dependabot[bot] opened a new pull request, #19497:
URL: https://github.com/apache/pinot/pull/19497

   Bumps [org.slf4j:slf4j-bom](https://github.com/qos-ch/slf4j) from 2.0.18 to 
2.0.19.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/qos-ch/slf4j/releases";>org.slf4j:slf4j-bom's 
releases</a>.</em></p>
   <blockquote>
   <h2>SLF4J 2.0.19</h2>
   <h3>2026-09-04 - Release of SLF4J 2.0.19</h3>
   <ul>
   <li>
   <p>When the fluent API was used with 
<code>XLogger</code>/<code>LoggerWrapper</code> in the <em>slf4j-ext</em> 
module, caller location was incorrectly reported. To correct this, 
<code>LoggerWrapper</code> now delegates <code>makeLoggingEventBuilder()</code> 
to the wrapped logger so that the application caller can be correctly 
extracted. This issue was reported in <a 
href="https://redirect.github.com/qos-ch/slf4j/issues/464";>issues/464</a>.</p>
   </li>
   <li>
   <p>In <code>slf4j-api/DefaultLoggingEventBuilder</code>, a failing 
<code>toString()</code> invocation on a key-value value, including 
<code>StackOverflowError</code>, no longer aborts logging. The builder now 
substitutes <code>[FAILED toString()]</code>, matching the existing behaviour 
of <code>MessageFormatter</code> for message arguments. This issue was reported 
in <a 
href="https://redirect.github.com/qos-ch/slf4j/issues/448";>issues/448</a>.</p>
   </li>
   <li>
   <p>The <code>isLoggable()</code> method in <code>SLF4JPlatformLogger</code> 
now maps <code>System.Logger.Level.ALL</code> and <code>Level.OFF</code> the 
same way as <code>log()</code>, that is ALL as TRACE and OFF as ERROR, instead 
of treating both as always loggable. This is a follow-up to the changes 
introduced in 2.0.17. See <a 
href="https://redirect.github.com/qos-ch/slf4j/issues/430";>issues/430</a>.</p>
   </li>
   <li>
   <p>Published JAR files now package each module's own <em>LICENSE.txt</em> 
under <em>META-INF/</em>. Previously the parent POM copied the repository-root 
MIT license into every module, so Apache-2.0 modules such as 
<em>jcl-over-slf4j</em> and <em>log4j-over-slf4j</em> shipped the wrong license 
text. This issue was reported in <a 
href="https://redirect.github.com/qos-ch/slf4j/issues/465";>issues/465</a>.</p>
   </li>
   <li>
   <p>A bit-wise identical binary of this version can be reproduced by building 
from source code at commit f0fc3e52a16d5053039495f4f3b64d191508204f associated 
with the tag v_2.0.19. Release built using Java &quot;21&quot; 2023-10-17 LTS 
build 21.0.1.+12-LTS-29 under Linux Debian 11.6.</p>
   </li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/qos-ch/slf4j/commit/f0fc3e52a16d5053039495f4f3b64d191508204f";><code>f0fc3e5</code></a>
 prepare release 2.0.19</li>
   <li><a 
href="https://github.com/qos-ch/slf4j/commit/2288d0cab686d71a4f3600729feba14e53407f50";><code>2288d0c</code></a>
 fix issues/464. slf4j-ext/XLogger incorrect caller extraction when the 
fluent...</li>
   <li><a 
href="https://github.com/qos-ch/slf4j/commit/6ff7f772591349cb3402be9c586f9eb50f0ab2c4";><code>6ff7f77</code></a>
 test: pin fluent API caller method name</li>
   <li><a 
href="https://github.com/qos-ch/slf4j/commit/2b3f94bae0cd19eec3d4a2e4e3b61b6a6db0faa3";><code>2b3f94b</code></a>
 SLF4JPlatformLogger.isLoggable should handle Logger.ALL and Logger.OFF in a 
c...</li>
   <li><a 
href="https://github.com/qos-ch/slf4j/commit/9221f77352ab0f35e3f641ed028ffce7f9fe1750";><code>9221f77</code></a>
 fix(api): guard addKeyValue value toString from fatal errors</li>
   <li><a 
href="https://github.com/qos-ch/slf4j/commit/027c54338b383461bf051d01d79b9d20f8eee3e6";><code>027c543</code></a>
 fix(build): package each module's LICENSE.txt into JAR META-INF</li>
   <li><a 
href="https://github.com/qos-ch/slf4j/commit/61400453cd366f227dbc36036d6ac128a36da59b";><code>6140045</code></a>
 start work on 2.0.19-SNAPSHOT</li>
   <li>See full diff in <a 
href="https://github.com/qos-ch/slf4j/compare/v_2.0.18...v_2.0.19";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=org.slf4j:slf4j-bom&package-manager=maven&previous-version=2.0.18&new-version=2.0.19)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to