Skip to content

chore: [DevOps] bump the production-minor-patch group with 6 updates - #1276

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/main/production-minor-patch-2b084afbca
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/main/production-minor-patch-2b084afbca

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown
Contributor

Bumps the production-minor-patch group with 6 updates:

Package From To
org.slf4j:jcl-over-slf4j 2.0.18 2.0.19
org.slf4j:slf4j-ext 2.0.18 2.0.19
org.apache.maven.plugin-tools:maven-plugin-annotations 3.15.2 3.16.0
org.slf4j:slf4j-api 2.0.18 2.0.19
com.auth0:java-jwt 4.6.0 4.6.1
io.netty:netty-bom 4.2.17.Final 4.2.18.Final

Updates org.slf4j:jcl-over-slf4j from 2.0.18 to 2.0.19

Updates org.slf4j:slf4j-ext from 2.0.18 to 2.0.19

Updates org.apache.maven.plugin-tools:maven-plugin-annotations from 3.15.2 to 3.16.0

Release notes

Sourced from org.apache.maven.plugin-tools:maven-plugin-annotations's releases.

3.16.0

🚀 New features and improvements

🐛 Bug Fixes

📝 Documentation updates

👻 Maintenance

🔧 Build

📦 Dependency updates

... (truncated)

Commits
  • 1d3f05b [maven-release-plugin] prepare release maven-plugin-tools-3.16.0
  • 2f22792 Update issue management system to GitHubx
  • 919e0a1 Update SCM tag and resolver version
  • c69e644 Bump org.jsoup:jsoup from 1.23.1 to 1.23.2
  • 6a201eb Bump org.codehaus.plexus:plexus-xml from 3.0.2 to 3.1.0
  • 7f16754 Bump org.codehaus.plexus:plexus-utils from 4.0.3 to 4.1.0
  • a0caf79 Bump org.codehaus.plexus:plexus-archiver from 4.12.0 to 4.14.0
  • 4e05797 Bump org.codehaus.plexus:plexus-classworlds from 2.12.0 to 2.12.1
  • c3ff08f Bump org.codehaus.plexus:plexus-velocity from 2.3.0 to 2.4.0
  • 649559a Bump org.codehaus.plexus:plexus-i18n from 1.1.0 to 1.2.0
  • Additional commits viewable in compare view

Updates org.slf4j:slf4j-ext from 2.0.18 to 2.0.19

Updates org.slf4j:slf4j-api from 2.0.18 to 2.0.19

Updates com.auth0:java-jwt from 4.6.0 to 4.6.1

Release notes

Sourced from com.auth0:java-jwt's releases.

4.6.1

Added

Changelog

Sourced from com.auth0:java-jwt's changelog.

4.6.1 (2026-09-08)

Full Changelog

Added

Commits
  • 29f252b Release 4.6.1 (#803)
  • 4674f5a Bump actions/setup-java from 5 to 6 (#798)
  • f9c6113 chore: update bouncycastle (#801)
  • bca344b chore: Remove Semgrep Workflow (#802)
  • b7645c2 Bump gradle/actions/setup-gradle from 6.2.0 to 6.3.0 (#796)
  • eb1b160 Bump com.fasterxml.jackson.core:jackson-core from 2.22.1 to 2.22.2 in /lib (#...
  • f4a2401 Bump gradle/actions/wrapper-validation from 6.2.0 to 6.3.0 (#795)
  • 021af99 Bump com.fasterxml.jackson.core:jackson-core from 2.22.0 to 2.22.1 in /lib (#...
  • 4994fdf chore: remove unused imports (#794)
  • See full diff in compare view

Updates io.netty:netty-bom from 4.2.17.Final to 4.2.18.Final

Release notes

Sourced from io.netty:netty-bom's releases.

netty-4.2.18.Final

Security fixes

  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-http (SPDY)
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-http (HTTP/1.1)
  • CVE-2026-XXXXX : denial of service vector in io.netty:netty-codec-http2
  • CVE-2026-XXXXX : improper certificate validation in io.netty:netty-handler-ssl-ocsp
  • CVE-2026-XXXXX : memory leak in io.netty:netty-codec-stomp
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-http
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http3
  • CVE-2026-XXXXX : denial of service vector in io.netty:netty-codec-stomp
  • CVE-2026-XXXXX : parser desync/response smuggling in io.netty:netty-codec-memcache
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-http3
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-http3
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-http3
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-smtp
  • CVE-2026-XXXXX : memory leak in io.netty:netty-codec-haproxy
  • CVE-2026-XXXXX : request smuggling in io.netty:netty-codec-http (RTSP)
  • CVE-2026-XXXXX : request smuggling in io.netty:netty-codec-http (HTTP/1)
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http2
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http (HTTP/1)
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http3
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http3 and in io.netty:netty-codec-http2
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http2
  • CVE-2026-XXXXX : improper hostname verification in io.netty:netty-codec-classes-quic
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-redis
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http (HTTP/1.1)
  • CVE-2026-XXXXX : request smuggling vector in io.netty:netty-codec-http (HTTP/1.1)
  • CVE-2026-XXXXX : unbounded resource usage in io.netty:netty-codec-mqtt
  • CVE-2026-XXXXX : improper CRLF neutralization in io.netty:netty-codec-smtp
  • CVE-2026-XXXXX : improper certificate validation in io.netty:netty-handler-ssl-ocsp
  • CVE-2026-XXXXX : improper header validation in io.netty:netty-codec-http2

Compatibility Notes

A number of security fixes have added additional validation and impose new resource usage limits, which may cause existing workloads to fail or be rejected. We recommend that you test your systems thoroughly as part of your Netty upgrade.

Two specific changes are worth calling out:

QUIC now explicitly requires X509ExtendedTrustManager when hostname verification is enabled. Previously, when configuring QUIC with an endpoint identification algorithm and an X509TrustManager, hostname verification would be silently skipped. This is now considered a misconfiguration and an exception will be thrown.

HTTP/2 header value validation is now enabled by default. HTTP/2 header name validation has always been enabled by default, with an option to disable it, but HTTP/2 header value validation has been disabled by default until now. Configuration options still exist to disable this, but validation of HTTP header names and values are now both opt-in by default rather than opt-out.

What's Changed

... (truncated)

Commits
  • 2521f49 [maven-release-plugin] prepare release netty-4.2.18.Final
  • 6fd5327 HTTP/1 absolute-form Host mismatch is translated to HTTP/3 :authority, overri...
  • c44a052 SPDY: SpdySessionHandler must limit the concurrent streams
  • 374d965 HTTP: Limit the maximum number of concurrent pipelined requests
  • 7e8b325 HTTP/2: Limit HPACK encoding table size
  • e3ebf70 OCSP: Correctly handle that nextUpdate is optional
  • 5388535 STOMP: Correctly release partial content on handler removal
  • 3a80f5a WebSockets: Enforce a limit for the max pipelined requests in WebSocketServer...
  • 1b6ea48 HTTP3: Correctly handle ":authority" and "host" headers
  • 3630659 STOMP codec content-length long-to-int truncation causes infinite decode loop...
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the production-minor-patch group with 6 updates:

| Package | From | To |
| --- | --- | --- |
| org.slf4j:jcl-over-slf4j | `2.0.18` | `2.0.19` |
| org.slf4j:slf4j-ext | `2.0.18` | `2.0.19` |
| [org.apache.maven.plugin-tools:maven-plugin-annotations](https://github.com/apache/maven-plugin-tools) | `3.15.2` | `3.16.0` |
| org.slf4j:slf4j-api | `2.0.18` | `2.0.19` |
| [com.auth0:java-jwt](https://github.com/auth0/java-jwt) | `4.6.0` | `4.6.1` |
| [io.netty:netty-bom](https://github.com/netty/netty) | `4.2.17.Final` | `4.2.18.Final` |


Updates `org.slf4j:jcl-over-slf4j` from 2.0.18 to 2.0.19

Updates `org.slf4j:slf4j-ext` from 2.0.18 to 2.0.19

Updates `org.apache.maven.plugin-tools:maven-plugin-annotations` from 3.15.2 to 3.16.0
- [Release notes](https://github.com/apache/maven-plugin-tools/releases)
- [Commits](apache/maven-plugin-tools@maven-plugin-tools-3.15.2...maven-plugin-tools-3.16.0)

Updates `org.slf4j:slf4j-ext` from 2.0.18 to 2.0.19

Updates `org.slf4j:slf4j-api` from 2.0.18 to 2.0.19

Updates `com.auth0:java-jwt` from 4.6.0 to 4.6.1
- [Release notes](https://github.com/auth0/java-jwt/releases)
- [Changelog](https://github.com/auth0/java-jwt/blob/master/CHANGELOG.md)
- [Commits](auth0/java-jwt@4.6.0...4.6.1)

Updates `io.netty:netty-bom` from 4.2.17.Final to 4.2.18.Final
- [Release notes](https://github.com/netty/netty/releases)
- [Commits](netty/netty@netty-4.2.17.Final...netty-4.2.18.Final)

---
updated-dependencies:
- dependency-name: org.slf4j:jcl-over-slf4j
  dependency-version: 2.0.19
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
- dependency-name: org.slf4j:slf4j-ext
  dependency-version: 2.0.19
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
- dependency-name: org.apache.maven.plugin-tools:maven-plugin-annotations
  dependency-version: 3.16.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: production-minor-patch
- dependency-name: org.slf4j:slf4j-ext
  dependency-version: 2.0.19
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
- dependency-name: org.slf4j:slf4j-api
  dependency-version: 2.0.19
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
- dependency-name: com.auth0:java-jwt
  dependency-version: 4.6.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
- dependency-name: io.netty:netty-bom
  dependency-version: 4.2.18.Final
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: production-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Sep 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants