chore(deps): bump the low-risk group across 1 directory with 8 updates#357
Merged
RichardSlater merged 1 commit intomainfrom Apr 29, 2026
Merged
Conversation
Bumps the low-risk group with 8 updates in the / directory: | Package | From | To | | --- | --- | --- | | [org.projectlombok:lombok](https://github.com/projectlombok/lombok) | `1.18.44` | `1.18.46` | | [nl.jqno.equalsverifier:equalsverifier](https://github.com/jqno/equalsverifier) | `4.4.2` | `4.5` | | [io.projectreactor:reactor-bom](https://github.com/reactor/reactor) | `2025.0.4` | `2025.0.5` | | [org.springframework.boot:spring-boot-dependencies](https://github.com/spring-projects/spring-boot) | `3.5.13` | `3.5.14` | | [io.projectreactor.netty:reactor-netty-core](https://github.com/reactor/reactor-netty) | `1.3.4` | `1.3.5` | | [org.pitest:pitest-parent](https://github.com/hcoles/pitest) | `1.23.0` | `1.23.1` | | [org.pitest:pitest-maven](https://github.com/hcoles/pitest) | `1.23.0` | `1.23.1` | | [com.google.code.gson:gson](https://github.com/google/gson) | `2.13.2` | `2.14.0` | Updates `org.projectlombok:lombok` from 1.18.44 to 1.18.46 - [Changelog](https://github.com/projectlombok/lombok/blob/master/doc/changelog.markdown) - [Commits](projectlombok/lombok@v1.18.44...v1.18.46) Updates `nl.jqno.equalsverifier:equalsverifier` from 4.4.2 to 4.5 - [Release notes](https://github.com/jqno/equalsverifier/releases) - [Changelog](https://github.com/jqno/equalsverifier/blob/main/CHANGELOG.md) - [Commits](jqno/equalsverifier@equalsverifier-4.4.2...equalsverifier-4.5) Updates `io.projectreactor:reactor-bom` from 2025.0.4 to 2025.0.5 - [Release notes](https://github.com/reactor/reactor/releases) - [Commits](reactor/reactor@2025.0.4...2025.0.5) Updates `org.springframework.boot:spring-boot-dependencies` from 3.5.13 to 3.5.14 - [Release notes](https://github.com/spring-projects/spring-boot/releases) - [Commits](spring-projects/spring-boot@v3.5.13...v3.5.14) Updates `io.projectreactor.netty:reactor-netty-core` from 1.3.4 to 1.3.5 - [Release notes](https://github.com/reactor/reactor-netty/releases) - [Commits](reactor/reactor-netty@v1.3.4...v1.3.5) Updates `org.pitest:pitest-parent` from 1.23.0 to 1.23.1 - [Release notes](https://github.com/hcoles/pitest/releases) - [Commits](hcoles/pitest@1.23.0...1.23.1) Updates `org.pitest:pitest-maven` from 1.23.0 to 1.23.1 - [Release notes](https://github.com/hcoles/pitest/releases) - [Commits](hcoles/pitest@1.23.0...1.23.1) Updates `com.google.code.gson:gson` from 2.13.2 to 2.14.0 - [Release notes](https://github.com/google/gson/releases) - [Changelog](https://github.com/google/gson/blob/main/CHANGELOG.md) - [Commits](google/gson@gson-parent-2.13.2...gson-parent-2.14.0) Updates `org.pitest:pitest-maven` from 1.23.0 to 1.23.1 - [Release notes](https://github.com/hcoles/pitest/releases) - [Commits](hcoles/pitest@1.23.0...1.23.1) --- updated-dependencies: - dependency-name: org.projectlombok:lombok dependency-version: 1.18.46 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: low-risk - dependency-name: nl.jqno.equalsverifier:equalsverifier dependency-version: '4.5' dependency-type: direct:development update-type: version-update:semver-minor dependency-group: low-risk - dependency-name: io.projectreactor:reactor-bom dependency-version: 2025.0.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: low-risk - dependency-name: org.springframework.boot:spring-boot-dependencies dependency-version: 3.5.14 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: low-risk - dependency-name: io.projectreactor.netty:reactor-netty-core dependency-version: 1.3.5 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: low-risk - dependency-name: org.pitest:pitest-parent dependency-version: 1.23.1 dependency-type: direct:production update-type: version-update:semver-patch dependency-group: low-risk - dependency-name: org.pitest:pitest-maven dependency-version: 1.23.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: low-risk - dependency-name: com.google.code.gson:gson dependency-version: 2.14.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: low-risk - dependency-name: org.pitest:pitest-maven dependency-version: 1.23.1 dependency-type: direct:development update-type: version-update:semver-patch dependency-group: low-risk ... Signed-off-by: dependabot[bot] <support@github.com>
Contributor
|
/azp run |
|
Azure Pipelines successfully started running 1 pipeline(s). |
|
RichardSlater
approved these changes
Apr 29, 2026
Contributor
RichardSlater
left a comment
There was a problem hiding this comment.
Patch bump, standard pre-approved change.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.



Bumps the low-risk group with 8 updates in the / directory:
1.18.441.18.464.4.24.52025.0.42025.0.53.5.133.5.141.3.41.3.51.23.01.23.11.23.01.23.12.13.22.14.0Updates
org.projectlombok:lombokfrom 1.18.44 to 1.18.46Changelog
Sourced from org.projectlombok:lombok's changelog.
Commits
936ca59[build] lombok's launcher is still intended to be 1.4 compatible, or at least...fcdab3f[version] pre-release version bump1cb7d49[changelog]#4004 Mention Jackson3 final touches in changelog.12a15b0Fix: Bump EA_JDK to 27 (25 and 26 have been released)2be766cMerge branch 'jackson3-final-touches'290fa4c[trivial] constantize the warning we spit out for ambiguous jackson2/3, and m...e6567b6test: Add Jackson 3 test cases and version ambiguity warnings45e72e2feat: Add Jackson 3 databind/dataformat annotations to HandlerUtil copy lists184d423feat: Add Jackson 3 support to@Jacksonizedhandlerse027ad0refactored to ShadowClassLoader use Collections::enumeration instead of VectorUpdates
nl.jqno.equalsverifier:equalsverifierfrom 4.4.2 to 4.5Release notes
Sourced from nl.jqno.equalsverifier:equalsverifier's releases.
Changelog
Sourced from nl.jqno.equalsverifier:equalsverifier's changelog.
Commits
3f72cbcBumps version to 4.5abd5aa9Updates CHANGELOG for release04f89c1Merge pull request #1204 from jqno/add-url-fieldcheckffc7f03Streamlines UrlTeste9cf3beAdds URL FieldCheck472e8b1Update copyright year in README.md94ebdf6Merge pull request #1202 from jqno/vendors-signedjar-test8d6327dExcludes equalsverifier-test-signedjar from PITest coverage7b828dcAll signed-jar tests should run via failsafe so it runs through the actual ja...377c217Incorporates SignedJarTest from separate repositoryUpdates
io.projectreactor:reactor-bomfrom 2025.0.4 to 2025.0.5Release notes
Sourced from io.projectreactor:reactor-bom's releases.
Commits
23647bf[release] Prepare and release BOM 2025.0.5a06b97cMerge-ignore release 2024.0.17 into 2025.0.55d94ca6[release] Back to snapshots, next BOM will be SR 182f52f4a[release] Prepare and release BOM 2024.0.17e68d8adMerge bbbf5d86 into 2025.0.5bbbf5d8Fix Gradle deprecation warnings scheduled for removal in Gradle 101e8ee7cMerge #777 into 2025.0.5997c971Bump gradle-wrapper from 9.4.0 to 9.4.1 (#777)ba97cffRemove dependabot ignore configurationb8cb92aMerge 5e94cb91 into 2025.0.5Updates
org.springframework.boot:spring-boot-dependenciesfrom 3.5.13 to 3.5.14Release notes
Sourced from org.springframework.boot:spring-boot-dependencies's releases.
... (truncated)
Commits
7d7b3acRelease v3.5.149dc5aa2Polishf533a45Do not follow symlinks when writing PID filef3b8eb0Use SecureRandom in RandomValuePropertySourcee22083aEnable hostname verification for SSL connections to Cassandra5ceb1a2Improve ApplicationTemp's temporary directory creation4b0862cUse constant-time comparison for remote DevTools secrete4febe2Apply verify-hostname consistently2c2ffe5Fix Windows test failure0046a44Protect against corrupt buildpack archivesUpdates
io.projectreactor.netty:reactor-netty-corefrom 1.3.4 to 1.3.5Release notes
Sourced from io.projectreactor.netty:reactor-netty-core's releases.
Commits
b68daca[release] Prepare and release 1.3.5f8fc51bMerge-ignore release 1.2.17 into 1.3.54cffaf0[release] Back to snapshots, next is 1.2.18-SNAPSHOT3f6ae4cDefer asciidoctor-pdf check to execution time9f6f3e0[release] Prepare and release 1.2.177b2c429Merge #4190 into 1.3.56225c6dBump ruby/setup-ruby from 1.299.0 to 1.301.0 (#4190)f4f9b50Bump org.bouncycastle:bcpkix-jdk18on from 1.83 to 1.84 (#4191)5b344dcMerge #4187 into 1.3.5e177f39Bump@springio/antora-extensionsfrom 1.14.10 to 1.14.11 in /docs (#4187)Updates
org.pitest:pitest-parentfrom 1.23.0 to 1.23.1Release notes
Sourced from org.pitest:pitest-parent's releases.
Commits
97b4bc4Merge pull request #1463 from hcoles/feature/extend_unmofiable_filter9f93c02filter unmodifiable Map.copyOf43be4cffilter unmodifiable Collections.singletonaa42551add support link to reportf2ec3b2add funding infoUpdates
org.pitest:pitest-mavenfrom 1.23.0 to 1.23.1Release notes
Sourced from org.pitest:pitest-maven's releases.
Commits
97b4bc4Merge pull request #1463 from hcoles/feature/extend_unmofiable_filter9f93c02filter unmodifiable Map.copyOf43be4cffilter unmodifiable Collections.singletonaa42551add support link to reportf2ec3b2add funding infoUpdates
com.google.code.gson:gsonfrom 2.13.2 to 2.14.0Release notes
Sourced from com.google.code.gson:gson's releases.
Commits
3ff35d6[maven-release-plugin] prepare release gson-parent-2.14.0a3024fdBump the maven group with 13 updates (#3002)5689ffeBump the github-actions group across 1 directory with 3 updates (#3018)48db33cAddLegacyProtoTypeAdapterFactory. (#3014)53d703eUpdate outdated comment regarding serializable types (#3012)0189b72RemoveSerializablefrom internalTypeimplementation classes. (#3011)f4d371dFix duplicate key detection when first value is null (#3006)27d9ba1Fix typo in README (JPMS dependencies section) (#3005)1fa9b7aValidate that strings being parsed as integers consist of ASCII characters (#...b7d5954Add iterator fail-fast tests for LinkedTreeMap.clear() (#2992)Updates
org.pitest:pitest-mavenfrom 1.23.0 to 1.23.1Release notes
Sourced from org.pitest:pitest-maven's releases.
Commits
97b4bc4Merge pull request #1463 from hcoles/feature/extend_unmofiable_filter9f93c02filter unmodifiable Map.copyOf43be4cffilter unmodifiable Collections.singletonaa42551add support link to reportf2ec3b2add funding infoMost Recent Ignore Conditions Applied to This Pull Request
You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore <dependency name> major versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)@dependabot ignore <dependency name> minor versionwill close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)@dependabot ignore <dependency name>will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)@dependabot unignore <dependency name>will remove all of the ignore conditions of the specified dependency@dependabot unignore <dependency name> <ignore condition>will remove the ignore condition of the specified dependency and ignore conditions