Update maven - #158
Open
renovate[bot] wants to merge 1 commit into
Open
Conversation
renovate
Bot
force-pushed
the
renovate-main/maven
branch
2 times, most recently
from
July 27, 2026 12:04
a0f7900 to
1779917
Compare
renovate
Bot
force-pushed
the
renovate-main/maven
branch
4 times, most recently
from
July 27, 2026 13:53
d59a141 to
2447c1f
Compare
renovate
Bot
force-pushed
the
renovate-main/maven
branch
4 times, most recently
from
August 2, 2026 01:12
c0c1758 to
67689d3
Compare
renovate
Bot
force-pushed
the
renovate-main/maven
branch
6 times, most recently
from
August 7, 2026 13:45
0336c82 to
6a01971
Compare
renovate
Bot
force-pushed
the
renovate-main/maven
branch
from
August 9, 2026 07:10
6a01971 to
58c4661
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1.7.3→1.8.04.8.184→4.8.1863.17.0→3.18.11.22.2→1.23.13.33.2.1→3.33.33.33.2.1→3.33.33.33.2.1→3.33.31.79.0→1.81.01.79.0→1.81.01.79.0→1.81.04.19.2→4.19.34.19.2→4.19.33.0.3→3.1.03.0.3→3.1.03.0.3→3.1.03.0.3→3.1.03.33.2.1→3.33.33.33.2.1→3.33.33.33.2.1→3.33.310.0.1→10.1.010.0.1→10.1.010.0.1→10.1.0Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
jsoup: Cleaner may expose markup with custom raw-text elements
CVE-2026-71497 / GHSA-pmhh-3w7g-xqp8
More information
Details
When a custom
Safelistpermits certain raw-text elements, jsoup may incorrectly sanitize malformed HTML containing a tag name that ends in a control character. The tag may acquire the parsing behavior of a different element, causing content that should remain text to be emitted as active markup after serialization and potentially allowing XSS.jsoup’s built-in Safelists are unaffected.
Patches
Upgrade to jsoup 1.23.1.
Workarounds
Until upgrading, do not permit raw-text elements in custom Safelists used to clean untrusted HTML.
Additional security considerations
This fix addresses malformed tag-name handling only.
Permitting raw-text elements in a custom
Safelistdoes not make their contents inherently safe. For example, applications that permitstylemust apply appropriate CSS safeguards separately, because jsoup does not parse or sanitize CSS.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
jsoup: Cleaner may expose markup with custom raw-text elements
CVE-2026-71497 / GHSA-pmhh-3w7g-xqp8
More information
Details
When a custom
Safelistpermits certain raw-text elements, jsoup may incorrectly sanitize malformed HTML containing a tag name that ends in a control character. The tag may acquire the parsing behavior of a different element, causing content that should remain text to be emitted as active markup after serialization and potentially allowing XSS.jsoup’s built-in Safelists are unaffected.
Patches
Upgrade to jsoup 1.23.1.
Workarounds
Until upgrading, do not permit raw-text elements in custom Safelists used to clean untrusted HTML.
Additional security considerations
This fix addresses malformed tag-name handling only.
Permitting raw-text elements in a custom
Safelistdoes not make their contents inherently safe. For example, applications that permitstylemust apply appropriate CSS safeguards separately, because jsoup does not parse or sanitize CSS.Severity
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:NReferences
This data is provided by OSV and the GitHub Advisory Database (CC-BY 4.0).
Release Notes
mojohaus/flatten-maven-plugin (org.codehaus.mojo:flatten-maven-plugin)
v1.8.0Compare Source
🚀 New features and improvements
🐛 Bug Fixes
🔧 Build
📦 Dependency updates
lysine-dev/okio (com.squareup.okio:okio)
v3.18.12026-07-28
the new
base64()function, we inadvertently changed the binary signature! Ugh! This is nowfixed and we've automated binary-compatibility checking for Kotlin/Native going forward.
v3.18.02026-07-21
AssetFileSystem.exists()when the underlying storage throws aFileNotFoundException.preopen. The platform behavior recently changed inNodeJS, causing our
WasiFileSystemto be unable to access files!BufferedSource.readUInt(),BufferedSink.writeUInt(), and similar functions forUByte,UShortandULong. Also add support for unsigned and little-endian.BufferedSink.utf8Appendable(). Use this to adapt an Okio sink to anAppendable.Source.limit()returns a wrapped source with a strict limit on how many bytes arereturned.
ByteString.equals(other, constantTime)for subtle defense against timing attacks.jhy/jsoup (org.jsoup:jsoup)
v1.23.1Improvements
Parser#setTrackPosition(true)). Source ranges are now stored in compact parser-owned span records instead of node and attribute user data, andPositionobjects are created lazily when source ranges are read. This cuts tracked DOM retained size by about 50-60% on representative benchmark documents, while keepingNode#sourceRange(),Element#endSourceRange(), andAttribute#sourceRange()behavior intact. #2498Element#classList(), an immutable snapshot of an element's class names in attribute order. UsehasClass()when you just need to test for one class,classList()when you want to read or iterate classes without needing a mutable result, andclassNames()when you want the existing mutable, deduplicated set that can be written back withclassNames(Set). The class APIs now share an HTML-whitespace scanner, which also makesclassNames()faster and lighter on allocation, especially when walking many elements without class names. #2500select,foreignObject, andtemplate. #2501<noscript>fallback markup is now parsed into an inspectable DOM subtree in both the document head and body. The fallback acts as a contained parsing island, so malformed markup cannot disrupt the surrounding document structure, while normal HTML tokenization still applies within it. This also improves round-trip serialization. #2537CookieStorecontinue to follow their configured scope. #2540AppendablewithNode#outerHtml(Appendable), without first creating aString. This complementsElement#html(Appendable), which appends inner HTML only. #2532re2jregular expression engine, stack overflows caused by complex selector patterns are now normalized to aValidationExceptionwith aPattern complexity errormessage. #2548Bug Fixes
<title><p>Foo</TiTLE>and<textarea><img src=x></TeXtArEa>now keep the tag-shaped content as text instead of promoting it to markup. #2503W3CDomXML conversion so plain XML elements don't serialize with the reserved XML namespace as the default namespace. Explicit XML namespaces andxml:*attributes are still preserved. #2504Locationis followed only for 301, 302, 303, 307, and 308 responses. Streamed request bodies are not buffered; if an automatic redirect requires replaying one, execution fails, so the caller can resend with a fresh stream. #2540rel=nofollow. #2543Build Changes
mvn clean verifydrops from ~ 1m18s to ~ 21 seconds.quarkusio/quarkus (io.quarkus:quarkus-extension-maven-plugin)
v3.33.3Compare Source
Complete changelog
io.quarkus.security.PermissionsAllowed@ConfigPropertywith Google Cloud Function throws Exception when executing QuarkusTest+to space in file pathsQuarkusEntryPointpath decoding issuelogicalFilePathin Native-ModeQuarkusServerFileBodyHandlerleaks temp files when any ReaderInterceptor is registeredorderedexecution for@RunOnVertxContext@ServerExceptionMapperwith generic base class drops other exception mappers at runtime@ServerExceptionMapperbridge method handling for generic typesReflectiveClassConditionBuildItemRecord, succeeds when swapped toObjectjava.lang.Recordas Lambda return typeFuturein Smallrye HealthimageBuildandimagePushuse this output of:jandexwithout declaring dependencyClientRedirectHandler@CancellableonContainerResponseFiltergrpc/grpc-java (io.grpc:grpc-stub)
v1.81.0In this release we drop support for Android API level 22 or lower (Lollipop or earlier), following Google Play Service’s discontinued updates for Lollipop (API levels 21 & 22) and now requires a minimum of API level 23 (Android 6.0 Marshmallow).
API Changes
Behavior Changes
0675f70). DnsNameResolver ignores re-resolution requests on OpenJDK-like platforms if it has been too soon since the last DNS query because InetAddress.getAllByName() has a cache with a fixed entry lifetime, but this logic was disabled for Android which does not have that style of cache. Android’s cache uses the result TTL, which will rarely be less than 30 seconds. This change would probably be most noticeable when 1) changing to a different network (e.g., from wifi to mobile), 2) the server has different addresses for different networks, and 3) the app is not using AndroidChannelBuilder with anandroid.context.Context. For reference, it seems Chrome caches for 1 minutee39c38b). Previously each channel using the xds name resolver would create its own channel to communicate with the control plane. Now they share control plane channels, while still having separate RPCsBug Fixes
ManagedChannelOrphanWrappercould incorrectly log a "not shutdown properly" warning during garbage collection when using directExecutor(). (#12705) (d459338)typeUrl. (#12740) (eac9fe9)backend_service. This ensures xDS load balancing metrics are reported accurately. (#12735)New Features
0e39b29). This CallOption is copied by grpc-opentelemetry to thegrpc.client.call.customlabel as defined by gRFC A108. See also the gRPC OpenTelemetry Metrics guide (update in-progress)AdvancedTlsX509KeyManagerso that developers can now preserve and use key aliases when dynamically reloading TLS certificates. (#12686)Documentation
a3a9ffc) (#12726) (65ae2ef)3ed732f)Dependencies
16e17ab). Google-auth-library: 1.42.1, animal-sniffer: 1.27, assertj-core:3.27.7, error_prone_annotations:2.48.0, proto-google-common-protos:2.64.1, google-cloud-logging:3.23.10, jetty-http2-server:12.1.7, jetty-ee10-servlet:12.1.7, lincheck:3.4, opentelemetry-api:1.60.1, opentelemetry-exporter-prometheus:1.60.1-alpha, opentelemetry-gcp-resources:1.54.0-alpha, opentelemetry-sdk-extension-autoconfigure:1.60.1, opentelemetry-sdk-testing:1.60.1, robolectric:4.16.1, tomcat-embed-core:10.1.52, tomcat-embed-core9: 9.0.115,1528f80)Thanks to
v1.80.0API Changes
eae16b2)Bug Fixes
024fdd0)core: Fixed a race condition in RetriableStream where inFlightSubStreams counting could become inconsistent during concurrent retry and deadline events. This ensures that client calls (such as blockingUnaryCall) do not hang indefinitely and correctly receive a close signal. (#12649) (
73abb48)Improvements
470219f). This allows gRPC to avoid reflection, and the need to specify -keeps for various class’s constructors.Upgrade to protobuf 33.4 (#12615) (
50c18f1)31fdb6c)9903488)ac44e96)New Features
34dd290). This finishes the gRFC A113 pick_first: Weighted Random Shuffling supportThanks to
datastax/java-driver (org.apache.cassandra:java-driver-metrics-micrometer)
v4.19.3Compare Source
Release announcement
Changelog:
springdoc/springdoc-openapi (org.springdoc:springdoc-openapi-starter-common)
v3.1.0Compare Source
Added
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.