Skip to content

Bump the prod-deps group across 1 directory with 3 updates#283

Merged
skunkworks-rabot merged 1 commit into
mainfrom
dependabot/maven/prod-deps-c04d07c1fb
Jun 3, 2026
Merged

Bump the prod-deps group across 1 directory with 3 updates#283
skunkworks-rabot merged 1 commit into
mainfrom
dependabot/maven/prod-deps-c04d07c1fb

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 2, 2026

Copy link
Copy Markdown
Contributor

Bumps the prod-deps group with 3 updates in the / directory: io.quarkus.platform:quarkus-bom, io.quarkus.platform:quarkus-maven-plugin and org.apache.sshd:sshd-core.

Updates io.quarkus.platform:quarkus-bom from 3.35.1 to 3.36.0

Commits
  • e34692d [maven-release-plugin] prepare release 3.36.0
  • a9ac7f2 Merge pull request #1984 from quarkusio/dependabot/maven/quarkus-platform-bom...
  • ced7b09 Bump quarkus-platform-bom-generator.version from 0.0.130 to 0.0.131
  • 262a3f0 Merge pull request #1971 from quarkusio/update-automation/main-operatorsdk-7.7.5
  • d90018e Merge pull request #1983 from zbendhiba/cq-3.36.0
  • 39a1de6 Upgrade to Camel Quarkus 3.36.0
  • 37de437 Merge pull request #1977 from gsmet/quarkus-3.36.0
  • f683e9e Merge pull request #1975 from jmartisk/claude-md-version-overrides
  • 63728a8 Upgrade to Quarkus 3.36.0
  • b1ff02b Enhance CLAUDE.md with instructions how to override dependency versions
  • Additional commits viewable in compare view

Updates io.quarkus.platform:quarkus-maven-plugin from 3.35.1 to 3.36.0

Commits
  • e34692d [maven-release-plugin] prepare release 3.36.0
  • a9ac7f2 Merge pull request #1984 from quarkusio/dependabot/maven/quarkus-platform-bom...
  • ced7b09 Bump quarkus-platform-bom-generator.version from 0.0.130 to 0.0.131
  • 262a3f0 Merge pull request #1971 from quarkusio/update-automation/main-operatorsdk-7.7.5
  • d90018e Merge pull request #1983 from zbendhiba/cq-3.36.0
  • 39a1de6 Upgrade to Camel Quarkus 3.36.0
  • 37de437 Merge pull request #1977 from gsmet/quarkus-3.36.0
  • f683e9e Merge pull request #1975 from jmartisk/claude-md-version-overrides
  • 63728a8 Upgrade to Quarkus 3.36.0
  • b1ff02b Enhance CLAUDE.md with instructions how to override dependency versions
  • Additional commits viewable in compare view

Updates org.apache.sshd:sshd-core from 2.17.1 to 2.18.0

Release notes

Sourced from org.apache.sshd:sshd-core's releases.

Apache MINA SSHD 2.18.0

Bug Fixes

  • GH-743 Ensure the Java ServiceLoader use a singleton SftpFileSystemProvider
  • GH-879 Close SSH channel gracefully on exception in port forwarding
  • Security: Improve handling of repository paths in sshd-git. Resolves CVE-2026-48827, announced 2026-05-30.

New Features

  • GH-892 Align handling certificates without principals with OpenSSH 10.3

Wildcard principals in host certificates are handled now.

  • Putty keys with non-ASCII passphrases

The passphrase needs to be converted to a byte sequence to compute a decryption key for an encrypted private key. This conversion depends on the character encoding. Putty on Windows uses the ANSI codepage set when the key was generated. Apache MINA SSHD now tries multiple encodings in sequence: UTF-8, then the OS encoding, and finally ISO-8859-1 as a last-chance fallback.

Potential Compatibility Issues

  • GH-892 Align handling certificates without principals with OpenSSH 10.3

OpenSSH 10.3 changed the way such certificates are handled; see the OpenSSH 10.3 release notes. In Apache MINA SSHD, there is a new flag CoreModuleProperties.ALLOW_EMPTY_CERTIFICATE_PRINCIPALS (by default false) that can be set on an SshClient or SshServer or also on a Session directly. If the value is false, certificates without principals are rejected as in OpenSSH 10.3; if it is true, such certificates are considered to match any user or host name as in OpenSSH < 10.3.

Set the flag on an SshClient or ClientSession to determine the handling of host certificates. Set it on an SshServer or ServerSession to govern the handling of user certificates.

Changelog

Sourced from org.apache.sshd:sshd-core's changelog.

Previous Versions

Latest Version

Planned for Next Version

Bug Fixes

New Features

Potential Compatibility Issues

Major Code Re-factoring

Commits
  • c2d7b7a [maven-release-plugin] prepare release sshd-2.18.0
  • 084cee8 Prepare release documentation
  • db0567b Improve git access
  • 1285419 GH-743: Use a singleton SftpFileSystemProvider for the ServiceLoader
  • 4e820c9 Add test cases to AuthorizedKeysCertificateTest
  • a85a3b1 Better handling of Putty keys with non-ASCII passphrases
  • 6c215e8 Bump BCFIPS bundles used in a test
  • 9def203 Fix annotation to ignore an unstable test
  • a0ef7a5 Host certificates: check both public keys for not being revoked
  • b11c159 GH-892: Host certificate principals may contain wildcards
  • Additional commits viewable in compare view

Updates io.quarkus.platform:quarkus-maven-plugin from 3.35.1 to 3.36.0

Commits
  • e34692d [maven-release-plugin] prepare release 3.36.0
  • a9ac7f2 Merge pull request #1984 from quarkusio/dependabot/maven/quarkus-platform-bom...
  • ced7b09 Bump quarkus-platform-bom-generator.version from 0.0.130 to 0.0.131
  • 262a3f0 Merge pull request #1971 from quarkusio/update-automation/main-operatorsdk-7.7.5
  • d90018e Merge pull request #1983 from zbendhiba/cq-3.36.0
  • 39a1de6 Upgrade to Camel Quarkus 3.36.0
  • 37de437 Merge pull request #1977 from gsmet/quarkus-3.36.0
  • f683e9e Merge pull request #1975 from jmartisk/claude-md-version-overrides
  • 63728a8 Upgrade to Quarkus 3.36.0
  • b1ff02b Enhance CLAUDE.md with instructions how to override dependency versions
  • Additional commits viewable in compare view

@dependabot dependabot Bot requested review from a team and skunkworks-rabot as code owners June 2, 2026 20:42
@skunkworks-rabot skunkworks-rabot enabled auto-merge (rebase) June 2, 2026 20:42
@martinvisser

Copy link
Copy Markdown
Contributor

@dependabot recreate

Bumps the prod-deps group with 3 updates in the / directory: [io.quarkus.platform:quarkus-bom](https://github.com/quarkusio/quarkus-platform), [io.quarkus.platform:quarkus-maven-plugin](https://github.com/quarkusio/quarkus-platform) and [org.apache.sshd:sshd-core](https://github.com/apache/mina-sshd).


Updates `io.quarkus.platform:quarkus-bom` from 3.35.1 to 3.36.0
- [Commits](quarkusio/quarkus-platform@3.35.1...3.36.0)

Updates `io.quarkus.platform:quarkus-maven-plugin` from 3.35.1 to 3.36.0
- [Commits](quarkusio/quarkus-platform@3.35.1...3.36.0)

Updates `org.apache.sshd:sshd-core` from 2.17.1 to 2.18.0
- [Release notes](https://github.com/apache/mina-sshd/releases)
- [Changelog](https://github.com/apache/mina-sshd/blob/master/CHANGES.md)
- [Commits](apache/mina-sshd@sshd-2.17.1...sshd-2.18.0)

Updates `io.quarkus.platform:quarkus-maven-plugin` from 3.35.1 to 3.36.0
- [Commits](quarkusio/quarkus-platform@3.35.1...3.36.0)

---
updated-dependencies:
- dependency-name: io.quarkus.platform:quarkus-bom
  dependency-version: 3.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-deps
- dependency-name: io.quarkus.platform:quarkus-maven-plugin
  dependency-version: 3.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-deps
- dependency-name: io.quarkus.platform:quarkus-maven-plugin
  dependency-version: 3.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-deps
- dependency-name: org.apache.sshd:sshd-core
  dependency-version: 2.18.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: prod-deps
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump the prod-deps group with 3 updates Bump the prod-deps group across 1 directory with 3 updates Jun 3, 2026
@dependabot dependabot Bot force-pushed the dependabot/maven/prod-deps-c04d07c1fb branch from 49f2239 to f130ee3 Compare June 3, 2026 06:17
@skunkworks-rabot skunkworks-rabot merged commit e6bba95 into main Jun 3, 2026
1 of 2 checks passed
@skunkworks-rabot skunkworks-rabot deleted the dependabot/maven/prod-deps-c04d07c1fb branch June 3, 2026 06:18
@sonarqubecloud

sonarqubecloud Bot commented Jun 3, 2026

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants