Skip to content

Bump the minor-java-dependencies group across 1 directory with 11 updates - #1155

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/minor-java-dependencies-d31d8aa3d9
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/minor-java-dependencies-d31d8aa3d9

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-java-dependencies group with 11 updates in the / directory:

Package From To
io.netty:netty-bom 4.1.136.Final 4.1.138.Final
io.netty:netty-tcnative-boringssl-static 2.0.81.Final 2.0.84.Final
org.slf4j:slf4j-bom 2.0.18 2.0.20
org.apache.maven.plugins:maven-compiler-plugin 3.15.0 3.16.0
org.apache.maven.plugins:maven-deploy-plugin 3.1.4 3.2.0
org.apache.maven.plugins:maven-surefire-plugin 3.5.6 3.6.0
org.apache.commons:commons-lang3 3.20.0 3.21.0
io.dropwizard.metrics:metrics-core 4.2.39 4.2.40
io.micrometer:micrometer-core 1.17.0 1.17.1
org.apache.maven:apache-maven 3.9.6 3.9.16
org.apache.maven.wrapper:maven-wrapper 3.2.0 3.3.4

Updates io.netty:netty-bom from 4.1.136.Final to 4.1.138.Final

Release notes

Sourced from io.netty:netty-bom's releases.

netty-4.1.138.Final

Security fixes

  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-http (SPDY)
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-http (HTTP/1.1)
  • CVE-2026-XXXXX : denial of service vector in io.netty:netty-codec-http2
  • CVE-2026-XXXXX : improper certificate validation in io.netty:netty-handler-ssl-ocsp
  • CVE-2026-XXXXX : memory leak in io.netty:netty-codec-stomp
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-http
  • CVE-2026-XXXXX : denial of service vector in io.netty:netty-codec-stomp
  • CVE-2026-XXXXX : parser desync/response smuggling in io.netty:netty-codec-memcache
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-smtp
  • CVE-2026-XXXXX : memory leak in io.netty:netty-codec-haproxy
  • CVE-2026-XXXXX : request smuggling in io.netty:netty-codec-http (RTSP)
  • CVE-2026-XXXXX : request smuggling in io.netty:netty-codec-http (HTTP/1)
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http2
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http2
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http2
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-redis
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http (HTTP/1.1)
  • CVE-2026-XXXXX : request smuggling vector in io.netty:netty-codec-http (HTTP/1.1)
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-mqtt
  • CVE-2026-XXXXX : improper CRLF neutralization in io.netty:netty-codec-smtp
  • CVE-2026-XXXXX : improper certificate validation in io.netty:netty-handler-ssl-ocsp
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http2

Compatibility note

HTTP/2 header value validation is now enabled by default. HTTP/2 header name validation has always been enabled by default, with an option to disable it, but HTTP/2 header value validation has been disabled by default until now. Configuration options still exist to disable this, but validation of HTTP header names and values are now both opt-in by default rather than opt-out.

What's Changed

... (truncated)

Commits
  • 26e68a2 [maven-release-plugin] prepare release netty-4.1.138.Final
  • 9099e6b OCSP: Correctly handle that nextUpdate is optional
  • 46f4ab0 Verify id-kp-OCSPSigning EKU on delegated OCSP responder certificates
  • ab3f6df SPDY: SpdySessionHandler must limit the concurrent streams
  • 36ee644 HTTP: Limit the maximum number of concurrent pipelined requests
  • d9cf57d HTTP/2: Limit HPACK encoding table size
  • cb84b06 STOMP: Correctly release partial content on handler removal
  • 3574f7e WebSockets: Enforce a limit for the max pipelined requests in WebSocketServer...
  • 9551ac4 STOMP codec content-length long-to-int truncation causes infinite decode loop...
  • d5bc028 Fix frame desynchronization in the binary memcache decoder
  • Additional commits viewable in compare view

Updates io.netty:netty-tcnative-boringssl-static from 2.0.81.Final to 2.0.84.Final

Release notes

Sourced from io.netty:netty-tcnative-boringssl-static's releases.

bootstrap-gcc-precompile

Pre-compiled gcc to use on centos 6.

Commits
  • 68007b7 [maven-release-plugin] prepare release netty-tcnative-parent-2.0.84.Final
  • 2228a81 Fix download of go
  • e31df4a Custom BIO_java_bytebuffer write callback over-reports bytes written, violati...
  • 865531f Clearify when it's safe to set protos in SSLContext javadocs
  • a879c85 Decoding of the SNI server_name allow to embed NUL Character
  • 92dd66f Correctly handle wrap around in ring buffer used internally to buffer applica...
  • e28f849 Clearify when it's safe to set callbacks in SSLContext javadocs
  • 9c01de6 *SSLPrivateKeyMethod does not correctly report back signing errors
  • 59662a8 Fix use after free bug that could cause crash when session keys are rotated
  • 3f1724d Check if hostname matcher is NULL and if so return early (#1004)
  • Additional commits viewable in compare view

Updates org.slf4j:slf4j-bom from 2.0.18 to 2.0.20

Release notes

Sourced from org.slf4j:slf4j-bom's releases.

SLF4J 2.0.20

2026-09-22 - Release of SLF4J 2.0.20

• Marker instances are slated to become immutable in future releases. As such, methods in the Marker interface adding/removing children are now marked as deprecated.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit 58d80a4fe8f2e811707fcfba4d292b5d62fc2fe9 associated with the tag v_2.0.20. Release built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Full Changelog: qos-ch/slf4j@v_2.0.19...v_2.0.20

SLF4J 2.0.19

2026-09-04 - Release of SLF4J 2.0.19

  • When the fluent API was used with XLogger/LoggerWrapper in the slf4j-ext module, caller location was incorrectly reported. To correct this, LoggerWrapper now delegates makeLoggingEventBuilder() to the wrapped logger so that the application caller can be correctly extracted. This issue was reported in issues/464.

  • In slf4j-api/DefaultLoggingEventBuilder, a failing toString() invocation on a key-value value, including StackOverflowError, no longer aborts logging. The builder now substitutes [FAILED toString()], matching the existing behaviour of MessageFormatter for message arguments. This issue was reported in issues/448.

  • The isLoggable() method in SLF4JPlatformLogger now maps System.Logger.Level.ALL and Level.OFF the same way as log(), that is ALL as TRACE and OFF as ERROR, instead of treating both as always loggable. This is a follow-up to the changes introduced in 2.0.17. See issues/430.

  • Published JAR files now package each module's own LICENSE.txt under META-INF/. Previously the parent POM copied the repository-root MIT license into every module, so Apache-2.0 modules such as jcl-over-slf4j and log4j-over-slf4j shipped the wrong license text. This issue was reported in issues/465.

  • A bit-wise identical binary of this version can be reproduced by building from source code at commit f0fc3e52a16d5053039495f4f3b64d191508204f associated with the tag v_2.0.19. Release built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Commits
  • 58d80a4 prepare release 2.0.20
  • ef47ab9 deprecate methods for adding/remocing children to markers
  • 6b6c63e fix failing test on Windows
  • 233d4d1 renamed LoggerTestSuite.java as SimpleLoggerAcceptanceTest
  • bf3a7b9 start work on 2.0.20-SNAPSHOT
  • f0fc3e5 prepare release 2.0.19
  • 2288d0c fix issues/464. slf4j-ext/XLogger incorrect caller extraction when the fluent...
  • 6ff7f77 test: pin fluent API caller method name
  • 2b3f94b SLF4JPlatformLogger.isLoggable should handle Logger.ALL and Logger.OFF in a c...
  • 9221f77 fix(api): guard addKeyValue value toString from fatal errors
  • Additional commits viewable in compare view

Updates org.apache.maven.plugins:maven-compiler-plugin from 3.15.0 to 3.16.0

Release notes

Sourced from org.apache.maven.plugins:maven-compiler-plugin's releases.

3.16.0

🚀 New features and improvements

🐛 Bug Fixes

📝 Documentation updates

👻 Maintenance

📦 Dependency updates

Commits
  • e7bba6e [maven-release-plugin] prepare release maven-compiler-plugin-3.16.0
  • c906809 Avoid using deprecated method CompilerConfiguration.setCompilerVersion
  • ad74fee Replace adopt-openj9 by semeru JDK distribution on GH
  • beb0eda Recompile when dependencies change (#1102)
  • a0b689e [MCOMPILER-578] Track outputs across compiler executions (#1091)
  • 2e81228 Fix incremental detection of empty sources, 3.x (#1075)
  • 2132f5b configure ATR project
  • 5992b77 Build fails when annotation processor list is empty (but present) (#1077)
  • acccef7 Bump plexusCompilerVersion from 2.16.2 to 2.17.0
  • 72bc445 Bump org.codehaus.plexus:plexus-java from 1.5.2 to 1.6.0
  • Additional commits viewable in compare view

Updates org.apache.maven.plugins:maven-deploy-plugin from 3.1.4 to 3.2.0

Release notes

Sourced from org.apache.maven.plugins:maven-deploy-plugin's releases.

3.2.0

🚀 New features and improvements

🐛 Bug Fixes

  • Backport security audit fixes to 3.x (f004-f008, f010, f012) (#701) @​gnodet

📝 Documentation updates

👻 Maintenance

🔧 Build

📦 Dependency updates

... (truncated)

Commits
  • 7aab9fb [maven-release-plugin] prepare release maven-deploy-plugin-3.2.0
  • 1f3eef5 Backport security audit fixes to 3.x (f004-f008, f010, f012)
  • 307f328 Simplify remote repository creation
  • 7b1bbc4 Cache projectsWithDeployExecution to fix O(N²) reactor scan
  • a9177c6 Clarify deploy without editing this projects POM
  • 7c40513 Restore the plain form of the ASF licence header
  • 5969234 Update Release Drafter configuration to use custom tag template and remove un...
  • df7b3fa Bump apache/maven-gh-actions-shared/.github/workflows/release-drafter.yml
  • b4e8aed work around Maven 4 CLI lack of interpolation
  • d634bb4 enable build with Maven 4
  • Additional commits viewable in compare view

Updates org.apache.maven.plugins:maven-surefire-plugin from 3.5.6 to 3.6.0

Release notes

Sourced from org.apache.maven.plugins:maven-surefire-plugin's releases.

3.6.0

Please refer to the main page for what's new https://maven.apache.org/surefire/ And the migration page https://maven.apache.org/surefire/maven-surefire-plugin/whats-new-3-6-0.html

🚀 New features and improvements

🐛 Bug Fixes

📝 Documentation updates

👻 Maintenance

... (truncated)

Commits
  • 0ff622b [maven-release-plugin] prepare release surefire-3.6.0
  • bb3932a Let's go for 3.6.0 release
  • 3002a16 Bump mavenVersion from 3.9.14 to 3.9.16
  • 61a531d Bump Maven parent version from 47 to 49 (#3449)
  • e52ead4 [SUREFIRE-523] Link all reported tests to source XRef (#3445)
  • 45102fa [SUREFIRE-3446] Fix direct selection of JUnit Jupiter @​Nested classes (#3447)
  • b2e1f70 Fix #3303: distinguish JUnit 6 ParameterizedClass invocations (#3432)
  • c051938 Discover tests in a fork when a toolchain JDK is used (#3444)
  • db75df8 Bump org.codehaus.plexus:plexus-java from 1.5.2 to 1.6.0 (#3441)
  • 77f2759 Bump org.codehaus.plexus:plexus-interpolation from 1.29 to 1.30.0
  • Additional commits viewable in compare view

Updates org.apache.commons:commons-lang3 from 3.20.0 to 3.21.0

Updates io.dropwizard.metrics:metrics-core from 4.2.39 to 4.2.40

Release notes

Sourced from io.dropwizard.metrics:metrics-core's releases.

v4.2.40

What's Changed

Full Changelog: dropwizard/metrics@v4.2.39...v4.2.40

Commits
  • deca21f [maven-release-plugin] prepare release v4.2.40
  • adc06fc feat: add module for logback 1.6.x (#5370)
  • 7a8bae2 fix(deps): update jackson3 monorepo (release/4.2.x) (minor) (#5288)
  • c04e360 build: compile in-process rather than by forking javac (#5369)
  • 16f0efc fix(deps): update dependency com.rabbitmq:amqp-client to v5.35.0 (#5367)
  • 2f4a844 fix(deps): update dependency net.bytebuddy:byte-buddy to v1.18.12-jdk5 (#5361)
  • 9789a72 fix(deps): update jackson monorepo to v3.1.6 (#5362)
  • d8603c7 fix(deps): update dependency org.apache.httpcomponents.client5:ht...

    Description has been truncated

…ates

Bumps the minor-java-dependencies group with 11 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [io.netty:netty-bom](https://github.com/netty/netty) | `4.1.136.Final` | `4.1.138.Final` |
| [io.netty:netty-tcnative-boringssl-static](https://github.com/netty/netty-tcnative) | `2.0.81.Final` | `2.0.84.Final` |
| [org.slf4j:slf4j-bom](https://github.com/qos-ch/slf4j) | `2.0.18` | `2.0.20` |
| [org.apache.maven.plugins:maven-compiler-plugin](https://github.com/apache/maven-compiler-plugin) | `3.15.0` | `3.16.0` |
| [org.apache.maven.plugins:maven-deploy-plugin](https://github.com/apache/maven-deploy-plugin) | `3.1.4` | `3.2.0` |
| [org.apache.maven.plugins:maven-surefire-plugin](https://github.com/apache/maven-surefire) | `3.5.6` | `3.6.0` |
| org.apache.commons:commons-lang3 | `3.20.0` | `3.21.0` |
| [io.dropwizard.metrics:metrics-core](https://github.com/dropwizard/metrics) | `4.2.39` | `4.2.40` |
| [io.micrometer:micrometer-core](https://github.com/micrometer-metrics/micrometer-commercial) | `1.17.0` | `1.17.1` |
| org.apache.maven:apache-maven | `3.9.6` | `3.9.16` |
| [org.apache.maven.wrapper:maven-wrapper](https://github.com/apache/maven-wrapper) | `3.2.0` | `3.3.4` |



Updates `io.netty:netty-bom` from 4.1.136.Final to 4.1.138.Final
- [Release notes](https://github.com/netty/netty/releases)
- [Commits](netty/netty@netty-4.1.136.Final...netty-4.1.138.Final)

Updates `io.netty:netty-tcnative-boringssl-static` from 2.0.81.Final to 2.0.84.Final
- [Release notes](https://github.com/netty/netty-tcnative/releases)
- [Commits](netty/netty-tcnative@netty-tcnative-parent-2.0.81.Final...netty-tcnative-parent-2.0.84.Final)

Updates `org.slf4j:slf4j-bom` from 2.0.18 to 2.0.20
- [Release notes](https://github.com/qos-ch/slf4j/releases)
- [Commits](qos-ch/slf4j@v_2.0.18...v_2.0.20)

Updates `org.apache.maven.plugins:maven-compiler-plugin` from 3.15.0 to 3.16.0
- [Release notes](https://github.com/apache/maven-compiler-plugin/releases)
- [Commits](apache/maven-compiler-plugin@maven-compiler-plugin-3.15.0...maven-compiler-plugin-3.16.0)

Updates `org.apache.maven.plugins:maven-deploy-plugin` from 3.1.4 to 3.2.0
- [Release notes](https://github.com/apache/maven-deploy-plugin/releases)
- [Commits](apache/maven-deploy-plugin@maven-deploy-plugin-3.1.4...maven-deploy-plugin-3.2.0)

Updates `org.apache.maven.plugins:maven-surefire-plugin` from 3.5.6 to 3.6.0
- [Release notes](https://github.com/apache/maven-surefire/releases)
- [Commits](apache/maven-surefire@surefire-3.5.6...surefire-3.6.0)

Updates `org.apache.commons:commons-lang3` from 3.20.0 to 3.21.0

Updates `io.dropwizard.metrics:metrics-core` from 4.2.39 to 4.2.40
- [Release notes](https://github.com/dropwizard/metrics/releases)
- [Commits](dropwizard/metrics@v4.2.39...v4.2.40)

Updates `io.micrometer:micrometer-core` from 1.17.0 to 1.17.1
- [Commits](https://github.com/micrometer-metrics/micrometer-commercial/commits)

Updates `org.apache.maven:apache-maven` from 3.9.6 to 3.9.16

Updates `org.apache.maven.wrapper:maven-wrapper` from 3.2.0 to 3.3.4
- [Release notes](https://github.com/apache/maven-wrapper/releases)
- [Commits](apache/maven-wrapper@maven-wrapper-3.2.0...maven-wrapper-3.3.4)

---
updated-dependencies:
- dependency-name: io.netty:netty-bom
  dependency-version: 4.1.138.Final
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-java-dependencies
- dependency-name: io.netty:netty-tcnative-boringssl-static
  dependency-version: 2.0.84.Final
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: minor-java-dependencies
- dependency-name: org.slf4j:slf4j-bom
  dependency-version: 2.0.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-java-dependencies
- dependency-name: org.apache.maven.plugins:maven-compiler-plugin
  dependency-version: 3.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-java-dependencies
- dependency-name: org.apache.maven.plugins:maven-deploy-plugin
  dependency-version: 3.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-java-dependencies
- dependency-name: org.apache.maven.plugins:maven-surefire-plugin
  dependency-version: 3.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-java-dependencies
- dependency-name: org.apache.commons:commons-lang3
  dependency-version: 3.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-java-dependencies
- dependency-name: io.dropwizard.metrics:metrics-core
  dependency-version: 4.2.40
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-java-dependencies
- dependency-name: io.micrometer:micrometer-core
  dependency-version: 1.17.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-java-dependencies
- dependency-name: org.apache.maven:apache-maven
  dependency-version: 3.9.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-java-dependencies
- dependency-name: org.apache.maven.wrapper:maven-wrapper
  dependency-version: 3.3.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-java-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants