Skip to content

chore(deps): bump the other-dependencies group with 6 updates - #1274

Merged
jjjasper merged 2 commits into
mainfrom
dependabot/maven/other-dependencies-8a99970f37
Aug 21, 2026
Merged

chore(deps): bump the other-dependencies group with 6 updates#1274
jjjasper merged 2 commits into
mainfrom
dependabot/maven/other-dependencies-8a99970f37

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 21, 2026

Copy link
Copy Markdown
Contributor

Bumps the other-dependencies group with 6 updates:

Package From To
com.fasterxml.jackson:jackson-bom 2.22.1 2.22.2
ch.qos.logback:logback-classic 1.6.1 1.6.3
io.swagger.core.v3:swagger-models 2.2.53 2.2.54
io.swagger.core.v3:swagger-core 2.2.53 2.2.54
com.squareup.okhttp3:mockwebserver 5.4.0 5.5.0
com.squareup.okhttp3:okhttp 5.4.0 5.5.0

Updates com.fasterxml.jackson:jackson-bom from 2.22.1 to 2.22.2

Commits
  • 062d76d [maven-release-plugin] prepare release jackson-bom-2.22.2
  • dcf18f7 Prep for 2.22.2 release
  • 9688c7b Merge branch '2.21' into 2.22
  • 7796a7d Merge branch '2.20' into 2.21
  • d3cd7fc Merge branch '2.19' into 2.20
  • 7a28068 Merge branch '2.18' into 2.19
  • 51eb465 Post-release dep version bump
  • 34ff5e8 [maven-release-plugin] prepare for next development iteration
  • 0b44a45 [maven-release-plugin] prepare release jackson-bom-2.18.10
  • 691ec93 Prep for 2.18.10 release
  • Additional commits viewable in compare view

Updates ch.qos.logback:logback-classic from 1.6.1 to 1.6.3

Release notes

Sourced from ch.qos.logback:logback-classic's releases.

Logback 1.6.3

2026-08-14 Release of logback version 1.6.3

  • In response CVE-2026-19880, MDCBasedDiscriminator (used by SiftingAppender) now strips forward and backward slashes (/, \) from MDC values before they are used as discriminating keys. This prevents path segments from escaping into destinations controlled by an attacker. When sanitisation actually changes a value, a warning is emitted; the warning is rate-limited (a small batch, then a lull of about ten minutes).

  • Colour console support is split out into a dedicated JansiConsoleAppender. It wraps stdout or stderr with Jansi so ANSI escape sequences (for example coloured patterns) render correctly on terminals that need it, notably Windows. Prefer this class over the older path described next. See the appenders documentation.

  • The withJansi property on ConsoleAppender is deprecated. Existing configurations that still set <withJansi>true</withJansi> continue to work for compatibility, but new setups should use JansiConsoleAppender instead.

  • ConsoleAppender no longer treats the process console as an exclusive resource: stopping it does not close System.out / System.err. JansiConsoleAppender pairs each AnsiConsole.systemInstall() with systemUninstall() on stop, so repeated start/stop cycles do not leave Jansi installed or tear down streams shared with the rest of the JVM. Related behavior is covered by tests for issues/1063.

  • Invocation throttling helpers were reworked: SimpleInvocationGate is renamed FixedIntervalInvocationGate, and BatchedFixedIntervalInvocationGate allows a short burst of invocations before applying a fixed lull. The sanitisation warning above uses the batched gate.

  • The JPMS module-info for logback-core now exports the ch.qos.logback.core.property package, which had been missing from the module descriptor.

  • A bit-wise identical binary of this version can be reproduced by building from source code at commit e8e824dede022a6d7208b36cfa875b0d1b7772f3 associated with the tag v_1.6.3. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

-- Sponsoring SLF4J/logback/reload4j at https://github.com/sponsors/qos-ch

Logback 1.6.2

clean.full.1.6.2.mp4

2026-08-10 Release of logback version 1.6.2

  • Configuration analysis now detects contradictory caller-data inclusion instructions. For example, an AsyncAppender, SocketAppender or SMTPAppender with includeCallerData left at the default false is incompatible with a layout or encoder pattern that uses a caller-data converter such as %C, %M, %L, %F, %l or %caller. At runtime those converters would print question marks and still incur extraction cost on a worker thread. Logback now emits a configuration-time warning when such instructions disagree. See codes.html#callerContradiction for details. This issue was reported in issues/1059 by leeychee. The initial analysis was contributed by seonwoo_jung.

  • Caller-contradiction analysis can be turned off by setting the logback.skipCallerContradictionAnalysis variable to true, either as a system property (-Dlogback.skipCallerContradictionAnalysis=true) or as a property in the configuration file:

    <property name="logback.skipCallerContradictionAnalysis" value="true"/>
  • SimpleSocketServer and SimpleSSLSocketServer now require an explicit client IP whitelist. On the command line, pass one or more allowed addresses (single IPs or CIDR ranges) after the configuration file. An empty whitelist means no clients are accepted. When embedding the server programmatically, register allowed addresses with addAllowedClientAddress(String) or setAllowedClientAddresses(Collection) before clients connect. See the documentation on restricting client access.

  • Added ThrowableProxyVOBuilder for assembling a ThrowableProxyVO field by field, with a corresponding ThrowableProxyVO.builder() entry point.

  • Dependency analysis handlers now run their postHandle method after child models have been processed, so checks that depend on nested appenders (such as caller-contradiction analysis) see a complete picture.

  • Updated several dependencies, including Angus Mail to 2.0.4 and Jetty (test) to 12.1.12.

  • A bit-wise identical binary of this version can be reproduced by building from source code at commit e3d78330ad1ba024fd987fd00c3ffb9cfcdb07dc associated with the tag v_1.6.2. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Commits
  • e8e824d prepare release 1.6.3
  • 761821b MDCBasedDiscriminator has a gated warning mechanism
  • 53ed122 update copyright year
  • c7e2db2 rename SimpleInvocationGate as FixedIntervalInvocationGate
  • b5aa931 added BatchedSimpleInvocationGate
  • 1f22af7 add javadocs to SimpleInvocationGate
  • 638ffa7 prevent forward and backward slashes to escape to other directories
  • 7d6b9a4 add missing ch.qos.logback.core.property package
  • fa25930 add an extension path in ConsoleAppender for JansiConsoleAppender
  • c73b43f deprecate the withJansi path
  • Additional commits viewable in compare view

Updates io.swagger.core.v3:swagger-models from 2.2.53 to 2.2.54

Updates io.swagger.core.v3:swagger-core from 2.2.53 to 2.2.54

Release notes

Sourced from io.swagger.core.v3:swagger-core's releases.

Swagger-core 2.2.54 released!

  • chore(deps): bump jersey2-version from 2.46 to 2.48 (#5273)
  • chore(deps): bump io.github.classgraph:classgraph from 4.8.184 to 4.8.192 (#5272)
  • chore(deps-dev): bump logback-version from 1.5.37 to 1.6.3 (#5271)
  • chore(deps): update plexus-component-metadata to version 2.2.0 (#5269)
  • docs: add CHANGELOG.md and update README for versioning information (#5267)
  • refactor: streamline tag filtering logic in SpecFilter (#5256)
  • chore(deps): bump org.testng:testng from 7.10.2 to 7.12.0 (#5244)
  • chore(deps): bump org.apache.maven.plugins:maven-dependency-plugin from 3.6.1 to 3.11.0 (#5242)
  • chore(deps): bump org.apache.maven.plugins:maven-jar-plugin from 3.3.0 to 3.5.1 (#5241)
  • fix(model-resolver): retain identical recursive properties (#5232)
  • feat: support Java 8 date/time formats per OpenAPI Formats Registry (#5172) (#5184)
Changelog

Sourced from io.swagger.core.v3:swagger-core's changelog.

[2.2.54] - 2026-08-18

Fixed

  • Java 8 date/time types (OffsetTime, Duration, LocalTime) now map by default to the correct OpenAPI Formats Registry strings ("time", "duration", "time-local") instead of an unusable expanded object. (#5172)
  • LocalDateTime deserialization from an existing OpenAPI spec now correctly round-trips through the new TimeSchema/DurationSchema/DateTimeLocalSchema/ TimeLocalSchema classes instead of falling back to a generic StringSchema.

Added

  • PrimitiveType.enableJava8Formats() — opt-in to map LocalDateTime to the registry-compliant "date-time-local" format (default remains "date-time" for backward compatibility).

Deprecated

  • PrimitiveType.enablePartialTime() — prefer the new default "time-local" mapping for LocalTime; kept for callers who specifically need the non-registry "partial-time" format.
Commits
  • 9bcf891 prepare release 2.2.54 (#5279)
  • 06b8031 chore(deps): bump jersey2-version from 2.46 to 2.48 (#5273)
  • f3f0a8a chore(deps): bump io.github.classgraph:classgraph (#5272)
  • 85c281f chore(deps-dev): bump logback-version from 1.5.37 to 1.6.3 (#5271)
  • 9aaee38 fix: check allowableValues for enum (#4712)
  • 73afd82 chore(deps): update plexus-component-metadata to version 2.2.0 (#5269)
  • d4c5980 chore(deps): bump org.testng:testng from 7.10.2 to 7.12.0 (#5244)
  • af39326 chore(deps): bump org.apache.maven.plugins:maven-dependency-plugin (#5242)
  • b153770 chore(deps): bump org.apache.maven.plugins:maven-jar-plugin (#5241)
  • c56ca3b refactor: streamline tag filtering logic in SpecFilter (#5256)
  • Additional commits viewable in compare view

Updates io.swagger.core.v3:swagger-core from 2.2.53 to 2.2.54

Release notes

Sourced from io.swagger.core.v3:swagger-core's releases.

Swagger-core 2.2.54 released!

  • chore(deps): bump jersey2-version from 2.46 to 2.48 (#5273)
  • chore(deps): bump io.github.classgraph:classgraph from 4.8.184 to 4.8.192 (#5272)
  • chore(deps-dev): bump logback-version from 1.5.37 to 1.6.3 (#5271)
  • chore(deps): update plexus-component-metadata to version 2.2.0 (#5269)
  • docs: add CHANGELOG.md and update README for versioning information (#5267)
  • refactor: streamline tag filtering logic in SpecFilter (#5256)
  • chore(deps): bump org.testng:testng from 7.10.2 to 7.12.0 (#5244)
  • chore(deps): bump org.apache.maven.plugins:maven-dependency-plugin from 3.6.1 to 3.11.0 (#5242)
  • chore(deps): bump org.apache.maven.plugins:maven-jar-plugin from 3.3.0 to 3.5.1 (#5241)
  • fix(model-resolver): retain identical recursive properties (#5232)
  • feat: support Java 8 date/time formats per OpenAPI Formats Registry (#5172) (#5184)
Changelog

Sourced from io.swagger.core.v3:swagger-core's changelog.

[2.2.54] - 2026-08-18

Fixed

  • Java 8 date/time types (OffsetTime, Duration, LocalTime) now map by default to the correct OpenAPI Formats Registry strings ("time", "duration", "time-local") instead of an unusable expanded object. (#5172)
  • LocalDateTime deserialization from an existing OpenAPI spec now correctly round-trips through the new TimeSchema/DurationSchema/DateTimeLocalSchema/ TimeLocalSchema classes instead of falling back to a generic StringSchema.

Added

  • PrimitiveType.enableJava8Formats() — opt-in to map LocalDateTime to the registry-compliant "date-time-local" format (default remains "date-time" for backward compatibility).

Deprecated

  • PrimitiveType.enablePartialTime() — prefer the new default "time-local" mapping for LocalTime; kept for callers who specifically need the non-registry "partial-time" format.
Commits
  • 9bcf891 prepare release 2.2.54 (#5279)
  • 06b8031 chore(deps): bump jersey2-version from 2.46 to 2.48 (#5273)
  • f3f0a8a chore(deps): bump io.github.classgraph:classgraph (#5272)
  • 85c281f chore(deps-dev): bump logback-version from 1.5.37 to 1.6.3 (#5271)
  • 9aaee38 fix: check allowableValues for enum (#4712)
  • 73afd82 chore(deps): update plexus-component-metadata to version 2.2.0 (#5269)
  • d4c5980 chore(deps): bump org.testng:testng from 7.10.2 to 7.12.0 (#5244)
  • af39326 chore(deps): bump org.apache.maven.plugins:maven-dependency-plugin (#5242)
  • b153770 chore(deps): bump org.apache.maven.plugins:maven-jar-plugin (#5241)
  • c56ca3b refactor: streamline tag filtering logic in SpecFilter (#5256)
  • Additional commits viewable in compare view

Updates com.squareup.okhttp3:mockwebserver from 5.4.0 to 5.5.0

Changelog

Sourced from com.squareup.okhttp3:mockwebserver's changelog.

Version 5.5.0

2026-08-16

This release introduces opt-in support for [Encrypted Client Hello (ECH)]. This new feature improves user privacy by encrypting domain names in transit. With regular TLS, your coffee shop’s Wi-Fi router can see that you’re visiting wikipedia.com, but it cannot see which page you’re looking at. With ECH, the router observes only the IP address. This additional privacy is most effective on sites hosted by big CDNs because the IP address doesn’t imply a particular website.

This requires ECH support in the platform’s TLS stack. Today this is only Android 17 (API 37, released June 2026). When other TLS stacks add ECH support, we'll integrate them.

ECH took a lot of work to implement because the encryption keys are published over DNS in the [HTTPS resource record], and we needed to write new code to fetch these records. This release includes a major update to OkHttp’s DNS API: it now supports multiple resource record types (not just IP addresses!), asynchronous streaming results, and in-memory caching.

To opt in, you can use DnsOverHttps:

// DnsOverHttps itself uses OkHttpClient. Build both clients upon the
// same bootstrap client so they share a connection pool and dispatcher.
val bootstrapClient = OkHttpClient()
// This sample uses Cloudflare's 1.1.1.1 DnsOverHttps service.
val client = bootstrapClient.newBuilder()
.dns(DnsOverHttps.Builder()
.client(bootstrapClient)
.url("https://1.1.1.1/dns-query&quot;.toHttpUrl())
.build())
.build()

You could also opt in with our new AndroidDns API. Unfortunately, the privacy benefits of ECH are thwarted because its DNS queries are not encrypted by default.

// AndroidDns fetches the HTTPS DNS resource records necessary for ECH.
val client = OkHttpClient.Builder()
  .dns(AndroidDns())
  .build()
  • New: OkHttp artifacts are now signed with our [new signing key]. This project and three sibling projects ([Retrofit], [Okio], and [SQLDelight]) recently joined [the Commonhaus Foundation].
  • Fix: MockWebServer’s @StartStop annotation now supports @Nested JUnit 5 tests.
  • Fix: Our default TLS hostname verifier now reject hosts that fail IP canonicalization.
  • Fix: Closing a multipart part's sink no longer closes the entire request body.
  • Fix: Flush HTTP/1 request bodies before detaching the timeout. We had a bug where timeouts

... (truncated)

Commits

Updates com.squareup.okhttp3:okhttp from 5.4.0 to 5.5.0

Changelog

Sourced from com.squareup.okhttp3:okhttp's changelog.

Version 5.5.0

2026-08-16

This release introduces opt-in support for [Encrypted Client Hello (ECH)]. This new feature improves user privacy by encrypting domain names in transit. With regular TLS, your coffee shop’s Wi-Fi router can see that you’re visiting wikipedia.com, but it cannot see which page you’re looking at. With ECH, the router observes only the IP address. This additional privacy is most effective on sites hosted by big CDNs because the IP address doesn’t imply a particular website.

This requires ECH support in the platform’s TLS stack. Today this is only Android 17 (API 37, released June 2026). When other TLS stacks add ECH support, we'll integrate them.

ECH took a lot of work to implement because the encryption keys are published over DNS in the [HTTPS resource record], and we needed to write new code to fetch these records. This release includes a major update to OkHttp’s DNS API: it now supports multiple resource record types (not just IP addresses!), asynchronous streaming results, and in-memory caching.

To opt in, you can use DnsOverHttps:

// DnsOverHttps itself uses OkHttpClient. Build both clients upon the
// same bootstrap client so they share a connection pool and dispatcher.
val bootstrapClient = OkHttpClient()
// This sample uses Cloudflare's 1.1.1.1 DnsOverHttps service.
val client = bootstrapClient.newBuilder()
.dns(DnsOverHttps.Builder()
.client(bootstrapClient)
.url("https://1.1.1.1/dns-query&quot;.toHttpUrl())
.build())
.build()

You could also opt in with our new AndroidDns API. Unfortunately, the privacy benefits of ECH are thwarted because its DNS queries are not encrypted by default.

// AndroidDns fetches the HTTPS DNS resource records necessary for ECH.
val client = OkHttpClient.Builder()
  .dns(AndroidDns())
  .build()
  • New: OkHttp artifacts are now signed with our [new signing key]. This project and three sibling projects ([Retrofit], [Okio], and [SQLDelight]) recently joined [the Commonhaus Foundation].
  • Fix: MockWebServer’s @StartStop annotation now supports @Nested JUnit 5 tests.
  • Fix: Our default TLS hostname verifier now reject hosts that fail IP canonicalization.
  • Fix: Closing a multipart part's sink no longer closes the entire request body.
  • Fix: Flush HTTP/1 request bodies before detaching the timeout. We had a bug where timeouts

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the other-dependencies group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| [com.fasterxml.jackson:jackson-bom](https://github.com/FasterXML/jackson-bom) | `2.22.1` | `2.22.2` |
| [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) | `1.6.1` | `1.6.3` |
| io.swagger.core.v3:swagger-models | `2.2.53` | `2.2.54` |
| [io.swagger.core.v3:swagger-core](https://github.com/swagger-api/swagger-core) | `2.2.53` | `2.2.54` |
| [com.squareup.okhttp3:mockwebserver](https://github.com/lysine-dev/okhttp) | `5.4.0` | `5.5.0` |
| [com.squareup.okhttp3:okhttp](https://github.com/lysine-dev/okhttp) | `5.4.0` | `5.5.0` |


Updates `com.fasterxml.jackson:jackson-bom` from 2.22.1 to 2.22.2
- [Commits](FasterXML/jackson-bom@jackson-bom-2.22.1...jackson-bom-2.22.2)

Updates `ch.qos.logback:logback-classic` from 1.6.1 to 1.6.3
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.6.1...v_1.6.3)

Updates `io.swagger.core.v3:swagger-models` from 2.2.53 to 2.2.54

Updates `io.swagger.core.v3:swagger-core` from 2.2.53 to 2.2.54
- [Release notes](https://github.com/swagger-api/swagger-core/releases)
- [Changelog](https://github.com/swagger-api/swagger-core/blob/master/CHANGELOG.md)
- [Commits](swagger-api/swagger-core@v2.2.53...v2.2.54)

Updates `io.swagger.core.v3:swagger-core` from 2.2.53 to 2.2.54
- [Release notes](https://github.com/swagger-api/swagger-core/releases)
- [Changelog](https://github.com/swagger-api/swagger-core/blob/master/CHANGELOG.md)
- [Commits](swagger-api/swagger-core@v2.2.53...v2.2.54)

Updates `com.squareup.okhttp3:mockwebserver` from 5.4.0 to 5.5.0
- [Changelog](https://github.com/lysine-dev/okhttp/blob/main/CHANGELOG.md)
- [Commits](lysine-dev/okhttp@parent-5.4.0...parent-5.5.0)

Updates `com.squareup.okhttp3:okhttp` from 5.4.0 to 5.5.0
- [Changelog](https://github.com/lysine-dev/okhttp/blob/main/CHANGELOG.md)
- [Commits](lysine-dev/okhttp@parent-5.4.0...parent-5.5.0)

---
updated-dependencies:
- dependency-name: com.fasterxml.jackson:jackson-bom
  dependency-version: 2.22.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: other-dependencies
- dependency-name: ch.qos.logback:logback-classic
  dependency-version: 1.6.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: other-dependencies
- dependency-name: io.swagger.core.v3:swagger-models
  dependency-version: 2.2.54
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: other-dependencies
- dependency-name: io.swagger.core.v3:swagger-core
  dependency-version: 2.2.54
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: other-dependencies
- dependency-name: io.swagger.core.v3:swagger-core
  dependency-version: 2.2.54
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: other-dependencies
- dependency-name: com.squareup.okhttp3:mockwebserver
  dependency-version: 5.5.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: other-dependencies
- dependency-name: com.squareup.okhttp3:okhttp
  dependency-version: 5.5.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: other-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Aug 21, 2026
…rver

okhttp/mockwebserver were bumped to 5.5.0, but feign-okhttp:13.13
transitively depends on okhttp-jvm:5.4.0. Maven's dependency
mediation could pick the older okhttp-jvm, which is missing
Platform.getServerSocketFactory() required by mockwebserver 5.5.0,
causing NoSuchMethodError in RadioMojoTests.setUp.

Co-Authored-By: Claude <noreply@anthropic.com>
@jjjasper
jjjasper enabled auto-merge (squash) August 21, 2026 10:56
@sonarqubecloud

Copy link
Copy Markdown

@jjjasper
jjjasper merged commit 8dc4cd0 into main Aug 21, 2026
4 checks passed
@dependabot
dependabot Bot deleted the dependabot/maven/other-dependencies-8a99970f37 branch August 21, 2026 10:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant