Skip to content

Bump the dependencies group with 5 updates - #339

Merged
rfresh2 merged 1 commit into
1.21.4from
dependabot/gradle/dependencies-9e1e1e70c1
Sep 28, 2026
Merged

rfresh2 merged 1 commit into
1.21.4from
dependabot/gradle/dependencies-9e1e1e70c1

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026

Copy link
Copy Markdown
Contributor

Bumps the dependencies group with 5 updates:

Package From To
org.jline:jline 4.4.5 4.4.6
ch.qos.logback:logback-classic 1.6.3 1.6.4
tools.jackson:jackson-bom 3.2.2 3.2.3
io.freefair.lombok 9.5.0 9.7.0
gradle-wrapper 9.7.1 9.8.0

Updates org.jline:jline from 4.4.5 to 4.4.6

Release notes

Sourced from org.jline:jline's releases.

JLine 4.4.6 is a bugfix release addressing two correctness issues and updating several dependencies.

The main fix resolves a boot layer initialization failure (InvalidModuleDescriptorException) that affected Java 17+ projects with jline-terminal-ffm on the module path: the module-info.class was compiled at Java 22 and placed at the jar root, causing the JVM to reject it. The module is now packaged as a proper Multi-Release JAR, with the module descriptor in META-INF/versions/22/, so Java 17 consumers load the jar without issues while Java 22+ still gets the full JPMS module. The second fix corrects codePointAt/codePointBefore in AttributedString to respect subsequence bounds, preventing surrogates from being combined with characters outside the logical range.

🐛 Bug Fixes

  • fix: make jline-terminal-ffm a Multi-Release JAR to fix Java 17 boot layer failure (#2285) @​gnodet
  • fix: respect attributed sequence bounds when reading code points (#2278) @​jakezwang

📦 Dependency Updates

Full Changelog: jline/jline3@4.4.5...4.4.6

Commits
  • 2ab1d06 fix: make jline-terminal-ffm a Multi-Release JAR to fix Java 17 boot layer fa...
  • c59e109 fix: respect attributed sequence bounds when reading code points
  • 1a5900b chore: bump groovy.version from 5.1.2 to 6.0.0
  • b640a9c chore: bump org.graalvm.buildtools:native-maven-plugin from 1.1.12 to 1.1.14
  • 696fc40 chore: bump org.apache.felix:maven-bundle-plugin from 6.1.2 to 6.2.0
  • 8476e8c chore: add njord auto-publish parameters to release workflow
  • a5cd208 chore: ignore Groovy major version bumps on jline-3.x (#2283)
  • See full diff in compare view

Updates ch.qos.logback:logback-classic from 1.6.3 to 1.6.4

Release notes

Sourced from ch.qos.logback:logback-classic's releases.

Logback 1.6.4

2026-09-24 Release of logback version 1.6.4

• Variable substitution is again applied to the scan attribute of the <configuration> element. The scanning refactoring in version 1.5.27 had dropped substitution, so values such as ${logback.scan.enabled:-true} were no longer resolved. As before version 1.5.27, an unrecognized non-empty value turns scanning on. The same substitution now applies to the scan attribute of <propertiesConfigurator>. This regression was reported in issues/1065 by vaibhavjain2.

• OutputStreamAppender and FileAppender now handle stateful encoders. The Encoder interface has a new default method called isStateful(), which returns false. An encoder that keeps state between calls to encode() can return true. For such encoders, the appender holds its write lock while encoding and while writing, so the output of concurrent appends cannot interleave. Stateless encoders still encode outside the lock, so their performance does not change. Existing encoders need no changes.

• Several race conditions in OutputStreamAppender and FileAppender were fixed. The appender is now marked started and the encoder header is written while the same lock is held, so a concurrent append can no longer write an event before the header. After acquiring the lock, the appender checks again whether it has been stopped, so no event is written after the footer. In prudent mode, FileAppender now encodes and writes each event while holding the lock.

• Fixed a data race on the logger count in LoggerContext. Loggers are created under the lock of their parent logger, so loggers with different parents could be created at the same time and increments of the shared counter could be lost. As a result, LoggerContext.size() could return a value lower than the actual number of loggers. The counter is now an AtomicInteger. This issue was reported in issues/1038 by hcantunc. The fix was contributed in PR #1055 by seonwoo_jung.

• TimeBasedRollingPolicy now supports half-day periods. Date patterns with the AM/PM marker, for example %d{yyyy-MM-dd-a}, used to be detected as daily and rolled over only at midnight. They now roll over at both 00:00 and 12:00. This issue was reported in issues/976 by shakthifuture. The fix was contributed in PR #1051 by seonwoo_jung. See TimeBasedRollingPolicy.

• If org.jline.jansi.AnsiConsole cannot be found on the class path, JansiConsoleAppender now emits warnings that explain how to add org.jline:jansi-core and then writes to the plain console stream. See codes.html#missingJlineJansi.

• The unused ch.qos.logback.classic.util.LogbackMDCAdapterSimple class was removed. LogbackMDCAdapter remains the default MDC adapter.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit 07d291ca0d280bc5da934ec9ff5f1da634fd7937 associated with the tag v_1.6.4. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Full Changelog: qos-ch/logback@v_1.6.3...v_1.6.4

Commits
  • 07d291c preapre release 1.6.4
  • 9627daf revert to Collections.unmodifiableMap instead of
  • aa42fb5 disabled RollingCalendarTest#testVaryingNumberOfHalfDailyPeriods to shave off...
  • ddc7459 Support HALF_DAY periodicity for AM/PM date patterns
  • 42d75d7 disable LoggerContextTest#concurrentGetLoggerKeepsSizeConsistent to shave exe...
  • bffd55e add warnings about missing jline.jansi classes
  • 8de0b9b Fix data race on LoggerContext.size (#1038)
  • 76c73d1 add MinimalUnmodifiableMap and return it in LogbackMDCAdapter#getPropertyMap
  • a2c416a Fix formatting of email instruction in README
  • 2c89727 mailing lists have been deactivated
  • Additional commits viewable in compare view

Updates tools.jackson:jackson-bom from 3.2.2 to 3.2.3

Commits
  • 169de87 [maven-release-plugin] prepare release jackson-bom-3.2.3
  • c64410b Prep for 3.2.3 release
  • 1f23ca6 Merge branch '3.1' into 3.2
  • 432ca52 Post-release dep version bump
  • e0d3ccf [maven-release-plugin] prepare for next development iteration
  • 8abdaa6 [maven-release-plugin] prepare release jackson-bom-3.1.7
  • 2abd85b Prep for 3.1.7 release
  • c63b07a Post-release dep version bump
  • b0a5033 [maven-release-plugin] prepare for next development iteration
  • See full diff in compare view

Updates io.freefair.lombok from 9.5.0 to 9.7.0

Release notes

Sourced from io.freefair.lombok's releases.

9.7.0

What's Changed

... (truncated)

Commits
  • c216850 chore(deps): bump com.github.spotbugs from 6.5.10 to 6.5.11 in /examples (#1856)
  • 1966ff2 chore(deps): bump github/codeql-action from 4.37.9 to 4.38.0 (#1878)
  • 978f1af chore(deps): bump org.graalvm.buildtools.native in /examples (#1883)
  • d1b9240 chore(deps): bump actions/setup-java from 6.0.0 to 6.0.1 (#1877)
  • ce71cb8 chore(deps): bump com.gradle.develocity from 4.5.0 to 4.5.1 in /examples (#1881)
  • 185e4b2 chore(deps): bump com.gradle.develocity from 4.5.0 to 4.5.1 (#1882)
  • 6c48b72 chore(deps): bump com.gradle.plugin-publish in /examples (#1879)
  • 9298910 delombok: preserve all input dirs (#1858)
  • c2daf9c Merge branch 'main' of github.com:freefair/gradle-plugins
  • 69c7d6f Update to PlantUML 1.2026.8
  • Additional commits viewable in compare view

Updates gradle-wrapper from 9.7.1 to 9.8.0

Release notes

Sourced from gradle-wrapper's releases.

9.8.0

The Gradle team is excited to announce Gradle 9.8.0.

Here are the highlights of this release:

  • Java 27 support
  • Maven mirror settings reuse
  • Linked problem locations in build output

Read the Release Notes

We would like to thank the following community members for their contributions to this release of Gradle: Aman Gautam, Björn Kautler, Eng Zer Jun, Hashim Khan, Julian Krannich, KBS, Labh R Jethe, Mark Dodgson, Maxim, monkey, nataphon-ktsystems, Paul King, Qiu Tian, rg_sandesh, Roberto Perez Alcolea, Sean, Zongle Wang.

Upgrade instructions

Switch your build to use Gradle 9.8.0 by updating your wrapper:

./gradlew :wrapper --gradle-version=9.8.0 && ./gradlew :wrapper

See the Gradle 9.x upgrade guide to learn about deprecations, breaking changes and other considerations when upgrading.

For Java, Groovy, Kotlin and Android compatibility, see the full compatibility notes.

Reporting problems

If you find a problem with this release, please file a bug on GitHub Issues adhering to our issue guidelines. If you're not sure you're encountering a bug, please use the forum.

We hope you will build happiness with Gradle, and we look forward to your feedback via Twitter or on GitHub.

9.8.0 RC3

The Gradle team is excited to announce Gradle 9.8.0 RC3.

Here are the highlights of this release:

... (truncated)

Commits
  • a927be5 Add the Develocity plugin back to the Android smoke tests (#39273)
  • eaee500 Add the Develocity plugin back to the Android smoke tests
  • 189b672 Route everything still hitting Maven Central through the mirror (#39257)
  • 36b1814 Add back mavenCentral to doc snippets
  • 2740c2d Update Gradle wrapper to version 9.8.0-rc-3 (#39264)
  • 2099383 Update Gradle wrapper to version 9.8.0-rc-3
  • c80202f Route everything still hitting Maven Central through the mirror
  • 3f6a534 Fix when a best practice was introduced (#39253)
  • 9efc9ed Fix when a best practice was introduced
  • 459e143 Route integration test dependencies through the repository mirror (#39239)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the dependencies group with 5 updates:

| Package | From | To |
| --- | --- | --- |
| [org.jline:jline](https://github.com/jline/jline3) | `4.4.5` | `4.4.6` |
| [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) | `1.6.3` | `1.6.4` |
| [tools.jackson:jackson-bom](https://github.com/FasterXML/jackson-bom) | `3.2.2` | `3.2.3` |
| [io.freefair.lombok](https://github.com/freefair/gradle-plugins) | `9.5.0` | `9.7.0` |
| [gradle-wrapper](https://github.com/gradle/gradle) | `9.7.1` | `9.8.0` |


Updates `org.jline:jline` from 4.4.5 to 4.4.6
- [Release notes](https://github.com/jline/jline3/releases)
- [Commits](jline/jline3@4.4.5...4.4.6)

Updates `ch.qos.logback:logback-classic` from 1.6.3 to 1.6.4
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.6.3...v_1.6.4)

Updates `tools.jackson:jackson-bom` from 3.2.2 to 3.2.3
- [Commits](FasterXML/jackson-bom@jackson-bom-3.2.2...jackson-bom-3.2.3)

Updates `io.freefair.lombok` from 9.5.0 to 9.7.0
- [Release notes](https://github.com/freefair/gradle-plugins/releases)
- [Commits](freefair/gradle-plugins@9.5.0...9.7.0)

Updates `gradle-wrapper` from 9.7.1 to 9.8.0
- [Release notes](https://github.com/gradle/gradle/releases)
- [Commits](gradle/gradle@v9.7.1...v9.8.0)

---
updated-dependencies:
- dependency-name: org.jline:jline
  dependency-version: 4.4.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: ch.qos.logback:logback-classic
  dependency-version: 1.6.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: tools.jackson:jackson-bom
  dependency-version: 3.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: dependencies
- dependency-name: io.freefair.lombok
  dependency-version: 9.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
- dependency-name: gradle-wrapper
  dependency-version: 9.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Sep 28, 2026
@rfresh2
rfresh2 merged commit 9d24f33 into 1.21.4 Sep 28, 2026
2 checks passed
@rfresh2
rfresh2 deleted the dependabot/gradle/dependencies-9e1e1e70c1 branch September 28, 2026 23:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant