chore: bump net.bytebuddy:byte-buddy from 1.15.11 to 1.18.14 in /android - #398
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [net.bytebuddy:byte-buddy](https://github.com/raphw/byte-buddy) from 1.15.11 to 1.18.14. - [Release notes](https://github.com/raphw/byte-buddy/releases) - [Changelog](https://github.com/raphw/byte-buddy/blob/master/release-notes.md) - [Commits](raphw/byte-buddy@byte-buddy-1.15.11...byte-buddy-1.18.14) --- updated-dependencies: - dependency-name: net.bytebuddy:byte-buddy dependency-version: 1.18.14 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
PR SummaryLow Risk Overview Reviewed by Cursor Bugbot for commit 8a49248. Bugbot is set up for automated code reviews on this repo. Configure here. |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes using default effort and found 1 potential issue.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, have a team admin enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 8a49248. Configure here.
| force 'net.bytebuddy:byte-buddy:1.15.11' | ||
| force 'net.bytebuddy:byte-buddy-agent:1.15.11' | ||
| force 'net.bytebuddy:byte-buddy:1.18.14' | ||
| force 'net.bytebuddy:byte-buddy-agent:1.18.14' |
There was a problem hiding this comment.
Version bump contradicts comment warning about Jetifier incompatibility
Medium Severity
The comment on lines 145–148 explicitly states that 1.15.x is the last byte-buddy line without the META-INF/versions/24 multi-release overlay that this project's AGP Jetifier can't parse (class file major version 68 error). The force directives now pin 1.18.14, which is well past the stated safe range. If the overlay issue persists in 1.18.14, this will break the build. If 1.18.x actually resolved the overlay problem (e.g., via the Java 8 baseline introduced in 1.18.7), the comment is now stale and misleading.
Reviewed by Cursor Bugbot for commit 8a49248. Configure here.
|
Not compatible |
|
OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting If you change your mind, just re-open this PR and I'll resolve any conflicts on it. |


Bumps net.bytebuddy:byte-buddy from 1.15.11 to 1.18.14.
Release notes
Sourced from net.bytebuddy:byte-buddy's releases.
... (truncated)
Changelog
Sourced from net.bytebuddy:byte-buddy's changelog.
... (truncated)
Commits
92846cb[publish] Releasing Byte Buddy 1.18.14a8a9f14[release] Release new versionb0fe006Skip the signature creation for artifacts that are not deployed.c610783Resolve the signed POM file by the path of the project file.caab321Sign the deployed POM file and allow for a sigstore dry run.c68a9c1Supply the agent argument to the attacher process as an environment variable.3ac9dedAvoid symbolic link resolution on recursive deletion and validate Android ent...8dbae60Sign deployed files using sigstore.5d83cd4Disable semantic versioning check for protected constructor in abstract class...172e0f4Move to method to apply suppression.Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)