Skip to content

Bump org.jline:jline-reader from 3.30.16 to 3.30.17 - #112

Merged
slachiewicz merged 1 commit into
masterfrom
dependabot/maven/org.jline-jline-reader-3.30.17
Sep 16, 2026
Merged

slachiewicz merged 1 commit into
masterfrom
dependabot/maven/org.jline-jline-reader-3.30.17

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 14, 2026

Copy link
Copy Markdown
Contributor

Bumps org.jline:jline-reader from 3.30.16 to 3.30.17.

Release notes

Sourced from org.jline:jline-reader's releases.

JLine 3.30.17 is a security patch release addressing multiple vulnerabilities reported by AFINE/CERT.PL, plus dependency updates.

🔒 Security Fixes

  • Native Stack Buffer Overflow in Public INPUT_RECORD.memmove JNI Method (Windows) (GHSA-6r3w-6jpj-x5w6)
  • Authenticated SSH Shell Channel Resource Leak via Null or Non-Numeric PTY Dimensions (GHSA-7h86-pjwh-gpqj)
  • Authenticated SSH DoS via Unbounded Window-Change Terminal Geometry (GHSA-m935-wqpj-pvp3)
  • TCP Socket File Descriptor Leak When Maximum Connections Reached (GHSA-c87g-867h-cqr6)

🐛 Bug Fixes

  • fix: strip control characters from file names in posix builtins (3.x backport) (#2240) @​gnodet
  • fix: bound !# history expansion to prevent exponential blowup (3.x backport) (#2239) @​gnodet
  • fix: verify server host keys in the ssh client builtin (3.x backport) (#2237) @​gnodet
  • fix: address remaining security vulnerabilities reported by AFINE/CERT.PL (3.x backport) (#2238) @​gnodet
  • fix: backport security fixes from master (#2156, #2164, #2175) (#2190) @​gnodet
  • fix: backport security fixes to 3.x (path traversal + DSR plain text) (#2137) @​gnodet
  • fix: strip control characters from ssh banner and prompts (3.x backport) (#2136) @​gnodet

📦 Dependency updates

  • chore: bump com.diffplug.spotless:spotless-maven-plugin from 3.10.1 to 3.10.2 (#2243)
  • chore: bump slf4j.version from 2.0.18 to 2.0.19 (#2241)
  • chore: bump org.apache.maven.plugins:maven-surefire-plugin from 3.5.6 to 3.6.0 (#2233)
  • chore: bump org.apache.maven.plugins:maven-compiler-plugin from 3.15.0 to 3.16.0 (#2226)
  • chore: bump org.apache.felix:maven-bundle-plugin from 6.1.0 to 6.1.2 (#2224)
  • chore: bump com.diffplug.spotless:spotless-maven-plugin from 3.10.0 to 3.10.1 (#2216)
  • chore: bump actions/setup-java from 5.7.0 to 6.0.0 (#2205)
  • chore: bump org.graalvm.sdk:graal-sdk from 25.2.4 to 25.3.4.1 (#2202)
  • chore: bump com.mycila:license-maven-plugin from 5.1.1 to 5.1.2 (#2187)
  • chore: bump org.easymock:easymock from 5.6.0 to 5.7.0 (#2188)
  • chore: bump com.diffplug.spotless:spotless-maven-plugin from 3.9.0 to 3.10.0 (#2182)
  • chore: bump com.google.jimfs:jimfs from 1.3.1 to 1.3.2 (#2184)
  • chore: bump org.apache.maven.wrapper:maven-wrapper from 3.3.2 to 3.3.4 (#2166)
  • chore: bump org.apache.maven:apache-maven from 4.0.0-rc-3 to 4.0.0-rc-6 (#2165)
  • chore: bump eu.maveniverse.maven.njord:extension3 from 0.9.9 to 0.9.10 (#2161)
  • chore: bump com.palantir.javaformat:palantir-java-format from 2.96.0 to 2.97.0 (#2159)
  • chore: bump actions/setup-java from 5.6.0 to 5.7.0 (#2147)
  • chore: bump release-drafter/release-drafter from 7.6.0 to 7.7.0 (#2146)
  • chore: bump groovy.version from 4.0.32 to 4.0.33 (#2143)
  • chore: bump actions/setup-java from 5 to 5.6.0 (#2134)
  • chore: bump release-drafter/release-drafter from 7 to 7.6.0 (#2133)
  • chore: bump org.apache.felix:maven-bundle-plugin from 6.0.2 to 6.1.0 (#2132)
  • chore: bump com.diffplug.spotless:spotless-maven-plugin from 3.8.0 to 3.9.0 (#2125)
  • chore: bump org.graalvm.sdk:graal-sdk from 25.1.3 to 25.2.4 (#2123)
  • chore: bump com.mycila:license-maven-plugin from 5.0.0 to 5.1.1 (#2115)
  • chore: bump org.apache.maven.plugins:maven-jar-plugin from 3.5.0 to 3.5.1 (#2113)
Commits
  • 261936f [maven-release-plugin] prepare release jline-3.30.17
  • 2c6f1ff fix: strip control characters from file names in posix builtins (3.x backport...
  • 89ee22e fix: bound !# history expansion to prevent exponential blowup (3.x backport) ...
  • 2b1cff8 fix: verify server host keys in the ssh client builtin (3.x backport) (#2237)
  • 6d00cbc fix: address remaining security vulnerabilities reported by AFINE/CERT.PL (#2...
  • 3cfe884 chore: bump com.diffplug.spotless:spotless-maven-plugin (#2243)
  • f4c4d10 chore: bump slf4j.version from 2.0.18 to 2.0.19 (#2241)
  • 297e475 chore: bump org.apache.maven.plugins:maven-surefire-plugin (#2233)
  • 818a32e chore: bump org.apache.maven.plugins:maven-compiler-plugin (#2226)
  • b46e8c1 chore: bump org.apache.felix:maven-bundle-plugin from 6.1.0 to 6.1.2 (#2224)
  • Additional commits viewable in compare view

Most Recent Ignore Conditions Applied to This Pull Request
Dependency Name Ignore Conditions
org.jline:jline-reader [>= 4.a0, < 5]

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [org.jline:jline-reader](https://github.com/jline/jline3) from 3.30.16 to 3.30.17.
- [Release notes](https://github.com/jline/jline3/releases)
- [Commits](jline/jline3@jline-3.30.16...jline-3.30.17)

---
updated-dependencies:
- dependency-name: org.jline:jline-reader
  dependency-version: 3.30.17
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Sep 14, 2026
@slachiewicz
slachiewicz merged commit b9cf91e into master Sep 16, 2026
14 checks passed
@dependabot
dependabot Bot deleted the dependabot/maven/org.jline-jline-reader-3.30.17 branch September 16, 2026 21:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant