Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 27, 2025

Bumps version.io.quarkus from 3.17.7 to 3.18.0.
Updates io.quarkus:quarkus-bom from 3.17.7 to 3.18.0

Release notes

Sourced from io.quarkus:quarkus-bom's releases.

3.18.0.CR1

Major changes

  • #32447 - Introduce Report an Issue menu in DevUI
  • #35324 - OIDC dev services and ui changes
  • #43618 - Add a Dev UI Screen for Agroal (DB)
  • #43885 - Exclude uri from otel tracing
  • #44105 - Reimplement security-webauthn on top of webauthn4j
  • #44305 - Ability to configure extension Dev mode JVM options
  • #44379 - Integrate Micrometer with WebSockets Next
  • #44424 - Support for dev-mode-only conditional dependencies
  • #44546 - Add OIDC Redis Token State Manager extension
  • #44549 - Add support for encrypted PKCS#8
  • #44993 - Support OidcProviderClient injection and token revocation
  • #45117 - TLS - Enable Policy Configuration for Expired or Not Yet Valid Certificates
  • #45121 - Support for OIDC MTLS binding
  • #45131 - OIDC and OIDC Client: Support JWT bearer client authentication using client assertion loaded from filesystem
  • #45259 - Bump kubernetes-client-bom from 6.13.4 to 7.0.1
  • #45294 - Allow to create static OIDC tenants programmatically

Complete changelog

  • #4482 - Support the access token binding to the client MTLS authentication
  • #5702 - Reexamine how we manage config in tests
  • #8300 - Warn or refuse configuration files with duplicate keys
  • #24533 - Fault Tolerance in config file could use dash seperated names
  • #28474 - Can't load static resource created by extension
  • #31340 - Provide OIDC Mock DevService
  • #32109 - Retain OIDC access token expiry time in the cookie
  • #32431 - Report bugs from the DevUI
  • #32447 - Introduce Report an Issue menu in DevUI
  • #34577 - Dev UI: security / JWT / OIDC
  • #35064 - OIDC Dev UI should support web-app application by recognizing q_session cookie
  • #35215 - Native build failed after 3.x.x upgrade, using panache mongodb (maybe releated to ManagedExecuter and narayana)
  • #35324 - OIDC dev services and ui changes
  • #35693 - Confusing documentation or behaviour for quarkus.test.profile.tags
  • #35751 - Reconsider the precedence of Forwarded vs X-Forwarded-For
  • #35824 - Add capability to add topic configuration during topic creation
  • #35953 - quarkus cli should give hint that you can run with -e to get error info
  • #36006 - Dev mode hangs when graceful shutdown active
  • #36265 - Unexpected commit of transaction using Oracle
  • #36934 - PostgreSQL DevService does not enable max_prepared_transactions for XA operations
  • #37626 - Netty's PlatformDependent and PlatformDependent0 class initializers require reflective access to some classes ?
  • #38486 - Jandex warning when using @RegisterForReflection(registerFullHierarchy = true)
  • #39143 - WebSockets Next: OTel integration
  • #39155 - Custom Exception in SecurityIdentityAugmentor
  • #39185 - Migrate OIDC-based extensions from config classes to @ConfigMapping
  • #39230 - Options with quarkus.openshift.init-containers prefix are ignored
  • #39416 - Shared extension for the Hibernate Search Elasticsearch backend
  • #39561 - Quarkus management interface and Swagger UI executing APIs at wrong path

... (truncated)

Commits
  • 28ead05 [RELEASE] - Bump version to 3.18.0
  • 3a27b80 Merge pull request #45759 from gsmet/3.18.0-backports-1
  • 3a4cf41 Remove quarkus-extension-processor from cache-runtime-spi
  • b6bd029 Upgrade to ByteBuddy 1.15.11
  • d8f56cb Bump hibernate-orm.version from 6.6.4.Final to 6.6.5.Final
  • 63463cb Bump hibernate-reactive.version from 2.4.3.Final to 2.4.4.Final
  • e0360ad Add HTTP response to HttpClientMetricsTagsContributor.Context
  • d382c35 Add HTTP response to HttpServerMetricsTagsContributor.Context
  • cf9a219 Enable new scripts config in Swagger UI
  • 3fcba30 Bump grpc.version from 1.69.0 to 1.69.1
  • Additional commits viewable in compare view

Updates io.quarkus:quarkus-maven-plugin from 3.17.7 to 3.18.0

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps `version.io.quarkus` from 3.17.7 to 3.18.0.

Updates `io.quarkus:quarkus-bom` from 3.17.7 to 3.18.0
- [Release notes](https://github.com/quarkusio/quarkus/releases)
- [Commits](quarkusio/quarkus@3.17.7...3.18.0)

Updates `io.quarkus:quarkus-maven-plugin` from 3.17.7 to 3.18.0

---
updated-dependencies:
- dependency-name: io.quarkus:quarkus-bom
  dependency-type: direct:production
  update-type: version-update:semver-minor
- dependency-name: io.quarkus:quarkus-maven-plugin
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Jan 27, 2025
@triceo
Copy link
Collaborator

triceo commented Jan 27, 2025

We don't upgrade to .0 releases of Quarkus.

@triceo triceo closed this Jan 27, 2025
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Jan 27, 2025

OK, I won't notify you again about this release, but will get in touch when a new version is available. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot bot deleted the dependabot/maven/development/version.io.quarkus-3.18.0 branch January 27, 2025 06:06
triceo added a commit that referenced this pull request Dec 8, 2025
…#959)

Bumps the base group with 1 update:
[graalvm/setup-graalvm](https://github.com/graalvm/setup-graalvm).

Updates `graalvm/setup-graalvm` from 1.4.3 to 1.4.4
<details>
<summary>Release notes</summary>
<p><em>Sourced from <a
href="https://github.com/graalvm/setup-graalvm/releases">graalvm/setup-graalvm's
releases</a>.</em></p>
<blockquote>
<h2>v1.4.4</h2>
<h2>What's Changed</h2>
<ul>
<li>Bump actions/checkout from 5.0.0 to 6.0.0 in the
github-actions-updates group by <a
href="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/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/graalvm/setup-graalvm/pull/198">graalvm/setup-graalvm#198</a></li>
<li>Bump the npm-updates group with 10 updates by <a
href="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/dependabot"><code>@​dependabot</code></a>[bot]
in <a
href="https://redirect.github.com/graalvm/setup-graalvm/pull/197">graalvm/setup-graalvm#197</a></li>
</ul>
<p><strong>Full Changelog</strong>: <a
href="https://github.com/graalvm/setup-graalvm/compare/v1.4.3...v1.4.4">https://github.com/graalvm/setup-graalvm/compare/v1.4.3...v1.4.4</a></p>
</blockquote>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/graalvm/setup-graalvm/commit/790e28947b79a9c09c3391c0f18bf8d0f102ed69"><code>790e289</code></a>
Bump version to <code>1.4.4</code>.</li>
<li><a
href="https://github.com/graalvm/setup-graalvm/commit/434a92bc4faf302845542ab080ba51cea01d392d"><code>434a92b</code></a>
Update dist files.</li>
<li><a
href="https://github.com/graalvm/setup-graalvm/commit/fe4a6b3a89d8ba8639f157689d83cbe564402ce5"><code>fe4a6b3</code></a>
Update dependencies</li>
<li><a
href="https://github.com/graalvm/setup-graalvm/commit/d8578a7f98f24a05ed4eddd4f76472b40cae484e"><code>d8578a7</code></a>
Bump the npm-updates group with 10 updates</li>
<li><a
href="https://github.com/graalvm/setup-graalvm/commit/98e485c1fbbf7e7a85fd316979ff3424e8814f2f"><code>98e485c</code></a>
Bump actions/checkout in the github-actions-updates group</li>
<li>See full diff in <a
href="https://github.com/graalvm/setup-graalvm/compare/dec5790292b7b36d7ad368abe856887749c6c520...790e28947b79a9c09c3391c0f18bf8d0f102ed69">compare
view</a></li>
</ul>
</details>
<br />

Bumps the base group with 1 update:
[org.apache.commons:commons-text](https://github.com/apache/commons-text).

Updates `org.apache.commons:commons-text` from 1.14.0 to 1.15.0
<details>
<summary>Changelog</summary>
<p><em>Sourced from <a
href="https://github.com/apache/commons-text/blob/master/RELEASE-NOTES.txt">org.apache.commons:commons-text's
changelog</a>.</em></p>
<blockquote>
<h2>Apache Commons Text 1.15.0 Release Notes</h2>
<p>The Apache Commons Text team is pleased to announce the release of
Apache Commons Text 1.15.0.</p>
<p>Apache Commons Text is a set of utility functions and reusable
components for processing
and manipulating text in a Java environment.</p>
<p>Release 1.15.0. This is a feature and maintenance release. Java 8 or
later is required.</p>
<h2>New features</h2>
<ul>
<li>
<pre><code> Add experimental CycloneDX VEX file
[#683](apache/commons-text#683). Thanks to
Piotr P. Karwasz, Gary Gregory.
</code></pre>
</li>
<li>TEXT-235: Add Damerau-Levenshtein distance <a
href="https://redirect.github.com/apache/commons-text/issues/687">#687</a>.
Thanks to LorgeN, Gary Gregory.</li>
<li>
<pre><code> Add unit tests to increase coverage
[#719](apache/commons-text#719). Thanks to
Michael Hausegger, Gary Gregory.
</code></pre>
</li>
<li>
<pre><code> Add new test for CharSequenceTranslator#with()
[#725](apache/commons-text#725). Thanks to
Michael Hausegger, Gary Gregory.
</code></pre>
</li>
<li>
<pre><code> Add tests and assertions to
org.apache.commons.text.similarity to get to 100% code coverage
[#727](apache/commons-text#727),
[#728](apache/commons-text#728). Thanks to
Michael Hausegger.
</code></pre>
</li>
</ul>
<h2>Fixed Bugs</h2>
<ul>
<li>
<pre><code> Fix exception message typo in
XmlStringLookup.XmlStringLookup(Map, Path...). Thanks to Gary Gregory.
</code></pre>
</li>
<li>TEXT-236: Inserting at the end of a TextStringBuilder throws a
StringIndexOutOfBoundsException. Thanks to Pierre Post, Sumit Bera, Alex
Herbert, Gary Gregory.</li>
<li>
<pre><code> Fix TextStringBuilderTest.testAppendToCharBuffer() to use
proper argument type
[#724](apache/commons-text#724). Thanks to
Michael Hausegger.
</code></pre>
</li>
<li>
<pre><code> Fix Apache RAT plugin console warnings. Thanks to Gary
Gregory.
</code></pre>
</li>
<li>
<pre><code> Fix site XML to use version 2.0.0 XML schema. Thanks to Gary
Gregory.
</code></pre>
</li>
<li>
<pre><code> Removed unreachable threshold verification code in
src/main/java/org/apache/commons/text/similarity
[#730](apache/commons-text#730). Thanks to
Michael Hausegger.
</code></pre>
</li>
<li>
<pre><code> Enable secure processing for the XML parser in
XmlStringLookup in case the underlying JAXP implementation doesn't
[#729](apache/commons-text#729). Thanks to 김민재
(minjas0507), Gary Gregory, Piotr Karwasz.
</code></pre>
</li>
</ul>
<h2>Changes</h2>
<ul>
<li>
<pre><code> Bump org.apache.commons:commons-parent from 85 to 93
[#704](apache/commons-text#704),
[#723](apache/commons-text#723),
[#726](apache/commons-text#726). Thanks to
Gary Gregory.
</code></pre>
</li>
<li>
<pre><code> Bump commons.bytebuddy.version from 1.17.6 to 1.18.2
[#696](apache/commons-text#696),
[#722](apache/commons-text#722). Thanks to
Gary Gregory.
</code></pre>
</li>
<li>
<pre><code> Bump graalvm.version from 24.2.2 to 25.0.1
[#703](apache/commons-text#703),
[#716](apache/commons-text#716). Thanks to
Gary Gregory, Dependabot.
</code></pre>
</li>
<li>
<pre><code> Bump org.apache.commons:commons-lang3 from 3.18.0 to 3.20.0.
Thanks to Gary Gregory.
</code></pre>
</li>
<li>
<pre><code> Bump commons-io:commons-io from 2.20.0 to 2.21.0. Thanks to
Gary Gregory.
</code></pre>
</li>
</ul>
<p>Historical list of changes: <a
href="https://commons.apache.org/proper/commons-text/changes.html">https://commons.apache.org/proper/commons-text/changes.html</a></p>
<p>For complete information on Apache Commons Text, including
instructions on how to submit bug reports,
patches, or suggestions for improvement, see the Apache Commons Text
website:</p>
<p><a
href="https://commons.apache.org/proper/commons-text">https://commons.apache.org/proper/commons-text</a></p>
<p>Download page: <a
href="https://commons.apache.org/proper/commons-text/download_text.cgi">https://commons.apache.org/proper/commons-text/download_text.cgi</a></p>
<!-- raw HTML omitted -->
</blockquote>
<p>... (truncated)</p>
</details>
<details>
<summary>Commits</summary>
<ul>
<li><a
href="https://github.com/apache/commons-text/commit/04e937470d3679cc163df85d82d5b6d2e3e71128"><code>04e9374</code></a>
Prepare for the release candidate 1.15.0 RC1</li>
<li><a
href="https://github.com/apache/commons-text/commit/502c4c41be5671681b58a9b50297f99737e8ea93"><code>502c4c4</code></a>
Prepare for the next release candidate</li>
<li><a
href="https://github.com/apache/commons-text/commit/c6e17ec24cc8374eb12676b717bf797f41b6e539"><code>c6e17ec</code></a>
Use direct access</li>
<li><a
href="https://github.com/apache/commons-text/commit/58e1e125daaa0aebf8c5ffaa82af48821a1ccf2d"><code>58e1e12</code></a>
Simplify XML FSP (<a
href="https://redirect.github.com/apache/commons-text/issues/731">#731</a>)</li>
<li><a
href="https://github.com/apache/commons-text/commit/b5052c97e84e1c174ec8bfbbb749e33f22917a07"><code>b5052c9</code></a>
Bump actions/setup-java from 5.0.0 to 5.1.0</li>
<li><a
href="https://github.com/apache/commons-text/commit/2e2d4bc90f1b3274e7943ac27d037d47c0cc098d"><code>2e2d4bc</code></a>
Revert &quot;Bump actions/setup-java from 5.0.0 to 5.1.0&quot;</li>
<li><a
href="https://github.com/apache/commons-text/commit/b0ddbd17bbeee12ad33b8a61c60b4edbe6c85838"><code>b0ddbd1</code></a>
Bump actions/setup-java from 5.0.0 to 5.1.0</li>
<li><a
href="https://github.com/apache/commons-text/commit/1c2d3821e67e08342b8cef4d4445c30b4a22daca"><code>1c2d382</code></a>
Add tests with external DTD</li>
<li><a
href="https://github.com/apache/commons-text/commit/ed3df4b25cd5301921a6523ae7db2411f4a84d98"><code>ed3df4b</code></a>
Internal clean up</li>
<li><a
href="https://github.com/apache/commons-text/commit/bb508f304a8835ac2319af1d872b2f1a9ff6f81d"><code>bb508f3</code></a>
Bump actions/checkout from 6.0.0 to 6.0.1</li>
<li>Additional commits viewable in <a
href="https://github.com/apache/commons-text/compare/rel/commons-text-1.14.0...rel/commons-text-1.15.0">compare
view</a></li>
</ul>
</details>
<br />

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)

---

<details>
<summary>Dependabot commands and options</summary>
<br />

You can trigger Dependabot actions by commenting on this PR:
- `@dependabot rebase` will rebase this PR
- `@dependabot recreate` will recreate this PR, overwriting any edits
that have been made to it
- `@dependabot merge` will merge this PR after your CI passes on it
- `@dependabot squash and merge` will squash and merge this PR after
your CI passes on it
- `@dependabot cancel merge` will cancel a previously requested merge
and block automerging
- `@dependabot reopen` will reopen this PR if it is closed
- `@dependabot close` will close this PR and stop Dependabot recreating
it. You can achieve the same result by closing it manually
- `@dependabot show <dependency name> ignore conditions` will show all
of the ignore conditions of the specified dependency
- `@dependabot ignore <dependency name> major version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's major version (unless you unignore this specific
dependency's major version or upgrade to it yourself)
- `@dependabot ignore <dependency name> minor version` will close this
group update PR and stop Dependabot creating any more for the specific
dependency's minor version (unless you unignore this specific
dependency's minor version or upgrade to it yourself)
- `@dependabot ignore <dependency name>` will close this group update PR
and stop Dependabot creating any more for the specific dependency
(unless you unignore this specific dependency or upgrade to it yourself)
- `@dependabot unignore <dependency name>` will remove all of the ignore
conditions of the specified dependency
- `@dependabot unignore <dependency name> <ignore condition>` will
remove the ignore condition of the specified dependency and ignore
conditions


</details>

---------

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Lukáš Petrovický <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant