Skip to content

[CORE-69]: Bump the minor-and-patch-updates group with 4 updates - #146

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/minor-and-patch-updates-c8183f0efc
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/minor-and-patch-updates-c8183f0efc

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch-updates group with 4 updates: ch.qos.logback:logback-classic, com.fasterxml.jackson.core:jackson-databind, com.diffplug.spotless:spotless-plugin-gradle and gradle-wrapper.

Updates ch.qos.logback:logback-classic from 1.6.3 to 1.6.4

Release notes

Sourced from ch.qos.logback:logback-classic's releases.

Logback 1.6.4

2026-09-24 Release of logback version 1.6.4

• Variable substitution is again applied to the scan attribute of the <configuration> element. The scanning refactoring in version 1.5.27 had dropped substitution, so values such as ${logback.scan.enabled:-true} were no longer resolved. As before version 1.5.27, an unrecognized non-empty value turns scanning on. The same substitution now applies to the scan attribute of <propertiesConfigurator>. This regression was reported in issues/1065 by vaibhavjain2.

• OutputStreamAppender and FileAppender now handle stateful encoders. The Encoder interface has a new default method called isStateful(), which returns false. An encoder that keeps state between calls to encode() can return true. For such encoders, the appender holds its write lock while encoding and while writing, so the output of concurrent appends cannot interleave. Stateless encoders still encode outside the lock, so their performance does not change. Existing encoders need no changes.

• Several race conditions in OutputStreamAppender and FileAppender were fixed. The appender is now marked started and the encoder header is written while the same lock is held, so a concurrent append can no longer write an event before the header. After acquiring the lock, the appender checks again whether it has been stopped, so no event is written after the footer. In prudent mode, FileAppender now encodes and writes each event while holding the lock.

• Fixed a data race on the logger count in LoggerContext. Loggers are created under the lock of their parent logger, so loggers with different parents could be created at the same time and increments of the shared counter could be lost. As a result, LoggerContext.size() could return a value lower than the actual number of loggers. The counter is now an AtomicInteger. This issue was reported in issues/1038 by hcantunc. The fix was contributed in PR #1055 by seonwoo_jung.

• TimeBasedRollingPolicy now supports half-day periods. Date patterns with the AM/PM marker, for example %d{yyyy-MM-dd-a}, used to be detected as daily and rolled over only at midnight. They now roll over at both 00:00 and 12:00. This issue was reported in issues/976 by shakthifuture. The fix was contributed in PR #1051 by seonwoo_jung. See TimeBasedRollingPolicy.

• If org.jline.jansi.AnsiConsole cannot be found on the class path, JansiConsoleAppender now emits warnings that explain how to add org.jline:jansi-core and then writes to the plain console stream. See codes.html#missingJlineJansi.

• The unused ch.qos.logback.classic.util.LogbackMDCAdapterSimple class was removed. LogbackMDCAdapter remains the default MDC adapter.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit 07d291ca0d280bc5da934ec9ff5f1da634fd7937 associated with the tag v_1.6.4. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Full Changelog: qos-ch/logback@v_1.6.3...v_1.6.4

Commits
  • 07d291c preapre release 1.6.4
  • 9627daf revert to Collections.unmodifiableMap instead of
  • aa42fb5 disabled RollingCalendarTest#testVaryingNumberOfHalfDailyPeriods to shave off...
  • ddc7459 Support HALF_DAY periodicity for AM/PM date patterns
  • 42d75d7 disable LoggerContextTest#concurrentGetLoggerKeepsSizeConsistent to shave exe...
  • bffd55e add warnings about missing jline.jansi classes
  • 8de0b9b Fix data race on LoggerContext.size (#1038)
  • 76c73d1 add MinimalUnmodifiableMap and return it in LogbackMDCAdapter#getPropertyMap
  • a2c416a Fix formatting of email instruction in README
  • 2c89727 mailing lists have been deactivated
  • Additional commits viewable in compare view

Updates com.fasterxml.jackson.core:jackson-databind from 2.22.2 to 2.22.3

Commits
  • 4385c5f [maven-release-plugin] prepare release jackson-databind-2.22.3
  • ccb4fd0 Prep for 2.22.3 release
  • 2958412 Merge branch '2.21' into 2.22
  • 1215b94 Post-release dep version bump
  • 1f0df62 [maven-release-plugin] prepare for next development iteration
  • 13a9ff4 [maven-release-plugin] prepare release jackson-databind-2.21.7
  • d168f96 Prep for 2.21.7 release
  • eaf5c76 Merge branch '2.21' into 2.22
  • e05ef4c Merge branch '2.20' into 2.21
  • f6d4000 Merge branch '2.19' into 2.20
  • Additional commits viewable in compare view

Updates com.diffplug.spotless:spotless-plugin-gradle from 8.10.2 to 8.10.3

Release notes

Sourced from com.diffplug.spotless:spotless-plugin-gradle's releases.

Gradle Plugin v8.10.3

Changes

  • Generate formatter defaults from version catalog. (#3045)
  • Bump default gson version 2.13.2 -> 2.14.0. (#3045)
  • Bump default zjsonpatch version 0.4.14 -> 0.4.16. (#3045)
  • Bump default jackson-dataformat-yaml version 2.14.1 -> 2.20.1. (#3045)
  • Bump default ktfmt version 0.63 -> 0.64. (2988)
  • Bump default cleanthat version 2.25 -> 2.26. (#2882)
  • Bump default jackson version 2.20.1 -> 2.22.2. (#2819)
  • Bump default javaparser version 3.27.1 -> 3.28.2. (#3065)
  • Bump default palantir-java-format version 2.80.0 -> 2.98.0. (#3068)
  • Bump default scalafmt version 3.8.1 -> 3.11.5. (#2173)
  • Bump default google-java-format version 1.30.0 -> 1.36.1. (#3075)
  • Bump default gherkin-utils version 10.0.0 -> 12.0.2. (#2979)
  • We no longer publish a plugin marker for the legacy com.diffplug.gradle.spotless id, which has been redirecting to com.diffplug.spotless since 4.0. Builds that still request it now fail with Plugin [id: 'com.diffplug.gradle.spotless'] was not found instead of the migration message. (#3086)

Fixed

  • Fix release signing by using Gradle's required eight-digit signing subkey ID. (#3105)
  • Fix race when creating the npm install cache directory. ((#3096)
  • GrEclipse no longer emits expected OSGi and nested-jar warnings during initialization. (#2445)
  • typescript prettier() no longer emits a warning when its parser is already set to typescript. (#3098)
  • versionCatalog() preserves standalone comments at section boundaries and the end of the file. (#3048)
  • versionCatalog() preserves entries when comments contain unmatched brackets, preserves commas inside quoted strings, and keeps significant line boundaries in multiline entries. (#3042)
  • versionCatalog() now reports unfinished entries as lints at their starting line. These fail formatting by default, so upgrading may expose catalog errors that previously caused silent data loss. (#3042)
  • Stop calling deprecated Configuration.setVisible from Gradle 9.0.0 (#3053)
  • Eclipse JDT formatter step no longer fails with NoClassDefFoundError or NoSuchMethodError when lombok is active as a JVM agent (e.g. -javaagent:lombok.jar in Eclipse/VS Code/Cursor). (#2795)
Commits
  • eae36d8 Published gradle/8.10.3
  • 61e2016 Published maven/3.10.3
  • 49e0b07 Published lib/4.10.3
  • b7a7748 Fix release signing key ID format (#3105)
  • be8005a Document release signing correction (#3105)
  • 073fe61 Use short signing subkey ID for release publishing
  • 8ac44c7 Fix race when creating the npm install cache directory (#3096)
  • 3f2d955 Update dependency org.slf4j:slf4j-api to v2.0.20 (#3100)
  • 0c70ca8 Merge branch 'main' into fix/npm-cache-directory-race
  • bbf44a4 Fix GrEclipse initialization warnings (#3097)
  • Additional commits viewable in compare view

Updates gradle-wrapper from 9.7.1 to 9.8.0

Release notes

Sourced from gradle-wrapper's releases.

9.8.0

The Gradle team is excited to announce Gradle 9.8.0.

Here are the highlights of this release:

  • Java 27 support
  • Maven mirror settings reuse
  • Linked problem locations in build output

Read the Release Notes

We would like to thank the following community members for their contributions to this release of Gradle: Aman Gautam, Björn Kautler, Eng Zer Jun, Hashim Khan, Julian Krannich, KBS, Labh R Jethe, Mark Dodgson, Maxim, monkey, nataphon-ktsystems, Paul King, Qiu Tian, rg_sandesh, Roberto Perez Alcolea, Sean, Zongle Wang.

Upgrade instructions

Switch your build to use Gradle 9.8.0 by updating your wrapper:

./gradlew :wrapper --gradle-version=9.8.0 && ./gradlew :wrapper

See the Gradle 9.x upgrade guide to learn about deprecations, breaking changes and other considerations when upgrading.

For Java, Groovy, Kotlin and Android compatibility, see the full compatibility notes.

Reporting problems

If you find a problem with this release, please file a bug on GitHub Issues adhering to our issue guidelines. If you're not sure you're encountering a bug, please use the forum.

We hope you will build happiness with Gradle, and we look forward to your feedback via Twitter or on GitHub.

9.8.0 RC3

The Gradle team is excited to announce Gradle 9.8.0 RC3.

Here are the highlights of this release:

... (truncated)

Commits
  • a927be5 Add the Develocity plugin back to the Android smoke tests (#39273)
  • eaee500 Add the Develocity plugin back to the Android smoke tests
  • 189b672 Route everything still hitting Maven Central through the mirror (#39257)
  • 36b1814 Add back mavenCentral to doc snippets
  • 2740c2d Update Gradle wrapper to version 9.8.0-rc-3 (#39264)
  • 2099383 Update Gradle wrapper to version 9.8.0-rc-3
  • c80202f Route everything still hitting Maven Central through the mirror
  • 3f6a534 Fix when a best practice was introduced (#39253)
  • 9efc9ed Fix when a best practice was introduced
  • 459e143 Route integration test dependencies through the repository mirror (#39239)
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the minor-and-patch-updates group with 4 updates: [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback), [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind), [com.diffplug.spotless:spotless-plugin-gradle](https://github.com/diffplug/spotless) and [gradle-wrapper](https://github.com/gradle/gradle).


Updates `ch.qos.logback:logback-classic` from 1.6.3 to 1.6.4
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.6.3...v_1.6.4)

Updates `com.fasterxml.jackson.core:jackson-databind` from 2.22.2 to 2.22.3
- [Commits](FasterXML/jackson-databind@jackson-databind-2.22.2...jackson-databind-2.22.3)

Updates `com.diffplug.spotless:spotless-plugin-gradle` from 8.10.2 to 8.10.3
- [Release notes](https://github.com/diffplug/spotless/releases)
- [Changelog](https://github.com/diffplug/spotless/blob/main/CHANGES.md)
- [Commits](diffplug/spotless@gradle/8.10.2...gradle/8.10.3)

Updates `gradle-wrapper` from 9.7.1 to 9.8.0
- [Release notes](https://github.com/gradle/gradle/releases)
- [Commits](gradle/gradle@v9.7.1...v9.8.0)

---
updated-dependencies:
- dependency-name: ch.qos.logback:logback-classic
  dependency-version: 1.6.4
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch-updates
- dependency-name: com.fasterxml.jackson.core:jackson-databind
  dependency-version: 2.22.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch-updates
- dependency-name: com.diffplug.spotless:spotless-plugin-gradle
  dependency-version: 8.10.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch-updates
- dependency-name: gradle-wrapper
  dependency-version: 9.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Dependency Update gradle Gradle dependency updates labels Oct 1, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner October 1, 2026 12:04
@dependabot
dependabot Bot requested review from davidangb and snf2ye October 1, 2026 12:04
@dependabot dependabot Bot added dependencies Dependency Update gradle Gradle dependency updates labels Oct 1, 2026
@sonarqubecloud

sonarqubecloud Bot commented Oct 1, 2026

Copy link
Copy Markdown

@sonarqubecloud

sonarqubecloud Bot commented Oct 1, 2026

Copy link
Copy Markdown

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency Update gradle Gradle dependency updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants