Skip to content

deps: bump io.quarkus:quarkus-bom from 3.18.3 to 3.19.0#729

Closed
dependabot[bot] wants to merge 1 commit intodevelopmentfrom
dependabot/gradle/development/io.quarkus-quarkus-bom-3.19.0
Closed

deps: bump io.quarkus:quarkus-bom from 3.18.3 to 3.19.0#729
dependabot[bot] wants to merge 1 commit intodevelopmentfrom
dependabot/gradle/development/io.quarkus-quarkus-bom-3.19.0

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Feb 24, 2025

Bumps io.quarkus:quarkus-bom from 3.18.3 to 3.19.0.

Release notes

Sourced from io.quarkus:quarkus-bom's releases.

3.19.0.CR1

Major changes

  • #43831 - Micrometer to OpenTelemetry Bridge
  • #45446 - Migrate core extensions to @ConfigMapping
  • #45704 - Support permission checkers for WebSockets Next
  • #45809 - WebSockets Next: Allow to send authorization headers from web browsers using JavaScript clients
  • #45973 - Switch to UBI 9 by default
  • #46169 - Introduce support for JEP 483's new AOT cache

Complete changelog

  • #24249 - Reuse maven-surefire-plugin environmentVariables and systemPropertyVariables for continuous testing
  • #25975 - Refactoring the way we register classes for reflection, JNI, etc.
  • #27376 - OpenAPI should list a 400 error code on certain conditions
  • #34016 - Configuration property to make transaction mandatory even for read operations
  • #37531 - Allow http/2 requests to fallback to host header if authority pseudoheader is not provided
  • #37845 - Docs: security-oidc-bearer-token-authentication guide Keycloak SPA not working
  • #37927 - Cannot mock/spy class error, after adding quarkus-junit5-mockito dependency
  • #38061 - OpenTelemetry: context of sender not active in consumer
  • #38368 - @QuarkusMainIntegrationTest not implemented for Docker
  • #41607 - Netty finalizers load classes from closed class loaders
  • #41686 - Enable io.netty.allocator.disableCacheFinalizersForFastThreadLocalThreads
  • #42623 - Support optional @QueryParam on Rest client
  • #42756 - Quarkus main branch build on Windows fails with internal Develocity error
  • #42824 - quarkus-websockets-next connecting from browser with JWT
  • #43831 - Micrometer to OpenTelemetry Bridge
  • #44115 - Migrate Quarkus Vert.x HTTP extension config classes to @ConfigMapping
  • #44409 - Provide WebSockets Next support for authenticated JavaScript web socket upgrade and messages
  • #44411 - Implement withSpan method utilities for Mutiny
  • #44714 - io.quarkus.credentials is split across extensions/credentials/deployment and .../runtime
  • #44725 - io.quarkus.elytron.security.runtime is split across multiple modules
  • #44729 - io.quarkus.keycloak.admin.client.common is split across runtime and deployment modules
  • #44737 - io.quarkus.oidc.token.propagation.reactive is split across deployment and runtime modules
  • #44744 - Use ConfigRoot and ConfigMapping without -AlegacyConfigRoot=true
  • #44793 - Code format broken on page "Writing a Dev Service"
  • #44998 - Verify that we do not exceed the number of tags that can be recorded for HTTP requests
  • #45175 - TLS Registry: provide a TLS configuration called javax.net.ssl having truststore set in the same way as default SunJSSE provider
  • #45184 - TLS Registry: provide a TLS configuration called javax.net.ssl having truststore set in the same way as default SunJSSE provider
  • #45292 - Add a note about SDKMAN! to the Contributing guide
  • #45446 - Migrate core extensions to @ConfigMapping
  • #45478 - Add helper methods for manual spans in mutiny pipelines
  • #45525 - Hibernate tries to reflectively access Service methods not registered for reflection
  • #45546 - Improving Qute Escaper to be as branch-free as possible
  • #45551 - Further copyedit Keycloak authorization
  • #45589 - Update OIDC Redis TokenStateManager to keep access token expires_in
  • #45594 - Bump bouncycastle.version from 1.79 to 1.80
  • #45596 - Bump smallrye-reactive-messaging.version from 4.26.0 to 4.27.0
  • #45604 - Remove unused NativeImageFeatureUtils
  • #45607 - Bump strimzi-test-container version from 0.107.0 to 0.109.1

... (truncated)

Commits
  • b423a8d [RELEASE] - Bump version to 3.19.0
  • 75f8379 Merge pull request #46342 from gsmet/3.19.0-backports-2
  • c53a7e4 Update mime4j to 0.8.12
  • 9bbac27 fix(core): Use UBI9-based binary s2i image by default
  • fc7c67e Text cannot be parsed to a Duration when assessing
  • 9ad3391 Use proper call to Logger#getMessageLogger
  • 2f473fa Prevent indexing warning about Lombok annotation in REST Client
  • 96acd96 Qute: add some more built-in string extensions
  • 84a5fe7 Hibernate ORM tries to load import.sql
  • d4acc3a Upgrade Hibernate ORM to 6.6.8.Final
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [io.quarkus:quarkus-bom](https://github.com/quarkusio/quarkus) from 3.18.3 to 3.19.0.
- [Release notes](https://github.com/quarkusio/quarkus/releases)
- [Commits](quarkusio/quarkus@3.18.3...3.19.0)

---
updated-dependencies:
- dependency-name: io.quarkus:quarkus-bom
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Feb 24, 2025
@triceo triceo closed this Feb 24, 2025
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Feb 24, 2025

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot bot deleted the dependabot/gradle/development/io.quarkus-quarkus-bom-3.19.0 branch February 24, 2025 05:56
triceo added a commit that referenced this pull request Dec 8, 2025
…#959)

Bumps the base group with 1 update:
[graalvm/setup-graalvm](https://github.com/graalvm/setup-graalvm).

Updates `graalvm/setup-graalvm` from 1.4.3 to 1.4.4
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/graalvm/setup-graalvm/releases">graalvm/setup-graalvm's
releases</a>.</em></p>
<blockquote>
<h2>v1.4.4</h2>
<h2>What's Changed</h2>
<ul>
<li>Bump actions/checkout from 5.0.0 to 6.0.0 in the
github-actions-updates group by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/graalvm/setup-graalvm/pull/198">graalvm/setup-graalvm#198</a></li>
<li>Bump the npm-updates group with 10 updates by <a
href="https://github.com/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/graalvm/setup-graalvm/pull/197">graalvm/setup-graalvm#197</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/graalvm/setup-graalvm/compare/v1.4.3...v1.4.4">https://github.com/graalvm/setup-graalvm/compare/v1.4.3...v1.4.4</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/graalvm/setup-graalvm/commit/790e28947b79a9c09c3391c0f18bf8d0f102ed69"><code>790e289</code></a>
Bump version to <code>1.4.4</code>.</li>
<li><a
href="https://github.com/graalvm/setup-graalvm/commit/434a92bc4faf302845542ab080ba51cea01d392d"><code>434a92b</code></a>
Update dist files.</li>
<li><a
href="https://github.com/graalvm/setup-graalvm/commit/fe4a6b3a89d8ba8639f157689d83cbe564402ce5"><code>fe4a6b3</code></a>
Update dependencies</li>
<li><a
href="https://github.com/graalvm/setup-graalvm/commit/d8578a7f98f24a05ed4eddd4f76472b40cae484e"><code>d8578a7</code></a>
Bump the npm-updates group with 10 updates</li>
<li><a
href="https://github.com/graalvm/setup-graalvm/commit/98e485c1fbbf7e7a85fd316979ff3424e8814f2f"><code>98e485c</code></a>
Bump actions/checkout in the github-actions-updates group</li>
<li>See full diff in <a
href="https://github.com/graalvm/setup-graalvm/compare/dec5790292b7b36d7ad368abe856887749c6c520...790e28947b79a9c09c3391c0f18bf8d0f102ed69">compare
view</a></li>
</ul>
</details>
<br />

Bumps the base group with 1 update:
[org.apache.commons:commons-text](https://github.com/apache/commons-text).

Updates `org.apache.commons:commons-text` from 1.14.0 to 1.15.0
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/apache/commons-text/blob/master/RELEASE-NOTES.txt">org.apache.commons:commons-text's
changelog</a>.</em></p>
<blockquote>
<h2>Apache Commons Text 1.15.0 Release Notes</h2>
<p>The Apache Commons Text team is pleased to announce the release of
Apache Commons Text 1.15.0.</p>
<p>Apache Commons Text is a set of utility functions and reusable
components for processing
and manipulating text in a Java environment.</p>
<p>Release 1.15.0. This is a feature and maintenance release. Java 8 or
later is required.</p>
<h2>New features</h2>
<ul>
<li>
<pre><code> Add experimental CycloneDX VEX file
[#683](apache/commons-text#683). Thanks to
Piotr P. Karwasz, Gary Gregory.
</code></pre>
</li>
<li>TEXT-235: Add Damerau-Levenshtein distance <a
href="https://redirect.github.com/apache/commons-text/issues/687">#687</a>.
Thanks to LorgeN, Gary Gregory.</li>
<li>
<pre><code> Add unit tests to increase coverage
[#719](apache/commons-text#719). Thanks to
Michael Hausegger, Gary Gregory.
</code></pre>
</li>
<li>
<pre><code> Add new test for CharSequenceTranslator#with()
[#725](apache/commons-text#725). Thanks to
Michael Hausegger, Gary Gregory.
</code></pre>
</li>
<li>
<pre><code> Add tests and assertions to
org.apache.commons.text.similarity to get to 100% code coverage
[#727](apache/commons-text#727),
[#728](apache/commons-text#728). Thanks to
Michael Hausegger.
</code></pre>
</li>
</ul>
<h2>Fixed Bugs</h2>
<ul>
<li>
<pre><code> Fix exception message typo in
XmlStringLookup.XmlStringLookup(Map, Path...). Thanks to Gary Gregory.
</code></pre>
</li>
<li>TEXT-236: Inserting at the end of a TextStringBuilder throws a
StringIndexOutOfBoundsException. Thanks to Pierre Post, Sumit Bera, Alex
Herbert, Gary Gregory.</li>
<li>
<pre><code> Fix TextStringBuilderTest.testAppendToCharBuffer() to use
proper argument type
[#724](apache/commons-text#724). Thanks to
Michael Hausegger.
</code></pre>
</li>
<li>
<pre><code> Fix Apache RAT plugin console warnings. Thanks to Gary
Gregory.
</code></pre>
</li>
<li>
<pre><code> Fix site XML to use version 2.0.0 XML schema. Thanks to Gary
Gregory.
</code></pre>
</li>
<li>
<pre><code> Removed unreachable threshold verification code in
src/main/java/org/apache/commons/text/similarity
[#730](apache/commons-text#730). Thanks to
Michael Hausegger.
</code></pre>
</li>
<li>
<pre><code> Enable secure processing for the XML parser in
XmlStringLookup in case the underlying JAXP implementation doesn't
[#729](apache/commons-text#729). Thanks to 김민재
(minjas0507), Gary Gregory, Piotr Karwasz.
</code></pre>
</li>
</ul>
<h2>Changes</h2>
<ul>
<li>
<pre><code> Bump org.apache.commons:commons-parent from 85 to 93
[#704](apache/commons-text#704),
[#723](apache/commons-text#723),
[#726](apache/commons-text#726). Thanks to
Gary Gregory.
</code></pre>
</li>
<li>
<pre><code> Bump commons.bytebuddy.version from 1.17.6 to 1.18.2
[#696](apache/commons-text#696),
[#722](apache/commons-text#722). Thanks to
Gary Gregory.
</code></pre>
</li>
<li>
<pre><code> Bump graalvm.version from 24.2.2 to 25.0.1
[#703](apache/commons-text#703),
[#716](apache/commons-text#716). Thanks to
Gary Gregory, Dependabot.
</code></pre>
</li>
<li>
<pre><code> Bump org.apache.commons:commons-lang3 from 3.18.0 to 3.20.0.
Thanks to Gary Gregory.
</code></pre>
</li>
<li>
<pre><code> Bump commons-io:commons-io from 2.20.0 to 2.21.0. Thanks to
Gary Gregory.
</code></pre>
</li>
</ul>
<p>Historical list of changes: <a
href="https://commons.apache.org/proper/commons-text/changes.html">https://commons.apache.org/proper/commons-text/changes.html</a></p>
<p>For complete information on Apache Commons Text, including
instructions on how to submit bug reports,
patches, or suggestions for improvement, see the Apache Commons Text
website:</p>
<p><a
href="https://commons.apache.org/proper/commons-text">https://commons.apache.org/proper/commons-text</a></p>
<p>Download page: <a
href="https://commons.apache.org/proper/commons-text/download_text.cgi">https://commons.apache.org/proper/commons-text/download_text.cgi</a></p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/apache/commons-text/commit/04e937470d3679cc163df85d82d5b6d2e3e71128"><code>04e9374</code></a>
Prepare for the release candidate 1.15.0 RC1</li>
<li><a
href="https://github.com/apache/commons-text/commit/502c4c41be5671681b58a9b50297f99737e8ea93"><code>502c4c4</code></a>
Prepare for the next release candidate</li>
<li><a
href="https://github.com/apache/commons-text/commit/c6e17ec24cc8374eb12676b717bf797f41b6e539"><code>c6e17ec</code></a>
Use direct access</li>
<li><a
href="https://github.com/apache/commons-text/commit/58e1e125daaa0aebf8c5ffaa82af48821a1ccf2d"><code>58e1e12</code></a>
Simplify XML FSP (<a
href="https://redirect.github.com/apache/commons-text/issues/731">#731</a>)</li>
<li><a
href="https://github.com/apache/commons-text/commit/b5052c97e84e1c174ec8bfbbb749e33f22917a07"><code>b5052c9</code></a>
Bump actions/setup-java from 5.0.0 to 5.1.0</li>
<li><a
href="https://github.com/apache/commons-text/commit/2e2d4bc90f1b3274e7943ac27d037d47c0cc098d"><code>2e2d4bc</code></a>
Revert &quot;Bump actions/setup-java from 5.0.0 to 5.1.0&quot;</li>
<li><a
href="https://github.com/apache/commons-text/commit/b0ddbd17bbeee12ad33b8a61c60b4edbe6c85838"><code>b0ddbd1</code></a>
Bump actions/setup-java from 5.0.0 to 5.1.0</li>
<li><a
href="https://github.com/apache/commons-text/commit/1c2d3821e67e08342b8cef4d4445c30b4a22daca"><code>1c2d382</code></a>
Add tests with external DTD</li>
<li><a
href="https://github.com/apache/commons-text/commit/ed3df4b25cd5301921a6523ae7db2411f4a84d98"><code>ed3df4b</code></a>
Internal clean up</li>
<li><a
href="https://github.com/apache/commons-text/commit/bb508f304a8835ac2319af1d872b2f1a9ff6f81d"><code>bb508f3</code></a>
Bump actions/checkout from 6.0.0 to 6.0.1</li>
<li>Additional commits viewable in <a
href="https://github.com/apache/commons-text/compare/rel/commons-text-1.14.0...rel/commons-text-1.15.0">compare
view</a></li>
</ul>
</details>
<br />

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Lukáš Petrovický <lukas@timefold.ai>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant