Skip to content

Update dependency io.dropwizard:dropwizard-testing to v2 - abandoned#635

Open
mend-for-github-com[bot] wants to merge 1 commit intomasterfrom
whitesource-remediate/io.dropwizard-dropwizard-testing-2.x
Open

Update dependency io.dropwizard:dropwizard-testing to v2 - abandoned#635
mend-for-github-com[bot] wants to merge 1 commit intomasterfrom
whitesource-remediate/io.dropwizard-dropwizard-testing-2.x

Conversation

@mend-for-github-com
Copy link

@mend-for-github-com mend-for-github-com bot commented May 15, 2022

This PR contains the following updates:

Package Update Change
io.dropwizard:dropwizard-testing major 0.8.0 -> 2.0.22

By merging this PR, the below issues will be automatically resolved and closed:

Severity CVSS Score CVE GitHub Issue
High 9.8 CVE-2016-4800 #279
High 9.8 CVE-2016-4800 #279
High 9.8 CVE-2017-7657 #372
High 9.8 CVE-2017-7657 #372
High 9.8 CVE-2017-7658 #370
High 9.8 CVE-2017-7658 #370
High 7.5 CVE-2017-7656 #374
High 7.5 CVE-2017-7656 #374
High 7.5 CVE-2017-9735 #403
High 7.5 CVE-2021-28165 #165
High 7.0 CVE-2020-27216 #379
Medium 6.1 CVE-2019-10241 #282
Medium 6.1 CVE-2019-10241 #282
Medium 6.1 CVE-2019-10241 #282
Medium 5.3 CVE-2019-10247 #288
Medium 5.3 CVE-2020-10693 #192
Medium 5.3 CVE-2021-28169 #166
Medium 5.3 CVE-2021-28169 #166
Low 3.5 CVE-2021-34428 #29

By merging this PR, the below issues will be automatically resolved and closed:

Severity CVSS Score CVE GitHub Issue
High 9.8 CVE-2019-14540 #297
High 9.8 CVE-2019-16942 #331
High 9.8 CVE-2019-16943 #333
High 9.8 CVE-2019-17531 #4
High 9.8 CVE-2019-20330 #219
High 9.8 CVE-2020-8840 #53
High 9.8 CVE-2020-9546 #345
High 9.8 CVE-2020-9547 #346
High 9.8 CVE-2020-9548 #347
High 8.8 CVE-2020-10672 #175
High 8.8 CVE-2020-10673 #176
High 8.8 CVE-2020-10968 #96
High 8.8 CVE-2020-10969 #98
High 8.8 CVE-2020-11111 #248
High 8.8 CVE-2020-11112 #250
High 8.8 CVE-2020-11113 #249
High 8.1 CVE-2020-11619 #144
High 8.1 CVE-2020-11620 #156
High 8.1 CVE-2020-14060 #56
High 8.1 CVE-2020-14061 #57
High 8.1 CVE-2020-14062 #58
High 8.1 CVE-2020-14195 #73
High 8.1 CVE-2020-24616 #209
High 8.1 CVE-2020-24750 #213
High 8.1 CVE-2020-35490 #326
High 8.1 CVE-2020-35491 #329
High 8.1 CVE-2020-35728 #188
High 8.1 CVE-2020-36179 #389
High 8.1 CVE-2020-36180 #41
High 8.1 CVE-2020-36181 #40
High 8.1 CVE-2020-36182 #43
High 8.1 CVE-2020-36183 #42
High 8.1 CVE-2020-36184 #47
High 8.1 CVE-2020-36185 #45
High 8.1 CVE-2020-36186 #49
High 8.1 CVE-2020-36187 #48
High 8.1 CVE-2020-36188 #37
High 8.1 CVE-2020-36189 #36
High 8.1 CVE-2021-20190 #163
High 7.5 CVE-2020-25649 #268
Medium 5.3 CVE-2021-28169 #166

Release Notes

dropwizard/dropwizard

v2.0.22

Upgrade notes for dropwizard-jdbi3 users

Starting with Jdbi 3.19.0, the Jdbi project started pulling in Caffeine 3.x as a transitive dependency which only works with Java 11 or later:

Java 8 support is considered deprecated and will be maintained best-effort for now, but will be going away soon! In order to run on 8, you might need to dependency-manage your caffeine version back to 2.x. 3.x is required to run on newer JDKs, but will not run on 8.

Source: http://jdbi.org/#\_java_compatibility

If you're still on Java 8, you'll have to exclude the com.github.ben-manes.caffeine:caffeine dependency or force the version to a Caffeine release which still works with Java 8.

See also https://github.com/jdbi/jdbi/issues/1853.

Improvements
  • Add method to AbstractDAO to get NamedQuery in a type-safe manner (#​3978)
  • Implement expandChildren() in ContextRoutingHandler (#​3997)
Dependency updates
  • Bump Dropwizard Metrics from 4.1.19 to 4.1.22 (#​3893, #​3990, #​3939)
  • Bump byte-buddy from 1.10.22 to 1.11.0 (#​3883)
  • Bump checker-qual from 3.12.0 to 3.13.0 (#​3928)
  • Bump error_prone_annotations from 2.6.0 to 2.7.1 (#​3966)
  • Bump hibernate-core from 5.4.30.Final to 5.4.31.Final (#​3916)
  • Bump jdbi3-bom from 3.18.1 to 3.20.0 (#​3855, #​3892)
  • Bump jetty.version from 9.4.39.v20210325 to 9.4.41.v20210516 (#​3879, #​3976)
  • Force commons-codec 1.15 to address WS-2019-0379 (#​3856)
  • Update dependency com.github.ben-manes.caffeine:caffeine to v2.9.1 (#​3937)
  • Update dependency com.uber.nullaway:nullaway to v0.9.1 (#​3848)
  • Update dependency org.apache.tomcat:tomcat-jdbc to v9.0.46 (#​3965)
  • Bump awaitility from 4.0.3 to 4.1.0 (#​3943)
  • Bump javassist from 3.27.0-GA to 3.28.0-GA (#​3944)
  • Bump jmh.version from 1.29 to 1.31 (#​3934, #​3960)
  • Bump junit-jupiter from 5.7.1 to 5.7.2 (#​3970, #​3971)
  • Bump mockito.version from 3.8.0 to 3.10.0 (#​3845, #​3961)
  • Bump mysql-connector-java from 8.0.23 to 8.0.25 (#​3886, #​3954)
  • Bump testcontainers-bom from 1.15.2 to 1.15.3 (#​3880)
  • Bump jacoco-maven-plugin from 0.8.6 to 0.8.7 (#​3930)
  • Bump pgpverify-maven-plugin from 1.11.0 to 1.12.0 (#​3862)
  • Bump maven-gpg-plugin from 1.6 to 3.0.1 (#​3945)
  • Bump maven-javadoc-plugin from 3.2.0 to 3.3.0 (#​3993, #​3995)
  • Bump maven-project-info-reports-plugin from 3.1.1 to 3.1.2 (#​3920, #​3940)
  • Bump sonar-maven-plugin from 3.8.0.2131 to 3.9.0.2155 (#​3915)
  • Bump octokit from 4.20.0 to 4.21.0 in /docs (#​3906)
  • Bump sphinx from 3.5.3 to 4.0.2 in /docs (#​3867, #​3953, #​3986)
  • Update actions/cache action to v2.1.5 (#​3874)
  • Bump actions/checkout from 2 to 2.3.4 (#​3958)
  • Update actions/stale action to v3.0.19
Documentation
  • Add example for using HK2 for DI in your project (#​3177)
Assorted
  • Exclude TLSv1.1 in HttpsConnectorFactoryTest (#​3894)
  • Make ResourceExtensionRandomPortsTest less flaky (#​3897)
  • Use maven-surefire-plugin in archetype compatible with JUnit 5 (#​3936)

v2.0.21

⚠️ Security fixes
Bug fixes
  • Ensure correct TreeTraversingParser initialization in BaseConfigurationFactory (#​3800)
  • Properly support HTTP/1.1 in Http2ConnectorFactory (#​3786)
Dependency updates
  • Bump byte-buddy from 1.10.21 to 1.10.22 (#​3768)
  • Bump checker-qual from 3.10.0 to 3.12.0 (#​3740, #​3832)
  • Bump commons-lang3 from 3.11 to 3.12.0 (#​3742)
  • Bump conscrypt-openjdk-uber from 2.5.1 to 2.5.2 (#​3826)
  • Bump error_prone_annotations from 2.5.1 to 2.6.0 (#​3829)
  • Bump guava from 30.1-jre to 30.1.1-jre (#​3799)
  • Bump hibernate-core from 5.4.28.Final to 5.4.30.Final (#​3752, #​3795)
  • Bump jdbi3-bom from 3.18.0 to 3.18.1 (#​3820)
  • Bump metrics-bom from 4.1.18 to 4.1.19 (#​3842)
  • Update dependency com.uber.nullaway:nullaway to v0.9.0 (master) (#​3728)
  • Update dependency org.apache.tomcat:tomcat-jdbc to v9.0.45 (#​3771, #​3838)
  • Update dependency org.liquibase:liquibase-core to v3.10.3 (release/2.0.x) (#​3764)
  • Bump jmh.version from 1.27 to 1.29 (#​3741, #​3817)
  • Bump jna from 5.7.0 to 5.8.0 (#​3811)
  • Update dependency org.apache.maven.plugins:maven-project-info-reports-plugin to v3.1.1 (master) (#​3729)
  • Bump sphinx from 3.5.2 to 3.5.3 in /docs (#​3804)
  • Bump sphinx-autobuild from 2020.9.1 to 2021.3.14 in /docs (#​3781)
  • Bump sphinx-rtd-theme from 0.5.1 to 0.5.2 in /docs (#​3836)
  • Update actions/stale action to v3.0.18
  • Update dependency Sphinx to v3.5.2
  • Bump Maven to version 3.8.1
Assorted
  • Add assertions for json-logging start() and stop() methods (#​3689)
  • Add assertions to some tests which lacked them (#​3730)
  • Address some Sonar issues (#​3737)
  • Appease Sonar in dropwizard-benchmarks (#​3703)
  • Improve dropwizard-example integration test logging assertions
  • Make jUnit 4 test methods public (#​3727)
  • Remove Apache HttpClient from dropwizard-e2e (#​3713)
  • Remove public modifiers from tests (#​3691)
  • Update list of keyservers to validate dependency signatures
  • Skip POM signature verification (#​3789)
  • Support clearing the GitHub workflow cache (#​3787)

v2.0.20

Dependency updates

  • Bump byte-buddy from 1.10.19 to 1.10.21 (#​3681, #​3716)
  • Bump caffeine from 2.8.8 to 2.9.0 (#​3710)
  • Bump checker-qual from 3.9.1 to 3.10.0 (#​3679)
  • Bump freemarker from 2.3.30 to 2.3.31 (#​3711)
  • Bump hibernate-core from 5.4.24.Final to 5.4.28.Final (#​3698)
  • Bump jetty.version from 9.4.36.v20210114 to 9.4.37.v20210219 (#​3721)
  • Bump jna from 5.6.0 to 5.7.0 (#​3696)
  • Bump joda-time from 2.10.9 to 2.10.10 (#​3694)
  • Bump metrics-bom from 4.1.17 to 4.1.18 (#​3722)
  • Bump tomcat-jdbc from 9.0.41 to 9.0.43 (#​3723)
  • Bump junit from 4.13.1 to 4.13.2 (#​3706)
  • Bump junit-jupiter from 5.7.0 to 5.7.1 (#​3683)
  • Bump junit5.version from 5.7.0 to 5.7.1 (#​3682)
  • Bump mockito.version from 3.7.7 to 3.8.0 (#​3719)
  • Bump testcontainers-bom from 1.15.1 to 1.15.2 (#​3700)
  • Bump maven-invoker-plugin from 3.2.1 to 3.2.2 (#​3715)
  • Bump sphinx-maven-plugin from 2.9.0 to 2.10.0 (#​3699)
  • Bump actions/cache from v2.1.3 to v2.1.4 (#​3684)
  • Bump actions/stale from v3.0.15 to v3.0.17 (#​3695, #​3712)
  • Bump sphinx from 3.4.3 to 3.5.1 in /docs (#​3705, #​3709)

Assorted

  • Address SonarCloud concerns in dropwizard-auth (#​3688)
  • Ensure FileAppenderFactoryTest works within its temporary directories (#​3692)
  • Refactor testing of thrown exceptions (#​3676)
  • Refactor testing of thrown exceptions in dropwizard-client (#​3686)
  • Remove public modifiers from dropwizard-assets tests (#​3687)

v2.0.19

Upgrade notes

Improvements

  • Add support for testing plain Command classes (#​3673)

Dependency updates

  • Upgrade to Jersey 2.33 (#​3671)
  • Bump jetty.version from 9.4.35.v20201120 to 9.4.36.v20210114 (#​3662)
  • Bump checker-qual from 3.9.0 to 3.9.1 (#​3653)
  • Bump error_prone_annotations from 2.4.0 to 2.5.1 (#​3656)
  • Bump assertj-core from 3.18.1 to 3.19.0 (#​3665)
  • Bump mockito.version from 3.7.0 to 3.7.7 (#​3659)
  • Bump mysql-connector-java from 8.0.22 to 8.0.23 (#​3660)
  • Bump sonar-maven-plugin from 3.7.0.1746 to 3.8.0.2131 (#​3655)
  • Bump actions/stale from v3.0.14 to v3.0.15 (#​3668)

Documentation

  • Update contributors list
  • Clarify how to override ConfiguredCommand#configure (#​3675)

Assorted

  • Address SonarCloud issues (#​3666)
  • Move DropwizardSSLConnectionSocketFactoryTest to io.dropwizard.client (#​3657)
  • Reduce use of reflection in dropwizard-jetty tests (#​3658)
  • Remove apache commons-lang3 from tests (#​3625)
  • Use assertThatExceptionOfType in dropwizard-auth (#​3667)
  • Fix GitHub release workflow

v2.0.18

Improvements

  • Support custom StatsCounter in CachingAuthenticator/CachingAuthorization (#​3642)
  • DropwizardAppExtension support for RegisterExtension (#​3549, #​3649)
  • Do not print error message about class not found (#​3616)

Dependency updates

  • Bump bcprov-jdk15on from 1.67 to 1.68 (#​3614)
  • Bump byte-buddy from 1.10.18 to 1.10.19 (#​3611)
  • Bump checker-qual from 3.8.0 to 3.9.0 (#​3638)
  • Bump guava from 30.0-jre to 30.1-jre (#​3606)
  • Bump hibernate-validator from 6.1.6.Final to 6.1.7.Final (#​3608)
  • Bump joda-time from 2.10.8 to 2.10.9 (#​3628)
  • Bump metrics-bom from 4.1.16 to 4.1.17 (#​3648)
  • Bump mockito.version from 3.6.28 to 3.7.0 (#​3637)
  • Bump octokit from 4.19.0 to 4.20.0 in /docs (#​3626)
  • Bump pgpverify-maven-plugin from 1.10.1 to 1.11.0 (#​3640)
  • Bump sphinx from 3.3.1 to 3.4.3 in /docs (#​3610, #​3618, #​3635, #​3643)
  • Bump sphinx-rtd-theme from 0.5.0 to 0.5.1 in /docs (#​3636)

Documentation

  • Add missing parentheses in example docs #​3624
  • Fix typo in HttpClientBuilder Javadoc (#​3632)
  • Fix the AssertJ documentation URL (#​3620)
  • Remove unused import from Getting Started docs #​3619
  • Rename jdbi3 to db packages in example docs (#​3623)

Assorted

  • Add GitHub release workflow
  • Remove Travis CI configuration
  • Add checks for logging statements via errorprone-slf4j (#​3607)
  • Remove commons-lang3 from dropwizard-benchmarks (#​3627)
  • Remove usage of deprecated Mockito#initMocks() (#​3630)
  • Replace Mockito#verifyZeroInteractions with verifyNoInteractions (#​3631)
  • Replace Streams usage with String#join (#​3646)
  • Replace deprecated AssertJ assertions (#​3645)
  • Small cleanups (#​3621)
  • Stop ignoring exceptions in dropwizard-logging tests (#​3633)
  • Use System.lineSeparator() instead of String.format(%n") (#​3644)

v2.0.17

Dependency updates

  • Upgrade to Jackson 2.10.5.20201202 (#​3587)
  • Bump caffeine from 2.8.6 to 2.8.8 (#​3593, #​3597)
  • Bump checker-qual from 3.7.1 to 3.8.0 (#​3586)
  • Bump httpcore from 4.4.13 to 4.4.14 (#​3584)
  • Bump jdbi3-bom from 3.17.0 to 3.18.0 (#​3589)
  • Bump tomcat-jdbc from 9.0.40 to 9.0.41 (#​3600)
  • Bump jmh.version from 1.26 to 1.27 (#​3598)
  • Bump pgpverify-maven-plugin from 1.10.0 to 1.10.1 (#​3596)
  • Bump testcontainers-bom from 1.15.0 to 1.15.1 (#​3602)

Documentation

  • Fixed syntax in Testing Database Interactions example (#​3601)
  • Update FreeMarker links in documentation (#​3591)

v2.0.16

Improvements

  • Add ConfigOverride for random application ports during tests (#​3561)

Bug fixes

  • Skip errors when visiting default implementations in ConfigurationMetadata (#​3577)

Dependency updates

  • Bump hibernate-core from 5.4.23.Final to 5.4.24.Final (#​3571)
  • Bump jetty.version from 9.4.33.v20201020 to 9.4.35.v20201120 (#​3552, #​3574)
  • Bump metrics-bom from 4.1.14 to 4.1.16 (#​3566, #​3578)
  • Bump tomcat-jdbc from 9.0.39 to 9.0.40 (#​3570)
  • Bump assertj-core from 3.18.0 to 3.18.1 (#​3564)
  • Bump jna from 5.5.0 to 5.6.0 (#​3562)
  • Bump mockito.version from 3.5.15 to 3.6.28 (#​3529, #​3575)
  • Bump testcontainers-bom from 1.14.3 to 1.15.0 (#​3559)
  • Bump pgpverify-maven-plugin from 1.9.0 to 1.10.0 (#​3568)
  • Bump sphinx from 3.3.0 to 3.3.1 in /docs (#​3565)
  • Bump actions/cache from v2.1.2 to v2.1.3 (#​3560)
  • Bump actions/stale from v3.0.13 to v3.0.14 (#​3573)

Assorted

  • Tighten up commons-lang3 dependencies (#​3567)
  • Revert "Replace invalid default excludedProtocols in HttpsConnectorFactory" (#​3579)

v2.0.15

Improvements

  • Fix logFormat configuration inconsistencies (#​3530)

Bug fixes

  • Prevent deep recursion in ConfigurationMetadata (#​3536)

Security

  • Replace invalid default excludedProtocols in HttpsConnectorFactory (#​3533)
    • If you're using regular expressions in the excludedProtocols configuration setting, make sure change these to specific protocols, for example ["TLSv1", "TLSv1.1", "TLSv1.2"] instead of ["TLSv1(\.[12])?"].
  • Bump jetty.version from 9.4.32.v20200930 to 9.4.33.v20201020 (#​3522)

Dependency updates

  • Bump byte-buddy from 1.10.17 to 1.10.18 (#​3539)
  • Bump checker-qual from 3.7.0 to 3.7.1 (#​3544)
  • Bump hibernate-core from 5.4.22.Final to 5.4.23.Final (#​3538)
  • Bump joda-time from 2.10.7 to 2.10.8 (#​3525)
  • Bump assertj-core from 3.17.2 to 3.18.0 (#​3524)
  • Bump bcprov-jdk15on from 1.66 to 1.67 (#​3540)
  • Bump actions/stale from v3.0.12 to v3.0.13 (#​3545)
  • Bump sphinx from 3.2.1 to 3.3.0 in /docs (#​3543)

Assorted

  • Remove obsolete NonblockingServletHolder (#​3527)
  • Reduce flakiness of LayoutIntegrationTests (#​3537)
  • Move SonarQube settings to GitHub workflow (#​3534)

v2.0.14

Bug fixes

  • Support parsing system property configuration values as arrays when the field does not exist (#​3442)
  • Add null-checks to AnnotationSensitivePropertyNamingStrategy (#​3515)

Dependency updates

Assorted

  • Add analysis with SonarCloud (#​3493)
  • Build Dropwizard with Java 15 (#​3458)
  • Hacktoberfest: Simplify conditional experession (#​3482)
  • Fix typos in documentation (#​3483)

v2.0.13

Bug fixes

  • Handle null values in Optional* ParamConverters (#​3431)

Dependency updates

Assorted

  • Add Jersey bean validation end-to-end test (#​3391)
  • Less noisy CI output: mvn --no-transfer-progress (#​3400)

v2.0.12

Improvements

  • Swallow EofException when response was incomplete (#​3372)
  • Don't specify scope in dependencyManagement of BOM (#​3373)

Dependency updates

  • Upgrade to Jackson 2.10.5 (#​3381)
  • Bump bcprov-jdk15on from 1.65.01 to 1.66 (#​3364)
  • Bump commons-lang3 from 3.10 to 3.11 (#​3371)
  • Bump metrics-bom from 4.1.10.1 to 4.1.11 (#​3374)
  • Bump mockito.version from 3.3.3 to 3.4.0 (#​3367)
  • Bump mockito.version from 3.4.0 to 3.4.2 (#​3370)
  • Bump mockito.version from 3.4.2 to 3.4.3 (#​3375)
  • Bump mockito.version from 3.4.3 to 3.4.4 (#​3380)
  • Bump mysql-connector-java from 8.0.20 to 8.0.21 (#​3368)
  • Bump pgpverify-maven-plugin from 1.8.0 to 1.9.0 (#​3365)

Assorted

  • Add CodeQL analysis for security scans (#​3298)
  • Update wrapper to Maven 3.6.3
  • Try making App1Test#earlyEofTest() less flaky (#​3378)
  • Removed some conditional tests (test smell) (#​3379)

v2.0.11

Improvements

  • Export cache stats in CachingAuthorizer and CachingAuthenticator (#​3360)

Dependency updates

  • Bump bcprov-jdk15on from 1.65 to 1.65.01 (#​3312)
  • Bump byte-buddy from 1.10.10 to 1.10.11 (#​3324)
  • Bump byte-buddy from 1.10.11 to 1.10.12 (#​3339)
  • Bump byte-buddy from 1.10.12 to 1.10.13 (#​3354)
  • Bump caffeine from 2.8.4 to 2.8.5 (#​3353)
  • Bump checker-qual from 3.4.0 to 3.4.1 (#​3318)
  • Bump checker-qual from 3.4.1 to 3.5.0 (#​3357)
  • Bump hibernate-core from 5.4.16.Final to 5.4.17.Final (#​3316)
  • Bump hibernate-core from 5.4.17.Final to 5.4.18.Final (#​3341)
  • Bump hsqldb from 2.5.0 to 2.5.1 (#​3352)
  • Bump jakarta.servlet-api from 4.0.3 to 4.0.4 (#​3342)
  • Bump jdbi3-bom from 3.13.0 to 3.14.0 (#​3334)
  • Bump jdbi3-bom from 3.14.0 to 3.14.1 (#​3336)
  • Bump jetty.version from 9.4.29.v20200521 to 9.4.30.v20200611 (#​3333)
  • Bump maven-project-info-reports-plugin from 3.0.0 to 3.1.0 (#​3323)
  • Bump maven-shade-plugin from 3.2.3 to 3.2.4 (#​3322)
  • Bump maven-site-plugin from 3.9.0 to 3.9.1 (#​3349)
  • Bump metrics-bom from 4.1.10 to 4.1.10.1 (#​3359)
  • Bump metrics-bom from 4.1.9 to 4.1.10 (#​3358)
  • Bump sphinx from 3.0.2 to 3.0.3 in /docs
  • Bump sphinx from 3.0.3 to 3.0.4 in /docs (#​3310)
  • Bump sphinx from 3.0.4 to 3.1.0 in /docs (#​3328)
  • Bump sphinx from 3.1.0 to 3.1.1 in /docs (#​3332)
  • Bump sphinx from 3.1.1 to 3.1.2 in /docs (#​3361)
  • Bump sphinx-rtd-theme from 0.4.3 to 0.5.0 in /docs (#​3337)
  • Bump testcontainers-bom from 1.14.2 to 1.14.3 (#​3314)
  • Bump tomcat-jdbc from 9.0.35 to 9.0.36 (#​3325)
  • Bump tomcat-jdbc from 9.0.36 to 9.0.37 (#​3362)
  • Upgrade to Error Prone 2.4.0 (#​3345)
  • Upgrade to Liquibase 3.10.0 (#​3350)

Assorted

  • Remove explicit SnakeYAML dependency

Documentation

  • Add docs for includeStackTrace setting of syslog appender
  • Add documentation on JUnit 5.x support

v2.0.10

Improvements

Assorted

  • Stabilize JSON serialization of potentially flakey tests
  • Use circleci/openjdk:11-jdk-buster on CircleCI

Documentation

  • Add details on how to configure filterFactories (#​3283)
  • Added note on Task.execute method (#​3279)
  • Changed signature of Task.execute method (#​3278)

Dependency updates

  • Bump assertj-core from 3.15.0 to 3.16.0 (#​3281)
  • Bump assertj-core from 3.16.0 to 3.16.1 (#​3288)
  • Bump byte-buddy from 1.10.9 to 1.10.10 (#​3267)
  • Bump caffeine from 2.8.2 to 2.8.3 (#​3296)
  • Bump caffeine from 2.8.3 to 2.8.4 (#​3303)
  • Bump checker-qual from 3.3.0 to 3.4.0 (#​3275)
  • Bump hibernate-core from 5.4.15.Final to 5.4.16.Final (#​3297)
  • Bump hibernate-validator from 6.1.4.Final to 6.1.5.Final (#​3282)
  • Bump jersey-bom from 2.30.1 to 2.31 (#​3307)
  • Bump jetty.version from 9.4.28.v20200408 to 9.4.29.v20200521 (#​3304)
  • Bump metrics-bom from 4.1.7 to 4.1.8 (#​3294)
  • Bump metrics-bom from 4.1.8 to 4.1.9 (#​3308)
  • Bump pgpverify-maven-plugin from 1.7.0 to 1.8.0 (#​3302)
  • Bump testcontainers-bom from 1.14.1 to 1.14.2 (#​3295)
  • Bump tomcat-jdbc from 9.0.34 to 9.0.35 (#​3290)
  • Remove unused dependency on Objenesis (#​3300)

v2.0.9

Improvements

  • Allow overriding default media type in AssetServlet and AssetBundle (#​3269)
  • Fix random port assignment in Resource (dropwizard-testing) (#​3270)
  • Add

@mend-for-github-com mend-for-github-com bot added the security fix Security fix generated by WhiteSource label May 15, 2022
@mend-for-github-com mend-for-github-com bot changed the title Update dependency io.dropwizard:dropwizard-testing to v2 Update dependency io.dropwizard:dropwizard-testing to v2 - abandoned Jun 20, 2023
@mend-for-github-com
Copy link
Author

Autoclosing Skipped

This PR has been flagged for autoclosing. However, it is being skipped due to the branch being already modified. Please close/delete it manually or report a bug if you think this is in error.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

security fix Security fix generated by WhiteSource

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants