Skip to content

Bump the all group with 9 updates - #716

Closed
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/all-1fb4a537e2
Closed

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/all-1fb4a537e2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the all group with 9 updates:

Package From To
org.apache.httpcomponents:httpcomponents-parent 14 15
org.conscrypt:conscrypt-openjdk-uber 2.6.1 2.7.0
org.apache.logging.log4j:log4j-slf4j-impl 2.25.4 2.26.1
org.apache.logging.log4j:log4j-core 2.25.4 2.26.1
org.apache.maven.plugins:maven-enforcer-plugin 3.6.2 3.6.3
com.github.siom79.japicmp:japicmp-maven-plugin 0.25.6 0.26.2
org.apache.maven.plugins:maven-toolchains-plugin 3.2.0 3.3.0
tools.jackson.core:jackson-databind 3.2.0 3.2.3
org.apache.maven:apache-maven 3.9.14 3.10.0

Updates org.apache.httpcomponents:httpcomponents-parent from 14 to 15

Changelog

Sourced from org.apache.httpcomponents:httpcomponents-parent's changelog.

Release 15

Change Log

  • Upgraded org.apache.apache to 40
  • Removed outdated profiles
  • Removed reporting section and report plugin version declarations
Commits

Updates org.conscrypt:conscrypt-openjdk-uber from 2.6.1 to 2.7.0

Release notes

Sourced from org.conscrypt:conscrypt-openjdk-uber's releases.

v2.7.0

Conscrypt Version 2.7.0.

This is a new release of conscrypt-openjdk, conscrypt-openjdk-uber and conscrypt-android on maven.

It includes the following changes:

  • TLS uses X25519MLKEM768 by default.
  • Encrypted Client Hello (ECH).
  • Composite-ML-DSA Signatures (with Ed25519, ECDSA, RSA PKCS1 and RSA PSS).
  • Hash-SLH-DSA Signatures (with SHA384).
  • Some cleanups.

v2.7-alpha

Conscrypt Version 2.7-alpha.

This is a new release of conscrypt-openjdk, conscrypt-openjdk-uber and conscrypt-android on maven.

It includes the following changes:

  • TLS uses X25519MLKEM768 by default.
  • Encrypted Client Hello (ECH).
  • Composite-ML-DSA Signatures (with Ed25519, ECDSA, RSA PKCS1 and RSA PSS).
  • Hash-SLH-DSA Signatures (with SHA384).
  • Some cleanups.

v2.6.3

This release uses the same Conscrypt source code as release 2.6.2, but the maven binary was compiled with this boringssl version: https://boringssl.googlesource.com/boringssl/+/refs/tags/0.20260616.0

This should fix google/conscrypt#1530

v2.6.2

Commits

Updates org.apache.logging.log4j:log4j-slf4j-impl from 2.25.4 to 2.26.1

Updates org.apache.logging.log4j:log4j-core from 2.25.4 to 2.26.1

Updates org.apache.logging.log4j:log4j-core from 2.25.4 to 2.26.1

Updates org.apache.maven.plugins:maven-enforcer-plugin from 3.6.2 to 3.6.3

Release notes

Sourced from org.apache.maven.plugins:maven-enforcer-plugin's releases.

3.6.3

🚀 New features and improvements

  • Make bannedDependencies report root and transitive dependency in case both are banned. (#940) @​hvoynov
  • Add enforceBytecodeVersion rule based on mojohaus (#968) @​cstamas
  • Improve formatting of deprecated API warning (#951) @​mthmulders

🐛 Bug Fixes

📝 Documentation updates

  • Document the banMavenDefaults option for the requirePluginVersions rule. (#936) @​rpkrajewski

👻 Maintenance

📦 Dependency updates

Commits
  • c7daff3 [maven-release-plugin] prepare release enforcer-3.6.3
  • ee46e78 Make bannedDependencies report root and transitive dependency in case both ar...
  • 0806924 Document the banMavenDefaults option for the requirePluginVersions rule. (#936)
  • 8e4f5b9 Add better enforceBytecodeVersion rule based on mojohaus (#968)
  • fd4b148 Add fix for 21.0.10.0.1 issue (#967)
  • f32d597 Deps: Parent POM 48 and align deps (#979)
  • df0f2a6 Bump commons-codec:commons-codec from 1.21.0 to 1.22.0 (#976)
  • 2da7a68 Add null checks for modelId in PluginWrapper
  • 91eb4d9 Bump commons-io:commons-io from 2.21.0 to 2.22.0 (#975)
  • b622245 Bump mavenVersion from 3.9.14 to 3.9.15 (#973)
  • Additional commits viewable in compare view

Updates com.github.siom79.japicmp:japicmp-maven-plugin from 0.25.6 to 0.26.2

Release notes

Sourced from com.github.siom79.japicmp:japicmp-maven-plugin's releases.

japicmp-base-0.26.2

  • Fix false CLASS_NOW_NOT_EXTENDABLE for added private constructors #527

japicmp-base-0.26.1

  • New change METHOD_RETURN_TYPE_COVARIANT_CHANGED #522

japicmp-base-0.26.0

  • No NPE when using Markdown-Processsor with byte-based archive #516

japicmp-base-0.25.7

  • Report incompatiblity in case a class changes from implementing a generic interface with raw types to concrete type parameters #507
Commits
  • e874564 [maven-release-plugin] prepare release japicmp-base-0.26.2
  • 06891fb upgraded version in *.md files to 0.26.2
  • 7239921 Add release notes for version 0.26.2
  • 797cd10 Merge pull request #527 from dossett/fix-private-constructor-extendability
  • 255f72f Fix extendability checks for version-specific constructors
  • 5186e1d Merge pull request #524 from siom79/release-v0.26.1
  • 2d326a4 [maven-release-plugin] prepare for next development iteration
  • 9303487 [maven-release-plugin] prepare release japicmp-base-0.26.1
  • a11fb26 upgraded version in *.md files to 0.26.1
  • 831b0f1 Add release notes for version 0.26.1
  • Additional commits viewable in compare view

Updates org.apache.maven.plugins:maven-toolchains-plugin from 3.2.0 to 3.3.0

Release notes

Sourced from org.apache.maven.plugins:maven-toolchains-plugin's releases.

3.3.0

🚀 New features and improvements

🐛 Bug Fixes

📝 Documentation updates

👻 Maintenance

📦 Dependency updates

... (truncated)

Commits
  • 52474c0 [maven-release-plugin] prepare release maven-toolchains-plugin-3.3.0
  • 39e84b2 Update toolchains documentation to use JSR-330 terminology and links (#165)
  • a213292 Bump apache/maven-gh-actions-shared/.github/workflows/release-drafter.yml
  • 2402d77 Replace Plexus XML configuration with JSR-330 annotated beans (#160)
  • ab80fc8 Bump apache/maven-gh-actions-shared/.github/workflows/stale.yml (#161)
  • 525f40c Bump apache/maven-gh-actions-shared/.github/workflows/pr-automation.yml (#163)
  • d3960b9 Bump apache/maven-gh-actions-shared/.github/workflows/maven-verify.yml (#164)
  • e0b39a6 Add .asf.yaml project metadata for ATR
  • e53bcec Add tag-template to release-drafter config
  • df6df08 Update site descriptors and download page content
  • Additional commits viewable in compare view

Updates tools.jackson.core:jackson-databind from 3.2.0 to 3.2.3

Commits
  • 4179a66 [maven-release-plugin] prepare release jackson-databind-3.2.3
  • 37c8a72 Prep for 3.2.3 release
  • 5fa7881 Merge branch '3.1' into 3.2
  • c9f17a2 Post-release dep version bump
  • 1ea1c40 [maven-release-plugin] prepare for next development iteration
  • 2968e8f [maven-release-plugin] prepare release jackson-databind-3.1.7
  • d61810b Prep for 3.1.7 release
  • e065a09 Merge branch '2.x' into 3.1
  • fd189a7 Merge branch '2.22' into 2.x
  • 211faf7 Post-release dep version bump
  • Additional commits viewable in compare view

Updates org.apache.maven:apache-maven from 3.9.14 to 3.10.0

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the all group with 9 updates:

| Package | From | To |
| --- | --- | --- |
| [org.apache.httpcomponents:httpcomponents-parent](https://github.com/apache/httpcomponents-parent) | `14` | `15` |
| [org.conscrypt:conscrypt-openjdk-uber](https://github.com/google/conscrypt) | `2.6.1` | `2.7.0` |
| org.apache.logging.log4j:log4j-slf4j-impl | `2.25.4` | `2.26.1` |
| org.apache.logging.log4j:log4j-core | `2.25.4` | `2.26.1` |
| [org.apache.maven.plugins:maven-enforcer-plugin](https://github.com/apache/maven-enforcer) | `3.6.2` | `3.6.3` |
| [com.github.siom79.japicmp:japicmp-maven-plugin](https://github.com/siom79/japicmp) | `0.25.6` | `0.26.2` |
| [org.apache.maven.plugins:maven-toolchains-plugin](https://github.com/apache/maven-toolchains-plugin) | `3.2.0` | `3.3.0` |
| [tools.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) | `3.2.0` | `3.2.3` |
| org.apache.maven:apache-maven | `3.9.14` | `3.10.0` |


Updates `org.apache.httpcomponents:httpcomponents-parent` from 14 to 15
- [Changelog](https://github.com/apache/httpcomponents-parent/blob/master/RELEASE_NOTES.txt)
- [Commits](https://github.com/apache/httpcomponents-parent/commits)

Updates `org.conscrypt:conscrypt-openjdk-uber` from 2.6.1 to 2.7.0
- [Release notes](https://github.com/google/conscrypt/releases)
- [Commits](google/conscrypt@2.6.1...2.7.0)

Updates `org.apache.logging.log4j:log4j-slf4j-impl` from 2.25.4 to 2.26.1

Updates `org.apache.logging.log4j:log4j-core` from 2.25.4 to 2.26.1

Updates `org.apache.logging.log4j:log4j-core` from 2.25.4 to 2.26.1

Updates `org.apache.maven.plugins:maven-enforcer-plugin` from 3.6.2 to 3.6.3
- [Release notes](https://github.com/apache/maven-enforcer/releases)
- [Commits](apache/maven-enforcer@enforcer-3.6.2...enforcer-3.6.3)

Updates `com.github.siom79.japicmp:japicmp-maven-plugin` from 0.25.6 to 0.26.2
- [Release notes](https://github.com/siom79/japicmp/releases)
- [Changelog](https://github.com/siom79/japicmp/blob/master/release.py)
- [Commits](siom79/japicmp@japicmp-base-0.25.6...japicmp-base-0.26.2)

Updates `org.apache.maven.plugins:maven-toolchains-plugin` from 3.2.0 to 3.3.0
- [Release notes](https://github.com/apache/maven-toolchains-plugin/releases)
- [Commits](apache/maven-toolchains-plugin@maven-toolchains-plugin-3.2.0...maven-toolchains-plugin-3.3.0)

Updates `tools.jackson.core:jackson-databind` from 3.2.0 to 3.2.3
- [Commits](FasterXML/jackson-databind@jackson-databind-3.2.0...jackson-databind-3.2.3)

Updates `org.apache.maven:apache-maven` from 3.9.14 to 3.10.0

---
updated-dependencies:
- dependency-name: org.apache.httpcomponents:httpcomponents-parent
  dependency-version: '15'
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: all
- dependency-name: org.conscrypt:conscrypt-openjdk-uber
  dependency-version: 2.7.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: org.apache.logging.log4j:log4j-slf4j-impl
  dependency-version: 2.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: org.apache.logging.log4j:log4j-core
  dependency-version: 2.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: org.apache.logging.log4j:log4j-core
  dependency-version: 2.26.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: org.apache.maven.plugins:maven-enforcer-plugin
  dependency-version: 3.6.3
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: com.github.siom79.japicmp:japicmp-maven-plugin
  dependency-version: 0.26.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: org.apache.maven.plugins:maven-toolchains-plugin
  dependency-version: 3.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: tools.jackson.core:jackson-databind
  dependency-version: 3.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: org.apache.maven:apache-maven
  dependency-version: 3.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Oct 1, 2026
@dependabot @github

dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Oct 2, 2026
@dependabot
dependabot Bot deleted the dependabot/maven/all-1fb4a537e2 branch October 2, 2026 07:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants