chore: [DevOps] bump the production-minor-patch group across 1 directory with 13 updates#1116
Merged
bot-sdk-js merged 1 commit intomainfrom Mar 10, 2026
Conversation
…ory with 13 updates Bumps the production-minor-patch group with 13 updates in the / directory: | Package | From | To | | --- | --- | --- | | org.apache.maven:maven-core | `3.9.12` | `3.9.13` | | [org.apache.maven:maven-plugin-api](https://github.com/apache/maven) | `3.9.12` | `3.9.13` | | [org.apache.maven:maven-compat](https://github.com/apache/maven) | `3.9.12` | `3.9.13` | | io.swagger.core.v3:swagger-models | `2.2.43` | `2.2.44` | | [org.assertj:assertj-vavr](https://github.com/assertj/assertj-vavr) | `0.4.3` | `0.5.0` | | [org.yaml:snakeyaml](https://bitbucket.org/snakeyaml/snakeyaml) | `2.5` | `2.6` | | [com.sap.cloud.security:java-bom](https://github.com/SAP/cloud-security-xsuaa-integration) | `3.6.6` | `3.6.8` | | [io.vavr:vavr](https://github.com/vavr-io/vavr) | `1.0.0` | `1.0.1` | | [org.checkerframework:checker-qual](https://github.com/typetools/checker-framework) | `3.53.1` | `3.54.0` | | [com.google.errorprone:error_prone_annotations](https://github.com/google/error-prone) | `2.47.0` | `2.48.0` | | [io.spiffe:java-spiffe-core](https://github.com/spiffe/java-spiffe) | `0.8.15` | `0.8.16` | | [io.spiffe:grpc-netty-linux](https://github.com/spiffe/java-spiffe) | `0.8.15` | `0.8.16` | | [joda-time:joda-time](https://github.com/JodaOrg/joda-time) | `2.14.0` | `2.14.1` | Updates `org.apache.maven:maven-core` from 3.9.12 to 3.9.13 Updates `org.apache.maven:maven-plugin-api` from 3.9.12 to 3.9.13 - [Release notes](https://github.com/apache/maven/releases) - [Commits](apache/maven@maven-3.9.12...maven-3.9.13) Updates `org.apache.maven:maven-compat` from 3.9.12 to 3.9.13 - [Release notes](https://github.com/apache/maven/releases) - [Commits](apache/maven@maven-3.9.12...maven-3.9.13) Updates `org.apache.maven:maven-plugin-api` from 3.9.12 to 3.9.13 - [Release notes](https://github.com/apache/maven/releases) - [Commits](apache/maven@maven-3.9.12...maven-3.9.13) Updates `io.swagger.core.v3:swagger-models` from 2.2.43 to 2.2.44 Updates `org.assertj:assertj-vavr` from 0.4.3 to 0.5.0 - [Release notes](https://github.com/assertj/assertj-vavr/releases) - [Commits](assertj/assertj-vavr@v0.4.3...v0.5.0) Updates `org.apache.maven:maven-compat` from 3.9.12 to 3.9.13 - [Release notes](https://github.com/apache/maven/releases) - [Commits](apache/maven@maven-3.9.12...maven-3.9.13) Updates `org.yaml:snakeyaml` from 2.5 to 2.6 - [Commits](https://bitbucket.org/snakeyaml/snakeyaml/branches/compare/snakeyaml-2.6..snakeyaml-2.5) Updates `com.sap.cloud.security:java-bom` from 3.6.6 to 3.6.8 - [Release notes](https://github.com/SAP/cloud-security-xsuaa-integration/releases) - [Changelog](https://github.com/SAP/cloud-security-services-integration-library/blob/main/CHANGELOG.md) - [Commits](SAP/cloud-security-services-integration-library@3.6.6...3.6.8) Updates `io.vavr:vavr` from 1.0.0 to 1.0.1 - [Release notes](https://github.com/vavr-io/vavr/releases) - [Commits](vavr-io/vavr@v1.0.0...v1.0.1) Updates `org.checkerframework:checker-qual` from 3.53.1 to 3.54.0 - [Release notes](https://github.com/typetools/checker-framework/releases) - [Changelog](https://github.com/typetools/checker-framework/blob/master/docs/CHANGELOG.md) - [Commits](typetools/checker-framework@checker-framework-3.53.1...checker-framework-3.54.0) Updates `com.google.errorprone:error_prone_annotations` from 2.47.0 to 2.48.0 - [Release notes](https://github.com/google/error-prone/releases) - [Commits](google/error-prone@v2.47.0...v2.48.0) Updates `io.spiffe:java-spiffe-core` from 0.8.15 to 0.8.16 - [Release notes](https://github.com/spiffe/java-spiffe/releases) - [Changelog](https://github.com/spiffe/java-spiffe/blob/main/CHANGELOG.md) - [Commits](spiffe/java-spiffe@v0.8.15...v0.8.16) Updates `io.spiffe:grpc-netty-linux` from 0.8.15 to 0.8.16 - [Release notes](https://github.com/spiffe/java-spiffe/releases) - [Changelog](https://github.com/spiffe/java-spiffe/blob/main/CHANGELOG.md) - [Commits](spiffe/java-spiffe@v0.8.15...v0.8.16) Updates `joda-time:joda-time` from 2.14.0 to 2.14.1 - [Release notes](https://github.com/JodaOrg/joda-time/releases) - [Changelog](https://github.com/JodaOrg/joda-time/blob/main/RELEASE-NOTES.txt) - [Commits](JodaOrg/joda-time@v2.14.0...v2.14.1) --- updated-dependencies: - dependency-name: org.apache.maven:maven-core dependency-version: 3.9.13 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-minor-patch - dependency-name: org.apache.maven:maven-plugin-api dependency-version: 3.9.13 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-minor-patch - dependency-name: org.apache.maven:maven-compat dependency-version: 3.9.13 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-minor-patch - dependency-name: org.apache.maven:maven-plugin-api dependency-version: 3.9.13 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-minor-patch - dependency-name: io.swagger.core.v3:swagger-models dependency-version: 2.2.44 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-minor-patch - dependency-name: org.assertj:assertj-vavr dependency-version: 0.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-minor-patch - dependency-name: org.apache.maven:maven-compat dependency-version: 3.9.13 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-minor-patch - dependency-name: org.yaml:snakeyaml dependency-version: '2.6' dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-minor-patch - dependency-name: com.sap.cloud.security:java-bom dependency-version: 3.6.8 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-minor-patch - dependency-name: io.vavr:vavr dependency-version: 1.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-minor-patch - dependency-name: org.checkerframework:checker-qual dependency-version: 3.54.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-minor-patch - dependency-name: com.google.errorprone:error_prone_annotations dependency-version: 2.48.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-minor-patch - dependency-name: io.spiffe:java-spiffe-core dependency-version: 0.8.16 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-minor-patch - dependency-name: io.spiffe:grpc-netty-linux dependency-version: 0.8.16 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-minor-patch - dependency-name: joda-time:joda-time dependency-version: 2.14.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-minor-patch ... Signed-off-by: dependabot[bot] <support@github.com>
bot-sdk-js
approved these changes
Mar 10, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the production-minor-patch group with 13 updates in the / directory:
3.9.123.9.133.9.123.9.133.9.123.9.132.2.432.2.440.4.30.5.02.52.63.6.63.6.81.0.01.0.13.53.13.54.02.47.02.48.00.8.150.8.160.8.150.8.162.14.02.14.1Updates
org.apache.maven:maven-corefrom 3.9.12 to 3.9.13Updates
org.apache.maven:maven-plugin-apifrom 3.9.12 to 3.9.13Release notes
Sourced from org.apache.maven:maven-plugin-api's releases.
Commits
39d686b[maven-release-plugin] prepare release maven-3.9.131779f34Maven Resolver 1.9.27 (#11732)18a5264Bump resolverVersion from 1.9.25 to 1.9.26 (#11725)c081a92Update Maven plugin versions in default-bindings.xmldea5f14Bug: SecDispatcher is managed by legacy Plexus DI (#11711)5bcfc50Bump version.sisu-maven-plugin from 0.9.0.M4 to 1.0.0 (#11706)067cb25Bump actions/cache from 5.0.2 to 5.0.3 (#11688)d898a51Fix build71656a5Bump org.apache.maven:maven-parent from 45 to 47ad17267Bump actions/checkout from 6.0.1 to 6.0.2 (#11666)Updates
org.apache.maven:maven-compatfrom 3.9.12 to 3.9.13Release notes
Sourced from org.apache.maven:maven-compat's releases.
Commits
39d686b[maven-release-plugin] prepare release maven-3.9.131779f34Maven Resolver 1.9.27 (#11732)18a5264Bump resolverVersion from 1.9.25 to 1.9.26 (#11725)c081a92Update Maven plugin versions in default-bindings.xmldea5f14Bug: SecDispatcher is managed by legacy Plexus DI (#11711)5bcfc50Bump version.sisu-maven-plugin from 0.9.0.M4 to 1.0.0 (#11706)067cb25Bump actions/cache from 5.0.2 to 5.0.3 (#11688)d898a51Fix build71656a5Bump org.apache.maven:maven-parent from 45 to 47ad17267Bump actions/checkout from 6.0.1 to 6.0.2 (#11666)Updates
org.apache.maven:maven-plugin-apifrom 3.9.12 to 3.9.13Release notes
Sourced from org.apache.maven:maven-plugin-api's releases.
Commits
39d686b[maven-release-plugin] prepare release maven-3.9.131779f34Maven Resolver 1.9.27 (#11732)18a5264Bump resolverVersion from 1.9.25 to 1.9.26 (#11725)c081a92Update Maven plugin versions in default-bindings.xmldea5f14Bug: SecDispatcher is managed by legacy Plexus DI (#11711)5bcfc50Bump version.sisu-maven-plugin from 0.9.0.M4 to 1.0.0 (#11706)067cb25Bump actions/cache from 5.0.2 to 5.0.3 (#11688)d898a51Fix build71656a5Bump org.apache.maven:maven-parent from 45 to 47ad17267Bump actions/checkout from 6.0.1 to 6.0.2 (#11666)Updates
io.swagger.core.v3:swagger-modelsfrom 2.2.43 to 2.2.44Updates
org.assertj:assertj-vavrfrom 0.4.3 to 0.5.0Release notes
Sourced from org.assertj:assertj-vavr's releases.
Commits
c5470bf[maven-release-plugin] prepare release v0.5.006cec56fix the release job (#257)9590ce7pin remaining GitHub Actions workflows (#256)bfe9e91configure release job (#255)60f8e08fix assertions returning inaccessible types (#254)02c21feupgrade assertj-parent to 3.27.7 (#252)36d1e00rework README.MD (#253)b73e8d1Bump the github-actions group with 2 updates (#250)0651106Bump the github-actions group with 2 updates (#246)5ff1309Update CODEOWNERS to include new owner (#249)Updates
org.apache.maven:maven-compatfrom 3.9.12 to 3.9.13Release notes
Sourced from org.apache.maven:maven-compat's releases.
Commits
39d686b[maven-release-plugin] prepare release maven-3.9.131779f34Maven Resolver 1.9.27 (#11732)18a5264Bump resolverVersion from 1.9.25 to 1.9.26 (#11725)c081a92Update Maven plugin versions in default-bindings.xmldea5f14Bug: SecDispatcher is managed by legacy Plexus DI (#11711)5bcfc50Bump version.sisu-maven-plugin from 0.9.0.M4 to 1.0.0 (#11706)067cb25Bump actions/cache from 5.0.2 to 5.0.3 (#11688)d898a51Fix build71656a5Bump org.apache.maven:maven-parent from 45 to 47ad17267Bump actions/checkout from 6.0.1 to 6.0.2 (#11666)Updates
org.yaml:snakeyamlfrom 2.5 to 2.6Commits
cc19a61[maven-release-plugin] prepare for next development iterationbc4a8f4Minor fixes in Javadocf18203aAdd a test for Y79Y-003ad1fcebLess output in tests1db66b7Add (failing) build with JDK 2588ebaa8build: fix JKD 25 tests compilation6af8790Update Javadoca006b7aUpdate Javadocc143db2Update changesd78d11fUpdate changesUpdates
com.sap.cloud.security:java-bomfrom 3.6.6 to 3.6.8Release notes
Sourced from com.sap.cloud.security:java-bom's releases.
Changelog
Sourced from com.sap.cloud.security:java-bom's changelog.
Commits
dbd78a8Token exchange issue (#1927)553be9aRelease 3.6.8 (#1926)6c02d6aBump the prod-deps-ver group with 3 updates (#1925)eb76c9fMerge pull request #1921 from SAP/release-3.6.73536b93Release 3.6.748795faFix connection pool shutdown by reusing cached SSL connectionsc9061a3Fix FIPS compatibility by using default KeyManagerFactory algorithmf90715cBump the prod-deps-ver group across 1 directory with 8 updates (#1920)Updates
io.vavr:vavrfrom 1.0.0 to 1.0.1Release notes
Sourced from io.vavr:vavr's releases.
Commits
ee2a57b[maven-release-plugin] prepare release v1.0.1 [ci skip]9f4e95eupdate project version to 1.0.1-SNAPSHOT08e55f4Added the serialization proxy pattern to HashMap (#3242)Updates
org.checkerframework:checker-qualfrom 3.53.1 to 3.54.0Release notes
Sourced from org.checkerframework:checker-qual's releases.
Changelog
Sourced from org.checkerframework:checker-qual's changelog.
Commits
a6eff70new release 3.54.0fd34700Prep for release.edb6e7aPrint error key in brackets (#7525)a79b1deShow details of the error message in test failures (#7513)a5ecc22Clone the JDK using the same fork and branch as CF (#7491)2770c52Update cimg/base Docker tag to v2026.03bba6bc9Update plugin com-gradleup-shadow to v9.3.23a6d4d4Update error-prone monorepo to v2.48.070aa5f3Update plugin net-ltgt-errorprone to v5.1.00dbd3e7Prepare for javac AST changesUpdates
com.google.errorprone:error_prone_annotationsfrom 2.47.0 to 2.48.0Release notes
Sourced from com.google.errorprone:error_prone_annotations's releases.
Commits
7cec0a0Release Error Prone 2.48.001c603aExtend MissingTestCall to check for member references.3d817b0HandlevarinUnnecessaryBoxedVariablead26f3eAddConcurrentHashMap.keys()andConcurrentHashMap.elements()to `JdkObso...7926dbcFix MustBeClosedChecker crash on flexible constructors.d08f003Check for jakarta annotations in DI checks171448cAdd android internal GuardedBy to ACCEPTED_GUARDED_BY_ANNOTATIONS5cb6075Remove theMissingTestCall:MatchGraphVerifyflag.ab81681Improve crash messages for fixes that don't applyfe9bb21Add a test to confirm that TimeUnitMismatch catches `seconds * 1000 + nanos /...Updates
io.spiffe:java-spiffe-corefrom 0.8.15 to 0.8.16Release notes
Sourced from io.spiffe:java-spiffe-core's releases.
Changelog
Sourced from io.spiffe:java-spiffe-core's changelog.
Commits
393a892chore(release): prepare release 0.8.16 (#407)be7416echore(deps): bump com.nimbusds:nimbus-jose-jwt from 10.7 to 10.8 (#409)4bd0149chore(ci): bump java-spiffe-helper ci charts versions (#408)753812achore(ci): simplify dependabot config and group coupled gradle deps (#403)c616b61Bump gradle-wrapper from 9.3.0 to 9.3.1 (#401)f8e1695Bump grpcVersion from 1.78.0 to 1.79.0 (#402)157d491Bump gradle-wrapper from 9.2.1 to 9.3.0 (#400)4d1cee3fix(core): harden parsing and cache edge cases (#399)8bf98fbfix(x509source): ensure atomic snapshot of SVID and bundles (#397)f9969c1fix(spiffeid): require spiffe:// prefix when parsing IDs (#398)Updates
io.spiffe:grpc-netty-linuxfrom 0.8.15 to 0.8.16Release notes
Sourced from io.spiffe:grpc-netty-linux's releases.
Changelog
Sourced from io.spiffe:grpc-netty-linux's changelog.
Commits
393a892chore(release): prepare release 0.8.16 (#407)be7416echore(deps): bump com.nimbusds:nimbus-jose-jwt from 10.7 to 10.8 (#409)4bd0149chore(ci): bump java-spiffe-helper ci charts versions (#408)753812achore(ci): simplify dependabot config and group coupled gradle deps (#403)c616b61Bump gradle-wrapper from 9.3.0 to 9.3.1 (#401)f8e1695Bump grpcVersion from 1.78.0 to 1.79.0 (#402)157d491Bump gradle-wrapper from 9.2.1 to 9.3.0 (#400)4d1cee3fix(core): harden parsing and cache edge cases (#399)8bf98fbfix(x509source): ensure atomic snapshot of SVID and bundles (#397)f9969c1fix(spiffeid): require spiffe:// prefix when parsing IDs (#398)Updates
joda-time:joda-timefrom 2.14.0 to 2.14.1Release notes
Sourced from joda-time:joda-time's releases.