dependabot[bot] opened a new pull request, #4026: URL: https://github.com/apache/avro/pull/4026
Bumps [org.apache.thrift:libthrift](https://github.com/apache/thrift) from 0.20.0 to 0.25.0. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/apache/thrift/releases">org.apache.thrift:libthrift's releases</a>.</em></p> <blockquote> <h2>Version 0.25.0</h2> <p>Please head over to the official release download source: <a href="http://thrift.apache.org/download">http://thrift.apache.org/download</a></p> <p>The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.</p> <h2>Version 0.24.0</h2> <p>Please head over to the official release download source: <a href="http://thrift.apache.org/download">http://thrift.apache.org/download</a></p> <p>The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.</p> <h2>Version 0.23.0</h2> <p>Please head over to the official release download source: <a href="http://thrift.apache.org/download">http://thrift.apache.org/download</a></p> <p>The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.</p> <h2>Version 0.22.0</h2> <p>Please head over to the official release download source: <a href="http://thrift.apache.org/download">http://thrift.apache.org/download</a></p> <p>The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.</p> <h2>Version 0.21.0</h2> <p>Please head over to the official release download source: <a href="http://thrift.apache.org/download">http://thrift.apache.org/download</a></p> <p>The assets listed below are added by Github based on the release tag and they will therefore not match the checkums published on the Thrift project website.</p> </blockquote> </details> <details> <summary>Changelog</summary> <p><em>Sourced from <a href="https://github.com/apache/thrift/blob/master/CHANGES.md">org.apache.thrift:libthrift's changelog</a>.</em></p> <blockquote> <h2>0.25.0</h2> <h3>Build Process</h3> <ul> <li><a href="https://issues.apache.org/jira/browse/THRIFT-2208">THRIFT-2208</a> - Thrift package for chocolatey</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6077">THRIFT-6077</a> - improve CHANGES.md generator section assignment</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6170">THRIFT-6170</a> - Add a GitHub Actions CI job for the D library</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6171">THRIFT-6171</a> - Add a GitHub Actions CI job for the Erlang library</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6172">THRIFT-6172</a> - Dart tests are not run by make check, and no CI job builds the binding</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6185">THRIFT-6185</a> - lib/d does not build against OpenSSL 3.x</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6189">THRIFT-6189</a> - Add a GitHub Actions CI job for the Lua library</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6190">THRIFT-6190</a> - Add a compile and test check for the JavaME library</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6196">THRIFT-6196</a> - Remove the unreleased contrib thrift-maven-plugin in favour of standard Maven plugins</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6234">THRIFT-6234</a> - Configure apt retries and timeouts in GitHub Actions workflows</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6235">THRIFT-6235</a> - Compiler unit tests fail to link when the Go generator is disabled</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6237">THRIFT-6237</a> - Shrink the MSVC Docker image: drop the unused .NET Framework base and JDK, prune Boost, pin tool versions</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6247">THRIFT-6247</a> - AppVeyor jobs depend on a single fallback URL for the zlib download</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6250">THRIFT-6250</a> - Clean up the warnings in the MSVC CI build</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6270">THRIFT-6270</a> - Sweep for source files that no build list mentions</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6274">THRIFT-6274</a> - Reject AI session and conversation links in pull request commits and text</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6276">THRIFT-6276</a> - AppVeyor MINGW job fails when one MSYS2 mirror drops a signature download</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6277">THRIFT-6277</a> - CHANGES draft lists tickets that are not fixed in the release</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6278">THRIFT-6278</a> - CHANGES draft generator loses a whole JIRA lookup over one nonexistent ticket key</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6284">THRIFT-6284</a> - Wire up source and test files that a build list misses (THRIFT-6270 follow-up)</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6301">THRIFT-6301</a> - veralign.sh rewrites third-party versions in lockfiles when they match the old Thrift version</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6302">THRIFT-6302</a> - veralign.sh: jsonReplace reports failures as OK, and the file loop is not sorted</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6305">THRIFT-6305</a> - veralign.sh reports a JSON file that jq cannot read as a missing version</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6310">THRIFT-6310</a> - Build the Thrift compiler on Windows in CI</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6311">THRIFT-6311</a> - Build a Windows installer for the Thrift compiler at release time</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6313">THRIFT-6313</a> - Publish the Windows Thrift compiler as a .NET tool</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6314">THRIFT-6314</a> - Publish the Windows Thrift compiler through WinGet</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6315">THRIFT-6315</a> - Stale msvc2017 paths in the Windows Docker documentation</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6319">THRIFT-6319</a> - lib/ts is not part of the build, so its check-local target never runs</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6320">THRIFT-6320</a> - Stop asking for a static runtime when building the release compiler</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6324">THRIFT-6324</a> - Cut the AppVeyor build matrix and build in parallel</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6325">THRIFT-6325</a> - Let the MSVC builds use /MP again</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6326">THRIFT-6326</a> - Compile the compiler sources once for the executable and the unit tests</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6327">THRIFT-6327</a> - Document the credentials the release workflows need in one place</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6330">THRIFT-6330</a> - Add a GitHub Actions CI job for the JavaScript library</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6334">THRIFT-6334</a> - Adopt a version support policy and require PHP 8.2</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6349">THRIFT-6349</a> - Drop the ubuntu-focal build image</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6351">THRIFT-6351</a> - Require GLib 2.48 in configure and CMake</li> <li><a href="https://issues.apache.org/jira/browse/THRIFT-6361">THRIFT-6361</a> - Add a GitHub Actions CI job for the C (GLib) library</li> <li><a href="https://redirect.github.com/apache/thrift/pull/3945">#3945</a> - Bump <code>@babel/core</code> from 7.8.4 to 7.29.7</li> <li><a href="https://redirect.github.com/apache/thrift/pull/3911">#3911</a> - Bump brace-expansion from 2.1.0 to 2.1.7</li> <li><a href="https://redirect.github.com/apache/thrift/pull/3890">#3890</a> - Let prose-only commits skip CI</li> <li><a href="https://redirect.github.com/apache/thrift/pull/3816">#3816</a> - Cap every build workflow job at 60 minutes</li> <li><a href="https://redirect.github.com/apache/thrift/pull/3837">#3837</a> - Resolve config.h.in relative to ConfigureChecks.cmake</li> <li><a href="https://redirect.github.com/apache/thrift/pull/3833">#3833</a> - Bump js-yaml from 3.15.1 to 3.15.2 in /lib/js</li> <li><a href="https://redirect.github.com/apache/thrift/pull/3790">#3790</a> - Bump <code>@humanfs/node</code> from 0.16.6 to 0.16.8</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/apache/thrift/commit/27e8a425ffb498e190df3a12e239326bf5ba9ed6"><code>27e8a42</code></a> THRIFT-6367: Cap the message name in the Erlang binary and compact protocols</li> <li><a href="https://github.com/apache/thrift/commit/e6f57e24f649c7e4f011fdc61185daca46e97626"><code>e6f57e2</code></a> Collect JSON strings in chunks; bound numbers and message names</li> <li><a href="https://github.com/apache/thrift/commit/27fa70442bccdf981d72b1e57d1080646cb5e360"><code>27fa704</code></a> THRIFT-6366: Bound the message size in the Erlang binary and compact protocols</li> <li><a href="https://github.com/apache/thrift/commit/02b7d4dd3eed5f35165bd51eac99ebf053c62ea4"><code>02b7d4d</code></a> Updated CHANGES.md</li> <li><a href="https://github.com/apache/thrift/commit/e9360fe4834e3437444381169b206fcb3c03ef7f"><code>e9360fe</code></a> THRIFT-6365: Add a container-size limit to the Lua protocols</li> <li><a href="https://github.com/apache/thrift/commit/2c09024bde00de4e3cb0c77a371880fae3882171"><code>2c09024</code></a> Bound the size of a message thrift_json_protocol reads</li> <li><a href="https://github.com/apache/thrift/commit/74a4f3e13fb923bb842fd7ce60565f39c5a68f3e"><code>74a4f3e</code></a> Updated CHANGES.md</li> <li><a href="https://github.com/apache/thrift/commit/3bd6bfbe6b0072ebc18c16a18e7479431c4c2747"><code>3bd6bfb</code></a> keep branch at 0.25.0</li> <li><a href="https://github.com/apache/thrift/commit/04502bd39348fa2ffe5bc77e6fee362870816192"><code>04502bd</code></a> keep branch at 0.25.0</li> <li><a href="https://github.com/apache/thrift/commit/6dcc437b40041216e7c0ce589fbd65c0cd39e3b0"><code>6dcc437</code></a> Merge branch 'master' into release/0.25.0</li> <li>Additional commits viewable in <a href="https://github.com/apache/thrift/compare/v0.20.0...v0.25.0">compare view</a></li> </ul> </details> <br /> [](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot show <dependency name> ignore conditions` will show all of the ignore conditions of the specified dependency - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
