Skip to content

fix(deps): update all non-major dependencies (minor) - #364

Merged
renovate[bot] merged 1 commit into
mainfrom
renovate/all-minor-patch
Jul 25, 2026
Merged

fix(deps): update all non-major dependencies (minor)#364
renovate[bot] merged 1 commit into
mainfrom
renovate/all-minor-patch

Conversation

@renovate

@renovate renovate Bot commented Apr 26, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
org.jreleaser:jreleaser-maven-plugin 1.23.01.25.0 age confidence
org.sonarsource.scanner.maven:sonar-maven-plugin (source) 5.5.0.63565.7.0.6970 age confidence
org.apache.maven.plugins:maven-site-plugin (source) 3.21.03.22.0 age confidence
org.junit.jupiter:junit-jupiter-params (source) 6.0.36.1.2 age confidence
org.junit.jupiter:junit-jupiter-api (source) 6.0.36.1.2 age confidence
org.junit.jupiter:junit-jupiter-engine (source) 6.0.36.1.2 age confidence
org.zeroturnaround:zt-zip 1.171.18.2 age confidence
net.sf.saxon:Saxon-HE (source) 12.912.10 age confidence

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

jreleaser/jreleaser (org.jreleaser:jreleaser-maven-plugin)

v1.25.0

Compare Source

Binaries

https://github.com/jreleaser/jreleaser/wiki/Release-v1.25.0

Changelog

🚀 Features

assemble

  • 1404462 Resolve native-image distribution artifacts with multiple archive formats, closes #​2106
  • e0c5956 Update gradle DSL, closes #​2106
  • 03ece6e Resolve jlink distribution artifacts with multiple archive formats, closes #​2106
  • 27d5a50 Support multiple archive formats in jlink assembler, closes #​2106

core

release

  • d2c2784 Expose snapshot enabled status

🐛 Fixes

deploy

jdks

  • 2dac6f3 Drop unsupported connectTimeOut from download-maven-plugin call, closes #​2126

packager

release

  • 7d4d23a Ensure JRELEASER_PREVIOUS_TAG_NAME is used with snapshot releases, closes #​2136

signing

validation

  • c47df63 Correct project identifier log message for GitLab deployer

🛠 Build

  • e6c5adc Update release announcements
  • ddd5b2c Bump flatpack runtime to 25.08

📝 Documentation

  • 347c635 Add mvanhorn as a contributor for code
  • cb8ab48 Add seonwooj0810 as a contributor for code

⚙️ Dependencies


  • 76e2acc Releasing version 1.25.0
  • 5e48b86 Bump for next development cycle

Contributors

We'd like to thank the following people for their contributions:

v1.24.0

Compare Source

Binaries

https://github.com/jreleaser/jreleaser/wiki/Release-v1.24.0

Changelog

🚀 Features

announce

core

gradle

  • 48a2685 Fix access to Task.project at task execution time, closes #​1992

jdks

🐛 Fixes

assemble

  • af9767b Pass JVM options to generated launcher by jlink, closes #​2090
  • e7b4afb Resolve relative launcher symlinks, closes #​1994
  • dce1c0f Avoid duplicate resources in Native Image by using -cp option during assemble step, closes #​2094

deploy

  • 39250fa Consider PUBLISHED state when checking deployment transition, closes #​2082

gradle

  • 2737a31 Add property keys related to deprecated Convention APIs, closes #​2078

packager

packagers

sign

🔄️ Changes

packagers

unscoped

  • 735a8df More code audit fixes
  • 37fc14b Apply suggestions from code audits

🛠 Build

  • 7d313fd Fix GH workflows
  • d7488ab Update release announcements
  • 805a0fd Fix wiki updates
  • e20ce15 Fix workflow issues
  • 1d195ce Fix update-wiki script
  • a94a966 Fix issues found by CodeQL
  • af15bca Update GH workflows based on lint audits
  • f925bed Update CodeQL settings
  • 1ff8029 More GH workflow improvements based on audits
  • 4e9bb7d Improve GH workflows based on audits
  • ab785d8 Update github workflows in templates
  • 161c490 Fix workflow linting issues
  • 77d1e3c Pin versions in GH workflows
  • 84aa4b9 Fix some linting issues in GH workflows
  • 9ef4afe Add version management to release workflow
  • 19eb19a Add a GH workflow for linting GH workflows
  • 2f79751 Update readme
  • f978967 Fix wiki template
  • 337c1d3 Update release workflow

📝 Documentation

  • 2f0fd0a Add XiaoPengMei as a contributor for code
  • 564ed30 Add mhoffrog as a contributor for code
  • de84e9e Add PrakarshSrivastav as a contributor for code

⚙️ Dependencies


  • 4def722 Releasing version 1.24.0
  • f645ecd Bump for next development cycle

Contributors

We'd like to thank the following people for their contributions:

SonarSource/sonar-scanner-maven (org.sonarsource.scanner.maven:sonar-maven-plugin)

v5.7.0.6970

Compare Source

Release notes - Sonar Scanner for Maven - 5.7

Feature

SCANMAVEN-317 Support encryption of sonar.token, and other new secure properties
SCANMAVEN-332 support modular-jar artifact type
SCANMAVEN-341 Rework the support of encrypted properties

Maintenance

SCANMAVEN-370 Prepare next development iteration 5.7.0
SCANMAVEN-372 Configure Renovate for sonar-scanner-maven
SCANMAVEN-373 SubmitReview: Use Vault token
SCANMAVEN-374 Unpin internal GitHub actions
SCANMAVEN-376 Use SonarSource/.../sonar-update-center-release@​v1 instead of @​master
SCANMAVEN-377 Update dependency org.assertj:assertj-core to v3.27.7 [SECURITY]

v5.6.0.6792

Compare Source

Release notes - Sonar Scanner for Maven - 5.6

Maintenance

SCANMAVEN-318 Update Orchestrator and fix e2e matrix
SCANMAVEN-324 Convert e2e tests to invoker
SCANMAVEN-346 Fix CI failure
SCANMAVEN-347 Automate detection of sonar:sonar shorthand failure
SCANMAVEN-348 Bump org.assertj:assertj-core from 3.26.3 to 3.27.7 in /sonar-maven-plugin
SCANMAVEN-349 Remove Maven 4 e2e tests from promotion requirements
SCANMAVEN-356 Add automated release workflow
SCANMAVEN-357 Licence packaging standard - Maven Scanner
SCANMAVEN-358 Create SonarUpdateCenterRelease.yml
SCANMAVEN-361 Add issue-categories in automated release
SCANMAVEN-363 Fix e2e tests with Maven 4
SCANMAVEN-364 Do not run nightly builds on weekends
SCANMAVEN-365 Set up orchestrator cache
SCANMAVEN-366 Update sonar-scanner-java-library to 4.1.0.1619
SCANMAVEN-367 Update sonar-scanner-java-library to 4.1.1.1633
SCANMAVEN-369 Update parent pom to 87.0.0.3057

Feature

SCANMAVEN-281 Irrelevant encrypted properties are not filtered out in multi-module project with "sonar" in the name

junit-team/junit-framework (org.junit.jupiter:junit-jupiter-params)

v6.1.1

zeroturnaround/zt-zip (org.zeroturnaround:zt-zip)

v1.18.2

Security
  • Windows only (no effect on other platforms): hardened the directory-traversal and output-directory checks used when unpacking against Windows path normalization. Windows strips a path component's trailing dots and spaces and treats : as a drive/stream separator, so an entry name like " ." could resolve to the output directory itself (re-applying the entry's permissions to it, GHSA-v2g6-7r9j-v6px) and a name like ".. \evil.txt" could escape the output directory. The allocation-free fast path that clears genuine descendant entry names (avoiding a getCanonicalFile() call) no longer clears such names; they are canonicalized and rejected as malicious when their canonical path cannot be resolved or does not stay inside the output directory. The output-directory check compares canonical java.nio.file.Paths so a self-referencing name is recognised even when getCanonicalFile() renders it with a trailing separator. Reported by Marcono1234.

v1.18.1

Fixed
  • ZipUtil.unpack no longer applies a ZIP entry's stored file permissions to the output directory itself when an entry's name resolves to it (for example an entry named /), which could change the output directory's permissions (GHSA-v2g6-7r9j-v6px).

v1.18.0

Added
  • pack overloads that write to an existing java.util.zip.ZipOutputStream.
Changed
  • Raised the minimum runtime to Java 8 (bytecode target moved from 1.6 to 1.8).
  • Upgraded the slf4j-api dependency from 1.6.6 to 2.0.18. zt-zip uses only the SLF4J API; applications that pick this newer API up transitively and still use an SLF4J 1.x binding must move to an SLF4J 2.x-compatible binding.
  • slf4j-api is now a runtime-scoped dependency (previously compile scope), so it is no longer on the consumer compile classpath. Declare a direct slf4j-api dependency if your own code references SLF4J.
Fixed
  • Zips unpack with a transformer no longer hangs when the transformer produces no entry, and a transformer that throws now surfaces its real exception to the caller instead of a misleading "Write end dead" pipe error.
  • Zips.addEntry/addEntries no longer fail with "Stream closed" when adding a directory FileSource; a directory is now stored as a proper directory entry (#​138).
  • ZipUtil.pack no longer fails with FileNotFoundException when a directory contains a broken (dangling) symbolic link; such entries are skipped (#​122).
  • ZipUtil.packEntries/packEntry(File, File, NameMapper) now skip an entry whose NameMapper returns null (the same convention as the directory pack) instead of throwing NullPointerException and leaving a partial zip.
  • The ZipUtil methods that take a separate destination — addEntry/addEntries, removeEntry/removeEntries, replaceEntry/replaceEntries, addOrReplaceEntries, transformEntry/transformEntries, repack — now reject a destination equal to the source with an IllegalArgumentException instead of truncating and destroying the source before reading it; use the in-place variant (without a destination) instead.
  • ByteSource (and the byte[] ZipUtil.addEntry/replaceEntry overloads) now accept null bytes as the documented directory entry instead of throwing NullPointerException.
  • ByteSource with null bytes and the STORED method now produces a valid empty entry (size 0, CRC 0) instead of failing with "STORED entry missing size, compressed size, or crc-32".
Security
  • Hardened the relative path-traversal checks when unpacking, using java.nio.file.Path for consistent sub-directory containment checks.
  • The Zips fluent API unpack path (Zips.get(...).unpack().destination(...).process()) now applies the same path-traversal guard as ZipUtil.unpack, rejecting entries that resolve outside the destination directory; this covers both the plain and transformer branches (#​180).
  • In-place unpack now creates its temporary directory securely with Files.createTempDirectory (atomic, owner-only permissions) instead of a predictable, world-readable directory.
  • AsiExtraField now validates the declared symbolic-link length against the bytes actually present before allocating, so a forged length in a crafted archive can no longer trigger a large (up to ~2 GB) memory allocation per entry while unpacking (#​181).
  • AsiExtraField now rejects a truncated ASI extra field with a ZipException instead of letting an ArrayIndexOutOfBoundsException/NegativeArraySizeException abort unpacking, completing the bounds check added in #​181.
  • BackslashUnpacker now validates the resolved path before creating any directories, so a backslash-separated ..\ entry can no longer create directories outside the output directory (the file write itself was already blocked).
  • ZipUtil.explode, repack and unexplode now create their working file or directory atomically (File.createTempFile / Files.createTempDirectory) instead of a predictable name next to the target, closing a symlink/TOCTOU race when the target sits in a shared directory; the predictable FileUtils.getTempFileFor helper is deprecated.
  • ZipUtil.unwrap now throws a ZipException for an entry name whose path prefix resolves outside the name (such as a ~- or :-prefixed name) instead of letting an unchecked StringIndexOutOfBoundsException abort the operation.

Configuration

📅 Schedule: (in timezone Europe/Oslo)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from c760792 to d66c9d4 Compare May 4, 2026 11:41
@renovate renovate Bot changed the title chore(deps): update dependency org.sonarsource.scanner.maven:sonar-maven-plugin from v5.5.0.6356 to v5.6.0.6792 chore(deps): update all non-major dependencies (minor) May 4, 2026
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 2 times, most recently from 5449321 to 88f3ea0 Compare May 24, 2026 18:37
@sonarqubecloud

Copy link
Copy Markdown

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 88f3ea0 to 16c2802 Compare May 31, 2026 10:46
@sonarqubecloud

Copy link
Copy Markdown

@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch 4 times, most recently from a69b43f to 36d9b5f Compare July 5, 2026 15:25
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from 36d9b5f to cfed6c7 Compare July 16, 2026 07:28
@renovate renovate Bot changed the title chore(deps): update all non-major dependencies (minor) fix(deps): update all non-major dependencies (minor) Jul 16, 2026
@renovate
renovate Bot force-pushed the renovate/all-minor-patch branch from cfed6c7 to 16de96f Compare July 17, 2026 02:43
@sonarqubecloud

Copy link
Copy Markdown

@renovate
renovate Bot merged commit 421370a into main Jul 25, 2026
4 checks passed
@renovate
renovate Bot deleted the renovate/all-minor-patch branch July 25, 2026 18:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants