This is an automated email from the ASF dual-hosted git repository.

lprimak pushed a commit to branch 2.x
in repository https://gitbox.apache.org/repos/asf/shiro.git


The following commit(s) were added to refs/heads/2.x by this push:
     new 0c7cb62b2 chore(deps): bump the maven-dependencies group with 23 
updates (#2878)
0c7cb62b2 is described below

commit 0c7cb62b26d0b61a16621c3c6ef046979e6a2541
Author: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
AuthorDate: Tue Sep 1 13:16:56 2026 -0500

    chore(deps): bump the maven-dependencies group with 23 updates (#2878)
    
    Bumps the maven-dependencies group with 28 updates:
    
    | Package | From | To |
    | --- | --- | --- |
    | [org.easymock:easymock](https://github.com/easymock/easymock) | `5.6.0` | 
`5.7.0` |
    | [net.bytebuddy:byte-buddy](https://github.com/raphw/byte-buddy) | 
`1.18.11` | `1.18.12` |
    | [net.bytebuddy:byte-buddy-agent](https://github.com/raphw/byte-buddy) | 
`1.18.11` | `1.18.12` |
    | [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) | 
`1.6.1` | `1.6.3` |
    | [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) | 
`1.6.1` | `1.6.3` |
    | [org.bouncycastle:bcprov-jdk18on](https://github.com/bcgit/bc-java) | 
`1.85` | `1.85.2` |
    | 
[com.mycila:license-maven-plugin](https://github.com/mathieucarbou/license-maven-plugin)
 | `5.1.1` | `5.1.2` |
    | 
[org.owasp:dependency-check-maven](https://github.com/dependency-check/DependencyCheck)
 | `12.2.2` | `13.0.0` |
    | org.apache.tomcat.embed:tomcat-embed-core | `9.0.120` | `9.0.121` |
    | org.apache.tomcat.embed:tomcat-embed-el | `9.0.120` | `9.0.121` |
    | org.apache.tomcat.embed:tomcat-embed-websocket | `9.0.120` | `9.0.121` |
    | org.apache.tomcat:tomcat-jaspic-api | `9.0.120` | `9.0.121` |
    | org.apache.tomcat:tomcat-catalina | `9.0.120` | `9.0.121` |
    | org.apache.cxf:cxf-rt-frontend-jaxrs | `3.6.11` | `3.6.12` |
    | [org.omnifaces:omnifaces](https://github.com/omnifaces/omnifaces) | 
`3.14.23` | `3.14.24` |
    | [org.jsoup:jsoup](https://github.com/jhy/jsoup) | `1.22.2` | `1.23.2` |
    | org.apache.cxf:cxf-bom | `3.6.11` | `3.6.12` |
    | org.apache.cxf:cxf-rt-rs-client | `3.6.11` | `3.6.12` |
    | 
[io.openliberty.tools:liberty-maven-plugin](https://github.com/OpenLiberty/ci.maven)
 | `3.12.1` | `3.12.3` |
    | [org.javassist:javassist](https://github.com/jboss-javassist/javassist) | 
`3.32.0-GA` | `3.33.0-GA` |
    | org.apache.tomcat.embed:tomcat-embed-core | `10.1.57` | `10.1.59` |
    | org.apache.tomcat.embed:tomcat-embed-el | `10.1.57` | `10.1.59` |
    | org.apache.tomcat.embed:tomcat-embed-websocket | `10.1.57` | `10.1.59` |
    | org.apache.tomcat:tomcat-jaspic-api | `10.1.57` | `10.1.59` |
    | org.apache.tomcat:tomcat-catalina | `10.1.57` | `10.1.59` |
    | org.apache.tomcat:tomcat-jasper | `10.1.57` | `10.1.59` |
    | org.apache.tomcat:tomcat-jasper-el | `10.1.57` | `10.1.59` |
    | org.apache.maven:apache-maven | `3.9.12` | `3.9.16` |
    
    
    Updates `org.easymock:easymock` from 5.6.0 to 5.7.0
    - [Release notes](https://github.com/easymock/easymock/releases)
    - 
[Changelog](https://github.com/easymock/easymock/blob/master/ReleaseNotes.md)
    - 
[Commits](https://github.com/easymock/easymock/compare/easymock-5.6.0...easymock-5.7.0)
    
    Updates `net.bytebuddy:byte-buddy` from 1.18.11 to 1.18.12
    - [Release notes](https://github.com/raphw/byte-buddy/releases)
    - 
[Changelog](https://github.com/raphw/byte-buddy/blob/master/release-notes.md)
    - 
[Commits](https://github.com/raphw/byte-buddy/compare/byte-buddy-1.18.11...byte-buddy-1.18.12)
    
    Updates `net.bytebuddy:byte-buddy-agent` from 1.18.11 to 1.18.12
    - [Release notes](https://github.com/raphw/byte-buddy/releases)
    - 
[Changelog](https://github.com/raphw/byte-buddy/blob/master/release-notes.md)
    - 
[Commits](https://github.com/raphw/byte-buddy/compare/byte-buddy-1.18.11...byte-buddy-1.18.12)
    
    Updates `net.bytebuddy:byte-buddy-agent` from 1.18.11 to 1.18.12
    - [Release notes](https://github.com/raphw/byte-buddy/releases)
    - 
[Changelog](https://github.com/raphw/byte-buddy/blob/master/release-notes.md)
    - 
[Commits](https://github.com/raphw/byte-buddy/compare/byte-buddy-1.18.11...byte-buddy-1.18.12)
    
    Updates `ch.qos.logback:logback-core` from 1.6.1 to 1.6.3
    - [Release notes](https://github.com/qos-ch/logback/releases)
    - [Commits](https://github.com/qos-ch/logback/compare/v_1.6.1...v_1.6.3)
    
    Updates `ch.qos.logback:logback-classic` from 1.6.1 to 1.6.3
    - [Release notes](https://github.com/qos-ch/logback/releases)
    - [Commits](https://github.com/qos-ch/logback/compare/v_1.6.1...v_1.6.3)
    
    Updates `org.bouncycastle:bcprov-jdk18on` from 1.85 to 1.85.2
    - 
[Changelog](https://github.com/bcgit/bc-java/blob/main/docs/releasenotes.md)
    - [Commits](https://github.com/bcgit/bc-java/commits)
    
    Updates `com.mycila:license-maven-plugin` from 5.1.1 to 5.1.2
    - [Release 
notes](https://github.com/mathieucarbou/license-maven-plugin/releases)
    - 
[Changelog](https://github.com/mathieucarbou/license-maven-plugin/blob/master/docs/releases.md)
    - 
[Commits](https://github.com/mathieucarbou/license-maven-plugin/compare/v5.1.1...v5.1.2)
    
    Updates `org.owasp:dependency-check-maven` from 12.2.2 to 13.0.0
    - [Release 
notes](https://github.com/dependency-check/DependencyCheck/releases)
    - 
[Changelog](https://github.com/dependency-check/DependencyCheck/blob/main/CHANGELOG.md)
    - 
[Commits](https://github.com/dependency-check/DependencyCheck/compare/v12.2.2...v13.0.0)
    
    Updates `org.apache.tomcat.embed:tomcat-embed-core` from 9.0.120 to 9.0.121
    
    Updates `org.apache.tomcat.embed:tomcat-embed-el` from 9.0.120 to 9.0.121
    
    Updates `org.apache.tomcat.embed:tomcat-embed-websocket` from 9.0.120 to 
9.0.121
    
    Updates `org.apache.tomcat:tomcat-jaspic-api` from 9.0.120 to 9.0.121
    
    Updates `org.apache.tomcat:tomcat-catalina` from 9.0.120 to 9.0.121
    
    Updates `org.apache.tomcat.embed:tomcat-embed-el` from 9.0.120 to 9.0.121
    
    Updates `org.apache.tomcat.embed:tomcat-embed-websocket` from 9.0.120 to 
9.0.121
    
    Updates `org.apache.cxf:cxf-rt-frontend-jaxrs` from 3.6.11 to 3.6.12
    
    Updates `org.omnifaces:omnifaces` from 3.14.23 to 3.14.24
    - 
[Commits](https://github.com/omnifaces/omnifaces/compare/3.14.23...3.14.24)
    
    Updates `org.jsoup:jsoup` from 1.22.2 to 1.23.2
    - [Release notes](https://github.com/jhy/jsoup/releases)
    - [Changelog](https://github.com/jhy/jsoup/blob/master/CHANGES.md)
    - 
[Commits](https://github.com/jhy/jsoup/compare/jsoup-1.22.2...jsoup-1.23.2)
    
    Updates `org.apache.cxf:cxf-bom` from 3.6.11 to 3.6.12
    
    Updates `org.apache.tomcat:tomcat-jaspic-api` from 9.0.120 to 9.0.121
    
    Updates `org.apache.tomcat:tomcat-catalina` from 9.0.120 to 9.0.121
    
    Updates `org.apache.cxf:cxf-rt-rs-client` from 3.6.11 to 3.6.12
    
    Updates `io.openliberty.tools:liberty-maven-plugin` from 3.12.1 to 3.12.3
    - [Release notes](https://github.com/OpenLiberty/ci.maven/releases)
    - 
[Commits](https://github.com/OpenLiberty/ci.maven/compare/liberty-maven-3.12.1...liberty-maven-3.12.3)
    
    Updates `org.javassist:javassist` from 3.32.0-GA to 3.33.0-GA
    - [Release notes](https://github.com/jboss-javassist/javassist/releases)
    - 
[Changelog](https://github.com/jboss-javassist/javassist/blob/master/Changes.md)
    - [Commits](https://github.com/jboss-javassist/javassist/commits)
    
    Updates `org.apache.tomcat.embed:tomcat-embed-core` from 10.1.57 to 10.1.59
    
    Updates `org.apache.tomcat.embed:tomcat-embed-el` from 10.1.57 to 10.1.59
    
    Updates `org.apache.tomcat.embed:tomcat-embed-websocket` from 10.1.57 to 
10.1.59
    
    Updates `org.apache.tomcat:tomcat-jaspic-api` from 10.1.57 to 10.1.59
    
    Updates `org.apache.tomcat:tomcat-catalina` from 10.1.57 to 10.1.59
    
    Updates `org.apache.tomcat:tomcat-jasper` from 10.1.57 to 10.1.59
    
    Updates `org.apache.tomcat:tomcat-jasper-el` from 10.1.57 to 10.1.59
    
    Updates `org.apache.tomcat:tomcat-jasper-el` from 10.1.57 to 10.1.59
    
    Updates `org.apache.maven:apache-maven` from 3.9.12 to 3.9.16
    
    ---
    updated-dependencies:
    - dependency-name: org.easymock:easymock
      dependency-version: 5.7.0
      dependency-type: direct:development
      update-type: version-update:semver-minor
      dependency-group: maven-dependencies
    - dependency-name: net.bytebuddy:byte-buddy
      dependency-version: 1.18.12
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: net.bytebuddy:byte-buddy-agent
      dependency-version: 1.18.12
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: net.bytebuddy:byte-buddy-agent
      dependency-version: 1.18.12
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: ch.qos.logback:logback-core
      dependency-version: 1.6.3
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: ch.qos.logback:logback-classic
      dependency-version: 1.6.3
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: org.bouncycastle:bcprov-jdk18on
      dependency-version: 1.85.2
      dependency-type: direct:development
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: com.mycila:license-maven-plugin
      dependency-version: 5.1.2
      dependency-type: direct:development
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: org.owasp:dependency-check-maven
      dependency-version: 13.0.0
      dependency-type: direct:production
      update-type: version-update:semver-major
      dependency-group: maven-dependencies
    - dependency-name: org.apache.tomcat.embed:tomcat-embed-core
      dependency-version: 9.0.121
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: org.apache.tomcat.embed:tomcat-embed-el
      dependency-version: 9.0.121
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: org.apache.tomcat.embed:tomcat-embed-websocket
      dependency-version: 9.0.121
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: org.apache.tomcat:tomcat-jaspic-api
      dependency-version: 9.0.121
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: org.apache.tomcat:tomcat-catalina
      dependency-version: 9.0.121
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: org.apache.tomcat.embed:tomcat-embed-el
      dependency-version: 9.0.121
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: org.apache.tomcat.embed:tomcat-embed-websocket
      dependency-version: 9.0.121
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: org.apache.cxf:cxf-rt-frontend-jaxrs
      dependency-version: 3.6.12
      dependency-type: direct:development
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: org.omnifaces:omnifaces
      dependency-version: 3.14.24
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: org.jsoup:jsoup
      dependency-version: 1.23.2
      dependency-type: direct:production
      update-type: version-update:semver-minor
      dependency-group: maven-dependencies
    - dependency-name: org.apache.cxf:cxf-bom
      dependency-version: 3.6.12
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: org.apache.tomcat:tomcat-jaspic-api
      dependency-version: 9.0.121
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: org.apache.tomcat:tomcat-catalina
      dependency-version: 9.0.121
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: org.apache.cxf:cxf-rt-rs-client
      dependency-version: 3.6.12
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: io.openliberty.tools:liberty-maven-plugin
      dependency-version: 3.12.3
      dependency-type: direct:development
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: org.javassist:javassist
      dependency-version: 3.33.0-GA
      dependency-type: direct:development
      update-type: version-update:semver-minor
      dependency-group: maven-dependencies
    - dependency-name: org.apache.tomcat.embed:tomcat-embed-core
      dependency-version: 10.1.59
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: org.apache.tomcat.embed:tomcat-embed-el
      dependency-version: 10.1.59
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: org.apache.tomcat.embed:tomcat-embed-websocket
      dependency-version: 10.1.59
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: org.apache.tomcat:tomcat-jaspic-api
      dependency-version: 10.1.59
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: org.apache.tomcat:tomcat-catalina
      dependency-version: 10.1.59
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: org.apache.tomcat:tomcat-jasper
      dependency-version: 10.1.59
      dependency-type: direct:development
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: org.apache.tomcat:tomcat-jasper-el
      dependency-version: 10.1.59
      dependency-type: direct:development
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: org.apache.tomcat:tomcat-jasper-el
      dependency-version: 10.1.59
      dependency-type: direct:development
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    - dependency-name: org.apache.maven:apache-maven
      dependency-version: 3.9.16
      dependency-type: direct:production
      update-type: version-update:semver-patch
      dependency-group: maven-dependencies
    ...
    
    Signed-off-by: dependabot[bot] <[email protected]>
    Co-authored-by: dependabot[bot] 
<49699333+dependabot[bot]@users.noreply.github.com>
---
 .mvn/wrapper/maven-wrapper.properties        |   2 +-
 integration-tests/jakarta-ee/pom.xml         |   4 +-
 integration-tests/jaxrs/openliberty/pom.xml  |   2 +-
 integration-tests/jaxrs/tests/pom.xml        |   2 +-
 integration-tests/meecrowave-support/pom.xml |   2 +-
 mvnw.cmd                                     | 378 +++++++++++++--------------
 pom.xml                                      |  18 +-
 samples/web-jakarta/pom.xml                  |   2 +-
 support/jakarta-ee/pom.xml                   |   4 +-
 support/jaxrs/pom.xml                        |   2 +-
 10 files changed, 208 insertions(+), 208 deletions(-)

diff --git a/.mvn/wrapper/maven-wrapper.properties 
b/.mvn/wrapper/maven-wrapper.properties
index 8dea6c227..216df0589 100644
--- a/.mvn/wrapper/maven-wrapper.properties
+++ b/.mvn/wrapper/maven-wrapper.properties
@@ -1,3 +1,3 @@
 wrapperVersion=3.3.4
 distributionType=only-script
-distributionUrl=https://repo.maven.apache.org/maven2/org/apache/maven/apache-maven/3.9.12/apache-maven-3.9.12-bin.zip
+distributionUrl=https://repo.maven.apache.org/maven2/org/apache/maven/apache-maven/3.9.16/apache-maven-3.9.16-bin.zip
diff --git a/integration-tests/jakarta-ee/pom.xml 
b/integration-tests/jakarta-ee/pom.xml
index 0d4a59db1..1bbb15cfd 100644
--- a/integration-tests/jakarta-ee/pom.xml
+++ b/integration-tests/jakarta-ee/pom.xml
@@ -65,7 +65,7 @@
         <dependency>
             <groupId>org.omnifaces</groupId>
             <artifactId>omnifaces</artifactId>
-            <version>3.14.23</version>
+            <version>3.14.24</version>
         </dependency>
         <dependency>
             <groupId>org.projectlombok</groupId>
@@ -237,7 +237,7 @@
         <dependency>
             <groupId>org.javassist</groupId>
             <artifactId>javassist</artifactId>
-            <version>3.32.0-GA</version>
+            <version>3.33.0-GA</version>
             <scope>test</scope>
         </dependency>
 
diff --git a/integration-tests/jaxrs/openliberty/pom.xml 
b/integration-tests/jaxrs/openliberty/pom.xml
index 095ff998d..700fce34f 100644
--- a/integration-tests/jaxrs/openliberty/pom.xml
+++ b/integration-tests/jaxrs/openliberty/pom.xml
@@ -60,7 +60,7 @@
             <plugin>
                 <groupId>io.openliberty.tools</groupId>
                 <artifactId>liberty-maven-plugin</artifactId>
-                <version>3.12.1</version>
+                <version>3.12.3</version>
                 <configuration>
                     <serverName>shiro-its-jaxrs-openliberty</serverName>
                     <features>
diff --git a/integration-tests/jaxrs/tests/pom.xml 
b/integration-tests/jaxrs/tests/pom.xml
index 21e820753..3b4a6957c 100644
--- a/integration-tests/jaxrs/tests/pom.xml
+++ b/integration-tests/jaxrs/tests/pom.xml
@@ -67,7 +67,7 @@
         <dependency>
             <groupId>org.apache.cxf</groupId>
             <artifactId>cxf-rt-rs-client</artifactId>
-            <version>3.6.11</version>
+            <version>3.6.12</version>
             <scope>runtime</scope>
         </dependency>
         <dependency>
diff --git a/integration-tests/meecrowave-support/pom.xml 
b/integration-tests/meecrowave-support/pom.xml
index 387c94daa..31e68379f 100644
--- a/integration-tests/meecrowave-support/pom.xml
+++ b/integration-tests/meecrowave-support/pom.xml
@@ -78,7 +78,7 @@
             <dependency>
                 <groupId>org.apache.cxf</groupId>
                 <artifactId>cxf-bom</artifactId>
-                <version>3.6.11</version>
+                <version>3.6.12</version>
                 <scope>import</scope>
                 <type>pom</type>
             </dependency>
diff --git a/mvnw.cmd b/mvnw.cmd
index 92450f932..5761d9489 100644
--- a/mvnw.cmd
+++ b/mvnw.cmd
@@ -1,189 +1,189 @@
-<# : batch portion
-@REM 
----------------------------------------------------------------------------
-@REM Licensed to the Apache Software Foundation (ASF) under one
-@REM or more contributor license agreements.  See the NOTICE file
-@REM distributed with this work for additional information
-@REM regarding copyright ownership.  The ASF licenses this file
-@REM to you under the Apache License, Version 2.0 (the
-@REM "License"); you may not use this file except in compliance
-@REM with the License.  You may obtain a copy of the License at
-@REM
-@REM    http://www.apache.org/licenses/LICENSE-2.0
-@REM
-@REM Unless required by applicable law or agreed to in writing,
-@REM software distributed under the License is distributed on an
-@REM "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
-@REM KIND, either express or implied.  See the License for the
-@REM specific language governing permissions and limitations
-@REM under the License.
-@REM 
----------------------------------------------------------------------------
-
-@REM 
----------------------------------------------------------------------------
-@REM Apache Maven Wrapper startup batch script, version 3.3.4
-@REM
-@REM Optional ENV vars
-@REM   MVNW_REPOURL - repo url base for downloading maven distribution
-@REM   MVNW_USERNAME/MVNW_PASSWORD - user and password for downloading maven
-@REM   MVNW_VERBOSE - true: enable verbose log; others: silence the output
-@REM 
----------------------------------------------------------------------------
-
-@IF "%__MVNW_ARG0_NAME__%"=="" (SET __MVNW_ARG0_NAME__=%~nx0)
-@SET __MVNW_CMD__=
-@SET __MVNW_ERROR__=
-@SET __MVNW_PSMODULEP_SAVE=%PSModulePath%
-@SET PSModulePath=
-@FOR /F "usebackq tokens=1* delims==" %%A IN (`powershell -noprofile "& 
{$scriptDir='%~dp0'; $script='%__MVNW_ARG0_NAME__%'; icm -ScriptBlock 
([Scriptblock]::Create((Get-Content -Raw '%~f0'))) -NoNewScope}"`) DO @(
-  IF "%%A"=="MVN_CMD" (set __MVNW_CMD__=%%B) ELSE IF "%%B"=="" (echo %%A) ELSE 
(echo %%A=%%B)
-)
-@SET PSModulePath=%__MVNW_PSMODULEP_SAVE%
-@SET __MVNW_PSMODULEP_SAVE=
-@SET __MVNW_ARG0_NAME__=
-@SET MVNW_USERNAME=
-@SET MVNW_PASSWORD=
-@IF NOT "%__MVNW_CMD__%"=="" ("%__MVNW_CMD__%" %*)
-@echo Cannot start maven from wrapper >&2 && exit /b 1
-@GOTO :EOF
-: end batch / begin powershell #>
-
-$ErrorActionPreference = "Stop"
-if ($env:MVNW_VERBOSE -eq "true") {
-  $VerbosePreference = "Continue"
-}
-
-# calculate distributionUrl, requires .mvn/wrapper/maven-wrapper.properties
-$distributionUrl = (Get-Content -Raw 
"$scriptDir/.mvn/wrapper/maven-wrapper.properties" | 
ConvertFrom-StringData).distributionUrl
-if (!$distributionUrl) {
-  Write-Error "cannot read distributionUrl property in 
$scriptDir/.mvn/wrapper/maven-wrapper.properties"
-}
-
-switch -wildcard -casesensitive ( $($distributionUrl -replace '^.*/','') ) {
-  "maven-mvnd-*" {
-    $USE_MVND = $true
-    $distributionUrl = $distributionUrl -replace 
'-bin\.[^.]*$',"-windows-amd64.zip"
-    $MVN_CMD = "mvnd.cmd"
-    break
-  }
-  default {
-    $USE_MVND = $false
-    $MVN_CMD = $script -replace '^mvnw','mvn'
-    break
-  }
-}
-
-# apply MVNW_REPOURL and calculate MAVEN_HOME
-# maven home pattern: 
~/.m2/wrapper/dists/{apache-maven-<version>,maven-mvnd-<version>-<platform>}/<hash>
-if ($env:MVNW_REPOURL) {
-  $MVNW_REPO_PATTERN = if ($USE_MVND -eq $False) { "/org/apache/maven/" } else 
{ "/maven/mvnd/" }
-  $distributionUrl = "$env:MVNW_REPOURL$MVNW_REPO_PATTERN$($distributionUrl 
-replace "^.*$MVNW_REPO_PATTERN",'')"
-}
-$distributionUrlName = $distributionUrl -replace '^.*/',''
-$distributionUrlNameMain = $distributionUrlName -replace '\.[^.]*$','' 
-replace '-bin$',''
-
-$MAVEN_M2_PATH = "$HOME/.m2"
-if ($env:MAVEN_USER_HOME) {
-  $MAVEN_M2_PATH = "$env:MAVEN_USER_HOME"
-}
-
-if (-not (Test-Path -Path $MAVEN_M2_PATH)) {
-    New-Item -Path $MAVEN_M2_PATH -ItemType Directory | Out-Null
-}
-
-$MAVEN_WRAPPER_DISTS = $null
-if ((Get-Item $MAVEN_M2_PATH).Target[0] -eq $null) {
-  $MAVEN_WRAPPER_DISTS = "$MAVEN_M2_PATH/wrapper/dists"
-} else {
-  $MAVEN_WRAPPER_DISTS = (Get-Item $MAVEN_M2_PATH).Target[0] + "/wrapper/dists"
-}
-
-$MAVEN_HOME_PARENT = "$MAVEN_WRAPPER_DISTS/$distributionUrlNameMain"
-$MAVEN_HOME_NAME = 
([System.Security.Cryptography.SHA256]::Create().ComputeHash([byte[]][char[]]$distributionUrl)
 | ForEach-Object {$_.ToString("x2")}) -join ''
-$MAVEN_HOME = "$MAVEN_HOME_PARENT/$MAVEN_HOME_NAME"
-
-if (Test-Path -Path "$MAVEN_HOME" -PathType Container) {
-  Write-Verbose "found existing MAVEN_HOME at $MAVEN_HOME"
-  Write-Output "MVN_CMD=$MAVEN_HOME/bin/$MVN_CMD"
-  exit $?
-}
-
-if (! $distributionUrlNameMain -or ($distributionUrlName -eq 
$distributionUrlNameMain)) {
-  Write-Error "distributionUrl is not valid, must end with *-bin.zip, but 
found $distributionUrl"
-}
-
-# prepare tmp dir
-$TMP_DOWNLOAD_DIR_HOLDER = New-TemporaryFile
-$TMP_DOWNLOAD_DIR = New-Item -Itemtype Directory -Path 
"$TMP_DOWNLOAD_DIR_HOLDER.dir"
-$TMP_DOWNLOAD_DIR_HOLDER.Delete() | Out-Null
-trap {
-  if ($TMP_DOWNLOAD_DIR.Exists) {
-    try { Remove-Item $TMP_DOWNLOAD_DIR -Recurse -Force | Out-Null }
-    catch { Write-Warning "Cannot remove $TMP_DOWNLOAD_DIR" }
-  }
-}
-
-New-Item -Itemtype Directory -Path "$MAVEN_HOME_PARENT" -Force | Out-Null
-
-# Download and Install Apache Maven
-Write-Verbose "Couldn't find MAVEN_HOME, downloading and installing it ..."
-Write-Verbose "Downloading from: $distributionUrl"
-Write-Verbose "Downloading to: $TMP_DOWNLOAD_DIR/$distributionUrlName"
-
-$webclient = New-Object System.Net.WebClient
-if ($env:MVNW_USERNAME -and $env:MVNW_PASSWORD) {
-  $webclient.Credentials = New-Object 
System.Net.NetworkCredential($env:MVNW_USERNAME, $env:MVNW_PASSWORD)
-}
-[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
-$webclient.DownloadFile($distributionUrl, 
"$TMP_DOWNLOAD_DIR/$distributionUrlName") | Out-Null
-
-# If specified, validate the SHA-256 sum of the Maven distribution zip file
-$distributionSha256Sum = (Get-Content -Raw 
"$scriptDir/.mvn/wrapper/maven-wrapper.properties" | 
ConvertFrom-StringData).distributionSha256Sum
-if ($distributionSha256Sum) {
-  if ($USE_MVND) {
-    Write-Error "Checksum validation is not supported for maven-mvnd. `nPlease 
disable validation by removing 'distributionSha256Sum' from your 
maven-wrapper.properties."
-  }
-  Import-Module $PSHOME\Modules\Microsoft.PowerShell.Utility -Function 
Get-FileHash
-  if ((Get-FileHash "$TMP_DOWNLOAD_DIR/$distributionUrlName" -Algorithm 
SHA256).Hash.ToLower() -ne $distributionSha256Sum) {
-    Write-Error "Error: Failed to validate Maven distribution SHA-256, your 
Maven distribution might be compromised. If you updated your Maven version, you 
need to update the specified distributionSha256Sum property."
-  }
-}
-
-# unzip and move
-Expand-Archive "$TMP_DOWNLOAD_DIR/$distributionUrlName" -DestinationPath 
"$TMP_DOWNLOAD_DIR" | Out-Null
-
-# Find the actual extracted directory name (handles snapshots where filename 
!= directory name)
-$actualDistributionDir = ""
-
-# First try the expected directory name (for regular distributions)
-$expectedPath = Join-Path "$TMP_DOWNLOAD_DIR" "$distributionUrlNameMain"
-$expectedMvnPath = Join-Path "$expectedPath" "bin/$MVN_CMD"
-if ((Test-Path -Path $expectedPath -PathType Container) -and (Test-Path -Path 
$expectedMvnPath -PathType Leaf)) {
-  $actualDistributionDir = $distributionUrlNameMain
-}
-
-# If not found, search for any directory with the Maven executable (for 
snapshots)
-if (!$actualDistributionDir) {
-  Get-ChildItem -Path "$TMP_DOWNLOAD_DIR" -Directory | ForEach-Object {
-    $testPath = Join-Path $_.FullName "bin/$MVN_CMD"
-    if (Test-Path -Path $testPath -PathType Leaf) {
-      $actualDistributionDir = $_.Name
-    }
-  }
-}
-
-if (!$actualDistributionDir) {
-  Write-Error "Could not find Maven distribution directory in extracted 
archive"
-}
-
-Write-Verbose "Found extracted Maven distribution directory: 
$actualDistributionDir"
-Rename-Item -Path "$TMP_DOWNLOAD_DIR/$actualDistributionDir" -NewName 
$MAVEN_HOME_NAME | Out-Null
-try {
-  Move-Item -Path "$TMP_DOWNLOAD_DIR/$MAVEN_HOME_NAME" -Destination 
$MAVEN_HOME_PARENT | Out-Null
-} catch {
-  if (! (Test-Path -Path "$MAVEN_HOME" -PathType Container)) {
-    Write-Error "fail to move MAVEN_HOME"
-  }
-} finally {
-  try { Remove-Item $TMP_DOWNLOAD_DIR -Recurse -Force | Out-Null }
-  catch { Write-Warning "Cannot remove $TMP_DOWNLOAD_DIR" }
-}
-
-Write-Output "MVN_CMD=$MAVEN_HOME/bin/$MVN_CMD"
+<# : batch portion
+@REM 
----------------------------------------------------------------------------
+@REM Licensed to the Apache Software Foundation (ASF) under one
+@REM or more contributor license agreements.  See the NOTICE file
+@REM distributed with this work for additional information
+@REM regarding copyright ownership.  The ASF licenses this file
+@REM to you under the Apache License, Version 2.0 (the
+@REM "License"); you may not use this file except in compliance
+@REM with the License.  You may obtain a copy of the License at
+@REM
+@REM    http://www.apache.org/licenses/LICENSE-2.0
+@REM
+@REM Unless required by applicable law or agreed to in writing,
+@REM software distributed under the License is distributed on an
+@REM "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY
+@REM KIND, either express or implied.  See the License for the
+@REM specific language governing permissions and limitations
+@REM under the License.
+@REM 
----------------------------------------------------------------------------
+
+@REM 
----------------------------------------------------------------------------
+@REM Apache Maven Wrapper startup batch script, version 3.3.4
+@REM
+@REM Optional ENV vars
+@REM   MVNW_REPOURL - repo url base for downloading maven distribution
+@REM   MVNW_USERNAME/MVNW_PASSWORD - user and password for downloading maven
+@REM   MVNW_VERBOSE - true: enable verbose log; others: silence the output
+@REM 
----------------------------------------------------------------------------
+
+@IF "%__MVNW_ARG0_NAME__%"=="" (SET __MVNW_ARG0_NAME__=%~nx0)
+@SET __MVNW_CMD__=
+@SET __MVNW_ERROR__=
+@SET __MVNW_PSMODULEP_SAVE=%PSModulePath%
+@SET PSModulePath=
+@FOR /F "usebackq tokens=1* delims==" %%A IN (`powershell -noprofile "& 
{$scriptDir='%~dp0'; $script='%__MVNW_ARG0_NAME__%'; icm -ScriptBlock 
([Scriptblock]::Create((Get-Content -Raw '%~f0'))) -NoNewScope}"`) DO @(
+  IF "%%A"=="MVN_CMD" (set __MVNW_CMD__=%%B) ELSE IF "%%B"=="" (echo %%A) ELSE 
(echo %%A=%%B)
+)
+@SET PSModulePath=%__MVNW_PSMODULEP_SAVE%
+@SET __MVNW_PSMODULEP_SAVE=
+@SET __MVNW_ARG0_NAME__=
+@SET MVNW_USERNAME=
+@SET MVNW_PASSWORD=
+@IF NOT "%__MVNW_CMD__%"=="" ("%__MVNW_CMD__%" %*)
+@echo Cannot start maven from wrapper >&2 && exit /b 1
+@GOTO :EOF
+: end batch / begin powershell #>
+
+$ErrorActionPreference = "Stop"
+if ($env:MVNW_VERBOSE -eq "true") {
+  $VerbosePreference = "Continue"
+}
+
+# calculate distributionUrl, requires .mvn/wrapper/maven-wrapper.properties
+$distributionUrl = (Get-Content -Raw 
"$scriptDir/.mvn/wrapper/maven-wrapper.properties" | 
ConvertFrom-StringData).distributionUrl
+if (!$distributionUrl) {
+  Write-Error "cannot read distributionUrl property in 
$scriptDir/.mvn/wrapper/maven-wrapper.properties"
+}
+
+switch -wildcard -casesensitive ( $($distributionUrl -replace '^.*/','') ) {
+  "maven-mvnd-*" {
+    $USE_MVND = $true
+    $distributionUrl = $distributionUrl -replace 
'-bin\.[^.]*$',"-windows-amd64.zip"
+    $MVN_CMD = "mvnd.cmd"
+    break
+  }
+  default {
+    $USE_MVND = $false
+    $MVN_CMD = $script -replace '^mvnw','mvn'
+    break
+  }
+}
+
+# apply MVNW_REPOURL and calculate MAVEN_HOME
+# maven home pattern: 
~/.m2/wrapper/dists/{apache-maven-<version>,maven-mvnd-<version>-<platform>}/<hash>
+if ($env:MVNW_REPOURL) {
+  $MVNW_REPO_PATTERN = if ($USE_MVND -eq $False) { "/org/apache/maven/" } else 
{ "/maven/mvnd/" }
+  $distributionUrl = "$env:MVNW_REPOURL$MVNW_REPO_PATTERN$($distributionUrl 
-replace "^.*$MVNW_REPO_PATTERN",'')"
+}
+$distributionUrlName = $distributionUrl -replace '^.*/',''
+$distributionUrlNameMain = $distributionUrlName -replace '\.[^.]*$','' 
-replace '-bin$',''
+
+$MAVEN_M2_PATH = "$HOME/.m2"
+if ($env:MAVEN_USER_HOME) {
+  $MAVEN_M2_PATH = "$env:MAVEN_USER_HOME"
+}
+
+if (-not (Test-Path -Path $MAVEN_M2_PATH)) {
+    New-Item -Path $MAVEN_M2_PATH -ItemType Directory | Out-Null
+}
+
+$MAVEN_WRAPPER_DISTS = $null
+if ((Get-Item $MAVEN_M2_PATH).Target[0] -eq $null) {
+  $MAVEN_WRAPPER_DISTS = "$MAVEN_M2_PATH/wrapper/dists"
+} else {
+  $MAVEN_WRAPPER_DISTS = (Get-Item $MAVEN_M2_PATH).Target[0] + "/wrapper/dists"
+}
+
+$MAVEN_HOME_PARENT = "$MAVEN_WRAPPER_DISTS/$distributionUrlNameMain"
+$MAVEN_HOME_NAME = 
([System.Security.Cryptography.SHA256]::Create().ComputeHash([byte[]][char[]]$distributionUrl)
 | ForEach-Object {$_.ToString("x2")}) -join ''
+$MAVEN_HOME = "$MAVEN_HOME_PARENT/$MAVEN_HOME_NAME"
+
+if (Test-Path -Path "$MAVEN_HOME" -PathType Container) {
+  Write-Verbose "found existing MAVEN_HOME at $MAVEN_HOME"
+  Write-Output "MVN_CMD=$MAVEN_HOME/bin/$MVN_CMD"
+  exit $?
+}
+
+if (! $distributionUrlNameMain -or ($distributionUrlName -eq 
$distributionUrlNameMain)) {
+  Write-Error "distributionUrl is not valid, must end with *-bin.zip, but 
found $distributionUrl"
+}
+
+# prepare tmp dir
+$TMP_DOWNLOAD_DIR_HOLDER = New-TemporaryFile
+$TMP_DOWNLOAD_DIR = New-Item -Itemtype Directory -Path 
"$TMP_DOWNLOAD_DIR_HOLDER.dir"
+$TMP_DOWNLOAD_DIR_HOLDER.Delete() | Out-Null
+trap {
+  if ($TMP_DOWNLOAD_DIR.Exists) {
+    try { Remove-Item $TMP_DOWNLOAD_DIR -Recurse -Force | Out-Null }
+    catch { Write-Warning "Cannot remove $TMP_DOWNLOAD_DIR" }
+  }
+}
+
+New-Item -Itemtype Directory -Path "$MAVEN_HOME_PARENT" -Force | Out-Null
+
+# Download and Install Apache Maven
+Write-Verbose "Couldn't find MAVEN_HOME, downloading and installing it ..."
+Write-Verbose "Downloading from: $distributionUrl"
+Write-Verbose "Downloading to: $TMP_DOWNLOAD_DIR/$distributionUrlName"
+
+$webclient = New-Object System.Net.WebClient
+if ($env:MVNW_USERNAME -and $env:MVNW_PASSWORD) {
+  $webclient.Credentials = New-Object 
System.Net.NetworkCredential($env:MVNW_USERNAME, $env:MVNW_PASSWORD)
+}
+[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12
+$webclient.DownloadFile($distributionUrl, 
"$TMP_DOWNLOAD_DIR/$distributionUrlName") | Out-Null
+
+# If specified, validate the SHA-256 sum of the Maven distribution zip file
+$distributionSha256Sum = (Get-Content -Raw 
"$scriptDir/.mvn/wrapper/maven-wrapper.properties" | 
ConvertFrom-StringData).distributionSha256Sum
+if ($distributionSha256Sum) {
+  if ($USE_MVND) {
+    Write-Error "Checksum validation is not supported for maven-mvnd. `nPlease 
disable validation by removing 'distributionSha256Sum' from your 
maven-wrapper.properties."
+  }
+  Import-Module $PSHOME\Modules\Microsoft.PowerShell.Utility -Function 
Get-FileHash
+  if ((Get-FileHash "$TMP_DOWNLOAD_DIR/$distributionUrlName" -Algorithm 
SHA256).Hash.ToLower() -ne $distributionSha256Sum) {
+    Write-Error "Error: Failed to validate Maven distribution SHA-256, your 
Maven distribution might be compromised. If you updated your Maven version, you 
need to update the specified distributionSha256Sum property."
+  }
+}
+
+# unzip and move
+Expand-Archive "$TMP_DOWNLOAD_DIR/$distributionUrlName" -DestinationPath 
"$TMP_DOWNLOAD_DIR" | Out-Null
+
+# Find the actual extracted directory name (handles snapshots where filename 
!= directory name)
+$actualDistributionDir = ""
+
+# First try the expected directory name (for regular distributions)
+$expectedPath = Join-Path "$TMP_DOWNLOAD_DIR" "$distributionUrlNameMain"
+$expectedMvnPath = Join-Path "$expectedPath" "bin/$MVN_CMD"
+if ((Test-Path -Path $expectedPath -PathType Container) -and (Test-Path -Path 
$expectedMvnPath -PathType Leaf)) {
+  $actualDistributionDir = $distributionUrlNameMain
+}
+
+# If not found, search for any directory with the Maven executable (for 
snapshots)
+if (!$actualDistributionDir) {
+  Get-ChildItem -Path "$TMP_DOWNLOAD_DIR" -Directory | ForEach-Object {
+    $testPath = Join-Path $_.FullName "bin/$MVN_CMD"
+    if (Test-Path -Path $testPath -PathType Leaf) {
+      $actualDistributionDir = $_.Name
+    }
+  }
+}
+
+if (!$actualDistributionDir) {
+  Write-Error "Could not find Maven distribution directory in extracted 
archive"
+}
+
+Write-Verbose "Found extracted Maven distribution directory: 
$actualDistributionDir"
+Rename-Item -Path "$TMP_DOWNLOAD_DIR/$actualDistributionDir" -NewName 
$MAVEN_HOME_NAME | Out-Null
+try {
+  Move-Item -Path "$TMP_DOWNLOAD_DIR/$MAVEN_HOME_NAME" -Destination 
$MAVEN_HOME_PARENT | Out-Null
+} catch {
+  if (! (Test-Path -Path "$MAVEN_HOME" -PathType Container)) {
+    Write-Error "fail to move MAVEN_HOME"
+  }
+} finally {
+  try { Remove-Item $TMP_DOWNLOAD_DIR -Recurse -Force | Out-Null }
+  catch { Write-Warning "Cannot remove $TMP_DOWNLOAD_DIR" }
+}
+
+Write-Output "MVN_CMD=$MAVEN_HOME/bin/$MVN_CMD"
diff --git a/pom.xml b/pom.xml
index c14f9ec85..b2429d967 100644
--- a/pom.xml
+++ b/pom.xml
@@ -108,8 +108,8 @@
         <jcache.api.version>1.1.1</jcache.api.version>
         <jdk.version>11</jdk.version>
         <jetty.version>9.4.58.v20250814</jetty.version>
-        <tomcat.version>9.0.120</tomcat.version>
-        <tomcat10.version>10.1.57</tomcat10.version>
+        <tomcat.version>9.0.121</tomcat.version>
+        <tomcat10.version>10.1.59</tomcat10.version>
         <owasp.java.encoder.version>1.4.0</owasp.java.encoder.version>
         <!-- Don't change this version without also changing the shiro-quartz 
and shiro-features
              modules' OSGi metadata: -->
@@ -122,12 +122,12 @@
         <guice.version>4.2.3</guice.version>
         <jaxrs.api.version>2.1.6</jaxrs.api.version>
         <htmlunit.version>4.21.0</htmlunit.version>
-        <bouncycastle.version>1.85</bouncycastle.version>
+        <bouncycastle.version>1.85.2</bouncycastle.version>
 
         <!-- Test 3rd-party dependencies: -->
-        <easymock.version>5.6.0</easymock.version>
+        <easymock.version>5.7.0</easymock.version>
         <mockito.version>5.23.0</mockito.version>
-        <bytebuddy.version>1.18.11</bytebuddy.version>
+        <bytebuddy.version>1.18.12</bytebuddy.version>
         <gmaven.version>5.1.0</gmaven.version>
         <groovy.version>4.0.33</groovy.version>
         <junit.version>5.14.4</junit.version>
@@ -421,7 +421,7 @@
                 <plugin>
                     <groupId>com.mycila</groupId>
                     <artifactId>license-maven-plugin</artifactId>
-                    <version>5.1.1</version>
+                    <version>5.1.2</version>
                     <configuration>
                         <aggregate>true</aggregate>
                         <header>${root.dir}/src/license/header.txt</header>
@@ -455,7 +455,7 @@
                 <plugin>
                     <groupId>org.owasp</groupId>
                     <artifactId>dependency-check-maven</artifactId>
-                    <version>12.2.2</version>
+                    <version>13.0.0</version>
                 </plugin>
                 <plugin>
                     <groupId>com.github.siom79.japicmp</groupId>
@@ -1230,12 +1230,12 @@
             <dependency>
                 <groupId>ch.qos.logback</groupId>
                 <artifactId>logback-core</artifactId>
-                <version>1.6.1</version>
+                <version>1.6.3</version>
             </dependency>
             <dependency>
                 <groupId>ch.qos.logback</groupId>
                 <artifactId>logback-classic</artifactId>
-                <version>1.6.1</version>
+                <version>1.6.3</version>
             </dependency>
 
             <dependency>
diff --git a/samples/web-jakarta/pom.xml b/samples/web-jakarta/pom.xml
index 135e31eaa..ae06a18c9 100644
--- a/samples/web-jakarta/pom.xml
+++ b/samples/web-jakarta/pom.xml
@@ -48,7 +48,7 @@
             <dependency>
                 <groupId>org.apache.cxf</groupId>
                 <artifactId>cxf-bom</artifactId>
-                <version>3.6.11</version>
+                <version>3.6.12</version>
                 <scope>import</scope>
                 <type>pom</type>
             </dependency>
diff --git a/support/jakarta-ee/pom.xml b/support/jakarta-ee/pom.xml
index 897ca891f..12d28260c 100644
--- a/support/jakarta-ee/pom.xml
+++ b/support/jakarta-ee/pom.xml
@@ -72,12 +72,12 @@
         <dependency>
             <groupId>org.omnifaces</groupId>
             <artifactId>omnifaces</artifactId>
-            <version>3.14.23</version>
+            <version>3.14.24</version>
         </dependency>
         <dependency>
             <groupId>org.jsoup</groupId>
             <artifactId>jsoup</artifactId>
-            <version>1.22.2</version>
+            <version>1.23.2</version>
         </dependency>
 
         <!-- Test Dependencies -->
diff --git a/support/jaxrs/pom.xml b/support/jaxrs/pom.xml
index 63f474581..82df45be5 100644
--- a/support/jaxrs/pom.xml
+++ b/support/jaxrs/pom.xml
@@ -74,7 +74,7 @@
         <dependency>
             <groupId>org.apache.cxf</groupId>
             <artifactId>cxf-rt-frontend-jaxrs</artifactId>
-            <version>3.6.11</version>
+            <version>3.6.12</version>
             <scope>test</scope>
             <exclusions>
                 <exclusion>

Reply via email to