renovate-bot opened a new pull request, #6797:
URL: https://github.com/apache/jmeter/pull/6797

   This PR contains the following updates:
   
   | Package | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | 
[Confidence](https://docs.renovatebot.com/merge-confidence/) |
   |---|---|---|---|
   | [net.bytebuddy:byte-buddy](https://bytebuddy.net) 
([source](https://redirect.github.com/raphw/byte-buddy)) | `1.17.8` → 
`1.18.14-jdk5` | 
![age](https://developer.mend.io/api/mc/badges/age/maven/net.bytebuddy:byte-buddy/1.18.14-jdk5?slim=true)
 | 
![confidence](https://developer.mend.io/api/mc/badges/confidence/maven/net.bytebuddy:byte-buddy/1.17.8/1.18.14-jdk5?slim=true)
 |
   
   ---
   
   ### Release Notes
   
   <details>
   <summary>raphw/byte-buddy (net.bytebuddy:byte-buddy)</summary>
   
   ### 
[`v1.18.13`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#2-September-2026-version-11813)
   
   - Actually include the SBOM within the published artifacts.
   - Avoid propagation of path traversals that are contained in jar files which 
are copied without transformation.
   - Avoid repeated traversal of previously visited type hierarchies to improve 
performance.
   - Correct Kotlin support of the Gradle plugin to redirect the classes 
directory of a source set while retaining support for legacy Gradle versions.
   - Create Gradle tasks using Gradle's task registration API if available.
   
   ### 
[`v1.18.12`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#17-July-2026-version-11812)
   
   - Automatically support Kotlin in Gradle plugin.
   - Correct JNA injector which accidentally created on based on Unsafe.
   - Support dynamic attach on Windows ARM64 by shipping a native 
`attach_hotspot_windows` library for `win32-aarch64`.
   
   ### 
[`v1.18.11`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#2-July-2026-version-11811)
   
   - Add SBOM to published artifacts.
   - Check for traversable paths injected into class files as a rather 
hypothetical attack vector.
   
   ### 
[`v1.18.10`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#3-June-2026-version-11810)
   
   - Delay change of default for unsage use to Java 26 and improve error 
message.
   
   ### 
[`v1.18.9`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#1-June-2026-version-1189)
   
   - Disable use of Unsafe by default when Java 25or newer is discovered.
   - Check for escape when creating folders in `Plugin.Engine`.
   - Improve OpenJ9 attachment.
   - Avoid null pointer on missing annotation types.
   - Improve diagnostics for external agent attachment.
   - Improve on Gradle context discovery.
   - Support Android libraries on AGP9 or newer.
   - Update ASM.
   
   ### 
[`v1.18.8`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#1-April-2026-version-1188)
   
   - Improve support for repeatable builds.
   - Fix reordering of exception table in type initializers when instrumenting.
   
   ### 
[`v1.18.7`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#1-March-2026-version-1187)
   
   - Introduce new versioning concept with *-jdk5* suffix for 
backwards-compatible jar and Java 8 baseline for regular jar.
   
   ### 
[`v1.18.5`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#15-February-2026-version-1185)
   
   - Eagerly resolve of canonical files during attach emulation to avoid 
failure when process ends before file can be deleted.
   - Add super classes to hash code / equals computation in `Advice` that were 
missing.
   
   ### 
[`v1.18.4`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#16-January-2026-version-1184)
   
   - Add support for new build description in Android 9.
   
   ### 
[`v1.18.3`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#26-November-2025-version-1183)
   
   - Avoid using Class File API when Byte Buddy is loaded on the boot loader 
where multi-release jars are not available.
   - Add additional safety when processing class files with illegally formed 
parameters.
   - Update to latest ASM.
   
   ### 
[`v1.18.2`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#26-November-2025-version-1182)
   
   - Support modifiers for value classes in Valhalla builds.
   - Improve use of build cache in Gradle.
   
   ### 
[`v1.18.1`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#14-September-2026-version-11814)
   
   - Avoid exposure of the agent argument on the command line of the process 
that is spawned for an external attachment.
   - Avoid the resolution of symbolic links when the Gradle plugin deletes a 
folder recursively.
   - Limit the nesting depth that is accepted when parsing a generic type 
signature to avoid an exhaustion of the stack for a malformed class file.
   - Sign all deployed files using sigstore, in addition to the existing GPG 
signature.
   - Validate entry names when the Android plugin retains a file to avoid the 
propagation of path traversals.
   
   ### 
[`v1.18.0`](https://redirect.github.com/raphw/byte-buddy/blob/HEAD/release-notes.md#11-November-2025-version-1180)
   
   - Add support for `module-info` class files and `ModuleDescription`s.
   - Allow for manipulating module information using the `ByteBuddy` API.
   
   </details>
   
   ---
   
   ### Configuration
   
   📅 **Schedule**: (UTC)
   
   - Branch creation
     - "every 3 weeks on Monday"
   - Automerge
     - At any time (no schedule defined)
   
   🚦 **Automerge**: Disabled by config. Please merge this manually once you are 
satisfied.
   
   ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry 
checkbox.
   
   🔕 **Ignore**: Close this PR and you won't be reminded about this update 
again.
   
   ---
   
    - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this 
box
   
   ---
   
   This PR was generated by [Mend Renovate](https://mend.io/renovate/). View 
the [repository job log](https://developer.mend.io/github/apache/jmeter).
   
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMjUuMSIsInVwZGF0ZWRJblZlciI6IjQ0LjEyNS4xIiwidGFyZ2V0QnJhbmNoIjoibWFzdGVyIiwibGFiZWxzIjpbImRlcGVuZGVuY2llcyJdfQ==-->
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to