Skip to content

[CORE-69]: Bump the minor-patch-dependencies group across 1 directory with 20 updates - #169

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/main/minor-patch-dependencies-66da6b23b5
Open

[CORE-69]: Bump the minor-patch-dependencies group across 1 directory with 20 updates#169
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/main/minor-patch-dependencies-66da6b23b5

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 27, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-patch-dependencies group with 19 updates in the / directory:

Package From To
com.google.guava:guava 33.5.0-jre 33.6.0-jre
org.postgresql:postgresql 42.7.8 42.7.13
org.springframework.boot:spring-boot-starter-data-jdbc 3.5.12 3.5.16
org.springframework.boot:spring-boot-starter-web 3.5.12 3.5.16
org.springframework.boot:spring-boot-starter-validation 3.5.12 3.5.16
org.springframework.boot:spring-boot-starter-thymeleaf 3.5.12 3.5.16
org.springframework.boot:spring-boot-configuration-processor 3.5.12 3.5.16
org.springframework.boot:spring-boot-starter-test 3.5.12 3.5.16
org.springframework.boot:spring-boot-starter-actuator 3.5.12 3.5.16
org.springframework.retry:spring-retry 2.0.12 2.0.13
io.sentry:sentry-spring-boot-starter 8.29.0 8.50.1
ch.qos.logback:logback-classic 1.5.23 1.6.1
org.slf4j:slf4j-simple 2.0.17 2.0.18
org.jacoco:org.jacoco.agent 0.8.14 0.8.15
io.micrometer:micrometer-registry-prometheus 1.16.1 1.17.0
com.diffplug.spotless:spotless-plugin-gradle 8.1.0 8.9.0
de.undercouch.download:de.undercouch.download.gradle.plugin 5.6.0 5.7.0
org.springframework.boot:spring-boot-gradle-plugin 3.5.12 3.5.16
org.yaml:snakeyaml 2.5 2.6

Updates com.google.guava:guava from 33.5.0-jre to 33.6.0-jre

Release notes

Sourced from com.google.guava:guava's releases.

33.6.0

Maven

<dependency>
  <groupId>com.google.guava</groupId>
  <artifactId>guava</artifactId>
  <version>33.6.0-jre</version>
  <!-- or, for Android: -->
  <version>33.6.0-android</version>
</dependency>

Jar files

Guava requires one runtime dependency, which you can download here:

Javadoc

JDiff

Changelog

  • Migrated some classes from finalize() to PhantomReference in preparation for the removal of finalization. (786b619dd6, 7c6b17c, aeef90988d)
  • cache: Deprecated CacheBuilder APIs that use TimeUnit in favor of those that use Duration. (73f8b0bb84)
  • collect: Added toImmutableSortedMap collectors that use the natural comparator. (64d70b9f94)
  • collect: Changed ConcurrentHashMultiset, ImmutableMultimap, and TreeMultiset deserialization to avoid mutating final fields. In extremely unlikely scenarios in which an instance of that type contains an object that refers back to that instance, this could lead to a broken instance that throws NullPointerException when used. (8240c7e596, 046468055f)
  • graph: Removed @Beta from all APIs in the package. (dae9566b73)
  • graph: Added support to Graphs.transitiveClosure() for different strategies for adding self-loops. (2e13df25b2)
  • graph: Added an asNetwork() view to Graph and ValueGraph. (909c593c61)
  • hash: Added BloomFilter.serializedSize(). (df9bcc251a)
  • net: Added HttpHeaders.CDN_CACHE_CONTROL. (75331b5030)
Commits

Updates org.postgresql:postgresql from 42.7.8 to 42.7.13

Release notes

Sourced from org.postgresql:postgresql's releases.

v42.7.13

Changes

  • docs: add 42.7.13 release changelog @​davecramer (#4270)
  • Adjust EditorConfig für Makefile @​BaumiCoder (#4279)
  • fix(scram): fail closed on channel-binding downgrade (no scram bump) @​vlsi (#4272)
  • Bump pgjdbc version from 42.7.12 to 42.7.13 @​davecramer (#4269)
  • chore: remove test-anorm-sbt module and its disabled CI wiring @​vlsi (#4261)
  • refactor(test-gss): convert to Java/JUnit 5 submodule of the main build @​vlsi (#4166)
  • ci: derive PG test versions from a Renovate-managed maxPgVersion @​vlsi (#4218)
  • feat(insert): cap reWriteBatchedInserts by the protocol limit, not 128 @​vlsi (#4207)
  • refactor(metadata): derive getPrimaryKeys from pg_constraint.conkey @​vlsi (#4202)
  • fix(protocol): defer flushes until response processing @​vlsi (#4196)
  • fix(build): resolve the Temurin 8 test toolchain by vendor @​vlsi (#4257)
  • build: include multi-release source sets in the JaCoCo coverage report @​vlsi (#4256)
  • fix(ci): read java_vendor before overwriting java_distribution @​vlsi (#4255)
  • ci: generate the whole matrix in one batch, coverage job included @​vlsi (#4253)
  • ci: pass CODECOV_TOKEN so protected-branch coverage uploads succeed @​vlsi (#4254)
  • ci: collect coverage on one pinned job @​vlsi (#4245)
  • ci: apply -DqueryTimeout from the matrix query_timeout axis @​vlsi (#4246)
  • ci: make Codecov project and patch statuses informational @​vlsi (#4244)
  • fix(build): restore JaCoCo XML report so Codecov receives coverage @​vlsi (#4240)
  • test(replication): shrink big-transaction inserts to avoid CI timeouts @​vlsi (#4243)
  • update maintainers @​davecramer (#4222)
  • test: add hermetic test for localSocketAddress @​vlsi (#4224)
  • docs(translation): clean up leftover German header in ja.po @​vlsi (#4206)
  • Update ja.po @​davecramer (#2004)
  • test: add PostgreSQL 18 to the CI test matrix @​vlsi (#4198)
  • test: silence expected SSPI warning stack trace in SSPIClientWaffleTest @​vlsi (#4197)
  • fix(ssl): build PKIX trust anchors without a KeyStore so FIPS-mode JVMs can load sslrootcert @​vlsi (#4193)
  • test: fix flaky sentLocationEqualToLastReceiveLSN replication test @​vlsi (#4175)
  • build: promote MethodCanBeStatic to error level @​vlsi (#4172)
  • Fix PGInterval.setSeconds to reject out of range and NaN values @​sehrope (#4194)
  • Replace connectThreadFactory with connectExecutor @​sehrope (#4165)
  • Fix deleting temp file when spooling large stream to disk in StreamWrapper @​sehrope (#4190)
  • chore: Add top level /scratch to gitignore @​sehrope (#4164)
  • refactor: favour composition over inheritance for Driver.ConnectTask @​vlsi (#4160)
  • Fix NumberParser.getFastLong(...) handling of overlong values @​sehrope (#4163)
  • build: produce a multi-release jar from reduced-pom.xml on Java 11+ @​vlsi (#4157)
  • Add connectThreadFactory and refactor Driver to use FutureTask for loginTimeout connection attempts @​sehrope (#4120)
  • test: verify custom properties reach socket factory @​vlsi (#4125)
  • test: fix LazyCleanerTest timeouts for the lingering Java 8 cleanup thread @​vlsi (#4122)
  • test: stabilise StatementTest.fastCloses on Windows @​vlsi (#4121)
  • fix: append default non-proxy hosts when socksNonProxyHosts is set @​davecramer (#4045)
  • test: budget terminating Sync in BatchDeadlockTest small-RETURNING branch @​vlsi (#4116)
  • test: make message assertions locale-independent @​vlsi (#4113)
  • build: drop xgettext default keywords; regenerate translations @​vlsi (#4100)
  • ci: opt-in scheduled workflows via ENABLE_SCHEDULED_JOBS repo variable @​vlsi (#4085)
  • Avoid direct java.lang.management dependency in maxResultBuffer parser @​mblakley-casana (#4069)
  • fix: restore pre-describe for generated-key batches @​bilalshehata (#4014)

... (truncated)

Changelog

Sourced from org.postgresql:postgresql's changelog.

[42.7.13] (2026-07-06)

Added

  • feat: invalidate the prepared-statement cache when the server reports a search_path change via GUC_REPORT (PostgreSQL 18+), so cached plans are no longer used against the wrong schema [PR #4259](pgjdbc/pgjdbc#4259)
  • feat: reWriteBatchedInserts now merges up to 32768 rows into one multi-values INSERT (bounded by the 65535 bind-parameter limit on the extended protocol) instead of capping at 128, which speeds up batches of few-column rows. The new reWriteBatchedInsertsSize connection property lowers that cap when set; the default of 0 uses that maximum. [PR #4207](pgjdbc/pgjdbc#4207)
  • feat: invalidate the prepared-statement cache after CREATE/DROP/ALTER so callers no longer trip on "cached plan must not change result type" without opting into autosave=ALWAYS. Controlled by the new flushCacheOnDdl connection property (default true); set to false for the prior behaviour. [PR #4067](pgjdbc/pgjdbc#4067)
  • feat: add connectExecutor connection property to customize the Executor used to run the worker task that performs the connection attempt when loginTimeout is in effect. The value is the fully qualified name of a class implementing java.util.concurrent.Executor. With a null value, the default, the driver retains the prior behavior of running the connection attempt on a daemon thread named "PostgreSQL JDBC driver connection thread". The executor must run the task on a thread other than the caller's. Running the attempt on a named thread lets applications that monitor driver-created threads identify it. [PR #4165](pgjdbc/pgjdbc#4165)
  • feat: add classLoaderStrategy connection property to control which classloaders the driver searches when loading a class named by a connection property, for example socketFactory. The default driver-first now falls back to the thread context classloader when the driver's classloader cannot resolve the class, which fixes class loading in non-flat class paths such as Quarkus and OSGi. Set driver to keep the previous driver-classloader-only behaviour, or context-first to prefer the thread context classloader [Issue #2112](pgjdbc/pgjdbc#2112) [PR #4167](pgjdbc/pgjdbc#4167)
  • feat: add OID constants for geometric arrays, RECORD, and refcursor [PR #4220](pgjdbc/pgjdbc#4220)
  • feat: LargeObject BlobInputStream now skips by seeking instead of reading, and the driver exposes the server version so it can select the 64-bit large-object API where available [PR #4204](pgjdbc/pgjdbc#4204)

Changed

  • refactor: the worker that runs the connection attempt under loginTimeout is now a FutureTask (ConnectTask) instead of the hand-rolled ConnectThread. When the caller hits the timeout, the task is now cancelled with cancel(true), which interrupts the worker thread rather than letting it run to completion. This makes the connection attempt interruptible, so loginTimeout can stop a slow connection attempt instead of leaking a thread. As before, a connection that the worker still manages to establish after the caller gives up is closed by the worker so that it does not leak. There are no public API changes and this should only lead to faster background resource cleanup for connections that time out. [PR #4120](pgjdbc/pgjdbc#4120)
  • chore: PGXAConnection.ConnectionHandler now rejects setAutoCommit(false) and setSavepoint(...) during an active XA branch, in addition to the long-rejected setAutoCommit(true) / commit() / rollback(). The setSavepoint rejection was already meant to be in place but the guard misspelled the method name as setSavePoint, so savepoints silently went through. Both changes bring the proxy in line with JTA 1.2 §3.4. [PR #4114](pgjdbc/pgjdbc#4114)
  • chore: commitPrepared / rollback-of-prepared now return XAER_RMFAIL instead of XAER_RMERR when the underlying connection is left in a non-idle TransactionState. Transaction managers (Geronimo, Narayana, Atomikos) treat XAER_RMFAIL as retryable on a fresh XAResource; the prepared transaction is no longer abandoned. [PR #4114](pgjdbc/pgjdbc#4114)
  • refactor: derive getPrimaryKeys from pg_constraint.conkey [PR #4202](pgjdbc/pgjdbc#4202)

Fixed

  • fix: the published GitHub release now ships the released postgresql-<version>.jar and its detached PGP signature, taken from the same signed build that is uploaded to Maven Central, instead of a leftover SNAPSHOT jar [Issue #3812](pgjdbc/pgjdbc#3812) [PR #3814](pgjdbc/pgjdbc#3814)
  • fix: simplify the Statement#cancel state machine by dropping the redundant CANCELLED state. killTimerTask now waits for the state to return to IDLE directly, which removes a spin-forever case when more than one thread observes the cancel completing [PR #1827](pgjdbc/pgjdbc#1827).
  • perf: defer simple-query flushes until the driver reads the response, allowing BEGIN and the following query to share a network flush [Issue #3894](pgjdbc/pgjdbc#3894) [PR #4196](pgjdbc/pgjdbc#4196)
  • fix: reWriteBatchedInserts no longer throws IllegalArgumentException when batching a parameterless INSERT (for example INSERT INTO t VALUES (1, 2)) of 256 rows or more [PR #4207](pgjdbc/pgjdbc#4207)
  • fix: a comment before CALL in a CallableStatement no longer hides the native call, so OUT parameter registration works for /* comment */ call proc(?, ?) and similar. Parser.modifyJdbcCall now skips leading whitespace and SQL comments (both -- and /* */) before the call, tolerates a trailing comment after a { ... } escape, and no longer adds a spurious comma when moving an OUT parameter into a call whose arguments are only a comment [Issue #2538](pgjdbc/pgjdbc#2538) [PR #4209](pgjdbc/pgjdbc#4209)
  • fix: PreparedStatement.toString() no longer throws for a bytea value supplied as text via PGobject. Hex-format values (\x...) are validated and rendered as a bytea literal, and escape-format values are quoted and cast like any other literal [Issue #3757](pgjdbc/pgjdbc#3757) [PR #4201](pgjdbc/pgjdbc#4201)
  • fix: the driver no longer nulls the contextClassLoader of shared ForkJoinPool.commonPool() worker threads, which previously left unrelated tasks on those threads running with a null classloader [Issue #4155](pgjdbc/pgjdbc#4155) [PR #4156](pgjdbc/pgjdbc#4156)
  • fix: PgResultSet#getCharacterStream wraps String in a StringReader [PR #4063](pgjdbc/pgjdbc#4063)
  • fix: PGXAConnection no longer saves and restores the underlying connection's JDBC autoCommit flag. All XA-protocol SQL (BEGIN, PREPARE TRANSACTION, COMMIT, ROLLBACK, COMMIT PREPARED, ROLLBACK PREPARED, the recover() SELECT) is sent through QUERY_SUPPRESS_BEGIN, so the caller's autoCommit value is invariant across every XAResource call. Fixes the "2nd phase commit must be issued using an idle connection" failure during recovery on managed datasources that pool connections with autoCommit=false (TomEE, WildFly, WebSphere Liberty) [PR #4114](pgjdbc/pgjdbc#4114)
  • fix: PGXAConnection.prepare() now mutates XA state only after PREPARE TRANSACTION succeeds. A failed PREPARE previously left the driver thinking the branch was already prepared, so the follow-up rollback(xid) tried ROLLBACK PREPARED against a non-existent gid and returned XAER_RMERR. Transaction managers (Narayana) escalated this to HeuristicMixedException. With the fix, rollback(xid) takes the active-branch path and issues a plain ROLLBACK, which the server accepts cleanly. Fixes [Issue #3153](pgjdbc/pgjdbc#3153), [Issue #3123](pgjdbc/pgjdbc#3123). [PR #4114](pgjdbc/pgjdbc#4114)
  • fix: an updatable result set over an unqualified table name is now classified using only the table visible through search_path. When two schemas held a table with the same name and the same primary or unique index name but a different set of key columns, the driver took the union of both schemas' columns, so the result set could be wrongly rejected as not updatable [PR #4214](pgjdbc/pgjdbc#4214). Supersedes [PR #3400](pgjdbc/pgjdbc#3400).
  • fix: LargeObject.close() now flushes a buffered output stream before marking the object closed, so closing a large object without an explicit flush() no longer drops buffered writes. The flush runs while the object is still open (it calls back into LargeObject.write()), and lo_close always runs afterward; a failure from lo_close no longer masks an earlier flush error, and the transaction is not committed when the flush failed [Issue #4247](pgjdbc/pgjdbc#4247) [PR #4248](pgjdbc/pgjdbc#4248).
  • fix: reject empty timestamp, timestamptz, and date text with a clear SQLException (SQLState 22007) instead of an ArrayIndexOutOfBoundsException [PR #4278](pgjdbc/pgjdbc#4278)
  • fix: return null CHAR_OCTET_LENGTH for non-character columns [PR #4231](pgjdbc/pgjdbc#4231)
  • fix: honor scale in ResultSet.getBigDecimal(int, int) [PR #4211](pgjdbc/pgjdbc#4211)
  • fix: support java.time values in an updatable ResultSet updateRow() / insertRow() [PR #3848](pgjdbc/pgjdbc#3848)
  • fix: improve batching when the RETURNING clause contains varchar or numeric types [PR #4014](pgjdbc/pgjdbc#4014)
  • fix: correct estimatedReceiveBufferBytes accounting after a forced Sync [PR #4014](pgjdbc/pgjdbc#4014)
  • fix: avoid creating a transient ResultSet for describe-statement purposes, and restore the pre-describe path for generated-key batches [PR #4014](pgjdbc/pgjdbc#4014)
  • fix: add an explicit failure message when a multi-statement command executes in a batch [PR #4014](pgjdbc/pgjdbc#4014)
  • fix: detect search_path changes case-insensitively [PR #4216](pgjdbc/pgjdbc#4216)
  • fix: auto-detect the SSL key format instead of relying on the .key extension [PR #3946](pgjdbc/pgjdbc#3946)
  • fix: build PKIX trust anchors without a KeyStore so FIPS JVMs work [PR #4193](pgjdbc/pgjdbc#4193)
  • fix: use gssResponseTimeout rather than sslResponseTimeout for GSS connections [PR #4076](pgjdbc/pgjdbc#4076)
  • fix: skip the autosave savepoint for SET LOCAL / SET SESSION TRANSACTION [PR #4203](pgjdbc/pgjdbc#4203)
  • fix: do not throw AssertionError from BatchResultHandler on a closed connection [PR #4187](pgjdbc/pgjdbc#4187)
  • fix: reject SQL_TSI_FRAC_SECOND with an explicit, explained error [PR #4229](pgjdbc/pgjdbc#4229)
  • fix: reject a null URL in Driver.acceptsURL with a clear NullPointerException [PR #4205](pgjdbc/pgjdbc#4205)
  • fix: reject overlong inputs in NumberParser.getFastLong instead of silently wrapping [PR #4163](pgjdbc/pgjdbc#4163)
  • fix: reject out-of-range and NaN values in PGInterval.setSeconds [PR #4194](pgjdbc/pgjdbc#4194)
  • fix: close the socket when PgConnection setup fails after connect [PR #4161](pgjdbc/pgjdbc#4161)
  • fix: keep the LazyCleanerImpl cleanup task alive across a transient empty queue [PR #4038](pgjdbc/pgjdbc#4038)

... (truncated)

Commits
  • 3297557 docs: add 42.7.13 release changelog (#4270)
  • d93d370 style: apply Autostyle to docs/ and .github/
  • 2e05ff9 build: check docs/ and .github/ formatting with Autostyle
  • b4a6087 Adjust EditorConfig für Makefiles
  • 725cebb fix(jdbc): reject empty timestamp/timestamptz text with a clear error
  • 23a1b0d fix(scram): fail closed on channel-binding downgrade (no scram bump)
  • 0b4077a Bump pgjdbc version from 42.7.12 to 42.7.13 (#4269)
  • 394800a fix: flush LargeObject output stream before marking closed (#4248)
  • 83780f1 Maintain consistency with the use of the word maintainer vs comitter (#4234)
  • d42cad5 fix(jdbc): classify updatable result set by search_path visibility
  • Additional commits viewable in compare view

Updates org.springframework.boot:spring-boot-starter-data-jdbc from 3.5.12 to 3.5.16

Release notes

Sourced from org.springframework.boot:spring-boot-starter-data-jdbc's releases.

v3.5.16

🔨 Dependency Upgrades

v3.5.15

🐞 Bug Fixes

  • Artemis auto-configuration uses a predictable default location for the embedded broker's data #50743
  • MailSender auto-configuration does not enable hostname verification #50742
  • SSL should not be enabled when a SSL bundle is overridden to an empty string #50624
  • Layer written outside the output location of '//' exception is thrown when using extract layers in root directory #50501
  • Docker Compose support does not restore thread interrupt flag when catching InterruptedException #50451
  • RabbitProperties enables SSL even when spring.rabbitmq.ssl.bundle is overridden to an empty string #50429
  • GraphQL WebSocket support does not configure allowed origins #50391
  • Buildpack module does not validate long-to-int casts #50382
  • MappingsEndpoint reports the context's own ID as parentId when a parent exists #50373
  • Created StackTracePrinter instances have no access to the Environment #50303
  • NullPointerException in reactor-netty SniProvider when SSL bundle uses client-auth or server truststore without server-name-bundles #50301
  • Spring Boot Loader Does Not Support RSA and EC Signed Jars #50292
  • ConfigurationPropertiesReportEndpoint exposes AOP proxy internals #50273
  • Actuator's '/cloudfoundryapplication' endpoint does not work if restrictive CORS configuration is provided using a bean named corsConfigurationSource #50254
  • Meter registries are not removed from the global registry when the context is closed #50235
  • ThreadPoolTaskScheduleBuilder unnecessarily loses precision when configuring await termination time #50225
  • Apply HTML escaping to timestamp attribute in Whitelabel error page #50205
  • NimbusJwtDecoder silently accepts unknown values for spring.security.oauth2.resourceserver.jwt.jws-algorithms #50118
  • EndpointRequest links matcher unnecessarily matches HTTP methods other than GET #50095

📔 Documentation

  • Fix reference to Gradle documentation for module replacement #50641
  • Remove the use of Optional from Data Neo4j repository examples #50600
  • Fix typos in documentation #50593
  • Document Java 25 requirement for AOT cache #50482
  • Clarify dependency requirement for Bean Validation support #50290
  • Document SSL reloading with Let's Encrypt #50222
  • Polish InvalidConfigurationPropertyValueException constructor javadoc #50212
  • Document known testcontainers lifecycle issues #50210
  • Document configuring multiple connectors with Jetty #50206
  • Fix typo in Spring Security OAuth2 client registration documentation #50193

🔨 Dependency Upgrades

... (truncated)

Commits
  • 0566f69 Release v3.5.16
  • 93edd16 Next development version (v3.5.16-SNAPSHOT)
  • 5bafd0a Upgrade to Spring Integration 6.5.10
  • baf3290 Upgrade to Spring AMQP 3.2.12
  • 2c5964a Upgrade to Spring Data Bom 2025.0.13
  • dbb08aa Upgrade Antora dependencies
  • 9b281d5 Upgrade to actions/checkout 7.0.0
  • a854058 Upgrade to jfrog/setup-jfrog-cli 5.1.0
  • fc236ae Start building against Spring Integration 6.5.10 snapshots
  • 5271da7 Start building against Spring Data Bom 2025.0.13 snapshots
  • Additional commits viewable in compare view

Updates org.springframework.boot:spring-boot-starter-web from 3.5.12 to 3.5.16

Release notes

Sourced from org.springframework.boot:spring-boot-starter-web's releases.

v3.5.16

🔨 Dependency Upgrades

v3.5.15

🐞 Bug Fixes

  • Artemis auto-configuration uses a predictable default location for the embedded broker's data #50743
  • MailSender auto-configuration does not enable hostname verification #50742
  • SSL should not be enabled when a SSL bundle is overridden to an empty string #50624
  • Layer written outside the output location of '//' exception is thrown when using extract layers in root directory #50501
  • Docker Compose support does not restore thread interrupt flag when catching InterruptedException #50451
  • RabbitProperties enables SSL even when spring.rabbitmq.ssl.bundle is overridden to an empty string #50429
  • GraphQL WebSocket support does not configure allowed origins #50391
  • Buildpack module does not validate long-to-int casts #50382
  • MappingsEndpoint reports the context's own ID as parentId when a parent exists #50373
  • Created StackTracePrinter instances have no access to the Environment #50303
  • NullPointerException in reactor-netty SniProvider when SSL bundle uses client-auth or server truststore without server-name-bundles #50301
  • Spring Boot Loader Does Not Support RSA and EC Signed Jars #50292
  • ConfigurationPropertiesReportEndpoint exposes AOP proxy internals #50273
  • Actuator's '/cloudfoundryapplication' endpoint does not work if restrictive CORS configuration is provided using a bean named corsConfigurationSource #50254
  • Meter registries are not removed from the global registry when the context is closed #50235
  • ThreadPoolTaskScheduleBuilder unnecessarily loses precision when configuring await termination time #50225
  • Apply HTML escaping to timestamp attribute in Whitelabel error page #50205
  • NimbusJwtDecoder silently accepts unknown values for spring.security.oauth2.resourceserver.jwt.jws-algorithms #50118
  • EndpointRequest links matcher unnecessarily matches HTTP methods other than GET #50095

📔 Documentation

  • Fix reference to Gradle documentation for module replacement #50641
  • Remove the use of Optional from Data Neo4j repository examples #50600
  • Fix typos in documentation #50593
  • Document Java 25 requirement for AOT cache #50482
  • Clarify dependency requirement for Bean Validation support #50290
  • Document SSL reloading with Let's Encrypt #50222
  • Polish InvalidConfigurationPropertyValueException constructor javadoc #50212
  • Document known testcontainers lifecycle issues #50210
  • Document configuring multiple connectors with Jetty #50206
  • Fix typo in Spring Security OAuth2 client registration documentation #50193

🔨 Dependency Upgrades

... (truncated)

Commits
  • 0566f69 Release v3.5.16
  • 93edd16 Next development version (v3.5.16-SNAPSHOT)
  • 5bafd0a Upgrade to Spring Integration 6.5.10
  • baf3290 Upgrade to Spring AMQP 3.2.12
  • 2c5964a Upgrade to Spring Data Bom 2025.0.13
  • dbb08aa Upgrade Antora dependencies
  • 9b281d5 Upgrade to actions/checkout 7.0.0
  • a854058 Upgrade to jfrog/setup-jfrog-cli 5.1.0
  • fc236ae Start building against Spring Integration 6.5.10 snapshots
  • 5271da7 Start building against Spring Data Bom 2025.0.13 snapshots
  • Additional commits viewable in compare view

Updates org.springframework.boot:spring-boot-starter-validation from 3.5.12 to 3.5.16

Release notes

Sourced from org.springframework.boot:spring-boot-starter-validation's releases.

v3.5.16

🔨 Dependency Upgrades

v3.5.15

🐞 Bug Fixes

  • Artemis auto-configuration uses a predictable default location for the embedded broker's data #50743
  • MailSender auto-configuration does not enable hostname verification #50742
  • SSL should not be enabled when a SSL bundle is overridden to an empty string #50624
  • Layer written outside the output location of '//' exception is thrown when using extract layers in root directory #50501
  • Docker Compose support does not restore thread interrupt flag when catching InterruptedException #50451
  • RabbitProperties enables SSL even when spring.rabbitmq.ssl.bundle is overridden to an empty string #50429
  • GraphQL WebSocket support does not configure allowed origins #50391
  • Buildpack module does not validate long-to-int casts #50382
  • MappingsEndpoint reports the context's own ID as parentId when a parent exists #50373
  • Created StackTracePrinter instances have no access to the Environment #50303
  • NullPointerException in reactor-netty SniProvider when SSL bundle uses client-auth or server truststore without server-name-bundles #50301
  • Spring Boot Loader Does Not Support RSA and EC Signed Jars #50292
  • ConfigurationPropertiesReportEndpoint exposes AOP proxy internals #50273
  • Actuator's '/cloudfoundryapplication' endpoint does not work if restrictive CORS configuration is provided using a bean named corsConfigurationSource #50254
  • Meter registries are not removed from the global registry when the context is closed #50235
  • ThreadPoolTaskScheduleBuilder unnecessarily loses precision when configuring await termination time #50225
  • Apply HTML escaping to timestamp attribute in Whitelabel error page #50205
  • NimbusJwtDecoder silently accepts unknown values for spring.security.oauth2.resourceserver.jwt.jws-algorithms #50118
  • EndpointRequest links matcher unnecessarily matches HTTP methods other than GET #50095

📔 Documentation

  • Fix reference to Gradle documentation for module replacement #50641
  • Remove the use of Optional from Data Neo4j repository examples #50600
  • Fix typos in documentation #50593
  • Document Java 25 requirement for AOT cache #50482
  • Clarify dependency requirement for Bean Validation support #50290
  • Document SSL reloading with Let's Encrypt #50222
  • Polish InvalidConfigurationPropertyValueException constructor javadoc #50212
  • Document known testcontainers lifecycle issues #50210
  • Document configuring multiple connectors with Jetty #50206
  • Fix typo in Spring Security OAuth2 client registration documentation #50193

🔨 Dependency Upgrades

... (truncated)

Commits
  • 0566f69 Release v3.5.16
  • 93edd16 Next development version (v3.5.16-SNAPSHOT)
  • 5bafd0a Upgrade to Spring Integration 6.5.10
  • baf3290 Upgrade to Spring AMQP 3.2.12
  • 2c5964a Upgrade to Spring Data Bom 2025.0.13
  • dbb08aa Upgrade Antora dependencies
  • 9b281d5 Upgrade to actions/checkout 7.0.0
  • a854058 Upgrade to jfrog/setup-jfrog-cli 5.1.0
  • fc236ae Start building against Spring Integration 6.5.10 snapshots
  • 5271da7 Start building against Spring Data Bom 2025.0.13 snapshots
  • Additional commits viewable in

@dependabot
dependabot Bot requested a review from a team as a code owner July 27, 2026 18:33
@dependabot
dependabot Bot requested review from jgainerdewar and marctalbott and removed request for a team July 27, 2026 18:33
@dependabot
dependabot Bot force-pushed the dependabot/gradle/main/minor-patch-dependencies-66da6b23b5 branch from 9e2ba9e to 590318b Compare July 28, 2026 13:51
… with 20 updates

Bumps the minor-patch-dependencies group with 19 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [com.google.guava:guava](https://github.com/google/guava) | `33.5.0-jre` | `33.6.0-jre` |
| [org.postgresql:postgresql](https://github.com/pgjdbc/pgjdbc) | `42.7.8` | `42.7.13` |
| [org.springframework.boot:spring-boot-starter-data-jdbc](https://github.com/spring-projects/spring-boot) | `3.5.12` | `3.5.16` |
| [org.springframework.boot:spring-boot-starter-web](https://github.com/spring-projects/spring-boot) | `3.5.12` | `3.5.16` |
| [org.springframework.boot:spring-boot-starter-validation](https://github.com/spring-projects/spring-boot) | `3.5.12` | `3.5.16` |
| [org.springframework.boot:spring-boot-starter-thymeleaf](https://github.com/spring-projects/spring-boot) | `3.5.12` | `3.5.16` |
| [org.springframework.boot:spring-boot-configuration-processor](https://github.com/spring-projects/spring-boot) | `3.5.12` | `3.5.16` |
| [org.springframework.boot:spring-boot-starter-test](https://github.com/spring-projects/spring-boot) | `3.5.12` | `3.5.16` |
| [org.springframework.boot:spring-boot-starter-actuator](https://github.com/spring-projects/spring-boot) | `3.5.12` | `3.5.16` |
| [org.springframework.retry:spring-retry](https://github.com/spring-projects/spring-retry) | `2.0.12` | `2.0.13` |
| [io.sentry:sentry-spring-boot-starter](https://github.com/getsentry/sentry-java) | `8.29.0` | `8.50.1` |
| [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) | `1.5.23` | `1.6.1` |
| org.slf4j:slf4j-simple | `2.0.17` | `2.0.18` |
| [org.jacoco:org.jacoco.agent](https://github.com/jacoco/jacoco) | `0.8.14` | `0.8.15` |
| [io.micrometer:micrometer-registry-prometheus](https://github.com/micrometer-metrics/micrometer) | `1.16.1` | `1.17.0` |
| [com.diffplug.spotless:spotless-plugin-gradle](https://github.com/diffplug/spotless) | `8.1.0` | `8.9.0` |
| [de.undercouch.download:de.undercouch.download.gradle.plugin](https://github.com/michel-kraemer/gradle-download-task) | `5.6.0` | `5.7.0` |
| [org.springframework.boot:spring-boot-gradle-plugin](https://github.com/spring-projects/spring-boot) | `3.5.12` | `3.5.16` |
| [org.yaml:snakeyaml](https://bitbucket.org/snakeyaml/snakeyaml) | `2.5` | `2.6` |



Updates `com.google.guava:guava` from 33.5.0-jre to 33.6.0-jre
- [Release notes](https://github.com/google/guava/releases)
- [Commits](https://github.com/google/guava/commits)

Updates `org.postgresql:postgresql` from 42.7.8 to 42.7.13
- [Release notes](https://github.com/pgjdbc/pgjdbc/releases)
- [Changelog](https://github.com/pgjdbc/pgjdbc/blob/master/CHANGELOG.md)
- [Commits](pgjdbc/pgjdbc@REL42.7.8...REL42.7.13)

Updates `org.springframework.boot:spring-boot-starter-data-jdbc` from 3.5.12 to 3.5.16
- [Release notes](https://github.com/spring-projects/spring-boot/releases)
- [Commits](spring-projects/spring-boot@v3.5.12...v3.5.16)

Updates `org.springframework.boot:spring-boot-starter-web` from 3.5.12 to 3.5.16
- [Release notes](https://github.com/spring-projects/spring-boot/releases)
- [Commits](spring-projects/spring-boot@v3.5.12...v3.5.16)

Updates `org.springframework.boot:spring-boot-starter-validation` from 3.5.12 to 3.5.16
- [Release notes](https://github.com/spring-projects/spring-boot/releases)
- [Commits](spring-projects/spring-boot@v3.5.12...v3.5.16)

Updates `org.springframework.boot:spring-boot-starter-thymeleaf` from 3.5.12 to 3.5.16
- [Release notes](https://github.com/spring-projects/spring-boot/releases)
- [Commits](spring-projects/spring-boot@v3.5.12...v3.5.16)

Updates `org.springframework.boot:spring-boot-configuration-processor` from 3.5.12 to 3.5.16
- [Release notes](https://github.com/spring-projects/spring-boot/releases)
- [Commits](spring-projects/spring-boot@v3.5.12...v3.5.16)

Updates `org.springframework.boot:spring-boot-starter-test` from 3.5.12 to 3.5.16
- [Release notes](https://github.com/spring-projects/spring-boot/releases)
- [Commits](spring-projects/spring-boot@v3.5.12...v3.5.16)

Updates `org.springframework.boot:spring-boot-starter-actuator` from 3.5.12 to 3.5.16
- [Release notes](https://github.com/spring-projects/spring-boot/releases)
- [Commits](spring-projects/spring-boot@v3.5.12...v3.5.16)

Updates `org.springframework.boot:spring-boot-starter-web` from 3.5.12 to 3.5.16
- [Release notes](https://github.com/spring-projects/spring-boot/releases)
- [Commits](spring-projects/spring-boot@v3.5.12...v3.5.16)

Updates `org.springframework.boot:spring-boot-starter-validation` from 3.5.12 to 3.5.16
- [Release notes](https://github.com/spring-projects/spring-boot/releases)
- [Commits](spring-projects/spring-boot@v3.5.12...v3.5.16)

Updates `org.springframework.boot:spring-boot-starter-thymeleaf` from 3.5.12 to 3.5.16
- [Release notes](https://github.com/spring-projects/spring-boot/releases)
- [Commits](spring-projects/spring-boot@v3.5.12...v3.5.16)

Updates `org.springframework.retry:spring-retry` from 2.0.12 to 2.0.13
- [Release notes](https://github.com/spring-projects/spring-retry/releases)
- [Commits](spring-attic/spring-retry@v2.0.12...v2.0.13)

Updates `io.sentry:sentry-spring-boot-starter` from 8.29.0 to 8.50.1
- [Release notes](https://github.com/getsentry/sentry-java/releases)
- [Changelog](https://github.com/getsentry/sentry-java/blob/main/CHANGELOG.md)
- [Commits](getsentry/sentry-java@8.29.0...8.50.1)

Updates `ch.qos.logback:logback-classic` from 1.5.23 to 1.6.1
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.5.23...v_1.6.1)

Updates `ch.qos.logback:logback-core` from 1.5.23 to 1.6.1
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.5.23...v_1.6.1)

Updates `org.springframework.boot:spring-boot-configuration-processor` from 3.5.12 to 3.5.16
- [Release notes](https://github.com/spring-projects/spring-boot/releases)
- [Commits](spring-projects/spring-boot@v3.5.12...v3.5.16)

Updates `org.slf4j:slf4j-simple` from 2.0.17 to 2.0.18

Updates `org.jacoco:org.jacoco.agent` from 0.8.14 to 0.8.15
- [Release notes](https://github.com/jacoco/jacoco/releases)
- [Commits](jacoco/jacoco@v0.8.14...v0.8.15)

Updates `org.springframework.boot:spring-boot-starter-test` from 3.5.12 to 3.5.16
- [Release notes](https://github.com/spring-projects/spring-boot/releases)
- [Commits](spring-projects/spring-boot@v3.5.12...v3.5.16)

Updates `org.springframework.boot:spring-boot-starter-actuator` from 3.5.12 to 3.5.16
- [Release notes](https://github.com/spring-projects/spring-boot/releases)
- [Commits](spring-projects/spring-boot@v3.5.12...v3.5.16)

Updates `io.micrometer:micrometer-registry-prometheus` from 1.16.1 to 1.17.0
- [Release notes](https://github.com/micrometer-metrics/micrometer/releases)
- [Commits](micrometer-metrics/micrometer@v1.16.1...v1.17.0)

Updates `com.diffplug.spotless:spotless-plugin-gradle` from 8.1.0 to 8.9.0
- [Release notes](https://github.com/diffplug/spotless/releases)
- [Changelog](https://github.com/diffplug/spotless/blob/main/CHANGES.md)
- [Commits](diffplug/spotless@gradle/8.1.0...gradle/8.9.0)

Updates `de.undercouch.download:de.undercouch.download.gradle.plugin` from 5.6.0 to 5.7.0
- [Release notes](https://github.com/michel-kraemer/gradle-download-task/releases)
- [Commits](michel-kraemer/gradle-download-task@5.6.0...5.7.0)

Updates `org.springframework.boot:spring-boot-gradle-plugin` from 3.5.12 to 3.5.16
- [Release notes](https://github.com/spring-projects/spring-boot/releases)
- [Commits](spring-projects/spring-boot@v3.5.12...v3.5.16)

Updates `org.yaml:snakeyaml` from 2.5 to 2.6
- [Commits](https://bitbucket.org/snakeyaml/snakeyaml/branches/compare/snakeyaml-2.6..snakeyaml-2.5)

---
updated-dependencies:
- dependency-name: ch.qos.logback:logback-classic
  dependency-version: 1.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-patch-dependencies
- dependency-name: ch.qos.logback:logback-core
  dependency-version: 1.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-patch-dependencies
- dependency-name: com.diffplug.spotless:spotless-plugin-gradle
  dependency-version: 8.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-patch-dependencies
- dependency-name: com.google.guava:guava
  dependency-version: 33.6.0-jre
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-patch-dependencies
- dependency-name: de.undercouch.download:de.undercouch.download.gradle.plugin
  dependency-version: 5.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-patch-dependencies
- dependency-name: io.micrometer:micrometer-registry-prometheus
  dependency-version: 1.17.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-patch-dependencies
- dependency-name: io.sentry:sentry-spring-boot-starter
  dependency-version: 8.50.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-patch-dependencies
- dependency-name: org.jacoco:org.jacoco.agent
  dependency-version: 0.8.15
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch-dependencies
- dependency-name: org.postgresql:postgresql
  dependency-version: 42.7.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch-dependencies
- dependency-name: org.slf4j:slf4j-simple
  dependency-version: 2.0.18
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch-dependencies
- dependency-name: org.springframework.boot:spring-boot-configuration-processor
  dependency-version: 3.5.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch-dependencies
- dependency-name: org.springframework.boot:spring-boot-configuration-processor
  dependency-version: 3.5.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch-dependencies
- dependency-name: org.springframework.boot:spring-boot-gradle-plugin
  dependency-version: 3.5.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch-dependencies
- dependency-name: org.springframework.boot:spring-boot-starter-actuator
  dependency-version: 3.5.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch-dependencies
- dependency-name: org.springframework.boot:spring-boot-starter-actuator
  dependency-version: 3.5.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch-dependencies
- dependency-name: org.springframework.boot:spring-boot-starter-data-jdbc
  dependency-version: 3.5.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch-dependencies
- dependency-name: org.springframework.boot:spring-boot-starter-test
  dependency-version: 3.5.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch-dependencies
- dependency-name: org.springframework.boot:spring-boot-starter-test
  dependency-version: 3.5.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch-dependencies
- dependency-name: org.springframework.boot:spring-boot-starter-thymeleaf
  dependency-version: 3.5.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch-dependencies
- dependency-name: org.springframework.boot:spring-boot-starter-thymeleaf
  dependency-version: 3.5.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch-dependencies
- dependency-name: org.springframework.boot:spring-boot-starter-validation
  dependency-version: 3.5.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch-dependencies
- dependency-name: org.springframework.boot:spring-boot-starter-validation
  dependency-version: 3.5.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch-dependencies
- dependency-name: org.springframework.boot:spring-boot-starter-web
  dependency-version: 3.5.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch-dependencies
- dependency-name: org.springframework.boot:spring-boot-starter-web
  dependency-version: 3.5.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch-dependencies
- dependency-name: org.springframework.retry:spring-retry
  dependency-version: 2.0.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-patch-dependencies
- dependency-name: org.yaml:snakeyaml
  dependency-version: '2.6'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-patch-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/gradle/main/minor-patch-dependencies-66da6b23b5 branch from 590318b to d4db3d3 Compare July 29, 2026 14:31
@sonarqubecloud

Copy link
Copy Markdown

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants