Skip to content

Bump the java-patch-and-minor group across 1 directory with 4 updates - #194

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/java-patch-and-minor-f8d62c1e41
Open

Bump the java-patch-and-minor group across 1 directory with 4 updates#194
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/java-patch-and-minor-f8d62c1e41

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 29, 2026

Copy link
Copy Markdown
Contributor

Bumps the java-patch-and-minor group with 4 updates in the / directory: com.microsoft.signalr:signalr, org.apache.httpcomponents.client5:httpclient5, com.fasterxml.jackson.core:jackson-databind and com.github.spotbugs:spotbugs-maven-plugin.

Updates com.microsoft.signalr:signalr from 8.0.29 to 8.0.30

Release notes

Sourced from com.microsoft.signalr:signalr's releases.

.NET 8.0.30

Release

What's Changed

New Contributors

Full Changelog: dotnet/aspnetcore@v8.0.29...v8.0.30

Commits
  • f336360 Merged PR 63140: Revert System.Security.Cryptography.Xml to the released version
  • 8577938 Merged PR 63133: [internal/release/8.0] Add .npmrc files next to yarn.lock files
  • b4e3030 Revert "TEMP: Add verbose yarn/npm restore diagnostics for ws@7.5.11 investig...
  • c73d33d Suppress NU1902 AngleSharp audit warning per-project instead of globally
  • 21c07ef Update stale yarn.lock files to resolve ws@^7.5.11
  • bd988fa TEMP: Add verbose yarn/npm restore diagnostics for ws@7.5.11 investigation
  • a64050d TEMP: Suppress NU1902 AngleSharp audit warning for CI diagnosis
  • aafcb55 Add .npmrc files next to yarn.lock files
  • f936636 Merged PR 63080: merge from public
  • 948ce52 Update dependencies from https://github.com/dotnet/arcade build 20260721.5 (#...
  • Additional commits viewable in compare view

Updates org.apache.httpcomponents.client5:httpclient5 from 5.6.3 to 5.6.4

Changelog

Sourced from org.apache.httpcomponents.client5:httpclient5's changelog.

Release 5.6.4

This maintenance release fixes SSL parameter application in the async TLS upgrade strategy.

Change Log

  • BearerScheme to reject control characters in bearer token. Contributed by Javid Khan

  • Corrects application of SSL parameters in the async TLS upgrade method. Contributed by Oleg Kalnichevski

Commits
  • 36508ce HttpClient 5.6.4 release
  • 59b3d2e Updated release notes for HttpClient 5.6.4 release
  • c0af759 reject control characters in bearer token in BearerScheme
  • 2422b6c Corrects application of SSL parameters in the async TLS upgrade method
  • 66452ea Upgraded HttpClient version to 5.6.4-SNAPSHOT
  • See full diff in compare view

Updates com.fasterxml.jackson.core:jackson-databind from 2.22.1 to 2.22.2

Commits
  • 25b2a22 [maven-release-plugin] prepare release jackson-databind-2.22.2
  • bab1c1a Prep for 2.22.2 release
  • bc03cf8 Merge branch '2.21' into 2.22
  • 83379fb Merge branch '2.20' into 2.21
  • 0d400c9 Merge branch '2.19' into 2.20
  • ce36a27 Merge branch '2.18' into 2.19
  • 7a209e1 Post-release dep version bump
  • a432707 [maven-release-plugin] prepare for next development iteration
  • 176df1d [maven-release-plugin] prepare release jackson-databind-2.18.10
  • 7785f5f Prep for 2.18.10 release
  • Additional commits viewable in compare view

Updates com.github.spotbugs:spotbugs-maven-plugin from 4.10.3.0 to 4.10.4.0

Release notes

Sourced from com.github.spotbugs:spotbugs-maven-plugin's releases.

spotbugs-maven-plugin-4.10.4.0

What's Changed

New Contributors

Full Changelog: spotbugs/spotbugs-maven-plugin@spotbugs-maven-plugin-4.10.3.0...spotbugs-maven-plugin-4.10.4.0

Commits
  • 698cfa7 [maven-release-plugin] prepare release spotbugs-maven-plugin-4.10.4.0
  • f12b09f [pom] Update spotbugs core to 4.10.4
  • 2fc78c6 Merge pull request #1500 from hazendaz/master
  • 87e41d6 Add more missing javadocs throughout
  • b2149c3 [docs] Add missing javadocs to rest of integration tests
  • 6cdda40 Merge pull request #1499 from hazendaz/master
  • d9d54a6 Merge pull request #1498 from spotbugs/renovate/byte-buddy.version
  • 54738d7 Require maven 3.8.9 or better
  • d3646ee Update byte-buddy.version to v1.18.12
  • 011cbec Merge pull request #1497 from hazendaz/master
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the java-patch-and-minor group with 4 updates in the / directory: [com.microsoft.signalr:signalr](https://github.com/dotnet/aspnetcore), [org.apache.httpcomponents.client5:httpclient5](https://github.com/apache/httpcomponents-client), [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) and [com.github.spotbugs:spotbugs-maven-plugin](https://github.com/spotbugs/spotbugs-maven-plugin).


Updates `com.microsoft.signalr:signalr` from 8.0.29 to 8.0.30
- [Release notes](https://github.com/dotnet/aspnetcore/releases)
- [Changelog](https://github.com/dotnet/aspnetcore/blob/main/docs/ReleasePlanning.md)
- [Commits](dotnet/aspnetcore@v8.0.29...v8.0.30)

Updates `org.apache.httpcomponents.client5:httpclient5` from 5.6.3 to 5.6.4
- [Changelog](https://github.com/apache/httpcomponents-client/blob/rel/v5.6.4/RELEASE_NOTES.txt)
- [Commits](apache/httpcomponents-client@rel/v5.6.3...rel/v5.6.4)

Updates `com.fasterxml.jackson.core:jackson-databind` from 2.22.1 to 2.22.2
- [Commits](FasterXML/jackson-databind@jackson-databind-2.22.1...jackson-databind-2.22.2)

Updates `com.github.spotbugs:spotbugs-maven-plugin` from 4.10.3.0 to 4.10.4.0
- [Release notes](https://github.com/spotbugs/spotbugs-maven-plugin/releases)
- [Commits](spotbugs/spotbugs-maven-plugin@spotbugs-maven-plugin-4.10.3.0...spotbugs-maven-plugin-4.10.4.0)

---
updated-dependencies:
- dependency-name: com.microsoft.signalr:signalr
  dependency-version: 8.0.30
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: java-patch-and-minor
- dependency-name: org.apache.httpcomponents.client5:httpclient5
  dependency-version: 5.6.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: java-patch-and-minor
- dependency-name: com.fasterxml.jackson.core:jackson-databind
  dependency-version: 2.22.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: java-patch-and-minor
- dependency-name: com.github.spotbugs:spotbugs-maven-plugin
  dependency-version: 4.10.4.0
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: java-patch-and-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file security Security-related changes, fixes, or advisories labels Aug 29, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner August 29, 2026 22:53
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file security Security-related changes, fixes, or advisories labels Aug 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file security Security-related changes, fixes, or advisories

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants