dependabot-bot's Description of Work
Bumps the dependencies group with 10 updates in the / directory:
| Package | From | To |
| --- | --- | --- |
| org.eclipse.jetty.ee10:jetty-ee10-servlet | 12.1.12 | 12.1.13 |
| org.jooq:jooq | 3.21.7 | 3.21.8 |
| org.jooq:jooq-codegen | 3.21.7 | 3.21.8 |
| org.jooq:jooq-meta | 3.21.7 | 3.21.8 |
| org.slf4j:jul-to-slf4j | 2.0.18 | 2.0.19 |
| org.slf4j:slf4j-api | 2.0.18 | 2.0.19 |
| io.github.git-commit-id:git-commit-id-maven-plugin | 10.0.0 | 10.0.1 |
| org.apache.maven.plugins:maven-compiler-plugin | 3.15.0 | 3.16.0 |
| com.diffplug.spotless:spotless-maven-plugin | 3.10.1 | 3.10.2 |
| org.apache.maven.plugins:maven-surefire-plugin | 3.5.6 | 3.6.0 |
Updates org.eclipse.jetty.ee10:jetty-ee10-servlet from 12.1.12 to 12.1.13
Updates org.jooq:jooq from 3.21.7 to 3.21.8
Updates org.jooq:jooq-codegen from 3.21.7 to 3.21.8
Updates org.jooq:jooq-meta from 3.21.7 to 3.21.8
Updates org.jooq:jooq-codegen from 3.21.7 to 3.21.8
Updates org.jooq:jooq-meta from 3.21.7 to 3.21.8
Updates org.slf4j:jul-to-slf4j from 2.0.18 to 2.0.19
Updates org.slf4j:slf4j-api from 2.0.18 to 2.0.19
Updates org.slf4j:slf4j-api from 2.0.18 to 2.0.19
Updates io.github.git-commit-id:git-commit-id-maven-plugin from 10.0.0 to 10.0.1
Release notes
Sourced from io.github.git-commit-id:git-commit-id-maven-plugin's releases.
Version 10.0.1 is finally there and includes various bug-fixes and improvements :-)
What's Changed
Dependencies used by the plugin
git-commit-id/git-commit-id-maven-plugin#915: bump commons-io:commons-io from 2.21.0 to 2.22.0
git-commit-id/git-commit-id-maven-plugin#933: bump org.jspecify:jspecify from 1.0.0 to 1.0.1
git-commit-id/git-commit-id-maven-plugin#919: bump org.slf4j:slf4j-simple from 2.0.17 to 2.0.18 (test)- bump git-commit-id-plugin-core from 6.2.0 to 6.2.1 (refs https://github.com/git-commit-id/git-commit-id-plugin-core/releases/tag/v6.2.1, fix CVE-2026-59638 by making use of org.bouncycastle:bcpkix-jdk18on 1.85)
Github Action
git-commit-id/git-commit-id-maven-plugin#924: bump actions/cache from 5 to 6
git-commit-id/git-commit-id-maven-plugin#923: bump actions/checkout from 6 to 7
git-commit-id/git-commit-id-maven-plugin#935: bump actions/setup-java from 5 to 6Maven Plugins used by the plugin
git-commit-id/git-commit-id-maven-plugin#921: bump org.apache.maven.plugins:maven-site-plugin from 3.21.0 to 3.22.0
git-commit-id/git-commit-id-maven-plugin#918: bump org.apache.maven.plugins:maven-enforcer-plugin from 3.6.2 to 3.6.3
git-commit-id/git-commit-id-maven-plugin#925: bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.5 to 3.5.6
git-commit-id/git-commit-id-maven-plugin#927: bump org.jacoco:jacoco-maven-plugin from 0.8.14 to 0.8.15
git-commit-id/git-commit-id-maven-plugin#928: bump org.apache.maven.plugins:maven-dependency-plugin from 3.10.0 to 3.11.0
git-commit-id/git-commit-id-maven-plugin#930: bump org.sonatype.central:central-publishing-maven-plugin from 0.10.0 to 0.11.0
git-commit-id/git-commit-id-maven-plugin#934: bump org.apache.maven.plugins:maven-jar-plugin from 3.5.0 to 3.5.1Getting the latest release
The plugin is available from Maven Central (see here), so you don't have to configure any additional repositories to use this plugin. All you need to do is to configure it inside your project as dependency:
<dependency>
<groupId>io.github.git-commit-id</groupId>
<artifactId>git-commit-id-maven-plugin</artifactId>
<version>10.0.1</version>
</dependency>Getting the latest snapshot (build automatically)
If you can't wait for the next release, you can also get the latest snapshot version from sonatype, that is being deployed automatically by github actions:
<pluginRepositories>
<pluginRepository>
<id>sonatype-snapshots</id>
<name>Sonatype Snapshots</name>
<url>https://s01.oss.sonatype.org/content/repositories/snapshots/</url>
</pluginRepository>
</pluginRepositories>Even though the github actions will only deploy a new snapshot once all tests have finished, it is recommended to rely on the released and more stable version.
Known Issues / Limitations:
- This plugin is unfortunately not working with Heroku which is due to the fact how Heroku works. In summary Heroku does not copy over the .git-repository but in order to determine the git properties this plugin relies on the fact that it has access to the git-repository. A somewhat workaround to get some information is outlined in ktoso/maven-git-commit-id-plugin#279
- Using maven's plugin prefix resolution (e.g.
mvn com.test.plugins:myPlugin:myMojo) might result in unresolved properties even with<injectAllReactorProjects>true</injectAllReactorProjects>. Please refer to git-commit-id/maven-git-commit-id-plugin#287 or git-commit-id/maven-git-commit-id-plugin#413 for details and potential workarounds
<!-- raw HTML omitted -->
... (truncated)
Commits
-
73542f2Bump version: 10.0.0 → 10.0.1 -
7e95a7eRevert "add tests for java 27" -
dae217cadd tests for java 27 -
dc5b90brun tests with the latest maven versions 3.9.9 -> 3.9.16; 4.0.0-rc-5 -> 4.0.0... -
28f14aabump git-commit-id-plugin-core from 6.2.0 to 6.2.1 (refs https://github.com/g... -
dcf31abMerge pull request #934 from git-commit-id/dependabot/maven/org.apache.maven.... -
e4e48baMerge pull request #933 from git-commit-id/dependabot/maven/org.jspecify-jspe... -
ef3c336Merge pull request #935 from git-commit-id/dependabot/github_actions/actions/... -
eacd498Merge pull request #930 from git-commit-id/dependabot/maven/org.sonatype.cent... -
d892203build(deps): bump actions/setup-java from 5 to 6 - Additional commits viewable in compare view
Updates org.apache.maven.plugins:maven-compiler-plugin from 3.15.0 to 3.16.0
Release notes
Sourced from org.apache.maven.plugins:maven-compiler-plugin's releases.
3.16.0
<!-- raw HTML omitted -->🚀 New features and improvements
- Recompile when dependencies change (#1102)
@wilx- Fix incremental detection of empty sources, 3.x (#1075)
@wilx🐛 Bug Fixes
[MCOMPILER-578] - Track outputs across compiler executions (#1091)@wilx- Build fails when annotation processor list is empty (but present) (#1077)
@wilx
[MCOMPILER-374] - Unable to compile MR-JAR code against older directories when module-info.java is present (#1093)@wilx- Make mcompiler-120 IT locale independent (#1063)
@anilvdl📝 Documentation updates
[MCOMPILER-569] - Document implicitly compiled excluded sources (#1092)@wilx- Add AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (#1074)
@potiuk👻 Maintenance
- Avoid using deprecated method CompilerConfiguration.setCompilerVersion (#1121)
@slawekjaranowski- Replace adopt-openj9 by semeru JDK distribution on GH (#1122)
@slawekjaranowski- Port the site documentation from APT to Markdown (#1110)
@slachiewicz- Verify against Maven 4.0.0-rc-6 (#1105)
@slachiewicz- Fix tests on Jenkins (#1100)
@slawekjaranowski- Add AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (#1074)
@potiuk- Refactor compiler mojo to use dependency injection and improve string… (#1066)
@slachiewicz- Fix ITs for Maven 3.10.x (#1061)
@slawekjaranowski- Update maven-surefire-plugin version to 3.x in the MCOMPILER-481 IT (#1035)
@cdouillard📦 Dependency updates
- Bump plexusCompilerVersion from 2.16.2 to 2.17.0 (#1112) @dependabot[bot]
- Bump org.codehaus.plexus:plexus-java from 1.5.2 to 1.6.0 (#1113) @dependabot[bot]
- use latest Maven 4 (#1045)
@hboutemy- Bump apache/maven-gh-actions-shared/.github/workflows/release-drafter.yml from 4 to 5 (#1083) @dependabot[bot]
- Bump apache/maven-gh-actions-shared/.github/workflows/pr-automation.yml from 4 to 5 (#1082) @dependabot[bot]
- Bump apache/maven-gh-actions-shared/.github/workflows/maven-verify.yml from 4 to 5 (#1084) @dependabot[bot]
- Bump org.apache.maven.plugins:maven-plugins from 48 to 49 (#1068) @dependabot[bot]
- Bump org.apache.maven.plugins:maven-invoker-plugin from 3.9.1 to 3.10.1 (#1047) @dependabot[bot]
- Bump org.apache.maven.plugins:maven-plugins from 47 to 48 (#1050) @dependabot[bot]
- Bump mavenVersion from 3.9.14 to 3.9.16 (#1054) @dependabot[bot]
- Bump org.ow2.asm:asm from 9.10 to 9.10.1 (#1059) @dependabot[bot]
- Bump org.ow2.asm:asm from 9.9.1 to 9.10 (#1053) @dependabot[bot]
- Bump mavenVersion from 3.9.13 to 3.9.14 (#1041) @dependabot[bot]
- Bump mavenVersion from 3.9.12 to 3.9.13 (#1038) @dependabot[bot]
- Bump org.apache.maven.plugin-testing:maven-plugin-testing-harness from 3.5.0 to 3.5.1 (#1032) @dependabot[bot]
Commits
-
e7bba6e[maven-release-plugin] prepare release maven-compiler-plugin-3.16.0 -
c906809Avoid using deprecated method CompilerConfiguration.setCompilerVersion -
ad74feeReplace adopt-openj9 by semeru JDK distribution on GH -
beb0edaRecompile when dependencies change (#1102) -
a0b689e[MCOMPILER-578] Track outputs across compiler executions (#1091) -
2e81228Fix incremental detection of empty sources, 3.x (#1075) -
2132f5bconfigure ATR project -
5992b77Build fails when annotation processor list is empty (but present) (#1077) -
acccef7Bump plexusCompilerVersion from 2.16.2 to 2.17.0 -
72bc445Bump org.codehaus.plexus:plexus-java from 1.5.2 to 1.6.0 - Additional commits viewable in compare view
Updates com.diffplug.spotless:spotless-maven-plugin from 3.10.1 to 3.10.2
Release notes
Sourced from com.diffplug.spotless:spotless-maven-plugin's releases.
Maven Plugin v3.10.2
Fixed
<shortenFullyQualifiedTypes>now shortens fully-qualified types used in expression contexts (such as static method calls, static fields, and enum constants) while avoiding imports that would change how existing unqualified type references resolve. (#3039)- Eclipse JDT formatter step no longer fails with
NoClassDefFoundErrorwhen lombok is active as a JVM agent (e.g.-javaagent:lombok.jarin Eclipse/VS Code/Cursor). (#2795)
Commits
-
dc2a4cbPublished maven/3.10.2 -
876c8c4Published gradle/8.10.2 -
ff28375Published lib/4.10.2 -
e260aa7shortenFullyQualifiedTypes: preserve unqualified type resolution (#3037) -
5a2cdcaUpdate changelogs. -
98ca50eMerge remote-tracking branch 'origin/main' into 3033-unqualified-type-collision -
9591d7eResolve interopability with spotless, lombok and VSCode (#3038) -
5842e1bshortenFullyQualifiedTypes: shorten FQTs in expression context (#3039) -
e7f5b60Add changelog entries -
79ff6c7Resolve interopability with spotless, lombok and VSCode - Additional commits viewable in compare view
Updates org.apache.maven.plugins:maven-surefire-plugin from 3.5.6 to 3.6.0
Release notes
Sourced from org.apache.maven.plugins:maven-surefire-plugin's releases.
3.6.0
<!-- raw HTML omitted -->Please refer to the main page for what's new https://maven.apache.org/surefire/
And the migration page https://maven.apache.org/surefire/maven-surefire-plugin/whats-new-3-6-0.html🚀 New features and improvements
- Fix #3303: distinguish JUnit 6 ParameterizedClass invocations (#3432)
@AzazelSensei
[SUREFIRE-1639] - Add ability to configure JUnit 5 TestExecutionListener (#3438)@pan3793- Issue #838 Implement extension point to run diagnosis tools when forked JVM times out (#3372)
@olamy
[SUREFIRE-2148] - Verify recovered BeforeAll does not fail build (#3419)@wilx
[SUREFIRE-823] - Decouple -DskipTests from Failsafe plugin (#3371)@olamy- Use StackWalker in StackTraceProvider when available (Java 9+) (#3374)
@olamy- [Issue-3380] Send sourceQualifiedName to forked clients (#3380) (#3381)
@fabriciorby🐛 Bug Fixes
[SUREFIRE-523] - Link all reported tests to source XRef (#3445)@wilx
[SUREFIRE-3446] - Fix direct selection of JUnit Jupiter@Nestedclasses (#3447)@wilx- Discover tests in a fork when a toolchain JDK is used (#3444)
@olamy- [SUREFIRE-2239, SUREFIRE-2241, SUREFIRE-2260, SUREFIRE-2274, SUREFIRE-2300] Preserve JUnit Platform test identity across reruns (#3418)
@wilx- Fix #3428: resolve parents via TestPlan.getParent for pre-1.8 platforms (#3429)
@kalayciburak
[SUREFIRE-859] - Make random test order reproducible (#3421)@wilx- [SUREFIRE-862, SUREFIRE-3178] Handle missing Failsafe summary files (#3417)
@wilx- fix: report AfterAll/AfterClass exceptions as errors again (#3412) (#3413)
@arimu1- Fixes #3264 : tests inside
@Suiteincorrectly classified as flakes (#3342)@mirkoalicastro- Fix Windows flake in CommandChannelDecoderTest (#3400)
@ascheman- Fix reportNameSuffix in XML testcase classname (#3379)
@goutamadwant- Fix: resolve relative classpath elements against the fork's working dir (#3333)
@cwegener-79📝 Documentation updates
- Magnify the home, well at least have something rather than nothing :) (#3377)
@olamy- Restore the straight quotes the FAQ conversion turned typographic (#3425)
@slachiewicz- Restore the table borders lost in the APT conversion (#3424)
@slachiewicz- Convert the FAQ from FML to Markdown (#3423)
@slachiewicz- Convert the remaining site documentation from APT to Markdown (#3422)
@slachiewicz- javadoc: clarify statelessTestsetReporter, consoleOutputReporter, (#3410)
@joshinii- Add AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (#3387)
@potiuk- Update documentation we support Junit 6 as well :) (#3370)
@olamy👻 Maintenance
- Stop dependabot from updating test fixtures (#3440)
@slachiewicz- Migrate legacy plugin Javadoc annotations (#3416)
@wilx- Use the resolver's own HTTP transport in the report plugin tests (#3414)
@slachiewicz- Pin maven-jar-plugin 3.5.1 in modular IT fixtures (#3398)
@ascheman- Add AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (#3387)
@potiuk
<!-- raw HTML omitted -->
... (truncated)
Commits
-
0ff622b[maven-release-plugin] prepare release surefire-3.6.0 -
bb3932aLet's go for 3.6.0 release -
3002a16Bump mavenVersion from 3.9.14 to 3.9.16 -
61a531dBump Maven parent version from 47 to 49 (#3449) -
e52ead4[SUREFIRE-523] Link all reported tests to source XRef (#3445) -
45102fa[SUREFIRE-3446] Fix direct selection of JUnit Jupiter@Nestedclasses (#3447) -
b2e1f70Fix #3303: distinguish JUnit 6 ParameterizedClass invocations (#3432) -
c051938Discover tests in a fork when a toolchain JDK is used (#3444) -
db75df8Bump org.codehaus.plexus:plexus-java from 1.5.2 to 1.6.0 (#3441) -
77f2759Bump org.codehaus.plexus:plexus-interpolation from 1.29 to 1.30.0 - Additional commits viewable in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `@dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `@dependabot ignore major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
- `@dependabot ignore minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
- `@dependabot ignore ` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore ` will remove all of the ignore conditions of the specified dependency
- `@dependabot unignore ` will remove the ignore condition of the specified dependency and ignore conditions