Skip to content

Bump the all group across 1 directory with 11 updates - #889

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/all-5feefc120e
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/all-5feefc120e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 2, 2026

Copy link
Copy Markdown
Contributor

Bumps the all group with 11 updates in the / directory:

Package From To
org.conscrypt:conscrypt-openjdk-uber 2.6.1 2.7.0
com.kohlschutter.junixsocket:junixsocket-core 2.10.1 2.11.1
com.github.luben:zstd-jni 1.5.7-11 1.5.7-20
io.micrometer:micrometer-core 1.17.0 1.17.1
io.micrometer:micrometer-observation 1.17.0 1.17.1
io.micrometer:micrometer-registry-prometheus 1.17.0 1.17.1
io.micrometer:micrometer-observation 1.17.0 1.17.1
io.micrometer:micrometer-registry-prometheus 1.17.0 1.17.1
io.micrometer:micrometer-tracing 1.7.0 1.7.1
io.micrometer:micrometer-tracing-bridge-otel 1.7.0 1.7.1
io.micrometer:micrometer-tracing-bridge-otel 1.7.0 1.7.1
io.opentelemetry:opentelemetry-bom 1.64.0 1.66.0
org.apache.maven.plugins:maven-surefire-plugin 3.5.0 3.6.0
org.apache.maven:apache-maven 3.9.14 3.10.0

Updates org.conscrypt:conscrypt-openjdk-uber from 2.6.1 to 2.7.0

Release notes

Sourced from org.conscrypt:conscrypt-openjdk-uber's releases.

v2.7.0

Conscrypt Version 2.7.0.

This is a new release of conscrypt-openjdk, conscrypt-openjdk-uber and conscrypt-android on maven.

It includes the following changes:

  • TLS uses X25519MLKEM768 by default.
  • Encrypted Client Hello (ECH).
  • Composite-ML-DSA Signatures (with Ed25519, ECDSA, RSA PKCS1 and RSA PSS).
  • Hash-SLH-DSA Signatures (with SHA384).
  • Some cleanups.

v2.7-alpha

Conscrypt Version 2.7-alpha.

This is a new release of conscrypt-openjdk, conscrypt-openjdk-uber and conscrypt-android on maven.

It includes the following changes:

  • TLS uses X25519MLKEM768 by default.
  • Encrypted Client Hello (ECH).
  • Composite-ML-DSA Signatures (with Ed25519, ECDSA, RSA PKCS1 and RSA PSS).
  • Hash-SLH-DSA Signatures (with SHA384).
  • Some cleanups.

v2.6.3

This release uses the same Conscrypt source code as release 2.6.2, but the maven binary was compiled with this boringssl version: https://boringssl.googlesource.com/boringssl/+/refs/tags/0.20260616.0

This should fix google/conscrypt#1530

v2.6.2

Commits

Updates com.kohlschutter.junixsocket:junixsocket-core from 2.10.1 to 2.11.1

Release notes

Sourced from com.kohlschutter.junixsocket:junixsocket-core's releases.

junixsocket 2.11.0

  • New module: junixsocket-memory (Java 22+): SharedMemory/mmap, POSIX shm, futex-based Mutexes, memfd, etc.
  • Remove junixsocket-jetty support for Jetty 12.0.x and older (breaking change)
  • Add several new exceptions (subclasses of IOException / SocketException)
  • Add FileChannelSupplier for FileDescriptorCast
  • Add support for Astral OS; native binary not included yet
  • Add AFSocketCapability for send/receive timeout
  • Add support for AF_SYSTEM CTLIOCGINFO (number of registered kernel control names)
  • Improve/simplify check for AFServerSocket.isLocalSocketAddressValid
  • Improve exception reporting upon "accept"
  • Reduce possible local JNI refernce accumulation in poll
  • Fix NullPointerException in AFSelector
  • Fix spurious Connection-Refused in AFSocketImpl.connect
  • Fix AFSocketChannel.read returning 0 on EOF
  • Fix VirtualThread issue on machines with 1 or 2 CPUs
  • Fix spurious connect timeouts on Windows
  • Fix for TIPC: Ignore EINVAL upon setsocketopt SOL_TIPC/TIPC_GROUP_LEAVE
  • Improve selftest
  • Code cleanup and other optimizations
  • Update documentation
Commits
  • 52dc074 docs: Update changelog, README
  • c36ccf2 Set version to 2.11.1
  • 76f1de4 native: Fix invalid pointer cast when checking "available"
  • ecbef49 docs: changelog: fix typo
  • f6d2f6c docs: Update README, changelog
  • 954836d memory: test: Fix futex wakeup assumptions
  • 646a005 Set version to 2.11.0
  • 593d9d2 test: rmi: Fix testRemoteShutdownNotAllowed
  • c7e3f62 Update dependencies
  • b776161 demo: Update PostgreSQL version
  • Additional commits viewable in compare view

Updates com.github.luben:zstd-jni from 1.5.7-11 to 1.5.7-20

Commits
  • b154531 Don't re-run jniCompile before packaging
  • a47b87f Faster perf test runs
  • 6564a02 GetPrimitiveArrayCritical calls can be nested
  • 82d7f90 Revert "Don't jniCompile when packaging"
  • acc7b2c simplify comments
  • 9a643d6 keep FrameProgressionBuffer off-heap
  • 6d5439f improve getFrameProgression method performance & memory usage
  • 518e870 implement ZstdCompressCtx based on FFM API
  • d061790 Next version is v1.5.7-20
  • 5ddc98b Don't jniCompile when packaging
  • Additional commits viewable in compare view

Updates io.micrometer:micrometer-core from 1.17.0 to 1.17.1

Commits

Updates io.micrometer:micrometer-observation from 1.17.0 to 1.17.1

Commits

Updates io.micrometer:micrometer-registry-prometheus from 1.17.0 to 1.17.1

Commits

Updates io.micrometer:micrometer-observation from 1.17.0 to 1.17.1

Commits

Updates io.micrometer:micrometer-registry-prometheus from 1.17.0 to 1.17.1

Commits

Updates io.micrometer:micrometer-tracing from 1.7.0 to 1.7.1

Commits

Updates io.micrometer:micrometer-tracing-bridge-otel from 1.7.0 to 1.7.1

Commits

Updates io.micrometer:micrometer-tracing-bridge-otel from 1.7.0 to 1.7.1

Commits

Updates io.opentelemetry:opentelemetry-bom from 1.64.0 to 1.66.0

Release notes

Sourced from io.opentelemetry:opentelemetry-bom's releases.

Version 1.66.0

API

  • Fix Baggage.fromContext() and Baggage.fromContextOrNull() to handle a null context (#8667)
  • Do not percent-encode W3C baggage metadata (#8682)
  • Fix ArrayIndexOutOfBoundsException in OtelEncodingUtils for invalid hex characters (#8748)

SDK

Traces

  • Record processed spans before export completes and reject new spans on shutdown in SpanProcessor self-observability instrumentation (#8735)

Metrics

  • Improve explicit bucket histogram contention performance (#8717)

Logs

  • Record processed logs before export completes and reject new logs on shutdown in LogRecordProcessor self-observability instrumentation (#8698)

Exporters

  • OTLP: Respect Retry-After in OTLP HTTP senders (#8633)
  • OTLP: Add setEnabledProtocols option to OTLP HTTP exporter builders (#8610)
  • OTLP: Reject mixing keyManager and sslContext in TlsConfigHelper (#8710)
  • OTLP: Fix OkHttpGrpcSender mTLS when using the platform default trust store (#8758)
  • OTLP: Suppress instrumentation of exporter requests in JdkHttpSender (#8757)
  • OTLP: Accept RFC 1123 hostnames in EndpointUtil.validateEndpoint for OkHttp senders (#8746)
  • OTLP: Include the number of affected items in exporter error logging (#8780)
  • OTLP: Add toString to OtlpJsonLogging{Span,Metric,LogRecord}Exporter (#8725)
  • OTLP Profiles: Improve JFR export example and align LinkData null-element handling with the spec (#8349)
  • Prometheus: Remove default host log warning in PrometheusHttpServerBuilder (#8679)
  • Prometheus: Align UCUM byte unit conversions with the specification table (#8752)

Extensions

  • BREAKING Declarative config: Rename generated model POJO setters from with<Prop> to set<Prop> (#8742)
  • Declarative config: Resolve experimental properties on stable APIs in generated model POJOs (#8654)
  • Declarative config: Fix inverted scope_info_enabled and target_info_enabled flags in the Prometheus component provider (#8750)
  • Declarative config: Support output_stream in otlp_file/development (#8676)
  • Incubator: Add toString to ComposableAnnotatingSampler (#8645)

Project tooling

  • Remediate zizmor findings in GitHub Actions workflows (#8592)

🙇 Thank you

This release was possible thanks to the following contributors who shared their brilliant ideas and awesome pull requests:

... (truncated)

Changelog

Sourced from io.opentelemetry:opentelemetry-bom's changelog.

Version 1.66.0 (2026-09-11)

API

  • Fix Baggage.fromContext() and Baggage.fromContextOrNull() to handle a null context (#8667)
  • Do not percent-encode W3C baggage metadata (#8682)
  • Fix ArrayIndexOutOfBoundsException in OtelEncodingUtils for invalid hex characters (#8748)

SDK

Traces

  • Record processed spans before export completes and reject new spans on shutdown in SpanProcessor self-observability instrumentation (#8735)

Metrics

  • Improve explicit bucket histogram contention performance (#8717)

Logs

  • Record processed logs before export completes and reject new logs on shutdown in LogRecordProcessor self-observability instrumentation (#8698)

Exporters

  • OTLP: Respect Retry-After in OTLP HTTP senders (#8633)
  • OTLP: Add setEnabledProtocols option to OTLP HTTP exporter builders (#8610)
  • OTLP: Reject mixing keyManager and sslContext in TlsConfigHelper (#8710)
  • OTLP: Fix OkHttpGrpcSender mTLS when using the platform default trust store (#8758)
  • OTLP: Suppress instrumentation of exporter requests in JdkHttpSender (#8757)
  • OTLP: Accept RFC 1123 hostnames in EndpointUtil.validateEndpoint for OkHttp senders (#8746)
  • OTLP: Include the number of affected items in exporter error logging (#8780)
  • OTLP: Add toString to OtlpJsonLogging{Span,Metric,LogRecord}Exporter (#8725)
  • OTLP Profiles: Improve JFR export example and align LinkData null-element handling with the spec (#8349)

... (truncated)

Commits
  • 300a358 [release/v1.66.x] Prepare release 1.66.0 (#8799)
  • dd71106 Prepare for 1.66.0 release (#8795)
  • 9284265 Manual 1.65.0 post release (#8794)
  • 10c7338 Align UCUM byte unit conversions with the specification table (#8752)
  • bf1a64c Accept RFC 1123 hostnames in EndpointUtil.validateEndpoint (#8746)
  • ab72956 Add number of affected items to Exporter error logging (#8780)
  • 275fe92 Update dependency com.squareup.wire:wire-bom to v7 (#8793)
  • 050f481 Remove unused parameter from B3 propagation integration tests (#8791)
  • 8d7bd65 Improve explicit histogram contention performance (#8717)
  • 2c880d9 Rename inverted grpc detection test in GrpcJavaOtlpIntegrationTest (#8790)
  • Additional commits viewable in compare view

Updates org.apache.maven.plugins:maven-surefire-plugin from 3.5.0 to 3.6.0

Release notes

Sourced from org.apache.maven.plugins:maven-surefire-plugin's releases.

3.6.0

Please refer to the main page for what's new https://maven.apache.org/surefire/ And the migration page https://maven.apache.org/surefire/maven-surefire-plugin/whats-new-3-6-0.html

🚀 New features and improvements

🐛 Bug Fixes

📝 Documentation updates

👻 Maintenance

... (truncated)

Commits
  • 0ff622b [maven-release-plugin] prepare release surefire-3.6.0
  • bb3932a Let's go for 3.6.0 release
  • 3002a16 Bump mavenVersion from 3.9.14 to 3.9.16
  • 61a531d Bump Maven parent version from 47 to 49 (#3449)
  • e52ead4 [SUREFIRE-523] Link all reported tests to source XRef (#3445)
  • 45102fa [SUREFIRE-3446] Fix direct selection of JUnit Jupiter @​Nested classes (#3447)
  • b2e1f70 Fix #3303: distinguish JUnit 6 ParameterizedClass invocations (#3432)
  • c051938 Discover tests in a fork when a toolchain JDK is used (#3444)
  • db75df8 Bump org.codehaus.plexus:plexus-java from 1.5.2 to 1.6.0 (#3441)
  • 77f2759 Bump org.codehaus.plexus:plexus-interpolation from 1.29 to 1.30.0
  • Additional commits viewable in compare view

Updates org.apache.maven:apache-maven from 3.9.14 to 3.10.0

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the all group with 11 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [org.conscrypt:conscrypt-openjdk-uber](https://github.com/google/conscrypt) | `2.6.1` | `2.7.0` |
| [com.kohlschutter.junixsocket:junixsocket-core](https://github.com/kohlschutter/junixsocket) | `2.10.1` | `2.11.1` |
| [com.github.luben:zstd-jni](https://github.com/luben/zstd-jni) | `1.5.7-11` | `1.5.7-20` |
| [io.micrometer:micrometer-core](https://github.com/micrometer-metrics/micrometer-commercial) | `1.17.0` | `1.17.1` |
| [io.micrometer:micrometer-observation](https://github.com/micrometer-metrics/micrometer-commercial) | `1.17.0` | `1.17.1` |
| [io.micrometer:micrometer-registry-prometheus](https://github.com/micrometer-metrics/micrometer-commercial) | `1.17.0` | `1.17.1` |
| [io.micrometer:micrometer-observation](https://github.com/micrometer-metrics/micrometer-commercial) | `1.17.0` | `1.17.1` |
| [io.micrometer:micrometer-registry-prometheus](https://github.com/micrometer-metrics/micrometer-commercial) | `1.17.0` | `1.17.1` |
| [io.micrometer:micrometer-tracing](https://github.com/micrometer-metrics/tracing-commercial) | `1.7.0` | `1.7.1` |
| [io.micrometer:micrometer-tracing-bridge-otel](https://github.com/micrometer-metrics/tracing-commercial) | `1.7.0` | `1.7.1` |
| [io.micrometer:micrometer-tracing-bridge-otel](https://github.com/micrometer-metrics/tracing-commercial) | `1.7.0` | `1.7.1` |
| [io.opentelemetry:opentelemetry-bom](https://github.com/open-telemetry/opentelemetry-java) | `1.64.0` | `1.66.0` |
| [org.apache.maven.plugins:maven-surefire-plugin](https://github.com/apache/maven-surefire) | `3.5.0` | `3.6.0` |
| org.apache.maven:apache-maven | `3.9.14` | `3.10.0` |



Updates `org.conscrypt:conscrypt-openjdk-uber` from 2.6.1 to 2.7.0
- [Release notes](https://github.com/google/conscrypt/releases)
- [Commits](google/conscrypt@2.6.1...2.7.0)

Updates `com.kohlschutter.junixsocket:junixsocket-core` from 2.10.1 to 2.11.1
- [Release notes](https://github.com/kohlschutter/junixsocket/releases)
- [Commits](kohlschutter/junixsocket@junixsocket-2.10.1...junixsocket-2.11.1)

Updates `com.github.luben:zstd-jni` from 1.5.7-11 to 1.5.7-20
- [Commits](luben/zstd-jni@v1.5.7-11...v1.5.7-20)

Updates `io.micrometer:micrometer-core` from 1.17.0 to 1.17.1
- [Commits](https://github.com/micrometer-metrics/micrometer-commercial/commits)

Updates `io.micrometer:micrometer-observation` from 1.17.0 to 1.17.1
- [Commits](https://github.com/micrometer-metrics/micrometer-commercial/commits)

Updates `io.micrometer:micrometer-registry-prometheus` from 1.17.0 to 1.17.1
- [Commits](https://github.com/micrometer-metrics/micrometer-commercial/commits)

Updates `io.micrometer:micrometer-observation` from 1.17.0 to 1.17.1
- [Commits](https://github.com/micrometer-metrics/micrometer-commercial/commits)

Updates `io.micrometer:micrometer-registry-prometheus` from 1.17.0 to 1.17.1
- [Commits](https://github.com/micrometer-metrics/micrometer-commercial/commits)

Updates `io.micrometer:micrometer-tracing` from 1.7.0 to 1.7.1
- [Commits](https://github.com/micrometer-metrics/tracing-commercial/commits)

Updates `io.micrometer:micrometer-tracing-bridge-otel` from 1.7.0 to 1.7.1
- [Commits](https://github.com/micrometer-metrics/tracing-commercial/commits)

Updates `io.micrometer:micrometer-tracing-bridge-otel` from 1.7.0 to 1.7.1
- [Commits](https://github.com/micrometer-metrics/tracing-commercial/commits)

Updates `io.opentelemetry:opentelemetry-bom` from 1.64.0 to 1.66.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-java/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-java/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-java@v1.64.0...v1.66.0)

Updates `org.apache.maven.plugins:maven-surefire-plugin` from 3.5.0 to 3.6.0
- [Release notes](https://github.com/apache/maven-surefire/releases)
- [Commits](apache/maven-surefire@surefire-3.5.0...surefire-3.6.0)

Updates `org.apache.maven:apache-maven` from 3.9.14 to 3.10.0

---
updated-dependencies:
- dependency-name: org.conscrypt:conscrypt-openjdk-uber
  dependency-version: 2.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: com.kohlschutter.junixsocket:junixsocket-core
  dependency-version: 2.11.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: com.github.luben:zstd-jni
  dependency-version: 1.5.7-20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: io.micrometer:micrometer-core
  dependency-version: 1.17.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: io.micrometer:micrometer-observation
  dependency-version: 1.17.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: io.micrometer:micrometer-registry-prometheus
  dependency-version: 1.17.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: io.micrometer:micrometer-observation
  dependency-version: 1.17.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: io.micrometer:micrometer-registry-prometheus
  dependency-version: 1.17.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: io.micrometer:micrometer-tracing
  dependency-version: 1.7.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: io.micrometer:micrometer-tracing-bridge-otel
  dependency-version: 1.7.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: io.micrometer:micrometer-tracing-bridge-otel
  dependency-version: 1.7.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: all
- dependency-name: io.opentelemetry:opentelemetry-bom
  dependency-version: 1.66.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: org.apache.maven.plugins:maven-surefire-plugin
  dependency-version: 3.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
- dependency-name: org.apache.maven:apache-maven
  dependency-version: 3.10.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: all
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Oct 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants