dependabot[bot] opened a new pull request, #13284:
URL: https://github.com/apache/maven/pull/13284

   Bumps [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) 
from 1.6.3 to 1.6.4.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/qos-ch/logback/releases";>ch.qos.logback:logback-classic's
 releases</a>.</em></p>
   <blockquote>
   <h2>Logback 1.6.4</h2>
   <p><strong>2026-09-24 Release of logback version 1.6.4</strong></p>
   <p>• Variable substitution is again applied to the <code>scan</code> 
attribute of the <code>&lt;configuration&gt;</code> element. The scanning 
refactoring in version 1.5.27 had dropped substitution, so values such as 
<code>${logback.scan.enabled:-true}</code> were no longer resolved. As before 
version 1.5.27, an unrecognized non-empty value turns scanning on. The same 
substitution now applies to the scan attribute of 
<code>&lt;propertiesConfigurator&gt;</code>. This regression was reported in <a 
href="https://redirect.github.com/qos-ch/logback/issues/1065";>issues/1065</a> 
by <a href="https://github.com/vaibhavjain2";>vaibhavjain2</a>.</p>
   <p>• <code>OutputStreamAppender</code> and <code>FileAppender</code> now 
handle stateful encoders. The <code>Encoder</code> interface has a new default 
method called <code>isStateful()</code>, which returns <code>false</code>. An 
encoder that keeps state between calls to <code>encode()</code> can return 
true. For such encoders, the appender holds its write lock while encoding and 
while writing, so the output of concurrent appends cannot interleave. Stateless 
encoders still encode outside the lock, so their performance does not change. 
Existing encoders need no changes.</p>
   <p>• Several race conditions in <code>OutputStreamAppender</code> and 
<code>FileAppender</code> were fixed. The appender is now marked started and 
the encoder header is written while the same lock is held, so a concurrent 
append can no longer write an event before the header. After acquiring the 
lock, the appender checks again whether it has been stopped, so no event is 
written after the footer. In prudent mode, FileAppender now encodes and writes 
each event while holding the lock.</p>
   <p>• Fixed a data race on the logger count in LoggerContext. Loggers are 
created under the lock of their parent logger, so loggers with different 
parents could be created at the same time and increments of the shared counter 
could be lost. As a result, <code>LoggerContext.size()</code> could return a 
value lower than the actual number of loggers. The counter is now an 
<code>AtomicInteger</code>. This issue was reported in <a 
href="https://redirect.github.com/qos-ch/logback/issues/1038";>issues/1038</a> 
by hcantunc. The fix was contributed in PR <a 
href="https://redirect.github.com/qos-ch/logback/issues/1055";>#1055</a> by <a 
href="https://github.com/seonwooj0810";>seonwoo_jung</a>.</p>
   <p>• <code>TimeBasedRollingPolicy</code> now supports half-day periods. Date 
patterns with the AM/PM marker, for example %d{yyyy-MM-dd-a}, used to be 
detected as daily and rolled over only at midnight. They now roll over at both 
00:00 and 12:00. This issue was reported in issues/976 by shakthifuture. The 
fix was contributed in PR <a 
href="https://redirect.github.com/qos-ch/logback/issues/1051";>#1051</a> by <a 
href="https://github.com/seonwooj0810";>seonwoo_jung</a>. See 
<code>TimeBasedRollingPolicy</code>.</p>
   <p>• If <code>org.jline.jansi.AnsiConsole</code> cannot be found on the 
class path, <code>JansiConsoleAppender</code> now emits warnings that explain 
how to add org.jline:jansi-core and then writes to the plain console stream. 
See codes.html#missingJlineJansi.</p>
   <p>• The unused 
<code>ch.qos.logback.classic.util.LogbackMDCAdapterSimple</code> class was 
removed. <code>LogbackMDCAdapter</code> remains the default MDC adapter.</p>
   <p>• A bit-wise identical binary of this version can be reproduced by 
building from source code at commit 07d291ca0d280bc5da934ec9ff5f1da634fd7937 
associated with the tag v_1.6.4. The release was built using Java 
&quot;21&quot; 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 
11.6.</p>
   <p><strong>Full Changelog</strong>: <a 
href="https://github.com/qos-ch/logback/compare/v_1.6.3...v_1.6.4";>https://github.com/qos-ch/logback/compare/v_1.6.3...v_1.6.4</a></p>
   </blockquote>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/qos-ch/logback/commit/07d291ca0d280bc5da934ec9ff5f1da634fd7937";><code>07d291c</code></a>
 preapre release 1.6.4</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/9627dafd8c21639e653f80c3e1f98bf8b4bb9be5";><code>9627daf</code></a>
 revert to Collections.unmodifiableMap instead of</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/aa42fb551a52901929433cd7282264a911e5a12e";><code>aa42fb5</code></a>
 disabled RollingCalendarTest#testVaryingNumberOfHalfDailyPeriods to shave 
off...</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/ddc7459d0022d4c07b2800490f6e607258d1f567";><code>ddc7459</code></a>
 Support HALF_DAY periodicity for AM/PM date patterns</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/42d75d76bebc4789edcd06869e8ad6f5b74c8da4";><code>42d75d7</code></a>
 disable LoggerContextTest#concurrentGetLoggerKeepsSizeConsistent to shave 
exe...</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/bffd55ed222eda41a67b0f2736476e47fad49f57";><code>bffd55e</code></a>
 add warnings about missing jline.jansi classes</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/8de0b9b64abc9a4be13df0e7332a0c6827e1d0a7";><code>8de0b9b</code></a>
 Fix data race on LoggerContext.size (<a 
href="https://redirect.github.com/qos-ch/logback/issues/1038";>#1038</a>)</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/76c73d1402cef39586527446665e870efe32d2d6";><code>76c73d1</code></a>
 add MinimalUnmodifiableMap and return it in 
LogbackMDCAdapter#getPropertyMap</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/a2c416a361a9af8677b79ba3b3c235a6984a2dfd";><code>a2c416a</code></a>
 Fix formatting of email instruction in README</li>
   <li><a 
href="https://github.com/qos-ch/logback/commit/2c89727c6a24a8283d7485165f70199abbf00b16";><code>2c89727</code></a>
 mailing lists have been deactivated</li>
   <li>Additional commits viewable in <a 
href="https://github.com/qos-ch/logback/compare/v_1.6.3...v_1.6.4";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=ch.qos.logback:logback-classic&package-manager=maven&previous-version=1.6.3&new-version=1.6.4)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to