dependabot[bot] opened a new pull request, #2895:
URL: https://github.com/apache/shiro/pull/2895

   Bumps the maven-dependencies group with 8 updates:
   
   | Package | From | To |
   | --- | --- | --- |
   | [org.apache:apache](https://github.com/apache/maven-apache-parent) | `39` 
| `40` |
   | [org.apache.groovy:groovy-all](https://github.com/apache/groovy) | `5.1.2` 
| `6.0.0` |
   | [org.apache.groovy:groovy](https://github.com/apache/groovy) | `5.1.2` | 
`6.0.0` |
   | [net.bytebuddy:byte-buddy](https://github.com/raphw/byte-buddy) | 
`1.18.13` | `1.18.14` |
   | [net.bytebuddy:byte-buddy-agent](https://github.com/raphw/byte-buddy) | 
`1.18.13` | `1.18.14` |
   | 
[org.hibernate.orm:hibernate-core](https://github.com/hibernate/hibernate-orm) 
| `7.4.7.Final` | `7.4.9.Final` |
   | org.apache.felix:maven-bundle-plugin | `6.1.2` | `6.2.0` |
   | [fish.payara.extras:payara-micro](https://github.com/payara/payara) | 
`7.2026.8` | `7.2026.9` |
   
   Updates `org.apache:apache` from 39 to 40
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/apache/maven-apache-parent/releases";>org.apache:apache's
 releases</a>.</em></p>
   <blockquote>
   <h2>40</h2>
   <!-- raw HTML omitted -->
   <h2>:boom: Breaking changes</h2>
   <ul>
   <li>Replace nicoulaj checksum plugin with maveniverse checksum plugin (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/599";>#599</a>)
 <a 
href="https://github.com/slawekjaranowski";><code>@​slawekjaranowski</code></a></li>
   <li><a 
href="https://redirect.github.com/apache/maven-apache-parent/issues/586";>#586</a>:
 Use RAT0.18 and remove commons-lang3 configuration for JDK25 (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/587";>#587</a>)
 <a href="https://github.com/ottlinger";><code>@​ottlinger</code></a></li>
   <li>Property <code>version.maven-surefire</code> was removed in <a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/588";>apache/maven-apache-parent#588</a>,
 should be replaced by <code>version.maven-surefire-plugin</code>, 
<code>version.maven-failsafe-plugin</code> or 
<code>version.maven-surefire-report-plugin</code></li>
   </ul>
   <h2>🚀 New features and improvements</h2>
   <ul>
   <li>Fix several version property issues (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/588";>#588</a>)
 <a href="https://github.com/ctubbsii";><code>@​ctubbsii</code></a></li>
   </ul>
   <h2>📝 Documentation updates</h2>
   <ul>
   <li>Update documentation for push-to-atr profile (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/613";>#613</a>)
 <a 
href="https://github.com/slawekjaranowski";><code>@​slawekjaranowski</code></a></li>
   <li>Restore the common wording on the download page (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/596";>#596</a>)
 <a href="https://github.com/slachiewicz";><code>@​slachiewicz</code></a></li>
   </ul>
   <h2>👻 Maintenance</h2>
   <ul>
   <li>Add local maven configuration for ATR project name override (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/614";>#614</a>)
 <a 
href="https://github.com/slawekjaranowski";><code>@​slawekjaranowski</code></a></li>
   <li>Remove custom name-template for release-drafter (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/604";>#604</a>)
 <a 
href="https://github.com/slawekjaranowski";><code>@​slawekjaranowski</code></a></li>
   <li>Port the site documentation from APT to Markdown (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/595";>#595</a>)
 <a href="https://github.com/slachiewicz";><code>@​slachiewicz</code></a></li>
   </ul>
   <h2>📦 Dependency updates</h2>
   <ul>
   <li>Bump org.apache.maven.plugins:maven-deploy-plugin from 3.1.4 to 3.2.0 
(<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/612";>#612</a>)
 @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
   <li>Bump org.apache.maven.plugins:maven-install-plugin from 3.1.4 to 3.2.0 
(<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/611";>#611</a>)
 @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
   <li>Bump org.apache.maven.plugins:maven-plugin-tools from 3.15.2 to 3.16.0 
(<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/610";>#610</a>)
 <a 
href="https://github.com/slawekjaranowski";><code>@​slawekjaranowski</code></a></li>
   <li>Bump surefire-plugin, failsafe-plugin, surefire-report-plugin from 3.5.6 
to 3.6.0 (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/605";>#605</a>)
 <a 
href="https://github.com/slawekjaranowski";><code>@​slawekjaranowski</code></a></li>
   <li>Bump org.apache.tooling:atr-maven-plugin from 1.0.0-alpha-1 to 
1.0.0-beta-1 (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/598";>#598</a>)
 @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
   <li>Bump org.apache.maven.plugins:maven-compiler-plugin from 3.15.0 to 
3.16.0 (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/600";>#600</a>)
 @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
   <li><a 
href="https://redirect.github.com/apache/maven-apache-parent/issues/586";>#586</a>:
 Use RAT0.18 and remove commons-lang3 configuration for JDK25 (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/587";>#587</a>)
 <a href="https://github.com/ottlinger";><code>@​ottlinger</code></a></li>
   <li>Bump org.apache.maven.plugins:maven-jar-plugin from 3.5.0 to 3.5.1 (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/594";>#594</a>)
 @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
   <li>Bump 
apache/maven-gh-actions-shared/.github/workflows/release-drafter.yml from 4 to 
5 (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/591";>#591</a>)
 @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
   <li>Bump apache/maven-gh-actions-shared/.github/workflows/pr-automation.yml 
from 4 to 5 (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/593";>#593</a>)
 @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
   <li>Bump apache/maven-gh-actions-shared/.github/workflows/stale.yml from 4 
to 5 (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/592";>#592</a>)
 @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
   <li>Bump apache/maven-gh-actions-shared/.github/workflows/maven-verify.yml 
from 4 to 5 (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/590";>#590</a>)
 @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
   <li>Bump org.apache.maven.plugins:maven-help-plugin from 3.5.1 to 3.5.2 (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/589";>#589</a>)
 @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li>See full diff in <a 
href="https://github.com/apache/maven-apache-parent/commits";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `org.apache.groovy:groovy-all` from 5.1.2 to 6.0.0
   <details>
   <summary>Commits</summary>
   <ul>
   <li>See full diff in <a 
href="https://github.com/apache/groovy/commits";>compare view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `org.apache.groovy:groovy` from 5.1.2 to 6.0.0
   <details>
   <summary>Commits</summary>
   <ul>
   <li>See full diff in <a 
href="https://github.com/apache/groovy/commits";>compare view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `org.apache.groovy:groovy` from 5.1.2 to 6.0.0
   <details>
   <summary>Commits</summary>
   <ul>
   <li>See full diff in <a 
href="https://github.com/apache/groovy/commits";>compare view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `net.bytebuddy:byte-buddy` from 1.18.13 to 1.18.14
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/raphw/byte-buddy/releases";>net.bytebuddy:byte-buddy's 
releases</a>.</em></p>
   <blockquote>
   <h2>Byte Buddy 1.18.14</h2>
   <ul>
   <li>Avoid exposure of the agent argument on the command line of the process 
that is spawned for an external attachment.</li>
   <li>Avoid the resolution of symbolic links when the Gradle plugin deletes a 
folder recursively.</li>
   <li>Limit the nesting depth that is accepted when parsing a generic type 
signature to avoid an exhaustion of the stack for a malformed class file.</li>
   <li>Sign all deployed files using sigstore, in addition to the existing GPG 
signature.</li>
   <li>Validate entry names when the Android plugin retains a file to avoid the 
propagation of path traversals.</li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/raphw/byte-buddy/blob/master/release-notes.md";>net.bytebuddy:byte-buddy's
 changelog</a>.</em></p>
   <blockquote>
   <h3>14. September 2026: version 1.18.14</h3>
   <ul>
   <li>Avoid exposure of the agent argument on the command line of the process 
that is spawned for an external attachment.</li>
   <li>Avoid the resolution of symbolic links when the Gradle plugin deletes a 
folder recursively.</li>
   <li>Limit the nesting depth that is accepted when parsing a generic type 
signature to avoid an exhaustion of the stack for a malformed class file.</li>
   <li>Sign all deployed files using sigstore, in addition to the existing GPG 
signature.</li>
   <li>Validate entry names when the Android plugin retains a file to avoid the 
propagation of path traversals.</li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/92846cb0fa3480ed6e0fc41803e8e74f52070c59";><code>92846cb</code></a>
 [publish] Releasing Byte Buddy 1.18.14</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/a8a9f14e225f87477f65251db17f475895d73369";><code>a8a9f14</code></a>
 [release] Release new version</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/b0fe0066a8ea4f9316aa2a06906c87c0f529ddcd";><code>b0fe006</code></a>
 Skip the signature creation for artifacts that are not deployed.</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/c6107833a61e389719b56623fc36e3e476442e11";><code>c610783</code></a>
 Resolve the signed POM file by the path of the project file.</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/caab321964c9da0e0620fc0ff931413629ecf0b3";><code>caab321</code></a>
 Sign the deployed POM file and allow for a sigstore dry run.</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/c68a9c1761bc3fcda4d942ac7cc3a9e58a200e78";><code>c68a9c1</code></a>
 Supply the agent argument to the attacher process as an environment 
variable.</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/3ac9ded1959f2aa29809f1bf156d736ef602e3fa";><code>3ac9ded</code></a>
 Avoid symbolic link resolution on recursive deletion and validate Android 
ent...</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/8dbae60638aac34bed01685d9b322d08433c38de";><code>8dbae60</code></a>
 Sign deployed files using sigstore.</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/5d83cd4a0fc954fb0f6bd13e71f60b532a5d7f95";><code>5d83cd4</code></a>
 Disable semantic versioning check for protected constructor in abstract 
class...</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/172e0f4712366d4c82c53604214f427cd9232e69";><code>172e0f4</code></a>
 Move to method to apply suppression.</li>
   <li>Additional commits viewable in <a 
href="https://github.com/raphw/byte-buddy/compare/byte-buddy-1.18.13...byte-buddy-1.18.14";>compare
 view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `net.bytebuddy:byte-buddy-agent` from 1.18.13 to 1.18.14
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/raphw/byte-buddy/releases";>net.bytebuddy:byte-buddy-agent's
 releases</a>.</em></p>
   <blockquote>
   <h2>Byte Buddy 1.18.14</h2>
   <ul>
   <li>Avoid exposure of the agent argument on the command line of the process 
that is spawned for an external attachment.</li>
   <li>Avoid the resolution of symbolic links when the Gradle plugin deletes a 
folder recursively.</li>
   <li>Limit the nesting depth that is accepted when parsing a generic type 
signature to avoid an exhaustion of the stack for a malformed class file.</li>
   <li>Sign all deployed files using sigstore, in addition to the existing GPG 
signature.</li>
   <li>Validate entry names when the Android plugin retains a file to avoid the 
propagation of path traversals.</li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/raphw/byte-buddy/blob/master/release-notes.md";>net.bytebuddy:byte-buddy-agent's
 changelog</a>.</em></p>
   <blockquote>
   <h3>14. September 2026: version 1.18.14</h3>
   <ul>
   <li>Avoid exposure of the agent argument on the command line of the process 
that is spawned for an external attachment.</li>
   <li>Avoid the resolution of symbolic links when the Gradle plugin deletes a 
folder recursively.</li>
   <li>Limit the nesting depth that is accepted when parsing a generic type 
signature to avoid an exhaustion of the stack for a malformed class file.</li>
   <li>Sign all deployed files using sigstore, in addition to the existing GPG 
signature.</li>
   <li>Validate entry names when the Android plugin retains a file to avoid the 
propagation of path traversals.</li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/92846cb0fa3480ed6e0fc41803e8e74f52070c59";><code>92846cb</code></a>
 [publish] Releasing Byte Buddy 1.18.14</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/a8a9f14e225f87477f65251db17f475895d73369";><code>a8a9f14</code></a>
 [release] Release new version</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/b0fe0066a8ea4f9316aa2a06906c87c0f529ddcd";><code>b0fe006</code></a>
 Skip the signature creation for artifacts that are not deployed.</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/c6107833a61e389719b56623fc36e3e476442e11";><code>c610783</code></a>
 Resolve the signed POM file by the path of the project file.</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/caab321964c9da0e0620fc0ff931413629ecf0b3";><code>caab321</code></a>
 Sign the deployed POM file and allow for a sigstore dry run.</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/c68a9c1761bc3fcda4d942ac7cc3a9e58a200e78";><code>c68a9c1</code></a>
 Supply the agent argument to the attacher process as an environment 
variable.</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/3ac9ded1959f2aa29809f1bf156d736ef602e3fa";><code>3ac9ded</code></a>
 Avoid symbolic link resolution on recursive deletion and validate Android 
ent...</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/8dbae60638aac34bed01685d9b322d08433c38de";><code>8dbae60</code></a>
 Sign deployed files using sigstore.</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/5d83cd4a0fc954fb0f6bd13e71f60b532a5d7f95";><code>5d83cd4</code></a>
 Disable semantic versioning check for protected constructor in abstract 
class...</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/172e0f4712366d4c82c53604214f427cd9232e69";><code>172e0f4</code></a>
 Move to method to apply suppression.</li>
   <li>Additional commits viewable in <a 
href="https://github.com/raphw/byte-buddy/compare/byte-buddy-1.18.13...byte-buddy-1.18.14";>compare
 view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `net.bytebuddy:byte-buddy-agent` from 1.18.13 to 1.18.14
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/raphw/byte-buddy/releases";>net.bytebuddy:byte-buddy-agent's
 releases</a>.</em></p>
   <blockquote>
   <h2>Byte Buddy 1.18.14</h2>
   <ul>
   <li>Avoid exposure of the agent argument on the command line of the process 
that is spawned for an external attachment.</li>
   <li>Avoid the resolution of symbolic links when the Gradle plugin deletes a 
folder recursively.</li>
   <li>Limit the nesting depth that is accepted when parsing a generic type 
signature to avoid an exhaustion of the stack for a malformed class file.</li>
   <li>Sign all deployed files using sigstore, in addition to the existing GPG 
signature.</li>
   <li>Validate entry names when the Android plugin retains a file to avoid the 
propagation of path traversals.</li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/raphw/byte-buddy/blob/master/release-notes.md";>net.bytebuddy:byte-buddy-agent's
 changelog</a>.</em></p>
   <blockquote>
   <h3>14. September 2026: version 1.18.14</h3>
   <ul>
   <li>Avoid exposure of the agent argument on the command line of the process 
that is spawned for an external attachment.</li>
   <li>Avoid the resolution of symbolic links when the Gradle plugin deletes a 
folder recursively.</li>
   <li>Limit the nesting depth that is accepted when parsing a generic type 
signature to avoid an exhaustion of the stack for a malformed class file.</li>
   <li>Sign all deployed files using sigstore, in addition to the existing GPG 
signature.</li>
   <li>Validate entry names when the Android plugin retains a file to avoid the 
propagation of path traversals.</li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/92846cb0fa3480ed6e0fc41803e8e74f52070c59";><code>92846cb</code></a>
 [publish] Releasing Byte Buddy 1.18.14</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/a8a9f14e225f87477f65251db17f475895d73369";><code>a8a9f14</code></a>
 [release] Release new version</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/b0fe0066a8ea4f9316aa2a06906c87c0f529ddcd";><code>b0fe006</code></a>
 Skip the signature creation for artifacts that are not deployed.</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/c6107833a61e389719b56623fc36e3e476442e11";><code>c610783</code></a>
 Resolve the signed POM file by the path of the project file.</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/caab321964c9da0e0620fc0ff931413629ecf0b3";><code>caab321</code></a>
 Sign the deployed POM file and allow for a sigstore dry run.</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/c68a9c1761bc3fcda4d942ac7cc3a9e58a200e78";><code>c68a9c1</code></a>
 Supply the agent argument to the attacher process as an environment 
variable.</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/3ac9ded1959f2aa29809f1bf156d736ef602e3fa";><code>3ac9ded</code></a>
 Avoid symbolic link resolution on recursive deletion and validate Android 
ent...</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/8dbae60638aac34bed01685d9b322d08433c38de";><code>8dbae60</code></a>
 Sign deployed files using sigstore.</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/5d83cd4a0fc954fb0f6bd13e71f60b532a5d7f95";><code>5d83cd4</code></a>
 Disable semantic versioning check for protected constructor in abstract 
class...</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/172e0f4712366d4c82c53604214f427cd9232e69";><code>172e0f4</code></a>
 Move to method to apply suppression.</li>
   <li>Additional commits viewable in <a 
href="https://github.com/raphw/byte-buddy/compare/byte-buddy-1.18.13...byte-buddy-1.18.14";>compare
 view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `org.hibernate.orm:hibernate-core` from 7.4.7.Final to 7.4.9.Final
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/hibernate/hibernate-orm/releases";>org.hibernate.orm:hibernate-core's
 releases</a>.</em></p>
   <blockquote>
   <h2>Release 7.4.9</h2>
   <h1>Hibernate ORM 7.4.9.Final released</h1>
   <p>Today, we published a new release of Hibernate ORM 7.4: 7.4.9.Final.</p>
   <p>You can find the full list of 7.4.9.Final changes <a 
href="https://hibernate.atlassian.net/issues/?jql=project%20%3D%20HHH%20AND%20fixVersion%20%3D%207.4.9";>here</a>.</p>
   <h2>What's new</h2>
   <ul>
   <li>See the <a href="https://hibernate.org/orm/releases/7.4";>website</a> for 
requirements and compatibilities.</li>
   <li>See the <a 
href="https://docs.hibernate.org/orm/7.4/whats-new/whats-new.html";>What's 
New</a> guide for details about new features and capabilities.</li>
   <li>See the <a 
href="https://docs.hibernate.org/orm/7.4/migration-guide/";>Migration Guide</a> 
for details about migration.</li>
   </ul>
   <h2>Conclusion</h2>
   <p>For additional details, see:</p>
   <ul>
   <li>the <a href="https://hibernate.org/orm/releases/7.4/";>release 
page</a></li>
   <li>the <a 
href="https://docs.hibernate.org/orm/7.4/migration-guide/";>Migration 
Guide</a></li>
   <li>the <a 
href="https://docs.hibernate.org/orm/7.4/introduction/html_single/";>Introduction
 Guide</a></li>
   <li>the <a 
href="https://docs.hibernate.org/orm/7.4/userguide/html_single/";>User 
Guide</a></li>
   <li>the <a href="https://docs.hibernate.org/orm/7.4/javadocs";>API 
docs</a></li>
   </ul>
   <p>See also the following resources related to supported APIs:</p>
   <ul>
   <li>the <a 
href="https://hibernate.org/community/compatibility-policy/";>compatibility 
policy</a></li>
   <li>the <a 
href="https://docs.hibernate.org/orm/7.4/incubating/incubating.txt";>incubating 
API report</a> (<code>@Incubating</code>)</li>
   <li>the <a 
href="https://docs.hibernate.org/orm/7.4/deprecated/deprecated.txt";>deprecated 
API report</a> (<code>@Deprecated</code> + <code>@Remove</code>)</li>
   <li>the <a 
href="https://docs.hibernate.org/orm/7.4/internals/internal.txt";>internal API 
report</a> (internal packages, <code>@Internal</code>)</li>
   </ul>
   <p>Visit the <a href="https://hibernate.org/community/";>website</a> for 
details on getting in touch with us.</p>
   <h2>Release 7.4.8</h2>
   <h1>Hibernate ORM 7.4.8.Final released</h1>
   <p>Today, we published a new release of Hibernate ORM 7.4: 7.4.8.Final.</p>
   <p>You can find the full list of 7.4.8.Final changes <a 
href="https://hibernate.atlassian.net/issues/?jql=project%20%3D%20HHH%20AND%20fixVersion%20%3D%207.4.8";>here</a>.</p>
   <h2>What's new</h2>
   <ul>
   <li>See the <a href="https://hibernate.org/orm/releases/7.4";>website</a> for 
requirements and compatibilities.</li>
   <li>See the <a 
href="https://docs.hibernate.org/orm/7.4/whats-new/whats-new.html";>What's 
New</a> guide for details about new features and capabilities.</li>
   <li>See the <a 
href="https://docs.hibernate.org/orm/7.4/migration-guide/";>Migration Guide</a> 
for details about migration.</li>
   </ul>
   <h2>Conclusion</h2>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/hibernate/hibernate-orm/blob/7.4.9/changelog.txt";>org.hibernate.orm:hibernate-core's
 changelog</a>.</em></p>
   <blockquote>
   <h2>Changes in 7.4.9.Final (September 17, 2026)</h2>
   <p><a 
href="https://hibernate.atlassian.net/projects/HHH/versions/40446";>https://hibernate.atlassian.net/projects/HHH/versions/40446</a></p>
   <h2>Changes in 7.4.8.Final (September 13, 2026)</h2>
   <p><a 
href="https://hibernate.atlassian.net/projects/HHH/versions/40444";>https://hibernate.atlassian.net/projects/HHH/versions/40444</a></p>
   <p>** Bug
   * HHH-20855 SQL Server temporal rounding causing trouble with sub-micro 
input values
   * HHH-20849 org.hibernate.query.range.Range#suffix wrongly expects pattern
   * HHH-20806 Join elimination in 7.x skips <a 
href="https://github.com/SQLRestriction";><code>@​SQLRestriction</code></a> when 
querying by to-one association id
   * HHH-20805 MySQL schema update fails, if foreignkey related index is unique
   * HHH-20804 StatefulPersistenceContext.clear() does not release 
newEntityHolder
   * HHH-20801 AnyType.guessEntityPersister uses the wrapped proxy instead of 
the unwrapped implementation in its fallback → UnknownEntityTypeException 
during flush logging
   * HHH-20782 <a 
href="https://github.com/FilterJoinTable";><code>@​FilterJoinTable</code></a> 
throws NPE when used with explicit HQL join
   * HHH-20744 UnknownTableReferenceException when querying the non-owning side 
of a one-to-one-mapping with a pessimistic lock mode
   * HHH-20675 <a 
href="https://github.com/FilterDef";><code>@​FilterDef</code></a>(applyToLoadByKey
 = true) breaks JOIN FETCH of a JOINED-inheritance to-one association: subclass 
table joins dropped from FROM while their columns remain in SELECT (invalid SQL)
   * HHH-20632 Regression: UnknownTableReferenceException fetching an <a 
href="https://github.com/Any";><code>@​Any</code></a> discriminator through 
treat() (since 7.4.0, HHH-16730)
   * HHH-20343 HTE (Bulk ID) temporary table ignores PhysicalNamingStrategy 
when using SequenceGenerator
   * HHH-19486 SQLGrammarException when joining to subquery with Case expression
   * HHH-19485 AssertionError when using Subquery with Case in Criteria API
   * HHH-18911 Usage of ConcreteProxy in lazy loaded ManyToOne reference</p>
   <p>** Deprecation
   * HHH-20862 Deprecate reflection optimizer and related property access 
APIs</p>
   <p>** Task
   * HHH-20851 Upgrade to ant 1.10.18
   * HHH-20848 Drop meaningless &quot;provided&quot; dependency to ant in 
hibernate-envers</p>
   </blockquote>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/hibernate/hibernate-orm/commit/208bf6c64920d90a24cda739e3db46093b3962aa";><code>208bf6c</code></a>
 [Jenkins release job] Preparing release 7.4.9.Final</li>
   <li><a 
href="https://github.com/hibernate/hibernate-orm/commit/0204513038ace82b22004245b367540703ac27fb";><code>0204513</code></a>
 [Jenkins release job] changelog.txt updated by release build 7.4.9.Final</li>
   <li><a 
href="https://github.com/hibernate/hibernate-orm/commit/83109832798212488b7f6b01548ea37e1d557f11";><code>8310983</code></a>
 HHH-20883 add tenant id to mutation SQL (<a 
href="https://redirect.github.com/hibernate/hibernate-orm/issues/13412";>#13412</a>)</li>
   <li><a 
href="https://github.com/hibernate/hibernate-orm/commit/a36fbebfe207c93b439b079b4c2fbd479ba6f0e0";><code>a36fbeb</code></a>
 HHH-20882 Avoid exposing MariaDB JDBC parameters in logs</li>
   <li><a 
href="https://github.com/hibernate/hibernate-orm/commit/ec66308492cfc0d7d89802cd35dadb2d044a6bc8";><code>ec66308</code></a>
 HHH-20882 Redact MariaDB JDBC parameters from logging</li>
   <li><a 
href="https://github.com/hibernate/hibernate-orm/commit/006022ca7d21f0d22e66142bef0a3569d3fe39dc";><code>006022c</code></a>
 HHH-20882 Redact credentials from database connection info logging</li>
   <li><a 
href="https://github.com/hibernate/hibernate-orm/commit/07ee9126d662006fa7d071e909afcb12e7909e1d";><code>07ee912</code></a>
 HHH-19930 Implement cascade support for key-to-ones</li>
   <li><a 
href="https://github.com/hibernate/hibernate-orm/commit/fd92450f4ed1e97daa1c96139bdd6ca2960ced39";><code>fd92450</code></a>
 HHH-20816 Ensure arguments to JSON functions don't allow SQL injection</li>
   <li><a 
href="https://github.com/hibernate/hibernate-orm/commit/ec81e8931c9f1367a5996eb25983f91b6a025959";><code>ec81e89</code></a>
 [Jenkins release job] Preparing next development iteration</li>
   <li><a 
href="https://github.com/hibernate/hibernate-orm/commit/2d3a7b8c1d85d772fb0334d43f37b9e2ef6b0103";><code>2d3a7b8</code></a>
 [Jenkins release job] Preparing release 7.4.8.Final</li>
   <li>Additional commits viewable in <a 
href="https://github.com/hibernate/hibernate-orm/compare/7.4.7...7.4.9";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `org.apache.felix:maven-bundle-plugin` from 6.1.2 to 6.2.0
   
   Updates `fish.payara.extras:payara-micro` from 7.2026.8 to 7.2026.9
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/payara/payara/releases";>fish.payara.extras:payara-micro's
 releases</a>.</em></p>
   <blockquote>
   <h2>Azul Payara Community 7.2026.9</h2>
   <h1>Supported APIs and Applications</h1>
   <ul>
   <li>
   <p>Jakarta EE 11</p>
   </li>
   <li>
   <p>Jakarta EE 11 Applications</p>
   </li>
   <li>
   <p>MicroProfile 7.1</p>
   </li>
   </ul>
   <h1>Bug Fixes</h1>
   <ul>
   <li>
   <p>[<a 
href="https://redirect.github.com/payara/Payara/pull/8356";>FISH-13664</a>] Fix 
Blank Admin Console Page After Deployment</p>
   </li>
   <li>
   <p>[<a 
href="https://redirect.github.com/payara/Payara/pull/8389";>FISH-14186</a>] Fix 
Instance on SSH Node Unreachable from DAS</p>
   </li>
   <li>
   <p>[<a 
href="https://redirect.github.com/payara/Payara/pull/8380";>FISH-14203</a>] 
[Community Contribution - <a href="https://github.com/lprimak";>lprimak</a>] Fix 
Logs Leaking Injection Manager Found in the Current Thread</p>
   </li>
   <li>
   <p>[<a 
href="https://redirect.github.com/payara/Payara/pull/8351";>FISH-14301</a>] Fix 
Payara 6 Deployment Descriptors Erroneously Removing Deprecated Elements</p>
   </li>
   </ul>
   <h1>Security Fixes</h1>
   <ul>
   <li>
   <p>[<a 
href="https://redirect.github.com/payara/patched-src-hazelcast/pull/11";>FISH-13990</a>]
 Upgrade Hazelcast Implementation to Shaded Jackson 2.18.6 or Later</p>
   </li>
   <li>
   <p>[<a 
href="https://redirect.github.com/payara/Payara/pull/8359";>FISH-14390</a>] 
CVE-2026-68497: Resource Exhaustion in <code>jackson-databind</code></p>
   </li>
   </ul>
   <h1>Improvements</h1>
   <ul>
   <li>
   <p>[<a 
href="https://redirect.github.com/payara/Payara/pull/8357";>FISH-13353</a>] 
Create JSON Formatted HTTP Access Log</p>
   </li>
   <li>
   <p>[<a 
href="https://redirect.github.com/payara/Payara/pull/8351";>FISH-13494</a>] Add 
<code>payara-</code> Deployment Descriptors for Payara 5</p>
   </li>
   <li>
   <p>[<a 
href="https://redirect.github.com/payara/Payara/pull/8335";>FISH-13880</a>] 
Reintroduce Ability to Define Managed Executors in Payara Deployment 
Descriptors</p>
   </li>
   <li>
   <p>[<a 
href="https://redirect.github.com/payara/Payara/pull/8386";>FISH-14240</a>] Add 
Jakarta Agentic AI to Payara Micro and Embedded</p>
   </li>
   </ul>
   <h1>Component Upgrades</h1>
   <ul>
   <li>
   <p>[<a 
href="https://redirect.github.com/payara/Payara/pull/8281";>FISH-13986</a>] 
Upgrade <code>io.opentelemetry.semconv:opentelemetry-semconv</code> from 1.42.0 
to 1.43.0</p>
   </li>
   <li>
   <p>[<a 
href="https://redirect.github.com/payara/Payara/pull/8298";>FISH-14039</a>] 
Upgrade Mojarra from 4.1.7 to 4.1.14</p>
   </li>
   <li>
   <p>[<a 
href="https://redirect.github.com/payara/Payara/pull/8308";>FISH-14096</a>] 
Upgrade Docker JDK to 25.0.4.1</p>
   </li>
   <li>
   <p>[<a 
href="https://redirect.github.com/payara/Payara/pull/8308";>FISH-14097</a>] 
Upgrade Docker JDK to 21.0.12.1</p>
   </li>
   <li>
   <p>[<a 
href="https://redirect.github.com/payara/Payara/pull/8311";>FISH-14117</a>] 
Remove Unnecessary 
<code>opentelemetry.instrumentation:opentelemetry-instrumentation-bom</code></p>
   </li>
   <li>
   <p>[<a 
href="https://redirect.github.com/payara/Payara/pull/8352";>FISH-14150</a>] 
Upgrade Hazelcast to 5.7.0</p>
   </li>
   <li>
   <p>[<a 
href="https://redirect.github.com/payara/Payara/pull/8347";>FISH-14244</a>] 
Upgrade <code>opentelemetry.version</code> from 1.64.0 to 1.65.0</p>
   </li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/payara/Payara/commit/d4f0b8b074746a511ad11ea3b1b1f10a683a4078";><code>d4f0b8b</code></a>
 Increment version numbers for Release</li>
   <li><a 
href="https://github.com/payara/Payara/commit/914c60d9041b4a92976903595948f60d5532451a";><code>914c60d</code></a>
 Merge pull request <a 
href="https://redirect.github.com/payara/payara/issues/8403";>#8403</a> from 
payara/revert-8400-dependabot/maven/main/org.pr...</li>
   <li><a 
href="https://github.com/payara/Payara/commit/d852a6c163030a9535025beb3a3ed682022df4cc";><code>d852a6c</code></a>
 Revert &quot;FISH-14513 Bump org.primefaces:primefaces from 15.0.17 to 
15.0.18&quot;</li>
   <li><a 
href="https://github.com/payara/Payara/commit/4969dca160cb4c615459240d1ffc03b26814f03e";><code>4969dca</code></a>
 Merge pull request <a 
href="https://redirect.github.com/payara/payara/issues/8400";>#8400</a> from 
payara/dependabot/maven/main/org.primefaces-pri...</li>
   <li><a 
href="https://github.com/payara/Payara/commit/5569518c1b7c39d88d3b9411823ab9336796d354";><code>5569518</code></a>
 Merge pull request <a 
href="https://redirect.github.com/payara/payara/issues/8399";>#8399</a> from 
payara/dependabot/maven/main/jline.version-4.4.2</li>
   <li><a 
href="https://github.com/payara/Payara/commit/51e649595a401b9e9affd6843c348003b27306ca";><code>51e6495</code></a>
 Merge pull request <a 
href="https://redirect.github.com/payara/payara/issues/8397";>#8397</a> from 
payara/dependabot/maven/main/org.apache.ant-ant...</li>
   <li><a 
href="https://github.com/payara/Payara/commit/a72038f90dc5fcf8987ca8fe886686e437ddaae6";><code>a72038f</code></a>
 Merge pull request <a 
href="https://redirect.github.com/payara/payara/issues/8396";>#8396</a> from 
payara/dependabot/maven/main/ant.version-1.10.18</li>
   <li><a 
href="https://github.com/payara/Payara/commit/9b4a7a3e995a98e02b0f7f366756835268275772";><code>9b4a7a3</code></a>
 Merge pull request <a 
href="https://redirect.github.com/payara/payara/issues/8401";>#8401</a> from 
raushan606/FISH-14487-p7</li>
   <li><a 
href="https://github.com/payara/Payara/commit/7dbbb5e275291b56ac73f13ae1649eb025c21ab3";><code>7dbbb5e</code></a>
 FISH-14487: merge OTLP exporter service files via shade transformer</li>
   <li><a 
href="https://github.com/payara/Payara/commit/b68b7b45d3761484395b12fa5a9beefc22edd263";><code>b68b7b4</code></a>
 Bump org.primefaces:primefaces from 15.0.17 to 15.0.18</li>
   <li>Additional commits viewable in <a 
href="https://github.com/payara/payara/compare/payara-server-7.2026.8...payara-server-7.2026.9";>compare
 view</a></li>
   </ul>
   </details>
   <br />
   
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore <dependency name> major version` will close this group 
update PR and stop Dependabot creating any more for the specific dependency's 
major version (unless you unignore this specific dependency's major version or 
upgrade to it yourself)
   - `@dependabot ignore <dependency name> minor version` will close this group 
update PR and stop Dependabot creating any more for the specific dependency's 
minor version (unless you unignore this specific dependency's minor version or 
upgrade to it yourself)
   - `@dependabot ignore <dependency name>` will close this group update PR and 
stop Dependabot creating any more for the specific dependency (unless you 
unignore this specific dependency or upgrade to it yourself)
   - `@dependabot unignore <dependency name>` will remove all of the ignore 
conditions of the specified dependency
   - `@dependabot unignore <dependency name> <ignore condition>` will remove 
the ignore condition of the specified dependency and ignore conditions
   
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to