Skip to content

chore(deps, amber): update sbt patch updates - #7264

Open
renovate-bot wants to merge 2 commits into
apache:mainfrom
renovate-bot:renovate/sbt-patch-updates
Open

chore(deps, amber): update sbt patch updates#7264
renovate-bot wants to merge 2 commits into
apache:mainfrom
renovate-bot:renovate/sbt-patch-updates

Conversation

@renovate-bot

@renovate-bot renovate-bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

ℹ️ Note

This PR body was truncated due to platform limits.

This PR contains the following updates:

Package Type Update Change
ch.epfl.scala:sbt-scalafix plugin patch 0.14.60.14.7
com.github.sbt:sbt-native-packager plugin patch 1.11.11.11.7
com.konghq:unirest-java patch 3.14.23.14.5
com.thesamet.scalapb:scalapb-json4s patch 0.12.00.12.2
com.typesafe.play:play-json patch 2.10.62.10.8
com.typesafe.scala-logging:scala-logging patch 3.9.53.9.6
com.typesafe:config patch 1.4.61.4.9
io.dropwizard:dropwizard-auth patch 4.0.74.0.17
io.dropwizard:dropwizard-auth provided patch 4.0.74.0.17
io.dropwizard:dropwizard-auth patch 1.3.231.3.29
io.dropwizard:dropwizard-client patch 1.3.231.3.29
io.dropwizard:dropwizard-core patch 4.0.74.0.17
io.dropwizard:dropwizard-core provided patch 4.0.74.0.17
io.dropwizard:dropwizard-core patch 1.3.231.3.29
io.dropwizard:dropwizard-testing Test patch 4.0.74.0.17
io.github.classgraph:classgraph Test patch 4.8.1844.8.186
io.github.classgraph:classgraph patch 4.8.1574.8.186
io.github.classgraph:classgraph patch 4.8.1844.8.186
io.kubernetes:client-java patch 21.0.021.0.2-legacy
io.netty:netty-all patch 4.2.15.Final4.2.17.Final
io.netty:netty-buffer patch 4.2.15.Final4.2.17.Final
io.netty:netty-codec patch 4.2.15.Final4.2.17.Final
io.netty:netty-codec-http patch 4.2.15.Final4.2.17.Final
io.netty:netty-codec-http2 patch 4.2.15.Final4.2.17.Final
io.netty:netty-codec-socks patch 4.2.15.Final4.2.17.Final
io.netty:netty-common patch 4.2.15.Final4.2.17.Final
io.netty:netty-handler patch 4.2.15.Final4.2.17.Final
io.netty:netty-handler-proxy patch 4.2.15.Final4.2.17.Final
io.netty:netty-resolver patch 4.2.15.Final4.2.17.Final
io.netty:netty-transport patch 4.2.15.Final4.2.17.Final
io.netty:netty-transport-classes-epoll patch 4.2.15.Final4.2.17.Final
io.netty:netty-transport-native-epoll patch 4.2.15.Final4.2.17.Final
io.netty:netty-transport-native-unix-common patch 4.2.15.Final4.2.17.Final
org.apache.commons:commons-jcs3-core patch 3.23.2.1
org.eclipse.jetty:jetty-http patch 9.4.20.v201908139.4.58.v20250814
org.eclipse.jetty:jetty-server patch 9.4.20.v201908139.4.58.v20250814
org.eclipse.jetty:jetty-servlet provided patch 11.0.2411.0.26
org.eclipse.jetty:jetty-servlet patch 9.4.20.v201908139.4.58.v20250814
org.eclipse.jgit:org.eclipse.jgit patch 5.13.0.202109080827-r5.13.5.202508271544-r
org.ehcache:sizeof patch 0.4.30.4.4
org.playframework:play-json patch 3.1.0-M13.1.0-M10
org.postgresql:postgresql (source) patch 42.7.1042.7.13
org.scalatest:scalatest (source) Test patch 3.2.153.2.20
org.scalatest:scalatest (source) Test patch 3.2.173.2.20
org.slf4j:slf4j-api patch 1.7.261.7.36
sbt/sbt patch 1.12.91.12.14

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

scalacenter/sbt-scalafix (ch.epfl.scala:sbt-scalafix)

v0.14.7

Compare Source

Pull Requests

sbt/sbt-native-packager (com.github.sbt:sbt-native-packager)

v1.11.7: 1.11.7 SBT Native Packager 📦

Compare Source

In This Release

  • Use release drafter for releases (#​1737)
  • Update sbt-ghpages to 0.9.0 (#​1723)
  • Update sbt, scripted-plugin to 1.11.7 (#​1728)
  • Update sbt-scalafmt to 2.5.6 (#​1729)
  • Use eclipse-temurin:25 For Base Image (#​1735)
  • Remove sbt-heroku from related plugins list (#​1731)

🐛 Bug Fixes

v1.11.4: 1.11.4

Compare Source

sbt-native-packager 1.11.4 is cross published to:

sbt Version Published
1.x
2.x

About sbt-native-packager

sbt-native-packager is an sbt plugin to build packages for different operating systems. See https://www.scala-sbt.org/sbt-native-packager/ for the documentation.

Security update

Updates

Behind the scene

Full Changelog: sbt/sbt-native-packager@v1.11.3...v1.11.4

v1.11.3: 1.11.3

Compare Source

sbt-native-packager 1.11.3 is cross published to:

sbt Version Published
1.x
2.x

About sbt-native-packager

sbt-native-packager is an sbt plugin to build packages for different operating systems. See https://www.scala-sbt.org/sbt-native-packager/ for the documentation.

sbt 2.x migration

Other updates

Behind the scene

New Contributors

Full Changelog: sbt/sbt-native-packager@v1.11.1...v1.11.3

scalapb/scalapb-json4s (com.thesamet.scalapb:scalapb-json4s)

v0.12.2

Compare Source

v0.12.1

Compare Source

playframework/play-json (com.typesafe.play:play-json)

v2.10.8: Play JSON 2.10.8

Compare Source

Noteworthy improvements

  • #​1226 [2.10.x] Avoid running out of memory when parsing heavily nested arrays or objects by @​mkurz
    • We now limit the maximum allowed nesting depth of JSON structures (arrays, objects, or a mix of both) to 1000.
      This limit can be adjusted using the system property play.json.parser.maxNestingDepth.
      We assume a depth of 1000 should be more than sufficient for virtually all real-world use cases.

      This change helps prevent both potential OutOfMemoryErrors and StackOverflowErrors.
      The latter, however, is not a concern for Play JSON, since it already uses a @tailrec-optimized parsing method.
      As a result, Play JSON is not affected by CVE-2025-52999, which specifically addresses StackOverflowError risks.
      This improvement is simply an additional safety measure.

Changes

❤️ Thanks to our premium sponsors!

If you find this OSS project useful for work, please consider asking your company to support it by becoming a sponsor.
You can also individually sponsor the project by becoming a backer.

🙇 Thanks to our contributors

Finally, thanks to the community for their help with detailed bug reports, discussions about new features and pull request reviews. This project is only possible due to the help we had from amazing contributors.
Special thanks to all code contributors who helped with this particular release (they are listed below)!

v2.10.7: Play JSON 2.10.7

Compare Source

Noteworthy Scala 3 improvements

Changes

❤️ Thanks to our premium sponsors!

If you find this OSS project useful for work, please consider asking your company to support it by becoming a sponsor.
You can also individually sponsor the project by becoming a backer.

🙇 Thanks to our contributors

Finally, thanks to the community for their help with detailed bug reports, discussions about new features and pull request reviews. This project is only possible due to the help we had from amazing contributors.
Special thanks to all code contributors who helped with this particular release (they are listed below)!

lightbend/scala-logging (com.typesafe.scala-logging:scala-logging)

v3.9.6

Compare Source

What's Changed
New Contributors

Full Changelog: scala-garden/scala-logging@v3.9.5...v3.9.6

lightbend/config (com.typesafe:config)

v1.4.9

Compare Source

What's Changed
New Contributors

Full Changelog: lightbend/config@v1.4.8...v1.4.9

v1.4.8

Compare Source

What's Changed

Full Changelog: lightbend/config@v1.4.7...v1.4.8

v1.4.7

Compare Source

What's Changed
New Contributors

Full Changelog: lightbend/config@v1.4.6...v1.4.7

kubernetes-client/java (io.kubernetes:client-java)

v21.0.2-legacy

Compare Source

[maven-release-plugin] copy for tag v21.0.2-legacy

v21.0.1

Compare Source

  • Misc
    • Patch release — dependency and stability updates.

v21.0.0-legacy

Compare Source

ehcache/sizeof (org.ehcache:sizeof)

v0.4.4

Compare Source

pgjdbc/pgjdbc (org.postgresql:postgresql)

v42.7.13

Added
  • feat: invalidate the prepared-statement cache when the server reports a search_path change via GUC_REPORT (PostgreSQL 18+), so cached plans are no longer used against the wrong schema PR #​4259
  • feat: reWriteBatchedInserts now merges up to 32768 rows into one multi-values INSERT (bounded by the 65535 bind-parameter limit on the extended protocol) instead of capping at 128, which speeds up batches of few-column rows. The new reWriteBatchedInsertsSize connection property lowers that cap when set; the default of 0 uses that maximum. PR #​4207
  • feat: invalidate the prepared-statement cache after CREATE/DROP/ALTER so callers no longer trip on "cached plan must not change result type" without opting into autosave=ALWAYS. Controlled by the new flushCacheOnDdl connection property (default true); set to false for the prior behaviour. PR #​4067
  • feat: add connectExecutor connection property to customize the Executor used to run the worker task that performs the connection attempt when loginTimeout is in effect. The value is the fully qualified name of a class implementing java.util.concurrent.Executor. With a null value, the default, the driver retains the prior behavior of running the connection attempt on a daemon thread named "PostgreSQL JDBC driver connection thread". The executor must run the task on a thread other than the caller's. Running the attempt on a named thread lets applications that monitor driver-created threads identify it. PR #​4165
  • feat: add classLoaderStrategy connection property to control which classloaders the driver searches when loading a class named by a connection property, for example socketFactory. The default driver-first now falls back to the thread context classloader when the driver's classloader cannot resolve the class, which fixes class loading in non-flat class paths such as Quarkus and OSGi. Set driver to keep the previous driver-classloader-only behaviour, or context-first to prefer the thread context classloader Issue #​2112 PR #​4167
  • feat: add OID constants for geometric arrays, RECORD, and refcursor PR #​4220
  • feat: LargeObject BlobInputStream now skips by seeking instead of reading, and the driver exposes the server version so it can select the 64-bit large-object API where available PR #​4204
Changed
  • refactor: the worker that runs the connection attempt under loginTimeout is now a FutureTask (ConnectTask) instead of the hand-rolled ConnectThread. When the caller hits the timeout, the task is now cancelled with cancel(true), which interrupts the worker thread rather than letting it run to completion. This makes the connection attempt interruptible, so loginTimeout can stop a slow connection attempt instead of leaking a thread. As before, a connection that the worker still manages to establish after the caller gives up is closed by the worker so that it does not leak. There are no public API changes and this should only lead to faster background resource cleanup for connections that time out. PR #​4120
  • chore: PGXAConnection.ConnectionHandler now rejects setAutoCommit(false) and setSavepoint(...) during an active XA branch, in addition to the long-rejected setAutoCommit(true) / commit() / rollback(). The setSavepoint rejection was already meant to be in place but the guard misspelled the method name as setSavePoint, so savepoints silently went through. Both changes bring the proxy in line with JTA 1.2 §3.4. PR #​4114
  • chore: commitPrepared / rollback-of-prepared now return XAER_RMFAIL instead of XAER_RMERR when the underlying connection is left in a non-idle TransactionState. Transaction managers (Geronimo, Narayana, Atomikos) treat XAER_RMFAIL as retryable on a fresh XAResource; the prepared transaction is no longer abandoned. PR #​4114
  • refactor: derive getPrimaryKeys from pg_constraint.conkey PR #​4202
Fixed
  • fix: the published GitHub release now ships the released postgresql-<version>.jar and its detached PGP signature, taken from the same signed build that is uploaded to Maven Central, instead of a leftover SNAPSHOT jar Issue #​3812 PR #​3814
  • fix: simplify the Statement#cancel state machine by dropping the redundant CANCELLED state. killTimerTask now waits for the state to return to IDLE directly, which removes a spin-forever case when more than one thread observes the cancel completing PR #​1827.
  • perf: defer simple-query flushes until the driver reads the response, allowing BEGIN and the following query to share a network flush Issue #​3894 PR #​4196
  • fix: reWriteBatchedInserts no longer throws IllegalArgumentException when batching a parameterless INSERT (for example INSERT INTO t VALUES (1, 2)) of 256 rows or more PR #​4207
  • fix: a comment before CALL in a CallableStatement no longer hides the native call, so OUT parameter registration works for /* comment */ call proc(?, ?) and similar. Parser.modifyJdbcCall now skips leading whitespace and SQL comments (both -- and /* */) before the call, tolerates a trailing comment after a { ... } escape, and no longer adds a spurious comma when moving an OUT parameter into a call whose arguments are only a comment Issue #​2538 PR #​4209
  • fix: PreparedStatement.toString() no longer throws for a bytea value supplied as text via PGobject. Hex-format values (\x...) are validated and rendered as a bytea literal, and escape-format values are quoted and cast like any other literal Issue #​3757 PR #​4201
  • fix: the driver no longer nulls the contextClassLoader of shared ForkJoinPool.commonPool() worker threads, which previously left unrelated tasks on those threads running with a null classloader Issue #​4155 PR #​4156
  • fix: PgResultSet#getCharacterStream wraps String in a StringReader PR #​4063
  • fix: PGXAConnection no longer saves and restores the underlying connection's JDBC autoCommit flag. All XA-protocol SQL (BEGIN, PREPARE TRANSACTION, COMMIT, ROLLBACK, COMMIT PREPARED, ROLLBACK PREPARED, the recover() SELECT) is sent through QUERY_SUPPRESS_BEGIN, so the caller's autoCommit value is invariant across every XAResource call. Fixes the "2nd phase commit must be issued using an idle connection" failure during recovery on managed datasources that pool connections with autoCommit=false (TomEE, WildFly, WebSphere Liberty) PR #​4114
  • fix: PGXAConnection.prepare() now mutates XA state only after PREPARE TRANSACTION succeeds. A failed PREPARE previously left the driver thinking the branch was already prepared, so the follow-up rollback(xid) tried ROLLBACK PREPARED against a non-existent gid and returned XAER_RMERR. Transaction managers (Narayana) escalated this to HeuristicMixedException. With the fix, rollback(xid) takes the active-branch path and issues a plain ROLLBACK, which the server accepts cleanly. Fixes Issue #​3153, Issue #​3123. PR #​4114
  • fix: an updatable result set over an unqualified table name is now classified using only the table visible through search_path. When two schemas held a table with the same name and the same primary or unique index name but a different set of key columns, the driver took the union of both schemas' columns, so the result set could be wrongly rejected as not updatable [PR #​4214](https://redirect.github.com/pgjdbc/pgjdb

Note

PR body was truncated to here.


Configuration

📅 Schedule: (in timezone Etc/UTC)

  • Branch creation
    • "before 8am on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@forking-renovate forking-renovate Bot added the dependencies Pull requests that update a dependency file label Aug 3, 2026
@github-actions github-actions Bot added engine common platform Non-amber Scala service paths labels Aug 3, 2026
@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

Automated Reviewer Suggestions

Based on the git blame history of the changed files, we recommend the following reviewers:

  • Committers with relevant context: @pjfanning
    You can request their reviews formally with /request-review @pjfanning.

  • Contributors with relevant context: @Ma77Ball, @aglinxinyuan, @Yicong-Huang
    You can notify them by mentioning @Ma77Ball, @aglinxinyuan, @Yicong-Huang in a comment.

@codecov-commenter

codecov-commenter commented Aug 3, 2026

Copy link
Copy Markdown

❌ 1 Tests Failed:

Tests completed Failed Passed Skipped
2 1 1 0
View the top 1 failed test(s) by shortest run time
org.apache.texera.service.resource.ConfigResourceSpec::(It is not a test it is a sbt.testing.SuiteSelector)
Stack Traces | 0.015s run time
com.fasterxml.jackson.databind.JsonMappingException: Scala module 2.18.8 requires Jackson Databind version >= 2.18.0 and < 2.19.0 - Found jackson-databind version 2.21.2
	at com.fasterxml.jackson.module.scala.JacksonModule.setupModule(JacksonModule.scala:61)
	at com.fasterxml.jackson.module.scala.JacksonModule.setupModule$(JacksonModule.scala:46)
	at com.fasterxml.jackson.module.scala.DefaultScalaModule.setupModule(DefaultScalaModule.scala:17)
	at com.fasterxml.jackson.databind.ObjectMapper.registerModule(ObjectMapper.java:909)
	at org.apache.texera.service.resource.ConfigResourceSpec.<init>(ConfigResourceSpec.scala:65)
	at java.base/jdk.internal.reflect.NativeConstructorAccessorImpl.newInstance0(Native Method)
	at java.base/jdk.internal.reflect.NativeConstructorAccessorImpl.newInstance(NativeConstructorAccessorImpl.java:77)
	at java.base/jdk.internal.reflect.DelegatingConstructorAccessorImpl.newInstance(DelegatingConstructorAccessorImpl.java:45)
	at java.base/java.lang.reflect.Constructor.newInstanceWithCaller(Constructor.java:500)
	at java.base/java.lang.reflect.ReflectAccess.newInstance(ReflectAccess.java:128)
	at java.base/jdk.internal.reflect.ReflectionFactory.newInstance(ReflectionFactory.java:347)
	at java.base/java.lang.Class.newInstance(Class.java:647)
	at org.scalatest.tools.Framework$ScalaTestTask.execute(Framework.scala:454)
	at sbt.TestRunner.runTest$1(TestFramework.scala:153)
	at sbt.TestRunner.run(TestFramework.scala:168)
	at sbt.TestFramework$$anon$3$$anonfun$$lessinit$greater$1.$anonfun$apply$1(TestFramework.scala:336)
	at sbt.TestFramework$.sbt$TestFramework$$withContextLoader(TestFramework.scala:296)
	at sbt.TestFramework$$anon$3$$anonfun$$lessinit$greater$1.apply(TestFramework.scala:336)
	at sbt.TestFramework$$anon$3$$anonfun$$lessinit$greater$1.apply(TestFramework.scala:336)
	at sbt.TestFunction.apply(TestFramework.scala:348)
	at sbt.Tests$.$anonfun$toTask$1(Tests.scala:436)
	at sbt.std.Transform$$anon$3.$anonfun$apply$2(Transform.scala:47)
	at sbt.std.Transform$$anon$4.work(Transform.scala:69)
	at sbt.Execute.$anonfun$submit$2(Execute.scala:283)
	at sbt.internal.util.ErrorHandling$.wideConvert(ErrorHandling.scala:24)
	at sbt.Execute.work(Execute.scala:292)
	at sbt.Execute.$anonfun$submit$1(Execute.scala:283)
	at sbt.ConcurrentRestrictions$$anon$4.$anonfun$submitValid$1(ConcurrentRestrictions.scala:265)
	at sbt.CompletionService$$anon$2.call(CompletionService.scala:65)
	at java.base/java.util.concurrent.FutureTask.run(FutureTask.java:264)
	at java.base/java.util.concurrent.Executors$RunnableAdapter.call(Executors.java:539)
	at java.base/java.util.concurrent.FutureTask.run(FutureTask.java:264)
	at java.base/java.util.concurrent.ThreadPoolExecutor.runWorker(ThreadPoolExecutor.java:1136)
	at java.base/java.util.concurrent.ThreadPoolExecutor$Worker.run(ThreadPoolExecutor.java:635)
	at java.base/java.lang.Thread.run(Thread.java:840)

To view more test analytics, go to the Test Analytics Dashboard
📋 Got 3 mins? Take this short survey to help us improve Test Analytics.

@github-actions

github-actions Bot commented Aug 3, 2026

Copy link
Copy Markdown
Contributor

⚠️ Benchmark changes need a look

🟢 2 better · 🔴 3 worse · ⚪ 10 noise (<±5%) · 0 without baseline

Compared against main cd28761 benchmarked on this same runner, so the delta is largely free of cross-runner hardware noise. The "7d avg" column still reflects the gh-pages dashboard. Treat <±5% as noise unless repeated.

Dashboard · Run

config throughput MB/s latency max Δ latest / 7d
🔴 bs=10 sw=10 sl=64 411 0.251 23,170/34,295/34,295 us 🔴 +7.5% / 🔴 +120.7%
🟢 bs=100 sw=10 sl=64 955 0.583 104,997/119,677/119,677 us 🟢 -21.2% / 🔴 +9.7%
bs=1000 sw=10 sl=64 1,094 0.667 901,283/1,043,123/1,043,123 us ⚪ within ±5% / 🟢 -10.1%
Baseline details

Latest main cd28761 from same runner

config metric PR latest main 7d avg Δ latest Δ 7d
bs=10 sw=10 sl=64 throughput 411 tuples/sec 443 tuples/sec 767.32 tuples/sec -7.2% -46.4%
bs=10 sw=10 sl=64 MB/s 0.251 MB/s 0.27 MB/s 0.468 MB/s -7.0% -46.4%
bs=10 sw=10 sl=64 p50 23,170 us 21,554 us 12,772 us +7.5% +81.4%
bs=10 sw=10 sl=64 p95 34,295 us 35,689 us 15,538 us -3.9% +120.7%
bs=10 sw=10 sl=64 p99 34,295 us 35,689 us 18,948 us -3.9% +81.0%
bs=100 sw=10 sl=64 throughput 955 tuples/sec 928 tuples/sec 972.51 tuples/sec +2.9% -1.8%
bs=100 sw=10 sl=64 MB/s 0.583 MB/s 0.566 MB/s 0.594 MB/s +3.0% -1.8%
bs=100 sw=10 sl=64 p50 104,997 us 108,379 us 103,020 us -3.1% +1.9%
bs=100 sw=10 sl=64 p95 119,677 us 151,928 us 109,070 us -21.2% +9.7%
bs=100 sw=10 sl=64 p99 119,677 us 151,928 us 118,964 us -21.2% +0.6%
bs=1000 sw=10 sl=64 throughput 1,094 tuples/sec 1,092 tuples/sec 1,005 tuples/sec +0.2% +8.9%
bs=1000 sw=10 sl=64 MB/s 0.667 MB/s 0.666 MB/s 0.613 MB/s +0.2% +8.7%
bs=1000 sw=10 sl=64 p50 901,283 us 901,190 us 1,002,400 us +0.0% -10.1%
bs=1000 sw=10 sl=64 p95 1,043,123 us 1,062,439 us 1,039,228 us -1.8% +0.4%
bs=1000 sw=10 sl=64 p99 1,043,123 us 1,062,439 us 1,069,081 us -1.8% -2.4%
Raw CSV
config_idx,batch_size,schema_width,string_len,num_batches,total_ms,total_tuples,total_bytes,tuples_per_sec,mb_per_sec,lat_p50_us,lat_p95_us,lat_p99_us
0,10,10,64,20,486.67,200,128000,411,0.251,23170.20,34294.69,34294.69
1,100,10,64,20,2094.21,2000,1280000,955,0.583,104997.05,119676.55,119676.55
2,1000,10,64,20,18289.84,20000,12800000,1094,0.667,901283.38,1043122.92,1043122.92

@aglinxinyuan

Copy link
Copy Markdown
Contributor

Pushed 87ca804 to get this green. Three of the grouped bumps are not actually safe patches, and none of the LICENSE-binary / NOTICE-binary files had been synced.

Held back

Bump Why it breaks
io.dropwizard:* 4.0.7 → 4.0.17 Two independent breaks. (1) It resolves jersey 3.0.18, but the root build.sbt dependencyOverrides pin jersey-common at 3.0.12 for FileService / WorkflowCompilingService. ResourceConfig in jersey-server 3.0.18 implements org.glassfish.jersey.ApplicationSupplier, which does not exist in jersey-common 3.0.12 — scalac fails at RoleAnnotationEnforcer.enforce: Class org.glassfish.jersey.ApplicationSupplier not found - continuing with a stub. (2) It resolves jackson 2.21.0, while jackson-module-scala is pinned at 2.18.8, which requires databind >= 2.18.0 && < 2.19.0 — every resource spec dies with ExceptionInInitializerError / Scala module 2.18.8 requires Jackson Databind version ... Found 2.21.0. Moving dropwizard 4.x needs a deliberate jackson upgrade first, so it stays at 4.0.7.
org.playframework:play-json 3.1.0-M1 → 3.1.0-M10 Drags jackson-databind 2.21.2 into ConfigService, which (unlike FileService) has no databind override — ConfigResourceSpec aborts with the same jackson-module-scala mismatch. Also a milestone-to-milestone jump rather than a patch.
io.kubernetes:client-java 21.0.0 → 21.0.2-legacy The -legacy classifier is a separate artifact line, picked only because it sorts above the plain 21.0.2 that also exists. It pulls jakarta.ws.rs-api 4.0.0 (JAX-RS 4.0) and httpclient 4.5.14 under a JAX-RS 3.1 Dropwizard. Retargeted to plain 21.0.2, which keeps jakarta.ws.rs-api at 3.1.0.

Licensing

Every remaining bump needed the binary-license bookkeeping that was missing — this is what made platform (computing-unit-managing-service) fail on NOTICE-binary differs from generator output:

  • direct + transitive version entries refreshed in all six service LICENSE-binary files and amber/LICENSE-binary-java;
  • amber/LICENSE-binary-java jar set adjusted for dropwizard 1.3.29's changed transitive closure — com.papertrail:profiler:1.0.2 is gone, replaced by com.helger:profiler:1.1.1 (Apache-2.0), plus new javax.activation:javax.activation-api:1.2.0 (CDDL 1.1) and org.eclipse.jetty:jetty-util-ajax:9.4.58 (Apache-2.0);
  • all seven NOTICE-binary files regenerated with bin/licensing/generate_notice_binary.py from freshly built dists.

Verified locally (JDK 17)

  • Test/compile clean across the build; scalafmtCheckAll and scalafixAll --check clean.
  • Previously failing suites now pass: AccessControlService (37), ConfigService (34), NotebookMigrationService (26), ComputingUnitManagingService (73), WorkflowCompilingService (4).
  • All seven dists built, then check_binary_deps.py --ignore-transitive-version + the generate_notice_binary.py diff run exactly as build.yml does — clean for all seven.
  • WorkflowExecutionService/test failures are byte-identical to base 436b37e (local-only e2e / Iceberg / Windows issues), so nothing here regressed amber.
  • FileService's testcontainers suites were not run locally (no Docker on this machine); CI covers them.

One follow-up worth considering separately: renovate.json5 already disables lockstep families like arrow/pandas. io.dropwizard 4.x is coupled to jackson the same way, so a similar rule would stop this bump from reappearing each week.

@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

👋 Thanks for opening this pull request, @renovate-bot!

It looks like the pull request description doesn't quite follow our template yet:

  • The What changes were proposed in this PR? section is missing; please keep the template's headings.
  • The How was this PR tested? section is missing; please keep the template's headings.
  • The Was this PR authored or co-authored using generative AI tooling? section is missing; please keep the template's headings.

Filling out the template helps reviewers understand and triage your contribution faster. Please edit the description to complete it. This message will disappear automatically once the template is followed.

You can find the template prompts by editing the description, or see CONTRIBUTING.md for the full contribution flow.

@renovate-bot
renovate-bot force-pushed the renovate/sbt-patch-updates branch from 87ca804 to b8353d1 Compare August 5, 2026 00:53
@forking-renovate

Copy link
Copy Markdown

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

common dependencies Pull requests that update a dependency file engine platform Non-amber Scala service paths

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants