Skip to content

chore(deps): bump the maven-dependencies group with 8 updates - #2895

Merged
lprimak merged 6 commits into
mainfrom
dependabot/maven/maven-dependencies-68e4406920
Sep 26, 2026
Merged

lprimak merged 6 commits into
mainfrom
dependabot/maven/maven-dependencies-68e4406920

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 22, 2026

Copy link
Copy Markdown
Contributor

Bumps the maven-dependencies group with 8 updates:

Package From To
org.apache:apache 39 40
org.apache.groovy:groovy-all 5.1.2 6.0.0
org.apache.groovy:groovy 5.1.2 6.0.0
net.bytebuddy:byte-buddy 1.18.13 1.18.14
net.bytebuddy:byte-buddy-agent 1.18.13 1.18.14
org.hibernate.orm:hibernate-core 7.4.7.Final 7.4.9.Final
org.apache.felix:maven-bundle-plugin 6.1.2 6.2.0
fish.payara.extras:payara-micro 7.2026.8 7.2026.9

Updates org.apache:apache from 39 to 40

Release notes

Sourced from org.apache:apache's releases.

40

💥 Breaking changes

  • Replace nicoulaj checksum plugin with maveniverse checksum plugin (#599) @​slawekjaranowski
  • #586: Use RAT0.18 and remove commons-lang3 configuration for JDK25 (#587) @​ottlinger
  • Property version.maven-surefire was removed in apache/maven-apache-parent#588, should be replaced by version.maven-surefire-plugin, version.maven-failsafe-plugin or version.maven-surefire-report-plugin

🚀 New features and improvements

📝 Documentation updates

👻 Maintenance

📦 Dependency updates

Commits

Updates org.apache.groovy:groovy-all from 5.1.2 to 6.0.0

Commits

Updates org.apache.groovy:groovy from 5.1.2 to 6.0.0

Commits

Updates org.apache.groovy:groovy from 5.1.2 to 6.0.0

Commits

Updates net.bytebuddy:byte-buddy from 1.18.13 to 1.18.14

Release notes

Sourced from net.bytebuddy:byte-buddy's releases.

Byte Buddy 1.18.14

  • Avoid exposure of the agent argument on the command line of the process that is spawned for an external attachment.
  • Avoid the resolution of symbolic links when the Gradle plugin deletes a folder recursively.
  • Limit the nesting depth that is accepted when parsing a generic type signature to avoid an exhaustion of the stack for a malformed class file.
  • Sign all deployed files using sigstore, in addition to the existing GPG signature.
  • Validate entry names when the Android plugin retains a file to avoid the propagation of path traversals.
Changelog

Sourced from net.bytebuddy:byte-buddy's changelog.

14. September 2026: version 1.18.14

  • Avoid exposure of the agent argument on the command line of the process that is spawned for an external attachment.
  • Avoid the resolution of symbolic links when the Gradle plugin deletes a folder recursively.
  • Limit the nesting depth that is accepted when parsing a generic type signature to avoid an exhaustion of the stack for a malformed class file.
  • Sign all deployed files using sigstore, in addition to the existing GPG signature.
  • Validate entry names when the Android plugin retains a file to avoid the propagation of path traversals.
Commits
  • 92846cb [publish] Releasing Byte Buddy 1.18.14
  • a8a9f14 [release] Release new version
  • b0fe006 Skip the signature creation for artifacts that are not deployed.
  • c610783 Resolve the signed POM file by the path of the project file.
  • caab321 Sign the deployed POM file and allow for a sigstore dry run.
  • c68a9c1 Supply the agent argument to the attacher process as an environment variable.
  • 3ac9ded Avoid symbolic link resolution on recursive deletion and validate Android ent...
  • 8dbae60 Sign deployed files using sigstore.
  • 5d83cd4 Disable semantic versioning check for protected constructor in abstract class...
  • 172e0f4 Move to method to apply suppression.
  • Additional commits viewable in compare view

Updates net.bytebuddy:byte-buddy-agent from 1.18.13 to 1.18.14

Release notes

Sourced from net.bytebuddy:byte-buddy-agent's releases.

Byte Buddy 1.18.14

  • Avoid exposure of the agent argument on the command line of the process that is spawned for an external attachment.
  • Avoid the resolution of symbolic links when the Gradle plugin deletes a folder recursively.
  • Limit the nesting depth that is accepted when parsing a generic type signature to avoid an exhaustion of the stack for a malformed class file.
  • Sign all deployed files using sigstore, in addition to the existing GPG signature.
  • Validate entry names when the Android plugin retains a file to avoid the propagation of path traversals.
Changelog

Sourced from net.bytebuddy:byte-buddy-agent's changelog.

14. September 2026: version 1.18.14

  • Avoid exposure of the agent argument on the command line of the process that is spawned for an external attachment.
  • Avoid the resolution of symbolic links when the Gradle plugin deletes a folder recursively.
  • Limit the nesting depth that is accepted when parsing a generic type signature to avoid an exhaustion of the stack for a malformed class file.
  • Sign all deployed files using sigstore, in addition to the existing GPG signature.
  • Validate entry names when the Android plugin retains a file to avoid the propagation of path traversals.
Commits
  • 92846cb [publish] Releasing Byte Buddy 1.18.14
  • a8a9f14 [release] Release new version
  • b0fe006 Skip the signature creation for artifacts that are not deployed.
  • c610783 Resolve the signed POM file by the path of the project file.
  • caab321 Sign the deployed POM file and allow for a sigstore dry run.
  • c68a9c1 Supply the agent argument to the attacher process as an environment variable.
  • 3ac9ded Avoid symbolic link resolution on recursive deletion and validate Android ent...
  • 8dbae60 Sign deployed files using sigstore.
  • 5d83cd4 Disable semantic versioning check for protected constructor in abstract class...
  • 172e0f4 Move to method to apply suppression.
  • Additional commits viewable in compare view

Updates net.bytebuddy:byte-buddy-agent from 1.18.13 to 1.18.14

Release notes

Sourced from net.bytebuddy:byte-buddy-agent's releases.

Byte Buddy 1.18.14

  • Avoid exposure of the agent argument on the command line of the process that is spawned for an external attachment.
  • Avoid the resolution of symbolic links when the Gradle plugin deletes a folder recursively.
  • Limit the nesting depth that is accepted when parsing a generic type signature to avoid an exhaustion of the stack for a malformed class file.
  • Sign all deployed files using sigstore, in addition to the existing GPG signature.
  • Validate entry names when the Android plugin retains a file to avoid the propagation of path traversals.
Changelog

Sourced from net.bytebuddy:byte-buddy-agent's changelog.

14. September 2026: version 1.18.14

  • Avoid exposure of the agent argument on the command line of the process that is spawned for an external attachment.
  • Avoid the resolution of symbolic links when the Gradle plugin deletes a folder recursively.
  • Limit the nesting depth that is accepted when parsing a generic type signature to avoid an exhaustion of the stack for a malformed class file.
  • Sign all deployed files using sigstore, in addition to the existing GPG signature.
  • Validate entry names when the Android plugin retains a file to avoid the propagation of path traversals.
Commits
  • 92846cb [publish] Releasing Byte Buddy 1.18.14
  • a8a9f14 [release] Release new version
  • b0fe006 Skip the signature creation for artifacts that are not deployed.
  • c610783 Resolve the signed POM file by the path of the project file.
  • caab321 Sign the deployed POM file and allow for a sigstore dry run.
  • c68a9c1 Supply the agent argument to the attacher process as an environment variable.
  • 3ac9ded Avoid symbolic link resolution on recursive deletion and validate Android ent...
  • 8dbae60 Sign deployed files using sigstore.
  • 5d83cd4 Disable semantic versioning check for protected constructor in abstract class...
  • 172e0f4 Move to method to apply suppression.
  • Additional commits viewable in compare view

Updates org.hibernate.orm:hibernate-core from 7.4.7.Final to 7.4.9.Final

Release notes

Sourced from org.hibernate.orm:hibernate-core's releases.

Release 7.4.9

Hibernate ORM 7.4.9.Final released

Today, we published a new release of Hibernate ORM 7.4: 7.4.9.Final.

You can find the full list of 7.4.9.Final changes here.

What's new

  • See the website for requirements and compatibilities.
  • See the What's New guide for details about new features and capabilities.
  • See the Migration Guide for details about migration.

Conclusion

For additional details, see:

See also the following resources related to supported APIs:

Visit the website for details on getting in touch with us.

Release 7.4.8

Hibernate ORM 7.4.8.Final released

Today, we published a new release of Hibernate ORM 7.4: 7.4.8.Final.

You can find the full list of 7.4.8.Final changes here.

What's new

  • See the website for requirements and compatibilities.
  • See the What's New guide for details about new features and capabilities.
  • See the Migration Guide for details about migration.

Conclusion

... (truncated)

Changelog

Sourced from org.hibernate.orm:hibernate-core's changelog.

Changes in 7.4.9.Final (September 17, 2026)

https://hibernate.atlassian.net/projects/HHH/versions/40446

Changes in 7.4.8.Final (September 13, 2026)

https://hibernate.atlassian.net/projects/HHH/versions/40444

** Bug * HHH-20855 SQL Server temporal rounding causing trouble with sub-micro input values * HHH-20849 org.hibernate.query.range.Range#suffix wrongly expects pattern * HHH-20806 Join elimination in 7.x skips @​SQLRestriction when querying by to-one association id * HHH-20805 MySQL schema update fails, if foreignkey related index is unique * HHH-20804 StatefulPersistenceContext.clear() does not release newEntityHolder * HHH-20801 AnyType.guessEntityPersister uses the wrapped proxy instead of the unwrapped implementation in its fallback → UnknownEntityTypeException during flush logging * HHH-20782 @​FilterJoinTable throws NPE when used with explicit HQL join * HHH-20744 UnknownTableReferenceException when querying the non-owning side of a one-to-one-mapping with a pessimistic lock mode * HHH-20675 @​FilterDef(applyToLoadByKey = true) breaks JOIN FETCH of a JOINED-inheritance to-one association: subclass table joins dropped from FROM while their columns remain in SELECT (invalid SQL) * HHH-20632 Regression: UnknownTableReferenceException fetching an @​Any discriminator through treat() (since 7.4.0, HHH-16730) * HHH-20343 HTE (Bulk ID) temporary table ignores PhysicalNamingStrategy when using SequenceGenerator * HHH-19486 SQLGrammarException when joining to subquery with Case expression * HHH-19485 AssertionError when using Subquery with Case in Criteria API * HHH-18911 Usage of ConcreteProxy in lazy loaded ManyToOne reference

** Deprecation * HHH-20862 Deprecate reflection optimizer and related property access APIs

** Task * HHH-20851 Upgrade to ant 1.10.18 * HHH-20848 Drop meaningless "provided" dependency to ant in hibernate-envers

Commits
  • 208bf6c [Jenkins release job] Preparing release 7.4.9.Final
  • 0204513 [Jenkins release job] changelog.txt updated by release build 7.4.9.Final
  • 8310983 HHH-20883 add tenant id to mutation SQL (#13412)
  • a36fbeb HHH-20882 Avoid exposing MariaDB JDBC parameters in logs
  • ec66308 HHH-20882 Redact MariaDB JDBC parameters from logging
  • 006022c HHH-20882 Redact credentials from database connection info logging
  • 07ee912 HHH-19930 Implement cascade support for key-to-ones
  • fd92450 HHH-20816 Ensure arguments to JSON functions don't allow SQL injection
  • ec81e89 [Jenkins release job] Preparing next development iteration
  • 2d3a7b8 [Jenkins release job] Preparing release 7.4.8.Final
  • Additional commits viewable in compare view

Updates org.apache.felix:maven-bundle-plugin from 6.1.2 to 6.2.0

Updates fish.payara.extras:payara-micro from 7.2026.8 to 7.2026.9

Release notes

Sourced from fish.payara.extras:payara-micro's releases.

Azul Payara Community 7.2026.9

Supported APIs and Applications

  • Jakarta EE 11

  • Jakarta EE 11 Applications

  • MicroProfile 7.1

Bug Fixes

  • [FISH-13664] Fix Blank Admin Console Page After Deployment

  • [FISH-14186] Fix Instance on SSH Node Unreachable from DAS

  • [FISH-14203] [Community Contribution - lprimak] Fix Logs Leaking Injection Manager Found in the Current Thread

  • [FISH-14301] Fix Payara 6 Deployment Descriptors Erroneously Removing Deprecated Elements

Security Fixes

Improvements

  • [FISH-13353] Create JSON Formatted HTTP Access Log

  • [FISH-13494] Add payara- Deployment Descriptors for Payara 5

  • [FISH-13880] Reintroduce Ability to Define Managed Executors in Payara Deployment Descriptors

  • [FISH-14240] Add Jakarta Agentic AI to Payara Micro and Embedded

Component Upgrades

  • [FISH-13986] Upgrade io.opentelemetry.semconv:opentelemetry-semconv from 1.42.0 to 1.43.0

  • [FISH-14039] Upgrade Mojarra from 4.1.7 to 4.1.14

  • [FISH-14096] Upgrade Docker JDK to 25.0.4.1

  • [FISH-14097] Upgrade Docker JDK to 21.0.12.1

  • [FISH-14117] Remove Unnecessary opentelemetry.instrumentation:opentelemetry-instrumentation-bom

  • [FISH-14150] Upgrade Hazelcast to 5.7.0

  • [FISH-14244] Upgrade opentelemetry.version from 1.64.0 to 1.65.0

... (truncated)

Commits
  • d4f0b8b Increment version numbers for Release
  • 914c60d Merge pull request #8403 from payara/revert-8400-dependabot/maven/main/org.pr...
  • d852a6c Revert "FISH-14513 Bump org.primefaces:primefaces from 15.0.17 to 15.0.18"
  • 4969dca Merge pull request #8400 from payara/dependabot/maven/main/org.primefaces-pri...
  • 5569518 Merge pull request #8399 from payara/dependabot/maven/main/jline.version-4.4.2
  • 51e6495 Merge pull request #8397 from payara/dependabot/maven/main/org.apache.ant-ant...
  • a72038f Merge pull request #8396 from payara/dependabot/maven/main/ant.version-1.10.18
  • 9b4a7a3 Merge pull request #8401 from raushan606/FISH-14487-p7
  • 7dbbb5e FISH-14487: merge OTLP exporter service files via shade transformer
  • b68b7b4 Bump org.primefaces:primefaces from 15.0.17 to 15.0.18
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the maven-dependencies group with 8 updates:

| Package | From | To |
| --- | --- | --- |
| [org.apache:apache](https://github.com/apache/maven-apache-parent) | `39` | `40` |
| [org.apache.groovy:groovy-all](https://github.com/apache/groovy) | `5.1.2` | `6.0.0` |
| [org.apache.groovy:groovy](https://github.com/apache/groovy) | `5.1.2` | `6.0.0` |
| [net.bytebuddy:byte-buddy](https://github.com/raphw/byte-buddy) | `1.18.13` | `1.18.14` |
| [net.bytebuddy:byte-buddy-agent](https://github.com/raphw/byte-buddy) | `1.18.13` | `1.18.14` |
| [org.hibernate.orm:hibernate-core](https://github.com/hibernate/hibernate-orm) | `7.4.7.Final` | `7.4.9.Final` |
| org.apache.felix:maven-bundle-plugin | `6.1.2` | `6.2.0` |
| [fish.payara.extras:payara-micro](https://github.com/payara/payara) | `7.2026.8` | `7.2026.9` |


Updates `org.apache:apache` from 39 to 40
- [Release notes](https://github.com/apache/maven-apache-parent/releases)
- [Commits](https://github.com/apache/maven-apache-parent/commits)

Updates `org.apache.groovy:groovy-all` from 5.1.2 to 6.0.0
- [Commits](https://github.com/apache/groovy/commits)

Updates `org.apache.groovy:groovy` from 5.1.2 to 6.0.0
- [Commits](https://github.com/apache/groovy/commits)

Updates `org.apache.groovy:groovy` from 5.1.2 to 6.0.0
- [Commits](https://github.com/apache/groovy/commits)

Updates `net.bytebuddy:byte-buddy` from 1.18.13 to 1.18.14
- [Release notes](https://github.com/raphw/byte-buddy/releases)
- [Changelog](https://github.com/raphw/byte-buddy/blob/master/release-notes.md)
- [Commits](raphw/byte-buddy@byte-buddy-1.18.13...byte-buddy-1.18.14)

Updates `net.bytebuddy:byte-buddy-agent` from 1.18.13 to 1.18.14
- [Release notes](https://github.com/raphw/byte-buddy/releases)
- [Changelog](https://github.com/raphw/byte-buddy/blob/master/release-notes.md)
- [Commits](raphw/byte-buddy@byte-buddy-1.18.13...byte-buddy-1.18.14)

Updates `net.bytebuddy:byte-buddy-agent` from 1.18.13 to 1.18.14
- [Release notes](https://github.com/raphw/byte-buddy/releases)
- [Changelog](https://github.com/raphw/byte-buddy/blob/master/release-notes.md)
- [Commits](raphw/byte-buddy@byte-buddy-1.18.13...byte-buddy-1.18.14)

Updates `org.hibernate.orm:hibernate-core` from 7.4.7.Final to 7.4.9.Final
- [Release notes](https://github.com/hibernate/hibernate-orm/releases)
- [Changelog](https://github.com/hibernate/hibernate-orm/blob/7.4.9/changelog.txt)
- [Commits](hibernate/hibernate-orm@7.4.7...7.4.9)

Updates `org.apache.felix:maven-bundle-plugin` from 6.1.2 to 6.2.0

Updates `fish.payara.extras:payara-micro` from 7.2026.8 to 7.2026.9
- [Release notes](https://github.com/payara/payara/releases)
- [Commits](payara/Payara@payara-server-7.2026.8...payara-server-7.2026.9)

---
updated-dependencies:
- dependency-name: org.apache:apache
  dependency-version: '40'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: maven-dependencies
- dependency-name: org.apache.groovy:groovy-all
  dependency-version: 6.0.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: maven-dependencies
- dependency-name: org.apache.groovy:groovy
  dependency-version: 6.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: maven-dependencies
- dependency-name: org.apache.groovy:groovy
  dependency-version: 6.0.0
  dependency-type: direct:development
  update-type: version-update:semver-major
  dependency-group: maven-dependencies
- dependency-name: net.bytebuddy:byte-buddy
  dependency-version: 1.18.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: net.bytebuddy:byte-buddy-agent
  dependency-version: 1.18.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: net.bytebuddy:byte-buddy-agent
  dependency-version: 1.18.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.hibernate.orm:hibernate-core
  dependency-version: 7.4.9.Final
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.felix:maven-bundle-plugin
  dependency-version: 6.2.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: fish.payara.extras:payara-micro
  dependency-version: 7.2026.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Sep 22, 2026
@github-actions github-actions Bot added xml and removed java Pull requests that update Java code labels Sep 22, 2026
@lprimak
lprimak requested a review from fpapon September 22, 2026 21:51
@lprimak

lprimak commented Sep 22, 2026

Copy link
Copy Markdown
Contributor

@fpapon I added some mitigations for breaking changes in Apache parent. Please verify, thank you!

@fpapon

fpapon commented Sep 23, 2026

Copy link
Copy Markdown
Member

@lprimak the only change that I can see for us is the move of the maven checksum plugin:

apache/maven-apache-parent#599

We are overriding it here:

shiro/pom.xml

Line 1672 in 0b5c1ae

<groupId>net.nicoulaj.maven.plugins</groupId>

So may be just remove it can work.

@lprimak

lprimak commented Sep 23, 2026

Copy link
Copy Markdown
Contributor

Yes, but I already remove that... or are you talking about something else here?

@lprimak
lprimak merged commit 9a7bf22 into main Sep 26, 2026
20 checks passed
@lprimak
lprimak deleted the dependabot/maven/maven-dependencies-68e4406920 branch September 26, 2026 18:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file groovy xml

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants