renovate-bot opened a new pull request, #6275: URL: https://github.com/apache/fineract/pull/6275
> ℹ️ **Note** > > This PR body was truncated due to platform limits. This PR contains the following updates: | Package | Type | Update | Change | [Age](https://docs.renovatebot.com/merge-confidence/) | [Confidence](https://docs.renovatebot.com/merge-confidence/) | |---|---|---|---|---|---| | [apache/kafka](https://redirect.github.com/apache/kafka) | | minor | `4.2.0-rc2` → `4.3.1-rc2` |  |  | | [gradle/actions](https://redirect.github.com/gradle/actions) | action | minor | `v6.2.0` → `v6.3.0` |  |  | | localstack/localstack | | minor | `2.1` → `2.3` |  |  | | [mariadb](https://hub.docker.com/_/mariadb) ([source](https://redirect.github.com/MariaDB/mariadb-docker)) | | minor | `12.2` → `12.3` |  |  | | [postgres](https://hub.docker.com/_/postgres) ([source](https://redirect.github.com/docker-library/postgres)) | service | minor | `18.3` → `18.6` |  |  | | [zizmorcore/zizmor-action](https://redirect.github.com/zizmorcore/zizmor-action) | action | patch | `v0.6.1` → `v0.6.2` |  |  | | [org.apache.tomcat.embed:tomcat-embed-websocket](https://tomcat.apache.org/) | devDependencies | patch | `10.1.55` → `10.1.57` |  |  | | [org.apache.tomcat.embed:tomcat-embed-el](https://tomcat.apache.org/) | devDependencies | patch | `10.1.55` → `10.1.57` |  |  | | [org.apache.tomcat.embed:tomcat-embed-core](https://tomcat.apache.org/) | devDependencies | patch | `10.1.55` → `10.1.57` |  |  | | [at.yawk.lz4:lz4-java](https://redirect.github.com/yawkat/lz4-java) | devDependencies | patch | `1.11.0` → `1.11.2` |  |  | | [io.netty:netty-transport-native-unix-common](https://netty.io/) ([source](https://redirect.github.com/netty/netty)) | devDependencies | minor | `4.1.135.Final` → `4.2.17.Final` |  |  | | [io.netty:netty-transport-classes-epoll](https://netty.io/) ([source](https://redirect.github.com/netty/netty)) | devDependencies | minor | `4.1.135.Final` → `4.2.17.Final` |  |  | | [io.netty:netty-transport](https://netty.io/) ([source](https://redirect.github.com/netty/netty)) | devDependencies | minor | `4.1.135.Final` → `4.2.17.Final` |  |  | | [io.netty:netty-resolver](https://netty.io/) ([source](https://redirect.github.com/netty/netty)) | devDependencies | minor | `4.1.135.Final` → `4.2.17.Final` |  |  | | [io.netty:netty-handler-proxy](https://netty.io/) ([source](https://redirect.github.com/netty/netty)) | devDependencies | minor | `4.1.135.Final` → `4.2.17.Final` |  |  | | [io.netty:netty-handler](https://netty.io/) ([source](https://redirect.github.com/netty/netty)) | devDependencies | minor | `4.1.135.Final` → `4.2.17.Final` |  |  | | [io.netty:netty-codec-socks](https://netty.io/) ([source](https://redirect.github.com/netty/netty)) | devDependencies | minor | `4.1.135.Final` → `4.2.17.Final` |  |  | | [io.netty:netty-codec-protobuf](https://netty.io/) ([source](https://redirect.github.com/netty/netty)) | devDependencies | minor | `4.1.135.Final` → `4.2.17.Final` |  |  | | [io.netty:netty-codec-marshalling](https://netty.io/) ([source](https://redirect.github.com/netty/netty)) | devDependencies | minor | `4.1.135.Final` → `4.2.17.Final` |  |  | | [io.netty:netty-codec-http2](https://netty.io/) ([source](https://redirect.github.com/netty/netty)) | devDependencies | minor | `4.1.135.Final` → `4.2.17.Final` |  |  | | [io.netty:netty-codec-http](https://netty.io/) ([source](https://redirect.github.com/netty/netty)) | devDependencies | minor | `4.1.135.Final` → `4.2.17.Final` |  |  | | [io.netty:netty-codec-compression](https://netty.io/) ([source](https://redirect.github.com/netty/netty)) | devDependencies | minor | `4.1.135.Final` → `4.2.17.Final` |  |  | | [io.netty:netty-codec-base](https://netty.io/) ([source](https://redirect.github.com/netty/netty)) | devDependencies | minor | `4.1.135.Final` → `4.2.17.Final` |  |  | | [io.netty:netty-codec](https://netty.io/) ([source](https://redirect.github.com/netty/netty)) | devDependencies | minor | `4.1.135.Final` → `4.2.17.Final` |  |  | | [io.netty:netty-common](https://netty.io/) ([source](https://redirect.github.com/netty/netty)) | devDependencies | minor | `4.1.135.Final` → `4.2.17.Final` |  |  | | [io.netty:netty-buffer](https://netty.io/) ([source](https://redirect.github.com/netty/netty)) | devDependencies | minor | `4.1.135.Final` → `4.2.17.Final` |  |  | | [org.springframework.security:spring-security-core](https://spring.io/projects/spring-security) ([source](https://redirect.github.com/spring-projects/spring-security)) | devDependencies | patch | `6.5.10` → `6.5.11` |  |  | | [org.springframework:spring-core](https://redirect.github.com/spring-projects/spring-framework) | devDependencies | patch | `6.2.18` → `6.2.19` |  |  | | [com.nimbusds:nimbus-jose-jwt](https://bitbucket.org/connect2id/nimbus-jose-jwt) | devDependencies | patch | `10.9` → `10.9.1` |  |  | | [org.springframework.restdocs:spring-restdocs-restassured](https://redirect.github.com/spring-projects/spring-restdocs) | devDependencies | patch | `3.0.5` → `3.0.6` |  |  | | [org.springframework.restdocs:spring-restdocs-webtestclient](https://redirect.github.com/spring-projects/spring-restdocs) | devDependencies | patch | `3.0.5` → `3.0.6` |  |  | | [org.springframework.restdocs:spring-restdocs-mockmvc](https://redirect.github.com/spring-projects/spring-restdocs) | devDependencies | patch | `3.0.5` → `3.0.6` |  |  | | [org.springframework.restdocs:spring-restdocs-asciidoctor](https://redirect.github.com/spring-projects/spring-restdocs) | devDependencies | patch | `3.0.5` → `3.0.6` |  |  | | [io.cucumber:cucumber-spring](https://cucumber.io/) ([source](https://redirect.github.com/cucumber/cucumber-jvm)) | devDependencies | patch | `7.34.3` → `7.34.7` |  |  | | [io.cucumber:cucumber-junit-platform-engine](https://cucumber.io/) ([source](https://redirect.github.com/cucumber/cucumber-jvm)) | devDependencies | patch | `7.34.3` → `7.34.7` |  |  | | [io.cucumber:cucumber-java8](https://cucumber.io/) ([source](https://redirect.github.com/cucumber/cucumber-jvm)) | devDependencies | patch | `7.34.3` → `7.34.7` |  |  | | [io.cucumber:cucumber-java](https://cucumber.io/) ([source](https://redirect.github.com/cucumber/cucumber-jvm)) | devDependencies | patch | `7.34.3` → `7.34.7` |  |  | | [org.apache.sshd:sshd-core](https://www.apache.org/) ([source](https://redirect.github.com/apache/mina-sshd)) | devDependencies | minor | `2.17.1` → `2.19.0` |  |  | | [org.apache.sshd:sshd-common](https://www.apache.org/) ([source](https://redirect.github.com/apache/mina-sshd)) | devDependencies | minor | `2.17.1` → `2.19.0` |  |  | | [org.postgresql:postgresql](https://jdbc.postgresql.org) ([source](https://redirect.github.com/pgjdbc/pgjdbc)) | devDependencies | patch | `42.7.11` → `42.7.13` |  |  | | [org.mariadb.jdbc:mariadb-java-client](https://mariadb.com/kb/en/mariadb/about-mariadb-connector-j/) ([source](https://redirect.github.com/mariadb-corporation/mariadb-connector-j)) | devDependencies | patch | `3.5.8` → `3.5.10` |  |  | | [org.apache.groovy:groovy-json](https://groovy-lang.org) ([source](https://redirect.github.com/apache/groovy)) | devDependencies | minor | `5.0.6` → `5.1.0` |  |  | | [org.apache.groovy:groovy-xml](https://groovy-lang.org) ([source](https://redirect.github.com/apache/groovy)) | devDependencies | minor | `5.0.6` → `5.1.0` |  |  | | [org.hibernate.validator:hibernate-validator](https://hibernate.org/validator) ([source](https://redirect.github.com/hibernate/hibernate-validator)) | devDependencies | patch | `9.1.0.Final` → `9.1.3.Final` |  |  | | [io.swagger.core.v3:swagger-core-jakarta](https://redirect.github.com/swagger-api/swagger-core) | devDependencies | patch | `2.2.49` → `2.2.53` |  |  | | [io.swagger.core.v3:swagger-jaxrs2-jakarta](https://redirect.github.com/swagger-api/swagger-core) | devDependencies | patch | `2.2.49` → `2.2.53` |  |  | | [io.swagger.core.v3:swagger-annotations-jakarta](https://redirect.github.com/swagger-api/swagger-core) | devDependencies | patch | `2.2.49` → `2.2.53` |  |  | | [org.apache.activemq:activemq-client](http://activemq.apache.org) ([source](https://redirect.github.com/apache/activemq)) | devDependencies | minor | `6.2.5` → `6.3.1` |  |  | | [org.springdoc:springdoc-openapi-starter-webmvc-ui](https://springdoc.org/) ([source](https://redirect.github.com/springdoc/springdoc-openapi)) | devDependencies | minor | `2.8.17` → `2.9.0` |  |  | | [org.eclipse.jgit:org.eclipse.jgit.ssh.apache](https://eclipse.gerrithub.io/admin/repos/eclipse-jgit/jgit) | devDependencies | minor | `7.6.0.202603022253-r` → `7.7.1.202607240634-r` |  |  | | [org.eclipse.jgit:org.eclipse.jgit.gpg.bc](https://eclipse.gerrithub.io/admin/repos/eclipse-jgit/jgit) | devDependencies | minor | `7.6.0.202603022253-r` → `7.7.1.202607240634-r` |  |  | | [org.eclipse.jgit:org.eclipse.jgit](https://eclipse.gerrithub.io/admin/repos/eclipse-jgit/jgit) | devDependencies | minor | `7.6.0.202603022253-r` → `7.7.1.202607240634-r` |  |  | | [org.bouncycastle:bcpg-jdk18on](https://www.bouncycastle.org/download/bouncy-castle-java/) ([source](https://redirect.github.com/bcgit/bc-java)) | devDependencies | minor | `1.84` → `1.85` |  |  | | [org.bouncycastle:bcutil-jdk18on](https://www.bouncycastle.org/download/bouncy-castle-java/) ([source](https://redirect.github.com/bcgit/bc-java)) | devDependencies | minor | `1.84` → `1.85` |  |  | | [org.bouncycastle:bcprov-jdk18on](https://www.bouncycastle.org/download/bouncy-castle-java/) ([source](https://redirect.github.com/bcgit/bc-java)) | devDependencies | minor | `1.84` → `1.85.2` |  |  | | [org.bouncycastle:bcpkix-jdk18on](https://www.bouncycastle.org/download/bouncy-castle-java/) ([source](https://redirect.github.com/bcgit/bc-java)) | devDependencies | minor | `1.84` → `1.85` |  |  | | [commons-codec:commons-codec](https://commons.apache.org/proper/commons-codec/) ([source](https://redirect.github.com/apache/commons-codec)) | devDependencies | patch | `1.22.0` → `1.22.1` |  |  | | [org.mock-server:mockserver-junit-jupiter](https://www.mock-server.com) ([source](https://redirect.github.com/mock-server/mockserver-monorepo)) | devDependencies | minor | `5.14.0` → `5.15.0` |  |  | | [com.github.spotbugs:spotbugs-annotations](https://spotbugs.github.io/) ([source](https://redirect.github.com/spotbugs/spotbugs)) | devDependencies | minor | `4.9.8` → `4.10.3` |  |  | | [io.github.classgraph:classgraph](https://redirect.github.com/classgraph/classgraph) | devDependencies | patch | `4.8.184` → `4.8.192` |  |  | | [joda-time:joda-time](https://www.joda.org/joda-time/) ([source](https://redirect.github.com/JodaOrg/joda-time)) | devDependencies | patch | `2.14.2` → `2.14.3` |  |  | | [org.apache.httpcomponents.core5:httpcore5-h2](https://hc.apache.org/) ([source](https://redirect.github.com/apache/httpcomponents-core)) | devDependencies | patch | `5.4` → `5.4.3` |  |  | | [org.apache.httpcomponents.core5:httpcore5](https://hc.apache.org/) ([source](https://redirect.github.com/apache/httpcomponents-core)) | devDependencies | patch | `5.4` → `5.4.3` |  |  | | [org.apache.tika:tika-parser-image-module](https://tika.apache.org/) ([source](https://redirect.github.com/apache/tika)) | devDependencies | patch | `3.3.0` → `3.3.2` |  |  | | org.cyclonedx.bom | plugin | minor | `3.2.4` → `3.4.1` |  |  | | com.gradleup.shadow | plugin | minor | `9.4.1` → `9.6.1` |  |  | | org.openapi.generator | plugin | minor | `7.22.0` → `7.24.0` |  |  | | com.github.spotbugs | plugin | patch | `6.5.4` → `6.5.10` |  |  | | com.github.andygoossens.modernizer | plugin | minor | `1.13.0` → `1.15.0` |  |  | | com.google.cloud.tools.jib | plugin | patch | `3.5.3` → `3.5.4` |  |  | | [org.apache.tika:tika-parser-microsoft-module](https://tika.apache.org/) ([source](https://redirect.github.com/apache/tika)) | devDependencies | patch | `3.3.0` → `3.3.2` |  |  | | io.swagger.core.v3.swagger-gradle-plugin | plugin | patch | `2.2.49` → `2.2.53` |  |  | | org.springframework.boot | plugin | patch | `3.5.15` → `3.5.16` |  |  | | [org.apache.tika:tika-parser-miscoffice-module](https://tika.apache.org/) ([source](https://redirect.github.com/apache/tika)) | devDependencies | patch | `3.3.0` → `3.3.2` |  |  | | [org.apache.tika:tika-core](https://tika.apache.org/) ([source](https://redirect.github.com/apache/tika)) | devDependencies | patch | `3.3.0` → `3.3.2` |  |  | | [com.github.librepdf:openpdf](https://redirect.github.com/LibrePDF/OpenPDF) | devDependencies | patch | `3.0.4` → `3.0.5` |  |  | | [software.amazon.msk:aws-msk-iam-auth](https://docs.aws.amazon.com/msk/latest/developerguide/iam-access-control.html) ([source](https://redirect.github.com/aws/aws-msk-iam-auth)) | devDependencies | patch | `2.3.6` → `2.3.7` |  |  | | [org.apache.commons:commons-collections4](https://commons.apache.org/proper/commons-collections/) ([source](https://gitbox.apache.org/repos/asf?p=commons-collections.git)) | devDependencies | minor | `4.5.0` → `4.6.0` |  |  | | [com.google.googlejavaformat:google-java-format](https://redirect.github.com/google/google-java-format) | devDependencies | minor | `1.35.0` → `1.36.1` |  |  | | [ch.qos.logback:logback-classic](http://logback.qos.ch) ([source](https://redirect.github.com/qos-ch/logback), [changelog](https://logback.qos.ch/news.html)) | devDependencies | minor | `1.5.35` → `1.6.3` |  |  | | [ch.qos.logback:logback-core](http://logback.qos.ch) ([source](https://redirect.github.com/qos-ch/logback), [changelog](https://logback.qos.ch/news.html)) | devDependencies | minor | `1.5.35` → `1.6.3` |  |  | | [org.glassfish.jersey:jersey-bom](https://projects.eclipse.org/projects/ee4j) ([source](https://redirect.github.com/eclipse-ee4j/ee4j)) | devDependencies | patch | `3.1.11` → `3.1.12` |  |  | | [software.amazon.awssdk:bom](https://aws.amazon.com/sdkforjava) | devDependencies | minor | `2.44.4` → `2.53.1` |  |  | | [io.cucumber:cucumber-bom](https://cucumber.io/) ([source](https://redirect.github.com/cucumber/cucumber-jvm)) | devDependencies | patch | `7.34.3` → `7.34.7` |  |  | | [com.fasterxml.jackson:jackson-bom](https://redirect.github.com/FasterXML/jackson-bom) | devDependencies | patch | `2.22.1` → `2.22.2` |  |  | | [org.jetbrains.kotlin:kotlin-bom](https://kotlinlang.org/) ([source](https://redirect.github.com/JetBrains/kotlin)) | devDependencies | minor | `2.3.21` → `2.4.10` |  |  | | [io.opentelemetry:opentelemetry-bom](https://redirect.github.com/open-telemetry/opentelemetry-java) | devDependencies | minor | `1.62.0` → `1.65.0` |  |  | | [io.awspring.cloud:spring-cloud-aws-dependencies](https://projects.spring.io/spring-cloud/) ([source](https://redirect.github.com/awspring/spring-cloud-aws)) | devDependencies | minor | `4.0.2` → `4.1.0` |  |  | | [org.springframework.boot:spring-boot-dependencies](https://spring.io/projects/spring-boot) ([source](https://redirect.github.com/spring-projects/spring-boot)) | devDependencies | patch | `3.5.15` → `3.5.16` |  |  | | [io.micrometer:micrometer-bom](https://redirect.github.com/micrometer-metrics/micrometer) | devDependencies | minor | `1.16.5` → `1.17.0` |  |  | | [org.slf4j:slf4j-bom](http://www.slf4j.org) ([source](https://redirect.github.com/qos-ch/slf4j), [changelog](https://www.slf4j.org/news.html)) | devDependencies | patch | `2.0.17` → `2.0.18` |  |  | | com.gradle.common-custom-user-data-gradle-plugin | plugin | minor | `2.6.0` → `2.8.0` |  |  | --- ### Release Notes <details> <summary>apache/kafka (apache/kafka)</summary> ### [`v4.3.1`](https://redirect.github.com/apache/kafka/compare/4.3.0...4.3.1) [Compare Source](https://redirect.github.com/apache/kafka/compare/4.3.0...4.3.1) ### [`v4.3.0`](https://redirect.github.com/apache/kafka/compare/4.2.1...4.3.0) [Compare Source](https://redirect.github.com/apache/kafka/compare/4.2.1...4.3.0) ### [`v4.2.1`](https://redirect.github.com/apache/kafka/compare/4.2.0...4.2.1) [Compare Source](https://redirect.github.com/apache/kafka/compare/4.2.0...4.2.1) </details> <details> <summary>gradle/actions (gradle/actions)</summary> ### [`v6.3.0`](https://redirect.github.com/gradle/actions/releases/tag/v6.3.0) [Compare Source](https://redirect.github.com/gradle/actions/compare/v6.2.0...v6.3.0) #### Highlights ##### Enhanced Caching: Windows fixes and a cache-protocol bump This release updates `gradle-actions-caching` to **v1.0.0** (up from v0.7.0), which fixes two significant caching defects, both most visible on Windows: - **Cache entries failed to store at all on Windows.**. Every entry failed with `Path Validation Error: Path(s) specified in the action for caching do(es) not exist`, even though the Gradle User Home was fully intact. Nothing was stored, so every downstream job ran against an empty Gradle User Home. The cause was a nested, unpatched copy of `@actions/glob` combined with a silently swallowed `require()` in the bundle, which left Windows path separators unnormalized. - **Cache cleanup deleted instrumented jars that were in use.** A bug in key hashing for paths shorter than 64 characters made cleanup judge freshly created `caches/jars-9` entries as unused and remove them, so the `instrumented-jars` entry was never saved and every job re-instrumented its classpaths. Also included: cache entry names are now consistent between the save and restore reports — restore previously fell back to showing the raw glob pattern (e.g. `/home/runner/.gradle/caches/modules-*/files-*/*/*/*/*/`) instead of `dependencies`. > \[!IMPORTANT] > **Existing cache entries are invalidated by this release.** The cache protocol > version was bumped to `v2`, so the first run after upgrading will be a cache miss > and will repopulate the cache. No configuration changes are required. ##### Basic caching warns instead of failing silently The basic (open-source) caching provider now emits a warning and reports `(Entry not saved: save failed)` in the Job Summary when a cache save fails, rather than reporting success ([#​1028](https://redirect.github.com/gradle/actions/issues/1028)). ##### Dependency submission works with Isolated Projects `dependency-submission` now disables Isolated Projects via a promoted property, so dependency graph generation works on builds that enable it ([#​1025](https://redirect.github.com/gradle/actions/issues/1025)). Thanks to [@​reinsch82](https://redirect.github.com/reinsch82) for the contribution. ##### Updated defaults - Injected Develocity Gradle plugin: **4.4.2 → 4.5.0** - 36 new known-good wrapper checksums added for `wrapper-validation` #### What's Changed - Render configuration-cache status in the caching Job Summary by [@​bigdaz](https://redirect.github.com/bigdaz) in [#​989](https://redirect.github.com/gradle/actions/pull/989) - Update gradle-actions-caching library to v0.8.0 by [@​bot-githubaction](https://redirect.github.com/bot-githubaction) in [#​993](https://redirect.github.com/gradle/actions/pull/993) - Support experimental project-entry caching (configuration-cache + build-logic) by [@​bigdaz](https://redirect.github.com/bigdaz) in [#​994](https://redirect.github.com/gradle/actions/pull/994) - Update gradle-actions-caching library to v0.9.0 by [@​bot-githubaction](https://redirect.github.com/bot-githubaction) in [#​996](https://redirect.github.com/gradle/actions/pull/996) - Disable Isolated Projects via promoted property in dependency-submission by [@​reinsch82](https://redirect.github.com/reinsch82) in [#​1025](https://redirect.github.com/gradle/actions/pull/1025) - Add Windows coverage for caching via a new smoke-test suite by [@​bigdaz](https://redirect.github.com/bigdaz) in [#​1027](https://redirect.github.com/gradle/actions/pull/1027) - Fix basic caching smoke test on Windows, and warn on save failure by [@​bigdaz](https://redirect.github.com/bigdaz) in [#​1028](https://redirect.github.com/gradle/actions/pull/1028) - Move non-smoke restore-gradle-home tests back to the integ-test suite by [@​bigdaz](https://redirect.github.com/bigdaz) in [#​1032](https://redirect.github.com/gradle/actions/pull/1032) - Bump npm-dependencies group with TypeScript 6.0.3, [@​types/node](https://redirect.github.com/types/node) 24.x, and security fixes by [@​bigdaz](https://redirect.github.com/bigdaz) in [#​1033](https://redirect.github.com/gradle/actions/pull/1033) - Bump Gradle Wrapper to 9.6.1, wrapper checksums, and Develocity plugin to 4.5.0 by [@​bigdaz](https://redirect.github.com/bigdaz) in [#​1034](https://redirect.github.com/gradle/actions/pull/1034) - Update gradle-actions-caching library to v1.0.0 by [@​bot-githubaction](https://redirect.github.com/bot-githubaction) in [#​1029](https://redirect.github.com/gradle/actions/pull/1029) - Bump the npm-dependencies group across 1 directory with 2 updates by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​1037](https://redirect.github.com/gradle/actions/pull/1037) - Bump the github-actions group across 2 directories with 9 updates by [@​dependabot](https://redirect.github.com/dependabot)\[bot] in [#​1024](https://redirect.github.com/gradle/actions/pull/1024) #### New Contributors - [@​reinsch82](https://redirect.github.com/reinsch82) made their first contribution in [#​1025](https://redirect.github.com/gradle/actions/pull/1025) **Full Changelog**: <https://github.com/gradle/actions/compare/v6.2.0...v6.3.0> </details> <details> <summary>zizmorcore/zizmor-action (zizmorcore/zizmor-action)</summary> ### [`v0.6.2`](https://redirect.github.com/zizmorcore/zizmor-action/releases/tag/v0.6.2) [Compare Source](https://redirect.github.com/zizmorcore/zizmor-action/compare/v0.6.1...v0.6.2) zizmor 1.29.0 is now the default version. </details> <details> <summary>yawkat/lz4-java (at.yawk.lz4:lz4-java)</summary> ### [`v1.11.2`](https://redirect.github.com/yawkat/lz4-java/releases/tag/v1.11.2): lz4-java v1.11.2 **Security release for [GHSA-6cx8-rjf8-pr8g](https://redirect.github.com/yawkat/lz4-java/security/advisories/GHSA-6cx8-rjf8-pr8g) and [GHSA-4v53-57pg-c464](https://redirect.github.com/yawkat/lz4-java/security/advisories/GHSA-4v53-57pg-c464).** #### What's Changed - Update bnd.maven.plugin.version to v7.3.0 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​59](https://redirect.github.com/yawkat/lz4-java/pull/59) - Update dependency me.qoomon:maven-git-versioning-extension to v9.12.1 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​62](https://redirect.github.com/yawkat/lz4-java/pull/62) - Update dependency com.carrotsearch.randomizedtesting:randomizedtesting-runner to v2.9.1 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​60](https://redirect.github.com/yawkat/lz4-java/pull/60) - Update dependency maven to v3.9.16 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​57](https://redirect.github.com/yawkat/lz4-java/pull/57) - Update dependency com.code-intelligence:jazzer-junit to v0.30.0 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​61](https://redirect.github.com/yawkat/lz4-java/pull/61) - Pin dependencies by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​56](https://redirect.github.com/yawkat/lz4-java/pull/56) - Update dependency org.codehaus.mojo:build-helper-maven-plugin to v3.6.1 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​64](https://redirect.github.com/yawkat/lz4-java/pull/64) - Update dependency maven-wrapper to v3.3.4 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​63](https://redirect.github.com/yawkat/lz4-java/pull/63) - Update dependency org.apache.maven.plugins:maven-source-plugin to v3.4.0 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​69](https://redirect.github.com/yawkat/lz4-java/pull/69) - Update actions/checkout action to v7 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​74](https://redirect.github.com/yawkat/lz4-java/pull/74) - Update junit-framework monorepo by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​72](https://redirect.github.com/yawkat/lz4-java/pull/72) - Update dependency org.apache.maven.plugins:maven-antrun-plugin to v3.2.0 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​65](https://redirect.github.com/yawkat/lz4-java/pull/65) - Update dependency org.sonatype.central:central-publishing-maven-plugin to v0.11.0 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​71](https://redirect.github.com/yawkat/lz4-java/pull/71) - Update dependency org.apache.maven.plugins:maven-compiler-plugin to v3.15.0 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​66](https://redirect.github.com/yawkat/lz4-java/pull/66) - Update dependency org.apache.maven.plugins:maven-jar-plugin to v3.5.1 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​67](https://redirect.github.com/yawkat/lz4-java/pull/67) - Update dependency org.apache.maven.plugins:maven-surefire-plugin to v3.5.6 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​70](https://redirect.github.com/yawkat/lz4-java/pull/70) - Update dependency org.apache.maven.plugins:maven-gpg-plugin to v3 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​77](https://redirect.github.com/yawkat/lz4-java/pull/77) - Update GitHub Artifact Actions (major) by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​78](https://redirect.github.com/yawkat/lz4-java/pull/78) - Update junit-framework monorepo to v6 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​79](https://redirect.github.com/yawkat/lz4-java/pull/79) - Update cloudflare/wrangler-action action to v4 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​76](https://redirect.github.com/yawkat/lz4-java/pull/76) - Update astral-sh/setup-uv action to v9 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​75](https://redirect.github.com/yawkat/lz4-java/pull/75) - Update 8BitJonny/gh-get-current-pr action to v4 by [@​renovate](https://redirect.github.com/renovate)\[bot] in [#​73](https://redirect.github.com/yawkat/lz4-java/pull/73) #### New Contributors - [@​renovate](https://redirect.github.com/renovate)\[bot] made their first contribution in [#​59](https://redirect.github.com/yawkat/lz4-java/pull/59) **Full Changelog**: <https://github.com/yawkat/lz4-java/compare/v1.11.1...v1.11.2> ### [`v1.11.1`](https://redirect.github.com/yawkat/lz4-java/releases/tag/v1.11.1): lz4-java v1.11.1 **Security release for [CVE-2026-59949](https://redirect.github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r).** #### What's Changed - Fix docs code block line breaks by [@​yawkat](https://redirect.github.com/yawkat) in [#​52](https://redirect.github.com/yawkat/lz4-java/pull/52) **Full Changelog**: <https://github.com/yawkat/lz4-java/compare/v1.11.0...v1.11.1> </details> <details> <summary>spring-projects/spring-security (org.springframework.security:spring-security-core)</summary> ### [`v6.5.11`](https://redirect.github.com/spring-projects/spring-security/releases/tag/6.5.11) [Compare Source](https://redirect.github.com/spring-projects/spring-security/compare/6.5.10...6.5.11) #### :beetle: Bug Fixes - `FormPostRedirectStrategy` should not emit percent-encoded values into hidden form inputs [#​19136](https://redirect.github.com/spring-projects/spring-security/issues/19136) #### :hammer: Dependency Upgrades - Bump antora from 3.2.0-alpha.11 to 3.2.0-alpha.12 in /docs [#​19185](https://redirect.github.com/spring-projects/spring-security/pull/19185) - Bump ch.qos.logback:logback-classic from 1.5.32 to 1.5.34 [#​19299](https://redirect.github.com/spring-projects/spring-security/pull/19299) - Bump com.fasterxml.jackson:jackson-bom from 2.18.6 to 2.18.7 [#​19129](https://redirect.github.com/spring-projects/spring-security/pull/19129) - Bump com.fasterxml.jackson:jackson-bom from 2.18.7 to 2.18.8 [#​19297](https://redirect.github.com/spring-projects/spring-security/pull/19297) - Bump gradle-wrapper from 8.14.4 to 8.14.5 [#​19159](https://redirect.github.com/spring-projects/spring-security/pull/19159) - Bump org-bouncycastle from 1.80 to 1.80.2 [#​19204](https://redirect.github.com/spring-projects/spring-security/pull/19204) - Bump org.apache.maven:maven-resolver-provider from 3.9.15 to 3.9.16 [#​19205](https://redirect.github.com/spring-projects/spring-security/pull/19205) - Bump org.hibernate.orm:hibernate-core from 6.6.49.Final to 6.6.50.Final [#​19150](https://redirect.github.com/spring-projects/spring-security/pull/19150) - Bump org.hibernate.orm:hibernate-core from 6.6.50.Final to 6.6.51.Final [#​19213](https://redirect.github.com/spring-projects/spring-security/pull/19213) - Bump org.hibernate.orm:hibernate-core from 6.6.51.Final to 6.6.53.Final [#​19300](https://redirect.github.com/spring-projects/spring-security/pull/19300) - Bump org.slf4j:slf4j-api from 2.0.17 to 2.0.18 [#​19173](https://redirect.github.com/spring-projects/spring-security/pull/19173) - Bump org.springframework:spring-framework-bom from 6.2.18 to 6.2.19 [#​19293](https://redirect.github.com/spring-projects/spring-security/pull/19293) - Bump spring-io/spring-gradle-build-action from 2.0.5 to 2.0.6 [#​19124](https://redirect.github.com/spring-projects/spring-security/pull/19124) - Bump spring-io/spring-release-actions from 0.0.4 to 0.0.5 [#​19183](https://redirect.github.com/spring-projects/spring-security/pull/19183) - Update micrometer-bom to 1.15.12 [#​19302](https://redirect.github.com/spring-projects/spring-security/issues/19302) - Update to Micrometer 1.15.11 [#​19224](https://redirect.github.com/spring-projects/spring-security/issues/19224) - Update to reactor-bom 2024.0.18 [#​19301](https://redirect.github.com/spring-projects/spring-security/issues/19301) #### :nut\_and\_bolt: Build Updates - Release 6.5.11 [#​19118](https://redirect.github.com/spring-projects/spring-security/issues/19118) </details> <details> <summary>spring-projects/spring-framework (org.springframework:spring-core)</summary> ### [`v6.2.19`](https://redirect.github.com/spring-projects/spring-framework/releases/tag/v6.2.19) #### :warning: Security Fixes This maintenance release fixes a high number of CVEs. You can learn more about this in the ["Spring and Security In The Times Of AI"](https://spring.io/blog/2026/06/01/spring_and_security_in_the_times_of_ai) blog post. Here is the full list of 16 CVEs: - [CVE-2026-41838](https://spring.io/security/cve-2026-41838) "Spring Framework Predictable Session ID in WebSocket Module" - [CVE-2026-41839](https://spring.io/security/cve-2026-41839) "Spring Framework Escalation via Session Fixation in WebFlux" - [CVE-2026-41840](https://spring.io/security/cve-2026-41840) "Spring Framework Denial of Service via Multipart Requests in WebFlux" - [CVE-2026-41841](https://spring.io/security/cve-2026-41841) "Spring Framework Information Disclosure via Static Resource Cache in Spring MVC and WebFlux" - [CVE-2026-41842](https://spring.io/security/cve-2026-41842) "Spring Framework Denial of Service via Versioned Resources in Spring MVC and WebFlux" - [CVE-2026-41843](https://spring.io/security/cve-2026-41843) "Spring Framework Path Traversal via Versioned Static Resources in Spring MVC and WebFlux" - [CVE-2026-41844](https://spring.io/security/cve-2026-41844) "Spring Framework Open Redirect in Spring MVC and WebFlux" - [CVE-2026-41845](https://spring.io/security/cve-2026-41845) "Spring Framework Cross-site Scripting via JavaScriptUtils" - [CVE-2026-41846](https://spring.io/security/cve-2026-41846) "Spring Framework Cross-site Scripting via JSP Form Tags" - [CVE-2026-41848](https://spring.io/security/cve-2026-41848) "Spring Framework Denial of Service via AntPathMatcher" - [CVE-2026-41850](https://spring.io/security/cve-2026-41850) "Spring Framework Algorithmic Denial of Service via SpEL Expressions" - [CVE-2026-41851](https://spring.io/security/cve-2026-41851) "Spring Framework Denial of Service via Unbounded Cache in SpEL" - [CVE-2026-41852](https://spring.io/security/cve-2026-41852) "Spring Framework Arbitrary Method Invocation in SpEL Expressions" - [CVE-2026-41853](https://spring.io/security/cve-2026-41853) "Spring Framework Multipart Request Smuggling in Spring MVC and WebFlux" - [CVE-2026-41854](https://spring.io/security/cve-2026-41854) "Spring Framework Server-Side Request Forgery via UriComponentsBuilder" - [CVE-2026-41855](https://spring.io/security/cve-2026-41855) "Spring Framework Unsafe Deserialization via Jackson JMS Converters" #### :star: New Features - Avoid too many character access attempts in `AntPathMatcher` [#​36886](https://redirect.github.com/spring-projects/spring-framework/issues/36886) - Track operations during SpEL expression evaluation [#​36887](https://redirect.github.com/spring-projects/spring-framework/issues/36887) - Ensure getters have non-void return types in SpEL [#​36888](https://redirect.github.com/spring-projects/spring-framework/issues/36888) - Expose `ClassLoader` from `DefaultDeserializer` [#​36839](https://redirect.github.com/spring-projects/spring-framework/issues/36839) - Refine default view name resolution [#​36794](https://redirect.github.com/spring-projects/spring-framework/issues/36794) - Refine Jackson JMS converters [#​36792](https://redirect.github.com/spring-projects/spring-framework/issues/36792) - Improve ABNF rule checks in RfcUriParser [#​36788](https://redirect.github.com/spring-projects/spring-framework/issues/36788) - Detect custom deserialized `NullValue` instances in `AbstractValueAdaptingCache` [#​36728](https://redirect.github.com/spring-projects/spring-framework/issues/36728) - Warn against unsafe static resource lo > ✂ **Note** > > PR body was truncated to here. </details> --- ### Configuration 📅 **Schedule**: (UTC) - Branch creation - Between 12:00 AM and 03:59 AM, only on Monday (`* 0-3 * * 1`) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config help](https://redirect.github.com/renovatebot/renovate/discussions) if that's undesired. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR was generated by [Mend Renovate](https://mend.io/renovate/). View the [repository job log](https://developer.mend.io/github/apache/fineract). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4yOS41IiwidXBkYXRlZEluVmVyIjoiNDQuMjkuNSIsInRhcmdldEJyYW5jaCI6ImRldmVsb3AiLCJsYWJlbHMiOlsicmVub3ZhdGUiXX0=--> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
