Skip to content

chore(deps): Consolidated dependency updates#2576

Merged
cmgrote merged 2 commits into
mainfrom
dependencies
Jun 18, 2026
Merged

chore(deps): Consolidated dependency updates#2576
cmgrote merged 2 commits into
mainfrom
dependencies

Conversation

@cmgrote

@cmgrote cmgrote commented Jun 18, 2026

Copy link
Copy Markdown
Collaborator

Summary

Consolidates 24 dependency PRs into a single update.

Updates

Dependency Version Change Original PR
awssdk 2.44.9 → 2.46.13 #2574
spotless-plugin-gradle 8.5.1 → 8.7.0 #2572
actions/setup-java v5.2.0 → v5.3.0 #2571
com.google.cloud:libraries-bom 26.83.0 → 26.84.0 #2567
swagger-parser 2.1.42 → 2.1.44 #2565
azure-identity 1.18.3 → 1.18.4 #2564
azure-storage-file-datalake 12.27.0 → 12.28.0 #2563
openlineage-java 1.47.1 → 1.49.0 #2559
azure-core-http-okhttp 1.13.4 → 1.13.5 #2557
sqlite-jdbc 3.53.1.0 → 3.53.2.0 #2551
kotlin-test 2.3.21 → 2.4.0 #2550
kotlin.jvm gradle plugin 2.3.21 → 2.4.0 #2549
netty 4.2.13.Final → 4.2.15.Final #2547
jetty 12.1.9 → 12.1.10 #2545
actions/checkout v6.0.2 → v6.0.3 #2544
jackson 2.21.3 → 2.22.0 #2541
nimbus-jose-jwt 10.9 → 10.9.1 #2540
elasticsearch-java 9.4.0 → 9.4.2 #2536
shadow plugin 9.4.1 → 9.4.2 #2533
parsson 1.1.7 → 1.1.9 #2528
docker/setup-buildx-action v4.0.0 → v4.1.0 #2527
docker/login-action v4.1.0 → v4.2.0 #2526
docker/build-push-action v7.1.0 → v7.2.0 #2522
otel-instrumentation-bom-alpha 2.28.0-alpha → 2.28.1-alpha #2515

Excluded (needs separate review)

Original PRs consolidated

#2574, #2572, #2571, #2567, #2565, #2564, #2563, #2559, #2557, #2551, #2550, #2549, #2547, #2545, #2544, #2541, #2540, #2536, #2533, #2528, #2527, #2526, #2522, #2515


Generated by /consolidate-deps skill

Consolidates updates from the following dependency PRs:
- #2574: chore(deps): Bump awssdk from 2.44.9 to 2.46.13
- #2572: chore(deps): Bump spotless-plugin-gradle from 8.5.1 to 8.7.0
- #2571: chore(deps): Bump actions/setup-java from 5.2.0 to 5.3.0
- #2567: chore(deps): Bump com.google.cloud:libraries-bom from 26.83.0 to 26.84.0
- #2565: chore(deps): Bump swagger-parser from 2.1.42 to 2.1.44
- #2564: chore(deps): Bump azure-identity from 1.18.3 to 1.18.4
- #2563: chore(deps): Bump azure-storage-file-datalake from 12.27.0 to 12.28.0
- #2559: chore(deps): Bump openlineage-java from 1.47.1 to 1.49.0
- #2557: chore(deps): Bump azure-core-http-okhttp from 1.13.4 to 1.13.5
- #2551: chore(deps): Bump sqlite-jdbc from 3.53.1.0 to 3.53.2.0
- #2550: chore(deps): Bump kotlin-test from 2.3.21 to 2.4.0
- #2549: chore(deps): Bump kotlin.jvm gradle plugin from 2.3.21 to 2.4.0
- #2547: chore(deps): Bump netty from 4.2.13.Final to 4.2.15.Final
- #2545: chore(deps): Bump jetty from 12.1.9 to 12.1.10
- #2544: chore(deps): Bump actions/checkout from 6.0.2 to 6.0.3
- #2541: chore(deps): Bump jackson from 2.21.3 to 2.22.0
- #2540: chore(deps): Bump nimbus-jose-jwt from 10.9 to 10.9.1
- #2536: chore(deps): Bump elasticsearch-java from 9.4.0 to 9.4.2
- #2533: chore(deps): Bump shadow plugin from 9.4.1 to 9.4.2
- #2528: chore(deps): Bump parsson from 1.1.7 to 1.1.9
- #2527: chore(deps): Bump docker/setup-buildx-action from 4.0.0 to 4.1.0
- #2526: chore(deps): Bump docker/login-action from 4.1.0 to 4.2.0
- #2522: chore(deps): Bump docker/build-push-action from 7.1.0 to 7.2.0

Excluded (needs separate review):
- #2482: Bump gradle-wrapper from 8.14.3 to 9.5.1 (major Gradle version upgrade)
- #2555: Bump opentelemetry-bom from 1.62.0 to 1.63.0
- #2515: Bump opentelemetry-instrumentation-bom-alpha from 2.28.0-alpha to 2.28.1-alpha

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Chris (He/Him) <cgrote@gmail.com>
@cmgrote cmgrote added the dependencies Pull requests that update a dependency file label Jun 18, 2026
@cmgrote cmgrote enabled auto-merge (squash) June 18, 2026 16:52
… 2.28.1-alpha (#2515)

Co-Authored-By: Claude <noreply@anthropic.com>
Signed-off-by: Chris (He/Him) <cgrote@gmail.com>
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedcom.google.cloud/​libraries-bom@​26.83.0 ⏵ 26.84.000000
Updatedcom.azure/​azure-storage-file-datalake@​12.27.0 ⏵ 12.28.036 -6410090100100
Updatedcom.fasterxml.jackson.module/​jackson-module-kotlin@​2.21.3 ⏵ 2.22.03610090100100
Updatedcom.nimbusds/​nimbus-jose-jwt@​10.9 ⏵ 10.9.13610090100100
Updatedio.openlineage/​openlineage-java@​1.47.1 ⏵ 1.49.03610090100100
Updatedorg.eclipse.jetty/​jetty-http@​12.1.9 ⏵ 12.1.10361009010070
Updatedorg.jetbrains.kotlin/​kotlin-test@​2.3.21 ⏵ 2.4.04810090100100
Updatedsoftware.amazon.awssdk/​sts@​2.44.9 ⏵ 2.46.135010095100100
Updatedcom.azure/​azure-identity@​1.18.3 ⏵ 1.18.456100100100100
Updatedsoftware.amazon.awssdk/​s3@​2.44.9 ⏵ 2.46.1361 -39100100 +11100100
Updatedorg.eclipse.jetty/​jetty-bom@​12.1.9 ⏵ 12.1.101001009010070
Updatedorg.eclipse.parsson/​parsson@​1.1.7 ⏵ 1.1.9100 +51009010070
Updatedio.netty/​netty-codec-http2@​4.2.13.Final ⏵ 4.2.15.Final100 +37100 +490 -1075100
Updatedio.netty/​netty-common@​4.2.13.Final ⏵ 4.2.15.Final100 +4310090 -1075100
Updatedco.elastic.clients/​elasticsearch-java@​9.4.0 ⏵ 9.4.2100 +6410090100100
Updatedcom.azure/​azure-core-http-okhttp@​1.13.4 ⏵ 1.13.59410090100100
Updatedcom.fasterxml.jackson.core/​jackson-databind@​2.21.3 ⏵ 2.22.0100 +6410090100100
Updatedcom.fasterxml.jackson.dataformat/​jackson-dataformat-yaml@​2.21.3 ⏵ 2.22.0100 +710090100100 +20
Updatedio.opentelemetry.instrumentation/​opentelemetry-instrumentation-bom-alpha@​2.28.0-alpha ⏵ 2.28.1-alpha10010090100100
Updatedio.swagger.parser.v3/​swagger-parser@​2.1.42 ⏵ 2.1.4410010090100100
Updatedorg.eclipse.jetty.http2/​jetty-http2-common@​12.1.9 ⏵ 12.1.10100 +6110090100100 +31
Updatedorg.eclipse.jetty.http2/​jetty-http2-hpack@​12.1.9 ⏵ 12.1.10100 +210090100100 +31
Updatedorg.eclipse.jetty.http2/​jetty-http2-server@​12.1.9 ⏵ 12.1.10100 +410090100100 +31
Updatedorg.eclipse.jetty/​jetty-server@​12.1.9 ⏵ 12.1.1010010090100100
Updatedorg.xerial/​sqlite-jdbc@​3.53.1.0 ⏵ 3.53.2.0100 +6410090100100

View full report

@socket-security

Copy link
Copy Markdown

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn High
Obfuscated code: maven io.netty:netty-codec is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ?maven/com.azure/azure-identity@1.18.4maven/io.netty/netty-codec@4.1.135.Final

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/io.netty/netty-codec@4.1.135.Final. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

Warn High
Obfuscated code: maven io.netty:netty-codec is 90.0% likely obfuscated

Confidence: 0.90

Location: Package overview

From: ?maven/com.azure/azure-identity@1.18.4maven/io.netty/netty-codec@4.1.135.Final

ℹ Read more on: This package | This alert | What is obfuscated code?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Packages should not obfuscate their code. Consider not using packages with obfuscated code.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity ignore maven/io.netty/netty-codec@4.1.135.Final. You can also ignore all packages with @SocketSecurity ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

@cmgrote cmgrote merged commit b99e33e into main Jun 18, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant