chore: [DevOps] bump the production-minor-patch group with 8 updates#1107
Closed
dependabot[bot] wants to merge 1 commit intomainfrom
Closed
chore: [DevOps] bump the production-minor-patch group with 8 updates#1107dependabot[bot] wants to merge 1 commit intomainfrom
dependabot[bot] wants to merge 1 commit intomainfrom
Conversation
Bumps the production-minor-patch group with 8 updates: | Package | From | To | | --- | --- | --- | | [org.assertj:assertj-vavr](https://github.com/assertj/assertj-vavr) | `0.4.3` | `0.5.0` | | [org.mockito:mockito-core](https://github.com/mockito/mockito) | `5.21.0` | `5.22.0` | | [org.yaml:snakeyaml](https://bitbucket.org/snakeyaml/snakeyaml) | `2.5` | `2.6` | | [io.vavr:vavr](https://github.com/vavr-io/vavr) | `1.0.0` | `1.0.1` | | [org.checkerframework:checker-qual](https://github.com/typetools/checker-framework) | `3.53.1` | `3.54.0` | | [com.google.errorprone:error_prone_annotations](https://github.com/google/error-prone) | `2.47.0` | `2.48.0` | | [io.spiffe:java-spiffe-core](https://github.com/spiffe/java-spiffe) | `0.8.15` | `0.8.16` | | [io.spiffe:grpc-netty-linux](https://github.com/spiffe/java-spiffe) | `0.8.15` | `0.8.16` | Updates `org.assertj:assertj-vavr` from 0.4.3 to 0.5.0 - [Release notes](https://github.com/assertj/assertj-vavr/releases) - [Commits](assertj/assertj-vavr@v0.4.3...v0.5.0) Updates `org.mockito:mockito-core` from 5.21.0 to 5.22.0 - [Release notes](https://github.com/mockito/mockito/releases) - [Commits](mockito/mockito@v5.21.0...v5.22.0) Updates `org.yaml:snakeyaml` from 2.5 to 2.6 - [Commits](https://bitbucket.org/snakeyaml/snakeyaml/branches/compare/snakeyaml-2.6..snakeyaml-2.5) Updates `io.vavr:vavr` from 1.0.0 to 1.0.1 - [Release notes](https://github.com/vavr-io/vavr/releases) - [Commits](vavr-io/vavr@v1.0.0...v1.0.1) Updates `org.checkerframework:checker-qual` from 3.53.1 to 3.54.0 - [Release notes](https://github.com/typetools/checker-framework/releases) - [Changelog](https://github.com/typetools/checker-framework/blob/master/docs/CHANGELOG.md) - [Commits](typetools/checker-framework@checker-framework-3.53.1...checker-framework-3.54.0) Updates `com.google.errorprone:error_prone_annotations` from 2.47.0 to 2.48.0 - [Release notes](https://github.com/google/error-prone/releases) - [Commits](google/error-prone@v2.47.0...v2.48.0) Updates `io.spiffe:java-spiffe-core` from 0.8.15 to 0.8.16 - [Release notes](https://github.com/spiffe/java-spiffe/releases) - [Changelog](https://github.com/spiffe/java-spiffe/blob/main/CHANGELOG.md) - [Commits](spiffe/java-spiffe@v0.8.15...v0.8.16) Updates `io.spiffe:grpc-netty-linux` from 0.8.15 to 0.8.16 - [Release notes](https://github.com/spiffe/java-spiffe/releases) - [Changelog](https://github.com/spiffe/java-spiffe/blob/main/CHANGELOG.md) - [Commits](spiffe/java-spiffe@v0.8.15...v0.8.16) --- updated-dependencies: - dependency-name: org.assertj:assertj-vavr dependency-version: 0.5.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-minor-patch - dependency-name: org.mockito:mockito-core dependency-version: 5.22.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-minor-patch - dependency-name: org.yaml:snakeyaml dependency-version: '2.6' dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-minor-patch - dependency-name: io.vavr:vavr dependency-version: 1.0.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-minor-patch - dependency-name: org.checkerframework:checker-qual dependency-version: 3.54.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-minor-patch - dependency-name: com.google.errorprone:error_prone_annotations dependency-version: 2.48.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: production-minor-patch - dependency-name: io.spiffe:java-spiffe-core dependency-version: 0.8.16 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-minor-patch - dependency-name: io.spiffe:grpc-netty-linux dependency-version: 0.8.16 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: production-minor-patch ... Signed-off-by: dependabot[bot] <support@github.com>
bot-sdk-js
approved these changes
Mar 3, 2026
auto-merge was automatically disabled
March 3, 2026 10:24
Pull Request is not mergeable
Contributor
Author
|
Looks like these dependencies are updatable in another way, so this is no longer needed. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the production-minor-patch group with 8 updates:
0.4.30.5.05.21.05.22.02.52.61.0.01.0.13.53.13.54.02.47.02.48.00.8.150.8.160.8.150.8.16Updates
org.assertj:assertj-vavrfrom 0.4.3 to 0.5.0Release notes
Sourced from org.assertj:assertj-vavr's releases.
Commits
c5470bf[maven-release-plugin] prepare release v0.5.006cec56fix the release job (#257)9590ce7pin remaining GitHub Actions workflows (#256)bfe9e91configure release job (#255)60f8e08fix assertions returning inaccessible types (#254)02c21feupgrade assertj-parent to 3.27.7 (#252)36d1e00rework README.MD (#253)b73e8d1Bump the github-actions group with 2 updates (#250)0651106Bump the github-actions group with 2 updates (#246)5ff1309Update CODEOWNERS to include new owner (#249)Updates
org.mockito:mockito-corefrom 5.21.0 to 5.22.0Release notes
Sourced from org.mockito:mockito-core's releases.
Commits
25f1395Add core API to enable Kotlin singleton mocking (#3762)ef9ee55Avoids mocking private static methods, as well as package-private static meth...d16fcfcBump graalvm/setup-graalvm from 1.4.4 to 1.4.5 (#3780)27eb8a3ClarifyRETURNS_MOCKSbehavior with sealed abstract enums (Java 15+) (#3773)9e5d449Add tests for Sets utility class (#3771)8d9a62fBump actions/upload-artifact from 5 to 6 (#3774)Updates
org.yaml:snakeyamlfrom 2.5 to 2.6Commits
cc19a61[maven-release-plugin] prepare for next development iterationbc4a8f4Minor fixes in Javadocf18203aAdd a test for Y79Y-003ad1fcebLess output in tests1db66b7Add (failing) build with JDK 2588ebaa8build: fix JKD 25 tests compilation6af8790Update Javadoca006b7aUpdate Javadocc143db2Update changesd78d11fUpdate changesUpdates
io.vavr:vavrfrom 1.0.0 to 1.0.1Release notes
Sourced from io.vavr:vavr's releases.
Commits
ee2a57b[maven-release-plugin] prepare release v1.0.1 [ci skip]9f4e95eupdate project version to 1.0.1-SNAPSHOT08e55f4Added the serialization proxy pattern to HashMap (#3242)Updates
org.checkerframework:checker-qualfrom 3.53.1 to 3.54.0Release notes
Sourced from org.checkerframework:checker-qual's releases.
Changelog
Sourced from org.checkerframework:checker-qual's changelog.
Commits
a6eff70new release 3.54.0fd34700Prep for release.edb6e7aPrint error key in brackets (#7525)a79b1deShow details of the error message in test failures (#7513)a5ecc22Clone the JDK using the same fork and branch as CF (#7491)2770c52Update cimg/base Docker tag to v2026.03bba6bc9Update plugin com-gradleup-shadow to v9.3.23a6d4d4Update error-prone monorepo to v2.48.070aa5f3Update plugin net-ltgt-errorprone to v5.1.00dbd3e7Prepare for javac AST changesUpdates
com.google.errorprone:error_prone_annotationsfrom 2.47.0 to 2.48.0Release notes
Sourced from com.google.errorprone:error_prone_annotations's releases.
Commits
7cec0a0Release Error Prone 2.48.001c603aExtend MissingTestCall to check for member references.3d817b0HandlevarinUnnecessaryBoxedVariablead26f3eAddConcurrentHashMap.keys()andConcurrentHashMap.elements()to `JdkObso...7926dbcFix MustBeClosedChecker crash on flexible constructors.d08f003Check for jakarta annotations in DI checks171448cAdd android internal GuardedBy to ACCEPTED_GUARDED_BY_ANNOTATIONS5cb6075Remove theMissingTestCall:MatchGraphVerifyflag.ab81681Improve crash messages for fixes that don't applyfe9bb21Add a test to confirm that TimeUnitMismatch catches `seconds * 1000 + nanos /...Updates
io.spiffe:java-spiffe-corefrom 0.8.15 to 0.8.16Release notes
Sourced from io.spiffe:java-spiffe-core's releases.
Changelog
Sourced from io.spiffe:java-spiffe-core's changelog.
Commits
393a892chore(release): prepare release 0.8.16 (#407)be7416echore(deps): bump com.nimbusds:nimbus-jose-jwt from 10.7 to 10.8 (#409)4bd0149chore(ci): bump java-spiffe-helper ci charts versions (#408)753812achore(ci): simplify dependabot config and group coupled gradle deps (#403)c616b61Bump gradle-wrapper from 9.3.0 to 9.3.1 (#401)f8e1695Bump grpcVersion from 1.78.0 to 1.79.0 (#402)157d491Bump gradle-wrapper from 9.2.1 to 9.3.0 (#400)4d1cee3fix(core): harden parsing and cache edge cases (#399)8bf98fbfix(x509source): ensure atomic snapshot of SVID and bundles (#397)f9969c1fix(spiffeid): require spiffe:// prefix when parsing IDs (#398)Updates
io.spiffe:grpc-netty-linuxfrom 0.8.15 to 0.8.16Release notes
Sourced from io.spiffe:grpc-netty-linux's releases.
Changelog
Sourced from io.spiffe:grpc-netty-linux's changelog.
Commits
393a892chore(release): prepare release 0.8.16 (#407)be7416echore(deps): bump com.nimbusds:nimbus-jose-jwt from 10.7 to 10.8 (#409)4bd0149chore(ci): bump java-spiffe-helper ci charts versions (#408)753812achore(ci): simplify dependabot config and group coupled gradle deps (#403)c616b61Bump gradle-wrapper from 9.3.0 to 9.3.1 (#401)f8e1695Bump grpcVersion from 1.78.0 to 1.79.0 (#402)157d491Bump gradle-wrapper from 9.2.1 to 9.3.0 (#400)4d1cee3fix(core): harden parsing and cache edge cases (#399)8bf98fbfix(x509source): ensure atomic snapshot of SVID and bundles (#397)f9969c1fix(spiffeid): require spiffe:// prefix when parsing IDs (#398)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions