chore(deps): bump the maven-dependencies group with 8 updates - #2895
Merged
Merged
Conversation
Bumps the maven-dependencies group with 8 updates: | Package | From | To | | --- | --- | --- | | [org.apache:apache](https://github.com/apache/maven-apache-parent) | `39` | `40` | | [org.apache.groovy:groovy-all](https://github.com/apache/groovy) | `5.1.2` | `6.0.0` | | [org.apache.groovy:groovy](https://github.com/apache/groovy) | `5.1.2` | `6.0.0` | | [net.bytebuddy:byte-buddy](https://github.com/raphw/byte-buddy) | `1.18.13` | `1.18.14` | | [net.bytebuddy:byte-buddy-agent](https://github.com/raphw/byte-buddy) | `1.18.13` | `1.18.14` | | [org.hibernate.orm:hibernate-core](https://github.com/hibernate/hibernate-orm) | `7.4.7.Final` | `7.4.9.Final` | | org.apache.felix:maven-bundle-plugin | `6.1.2` | `6.2.0` | | [fish.payara.extras:payara-micro](https://github.com/payara/payara) | `7.2026.8` | `7.2026.9` | Updates `org.apache:apache` from 39 to 40 - [Release notes](https://github.com/apache/maven-apache-parent/releases) - [Commits](https://github.com/apache/maven-apache-parent/commits) Updates `org.apache.groovy:groovy-all` from 5.1.2 to 6.0.0 - [Commits](https://github.com/apache/groovy/commits) Updates `org.apache.groovy:groovy` from 5.1.2 to 6.0.0 - [Commits](https://github.com/apache/groovy/commits) Updates `org.apache.groovy:groovy` from 5.1.2 to 6.0.0 - [Commits](https://github.com/apache/groovy/commits) Updates `net.bytebuddy:byte-buddy` from 1.18.13 to 1.18.14 - [Release notes](https://github.com/raphw/byte-buddy/releases) - [Changelog](https://github.com/raphw/byte-buddy/blob/master/release-notes.md) - [Commits](raphw/byte-buddy@byte-buddy-1.18.13...byte-buddy-1.18.14) Updates `net.bytebuddy:byte-buddy-agent` from 1.18.13 to 1.18.14 - [Release notes](https://github.com/raphw/byte-buddy/releases) - [Changelog](https://github.com/raphw/byte-buddy/blob/master/release-notes.md) - [Commits](raphw/byte-buddy@byte-buddy-1.18.13...byte-buddy-1.18.14) Updates `net.bytebuddy:byte-buddy-agent` from 1.18.13 to 1.18.14 - [Release notes](https://github.com/raphw/byte-buddy/releases) - [Changelog](https://github.com/raphw/byte-buddy/blob/master/release-notes.md) - [Commits](raphw/byte-buddy@byte-buddy-1.18.13...byte-buddy-1.18.14) Updates `org.hibernate.orm:hibernate-core` from 7.4.7.Final to 7.4.9.Final - [Release notes](https://github.com/hibernate/hibernate-orm/releases) - [Changelog](https://github.com/hibernate/hibernate-orm/blob/7.4.9/changelog.txt) - [Commits](hibernate/hibernate-orm@7.4.7...7.4.9) Updates `org.apache.felix:maven-bundle-plugin` from 6.1.2 to 6.2.0 Updates `fish.payara.extras:payara-micro` from 7.2026.8 to 7.2026.9 - [Release notes](https://github.com/payara/payara/releases) - [Commits](payara/Payara@payara-server-7.2026.8...payara-server-7.2026.9) --- updated-dependencies: - dependency-name: org.apache:apache dependency-version: '40' dependency-type: direct:production update-type: version-update:semver-major dependency-group: maven-dependencies - dependency-name: org.apache.groovy:groovy-all dependency-version: 6.0.0 dependency-type: direct:production update-type: version-update:semver-major dependency-group: maven-dependencies - dependency-name: org.apache.groovy:groovy dependency-version: 6.0.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: maven-dependencies - dependency-name: org.apache.groovy:groovy dependency-version: 6.0.0 dependency-type: direct:development update-type: version-update:semver-major dependency-group: maven-dependencies - dependency-name: net.bytebuddy:byte-buddy dependency-version: 1.18.14 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: maven-dependencies - dependency-name: net.bytebuddy:byte-buddy-agent dependency-version: 1.18.14 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: maven-dependencies - dependency-name: net.bytebuddy:byte-buddy-agent dependency-version: 1.18.14 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: maven-dependencies - dependency-name: org.hibernate.orm:hibernate-core dependency-version: 7.4.9.Final dependency-type: direct:production update-type: version-update:semver-patch dependency-group: maven-dependencies - dependency-name: org.apache.felix:maven-bundle-plugin dependency-version: 6.2.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: maven-dependencies - dependency-name: fish.payara.extras:payara-micro dependency-version: 7.2026.9 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: maven-dependencies ... Signed-off-by: dependabot[bot] <support@github.com>
lprimak
approved these changes
Sep 22, 2026
Contributor
|
@fpapon I added some mitigations for breaking changes in Apache parent. Please verify, thank you! |
Member
|
@lprimak the only change that I can see for us is the move of the maven checksum plugin: apache/maven-apache-parent#599 We are overriding it here: Line 1672 in 0b5c1ae So may be just remove it can work. |
Contributor
|
Yes, but I already remove that... or are you talking about something else here? |
…e parent naming convention
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the maven-dependencies group with 8 updates:
39405.1.26.0.05.1.26.0.01.18.131.18.141.18.131.18.147.4.7.Final7.4.9.Final6.1.26.2.07.2026.87.2026.9Updates
org.apache:apachefrom 39 to 40Release notes
Sourced from org.apache:apache's releases.
Commits
Updates
org.apache.groovy:groovy-allfrom 5.1.2 to 6.0.0Commits
Updates
org.apache.groovy:groovyfrom 5.1.2 to 6.0.0Commits
Updates
org.apache.groovy:groovyfrom 5.1.2 to 6.0.0Commits
Updates
net.bytebuddy:byte-buddyfrom 1.18.13 to 1.18.14Release notes
Sourced from net.bytebuddy:byte-buddy's releases.
Changelog
Sourced from net.bytebuddy:byte-buddy's changelog.
Commits
92846cb[publish] Releasing Byte Buddy 1.18.14a8a9f14[release] Release new versionb0fe006Skip the signature creation for artifacts that are not deployed.c610783Resolve the signed POM file by the path of the project file.caab321Sign the deployed POM file and allow for a sigstore dry run.c68a9c1Supply the agent argument to the attacher process as an environment variable.3ac9dedAvoid symbolic link resolution on recursive deletion and validate Android ent...8dbae60Sign deployed files using sigstore.5d83cd4Disable semantic versioning check for protected constructor in abstract class...172e0f4Move to method to apply suppression.Updates
net.bytebuddy:byte-buddy-agentfrom 1.18.13 to 1.18.14Release notes
Sourced from net.bytebuddy:byte-buddy-agent's releases.
Changelog
Sourced from net.bytebuddy:byte-buddy-agent's changelog.
Commits
92846cb[publish] Releasing Byte Buddy 1.18.14a8a9f14[release] Release new versionb0fe006Skip the signature creation for artifacts that are not deployed.c610783Resolve the signed POM file by the path of the project file.caab321Sign the deployed POM file and allow for a sigstore dry run.c68a9c1Supply the agent argument to the attacher process as an environment variable.3ac9dedAvoid symbolic link resolution on recursive deletion and validate Android ent...8dbae60Sign deployed files using sigstore.5d83cd4Disable semantic versioning check for protected constructor in abstract class...172e0f4Move to method to apply suppression.Updates
net.bytebuddy:byte-buddy-agentfrom 1.18.13 to 1.18.14Release notes
Sourced from net.bytebuddy:byte-buddy-agent's releases.
Changelog
Sourced from net.bytebuddy:byte-buddy-agent's changelog.
Commits
92846cb[publish] Releasing Byte Buddy 1.18.14a8a9f14[release] Release new versionb0fe006Skip the signature creation for artifacts that are not deployed.c610783Resolve the signed POM file by the path of the project file.caab321Sign the deployed POM file and allow for a sigstore dry run.c68a9c1Supply the agent argument to the attacher process as an environment variable.3ac9dedAvoid symbolic link resolution on recursive deletion and validate Android ent...8dbae60Sign deployed files using sigstore.5d83cd4Disable semantic versioning check for protected constructor in abstract class...172e0f4Move to method to apply suppression.Updates
org.hibernate.orm:hibernate-corefrom 7.4.7.Final to 7.4.9.FinalRelease notes
Sourced from org.hibernate.orm:hibernate-core's releases.
... (truncated)
Changelog
Sourced from org.hibernate.orm:hibernate-core's changelog.
Commits
208bf6c[Jenkins release job] Preparing release 7.4.9.Final0204513[Jenkins release job] changelog.txt updated by release build 7.4.9.Final8310983HHH-20883 add tenant id to mutation SQL (#13412)a36fbebHHH-20882 Avoid exposing MariaDB JDBC parameters in logsec66308HHH-20882 Redact MariaDB JDBC parameters from logging006022cHHH-20882 Redact credentials from database connection info logging07ee912HHH-19930 Implement cascade support for key-to-onesfd92450HHH-20816 Ensure arguments to JSON functions don't allow SQL injectionec81e89[Jenkins release job] Preparing next development iteration2d3a7b8[Jenkins release job] Preparing release 7.4.8.FinalUpdates
org.apache.felix:maven-bundle-pluginfrom 6.1.2 to 6.2.0Updates
fish.payara.extras:payara-microfrom 7.2026.8 to 7.2026.9Release notes
Sourced from fish.payara.extras:payara-micro's releases.
... (truncated)
Commits
d4f0b8bIncrement version numbers for Release914c60dMerge pull request #8403 from payara/revert-8400-dependabot/maven/main/org.pr...d852a6cRevert "FISH-14513 Bump org.primefaces:primefaces from 15.0.17 to 15.0.18"4969dcaMerge pull request #8400 from payara/dependabot/maven/main/org.primefaces-pri...5569518Merge pull request #8399 from payara/dependabot/maven/main/jline.version-4.4.251e6495Merge pull request #8397 from payara/dependabot/maven/main/org.apache.ant-ant...a72038fMerge pull request #8396 from payara/dependabot/maven/main/ant.version-1.10.189b4a7a3Merge pull request #8401 from raushan606/FISH-14487-p77dbbb5eFISH-14487: merge OTLP exporter service files via shade transformerb68b7b4Bump org.primefaces:primefaces from 15.0.17 to 15.0.18Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions