dependabot[bot] opened a new pull request, #2895: URL: https://github.com/apache/shiro/pull/2895
Bumps the maven-dependencies group with 8 updates: | Package | From | To | | --- | --- | --- | | [org.apache:apache](https://github.com/apache/maven-apache-parent) | `39` | `40` | | [org.apache.groovy:groovy-all](https://github.com/apache/groovy) | `5.1.2` | `6.0.0` | | [org.apache.groovy:groovy](https://github.com/apache/groovy) | `5.1.2` | `6.0.0` | | [net.bytebuddy:byte-buddy](https://github.com/raphw/byte-buddy) | `1.18.13` | `1.18.14` | | [net.bytebuddy:byte-buddy-agent](https://github.com/raphw/byte-buddy) | `1.18.13` | `1.18.14` | | [org.hibernate.orm:hibernate-core](https://github.com/hibernate/hibernate-orm) | `7.4.7.Final` | `7.4.9.Final` | | org.apache.felix:maven-bundle-plugin | `6.1.2` | `6.2.0` | | [fish.payara.extras:payara-micro](https://github.com/payara/payara) | `7.2026.8` | `7.2026.9` | Updates `org.apache:apache` from 39 to 40 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/apache/maven-apache-parent/releases">org.apache:apache's releases</a>.</em></p> <blockquote> <h2>40</h2> <!-- raw HTML omitted --> <h2>:boom: Breaking changes</h2> <ul> <li>Replace nicoulaj checksum plugin with maveniverse checksum plugin (<a href="https://redirect.github.com/apache/maven-apache-parent/pull/599">#599</a>) <a href="https://github.com/slawekjaranowski"><code>@slawekjaranowski</code></a></li> <li><a href="https://redirect.github.com/apache/maven-apache-parent/issues/586">#586</a>: Use RAT0.18 and remove commons-lang3 configuration for JDK25 (<a href="https://redirect.github.com/apache/maven-apache-parent/pull/587">#587</a>) <a href="https://github.com/ottlinger"><code>@ottlinger</code></a></li> <li>Property <code>version.maven-surefire</code> was removed in <a href="https://redirect.github.com/apache/maven-apache-parent/pull/588">apache/maven-apache-parent#588</a>, should be replaced by <code>version.maven-surefire-plugin</code>, <code>version.maven-failsafe-plugin</code> or <code>version.maven-surefire-report-plugin</code></li> </ul> <h2>🚀 New features and improvements</h2> <ul> <li>Fix several version property issues (<a href="https://redirect.github.com/apache/maven-apache-parent/pull/588">#588</a>) <a href="https://github.com/ctubbsii"><code>@ctubbsii</code></a></li> </ul> <h2>📝 Documentation updates</h2> <ul> <li>Update documentation for push-to-atr profile (<a href="https://redirect.github.com/apache/maven-apache-parent/pull/613">#613</a>) <a href="https://github.com/slawekjaranowski"><code>@slawekjaranowski</code></a></li> <li>Restore the common wording on the download page (<a href="https://redirect.github.com/apache/maven-apache-parent/pull/596">#596</a>) <a href="https://github.com/slachiewicz"><code>@slachiewicz</code></a></li> </ul> <h2>👻 Maintenance</h2> <ul> <li>Add local maven configuration for ATR project name override (<a href="https://redirect.github.com/apache/maven-apache-parent/pull/614">#614</a>) <a href="https://github.com/slawekjaranowski"><code>@slawekjaranowski</code></a></li> <li>Remove custom name-template for release-drafter (<a href="https://redirect.github.com/apache/maven-apache-parent/pull/604">#604</a>) <a href="https://github.com/slawekjaranowski"><code>@slawekjaranowski</code></a></li> <li>Port the site documentation from APT to Markdown (<a href="https://redirect.github.com/apache/maven-apache-parent/pull/595">#595</a>) <a href="https://github.com/slachiewicz"><code>@slachiewicz</code></a></li> </ul> <h2>📦 Dependency updates</h2> <ul> <li>Bump org.apache.maven.plugins:maven-deploy-plugin from 3.1.4 to 3.2.0 (<a href="https://redirect.github.com/apache/maven-apache-parent/pull/612">#612</a>) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li> <li>Bump org.apache.maven.plugins:maven-install-plugin from 3.1.4 to 3.2.0 (<a href="https://redirect.github.com/apache/maven-apache-parent/pull/611">#611</a>) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li> <li>Bump org.apache.maven.plugins:maven-plugin-tools from 3.15.2 to 3.16.0 (<a href="https://redirect.github.com/apache/maven-apache-parent/pull/610">#610</a>) <a href="https://github.com/slawekjaranowski"><code>@slawekjaranowski</code></a></li> <li>Bump surefire-plugin, failsafe-plugin, surefire-report-plugin from 3.5.6 to 3.6.0 (<a href="https://redirect.github.com/apache/maven-apache-parent/pull/605">#605</a>) <a href="https://github.com/slawekjaranowski"><code>@slawekjaranowski</code></a></li> <li>Bump org.apache.tooling:atr-maven-plugin from 1.0.0-alpha-1 to 1.0.0-beta-1 (<a href="https://redirect.github.com/apache/maven-apache-parent/pull/598">#598</a>) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li> <li>Bump org.apache.maven.plugins:maven-compiler-plugin from 3.15.0 to 3.16.0 (<a href="https://redirect.github.com/apache/maven-apache-parent/pull/600">#600</a>) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li> <li><a href="https://redirect.github.com/apache/maven-apache-parent/issues/586">#586</a>: Use RAT0.18 and remove commons-lang3 configuration for JDK25 (<a href="https://redirect.github.com/apache/maven-apache-parent/pull/587">#587</a>) <a href="https://github.com/ottlinger"><code>@ottlinger</code></a></li> <li>Bump org.apache.maven.plugins:maven-jar-plugin from 3.5.0 to 3.5.1 (<a href="https://redirect.github.com/apache/maven-apache-parent/pull/594">#594</a>) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li> <li>Bump apache/maven-gh-actions-shared/.github/workflows/release-drafter.yml from 4 to 5 (<a href="https://redirect.github.com/apache/maven-apache-parent/pull/591">#591</a>) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li> <li>Bump apache/maven-gh-actions-shared/.github/workflows/pr-automation.yml from 4 to 5 (<a href="https://redirect.github.com/apache/maven-apache-parent/pull/593">#593</a>) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li> <li>Bump apache/maven-gh-actions-shared/.github/workflows/stale.yml from 4 to 5 (<a href="https://redirect.github.com/apache/maven-apache-parent/pull/592">#592</a>) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li> <li>Bump apache/maven-gh-actions-shared/.github/workflows/maven-verify.yml from 4 to 5 (<a href="https://redirect.github.com/apache/maven-apache-parent/pull/590">#590</a>) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li> <li>Bump org.apache.maven.plugins:maven-help-plugin from 3.5.1 to 3.5.2 (<a href="https://redirect.github.com/apache/maven-apache-parent/pull/589">#589</a>) @<a href="https://github.com/apps/dependabot">dependabot[bot]</a></li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/apache/maven-apache-parent/commits">compare view</a></li> </ul> </details> <br /> Updates `org.apache.groovy:groovy-all` from 5.1.2 to 6.0.0 <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/apache/groovy/commits">compare view</a></li> </ul> </details> <br /> Updates `org.apache.groovy:groovy` from 5.1.2 to 6.0.0 <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/apache/groovy/commits">compare view</a></li> </ul> </details> <br /> Updates `org.apache.groovy:groovy` from 5.1.2 to 6.0.0 <details> <summary>Commits</summary> <ul> <li>See full diff in <a href="https://github.com/apache/groovy/commits">compare view</a></li> </ul> </details> <br /> Updates `net.bytebuddy:byte-buddy` from 1.18.13 to 1.18.14 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/raphw/byte-buddy/releases">net.bytebuddy:byte-buddy's releases</a>.</em></p> <blockquote> <h2>Byte Buddy 1.18.14</h2> <ul> <li>Avoid exposure of the agent argument on the command line of the process that is spawned for an external attachment.</li> <li>Avoid the resolution of symbolic links when the Gradle plugin deletes a folder recursively.</li> <li>Limit the nesting depth that is accepted when parsing a generic type signature to avoid an exhaustion of the stack for a malformed class file.</li> <li>Sign all deployed files using sigstore, in addition to the existing GPG signature.</li> <li>Validate entry names when the Android plugin retains a file to avoid the propagation of path traversals.</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/raphw/byte-buddy/blob/master/release-notes.md">net.bytebuddy:byte-buddy's changelog</a>.</em></p> <blockquote> <h3>14. September 2026: version 1.18.14</h3> <ul> <li>Avoid exposure of the agent argument on the command line of the process that is spawned for an external attachment.</li> <li>Avoid the resolution of symbolic links when the Gradle plugin deletes a folder recursively.</li> <li>Limit the nesting depth that is accepted when parsing a generic type signature to avoid an exhaustion of the stack for a malformed class file.</li> <li>Sign all deployed files using sigstore, in addition to the existing GPG signature.</li> <li>Validate entry names when the Android plugin retains a file to avoid the propagation of path traversals.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/raphw/byte-buddy/commit/92846cb0fa3480ed6e0fc41803e8e74f52070c59"><code>92846cb</code></a> [publish] Releasing Byte Buddy 1.18.14</li> <li><a href="https://github.com/raphw/byte-buddy/commit/a8a9f14e225f87477f65251db17f475895d73369"><code>a8a9f14</code></a> [release] Release new version</li> <li><a href="https://github.com/raphw/byte-buddy/commit/b0fe0066a8ea4f9316aa2a06906c87c0f529ddcd"><code>b0fe006</code></a> Skip the signature creation for artifacts that are not deployed.</li> <li><a href="https://github.com/raphw/byte-buddy/commit/c6107833a61e389719b56623fc36e3e476442e11"><code>c610783</code></a> Resolve the signed POM file by the path of the project file.</li> <li><a href="https://github.com/raphw/byte-buddy/commit/caab321964c9da0e0620fc0ff931413629ecf0b3"><code>caab321</code></a> Sign the deployed POM file and allow for a sigstore dry run.</li> <li><a href="https://github.com/raphw/byte-buddy/commit/c68a9c1761bc3fcda4d942ac7cc3a9e58a200e78"><code>c68a9c1</code></a> Supply the agent argument to the attacher process as an environment variable.</li> <li><a href="https://github.com/raphw/byte-buddy/commit/3ac9ded1959f2aa29809f1bf156d736ef602e3fa"><code>3ac9ded</code></a> Avoid symbolic link resolution on recursive deletion and validate Android ent...</li> <li><a href="https://github.com/raphw/byte-buddy/commit/8dbae60638aac34bed01685d9b322d08433c38de"><code>8dbae60</code></a> Sign deployed files using sigstore.</li> <li><a href="https://github.com/raphw/byte-buddy/commit/5d83cd4a0fc954fb0f6bd13e71f60b532a5d7f95"><code>5d83cd4</code></a> Disable semantic versioning check for protected constructor in abstract class...</li> <li><a href="https://github.com/raphw/byte-buddy/commit/172e0f4712366d4c82c53604214f427cd9232e69"><code>172e0f4</code></a> Move to method to apply suppression.</li> <li>Additional commits viewable in <a href="https://github.com/raphw/byte-buddy/compare/byte-buddy-1.18.13...byte-buddy-1.18.14">compare view</a></li> </ul> </details> <br /> Updates `net.bytebuddy:byte-buddy-agent` from 1.18.13 to 1.18.14 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/raphw/byte-buddy/releases">net.bytebuddy:byte-buddy-agent's releases</a>.</em></p> <blockquote> <h2>Byte Buddy 1.18.14</h2> <ul> <li>Avoid exposure of the agent argument on the command line of the process that is spawned for an external attachment.</li> <li>Avoid the resolution of symbolic links when the Gradle plugin deletes a folder recursively.</li> <li>Limit the nesting depth that is accepted when parsing a generic type signature to avoid an exhaustion of the stack for a malformed class file.</li> <li>Sign all deployed files using sigstore, in addition to the existing GPG signature.</li> <li>Validate entry names when the Android plugin retains a file to avoid the propagation of path traversals.</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/raphw/byte-buddy/blob/master/release-notes.md">net.bytebuddy:byte-buddy-agent's changelog</a>.</em></p> <blockquote> <h3>14. September 2026: version 1.18.14</h3> <ul> <li>Avoid exposure of the agent argument on the command line of the process that is spawned for an external attachment.</li> <li>Avoid the resolution of symbolic links when the Gradle plugin deletes a folder recursively.</li> <li>Limit the nesting depth that is accepted when parsing a generic type signature to avoid an exhaustion of the stack for a malformed class file.</li> <li>Sign all deployed files using sigstore, in addition to the existing GPG signature.</li> <li>Validate entry names when the Android plugin retains a file to avoid the propagation of path traversals.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/raphw/byte-buddy/commit/92846cb0fa3480ed6e0fc41803e8e74f52070c59"><code>92846cb</code></a> [publish] Releasing Byte Buddy 1.18.14</li> <li><a href="https://github.com/raphw/byte-buddy/commit/a8a9f14e225f87477f65251db17f475895d73369"><code>a8a9f14</code></a> [release] Release new version</li> <li><a href="https://github.com/raphw/byte-buddy/commit/b0fe0066a8ea4f9316aa2a06906c87c0f529ddcd"><code>b0fe006</code></a> Skip the signature creation for artifacts that are not deployed.</li> <li><a href="https://github.com/raphw/byte-buddy/commit/c6107833a61e389719b56623fc36e3e476442e11"><code>c610783</code></a> Resolve the signed POM file by the path of the project file.</li> <li><a href="https://github.com/raphw/byte-buddy/commit/caab321964c9da0e0620fc0ff931413629ecf0b3"><code>caab321</code></a> Sign the deployed POM file and allow for a sigstore dry run.</li> <li><a href="https://github.com/raphw/byte-buddy/commit/c68a9c1761bc3fcda4d942ac7cc3a9e58a200e78"><code>c68a9c1</code></a> Supply the agent argument to the attacher process as an environment variable.</li> <li><a href="https://github.com/raphw/byte-buddy/commit/3ac9ded1959f2aa29809f1bf156d736ef602e3fa"><code>3ac9ded</code></a> Avoid symbolic link resolution on recursive deletion and validate Android ent...</li> <li><a href="https://github.com/raphw/byte-buddy/commit/8dbae60638aac34bed01685d9b322d08433c38de"><code>8dbae60</code></a> Sign deployed files using sigstore.</li> <li><a href="https://github.com/raphw/byte-buddy/commit/5d83cd4a0fc954fb0f6bd13e71f60b532a5d7f95"><code>5d83cd4</code></a> Disable semantic versioning check for protected constructor in abstract class...</li> <li><a href="https://github.com/raphw/byte-buddy/commit/172e0f4712366d4c82c53604214f427cd9232e69"><code>172e0f4</code></a> Move to method to apply suppression.</li> <li>Additional commits viewable in <a href="https://github.com/raphw/byte-buddy/compare/byte-buddy-1.18.13...byte-buddy-1.18.14">compare view</a></li> </ul> </details> <br /> Updates `net.bytebuddy:byte-buddy-agent` from 1.18.13 to 1.18.14 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/raphw/byte-buddy/releases">net.bytebuddy:byte-buddy-agent's releases</a>.</em></p> <blockquote> <h2>Byte Buddy 1.18.14</h2> <ul> <li>Avoid exposure of the agent argument on the command line of the process that is spawned for an external attachment.</li> <li>Avoid the resolution of symbolic links when the Gradle plugin deletes a folder recursively.</li> <li>Limit the nesting depth that is accepted when parsing a generic type signature to avoid an exhaustion of the stack for a malformed class file.</li> <li>Sign all deployed files using sigstore, in addition to the existing GPG signature.</li> <li>Validate entry names when the Android plugin retains a file to avoid the propagation of path traversals.</li> </ul> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/raphw/byte-buddy/blob/master/release-notes.md">net.bytebuddy:byte-buddy-agent's changelog</a>.</em></p> <blockquote> <h3>14. September 2026: version 1.18.14</h3> <ul> <li>Avoid exposure of the agent argument on the command line of the process that is spawned for an external attachment.</li> <li>Avoid the resolution of symbolic links when the Gradle plugin deletes a folder recursively.</li> <li>Limit the nesting depth that is accepted when parsing a generic type signature to avoid an exhaustion of the stack for a malformed class file.</li> <li>Sign all deployed files using sigstore, in addition to the existing GPG signature.</li> <li>Validate entry names when the Android plugin retains a file to avoid the propagation of path traversals.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/raphw/byte-buddy/commit/92846cb0fa3480ed6e0fc41803e8e74f52070c59"><code>92846cb</code></a> [publish] Releasing Byte Buddy 1.18.14</li> <li><a href="https://github.com/raphw/byte-buddy/commit/a8a9f14e225f87477f65251db17f475895d73369"><code>a8a9f14</code></a> [release] Release new version</li> <li><a href="https://github.com/raphw/byte-buddy/commit/b0fe0066a8ea4f9316aa2a06906c87c0f529ddcd"><code>b0fe006</code></a> Skip the signature creation for artifacts that are not deployed.</li> <li><a href="https://github.com/raphw/byte-buddy/commit/c6107833a61e389719b56623fc36e3e476442e11"><code>c610783</code></a> Resolve the signed POM file by the path of the project file.</li> <li><a href="https://github.com/raphw/byte-buddy/commit/caab321964c9da0e0620fc0ff931413629ecf0b3"><code>caab321</code></a> Sign the deployed POM file and allow for a sigstore dry run.</li> <li><a href="https://github.com/raphw/byte-buddy/commit/c68a9c1761bc3fcda4d942ac7cc3a9e58a200e78"><code>c68a9c1</code></a> Supply the agent argument to the attacher process as an environment variable.</li> <li><a href="https://github.com/raphw/byte-buddy/commit/3ac9ded1959f2aa29809f1bf156d736ef602e3fa"><code>3ac9ded</code></a> Avoid symbolic link resolution on recursive deletion and validate Android ent...</li> <li><a href="https://github.com/raphw/byte-buddy/commit/8dbae60638aac34bed01685d9b322d08433c38de"><code>8dbae60</code></a> Sign deployed files using sigstore.</li> <li><a href="https://github.com/raphw/byte-buddy/commit/5d83cd4a0fc954fb0f6bd13e71f60b532a5d7f95"><code>5d83cd4</code></a> Disable semantic versioning check for protected constructor in abstract class...</li> <li><a href="https://github.com/raphw/byte-buddy/commit/172e0f4712366d4c82c53604214f427cd9232e69"><code>172e0f4</code></a> Move to method to apply suppression.</li> <li>Additional commits viewable in <a href="https://github.com/raphw/byte-buddy/compare/byte-buddy-1.18.13...byte-buddy-1.18.14">compare view</a></li> </ul> </details> <br /> Updates `org.hibernate.orm:hibernate-core` from 7.4.7.Final to 7.4.9.Final <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/hibernate/hibernate-orm/releases">org.hibernate.orm:hibernate-core's releases</a>.</em></p> <blockquote> <h2>Release 7.4.9</h2> <h1>Hibernate ORM 7.4.9.Final released</h1> <p>Today, we published a new release of Hibernate ORM 7.4: 7.4.9.Final.</p> <p>You can find the full list of 7.4.9.Final changes <a href="https://hibernate.atlassian.net/issues/?jql=project%20%3D%20HHH%20AND%20fixVersion%20%3D%207.4.9">here</a>.</p> <h2>What's new</h2> <ul> <li>See the <a href="https://hibernate.org/orm/releases/7.4">website</a> for requirements and compatibilities.</li> <li>See the <a href="https://docs.hibernate.org/orm/7.4/whats-new/whats-new.html">What's New</a> guide for details about new features and capabilities.</li> <li>See the <a href="https://docs.hibernate.org/orm/7.4/migration-guide/">Migration Guide</a> for details about migration.</li> </ul> <h2>Conclusion</h2> <p>For additional details, see:</p> <ul> <li>the <a href="https://hibernate.org/orm/releases/7.4/">release page</a></li> <li>the <a href="https://docs.hibernate.org/orm/7.4/migration-guide/">Migration Guide</a></li> <li>the <a href="https://docs.hibernate.org/orm/7.4/introduction/html_single/">Introduction Guide</a></li> <li>the <a href="https://docs.hibernate.org/orm/7.4/userguide/html_single/">User Guide</a></li> <li>the <a href="https://docs.hibernate.org/orm/7.4/javadocs">API docs</a></li> </ul> <p>See also the following resources related to supported APIs:</p> <ul> <li>the <a href="https://hibernate.org/community/compatibility-policy/">compatibility policy</a></li> <li>the <a href="https://docs.hibernate.org/orm/7.4/incubating/incubating.txt">incubating API report</a> (<code>@Incubating</code>)</li> <li>the <a href="https://docs.hibernate.org/orm/7.4/deprecated/deprecated.txt">deprecated API report</a> (<code>@Deprecated</code> + <code>@Remove</code>)</li> <li>the <a href="https://docs.hibernate.org/orm/7.4/internals/internal.txt">internal API report</a> (internal packages, <code>@Internal</code>)</li> </ul> <p>Visit the <a href="https://hibernate.org/community/">website</a> for details on getting in touch with us.</p> <h2>Release 7.4.8</h2> <h1>Hibernate ORM 7.4.8.Final released</h1> <p>Today, we published a new release of Hibernate ORM 7.4: 7.4.8.Final.</p> <p>You can find the full list of 7.4.8.Final changes <a href="https://hibernate.atlassian.net/issues/?jql=project%20%3D%20HHH%20AND%20fixVersion%20%3D%207.4.8">here</a>.</p> <h2>What's new</h2> <ul> <li>See the <a href="https://hibernate.org/orm/releases/7.4">website</a> for requirements and compatibilities.</li> <li>See the <a href="https://docs.hibernate.org/orm/7.4/whats-new/whats-new.html">What's New</a> guide for details about new features and capabilities.</li> <li>See the <a href="https://docs.hibernate.org/orm/7.4/migration-guide/">Migration Guide</a> for details about migration.</li> </ul> <h2>Conclusion</h2> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/hibernate/hibernate-orm/blob/7.4.9/changelog.txt">org.hibernate.orm:hibernate-core's changelog</a>.</em></p> <blockquote> <h2>Changes in 7.4.9.Final (September 17, 2026)</h2> <p><a href="https://hibernate.atlassian.net/projects/HHH/versions/40446">https://hibernate.atlassian.net/projects/HHH/versions/40446</a></p> <h2>Changes in 7.4.8.Final (September 13, 2026)</h2> <p><a href="https://hibernate.atlassian.net/projects/HHH/versions/40444">https://hibernate.atlassian.net/projects/HHH/versions/40444</a></p> <p>** Bug * HHH-20855 SQL Server temporal rounding causing trouble with sub-micro input values * HHH-20849 org.hibernate.query.range.Range#suffix wrongly expects pattern * HHH-20806 Join elimination in 7.x skips <a href="https://github.com/SQLRestriction"><code>@SQLRestriction</code></a> when querying by to-one association id * HHH-20805 MySQL schema update fails, if foreignkey related index is unique * HHH-20804 StatefulPersistenceContext.clear() does not release newEntityHolder * HHH-20801 AnyType.guessEntityPersister uses the wrapped proxy instead of the unwrapped implementation in its fallback → UnknownEntityTypeException during flush logging * HHH-20782 <a href="https://github.com/FilterJoinTable"><code>@FilterJoinTable</code></a> throws NPE when used with explicit HQL join * HHH-20744 UnknownTableReferenceException when querying the non-owning side of a one-to-one-mapping with a pessimistic lock mode * HHH-20675 <a href="https://github.com/FilterDef"><code>@FilterDef</code></a>(applyToLoadByKey = true) breaks JOIN FETCH of a JOINED-inheritance to-one association: subclass table joins dropped from FROM while their columns remain in SELECT (invalid SQL) * HHH-20632 Regression: UnknownTableReferenceException fetching an <a href="https://github.com/Any"><code>@Any</code></a> discriminator through treat() (since 7.4.0, HHH-16730) * HHH-20343 HTE (Bulk ID) temporary table ignores PhysicalNamingStrategy when using SequenceGenerator * HHH-19486 SQLGrammarException when joining to subquery with Case expression * HHH-19485 AssertionError when using Subquery with Case in Criteria API * HHH-18911 Usage of ConcreteProxy in lazy loaded ManyToOne reference</p> <p>** Deprecation * HHH-20862 Deprecate reflection optimizer and related property access APIs</p> <p>** Task * HHH-20851 Upgrade to ant 1.10.18 * HHH-20848 Drop meaningless "provided" dependency to ant in hibernate-envers</p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/hibernate/hibernate-orm/commit/208bf6c64920d90a24cda739e3db46093b3962aa"><code>208bf6c</code></a> [Jenkins release job] Preparing release 7.4.9.Final</li> <li><a href="https://github.com/hibernate/hibernate-orm/commit/0204513038ace82b22004245b367540703ac27fb"><code>0204513</code></a> [Jenkins release job] changelog.txt updated by release build 7.4.9.Final</li> <li><a href="https://github.com/hibernate/hibernate-orm/commit/83109832798212488b7f6b01548ea37e1d557f11"><code>8310983</code></a> HHH-20883 add tenant id to mutation SQL (<a href="https://redirect.github.com/hibernate/hibernate-orm/issues/13412">#13412</a>)</li> <li><a href="https://github.com/hibernate/hibernate-orm/commit/a36fbebfe207c93b439b079b4c2fbd479ba6f0e0"><code>a36fbeb</code></a> HHH-20882 Avoid exposing MariaDB JDBC parameters in logs</li> <li><a href="https://github.com/hibernate/hibernate-orm/commit/ec66308492cfc0d7d89802cd35dadb2d044a6bc8"><code>ec66308</code></a> HHH-20882 Redact MariaDB JDBC parameters from logging</li> <li><a href="https://github.com/hibernate/hibernate-orm/commit/006022ca7d21f0d22e66142bef0a3569d3fe39dc"><code>006022c</code></a> HHH-20882 Redact credentials from database connection info logging</li> <li><a href="https://github.com/hibernate/hibernate-orm/commit/07ee9126d662006fa7d071e909afcb12e7909e1d"><code>07ee912</code></a> HHH-19930 Implement cascade support for key-to-ones</li> <li><a href="https://github.com/hibernate/hibernate-orm/commit/fd92450f4ed1e97daa1c96139bdd6ca2960ced39"><code>fd92450</code></a> HHH-20816 Ensure arguments to JSON functions don't allow SQL injection</li> <li><a href="https://github.com/hibernate/hibernate-orm/commit/ec81e8931c9f1367a5996eb25983f91b6a025959"><code>ec81e89</code></a> [Jenkins release job] Preparing next development iteration</li> <li><a href="https://github.com/hibernate/hibernate-orm/commit/2d3a7b8c1d85d772fb0334d43f37b9e2ef6b0103"><code>2d3a7b8</code></a> [Jenkins release job] Preparing release 7.4.8.Final</li> <li>Additional commits viewable in <a href="https://github.com/hibernate/hibernate-orm/compare/7.4.7...7.4.9">compare view</a></li> </ul> </details> <br /> Updates `org.apache.felix:maven-bundle-plugin` from 6.1.2 to 6.2.0 Updates `fish.payara.extras:payara-micro` from 7.2026.8 to 7.2026.9 <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/payara/payara/releases">fish.payara.extras:payara-micro's releases</a>.</em></p> <blockquote> <h2>Azul Payara Community 7.2026.9</h2> <h1>Supported APIs and Applications</h1> <ul> <li> <p>Jakarta EE 11</p> </li> <li> <p>Jakarta EE 11 Applications</p> </li> <li> <p>MicroProfile 7.1</p> </li> </ul> <h1>Bug Fixes</h1> <ul> <li> <p>[<a href="https://redirect.github.com/payara/Payara/pull/8356">FISH-13664</a>] Fix Blank Admin Console Page After Deployment</p> </li> <li> <p>[<a href="https://redirect.github.com/payara/Payara/pull/8389">FISH-14186</a>] Fix Instance on SSH Node Unreachable from DAS</p> </li> <li> <p>[<a href="https://redirect.github.com/payara/Payara/pull/8380">FISH-14203</a>] [Community Contribution - <a href="https://github.com/lprimak">lprimak</a>] Fix Logs Leaking Injection Manager Found in the Current Thread</p> </li> <li> <p>[<a href="https://redirect.github.com/payara/Payara/pull/8351">FISH-14301</a>] Fix Payara 6 Deployment Descriptors Erroneously Removing Deprecated Elements</p> </li> </ul> <h1>Security Fixes</h1> <ul> <li> <p>[<a href="https://redirect.github.com/payara/patched-src-hazelcast/pull/11">FISH-13990</a>] Upgrade Hazelcast Implementation to Shaded Jackson 2.18.6 or Later</p> </li> <li> <p>[<a href="https://redirect.github.com/payara/Payara/pull/8359">FISH-14390</a>] CVE-2026-68497: Resource Exhaustion in <code>jackson-databind</code></p> </li> </ul> <h1>Improvements</h1> <ul> <li> <p>[<a href="https://redirect.github.com/payara/Payara/pull/8357">FISH-13353</a>] Create JSON Formatted HTTP Access Log</p> </li> <li> <p>[<a href="https://redirect.github.com/payara/Payara/pull/8351">FISH-13494</a>] Add <code>payara-</code> Deployment Descriptors for Payara 5</p> </li> <li> <p>[<a href="https://redirect.github.com/payara/Payara/pull/8335">FISH-13880</a>] Reintroduce Ability to Define Managed Executors in Payara Deployment Descriptors</p> </li> <li> <p>[<a href="https://redirect.github.com/payara/Payara/pull/8386">FISH-14240</a>] Add Jakarta Agentic AI to Payara Micro and Embedded</p> </li> </ul> <h1>Component Upgrades</h1> <ul> <li> <p>[<a href="https://redirect.github.com/payara/Payara/pull/8281">FISH-13986</a>] Upgrade <code>io.opentelemetry.semconv:opentelemetry-semconv</code> from 1.42.0 to 1.43.0</p> </li> <li> <p>[<a href="https://redirect.github.com/payara/Payara/pull/8298">FISH-14039</a>] Upgrade Mojarra from 4.1.7 to 4.1.14</p> </li> <li> <p>[<a href="https://redirect.github.com/payara/Payara/pull/8308">FISH-14096</a>] Upgrade Docker JDK to 25.0.4.1</p> </li> <li> <p>[<a href="https://redirect.github.com/payara/Payara/pull/8308">FISH-14097</a>] Upgrade Docker JDK to 21.0.12.1</p> </li> <li> <p>[<a href="https://redirect.github.com/payara/Payara/pull/8311">FISH-14117</a>] Remove Unnecessary <code>opentelemetry.instrumentation:opentelemetry-instrumentation-bom</code></p> </li> <li> <p>[<a href="https://redirect.github.com/payara/Payara/pull/8352">FISH-14150</a>] Upgrade Hazelcast to 5.7.0</p> </li> <li> <p>[<a href="https://redirect.github.com/payara/Payara/pull/8347">FISH-14244</a>] Upgrade <code>opentelemetry.version</code> from 1.64.0 to 1.65.0</p> </li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/payara/Payara/commit/d4f0b8b074746a511ad11ea3b1b1f10a683a4078"><code>d4f0b8b</code></a> Increment version numbers for Release</li> <li><a href="https://github.com/payara/Payara/commit/914c60d9041b4a92976903595948f60d5532451a"><code>914c60d</code></a> Merge pull request <a href="https://redirect.github.com/payara/payara/issues/8403">#8403</a> from payara/revert-8400-dependabot/maven/main/org.pr...</li> <li><a href="https://github.com/payara/Payara/commit/d852a6c163030a9535025beb3a3ed682022df4cc"><code>d852a6c</code></a> Revert "FISH-14513 Bump org.primefaces:primefaces from 15.0.17 to 15.0.18"</li> <li><a href="https://github.com/payara/Payara/commit/4969dca160cb4c615459240d1ffc03b26814f03e"><code>4969dca</code></a> Merge pull request <a href="https://redirect.github.com/payara/payara/issues/8400">#8400</a> from payara/dependabot/maven/main/org.primefaces-pri...</li> <li><a href="https://github.com/payara/Payara/commit/5569518c1b7c39d88d3b9411823ab9336796d354"><code>5569518</code></a> Merge pull request <a href="https://redirect.github.com/payara/payara/issues/8399">#8399</a> from payara/dependabot/maven/main/jline.version-4.4.2</li> <li><a href="https://github.com/payara/Payara/commit/51e649595a401b9e9affd6843c348003b27306ca"><code>51e6495</code></a> Merge pull request <a href="https://redirect.github.com/payara/payara/issues/8397">#8397</a> from payara/dependabot/maven/main/org.apache.ant-ant...</li> <li><a href="https://github.com/payara/Payara/commit/a72038f90dc5fcf8987ca8fe886686e437ddaae6"><code>a72038f</code></a> Merge pull request <a href="https://redirect.github.com/payara/payara/issues/8396">#8396</a> from payara/dependabot/maven/main/ant.version-1.10.18</li> <li><a href="https://github.com/payara/Payara/commit/9b4a7a3e995a98e02b0f7f366756835268275772"><code>9b4a7a3</code></a> Merge pull request <a href="https://redirect.github.com/payara/payara/issues/8401">#8401</a> from raushan606/FISH-14487-p7</li> <li><a href="https://github.com/payara/Payara/commit/7dbbb5e275291b56ac73f13ae1649eb025c21ab3"><code>7dbbb5e</code></a> FISH-14487: merge OTLP exporter service files via shade transformer</li> <li><a href="https://github.com/payara/Payara/commit/b68b7b45d3761484395b12fa5a9beefc22edd263"><code>b68b7b4</code></a> Bump org.primefaces:primefaces from 15.0.17 to 15.0.18</li> <li>Additional commits viewable in <a href="https://github.com/payara/payara/compare/payara-server-7.2026.8...payara-server-7.2026.9">compare view</a></li> </ul> </details> <br /> Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore <dependency name> major version` will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself) - `@dependabot ignore <dependency name> minor version` will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself) - `@dependabot ignore <dependency name>` will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself) - `@dependabot unignore <dependency name>` will remove all of the ignore conditions of the specified dependency - `@dependabot unignore <dependency name> <ignore condition>` will remove the ignore condition of the specified dependency and ignore conditions </details> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
