This is an automated email from the ASF dual-hosted git repository.

jbonofre pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/arrow-java.git


The following commit(s) were added to refs/heads/main by this push:
     new 915428751 MINOR: Bump logback.version from 1.5.34 to 1.5.37 (#1209)
915428751 is described below

commit 915428751b8871406268aeb27bd2f055dcfba6bf
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
AuthorDate: Mon Jul 6 16:00:46 2026 +0200

    MINOR: Bump logback.version from 1.5.34 to 1.5.37 (#1209)
    
    Bumps `logback.version` from 1.5.34 to 1.5.37.
    Updates `ch.qos.logback:logback-classic` from 1.5.34 to 1.5.37
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    
href="https://github.com/qos-ch/logback/releases";>ch.qos.logback:logback-classic's
    releases</a>.</em></p>
    <blockquote>
    <h2>Logback 1.5.37</h2>
    <p><strong>2026-06-26 Release of logback version 1.5.37</strong></p>
    <ol>
    <li>• Given the numerous vulnerabilities related to conditional
    configuration processing based on the evaluation of Java expressions
    using the Janino library, support for such expressions has been removed.
    Users are offered the an <a
    
href="https://logback.qos.ch/translator/services/conditionalConfigMigrator.html";>online
    migration service</a> or the <code>&lt;condition&gt;</code> element
    introduced in version 1.5.20. See the <a
    href="https://logback.qos.ch/manual/configuration.html#conditional";>relevant
    documentation</a> for more details.</li>
    </ol>
    <p>• A bitwise identical binary of this version can be reproduced by
    building from source code at commit
    c1df7f522e648eec7b4ef6a12c8758fec0f00048 associated with the tag
    v_1.5.37. Release built using Java &quot;21&quot; 2023-10-17 LTS build
    21.0.1.+12-LTS-29 under Linux Debian 11.6.</p>
    <h2>Logback 1.5.36</h2>
    <p><strong>2026-06-25 Release of logback version 1.5.36</strong></p>
    <p>• The 'condition' attribute in <code>&lt;if&gt;</code> elements now
    reject certain references that are associated with ACE attacks. This
    issue was reported by &quot;yulate&quot; (<a
    href="mailto:[email protected]";>[email protected]</a>) and
    registered as <a
    href="https://www.cve.org/cverecord?id=CVE-2026-13006";>CVE-2026-13006</a>.
    <strong>Please note that version 1.5.37 provides the full fix to this
    vulnerability.</strong></p>
    <p>• A bitwise identical binary of this version can be reproduced by
    building from source code at commit
    9b94c37562bf25a6a944146701d42ee6c4eee888 associated with the tag
    v_1.5.36. Release built using Java &quot;21&quot; 2023-10-17 LTS build
    21.0.1.+12-LTS-29 under Linux Debian 11.6.</p>
    <h2>Logback 1.5.35</h2>
    <p><strong>026-06-23 Release of logback version 1.5.35</strong></p>
    <p>• The 'condition' attribute in <code>&lt;if&gt;</code> elements now
    rejects unicode escape sequences (\u and \U). This closes a bypass of
    the existing prohibition on the new operator in Janino-evaluated
    conditions. This issue was reported by IcySun (<a
    href="mailto:[email protected]";>[email protected]</a>) and registered as <a
    href="https://www.cve.org/cverecord?id=CVE-2026-13006";>CVE-2026-13006</a>.
    <strong>Please note that version 1.5.37 provides the full fix to this
    vulnerability.</strong></p>
    <p>• Added <code>ConfiguratorRank.AUTHENTICATING</code> (rank 100), the
    highest configurator rank, for certified/authenticating configurators
    discovered via the ServiceLoader mechanism.
    <code>ContextInitializer</code> now requires that at most one such
    configurator exist on the classpath; if more than one is found,
    initialization aborts with an error.</p>
    <p>• <code>ConsoleCharsetPropertyDefiner</code> is no longer shipped.
    The Java 21 multi-release compilation of logback-core has been disabled,
    which removes this class from the published artifact. Configurations
    that referenced
    <code>ch.qos.logback.core.property.ConsoleCharsetPropertyDefiner</code>
    will need an alternative approach for console charset detection.</p>
    <p>• The logback-examples module is now included in artifacts published
    to Maven Central.</p>
    <p>• <code>JoranConfigurator.makeAnotherInstance()</code> and
    
<code>DefaultJoranConfigurator.performMultiStepConfigurationFileSearch()</code>
    are now protected, allowing derived configurators to override these
    methods.</p>
    <p>• A bitwise identical binary of this version can be reproduced by
    building from source code at commit
    08bd1598d565d83444f72983935e7da4746783b7 associated with the tag
    v_1.5.35. Release built using Java &quot;21&quot; 2023-10-17 LTS build
    21.0.1.+12-LTS-29 under Linux Debian 11.6.</p>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    
href="https://github.com/qos-ch/logback/commit/c1df7f522e648eec7b4ef6a12c8758fec0f00048";><code>c1df7f5</code></a>
    prepare release 1.5.37</li>
    <li><a
    
href="https://github.com/qos-ch/logback/commit/a1899674579c67711a4fff6bdc569f4bfb25ead5";><code>a189967</code></a>
    remove conditional based on janino</li>
    <li><a
    
href="https://github.com/qos-ch/logback/commit/aaa905292dc24235a0cd7514c4815d0eeb6c0446";><code>aaa9052</code></a>
    start work on 1.5.37-SNAPSHOT</li>
    <li><a
    
href="https://github.com/qos-ch/logback/commit/9b94c37562bf25a6a944146701d42ee6c4eee888";><code>9b94c37</code></a>
    prepare release 1.5.36</li>
    <li><a
    
href="https://github.com/qos-ch/logback/commit/e6a8280ba2c61a448226bccbced70444aaa6e7eb";><code>e6a8280</code></a>
    prevent attacks using disallowed references</li>
    <li><a
    
href="https://github.com/qos-ch/logback/commit/24c4b63f60e5bbfa591c20cf39f2ce50ff8cff4f";><code>24c4b63</code></a>
    start work on 1.5.36-SNAPSHOT</li>
    <li><a
    
href="https://github.com/qos-ch/logback/commit/08bd1598d565d83444f72983935e7da4746783b7";><code>08bd159</code></a>
    preapre release 1.5.35</li>
    <li><a
    
href="https://github.com/qos-ch/logback/commit/37d256b825fc62b4a3908fa29d8b4e34acf79ed0";><code>37d256b</code></a>
    indentation changes only</li>
    <li><a
    
href="https://github.com/qos-ch/logback/commit/d3d73078afbb0691423f60a066d77503fdf05fc3";><code>d3d7307</code></a>
    minor comment</li>
    <li><a
    
href="https://github.com/qos-ch/logback/commit/fa0411a9393282ba69396ce65f122d281c079ac0";><code>fa0411a</code></a>
    radomize file location</li>
    <li>Additional commits viewable in <a
    href="https://github.com/qos-ch/logback/compare/v_1.5.34...v_1.5.37";>compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    Updates `ch.qos.logback:logback-core` from 1.5.34 to 1.5.37
    <details>
    <summary>Release notes</summary>
    <p><em>Sourced from <a
    
href="https://github.com/qos-ch/logback/releases";>ch.qos.logback:logback-core's
    releases</a>.</em></p>
    <blockquote>
    <h2>Logback 1.5.37</h2>
    <p><strong>2026-06-26 Release of logback version 1.5.37</strong></p>
    <ol>
    <li>• Given the numerous vulnerabilities related to conditional
    configuration processing based on the evaluation of Java expressions
    using the Janino library, support for such expressions has been removed.
    Users are offered the an <a
    
href="https://logback.qos.ch/translator/services/conditionalConfigMigrator.html";>online
    migration service</a> or the <code>&lt;condition&gt;</code> element
    introduced in version 1.5.20. See the <a
    href="https://logback.qos.ch/manual/configuration.html#conditional";>relevant
    documentation</a> for more details.</li>
    </ol>
    <p>• A bitwise identical binary of this version can be reproduced by
    building from source code at commit
    c1df7f522e648eec7b4ef6a12c8758fec0f00048 associated with the tag
    v_1.5.37. Release built using Java &quot;21&quot; 2023-10-17 LTS build
    21.0.1.+12-LTS-29 under Linux Debian 11.6.</p>
    <h2>Logback 1.5.36</h2>
    <p><strong>2026-06-25 Release of logback version 1.5.36</strong></p>
    <p>• The 'condition' attribute in <code>&lt;if&gt;</code> elements now
    reject certain references that are associated with ACE attacks. This
    issue was reported by &quot;yulate&quot; (<a
    href="mailto:[email protected]";>[email protected]</a>) and
    registered as <a
    href="https://www.cve.org/cverecord?id=CVE-2026-13006";>CVE-2026-13006</a>.
    <strong>Please note that version 1.5.37 provides the full fix to this
    vulnerability.</strong></p>
    <p>• A bitwise identical binary of this version can be reproduced by
    building from source code at commit
    9b94c37562bf25a6a944146701d42ee6c4eee888 associated with the tag
    v_1.5.36. Release built using Java &quot;21&quot; 2023-10-17 LTS build
    21.0.1.+12-LTS-29 under Linux Debian 11.6.</p>
    <h2>Logback 1.5.35</h2>
    <p><strong>026-06-23 Release of logback version 1.5.35</strong></p>
    <p>• The 'condition' attribute in <code>&lt;if&gt;</code> elements now
    rejects unicode escape sequences (\u and \U). This closes a bypass of
    the existing prohibition on the new operator in Janino-evaluated
    conditions. This issue was reported by IcySun (<a
    href="mailto:[email protected]";>[email protected]</a>) and registered as <a
    href="https://www.cve.org/cverecord?id=CVE-2026-13006";>CVE-2026-13006</a>.
    <strong>Please note that version 1.5.37 provides the full fix to this
    vulnerability.</strong></p>
    <p>• Added <code>ConfiguratorRank.AUTHENTICATING</code> (rank 100), the
    highest configurator rank, for certified/authenticating configurators
    discovered via the ServiceLoader mechanism.
    <code>ContextInitializer</code> now requires that at most one such
    configurator exist on the classpath; if more than one is found,
    initialization aborts with an error.</p>
    <p>• <code>ConsoleCharsetPropertyDefiner</code> is no longer shipped.
    The Java 21 multi-release compilation of logback-core has been disabled,
    which removes this class from the published artifact. Configurations
    that referenced
    <code>ch.qos.logback.core.property.ConsoleCharsetPropertyDefiner</code>
    will need an alternative approach for console charset detection.</p>
    <p>• The logback-examples module is now included in artifacts published
    to Maven Central.</p>
    <p>• <code>JoranConfigurator.makeAnotherInstance()</code> and
    
<code>DefaultJoranConfigurator.performMultiStepConfigurationFileSearch()</code>
    are now protected, allowing derived configurators to override these
    methods.</p>
    <p>• A bitwise identical binary of this version can be reproduced by
    building from source code at commit
    08bd1598d565d83444f72983935e7da4746783b7 associated with the tag
    v_1.5.35. Release built using Java &quot;21&quot; 2023-10-17 LTS build
    21.0.1.+12-LTS-29 under Linux Debian 11.6.</p>
    </blockquote>
    </details>
    <details>
    <summary>Commits</summary>
    <ul>
    <li><a
    
href="https://github.com/qos-ch/logback/commit/c1df7f522e648eec7b4ef6a12c8758fec0f00048";><code>c1df7f5</code></a>
    prepare release 1.5.37</li>
    <li><a
    
href="https://github.com/qos-ch/logback/commit/a1899674579c67711a4fff6bdc569f4bfb25ead5";><code>a189967</code></a>
    remove conditional based on janino</li>
    <li><a
    
href="https://github.com/qos-ch/logback/commit/aaa905292dc24235a0cd7514c4815d0eeb6c0446";><code>aaa9052</code></a>
    start work on 1.5.37-SNAPSHOT</li>
    <li><a
    
href="https://github.com/qos-ch/logback/commit/9b94c37562bf25a6a944146701d42ee6c4eee888";><code>9b94c37</code></a>
    prepare release 1.5.36</li>
    <li><a
    
href="https://github.com/qos-ch/logback/commit/e6a8280ba2c61a448226bccbced70444aaa6e7eb";><code>e6a8280</code></a>
    prevent attacks using disallowed references</li>
    <li><a
    
href="https://github.com/qos-ch/logback/commit/24c4b63f60e5bbfa591c20cf39f2ce50ff8cff4f";><code>24c4b63</code></a>
    start work on 1.5.36-SNAPSHOT</li>
    <li><a
    
href="https://github.com/qos-ch/logback/commit/08bd1598d565d83444f72983935e7da4746783b7";><code>08bd159</code></a>
    preapre release 1.5.35</li>
    <li><a
    
href="https://github.com/qos-ch/logback/commit/37d256b825fc62b4a3908fa29d8b4e34acf79ed0";><code>37d256b</code></a>
    indentation changes only</li>
    <li><a
    
href="https://github.com/qos-ch/logback/commit/d3d73078afbb0691423f60a066d77503fdf05fc3";><code>d3d7307</code></a>
    minor comment</li>
    <li><a
    
href="https://github.com/qos-ch/logback/commit/fa0411a9393282ba69396ce65f122d281c079ac0";><code>fa0411a</code></a>
    radomize file location</li>
    <li>Additional commits viewable in <a
    href="https://github.com/qos-ch/logback/compare/v_1.5.34...v_1.5.37";>compare
    view</a></li>
    </ul>
    </details>
    <br />
    
    
    Dependabot will resolve any conflicts with this PR as long as you don't
    alter it yourself. You can also trigger a rebase manually by commenting
    `@dependabot rebase`.
    
    [//]: # (dependabot-automerge-start)
    [//]: # (dependabot-automerge-end)
    
    ---
    
    <details>
    <summary>Dependabot commands and options</summary>
    <br />
    
    You can trigger Dependabot actions by commenting on this PR:
    - `@dependabot rebase` will rebase this PR
    - `@dependabot recreate` will recreate this PR, overwriting any edits
    that have been made to it
    - `@dependabot show <dependency name> ignore conditions` will show all
    of the ignore conditions of the specified dependency
    - `@dependabot ignore this major version` will close this PR and stop
    Dependabot creating any more for this major version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this minor version` will close this PR and stop
    Dependabot creating any more for this minor version (unless you reopen
    the PR or upgrade to it yourself)
    - `@dependabot ignore this dependency` will close this PR and stop
    Dependabot creating any more for this dependency (unless you reopen the
    PR or upgrade to it yourself)
    
    
    </details>
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] 
<49699333+dependabot[bot]@users.noreply.github.com>
    Co-authored-by: JB Onofré <[email protected]>
---
 pom.xml | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/pom.xml b/pom.xml
index d9f9d59c4..78137eb4e 100644
--- a/pom.xml
+++ b/pom.xml
@@ -113,7 +113,7 @@ under the License.
     <checkstyle.failOnViolation>true</checkstyle.failOnViolation>
     <error_prone_core.version>2.42.0</error_prone_core.version>
     <checker.framework.version>4.2.1</checker.framework.version>
-    <logback.version>1.5.34</logback.version>
+    <logback.version>1.5.37</logback.version>
     <doclint>none</doclint>
     <additionalparam>-Xdoclint:none</additionalparam>
     <!-- List of add-opens arg line arguments for tests -->

Reply via email to