Bump the dependencies group across 1 directory with 16 updates #2436

Open
dependabot[bot] opened 11:35am on September 21, 2026 wants to merge 1 commit into fraunhoferiosb/frost-server v2.6.x from
dependabot/maven/v2.6.x/dependencies-996fd6e2be
Diff Delta:
0
Classified as:  General

dependabot-bot's Description of Work

Bumps the dependencies group with 16 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| io.prometheus:prometheus-metrics-bom | 1.8.0 | 1.9.0 |
| org.eclipse.jetty.ee10:jetty-ee10-servlet | 12.1.12 | 12.1.13 |
| org.jooq:jooq | 3.21.7 | 3.21.8 |
| org.jooq:jooq-codegen | 3.21.7 | 3.21.8 |
| org.jooq:jooq-meta | 3.21.7 | 3.21.8 |
| org.jooq:jooq-codegen | 3.21.7 | 3.21.8 |
| org.jooq:jooq-meta | 3.21.7 | 3.21.8 |
| org.slf4j:jul-to-slf4j | 2.0.18 | 2.0.19 |
| org.slf4j:slf4j-api | 2.0.18 | 2.0.19 |
| org.slf4j:slf4j-api | 2.0.18 | 2.0.19 |
| io.github.git-commit-id:git-commit-id-maven-plugin | 10.0.0 | 10.0.1 |
| org.apache.maven.plugins:maven-compiler-plugin | 3.15.0 | 3.16.0 |
| org.codehaus.mojo:build-helper-maven-plugin | 3.6.1 | 3.6.2 |
| org.codehaus.mojo:exec-maven-plugin | 3.6.3 | 3.6.4 |
| com.diffplug.spotless:spotless-maven-plugin | 3.10.1 | 3.10.2 |
| org.apache.maven.plugins:maven-surefire-plugin | 3.5.6 | 3.6.0 |
| org.bouncycastle:bcpkix-jdk18on | 1.85 | 1.86 |
| org.bouncycastle:bcprov-jdk18on | 1.85 | 1.86 |
| org.bouncycastle:bcutil-jdk18on | 1.85 | 1.86 |
| org.bouncycastle:bcprov-jdk18on | 1.85 | 1.86 |
| org.bouncycastle:bcutil-jdk18on | 1.85 | 1.86 |

Updates io.prometheus:prometheus-metrics-bom from 1.8.0 to 1.9.0

Release notes

Sourced from io.prometheus:prometheus-metrics-bom's releases.



v1.9.0



1.9.0 (2026-09-16)


Features



  • support metric name filtering in OpenTelemetry exporter (#2344) (9b0ede8)


Bug Fixes



  • avoid protobuf debug reflection in native images (#2251) (7f899e7)

  • bound HTTPServer request resources (#2333) (33ec556)

  • bound observation buffering during collection (#2336) (43788f5)

  • bound scrape query parameters (#2334) (27e1912)


  • ci: skip benchmark report for skipped runs (#2422) (40eddb0)

  • clarify benchmark regression report verdicts (#2394) (e5fa067)


  • deps: update dependency com.google.guava:guava to v33.7.0-jre (#2387) (bf0db49)


  • deps: update dependency io.dropwizard.metrics:metrics-core to v4.2.40 (#2432) (dd88326)


  • deps: update dependency io.dropwizard.metrics5:metrics-core to v5.0.8 (#2433) (42f3c8a)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.29.0-alpha (#2235) (cf9f702)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.30.0-alpha (#2328) (1ca2716)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.30.0-alpha (#2330) (07623c1)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.31.0-alpha (#2401) (6c26619)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.31.0-alpha (#2402) (ac0d68a)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.31.1-alpha (#2409) (5eea652)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.31.1-alpha (#2410) (0bcef89)


  • deps: update dependency org.apache.tomcat.embed:tomcat-embed-core to v11.0.23 (#2241) (a017f80)


  • deps: update dependency org.apache.tomcat.embed:tomcat-embed-core to v11.0.24 (#2294) (63967bd)


  • deps: update dependency org.apache.tomcat.embed:tomcat-embed-core to v11.0.25 (#2389) (92f8344)


  • deps: update dependency org.apache.tomcat.embed:tomcat-embed-core to v11.0.26 (#2477) (05146c0)


  • deps: update dependency org.springframework.boot:spring-boot-starter-parent to v4.1.1 (#2399) (a0b0880)


  • deps: update jetty monorepo to v12.1.11 (#2279) (4dc54da)


  • deps: update jetty monorepo to v12.1.12 (#2371) (08967e0)


  • deps: update jetty monorepo to v12.1.13 (#2459) (b217f05)


  • deps: update junit-framework monorepo to v6.1.2 (#2300) (5966d1d)


  • deps: update junit-framework monorepo to v6.1.3 (#2374) (d1ade52)


  • deps: update otel.instrumentation.version (#2236) (158230d)


  • deps: update protobuf (#2400) (e2db1ed)


  • deps: update protobuf (#2438) (8ad6fa8)


  • deps: update protobuf to v4.35.1 (#2221) (cf17073)

  • disable micrometer compat build cache (#2457) (6a40eda)

  • drop +Inf bound from OpenTelemetry classic histogram boundaries (#2458) (a3bce9a)


  • exposition: export internal package for OSGi resolution (#2415) (28b503d)


  • httpserver: make scrape error responses secure and configurable (f6d9df5)

  • include counter names in negative value errors (#2315) (ea8f935)

  • include license files in release source jars (#2250) (08cf925), closes #2216

  • keep late observations out of subsequent collection buffers (#2471) (d78b149)

  • keep PR title check required after rebases (#2414) (e3d4c3b)

  • prevent buffer stripe index overflow (#2331) (b6cd000)


<!-- raw HTML omitted -->

... (truncated)

Changelog

Sourced from io.prometheus:prometheus-metrics-bom's changelog.




1.9.0 (2026-09-16)


Features



  • support metric name filtering in OpenTelemetry exporter (#2344) (9b0ede8)


Bug Fixes



  • avoid protobuf debug reflection in native images (#2251) (7f899e7)

  • bound HTTPServer request resources (#2333) (33ec556)

  • bound observation buffering during collection (#2336) (43788f5)

  • bound scrape query parameters (#2334) (27e1912)


  • ci: skip benchmark report for skipped runs (#2422) (40eddb0)

  • clarify benchmark regression report verdicts (#2394) (e5fa067)


  • deps: update dependency com.google.guava:guava to v33.7.0-jre (#2387) (bf0db49)


  • deps: update dependency io.dropwizard.metrics:metrics-core to v4.2.40 (#2432) (dd88326)


  • deps: update dependency io.dropwizard.metrics5:metrics-core to v5.0.8 (#2433) (42f3c8a)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.29.0-alpha (#2235) (cf9f702)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.30.0-alpha (#2328) (1ca2716)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.30.0-alpha (#2330) (07623c1)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.31.0-alpha (#2401) (6c26619)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.31.0-alpha (#2402) (ac0d68a)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.31.1-alpha (#2409) (5eea652)


  • deps: update dependency io.opentelemetry.instrumentation:opentelemetry-instrumentation-bom-alpha to v2.31.1-alpha (#2410) (0bcef89)


  • deps: update dependency org.apache.tomcat.embed:tomcat-embed-core to v11.0.23 (#2241) (a017f80)


  • deps: update dependency org.apache.tomcat.embed:tomcat-embed-core to v11.0.24 (#2294) (63967bd)


  • deps: update dependency org.apache.tomcat.embed:tomcat-embed-core to v11.0.25 (#2389) (92f8344)


  • deps: update dependency org.apache.tomcat.embed:tomcat-embed-core to v11.0.26 (#2477) (05146c0)


  • deps: update dependency org.springframework.boot:spring-boot-starter-parent to v4.1.1 (#2399) (a0b0880)


  • deps: update jetty monorepo to v12.1.11 (#2279) (4dc54da)


  • deps: update jetty monorepo to v12.1.12 (#2371) (08967e0)


  • deps: update jetty monorepo to v12.1.13 (#2459) (b217f05)


  • deps: update junit-framework monorepo to v6.1.2 (#2300) (5966d1d)


  • deps: update junit-framework monorepo to v6.1.3 (#2374) (d1ade52)


  • deps: update otel.instrumentation.version (#2236) (158230d)


  • deps: update protobuf (#2400) (e2db1ed)


  • deps: update protobuf (#2438) (8ad6fa8)


  • deps: update protobuf to v4.35.1 (#2221) (cf17073)

  • disable micrometer compat build cache (#2457) (6a40eda)

  • drop +Inf bound from OpenTelemetry classic histogram boundaries (#2458) (a3bce9a)


  • exposition: export internal package for OSGi resolution (#2415) (28b503d)


  • httpserver: make scrape error responses secure and configurable (f6d9df5)

  • include counter names in negative value errors (#2315) (ea8f935)

  • include license files in release source jars (#2250) (08cf925), closes #2216

  • keep late observations out of subsequent collection buffers (#2471) (d78b149)

  • keep PR title check required after rebases (#2414) (e3d4c3b)

  • prevent buffer stripe index overflow (#2331) (b6cd000)

  • redact invalid configuration values (#2335) (7e7e533)


<!-- raw HTML omitted -->

... (truncated)

Commits



  • 71e821c chore(main): release 1.9.0 (#2237)


  • d78b149 fix: keep late observations out of subsequent collection buffers (#2471)


  • 085263b perf: avoid allocating a mapping lambda on every labelValues() call (#2442)


  • 9ec38b7 chore(deps): update otel/opentelemetry-collector-contrib docker tag to v0.161...


  • 05146c0 fix(deps): update dependency org.apache.tomcat.embed:tomcat-embed-core to v11...


  • 59ca1f0 test: focus PR benchmarks on client_java and measure label lookups (#2468)


  • 398d087 fix: show uncertainty in benchmark comparisons (#2476)


  • 8722230 perf: skip snapshot rebuild in mergeDuplicates when names are unique (#2441)


  • ea8f935 fix: include counter names in negative value errors (#2315)


  • fba2007 test: verify buffer recovery after snapshot failures (#2446)

  • Additional commits viewable in compare view


Updates org.eclipse.jetty.ee10:jetty-ee10-servlet from 12.1.12 to 12.1.13

Updates org.jooq:jooq from 3.21.7 to 3.21.8

Updates org.jooq:jooq-codegen from 3.21.7 to 3.21.8

Updates org.jooq:jooq-meta from 3.21.7 to 3.21.8

Updates org.jooq:jooq-codegen from 3.21.7 to 3.21.8

Updates org.jooq:jooq-meta from 3.21.7 to 3.21.8

Updates org.slf4j:jul-to-slf4j from 2.0.18 to 2.0.19

Updates org.slf4j:slf4j-api from 2.0.18 to 2.0.19

Updates org.slf4j:slf4j-api from 2.0.18 to 2.0.19

Updates io.github.git-commit-id:git-commit-id-maven-plugin from 10.0.0 to 10.0.1

Release notes

Sourced from io.github.git-commit-id:git-commit-id-maven-plugin's releases.



Version 10.0.1 is finally there and includes various bug-fixes and improvements :-)


What's Changed


Dependencies used by the plugin



Github Action



Maven Plugins used by the plugin



Getting the latest release


The plugin is available from Maven Central (see here), so you don't have to configure any additional repositories to use this plugin. All you need to do is to configure it inside your project as dependency:


<dependency>

<groupId>io.github.git-commit-id</groupId>
<artifactId>git-commit-id-maven-plugin</artifactId>
<version>10.0.1</version>
</dependency>

Getting the latest snapshot (build automatically)


If you can't wait for the next release, you can also get the latest snapshot version from sonatype, that is being deployed automatically by github actions:


<pluginRepositories>

<pluginRepository>
<id>sonatype-snapshots</id>
<name>Sonatype Snapshots</name>
<url>https://s01.oss.sonatype.org/content/repositories/snapshots/&lt;/url>
</pluginRepository>
</pluginRepositories>

Even though the github actions will only deploy a new snapshot once all tests have finished, it is recommended to rely on the released and more stable version.


Known Issues / Limitations:



  • This plugin is unfortunately not working with Heroku which is due to the fact how Heroku works. In summary Heroku does not copy over the .git-repository but in order to determine the git properties this plugin relies on the fact that it has access to the git-repository. A somewhat workaround to get some information is outlined in ktoso/maven-git-commit-id-plugin#279

  • Using maven's plugin prefix resolution (e.g. mvn com.test.plugins:myPlugin:myMojo) might result in unresolved properties even with <injectAllReactorProjects>true</injectAllReactorProjects>. Please refer to git-commit-id/maven-git-commit-id-plugin#287 or git-commit-id/maven-git-commit-id-plugin#413 for details and potential workarounds


<!-- raw HTML omitted -->

... (truncated)

Commits



  • 73542f2 Bump version: 10.0.0 → 10.0.1


  • 7e95a7e Revert "add tests for java 27"


  • dae217c add tests for java 27


  • dc5b90b run tests with the latest maven versions 3.9.9 -> 3.9.16; 4.0.0-rc-5 -> 4.0.0...


  • 28f14aa bump git-commit-id-plugin-core from 6.2.0 to 6.2.1 (refs https://github.com/g...


  • dcf31ab Merge pull request #934 from git-commit-id/dependabot/maven/org.apache.maven....


  • e4e48ba Merge pull request #933 from git-commit-id/dependabot/maven/org.jspecify-jspe...


  • ef3c336 Merge pull request #935 from git-commit-id/dependabot/github_actions/actions/...


  • eacd498 Merge pull request #930 from git-commit-id/dependabot/maven/org.sonatype.cent...


  • d892203 build(deps): bump actions/setup-java from 5 to 6

  • Additional commits viewable in compare view


Updates org.apache.maven.plugins:maven-compiler-plugin from 3.15.0 to 3.16.0

Release notes

Sourced from org.apache.maven.plugins:maven-compiler-plugin's releases.



3.16.0


<!-- raw HTML omitted -->

🚀 New features and improvements



🐛 Bug Fixes



📝 Documentation updates



👻 Maintenance



📦 Dependency updates



Commits



  • e7bba6e [maven-release-plugin] prepare release maven-compiler-plugin-3.16.0


  • c906809 Avoid using deprecated method CompilerConfiguration.setCompilerVersion


  • ad74fee Replace adopt-openj9 by semeru JDK distribution on GH


  • beb0eda Recompile when dependencies change (#1102)


  • a0b689e [MCOMPILER-578] Track outputs across compiler executions (#1091)


  • 2e81228 Fix incremental detection of empty sources, 3.x (#1075)


  • 2132f5b configure ATR project


  • 5992b77 Build fails when annotation processor list is empty (but present) (#1077)


  • acccef7 Bump plexusCompilerVersion from 2.16.2 to 2.17.0


  • 72bc445 Bump org.codehaus.plexus:plexus-java from 1.5.2 to 1.6.0

  • Additional commits viewable in compare view


Updates org.codehaus.mojo:build-helper-maven-plugin from 3.6.1 to 3.6.2

Release notes

Sourced from org.codehaus.mojo:build-helper-maven-plugin's releases.



3.6.2


<!-- raw HTML omitted -->

🐛 Bug Fixes



👻 Maintenance



  • Remove redundant maven-resolver-api dependency and ignore Resolver/SLF4J 2.x in Dependabot (#248) @​slachiewicz


📦 Dependency updates


<!-- raw HTML omitted -->

<!-- raw HTML omitted -->

Commits



  • 813bc7d [maven-release-plugin] prepare release 3.6.2


  • 07d9109 Remove redundant maven-resolver-api and ignore Resolver/SLF4J 2.x in Dependabot


  • 9abd552 Bump org.codehaus.plexus:plexus-utils from 4.0.3 to 4.1.0


  • 3c15526 Bump apache/maven-gh-actions-shared/.github/workflows/release-drafter.yml


  • 3b1f104 Bump org.codehaus.mojo:mojo-parent from 96 to 97


  • 1749855 Bump apache/maven-gh-actions-shared/.github/workflows/maven-verify.yml


  • 5230041 Bump org.codehaus.plexus:plexus-utils from 4.0.2 to 4.0.3


  • c0e9375 Delete .github/release-drafter.yml


  • 84a839e Bump org.codehaus.mojo:mojo-parent from 95 to 96


  • a85c668 Replace raw NPEx with customized exception message

  • Additional commits viewable in compare view


Updates org.codehaus.mojo:exec-maven-plugin from 3.6.3 to 3.6.4

Release notes

Sourced from org.codehaus.mojo:exec-maven-plugin's releases.



3.6.4


<!-- raw HTML omitted -->

📝 Documentation updates



👻 Maintenance



📦 Dependency updates


<!-- raw HTML omitted -->

<!-- raw HTML omitted -->

Commits



  • 56083f0 [maven-release-plugin] prepare release 3.6.4


  • 57c594b Ignore Maven Resolver >= 2.0 and SLF4J >= 2.0 in Dependabot


  • c2f5d4e Update required module name in jigsaw IT to org.codehaus.plexus.util


  • d227ee6 Bump org.codehaus.plexus:plexus-utils in /src/it/projects/jigsaw


  • 388fd99 Bump org.codehaus.plexus:plexus-utils from 4.0.3 to 4.1.0


  • 30106e8 Stop dependabot from updating test fixtures


  • b6d5eab Bump apache/maven-gh-actions-shared/.github/workflows/release-drafter.yml


  • aa98aba Bump org.codehaus.mojo:mojo-parent from 96 to 97


  • 79cfdcd Bump org.apache.maven.plugins:maven-toolchains-plugin


  • 8c58ad6 Fix typo in docs (#531)

  • Additional commits viewable in compare view


Updates com.diffplug.spotless:spotless-maven-plugin from 3.10.1 to 3.10.2

Release notes

Sourced from com.diffplug.spotless:spotless-maven-plugin's releases.



Maven Plugin v3.10.2


Fixed




  • <shortenFullyQualifiedTypes> now shortens fully-qualified types used in expression contexts (such as static method calls, static fields, and enum constants) while avoiding imports that would change how existing unqualified type references resolve. (#3039)

  • Eclipse JDT formatter step no longer fails with NoClassDefFoundError when lombok is active as a JVM agent (e.g. -javaagent:lombok.jar in Eclipse/VS Code/Cursor). (#2795)


Commits



  • dc2a4cb Published maven/3.10.2


  • 876c8c4 Published gradle/8.10.2


  • ff28375 Published lib/4.10.2


  • e260aa7 shortenFullyQualifiedTypes: preserve unqualified type resolution (#3037)


  • 5a2cdca Update changelogs.


  • 98ca50e Merge remote-tracking branch 'origin/main' into 3033-unqualified-type-collision


  • 9591d7e Resolve interopability with spotless, lombok and VSCode (#3038)


  • 5842e1b shortenFullyQualifiedTypes: shorten FQTs in expression context (#3039)


  • e7f5b60 Add changelog entries


  • 79ff6c7 Resolve interopability with spotless, lombok and VSCode

  • Additional commits viewable in compare view


Updates org.apache.maven.plugins:maven-surefire-plugin from 3.5.6 to 3.6.0

Release notes

Sourced from org.apache.maven.plugins:maven-surefire-plugin's releases.



3.6.0


<!-- raw HTML omitted -->

Please refer to the main page for what's new https://maven.apache.org/surefire/
And the migration page https://maven.apache.org/surefire/maven-surefire-plugin/whats-new-3-6-0.html


🚀 New features and improvements



Description has been truncated

0 total changed files
End of PR:
Please mind the merge button