dependabot[bot] opened a new pull request, #3526: URL: https://github.com/apache/cxf/pull/3526
Bumps [org.asynchttpclient:async-http-client](https://github.com/AsyncHttpClient/async-http-client) from 3.0.13 to 3.0.14. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/AsyncHttpClient/async-http-client/releases">org.asynchttpclient:async-http-client's releases</a>.</em></p> <blockquote> <h2>AHC v3.0.14 Release</h2> <h2>What's Changed</h2> <ul> <li>fix(netty): fail fast when InputStream body cannot be reset by <a href="https://github.com/arimu1"><code>@arimu1</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2312">AsyncHttpClient/async-http-client#2312</a></li> <li>Arm request timeouts on an event loop by <a href="https://github.com/pavel-ptashyts"><code>@pavel-ptashyts</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2313">AsyncHttpClient/async-http-client#2313</a></li> <li>Make TimeoutsHolder.start idempotent by <a href="https://github.com/hyperxpro"><code>@hyperxpro</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2319">AsyncHttpClient/async-http-client#2319</a></li> <li>Bound an exchange by one request timeout by <a href="https://github.com/pavel-ptashyts"><code>@pavel-ptashyts</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2314">AsyncHttpClient/async-http-client#2314</a></li> <li>Add response body flow control by <a href="https://github.com/mkurz"><code>@mkurz</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2318">AsyncHttpClient/async-http-client#2318</a></li> <li>fix(netty): preserve all redirect body types by <a href="https://github.com/mkurz"><code>@mkurz</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2316">AsyncHttpClient/async-http-client#2316</a></li> <li>Bump the dependencies group with 5 updates by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2323">AsyncHttpClient/async-http-client#2323</a></li> <li>Bump actions/setup-java from 5.6.0 to 6.0.0 in the actions group by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2324">AsyncHttpClient/async-http-client#2324</a></li> <li>fix(netty): preserve QUERY across redirects by <a href="https://github.com/mkurz"><code>@mkurz</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2317">AsyncHttpClient/async-http-client#2317</a></li> <li>fix(netty): preserve non-POST redirect methods by <a href="https://github.com/mkurz"><code>@mkurz</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2325">AsyncHttpClient/async-http-client#2325</a></li> <li>Dependency Updates by <a href="https://github.com/hyperxpro"><code>@hyperxpro</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2327">AsyncHttpClient/async-http-client#2327</a></li> <li>Provide an opt-in zero-copy response body view by <a href="https://github.com/pavel-ptashyts"><code>@pavel-ptashyts</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2322">AsyncHttpClient/async-http-client#2322</a></li> <li>Fix response body accessors for bodyless and rebuilt responses by <a href="https://github.com/hyperxpro"><code>@hyperxpro</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2329">AsyncHttpClient/async-http-client#2329</a></li> <li>Tell the handler about a failure before completing its future by <a href="https://github.com/hyperxpro"><code>@hyperxpro</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2328">AsyncHttpClient/async-http-client#2328</a></li> <li>Mark an HTTP/2 connection instead of looking it up by <a href="https://github.com/pavel-ptashyts"><code>@pavel-ptashyts</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2320">AsyncHttpClient/async-http-client#2320</a></li> <li>Reject invalid HTTP/2 settings when the client is built by <a href="https://github.com/hyperxpro"><code>@hyperxpro</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2331">AsyncHttpClient/async-http-client#2331</a></li> <li>Fail fast when the scheme rules out HTTP/2 by <a href="https://github.com/hyperxpro"><code>@hyperxpro</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2334">AsyncHttpClient/async-http-client#2334</a></li> <li>Cache Maven distribution and dependencies in CI by <a href="https://github.com/hyperxpro"><code>@hyperxpro</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2335">AsyncHttpClient/async-http-client#2335</a></li> <li>Bump actions/setup-java from 6.0.0 to 6.0.1 in the actions group by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2336">AsyncHttpClient/async-http-client#2336</a></li> <li>Bump the dependencies group with 5 updates by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2337">AsyncHttpClient/async-http-client#2337</a></li> <li>Add opt-in refusals for downgrade and body replay by <a href="https://github.com/hyperxpro"><code>@hyperxpro</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2333">AsyncHttpClient/async-http-client#2333</a></li> <li>Reject fully qualified names and wildcard imports by <a href="https://github.com/hyperxpro"><code>@hyperxpro</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2338">AsyncHttpClient/async-http-client#2338</a></li> <li>Keep credentials out of logs and exception messages by <a href="https://github.com/hyperxpro"><code>@hyperxpro</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2339">AsyncHttpClient/async-http-client#2339</a></li> <li>Detect transport of external event loop group by IoHandler by <a href="https://github.com/hyperxpro"><code>@hyperxpro</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2340">AsyncHttpClient/async-http-client#2340</a></li> <li>Fix redirect and HTTP/2 follow-up defects by <a href="https://github.com/hyperxpro"><code>@hyperxpro</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2341">AsyncHttpClient/async-http-client#2341</a></li> <li>Keep connection-authenticated sockets off the HTTP/2 registry by <a href="https://github.com/hyperxpro"><code>@hyperxpro</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2342">AsyncHttpClient/async-http-client#2342</a></li> <li>Drop RepeatedIfExceptionsTest and fix the races it hid by <a href="https://github.com/hyperxpro"><code>@hyperxpro</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2343">AsyncHttpClient/async-http-client#2343</a></li> <li>Test cookie expiry with an injected clock by <a href="https://github.com/hyperxpro"><code>@hyperxpro</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2344">AsyncHttpClient/async-http-client#2344</a></li> <li>Fix the defects the rerunner removal uncovered by <a href="https://github.com/hyperxpro"><code>@hyperxpro</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2345">AsyncHttpClient/async-http-client#2345</a></li> <li>Send proxy custom headers only to the proxy by <a href="https://github.com/hyperxpro"><code>@hyperxpro</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2346">AsyncHttpClient/async-http-client#2346</a></li> <li>Attach the write listener before writing the request by <a href="https://github.com/hyperxpro"><code>@hyperxpro</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2347">AsyncHttpClient/async-http-client#2347</a></li> <li>Stop redirects reusing cookies from before the response by <a href="https://github.com/hyperxpro"><code>@hyperxpro</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2348">AsyncHttpClient/async-http-client#2348</a></li> <li>Close with 1009 when a WebSocket message is too big by <a href="https://github.com/hyperxpro"><code>@hyperxpro</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2352">AsyncHttpClient/async-http-client#2352</a></li> <li>Fix/auth retry stale cookies by <a href="https://github.com/hyperxpro"><code>@hyperxpro</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2351">AsyncHttpClient/async-http-client#2351</a></li> <li>Treat Domain=. as a host-only cookie by <a href="https://github.com/hyperxpro"><code>@hyperxpro</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2350">AsyncHttpClient/async-http-client#2350</a></li> <li>Keep a caller's cookie when the store refuses Set-Cookie by <a href="https://github.com/hyperxpro"><code>@hyperxpro</code></a> in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2349">AsyncHttpClient/async-http-client#2349</a></li> </ul> <h2>Security Advisory</h2> <p><a href="https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-v2j5-22fr-j62r">https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-v2j5-22fr-j62r</a> <a href="https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-qjr7-w8pj-pmv9">https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-qjr7-w8pj-pmv9</a> <a href="https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-x8v2-478q-2hvg">https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-x8v2-478q-2hvg</a> <a href="https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-p2jm-6hj6-9rjg">https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-p2jm-6hj6-9rjg</a> <a href="https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-2jwh-9rmr-j4xf">https://github.com/AsyncHttpClient/async-http-client/security/advisories/GHSA-2jwh-9rmr-j4xf</a></p> <h2>New Contributors</h2> <ul> <li><a href="https://github.com/arimu1"><code>@arimu1</code></a> made their first contribution in <a href="https://redirect.github.com/AsyncHttpClient/async-http-client/pull/2312">AsyncHttpClient/async-http-client#2312</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/AsyncHttpClient/async-http-client/compare/async-http-client-project-3.0.13...async-http-client-project-3.0.14">https://github.com/AsyncHttpClient/async-http-client/compare/async-http-client-project-3.0.13...async-http-client-project-3.0.14</a></p> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/AsyncHttpClient/async-http-client/commit/bec30bb3d27ad13f069f72b37351c61bff3394ff"><code>bec30bb</code></a> [maven-release-plugin] prepare release async-http-client-project-3.0.14</li> <li><a href="https://github.com/AsyncHttpClient/async-http-client/commit/b61637f30327f314b7693418f12ce141ac6b2b30"><code>b61637f</code></a> Bound how far a compressed WebSocket message may inflate</li> <li><a href="https://github.com/AsyncHttpClient/async-http-client/commit/6ec7ee45034d154f502852a962d2891746fb82c1"><code>6ec7ee4</code></a> Keep plaintext responses from setting or overlaying Secure cookies</li> <li><a href="https://github.com/AsyncHttpClient/async-http-client/commit/d3bb4d68b41acf5d3ab7541afa9fdfe7ec3ba054"><code>d3bb4d6</code></a> Scope pooled connections by authenticated identity, including proxies</li> <li><a href="https://github.com/AsyncHttpClient/async-http-client/commit/fd9763620725126c1c8bb0af1ceb9a7523099a5f"><code>fd97636</code></a> Keep a caller-set Cookie header when the jar contributes</li> <li><a href="https://github.com/AsyncHttpClient/async-http-client/commit/7dc5bbc2d0a48aa2a9caf089a626dcfd333168e9"><code>7dc5bbc</code></a> Enforce public suffix rules by A-label, locale, host-only, IP</li> <li><a href="https://github.com/AsyncHttpClient/async-http-client/commit/c1a6063bf43e5681e6207073b495a029e13ec8d8"><code>c1a6063</code></a> Keep a caller's cookie when the store refuses Set-Cookie (<a href="https://redirect.github.com/AsyncHttpClient/async-http-client/issues/2349">#2349</a>)</li> <li><a href="https://github.com/AsyncHttpClient/async-http-client/commit/5f970a4f3d4f2a389552c24ccfbf29c06374d71b"><code>5f970a4</code></a> Treat Domain=. as a host-only cookie (<a href="https://redirect.github.com/AsyncHttpClient/async-http-client/issues/2350">#2350</a>)</li> <li><a href="https://github.com/AsyncHttpClient/async-http-client/commit/faccbab7704c39b2eba2cb6be1ad29db9225d2e7"><code>faccbab</code></a> Fix/auth retry stale cookies (<a href="https://redirect.github.com/AsyncHttpClient/async-http-client/issues/2351">#2351</a>)</li> <li><a href="https://github.com/AsyncHttpClient/async-http-client/commit/0ace0002735f40241bec828f43791121ec9d3e1f"><code>0ace000</code></a> Close with 1009 when a WebSocket message is too big (<a href="https://redirect.github.com/AsyncHttpClient/async-http-client/issues/2352">#2352</a>)</li> <li>Additional commits viewable in <a href="https://github.com/AsyncHttpClient/async-http-client/compare/async-http-client-project-3.0.13...async-http-client-project-3.0.14">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
