dependabot[bot] opened a new pull request, #7538:
URL: https://github.com/apache/myfaces-tobago/pull/7538

   Bumps `logback.version` from 1.6.1 to 1.6.3.
   Updates `ch.qos.logback:logback-classic` from 1.6.1 to 1.6.3
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/qos-ch/logback/releases";>ch.qos.logback:logback-classic's
 releases</a>.</em></p>
   <blockquote>
   <h2>Logback 1.6.3</h2>
   <h1>2026-08-14 Release of logback version 1.6.3</h1>
   <ul>
   <li>
   <p>In response <a 
href="https://www.cve.org/cverecord?id=CVE-2026-19880";>CVE-2026-19880</a>,  
<code>MDCBasedDiscriminator</code> (used by <code>SiftingAppender</code>) now 
strips forward and  backward slashes (<code>/</code>, <code>\</code>) from MDC 
values before they are used as  discriminating keys. This prevents path 
segments from escaping into  destinations controlled by an attacker. When 
sanitisation actually changes a  value, a warning is emitted; the warning is 
rate-limited (a small batch, then  a lull of about ten minutes).</p>
   </li>
   <li>
   <p>Colour console support is split out into a dedicated  <a 
href="https://logback.qos.ch/manual/appenders.html#JansiConsoleAppender";><code>JansiConsoleAppender</code></a>.
 It wraps stdout or stderr with  Jansi so ANSI escape sequences (for example 
coloured patterns) render  correctly on terminals that need it, notably 
Windows. Prefer this class over  the older path described next. See the  <a 
href="https://logback.qos.ch/manual/appenders.html#JansiConsoleAppender";>appenders
 documentation</a>.</p>
   </li>
   <li>
   <p>The <code>withJansi</code> property on <code>ConsoleAppender</code> is 
<strong>deprecated</strong>. Existing  configurations that still set 
<code>&lt;withJansi&gt;true&lt;/withJansi&gt;</code> continue to work  for 
compatibility, but new setups should use <code>JansiConsoleAppender</code> 
instead.</p>
   </li>
   <li>
   <p><code>ConsoleAppender</code> no longer treats the process console as an 
exclusive  resource: stopping it does not close <code>System.out</code> / 
<code>System.err</code>.  <code>JansiConsoleAppender</code> pairs each 
<code>AnsiConsole.systemInstall()</code> with  <code>systemUninstall()</code> 
on stop, so repeated start/stop cycles do not leave Jansi  installed or tear 
down streams shared with the rest of the JVM. Related  behavior is covered by 
tests for  <a 
href="https://redirect.github.com/qos-ch/logback/issues/1063";>issues/1063</a>.</p>
   </li>
   <li>
   <p>Invocation throttling helpers were reworked: 
<code>SimpleInvocationGate</code> is renamed  
<code>FixedIntervalInvocationGate</code>, and 
<code>BatchedFixedIntervalInvocationGate</code> allows  a short burst of 
invocations before applying a fixed lull. The sanitisation
   warning above uses the batched gate.</p>
   </li>
   <li>
   <p>The JPMS <code>module-info</code> for logback-core now exports the  
<code>ch.qos.logback.core.property</code> package, which had been missing from 
the module   descriptor.</p>
   </li>
   <li>
   <p>A bit-wise identical binary of this version can be reproduced by building 
from  <a href="https://github.com/qos-ch/logback";>source code</a> at commit  
<code>e8e824dede022a6d7208b36cfa875b0d1b7772f3</code> associated with the tag 
<code>v_1.6.3</code>.  The release was built using Java &quot;21&quot; 
2023-10-17 LTS build 21.0.1.+12-LTS-29   under Linux Debian 11.6.</p>
   </li>
   </ul>
   <h2>Logback 1.6.2</h2>
   <p><a 
href="https://github.com/user-attachments/assets/9ceaf157-b758-4188-815d-edfe4e1b4edd";>https://github.com/user-attachments/assets/9ceaf157-b758-4188-815d-edfe4e1b4edd</a></p>
   <h1>2026-08-10 Release of logback version 1.6.2</h1>
   <ul>
   <li>
   <p>Configuration analysis now detects <em>contradictory caller-data 
inclusion instructions</em>. For example, an <code>AsyncAppender</code>, 
<code>SocketAppender</code> or <code>SMTPAppender</code> with 
<code>includeCallerData</code> left at the default <code>false</code> is 
incompatible with a layout or encoder pattern that uses a caller-data converter 
such as <code>%C</code>, <code>%M</code>, <code>%L</code>, <code>%F</code>, 
<code>%l</code> or <code>%caller</code>. At runtime those converters would 
print question marks and still incur extraction cost on a worker thread. 
Logback now emits a configuration-time warning when such instructions disagree. 
See <a 
href="https://logback.qos.ch/codes.html#callerContradiction";>codes.html#callerContradiction</a>
 for details. This issue was reported in <a 
href="https://redirect.github.com/qos-ch/logback/issues/1059";>issues/1059</a> 
by <a href="https://github.com/leeychee";>leeychee</a>. The initial analysis was 
contributed by <a href="https:/
 /github.com/seonwooj0810">seonwoo_jung</a>.</p>
   </li>
   <li>
   <p>Caller-contradiction analysis can be turned off by setting the 
<code>logback.skipCallerContradictionAnalysis</code> variable to 
<code>true</code>, either as a system property 
(<code>-Dlogback.skipCallerContradictionAnalysis=true</code>) or as a property 
in the configuration file:</p>
   <pre lang="xml"><code>&lt;property 
name=&quot;logback.skipCallerContradictionAnalysis&quot; 
value=&quot;true&quot;/&gt;
   </code></pre>
   </li>
   <li>
   <p><code>SimpleSocketServer</code> and <code>SimpleSSLSocketServer</code> 
now require an explicit client IP whitelist. On the command line, pass one or 
more allowed addresses (single IPs or CIDR ranges) after the configuration 
file. An empty whitelist means no clients are accepted. When embedding the 
server programmatically, register allowed addresses with 
<code>addAllowedClientAddress(String)</code> or 
<code>setAllowedClientAddresses(Collection)</code> before clients connect. See 
the documentation on <a 
href="https://logback.qos.ch/manual/appenders.html#simpleSocketServerClientAccess";>restricting
 client access</a>.</p>
   </li>
   <li>
   <p>Added <code>ThrowableProxyVOBuilder</code> for assembling a 
<code>ThrowableProxyVO</code> field by field, with a corresponding 
<code>ThrowableProxyVO.builder()</code> entry point.</p>
   </li>
   <li>
   <p>Dependency analysis handlers now run their <code>postHandle</code> method 
after child models have been processed, so checks that depend on nested 
appenders (such as caller-contradiction analysis) see a complete picture.</p>
   </li>
   <li>
   <p>Updated several dependencies, including Angus Mail to 2.0.4 and Jetty 
(test) to 12.1.12.</p>
   </li>
   <li>
   <p>A bit-wise identical binary of this version can be reproduced by building 
from <a href="https://github.com/qos-ch/logback";>source code</a> at commit 
e3d78330ad1ba024fd987fd00c3ffb9cfcdb07dc associated with the tag 
<code>v_1.6.2</code>. The release was built using Java &quot;21&quot; 
2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.</p>
   </li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/qos-ch/logback/commit/e8e824dede022a6d7208b36cfa875b0d1b7772f3";><code>e8e824d</code></a>
 prepare release 1.6.3</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/761821bfaacac3a0ad44fa546cfc814429bf9312";><code>761821b</code></a>
 MDCBasedDiscriminator has a gated warning mechanism</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/53ed1229008d8b1902f5c234deaa07d742890879";><code>53ed122</code></a>
 update copyright year</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/c7e2db244671ffa916182b5da8c89579eb54a645";><code>c7e2db2</code></a>
 rename SimpleInvocationGate as FixedIntervalInvocationGate</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/b5aa931b096a4b0b6a9e140b74fabe7da152cbf0";><code>b5aa931</code></a>
 added BatchedSimpleInvocationGate</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/1f22af7686aadd25c08b4bd1e6943a906a743ad4";><code>1f22af7</code></a>
 add javadocs to SimpleInvocationGate</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/638ffa7e7852478b605a91b3e91238ff26f8158c";><code>638ffa7</code></a>
 prevent forward and backward slashes to escape to other directories</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/7d6b9a4f8c8996834c0a694f6c141705a003d7bb";><code>7d6b9a4</code></a>
 add missing ch.qos.logback.core.property package</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/fa25930346f35636fb6a077c1f66ebb06edd3b6f";><code>fa25930</code></a>
 add an extension path in ConsoleAppender for JansiConsoleAppender</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/c73b43f2011f9d4545abc7ea461172276a0a43b3";><code>c73b43f</code></a>
 deprecate the withJansi path</li>
   <li>Additional commits viewable in <a 
href="https://github.com/qos-ch/logback/compare/v_1.6.1...v_1.6.3";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `ch.qos.logback:logback-core` from 1.6.1 to 1.6.3
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/qos-ch/logback/releases";>ch.qos.logback:logback-core's 
releases</a>.</em></p>
   <blockquote>
   <h2>Logback 1.6.3</h2>
   <h1>2026-08-14 Release of logback version 1.6.3</h1>
   <ul>
   <li>
   <p>In response <a 
href="https://www.cve.org/cverecord?id=CVE-2026-19880";>CVE-2026-19880</a>,  
<code>MDCBasedDiscriminator</code> (used by <code>SiftingAppender</code>) now 
strips forward and  backward slashes (<code>/</code>, <code>\</code>) from MDC 
values before they are used as  discriminating keys. This prevents path 
segments from escaping into  destinations controlled by an attacker. When 
sanitisation actually changes a  value, a warning is emitted; the warning is 
rate-limited (a small batch, then  a lull of about ten minutes).</p>
   </li>
   <li>
   <p>Colour console support is split out into a dedicated  <a 
href="https://logback.qos.ch/manual/appenders.html#JansiConsoleAppender";><code>JansiConsoleAppender</code></a>.
 It wraps stdout or stderr with  Jansi so ANSI escape sequences (for example 
coloured patterns) render  correctly on terminals that need it, notably 
Windows. Prefer this class over  the older path described next. See the  <a 
href="https://logback.qos.ch/manual/appenders.html#JansiConsoleAppender";>appenders
 documentation</a>.</p>
   </li>
   <li>
   <p>The <code>withJansi</code> property on <code>ConsoleAppender</code> is 
<strong>deprecated</strong>. Existing  configurations that still set 
<code>&lt;withJansi&gt;true&lt;/withJansi&gt;</code> continue to work  for 
compatibility, but new setups should use <code>JansiConsoleAppender</code> 
instead.</p>
   </li>
   <li>
   <p><code>ConsoleAppender</code> no longer treats the process console as an 
exclusive  resource: stopping it does not close <code>System.out</code> / 
<code>System.err</code>.  <code>JansiConsoleAppender</code> pairs each 
<code>AnsiConsole.systemInstall()</code> with  <code>systemUninstall()</code> 
on stop, so repeated start/stop cycles do not leave Jansi  installed or tear 
down streams shared with the rest of the JVM. Related  behavior is covered by 
tests for  <a 
href="https://redirect.github.com/qos-ch/logback/issues/1063";>issues/1063</a>.</p>
   </li>
   <li>
   <p>Invocation throttling helpers were reworked: 
<code>SimpleInvocationGate</code> is renamed  
<code>FixedIntervalInvocationGate</code>, and 
<code>BatchedFixedIntervalInvocationGate</code> allows  a short burst of 
invocations before applying a fixed lull. The sanitisation
   warning above uses the batched gate.</p>
   </li>
   <li>
   <p>The JPMS <code>module-info</code> for logback-core now exports the  
<code>ch.qos.logback.core.property</code> package, which had been missing from 
the module   descriptor.</p>
   </li>
   <li>
   <p>A bit-wise identical binary of this version can be reproduced by building 
from  <a href="https://github.com/qos-ch/logback";>source code</a> at commit  
<code>e8e824dede022a6d7208b36cfa875b0d1b7772f3</code> associated with the tag 
<code>v_1.6.3</code>.  The release was built using Java &quot;21&quot; 
2023-10-17 LTS build 21.0.1.+12-LTS-29   under Linux Debian 11.6.</p>
   </li>
   </ul>
   <h2>Logback 1.6.2</h2>
   <p><a 
href="https://github.com/user-attachments/assets/9ceaf157-b758-4188-815d-edfe4e1b4edd";>https://github.com/user-attachments/assets/9ceaf157-b758-4188-815d-edfe4e1b4edd</a></p>
   <h1>2026-08-10 Release of logback version 1.6.2</h1>
   <ul>
   <li>
   <p>Configuration analysis now detects <em>contradictory caller-data 
inclusion instructions</em>. For example, an <code>AsyncAppender</code>, 
<code>SocketAppender</code> or <code>SMTPAppender</code> with 
<code>includeCallerData</code> left at the default <code>false</code> is 
incompatible with a layout or encoder pattern that uses a caller-data converter 
such as <code>%C</code>, <code>%M</code>, <code>%L</code>, <code>%F</code>, 
<code>%l</code> or <code>%caller</code>. At runtime those converters would 
print question marks and still incur extraction cost on a worker thread. 
Logback now emits a configuration-time warning when such instructions disagree. 
See <a 
href="https://logback.qos.ch/codes.html#callerContradiction";>codes.html#callerContradiction</a>
 for details. This issue was reported in <a 
href="https://redirect.github.com/qos-ch/logback/issues/1059";>issues/1059</a> 
by <a href="https://github.com/leeychee";>leeychee</a>. The initial analysis was 
contributed by <a href="https:/
 /github.com/seonwooj0810">seonwoo_jung</a>.</p>
   </li>
   <li>
   <p>Caller-contradiction analysis can be turned off by setting the 
<code>logback.skipCallerContradictionAnalysis</code> variable to 
<code>true</code>, either as a system property 
(<code>-Dlogback.skipCallerContradictionAnalysis=true</code>) or as a property 
in the configuration file:</p>
   <pre lang="xml"><code>&lt;property 
name=&quot;logback.skipCallerContradictionAnalysis&quot; 
value=&quot;true&quot;/&gt;
   </code></pre>
   </li>
   <li>
   <p><code>SimpleSocketServer</code> and <code>SimpleSSLSocketServer</code> 
now require an explicit client IP whitelist. On the command line, pass one or 
more allowed addresses (single IPs or CIDR ranges) after the configuration 
file. An empty whitelist means no clients are accepted. When embedding the 
server programmatically, register allowed addresses with 
<code>addAllowedClientAddress(String)</code> or 
<code>setAllowedClientAddresses(Collection)</code> before clients connect. See 
the documentation on <a 
href="https://logback.qos.ch/manual/appenders.html#simpleSocketServerClientAccess";>restricting
 client access</a>.</p>
   </li>
   <li>
   <p>Added <code>ThrowableProxyVOBuilder</code> for assembling a 
<code>ThrowableProxyVO</code> field by field, with a corresponding 
<code>ThrowableProxyVO.builder()</code> entry point.</p>
   </li>
   <li>
   <p>Dependency analysis handlers now run their <code>postHandle</code> method 
after child models have been processed, so checks that depend on nested 
appenders (such as caller-contradiction analysis) see a complete picture.</p>
   </li>
   <li>
   <p>Updated several dependencies, including Angus Mail to 2.0.4 and Jetty 
(test) to 12.1.12.</p>
   </li>
   <li>
   <p>A bit-wise identical binary of this version can be reproduced by building 
from <a href="https://github.com/qos-ch/logback";>source code</a> at commit 
e3d78330ad1ba024fd987fd00c3ffb9cfcdb07dc associated with the tag 
<code>v_1.6.2</code>. The release was built using Java &quot;21&quot; 
2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.</p>
   </li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/qos-ch/logback/commit/e8e824dede022a6d7208b36cfa875b0d1b7772f3";><code>e8e824d</code></a>
 prepare release 1.6.3</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/761821bfaacac3a0ad44fa546cfc814429bf9312";><code>761821b</code></a>
 MDCBasedDiscriminator has a gated warning mechanism</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/53ed1229008d8b1902f5c234deaa07d742890879";><code>53ed122</code></a>
 update copyright year</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/c7e2db244671ffa916182b5da8c89579eb54a645";><code>c7e2db2</code></a>
 rename SimpleInvocationGate as FixedIntervalInvocationGate</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/b5aa931b096a4b0b6a9e140b74fabe7da152cbf0";><code>b5aa931</code></a>
 added BatchedSimpleInvocationGate</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/1f22af7686aadd25c08b4bd1e6943a906a743ad4";><code>1f22af7</code></a>
 add javadocs to SimpleInvocationGate</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/638ffa7e7852478b605a91b3e91238ff26f8158c";><code>638ffa7</code></a>
 prevent forward and backward slashes to escape to other directories</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/7d6b9a4f8c8996834c0a694f6c141705a003d7bb";><code>7d6b9a4</code></a>
 add missing ch.qos.logback.core.property package</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/fa25930346f35636fb6a077c1f66ebb06edd3b6f";><code>fa25930</code></a>
 add an extension path in ConsoleAppender for JansiConsoleAppender</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/c73b43f2011f9d4545abc7ea461172276a0a43b3";><code>c73b43f</code></a>
 deprecate the withJansi path</li>
   <li>Additional commits viewable in <a 
href="https://github.com/qos-ch/logback/compare/v_1.6.1...v_1.6.3";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to