter by @​jeffrey-easyesi (#1809)
  • Add JSpecifyUnrecognizedAnnotationLocation, an opt-in check that reports nullness annotations in locations JSpecify does not recognize by @​vlsi (#1787)
  • Detect support for the addTypeAnnotationsToSymbol flag on JDK 17 / 21 (#1794)
  • Fix RequireExplicitNullMarking diagnostics repeating the check name, so a report no longer begins with [RequireExplicitNullMarking] [RequireExplicitNullMarking] by @​vlsi (#1815)
  • Less conservative handling of raw array types (#1807)
  • Fix crasher example from Caffeine (#1820)
  • Add a script to remove unnecessary NullAway suppressions (#1803)
  • Use LinkedHashMap / LinkedHashSet for determinism (#1796)
  • Prevent classloader closure from interrupting stubx reads (#1830)
  • Preserve non-null type variables through wildcard capture (#1837)
  • Treat Maven plugin parameters as externally initialized by @​ZedingZhang (#1848)
  • Do not treat type variables from the caller as inference variables (#1824)
  • Prevent recursion on self-referential wildcard bounds during inference by @​adityaanikam (#1843)
  • Avoid stale wildcard bounds after javac supertype inspection (#1849)
  • Preserve contextual bounds for recursive wildcard captures (#1853)
  • Restore effective wildcard upper bounds for invocation types (#1855)
  • Preserve wildcard component types for array element assignments (#1857)
  • Lazily allocate maps to detect wildcard cycles (#1888)
  • Preserve all dimensions of multi-dimensional array creation expressions in JSpecify mode by @​dbwiddis (#1711)
  • Fix false positives for Spring SpEL expressions using null in comparisons by @​Beluomini (#1750)
  • Apply covariant array subtyping at every dimension by @​dbwiddis (#1889)

... (truncated)

Commits
  • fa89a56 (Fixed) Prepare for release 0.14.2
  • 2e0d12a fix release yaml
  • f472b6b Reset snapshot version
  • 738e5ff Prepare next development version.
  • 4765e0e Prepare for release 0.14.2.
  • 52fd671 Add workflow for cutting releases (#1892)
  • 5354f39 Add missing dependencies for publishShadowPublicationToMavenCentralRepository...
  • cec5171 Publish snapshots to Maven Central (#1890)
  • 079a1ff Apply covariant array subtyping at every dimension (#1889)
  • f1ab72a Fix false positive in SpringHandler for SpEL expressions using null in compar...
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the all group with 4 updates: org.slf4j:slf4j-simple, [org.apache.maven.plugins:maven-install-plugin](https://github.com/apache/maven-install-plugin), [org.apache.maven.plugins:maven-deploy-plugin](https://github.com/apache/maven-deploy-plugin) and [com.uber.nullaway:nullaway](https://github.com/uber/NullAway).


Updates `org.slf4j:slf4j-simple` from 2.0.18 to 2.0.20

Updates `org.apache.maven.plugins:maven-install-plugin` from 3.1.4 to 3.2.0
- [Release notes](https://github.com/apache/maven-install-plugin/releases)
- [Commits](apache/maven-install-plugin@maven-install-plugin-3.1.4...maven-install-plugin-3.2.0)

Updates `org.apache.maven.plugins:maven-deploy-plugin` from 3.1.4 to 3.2.0
- [Release notes](https://github.com/apache/maven-deploy-plugin/releases)
- [Commits](apache/maven-deploy-plugin@maven-deploy-plugin-3.1.4...maven-deploy-plugin-3.2.0)

Updates `com.uber.nullaway:nullaway` from 0.14.1 to 0.14.2
- [Release notes](https://github.com/uber/NullAway/releases)
- [Changelog](https://github.com/uber/NullAway/blob/master/CHANGELOG.md)
- [Commits](uber/NullAway@v0.14.1...v0.14.2)

---
updated-dependencies:
- dependency-name: org.slf4j:slf4j-simple
  dependency-version: 2.0.20
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: org.apache.maven.plugins:maven-install-plugin
  dependency-version: 3.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: org.apache.maven.plugins:maven-deploy-plugin
  dependency-version: 3.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: com.uber.nullaway:nullaway
  dependency-version: 0.14.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants