Skip to content

deps(deps): bump the maven-minor-patch group across 1 directory with 8 updates - #58

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/maven/develop/maven-minor-patch-75ce8680c3
Open

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/maven/develop/maven-minor-patch-75ce8680c3

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Contributor

Bumps the maven-minor-patch group with 8 updates in the / directory:

Package From To
org.junit:junit-bom 6.1.2 6.1.3
io.github.demchaav:graph-compose 2.1.1 2.4.0
io.github.demchaav:graph-compose-fonts 1.0.0 1.1.0
org.apache.maven.plugins:maven-install-plugin 3.1.4 3.2.0
org.apache.maven.plugins:maven-deploy-plugin 3.1.4 3.2.0
org.apache.maven.plugins:maven-compiler-plugin 3.15.0 3.16.0
org.apache.maven.plugins:maven-surefire-plugin 3.5.6 3.6.0
org.apache.maven:apache-maven 3.9.12 3.9.16

Updates org.junit:junit-bom from 6.1.2 to 6.1.3

Release notes

Sourced from org.junit:junit-bom's releases.

JUnit 6.1.3 = Platform 6.1.3 + Jupiter 6.1.3 + Vintage 6.1.3

See Release Notes.

Full Changelog: junit-team/junit-framework@r6.1.2...r6.1.3

Commits
  • f59f60d Release 6.1.3
  • cd8ec92 Finalize 6.1.3 release notes
  • c8729f2 Restore compatibility with GraalVM 25 (#5901)
  • ddc9e74 Update graalvm/setup-graalvm action to v1.6.4 (#5959)
  • fe2c52a Update plugin org.graalvm.buildtools.native to v1.1.7 (#5923)
  • 62afc02 Delay GraalVM plugin updates for 3 days
  • 0cc2902 Skip graalVmTest task if GraalVM env vars are not set
  • f6bbfc5 Move GraalVM tests to separate test task (#5903)
  • e87e052 Update plugin org.graalvm.buildtools.native to v1.1.6 (#5899)
  • 1cd56df Update plugin org.graalvm.buildtools.native to v1.1.5 (#5880)
  • Additional commits viewable in compare view

Updates io.github.demchaav:graph-compose from 2.1.1 to 2.4.0

Release notes

Sourced from io.github.demchaav:graph-compose's releases.

GraphCompose v2.4.0

v2.4.0 — 2026-09-14

2.4.0 leads with a much larger template line-up. Two families join invoice, proposal, CV and cover letter: receipt, for payment confirmations (ModernReceipt), and rota, a staff shift schedule (CobaltRota) on a new templates.data.rota model that replaces the data.schedule records nothing rendered. The invoice, proposal and CV families gain presets, and the structured invoice and proposal models grow to carry what those designs print. Every CV preset is now either ATS-friendly or design-first, a classification made by reading its showcase sample with three resume parsers; the showcase marks the ATS-friendly ones.

The engine work under it is typographic. DocumentTextStyle carries real letter spacing — PDF Tc, DrawingML spc, Word w:spacing — so spaced caps copy and search as the word they are instead of letters padded with spaces, and the built-in CV and cover-letter presets use it. A timeline's rail is one line resolved from where its markers landed, and the timeline can put a column before its markers, size the marker column in points and set the gap before a marker on its own. A list can hang its wrapped lines under its text, style an item in pieces, and draw its markers in a colour of their own. graph-compose-templates joins graph-compose-core under the binary-compatibility gate.

Public API

  • A proposal block carries the paragraph that opens it.
  • A proposal carries the header a one-page sales proposal has.
  • An invoice line carries where it was delivered.
  • A supplier carries the legal line it prints under its name.
  • A billed party carries a printed registration.
  • An invoice line carries a mark.
  • CvSkill carries the level as the document words it.
  • The structured invoice model carries what a second sheet needs.
  • CvEntry carries a link.
  • CvEntry carries a location and a mark, and gains a builder.
  • CvIdentity carries an optional portrait.
  • A structured invoice document model.
  • A structured proposal document model.
  • A rota document model, replacing data.schedule.
  • One place turns a printed contact into a followable one: core.identity.ContactUri.
  • Text style carries typographic tracking.
  • The built-in CV and cover-letter presets now use real tracking, so their text is readable again.
  • A list can hang its wrapped lines under its own text instead of under its marker.
  • A list item can be styled in pieces.
  • A list marker can be drawn, and can carry a colour of its own.
  • A timeline's rail is one line, drawn from where its markers landed.
  • A timeline's rail is one configuration.
  • A timeline marker can be anything you can draw.
  • A timeline's marker column can be given a width in points.
  • A timeline can put a column before its markers — the DATE of DATE | ● | CONTENT.
  • The gap before a timeline's marker is its own number.
  • A timeline entry can fill its own content column.

... (truncated)

Changelog

Sourced from io.github.demchaav:graph-compose's changelog.

v2.4.0 — 2026-09-14

Public API

  • A proposal block carries the paragraph that opens it. ProposalScope, ProposalGoals and ProposalGlance each set a heading and a list, and every one-page sales proposal measured for the header spine also sets a paragraph between the two — five of the seven set two of them, once over the solution and once over the reasons to choose the issuer. The header survey missed it, so it arrives here rather than inside the first preset that needs it. All three records gain intro, a plain string blank when absent, and each keeps its previous constructor explicitly, so existing calls compile and link unchanged and every block built through them opens straight into its list as before.

  • A proposal carries the header a one-page sales proposal has. The proposal model was shaped for a two-page consulting document: a running header naming three things by role, and a title of exactly three lines. A one-page sales proposal opens differently — an addressed organisation with its own address block, a named person at it with a role and two channels, a row of marked tiles whose captions are the document's own, a headline broken across however many lines the design breaks it across, and a foot carrying the legal entity rather than only a name. None of that had a home, and each of the seven designs measured for this needs the same five things, which is why they arrive together rather than one per preset: five separate additions to a published record would leave the model a patchwork of near-duplicates. ProposalRecipient, ProposalAttention and ProposalFooter are new; StructuredProposalData carries them as recipient, attention and footer, and its twelve-argument constructor is kept explicitly so existing calls compile and link unchanged. ProposalTitleLines gains eyebrow, lines and standfirst, with lines the canonical reading and lead/second/third its first three — one statement kept consistent by construction rather than by the caller, so a preset written against the three reads the same title a four-line document states. The list form is a factory, ProposalTitleLines.of, because a second three-argument constructor taking (String, List, List) is ambiguous for a caller passing nulls. ProposalMetaLine gains entries, and those do not derive from the trio in either direction: turning three roles into tiles would mean inventing their captions, and reading roles back out of arbitrary tiles would mean guessing which is which. A preset draws the one its design has.

  • An invoice line carries where it was delivered. A design that bills the same service in more than one place — the same instance type in two datacentres, the same plan in two jurisdictions — prints where beside what, as its own column next to the service. InvoiceServiceLines.Line had nowhere to put it: servicePeriod is the neighbouring column on such a sheet, so folding the two together collapses two columns the design draws apart, and vatRate is a tax rate that happens to be free. Line now carries region and Columns its caption, both plain strings blank when absent, and a design with one location per invoice leaves them alone. All three constructors that predate it — the ones before the per-line tax rate, the mark, and the region — are kept explicitly, so existing calls compile and link unchanged and every line built through them still prints no region.

... (truncated)

Commits
  • 23c9ea5 Release v2.4.0
  • fa104ba docs: pre-release fixes — 2.4 roadmap line, release status, stability map, sh...
  • 995cf79 chore(examples): drop the twin-output figures no page shows (#691)
  • b5817e1 docs(onboarding): lead the README with a first PDF, then route by task (#690)
  • a19af77 feat(templates): classify CV presets as ATS-friendly or design-first (#689)
  • e9a0110 fix(pdf): draw tracked text with the spacing in the glyph widths (#688)
  • 0d23ceb deps(deps): bump the maven-minor-patch group across 1 directory with 2 update...
  • 88eb90e test(templates): restore layout snapshot coverage for shipped presets (#686)
  • db9d90b test(release): hold the local and tag-time knowledge gates to the same tools ...
  • 1f2ff86 fix(release): document the knowledge-tooling refusal and execute it in CI (#684)
  • Additional commits viewable in compare view

Updates io.github.demchaav:graph-compose-fonts from 1.0.0 to 1.1.0

Release notes

Sourced from io.github.demchaav:graph-compose-fonts's releases.

GraphCompose v1.1.0

Highlights

  • compose-first built-in template usage is now the documented default
  • backend-neutral DocumentComposer and handler-driven rendering make the engine less PDF-centric internally
  • layout snapshot testing is now part of the regression workflow for pagination and geometry changes
  • runnable examples now cover CV, cover letter, invoice, proposal, and weekly schedule generation
  • document-level PDF features now include QR/barcodes, watermarks, headers/footers, bookmarks, metadata, protection, explicit page breaks, and dividers
  • visual showcase tests make pagination, document chrome, and barcode output easier to inspect
  • benchmark tooling now includes current-speed, comparative, and diffable JSON/CSV reports
  • an experimental live preview dev tool is available in test scope for fast template iteration

Added

  • barcode support with QR, Code 128, and EAN-13 builders
  • watermark support
  • configurable headers and footers with page numbers and separators
  • PDF bookmarks / outline generation
  • document metadata support
  • PDF protection hooks
  • explicit page-break and divider builders
  • visual showcase render tests
  • benchmark export and diff tooling
  • one-command benchmark runner

Compatibility

  • older tagged JitPack releases such as v1.0.3 remain usable
  • deprecated render(...) template adapters are still available for compatibility
  • new docs and examples now prefer compose(...)

v1.0.3 — First Public Release

Highlights:

  • Declarative document composition with reusable builders and layout systems
  • Automatic multi-page layout and pagination
  • Markdown support via Flexmark
  • Shared font registration and reusable text styles
  • Template layer with CvTheme and TemplateBuilder
  • JitPack distribution for easy integration
Changelog

Sourced from io.github.demchaav:graph-compose-fonts's changelog.

v1.1.0 - 2026-04-13

Highlights

  • shifted the public built-in template narrative to compose(DocumentSession, ...)
  • added document-level PDF features for richer real-world output
  • moved the engine further away from PDF-centric internals through backend-neutral composition and render-handler seams
  • strengthened architecture guard rails for template scene builders
  • expanded visual testing and benchmark tooling for day-to-day development

Added

  • canonical DocumentSession contract as the primary composition seam
  • layout snapshot extraction and JSON-based regression coverage for resolved document geometry
  • runnable examples/ module for CV, cover letter, invoice, proposal, and weekly schedule generation
  • new built-in business templates and data models for invoice, proposal, and weekly schedule documents
  • barcode support with QR, Code 128, and EAN-13 builders
  • watermark support
  • configurable headers and footers with page numbers and separators
  • PDF bookmarks / outline generation
  • document metadata support
  • PDF protection hooks
  • explicit page-break and divider builders
  • visual showcase render tests for barcodes, QR codes, pagination, and document chrome
  • current-speed benchmark suite
  • benchmark JSON/CSV export and diff tooling
  • one-command benchmark runner: scripts/run-benchmarks.ps1

Changed

  • bumped the library release to v1.1.0
  • updated README installation snippets to the new release version
  • documented built-in templates as compose-first by default
  • refreshed README visuals to show barcode/QR and compose-first template output
  • added release-facing notes for the experimental live preview dev tool in test scope
  • refreshed release documentation to point contributors at visual tests and benchmark workflows

Architecture and CI

  • engine-side text measurement and rendering dispatch are now more explicitly decoupled from PDFBox-specific implementation details
  • added template boundary guard coverage so *SceneBuilder classes stay free of backend-specific PDFBox types
  • split architecture/documentation guards into a dedicated CI job that can be required independently in branch protection

Compatibility notes

  • older tagged JitPack releases remain usable as long as consumers pin a specific version such as v1.0.3
  • deprecated render(...) template adapters remain available for compatibility, but new docs and examples now prefer compose(...)
Commits
  • cdedd9d Prepare v1.1.0 release
  • a5424fe Add quiet logging to stress and endurance benchmarks
  • dc65c2b Add benchmark diff workflow to README
  • 07b95b8 Add benchmark report export and usage docs
  • e9f7ef1 feat: Add PdfPageBreakRenderHandler and visual showcase tests
  • 2e08ecf feat: Add comprehensive document-level features and barcode support
  • ecefc8e Extract shared PDF template adapter support
  • 849103d Enforce template boundaries and compose-first examples
  • 3567aae Split built-in templates into compose-first scene builders
  • 4c6fa50 docs: Add contributor architecture rules for engine changes
  • Additional commits viewable in compare view

Updates org.apache.maven.plugins:maven-install-plugin from 3.1.4 to 3.2.0

Release notes

Sourced from org.apache.maven.plugins:maven-install-plugin's releases.

3.2.0

🚀 New features and improvements

🐛 Bug Fixes

  • chore: harden embedded-POM trust boundary in install:install-file (3.x backport) (#447) @​gnodet

📝 Documentation updates

  • Restore the common wording on the download page (#438) @​slachiewicz
  • Add AGENTS.md + SECURITY.md security-model pointer for scanner discoverability (#416) @​potiuk

👻 Maintenance

📦 Dependency updates

Commits
  • bcf484d [maven-release-plugin] prepare release maven-install-plugin-3.2.0
  • 5703691 chore: harden embedded-POM trust boundary in install:install-file (3.x backpo...
  • 9148a8f Cache projectsUsingPlugin to fix O(N²) reactor scan
  • 7465779 Fix workflow_dispatch indentation in release-drafter configuration
  • 7d4334d Use JSR-330 for component injection
  • bbcb1e7 Restore the common wording on the download page
  • 11f7073 Restore the document metadata dropped when the pages were ported
  • 9b34ac2 Port the site documentation from APT to Markdown
  • 510f48f Rename the site documents ahead of converting them
  • 26e0afc Bump apache/maven-gh-actions-shared/.github/workflows/pr-automation.yml
  • Additional commits viewable in compare view

Updates org.apache.maven.plugins:maven-deploy-plugin from 3.1.4 to 3.2.0

Release notes

Sourced from org.apache.maven.plugins:maven-deploy-plugin's releases.

3.2.0

🚀 New features and improvements

🐛 Bug Fixes

  • Backport security audit fixes to 3.x (f004-f008, f010, f012) (#701) @​gnodet

📝 Documentation updates

👻 Maintenance

🔧 Build

📦 Dependency updates

... (truncated)

Commits
  • 7aab9fb [maven-release-plugin] prepare release maven-deploy-plugin-3.2.0
  • 1f3eef5 Backport security audit fixes to 3.x (f004-f008, f010, f012)
  • 307f328 Simplify remote repository creation
  • 7b1bbc4 Cache projectsWithDeployExecution to fix O(N²) reactor scan
  • a9177c6 Clarify deploy without editing this projects POM
  • 7c40513 Restore the plain form of the ASF licence header
  • 5969234 Update Release Drafter configuration to use custom tag template and remove un...
  • df7b3fa Bump apache/maven-gh-actions-shared/.github/workflows/release-drafter.yml
  • b4e8aed work around Maven 4 CLI lack of interpolation
  • d634bb4 enable build with Maven 4
  • Additional commits viewable in compare view

Updates org.apache.maven.plugins:maven-compiler-plugin from 3.15.0 to 3.16.0

Release notes

Sourced from org.apache.maven.plugins:maven-compiler-plugin's releases.

3.16.0

🚀 New features and improvements

🐛 Bug Fixes

📝 Documentation updates

👻 Maintenance

📦 Dependency updates

Commits
  • e7bba6e [maven-release-plugin] prepare release maven-compiler-plugin-3.16.0
  • c906809 Avoid using deprecated method CompilerConfiguration.setCompilerVersion
  • ad74fee Replace adopt-openj9 by semeru JDK distribution on GH
  • beb0eda Recompile when dependencies change (#1102)
  • a0b689e [MCOMPILER-578] Track outputs across compiler executions (#1091)
  • 2e81228 Fix incremental detection of empty sources, 3.x (#1075)
  • 2132f5b configure ATR project
  • 5992b77 Build fails when annotation processor list is empty (but present) (#1077)
  • acccef7 Bump plexusCompilerVersion from 2.16.2 to 2.17.0
  • 72bc445 Bump org.codehaus.plexus:plexus-java from 1.5.2 to 1.6.0
  • Additional commits viewable in compare view

Updates org.apache.maven.plugins:maven-surefire-plugin from 3.5.6 to 3.6.0

Release notes

Sourced from org.apache.maven.plugins:maven-surefire-plugin's releases.

3.6.0

Please refer to the main page for what's new https://maven.apache.org/surefire/ And the migration page https://maven.apache.org/surefire/maven-surefire-plugin/whats-new-3-6-0.html

🚀 New features and improvements

🐛 Bug Fixes

📝 Documentation updates

👻 Maintenance

... (truncated)

Commits
  • 0ff622b [maven-release-plugin] prepare release surefire-3.6.0
  • bb3932a Let's go for 3.6.0 release
  • 3002a16 Bump mavenVersion from 3.9.14 to 3.9.16
  • 61a531d Bump Maven parent version from 47 to 49 (#3449)
  • e52ead4 [SUREFIRE-523] Link all reported tests to source XRef (#3445)
  • 45102fa [SUREFIRE-3446] Fix direct selection of JUnit Jupiter @​Nested classes (#3447)
  • b2e1f70 Fix #3303: distinguish JUnit 6 ParameterizedClass invocations (#3432)
  • c051938 Discover tests in a fork when a toolchain JDK is used (#3444)
  • db75df8 Bump org.codehaus.plexus:plexus-java from 1.5.2 to 1.6.0 (#3441)
  • 77f2759 Bump org.codehaus.plexus:plexus-interpolation from 1.29 to 1.30.0
  • Additional commits viewable in compare view

Updates org.apache.maven:apache-maven from 3.9.12 to 3.9.16

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more fo...

Description has been truncated

…8 updates

Bumps the maven-minor-patch group with 8 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [org.junit:junit-bom](https://github.com/junit-team/junit-framework) | `6.1.2` | `6.1.3` |
| [io.github.demchaav:graph-compose](https://github.com/DemchaAV/GraphCompose) | `2.1.1` | `2.4.0` |
| [io.github.demchaav:graph-compose-fonts](https://github.com/DemchaAV/GraphCompose) | `1.0.0` | `1.1.0` |
| [org.apache.maven.plugins:maven-install-plugin](https://github.com/apache/maven-install-plugin) | `3.1.4` | `3.2.0` |
| [org.apache.maven.plugins:maven-deploy-plugin](https://github.com/apache/maven-deploy-plugin) | `3.1.4` | `3.2.0` |
| [org.apache.maven.plugins:maven-compiler-plugin](https://github.com/apache/maven-compiler-plugin) | `3.15.0` | `3.16.0` |
| [org.apache.maven.plugins:maven-surefire-plugin](https://github.com/apache/maven-surefire) | `3.5.6` | `3.6.0` |
| org.apache.maven:apache-maven | `3.9.12` | `3.9.16` |



Updates `org.junit:junit-bom` from 6.1.2 to 6.1.3
- [Release notes](https://github.com/junit-team/junit-framework/releases)
- [Commits](junit-team/junit-framework@r6.1.2...r6.1.3)

Updates `io.github.demchaav:graph-compose` from 2.1.1 to 2.4.0
- [Release notes](https://github.com/DemchaAV/GraphCompose/releases)
- [Changelog](https://github.com/DemchaAV/GraphCompose/blob/main/CHANGELOG.md)
- [Commits](DemchaAV/GraphCompose@v2.1.1...v2.4.0)

Updates `io.github.demchaav:graph-compose-fonts` from 1.0.0 to 1.1.0
- [Release notes](https://github.com/DemchaAV/GraphCompose/releases)
- [Changelog](https://github.com/DemchaAV/GraphCompose/blob/main/CHANGELOG.md)
- [Commits](DemchaAV/GraphCompose@v1.0.0...v1.1.0)

Updates `org.apache.maven.plugins:maven-install-plugin` from 3.1.4 to 3.2.0
- [Release notes](https://github.com/apache/maven-install-plugin/releases)
- [Commits](apache/maven-install-plugin@maven-install-plugin-3.1.4...maven-install-plugin-3.2.0)

Updates `org.apache.maven.plugins:maven-deploy-plugin` from 3.1.4 to 3.2.0
- [Release notes](https://github.com/apache/maven-deploy-plugin/releases)
- [Commits](apache/maven-deploy-plugin@maven-deploy-plugin-3.1.4...maven-deploy-plugin-3.2.0)

Updates `org.apache.maven.plugins:maven-compiler-plugin` from 3.15.0 to 3.16.0
- [Release notes](https://github.com/apache/maven-compiler-plugin/releases)
- [Commits](apache/maven-compiler-plugin@maven-compiler-plugin-3.15.0...maven-compiler-plugin-3.16.0)

Updates `org.apache.maven.plugins:maven-surefire-plugin` from 3.5.6 to 3.6.0
- [Release notes](https://github.com/apache/maven-surefire/releases)
- [Commits](apache/maven-surefire@surefire-3.5.6...surefire-3.6.0)

Updates `org.apache.maven:apache-maven` from 3.9.12 to 3.9.16

---
updated-dependencies:
- dependency-name: org.junit:junit-bom
  dependency-version: 6.1.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-patch
- dependency-name: io.github.demchaav:graph-compose
  dependency-version: 2.4.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-patch
- dependency-name: io.github.demchaav:graph-compose-fonts
  dependency-version: 1.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-minor-patch
- dependency-name: org.apache.maven.plugins:maven-install-plugin
  dependency-version: 3.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-patch
- dependency-name: org.apache.maven.plugins:maven-deploy-plugin
  dependency-version: 3.2.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-patch
- dependency-name: org.apache.maven.plugins:maven-compiler-plugin
  dependency-version: 3.16.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-patch
- dependency-name: org.apache.maven.plugins:maven-surefire-plugin
  dependency-version: 3.6.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-minor-patch
- dependency-name: org.apache.maven:apache-maven
  dependency-version: 3.9.16
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-minor-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot @github

dependabot Bot commented on behalf of github Sep 21, 2026

Copy link
Copy Markdown
Contributor Author

Labels

The following labels could not be found: dependencies, maven. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot
dependabot Bot requested a review from DemchaAV as a code owner September 21, 2026 23:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants