Skip to content

Bump the maven group across 2 directories with 6 updates#2

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/todolist-goof/todolist-web-common/maven-7316534976
Open

Bump the maven group across 2 directories with 6 updates#2
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/todolist-goof/todolist-web-common/maven-7316534976

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 1, 2026

Copy link
Copy Markdown

Bumps the maven group with 3 updates in the /todolist-goof/todolist-web-common directory: com.fasterxml.jackson.core:jackson-core, org.hibernate:hibernate-validator and commons-collections:commons-collections.
Bumps the maven group with 3 updates in the /todolist-goof/todolist-web-struts directory: org.apache.logging.log4j:log4j-core, org.springframework:spring-web and org.apache.struts:struts2-core.

Updates com.fasterxml.jackson.core:jackson-core from 2.6.5 to 2.18.6

Commits
  • 9a46ef8 [maven-release-plugin] prepare release jackson-core-2.18.6
  • 5f192db Prep for 2.18.6 release
  • b0c428e Enforce StreamReadConstraints.maxNumberLength for non-blocking (async) pars...
  • 7c8b6d5 Add test for nesting for DataInput-backed JsonParser (#1550)
  • 97a647b Update CI: JDK 23 -> 25
  • 1601331 (backport from 2.21) Fix #1548: validate max doc length for fixed buffer inpu...
  • fae2542 release notes update
  • 70c99ba Update UTF8DataInputJsonParser.java (#1512)
  • caea665 Post-release dep version bump
  • 635d3bd [maven-release-plugin] prepare for next development iteration
  • Additional commits viewable in compare view

Updates org.hibernate:hibernate-validator from 4.3.1.Final to 6.2.0.Final

Updates commons-collections:commons-collections from 3.1 to 3.2.2

Updates org.apache.logging.log4j:log4j-core from 2.7 to 2.25.4

Updates org.springframework:spring-web from 3.2.6.RELEASE to 6.1.21

Release notes

Sourced from org.springframework:spring-web's releases.

v6.1.21

🐞 Bug Fixes

  • Encode non-printable character in Content-Disposition parameter #35035
  • Allow update of existing WebSession after max sessions limit is reached #35018
  • Enhanced configuration class fails to call package-visible superclass constructor on WebSphere #34951

🔨 Dependency Upgrades

  • Upgrade to Reactor 2023.0.19 #35022

v6.1.20

⭐ New Features

  • Add option for case-insensitive match to PatternMatchUtils #34802

🐞 Bug Fixes

  • HttpComponentsClientHttpRequestFactory setConnectionRequestTimeout not working with httpclient 5.3.1 #34854
  • Accidental ClassLoader defineClass enforcement after #34677 #34839

📔 Documentation

  • Clarify CompositePropertySource behavior for EnumerablePropertySource contract #34887

🔨 Dependency Upgrades

  • Upgrade to Reactor 2023.0.18 #34899

v6.1.19

⭐ New Features

  • Suggest compilation with -parameters when AspectJAdviceParameterNameDiscoverer fails against ambiguity #34618

🐞 Bug Fixes

  • PropertyBatchUpdateException: causes of nested PropertyAccessExceptions not shown in output #34698
  • Change in Jar usecache behavior with Spring 6.1.x causing java.lang.IllegalStateException: zip file closed #34694
  • Startup performance regression due to CGLIB class load attempts in Spring 6.1.x #34693
  • IllegalAccessError for package-private member of AzureStorageConfiguration on WebSphere #34690
  • @Configuration classes can no longer be abstract without @Bean methods #34689
  • Generated-code for LinkedHashMap is missing static keyword #34661
  • AbstractReactiveTransactionManager throws IllegalStateException when rollback fails after commit attempt #34619

📔 Documentation

  • Add javadoc notes on potential exception suppression in ListableBeanFactory#getBeansOfType #34631
  • Remove remaining references to Forwarded headers in MvcUriComponentsBuilder #34626
  • MvcUriComponentsBuilder javadocs inaccurately reflects usage of forwarded headers #34620

... (truncated)

Commits
  • fa36b34 Release v6.1.21
  • 498ccda Upgrade to Gradle 8.14.2
  • fd68ea6 Encode non-printable character in Content-Disposition parameter
  • 28caa39 Upgrade to Reactor 2023.0.19
  • 8ecc553 Polish contribution
  • cd44efa Allow update of existing WebSession after max sessions limit is reached
  • 59d2895 Fix InMemoryWebSessionStoreTests.startsSessionImplicitly() test
  • a876bb4 Polish WebSession support and tests
  • 3b6beca Check for package-visible constructor in case of ClassLoader mismatch
  • 59ffbd7 Test conversion support in PropertySourcesPlaceholderConfigurer
  • Additional commits viewable in compare view

Updates org.apache.struts:struts2-core from 2.3.20 to 6.8.0

Release notes

Sourced from org.apache.struts:struts2-core's releases.

Struts 6.8.0

What's Changed

Dependencies

Full Changelog: apache/struts@STRUTS_6_7_4...STRUTS_6_8_0

Struts 6.7.4

What's Changed

Full Changelog: apache/struts@STRUTS_6_7_0...STRUTS_6_7_4

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the maven group with 3 updates in the /todolist-goof/todolist-web-common directory: [com.fasterxml.jackson.core:jackson-core](https://github.com/FasterXML/jackson-core), org.hibernate:hibernate-validator and commons-collections:commons-collections.
Bumps the maven group with 3 updates in the /todolist-goof/todolist-web-struts directory: org.apache.logging.log4j:log4j-core, [org.springframework:spring-web](https://github.com/spring-projects/spring-framework) and [org.apache.struts:struts2-core](https://github.com/apache/struts).


Updates `com.fasterxml.jackson.core:jackson-core` from 2.6.5 to 2.18.6
- [Commits](FasterXML/jackson-core@jackson-core-2.6.5...jackson-core-2.18.6)

Updates `org.hibernate:hibernate-validator` from 4.3.1.Final to 6.2.0.Final

Updates `commons-collections:commons-collections` from 3.1 to 3.2.2

Updates `org.apache.logging.log4j:log4j-core` from 2.7 to 2.25.4

Updates `org.springframework:spring-web` from 3.2.6.RELEASE to 6.1.21
- [Release notes](https://github.com/spring-projects/spring-framework/releases)
- [Commits](spring-projects/spring-framework@v3.2.6.RELEASE...v6.1.21)

Updates `org.apache.struts:struts2-core` from 2.3.20 to 6.8.0
- [Release notes](https://github.com/apache/struts/releases)
- [Commits](https://github.com/apache/struts/commits)

---
updated-dependencies:
- dependency-name: com.fasterxml.jackson.core:jackson-core
  dependency-version: 2.18.6
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.hibernate:hibernate-validator
  dependency-version: 6.2.0.Final
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: commons-collections:commons-collections
  dependency-version: 3.2.2
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.logging.log4j:log4j-core
  dependency-version: 2.25.4
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.springframework:spring-web
  dependency-version: 6.1.21
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.apache.struts:struts2-core
  dependency-version: 6.8.0
  dependency-type: direct:production
  dependency-group: maven
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Jul 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants