From 35a4712a11d8acbd134f5831559de75653ac158f Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 17 Dec 2024 02:36:55 +0000 Subject: [PATCH 1/2] Bump the build-dependencies group with 7 updates Bumps the build-dependencies group with 7 updates: | Package | From | To | | --- | --- | --- | | [org.junit:junit-bom](https://github.com/junit-team/junit5) | `5.11.3` | `5.11.4` | | org.apache.logging.log4j:log4j-core | `2.24.1` | `2.24.3` | | org.apache.logging.log4j:log4j-api | `2.24.1` | `2.24.3` | | org.apache.logging.log4j:log4j-slf4j-impl | `2.24.1` | `2.24.3` | | org.jboss.weld.se:weld-se-shaded | `5.1.3.Final` | `6.0.0.Final` | | [com.puppycrawl.tools:checkstyle](https://github.com/checkstyle/checkstyle) | `10.20.2` | `10.21.0` | | com.gradle:develocity-maven-extension | `1.22.2` | `1.23` | Updates `org.junit:junit-bom` from 5.11.3 to 5.11.4 - [Release notes](https://github.com/junit-team/junit5/releases) - [Commits](https://github.com/junit-team/junit5/compare/r5.11.3...r5.11.4) Updates `org.apache.logging.log4j:log4j-core` from 2.24.1 to 2.24.3 Updates `org.apache.logging.log4j:log4j-api` from 2.24.1 to 2.24.3 Updates `org.apache.logging.log4j:log4j-slf4j-impl` from 2.24.1 to 2.24.3 Updates `org.apache.logging.log4j:log4j-api` from 2.24.1 to 2.24.3 Updates `org.apache.logging.log4j:log4j-slf4j-impl` from 2.24.1 to 2.24.3 Updates `org.jboss.weld.se:weld-se-shaded` from 5.1.3.Final to 6.0.0.Final Updates `com.puppycrawl.tools:checkstyle` from 10.20.2 to 10.21.0 - [Release notes](https://github.com/checkstyle/checkstyle/releases) - [Commits](https://github.com/checkstyle/checkstyle/compare/checkstyle-10.20.2...checkstyle-10.21.0) Updates `com.gradle:develocity-maven-extension` from 1.22.2 to 1.23 --- updated-dependencies: - dependency-name: org.junit:junit-bom dependency-type: direct:production update-type: version-update:semver-patch dependency-group: build-dependencies - dependency-name: org.apache.logging.log4j:log4j-core dependency-type: direct:production update-type: version-update:semver-patch dependency-group: build-dependencies - dependency-name: org.apache.logging.log4j:log4j-api dependency-type: direct:production update-type: version-update:semver-patch dependency-group: build-dependencies - dependency-name: org.apache.logging.log4j:log4j-slf4j-impl dependency-type: direct:production update-type: version-update:semver-patch dependency-group: build-dependencies - dependency-name: org.apache.logging.log4j:log4j-api dependency-type: direct:production update-type: version-update:semver-patch dependency-group: build-dependencies - dependency-name: org.apache.logging.log4j:log4j-slf4j-impl dependency-type: direct:production update-type: version-update:semver-patch dependency-group: build-dependencies - dependency-name: org.jboss.weld.se:weld-se-shaded dependency-type: direct:development update-type: version-update:semver-major dependency-group: build-dependencies - dependency-name: com.puppycrawl.tools:checkstyle dependency-type: direct:production update-type: version-update:semver-minor dependency-group: build-dependencies - dependency-name: com.gradle:develocity-maven-extension dependency-type: direct:production update-type: version-update:semver-minor dependency-group: build-dependencies ... Signed-off-by: dependabot[bot] --- .mvn/extensions.xml | 2 +- build/parents/build/pom.xml | 6 +++--- pom.xml | 2 +- 3 files changed, 5 insertions(+), 5 deletions(-) diff --git a/.mvn/extensions.xml b/.mvn/extensions.xml index aed8230ad29..69e1ab0004f 100644 --- a/.mvn/extensions.xml +++ b/.mvn/extensions.xml @@ -2,7 +2,7 @@ com.gradle develocity-maven-extension - 1.22.2 + 1.23 com.gradle diff --git a/build/parents/build/pom.xml b/build/parents/build/pom.xml index b9d9204ef58..88aa6720081 100644 --- a/build/parents/build/pom.xml +++ b/build/parents/build/pom.xml @@ -128,9 +128,9 @@ - 2.24.1 + 2.24.3 4.13.2 - 5.11.3 + 5.11.4 1.10.0 6.0.0 @@ -156,7 +156,7 @@ - remove and generate the files in mapper/orm-outbox-polling/src/main/avro/generated --> 1.12.0 - 5.1.3.Final + 6.0.0.Final 2.3.232 diff --git a/pom.xml b/pom.xml index d5b3e7de498..eb52bc0101c 100644 --- a/pom.xml +++ b/pom.xml @@ -301,7 +301,7 @@ 5.0.0.4389 3.0.0 4.0.13 - 10.20.2 + 10.21.0 2.18.0 3.3.2 1.0.0 From 2cf4a3fff601eac2ee9f8da7de21e8bef39498ae Mon Sep 17 00:00:00 2001 From: marko-bekhta Date: Tue, 17 Dec 2024 08:56:49 +0100 Subject: [PATCH 2/2] Stay on the current major Weld version --- .github/dependabot.yml | 4 ++++ build/parents/build/pom.xml | 6 +++--- 2 files changed, 7 insertions(+), 3 deletions(-) diff --git a/.github/dependabot.yml b/.github/dependabot.yml index 73ff2f8ee4d..1d633560cff 100644 --- a/.github/dependabot.yml +++ b/.github/dependabot.yml @@ -100,6 +100,10 @@ updates: - dependency-name: "jakarta.enterprise:jakarta.enterprise.cdi-api" - dependency-name: "jakarta.xml.bind:jakarta.xml.bind-api" - dependency-name: "net.bytebuddy:*" + # Because we stay on a particular version of CDI that matches the one in ORM + # we don't want always want to get the latest Weld version: + - dependency-name: "org.jboss.weld.se:*" + update-types: ["version-update:semver-major"] # Sticking to Derby 10.15 for now since later versions require JDK 17+, and we need to test with JDK 11. # See https://db.apache.org/derby/derby_downloads.html - dependency-name: "org.apache.derby:*" diff --git a/build/parents/build/pom.xml b/build/parents/build/pom.xml index 88aa6720081..cfca040448d 100644 --- a/build/parents/build/pom.xml +++ b/build/parents/build/pom.xml @@ -88,7 +88,7 @@ 1.7.36 - + 1.12.0 - 6.0.0.Final + 5.1.4.Final 2.3.232 @@ -1056,7 +1056,7 @@ - + javax.persistence:javax.persistence-api javax.transaction:javax.transaction-api javax.enterprise:cdi-api