dependabot[bot] opened a new pull request, #40325:
URL: https://github.com/apache/beam/pull/40325

   Bumps [com.diffplug.spotless](https://github.com/diffplug/spotless) from 
7.2.1 to 8.10.3.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/diffplug/spotless/releases";>com.diffplug.spotless's 
releases</a>.</em></p>
   <blockquote>
   <h2>Gradle Plugin v8.10.3</h2>
   <h3>Changes</h3>
   <ul>
   <li>Generate formatter defaults from version catalog. (<a 
href="https://redirect.github.com/diffplug/spotless/pull/3045";>#3045</a>)</li>
   <li>Bump default <code>gson</code> version <code>2.13.2</code> -&gt; 
<code>2.14.0</code>. (<a 
href="https://redirect.github.com/diffplug/spotless/pull/3045";>#3045</a>)</li>
   <li>Bump default <code>zjsonpatch</code> version <code>0.4.14</code> -&gt; 
<code>0.4.16</code>. (<a 
href="https://redirect.github.com/diffplug/spotless/pull/3045";>#3045</a>)</li>
   <li>Bump default <code>jackson-dataformat-yaml</code> version 
<code>2.14.1</code> -&gt; <code>2.20.1</code>. (<a 
href="https://redirect.github.com/diffplug/spotless/pull/3045";>#3045</a>)</li>
   <li>Bump default <code>ktfmt</code> version <code>0.63</code> -&gt; 
<code>0.64</code>. (<a 
href="https://redirect.github.com/diffplug/spotless/pull/2988";>2988</a>)</li>
   <li>Bump default <code>cleanthat</code> version <code>2.25</code> -&gt; 
<code>2.26</code>. (<a 
href="https://redirect.github.com/diffplug/spotless/pull/2882";>#2882</a>)</li>
   <li>Bump default <code>jackson</code> version <code>2.20.1</code> -&gt; 
<code>2.22.2</code>. (<a 
href="https://redirect.github.com/diffplug/spotless/pull/2819";>#2819</a>)</li>
   <li>Bump default <code>javaparser</code> version <code>3.27.1</code> -&gt; 
<code>3.28.2</code>. (<a 
href="https://redirect.github.com/diffplug/spotless/pull/3065";>#3065</a>)</li>
   <li>Bump default <code>palantir-java-format</code> version 
<code>2.80.0</code> -&gt; <code>2.98.0</code>. (<a 
href="https://redirect.github.com/diffplug/spotless/pull/3068";>#3068</a>)</li>
   <li>Bump default <code>scalafmt</code> version <code>3.8.1</code> -&gt; 
<code>3.11.5</code>. (<a 
href="https://redirect.github.com/diffplug/spotless/pull/2173";>#2173</a>)</li>
   <li>Bump default <code>google-java-format</code> version <code>1.30.0</code> 
-&gt; <code>1.36.1</code>. (<a 
href="https://redirect.github.com/diffplug/spotless/pull/3075";>#3075</a>)</li>
   <li>Bump default <code>gherkin-utils</code> version <code>10.0.0</code> 
-&gt; <code>12.0.2</code>. (<a 
href="https://redirect.github.com/diffplug/spotless/pull/2979";>#2979</a>)</li>
   <li>We no longer publish a plugin marker for the legacy 
<code>com.diffplug.gradle.spotless</code> id, which has been redirecting to 
<code>com.diffplug.spotless</code> since 4.0. Builds that still request it now 
fail with <code>Plugin [id: 'com.diffplug.gradle.spotless'] was not 
found</code> instead of the migration message. (<a 
href="https://redirect.github.com/diffplug/spotless/pull/3086";>#3086</a>)</li>
   </ul>
   <h3>Fixed</h3>
   <ul>
   <li>Fix release signing by using Gradle's required eight-digit signing 
subkey ID. (<a 
href="https://redirect.github.com/diffplug/spotless/pull/3105";>#3105</a>)</li>
   <li>Fix race when creating the npm install cache directory. ((<a 
href="https://redirect.github.com/diffplug/spotless/pull/3096";>#3096</a>)</li>
   <li>GrEclipse no longer emits expected OSGi and nested-jar warnings during 
initialization. (<a 
href="https://redirect.github.com/diffplug/spotless/issues/2445";>#2445</a>)</li>
   <li><code>typescript</code> <code>prettier()</code> no longer emits a 
warning when its parser is already set to <code>typescript</code>. (<a 
href="https://redirect.github.com/diffplug/spotless/pull/3098";>#3098</a>)</li>
   <li><code>versionCatalog()</code> preserves standalone comments at section 
boundaries and the end of the file. (<a 
href="https://redirect.github.com/diffplug/spotless/issues/3048";>#3048</a>)</li>
   <li><code>versionCatalog()</code> preserves entries when comments contain 
unmatched brackets, preserves commas inside quoted strings, and keeps 
significant line boundaries in multiline entries. (<a 
href="https://redirect.github.com/diffplug/spotless/pull/3042";>#3042</a>)</li>
   <li><code>versionCatalog()</code> now reports unfinished entries as lints at 
their starting line. These fail formatting by default, so upgrading may expose 
catalog errors that previously caused silent data loss. (<a 
href="https://redirect.github.com/diffplug/spotless/pull/3042";>#3042</a>)</li>
   <li>Stop calling deprecated <code>Configuration.setVisible</code> from 
Gradle 9.0.0 (<a 
href="https://redirect.github.com/diffplug/spotless/pull/3053";>#3053</a>)</li>
   <li>Eclipse JDT formatter step no longer fails with 
<code>NoClassDefFoundError</code> or <code>NoSuchMethodError</code> when lombok 
is active as a JVM agent (e.g. <code>-javaagent:lombok.jar</code> in Eclipse/VS 
Code/Cursor). (<a 
href="https://redirect.github.com/diffplug/spotless/issues/2795";>#2795</a>)</li>
   </ul>
   <h2>Gradle Plugin v8.10.2</h2>
   <h3>Fixed</h3>
   <ul>
   <li><code>shortenFullyQualifiedTypes()</code> now shortens fully-qualified 
types used in expression contexts (such as static method calls, static fields, 
and enum constants) while avoiding imports that would change how existing 
unqualified type references resolve. (<a 
href="https://redirect.github.com/diffplug/spotless/pull/3039";>#3039</a>)</li>
   <li>Eclipse JDT formatter step no longer fails with 
<code>NoClassDefFoundError</code> when lombok is active as a JVM agent (e.g. 
<code>-javaagent:lombok.jar</code> in Eclipse/VS Code/Cursor). (<a 
href="https://redirect.github.com/diffplug/spotless/issues/2795";>#2795</a>)</li>
   </ul>
   <h2>Gradle Plugin v8.10.1</h2>
   <h3>Fixed</h3>
   <ul>
   <li><code>prettier()</code> and other npm-based steps no longer fail to 
start on npm 12 (<code>EUNKNOWNCONFIG</code> from 
<code>--scripts-prepend-node-path</code>). (<a 
href="https://redirect.github.com/diffplug/spotless/issues/3024";>#3024</a>)</li>
   <li><code>spotlessInternalRegisterDependencies</code> now writes its output 
under a build directory that is configured after the plugin is applied, instead 
of always under the default <code>build/</code>. (<a 
href="https://redirect.github.com/diffplug/spotless/issues/2114";>#2114</a>)</li>
   <li><code>targetExclude</code> now accepts a Gradle <code>Directory</code>, 
<code>DirectoryProperty</code>, or <code>Provider&lt;Directory&gt;</code> and 
excludes the files under it. Previously the directory was treated as a single 
file, so excluding one silently did nothing. (<a 
href="https://redirect.github.com/diffplug/spotless/issues/2667";>#2667</a>)</li>
   </ul>
   <h2>Gradle Plugin v8.10.0</h2>
   <h3>Added</h3>
   <ul>
   <li>New <code>shortenFullyQualifiedTypes()</code> step for Java, which 
replaces fully-qualified type names with their simple names and adds the 
imports they need. Best combined with <code>importOrder()</code> and 
<code>removeUnusedImports()</code>. (<a 
href="https://redirect.github.com/diffplug/spotless/issues/2945";>#2945</a>)</li>
   <li>Add embedded lockfiles to Eclipse JDT for every supported version 
(<code>4.9</code> through <code>4.40</code>), so <code>eclipse()</code> 
resolves from Maven Central instead of querying a P2 update site. Versions 
without an embedded lockfile still fall back to P2 provisioning. (<a 
href="https://redirect.github.com/diffplug/spotless/issues/1996";>#1996</a>)</li>
   </ul>
   <h3>Fixed</h3>
   <ul>
   <li><code>removeUnusedImports</code> no longer fails on Java <code>import 
module</code> declarations. (<a 
href="https://redirect.github.com/diffplug/spotless/issues/2890";>#2890</a>)</li>
   <li><code>expandWildcardImports()</code> now builds its type-solver 
classpath from each Java source set's compile classpath instead of every 
resolvable configuration. Unrelated configurations (for example generated-code 
or custom resolvable configs that are not ready yet) are no longer resolved. 
(<a 
href="https://redirect.github.com/diffplug/spotless/issues/2998";>#2998</a>)</li>
   <li><code>spotlessCheck</code> violation message now suggests the correct 
composite/included-build task path (e.g. <code>./gradlew 
:my-utils:spotlessApply</code>) instead of a bare <code>spotlessApply</code> / 
<code>:spotlessApply</code> that does not select included-build tasks. (<a 
href="https://redirect.github.com/diffplug/spotless/issues/2421";>#2421</a>)</li>
   <li>Parallel multi-project builds no longer intermittently fail with 
&quot;Cannot fingerprint input property 'stepsInternalEquality': 
ConfigurationCacheHackList cannot be serialized&quot; / &quot;Failed to 
provision P2 dependencies&quot; when using <code>eclipse()</code> (or other 
P2-backed steps). Subprojects now share one deduping P2 provisioner and P2 
queries are serialized process-wide. (<a 
href="https://redirect.github.com/diffplug/spotless/issues/3004";>#3004</a>)</li>
   </ul>
   <h3>Changes</h3>
   <ul>
   <li>Default <code>google-java-format</code> remains <code>1.28.0</code> on 
JVM 17; bumps to <code>1.30.0</code> on JVM 21+; require at least 
<code>1.30.0</code> on JVM 25+ for <code>import module</code> support.</li>
   <li>Bump default <code>eclipse</code> version to latest <code>4.39</code> 
-&gt; <code>4.40</code>. (<a 
href="https://redirect.github.com/diffplug/spotless/issues/1996";>#1996</a>)</li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/diffplug/spotless/commit/eae36d86664fb5b186eb4e082fd319709e528178";><code>eae36d8</code></a>
 Published gradle/8.10.3</li>
   <li><a 
href="https://github.com/diffplug/spotless/commit/61e2016ee3ac82fb565b587e04408ae45dc5b709";><code>61e2016</code></a>
 Published maven/3.10.3</li>
   <li><a 
href="https://github.com/diffplug/spotless/commit/49e0b074905b6360848f9ab9c54e6f015911e301";><code>49e0b07</code></a>
 Published lib/4.10.3</li>
   <li><a 
href="https://github.com/diffplug/spotless/commit/b7a77486c6e6aad738b68ffce4075949680362d5";><code>b7a7748</code></a>
 Fix release signing key ID format (<a 
href="https://redirect.github.com/diffplug/spotless/issues/3105";>#3105</a>)</li>
   <li><a 
href="https://github.com/diffplug/spotless/commit/be8005aae5d5e17c6a2819b2c54df5268c5cf4c5";><code>be8005a</code></a>
 Document release signing correction (<a 
href="https://redirect.github.com/diffplug/spotless/issues/3105";>#3105</a>)</li>
   <li><a 
href="https://github.com/diffplug/spotless/commit/073fe6199960d95f733dad9b4d9311c3148d4914";><code>073fe61</code></a>
 Use short signing subkey ID for release publishing</li>
   <li><a 
href="https://github.com/diffplug/spotless/commit/8ac44c7aa8c08ca9b00e86d4dd59d589e7da8f09";><code>8ac44c7</code></a>
 Fix race when creating the npm install cache directory (<a 
href="https://redirect.github.com/diffplug/spotless/issues/3096";>#3096</a>)</li>
   <li><a 
href="https://github.com/diffplug/spotless/commit/3f2d95561185486350c02471dab99a28585e7b45";><code>3f2d955</code></a>
 Update dependency org.slf4j:slf4j-api to v2.0.20 (<a 
href="https://redirect.github.com/diffplug/spotless/issues/3100";>#3100</a>)</li>
   <li><a 
href="https://github.com/diffplug/spotless/commit/0c70ca8904be526d40923f47b0fd8e9cfecfd33a";><code>0c70ca8</code></a>
 Merge branch 'main' into fix/npm-cache-directory-race</li>
   <li><a 
href="https://github.com/diffplug/spotless/commit/bbf44a47b7cbdd2c4f55880f9767f79f36c9b6ee";><code>bbf44a4</code></a>
 Fix GrEclipse initialization warnings (<a 
href="https://redirect.github.com/diffplug/spotless/issues/3097";>#3097</a>)</li>
   <li>Additional commits viewable in <a 
href="https://github.com/diffplug/spotless/compare/gradle/7.2.1...gradle/8.10.3";>compare
 view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.diffplug.spotless&package-manager=gradle&previous-version=7.2.1&new-version=8.10.3)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to