Skip to content

build(deps): bump the maven-dependencies group across 1 directory with 12 updates - #4930

Merged
kubernetes-prow[bot] merged 2 commits into
masterfrom
dependabot/maven/maven-dependencies-e18daa9b0a
Oct 5, 2026
Merged

kubernetes-prow[bot] merged 2 commits into
masterfrom
dependabot/maven/maven-dependencies-e18daa9b0a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps the maven-dependencies group with 12 updates in the / directory:

Package From To
org.apache.commons:commons-lang3 3.20.0 3.21.0
software.amazon.awssdk:sts 2.55.5 2.55.10
software.amazon.awssdk:auth 2.55.5 2.55.10
software.amazon.awssdk:http-auth-aws 2.55.5 2.55.10
software.amazon.awssdk:http-auth-spi 2.55.5 2.55.10
software.amazon.awssdk:http-client-spi 2.55.5 2.55.10
software.amazon.awssdk:utils 2.55.5 2.55.10
software.amazon.awssdk:auth 2.55.5 2.55.10
software.amazon.awssdk:http-auth-aws 2.55.5 2.55.10
software.amazon.awssdk:http-auth-spi 2.55.5 2.55.10
software.amazon.awssdk:http-client-spi 2.55.5 2.55.10
software.amazon.awssdk:utils 2.55.5 2.55.10
com.google.auth:google-auth-library-oauth2-http 1.53.0 1.54.0
ch.qos.logback:logback-classic 1.6.4 1.6.5
ch.qos.logback:logback-core 1.6.4 1.6.5
ch.qos.logback:logback-core 1.6.4 1.6.5
com.diffplug.spotless:spotless-maven-plugin 3.10.2 3.10.3
org.apache.maven:apache-maven 3.9.16 3.10.0

Updates org.apache.commons:commons-lang3 from 3.20.0 to 3.21.0

Updates software.amazon.awssdk:sts from 2.55.5 to 2.55.10

Updates software.amazon.awssdk:auth from 2.55.5 to 2.55.10

Updates software.amazon.awssdk:http-auth-aws from 2.55.5 to 2.55.10

Updates software.amazon.awssdk:http-auth-spi from 2.55.5 to 2.55.10

Updates software.amazon.awssdk:http-client-spi from 2.55.5 to 2.55.10

Updates software.amazon.awssdk:utils from 2.55.5 to 2.55.10

Updates software.amazon.awssdk:auth from 2.55.5 to 2.55.10

Updates software.amazon.awssdk:http-auth-aws from 2.55.5 to 2.55.10

Updates software.amazon.awssdk:http-auth-spi from 2.55.5 to 2.55.10

Updates software.amazon.awssdk:http-client-spi from 2.55.5 to 2.55.10

Updates software.amazon.awssdk:utils from 2.55.5 to 2.55.10

Updates com.google.auth:google-auth-library-oauth2-http from 1.53.0 to 1.54.0

Updates ch.qos.logback:logback-classic from 1.6.4 to 1.6.5

Release notes

Sourced from ch.qos.logback:logback-classic's releases.

Logback 1.6.5

2026-09-30 Release of logback version 1.6.5

• Fixed a vulnerability CVE-2026-104721 closely related to CVE-2026-19880. The fix in version 1.6.3, which strips forward and backward slashes from MDC values, was insufficient. An MDC value could still contain relative path components such as .., variable references such as /, or characters that are special in file name patterns and email addresses. This latest vulnerability was found and reported by François Martin (GitHub: @​martinfrancois, https://github.com/martinfrancois).

MDCBasedDiscriminator, used by SiftingAppender, now rejects MDC values instead of stripping characters from them. An MDC value is rejected if it is empty, if it is longer than 64 characters, if it contains the sequence .., or if it contains any of the following characters: / \ $ { } [ ] ( ) | ? * + % , @. When an MDC value is rejected, the discriminator returns the value of its DefaultValue property. A warning is emitted for each rejected value. These warnings are rate-limited.

• When compression is enabled, TimeBasedRollingPolicy and SizeAndTimeBasedRollingPolicy now also remove old log files that were never compressed, for example because the application was not running at rollover time. Previously, such files were ignored by maxHistory and accumulated indefinitely. This issue was discussed in discussions/1032. See TimeBasedRollingPolicy.

• SimpleInvocationGate, deprecated in version 1.6.3, is now marked for removal. Use FixedIntervalInvocationGate instead.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit d1b829dcdb9fd98511c64401beb1419a9c9384aa associated with the tag v_1.6.5. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Commits
  • d1b829d prepare release 1.6.5
  • 065b9b2 enhance protectin against mischievious MDC values in MDCBasedDiscriminator
  • b69beab complete commit in relation to discussion_1032
  • 7266c0b fix intermittently failing SocketAppenderMessageLossTest rest condition
  • a633bb0 fix intermittently failing SocketAppenderMessageLossTest rest condition
  • 2bc5bcc renamed tbrp and eclosingTBRP, other minor changes
  • 2cd8762 fix typo in AGENTS.md
  • 647846c fix errors when running tests under intellij IDEA
  • 1048917 removed ConsoleCharsetPropertyDefiner.java
  • 39b5002 added 'since' and 'forRemoval' attributes to SimpleInvocationGate @​Deprecatio...
  • See full diff in compare view

Updates ch.qos.logback:logback-core from 1.6.4 to 1.6.5

Release notes

Sourced from ch.qos.logback:logback-core's releases.

Logback 1.6.5

2026-09-30 Release of logback version 1.6.5

• Fixed a vulnerability CVE-2026-104721 closely related to CVE-2026-19880. The fix in version 1.6.3, which strips forward and backward slashes from MDC values, was insufficient. An MDC value could still contain relative path components such as .., variable references such as /, or characters that are special in file name patterns and email addresses. This latest vulnerability was found and reported by François Martin (GitHub: @​martinfrancois, https://github.com/martinfrancois).

MDCBasedDiscriminator, used by SiftingAppender, now rejects MDC values instead of stripping characters from them. An MDC value is rejected if it is empty, if it is longer than 64 characters, if it contains the sequence .., or if it contains any of the following characters: / \ $ { } [ ] ( ) | ? * + % , @. When an MDC value is rejected, the discriminator returns the value of its DefaultValue property. A warning is emitted for each rejected value. These warnings are rate-limited.

• When compression is enabled, TimeBasedRollingPolicy and SizeAndTimeBasedRollingPolicy now also remove old log files that were never compressed, for example because the application was not running at rollover time. Previously, such files were ignored by maxHistory and accumulated indefinitely. This issue was discussed in discussions/1032. See TimeBasedRollingPolicy.

• SimpleInvocationGate, deprecated in version 1.6.3, is now marked for removal. Use FixedIntervalInvocationGate instead.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit d1b829dcdb9fd98511c64401beb1419a9c9384aa associated with the tag v_1.6.5. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Commits
  • d1b829d prepare release 1.6.5
  • 065b9b2 enhance protectin against mischievious MDC values in MDCBasedDiscriminator
  • b69beab complete commit in relation to discussion_1032
  • 7266c0b fix intermittently failing SocketAppenderMessageLossTest rest condition
  • a633bb0 fix intermittently failing SocketAppenderMessageLossTest rest condition
  • 2bc5bcc renamed tbrp and eclosingTBRP, other minor changes
  • 2cd8762 fix typo in AGENTS.md
  • 647846c fix errors when running tests under intellij IDEA
  • 1048917 removed ConsoleCharsetPropertyDefiner.java
  • 39b5002 added 'since' and 'forRemoval' attributes to SimpleInvocationGate @​Deprecatio...
  • See full diff in compare view

Updates ch.qos.logback:logback-core from 1.6.4 to 1.6.5

Release notes

Sourced from ch.qos.logback:logback-core's releases.

Logback 1.6.5

2026-09-30 Release of logback version 1.6.5

• Fixed a vulnerability CVE-2026-104721 closely related to CVE-2026-19880. The fix in version 1.6.3, which strips forward and backward slashes from MDC values, was insufficient. An MDC value could still contain relative path components such as .., variable references such as /, or characters that are special in file name patterns and email addresses. This latest vulnerability was found and reported by François Martin (GitHub: @​martinfrancois, https://github.com/martinfrancois).

MDCBasedDiscriminator, used by SiftingAppender, now rejects MDC values instead of stripping characters from them. An MDC value is rejected if it is empty, if it is longer than 64 characters, if it contains the sequence .., or if it contains any of the following characters: / \ $ { } [ ] ( ) | ? * + % , @. When an MDC value is rejected, the discriminator returns the value of its DefaultValue property. A warning is emitted for each rejected value. These warnings are rate-limited.

• When compression is enabled, TimeBasedRollingPolicy and SizeAndTimeBasedRollingPolicy now also remove old log files that were never compressed, for example because the application was not running at rollover time. Previously, such files were ignored by maxHistory and accumulated indefinitely. This issue was discussed in discussions/1032. See TimeBasedRollingPolicy.

• SimpleInvocationGate, deprecated in version 1.6.3, is now marked for removal. Use FixedIntervalInvocationGate instead.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit d1b829dcdb9fd98511c64401beb1419a9c9384aa associated with the tag v_1.6.5. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Commits
  • d1b829d prepare release 1.6.5
  • 065b9b2 enhance protectin against mischievious MDC values in MDCBasedDiscriminator
  • b69beab complete commit in relation to discussion_1032
  • 7266c0b fix intermittently failing SocketAppenderMessageLossTest rest condition
  • a633bb0 fix intermittently failing SocketAppenderMessageLossTest rest condition
  • 2bc5bcc renamed tbrp and eclosingTBRP, other minor changes
  • 2cd8762 fix typo in AGENTS.md
  • 647846c fix errors when running tests under intellij IDEA
  • 1048917 removed ConsoleCharsetPropertyDefiner.java
  • 39b5002 added 'since' and 'forRemoval' attributes to SimpleInvocationGate @​Deprecatio...
  • See full diff in compare view

Updates com.diffplug.spotless:spotless-maven-plugin from 3.10.2 to 3.10.3

Release notes

Sourced from com.diffplug.spotless:spotless-maven-plugin's releases.

Maven Plugin v3.10.3

Changes

  • Generate formatter defaults from version catalog. (#3045)
  • Bump default gson version 2.13.2 -> 2.14.0. (#3045)
  • Bump default zjsonpatch version 0.4.14 -> 0.4.16. (#3045)
  • Bump default jackson-dataformat-yaml version 2.14.1 -> 2.20.1. (#3045)
  • Bump default ktfmt version 0.63 -> 0.64. (2988)
  • Bump default cleanthat version 2.25 -> 2.26. (#2882)
  • Bump default jackson version 2.20.1 -> 2.22.2. (#2819)
  • Bump default javaparser version 3.27.1 -> 3.28.2. (#3065)
  • Bump default palantir-java-format version 2.80.0 -> 2.98.0. (#3068)
  • Bump default scalafmt version 3.8.1 -> 3.11.5. (#2173)
  • Bump default google-java-format version 1.30.0 -> 1.36.1. (#3075)
  • Bump default gherkin-utils version 10.0.0 -> 12.0.2. (#2979)

Fixed

  • Fix release signing by using Gradle's required eight-digit signing subkey ID. (#3105)
  • Fix race when creating the npm install cache directory. ((#3096)
  • GrEclipse no longer emits expected OSGi and nested-jar warnings during initialization. (#2445)
  • typescript prettier() no longer emits a warning when its parser is already set to typescript. (#3098)
  • <versionCatalog> preserves standalone comments at section boundaries and the end of the file. (#3048)
  • <versionCatalog> preserves entries when comments contain unmatched brackets, preserves commas inside quoted strings, and keeps significant line boundaries in multiline entries. (#3042)
  • <versionCatalog> now reports unfinished entries as lints at their starting line. These fail formatting by default, so upgrading may expose catalog errors that previously caused silent data loss. (#3042)
  • Eclipse JDT formatter step no longer fails with NoClassDefFoundError or NoSuchMethodError when lombok is active as a JVM agent (e.g. -javaagent:lombok.jar in Eclipse/VS Code/Cursor). (#2795)
Commits
  • 61e2016 Published maven/3.10.3
  • 49e0b07 Published lib/4.10.3
  • b7a7748 Fix release signing key ID format (#3105)
  • be8005a Document release signing correction (#3105)
  • 073fe61 Use short signing subkey ID for release publishing
  • 8ac44c7 Fix race when creating the npm install cache directory (#3096)
  • 3f2d955 Update dependency org.slf4j:slf4j-api to v2.0.20 (#3100)
  • 0c70ca8 Merge branch 'main' into fix/npm-cache-directory-race
  • bbf44a4 Fix GrEclipse initialization warnings (#3097)
  • b6bdcd0 Update dependency org.slf4j:slf4j-api to v2.0.20
  • Additional commits viewable in compare view

Updates org.apache.maven:apache-maven from 3.9.16 to 3.10.0

Most Recent Ignore Conditions Applied to This Pull Request
Dependency Name Ignore Conditions
com.diffplug.spotless:spotless-maven-plugin [>= 2.4.a, < 2.5]
com.diffplug.spotless:spotless-maven-plugin [>= 2.3.a, < 2.4]
ch.qos.logback:logback-classic [>= 1.4.a, < 1.5]

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

…h 12 updates

Bumps the maven-dependencies group with 12 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| org.apache.commons:commons-lang3 | `3.20.0` | `3.21.0` |
| software.amazon.awssdk:sts | `2.55.5` | `2.55.10` |
| software.amazon.awssdk:auth | `2.55.5` | `2.55.10` |
| software.amazon.awssdk:http-auth-aws | `2.55.5` | `2.55.10` |
| software.amazon.awssdk:http-auth-spi | `2.55.5` | `2.55.10` |
| software.amazon.awssdk:http-client-spi | `2.55.5` | `2.55.10` |
| software.amazon.awssdk:utils | `2.55.5` | `2.55.10` |
| software.amazon.awssdk:auth | `2.55.5` | `2.55.10` |
| software.amazon.awssdk:http-auth-aws | `2.55.5` | `2.55.10` |
| software.amazon.awssdk:http-auth-spi | `2.55.5` | `2.55.10` |
| software.amazon.awssdk:http-client-spi | `2.55.5` | `2.55.10` |
| software.amazon.awssdk:utils | `2.55.5` | `2.55.10` |
| com.google.auth:google-auth-library-oauth2-http | `1.53.0` | `1.54.0` |
| [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) | `1.6.4` | `1.6.5` |
| [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) | `1.6.4` | `1.6.5` |
| [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) | `1.6.4` | `1.6.5` |
| [com.diffplug.spotless:spotless-maven-plugin](https://github.com/diffplug/spotless) | `3.10.2` | `3.10.3` |
| org.apache.maven:apache-maven | `3.9.16` | `3.10.0` |



Updates `org.apache.commons:commons-lang3` from 3.20.0 to 3.21.0

Updates `software.amazon.awssdk:sts` from 2.55.5 to 2.55.10

Updates `software.amazon.awssdk:auth` from 2.55.5 to 2.55.10

Updates `software.amazon.awssdk:http-auth-aws` from 2.55.5 to 2.55.10

Updates `software.amazon.awssdk:http-auth-spi` from 2.55.5 to 2.55.10

Updates `software.amazon.awssdk:http-client-spi` from 2.55.5 to 2.55.10

Updates `software.amazon.awssdk:utils` from 2.55.5 to 2.55.10

Updates `software.amazon.awssdk:auth` from 2.55.5 to 2.55.10

Updates `software.amazon.awssdk:http-auth-aws` from 2.55.5 to 2.55.10

Updates `software.amazon.awssdk:http-auth-spi` from 2.55.5 to 2.55.10

Updates `software.amazon.awssdk:http-client-spi` from 2.55.5 to 2.55.10

Updates `software.amazon.awssdk:utils` from 2.55.5 to 2.55.10

Updates `com.google.auth:google-auth-library-oauth2-http` from 1.53.0 to 1.54.0

Updates `ch.qos.logback:logback-classic` from 1.6.4 to 1.6.5
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.6.4...v_1.6.5)

Updates `ch.qos.logback:logback-core` from 1.6.4 to 1.6.5
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.6.4...v_1.6.5)

Updates `ch.qos.logback:logback-core` from 1.6.4 to 1.6.5
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.6.4...v_1.6.5)

Updates `com.diffplug.spotless:spotless-maven-plugin` from 3.10.2 to 3.10.3
- [Release notes](https://github.com/diffplug/spotless/releases)
- [Changelog](https://github.com/diffplug/spotless/blob/main/CHANGES.md)
- [Commits](diffplug/spotless@maven/3.10.2...maven/3.10.3)

Updates `org.apache.maven:apache-maven` from 3.9.16 to 3.10.0

---
updated-dependencies:
- dependency-name: org.apache.commons:commons-lang3
  dependency-version: 3.21.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: software.amazon.awssdk:sts
  dependency-version: 2.55.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: software.amazon.awssdk:auth
  dependency-version: 2.55.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: software.amazon.awssdk:http-auth-aws
  dependency-version: 2.55.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: software.amazon.awssdk:http-auth-spi
  dependency-version: 2.55.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: software.amazon.awssdk:http-client-spi
  dependency-version: 2.55.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: software.amazon.awssdk:utils
  dependency-version: 2.55.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: software.amazon.awssdk:auth
  dependency-version: 2.55.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: software.amazon.awssdk:http-auth-aws
  dependency-version: 2.55.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: software.amazon.awssdk:http-auth-spi
  dependency-version: 2.55.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: software.amazon.awssdk:http-client-spi
  dependency-version: 2.55.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: software.amazon.awssdk:utils
  dependency-version: 2.55.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: com.google.auth:google-auth-library-oauth2-http
  dependency-version: 1.54.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: ch.qos.logback:logback-classic
  dependency-version: 1.6.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: ch.qos.logback:logback-core
  dependency-version: 1.6.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: ch.qos.logback:logback-core
  dependency-version: 1.6.5
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: com.diffplug.spotless:spotless-maven-plugin
  dependency-version: 3.10.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.maven:apache-maven
  dependency-version: 3.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Oct 5, 2026
@kubernetes-prow kubernetes-prow Bot added cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. size/S Denotes a PR that changes 10-29 lines, ignoring generated files. labels Oct 5, 2026
@kubernetes-prow kubernetes-prow Bot added size/L Denotes a PR that changes 100-499 lines, ignoring generated files. and removed size/S Denotes a PR that changes 10-29 lines, ignoring generated files. labels Oct 5, 2026
@brendandburns

Copy link
Copy Markdown
Contributor

/lgtm
/approve

@kubernetes-prow kubernetes-prow Bot added the lgtm "Looks good to me", indicates that a PR is ready to be merged. label Oct 5, 2026
@kubernetes-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: brendandburns, dependabot[bot]

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@kubernetes-prow kubernetes-prow Bot added the approved Indicates a PR has been approved by an approver from all required OWNERS files. label Oct 5, 2026
@kubernetes-prow
kubernetes-prow Bot merged commit 6541edc into master Oct 5, 2026
14 checks passed
@dependabot
dependabot Bot deleted the dependabot/maven/maven-dependencies-e18daa9b0a branch October 5, 2026 23:14
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

approved Indicates a PR has been approved by an approver from all required OWNERS files. cncf-cla: yes Indicates the PR's author has signed the CNCF CLA. dependencies Pull requests that update a dependency file java Pull requests that update Java code lgtm "Looks good to me", indicates that a PR is ready to be merged. size/L Denotes a PR that changes 100-499 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant