Skip to content

chore(deps): bump the all-minor-and-patch-updates group across 1 directory with 21 updates - #155

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot-maven-all-minor-and-patch-updates-8468856318
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot-maven-all-minor-and-patch-updates-8468856318

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the all-minor-and-patch-updates group with 21 updates in the / directory:

Package From To
org.springframework.boot:spring-boot-starter-parent 4.1.0 4.1.1
io.netty:netty-bom 4.2.16.Final 4.2.18.Final
io.swagger.core.v3:swagger-core-jakarta 2.2.52 2.2.55
io.swagger.core.v3:swagger-annotations-jakarta 2.2.52 2.2.55
io.swagger.core.v3:swagger-models-jakarta 2.2.52 2.2.55
io.swagger.core.v3:swagger-annotations-jakarta 2.2.52 2.2.55
io.swagger.core.v3:swagger-models-jakarta 2.2.52 2.2.55
tools.jackson.core:jackson-databind 3.1.5 3.2.3
org.apache.camel.springboot:camel-spring-boot-bom 4.21.0 4.22.1
org.apache.httpcomponents.client5:httpclient5 5.6.3 5.6.4
org.projectlombok:lombok 1.18.46 1.18.48
com.tngtech.archunit:archunit-junit5 1.4.2 1.5.1
org.springdoc:springdoc-openapi-starter-webmvc-ui 3.0.3 3.1.1
io.swagger.parser.v3:swagger-parser 2.1.45 2.1.48
com.schibsted.spt.data:jslt 0.1.14 0.1.15
org.sonarsource.scanner.maven:sonar-maven-plugin 5.7.0.6970 5.8.0.7211
org.flywaydb:flyway-maven-plugin 13.0.0 13.8.0
org.apache.maven.plugins:maven-compiler-plugin 3.15.0 3.16.0
org.codehaus.mojo:xml-maven-plugin 1.2.1 1.2.2
com.github.spotbugs:spotbugs-maven-plugin 4.10.3.0 4.10.4.1
com.diffplug.spotless:spotless-maven-plugin 3.8.0 3.10.2
org.apache.maven:apache-maven 3.9.9 3.9.16
org.apache.maven.wrapper:maven-wrapper 3.3.2 3.3.4

Updates org.springframework.boot:spring-boot-starter-parent from 4.1.0 to 4.1.1

Release notes

Sourced from org.springframework.boot:spring-boot-starter-parent's releases.

v4.1.1

⚠️ Attention Required

  • Spring Boot's Gradle plugin no longer automatically configures gRPC when the Protobuf plugin is applied. This behavior caused problems for those using Protobuf without gRPC. To opt in to the configuration of gRPC, configure the protobuf extension with the grpc plugin using an empty block. The Spring Boot Gradle plugin will then automatically configure the use of protoc-gen-grpc-java as before. #50822

🐞 Bug Fixes

  • Kafka consumer-specific security protocol is not taken into account #51369
  • Structured logging: a failed JSON encode corrupts the next log event written on the same thread #51156
  • Micrometer registries pin the application context #51135
  • Temporary file is not deleted when ExportedImageTar construction fails #51132
  • Metadata annotation processor ignores getter-level @NestedConfigurationProperty for records #51098
  • spring-boot-h2-console pulls servlet-api as transitive dependency #51095
  • PropertiesLauncher does not log nested archive paths #51089
  • Methods that return the result of Map#remove are not declared with a @Nullable return type #51087
  • NativeImageResourceProvider flattens Flyway migration paths in subdirectories #50964
  • Fix ordering of Kotlinx Serialization CodecCustomizer #50961
  • JarFile is not closed when finding main class from archive #50959
  • Application-managed JUL bridge handler should only be removed if installed #50950
  • CloudFoundry reactive auto-configuration should not require a WebClient.Builder bean to be defined #50944
  • Context refresh fails on reactive Cloud Foundry when using Actuator without spring-boot-health #50942
  • Resources are not cleaned up when resolving an image that is not yet present in the builder #50941
  • GraphQlWebMvcAutoConfiguration should apply customizers in order #50914
  • Auto-configured RedisMessageListenerContainer does not use virtual threads when spring.threads.virtual.enabled is true #50884
  • Context refresh fails when using Actuator on Jersey without spring-boot-health #50872
  • Context refresh fails on Cloud Foundry when using Actuator without spring-boot-health #50871
  • IllegalStateException when binding properties to a @Validated class that contains a map whose value type is a wildcard #50856
  • High number of connections due to Mongo health indicator #50852
  • Inconsistent handling of empty string values of spring.security.oauth2.resourceserver.jwt issuer-uri and jwk-set-uri #50849
  • Return type nullability of ApplicationContextAssert's getBean methods does not indicate that bean may be null #50845
  • PropertiesWebClientHttpServiceGroupConfigurer has highest precedence, preventing other configurers from being ordered ahead of it #50843
  • Exposing gRPC test server port should backoff if gRPC is not present #50825
  • JpaBaseConfiguration#entityManagerConfiguration can cause a dependency loop on beans declaring AsyncTaskExecutor #50801
  • spring.grpc.server.health.include-overall-health is not taken into account #50799
  • Setting 'server.servlet.session.cookie.partitioned' to false still emits the 'Partitioned' cookie attribute #50790
  • Managed version of Prometheus Client is not aligned with Micrometer's micrometer-registry-prometheus #50780
  • Map properties bound from empty strings fail with ConverterNotFoundException #50773
  • Protobuf Common Protos should not be a managed dependency #50772
  • An application that depends on spring-boot-security-oauth2-resource-server may fail to start with a ClassNotFoundException when Reactor is on the classpath but WebFlux is not #50764
  • W3CHeaderParser's decoding is not compliant with RFC 3986 #50650

📔 Documentation

  • Description of spring.graphql.websocket.connection-init-timeout does not render correctly in the reference guide #51348
  • spring.profiles.group should have a 'spring-profile-name' hint provider #51284
  • Remove reference to removed InfluxDB auto-configuration #51176
  • Use JacksonJsonSerde in Kafka Streams documentation #51161
  • Document alternatives to HttpMessageConverters #51129
  • Fix stale type reference for OTLP logging transport metadata #51119
  • Metadata for spring.test.mockmvc.htmlunit.url declares the wrong type #51115

... (truncated)

Commits
  • 6fdf67e Release 4.1.1
  • fde599b Upgrade to Spring Pulsar 2.0.7
  • 9daa58f Upgrade to Spring HATEOAS 3.1.2
  • 353993e Upgrade to Spring Data Bom 2026.0.1
  • 24ba596 Upgrade to Spring Session 4.1.1
  • 5cb5c29 Upgrade to Spring Security 7.1.1
  • 4adc8eb Upgrade to Spring LDAP 4.1.1
  • 4d9c19c Upgrade to Spring Kafka 4.1.1
  • f30f612 Upgrade to Spring Integration 7.1.1
  • b930283 Upgrade to Spring gRPC 1.1.1
  • Additional commits viewable in compare view

Updates io.netty:netty-bom from 4.2.16.Final to 4.2.18.Final

Release notes

Sourced from io.netty:netty-bom's releases.

netty-4.2.18.Final

Security fixes

  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-http (SPDY)
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-http (HTTP/1.1)
  • CVE-2026-XXXXX : denial of service vector in io.netty:netty-codec-http2
  • CVE-2026-XXXXX : improper certificate validation in io.netty:netty-handler-ssl-ocsp
  • CVE-2026-XXXXX : memory leak in io.netty:netty-codec-stomp
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-http
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http3
  • CVE-2026-XXXXX : denial of service vector in io.netty:netty-codec-stomp
  • CVE-2026-XXXXX : parser desync/response smuggling in io.netty:netty-codec-memcache
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-http3
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-http3
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-http3
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-smtp
  • CVE-2026-XXXXX : memory leak in io.netty:netty-codec-haproxy
  • CVE-2026-XXXXX : request smuggling in io.netty:netty-codec-http (RTSP)
  • CVE-2026-XXXXX : request smuggling in io.netty:netty-codec-http (HTTP/1)
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http2
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http (HTTP/1)
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http3
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http3 and in io.netty:netty-codec-http2
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http2
  • CVE-2026-XXXXX : improper hostname verification in io.netty:netty-codec-classes-quic
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-redis
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http (HTTP/1.1)
  • CVE-2026-XXXXX : request smuggling vector in io.netty:netty-codec-http (HTTP/1.1)
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-mqtt
  • CVE-2026-XXXXX : improper CRLF neutralization in io.netty:netty-codec-smtp
  • CVE-2026-XXXXX : improper certificate validation in io.netty:netty-handler-ssl-ocsp
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http2

Compatibility Notes

A number of security fixes have added additional validation and impose new resource usage limits, which may cause existing workloads to fail or be rejected. We recommend that you test your systems thoroughly as part of your Netty upgrade.

Two specific changes are worth calling out:

QUIC now explicitly requires X509ExtendedTrustManager when hostname verification is enabled. Previously, when configuring QUIC with an endpoint identification algorithm and an X509TrustManager, hostname verification would be silently skipped. This is now considered a misconfiguration and an exception will be thrown.

HTTP/2 header value validation is now enabled by default. HTTP/2 header name validation has always been enabled by default, with an option to disable it, but HTTP/2 header value validation has been disabled by default until now. Configuration options still exist to disable this, but validation of HTTP header names and values are now both opt-in by default rather than opt-out.

What's Changed

... (truncated)

Commits
  • 2521f49 [maven-release-plugin] prepare release netty-4.2.18.Final
  • 6fd5327 HTTP/1 absolute-form Host mismatch is translated to HTTP/3 :authority, overri...
  • c44a052 SPDY: SpdySessionHandler must limit the concurrent streams
  • 374d965 HTTP: Limit the maximum number of concurrent pipelined requests
  • 7e8b325 HTTP/2: Limit HPACK encoding table size
  • e3ebf70 OCSP: Correctly handle that nextUpdate is optional
  • 5388535 STOMP: Correctly release partial content on handler removal
  • 3a80f5a WebSockets: Enforce a limit for the max pipelined requests in WebSocketServer...
  • 1b6ea48 HTTP3: Correctly handle ":authority" and "host" headers
  • 3630659 STOMP codec content-length long-to-int truncation causes infinite decode loop...
  • Additional commits viewable in compare view

Updates io.swagger.core.v3:swagger-core-jakarta from 2.2.52 to 2.2.55

Updates io.swagger.core.v3:swagger-annotations-jakarta from 2.2.52 to 2.2.55

Updates io.swagger.core.v3:swagger-models-jakarta from 2.2.52 to 2.2.55

Updates io.swagger.core.v3:swagger-annotations-jakarta from 2.2.52 to 2.2.55

Updates io.swagger.core.v3:swagger-models-jakarta from 2.2.52 to 2.2.55

Updates tools.jackson.core:jackson-databind from 3.1.5 to 3.2.3

Commits
  • 4179a66 [maven-release-plugin] prepare release jackson-databind-3.2.3
  • 37c8a72 Prep for 3.2.3 release
  • 5fa7881 Merge branch '3.1' into 3.2
  • c9f17a2 Post-release dep version bump
  • 1ea1c40 [maven-release-plugin] prepare for next development iteration
  • 2968e8f [maven-release-plugin] prepare release jackson-databind-3.1.7
  • d61810b Prep for 3.1.7 release
  • e065a09 Merge branch '2.x' into 3.1
  • fd189a7 Merge branch '2.22' into 2.x
  • 211faf7 Post-release dep version bump
  • Additional commits viewable in compare view

Updates org.apache.camel.springboot:camel-spring-boot-bom from 4.21.0 to 4.22.1

Updates org.apache.httpcomponents.client5:httpclient5 from 5.6.3 to 5.6.4

Changelog

Sourced from org.apache.httpcomponents.client5:httpclient5's changelog.

Release 5.6.4

This maintenance release fixes SSL parameter application in the async TLS upgrade strategy.

Change Log

  • BearerScheme to reject control characters in bearer token. Contributed by Javid Khan

  • Corrects application of SSL parameters in the async TLS upgrade method. Contributed by Oleg Kalnichevski

Commits
  • 36508ce HttpClient 5.6.4 release
  • 59b3d2e Updated release notes for HttpClient 5.6.4 release
  • c0af759 reject control characters in bearer token in BearerScheme
  • 2422b6c Corrects application of SSL parameters in the async TLS upgrade method
  • 66452ea Upgraded HttpClient version to 5.6.4-SNAPSHOT
  • See full diff in compare view

Updates org.projectlombok:lombok from 1.18.46 to 1.18.48

Changelog

Sourced from org.projectlombok:lombok's changelog.

v1.18.48 (September 1st, 2026)

  • BREAKING CHANGE/BUGFIX: @Builder(builderClassName = "Builder") now generates an error, because the type names collide. #3857 (found after release)
  • PLATFORM: JDK27 support added #4072.
  • BUGFIX: @SneakyThrows usage on JDK26 no longer results in class files that require lombok.jar to be on the runtime classpath (which should not be neccessary). #4040.
  • FEATURE: New config key lombok.checkReturnValueAnnotation (values: none, lombok; default: none) lets lombok generate @lombok.CheckReturnValue on generated methods where the return value should not be ignored, such as @With methods and @Builder.build(). A future lombok release may flip the default to lombok. #4013.
  • PROMOTION: @SuperBuilder has been promoted to the main package. Otherwise, no changes have been made to the annotation. The old experimental annotation will remain for a few versions, at which point it will be marked as a deprecated annotation. Eventually it'll be removed. If you had lombok.config configuration for this annotation, the configuration keys for this feature have been renamed. #2209.
  • OLD-CRUFT: lombok.experimental.Wither and lombok.Delegate are deprecated remnants; these features were moved (to respectively lombok.With and lombok.experimental.Delegate over 5 years ago. They are now removed entirely. If your project is dependent on an older version of lombok which still has those; fret not, lombok still processes these annotations. It just no longer includes them in the jar.
  • FEATURE: CheckerFramework: Lombok now adds @SideEffectFree to constructors it makes if you have enabled checker framework via lombok.config.
  • BUGFIX: CheckerFramework: Lombok would add @SideEffectFree to the build() method of any generated builder, even if it is a builder for invoking a method; in that case, the side-effect-free nature of build() mirrors the side-effect-free nature of the method invocation you've built. Lombok now checks if the method it generated a builder for is side effect free / 'check return type'.
Commits
  • b48657c [version] pre-release version bump v1.18.48
  • d1d0039 Merge branch 'jdk27'
  • 1a23dad [review][refactor] No meaningful changes: Improved comments, javadoc, and cle...
  • 40cdde8 [changelog] JDK27 support
  • 25eae29 Add Danish Nawab to AUTHORS
  • 10ab92b Support JDK27: end positions moved from EndPosTable to JCTree.endpos
  • af01b7a Document the new configuration syntax for listy things
  • 1be3857 There is no more HtAccess
  • 405985d Semantic sections for website
  • 04b7340 [trivial] fixing some outdated tests (tests were broken, not lombok).
  • Additional commits viewable in compare view

Updates com.tngtech.archunit:archunit-junit5 from 1.4.2 to 1.5.1

Release notes

Sourced from com.tngtech.archunit:archunit-junit5's releases.

ArchUnit 1.5.1

Bug fixes

Core

Internal Improvements

ArchUnit 1.5.0

Enhancements

Core

  • Support Java 27 / class file major version 71 (#1618)
  • Improve descriptions of JavaAccess.Predicates.originOwner and JavaAccess.Predicates.targetOwner (#1603; thanks to @​StefanGraeber 👋)
  • Expose information on sealed classes via JavaClass: isSealed() and getPermittedSubclasses() (#1677)
  • Consider dependencies from caught exceptions (#1555; thanks to @​bannmann 👋)
  • ImportOption.DoNotIncludeTests and OnlyIncludeTests consider tests in custom Gradle source sets (#1660; thanks to @​Develop-KIM 👋)

Lang

  • ArchConditions offers new ArchCondition<JavaClass> haveAnyDependenciesThat(DescribedPredicate<Dependency>) (#1580; thanks to @​wakingrufus 👋)

Library

  • ArchitectureMetrics.lakosMetrics is computed much more performantly (#1629; thanks to @​ThanosTsiamis 👋)
  • TextFileBasedViolationStore is now thread-safe under parallel test execution (#1656; thanks to @​kelunik 👋)
  • ModuleDependency now provides stable descriptions (#1648; thanks to @​DragonFSKY 👋)

JUnit

Documentation

Internal Improvements

Commits
  • 6c2d659 prepare release 1.5.1
  • d5ff417 set snapshot version to 1.5.1 in preparation of release
  • aee04c5 Update Gradle Wrapper from 9.7.1 to 9.8.0 (#1727)
  • 73535af Update Gradle Wrapper from 9.7.1 to 9.8.0
  • 058f709 Count caught exception types as type dependencies (#1732) (#1725)
  • fbcc47c Count caught exception types as type dependencies (#1732)
  • e78e136 Bump io.github.ben-manes.versions from 0.63.0 to 0.64.0
  • a0a8aff Bump io.github.ben-manes.versions from 0.62.0 to 0.63.0
  • d30f80d Bump io.github.ben-manes.versions from 0.61.0 to 0.62.0
  • 22c0f6a Bump actions/setup-java from 6.0.0 to 6.0.1
  • Additional commits viewable in compare view

Updates org.springdoc:springdoc-openapi-starter-webmvc-ui from 3.0.3 to 3.1.1

Release notes

Sourced from org.springdoc:springdoc-openapi-starter-webmvc-ui's releases.

springdoc-openapi v3.1.1 released!

Security

  • GHSA-6f5m-mhjg-qwxq – MCP tool callbacks do not encode path parameters, allowing request retargeting
  • GHSA-4v2q-56v7-2cpw – MCP transport, admin and dashboard endpoints are exposed by default
  • GHSA-m4cg-mhpg-rh2r – MCP audit events record credentials and request/response bodies without redaction
  • GHSA-5f9r-4mc4-qh3c – Unbounded MCP pending-confirmation store allows memory exhaustion
  • GHSA-jcgg-59c8-w4wh – MCP request context in a ThreadLocal can leak headers between concurrent WebFlux requests
  • GHSA-rhhx-6j8h-8cvw – Unbounded per-locale OpenAPI cache allows memory exhaustion via Accept-Language
  • GHSA-c925-vm88-mpp9 – Scalar starters trust client-supplied forwarded headers and render from a shared mutable bean
  • CVE-2026-75838 – Cross-site scripting in the DOMPurify bundled with swagger-ui, addressed by upgrading swagger-ui to 5.32.14

Added

  • #3340 – Describe JsonNullable values without their Java wrapper
  • #3325 – Manage the swagger artifacts in springdoc-openapi-bom, so that modules holding only the annotations stay in lockstep
  • #3321 – Add springdoc.login-endpoint.username-example and springdoc.login-endpoint.password-example to document the Spring Security login endpoint

Changed

  • MCP is now opt-in. Set springdoc.ai.mcp.enabled=true, and springdoc.ai.mcp.dashboard-enabled=true for the dashboard
  • The Scalar starters no longer register forwarded-header handling. Set server.forward-headers-strategy=framework (or native) behind a trusted proxy
  • Add springdoc.cache.max-entries (default 100) to bound the per-locale OpenAPI cache
  • Add springdoc.ai.mcp.audit.redact (default true) to mask secrets in MCP audit events
  • Document that the MCP approval flow is a confirmation step, not an authorization control
  • Document the security policy and the release versioning scheme
  • #3351 – java.time.Duration, LocalTime and OffsetTime are now resolved by swagger-core instead of being forced to a bare string, so they carry a format (duration and partial-time respectively for the first two)
  • A property whose type only implements Set indirectly (LinkedHashSet, TreeSet, …) is now described with uniqueItems: true, following swagger-api/swagger-core#5265
  • Upgrade swagger-core to version 2.2.55
  • Upgrade swagger-ui to version 5.32.14

Fixed

  • #3328, #3337 – /v3/api-docs fails with a NullPointerException when spring-hateoas is on the classpath without HateoasProperties
  • #3314 – Json Processing Exception occurred is logged for every constrained parameter whose schema is not a JsonSchema
  • #3317 – An injected HttpHeaders parameter is described as a schema
  • #3332 – The properties a Kotlin entity inherits from an @Embeddable are missing from the Spring Data REST schemas
  • #3320 – @Order and Ordered ignored when applying customizers
  • #3319 – A Page nested in another schema is not replaced by PagedModel
  • #3313 – Springdoc auto-configurations rely on unspecified auto-configuration ordering
  • #3331 – Validation annotations declared inside Optional parameters are dropped
  • #3322 – Validation annotations on a container's type argument leak between parameters
  • #3315 – An OAS 3.1 JsonSchema cannot be cloned through JSON
  • #3300 – TYPE_USE annotations on @ParameterObject fields are not passed along
  • #3341 – Stabilize Spring Data Sort and Pageable schema property order
  • #3338 – Kotlin nullability interpretation of the Any? type
  • #3136 – A Spring Data REST association to a non-exported entity expands its @EmbeddedId and @MapsId fields recursively in the response schemas
  • The Spring Data REST response post-processing rewrote an association property in place, so the …Response refs could leak into the schema shared with the request body representation

New Contributors

... (truncated)

Changelog

Sourced from org.springdoc:springdoc-openapi-starter-webmvc-ui's changelog.

[3.1.1] - 2026-09-06

Security

  • GHSA-6f5m-mhjg-qwxq – MCP tool callbacks do not encode path parameters, allowing request retargeting
  • GHSA-4v2q-56v7-2cpw – MCP transport, admin and dashboard endpoints are exposed by default
  • GHSA-m4cg-mhpg-rh2r – MCP audit events record credentials and request/response bodies without redaction
  • GHSA-5f9r-4mc4-qh3c – Unbounded MCP pending-confirmation store allows memory exhaustion
  • GHSA-jcgg-59c8-w4wh – MCP request context in a ThreadLocal can leak headers between concurrent WebFlux requests
  • GHSA-rhhx-6j8h-8cvw – Unbounded per-locale OpenAPI cache allows memory exhaustion via Accept-Language
  • GHSA-c925-vm88-mpp9 – Scalar starters trust client-supplied forwarded headers and render from a shared mutable bean
  • CVE-2026-75838 – Cross-site scripting in the DOMPurify bundled with swagger-ui, addressed by upgrading swagger-ui to 5.32.14

Added

  • #3340 – Describe JsonNullable values without their Java wrapper
  • #3325 – Manage the swagger artifacts in springdoc-openapi-bom, so that modules holding only the annotations stay in lockstep
  • #3321 – Add springdoc.login-endpoint.username-example and springdoc.login-endpoint.password-example to document the Spring Security login endpoint

Changed

  • MCP is now opt-in. Set springdoc.ai.mcp.enabled=true, and springdoc.ai.mcp.dashboard-enabled=true for the dashboard
  • The Scalar starters no longer register forwarded-header handling. Set server.forward-headers-strategy=framework (or native) behind a trusted proxy
  • Add springdoc.cache.max-entries (default 100) to bound the per-locale OpenAPI cache
  • Add springdoc.ai.mcp.audit.redact (default true) to mask secrets in MCP audit events
  • Document that the MCP approval flow is a confirmation step, not an authorization control
  • Document the security policy and the release versioning scheme
  • #3351 – java.time.Duration, LocalTime and OffsetTime are now resolved by swagger-core instead of being forced to a bare string, so they carry a format (duration and partial-time respectively for the first two)
  • A property whose type only implements Set indirectly (LinkedHashSet, TreeSet, …) is now described with uniqueItems: true, following swagger-api/swagger-core#5265
  • Upgrade swagger-core to version 2.2.55
  • Upgrade swagger-ui to version 5.32.14

Fixed

  • #3328, #3337 – /v3/api-docs fails with a NullPointerException when spring-hateoas is on the classpath without HateoasProperties
  • #3314 – Json Processing Exception occurred is logged for every constrained parameter whose schema is not a JsonSchema
  • #3317 – An injected HttpHeaders parameter is described as a schema
  • #3332 – The properties a Kotlin entity inherits from an @Embeddable are missing from the Spring Data REST schemas
  • #3320 – @Order and Ordered ignored when applying customizers
  • #3319 – A Page nested in another schema is not replaced by PagedModel
  • #3313 – Springdoc auto-configurations rely on unspecified auto-configuration ordering
  • #3331 – Validation annotations declared inside Optional parameters are dropped
  • #3322 – Validation annotations on a container's type argument leak between parameters
  • #3315 – An OAS 3.1 JsonSchema cannot be cloned through JSON
  • #3300 – TYPE_USE annotations on @ParameterObject fields are not passed along
  • #3341 – Stabilize Spring Data Sort and Pageable schema property order
  • #3338 – Kotlin nullability interpretation of the Any? type
  • #3136 – A Spring Data REST association to a non-exported entity expands its @EmbeddedId and @MapsId fields recursively in the response schemas
  • The Spring Data REST response post-processing rewrote an association property in place, so the …Response refs could leak into the schema shared with the request body representation

... (truncated)

Commits
  • 1cc87a7 [maven-release-plugin] prepare release v3.1.1
  • 4e8ac26 docs: record the swagger-ui 5.32.14 upgrade as a security fix for 3.1.1
  • 958c79a Merge swagger-core 2.2.55 upgrade
  • cf7d7c7 Upgrade swagger-core to 2.2.55
  • 186adb3 Record the swagger-core 2.2.54 upgrade in the changelog
  • 2498ffb Merge pull request #3351 from Mattias-Sehlstedt/update-swagger-core
  • d78abd9 upgrade swagger-core from 2.2.53 to 2.2.54
  • 9f7f099 Rewrite a copy of a Spring Data REST association property
  • f47060e Record #3321 in the changelog and align the buildRequestBody indent
  • ccb2fc0 Merge pull request #3323 from Mattias-Sehlstedt/feature/3321-login-example-va...
  • Additional commits viewable in compare view

Updates io.swagger.parser.v3:swagger-parser from 2.1.45 to 2.1.48

Release notes

Sourced from io.swagger.parser.v3:swagger-parser's releases.

Swagger-parser 2.1.48 released!

  • Fix: resolution of external refs inside path items with templated fragments (#2033) (#2394)
  • fix: Fix relative references inside external path items (#1948, #2066) (#2393)
  • chore: update dependency-check-maven to 12.2.2 (#2387)
  • fix: Inlining of references with dot (#2109) (#2384)
  • fix: Fix duplicate schemas from root document back-references (#1961) (#2383)
  • fix: External Refs with same name are ignored (#2055) (#2382)
  • build(deps): bump org.apache.maven.plugins:maven-jar-plugin from 3.5.0 to 3.5.1 (#2379)
  • build(deps-dev): bump org.apache.maven.plugins:maven-compiler-plugin from 3.11.0 to 3.15.0 (#2378)
  • build(deps): bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.5 to 3.5.6 (#2377)
  • build(deps): bump swagger-core-version from 2.2.52 to 2.2.53 (#2376)

Swagger-parser 2.1.47 released!

  • build(deps): bump org.testng:testng from 7.11.0 to 7.12.0 (#2371)
  • build(deps): bump org.slf4j:slf4j-simple from 2.0.9 to 2.0.18 (#2358)
  • build(deps-dev): bump org.apache.maven.plugins:maven-enforcer-plugin from 3.4.1 to 3.6.3 (#2351)
  • Resolve same-named schemas from different files as distinct components (fixes #2333) (#2349)
  • fix: resolve relative refs correctly from spring boot jars (#2080, #2298) (#2320)

Swagger-parser 2.1.46 released!

  • chore: introduce jackson bom and update to 2.22 line (#2368)
Commits
  • a982879 prepare release 2.1.48 (#2397)
  • 28b1a73 Fix: resolution of external refs inside path items with templated fragments (...
  • b2a9955 fix: Fix relative references inside external path items (#1948, #2066) (#2393)
  • f23d962 chore: update dependabot to 12.2.2 (#2387)
  • d3398c8 fix: Inlining of references with dot (#2109) (#2384)
  • 0255d18 fix: Fix duplicate schemas from root document back-references (#1961) (#2383)
  • 2242451 build(deps): bump org.apache.maven.plugins:maven-jar-plugin (#2379)
  • 8b683a9 build(deps-dev): bump org.apache.maven.plugins:maven-compiler-plugin (#2378)
  • 9804796 build(deps): bump org.apache.maven.plugins:maven-surefire-plugin (#2377)
  • aea5c1e build(deps): bump swagger-core-version from 2.2.52 to 2.2.53 (#2376)
  • Additional commits viewable in compare view

Updates com.schibsted.spt.data:jslt from 0.1.14 to 0.1.15

Release notes

Sourced from com.schibsted.spt.data:jslt's releases.

Release 0.1.15: Bug fixes

Support for Unicode characters in identifiers was added by @​DineshSolanki.

One bug in the parsing of floating point numbers was fixed.

Support for trimm...

Description has been truncated

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Sep 28, 2026
…ctory with 21 updates

Bumps the all-minor-and-patch-updates group with 21 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [org.springframework.boot:spring-boot-starter-parent](https://github.com/spring-projects/spring-boot) | `4.1.0` | `4.1.1` |
| [io.netty:netty-bom](https://github.com/netty/netty) | `4.2.16.Final` | `4.2.18.Final` |
| io.swagger.core.v3:swagger-core-jakarta | `2.2.52` | `2.2.55` |
| io.swagger.core.v3:swagger-annotations-jakarta | `2.2.52` | `2.2.55` |
| io.swagger.core.v3:swagger-models-jakarta | `2.2.52` | `2.2.55` |
| io.swagger.core.v3:swagger-annotations-jakarta | `2.2.52` | `2.2.55` |
| io.swagger.core.v3:swagger-models-jakarta | `2.2.52` | `2.2.55` |
| [tools.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) | `3.1.5` | `3.2.3` |
| org.apache.camel.springboot:camel-spring-boot-bom | `4.21.0` | `4.22.1` |
| [org.apache.httpcomponents.client5:httpclient5](https://github.com/apache/httpcomponents-client) | `5.6.3` | `5.6.4` |
| [org.projectlombok:lombok](https://github.com/projectlombok/lombok) | `1.18.46` | `1.18.48` |
| [com.tngtech.archunit:archunit-junit5](https://github.com/TNG/ArchUnit) | `1.4.2` | `1.5.1` |
| [org.springdoc:springdoc-openapi-starter-webmvc-ui](https://github.com/springdoc/springdoc-openapi) | `3.0.3` | `3.1.1` |
| [io.swagger.parser.v3:swagger-parser](https://github.com/swagger-api/swagger-parser) | `2.1.45` | `2.1.48` |
| [com.schibsted.spt.data:jslt](https://github.com/schibsted/jslt) | `0.1.14` | `0.1.15` |
| [org.sonarsource.scanner.maven:sonar-maven-plugin](https://github.com/SonarSource/sonar-scanner-maven) | `5.7.0.6970` | `5.8.0.7211` |
| org.flywaydb:flyway-maven-plugin | `13.0.0` | `13.8.0` |
| [org.apache.maven.plugins:maven-compiler-plugin](https://github.com/apache/maven-compiler-plugin) | `3.15.0` | `3.16.0` |
| [org.codehaus.mojo:xml-maven-plugin](https://github.com/mojohaus/xml-maven-plugin) | `1.2.1` | `1.2.2` |
| [com.github.spotbugs:spotbugs-maven-plugin](https://github.com/spotbugs/spotbugs-maven-plugin) | `4.10.3.0` | `4.10.4.1` |
| [com.diffplug.spotless:spotless-maven-plugin](https://github.com/diffplug/spotless) | `3.8.0` | `3.10.2` |
| org.apache.maven:apache-maven | `3.9.9` | `3.9.16` |
| [org.apache.maven.wrapper:maven-wrapper](https://github.com/apache/maven-wrapper) | `3.3.2` | `3.3.4` |



Updates `org.springframework.boot:spring-boot-starter-parent` from 4.1.0 to 4.1.1
- [Release notes](https://github.com/spring-projects/spring-boot/releases)
- [Commits](spring-projects/spring-boot@v4.1.0...v4.1.1)

Updates `io.netty:netty-bom` from 4.2.16.Final to 4.2.18.Final
- [Release notes](https://github.com/netty/netty/releases)
- [Commits](netty/netty@netty-4.2.16.Final...netty-4.2.18.Final)

Updates `io.swagger.core.v3:swagger-core-jakarta` from 2.2.52 to 2.2.55

Updates `io.swagger.core.v3:swagger-annotations-jakarta` from 2.2.52 to 2.2.55

Updates `io.swagger.core.v3:swagger-models-jakarta` from 2.2.52 to 2.2.55

Updates `io.swagger.core.v3:swagger-annotations-jakarta` from 2.2.52 to 2.2.55

Updates `io.swagger.core.v3:swagger-models-jakarta` from 2.2.52 to 2.2.55

Updates `tools.jackson.core:jackson-databind` from 3.1.5 to 3.2.3
- [Commits](FasterXML/jackson-databind@jackson-databind-3.1.5...jackson-databind-3.2.3)

Updates `org.apache.camel.springboot:camel-spring-boot-bom` from 4.21.0 to 4.22.1

Updates `org.apache.httpcomponents.client5:httpclient5` from 5.6.3 to 5.6.4
- [Changelog](https://github.com/apache/httpcomponents-client/blob/rel/v5.6.4/RELEASE_NOTES.txt)
- [Commits](apache/httpcomponents-client@rel/v5.6.3...rel/v5.6.4)

Updates `org.projectlombok:lombok` from 1.18.46 to 1.18.48
- [Changelog](https://github.com/projectlombok/lombok/blob/master/doc/changelog.markdown)
- [Commits](projectlombok/lombok@v1.18.46...v1.18.48)

Updates `com.tngtech.archunit:archunit-junit5` from 1.4.2 to 1.5.1
- [Release notes](https://github.com/TNG/ArchUnit/releases)
- [Commits](TNG/ArchUnit@v1.4.2...v1.5.1)

Updates `org.springdoc:springdoc-openapi-starter-webmvc-ui` from 3.0.3 to 3.1.1
- [Release notes](https://github.com/springdoc/springdoc-openapi/releases)
- [Changelog](https://github.com/springdoc/springdoc-openapi/blob/main/CHANGELOG.md)
- [Commits](springdoc/springdoc-openapi@v3.0.3...v3.1.1)

Updates `io.swagger.parser.v3:swagger-parser` from 2.1.45 to 2.1.48
- [Release notes](https://github.com/swagger-api/swagger-parser/releases)
- [Commits](swagger-api/swagger-parser@v2.1.45...v2.1.48)

Updates `com.schibsted.spt.data:jslt` from 0.1.14 to 0.1.15
- [Release notes](https://github.com/schibsted/jslt/releases)
- [Commits](schibsted/jslt@0.1.14...0.1.15)

Updates `org.sonarsource.scanner.maven:sonar-maven-plugin` from 5.7.0.6970 to 5.8.0.7211
- [Release notes](https://github.com/SonarSource/sonar-scanner-maven/releases)
- [Commits](SonarSource/sonar-scanner-maven@5.7.0.6970...5.8.0.7211)

Updates `org.flywaydb:flyway-maven-plugin` from 13.0.0 to 13.8.0

Updates `org.apache.maven.plugins:maven-compiler-plugin` from 3.15.0 to 3.16.0
- [Release notes](https://github.com/apache/maven-compiler-plugin/releases)
- [Commits](apache/maven-compiler-plugin@maven-compiler-plugin-3.15.0...maven-compiler-plugin-3.16.0)

Updates `org.codehaus.mojo:xml-maven-plugin` from 1.2.1 to 1.2.2
- [Release notes](https://github.com/mojohaus/xml-maven-plugin/releases)
- [Commits](mojohaus/xml-maven-plugin@xml-maven-plugin-1.2.1...xml-maven-plugin-1.2.2)

Updates `com.github.spotbugs:spotbugs-maven-plugin` from 4.10.3.0 to 4.10.4.1
- [Release notes](https://github.com/spotbugs/spotbugs-maven-plugin/releases)
- [Commits](spotbugs/spotbugs-maven-plugin@spotbugs-maven-plugin-4.10.3.0...spotbugs-maven-plugin-4.10.4.1)

Updates `com.diffplug.spotless:spotless-maven-plugin` from 3.8.0 to 3.10.2
- [Release notes](https://github.com/diffplug/spotless/releases)
- [Changelog](https://github.com/diffplug/spotless/blob/main/CHANGES.md)
- [Commits](diffplug/spotless@maven/3.8.0...maven/3.10.2)

Updates `org.apache.maven:apache-maven` from 3.9.9 to 3.9.16

Updates `org.apache.maven.wrapper:maven-wrapper` from 3.3.2 to 3.3.4
- [Release notes](https://github.com/apache/maven-wrapper/releases)
- [Commits](apache/maven-wrapper@maven-wrapper-3.3.2...maven-wrapper-3.3.4)

---
updated-dependencies:
- dependency-name: com.diffplug.spotless:spotless-maven-plugin
  dependency-version: 3.10.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-minor-and-patch-updates
- dependency-name: com.github.spotbugs:spotbugs-maven-plugin
  dependency-version: 4.10.4.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-minor-and-patch-updates
- dependency-name: com.schibsted.spt.data:jslt
  dependency-version: 0.1.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-minor-and-patch-updates
- dependency-name: com.tngtech.archunit:archunit-junit5
  dependency-version: 1.5.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-minor-and-patch-updates
- dependency-name: io.netty:netty-bom
  dependency-version: 4.2.18.Final
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-minor-and-patch-updates
- dependency-name: io.swagger.core.v3:swagger-annotations-jakarta
  dependency-version: 2.2.55
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-minor-and-patch-updates
- dependency-name: io.swagger.core.v3:swagger-annotations-jakarta
  dependency-version: 2.2.55
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-minor-and-patch-updates
- dependency-name: io.swagger.core.v3:swagger-core-jakarta
  dependency-version: 2.2.55
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-minor-and-patch-updates
- dependency-name: io.swagger.core.v3:swagger-models-jakarta
  dependency-version: 2.2.55
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-minor-and-patch-updates
- dependency-name: io.swagger.core.v3:swagger-models-jakarta
  dependency-version: 2.2.55
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-minor-and-patch-updates
- dependency-name: io.swagger.parser.v3:swagger-parser
  dependency-version: 2.1.48
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-minor-and-patch-updates
- dependency-name: org.apache.camel.springboot:camel-spring-boot-bom
  dependency-version: 4.22.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-minor-and-patch-updates
- dependency-name: org.apache.httpcomponents.client5:httpclient5
  dependency-version: 5.6.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-minor-and-patch-updates
- dependency-name: org.apache.maven.plugins:maven-compiler-plugin
  dependency-version: 3.16.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-minor-and-patch-updates
- dependency-name: org.apache.maven.wrapper:maven-wrapper
  dependency-version: 3.3.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-minor-and-patch-updates
- dependency-name: org.apache.maven:apache-maven
  dependency-version: 3.9.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-minor-and-patch-updates
- dependency-name: org.codehaus.mojo:xml-maven-plugin
  dependency-version: 1.2.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all-minor-and-patch-updates
- dependency-name: org.flywaydb:flyway-maven-plugin
  dependency-version: 13.8.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-minor-and-patch-updates
- dependency-name: org.projectlombok:lombok
  dependency-version: 1.18.48
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-minor-and-patch-updates
- dependency-name: org.sonarsource.scanner.maven:sonar-maven-plugin
  dependency-version: 5.8.0.7211
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: all-minor-and-patch-updates
- dependency-name: org.springdoc:springdoc-openapi-starter-webmvc-ui
  dependency-version: 3.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-minor-and-patch-updates
- dependency-name: org.springframework.boot:spring-boot-starter-parent
  dependency-version: 4.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all-minor-and-patch-updates
- dependency-name: tools.jackson.core:jackson-databind
  dependency-version: 3.2.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all-minor-and-patch-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot-maven-all-minor-and-patch-updates-8468856318 branch from db3a9c8 to 0933fea Compare September 28, 2026 13:15

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants