Skip to content

Bump the maven-maintenance group with 8 updates - #13

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/maven-maintenance-209d1c5574
Closed

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/maven-maintenance-209d1c5574

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 1, 2026

Copy link
Copy Markdown

Bumps the maven-maintenance group with 8 updates:

Package From To
org.apache.poi:poi 5.4.0 5.5.1
org.apache.poi:poi-ooxml 5.4.0 5.5.1
org.apache.commons:commons-text 1.13.0 1.15.0
cn.hutool:hutool-all 5.8.35 5.8.47
com.google.guava:guava 33.4.8-jre 33.7.1-jre
com.github.oshi:oshi-core 6.6.5 7.6.0
com.alipay.sdk:alipay-sdk-java 4.22.57.ALL 4.40.978.ALL
software.amazon.awssdk:s3 2.30.13 2.54.7

Updates org.apache.poi:poi from 5.4.0 to 5.5.1

Updates org.apache.poi:poi-ooxml from 5.4.0 to 5.5.1

Updates org.apache.commons:commons-text from 1.13.0 to 1.15.0

Changelog

Sourced from org.apache.commons:commons-text's changelog.

Apache Commons Text 1.15.0 Release Notes

The Apache Commons Text team is pleased to announce the release of Apache Commons Text 1.15.0.

Apache Commons Text is a set of utility functions and reusable components for processing and manipulating text in a Java environment.

Release 1.15.0. This is a feature and maintenance release. Java 8 or later is required.

New features

  •        Add experimental CycloneDX VEX file [#683](https://github.com/apache/commons-text/issues/683). Thanks to Piotr P. Karwasz, Gary Gregory.
    
  • TEXT-235: Add Damerau-Levenshtein distance #687. Thanks to LorgeN, Gary Gregory.
  •        Add unit tests to increase coverage [#719](https://github.com/apache/commons-text/issues/719). Thanks to Michael Hausegger, Gary Gregory.
    
  •        Add new test for CharSequenceTranslator#with() [#725](https://github.com/apache/commons-text/issues/725). Thanks to Michael Hausegger, Gary Gregory.
    
  •        Add tests and assertions to org.apache.commons.text.similarity to get to 100% code coverage [#727](https://github.com/apache/commons-text/issues/727), [#728](https://github.com/apache/commons-text/issues/728). Thanks to Michael Hausegger.
    

Fixed Bugs

  •        Fix exception message typo in XmlStringLookup.XmlStringLookup(Map, Path...). Thanks to Gary Gregory.
    
  • TEXT-236: Inserting at the end of a TextStringBuilder throws a StringIndexOutOfBoundsException. Thanks to Pierre Post, Sumit Bera, Alex Herbert, Gary Gregory.
  •        Fix TextStringBuilderTest.testAppendToCharBuffer() to use proper argument type [#724](https://github.com/apache/commons-text/issues/724). Thanks to Michael Hausegger.
    
  •        Fix Apache RAT plugin console warnings. Thanks to Gary Gregory.
    
  •        Fix site XML to use version 2.0.0 XML schema. Thanks to Gary Gregory.
    
  •        Removed unreachable threshold verification code in src/main/java/org/apache/commons/text/similarity [#730](https://github.com/apache/commons-text/issues/730). Thanks to Michael Hausegger.
    
  •        Enable secure processing for the XML parser in XmlStringLookup in case the underlying JAXP implementation doesn't [#729](https://github.com/apache/commons-text/issues/729). Thanks to 김민재 (minjas0507), Gary Gregory, Piotr Karwasz.
    

Changes

  •        Bump org.apache.commons:commons-parent from 85 to 93 [#704](https://github.com/apache/commons-text/issues/704), [#723](https://github.com/apache/commons-text/issues/723), [#726](https://github.com/apache/commons-text/issues/726). Thanks to Gary Gregory.
    
  •        Bump commons.bytebuddy.version from 1.17.6 to 1.18.2 [#696](https://github.com/apache/commons-text/issues/696), [#722](https://github.com/apache/commons-text/issues/722). Thanks to Gary Gregory.
    
  •        Bump graalvm.version from 24.2.2 to 25.0.1 [#703](https://github.com/apache/commons-text/issues/703), [#716](https://github.com/apache/commons-text/issues/716). Thanks to Gary Gregory, Dependabot.
    
  •        Bump org.apache.commons:commons-lang3 from 3.18.0 to 3.20.0. Thanks to Gary Gregory.
    
  •        Bump commons-io:commons-io from 2.20.0 to 2.21.0. Thanks to Gary Gregory.
    

Historical list of changes: https://commons.apache.org/proper/commons-text/changes.html

For complete information on Apache Commons Text, including instructions on how to submit bug reports, patches, or suggestions for improvement, see the Apache Commons Text website:

https://commons.apache.org/proper/commons-text

Download page: https://commons.apache.org/proper/commons-text/download_text.cgi

... (truncated)

Commits
  • 04e9374 Prepare for the release candidate 1.15.0 RC1
  • 502c4c4 Prepare for the next release candidate
  • c6e17ec Use direct access
  • 58e1e12 Simplify XML FSP (#731)
  • b5052c9 Bump actions/setup-java from 5.0.0 to 5.1.0
  • 2e2d4bc Revert "Bump actions/setup-java from 5.0.0 to 5.1.0"
  • b0ddbd1 Bump actions/setup-java from 5.0.0 to 5.1.0
  • 1c2d382 Add tests with external DTD
  • ed3df4b Internal clean up
  • bb508f3 Bump actions/checkout from 6.0.0 to 6.0.1
  • Additional commits viewable in compare view

Updates cn.hutool:hutool-all from 5.8.35 to 5.8.47

Release notes

Sourced from cn.hutool:hutool-all's releases.

5.8.47(2026-07-06) 🐣新特性 【core 】 EnumConverter变更规则,当用户自定义方法返回null时,调用默认valueOf(pr#4258@Github) 【core 】 DateUtilparseISO8601增加检查范围(pr#4275@Github) 【core 】 Guard FileMagicNumber AAC/M4A/AMR matchers against short byte arrays(pr#4278@Github) 【crypto 】 Reject empty cipherKey in Vigenere with a clear exception(pr#4279@Github) 【core 】 Return null from CsvRow.get for a negative index(pr#4280@Github) 【crypto 】 Reject too-short salt in BCrypt.hashpw with IllegalArgumentException(pr#4282@Github) 【crypto 】 Validate md5HexTo16 input length to avoid StringIndexOutOfBoundsException(pr#4283@Github) 🐞Bug修复 【core 】 修复HexUtil.format奇数位数输出错误问题(issue#4263@Github) 【core 】 修复CamelCaseLinkedMap顺序错乱问题(issue#IJV845@Gitee) 【core 】 修复AntPathMatchersubstring问题(pr#4276@Github) 【poi 】 修复Excel03SaxReader读取xls时最后一行数据丢失问题(pr#1442@Gitee) 【core 】 修复根据新版外国人永久居留身份证(18位)身份编号获取户籍省份编码的问题(pr#4288@Github) 【core 】 修复Record反序列化时字段null导致报错问题(issue#4269@Github)

v5.8.46

5.8.46(2026-05-25) 🐣新特性 【core 】 AnnotationUtil新增两级缓存架构,提升高频注解解析性能(pr#1434@Gitee) 【core 】 RegexPool.PLATE_NUMBER新增粤AP号段支持(issue#IJNDJR@Gitee) 🐞Bug修复 【db 】 修复Page和PageResult首页调用问题(issue#IH7A18@Gitee) 【ai 】 修复AI SPI classloader找不到实现问题(issue#4241@Github) 【extra 】 修复ExpressionEngine中SpELEngine、MVEL白名单无效问题(issue#4249@Github) 【core 】 修复JNDIUtil远程加载漏洞(issue#4249@Github) 【core 】 修复ValidateObjectInputStream白名单规则问题(issue#4249@Github) 【core 】 修复VersionUtil比对null时结果异常问题(issue#IJNFQZ@Gitee) 【core 】 修复BeanConverter和MapConverter源Bean判断问题(pr#4252@Github)

5.8.44


5.8.44(2026-03-11)

🐣新特性

  • 【core 】 NumberUtil.parseNumber增加支持科学计数法(pr#4211@Github)
  • 【captcha】 AbstractCaptcha增加setStroke方法支持线条粗细(issue#IDJQ15@Gitee)
  • 【core 】 BooleanUtil新增 exactlyOneTrue 方法用于互斥条件校验(issue#IDJQ15@Gitee)
  • 【core 】 DateUtil.normalize方法中正则预编译提升效率(pr#4221@Gitee)
  • 【core 】 AppendableWriter增加checkNotClosed(issue#IDMZ5K@Gitee)
  • 【core 】 FastDateParser改进在JDK25下三字母时区警告(issue#4100@Github)
  • 【core 】 ReflectUtil增加二级缓存(pr#1433@Gitee)

🐞Bug修复

  • 【json 】 修复JSONUtil.wrap忽略错误问题(issue#4210@Github)
  • 【http 】 修复HttpUtil.normalizeParams 在极端输入下抛 StringIndexOutOfBoundsException(pr#4216@Github)
  • 【extra 】 修复MailAccount.setAuth参数与field不一致问题(issue#4217@Github)
  • 【core 】 修复TransMap.computeIfAbsentmappingFunction处理不一致问题(issue#IDM6UR@Gitee)
  • 【core 】 修复MultiResource游标歧义问题(issue#IDNAOY@Gitee)
  • 【core 】 修复BufferUtilcopy歧义问题(issue#IDN097@Gitee)

... (truncated)

Changelog

Sourced from cn.hutool:hutool-all's changelog.

5.8.47(2026-07-06)

🐣新特性

  • 【core 】 EnumConverter变更规则,当用户自定义方法返回null时,调用默认valueOf(pr#4258@Github)
  • 【core 】 DateUtilparseISO8601增加检查范围(pr#4275@Github)
  • 【core 】 Guard FileMagicNumber AAC/M4A/AMR matchers against short byte arrays(pr#4278@Github)
  • 【crypto 】 Reject empty cipherKey in Vigenere with a clear exception(pr#4279@Github)
  • 【core 】 Return null from CsvRow.get for a negative index(pr#4280@Github)
  • 【crypto 】 Reject too-short salt in BCrypt.hashpw with IllegalArgumentException(pr#4282@Github)
  • 【crypto 】 Validate md5HexTo16 input length to avoid StringIndexOutOfBoundsException(pr#4283@Github)

🐞Bug修复

  • 【core 】 修复HexUtil.format奇数位数输出错误问题(issue#4263@Github)
  • 【core 】 修复CamelCaseLinkedMap顺序错乱问题(issue#IJV845@Gitee)
  • 【core 】 修复AntPathMatchersubstring问题(pr#4276@Github)
  • 【poi 】 修复Excel03SaxReader读取xls时最后一行数据丢失问题(pr#1442@Gitee)
  • 【core 】 修复根据新版外国人永久居留身份证(18位)身份编号获取户籍省份编码的问题(pr#4288@Github)
  • 【core 】 修复Record反序列化时字段null导致报错问题(issue#4269@Github)

5.8.46(2026-05-25)

🐣新特性

  • 【core 】 AnnotationUtil新增两级缓存架构,提升高频注解解析性能(pr#1434@Gitee)
  • 【core 】 RegexPool.PLATE_NUMBER新增粤AP号段支持(issue#IJNDJR@Gitee)

🐞Bug修复

  • 【db 】 修复Page和PageResult首页调用问题(issue#IH7A18@Gitee)
  • 【ai 】 修复AI SPI classloader找不到实现问题(issue#4241@Github)
  • 【extra 】 修复ExpressionEngine中SpELEngine、MVEL白名单无效问题(issue#4249@Github)
  • 【core 】 修复JNDIUtil远程加载漏洞(issue#4249@Github)
  • 【core 】 修复ValidateObjectInputStream白名单规则问题(issue#4249@Github)
  • 【core 】 修复VersionUtil比对null时结果异常问题(issue#IJNFQZ@Gitee)
  • 【core 】 修复BeanConverter和MapConverter源Bean判断问题(pr#4252@Github)

5.8.45(2026-05-19)

🐣新特性

  • 此版本发布出现问题,跳过!

🐞Bug修复


5.8.44(2026-03-11)

🐣新特性

  • 【core 】 NumberUtil.parseNumber增加支持科学计数法(pr#4211@Github)
  • 【captcha】 AbstractCaptcha增加setStroke方法支持线条粗细(issue#IDJQ15@Gitee)
  • 【core 】 BooleanUtil新增 exactlyOneTrue 方法用于互斥条件校验(issue#IDJQ15@Gitee)
  • 【core 】 DateUtil.normalize方法中正则预编译提升效率(pr#4221@Gitee)
  • 【core 】 AppendableWriter增加checkNotClosed(issue#IDMZ5K@Gitee)
  • 【core 】 FastDateParser改进在JDK25下三字母时区警告(issue#4100@Github)
  • 【core 】 ReflectUtil增加二级缓存(pr#1433@Gitee)

🐞Bug修复

  • 【json 】 修复JSONUtil.wrap忽略错误问题(issue#4210@Github)

... (truncated)

Commits
  • 8870454 Prepare release
  • 853c29f 🚀release5.8.47
  • eaa0641 fix test
  • 90fae33 fix test
  • c57da4d 修复Record反序列化时字段null导致报错问题(issue#4269@Github)
  • 212c796 修复根据新版外国人永久居留身份证(18位)身份编号获取户籍省份编码的问题(pr#4288@Github)
  • faa08a8 Merge pull request #4288 from YamMangoTea/v5-dev
  • 8290d30 Merge pull request #4284 from vasiliy-mikhailov/fix-condition-unwrapquote-whi...
  • 71e7957 Validate md5HexTo16 input length to avoid StringIndexOutOfBoundsException
  • 6cbc8f8 Merge pull request #4283 from vasiliy-mikhailov/fix-md5hexto16-short-input
  • Additional commits viewable in compare view

Updates com.google.guava:guava from 33.4.8-jre to 33.7.1-jre

Release notes

Sourced from com.google.guava:guava's releases.

33.7.1

Maven

<dependency>
  <groupId>com.google.guava</groupId>
  <artifactId>guava</artifactId>
  <version>33.7.1-jre</version>
  <!-- or, for Android: -->
  <version>33.7.1-android</version>
</dependency>

Jar files

Guava requires one runtime dependency, which you can download here:

Javadoc

JDiff

Changelog

Guava 33.7.1 removes the Multi-Release line from our jar manifest, fixing an issue under Java 9 and 10 that was introduced to guava-jre in version 33.7.0. Sorry for the trouble.

33.7.0

Newly introduced problem for Java 9 and Java 10 only

Guava 33.7.0 includes a Multi-Release line in its jar manifest, even though it is no longer a multi-release jar. This causes some problems with tools from Java 9 and Java 10. The issue is fixed in version 33.7.1. Sorry for the trouble.

Maven

<dependency>
  <groupId>com.google.guava</groupId>
  <artifactId>guava</artifactId>
  <version>33.7.0-jre</version>
  <!-- or, for Android: -->
</tr></table> 

... (truncated)

Commits

Updates com.github.oshi:oshi-core from 6.6.5 to 7.6.0

Release notes

Sourced from com.github.oshi:oshi-core's releases.

Release 7.6.0

Maven Central Publication Change

The oshi-dist zip is no longer published to Maven Central; download it from the GitHub release instead.

New Features
  • #3652: oshi-metrics reports the OpenTelemetry reserved state for system.filesystem.usage and system.filesystem.utilization, alongside the existing used and free. The three states partition the filesystem, so the usage gauges sum to system.filesystem.limit and the utilization gauges sum to 1.0 - @​dbwiddis.
  • #3660, #3678: Display.getDevicePort() reports the port a display is attached to, and on systems with X RandR, Display.getOutputName() gives the name xrandr --output accepts for it - @​ayonization, @​dbwiddis.
Behavior Changes
  • #3705: OSDesktopWindow.getLocAndSize() returns a copy of the window's Rectangle and the constructor copies the one it is given, so the class honors the immutability its documentation promises. ApplicationInfo.getAdditionalInfo() returns an unmodifiable map. Code that wrote through either return value silently mutated OSHI's own state; it now has no effect, or throws UnsupportedOperationException for the map - @​dbwiddis.
  • #3705: UsbDevice.compareTo() breaks ties on the unique device ID, vendor ID, product ID and serial number after comparing names, and AbstractUsbDevice implements equals() and hashCode() over the same fields. Two distinct devices sharing a name previously compared equal, so a TreeSet or SortedSet of them kept only one. The ordering is now a default method on UsbDevice, so every implementation shares it - @​dbwiddis.
Bug Fixes and Improvements
  • #3651: OSFileStore now guarantees 0 <= getUsableSpace() <= getFreeSpace() <= getTotalSpace() on every platform. The three values are read by separate queries, so on a ZFS dataset or a swap-backed tmpfs they could previously contradict each other; they are now clamped downward to restore the ordering - @​dbwiddis.
  • #3657: Fix the TcpState for the FFM implementation of InternetProtocolStats.getConnections() on macOS and set the process cap from the kernel - @​dbwiddis.
  • #3661: Setting oshi.os.windows.hkeyperfdata to false now also skips the registry when fetching thread counters, matching its documented behavior and the existing handling for processes - @​dbwiddis.
  • #3662: Reading the processor description from the registry no longer throws when a value is missing. CentralProcessor.getFeatureFlags() on Windows now reports every processor feature IsProcessorFeaturePresent() accepts, matching the PF_ defines in winnt.h - @​dbwiddis.
  • #3665: NetworkParams.getRoutes() reads the routing table from the kernel through a NET_RT_DUMP sysctl on macOS, FreeBSD, DragonFly BSD and OpenBSD, rather than by running netstat twice - @​dbwiddis.
  • #3670: NetworkParams.getHostName() on Linux reads the kernel host name from /proc/sys/kernel/hostname in every backend, fixing the native-free implementation, which truncated a fully qualified name at the first dot and reported localhost when the name did not resolve - @​dbwiddis.
  • #3671: NetworkParams.getHostName() and getDomainName() report the empty-string sentinel when the local host name does not resolve, rather than the loopback address's localhost. NetBSD is the most affected platform, having no native host name query of its own - @​dbwiddis.
  • #3672, #3674: CentralProcessor frequencies and PhysicalProcessor.getEfficiency() on Apple Silicon are correct regardless of call order and on the M4 and M5 generations. Frequencies previously fell back to a 2.4 GHz placeholder unless getProcessorIdentifier() happened to be called first, were reported a thousand times too low on the M4 and later, and a chip with more or fewer than two kinds of core was misclassified - @​dbwiddis.
  • #3675: CentralProcessor.getCurrentFreq() on Apple Silicon can report the frequency the hardware actually ran at, rather than a nominal maximum that never changes. Set oshi.os.mac.cpu.frequency.ioreport to true; it is opt-in because it holds a subscription to a private framework for the lifetime of the process - @​dbwiddis.
  • #3680: oshi-metrics reads a disk or network interface once per memoizer expiration window rather than once per meter, so a scrape makes one query where it previously made five or seven, and the meters of one device report the same reading. A rate computed across two of them, such as errors per packet, is now comparable - @​dbwiddis.
  • #3681: GpuStats.getGpuUtilization() on Linux reads NVIDIA GPU utilization from NVML. It previously read only the amdgpu/i915/xe sysfs paths, none of which the NVIDIA driver exposes, so an NVIDIA card always returned the -1 sentinel - @​Krillsson.
  • #3686: GpuStats.getGpuUtilization() on Windows reads NVIDIA utilization from NVML and AMD utilization from ADL, matching the source order of every other metric on the class. It previously ran only LibreHardwareMonitor and a PDH engine-tick delta, which needs two samples, so the first call returned the -1 sentinel - @​dbwiddis.
  • #3687: GpuStats.getSharedMemoryUsed() on Linux reports the amdgpu GTT memory in use rather than always returning -1, and GraphicsCard.getVRam() on an amdgpu card reports the driver's own figure rather than the memory BAR size parsed from lspci or lshw. Several GpuStats metrics on Linux also now return the -1 sentinel when the sysfs file behind them is absent; they previously reported 0, so a card whose hwmon directory omits power1_average read as drawing 0.0 W - @​dbwiddis.
  • #3698: OSProcess.getCurrentWorkingDirectory() on macOS returns the directory rather than an empty string in the FFM implementation, and NetworkParams.getDomainName() on macOS and the BSDs returns the canonical name rather than an empty string in both implementations - @​dbwiddis.
  • #3705: An AIX process or thread that exits between enumeration and the /proc read is now reported as invalid rather than as a live process owned by root - @​dbwiddis.
  • #3705: A failure of kstat_open() on Solaris throws rather than releasing no lock and passing a null control structure to the kernel. The chain lock is static, so a failed open previously blocked every later kstat query on any thread - @​dbwiddis.

Full change log

Release 7.5.0

New Features
  • #3614 - #3636: Adopt JSpecify nullability annotations project-wide and enforce them in continuous integration with NullAway, so every type in a signature is non-null unless it is annotated @Nullable. A method not annotated @Nullable is now a checked guarantee rather than an aspiration, and a null check against one is dead code you can delete. The public API packages and the oshi.util tree carry the marking in their package-info.java, where every consumer sees it, including on a Java 8 or classpath build; the implementation packages are marked on their module descriptors; the native mapping packages under oshi.jna and oshi.ffm.platform opt out, because nullability there is the operating system's to state rather than OSHI's. The org.jspecify:jspecify dependency is optional and compile-time only, so it does not reach your runtime classpath. See the FAQ for what this does and does not promise - @​dbwiddis.
  • #3615: Add ParseUtil.getStringValueOrEmpty, which normalizes a nullable string to "", alongside the existing getStringValueOrUnknown - @​dbwiddis.
  • #3641: Add HardwareAbstractionLayer.getVirtualization(), which identifies the hypervisor, container runtime or cloud platform hosting the system, promoting the long-standing DetectVM demo into the library. It returns an Optional<String> naming the platform, or an empty Optional when no signature matched - which means undetermined, not confirmed bare metal. Detection reads the processor's CPUID vendor string, the computer system's manufacturer and model, and network interface MAC address OUIs, in that order. The signature tables ship as the oshi.vm.properties and oshi.vmmacaddr.properties resources; placing a file of either name earlier on the classpath replaces that table, so you can teach OSHI about a platform it does not know - @​dbwiddis.
  • #3646, #3647: Add NetworkParams.getRoutes(), which returns the operating system's routing table as a list of IPRoute objects covering both address families - @​dbwiddis.
Behavior Changes
  • #3646: NetworkParams.getIpv6DefaultGateway() on OpenBSD returns the IPv6 gateway. It previously omitted the -inet6 flag and returned the IPv4 gateway. NetworkParams default gateways on AIX return an empty string when no default route is configured, matching the documented contract. They previously returned Constants.UNKNOWN.
  • #3614 - #3636: Stating each nullability contract explicitly during the JSpecify sweep surfaced implementations that did not honor it. Values that were documented as unreadable but returned null now return the sentinel the rest of the API uses. The following user-facing behavior changed:

... (truncated)

Changelog

Sourced from com.github.oshi:oshi-core's changelog.

7.6.0 (2026-08-23), 7.6.1 (2026-09-01)

The oshi-dist zip is no longer published to Maven Central; download it from the GitHub release instead.

New Features
  • #3652: oshi-metrics reports the OpenTelemetry reserved state for system.filesystem.usage and system.filesystem.utilization, alongside the existing used and free. The three states partition the filesystem, so the usage gauges sum to system.filesystem.limit and the utilization gauges sum to 1.0 - @​dbwiddis.
  • #3660, #3678: Display.getDevicePort() reports the port a display is attached to, and on systems with X RandR, Display.getOutputName() gives the name xrandr --output accepts for it - @​ayonization, @​dbwiddis.
Behavior Changes
  • #3705: OSDesktopWindow.getLocAndSize() returns a copy of the window's Rectangle and the constructor copies the one it is given, so the class honors the immutability its documentation promises. ApplicationInfo.getAdditionalInfo() returns an unmodifiable map. Code that wrote through either return value silently mutated OSHI's own state; it now has no effect, or throws UnsupportedOperationException for the map - @​dbwiddis.
  • #3705: UsbDevice.compareTo() breaks ties on the unique device ID, vendor ID, product ID and serial number after comparing names, and AbstractUsbDevice implements equals() and hashCode() over the same fields. Two distinct devices sharing a name previously compared equal, so a TreeSet or SortedSet of them kept only one. The ordering is now a default method on UsbDevice, so every implementation shares it - @​dbwiddis.
Bug Fixes and Improvements
  • #3651: OSFileStore now guarantees 0 <= getUsableSpace() <= getFreeSpace() <= getTotalSpace() on every platform. The three values are read by separate queries, so on a ZFS dataset or a swap-backed tmpfs they could previously contradict each other; they are now clamped downward to restore the ordering - @​dbwiddis.
  • #3657: Fix the TcpState for the FFM implementation of InternetProtocolStats.getConnections() on macOS and set the process cap from the kernel - @​dbwiddis.
  • #3661: Setting oshi.os.windows.hkeyperfdata to false now also skips the registry when fetching thread counters, matching its documented behavior and the existing handling for processes - @​dbwiddis.
  • #3662: Reading the processor description from the registry no longer throws when a value is missing. CentralProcessor.getFeatureFlags() on Windows now reports every processor feature IsProcessorFeaturePresent() accepts, matching the PF_ defines in winnt.h - @​dbwiddis.
  • #3665: NetworkParams.getRoutes() reads the routing table from the kernel through a NET_RT_DUMP sysctl on macOS, FreeBSD, DragonFly BSD and OpenBSD, rather than by running netstat twice - @​dbwiddis.
  • #3670: NetworkParams.getHostName() on Linux reads the kernel host name from /proc/sys/kernel/hostname in every backend, fixing the native-free implementation, which truncated a fully qualified name at the first dot and reported localhost when the name did not resolve - @​dbwiddis.
  • #3671: NetworkParams.getHostName() and getDomainName() report the empty-string sentinel when the local host name does not resolve, rather than the loopback address's localhost. NetBSD is the most affected platform, having no native host name query of its own - @​dbwiddis.
  • #3672, #3674: CentralProcessor frequencies and PhysicalProcessor.getEfficiency() on Apple Silicon are correct regardless of call order and on the M4 and M5 generations. Frequencies previously fell back to a 2.4 GHz placeholder unless getProcessorIdentifier() happened to be called first, were reported a thousand times too low on the M4 and later, and a chip with more or fewer than two kinds of core was misclassified - @​dbwiddis.
  • #3675: CentralProcessor.getCurrentFreq() on Apple Silicon can report the frequency the hardware actually ran at, rather than a nominal maximum that never changes. Set oshi.os.mac.cpu.frequency.ioreport to true; it is opt-in because it holds a subscription to a private framework for the lifetime of the process - @​dbwiddis.
  • #3680: oshi-metrics reads a disk or network interface once per memoizer expiration window rather than once per meter, so a scrape makes one query where it previously made five or seven, and the meters of one device report the same reading. A rate computed across two of them, such as errors per packet, is now comparable - @​dbwiddis.
  • #3681: GpuStats.getGpuUtilization() on Linux reads NVIDIA GPU utilization from NVML. It previously read only the amdgpu/i915/xe sysfs paths, none of which the NVIDIA driver exposes, so an NVIDIA card always returned the -1 sentinel - @​Krillsson.
  • #3686: GpuStats.getGpuUtilization() on Windows reads NVIDIA utilization from NVML and AMD utilization from ADL, matching the source order of every other metric on the class. It previously ran only LibreHardwareMonitor and a PDH engine-tick delta, which needs two samples, so the first call returned the -1 sentinel - @​dbwiddis.
  • #3687: GpuStats.getSharedMemoryUsed() on Linux reports the amdgpu GTT memory in use rather than always returning -1, and GraphicsCard.getVRam() on an amdgpu card reports the driver's own figure rather than the memory BAR size parsed from lspci or lshw. Several GpuStats metrics on Linux also now return the -1 sentinel when the sysfs file behind them is absent; they previously reported 0, so a card whose hwmon directory omits power1_average read as drawing 0.0 W - @​dbwiddis.
  • #3698: OSProcess.getCurrentWorkingDirectory() on macOS returns the directory rather than an empty string in the FFM implementation, and NetworkParams.getDomainName() on macOS and the BSDs returns the canonical name rather than an empty string in both implementations - @​dbwiddis.
  • #3705: An AIX process or thread that exits between enumeration and the /proc read is now reported as invalid rather than as a live process owned by root - @​dbwiddis.
  • #3705: A failure of kstat_open() on Solaris throws rather than releasing no lock and passing a null control structure to the kernel. The chain lock is static, so a failed open previously blocked every later kstat query on any thread - @​dbwiddis.
  • #3710: Fix the bnd imports for oshi-core and oshi-core-ffm to make the JSpecify annotations optional, so both bundles resolve in an OSGi container without JSpecify - @​dbwiddis.

7.5.0 (2026-08-16)

New Features

... (truncated)

Commits
  • 430f530 [maven-release-plugin] prepare release oshi-parent-7.6.0
  • ae8b7bb 7.6.0 Release
  • d7e05aa Report an absent SMC once instead of on every sensor query, and quiet the stu...
  • 2382a05 Fix what SpotBugs and Sonar found (#3705)
  • 1534790 Update vmactions/freebsd-vm digest to d0518f9 (#3702)
  • 161dbee Run AppVeyor on JDK 25, and correct what pins testRelease
  • a93b66e Bring the new audit jobs onto upload-artifact v7
  • 8dde9a9 Extend the FFM layout audit to the Unix platforms, and fix what it found (#3701)
  • 3141850 Update vmactions/freebsd-vm digest to d0518f9 (#3699)
  • 75aabd0 Update actions/upload-artifact action to v7 (#3700)
  • Additional commits viewable in compare view

Updates com.alipay.sdk:alipay-sdk-java from 4.22.57.ALL to 4.40.978.ALL

Commits

Updates software.amazon.awssdk:s3 from 2.30.13 to 2.54.7

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the maven-maintenance group with 8 updates:

| Package | From | To |
| --- | --- | --- |
| org.apache.poi:poi | `5.4.0` | `5.5.1` |
| org.apache.poi:poi-ooxml | `5.4.0` | `5.5.1` |
| [org.apache.commons:commons-text](https://github.com/apache/commons-text) | `1.13.0` | `1.15.0` |
| [cn.hutool:hutool-all](https://github.com/looly/hutool) | `5.8.35` | `5.8.47` |
| [com.google.guava:guava](https://github.com/google/guava) | `33.4.8-jre` | `33.7.1-jre` |
| [com.github.oshi:oshi-core](https://github.com/oshi/oshi) | `6.6.5` | `7.6.0` |
| [com.alipay.sdk:alipay-sdk-java](https://github.com/alipay/alipay-sdk-java-all) | `4.22.57.ALL` | `4.40.978.ALL` |
| software.amazon.awssdk:s3 | `2.30.13` | `2.54.7` |


Updates `org.apache.poi:poi` from 5.4.0 to 5.5.1

Updates `org.apache.poi:poi-ooxml` from 5.4.0 to 5.5.1

Updates `org.apache.commons:commons-text` from 1.13.0 to 1.15.0
- [Changelog](https://github.com/apache/commons-text/blob/master/RELEASE-NOTES.txt)
- [Commits](apache/commons-text@rel/commons-text-1.13.0...rel/commons-text-1.15.0)

Updates `cn.hutool:hutool-all` from 5.8.35 to 5.8.47
- [Release notes](https://github.com/looly/hutool/releases)
- [Changelog](https://github.com/chinabugotech/hutool/blob/v5-master/CHANGELOG.md)
- [Commits](chinabugotech/hutool@5.8.35...5.8.47)

Updates `com.google.guava:guava` from 33.4.8-jre to 33.7.1-jre
- [Release notes](https://github.com/google/guava/releases)
- [Commits](https://github.com/google/guava/commits)

Updates `com.github.oshi:oshi-core` from 6.6.5 to 7.6.0
- [Release notes](https://github.com/oshi/oshi/releases)
- [Changelog](https://github.com/oshi/oshi/blob/master/CHANGELOG.md)
- [Commits](oshi/oshi@oshi-parent-6.6.5...oshi-parent-7.6.0)

Updates `com.alipay.sdk:alipay-sdk-java` from 4.22.57.ALL to 4.40.978.ALL
- [Commits](https://github.com/alipay/alipay-sdk-java-all/commits)

Updates `software.amazon.awssdk:s3` from 2.30.13 to 2.54.7

---
updated-dependencies:
- dependency-name: org.apache.poi:poi
  dependency-version: 5.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-maintenance
- dependency-name: org.apache.poi:poi-ooxml
  dependency-version: 5.5.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-maintenance
- dependency-name: org.apache.commons:commons-text
  dependency-version: 1.15.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-maintenance
- dependency-name: cn.hutool:hutool-all
  dependency-version: 5.8.47
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-maintenance
- dependency-name: com.google.guava:guava
  dependency-version: 33.7.1-jre
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-maintenance
- dependency-name: com.github.oshi:oshi-core
  dependency-version: 7.6.0
  dependency-type: direct:production
  update-type: version-update:semver-major
  dependency-group: maven-maintenance
- dependency-name: com.alipay.sdk:alipay-sdk-java
  dependency-version: 4.40.978.ALL
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-maintenance
- dependency-name: software.amazon.awssdk:s3
  dependency-version: 2.54.7
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-maintenance
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Sep 1, 2026
@SovNodeAI

Copy link
Copy Markdown
Owner

This groups several major dependency changes. The current release remains pinned to the versions covered by its compatibility and runtime evidence. We will review these updates separately after launch.

@SovNodeAI SovNodeAI closed this Sep 2, 2026
@dependabot @github

dependabot Bot commented on behalf of github Sep 2, 2026

Copy link
Copy Markdown
Author

This pull request was built based on a group rule. Closing it will not ignore any of these versions in future pull requests.

To ignore these dependencies, configure ignore rules in dependabot.yml

@dependabot
dependabot Bot deleted the dependabot/maven/maven-maintenance-209d1c5574 branch September 2, 2026 18:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant