Skip to content

build: bump the maven group across 1 directory with 6 updates - #197

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/maven-456442abca
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/maven-456442abca

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 19, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the maven group with 6 updates in the / directory:

Package From To
org.codehaus.mojo:build-helper-maven-plugin 3.6.1 3.6.2
com.diffplug.spotless:spotless-maven-plugin 3.9.0 3.10.2
com.github.spotbugs:spotbugs-maven-plugin 4.10.3.0 4.10.4.1
org.apache.maven.plugins:maven-surefire-plugin 3.5.6 3.6.0
dev.sigstore:sigstore-maven-plugin 2.2.0 2.3.0
io.github.mavenplugins:central-publishing-maven-plugin 1.3.0 1.3.1

Updates org.codehaus.mojo:build-helper-maven-plugin from 3.6.1 to 3.6.2

Release notes

Sourced from org.codehaus.mojo:build-helper-maven-plugin's releases.

3.6.2

🐛 Bug Fixes

👻 Maintenance

  • Remove redundant maven-resolver-api dependency and ignore Resolver/SLF4J 2.x in Dependabot (#248) @​slachiewicz

📦 Dependency updates

Commits
  • 813bc7d [maven-release-plugin] prepare release 3.6.2
  • 07d9109 Remove redundant maven-resolver-api and ignore Resolver/SLF4J 2.x in Dependabot
  • 9abd552 Bump org.codehaus.plexus:plexus-utils from 4.0.3 to 4.1.0
  • 3c15526 Bump apache/maven-gh-actions-shared/.github/workflows/release-drafter.yml
  • 3b1f104 Bump org.codehaus.mojo:mojo-parent from 96 to 97
  • 1749855 Bump apache/maven-gh-actions-shared/.github/workflows/maven-verify.yml
  • 5230041 Bump org.codehaus.plexus:plexus-utils from 4.0.2 to 4.0.3
  • c0e9375 Delete .github/release-drafter.yml
  • 84a839e Bump org.codehaus.mojo:mojo-parent from 95 to 96
  • a85c668 Replace raw NPEx with customized exception message
  • Additional commits viewable in compare view

Updates com.diffplug.spotless:spotless-maven-plugin from 3.9.0 to 3.10.2

Release notes

Sourced from com.diffplug.spotless:spotless-maven-plugin's releases.

Maven Plugin v3.10.2

Fixed

  • <shortenFullyQualifiedTypes> now shortens fully-qualified types used in expression contexts (such as static method calls, static fields, and enum constants) while avoiding imports that would change how existing unqualified type references resolve. (#3039)
  • Eclipse JDT formatter step no longer fails with NoClassDefFoundError when lombok is active as a JVM agent (e.g. -javaagent:lombok.jar in Eclipse/VS Code/Cursor). (#2795)

Maven Plugin v3.10.1

Fixed

  • <prettier> and other npm-based steps no longer fail to start on npm 12 (EUNKNOWNCONFIG from --scripts-prepend-node-path). (#3024)

Maven Plugin v3.10.0

Added

  • New <shortenFullyQualifiedTypes> step for Java, which replaces fully-qualified type names with their simple names and adds the imports they need. Best combined with <importOrder> and <removeUnusedImports>. (#2945)
  • Add embedded lockfiles to Eclipse JDT for every supported version (4.9 through 4.40), so eclipse() resolves from Maven Central instead of querying a P2 update site. Versions without an embedded lockfile still fall back to P2 provisioning. (#1996)
  • Add support to apply alternate license header within same format (#872)
  • Add support to skip license header application based on source file content pattern (#650).

Fixed

  • removeUnusedImports no longer fails on Java import module declarations. (#2890)
  • Concurrent P2 provisioning no longer races Solstice's on-disk cache (affects Eclipse-based formatters under parallel builds). (#3004)

Changes

  • Default google-java-format remains 1.28.0 on JVM 17; bumps to 1.30.0 on JVM 21+; require at least 1.30.0 on JVM 25+ for import module support.
  • Bump default eclipse version to latest 4.39 -> 4.40. (#1996)
  • Document Maven skip properties spotless.skip, spotless.check.skip, and spotless.apply.skip. Goal-specific skips now live on their own mojos so they no longer leak across goals. (#3009)
  • Bump default adocfmt version 0.2.0 -> 0.3.1, which adds table formatting support (<formatTables>, <tableLayout>, <tableMaxLineWidth>, <tableBlankLines>).
Commits
  • dc2a4cb Published maven/3.10.2
  • 876c8c4 Published gradle/8.10.2
  • ff28375 Published lib/4.10.2
  • e260aa7 shortenFullyQualifiedTypes: preserve unqualified type resolution (#3037)
  • 5a2cdca Update changelogs.
  • 98ca50e Merge remote-tracking branch 'origin/main' into 3033-unqualified-type-collision
  • 9591d7e Resolve interopability with spotless, lombok and VSCode (#3038)
  • 5842e1b shortenFullyQualifiedTypes: shorten FQTs in expression context (#3039)
  • e7f5b60 Add changelog entries
  • 79ff6c7 Resolve interopability with spotless, lombok and VSCode
  • Additional commits viewable in compare view

Updates com.github.spotbugs:spotbugs-maven-plugin from 4.10.3.0 to 4.10.4.1

Release notes

Sourced from com.github.spotbugs:spotbugs-maven-plugin's releases.

spotbugs-maven-plugin-4.10.4.1

BREAKING

In 2014, maven reporting added various settings that should have resulted in removal here but had gone unseen. These are now applied and therefore the state changed to immutable which will cause plugin to fail if users do not adjust configuration as noted here.

Users who previously configured outputEncoding directly on the SpotBugs Maven Plugin must configure project.reporting.outputEncoding instead and remove it to avoid errors. Users passing fork option should remove it to avoid warnings as support was gone in last release and it does nothing. Users who previously configured outputDirectory directly on the SpotBugs Maven Plugin must configure project.reporting.outputDirectory instead and remove it to avoid errors.

What's Changed

Full Changelog: spotbugs/spotbugs-maven-plugin@spotbugs-maven-plugin-4.10.4.0...spotbugs-maven-plugin-4.10.4.1

spotbugs-maven-plugin-4.10.4.0

What's Changed

New Contributors

Full Changelog: spotbugs/spotbugs-maven-plugin@spotbugs-maven-plugin-4.10.3.0...spotbugs-maven-plugin-4.10.4.0

Commits
  • 59f4efc [maven-release-plugin] prepare release spotbugs-maven-plugin-4.10.4.1
  • 1081359 Merge pull request #1519 from spotbugs/renovate/byte-buddy.version
  • 23caeff Merge pull request #1520 from spotbugs/renovate/slf4j-monorepo
  • 8a5d7f0 Update dependency org.slf4j:slf4j-bom to v2.0.19
  • 8be188f Update byte-buddy.version to v1.18.13
  • 742e10c Merge pull request #1518 from hazendaz/master
  • d7f6a56 Cleanup groovy in the trait
  • eda58b6 Cleanup groovy within report generator
  • a518d7b Cleanup xdocs reporter groovy each usage
  • 4c94029 Merge pull request #1517 from hazendaz/master
  • Additional commits viewable in compare view

Updates org.apache.maven.plugins:maven-surefire-plugin from 3.5.6 to 3.6.0

Release notes

Sourced from org.apache.maven.plugins:maven-surefire-plugin's releases.

3.6.0

Please refer to the main page for what's new https://maven.apache.org/surefire/ And the migration page https://maven.apache.org/surefire/maven-surefire-plugin/whats-new-3-6-0.html

🚀 New features and improvements

🐛 Bug Fixes

📝 Documentation updates

👻 Maintenance

... (truncated)

Commits
  • 0ff622b [maven-release-plugin] prepare release surefire-3.6.0
  • bb3932a Let's go for 3.6.0 release
  • 3002a16 Bump mavenVersion from 3.9.14 to 3.9.16
  • 61a531d Bump Maven parent version from 47 to 49 (#3449)
  • e52ead4 [SUREFIRE-523] Link all reported tests to source XRef (#3445)
  • 45102fa [SUREFIRE-3446] Fix direct selection of JUnit Jupiter @​Nested classes (#3447)
  • b2e1f70 Fix #3303: distinguish JUnit 6 ParameterizedClass invocations (#3432)
  • c051938 Discover tests in a fork when a toolchain JDK is used (#3444)
  • db75df8 Bump org.codehaus.plexus:plexus-java from 1.5.2 to 1.6.0 (#3441)
  • 77f2759 Bump org.codehaus.plexus:plexus-interpolation from 1.29 to 1.30.0
  • Additional commits viewable in compare view

Updates dev.sigstore:sigstore-maven-plugin from 2.2.0 to 2.3.0

Release notes

Sourced from dev.sigstore:sigstore-maven-plugin's releases.

v2.3.0

See CHANGELOG.md for more details.

What's Changed

... (truncated)

Changelog

Sourced from dev.sigstore:sigstore-maven-plugin's changelog.

[2.3.0] - 2026-09-08

Added

Fixed

Commits
  • a57658e Merge pull request #1269 from raphw/automatic-module-name
  • 921eefc Add Automatic-Module-Name to sigstore-java
  • cb46c4a Merge pull request #1283 from sigstore/renovate/com.gradleup.nmcp.aggregation
  • dc2476b Merge pull request #1284 from sigstore/renovate/com.google.guava
  • 73fd79d Merge pull request #1282 from sigstore/renovate/org.slf4j
  • b1f5074 Merge pull request #1281 from sigstore/renovate/org.eclipse.jetty
  • 07d4426 Merge pull request #1280 from sigstore/renovate/com.gradleup.nmcp
  • 76e15df Merge pull request #1279 from sigstore/renovate/com.diffplug.spotless
  • 1d8cc4b Merge pull request #1246 from hfhbd/isolated-projects
  • 832b1a7 Update dependency com.google.guava:guava to v33.7.1-jre
  • Additional commits viewable in compare view

Updates io.github.mavenplugins:central-publishing-maven-plugin from 1.3.0 to 1.3.1

Release notes

Sourced from io.github.mavenplugins:central-publishing-maven-plugin's releases.

v1.3.1

What's Changed

👻 Maintenance

  • Update central-publishing-maven-plugin version to 1.3.0 (#71) @​mhoffrog

🔧 Build

🛡️ Security

  • Bump com.fasterxml.jackson.core:jackson-databind from 2.16.1 to 2.18.9 in the maven group across 1 directory (#69) @dependabot[bot]
  • Bump org.apache.httpcomponents.client5:httpclient5 from 5.6.1 to 5.6.3 in the maven group across 1 directory (#70) @dependabot[bot]

📦 Dependency updates

  • Bump actions/checkout from 6 to 7 (#67) @dependabot[bot]
  • Bump com.fasterxml.jackson.core:jackson-databind from 2.16.1 to 2.18.9 in the maven group across 1 directory (#69) @dependabot[bot]
  • Bump org.codehaus.mojo:exec-maven-plugin from 3.1.0 to 3.6.3 (#64) @dependabot[bot]
  • Bump org.apache.maven:maven-compat from 3.9.15 to 3.9.16 (#65) @dependabot[bot]
  • Bump com.diffplug.spotless:spotless-maven-plugin from 2.46.1 to 3.7.0 (#66) @dependabot[bot]
  • Bump com.github.package-url:packageurl-java from 1.4.1 to 1.5.0 (#68) @dependabot[bot]
  • Bump org.apache.httpcomponents.client5:httpclient5 from 5.6.1 to 5.6.3 in the maven group across 1 directory (#70) @dependabot[bot]
  • Update central-publishing-maven-plugin version to 1.3.0 (#71) @​mhoffrog

❤️ Thanks

Many thanks for collaboration on this release for: @​mhoffrog

Full Changelog: mavenplugins/central-publishing-maven-plugin@v1.3.0...v1.3.1

Commits
  • 32f50b0 [unleash-maven-plugin] 1.3.1 -> 1.3.2-SNAPSHOT Preparation for tag v1.3.1
  • bea3331 Update central-publishing-maven-plugin version to 1.3.0
  • 7b2b84b Bump org.apache.httpcomponents.client5:httpclient5
  • 70887d7 Bump com.github.package-url:packageurl-java from 1.4.1 to 1.5.0
  • 855e958 Bump com.diffplug.spotless:spotless-maven-plugin from 2.46.1 to 3.7.0
  • 500156d Bump org.apache.maven:maven-compat from 3.9.15 to 3.9.16
  • 5473a55 Bump org.codehaus.mojo:exec-maven-plugin from 3.1.0 to 3.6.3
  • 153a631 Bump com.fasterxml.jackson.core:jackson-databind
  • f513dbf Bump actions/checkout from 6 to 7
  • 5ac47ca [unleash-maven-plugin] 1.3.0 -> 1.3.1-SNAPSHOT Preparation for next developm...
  • See full diff in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the maven group with 6 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [org.codehaus.mojo:build-helper-maven-plugin](https://github.com/mojohaus/build-helper-maven-plugin) | `3.6.1` | `3.6.2` |
| [com.diffplug.spotless:spotless-maven-plugin](https://github.com/diffplug/spotless) | `3.9.0` | `3.10.2` |
| [com.github.spotbugs:spotbugs-maven-plugin](https://github.com/spotbugs/spotbugs-maven-plugin) | `4.10.3.0` | `4.10.4.1` |
| [org.apache.maven.plugins:maven-surefire-plugin](https://github.com/apache/maven-surefire) | `3.5.6` | `3.6.0` |
| [dev.sigstore:sigstore-maven-plugin](https://github.com/sigstore/sigstore-java) | `2.2.0` | `2.3.0` |
| [io.github.mavenplugins:central-publishing-maven-plugin](https://github.com/mavenplugins/central-publishing-maven-plugin) | `1.3.0` | `1.3.1` |



Updates `org.codehaus.mojo:build-helper-maven-plugin` from 3.6.1 to 3.6.2
- [Release notes](https://github.com/mojohaus/build-helper-maven-plugin/releases)
- [Commits](mojohaus/build-helper-maven-plugin@3.6.1...3.6.2)

Updates `com.diffplug.spotless:spotless-maven-plugin` from 3.9.0 to 3.10.2
- [Release notes](https://github.com/diffplug/spotless/releases)
- [Changelog](https://github.com/diffplug/spotless/blob/main/CHANGES.md)
- [Commits](diffplug/spotless@maven/3.9.0...maven/3.10.2)

Updates `com.github.spotbugs:spotbugs-maven-plugin` from 4.10.3.0 to 4.10.4.1
- [Release notes](https://github.com/spotbugs/spotbugs-maven-plugin/releases)
- [Commits](spotbugs/spotbugs-maven-plugin@spotbugs-maven-plugin-4.10.3.0...spotbugs-maven-plugin-4.10.4.1)

Updates `org.apache.maven.plugins:maven-surefire-plugin` from 3.5.6 to 3.6.0
- [Release notes](https://github.com/apache/maven-surefire/releases)
- [Commits](apache/maven-surefire@surefire-3.5.6...surefire-3.6.0)

Updates `dev.sigstore:sigstore-maven-plugin` from 2.2.0 to 2.3.0
- [Release notes](https://github.com/sigstore/sigstore-java/releases)
- [Changelog](https://github.com/sigstore/sigstore-java/blob/main/CHANGELOG.md)
- [Commits](sigstore/sigstore-java@v2.2.0...v2.3.0)

Updates `io.github.mavenplugins:central-publishing-maven-plugin` from 1.3.0 to 1.3.1
- [Release notes](https://github.com/mavenplugins/central-publishing-maven-plugin/releases)
- [Commits](mavenplugins/central-publishing-maven-plugin@v1.3.0...v1.3.1)

---
updated-dependencies:
- dependency-name: org.codehaus.mojo:build-helper-maven-plugin
  dependency-version: 3.6.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven
- dependency-name: com.diffplug.spotless:spotless-maven-plugin
  dependency-version: 3.10.2
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven
- dependency-name: com.github.spotbugs:spotbugs-maven-plugin
  dependency-version: 4.10.4.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven
- dependency-name: org.apache.maven.plugins:maven-surefire-plugin
  dependency-version: 3.6.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven
- dependency-name: dev.sigstore:sigstore-maven-plugin
  dependency-version: 2.3.0
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven
- dependency-name: io.github.mavenplugins:central-publishing-maven-plugin
  dependency-version: 1.3.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added the dependencies Dependency updates label Sep 19, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Dependency updates

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants