renovate-bot opened a new pull request, #6797: URL: https://github.com/apache/jmeter/pull/6797
This PR contains the following updates: | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---| | [net.bytebuddy:byte-buddy](https://bytebuddy.net) ([source](https://redirect.github.com/raphw/byte-buddy)) | `1.17.8` → `1.18.14-jdk5` |  |  | --- ### Release Notes <details> <summary>raphw/byte-buddy (net.bytebuddy:byte-buddy)</summary> ### [`v1.18.13`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#2-September-2026-version-11813) - Actually include the SBOM within the published artifacts. - Avoid propagation of path traversals that are contained in jar files which are copied without transformation. - Avoid repeated traversal of previously visited type hierarchies to improve performance. - Correct Kotlin support of the Gradle plugin to redirect the classes directory of a source set while retaining support for legacy Gradle versions. - Create Gradle tasks using Gradle's task registration API if available. ### [`v1.18.12`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#17-July-2026-version-11812) - Automatically support Kotlin in Gradle plugin. - Correct JNA injector which accidentally created on based on Unsafe. - Support dynamic attach on Windows ARM64 by shipping a native `attach_hotspot_windows` library for `win32-aarch64`. ### [`v1.18.11`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#2-July-2026-version-11811) - Add SBOM to published artifacts. - Check for traversable paths injected into class files as a rather hypothetical attack vector. ### [`v1.18.10`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#3-June-2026-version-11810) - Delay change of default for unsage use to Java 26 and improve error message. ### [`v1.18.9`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#1-June-2026-version-1189) - Disable use of Unsafe by default when Java 25or newer is discovered. - Check for escape when creating folders in `Plugin.Engine`. - Improve OpenJ9 attachment. - Avoid null pointer on missing annotation types. - Improve diagnostics for external agent attachment. - Improve on Gradle context discovery. - Support Android libraries on AGP9 or newer. - Update ASM. ### [`v1.18.8`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#1-April-2026-version-1188) - Improve support for repeatable builds. - Fix reordering of exception table in type initializers when instrumenting. ### [`v1.18.7`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#1-March-2026-version-1187) - Introduce new versioning concept with *-jdk5* suffix for backwards-compatible jar and Java 8 baseline for regular jar. ### [`v1.18.5`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#15-February-2026-version-1185) - Eagerly resolve of canonical files during attach emulation to avoid failure when process ends before file can be deleted. - Add super classes to hash code / equals computation in `Advice` that were missing. ### [`v1.18.4`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#16-January-2026-version-1184) - Add support for new build description in Android 9. ### [`v1.18.3`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#26-November-2025-version-1183) - Avoid using Class File API when Byte Buddy is loaded on the boot loader where multi-release jars are not available. - Add additional safety when processing class files with illegally formed parameters. - Update to latest ASM. ### [`v1.18.2`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#26-November-2025-version-1182) - Support modifiers for value classes in Valhalla builds. - Improve use of build cache in Gradle. ### [`v1.18.1`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#14-September-2026-version-11814) - Avoid exposure of the agent argument on the command line of the process that is spawned for an external attachment. - Avoid the resolution of symbolic links when the Gradle plugin deletes a folder recursively. - Limit the nesting depth that is accepted when parsing a generic type signature to avoid an exhaustion of the stack for a malformed class file. - Sign all deployed files using sigstore, in addition to the existing GPG signature. - Validate entry names when the Android plugin retains a file to avoid the propagation of path traversals. ### [`v1.18.0`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#11-November-2025-version-1180) - Add support for `module-info` class files and `ModuleDescription`s. - Allow for manipulating module information using the `ByteBuddy` API. </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - "every 3 weeks on Monday" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/apache/jmeter). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMjUuMSIsInVwZGF0ZWRJblZlciI6IjQ0LjEyNS4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==--> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
