Skip to content

Bump the maven-patch-group group with 4 updates#3974

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/maven-patch-group-52fd5e174b
Closed

Bump the maven-patch-group group with 4 updates#3974
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/maven-patch-group-52fd5e174b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 8, 2026

Copy link
Copy Markdown
Contributor

Bumps the maven-patch-group group with 4 updates: org.eclipse.jetty:jetty-bom, org.eclipse.jetty.ee11:jetty-ee11-bom, org.apache.maven.plugins:maven-surefire-plugin and org.apache.maven.surefire:surefire-junit47.

Updates org.eclipse.jetty:jetty-bom from 12.1.9 to 12.1.10

Release notes

Sourced from org.eclipse.jetty:jetty-bom's releases.

12.1.10

Changelog

  • #15180 - Upgrade to Quiche version 0.29.1
  • #15161 - Reduce memory footprint for persistent HttpConnections
  • #15136 - Refresh Digest authentication implementation
  • #15118 - Upgrade to Quiche version 0.29.0
  • #15094 - Jetty 12.1 Regression: Deferred Authentication provides Callback.NOT_CALLED leading to errors
  • #15074 - HTTP/2 extended connect responses contain Content-Length: 0
  • #15031 - IOResources#toRetainableByteBuffer data loss when using resources without path
  • #15021 - Resource handling regression in 12.1.9
  • #15011 - PathResource.resolve() fails on Microsoft Windows due to Illegal char <:>
  • #15009 - Make processing of RST_STREAM more lenient
  • #14984 - XmlConfiguration emits "Deprecated method ... setMaxThreads" WARN from shipped jetty-threadpool-virtual.xml
  • #14745 - NPE in HttpChannelState.completeStream() when _request is null during multipart cleanup
  • #14528 - BinaryStreamTest.testMoreThanLargestMessageOneByteAtATime() is flaky
  • #14522 - Bundle org.eclipse.jetty.websocket.server OSGI metadata exports internal instead of public package
  • #14006 - How to handle "Warning Logs in org.eclipse.jetty.ee8.nested.HttpChannelState and org.eclipse.jetty.server.internal.HttpChannelState"
  • #9799 - Declare EncodingException for HPACK/QPACK encoders and decoders
Commits
  • 9860245 Updating to version 12.1.10
  • 6d62879 IteratingCallback concurrent abort() may not notify abort event. (#15185)
  • 962f73f Fixes #15009 - Make processing of RST_STREAM more lenient. (#15087)
  • 6324c65 #15180 upgrade quiche to version 0.29.1
  • d0bb829 Fixes #15136 - Refresh Digest authentication implementation.
  • ac73ac1 Issue #14522 Bundle org.eclipse.jetty.websocket.server OSGI metadata should e...
  • 206c2e6 Merge pull request #15179 from jetty/fix/jetty-12.1.x/14745-MultiPartCleanup
  • 8d86494 Merge pull request #15163 from jetty/fix/jetty-12.1.x/15161-HttpConnectionOpt...
  • 437e617 Merge pull request #15178 from jetty/fix/jetty-12.1.x/14006-ReadPendingWarnings
  • 577d932 Issue #14745 - fix race for double call of HttpChannelState.completeStream (1...
  • Additional commits viewable in compare view

Updates org.eclipse.jetty.ee11:jetty-ee11-bom from 12.1.9 to 12.1.10

Release notes

Sourced from org.eclipse.jetty.ee11:jetty-ee11-bom's releases.

12.1.10

Changelog

  • #15180 - Upgrade to Quiche version 0.29.1
  • #15161 - Reduce memory footprint for persistent HttpConnections
  • #15136 - Refresh Digest authentication implementation
  • #15118 - Upgrade to Quiche version 0.29.0
  • #15094 - Jetty 12.1 Regression: Deferred Authentication provides Callback.NOT_CALLED leading to errors
  • #15074 - HTTP/2 extended connect responses contain Content-Length: 0
  • #15031 - IOResources#toRetainableByteBuffer data loss when using resources without path
  • #15021 - Resource handling regression in 12.1.9
  • #15011 - PathResource.resolve() fails on Microsoft Windows due to Illegal char <:>
  • #15009 - Make processing of RST_STREAM more lenient
  • #14984 - XmlConfiguration emits "Deprecated method ... setMaxThreads" WARN from shipped jetty-threadpool-virtual.xml
  • #14745 - NPE in HttpChannelState.completeStream() when _request is null during multipart cleanup
  • #14528 - BinaryStreamTest.testMoreThanLargestMessageOneByteAtATime() is flaky
  • #14522 - Bundle org.eclipse.jetty.websocket.server OSGI metadata exports internal instead of public package
  • #14006 - How to handle "Warning Logs in org.eclipse.jetty.ee8.nested.HttpChannelState and org.eclipse.jetty.server.internal.HttpChannelState"
  • #9799 - Declare EncodingException for HPACK/QPACK encoders and decoders
Commits
  • 9860245 Updating to version 12.1.10
  • 6d62879 IteratingCallback concurrent abort() may not notify abort event. (#15185)
  • 962f73f Fixes #15009 - Make processing of RST_STREAM more lenient. (#15087)
  • 6324c65 #15180 upgrade quiche to version 0.29.1
  • d0bb829 Fixes #15136 - Refresh Digest authentication implementation.
  • ac73ac1 Issue #14522 Bundle org.eclipse.jetty.websocket.server OSGI metadata should e...
  • 206c2e6 Merge pull request #15179 from jetty/fix/jetty-12.1.x/14745-MultiPartCleanup
  • 8d86494 Merge pull request #15163 from jetty/fix/jetty-12.1.x/15161-HttpConnectionOpt...
  • 437e617 Merge pull request #15178 from jetty/fix/jetty-12.1.x/14006-ReadPendingWarnings
  • 577d932 Issue #14745 - fix race for double call of HttpChannelState.completeStream (1...
  • Additional commits viewable in compare view

Updates org.eclipse.jetty.ee11:jetty-ee11-bom from 12.1.9 to 12.1.10

Release notes

Sourced from org.eclipse.jetty.ee11:jetty-ee11-bom's releases.

12.1.10

Changelog

  • #15180 - Upgrade to Quiche version 0.29.1
  • #15161 - Reduce memory footprint for persistent HttpConnections
  • #15136 - Refresh Digest authentication implementation
  • #15118 - Upgrade to Quiche version 0.29.0
  • #15094 - Jetty 12.1 Regression: Deferred Authentication provides Callback.NOT_CALLED leading to errors
  • #15074 - HTTP/2 extended connect responses contain Content-Length: 0
  • #15031 - IOResources#toRetainableByteBuffer data loss when using resources without path
  • #15021 - Resource handling regression in 12.1.9
  • #15011 - PathResource.resolve() fails on Microsoft Windows due to Illegal char <:>
  • #15009 - Make processing of RST_STREAM more lenient
  • #14984 - XmlConfiguration emits "Deprecated method ... setMaxThreads" WARN from shipped jetty-threadpool-virtual.xml
  • #14745 - NPE in HttpChannelState.completeStream() when _request is null during multipart cleanup
  • #14528 - BinaryStreamTest.testMoreThanLargestMessageOneByteAtATime() is flaky
  • #14522 - Bundle org.eclipse.jetty.websocket.server OSGI metadata exports internal instead of public package
  • #14006 - How to handle "Warning Logs in org.eclipse.jetty.ee8.nested.HttpChannelState and org.eclipse.jetty.server.internal.HttpChannelState"
  • #9799 - Declare EncodingException for HPACK/QPACK encoders and decoders
Commits
  • 9860245 Updating to version 12.1.10
  • 6d62879 IteratingCallback concurrent abort() may not notify abort event. (#15185)
  • 962f73f Fixes #15009 - Make processing of RST_STREAM more lenient. (#15087)
  • 6324c65 #15180 upgrade quiche to version 0.29.1
  • d0bb829 Fixes #15136 - Refresh Digest authentication implementation.
  • ac73ac1 Issue #14522 Bundle org.eclipse.jetty.websocket.server OSGI metadata should e...
  • 206c2e6 Merge pull request #15179 from jetty/fix/jetty-12.1.x/14745-MultiPartCleanup
  • 8d86494 Merge pull request #15163 from jetty/fix/jetty-12.1.x/15161-HttpConnectionOpt...
  • 437e617 Merge pull request #15178 from jetty/fix/jetty-12.1.x/14006-ReadPendingWarnings
  • 577d932 Issue #14745 - fix race for double call of HttpChannelState.completeStream (1...
  • Additional commits viewable in compare view

Updates org.apache.maven.plugins:maven-surefire-plugin from 3.5.5 to 3.5.6

Release notes

Sourced from org.apache.maven.plugins:maven-surefire-plugin's releases.

3.5.6

🚀 New features and improvements

  • Introduce reportTestTimestamp option and include timestamp for test sets and test cases (#3261) (#3302) @​olamy

🐛 Bug Fixes

👻 Maintenance

📦 Dependency updates

Commits
  • 25ea054 [maven-release-plugin] prepare release surefire-3.5.6
  • e5f374c Bump org.fusesource.jansi:jansi from 2.4.2 to 2.4.3
  • dadd55b Issue #2613 Debugging failsafe tests: Message 'Listening for transport dt_soc...
  • 39dd250 Bump commons-io:commons-io from 2.21.0 to 2.22.0
  • 2774273 Ensure that the statistics filename is calculated only once. (#3326) (#3327)
  • 0d5df8a 3.5.x/bug/cherry pick embedded mode its (#3328)
  • 04ad9a2 Use surefire 3.5.5 by project itself for testing
  • 37e8f69 Add flakes attribute to use in testsuite report (#3306) (#3308)
  • a970fef Introduce reportTestTimestamp option and include timestamp for test sets and ...
  • e838393 deploy 3.5.x branch to nexus
  • Additional commits viewable in compare view

Updates org.apache.maven.surefire:surefire-junit47 from 3.5.5 to 3.5.6

Updates org.apache.maven.surefire:surefire-junit47 from 3.5.5 to 3.5.6

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the maven-patch-group group with 4 updates: [org.eclipse.jetty:jetty-bom](https://github.com/jetty/jetty.project), [org.eclipse.jetty.ee11:jetty-ee11-bom](https://github.com/jetty/jetty.project), [org.apache.maven.plugins:maven-surefire-plugin](https://github.com/apache/maven-surefire) and org.apache.maven.surefire:surefire-junit47.


Updates `org.eclipse.jetty:jetty-bom` from 12.1.9 to 12.1.10
- [Release notes](https://github.com/jetty/jetty.project/releases)
- [Commits](jetty/jetty.project@jetty-12.1.9...jetty-12.1.10)

Updates `org.eclipse.jetty.ee11:jetty-ee11-bom` from 12.1.9 to 12.1.10
- [Release notes](https://github.com/jetty/jetty.project/releases)
- [Commits](jetty/jetty.project@jetty-12.1.9...jetty-12.1.10)

Updates `org.eclipse.jetty.ee11:jetty-ee11-bom` from 12.1.9 to 12.1.10
- [Release notes](https://github.com/jetty/jetty.project/releases)
- [Commits](jetty/jetty.project@jetty-12.1.9...jetty-12.1.10)

Updates `org.apache.maven.plugins:maven-surefire-plugin` from 3.5.5 to 3.5.6
- [Release notes](https://github.com/apache/maven-surefire/releases)
- [Commits](apache/maven-surefire@surefire-3.5.5...surefire-3.5.6)

Updates `org.apache.maven.surefire:surefire-junit47` from 3.5.5 to 3.5.6

Updates `org.apache.maven.surefire:surefire-junit47` from 3.5.5 to 3.5.6

---
updated-dependencies:
- dependency-name: org.eclipse.jetty:jetty-bom
  dependency-version: 12.1.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-patch-group
- dependency-name: org.eclipse.jetty.ee11:jetty-ee11-bom
  dependency-version: 12.1.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-patch-group
- dependency-name: org.eclipse.jetty.ee11:jetty-ee11-bom
  dependency-version: 12.1.10
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-patch-group
- dependency-name: org.apache.maven.plugins:maven-surefire-plugin
  dependency-version: 3.5.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-patch-group
- dependency-name: org.apache.maven.surefire:surefire-junit47
  dependency-version: 3.5.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-patch-group
- dependency-name: org.apache.maven.surefire:surefire-junit47
  dependency-version: 3.5.6
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-patch-group
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Jun 8, 2026
@afs

afs commented Jun 8, 2026

Copy link
Copy Markdown
Member

The Jetty upgrade breaks digest authentication, probably because Jena's implementation is following the original RFC.

@afs afs marked this pull request as draft June 8, 2026 10:58
@afs

afs commented Jun 8, 2026

Copy link
Copy Markdown
Member

@dependabot rebase

@dependabot @github

dependabot Bot commented on behalf of github Jun 8, 2026

Copy link
Copy Markdown
Contributor Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Jun 8, 2026
@dependabot dependabot Bot deleted the dependabot/maven/maven-patch-group-52fd5e174b branch June 8, 2026 14:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant