dependabot[bot] opened a new pull request, #3523: URL: https://github.com/apache/cxf/pull/3523
Bumps [org.atmosphere:atmosphere-runtime](https://github.com/Atmosphere/atmosphere) from 3.1.0 to 4.0.71. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/Atmosphere/atmosphere/releases">org.atmosphere:atmosphere-runtime's releases</a>.</em></p> <blockquote> <h2>Atmosphere 4.0.71</h2> <h3>Added</h3> <ul> <li>serve Atmosphere from a Vert.x route with quarkus.atmosphere.container=vertx</li> <li>add completions, resource templates, tool annotations and outputSchema</li> </ul> <h3>Fixed</h3> <ul> <li>advertise MCP Apps under the spec id io.modelcontextprotocol/ui</li> <li>block the drift-log stop hook at most once per session</li> <li>register the commons-pool2 pool providers only when commons-pool2 is reached</li> <li>scope the drift-log stop hook to changes made during the session</li> <li>bound parallel fan-out with a fleet-wide maxParallel permit pool</li> <li>bump Bouncy Castle to 1.86 for CVE-2026-8763 and CVE-2026-13506</li> <li>close Tomcat auth-bypass CVEs and the vitest mocker path traversal</li> <li>boot fixture servers from packaged artifacts instead of Maven goals</li> <li>make the Expo client server URL an env override, not a source edit</li> </ul> <h3>Changed</h3> <ul> <li>make the queued-past-timeout maxParallel test deterministic</li> <li>pin the router behaviours a Vert.x container mode relies on</li> <li>prove BlockingIOCometSupport suspends on virtual threads; drop stale JDK 25 notes</li> <li>log unverified claims in the Vert.x-mode design session</li> <li>extract framework bootstrap helpers from the servlet</li> <li>build Quarkus native with the Mandrel JDK 25 builder image</li> <li>bump Quarkus to 3.39.5</li> <li>run the official MCP conformance suite on both dialects</li> <li>drop the org.json Dependabot ignore and the inert dependency-graph config</li> </ul> <h2>Atmosphere 4.0.70</h2> <h3>Fixed</h3> <ul> <li>keep the personal-assistant transport open while keying memory on the token</li> <li>stop compose hanging without a TTY and warn on an inherited LLM_BASE_URL</li> <li>resolve the run owner from the AuthInterceptor principal</li> <li>key personal-assistant memory on the authenticated principal</li> <li>track Boot 3.5.15's Tomcat 10.1.55 in the spring-boot3 profile pin</li> <li>close 72 of the 74 open Dependabot alerts across nine packages</li> </ul> <h3>Changed</h3> <ul> <li>pin the parity trail in save order, not as a sorted multiset</li> <li>log the blog-audit drift entries</li> <li>cite the shipping rate limits in the OWASP A09 evidence</li> <li>move to Jetty 12.1.12 and port HTTP/3 to the relocated QUIC API</li> <li>type-check the Console on TypeScript 7 and make .d.cts reachable</li> <li>move atmosphere.js and the e2e suite to TypeScript 7</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/Atmosphere/atmosphere/blob/main/CHANGELOG.md">org.atmosphere:atmosphere-runtime's changelog</a>.</em></p> <blockquote> <h2>[4.0.71] - 2026-09-24</h2> <h3>Added</h3> <ul> <li>serve Atmosphere from a Vert.x route with quarkus.atmosphere.container=vertx</li> <li>add completions, resource templates, tool annotations and outputSchema</li> </ul> <h3>Fixed</h3> <ul> <li>advertise MCP Apps under the spec id io.modelcontextprotocol/ui</li> <li>block the drift-log stop hook at most once per session</li> <li>register the commons-pool2 pool providers only when commons-pool2 is reached</li> <li>scope the drift-log stop hook to changes made during the session</li> <li>bound parallel fan-out with a fleet-wide maxParallel permit pool</li> <li>bump Bouncy Castle to 1.86 for CVE-2026-8763 and CVE-2026-13506</li> <li>close Tomcat auth-bypass CVEs and the vitest mocker path traversal</li> <li>boot fixture servers from packaged artifacts instead of Maven goals</li> <li>make the Expo client server URL an env override, not a source edit</li> </ul> <h3>Changed</h3> <ul> <li>make the queued-past-timeout maxParallel test deterministic</li> <li>pin the router behaviours a Vert.x container mode relies on</li> <li>prove BlockingIOCometSupport suspends on virtual threads; drop stale JDK 25 notes</li> <li>log unverified claims in the Vert.x-mode design session</li> <li>extract framework bootstrap helpers from the servlet</li> <li>build Quarkus native with the Mandrel JDK 25 builder image</li> <li>bump Quarkus to 3.39.5</li> <li>run the official MCP conformance suite on both dialects</li> <li>drop the org.json Dependabot ignore and the inert dependency-graph config</li> </ul> <h2>[4.0.70] - 2026-09-01</h2> <h3>Fixed</h3> <ul> <li>keep the personal-assistant transport open while keying memory on the token</li> <li>stop compose hanging without a TTY and warn on an inherited LLM_BASE_URL</li> <li>resolve the run owner from the AuthInterceptor principal</li> <li>key personal-assistant memory on the authenticated principal</li> <li>track Boot 3.5.15's Tomcat 10.1.55 in the spring-boot3 profile pin</li> <li>close 72 of the 74 open Dependabot alerts across nine packages</li> </ul> <h3>Changed</h3> <ul> <li>pin the parity trail in save order, not as a sorted multiset</li> <li>log the blog-audit drift entries</li> <li>cite the shipping rate limits in the OWASP A09 evidence</li> <li>move to Jetty 12.1.12 and port HTTP/3 to the relocated QUIC API</li> <li>type-check the Console on TypeScript 7 and make .d.cts reachable</li> <li>move atmosphere.js and the e2e suite to TypeScript 7</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/Atmosphere/atmosphere/commit/554bf0c700a3dc63767e7ebc97fd3d2d9e57d1de"><code>554bf0c</code></a> release: Atmosphere 4.0.71</li> <li><a href="https://github.com/Atmosphere/atmosphere/commit/9e74dc0f2cf4c403e08208ec1c2dac5dcb6da986"><code>9e74dc0</code></a> test(coordinator): make the queued-past-timeout maxParallel test deterministic</li> <li><a href="https://github.com/Atmosphere/atmosphere/commit/4ba2ffe621e2e7ba5883b06c508e28f9d9674c36"><code>4ba2ffe</code></a> feat(quarkus): serve Atmosphere from a Vert.x route with quarkus.atmosphere.c...</li> <li><a href="https://github.com/Atmosphere/atmosphere/commit/a56718a4dc54468ca0b6eb4e0168f90c0031823b"><code>a56718a</code></a> test(quarkus): pin the router behaviours a Vert.x container mode relies on</li> <li><a href="https://github.com/Atmosphere/atmosphere/commit/d6e17cc3fd9af0c54c6a139e3626a4c838edc228"><code>d6e17cc</code></a> test(cpr): prove BlockingIOCometSupport suspends on virtual threads; drop sta...</li> <li><a href="https://github.com/Atmosphere/atmosphere/commit/36f53be5b0f2b1b83ed6d22765c2ac48a15209b4"><code>36f53be</code></a> docs(harness): log unverified claims in the Vert.x-mode design session</li> <li><a href="https://github.com/Atmosphere/atmosphere/commit/8e8a038dda74bfcbc8c56101caa802e525196a4b"><code>8e8a038</code></a> refactor(quarkus): extract framework bootstrap helpers from the servlet</li> <li><a href="https://github.com/Atmosphere/atmosphere/commit/54516aef4e9adad944d79aecf52989973019d327"><code>54516ae</code></a> fix(mcp): advertise MCP Apps under the spec id io.modelcontextprotocol/ui</li> <li><a href="https://github.com/Atmosphere/atmosphere/commit/d9f2724e8c9ecb14af9cd7df25fd419182e3c058"><code>d9f2724</code></a> fix(hooks): block the drift-log stop hook at most once per session</li> <li><a href="https://github.com/Atmosphere/atmosphere/commit/11c94a45f4bf5b89928306d16ac9d1f44cad16e6"><code>11c94a4</code></a> fix(native): register the commons-pool2 pool providers only when commons-pool...</li> <li>Additional commits viewable in <a href="https://github.com/Atmosphere/atmosphere/compare/atmosphere-project-3.1.0...atmosphere-4.0.71">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
