Skip to content

Conversation

@dependabot
Copy link

@dependabot dependabot bot commented on behalf of github Jun 17, 2025

Bumps the maven group with 8 updates in the / directory:

Package From To
org.apache.bcel:bcel 6.4.1 6.6.0
junit:junit 4.13 4.13.1
com.fasterxml.jackson.core:jackson-databind 2.10.2 2.12.7.1
commons-io:commons-io 2.4 2.14.0
org.eclipse.jgit:org.eclipse.jgit 5.6.1.202002131546-r 6.10.1.202505221210-r
com.squareup.okio:okio 2.4.3 3.4.0
com.github.tomakehurst:wiremock-jre8-standalone 2.26.0 2.35.1
com.google.code.gson:gson 2.8.6 2.8.9

Updates org.apache.bcel:bcel from 6.4.1 to 6.6.0

Updates junit:junit from 4.13 to 4.13.1

Release notes

Sourced from junit:junit's releases.

JUnit 4.13.1

Please refer to the release notes for details.

Changelog

Sourced from junit:junit's changelog.

Summary of changes in version 4.13.1

Rules

Security fix: TemporaryFolder now limits access to temporary folders on Java 1.7 or later

A local information disclosure vulnerability in TemporaryFolder has been fixed. See the published security advisory for details.

Test Runners

[Pull request #1669:](junit-team/junit#1669) Make FrameworkField constructor public

Prior to this change, custom runners could make FrameworkMethod instances, but not FrameworkField instances. This small change allows for both now, because FrameworkField's constructor has been promoted from package-private to public.

Commits

Updates com.fasterxml.jackson.core:jackson-databind from 2.10.2 to 2.12.7.1

Commits

Updates commons-io:commons-io from 2.4 to 2.14.0

Updates org.eclipse.jgit:org.eclipse.jgit from 5.6.1.202002131546-r to 6.10.1.202505221210-r

Updates com.squareup.okio:okio from 2.4.3 to 3.4.0

Changelog

Sourced from com.squareup.okio:okio's changelog.

Version 3.4.0

2023-07-07

  • New: Adapt a Java NIO FileSystem (java.nio.file.FileSystem) as an Okio FileSystem using fileSystem.asOkioFileSystem().
  • New: Adapt Android’s AssetManager as an Okio FileSystem using AssetFileSystem. This is in the new okio-assetfilesystem module. Android applications should prefer this over FileSystem.RESOURCES as it’s faster to load.
  • Fix: Don't crash decoding GZIP files when the optional extra data (XLEN) is 32 KiB or larger.
  • Fix: Resolve symlinks in FakeFileSystem.canonicalize().
  • Fix: Report the correct createdAtMillis in NodeJsFileSystem file metadata. We were incorrectly using ctimeMs, where c means changed, not created.
  • Fix: UnsafeCursor is now Closeable.

Version 3.3.0

2023-01-07

  • Fix: Don't leak resources when use {} is used with a non-local return. We introduced this performance and stability bug by not considering that non-local returns execute neither the return nor catch control flows.
  • Fix: Use a sealed interface for BufferedSink and BufferedSource. These were never intended for end-users to implement, and we're happy that Kotlin now allows us to express that in our API.
  • New: Change internal locks from synchronized to ReentrantLock and Condition. We expect this to improve help when using Okio with Java virtual threads ([Project Loom][loom]).
  • Upgrade: [Kotlin 1.8.0][kotlin_1_8_0].

Version 3.2.0

2022-06-26

  • Fix: Configure the multiplatform artifact (com.squareup.okio:okio:3.x.x) to depend on the JVM artifact (com.squareup.okio:okio-jvm:3.x.x) for Maven builds. This should work-around an issue where Maven doesn't interpret Gradle metadata.
  • Fix: Change CipherSource and CipherSink to recover if the cipher doesn't support streaming. This should work around a crash with AES/GCM ciphers on Android.
  • New: Enable compatibility with non-hierarchical projects.

Version 3.1.0

2022-04-19

  • Upgrade: [Kotlin 1.6.20][kotlin_1_6_20].
  • New: Support [Hierarchical project structure][hierarchical_projects]. If you're using Okio in a multiplatform project please upgrade your project to Kotlin 1.6.20 (or newer) to take advantage of this. With hierarchical projects it's easier to use properties like FileSystem.SYSTEM that

... (truncated)

Commits
  • a161b07 Prepare for release 3.4.0.
  • c5f462b Copyright to files in build-support (#1285)
  • f21714d Upgrade Gradle and JMH (#1283)
  • 5f5db4a Merge pull request #1284 from square/renovate/com.google.jimfs
  • 8af8d2a Update dependency com.google.jimfs:jimfs to v1.3.0
  • b64c198 Update dependency com.vanniktech:gradle-maven-publish-plugin to v0.25.3 (#1282)
  • ea82713 Merge pull request #1281 from square/renovate/gradle-7.x
  • 3569daa Update dependency gradle to v7.6.2
  • e937a50 Merge pull request #1277 from sifmelcara/fix-int-sign-conversion
  • 81bce1a Fix a bug where xlen larger than 0x7fff was rejected (#1280)
  • Additional commits viewable in compare view

Updates com.github.tomakehurst:wiremock-jre8-standalone from 2.26.0 to 2.35.1

Release notes

Sourced from com.github.tomakehurst:wiremock-jre8-standalone's releases.

2.35.1 - Security Release

🔒 This is a security release that addresses the following issues

NOTE: WireMock Studio, a proprietary distribution discontinued in 2022, is also affected by those issues and also affected by CVE-2023-39967 - Overall CVSS Score 8.6 - “Controlled and full-read SSRF through URL parameter when testing a request, webhooks and proxy mode”. The fixes will not be provided. The vendor recommends migrating to WireMock Cloud which is available as SaaS and private beta for on-premises deployments

Credits: @​W0rty, @​numacanedo, @​Mahoney, @​tomakehurst, @​oleg-nenashev

2.35.0

Enhancements

  • Add a negative contains matcher - thanks Damian Orzepowski
  • Expose a Java API method for removing stubs by ID - thanks Patryk Fraczek
  • Document the import API in the OpenAPI doc - thanks to user i-whammy
  • Added the ability to restrict the addresses WireMock can proxy/record to, as a security measure.

Fixes

  • Strip Maven directories from the standalone JAR as some were appearing that weren't related to dependencies actually present, confusing scanning tools - thanks to user krageon
  • Dropped back to slf4j 1.7.36 and relocate it in the standalone JAR (ensuring 2.x users won't experience conflicts).

2.34.0

This will be the final 2.x.x release and also the last to support Java 8.

Fixes

  • Fixed #1689 - incorrect HTTP version header - thanks to user Poojitha
  • Fixed #1882 - bug preventing matching of date/time query params/headers with custom format - thanks Klaas Dellschaft
  • #1930 - Fixed a partial path traversal vulnerability in the file source code - thanks Jonathan Leitschuh
  • Fixed #1783 - proxyUrlPrefixToRemove ignored when using a response definition transformer - thanks to user Ross-H-Projects
  • Fixed #1872 - create a request entity for POST, PUT etc. proxied requests when a content-length header is present, regardless of whether the size is 0.
  • Fixed #1946 - maths helper now supports epoch dates as inputs.

Enhancements

  • Added a public, non-static getScenarios() method allowing access to all scenarios.

All dependencies brought up to date including Jetty to 9.4.48.v20220622.

2.33.2

WireMock 2.33.1 was accidentally released using Java 11 rather than 8, resulting in class incompatibilities in places.

This release is functionally identical but built using Java 8.

2.33.1

Fixes

... (truncated)

Commits
  • 8706343 Bumped patch version
  • 20adc25 Stop NetworkAddressRules doing DNS lookups
  • aa29d9c Make NetworkAddressRulesAdheringDnsResolver testable
  • 90a37e1 Applied DNS resolver enforcement to webhooks extension
  • d9fd0b4 Moved enforcement of network address rules to Apache client DNS resolver to a...
  • eac439f Prevent webhook calling forbidden endpoints
  • 9ba86d6 Rename poorly named method
  • ef5b722 spotless apply
  • 5412ed1 Fixed some formatting in NetworkAddressRulesTest
  • 295ad5c Added some extra NetworkAddressRules test cases
  • Additional commits viewable in compare view

Updates com.google.code.gson:gson from 2.8.6 to 2.8.9

Release notes

Sourced from com.google.code.gson:gson's releases.

Gson 2.8.9

  • Make OSGi bundle's dependency on sun.misc optional (#1993).
  • Deprecate Gson.excluder() exposing internal Excluder class (#1986).
  • Prevent Java deserialization of internal classes (#1991).
  • Improve number strategy implementation (#1987).
  • Fix LongSerializationPolicy null handling being inconsistent with Gson (#1990).
  • Support arbitrary Number implementation for Object and Number deserialization (#1290).
  • Bump proguard-maven-plugin from 2.4.0 to 2.5.1 (#1980).
  • Don't exclude static local classes (#1969).
  • Fix RuntimeTypeAdapterFactory depending on internal Streams class (#1959).
  • Improve Maven build (#1964).
  • Make dependency on java.sql optional (#1707).

Gson 2.8.8

  • Fixed issue with recursive types (#1390).
  • Better behaviour with Java 9+ and Unsafe if there is a security manager (#1712).
  • EnumTypeAdapter now works better when ProGuard has obfuscated enum fields (#1495).
Changelog

Sourced from com.google.code.gson:gson's changelog.

Version 2.8.9

Version 2.8.8

  • Fixed issue with recursive types (google/gson#1390).
  • Better behaviour with Java 9+ and Unsafe if there is a security manager (google/gson#1712).
  • EnumTypeAdapter now works better when ProGuard has obfuscated enum fields (google/gson#1495).

Version 2.8.7

Commits
  • 6a368d8 [maven-release-plugin] prepare release gson-parent-2.8.9
  • ba96d53 Fix missing bounds checks for JsonTreeReader.getPath() (#2001)
  • ca1df7f #1981: Optional OSGi bundle's dependency on sun.misc package (#1993)
  • c54caf3 Deprecate Gson.excluder() exposing internal Excluder class (#1986)
  • e6fae59 Prevent Java deserialization of internal classes (#1991)
  • bda2e3d Improve number strategy implementation (#1987)
  • cd748df Fix LongSerializationPolicy null handling being inconsistent with Gson (#1990)
  • fe30b85 Support arbitrary Number implementation for Object and Number deserialization...
  • 1cc1627 Fix incorrect feature request template label (#1982)
  • 7b9a283 Bump bnd-maven-plugin from 5.3.0 to 6.0.0 (#1985)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps the maven group with 8 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| org.apache.bcel:bcel | `6.4.1` | `6.6.0` |
| [junit:junit](https://github.com/junit-team/junit4) | `4.13` | `4.13.1` |
| [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson) | `2.10.2` | `2.12.7.1` |
| commons-io:commons-io | `2.4` | `2.14.0` |
| org.eclipse.jgit:org.eclipse.jgit | `5.6.1.202002131546-r` | `6.10.1.202505221210-r` |
| [com.squareup.okio:okio](https://github.com/square/okio) | `2.4.3` | `3.4.0` |
| [com.github.tomakehurst:wiremock-jre8-standalone](https://github.com/wiremock/wiremock) | `2.26.0` | `2.35.1` |
| [com.google.code.gson:gson](https://github.com/google/gson) | `2.8.6` | `2.8.9` |



Updates `org.apache.bcel:bcel` from 6.4.1 to 6.6.0

Updates `junit:junit` from 4.13 to 4.13.1
- [Release notes](https://github.com/junit-team/junit4/releases)
- [Changelog](https://github.com/junit-team/junit4/blob/main/doc/ReleaseNotes4.13.1.md)
- [Commits](junit-team/junit4@r4.13...r4.13.1)

Updates `com.fasterxml.jackson.core:jackson-databind` from 2.10.2 to 2.12.7.1
- [Commits](https://github.com/FasterXML/jackson/commits)

Updates `commons-io:commons-io` from 2.4 to 2.14.0

Updates `org.eclipse.jgit:org.eclipse.jgit` from 5.6.1.202002131546-r to 6.10.1.202505221210-r

Updates `com.squareup.okio:okio` from 2.4.3 to 3.4.0
- [Release notes](https://github.com/square/okio/releases)
- [Changelog](https://github.com/square/okio/blob/master/CHANGELOG.md)
- [Commits](square/okio@parent-2.4.3...parent-3.4.0)

Updates `com.github.tomakehurst:wiremock-jre8-standalone` from 2.26.0 to 2.35.1
- [Release notes](https://github.com/wiremock/wiremock/releases)
- [Commits](wiremock/wiremock@2.26.0...2.35.1)

Updates `com.google.code.gson:gson` from 2.8.6 to 2.8.9
- [Release notes](https://github.com/google/gson/releases)
- [Changelog](https://github.com/google/gson/blob/main/CHANGELOG.md)
- [Commits](google/gson@gson-parent-2.8.6...gson-parent-2.8.9)

---
updated-dependencies:
- dependency-name: org.apache.bcel:bcel
  dependency-version: 6.6.0
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: junit:junit
  dependency-version: 4.13.1
  dependency-type: direct:development
  dependency-group: maven
- dependency-name: com.fasterxml.jackson.core:jackson-databind
  dependency-version: 2.12.7.1
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: commons-io:commons-io
  dependency-version: 2.14.0
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: org.eclipse.jgit:org.eclipse.jgit
  dependency-version: 6.10.1.202505221210-r
  dependency-type: direct:development
  dependency-group: maven
- dependency-name: com.squareup.okio:okio
  dependency-version: 3.4.0
  dependency-type: direct:production
  dependency-group: maven
- dependency-name: com.github.tomakehurst:wiremock-jre8-standalone
  dependency-version: 2.35.1
  dependency-type: direct:development
  dependency-group: maven
- dependency-name: com.google.code.gson:gson
  dependency-version: 2.8.9
  dependency-type: direct:development
  dependency-group: maven
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Jun 17, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants