Skip to content

chore(deps): bump org.apache.tika:tika-core from 4.0.0 to 4.1.0 - #466

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/org.apache.tika-tika-core-4.1.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/org.apache.tika-tika-core-4.1.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 5, 2026

Copy link
Copy Markdown
Contributor

Bumps org.apache.tika:tika-core from 4.0.0 to 4.1.0.

Changelog

Sourced from org.apache.tika:tika-core's changelog.

Release 4.2.0 - unreleased

  • Refactor date parsing for more consistent, accurate dates. File-system times from archive entries and mail attachments move to fs:created/ fs:modified. MailDateParser is superseded by TikaDates and MailUtil moved to org.apache.tika.parser.mail in tika-parser-mail-module; tika-parser-mail-commons remains as a deprecated shim and will be removed in 4.3.0. DateNormalizingMetadataFilter honors explicit offsets, normalizes every value of a multi-valued key, and fills in partial dates (2019 -> 2019-01-01T12:00:00Z) so date fields never reject a document (TIKA-4917).

  • Fix a StackOverflowError when parsing or detecting through the Parser and Detector services tika-bundle-standard registers in OSGi: the registered DefaultParser and DefaultDetector no longer consume dynamic services, and a dynamic DefaultParser or DefaultDetector no longer nests another dynamic one (TIKA-4942).

  • XmlSecurityContractTest pins XMLReaderUtils' XXE and entity-expansion defenses forbidden-apis now rejects building JAXP or Commons Secure XML parsers anywhere but XMLReaderUtils (TIKA-4939).

  • Retire Tika's entity expansion limit (default 20) in SAX, DOM and StAX parsing in favor of standard Java configuration methods (TIKA-4940).

  • Report the external DTDs and entities a document's XML referenced, which Tika never resolves: tk:xml-external-reference (up to 20 system ids) and tk:xml-external-reference-count on that document's metadata, and tk:xml-external-reference-embedded on a container whose embedded document had any. Every resolver Tika installs answers with an empty stream, never null (TIKA-4941).

  • Deprecate XMLReaderUtils.getXMLInputFactory() and use SAX for XFA (TIKA-4938).

  • Raise the default maxFilesProcessedPerProcess from 10,000 to 100,000; forked pipes JVMs restart a tenth as often (TIKA-4950).

  • Quiet default pipes logging: per-parse timing lines (WORKER/CLIENT/ SERVER/RESOURCE_TIMING) move from INFO to TRACE, and per-fork-start, per-connection and plugin lifecycle lines move to DEBUG (TIKA-4949).

  • tika-core's OSGi manifest no longer requires a Service Loader Mediator or providers for Parser, Detector, EncodingDetector, LanguageDetector and MetadataFilter; 4.1.0 failed to install on its own in Equinox/p2 (TIKA-4945).

Release 4.1.0 - 9/26/2026

HIGHLIGHTS

  • OCR and enrichment engines are selected by name in a new "text-recognizers" list ("[]" turns enrichment off; no list resolves one engine per media type at startup); the image and PDF parsers invoke them

... (truncated)

Commits
  • e8dd07a [maven-release-plugin] prepare release 4.1.0-rc3
  • e53a7b4 TIKA-4836: update aws
  • 4df21a6 prep for rc3
  • e6bc8be TIKA-4933: build the .run-info test fixture at test time; the source release ...
  • f0b7ad7 [maven-release-plugin] prepare for next development iteration
  • 5a75213 [maven-release-plugin] prepare release 4.1.0-rc2
  • bb1f6f2 update CHANGES.txt
  • 5c1cda5 TIKA-4932: pipes no longer copies the caller's Content-Type hint back… (#3258)
  • ebc845c TIKA-4931: fix overrides in PipesForkParser (#3257)
  • 739a9c3 TIKA-4927: overwrite stale NER test models with the verified cache copy (#3256)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [org.apache.tika:tika-core](https://github.com/apache/tika) from 4.0.0 to 4.1.0.
- [Changelog](https://github.com/apache/tika/blob/main/CHANGES.txt)
- [Commits](apache/tika@4.0.0...4.1.0)

---
updated-dependencies:
- dependency-name: org.apache.tika:tika-core
  dependency-version: 4.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependency-upgrade Dependency upgrade is needed label Oct 5, 2026
@kestrabot kestrabot Bot added this to Pull Requests Oct 5, 2026
@github-actions

github-actions Bot commented Oct 5, 2026 •

Copy link
Copy Markdown
Contributor
📦 Artifacts (1 jar)
Name Size Updated Expiration
jar 203.33 MB Oct 5, 26, 10:32:44 PM UTC Oct 12, 26, 10:32:36 PM UTC
🔎 OpenGrep ✅ (0 findings)

Found 0 finding(s).

🐷 TruffleHog ✅ (0 secrets)

No secret found.

🧪 Java Unit Tests ✅ (0 failed, 183 passed, 81 skipped)
TestsPassed ✅Skipped ⚠️FailedTime ⏱
Java Tests Report264 ran183 ✅81 ⚠️0 ❌53s 332ms
🔁 Unreleased Commits ✅ (0 commits)

✅ No unreleased commits found.

@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

Tests report quick summary:

success ✅ > tests: 264, success: 183, skipped: 81, failed: 0

unfold for details
Project Status Success Skipped Failed
plugin-ai success ✅ 183 81 0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependency-upgrade Dependency upgrade is needed

Projects

Status: To review

Development

Successfully merging this pull request may close these issues.

0 participants