dependabot[bot] opened a new pull request, #27061:
URL: https://github.com/apache/camel/pull/27061

   Bumps 
[io.github.classgraph:classgraph](https://github.com/classgraph/classgraph) 
from 4.8.195 to 4.8.196.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/classgraph/classgraph/releases";>io.github.classgraph:classgraph's
 releases</a>.</em></p>
   <blockquote>
   <h2>ClassGraph 4.8.196</h2>
   <p><strong>ClassGraph 5.0.0 is coming shortly</strong>, and requires JDK 17 
or newer. 4.8.196 is a bugfix release on the 4.x maintenance branch, and 
continues the file-by-file audit that produced 4.8.190 through 4.8.195. As 
before, most of the bugs listed here were found by Claude through careful code 
analysis, and were fixed on the v5 branch and backported to v4.</p>
   <h2>Mocking the list classes with mockk works again (<a 
href="https://redirect.github.com/classgraph/classgraph/issues/945";>#945</a>)</h2>
   <p>Since 4.8.185, mockk failed to mock <code>ResourceList</code>, 
<code>ClassInfoList</code> and the other list classes, with &quot;class 
redefinition failed: attempted to add a method&quot;. These classes extend a 
package-private class, and releases since 4.8.185 were built with JDK 8, whose 
javac does not emit public bridge methods in the public subclass for 
<code>add(T)</code>, <code>add(int, T)</code>, <code>remove(int)</code> and 
<code>set(int, T)</code>. The list classes now declare these methods 
themselves, so they are present whichever JDK builds the release.</p>
   <h2>Bug fixes: classpath elements and jarfiles</h2>
   <ul>
   <li>
   <p><strong>The context classloader could be moved behind the application 
classloader.</strong> The classloaders found in the environment were sorted by 
descending delegation depth, so that a classloader is searched before its 
ancestors. That also put any classloader with more ancestors ahead of an 
unrelated one with fewer -- the application classloader ahead of a context 
classloader with no parent, for example -- although the context classloader is 
meant to be tried first. Each classloader is now inserted just ahead of the 
first of its ancestors that is already listed, which keeps descendants ahead of 
ancestors and otherwise keeps the preference order.</p>
   </li>
   <li>
   <p><strong><code>Class-Path</code> and <code>Bundle-ClassPath</code> 
manifest attributes are now read with their specified syntax.</strong> A 
<code>Class-Path</code> entry is a relative URL, so its percent encoding is now 
decoded, as the JVM's own classloader decodes it. Before, a jarfile written as 
<code>my%20lib.jar</code> was looked for under that literal name, so a jarfile 
with a space in its name could not be named at all. 
<code>Bundle-ClassPath</code> paths are now trimmed, unquoted and separated 
from their parameters, following the OSGi header syntax. Before, <code>. , 
inner.jar</code> named <code> inner.jar</code>, and a quoted path or one with a 
parameter named nothing that exists.</p>
   </li>
   <li>
   <p><strong>When a zipfile has two entries with the same name, the last one 
is now used, as the JDK does.</strong> ClassGraph kept the first, so a scan 
could report a different resource, and open a different nested jarfile, than 
the JVM would load.</p>
   </li>
   <li>
   <p><strong><code>META-INF/versions/09/</code> is no longer read as 
multi-release version 9.</strong> The JDK looks up versioned entries only under 
the plain decimal version number, so ClassGraph could report a class that the 
JVM never loads.</p>
   </li>
   <li>
   <p><strong>The file of a nested jarfile is now always the outermost 
jarfile.</strong> It was the outer jarfile if the nested jarfile was stored, 
but null or a temporary file if it was deflated. 
<code>ScanResult#getClasspathFiles()</code> lists the outer jarfile once, 
however many jarfiles are nested within it.</p>
   </li>
   <li>
   <p><strong>A zipfile with an Info-ZIP Unicode path extra field of a version 
other than 1 could not be read.</strong> <code>java.util.zip.ZipFile</code> 
opens such a file, since the JDK does not read that field. The field is now 
logged and ignored.</p>
   </li>
   <li>
   <p><strong>A large nested jar with a long name could not be opened.</strong> 
A nested jar too large to hold in RAM is written to a temporary file named 
after its zip entry, and a long entry name made 
<code>File.createTempFile</code> fail with &quot;File name too long&quot;. The 
name is now cut to its last 64 characters.</p>
   </li>
   <li>
   <p><strong>A jarfile URL that redirected from http to https failed</strong> 
with &quot;Got response code 301&quot;, since <code>HttpURLConnection</code> 
only follows a redirect that keeps the same scheme. Redirects are now followed, 
up to 20 times. A redirect from https to http, or to a scheme that has not been 
enabled, is refused.</p>
   </li>
   <li>
   <p><strong>A <code>SecurityManager</code> that refused to let ClassGraph 
read a file's attributes stopped the scan of the rest of that 
directory.</strong> Only that file is now skipped.</p>
   </li>
   <li>
   <p><strong>The Quarkus classloader handler failed the whole scan</strong> 
when a field it reads held a null or unexpected value. Such elements are now 
skipped.</p>
   </li>
   <li>
   <p><strong><code>normalizePath</code> did not collapse <code>//</code> in a 
path that did not end with a separator,</strong> so <code>a//b</code> stayed 
<code>a//b</code> while <code>a//b/</code> became <code>a/b</code>.</p>
   </li>
   </ul>
   <h2>Bug fixes: memory, file handles and temporary files</h2>
   <ul>
   <li>
   <p><strong>A file is no longer memory-mapped when it could not be unmapped 
again.</strong> A <code>SecurityManager</code> that denied access to the buffer 
cleaner made <code>new ClassGraph()</code> throw &quot;Cannot get buffer 
cleaner method&quot;. Now, below JDK 22, a file is only memory-mapped when the 
cleaner is available, since otherwise the mapping, and on Windows the file 
lock, would last until the buffer was garbage collected.</p>
   </li>
   <li>
   <p><strong>A canceled <code>scanAsync</code> future leaked its 
<code>ScanResult</code>.</strong> A result that arrived after the future was 
canceled was never handed to anyone, so nothing closed it. It is now closed. 
The call stack and context classloader are still read on the calling thread, 
but the jarfiles are now opened when the task runs, so a task that is canceled 
before it starts opens nothing.</p>
   </li>
   <li>
   <p><strong>Temporary files no longer use 
<code>deleteOnExit()</code>.</strong> Closing the scan already deletes every 
temporary file, so <code>deleteOnExit()</code> only made the JDK hold every 
temporary path until the JVM exited.</p>
   </li>
   <li>
   <p><strong>A module reader could be left open</strong> if it was returned to 
its pool at the same moment the pool was being force-closed.</p>
   </li>
   <li>
   <p><strong>Reading a stream of declared length allocated a buffer of that 
whole length up front,</strong> up to the maximum buffered jar size. The first 
buffer is now at most 16MB, and grows as data arrives. A related method doubled 
its buffer whenever a read returned zero bytes, even when the buffer was not 
full; no scan was affected, since the streams it is given never return zero.</p>
   </li>
   <li>
   <p><strong>A refused unmap of a buffer view was logged as &quot;Could not 
unmap ByteBuffer: java.lang.reflect.InvocationTargetException&quot;.</strong> 
Such a view is now refused without a log entry, and any other failure is logged 
with its real cause.</p>
   </li>
   </ul>
   <h2>Bug fixes: the class graph</h2>
   <ul>
   <li>
   <p><strong><code>ClassInfo#isAnonymousInnerClass()</code> returned true for 
named local classes.</strong> It now agrees with 
<code>Class#isAnonymousClass()</code>. 
<code>getFullyQualifiedDefiningMethodName()</code> returned 
<code>&lt;clinit&gt;</code> for a class declared in an instance initializer or 
an instance field initializer, which javac compiles into the constructors; it 
now returns null for these, as <code>Class#getEnclosingMethod()</code> does.</p>
   </li>
   <li>
   <p><strong>A local record, enum or interface was reported as not 
static.</strong></p>
   </li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/classgraph/classgraph/commit/8f16afe2a8483bd8e5f020da31e9b870fb267f4c";><code>8f16afe</code></a>
 [maven-release-plugin] prepare release classgraph-4.8.196</li>
   <li><a 
href="https://github.com/classgraph/classgraph/commit/f0f3d2d43e8d28b9745a3750f844f18d8fd42a51";><code>f0f3d2d</code></a>
 Declare the element methods in the public list classes, so mockk can mock 
the...</li>
   <li><a 
href="https://github.com/classgraph/classgraph/commit/a4d872db94e0da69f2a460e99bbd20abfe26159e";><code>a4d872d</code></a>
 [maven-release-plugin] prepare for next development iteration</li>
   <li><a 
href="https://github.com/classgraph/classgraph/commit/495b19635b65a39108df3106fc7797dd13e3ed29";><code>495b196</code></a>
 [maven-release-plugin] prepare release classgraph-4.8.196</li>
   <li><a 
href="https://github.com/classgraph/classgraph/commit/4d08ea262561c964c0470189b31a291428f41deb";><code>4d08ea2</code></a>
 Keep a '$' after a '.' in a class reference as part of the nested class 
name</li>
   <li><a 
href="https://github.com/classgraph/classgraph/commit/67c7d33fcf0655f3abd926dc6da14e7d43f43efb";><code>67c7d33</code></a>
 Follow an http to https redirect when downloading a jarfile</li>
   <li><a 
href="https://github.com/classgraph/classgraph/commit/b8d2225c0fa226c44b35ddb76b716d126f8a2a82";><code>b8d2225</code></a>
 Check in the LocalRecordTest classfile fixtures, which .gitignore excluded</li>
   <li><a 
href="https://github.com/classgraph/classgraph/commit/1eb2fb25040501bed37c492a19fea399ba2afdcb";><code>1eb2fb2</code></a>
 Make AnnotationParameterValue.equals and hashCode agree with compareTo for 
un...</li>
   <li><a 
href="https://github.com/classgraph/classgraph/commit/707fea6b3a9124485711fbed622f91c6375f45b7";><code>707fea6</code></a>
 Resolve type variables of an enclosing class, and tell a method's type 
variab...</li>
   <li><a 
href="https://github.com/classgraph/classgraph/commit/534d034cd3004750979a4592941856949d6f4ad1";><code>534d034</code></a>
 Report local records as static, and fix type annotations on local class 
const...</li>
   <li>Additional commits viewable in <a 
href="https://github.com/classgraph/classgraph/compare/classgraph-4.8.195...classgraph-4.8.196";>compare
 view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=io.github.classgraph:classgraph&package-manager=maven&previous-version=4.8.195&new-version=4.8.196)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to