Repository navigation
build(deps): bump the maven group across 6 directories with 5 updates - #22
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps the maven group with 5 updates in the / directory: | Package | From | To | | --- | --- | --- | | [org.apache.jackrabbit:jackrabbit-jcr-commons](https://github.com/apache/jackrabbit) | `2.20.17` | `2.22.2` | | [org.jsoup:jsoup](https://github.com/jhy/jsoup) | `1.22.1` | `1.23.1` | | [org.apache.shiro:shiro-web](https://github.com/apache/shiro) | `2.1.0` | `2.2.0` | | [org.springframework.security:spring-security-web](https://github.com/spring-projects/spring-security) | `5.8.16` | `6.5.11` | | org.apache.tomcat:tomcat-catalina | `9.0.117` | `9.0.118` | Bumps the maven group with 2 updates in the /system directory: [org.apache.jackrabbit:jackrabbit-jcr-commons](https://github.com/apache/jackrabbit) and [org.jsoup:jsoup](https://github.com/jhy/jsoup). Bumps the maven group with 2 updates in the /projects/sitemanage directory: [org.apache.jackrabbit:jackrabbit-jcr-commons](https://github.com/apache/jackrabbit) and [org.jsoup:jsoup](https://github.com/jhy/jsoup). Bumps the maven group with 3 updates in the /modules/shindig-uber directory: [org.apache.jackrabbit:jackrabbit-jcr-commons](https://github.com/apache/jackrabbit), [org.jsoup:jsoup](https://github.com/jhy/jsoup) and [org.apache.shiro:shiro-web](https://github.com/apache/shiro). Bumps the maven group with 1 update in the /modules/segmentation-api directory: [org.apache.jackrabbit:jackrabbit-jcr-commons](https://github.com/apache/jackrabbit). Bumps the maven group with 1 update in the /modules/p13n-api directory: [org.apache.jackrabbit:jackrabbit-jcr-commons](https://github.com/apache/jackrabbit). Updates `org.apache.jackrabbit:jackrabbit-jcr-commons` from 2.20.17 to 2.22.2 - [Changelog](https://github.com/apache/jackrabbit/blob/jackrabbit-2.22.2/RELEASE-NOTES.txt) - [Commits](apache/jackrabbit@jackrabbit-2.20.17...jackrabbit-2.22.2) Updates `org.jsoup:jsoup` from 1.22.1 to 1.23.1 - [Release notes](https://github.com/jhy/jsoup/releases) - [Changelog](https://github.com/jhy/jsoup/blob/master/CHANGES.md) - [Commits](jhy/jsoup@jsoup-1.22.1...jsoup-1.23.1) Updates `org.apache.shiro:shiro-web` from 2.1.0 to 2.2.0 - [Release notes](https://github.com/apache/shiro/releases) - [Changelog](https://github.com/apache/shiro/blob/main/RELEASE-NOTES) - [Commits](apache/shiro@shiro-root-2.1.0...shiro-root-2.2.0) Updates `org.springframework.security:spring-security-web` from 5.8.16 to 6.5.11 - [Release notes](https://github.com/spring-projects/spring-security/releases) - [Changelog](https://github.com/spring-projects/spring-security/blob/main/RELEASE.adoc) - [Commits](spring-projects/spring-security@5.8.16...6.5.11) Updates `org.apache.tomcat:tomcat-catalina` from 9.0.117 to 9.0.118 Updates `org.apache.jackrabbit:jackrabbit-jcr-commons` from 2.20.17 to 2.22.2 - [Changelog](https://github.com/apache/jackrabbit/blob/jackrabbit-2.22.2/RELEASE-NOTES.txt) - [Commits](apache/jackrabbit@jackrabbit-2.20.17...jackrabbit-2.22.2) Updates `org.jsoup:jsoup` from 1.22.1 to 1.23.1 - [Release notes](https://github.com/jhy/jsoup/releases) - [Changelog](https://github.com/jhy/jsoup/blob/master/CHANGES.md) - [Commits](jhy/jsoup@jsoup-1.22.1...jsoup-1.23.1) Updates `org.apache.jackrabbit:jackrabbit-jcr-commons` from 2.20.17 to 2.22.2 - [Changelog](https://github.com/apache/jackrabbit/blob/jackrabbit-2.22.2/RELEASE-NOTES.txt) - [Commits](apache/jackrabbit@jackrabbit-2.20.17...jackrabbit-2.22.2) Updates `org.jsoup:jsoup` from 1.22.1 to 1.23.1 - [Release notes](https://github.com/jhy/jsoup/releases) - [Changelog](https://github.com/jhy/jsoup/blob/master/CHANGES.md) - [Commits](jhy/jsoup@jsoup-1.22.1...jsoup-1.23.1) Updates `org.apache.jackrabbit:jackrabbit-jcr-commons` from 2.20.17 to 2.22.2 - [Changelog](https://github.com/apache/jackrabbit/blob/jackrabbit-2.22.2/RELEASE-NOTES.txt) - [Commits](apache/jackrabbit@jackrabbit-2.20.17...jackrabbit-2.22.2) Updates `org.jsoup:jsoup` from 1.22.1 to 1.23.1 - [Release notes](https://github.com/jhy/jsoup/releases) - [Changelog](https://github.com/jhy/jsoup/blob/master/CHANGES.md) - [Commits](jhy/jsoup@jsoup-1.22.1...jsoup-1.23.1) Updates `org.apache.shiro:shiro-web` from 2.1.0 to 2.2.0 - [Release notes](https://github.com/apache/shiro/releases) - [Changelog](https://github.com/apache/shiro/blob/main/RELEASE-NOTES) - [Commits](apache/shiro@shiro-root-2.1.0...shiro-root-2.2.0) Updates `org.apache.jackrabbit:jackrabbit-jcr-commons` from 1.6.0 to 2.22.2 - [Changelog](https://github.com/apache/jackrabbit/blob/jackrabbit-2.22.2/RELEASE-NOTES.txt) - [Commits](apache/jackrabbit@jackrabbit-2.20.17...jackrabbit-2.22.2) Updates `org.apache.jackrabbit:jackrabbit-jcr-commons` from 1.6.0 to 2.22.2 - [Changelog](https://github.com/apache/jackrabbit/blob/jackrabbit-2.22.2/RELEASE-NOTES.txt) - [Commits](apache/jackrabbit@jackrabbit-2.20.17...jackrabbit-2.22.2) --- updated-dependencies: - dependency-name: org.apache.jackrabbit:jackrabbit-jcr-commons dependency-version: 2.22.2 dependency-type: direct:production dependency-group: maven - dependency-name: org.jsoup:jsoup dependency-version: 1.23.1 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.shiro:shiro-web dependency-version: 2.2.0 dependency-type: direct:production dependency-group: maven - dependency-name: org.springframework.security:spring-security-web dependency-version: 6.5.11 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.tomcat:tomcat-catalina dependency-version: 9.0.118 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.jackrabbit:jackrabbit-jcr-commons dependency-version: 2.22.2 dependency-type: direct:production dependency-group: maven - dependency-name: org.jsoup:jsoup dependency-version: 1.23.1 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.jackrabbit:jackrabbit-jcr-commons dependency-version: 2.22.2 dependency-type: direct:production dependency-group: maven - dependency-name: org.jsoup:jsoup dependency-version: 1.23.1 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.jackrabbit:jackrabbit-jcr-commons dependency-version: 2.22.2 dependency-type: direct:production dependency-group: maven - dependency-name: org.jsoup:jsoup dependency-version: 1.23.1 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.shiro:shiro-web dependency-version: 2.2.0 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.jackrabbit:jackrabbit-jcr-commons dependency-version: 2.22.2 dependency-type: direct:production dependency-group: maven - dependency-name: org.apache.jackrabbit:jackrabbit-jcr-commons dependency-version: 2.22.2 dependency-type: direct:production dependency-group: maven ... Signed-off-by: dependabot[bot] <support@github.com>
natechadwick-intsof
left a comment
There was a problem hiding this comment.
Java 8 compatibility review
Do not merge as-is. At least three of the five root bumps are incompatible with the Java 8 LTS line.
Incompatible (must not land)
| Package | From → To | Evidence | Notes |
|---|---|---|---|
org.springframework.security:spring-security-web |
5.8.16 → 6.5.11 | JAR class major 61 = Java 17; Gradle metadata org.gradle.jvm.version: 17 |
Also pulls spring-*:6.2.19. Spring Security 6 requires Spring Framework 6 + Jakarta. Current 5.8.16 is major 52 (Java 8). |
org.apache.jackrabbit:jackrabbit-jcr-commons |
2.20.17 → 2.22.2 (and 1.6.0 → 2.22.2 in p13n/segmentation) | Class major 55 = Java 11 | 2.20.17 is still Java 8 (major 52). This is also a large major jump from 1.6.0 in two modules. |
org.apache.shiro:shiro-web |
2.1.0 → 2.2.0 | Class major 55 = Java 11 | Note: 2.1.0 is already Java 11 bytecode — already past a pure Java 8 Shiro line. Still should not bump further without an intentional Java 11 plan. |
Compatible on their own (but do not save this PR)
| Package | From → To | Evidence |
|---|---|---|
org.jsoup:jsoup |
1.22.1 → 1.23.1 | Class major 52 (Java 8) |
org.apache.tomcat:tomcat-catalina |
9.0.117 → 9.0.118 | Non-module classes major 52 (Java 8); Tomcat 9 remains the Java 8-capable line |
Dependabot policy
.github/dependabot.yml on main already intends to block:
org.springframework.security*versions>= 5.9.0org.apache.jackrabbit:jackrabbit-jcr-commonsversions>= 2.21.0org.apache.shiro*versions>= 2.0.0
This PR shows those ignores are still not fully preventing grouped multi-directory updates. Recommend:
- Close this PR (or drop the three incompatible deps and re-open only jsoup + tomcat if desired).
- Tighten Dependabot ignores for Spring Security (and optionally full-ignore Shiro majors) so
spring-security-web6.x cannot reappear in a group PR. - Keep Spring Security on the 5.8.x Java 8 line; security fixes for 6.x are not usable here without a Java 17 + Spring Framework 6 migration.
Recommendation
Request changes / close. The spring.security.version bump alone would break a Java 8 runtime (and fight the rest of the tree still on Spring 5.3.x / javax.*).
|
Closing: Java 8 incompatible. Review confirmed:
jsoup 1.23.1 and Tomcat 9.0.118 would be fine alone, but this grouped PR is not mergeable. Follow-up: tighten Dependabot ignores so these cannot reappear in group PRs. |
|
This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests. To ignore these dependencies, configure ignore rules in dependabot.yml |
Bumps the maven group with 5 updates in the / directory:
2.20.172.22.21.22.11.23.12.1.02.2.05.8.166.5.119.0.1179.0.118Bumps the maven group with 2 updates in the /system directory: org.apache.jackrabbit:jackrabbit-jcr-commons and org.jsoup:jsoup.
Bumps the maven group with 2 updates in the /projects/sitemanage directory: org.apache.jackrabbit:jackrabbit-jcr-commons and org.jsoup:jsoup.
Bumps the maven group with 3 updates in the /modules/shindig-uber directory: org.apache.jackrabbit:jackrabbit-jcr-commons, org.jsoup:jsoup and org.apache.shiro:shiro-web.
Bumps the maven group with 1 update in the /modules/segmentation-api directory: org.apache.jackrabbit:jackrabbit-jcr-commons.
Bumps the maven group with 1 update in the /modules/p13n-api directory: org.apache.jackrabbit:jackrabbit-jcr-commons.
Updates
org.apache.jackrabbit:jackrabbit-jcr-commonsfrom 2.20.17 to 2.22.2Changelog
Sourced from org.apache.jackrabbit:jackrabbit-jcr-commons's changelog.
... (truncated)
Commits
2b5babf[maven-release-plugin] prepare release jackrabbit-2.22.20d7c2e5JCR-5180: Release Jackrabbit 2.22.2 - Candidate Release Notes (#277)b487b6fJCR-5158: Update oak-jackrabbit-api.version.implemented in trunk to Oak 1.82....52d8411JCR-5161: NamespaceHelper - get NamespaceRegistry only once (#259)6b6171eJCR-5150 Add constant for jcr:title02b09fdJCR-5159: Create coverage for NamespaceHelper (#256)0b81850JCR-5152 Add method to check if a (local) name is valid according to JCR2e64ea5JCR-5137: Update JCR commons to implement current jackrabbit-api (#231)9ba0518JCR-5089: avoid use of deprecated junit.framework.Assert (#208)019f6f9JCR-5177: jackrabbit-jcr2spi: update to commons-collections4 4.5.0 (#270)Updates
org.jsoup:jsoupfrom 1.22.1 to 1.23.1Release notes
Sourced from org.jsoup:jsoup's releases.
... (truncated)
Changelog
Sourced from org.jsoup:jsoup's changelog.
Commits
bb077a8[maven-release-plugin] prepare release jsoup-1.23.1cdb5579Harden the test someb86b282Normalize re2j complexity exceptions0fcc369Bump github/codeql-action from 4.37.0 to 4.37.1aea4a1bBump actions/setup-java from 5.5.0 to 5.6.0ec9c879Bump actions/checkout from 7.0.0 to 7.0.11fb2c97FixKeyVal.inputStreamvalidation3475afcHandle non-string internal attribute values; test for internal attribute databe8c375Parse CDATA according to the context namespace8996fceAdd appendable outer HTML outputUpdates
org.apache.shiro:shiro-webfrom 2.1.0 to 2.2.0Release notes
Sourced from org.apache.shiro:shiro-web's releases.
... (truncated)
Commits
8454a31[maven-release-plugin] prepare release shiro-root-2.2.00819229chore: remove extra newlinea46600fimprovement: implemented session key rotation via changeSessionId() in Web-Co...be31c13enh(jakarta-ee): encrypt SAVED_REQUEST_KEY cookie97218c0Merge pull request #2689 from apache/dependabot/github_actions/github-actions...d6246a0Merge pull request #2691 from apache/dependabot/maven/org.apache.karaf.featur...5ab9e46Merge pull request #2692 from apache/dependabot/maven/org.owasp-dependency-ch...4cb75d9chore(deps): bump org.owasp:dependency-check-maven from 12.2.1 to 12.2.205a915fchore(deps): bump org.apache.karaf.features:framework0cc8c1achore(deps): bump github/codeql-actionUpdates
org.springframework.security:spring-security-webfrom 5.8.16 to 6.5.11Release notes
Sourced from org.springframework.security:spring-security-web's releases.
... (truncated)
Commits
73b0777Release 6.5.11fd5dae5Sync branch '6.5.x'700a453Bump ch.qos.logback:logback-classic from 1.5.32 to 1.5.343a394c6Update micrometer-bom to 1.15.1279f9becUpdate to reactor-bom 2024.0.185b01936Bump org.hibernate.orm:hibernate-core from 6.6.51.Final to 6.6.53.Finalf9b4afdBump com.fasterxml.jackson:jackson-bom from 2.18.7 to 2.18.8f325ddbBump org.springframework:spring-framework-bom from 6.2.18 to 6.2.194adfdf6Bump org.apache.maven:maven-resolver-provider from 3.9.15 to 3.9.16e91b81aBump org-bouncycastle from 1.80 to 1.80.2Updates
org.apache.tomcat:tomcat-catalinafrom 9.0.117 to 9.0.118Updates
org.apache.jackrabbit:jackrabbit-jcr-commonsfrom 2.20.17 to 2.22.2Changelog
Sourced from org.apache.jackrabbit:jackrabbit-jcr-commons's changelog.
... (truncated)
Commits
2b5babf[maven-release-plugin] prepare release jackrabbit-2.22.20d7c2e5JCR-5180: Release Jackrabbit 2.22.2 - Candidate Release Notes (#277)b487b6fJCR-5158: Update oak-jackrabbit-api.version.implemented in trunk to Oak 1.82....52d8411JCR-5161: NamespaceHelper - get NamespaceRegistry only once (#259)6b6171eJCR-5150 Add constant for jcr:title02b09fdJCR-5159: Create coverage for NamespaceHelper (#256)0b81850JCR-5152 Add method to check if a (local) name is valid according to JCR2e64ea5JCR-5137: Update JCR commons to implement current jackrabbit-api (#231)9ba0518JCR-5089: avoid use of deprecated junit.framework.Assert (#208)019f6f9JCR-5177: jackrabbit-jcr2spi: update to commons-collections4 4.5.0 (#270)Updates
org.jsoup:jsoupfrom 1.22.1 to 1.23.1Release notes
Sourced from org.jsoup:jsoup's releases.
... (truncated)
Changelog
Sourced from org.jsoup:jsoup's changelog.