dependabot[bot] opened a new pull request, #27476: URL: https://github.com/apache/camel/pull/27476
Bumps [dev.toonformat:jtoon](https://github.com/toon-format/toon-java) from 2.0.4 to 2.0.5. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/toon-format/toon-java/releases">dev.toonformat:jtoon's releases</a>.</em></p> <blockquote> <h2>v2.0.5</h2> <p>Spec 4.1.2 alignment with security/version handling, documentation and changelog updates.</p> <h2>What's Changed</h2> <ul> <li>Jackson update by <a href="https://github.com/jenspapenhagen"><code>@jenspapenhagen</code></a> in <a href="https://redirect.github.com/toon-format/toon-java/pull/196">toon-format/toon-java#196</a></li> <li>docs: record out-of-scope decisions by <a href="https://github.com/johannschopplich"><code>@johannschopplich</code></a> in <a href="https://redirect.github.com/toon-format/toon-java/pull/198">toon-format/toon-java#198</a></li> <li>docs: tighten out-of-scope records by <a href="https://github.com/johannschopplich"><code>@johannschopplich</code></a> in <a href="https://redirect.github.com/toon-format/toon-java/pull/199">toon-format/toon-java#199</a></li> <li>chore(deps): bump actions/setup-java from 6.0.0 to 6.0.1 by <a href="https://github.com/dependabot"><code>@dependabot</code></a>[bot] in <a href="https://redirect.github.com/toon-format/toon-java/pull/197">toon-format/toon-java#197</a></li> <li>fix(decoder): reject the removed <code>[#N]</code> length marker by <a href="https://github.com/johannschopplich"><code>@johannschopplich</code></a> in <a href="https://redirect.github.com/toon-format/toon-java/pull/200">toon-format/toon-java#200</a></li> <li>fix(encoder): reject strings with unpaired surrogates by <a href="https://github.com/johannschopplich"><code>@johannschopplich</code></a> in <a href="https://redirect.github.com/toon-format/toon-java/pull/202">toon-format/toon-java#202</a></li> <li>Spec 4.1.2 alignment: wrapper hash, release workflow guard, docs examples, changelog/FORMAT/README by <a href="https://github.com/jenspapenhagen"><code>@jenspapenhagen</code></a> in <a href="https://redirect.github.com/toon-format/toon-java/pull/206">toon-format/toon-java#206</a></li> </ul> <p><strong>Full Changelog</strong>: <a href="https://github.com/toon-format/toon-java/compare/v2.0.4...v2.0.5">https://github.com/toon-format/toon-java/compare/v2.0.4...v2.0.5</a></p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/toon-format/toon-java/blob/main/CHANGELOG.md">dev.toonformat:jtoon's changelog</a>.</em></p> <blockquote> <h2>[2.0.5] - 2026-10-03</h2> <h3>Fixed</h3> <ul> <li><strong>Token trimming is now exactly U+0020</strong>, as §12 requires. <code>String.trim()</code>, <code>String.isBlank()</code> and <code>String.stripTrailing()</code> also removed tabs and control characters, so <code>key: value<tab></code> decoded as <code>value</code>, and <code>key: "a"<tab></code> was accepted even though §7.4 requires the quoted token to end with its closing quote. A trailing tab at the end of a line is now line content. A single U+FEFF at the very start of a document is still stripped as a byte-order mark (§12).</li> <li><strong>Any character after the closing quote of a quoted token is now rejected in key position</strong> as well as in value position (§7.4).</li> <li><strong>Root-form discovery starts at the first non-blank line</strong> instead of assuming line 0, so a document with leading blank lines is no longer misparsed (§5).</li> <li><strong>An unquoted key token may contain spaces.</strong> <code>foo bar[2]: 1,2</code> now decodes with the literal key <code>foo bar</code>, which §7.4 requires of decoders. Whitespace between a key and its bracket segment (<code>foo [2]:</code>) remains a header syntax error (§6, §14.2).</li> <li><strong>A root string value starting with U+FEFF is now quoted</strong>, as §7.2 requires; unquoted, a conforming decoder would strip it as a byte-order mark and silently lose the character (§12). This is the one normative behaviour change in spec 4.1.2.</li> </ul> <h3>Changed</h3> <ul> <li>Conformance raised from spec 4.1.1 to <strong>4.1.2</strong>, which is a single normative change: a root primitive starting with U+FEFF must be quoted (§7.2). On top of that, decoder strictness was tightened in five places where the implementation accepted input the spec rejects — token trimming, quoted-token boundaries, root-form discovery, header key tokens and the <code>[N]</code> length marker. The full conformance suite from 4.1 (canonical number formatting, BOM stripping, comment pre-pass §5.1, strict header validation §5/§6/§7.3/§7.4, nested field groups in tabular arrays §9.3, keyed tabular form §9.5/§10, non-strict tab leniency §12) carries over unchanged and remains green. The 24 conformance fixture files are byte-identical to the spec repository at tag <code>v4.1.2</code>.</li> <li>Upstream [PR <a href="https://redirect.github.com/toon-format/toon-java/issues/201">#201</a>](<a href="https://redirect.github.com/toon-format/toon-java/pull/201">toon-format/toon-java#201</a>) integrated (squash merge). Conflicts in <code>KeyDecoder</code>, <code>ListItemDecoder</code> and <code>ValueDecoder</code> were resolved additively, keeping both the <code>validateQuotedTokenBoundary</code> check from <a href="https://redirect.github.com/toon-format/toon-java/issues/201">#201</a> and the <code>validateKeyHasNoUnquotedBrackets</code> check from <a href="https://redirect.github.com/toon-format/toon-java/issues/200">#200</a>. <code>DecodeHelper.trimSpaces()</code> remains the canonical token trimmer.</li> <li>The targeted specification version is now declared as <code>toon-spec: 4.1.2</code> in the README, as §13 recommends.</li> </ul> <h3>Documentation</h3> <ul> <li><code>README.md</code>: spec badge updated to v4.1.2; corrected a stale quick-start example that showed the non-conforming legacy empty-array form <code>preferences[0]:</code> instead of <code>preferences: []</code> (§9.1).</li> <li><code>docs/FORMAT.md</code> audited against the spec and corrected. The most serious defect was a flat contradiction: the document stated <em>"TOON does not support comments"</em>, while §5.1 defines full-line comments and the decoder has always implemented the comment pre-pass. Also corrected: empty arrays (§9.1, was the stale <code>items[0]:</code> form), number notation (§2, was stated as an absolute MUST where the spec only requires canonical decimal inside the canonical range and permits exponent notation outside it), nested-uniform tabular columns (§9.3), decoder key permissiveness (§7.4), and the quoting triggers for a leading <code>-</code> or <code>#</code> and for a root primitive starting with U+FEFF (§7.2).</li> <li><code>docs/FORMAT.md</code> gained the normative sections that were missing entirely: Keyed Tabular Arrays (§9.5), Header Syntax (§6), Quoted Token Boundaries (§7.4), line terminators and the BOM (§12), the two delimiter scopes (§11.1) and the full strict-mode error set (§14).</li> <li><code>util/package-info.java</code>: the documented unquoted-key pattern was <code>^[A-Z_][\w.]*$</code>, which is wrong — it excluded lowercase keys that the encoder in fact emits unquoted. Corrected to the spec's <code>^[A-Za-z_][A-Za-z0-9_.]*$</code> (§7.3), with a note that §7.3 constrains encoders only while decoders accept any token. The quoting trigger was documented as <code>- </code> (dash-space) rather than a hyphen at position 0, and the <code>#</code> trigger, the root U+FEFF trigger and <code>Constants.BYTE_ORDER_MARK</code> were missing.</li> <li><code>docs/javadoc/</code> regenerated. 20 pages had never been generated at all — the checked-in output predated the decoder, encoder and validator packages, so <code>Headers</code>, <code>KeyFolding</code>, every <code>decoder/*</code> class and the whole <code>validator</code> package were absent. 88 → 109 pages.</li> </ul> <h3>Build and Tooling</h3> <ul> <li>Gradle wrapper <strong>9.7.1 → 9.8.0</strong>.</li> <li>NullAway <strong>0.14.1 → 0.14.2</strong>.</li> <li>SpotBugs Gradle plugin <strong>6.5.11 → 6.5.12</strong>.</li> <li><code>gradle/verification-metadata.xml</code> <strong>regenerated from scratch</strong> instead of merged: <strong>3786 → 2821 lines, 522 → 398 components</strong>. The removed entries were artifacts of dependencies that have left the graph. Regenerated under Gradle 9.8.0 and spot-checked against Maven Central's published SHA1 checksums.</li> <li>Removed <code>gradle/verification-metadata.dryrun.xml</code>, a leftover from an earlier dry run that Gradle never reads and that nothing in the repository referenced.</li> <li>The <code>update-verification</code> workflow no longer lets stale entries accumulate: <code>--write-verification-metadata</code> <em>merges</em> into an existing file rather than replacing it, so the workflow now deletes the file first and then regenerates. A subsequent verification-enabled build was added as a self-check, since the write mode tolerates verification failures by design.</li> <li><code>README.md</code> and <code>CONTRIBUTING.md</code> document the delete-then-regenerate procedure, so the merge behaviour is not reintroduced locally.</li> <li>Checkstyle is clean again: <code>PrimitiveEncoder</code> overloads reordered, and the U+FEFF literal in <code>Constants</code> expressed without an escaped unicode character.</li> </ul> <h3>Tests</h3> <ul> <li>New <code>HeadersTest</code> coverage for §7.4 key tokens: keys containing a hyphen, a leading digit, an internal space, a tab, a non-breaking space and a quoted key; rejection of a space before the bracket segment and before the colon, and of content between the bracket segment and the colon.</li> <li>New <code>PrimitiveEncoderTest</code> coverage for the §7.2 root byte-order-mark rule: a root string starting with U+FEFF is quoted, a bare U+FEFF is quoted, and U+FEFF stays unquoted both in non-root position and in the interior of a root string.</li> <li>Full suite: <strong>1870 tests, 0 failures</strong>, with dependency verification enabled.</li> </ul> </blockquote> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/toon-format/toon-java/commit/9e0ab99889337927b89becbe38e1bc9eaa6dda86"><code>9e0ab99</code></a> fix(workflow): make jacoco badge step non-blocking (<a href="https://redirect.github.com/toon-format/toon-java/issues/214">#214</a>)</li> <li><a href="https://github.com/toon-format/toon-java/commit/c471299fd9fc9d86d271b4b95b9860f7e559eb94"><code>c471299</code></a> fix(workflow): add --clobber to gh release upload (<a href="https://redirect.github.com/toon-format/toon-java/issues/213">#213</a>)</li> <li><a href="https://github.com/toon-format/toon-java/commit/587d2d72a4276de8f2d6269fca05d643acd03cc9"><code>587d2d7</code></a> fix(workflow): update jacoco-badge-generator inputs for v2.12.1 (<a href="https://redirect.github.com/toon-format/toon-java/issues/212">#212</a>)</li> <li><a href="https://github.com/toon-format/toon-java/commit/fb3ff6b8de604a2d893d318fc108c03e025edb37"><code>fb3ff6b</code></a> fix(workflow): use gh release upload for assets (<a href="https://redirect.github.com/toon-format/toon-java/issues/211">#211</a>)</li> <li><a href="https://github.com/toon-format/toon-java/commit/17321133f0cc7771964460455d57edfc0992669d"><code>1732113</code></a> fix(workflow): add GH_TOKEN env for release creation (<a href="https://redirect.github.com/toon-format/toon-java/issues/210">#210</a>)</li> <li><a href="https://github.com/toon-format/toon-java/commit/cc836be15cab055d153daa81f8d256f702d6119d"><code>cc836be</code></a> docs: update version to 2.0.5 in README</li> <li><a href="https://github.com/toon-format/toon-java/commit/c9fe6664fa4a106f1494ac3d966ebee45806494f"><code>c9fe666</code></a> fix(workflow): fix shell syntax in maven central credentials check (<a href="https://redirect.github.com/toon-format/toon-java/issues/209">#209</a>)</li> <li><a href="https://github.com/toon-format/toon-java/commit/cf1991576269f310a67a6b2cc2bea218f31d099c"><code>cf19915</code></a> auto: update dependency verification metadata [skip ci]</li> <li><a href="https://github.com/toon-format/toon-java/commit/e9a5e6c9627ba91e8e9e7163670866390705b7d1"><code>e9a5e6c</code></a> fix(workflow): regenerate verification metadata before specs validation (<a href="https://redirect.github.com/toon-format/toon-java/issues/208">#208</a>)</li> <li><a href="https://github.com/toon-format/toon-java/commit/6e795a59e36a0137c9c1356ac6309f5b2082a16f"><code>6e795a5</code></a> fix: regenerate dependency verification metadata for Gradle 9.8.0 transitive ...</li> <li>Additional commits viewable in <a href="https://github.com/toon-format/toon-java/compare/v2.0.4...v2.0.5">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
