diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 47e5169135..d98f105833 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -160,7 +160,7 @@ jobs: run: ./gradlew codeCoverageReport - name: Send code coverage report to Codecov.io - uses: codecov/codecov-action@75cd11691c0faa626561e295848008c8a7dddffe # v5.5.4 + uses: codecov/codecov-action@0fb7174895f61a3b6b78fc075e0cd60383518dac # v5.5.5 with: token: ${{ secrets.CODECOV_TOKEN }} docs: diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 56e9af4d43..c98537d66d 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -54,7 +54,7 @@ jobs: # Initializes the CodeQL tools for scanning. - name: Initialize CodeQL - uses: github/codeql-action/init@03e4368ac7daa2bd82b3e85262f3bf87ee112f57 # v3.36.0 + uses: github/codeql-action/init@dd903d2e4f5405488e5ef1422510ee31c8b32357 # v3.36.2 with: languages: ${{ matrix.language }} # If you wish to specify custom queries, you can do so here or in a config file. @@ -68,7 +68,7 @@ jobs: # Autobuild attempts to build any compiled languages (C/C++, C#, Go, Java, or Swift). # If this step fails, then you should remove it and run the build manually (see below) - name: Autobuild - uses: github/codeql-action/autobuild@03e4368ac7daa2bd82b3e85262f3bf87ee112f57 # v3.36.0 + uses: github/codeql-action/autobuild@dd903d2e4f5405488e5ef1422510ee31c8b32357 # v3.36.2 # â„šī¸ Command-line programs to run using the OS shell. # 📚 See https://docs.github.com/en/actions/using-workflows/workflow-syntax-for-github-actions#jobsjob_idstepsrun @@ -81,6 +81,6 @@ jobs: # ./location_of_script_within_repo/buildscript.sh - name: Perform CodeQL Analysis - uses: github/codeql-action/analyze@03e4368ac7daa2bd82b3e85262f3bf87ee112f57 # v3.36.0 + uses: github/codeql-action/analyze@dd903d2e4f5405488e5ef1422510ee31c8b32357 # v3.36.2 with: category: "/language:${{matrix.language}}" diff --git a/.github/workflows/semgrep.yml b/.github/workflows/semgrep.yml index ff23ee5717..8a6fe6baea 100644 --- a/.github/workflows/semgrep.yml +++ b/.github/workflows/semgrep.yml @@ -29,14 +29,14 @@ jobs: steps: - name: Checkout - uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6.0.2 + uses: actions/checkout@df4cb1c069e1874edd31b4311f1884172cec0e10 # v6.0.3 with: persist-credentials: false - name: Run Semgrep run: semgrep scan --sarif --output=semgrep.sarif --config=p/auto --config=p/dockerfile --config=p/typescript --config=p/javascript --config=p/java --metrics=off --verbose - name: Upload SARIF file for GitHub Advanced Security Dashboard - uses: github/codeql-action/upload-sarif@03e4368ac7daa2bd82b3e85262f3bf87ee112f57 # v3.36.0 + uses: github/codeql-action/upload-sarif@dd903d2e4f5405488e5ef1422510ee31c8b32357 # v3.36.2 with: sarif_file: semgrep.sarif if: always() diff --git a/build.gradle b/build.gradle index b8df395a04..b45e33952e 100644 --- a/build.gradle +++ b/build.gradle @@ -72,7 +72,7 @@ allprojects { configurations { taglet { - resolutionStrategy.force("net.sourceforge.plantuml:plantuml:1.2026.5") + resolutionStrategy.force("net.sourceforge.plantuml:plantuml:1.2026.6") } } diff --git a/commercetools/commercetools-async-http-client/build.gradle b/commercetools/commercetools-async-http-client/build.gradle index b29a989868..ce9b694e3b 100644 --- a/commercetools/commercetools-async-http-client/build.gradle +++ b/commercetools/commercetools-async-http-client/build.gradle @@ -1,12 +1,12 @@ dependencies { api project(":rmf:rmf-java-base") - api "org.asynchttpclient:async-http-client:2.15.0" + api "org.asynchttpclient:async-http-client:2.16.0" api commons.io version commons.io_version - api "io.netty:netty-codec:4.2.14.Final" - api "io.netty:netty-codec-http:4.2.14.Final" - api "io.netty:netty-codec-socks:4.2.14.Final" - api "io.netty:netty-handler-proxy:4.2.14.Final" - api "io.netty:netty-handler:4.2.14.Final" + api "io.netty:netty-codec:4.2.15.Final" + api "io.netty:netty-codec-http:4.2.15.Final" + api "io.netty:netty-codec-socks:4.2.15.Final" + api "io.netty:netty-handler-proxy:4.2.15.Final" + api "io.netty:netty-handler:4.2.15.Final" implementation javax.validation } diff --git a/commercetools/commercetools-monitoring-datadog/build.gradle b/commercetools/commercetools-monitoring-datadog/build.gradle index 4e9f434945..c19ac155aa 100644 --- a/commercetools/commercetools-monitoring-datadog/build.gradle +++ b/commercetools/commercetools-monitoring-datadog/build.gradle @@ -1,7 +1,7 @@ dependencies { api project(":rmf:rmf-java-base") implementation "com.datadoghq:java-dogstatsd-client:4.4.5" - implementation "com.datadoghq:datadog-api-client:2.55.0" + implementation "com.datadoghq:datadog-api-client:2.56.0" testImplementation project(":commercetools:commercetools-sdk-java-api") } diff --git a/commercetools/commercetools-monitoring-opentelemetry/build.gradle b/commercetools/commercetools-monitoring-opentelemetry/build.gradle index 628b9ecf9d..e2552b5934 100644 --- a/commercetools/commercetools-monitoring-opentelemetry/build.gradle +++ b/commercetools/commercetools-monitoring-opentelemetry/build.gradle @@ -1,7 +1,7 @@ dependencies { api project(":rmf:rmf-java-base") - implementation 'io.opentelemetry:opentelemetry-api:1.62.0' + implementation 'io.opentelemetry:opentelemetry-api:1.63.0' testImplementation project(":commercetools:commercetools-sdk-java-api") } diff --git a/commercetools/commercetools-okhttp-client5/build.gradle b/commercetools/commercetools-okhttp-client5/build.gradle index 49f71fe1e7..32da40bfea 100644 --- a/commercetools/commercetools-okhttp-client5/build.gradle +++ b/commercetools/commercetools-okhttp-client5/build.gradle @@ -11,7 +11,7 @@ jmh { dependencies { api project(":rmf:rmf-java-base") - api "com.squareup.okhttp3:okhttp:5.3.2" version { + api "com.squareup.okhttp3:okhttp:5.4.0" version { strictly '[5.0,5.99999]' prefer "5.3.2" } diff --git a/commercetools/commercetools-reactornetty-client/build.gradle b/commercetools/commercetools-reactornetty-client/build.gradle index 4d952a9918..3a2cc260db 100644 --- a/commercetools/commercetools-reactornetty-client/build.gradle +++ b/commercetools/commercetools-reactornetty-client/build.gradle @@ -2,8 +2,8 @@ dependencies { api project(":rmf:rmf-java-base") - api "io.projectreactor.netty:reactor-netty-http:1.3.5" - api "io.projectreactor.netty:reactor-netty-core:1.3.5" + api "io.projectreactor.netty:reactor-netty-http:1.3.6" + api "io.projectreactor.netty:reactor-netty-core:1.3.6" implementation javax.validation } diff --git a/commercetools/commercetools-sdk-compat-v1/build.gradle b/commercetools/commercetools-sdk-compat-v1/build.gradle index 6080762b18..fa7a0b9e43 100644 --- a/commercetools/commercetools-sdk-compat-v1/build.gradle +++ b/commercetools/commercetools-sdk-compat-v1/build.gradle @@ -21,8 +21,8 @@ dependencies { api project(':commercetools:commercetools-sdk-java-api') api ctsdkv1.client version ctsdkv1.version api ctsdkv1.models version ctsdkv1.version - api "io.netty:netty-codec:4.2.14.Final" - api "io.netty:netty-codec-http:4.2.14.Final" + api "io.netty:netty-codec:4.2.15.Final" + api "io.netty:netty-codec-http:4.2.15.Final" jmhImplementation project(':commercetools:commercetools-async-http-client') jmhImplementation project(':commercetools:commercetools-apachehttp-client') diff --git a/common-plugins/build.gradle b/common-plugins/build.gradle index faca0a46a0..b973436460 100644 --- a/common-plugins/build.gradle +++ b/common-plugins/build.gradle @@ -1,7 +1,7 @@ plugins { id 'java-gradle-plugin' id 'idea' - id 'org.jetbrains.kotlin.jvm' version "2.3.21" + id 'org.jetbrains.kotlin.jvm' version "2.4.0" } repositories { diff --git a/common-plugins/javaparser/build.gradle b/common-plugins/javaparser/build.gradle index 42f4ff869d..c9cbef8c3f 100644 --- a/common-plugins/javaparser/build.gradle +++ b/common-plugins/javaparser/build.gradle @@ -15,5 +15,5 @@ shadowJar { } dependencies { - implementation 'com.github.javaparser:javaparser-core:3.28.1' + implementation 'com.github.javaparser:javaparser-core:3.28.2' } diff --git a/gradle-scripts/extensions.gradle b/gradle-scripts/extensions.gradle index 350012b137..69e94bef49 100644 --- a/gradle-scripts/extensions.gradle +++ b/gradle-scripts/extensions.gradle @@ -31,9 +31,9 @@ ext { jackson_core = [ version: '3.1.0', - annotations: 'com.fasterxml.jackson.core:jackson-annotations:2.21', - databind: 'tools.jackson.core:jackson-databind:3.1.0', - core: 'tools.jackson.core:jackson-core:3.1.0', + annotations: 'com.fasterxml.jackson.core:jackson-annotations:2.22', + databind: 'tools.jackson.core:jackson-databind:3.2.0', + core: 'tools.jackson.core:jackson-core:3.1.1', //datatype: 'com.fasterxml.jackson.datatype:jackson-datatype-jsr310:3.1.0', ] diff --git a/package.json b/package.json index eaa0497cf1..429c21fa7f 100644 --- a/package.json +++ b/package.json @@ -18,5 +18,5 @@ "format": "./gradlew spotlessApply", "prepare": "husky" }, - "packageManager": "yarn@4.15.0" + "packageManager": "yarn@4.17.0" }