solrbot opened a new pull request, #4976:
URL: https://github.com/apache/solr/pull/4976

   > ℹ️ **Note**
   > 
   > This PR body was truncated due to platform limits.
   
   This PR contains the following updates:
   
   | Package | Type | Update | Change | Pending |
   |---|---|---|---|---|
   | 
[tools.jackson:jackson-bom](https://redirect.github.com/FasterXML/jackson-bom) 
| dependencies | patch | `3.2.1` → `3.2.3` |  |
   | de.thetaphi.forbiddenapis | plugin | minor | `3.10` → `3.11` |  |
   | io.swagger.core.v3.swagger-gradle-plugin | plugin | patch | `2.2.54` → 
`2.2.55` |  |
   | 
[io.swagger.core.v3:swagger-jaxrs2-jakarta](https://redirect.github.com/swagger-api/swagger-core)
 | dependencies | patch | `2.2.54` → `2.2.55` |  |
   | 
[io.swagger.core.v3:swagger-annotations-jakarta](https://redirect.github.com/swagger-api/swagger-core)
 | dependencies | patch | `2.2.54` → `2.2.55` |  |
   | [org.seleniumhq.selenium:selenium-chrome-driver](https://selenium.dev/) 
([source](https://redirect.github.com/SeleniumHQ/selenium)) | dependencies | 
minor | `4.47.0` → `4.49.0` | `4.50.0` |
   | 
[com.microsoft.onnxruntime:onnxruntime](https://microsoft.github.io/onnxruntime/)
 ([source](https://redirect.github.com/microsoft/onnxruntime)) | dependencies | 
minor | `1.29.0` → `1.30.0` |  |
   | 
[com.nimbusds:nimbus-jose-jwt](https://bitbucket.org/connect2id/nimbus-jose-jwt)
 | dependencies | minor | `10.9.1` → `10.10` |  |
   | 
[no.nav.security:mock-oauth2-server](https://redirect.github.com/navikt/mock-oauth2-server)
 | dependencies | patch | `6.0.2` → `6.0.3` | `6.0.4` |
   | 
[org.mockito:mockito-subclass](https://redirect.github.com/mockito/mockito) | 
dependencies | minor | `5.23.0` → `5.24.0` |  |
   | [org.mockito:mockito-core](https://redirect.github.com/mockito/mockito) | 
dependencies | minor | `5.23.0` → `5.24.0` |  |
   | 
[dev.langchain4j:langchain4j-bom](https://redirect.github.com/langchain4j/langchain4j/tree/main/langchain4j-bom)
 
([source](https://redirect.github.com/langchain4j/langchain4j/tree/HEAD/langchain4j-bom))
 | dependencies | minor | `1.19.0` → `1.20.1` | `1.20.2` |
   | [joda-time:joda-time](https://www.joda.org/joda-time/) 
([source](https://redirect.github.com/JodaOrg/joda-time)) | dependencies | 
patch | `2.14.3` → `2.14.4` |  |
   | 
[org.eclipse.jgit:org.eclipse.jgit](https://eclipse.gerrithub.io/admin/repos/eclipse-jgit/jgit)
 | dependencies | minor | `7.7.1.202607240634-r` → `7.8.0.202609011348-r` |  |
   | 
[org.eclipse.jdt:ecj](https://redirect.github.com/eclipse-jdt/eclipse.jdt.core) 
([source](https://redirect.github.com/eclipse-jdt/eclipse.jdt.core/tree/HEAD/org.eclipse.jdt.core.compiler.batch))
 | dependencies | patch | `3.46.0` → `3.46.100` |  |
   | [io.dropwizard.metrics:metrics-core](https://metrics.dropwizard.io) 
([source](https://redirect.github.com/dropwizard/metrics)) | dependencies | 
patch | `4.2.39` → `4.2.40` |  |
   | com.diffplug.spotless | plugin | patch | `8.10.0` → `8.10.3` |  |
   | [org.checkerframework:checker-qual](https://checkerframework.org/) 
([source](https://redirect.github.com/typetools/checker-framework)) | 
dependencies | patch | `4.2.2` → `4.2.3` |  |
   | 
[com.carrotsearch.randomizedtesting:randomizedtesting-runner](https://redirect.github.com/randomizedtesting/randomizedtesting)
 | dependencies | patch | `2.9.1` → `2.9.2` |  |
   | [com.carrotsearch:hppc](https://redirect.github.com/carrotsearch/hppc) | 
dependencies | minor | `0.11.1` → `0.12.0` |  |
   | [net.bytebuddy:byte-buddy-agent](https://bytebuddy.net) 
([source](https://redirect.github.com/raphw/byte-buddy)) | dependencies | patch 
| `1.18.11` → `1.18.13` |  |
   | [net.bytebuddy:byte-buddy](https://bytebuddy.net) 
([source](https://redirect.github.com/raphw/byte-buddy)) | dependencies | patch 
| `1.18.11` → `1.18.13` |  |
   | 
[org.bouncycastle:bcprov-jdk18on](https://www.bouncycastle.org/download/bouncy-castle-java/)
 ([source](https://redirect.github.com/bcgit/bc-java)) | dependencies | minor | 
`1.85` → `1.86` |  |
   | 
[org.bouncycastle:bcpkix-jdk18on](https://www.bouncycastle.org/download/bouncy-castle-java/)
 ([source](https://redirect.github.com/bcgit/bc-java)) | dependencies | minor | 
`1.85` → `1.86` |  |
   | io.github.ben-manes.versions | plugin | minor | `0.61.0` → `0.64.0` |  |
   | 
[com.github.ben-manes.caffeine:caffeine](https://redirect.github.com/ben-manes/caffeine)
 | dependencies | minor | `3.2.4` → `3.3.0` |  |
   | [org.bitbucket.b_c:jose4j](https://bitbucket.org/b_c/jose4j/) 
([source](https://bitbucket.org/b_c/jose4j)) | dependencies | patch | `0.9.6` → 
`0.9.7` |  |
   | [org.apache.opennlp:opennlp-tools](https://www.apache.org/) 
([source](https://redirect.github.com/apache/opennlp)) | dependencies | patch | 
`2.5.11` → `2.5.12` |  |
   | [org.apache.opennlp:opennlp-dl](https://www.apache.org/) 
([source](https://redirect.github.com/apache/opennlp)) | dependencies | patch | 
`2.5.11` → `2.5.12` |  |
   | 
[org.apache.commons:commons-lang3](https://commons.apache.org/proper/commons-lang/)
 ([source](https://gitbox.apache.org/repos/asf/commons-lang.git)) | 
dependencies | minor | `3.20.0` → `3.21.0` |  |
   | 
[io.nlopez.compose.rules:ktlint](https://redirect.github.com/mrmans0n/compose-rules)
 | dependencies | patch | `0.6.2` → `0.6.7` |  |
   | 
[com.adobe.testing:s3mock-testcontainers](https://redirect.github.com/adobe/S3Mock)
 | dependencies | patch | `5.2.0` → `5.2.3` |  |
   
   ---
   
   ### Release Notes
   
   <details>
   <summary>swagger-api/swagger-core 
(io.swagger.core.v3:swagger-jaxrs2-jakarta)</summary>
   
   ### 
[`v2.2.55`](https://redirect.github.com/swagger-api/swagger-core/releases/tag/v2.2.55):
 Swagger-core 2.2.55 released!
   
   - chore: update dependency-check-maven to 12.2.2 
([#&#8203;5299](https://redirect.github.com/swagger-api/swagger-core/issues/5299))
   - chore: remove ACTIONS\_ALLOW\_UNSECURE\_COMMANDS from workflows 
([#&#8203;5293](https://redirect.github.com/swagger-api/swagger-core/issues/5293))
   - chore(deps-dev): bump 
org.jboss.arquillian.testng:arquillian-testng-container from 1.9.3.Final to 
1.10.2.Final 
([#&#8203;5285](https://redirect.github.com/swagger-api/swagger-core/issues/5285))
   - chore(deps): bump org.sonatype.central:central-publishing-maven-plugin 
from 0.10.0 to 0.11.0 
([#&#8203;5284](https://redirect.github.com/swagger-api/swagger-core/issues/5284))
   - chore(deps): bump slf4j-version from 2.0.17 to 2.0.18 
([#&#8203;5283](https://redirect.github.com/swagger-api/swagger-core/issues/5283))
   - fix: \_isSetType now detects indirect Set implementations 
([#&#8203;5265](https://redirect.github.com/swagger-api/swagger-core/issues/5265))
   
   </details>
   
   <details>
   <summary>microsoft/onnxruntime 
(com.microsoft.onnxruntime:onnxruntime)</summary>
   
   ### 
[`v1.30.0`](https://redirect.github.com/microsoft/onnxruntime/releases/tag/v1.30.0):
 ONNX Runtime v1.30.0
   
   ONNX Runtime 1.30.0 expands generative AI inference, improves CPU and GPU 
performance, adds Go bindings, and strengthens runtime reliability. These notes 
cover changes since ONNX Runtime 1.29.1.
   
   #### Highlights
   
   - Expanded CUDA inference support with variable-length causal convolution 
for continuous batching, speculative decoding in paged XQA, and INT4 paged KV 
caches with per-channel scales 
([#&#8203;32168](https://redirect.github.com/microsoft/onnxruntime/pull/32168), 
[#&#8203;32340](https://redirect.github.com/microsoft/onnxruntime/pull/32340), 
[#&#8203;32515](https://redirect.github.com/microsoft/onnxruntime/pull/32515)).
   - Improved WebGPU PagedAttention, added GPT-OSS support and INT8 KV-cache 
block quantization, and extended convolution optimizations 
([#&#8203;31727](https://redirect.github.com/microsoft/onnxruntime/pull/31727), 
[#&#8203;32277](https://redirect.github.com/microsoft/onnxruntime/pull/32277), 
[#&#8203;32284](https://redirect.github.com/microsoft/onnxruntime/pull/32284), 
[#&#8203;32420](https://redirect.github.com/microsoft/onnxruntime/pull/32420)).
   - Added fused CPU LinearAttention kernels for AVX-512, Arm64 NEON, and SVE, 
plus AVX2 LayerNorm/RMSNorm acceleration 
([#&#8203;31674](https://redirect.github.com/microsoft/onnxruntime/pull/31674), 
[#&#8203;31973](https://redirect.github.com/microsoft/onnxruntime/pull/31973), 
[#&#8203;32178](https://redirect.github.com/microsoft/onnxruntime/pull/32178), 
[#&#8203;32356](https://redirect.github.com/microsoft/onnxruntime/pull/32356)).
   - Added Go bindings for the ONNX Runtime C API and DeepSeek Engram contrib 
operators 
([#&#8203;29615](https://redirect.github.com/microsoft/onnxruntime/pull/29615), 
[#&#8203;32268](https://redirect.github.com/microsoft/onnxruntime/pull/32268)).
   
   #### Announcements & Compatibility
   
   - FP4 QMoE kernels are now enabled by default in CUDA builds, with Windows 
build support added in this release. Source builds can opt out with 
`-Donnxruntime_USE_FP4_QMOE=OFF` 
([#&#8203;32096](https://redirect.github.com/microsoft/onnxruntime/pull/32096), 
[#&#8203;32163](https://redirect.github.com/microsoft/onnxruntime/pull/32163)).
   - CUDA fpA-intB builds now default to a compact kernel set for FP16 
activations, INT4/INT8 weights, scale-only quantization, and `block_size=32`. 
Set `-Donnxruntime_USE_FPA_INTB_GEMM_FULL=ON` when building from source to 
retain the full kernel set, including BF16, zero-point, bias, 
larger-block-size, and native Hopper variants 
([#&#8203;32324](https://redirect.github.com/microsoft/onnxruntime/pull/32324)).
   - CPU FP16 `Gemm` and `MatMul` execution is gated on hardware acceleration. 
CPU-assigned FP16 nodes without a matching kernel now fall back to FP32 
([#&#8203;32301](https://redirect.github.com/microsoft/onnxruntime/pull/32301), 
[#&#8203;32197](https://redirect.github.com/microsoft/onnxruntime/pull/32197)).
   - WebGPU plugin EP packaging now supports Linux AArch64. Plugin versions 
were advanced to WebGPU 0.4.0 and CUDA 0.2 
([#&#8203;32287](https://redirect.github.com/microsoft/onnxruntime/pull/32287), 
[#&#8203;31960](https://redirect.github.com/microsoft/onnxruntime/pull/31960), 
[#&#8203;31970](https://redirect.github.com/microsoft/onnxruntime/pull/31970)).
   
   #### Security & Reliability
   
   ##### Model Loading, Memory, and Input Validation
   
   - Limited nested model-graph depth and canonicalized external-data locations 
to harden model loading 
([#&#8203;32344](https://redirect.github.com/microsoft/onnxruntime/pull/32344), 
[#&#8203;32135](https://redirect.github.com/microsoft/onnxruntime/pull/32135)).
   - Added checked rounding for BFC arena allocations and fixed 
prepacked-weight reference lifetimes 
([#&#8203;32010](https://redirect.github.com/microsoft/onnxruntime/pull/32010), 
[#&#8203;32040](https://redirect.github.com/microsoft/onnxruntime/pull/32040)).
   - Strengthened shape, rank, and parameter validation for `Split`, `Scan`, 
`GatherND`, `ScatterND`, `SpaceToDepth`/`DepthToSpace`, `Crop`, `Conv`, 
`Normalizer`, and pooling 
([#&#8203;29461](https://redirect.github.com/microsoft/onnxruntime/pull/29461), 
[#&#8203;31668](https://redirect.github.com/microsoft/onnxruntime/pull/31668), 
[#&#8203;32034](https://redirect.github.com/microsoft/onnxruntime/pull/32034), 
[#&#8203;32039](https://redirect.github.com/microsoft/onnxruntime/pull/32039), 
[#&#8203;32076](https://redirect.github.com/microsoft/onnxruntime/pull/32076), 
[#&#8203;32157](https://redirect.github.com/microsoft/onnxruntime/pull/32157), 
[#&#8203;32160](https://redirect.github.com/microsoft/onnxruntime/pull/32160), 
[#&#8203;32161](https://redirect.github.com/microsoft/onnxruntime/pull/32161), 
[#&#8203;32345](https://redirect.github.com/microsoft/onnxruntime/pull/32345), 
[#&#8203;32349](https://redirect.github.com/microsoft/onnxruntime/pull/32349)).
   - Hardened generation and attention input handling, including 
attention-attribute narrowing, `BifurcationDetector` inputs, generation 
subgraph shapes, and QEmbed segment inputs. BeamSearch buffer expansion now 
uses dynamic shape storage 
([#&#8203;31648](https://redirect.github.com/microsoft/onnxruntime/pull/31648), 
[#&#8203;31701](https://redirect.github.com/microsoft/onnxruntime/pull/31701), 
[#&#8203;32009](https://redirect.github.com/microsoft/onnxruntime/pull/32009), 
[#&#8203;32078](https://redirect.github.com/microsoft/onnxruntime/pull/32078), 
[#&#8203;32144](https://redirect.github.com/microsoft/onnxruntime/pull/32144)).
   - Validated `TreeEnsemble` node references and bounded subtree comparison, 
rejected non-finite CPU `RoiAlign` coordinates, and required `ImageScaler` bias 
to match the channel count 
([#&#8203;32031](https://redirect.github.com/microsoft/onnxruntime/pull/32031), 
[#&#8203;32043](https://redirect.github.com/microsoft/onnxruntime/pull/32043), 
[#&#8203;32011](https://redirect.github.com/microsoft/onnxruntime/pull/32011), 
[#&#8203;32002](https://redirect.github.com/microsoft/onnxruntime/pull/32002)).
   - Added an allowlist of safe LoRA adapter parameter data types, validated 
`MatMulFpQ4` shape inputs, and checked MLAS blockwise 
quantization/dequantization index ranges 
([#&#8203;31682](https://redirect.github.com/microsoft/onnxruntime/pull/31682), 
[#&#8203;32032](https://redirect.github.com/microsoft/onnxruntime/pull/32032), 
[#&#8203;32007](https://redirect.github.com/microsoft/onnxruntime/pull/32007)).
   
   ##### GPU Bounds and Resource Lifetimes
   
   - Hardened CUDA indexing and buffer-size arithmetic in `MatMulNBits`, 
`RemovePadding`, `RotaryEmbedding`, `SparseAttention`, Whisper beam search, 
NMS, QDQ, and `GatherElements` 
([#&#8203;31643](https://redirect.github.com/microsoft/onnxruntime/pull/31643), 
[#&#8203;31994](https://redirect.github.com/microsoft/onnxruntime/pull/31994), 
[#&#8203;31995](https://redirect.github.com/microsoft/onnxruntime/pull/31995), 
[#&#8203;31996](https://redirect.github.com/microsoft/onnxruntime/pull/31996), 
[#&#8203;31998](https://redirect.github.com/microsoft/onnxruntime/pull/31998), 
[#&#8203;32014](https://redirect.github.com/microsoft/onnxruntime/pull/32014), 
[#&#8203;32029](https://redirect.github.com/microsoft/onnxruntime/pull/32029), 
[#&#8203;32030](https://redirect.github.com/microsoft/onnxruntime/pull/32030)).
   - Fixed overflow in CUDA reduction scans and Softmax offset arithmetic, and 
handled zero-sized outputs in CUDA random-generator kernels 
([#&#8203;32137](https://redirect.github.com/microsoft/onnxruntime/pull/32137), 
[#&#8203;32330](https://redirect.github.com/microsoft/onnxruntime/pull/32330), 
[#&#8203;31997](https://redirect.github.com/microsoft/onnxruntime/pull/31997)).
   - Fixed CUDA MultiHeadAttention shared-cache scratch lifetimes and kept 
`CudaAsyncBuffer` staging storage alive across CUDA graph replay 
([#&#8203;31968](https://redirect.github.com/microsoft/onnxruntime/pull/31968), 
[#&#8203;32121](https://redirect.github.com/microsoft/onnxruntime/pull/32121)).
   - Fixed WebGPU out-of-bounds subgroup-matrix loads for partial tiles, 
zero-initialized writable device-allocator buffers, and rejected foreign GPU 
handles in built-in data transfers 
([#&#8203;32364](https://redirect.github.com/microsoft/onnxruntime/pull/32364), 
[#&#8203;32063](https://redirect.github.com/microsoft/onnxruntime/pull/32063), 
[#&#8203;32317](https://redirect.github.com/microsoft/onnxruntime/pull/32317)).
   
   ##### Dependencies and Tooling
   
   - Upgraded Protobuf to 33.6 and refreshed Python documentation dependencies, 
including an ONNX security-related update 
([#&#8203;29906](https://redirect.github.com/microsoft/onnxruntime/pull/29906), 
[#&#8203;32190](https://redirect.github.com/microsoft/onnxruntime/pull/32190), 
[#&#8203;32424](https://redirect.github.com/microsoft/onnxruntime/pull/32424)).
   - Updated JavaScript dependencies including `js-yaml`, `joi`, `fast-uri`, 
and the Next.js end-to-end fixture 
([#&#8203;32397](https://redirect.github.com/microsoft/onnxruntime/pull/32397), 
[#&#8203;32486](https://redirect.github.com/microsoft/onnxruntime/pull/32486), 
[#&#8203;32488](https://redirect.github.com/microsoft/onnxruntime/pull/32488), 
[#&#8203;32505](https://redirect.github.com/microsoft/onnxruntime/pull/32505), 
[#&#8203;32508](https://redirect.github.com/microsoft/onnxruntime/pull/32508)).
   - Pinned GitHub Actions to full-length commit SHAs and strengthened 
packaging infrastructure with authenticated package feeds and NPM network 
isolation 
([#&#8203;32176](https://redirect.github.com/microsoft/onnxruntime/pull/32176), 
[#&#8203;32005](https://redirect.github.com/microsoft/onnxruntime/pull/32005), 
[#&#8203;32440](https://redirect.github.com/microsoft/onnxruntime/pull/32440)).
   
   #### New Features
   
   ##### Core APIs & Runtime
   
   - Added Go bindings for the ONNX Runtime C API 
([#&#8203;29615](https://redirect.github.com/microsoft/onnxruntime/pull/29615)).
   - Extended memory importing with host-pointer support and added access to 
preallocated outputs through `KernelContext::GetPreallocatedOutput` 
([#&#8203;29726](https://redirect.github.com/microsoft/onnxruntime/pull/29726), 
[#&#8203;32089](https://redirect.github.com/microsoft/onnxruntime/pull/32089)).
   - Added packed-attention workspace recipes and estimates, and made workspace 
input-shape handling aware of optional inputs 
([#&#8203;32283](https://redirect.github.com/microsoft/onnxruntime/pull/32283), 
[#&#8203;32321](https://redirect.github.com/microsoft/onnxruntime/pull/32321), 
[#&#8203;32312](https://redirect.github.com/microsoft/onnxruntime/pull/32312)).
   - Added DeepSeek Engram contrib operators, `EngramGate` and 
`NGramHashMapping`, and expanded kernel coverage for Qwen-3.5 operators 
([#&#8203;32268](https://redirect.github.com/microsoft/onnxruntime/pull/32268), 
[#&#8203;32106](https://redirect.github.com/microsoft/onnxruntime/pull/32106)).
   
   ##### Plugin Execution Providers
   
   - Added LoRA adapter support with plugin EP allocators, preserved custom 
allocators during EP registration, and reset plugin stream chunks before 
release 
([#&#8203;32221](https://redirect.github.com/microsoft/onnxruntime/pull/32221), 
[#&#8203;32272](https://redirect.github.com/microsoft/onnxruntime/pull/32272), 
[#&#8203;31983](https://redirect.github.com/microsoft/onnxruntime/pull/31983)).
   - Fixed CUDA plugin device discovery on WSL and improved Windows ARM64 
packaging 
([#&#8203;32517](https://redirect.github.com/microsoft/onnxruntime/pull/32517), 
[#&#8203;32355](https://redirect.github.com/microsoft/onnxruntime/pull/32355)).
   
   #### Execution Provider Updates
   
   ##### CUDA EP
   
   ##### Attention and Decoding
   
   - Added INT4 paged KV caches with per-channel scales and an `is_causal` 
attribute to `PagedAttention` 
([#&#8203;32515](https://redirect.github.com/microsoft/onnxruntime/pull/32515), 
[#&#8203;32225](https://redirect.github.com/microsoft/onnxruntime/pull/32225)).
   - Extended paged XQA with speculative decoding, query-to-KV head group size 
6, head size 256 including FP16 caches, and native block tables for 128-token 
pages 
([#&#8203;32340](https://redirect.github.com/microsoft/onnxruntime/pull/32340), 
[#&#8203;32108](https://redirect.github.com/microsoft/onnxruntime/pull/32108), 
[#&#8203;32229](https://redirect.github.com/microsoft/onnxruntime/pull/32229), 
[#&#8203;32263](https://redirect.github.com/microsoft/onnxruntime/pull/32263), 
[#&#8203;32127](https://redirect.github.com/microsoft/onnxruntime/pull/32127)).
   - Enabled split-KV for paged FlashAttention decode and improved 
PagedAttention dispatch diagnostics 
([#&#8203;32102](https://redirect.github.com/microsoft/onnxruntime/pull/32102), 
[#&#8203;32099](https://redirect.github.com/microsoft/onnxruntime/pull/32099)).
   - Added `VarlenCausalConvWithState` for continuous batching and compact 
variable-length causal-convolution state updates 
([#&#8203;32168](https://redirect.github.com/microsoft/onnxruntime/pull/32168), 
[#&#8203;32290](https://redirect.github.com/microsoft/onnxruntime/pull/32290)).
   - Added a compact `GatedDeltaNet` operator and BFloat16 support for CUDA 
GatedDeltaNet 
([#&#8203;32282](https://redirect.github.com/microsoft/onnxruntime/pull/32282), 
[#&#8203;32307](https://redirect.github.com/microsoft/onnxruntime/pull/32307)).
   
   ##### MoE and Quantized Matrix Multiplication
   
   - Added an opt-in FP8 DeepGEMM MoE decode path for supported fixed-shape 
QMoE workloads on Hopper GPUs (`ORT_QMOE_FP4_DEEPGEMM=1`, default off). This 
path is disabled on Windows 
([#&#8203;32122](https://redirect.github.com/microsoft/onnxruntime/pull/32122), 
[#&#8203;32485](https://redirect.github.com/microsoft/onnxruntime/pull/32485)).
   - Bounded QMoE workspace with configurable row tiling and FP8 
weight-dequantization scratch memory by tiling over output columns 
([#&#8203;32097](https://redirect.github.com/microsoft/onnxruntime/pull/32097), 
[#&#8203;32129](https://redirect.github.com/microsoft/onnxruntime/pull/32129)).
   - Vectorized NVFP4 weight dequantization for prefill, tuned NVFP4 GEMV 
tiling for Qwen multi-token prediction, and extended speculative-decode GEMVs 
to 64 rows 
([#&#8203;32128](https://redirect.github.com/microsoft/onnxruntime/pull/32128), 
[#&#8203;32140](https://redirect.github.com/microsoft/onnxruntime/pull/32140), 
[#&#8203;32289](https://redirect.github.com/microsoft/onnxruntime/pull/32289)).
   - Tuned FP4 and FP8 GEMV scheduling for 48-SM SM121 GPUs, including FP8 
KSplit32 scheduling, and improved FP8 GEMV residency for grids just beyond two 
blocks per SM 
([#&#8203;32408](https://redirect.github.com/microsoft/onnxruntime/pull/32408), 
[#&#8203;32409](https://redirect.github.com/microsoft/onnxruntime/pull/32409), 
[#&#8203;32433](https://redirect.github.com/microsoft/onnxruntime/pull/32433)).
   - Added an opt-in split-K GEMV path for small-N FP16 `MatMul` shapes and 
refined fpA-intB GEMV support checks 
([#&#8203;31478](https://redirect.github.com/microsoft/onnxruntime/pull/31478), 
[#&#8203;32338](https://redirect.github.com/microsoft/onnxruntime/pull/32338)).
   
   ##### Operators
   
   - Improved `TopK`, `ArgMax`, and `ArgMin` performance for wide last axes, 
and accelerated low-lane INT64 `CumSum` 
([#&#8203;32404](https://redirect.github.com/microsoft/onnxruntime/pull/32404), 
[#&#8203;32092](https://redirect.github.com/microsoft/onnxruntime/pull/32092), 
[#&#8203;32238](https://redirect.github.com/microsoft/onnxruntime/pull/32238)).
   - Added a single-memcpy `Slice` fast path for contiguous subregions and 
removed pinned-buffer use from `Split` and `Concat` fast paths 
([#&#8203;28902](https://redirect.github.com/microsoft/onnxruntime/pull/28902), 
[#&#8203;32410](https://redirect.github.com/microsoft/onnxruntime/pull/32410)).
   - Registered BF16 `ReduceMean` kernels and fixed `ScatterElements` reduction 
dispatch by element type and signed-zero handling in `Abs` 
([#&#8203;32326](https://redirect.github.com/microsoft/onnxruntime/pull/32326), 
[#&#8203;29879](https://redirect.github.com/microsoft/onnxruntime/pull/29879), 
[#&#8203;31477](https://redirect.github.com/microsoft/onnxruntime/pull/31477)).
   
   ##### WebGPU EP
   
   - Improved PagedAttention and added PagedAttention metadata, GPT-OSS 
support, and INT8 KV-cache block quantization 
([#&#8203;31727](https://redirect.github.com/microsoft/onnxruntime/pull/31727), 
[#&#8203;32277](https://redirect.github.com/microsoft/onnxruntime/pull/32277), 
[#&#8203;32284](https://redirect.github.com/microsoft/onnxruntime/pull/32284)).
   - Added INT64 `Gather` support and optimized MatMulNBits wide tiles with 
subgroup shuffle 
([#&#8203;31714](https://redirect.github.com/microsoft/onnxruntime/pull/31714), 
[#&#8203;31703](https://redirect.github.com/microsoft/onnxruntime/pull/31703)).
   - Extended convolution fusion with eight additional activations, fused 
activation handling in the im2col path, and uniform-based activation parameters 
for Conv/MatMul 
([#&#8203;32117](https://redirect.github.com/microsoft/onnxruntime/pull/32117), 
[#&#8203;32185](https://redirect.github.com/microsoft/onnxruntime/pull/32185), 
[#&#8203;32116](https://redirect.github.com/microsoft/onnxruntime/pull/32116)).
   - Reused subgroup-matrix MatMul for pointwise convolution and added 
convolution-weight prepacking for the im2col-matmul path 
([#&#8203;32304](https://redirect.github.com/microsoft/onnxruntime/pull/32304), 
[#&#8203;32420](https://redirect.github.com/microsoft/onnxruntime/pull/32420)).
   - Enabled GELU and BiasGELU fusion, added transpose-optimizer handling for 
Elu and contrib GELU variants, and enabled LayerNorm fusion to fix FP16 
inference correctness 
([#&#8203;32053](https://redirect.github.com/microsoft/onnxruntime/pull/32053), 
[#&#8203;32118](https://redirect.github.com/microsoft/onnxruntime/pull/32118), 
[#&#8203;32294](https://redirect.github.com/microsoft/onnxruntime/pull/32294)).
   - Added subgroup-size control, selected subgroup size 32 for subgroup-matrix 
MatMul/Gemm, and enabled the subgroup-matrix path in WASM builds 
([#&#8203;32056](https://redirect.github.com/microsoft/onnxruntime/pull/32056), 
[#&#8203;32306](https://redirect.github.com/microsoft/onnxruntime/pull/32306), 
[#&#8203;32269](https://redirect.github.com/microsoft/onnxruntime/pull/32269)).
   - Scaled Dawn pipeline-compilation workers with CPU count, vectorized 
`Split` when all output segments are vec4-aligned, and selected pooling paths 
based on occupancy 
([#&#8203;29820](https://redirect.github.com/microsoft/onnxruntime/pull/29820), 
[#&#8203;32251](https://redirect.github.com/microsoft/onnxruntime/pull/32251), 
[#&#8203;32313](https://redirect.github.com/microsoft/onnxruntime/pull/32313)).
   - Exposed safe graph-capture I/O in Python, added a robustness provider 
option, and enabled forwarding of `onnxruntime_perf_test -i` options to WebGPU 
([#&#8203;32074](https://redirect.github.com/microsoft/onnxruntime/pull/32074), 
[#&#8203;31971](https://redirect.github.com/microsoft/onnxruntime/pull/31971), 
[#&#8203;32316](https://redirect.github.com/microsoft/onnxruntime/pull/32316)).
   - Fixed synchronization for user-provided `GPUDevice` instances, corrected 
MatMul pipeline-cache keys and the 1D-dispatch shader fast path, and changed 
`copy_tensors` misuse to report errors instead of terminating the process 
([#&#8203;32259](https://redirect.github.com/microsoft/onnxruntime/pull/32259), 
[#&#8203;32048](https://redirect.github.com/microsoft/onnxruntime/pull/32048), 
[#&#8203;32343](https://redirect.github.com/microsoft/onnxruntime/pull/32343), 
[#&#8203;32315](https://redirect.github.com/microsoft/onnxruntime/pull/32315)).
   
   ##### WebNN EP
   
   - Added `SkipLayerNormalization` support and corrected output-rank 
validation and fallback data-type support checks 
([#&#8203;32377](https://redirect.github.com/microsoft/onnxruntime/pull/32377), 
[#&#8203;31708](https://redirect.github.com/microsoft/onnxruntime/pull/31708), 
[#&#8203;32067](https://redirect.github.com/microsoft/onnxruntime/pull/32067), 
[#&#8203;32293](https://redirect.github.com/microsoft/onnxruntime/pull/32293)).
   
   ##### TensorRT & DirectML
   
   - Fixed TensorRT shape-value handling 
([#&#8203;32415](https://redirect.github.com/microsoft/onnxruntime/pull/32415)).
   - Validated `kernel_shape` and `output_padding` lengths during DirectML 
kernel setup 
([#&#8203;31999](https://redirect.github.com/microsoft/onnxruntime/pull/31999)).
   
   #### CPU & Core Optimizations
   
   ##### MLAS and CPU Kernels
   
   - Added fused LinearAttention kernels for AVX-512, Arm64 NEON, and SVE 
([#&#8203;31674](https://redirect.github.com/microsoft/onnxruntime/pull/31674), 
[#&#8203;32178](https://redirect.github.com/microsoft/onnxruntime/pull/32178), 
[#&#8203;32356](https://redirect.github.com/microsoft/onnxruntime/pull/32356)).
   - Added AVX2 LayerNorm/RMSNorm kernels and registered BFloat16 
LayerNorm/RMSNorm kernels on the CPU EP 
([#&#8203;31973](https://redirect.github.com/microsoft/onnxruntime/pull/31973), 
[#&#8203;31974](https://redirect.github.com/microsoft/onnxruntime/pull/31974)).
   - Added Arm SVE i8mm INT8 QGEMM kernels and enabled the SBGemm fast-math 
path on Darwin Arm64 
([#&#8203;31146](https://redirect.github.com/microsoft/onnxruntime/pull/31146), 
[#&#8203;32152](https://redirect.github.com/microsoft/onnxruntime/pull/32152)).
   - Improved NCHWc convolution thread utilization, added HardSwish fusion for 
MobileNetV3 models, and introduced an AVX-512 16-wide Erf kernel and NCHWc 
reorder improvements for MobileCLIP-S0 
([#&#8203;31660](https://redirect.github.com/microsoft/onnxruntime/pull/31660), 
[#&#8203;31957](https://redirect.github.com/microsoft/onnxruntime/pull/31957), 
[#&#8203;31958](https://redirect.github.com/microsoft/onnxruntime/pull/31958)).
   - Optimized INT4 weight prepacking on CPU, rejected KleidiAI Q4 prepacking 
with dynamic scales, and fixed Arm64 SymmQgemm INT16 overflow 
([#&#8203;31690](https://redirect.github.com/microsoft/onnxruntime/pull/31690), 
[#&#8203;32068](https://redirect.github.com/microsoft/onnxruntime/pull/32068), 
[#&#8203;32057](https://redirect.github.com/microsoft/onnxruntime/pull/32057)).
   - Fixed FP16 `QuantizeLinear` rounding, prevented CPU `TensorScatter` index 
overflow, serialized `ScatterND` string updates, and widened `Compress` loop 
counters 
([#&#8203;32452](https://redirect.github.com/microsoft/onnxruntime/pull/32452), 
[#&#8203;32012](https://redirect.github.com/microsoft/onnxruntime/pull/32012), 
[#&#8203;32033](https://redirect.github.com/microsoft/onnxruntime/pull/32033), 
[#&#8203;32008](https://redirect.github.com/microsoft/onnxruntime/pull/32008)).
   - Improved edge-case handling for empty `LpNormalization` inputs, 
zero-element `BiasGelu`/`FastGelu`, extreme `Trilu` diagonals, and empty 
reduction axes 
([#&#8203;32020](https://redirect.github.com/microsoft/onnxruntime/pull/32020), 
[#&#8203;31698](https://redirect.github.com/microsoft/onnxruntime/pull/31698), 
[#&#8203;32013](https://redirect.github.com/microsoft/onnxruntime/pull/32013), 
[#&#8203;32156](https://redirect.github.com/microsoft/onnxruntime/pull/32156)).
   
   ##### Graph, Optimizer, and Runtime
   
   - Hardened graph optimizers against model-supplied indices and invalid 
fusion inputs, including MatMulNBits dequantization block sizes, GQA projection 
shapes, and `Slice` starts rank 
([#&#8203;31670](https://redirect.github.com/microsoft/onnxruntime/pull/31670), 
[#&#8203;31678](https://redirect.github.com/microsoft/onnxruntime/pull/31678), 
[#&#8203;32018](https://redirect.github.com/microsoft/onnxruntime/pull/32018), 
[#&#8203;32044](https://redirect.github.com/microsoft/onnxruntime/pull/32044)).
   - Prevented overlapping MatMulIntegerToFloat fusions, skipped 
overridable-initializer fusion, fixed FuseInitializersTransformer 
consumer-input lookup, and avoided fusing identity transposes into `Gemm` 
([#&#8203;32038](https://redirect.github.com/microsoft/onnxruntime/pull/32038), 
[#&#8203;32143](https://redirect.github.com/microsoft/onnxruntime/pull/32143), 
[#&#8203;32426](https://redirect.github.com/microsoft/onnxruntime/pull/32426), 
[#&#8203;32435](https://redirect.github.com/microsoft/onnxruntime/pull/32435)).
   - Fixed optional zero-point input handling in QDQ, empty-initializer axis 
scaling, and `NodeAttrHelper` string-default lifetimes 
([#&#8203;32051](https://redirect.github.com/microsoft/onnxruntime/pull/32051), 
[#&#8203;32138](https://redirect.github.com/microsoft/onnxruntime/pull/32138), 
[#&#8203;32019](https://redirect.github.com/microsoft/onnxruntime/pull/32019)).
   - Released external-data loaders after graph initialization, added portable 
random-access file reads to `Env`, and clarified how external-initializer paths 
interact with EP context paths 
([#&#8203;32502](https://redirect.github.com/microsoft/onnxruntime/pull/32502), 
[#&#8203;32503](https://redirect.github.com/microsoft/onnxruntime/pull/32503), 
[#&#8203;32442](https://redirect.github.com/microsoft/onnxruntime/pull/32442)).
   - Avoided redundant ONNX schema registration when static registration is 
enabled, updated cpuinfo with thread-safe deinitialization, and prevented 
telemetry crashes in shell-less containers 
([#&#8203;32353](https://redirect.github.com/microsoft/onnxruntime/pull/32353), 
[#&#8203;32300](https://redirect.github.com/microsoft/onnxruntime/pull/32300), 
[#&#8203;32226](https://redirect.github.com/microsoft/onnxruntime/pull/32226)).
   - Reduced the active-session mutex scope around ETW callback registration 
and filtered out display adapters using the Microsoft Basic Render Driver 
([#&#8203;32000](https://redirect.github.com/microsoft/onnxruntime/pull/32000), 
[#&#8203;32006](https://redirect.github.com/microsoft/onnxruntime/pull/32006)).
   
   #### Language Bindings & Web
   
   - Retained Python asynchronous-run resources and pinned C# `RunAsync` 
arguments until completion 
([#&#8203;32041](https://redirect.github.com/microsoft/onnxruntime/pull/32041), 
[#&#8203;32015](https://redirect.github.com/microsoft/onnxruntime/pull/32015)).
   - Fixed Java provider-option value cleanup, validated Rust tensor element 
types, and made Rust string-tensor output extraction safe 
([#&#8203;31828](https://redirect.github.com/microsoft/onnxruntime/pull/31828), 
[#&#8203;32035](https://redirect.github.com/microsoft/onnxruntime/pull/32035), 
[#&#8203;32045](https://redirect.github.com/microsoft/onnxruntime/pull/32045)).
   - Avoided duplicate N-API cleanup-hook registration in Node.js and added 
FP16 support to the JavaScript WebGPU `Conv3DNaive` shader 
([#&#8203;32469](https://redirect.github.com/microsoft/onnxruntime/pull/32469), 
[#&#8203;32357](https://redirect.github.com/microsoft/onnxruntime/pull/32357)).
   - Fixed WinML image-dimension overflow 
([#&#8203;32046](https://redirect.github.com/microsoft/onnxruntime/pull/32046)).
   
   #### Build, Packaging & CI
   
   - Upgraded CUTLASS to 4.7 and cuDNN Frontend to 1.27, and enabled compact 
fpA-intB kernel builds by default 
([#&#8203;32111](https://redirect.github.com/microsoft/onnxruntime/pull/32111), 
[#&#8203;32324](https://redirect.github.com/microsoft/onnxruntime/pull/32324)).
   - Fixed Windows CUDA 12.9 SM120 compilation, CUDA 13 CCCL include paths in 
plugin builds, Windows DeepGEMM build errors, and PagedAttention builds without 
FlashAttention 
([#&#8203;32114](https://redirect.github.com/microsoft/onnxruntime/pull/32114), 
[#&#8203;32392](https://redirect.github.com/microsoft/onnxruntime/pull/32392), 
[#&#8203;32485](https://redirect.github.com/microsoft/onnxruntime/pull/32485), 
[#&#8203;32327](https://redirect.github.com/microsoft/onnxruntime/pull/32327)).
   - Added D3D12 Agility SDK support for Dawn WebGPU builds while excluding 
WebGPU plugin EP builds from Agility SDK use 
([#&#8203;32253](https://redirect.github.com/microsoft/onnxruntime/pull/32253), 
[#&#8203;32380](https://redirect.github.com/microsoft/onnxruntime/pull/32380)).
   - Added BTI support to MLAS AArch64 assembly, restored runtime 
vector-extension checks on RISC-V, and disabled POWER MLAS kernels when VSX is 
unavailable 
([#&#8203;32070](https://redirect.github.com/microsoft/onnxruntime/pull/32070), 
[#&#8203;32406](https://redirect.github.com/microsoft/onnxruntime/pull/32406), 
[#&#8203;32389](https://redirect.github.com/microsoft/onnxruntime/pull/32389)).
   - Improved CUDA plugin ARM64 build parallelism and packaging tests, and 
based plugin development versions on commit timestamps 
([#&#8203;32165](https://redirect.github.com/microsoft/onnxruntime/pull/32165), 
[#&#8203;32399](https://redirect.github.com/microsoft/onnxruntime/pull/32399), 
[#&#8203;32072](https://redirect.github.com/microsoft/onnxruntime/pull/32072), 
[#&#8203;32095](https://redirect.github.com/microsoft/onnxruntime/pull/32095)).
   - Separated provider compilation from archive creation, corrected 
Python-binding delay-load linkage, and fixed Linux minimal-build dependencies 
and spurious Windows Spectre-mitigation warnings 
([#&#8203;32162](https://redirect.github.com/microsoft/onnxruntime/pull/32162), 
[#&#8203;31637](https://redirect.github.com/microsoft/onnxruntime/pull/31637), 
[#&#8203;32491](https://redirect.github.com/microsoft/onnxruntime/pull/32491), 
[#&#8203;32516](https://redirect.github.com/microsoft/onnxruntime/pull/32516)).
   - Expanded PagedAttention CUDA test coverage and head-size-256 paged XQA 
coverage, corrected GatedDeltaNet test verification, and removed a Hugging Face 
download dependency from a dynamic-quantization test 
([#&#8203;31687](https://redirect.github.com/microsoft/onnxruntime/pull/31687), 
[#&#8203;32262](https://redirect.github.com/microsoft/onnxruntime/pull/32262), 
[#&#8203;32329](https://redirect.github.com/microsoft/onnxruntime/pull/32329), 
[#&#8203;32443](https://redirect.github.com/microsoft/onnxruntime/pull/32443)).
   - Added WGSL template tests to CI and enabled WebGPU CI on WebGPU plugin EP 
release branches 
([#&#8203;32214](https://redirect.github.com/microsoft/onnxruntime/pull/32214), 
[#&#8203;32090](https://redirect.github.com/microsoft/onnxruntime/pull/32090)).
   
   #### Contributors
   
   Thanks to our 57 human contributors for this release!
   
   [@&#8203;4n4ny4](https://redirect.github.com/4n4ny4), 
[@&#8203;apsonawane](https://redirect.github.com/apsonawane), 
[@&#8203;arnej27959](https://redirect.github.com/arnej27959), 
[@&#8203;baijumeswani](https://redirect.github.com/baijumeswani), 
[@&#8203;bmehta001](https://redirect.github.com/bmehta001), 
[@&#8203;chilo-ms](https://redirect.github.com/chilo-ms), 
[@&#8203;crvineeth97](https://redirect.github.com/crvineeth97), 
[@&#8203;daijh](https://redirect.github.com/daijh), 
[@&#8203;danfiedler-msft](https://redirect.github.com/danfiedler-msft), 
[@&#8203;danielsongmicrosoft](https://redirect.github.com/danielsongmicrosoft), 
[@&#8203;dannyota](https://redirect.github.com/dannyota), 
[@&#8203;DKAIN-py](https://redirect.github.com/DKAIN-py), 
[@&#8203;edgchen1](https://redirect.github.com/edgchen1), 
[@&#8203;ericcraw](https://redirect.github.com/ericcraw), 
[@&#8203;eserscor](https://redirect.github.com/eserscor), 
[@&#8203;fanchenkong1](https://redirect.github.com/fanchenkong1), [@&#8203;
 hanbitmyths](https://redirect.github.com/hanbitmyths), 
[@&#8203;hariharans29](https://redirect.github.com/hariharans29), 
[@&#8203;hdharpure9922](https://redirect.github.com/hdharpure9922), 
[@&#8203;Honry](https://redirect.github.com/Honry), 
[@&#8203;jambayk](https://redirect.github.com/jambayk), 
[@&#8203;javier-intel](https://redirect.github.com/javier-intel), 
[@&#8203;jchen10](https://redirect.github.com/jchen10), 
[@&#8203;jiafatom](https://redirect.github.com/jiafatom), 
[@&#8203;jnagi-intel](https://redirect.github.com/jnagi-intel), 
[@&#8203;justinchuby](https://redirect.github.com/justinchuby), 
[@&#8203;kadyrbekovhamit-cyber](https://redirect.github.com/kadyrbekovhamit-cyber),
 [@&#8203;kunal-vaishnavi](https://redirect.github.com/kunal-vaishnavi), 
[@&#8203;Lapis0x0](https://redirect.github.com/Lapis0x0), 
[@&#8203;LOGO127](https://redirect.github.com/LOGO127), 
[@&#8203;Manogna-Sree](https://redirect.github.com/Manogna-Sree), 
[@&#8203;martin-klacer-arm](https://redirect.github.com/
 martin-klacer-arm), [@&#8203;mei1127](https://redirect.github.com/mei1127), 
[@&#8203;miaobin](https://redirect.github.com/miaobin), 
[@&#8203;mirounga](https://redirect.github.com/mirounga), 
[@&#8203;miyanyan](https://redirect.github.com/miyanyan), 
[@&#8203;MohamedElashri](https://redirect.github.com/MohamedElashri), 
[@&#8203;mustjab](https://redirect.github.com/mustjab), 
[@&#8203;Nikhi00718](https://redirect.github.com/Nikhi00718), 
[@&#8203;Noperi0r](https://redirect.github.com/Noperi0r), 
[@&#8203;Novestars](https://redirect.github.com/Novestars), 
[@&#8203;pkubaj](https://redirect.github.com/pkubaj), 
[@&#8203;preetha-intel](https://redirect.github.com/preetha-intel), 
[@&#8203;qjia7](https://redirect.github.com/qjia7), 
[@&#8203;rvandermeulen](https://redirect.github.com/rvandermeulen), 
[@&#8203;sanaa-hamel-microsoft](https://redirect.github.com/sanaa-hamel-microsoft),
 [@&#8203;skottmckay](https://redirect.github.com/skottmckay), 
[@&#8203;sushraja-msft](https://redirect.github.com/sus
 hraja-msft), [@&#8203;swetha097](https://redirect.github.com/swetha097), 
[@&#8203;sylvesterkaczmarek](https://redirect.github.com/sylvesterkaczmarek), 
[@&#8203;tianleiwu](https://redirect.github.com/tianleiwu), 
[@&#8203;titaiwangms](https://redirect.github.com/titaiwangms), 
[@&#8203;toothache](https://redirect.github.com/toothache), 
[@&#8203;xadupre](https://redirect.github.com/xadupre), 
[@&#8203;xhcao](https://redirect.github.com/xhcao), 
[@&#8203;xiaofeihan1](https://redirect.github.com/xiaofeihan1), 
[@&#8203;Zestion](https://redirect.github.com/Zestion)
   
   **Full Changelog:** 
[rel-1.29.1...rel-1.30.0](https://redirect.github.com/microsoft/onnxruntime/compare/rel-1.29.1...rel-1.30.0)
   
   *Release highlights were prepared with AI assistance.*
   
   </details>
   
   <details>
   <summary>connect2id/nimbus-jose-jwt (com.nimbusds:nimbus-jose-jwt)</summary>
   
   ### 
[`v10.10`](https://bitbucket.org/connect2id/nimbus-jose-jwt/branches/compare/10.10%0D10.9.1)
   
   [Compare 
Source](https://bitbucket.org/connect2id/nimbus-jose-jwt/branches/compare/10.10%0D10.9.1)
   
   </details>
   
   <details>
   <summary>navikt/mock-oauth2-server 
(no.nav.security:mock-oauth2-server)</summary>
   
   ### 
[`v6.0.3`](https://redirect.github.com/navikt/mock-oauth2-server/releases/tag/6.0.3)
   
   [Compare 
Source](https://redirect.github.com/navikt/mock-oauth2-server/compare/6.0.2...6.0.3)
   
   #### What's Changed
   
   #### 🧰 Maintenance
   
   - fix(deps): make vulnerable transitives directly managed 
([#&#8203;1015](https://redirect.github.com/navikt/mock-oauth2-server/issues/1015))
 [@&#8203;ybelMekk](https://redirect.github.com/ybelMekk)
   - fix: migrate from Jackson 2 to Jackson 3 in example applications 
([#&#8203;1014](https://redirect.github.com/navikt/mock-oauth2-server/issues/1014))
 [@&#8203;ybelMekk](https://redirect.github.com/ybelMekk)
   - Fix Dependabot Jackson security update resolution 
([#&#8203;1012](https://redirect.github.com/navikt/mock-oauth2-server/issues/1012))
 [@&#8203;ybelMekk](https://redirect.github.com/ybelMekk)
   
   #### ⬆️ Dependency upgrades
   
   - chore(deps): bump com.github.ben-manes.versions from 0.54.0 to 0.64.0 
([#&#8203;1037](https://redirect.github.com/navikt/mock-oauth2-server/issues/1037))
 @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
   - chore(deps): bump kotestVersion from 6.2.4 to 6.2.5 
([#&#8203;1036](https://redirect.github.com/navikt/mock-oauth2-server/issues/1036))
 @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
   - chore(deps): bump the github-actions group across 1 directory with 2 
updates 
([#&#8203;1039](https://redirect.github.com/navikt/mock-oauth2-server/issues/1039))
 @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
   - chore(deps): bump io.projectreactor:reactor-test from 3.8.6 to 3.8.7 
([#&#8203;1034](https://redirect.github.com/navikt/mock-oauth2-server/issues/1034))
 @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
   - chore(deps): bump org.apache.httpcomponents.client5:httpclient5 from 5.6.3 
to 5.6.4 
([#&#8203;1033](https://redirect.github.com/navikt/mock-oauth2-server/issues/1033))
 @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
   - chore(deps): bump org.freemarker:freemarker from 2.3.34 to 2.3.35 
([#&#8203;1035](https://redirect.github.com/navikt/mock-oauth2-server/issues/1035))
 @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
   - chore(deps): bump org.apache.logging.log4j:log4j-api from 2.25.5 to 2.26.1 
([#&#8203;1032](https://redirect.github.com/navikt/mock-oauth2-server/issues/1032))
 @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
   - chore(deps): bump kotestVersion from 6.2.3 to 6.2.4 
([#&#8203;1031](https://redirect.github.com/navikt/mock-oauth2-server/issues/1031))
 @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
   - chore(deps): bump com.squareup.okhttp3:mockwebserver from 5.4.0 to 5.5.0 
([#&#8203;1026](https://redirect.github.com/navikt/mock-oauth2-server/issues/1026))
 @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
   - chore(deps): bump gradle-wrapper from 9.6.1 to 9.7.1 
([#&#8203;1028](https://redirect.github.com/navikt/mock-oauth2-server/issues/1028))
 @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
   - chore(deps): bump org.jmailen.kotlinter from 5.6.0 to 5.7.0 
([#&#8203;1027](https://redirect.github.com/navikt/mock-oauth2-server/issues/1027))
 @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
   - chore(deps): bump org.jsoup:jsoup from 1.23.1 to 1.23.2 
([#&#8203;1025](https://redirect.github.com/navikt/mock-oauth2-server/issues/1025))
 @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
   - chore(deps): bump jacksonVersion from 3.2.1 to 3.2.2 
([#&#8203;1024](https://redirect.github.com/navikt/mock-oauth2-server/issues/1024))
 @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
   - chore(deps): bump the github-actions group across 1 directory with 2 
updates 
([#&#8203;1029](https://redirect.github.com/navikt/mock-oauth2-server/issues/1029))
 @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
   - chore(deps): bump ch.qos.logback:logback-classic from 1.6.0 to 1.6.3 
([#&#8203;1020](https://redirect.github.com/navikt/mock-oauth2-server/issues/1020))
 @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
   - chore(deps): bump com.fasterxml.woodstox:woodstox-core from 7.2.1 to 7.2.2 
([#&#8203;1019](https://redirect.github.com/navikt/mock-oauth2-server/issues/1019))
 @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
   - chore(deps): bump jackson2TestVersion from 2.22.1 to 2.22.2 
([#&#8203;1018](https://redirect.github.com/navikt/mock-oauth2-server/issues/1018))
 @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
   - chore(deps): bump junitJupiterVersion from 6.1.2 to 6.1.3 
([#&#8203;1017](https://redirect.github.com/navikt/mock-oauth2-server/issues/1017))
 @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
   - chore(deps): bump springBootVersion from 4.1.0 to 4.1.1 
([#&#8203;1016](https://redirect.github.com/navikt/mock-oauth2-server/issues/1016))
 @&#8203;[dependabot\[bot\]](https://redirect.github.com/apps/dependabot)
   
   </details>
   
   <details>
   <summary>mockito/mockito (org.mockito:mockito-subclass)</summary>
   
   ### 
[`v5.24.0`](https://redirect.github.com/mockito/mockito/releases/tag/v5.24.0)
   
   <sup><sup>*Changelog generated by [Shipkit Changelog Gradle 
Plugin](https://redirect.github.com/shipkit/shipkit-changelog)*</sup></sup>
   
   ##### 5.24.0
   
   - 2026-09-23 - [27 
commit(s)](https://redirect.github.com/mockito/mockito/compare/v5.23.0...v5.24.0)
 by Andrei Solntsev, DragonFSKY, Hünkar Can Tunç, Joshua Selbo, M. Minot, 
Markus Gaisbauer, Mirko Alicastro, Vinod Kumar M ( codingkiddo ), 
dependabot\[bot]
   - Fix Mockito docs for -javaagent flag with Gradle 
[(#&#8203;3866)](https://redirect.github.com/mockito/mockito/pull/3866)
   - Kotlin example for adding Mockito as an agent is incorrect 
[(#&#8203;3864)](https://redirect.github.com/mockito/mockito/issues/3864)
   - Bump graalvm/setup-graalvm from 1.6.3 to 1.6.6 
[(#&#8203;3862)](https://redirect.github.com/mockito/mockito/pull/3862)
   - Bump gradle/actions from 6.2.0 to 6.3.0 
[(#&#8203;3852)](https://redirect.github.com/mockito/mockito/pull/3852)
   - Bump gradle/actions from 5 to 6.2.0 
[(#&#8203;3851)](https://redirect.github.com/mockito/mockito/pull/3851)
   - Preserve method parameters when clearing inline mocks 
[(#&#8203;3847)](https://redirect.github.com/mockito/mockito/pull/3847)
   - Bump graalvm/setup-graalvm from 1.6.0 to 1.6.3 
[(#&#8203;3845)](https://redirect.github.com/mockito/mockito/pull/3845)
   - Print object fields via reflection when `toString()` is not implemented 
[(#&#8203;3844)](https://redirect.github.com/mockito/mockito/pull/3844)
   - Migrate extensions-tests to JUnit Jupiter 
[(#&#8203;3840)](https://redirect.github.com/mockito/mockito/pull/3840)
   - Bump graalvm/setup-graalvm from 1.5.6 to 1.6.0 
[(#&#8203;3839)](https://redirect.github.com/mockito/mockito/pull/3839)
   - docs(when-verify): fixes to explanations about redundancy 
[(#&#8203;3838)](https://redirect.github.com/mockito/mockito/pull/3838)
   - Confusing inconsistency in example method calls in “stubbing and verifying 
is redundant” note of “when” and “verify” Javadoc 
[(#&#8203;3837)](https://redirect.github.com/mockito/mockito/issues/3837)
   - Bump actions/checkout from 6 to 7 
[(#&#8203;3836)](https://redirect.github.com/mockito/mockito/pull/3836)
   - Fixes 
[#&#8203;2740](https://redirect.github.com/mockito/mockito/issues/2740) : Add 
mockMaker option to `@Spy` annotation 
[(#&#8203;3835)](https://redirect.github.com/mockito/mockito/pull/3835)
   - Bump graalvm/setup-graalvm from 1.5.5 to 1.5.6 
[(#&#8203;3834)](https://redirect.github.com/mockito/mockito/pull/3834)
   - Bump graalvm/setup-graalvm from 1.5.4 to 1.5.5 
[(#&#8203;3833)](https://redirect.github.com/mockito/mockito/pull/3833)
   - Bump codecov/codecov-action from 6 to 7 
[(#&#8203;3831)](https://redirect.github.com/mockito/mockito/pull/3831)
   - Bump graalvm/setup-graalvm from 1.4.5 to 1.5.4 
[(#&#8203;3830)](https://redirect.github.com/mockito/mockito/pull/3830)
   - Fix clearInlineMocks not de-registering singleton mocks 
[(#&#8203;3829)](https://redirect.github.com/mockito/mockito/pull/3829)
   - Fix NotAMockException when using mockSingleton with MockitoJUnit 
[(#&#8203;3827)](https://redirect.github.com/mockito/mockito/pull/3827)
   - NotAMockException when using mockSingleton with MockitoSession or 
MockitoJUnit 
[(#&#8203;3826)](https://redirect.github.com/mockito/mockito/issues/3826)
   - Improve Gradle agent docs for configuration cache 
[(#&#8203;3823)](https://redirect.github.com/mockito/mockito/pull/3823)
   - Gradle documentation for setting up instrumentation with Gradle 
configuration cache 
[(#&#8203;3822)](https://redirect.github.com/mockito/mockito/issues/3822)
   - Fixes 
[#&#8203;3818](https://redirect.github.com/mockito/mockito/issues/3818) : Fix 
data race in InvocationContainerImpl.invocationForStubbing 
[(#&#8203;3819)](https://redirect.github.com/mockito/mockito/pull/3819)
   - Data race on invocationForPotentialStubbing 
[(#&#8203;3818)](https://redirect.github.com/mockito/mockito/issues/3818)
   - Fixes 
[#&#8203;3814](https://redirect.github.com/mockito/mockito/issues/3814) : 
implement package-level clinit suppression 
[(#&#8203;3815)](https://redirect.github.com/mockito/mockito/pull/3815)
   - Package-level clinit suppression 
[(#&#8203;3814)](https://redirect.github.com/mockito/mockito/issues/3814)
   - Upgrade Android Gradle Plugin to 8.13.2 
[(#&#8203;3812)](https://redirect.github.com/mockito/mockito/pull/3812)
   - Replaces raw generic types with type parameters 
[(#&#8203;3806)](https://redirect.github.com/mockito/mockito/pull/3806)
   - Fixes 
[#&#8203;2398](https://redirect.github.com/mockito/mockito/issues/2398) : 
Implement global suppress static initialization leveraging java agent 
[(#&#8203;3801)](https://redirect.github.com/mockito/mockito/pull/3801)
   - Bump codecov/codecov-action from 5 to 6 
[(#&#8203;3800)](https://redirect.github.com/mockito/mockito/pull/3800)
   - Fix non-deterministic AssertionError when using MockMakers.SUBCLASS 
([#&#8203;3406](https://redirect.github.com/mockito/mockito/issues/3406), 
[#&#8203;2823](https://redirect.github.com/mockito/mockito/issues/2823)) 
[(#&#8203;3795)](https://redirect.github.com/mockito/mockito/pull/3795)
   - Fixes 
[#&#8203;3536](https://redirect.github.com/mockito/mockito/issues/3536) : 
Implement SpyStatic API 
[(#&#8203;3794)](https://redirect.github.com/mockito/mockito/pull/3794)
   - The class's MethodParameters are removed after clearAllCaches is invoked 
[(#&#8203;3763)](https://redirect.github.com/mockito/mockito/issues/3763)
   - \[FeatureRequest / Idea] Create Mockito.spyStatic 
[(#&#8203;3536)](https://redirect.github.com/mockito/mockito/issues/3536)
   - Add option to specify mockmaker for `@Spy` 
[(#&#8203;2740)](https://redirect.github.com/mockito/mockito/issues/2740)
   - How can I suppress static initializer? 
[(#&#8203;2398)](https://redirect.github.com/mockito/mockito/issues/2398)
   
   </details>
   
   <details>
   <summary>langchain4j/langchain4j (dev.langchain4j:langchain4j-bom)</summary>
   
   ### 
[`v1.20.1`](https://redirect.github.com/langchain4j/langchain4j/releases/tag/1.20.1):
 and 1.20.1-beta30
   
   [Compare 
Source](https://redirect.github.com/langchain4j/langchain4j/compare/1.20.0...1.20.1)
   
   #### What's Changed
   
   - Allow methods annotated with 
[@&#8203;McpClientSupplier](https://redirect.github.com/McpClientSupplier) to 
also have supplier parameters by 
[@&#8203;mariofusco](https://redirect.github.com/mariofusco) in 
[#&#8203;6505](https://redirect.github.com/langchain4j/langchain4j/pull/6505)
   
   **Full Changelog**: 
<https://github.com/langchain4j/langchain4j/compare/1.20.0...1.20.1>
   
   ### 
[`v1.20.0`](https://redirect.github.com/langchain4j/langchain4j/releases/tag/1.20.0):
 and 1.20.0-beta30
   
   [Compare 
Source](https://redirect.github.com/langchain4j/langchain4j/compare/1.19.3...1.20.0)
   
   #### Notable Changes
   
   ##### Non-blocking / reactive support by 
[@&#8203;dliubarskyi](https://redirect.github.com/dliubarskyi) in 
[#&#8203;5527](https://redirect.github.com/langchain4j/langchain4j/pull/5527)
   
   An AI Service method used to hold its thread for the whole interaction - the 
model call, tool execution, memory I/O and guardrails. It can now return 
`CompletableFuture<T>`/`CompletionStage<T>` for a single response, or 
`Flow.Publisher<AiServiceStreamingEvent>`/`Flow.Publisher<String>` for 
streaming, and the interaction runs without blocking a thread. You choose the 
mode by the method's return type; nothing else about the interface changes.
   
   Non-blocking goes all the way down, because a blocking gap at any layer 
re-blocks the whole call: tool calling (sync and `CompletableFuture` tools, 
sequential or concurrent), chat memory, guardrails, and the full retrieval 
graph including `EmbeddingModel`, `EmbeddingStore`, `ScoringModel` and 
`WebSearchEngine`.
   
   The work is additive and marked `@Experimental`: the synchronous and 
`TokenStream` APIs are untouched. A few defaults deliberately differ on the 
async path - multiple tool calls run concurrently, a tool *execution* error 
fails the invocation rather than being sent to the LLM, and a tool 
*argument-parse* error is sent to the LLM rather than failing. See 
[Non-blocking and 
Reactive](https://docs.langchain4j.dev/tutorials/non-blocking).
   
   ##### Jackson 3 opt-in support by 
[@&#8203;dliubarskyi](https://redirect.github.com/dliubarskyi) in 
[#&#8203;6184](https://redirect.github.com/langchain4j/langchain4j/pull/6184)
   
   Add `langchain4j-jackson3` to your classpath and LangChain4j's JSON runs on 
Jackson 3. There is nothing to configure and no API to call, and removing the 
dependency puts everything back on Jackson 2. Nothing changes for anyone who 
does not opt in.
   
   With the opt-in in place, Jackson 2 can be excluded outright from most of 
the dependency graph; the modules that still need it are listed in the 
documentation. The one deliberate behaviour change is that a JSON failure 
surfaces as `JsonReadException` or `JsonWriteException` (both 
`LangChain4jException`) instead of a `RuntimeException` wrapping Jackson's own 
- catching `RuntimeException` works either way. See [Using Jackson 
3](https://docs.langchain4j.dev/tutorials/jackson-3).
   
   #### Other Changes
   
   - fix: ignore stale and duplicate tool names when restoring tools found 
earlier by 
[@&#8203;farzad-sedaghatbin](https://redirect.github.com/farzad-sedaghatbin) in 
[#&#8203;6080](https://redirect.github.com/langchain4j/langchain4j/pull/6080)
   - fix: consistent `addAll`/`removeAll` input handling across all embedding 
stores by 
[@&#8203;subhashpolisetti](https://redirect.github.com/subhashpolisetti) in 
[#&#8203;6069](https://redirect.github.com/langchain4j/langchain4j/pull/6069)
   - Fix Milvus vector lookup for IDs containing special characters by 
[@&#8203;subhashpolisetti](https://redirect.github.com/subhashpolisetti) in 
[#&#8203;6088](https://redirect.github.com/langchain4j/langchain4j/pull/6088)
   - Raise MCP JSON-RPC errors from list operations instead of 
NullPointerException by 
[@&#8203;martin-zatopek-cloverdx](https://redirect.github.com/martin-zatopek-cloverdx)
 in 
[#&#8203;6072](https://redirect.github.com/langchain4j/langchain4j/pull/6072)
   - Avoid duplicate declaration of jsoup version by 
[@&#8203;jmartisk](https://redirect.github.com/jmartisk) in 
[#&#8203;6092](https://redirect.github.com/langchain4j/langchain4j/pull/6092)
   - fix: Honor custom filter mapper in Azure Cosmos DB NoSQL token credential 
constructor by [@&#8203;thswlsqls](https://redirect.github.com/thswlsqls) in 
[#&#8203;5922](https://redirect.github.com/langchain4j/langchain4j/pull/5922)
   - fix: Add missing WHERE clause to filtered vector search in Azure Cosmos DB 
NoSQL store by [@&#8203;thswlsqls](https://redirect.github.com/thswlsqls) in 
[#&#8203;5921](https://redirect.github.com/langchain4j/langchain4j/pull/5921)
   - fix: Use the name of the provided Azure AI Search index when index 
creation is disabled by 
[@&#8203;thswlsqls](https://redirect.github.com/thswlsqls) in 
[#&#8203;5901](https://redirect.github.com/langchain4j/langchain4j/pull/5901)
   - fix: Escape single quotes in Azure AI Search metadata filter expressions 
by [@&#8203;thswlsqls](https://redirect.github.com/thswlsqls) in 
[#&#8203;5900](https://redirect.github.com/langchain4j/langchain4j/pull/5900)
   - Support customHeaders in OpenAI Responses API models by 
[@&#8203;dliubarskyi](https://redirect.github.com/dliubarskyi) in 
[#&#8203;6101](https://redirect.github.com/langchain4j/langchain4j/pull/6101)
   - Fix invalid Chroma relevance scores for collections that do not use cosine 
distance by 
[@&#8203;subhashpolisetti](https://redirect.github.com/subhashpolisetti) in 
[#&#8203;6077](https://redirect.github.com/langchain4j/langchain4j/pull/6077)
   - fix: split text without detectable sentences instead of failing or dropp
   
   > ✂ **Note**
   > 
   > PR body was truncated to here.
   
   
   </details>
   
   ---
   
   ### Configuration
   
   📅 **Schedule**: (UTC)
   
   - Branch creation
     - "before 9am on the first day of the month"
   - Automerge
     - At any time (no schedule defined)
   
   🚦 **Automerge**: Disabled by config. Please merge this manually once you are 
satisfied.
   
   ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry 
checkbox.
   
   👻 **Immortal**: This PR will be recreated if closed unmerged. Get [config 
help](https://redirect.github.com/renovatebot/renovate/discussions) if that's 
undesired.
   
   ---
   
    - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this 
box
   
   ---
   
   This PR has been generated by [Renovate 
Bot](https://redirect.github.com/solrbot/renovate-github-action)
   
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4xNzAuMTgiLCJ1cGRhdGVkSW5WZXIiOiI0My4xNzAuMTgiLCJ0YXJnZXRCcmFuY2giOiJtYWluIiwibGFiZWxzIjpbImV4ZW1wdC1zdGFsZSJdfQ==-->
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to