skrcode opened a new pull request, #4268: URL: https://github.com/apache/logging-log4j2/pull/4268
## Summary This completes the Maven patch update in apache/logging-log4j2#4204 by aligning Log4j's managed Guava version with Maven 3.9.16. The Dependabot branch updates Maven from 3.9.10 to 3.9.16. Maven 3.9.16 brings Guava 33.6.0-jre, while `log4j-parent` still manages 33.4.8-jre, so `RequireUpperBoundDeps` fails in `log4j-api-test` on Linux, macOS, and Windows. ## Change - Update the existing `guava.version` property from `33.4.8-jre` to `33.6.0-jre`. - Leave the other 31 grouped dependency updates unchanged. This is the smallest dependency-management change that resolves the convergence failure. ## Verification - Reproduced the original `RequireUpperBoundDeps` failure in `log4j-api-test` against the unmodified Dependabot commit. - `./mvnw ... -pl :log4j-api-test validate` — passed after the change; all Enforcer rules are green. - Dependency tree inspection confirms `org.apache.maven:maven-core:3.9.16` now resolves managed `com.google.guava:guava:33.6.0-jre`. - `./mvnw ... -DtrimStackTrace=false -DinstallAtEnd=true clean install` — passed all 41 reactor modules, including tests, Enforcer, SpotBugs, RAT, Spotless, OSGi checks, API baselines, SBOM generation, and artifact installation. - `./mvnw ... -DskipTests site` — passed all 41 reactor modules and generated the Antora/Javadoc site lane. - `git diff --check` — clean. The failing upstream matrix is visible in [the Dependabot workflow run](https://github.com/apache/logging-log4j2/actions/runs/30080446783). Built and verified with [JAIPilot](https://github.com/JAIPilot/jaipilot): - Skills: `jaipilot-maintainer-intent`, `jaipilot-fast-execution`, and `jaipilot-review-diff` - Execution profile: `gpt-5.6-sol · xhigh · fast` -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
