Skip to content

build(deps): Bump the dev-dependencies group with 5 updates - #169

Merged
github-actions[bot] merged 1 commit into
mainfrom
dependabot/gradle/dev-dependencies-f018328c36
Sep 23, 2026
Merged

github-actions[bot] merged 1 commit into
mainfrom
dependabot/gradle/dev-dependencies-f018328c36

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 23, 2026

Copy link
Copy Markdown
Contributor

Bumps the dev-dependencies group with 5 updates:

Package From To
com.nimbusds:nimbus-jose-jwt 10.9.1 10.10
org.flywaydb:flyway-core 13.6.0 13.7.0
org.flywaydb:flyway-database-postgresql 13.6.0 13.7.0
software.amazon.awssdk:dynamodb 2.54.17 2.55.1
software.amazon.awssdk:dynamodb-enhanced 2.54.17 2.55.1

Updates com.nimbusds:nimbus-jose-jwt from 10.9.1 to 10.10

Changelog

Sourced from com.nimbusds:nimbus-jose-jwt's changelog.

10.9.1 (2026-05-31) * Fixes health status reporting when RefreshAheadCachingJWKSetSource, JWKSetSourceWithHealthStatusReporting and OutageTolerantJWKSetSource are used together. A failed refresh-ahead background update could previously cause JWKSetSourceWithHealthStatusReporting to mark the JWK set source as UNHEALTHY, even though OutageTolerantJWKSetSource was still within its configured outage tolerance window and regular JWT validation could continue using the cached JWK set. Refresh-ahead failures that are covered by outage tolerance no longer cause the health status to become unhealthy before the outage tolerance period has been exceeded (iss #619).

10.10 (2026-09-17) * Adds JWEObject.MAX_DECOMPRESSED_PLAIN_TEXT_LENGTH for the default maximum allowed length of decompressed plain text, in bytes. Used to establish an active (dynamic) safety limit against zip-bomb attacks. Set to 1 mio bytes (iss #611). * Adds MaxDecompressedPlainTextLength implementing JWEDecrypterOption, to enable applications to override the default JWEObject.MAX_DECOMPRESSED_PLAIN_TEXT_LENGTH (iss #611). * Adds explicit non-null checks to DeflateUtils (iss #611). * Fixes potential native memory resource leak in DeflateUtils when Deflater or Inflater instances were not guaranteed to call .end() if stream closing or processing threw an exception (iss #611). * Optimizes DeflateUtils resource management and memory allocation by guaranteeing native stream cleanup, validating inputs, and pre-allocating decompression buffers (iss #611). * Updates to com.google.code.gson:gson:2.14.0 * Updates to com.google.crypto.tink:tink:1.23.0 * Updates to BouncyCastle 1.86

11.0 (2026-09-xx) * Compile source and target bumped from Java 7 to Java 8. * Optimises JWS input composition for unencoded payloads (RFC 7797) to conserve memory and CPU cycles. Introduces a helper JWSInput interface with a ByteArrayJWSInput and ComposedJWSInput implementations for the JWS input composition when the payloaded is encoded and when not (iss #613). * Adds JWTClaimsSet.getInstantClaims, getExpirationInstant, getNotBeforeInstant and getIssueInstant methods. Adds JWTClaimsSet.Builder.expirationInstant, notBeforeInstant and issueInstant methods. * Adds JSONObjectUtils.getEpochSecondAsInstant static method. * Overrides equals and hashCode in Payload. * Fixes health status reporting when RefreshAheadCachingJWKSetSource, JWKSetSourceWithHealthStatusReporting and OutageTolerantJWKSetSource are used together. A failed refresh-ahead background update could previously cause JWKSetSourceWithHealthStatusReporting to mark the JWK set source as UNHEALTHY, even though OutageTolerantJWKSetSource was still within its configured outage tolerance window and regular JWT validation could continue using the cached JWK set. Refresh-ahead failures that are

... (truncated)

Commits
  • e055b3b [maven-release-plugin] prepare for next development iteration
  • c06d769 Adds JWEObject.MAX_DECOMPRESSED_PLAIN_TEXT_LENGTH - 10.x WIP (iss #611)
  • a427513 Adds explicit non-null checks to DeflateUtils (iss #611)
  • 3302e15 Fixes potential native memory resource leak in DeflateUtils when Deflater or ...
  • d004e79 Optimizes DeflateUtils resource management and memory allocation by guarantee...
  • 98ed6ba Adjusts JWEObject.MAX_DECOMPRESSED_PLAIN_TEXT_LENGTH to 1 mio bytes (iss #611)
  • 0350144 Adds MaxDecompressedPlainTextLength implementing JWEDecrypterOption (iss #611)
  • 218575f Wires MaxDecompressedPlainTextLength (iss #611)
  • 3fcb8f5 Adds MaxDecompressedPlainTextLength tests for each JWEDecrypter (iss #611)
  • 14ae7ac Adds CHANGELOG.txt entries (iss #611)
  • Additional commits viewable in compare view

Updates org.flywaydb:flyway-core from 13.6.0 to 13.7.0

Updates org.flywaydb:flyway-database-postgresql from 13.6.0 to 13.7.0

Updates org.flywaydb:flyway-database-postgresql from 13.6.0 to 13.7.0

Updates software.amazon.awssdk:dynamodb from 2.54.17 to 2.55.1

Updates software.amazon.awssdk:dynamodb-enhanced from 2.54.17 to 2.55.1

Updates software.amazon.awssdk:dynamodb-enhanced from 2.54.17 to 2.55.1

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the dev-dependencies group with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [com.nimbusds:nimbus-jose-jwt](https://bitbucket.org/connect2id/nimbus-jose-jwt) | `10.9.1` | `10.10` |
| org.flywaydb:flyway-core | `13.6.0` | `13.7.0` |
| org.flywaydb:flyway-database-postgresql | `13.6.0` | `13.7.0` |
| software.amazon.awssdk:dynamodb | `2.54.17` | `2.55.1` |
| software.amazon.awssdk:dynamodb-enhanced | `2.54.17` | `2.55.1` |


Updates `com.nimbusds:nimbus-jose-jwt` from 10.9.1 to 10.10
- [Changelog](https://bitbucket.org/connect2id/nimbus-jose-jwt/src/master/CHANGELOG.txt)
- [Commits](https://bitbucket.org/connect2id/nimbus-jose-jwt/branches/compare/10.10..10.9.1)

Updates `org.flywaydb:flyway-core` from 13.6.0 to 13.7.0

Updates `org.flywaydb:flyway-database-postgresql` from 13.6.0 to 13.7.0

Updates `org.flywaydb:flyway-database-postgresql` from 13.6.0 to 13.7.0

Updates `software.amazon.awssdk:dynamodb` from 2.54.17 to 2.55.1

Updates `software.amazon.awssdk:dynamodb-enhanced` from 2.54.17 to 2.55.1

Updates `software.amazon.awssdk:dynamodb-enhanced` from 2.54.17 to 2.55.1

---
updated-dependencies:
- dependency-name: com.nimbusds:nimbus-jose-jwt
  dependency-version: '10.10'
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: org.flywaydb:flyway-core
  dependency-version: 13.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: org.flywaydb:flyway-database-postgresql
  dependency-version: 13.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: org.flywaydb:flyway-database-postgresql
  dependency-version: 13.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: software.amazon.awssdk:dynamodb
  dependency-version: 2.55.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: software.amazon.awssdk:dynamodb-enhanced
  dependency-version: 2.55.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
- dependency-name: software.amazon.awssdk:dynamodb-enhanced
  dependency-version: 2.55.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dev-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Sep 23, 2026
@github-actions
github-actions Bot enabled auto-merge (squash) September 23, 2026 04:55
@github-actions
github-actions Bot merged commit 6f5ecb2 into main Sep 23, 2026
7 checks passed
@dependabot
dependabot Bot deleted the dependabot/gradle/dev-dependencies-f018328c36 branch September 23, 2026 04:59
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants