Skip to content

Bump the minor-and-patch group with 9 updates - #57

Merged
jochen-testingbot merged 1 commit into
mainfrom
dependabot/maven/minor-and-patch-34e57931b6
Oct 2, 2026
Merged

jochen-testingbot merged 1 commit into
mainfrom
dependabot/maven/minor-and-patch-34e57931b6

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 9 updates:

Package From To
com.fasterxml.jackson:jackson-bom 2.22.2 2.22.3
org.mockito:mockito-core 5.23.0 5.24.0
org.mockito:mockito-junit-jupiter 5.23.0 5.24.0
org.apache.sshd:sshd-core 2.19.0 2.20.0
com.fasterxml.jackson.core:jackson-core 2.22.2 2.22.3
com.fasterxml.jackson.core:jackson-databind 2.22.2 2.22.3
org.slf4j:slf4j-api 2.0.19 2.0.20
ch.qos.logback:logback-classic 1.6.3 1.6.4
ch.qos.logback:logback-core 1.6.3 1.6.4

Updates com.fasterxml.jackson:jackson-bom from 2.22.2 to 2.22.3

Commits
  • 9b1c380 [maven-release-plugin] prepare release jackson-bom-2.22.3
  • f76ca14 Prep for 2.22.3 release
  • d6ac108 Merge branch '2.21' into 2.22
  • 093a05e Post-release dep version bump
  • e7a71a2 [maven-release-plugin] prepare for next development iteration
  • 62d4d51 [maven-release-plugin] prepare release jackson-bom-2.21.7
  • 6171b54 Prep for 2.21.7 release
  • 6702bf3 Merge branch '2.20' into 2.21
  • 2feb1f9 Merge branch '2.19' into 2.20
  • 1129aa0 Merge branch '2.18' into 2.19
  • Additional commits viewable in compare view

Updates org.mockito:mockito-core from 5.23.0 to 5.24.0

Release notes

Sourced from org.mockito:mockito-core's releases.

v5.24.0

Changelog generated by Shipkit Changelog Gradle Plugin

5.24.0

Commits
  • 5a2f0f8 Fix Mockito docs for -javaagent flag with Gradle (#3866)
  • 9c5f36f Bump graalvm/setup-graalvm from 1.6.3 to 1.6.6 (#3862)
  • e7fd06d Preserve method parameters when clearing inline mocks (#3847)
  • 5a676bc Bump gradle/actions from 6.2.0 to 6.3.0 (#3852)
  • 508f8e7 Bump gradle/actions from 5 to 6.2.0 (#3851)
  • ee8a330 Print object fields via reflection when toString() is not implemented (#3844)
  • 39b1aba Bump graalvm/setup-graalvm from 1.6.0 to 1.6.3 (#3845)
  • d8638e1 Migrate extensions-tests to JUnit Jupiter (#3840)
  • 0aab922 Bump graalvm/setup-graalvm from 1.5.6 to 1.6.0 (#3839)
  • f3cf74c docs(when-verify): fixes to explanations about redundancy (#3838)
  • Additional commits viewable in compare view

Updates org.mockito:mockito-junit-jupiter from 5.23.0 to 5.24.0

Release notes

Sourced from org.mockito:mockito-junit-jupiter's releases.

v5.24.0

Changelog generated by Shipkit Changelog Gradle Plugin

5.24.0

Commits
  • 5a2f0f8 Fix Mockito docs for -javaagent flag with Gradle (#3866)
  • 9c5f36f Bump graalvm/setup-graalvm from 1.6.3 to 1.6.6 (#3862)
  • e7fd06d Preserve method parameters when clearing inline mocks (#3847)
  • 5a676bc Bump gradle/actions from 6.2.0 to 6.3.0 (#3852)
  • 508f8e7 Bump gradle/actions from 5 to 6.2.0 (#3851)
  • ee8a330 Print object fields via reflection when toString() is not implemented (#3844)
  • 39b1aba Bump graalvm/setup-graalvm from 1.6.0 to 1.6.3 (#3845)
  • d8638e1 Migrate extensions-tests to JUnit Jupiter (#3840)
  • 0aab922 Bump graalvm/setup-graalvm from 1.5.6 to 1.6.0 (#3839)
  • f3cf74c docs(when-verify): fixes to explanations about redundancy (#3838)
  • Additional commits viewable in compare view

Updates org.apache.sshd:sshd-core from 2.19.0 to 2.20.0

Release notes

Sourced from org.apache.sshd:sshd-core's releases.

Apache MINA SSHD 2.20.0

Bug Fixes

  • GH-656 ChannelPipedInputStream: shrink buffer when emptied
  • GH-906 Fix finding a signature factory for BC ed25519 keys
  • GH-911 Fix server-side SOCKS5 proxy for fragmented and pipelined CONNECT requests
  • Allow asynchronous authentication only for password and keyboard-interactive authentication schemes
  • Fix authentication requiring multiple public keys (server-side)
  • Better argument handling in sshd-git
  • More checks in authentication (server-side)
  • Better SCP command handling
  • SFTP client: simplify response message handling
  • Fix check-file-name/check-file-handle SFTP v6 extension (server-side)
  • Improve LDAP authentication (sshd-ldap)

New Features

  • GH-905 Implement the "from" and "expiry-time" options in authorized_keys handling in public key authentication (server side)

Potential Compatibility Issues

None.

Major Code Re-factoring

None.

Changelog

Sourced from org.apache.sshd:sshd-core's changelog.

Previous Versions

Latest Version

Planned for Next Version

Bug Fixes

New Features

Potential Compatibility Issues

Major Code Re-factoring

Commits
  • 2221feb [maven-release-plugin] prepare release sshd-2.20.0
  • daa4002 Prepare release documentation
  • 0b41c6f Format PublickeyAuthenticator
  • cea7e24 Bump BC-FIPS test dependencies
  • 1c97396 Update CHANGES.md
  • 602896f PublicKeyAuthenticator.authenticate(): remove AsyncAuthException
  • 53b57ce Bump Bouncy Castle 1.85 -> 1.86
  • acc0f1e Fix LDAP authentication
  • f4f562c Fix check-file-name/check-file-handle SFTP v6 extension
  • 53bce94 DefaultSftpClient: simplify SFTP message handling
  • Additional commits viewable in compare view

Updates com.fasterxml.jackson.core:jackson-core from 2.22.2 to 2.22.3

Commits
  • eee4b9e [maven-release-plugin] prepare release jackson-core-2.22.3
  • 31ee7eb Prep for 2.22.3 release
  • 9fef13f Merge branch '2.21' into 2.22
  • 9160f40 Post-release dep version bump
  • 1169cb6 [maven-release-plugin] prepare for next development iteration
  • b33f455 [maven-release-plugin] prepare release jackson-core-2.21.7
  • ce8b7dc Prep for 2.21.7 release
  • b69555e Merge branch '2.21' into 2.22
  • 53df608 Merge branch '2.20' into 2.21
  • 892f757 Merge branch '2.19' into 2.20
  • Additional commits viewable in compare view

Updates com.fasterxml.jackson.core:jackson-databind from 2.22.2 to 2.22.3

Commits
  • 4385c5f [maven-release-plugin] prepare release jackson-databind-2.22.3
  • ccb4fd0 Prep for 2.22.3 release
  • 2958412 Merge branch '2.21' into 2.22
  • 1215b94 Post-release dep version bump
  • 1f0df62 [maven-release-plugin] prepare for next development iteration
  • 13a9ff4 [maven-release-plugin] prepare release jackson-databind-2.21.7
  • d168f96 Prep for 2.21.7 release
  • eaf5c76 Merge branch '2.21' into 2.22
  • e05ef4c Merge branch '2.20' into 2.21
  • f6d4000 Merge branch '2.19' into 2.20
  • Additional commits viewable in compare view

Updates org.slf4j:slf4j-api from 2.0.19 to 2.0.20

Updates ch.qos.logback:logback-classic from 1.6.3 to 1.6.4

Release notes

Sourced from ch.qos.logback:logback-classic's releases.

Logback 1.6.4

2026-09-24 Release of logback version 1.6.4

• Variable substitution is again applied to the scan attribute of the <configuration> element. The scanning refactoring in version 1.5.27 had dropped substitution, so values such as ${logback.scan.enabled:-true} were no longer resolved. As before version 1.5.27, an unrecognized non-empty value turns scanning on. The same substitution now applies to the scan attribute of <propertiesConfigurator>. This regression was reported in issues/1065 by vaibhavjain2.

• OutputStreamAppender and FileAppender now handle stateful encoders. The Encoder interface has a new default method called isStateful(), which returns false. An encoder that keeps state between calls to encode() can return true. For such encoders, the appender holds its write lock while encoding and while writing, so the output of concurrent appends cannot interleave. Stateless encoders still encode outside the lock, so their performance does not change. Existing encoders need no changes.

• Several race conditions in OutputStreamAppender and FileAppender were fixed. The appender is now marked started and the encoder header is written while the same lock is held, so a concurrent append can no longer write an event before the header. After acquiring the lock, the appender checks again whether it has been stopped, so no event is written after the footer. In prudent mode, FileAppender now encodes and writes each event while holding the lock.

• Fixed a data race on the logger count in LoggerContext. Loggers are created under the lock of their parent logger, so loggers with different parents could be created at the same time and increments of the shared counter could be lost. As a result, LoggerContext.size() could return a value lower than the actual number of loggers. The counter is now an AtomicInteger. This issue was reported in issues/1038 by hcantunc. The fix was contributed in PR #1055 by seonwoo_jung.

• TimeBasedRollingPolicy now supports half-day periods. Date patterns with the AM/PM marker, for example %d{yyyy-MM-dd-a}, used to be detected as daily and rolled over only at midnight. They now roll over at both 00:00 and 12:00. This issue was reported in issues/976 by shakthifuture. The fix was contributed in PR #1051 by seonwoo_jung. See TimeBasedRollingPolicy.

• If org.jline.jansi.AnsiConsole cannot be found on the class path, JansiConsoleAppender now emits warnings that explain how to add org.jline:jansi-core and then writes to the plain console stream. See codes.html#missingJlineJansi.

• The unused ch.qos.logback.classic.util.LogbackMDCAdapterSimple class was removed. LogbackMDCAdapter remains the default MDC adapter.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit 07d291ca0d280bc5da934ec9ff5f1da634fd7937 associated with the tag v_1.6.4. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Full Changelog: qos-ch/logback@v_1.6.3...v_1.6.4

Commits
  • 07d291c preapre release 1.6.4
  • 9627daf revert to Collections.unmodifiableMap instead of
  • aa42fb5 disabled RollingCalendarTest#testVaryingNumberOfHalfDailyPeriods to shave off...
  • ddc7459 Support HALF_DAY periodicity for AM/PM date patterns
  • 42d75d7 disable LoggerContextTest#concurrentGetLoggerKeepsSizeConsistent to shave exe...
  • bffd55e add warnings about missing jline.jansi classes
  • 8de0b9b Fix data race on LoggerContext.size (#1038)
  • 76c73d1 add MinimalUnmodifiableMap and return it in LogbackMDCAdapter#getPropertyMap
  • a2c416a Fix formatting of email instruction in README
  • 2c89727 mailing lists have been deactivated
  • Additional commits viewable in compare view

Updates ch.qos.logback:logback-core from 1.6.3 to 1.6.4

Release notes

Sourced from ch.qos.logback:logback-core's releases.

Logback 1.6.4

2026-09-24 Release of logback version 1.6.4

• Variable substitution is again applied to the scan attribute of the <configuration> element. The scanning refactoring in version 1.5.27 had dropped substitution, so values such as ${logback.scan.enabled:-true} were no longer resolved. As before version 1.5.27, an unrecognized non-empty value turns scanning on. The same substitution now applies to the scan attribute of <propertiesConfigurator>. This regression was reported in issues/1065 by vaibhavjain2.

• OutputStreamAppender and FileAppender now handle stateful encoders. The Encoder interface has a new default method called isStateful(), which returns false. An encoder that keeps state between calls to encode() can return true. For such encoders, the appender holds its write lock while encoding and while writing, so the output of concurrent appends cannot interleave. Stateless encoders still encode outside the lock, so their performance does not change. Existing encoders need no changes.

• Several race conditions in OutputStreamAppender and FileAppender were fixed. The appender is now marked started and the encoder header is written while the same lock is held, so a concurrent append can no longer write an event before the header. After acquiring the lock, the appender checks again whether it has been stopped, so no event is written after the footer. In prudent mode, FileAppender now encodes and writes each event while holding the lock.

• Fixed a data race on the logger count in LoggerContext. Loggers are created under the lock of their parent logger, so loggers with different parents could be created at the same time and increments of the shared counter could be lost. As a result, LoggerContext.size() could return a value lower than the actual number of loggers. The counter is now an AtomicInteger. This issue was reported in issues/1038 by hcantunc. The fix was contributed in PR #1055 by seonwoo_jung.

• TimeBasedRollingPolicy now supports half-day periods. Date patterns with the AM/PM marker, for example %d{yyyy-MM-dd-a}, used to be detected as daily and rolled over only at midnight. They now roll over at both 00:00 and 12:00. This issue was reported in issues/976 by shakthifuture. The fix was contributed in PR #1051 by seonwoo_jung. See TimeBasedRollingPolicy.

• If org.jline.jansi.AnsiConsole cannot be found on the class path, JansiConsoleAppender now emits warnings that explain how to add org.jline:jansi-core and then writes to the plain console stream. See codes.html#missingJlineJansi.

• The unused ch.qos.logback.classic.util.LogbackMDCAdapterSimple class was removed. LogbackMDCAdapter remains the default MDC adapter.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit 07d291ca0d280bc5da934ec9ff5f1da634fd7937 associated with the tag v_1.6.4. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Full Changelog: qos-ch/logback@v_1.6.3...v_1.6.4

Commits
  • 07d291c preapre release 1.6.4
  • 9627daf revert to Collections.unmodifiableMap instead of
  • aa42fb5 disabled RollingCalendarTest#testVaryingNumberOfHalfDailyPeriods to shave off...
  • ddc7459 Support HALF_DAY periodicity for AM/PM date patterns
  • 42d75d7 disable LoggerContextTest#concurrentGetLoggerKeepsSizeConsistent to shave exe...
  • bffd55e add warnings about missing jline.jansi classes
  • 8de0b9b Fix data race on LoggerContext.size (#1038)
  • 76c73d1 add MinimalUnmodifiableMap and return it in LogbackMDCAdapter#getPropertyMap
  • a2c416a Fix formatting of email instruction in README
  • 2c89727 mailing lists have been deactivated
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the minor-and-patch group with 9 updates:

| Package | From | To |
| --- | --- | --- |
| [com.fasterxml.jackson:jackson-bom](https://github.com/FasterXML/jackson-bom) | `2.22.2` | `2.22.3` |
| [org.mockito:mockito-core](https://github.com/mockito/mockito) | `5.23.0` | `5.24.0` |
| [org.mockito:mockito-junit-jupiter](https://github.com/mockito/mockito) | `5.23.0` | `5.24.0` |
| [org.apache.sshd:sshd-core](https://github.com/apache/mina-sshd) | `2.19.0` | `2.20.0` |
| [com.fasterxml.jackson.core:jackson-core](https://github.com/FasterXML/jackson-core) | `2.22.2` | `2.22.3` |
| [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) | `2.22.2` | `2.22.3` |
| org.slf4j:slf4j-api | `2.0.19` | `2.0.20` |
| [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) | `1.6.3` | `1.6.4` |
| [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) | `1.6.3` | `1.6.4` |


Updates `com.fasterxml.jackson:jackson-bom` from 2.22.2 to 2.22.3
- [Commits](FasterXML/jackson-bom@jackson-bom-2.22.2...jackson-bom-2.22.3)

Updates `org.mockito:mockito-core` from 5.23.0 to 5.24.0
- [Release notes](https://github.com/mockito/mockito/releases)
- [Commits](mockito/mockito@v5.23.0...v5.24.0)

Updates `org.mockito:mockito-junit-jupiter` from 5.23.0 to 5.24.0
- [Release notes](https://github.com/mockito/mockito/releases)
- [Commits](mockito/mockito@v5.23.0...v5.24.0)

Updates `org.apache.sshd:sshd-core` from 2.19.0 to 2.20.0
- [Release notes](https://github.com/apache/mina-sshd/releases)
- [Changelog](https://github.com/apache/mina-sshd/blob/master/CHANGES.md)
- [Commits](apache/mina-sshd@sshd-2.19.0...sshd-2.20.0)

Updates `com.fasterxml.jackson.core:jackson-core` from 2.22.2 to 2.22.3
- [Commits](FasterXML/jackson-core@jackson-core-2.22.2...jackson-core-2.22.3)

Updates `com.fasterxml.jackson.core:jackson-databind` from 2.22.2 to 2.22.3
- [Commits](FasterXML/jackson-databind@jackson-databind-2.22.2...jackson-databind-2.22.3)

Updates `org.slf4j:slf4j-api` from 2.0.19 to 2.0.20

Updates `ch.qos.logback:logback-classic` from 1.6.3 to 1.6.4
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.6.3...v_1.6.4)

Updates `ch.qos.logback:logback-core` from 1.6.3 to 1.6.4
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.6.3...v_1.6.4)

---
updated-dependencies:
- dependency-name: com.fasterxml.jackson:jackson-bom
  dependency-version: 2.22.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: org.mockito:mockito-core
  dependency-version: 5.24.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: org.mockito:mockito-junit-jupiter
  dependency-version: 5.24.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: org.apache.sshd:sshd-core
  dependency-version: 2.20.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: com.fasterxml.jackson.core:jackson-core
  dependency-version: 2.22.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: com.fasterxml.jackson.core:jackson-databind
  dependency-version: 2.22.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: org.slf4j:slf4j-api
  dependency-version: 2.0.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: ch.qos.logback:logback-classic
  dependency-version: 1.6.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: ch.qos.logback:logback-core
  dependency-version: 1.6.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Oct 1, 2026
@jochen-testingbot
jochen-testingbot merged commit 70287b7 into main Oct 2, 2026
6 checks passed
@dependabot
dependabot Bot deleted the dependabot/maven/minor-and-patch-34e57931b6 branch October 2, 2026 07:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant