dependabot[bot] opened a new pull request, #2195: URL: https://github.com/apache/maven-resolver/pull/2195
Bumps [org.eclipse.jetty:jetty-bom](https://github.com/jetty/jetty.project) from 12.1.13 to 12.1.14. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/jetty/jetty.project/releases">org.eclipse.jetty:jetty-bom's releases</a>.</em></p> <blockquote> <h2>12.1.14</h2> <h1>Special Thanks to the following Eclipse Jetty community members</h1> <ul> <li><a href="https://github.com/adityaanikam"><code>@adityaanikam</code></a> (Aditya Nikam)</li> <li><a href="https://github.com/wendigo"><code>@wendigo</code></a> (Mateusz "Serafin" Gajewski)</li> </ul> <h1>Changelog</h1> <ul> <li><a href="https://redirect.github.com/jetty/jetty.project/issues/15874">#15874</a> - [12.1.x] Introduced recursion depth limit in JSON parsing.</li> <li><a href="https://redirect.github.com/jetty/jetty.project/issues/15871">#15871</a> - SessionHandler uses ConnectionMetaData.isSecure() instead of Request.isSecure(), breaking secure session cookies behind ForwardedRequestCustomizer (<a href="https://github.com/adityaanikam"><code>@adityaanikam</code></a>)</li> <li><a href="https://redirect.github.com/jetty/jetty.project/issues/15869">#15869</a> - <code>PathResource</code> incorrectly treats a classpath resource inside a JAR under a non-ASCII path as an alias</li> <li><a href="https://redirect.github.com/jetty/jetty.project/issues/15852">#15852</a> - Upgrade quiche to version 0.30.0</li> <li><a href="https://redirect.github.com/jetty/jetty.project/issues/15846">#15846</a> - Allow per-request form limits to be used with EE8/EE9</li> <li><a href="https://redirect.github.com/jetty/jetty.project/issues/15840">#15840</a> - HTTP/1 response header overflow retry loses previously determined connection persistence</li> <li><a href="https://redirect.github.com/jetty/jetty.project/issues/15839">#15839</a> - Simplified callback method notifications.</li> <li><a href="https://redirect.github.com/jetty/jetty.project/issues/15822">#15822</a> - Introduce flag in Rewrite Rules to preserve UriCompliance Violations when rewriting URIs</li> <li><a href="https://redirect.github.com/jetty/jetty.project/issues/15807">#15807</a> - ArrayByteBufferPool.clear() leaves the bucket's secondary QueuedPool poisoned: NPE on the next acquire()</li> <li><a href="https://redirect.github.com/jetty/jetty.project/issues/15733">#15733</a> - ee11 servlet: ServletRequest.getServletContext() returns the source context, not the target, after a cross-context RequestDispatcher.include()</li> <li><a href="https://redirect.github.com/jetty/jetty.project/issues/15679">#15679</a> - Fixes race for HTTP3StreamConnection release of Chunk</li> <li><a href="https://redirect.github.com/jetty/jetty.project/issues/15678">#15678</a> - CompressionHandler randomly truncates output</li> <li><a href="https://redirect.github.com/jetty/jetty.project/issues/15675">#15675</a> - Optimize Huffman codec (<a href="https://github.com/wendigo"><code>@wendigo</code></a>)</li> <li><a href="https://redirect.github.com/jetty/jetty.project/issues/15674">#15674</a> - Optimize HPack (<a href="https://github.com/wendigo"><code>@wendigo</code></a>)</li> <li><a href="https://redirect.github.com/jetty/jetty.project/issues/15432">#15432</a> - BrotliEncoderSink drops all but the last pulled buffer, silently truncating large Brotli responses</li> <li><a href="https://redirect.github.com/jetty/jetty.project/issues/15386">#15386</a> - Issues in http2 stream idle timeouts</li> <li><a href="https://redirect.github.com/jetty/jetty.project/issues/15368">#15368</a> - HTTP/2 client aborts exchange and loses response completed during server graceful shutdown (regression in 12.1.10 / 12.0.36 from <a href="https://redirect.github.com/jetty/jetty.project/issues/15134">#15134</a> / <a href="https://redirect.github.com/jetty/jetty.project/issues/14692">#14692</a>)</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/jetty/jetty.project/commit/15cecbd757a2f6b0fdc6a8944f4c6d0020b17da0"><code>15cecbd</code></a> Updating to version 12.1.14</li> <li><a href="https://github.com/jetty/jetty.project/commit/4f315a10636c07b18ba384d071e11d6e0ea9720c"><code>4f315a1</code></a> Issue <a href="https://redirect.github.com/jetty/jetty.project/issues/15871">#15871</a> - Fix SessionHandler ignoring forwarded secure status (<a href="https://redirect.github.com/jetty/jetty.project/issues/15873">#15873</a>)</li> <li><a href="https://github.com/jetty/jetty.project/commit/134a7e9d23ed27e941ef90ddc3deac9f81686bcb"><code>134a7e9</code></a> <a href="https://redirect.github.com/jetty/jetty.project/issues/15869">#15869</a> fix PathResource.isAlias() when the path' URI is not encoded the same ...</li> <li><a href="https://github.com/jetty/jetty.project/commit/979f9acdb0f952fd878682ed543d632750592e12"><code>979f9ac</code></a> Merge pull request <a href="https://redirect.github.com/jetty/jetty.project/issues/15679">#15679</a> from jetty/fix/jetty-12.1.x/HTTP3StreamConnection-race</li> <li><a href="https://github.com/jetty/jetty.project/commit/a291a6691dfaab4efe6c5098865a3a24ef00106e"><code>a291a66</code></a> Issue <a href="https://redirect.github.com/jetty/jetty.project/issues/15733">#15733</a> Fix cross-context dispatch to use the target context (<a href="https://redirect.github.com/jetty/jetty.project/issues/15763">#15763</a>)</li> <li><a href="https://github.com/jetty/jetty.project/commit/73383fba03b616e6fd39116b7b02bf3c7cac85d7"><code>73383fb</code></a> Merge pull request <a href="https://redirect.github.com/jetty/jetty.project/issues/15846">#15846</a> from jetty/fix/jetty-12.1.x/ee9-per-request-form-li...</li> <li><a href="https://github.com/jetty/jetty.project/commit/1f2511916c553948492fcd8db962d511375d3ffb"><code>1f25119</code></a> Fixes <a href="https://redirect.github.com/jetty/jetty.project/issues/15368">#15368</a> - Fix incorrect eager aborting of H2 channels during graceful sh...</li> <li><a href="https://github.com/jetty/jetty.project/commit/6d7b56e4fe194430d8bfc4a663fb070e81633929"><code>6d7b56e</code></a> Fixes <a href="https://redirect.github.com/jetty/jetty.project/issues/15666">#15666</a> - Flaky Test: VirtualThreadsTest.testServletCallbacksInvokedOnVi...</li> <li><a href="https://github.com/jetty/jetty.project/commit/37dcd42089085d25981bd7299daf7c3e764d9495"><code>37dcd42</code></a> [12.1.x] Introduced recursion depth limit in JSON parsing. (<a href="https://redirect.github.com/jetty/jetty.project/issues/15874">#15874</a>)</li> <li><a href="https://github.com/jetty/jetty.project/commit/24064edc433f9f0a18e3272df183b2a05d2a244c"><code>24064ed</code></a> Simplified callback method notifications. (<a href="https://redirect.github.com/jetty/jetty.project/issues/15839">#15839</a>)</li> <li>Additional commits viewable in <a href="https://github.com/jetty/jetty.project/compare/jetty-12.1.13...jetty-12.1.14">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
