Skip to content

FINERACT-2684: Update all non-major dependencies - #6275

Open
renovate-bot wants to merge 1 commit into
apache:developfrom
renovate-bot:renovate/all-minor-patch
Open

FINERACT-2684: Update all non-major dependencies#6275
renovate-bot wants to merge 1 commit into
apache:developfrom
renovate-bot:renovate/all-minor-patch

Conversation

@renovate-bot

@renovate-bot renovate-bot commented Aug 17, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change Age Confidence
apache/kafka minor 4.2.0-rc24.3.1-rc2 age confidence
gradle/actions action minor v6.2.0v6.3.0 age confidence
localstack/localstack minor 2.12.3 age confidence
mariadb (source) minor 12.212.3 age confidence
postgres (source) service minor 18.318.6 age confidence
zizmorcore/zizmor-action action patch v0.6.1v0.6.2 age confidence
org.apache.tomcat.embed:tomcat-embed-websocket devDependencies patch 10.1.5510.1.59 age confidence
org.apache.tomcat.embed:tomcat-embed-el devDependencies patch 10.1.5510.1.59 age confidence
org.apache.tomcat.embed:tomcat-embed-core devDependencies patch 10.1.5510.1.59 age confidence
at.yawk.lz4:lz4-java devDependencies patch 1.11.01.11.2 age confidence
io.netty:netty-transport-native-unix-common (source) devDependencies minor 4.1.135.Final4.2.17.Final age confidence
io.netty:netty-transport-classes-epoll (source) devDependencies minor 4.1.135.Final4.2.17.Final age confidence
io.netty:netty-transport (source) devDependencies minor 4.1.135.Final4.2.17.Final age confidence
io.netty:netty-resolver (source) devDependencies minor 4.1.135.Final4.2.17.Final age confidence
io.netty:netty-handler-proxy (source) devDependencies minor 4.1.135.Final4.2.17.Final age confidence
io.netty:netty-handler (source) devDependencies minor 4.1.135.Final4.2.17.Final age confidence
io.netty:netty-codec-socks (source) devDependencies minor 4.1.135.Final4.2.17.Final age confidence
io.netty:netty-codec-protobuf (source) devDependencies minor 4.1.135.Final4.2.17.Final age confidence
io.netty:netty-codec-marshalling (source) devDependencies minor 4.1.135.Final4.2.17.Final age confidence
io.netty:netty-codec-http2 (source) devDependencies minor 4.1.135.Final4.2.17.Final age confidence
io.netty:netty-codec-http (source) devDependencies minor 4.1.135.Final4.2.17.Final age confidence
io.netty:netty-codec-compression (source) devDependencies minor 4.1.135.Final4.2.17.Final age confidence
io.netty:netty-codec-base (source) devDependencies minor 4.1.135.Final4.2.17.Final age confidence
io.netty:netty-codec (source) devDependencies minor 4.1.135.Final4.2.17.Final age confidence
io.netty:netty-common (source) devDependencies minor 4.1.135.Final4.2.17.Final age confidence
io.netty:netty-buffer (source) devDependencies minor 4.1.135.Final4.2.17.Final age confidence
org.springframework.security:spring-security-core (source) devDependencies patch 6.5.106.5.11 age confidence
org.springframework:spring-core devDependencies patch 6.2.186.2.19 age confidence
com.nimbusds:nimbus-jose-jwt devDependencies patch 10.910.9.1 age confidence
org.springframework.restdocs:spring-restdocs-restassured devDependencies patch 3.0.53.0.6 age confidence
org.springframework.restdocs:spring-restdocs-webtestclient devDependencies patch 3.0.53.0.6 age confidence
org.springframework.restdocs:spring-restdocs-mockmvc devDependencies patch 3.0.53.0.6 age confidence
org.springframework.restdocs:spring-restdocs-asciidoctor devDependencies patch 3.0.53.0.6 age confidence
io.cucumber:cucumber-spring (source) devDependencies patch 7.34.37.34.7 age confidence
io.cucumber:cucumber-junit-platform-engine (source) devDependencies patch 7.34.37.34.7 age confidence
io.cucumber:cucumber-java8 (source) devDependencies patch 7.34.37.34.7 age confidence
io.cucumber:cucumber-java (source) devDependencies patch 7.34.37.34.7 age confidence
org.apache.sshd:sshd-core (source) devDependencies minor 2.17.12.19.0 age confidence
org.apache.sshd:sshd-common (source) devDependencies minor 2.17.12.19.0 age confidence
org.postgresql:postgresql (source) devDependencies patch 42.7.1142.7.13 age confidence
org.mariadb.jdbc:mariadb-java-client (source) devDependencies patch 3.5.83.5.10 age confidence
org.apache.avro:avro (source) devDependencies patch 1.12.11.12.2 age confidence
org.apache.groovy:groovy-json (source) devDependencies minor 5.0.65.1.0 age confidence
org.apache.groovy:groovy-xml (source) devDependencies minor 5.0.65.1.0 age confidence
org.hibernate.validator:hibernate-validator (source) devDependencies patch 9.1.0.Final9.1.3.Final age confidence
io.swagger.core.v3:swagger-core-jakarta devDependencies patch 2.2.492.2.54 age confidence
io.swagger.core.v3:swagger-jaxrs2-jakarta devDependencies patch 2.2.492.2.54 age confidence
io.swagger.core.v3:swagger-annotations-jakarta devDependencies patch 2.2.492.2.54 age confidence
org.apache.activemq:activemq-client (source) devDependencies minor 6.2.56.3.1 age confidence
org.springdoc:springdoc-openapi-starter-webmvc-ui (source) devDependencies minor 2.8.172.9.0 age confidence
org.eclipse.jgit:org.eclipse.jgit.ssh.apache devDependencies minor 7.6.0.202603022253-r7.7.1.202607240634-r age confidence
org.eclipse.jgit:org.eclipse.jgit.gpg.bc devDependencies minor 7.6.0.202603022253-r7.7.1.202607240634-r age confidence
org.eclipse.jgit:org.eclipse.jgit devDependencies minor 7.6.0.202603022253-r7.7.1.202607240634-r age confidence
org.bouncycastle:bcpg-jdk18on (source) devDependencies minor 1.841.85 age confidence
org.bouncycastle:bcutil-jdk18on (source) devDependencies minor 1.841.85 age confidence
org.bouncycastle:bcprov-jdk18on (source) devDependencies minor 1.841.85.2 age confidence
org.bouncycastle:bcpkix-jdk18on (source) devDependencies minor 1.841.85 age confidence
commons-codec:commons-codec (source) devDependencies patch 1.22.01.22.1 age confidence
org.mock-server:mockserver-junit-jupiter (source) devDependencies minor 5.14.05.15.0 age confidence
com.github.spotbugs:spotbugs-annotations (source) devDependencies minor 4.9.84.10.4 age confidence
io.github.classgraph:classgraph devDependencies patch 4.8.1844.8.193 age confidence
joda-time:joda-time (source) devDependencies patch 2.14.22.14.3 age confidence
org.apache.httpcomponents.core5:httpcore5-h2 (source) devDependencies patch 5.45.4.3 age confidence
org.apache.httpcomponents.core5:httpcore5 (source) devDependencies patch 5.45.4.3 age confidence
org.apache.tika:tika-parser-image-module (source) devDependencies patch 3.3.03.3.2 age confidence
org.cyclonedx.bom plugin minor 3.2.43.4.1 age confidence
com.gradleup.shadow plugin minor 9.4.19.6.1 age confidence
org.openapi.generator plugin minor 7.22.07.24.0 age confidence
com.github.spotbugs plugin patch 6.5.46.5.11 age confidence
com.github.andygoossens.modernizer plugin minor 1.13.01.15.0 age confidence
com.google.cloud.tools.jib plugin patch 3.5.33.5.4 age confidence
org.apache.tika:tika-parser-microsoft-module (source) devDependencies patch 3.3.03.3.2 age confidence
io.swagger.core.v3.swagger-gradle-plugin plugin patch 2.2.492.2.54 age confidence
org.springframework.boot (source) plugin patch 3.5.153.5.16 age confidence
org.apache.tika:tika-parser-miscoffice-module (source) devDependencies patch 3.3.03.3.2 age confidence
org.apache.tika:tika-core (source) devDependencies patch 3.3.03.3.2 age confidence
com.github.librepdf:openpdf devDependencies patch 3.0.43.0.5 age confidence
software.amazon.msk:aws-msk-iam-auth (source) devDependencies patch 2.3.62.3.7 age confidence
org.apache.commons:commons-collections4 (source) devDependencies minor 4.5.04.6.0 age confidence
com.google.googlejavaformat:google-java-format devDependencies minor 1.35.01.36.1 age confidence
com.google.guava:guava devDependencies minor 33.6.0-jre33.7.1-jre age confidence
ch.qos.logback:logback-classic (source, changelog) devDependencies minor 1.5.351.6.3 age confidence
ch.qos.logback:logback-core (source, changelog) devDependencies minor 1.5.351.6.3 age confidence
org.glassfish.jersey:jersey-bom (source) devDependencies patch 3.1.113.1.12 age confidence
software.amazon.awssdk:bom devDependencies minor 2.44.42.54.2 age confidence
io.cucumber:cucumber-bom (source) devDependencies patch 7.34.37.34.7 age confidence
com.fasterxml.jackson:jackson-bom devDependencies patch 2.22.12.22.2 age confidence
org.jetbrains.kotlin:kotlin-bom (source) devDependencies minor 2.3.212.4.10 age confidence
io.opentelemetry:opentelemetry-bom devDependencies minor 1.62.01.65.0 age confidence
io.awspring.cloud:spring-cloud-aws-dependencies (source) devDependencies minor 4.0.24.1.0 age confidence
org.springframework.boot:spring-boot-dependencies (source) devDependencies patch 3.5.153.5.16 age confidence
io.micrometer:micrometer-bom devDependencies minor 1.16.51.17.1 age confidence
org.slf4j:slf4j-bom (source, changelog) devDependencies patch 2.0.172.0.18 age confidence
com.gradle.common-custom-user-data-gradle-plugin plugin minor 2.6.02.8.0 age confidence

Release Notes

apache/kafka (apache/kafka)

v4.3.1

Compare Source

v4.3.0

Compare Source

v4.2.1

Compare Source

gradle/actions (gradle/actions)

v6.3.0

Compare Source

Highlights

Enhanced Caching: Windows fixes and a cache-protocol bump

This release updates gradle-actions-caching to v1.0.0 (up from v0.7.0), which fixes two significant caching defects, both most visible on Windows:

  • Cache entries failed to store at all on Windows.. Every entry failed
    with Path Validation Error: Path(s) specified in the action for caching do(es) not exist, even though the Gradle User Home was fully intact. Nothing was stored, so
    every downstream job ran against an empty Gradle User Home. The cause was a nested,
    unpatched copy of @actions/glob combined with a silently swallowed require() in
    the bundle, which left Windows path separators unnormalized.

  • Cache cleanup deleted instrumented jars that were in use. A bug in key
    hashing for paths shorter than 64 characters made cleanup judge freshly created
    caches/jars-9 entries as unused and remove them, so the instrumented-jars entry
    was never saved and every job re-instrumented its classpaths.

    Also included: cache entry names are now consistent between the save and restore
    reports — restore previously fell back to showing the raw glob pattern (e.g.
    /home/runner/.gradle/caches/modules-*/files-*/*/*/*/*/) instead of dependencies.

[!IMPORTANT]
Existing cache entries are invalidated by this release. The cache protocol
version was bumped to v2, so the first run after upgrading will be a cache miss
and will repopulate the cache. No configuration changes are required.

Basic caching warns instead of failing silently

The basic (open-source) caching provider now emits a warning and reports
(Entry not saved: save failed) in the Job Summary when a cache save fails, rather
than reporting success (#​1028).

Dependency submission works with Isolated Projects

dependency-submission now disables Isolated Projects via a promoted property, so
dependency graph generation works on builds that enable it (#​1025). Thanks to @​reinsch82 for the contribution.

Updated defaults
  • Injected Develocity Gradle plugin: 4.4.2 → 4.5.0
  • 36 new known-good wrapper checksums added for wrapper-validation

What's Changed

New Contributors

Full Changelog: gradle/actions@v6.2.0...v6.3.0

zizmorcore/zizmor-action (zizmorcore/zizmor-action)

v0.6.2

Compare Source

zizmor 1.29.0 is now the default version.

yawkat/lz4-java (at.yawk.lz4:lz4-java)

v1.11.2: lz4-java v1.11.2

Security release for GHSA-6cx8-rjf8-pr8g and GHSA-4v53-57pg-c464.

What's Changed

New Contributors

Full Changelog: yawkat/lz4-java@v1.11.1...v1.11.2

v1.11.1: lz4-java v1.11.1

Security release for CVE-2026-59949.

What's Changed

Full Changelog: yawkat/lz4-java@v1.11.0...v1.11.1

spring-projects/spring-security (org.springframework.security:spring-security-core)

v6.5.11

Compare Source

🪲 Bug Fixes

  • FormPostRedirectStrategy should not emit percent-encoded values into hidden form inputs #​19136

🔨 Dependency Upgrades

  • Bump antora from 3.2.0-alpha.11 to 3.2.0-alpha.12 in /docs #​19185
  • Bump ch.qos.logback:logback-classic from 1.5.32 to 1.5.34 #​19299
  • Bump com.fasterxml.jackson:jackson-bom from 2.18.6 to 2.18.7 #​19129
  • Bump com.fasterxml.jackson:jackson-bom from 2.18.7 to 2.18.8 #​19297
  • Bump gradle-wrapper from 8.14.4 to 8.14.5 #​19159
  • Bump org-bouncycastle from 1.80 to 1.80.2 #​19204
  • Bump org.apache.maven:maven-resolver-provider from 3.9.15 to 3.9.16 #​19205
  • Bump org.hibernate.orm:hibernate-core from 6.6.49.Final to 6.6.50.Final #​19150
  • Bump org.hibernate.orm:hibernate-core from 6.6.50.Final to 6.6.51.Final #​19213
  • Bump org.hibernate.orm:hibernate-core from 6.6.51.Final to 6.6.53.Final #​19300
  • Bump org.slf4j:slf4j-api from 2.0.17 to 2.0.18 #​19173
  • Bump org.springframework:spring-framework-bom from 6.2.18 to 6.2.19 #​19293
  • Bump spring-io/spring-gradle-build-action from 2.0.5 to 2.0.6 #​19124
  • Bump spring-io/spring-release-actions from 0.0.4 to 0.0.5 #​19183
  • Update micrometer-bom to 1.15.12 #​19302
  • Update to Micrometer 1.15.11 #​19224
  • Update to reactor-bom 2024.0.18 #​19301

🔩 Build Updates

spring-projects/spring-framework (org.springframework:spring-core)

v6.2.19

⚠️ Security Fixes

This maintenance release fixes a high number of CVEs. You can learn more about this in the "Spring and Security In The Times Of AI" blog post. Here is the full list of 16 CVEs:

  • CVE-2026-41838 "Spring Framework Predictable Session ID in WebSocket Module"
  • CVE-2026-41839 "Spring Framework Escalation via Session Fixation in WebFlux"
  • CVE-2026-41840 "Spring Framework Denial of Service via Multipart Requests in WebFlux"
  • CVE-2026-41841 "Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux"
  • CVE-2026-41842 "Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux"
  • CVE-2026-41843 "Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux"
  • CVE-2026-41844 "Spring Framework Open Redirect in Spring MVC and WebFlux"
  • CVE-2026-41845 "Spring Framework Cross-site Scripting via JavaScriptUtils"
  • CVE-2026-41846 "Spring Framework Cross-site Scripting via JSP Form Tags"
  • CVE-2026-41848 "Spring Framework Denial of Service via AntPathMatcher"
  • CVE-2026-41850 "Spring Framework Algorithmic Denial of Service via SpEL Expressions"
  • CVE-2026-41851 "Spring Framework Denial of Service via Unbounded Cache in SpEL"
  • CVE-2026-41852 "Spring Framework Arbitrary Method Invocation in SpEL Expressions"
  • CVE-2026-41853 "Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux"
  • CVE-2026-41854 "Spring Framework Server-Side Request Forgery via UriComponentsBuilder"
  • CVE-2026-41855 "Spring Framework Unsafe Deserialization via Jackson JMS Converters"
⭐ New Features
  • Avoid too many character access attempts in AntPathMatcher #​36886
  • Track operations during SpEL expression evaluation #​36887
  • Ensure getters have non-void r

Note

PR body was truncated to here.


Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@forking-renovate forking-renovate Bot added the renovate https://renovate.whitesourcesoftware.com [FINERACT-962] label Aug 17, 2026
@renovate-bot
renovate-bot force-pushed the renovate/all-minor-patch branch 11 times, most recently from 06a5fcc to a7eff2b Compare August 21, 2026 00:56
@renovate-bot
renovate-bot force-pushed the renovate/all-minor-patch branch from a7eff2b to b3163ab Compare August 21, 2026 22:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

renovate https://renovate.whitesourcesoftware.com [FINERACT-962]

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant