dependabot[bot] opened a new pull request, #1299:
URL: https://github.com/apache/axis-axis2-java-core/pull/1299

   Bumps the production-dependencies group with 10 updates:
   
   | Package | From | To |
   | --- | --- | --- |
   | [org.apache:apache](https://github.com/apache/maven-apache-parent) | `39` 
| `40` |
   | org.apache.neethi:neethi | `3.2.3` | `3.2.4` |
   | 
[org.apache.httpcomponents.core5:httpcore5](https://github.com/apache/httpcomponents-core)
 | `5.4.3` | `5.4.4` |
   | 
[org.apache.httpcomponents.core5:httpcore5-h2](https://github.com/apache/httpcomponents-core)
 | `5.4.3` | `5.4.4` |
   | [org.xmlunit:xmlunit-legacy](https://github.com/xmlunit/xmlunit) | 
`2.13.0` | `2.14.0` |
   | org.apache.xmlbeans:xmlbeans | `5.4.0` | `5.4.1` |
   | [net.bytebuddy:byte-buddy](https://github.com/raphw/byte-buddy) | 
`1.18.13` | `1.18.14` |
   | [org.apache.groovy:groovy](https://github.com/apache/groovy) | `5.1.2` | 
`6.0.0` |
   | [org.apache.groovy:groovy-ant](https://github.com/apache/groovy) | `5.1.2` 
| `6.0.0` |
   | [org.apache.groovy:groovy-xml](https://github.com/apache/groovy) | `5.1.2` 
| `6.0.0` |
   
   Updates `org.apache:apache` from 39 to 40
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/apache/maven-apache-parent/releases";>org.apache:apache's
 releases</a>.</em></p>
   <blockquote>
   <h2>40</h2>
   <!-- raw HTML omitted -->
   <h2>:boom: Breaking changes</h2>
   <ul>
   <li>Replace nicoulaj checksum plugin with maveniverse checksum plugin (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/599";>#599</a>)
 <a 
href="https://github.com/slawekjaranowski";><code>@​slawekjaranowski</code></a></li>
   <li><a 
href="https://redirect.github.com/apache/maven-apache-parent/issues/586";>#586</a>:
 Use RAT0.18 and remove commons-lang3 configuration for JDK25 (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/587";>#587</a>)
 <a href="https://github.com/ottlinger";><code>@​ottlinger</code></a></li>
   <li>Property <code>version.maven-surefire</code> was removed in <a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/588";>apache/maven-apache-parent#588</a>,
 should be replaced by <code>version.maven-surefire-plugin</code>, 
<code>version.maven-failsafe-plugin</code> or 
<code>version.maven-surefire-report-plugin</code></li>
   </ul>
   <h2>🚀 New features and improvements</h2>
   <ul>
   <li>Fix several version property issues (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/588";>#588</a>)
 <a href="https://github.com/ctubbsii";><code>@​ctubbsii</code></a></li>
   </ul>
   <h2>📝 Documentation updates</h2>
   <ul>
   <li>Update documentation for push-to-atr profile (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/613";>#613</a>)
 <a 
href="https://github.com/slawekjaranowski";><code>@​slawekjaranowski</code></a></li>
   <li>Restore the common wording on the download page (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/596";>#596</a>)
 <a href="https://github.com/slachiewicz";><code>@​slachiewicz</code></a></li>
   </ul>
   <h2>👻 Maintenance</h2>
   <ul>
   <li>Add local maven configuration for ATR project name override (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/614";>#614</a>)
 <a 
href="https://github.com/slawekjaranowski";><code>@​slawekjaranowski</code></a></li>
   <li>Remove custom name-template for release-drafter (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/604";>#604</a>)
 <a 
href="https://github.com/slawekjaranowski";><code>@​slawekjaranowski</code></a></li>
   <li>Port the site documentation from APT to Markdown (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/595";>#595</a>)
 <a href="https://github.com/slachiewicz";><code>@​slachiewicz</code></a></li>
   </ul>
   <h2>📦 Dependency updates</h2>
   <ul>
   <li>Bump org.apache.maven.plugins:maven-deploy-plugin from 3.1.4 to 3.2.0 
(<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/612";>#612</a>)
 @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
   <li>Bump org.apache.maven.plugins:maven-install-plugin from 3.1.4 to 3.2.0 
(<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/611";>#611</a>)
 @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
   <li>Bump org.apache.maven.plugins:maven-plugin-tools from 3.15.2 to 3.16.0 
(<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/610";>#610</a>)
 <a 
href="https://github.com/slawekjaranowski";><code>@​slawekjaranowski</code></a></li>
   <li>Bump surefire-plugin, failsafe-plugin, surefire-report-plugin from 3.5.6 
to 3.6.0 (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/605";>#605</a>)
 <a 
href="https://github.com/slawekjaranowski";><code>@​slawekjaranowski</code></a></li>
   <li>Bump org.apache.tooling:atr-maven-plugin from 1.0.0-alpha-1 to 
1.0.0-beta-1 (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/598";>#598</a>)
 @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
   <li>Bump org.apache.maven.plugins:maven-compiler-plugin from 3.15.0 to 
3.16.0 (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/600";>#600</a>)
 @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
   <li><a 
href="https://redirect.github.com/apache/maven-apache-parent/issues/586";>#586</a>:
 Use RAT0.18 and remove commons-lang3 configuration for JDK25 (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/587";>#587</a>)
 <a href="https://github.com/ottlinger";><code>@​ottlinger</code></a></li>
   <li>Bump org.apache.maven.plugins:maven-jar-plugin from 3.5.0 to 3.5.1 (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/594";>#594</a>)
 @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
   <li>Bump 
apache/maven-gh-actions-shared/.github/workflows/release-drafter.yml from 4 to 
5 (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/591";>#591</a>)
 @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
   <li>Bump apache/maven-gh-actions-shared/.github/workflows/pr-automation.yml 
from 4 to 5 (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/593";>#593</a>)
 @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
   <li>Bump apache/maven-gh-actions-shared/.github/workflows/stale.yml from 4 
to 5 (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/592";>#592</a>)
 @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
   <li>Bump apache/maven-gh-actions-shared/.github/workflows/maven-verify.yml 
from 4 to 5 (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/590";>#590</a>)
 @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
   <li>Bump org.apache.maven.plugins:maven-help-plugin from 3.5.1 to 3.5.2 (<a 
href="https://redirect.github.com/apache/maven-apache-parent/pull/589";>#589</a>)
 @<a href="https://github.com/apps/dependabot";>dependabot[bot]</a></li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li>See full diff in <a 
href="https://github.com/apache/maven-apache-parent/commits";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `org.apache.neethi:neethi` from 3.2.3 to 3.2.4
   
   Updates `org.apache.httpcomponents.core5:httpcore5` from 5.4.3 to 5.4.4
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/apache/httpcomponents-core/blob/rel/v5.4.4/RELEASE_NOTES.txt";>org.apache.httpcomponents.core5:httpcore5's
 changelog</a>.</em></p>
   <blockquote>
   <h2>Release 5.4.4</h2>
   <p>This maintenance release optimizes HTTP/1.1 message buffer configuration 
and corrects
   the handling of asynchronous entity producer state resets after interrupted 
writes.</p>
   <h2>Change Log</h2>
   <ul>
   <li>
   <p>HTTPCORE-800: Fixed hexadecimal encoding of control characters in 
HttpException messages.
   Contributed by Arturo Bernal <!-- raw HTML omitted --></p>
   </li>
   <li>
   <p>HTTPCORE-799: Corrected the handling of asynchronous entity producer 
state resets after interrupted writes.
   Contributed by Matthias Kurz &lt;m.kurz at irregular.at&gt;</p>
   </li>
   <li>
   <p>Fixed URIBuilder encoding policy documentation and null reset behavior.
   Contributed by Praful Gupta <!-- raw HTML omitted --></p>
   </li>
   <li>
   <p>Increased the default HTTP/1.1 buffer size to 32 KiB.
   Contributed by Arturo Bernal <!-- raw HTML omitted --></p>
   </li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/apache/httpcomponents-core/commit/d40892ea9a52509a86960bb813f8241a134d2e0c";><code>d40892e</code></a>
 HttpCore 5.4.4 release</li>
   <li><a 
href="https://github.com/apache/httpcomponents-core/commit/698b2b66f8a7539c167f4b22eb7dfa2424e78acd";><code>698b2b6</code></a>
 Updated release notes for HttpCore 5.4.4 release</li>
   <li><a 
href="https://github.com/apache/httpcomponents-core/commit/8ada43a945066783288ffe0bc3fbc0a201c8bb43";><code>8ada43a</code></a>
 HTTPCORE-800: Fix hexadecimal encoding of control characters</li>
   <li><a 
href="https://github.com/apache/httpcomponents-core/commit/9cb751ee37589fd07b13563095959ede3ebac6be";><code>9cb751e</code></a>
 HTTPCORE-799: Reset async entity producer state after interrupted writes</li>
   <li><a 
href="https://github.com/apache/httpcomponents-core/commit/e871fa077ff112f3f26fdd881b02ac5ac9f1b07e";><code>e871fa0</code></a>
 Fix URIBuilder encoding policy documentation and null reset</li>
   <li><a 
href="https://github.com/apache/httpcomponents-core/commit/34542fccfeb19ec119db33e8af52c672bf0844ac";><code>34542fc</code></a>
 Increase default HTTP/1.1 buffer size to 32 KiB</li>
   <li><a 
href="https://github.com/apache/httpcomponents-core/commit/a79f87e8cad855a112240c3e393f320d0a1257b0";><code>a79f87e</code></a>
 Add details to solve compatibility issues.</li>
   <li><a 
href="https://github.com/apache/httpcomponents-core/commit/93421d33a0cce00a57dad4b3c3a9624cf994ef06";><code>93421d3</code></a>
 Upgraded HttpCore version to 5.4.4-SNAPSHOT</li>
   <li>See full diff in <a 
href="https://github.com/apache/httpcomponents-core/compare/rel/v5.4.3...rel/v5.4.4";>compare
 view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `org.apache.httpcomponents.core5:httpcore5-h2` from 5.4.3 to 5.4.4
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/apache/httpcomponents-core/blob/rel/v5.4.4/RELEASE_NOTES.txt";>org.apache.httpcomponents.core5:httpcore5-h2's
 changelog</a>.</em></p>
   <blockquote>
   <h2>Release 5.4.4</h2>
   <p>This maintenance release optimizes HTTP/1.1 message buffer configuration 
and corrects
   the handling of asynchronous entity producer state resets after interrupted 
writes.</p>
   <h2>Change Log</h2>
   <ul>
   <li>
   <p>HTTPCORE-800: Fixed hexadecimal encoding of control characters in 
HttpException messages.
   Contributed by Arturo Bernal <!-- raw HTML omitted --></p>
   </li>
   <li>
   <p>HTTPCORE-799: Corrected the handling of asynchronous entity producer 
state resets after interrupted writes.
   Contributed by Matthias Kurz &lt;m.kurz at irregular.at&gt;</p>
   </li>
   <li>
   <p>Fixed URIBuilder encoding policy documentation and null reset behavior.
   Contributed by Praful Gupta <!-- raw HTML omitted --></p>
   </li>
   <li>
   <p>Increased the default HTTP/1.1 buffer size to 32 KiB.
   Contributed by Arturo Bernal <!-- raw HTML omitted --></p>
   </li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/apache/httpcomponents-core/commit/d40892ea9a52509a86960bb813f8241a134d2e0c";><code>d40892e</code></a>
 HttpCore 5.4.4 release</li>
   <li><a 
href="https://github.com/apache/httpcomponents-core/commit/698b2b66f8a7539c167f4b22eb7dfa2424e78acd";><code>698b2b6</code></a>
 Updated release notes for HttpCore 5.4.4 release</li>
   <li><a 
href="https://github.com/apache/httpcomponents-core/commit/8ada43a945066783288ffe0bc3fbc0a201c8bb43";><code>8ada43a</code></a>
 HTTPCORE-800: Fix hexadecimal encoding of control characters</li>
   <li><a 
href="https://github.com/apache/httpcomponents-core/commit/9cb751ee37589fd07b13563095959ede3ebac6be";><code>9cb751e</code></a>
 HTTPCORE-799: Reset async entity producer state after interrupted writes</li>
   <li><a 
href="https://github.com/apache/httpcomponents-core/commit/e871fa077ff112f3f26fdd881b02ac5ac9f1b07e";><code>e871fa0</code></a>
 Fix URIBuilder encoding policy documentation and null reset</li>
   <li><a 
href="https://github.com/apache/httpcomponents-core/commit/34542fccfeb19ec119db33e8af52c672bf0844ac";><code>34542fc</code></a>
 Increase default HTTP/1.1 buffer size to 32 KiB</li>
   <li><a 
href="https://github.com/apache/httpcomponents-core/commit/a79f87e8cad855a112240c3e393f320d0a1257b0";><code>a79f87e</code></a>
 Add details to solve compatibility issues.</li>
   <li><a 
href="https://github.com/apache/httpcomponents-core/commit/93421d33a0cce00a57dad4b3c3a9624cf994ef06";><code>93421d3</code></a>
 Upgraded HttpCore version to 5.4.4-SNAPSHOT</li>
   <li>See full diff in <a 
href="https://github.com/apache/httpcomponents-core/compare/rel/v5.4.3...rel/v5.4.4";>compare
 view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `org.apache.httpcomponents.core5:httpcore5-h2` from 5.4.3 to 5.4.4
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/apache/httpcomponents-core/blob/rel/v5.4.4/RELEASE_NOTES.txt";>org.apache.httpcomponents.core5:httpcore5-h2's
 changelog</a>.</em></p>
   <blockquote>
   <h2>Release 5.4.4</h2>
   <p>This maintenance release optimizes HTTP/1.1 message buffer configuration 
and corrects
   the handling of asynchronous entity producer state resets after interrupted 
writes.</p>
   <h2>Change Log</h2>
   <ul>
   <li>
   <p>HTTPCORE-800: Fixed hexadecimal encoding of control characters in 
HttpException messages.
   Contributed by Arturo Bernal <!-- raw HTML omitted --></p>
   </li>
   <li>
   <p>HTTPCORE-799: Corrected the handling of asynchronous entity producer 
state resets after interrupted writes.
   Contributed by Matthias Kurz &lt;m.kurz at irregular.at&gt;</p>
   </li>
   <li>
   <p>Fixed URIBuilder encoding policy documentation and null reset behavior.
   Contributed by Praful Gupta <!-- raw HTML omitted --></p>
   </li>
   <li>
   <p>Increased the default HTTP/1.1 buffer size to 32 KiB.
   Contributed by Arturo Bernal <!-- raw HTML omitted --></p>
   </li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/apache/httpcomponents-core/commit/d40892ea9a52509a86960bb813f8241a134d2e0c";><code>d40892e</code></a>
 HttpCore 5.4.4 release</li>
   <li><a 
href="https://github.com/apache/httpcomponents-core/commit/698b2b66f8a7539c167f4b22eb7dfa2424e78acd";><code>698b2b6</code></a>
 Updated release notes for HttpCore 5.4.4 release</li>
   <li><a 
href="https://github.com/apache/httpcomponents-core/commit/8ada43a945066783288ffe0bc3fbc0a201c8bb43";><code>8ada43a</code></a>
 HTTPCORE-800: Fix hexadecimal encoding of control characters</li>
   <li><a 
href="https://github.com/apache/httpcomponents-core/commit/9cb751ee37589fd07b13563095959ede3ebac6be";><code>9cb751e</code></a>
 HTTPCORE-799: Reset async entity producer state after interrupted writes</li>
   <li><a 
href="https://github.com/apache/httpcomponents-core/commit/e871fa077ff112f3f26fdd881b02ac5ac9f1b07e";><code>e871fa0</code></a>
 Fix URIBuilder encoding policy documentation and null reset</li>
   <li><a 
href="https://github.com/apache/httpcomponents-core/commit/34542fccfeb19ec119db33e8af52c672bf0844ac";><code>34542fc</code></a>
 Increase default HTTP/1.1 buffer size to 32 KiB</li>
   <li><a 
href="https://github.com/apache/httpcomponents-core/commit/a79f87e8cad855a112240c3e393f320d0a1257b0";><code>a79f87e</code></a>
 Add details to solve compatibility issues.</li>
   <li><a 
href="https://github.com/apache/httpcomponents-core/commit/93421d33a0cce00a57dad4b3c3a9624cf994ef06";><code>93421d3</code></a>
 Upgraded HttpCore version to 5.4.4-SNAPSHOT</li>
   <li>See full diff in <a 
href="https://github.com/apache/httpcomponents-core/compare/rel/v5.4.3...rel/v5.4.4";>compare
 view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `org.xmlunit:xmlunit-legacy` from 2.13.0 to 2.14.0
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/xmlunit/xmlunit/releases";>org.xmlunit:xmlunit-legacy's 
releases</a>.</em></p>
   <blockquote>
   <h2>XMLUnit for Java 2.14.0</h2>
   <p>With this release the dependency of xmlunit-core on the JAXB API has been 
marked optional. If you need the JAXB parts of XMLUnit you now must explicitly 
add a dependency on the API version matching your implementation. There is no 
other change compared to version 2.13.0.</p>
   </blockquote>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/xmlunit/xmlunit/blob/main/RELEASE_NOTES.md";>org.xmlunit:xmlunit-legacy's
 changelog</a>.</em></p>
   <blockquote>
   <h2>XMLUnit for Java 2.14.0 - /Released 2026-09-18/</h2>
   <ul>
   <li>marked jakarta.xml.bind-api as optional in xmlunit-core.
   PR <a href="https://redirect.github.com/xmlunit/xmlunit/pull/340";>#340</a> 
by <a href="https://github.com/arimu1";><code>@​arimu1</code></a></li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/xmlunit/xmlunit/commit/c74255f0543ba9916440fe4637f0332c9b5792c3";><code>c74255f</code></a>
 prepare release 2.14.0</li>
   <li><a 
href="https://github.com/xmlunit/xmlunit/commit/a5dcffecc32e9311c84c0919492c49175f4ef084";><code>a5dcffe</code></a>
 Merge pull request <a 
href="https://redirect.github.com/xmlunit/xmlunit/issues/342";>#342</a> from 
xmlunit/add-new-key</li>
   <li><a 
href="https://github.com/xmlunit/xmlunit/commit/2b3d856151a05a61c416cc87733db069b869cd68";><code>2b3d856</code></a>
 record <a 
href="https://redirect.github.com/xmlunit/xmlunit/issues/340";>#340</a></li>
   <li><a 
href="https://github.com/xmlunit/xmlunit/commit/900097f783c420c9d0c0e31ebac56c6779c68110";><code>900097f</code></a>
 add new key</li>
   <li><a 
href="https://github.com/xmlunit/xmlunit/commit/dfa47c90a2d1b4cc595f8510b44858513ff2b3a2";><code>dfa47c9</code></a>
 Merge pull request <a 
href="https://redirect.github.com/xmlunit/xmlunit/issues/340";>#340</a> from 
arimu1/fix/339-optional-jakarta-bind-api</li>
   <li><a 
href="https://github.com/xmlunit/xmlunit/commit/00e4ba338a6f93eb05ae3213a3e67e620c837d04";><code>00e4ba3</code></a>
 Mark jakarta.xml.bind-api optional in xmlunit-core (<a 
href="https://redirect.github.com/xmlunit/xmlunit/issues/339";>#339</a>)</li>
   <li><a 
href="https://github.com/xmlunit/xmlunit/commit/963cfe61ae9dd77b6ed94cd17a0fb559b007d574";><code>963cfe6</code></a>
 Merge pull request <a 
href="https://redirect.github.com/xmlunit/xmlunit/issues/338";>#338</a> from 
xmlunit/bump-cyclonedx-plugin</li>
   <li><a 
href="https://github.com/xmlunit/xmlunit/commit/79c9fed07f3d2549712de764bdd83d05fbd1152e";><code>79c9fed</code></a>
 bump cyclonedx plugin</li>
   <li><a 
href="https://github.com/xmlunit/xmlunit/commit/ed72f1f6d6617bcd5306f5db146457b14eb42916";><code>ed72f1f</code></a>
 Merge pull request <a 
href="https://redirect.github.com/xmlunit/xmlunit/issues/337";>#337</a> from 
xmlunit/release-1.13.0</li>
   <li><a 
href="https://github.com/xmlunit/xmlunit/commit/5894610393dacc997112cfadbc20bb54752f2fad";><code>5894610</code></a>
 prepare next iteration</li>
   <li>See full diff in <a 
href="https://github.com/xmlunit/xmlunit/compare/v2.13.0...v2.14.0";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `org.apache.xmlbeans:xmlbeans` from 5.4.0 to 5.4.1
   
   Updates `net.bytebuddy:byte-buddy` from 1.18.13 to 1.18.14
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/raphw/byte-buddy/releases";>net.bytebuddy:byte-buddy's 
releases</a>.</em></p>
   <blockquote>
   <h2>Byte Buddy 1.18.14</h2>
   <ul>
   <li>Avoid exposure of the agent argument on the command line of the process 
that is spawned for an external attachment.</li>
   <li>Avoid the resolution of symbolic links when the Gradle plugin deletes a 
folder recursively.</li>
   <li>Limit the nesting depth that is accepted when parsing a generic type 
signature to avoid an exhaustion of the stack for a malformed class file.</li>
   <li>Sign all deployed files using sigstore, in addition to the existing GPG 
signature.</li>
   <li>Validate entry names when the Android plugin retains a file to avoid the 
propagation of path traversals.</li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Changelog</summary>
   <p><em>Sourced from <a 
href="https://github.com/raphw/byte-buddy/blob/master/release-notes.md";>net.bytebuddy:byte-buddy's
 changelog</a>.</em></p>
   <blockquote>
   <h3>14. September 2026: version 1.18.14</h3>
   <ul>
   <li>Avoid exposure of the agent argument on the command line of the process 
that is spawned for an external attachment.</li>
   <li>Avoid the resolution of symbolic links when the Gradle plugin deletes a 
folder recursively.</li>
   <li>Limit the nesting depth that is accepted when parsing a generic type 
signature to avoid an exhaustion of the stack for a malformed class file.</li>
   <li>Sign all deployed files using sigstore, in addition to the existing GPG 
signature.</li>
   <li>Validate entry names when the Android plugin retains a file to avoid the 
propagation of path traversals.</li>
   </ul>
   </blockquote>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/92846cb0fa3480ed6e0fc41803e8e74f52070c59";><code>92846cb</code></a>
 [publish] Releasing Byte Buddy 1.18.14</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/a8a9f14e225f87477f65251db17f475895d73369";><code>a8a9f14</code></a>
 [release] Release new version</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/b0fe0066a8ea4f9316aa2a06906c87c0f529ddcd";><code>b0fe006</code></a>
 Skip the signature creation for artifacts that are not deployed.</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/c6107833a61e389719b56623fc36e3e476442e11";><code>c610783</code></a>
 Resolve the signed POM file by the path of the project file.</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/caab321964c9da0e0620fc0ff931413629ecf0b3";><code>caab321</code></a>
 Sign the deployed POM file and allow for a sigstore dry run.</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/c68a9c1761bc3fcda4d942ac7cc3a9e58a200e78";><code>c68a9c1</code></a>
 Supply the agent argument to the attacher process as an environment 
variable.</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/3ac9ded1959f2aa29809f1bf156d736ef602e3fa";><code>3ac9ded</code></a>
 Avoid symbolic link resolution on recursive deletion and validate Android 
ent...</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/8dbae60638aac34bed01685d9b322d08433c38de";><code>8dbae60</code></a>
 Sign deployed files using sigstore.</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/5d83cd4a0fc954fb0f6bd13e71f60b532a5d7f95";><code>5d83cd4</code></a>
 Disable semantic versioning check for protected constructor in abstract 
class...</li>
   <li><a 
href="https://github.com/raphw/byte-buddy/commit/172e0f4712366d4c82c53604214f427cd9232e69";><code>172e0f4</code></a>
 Move to method to apply suppression.</li>
   <li>Additional commits viewable in <a 
href="https://github.com/raphw/byte-buddy/compare/byte-buddy-1.18.13...byte-buddy-1.18.14";>compare
 view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `org.apache.groovy:groovy` from 5.1.2 to 6.0.0
   <details>
   <summary>Commits</summary>
   <ul>
   <li>See full diff in <a 
href="https://github.com/apache/groovy/commits";>compare view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `org.apache.groovy:groovy-ant` from 5.1.2 to 6.0.0
   <details>
   <summary>Commits</summary>
   <ul>
   <li>See full diff in <a 
href="https://github.com/apache/groovy/commits";>compare view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `org.apache.groovy:groovy-xml` from 5.1.2 to 6.0.0
   <details>
   <summary>Commits</summary>
   <ul>
   <li>See full diff in <a 
href="https://github.com/apache/groovy/commits";>compare view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `org.apache.groovy:groovy-ant` from 5.1.2 to 6.0.0
   <details>
   <summary>Commits</summary>
   <ul>
   <li>See full diff in <a 
href="https://github.com/apache/groovy/commits";>compare view</a></li>
   </ul>
   </details>
   <br />
   
   Updates `org.apache.groovy:groovy-xml` from 5.1.2 to 6.0.0
   <details>
   <summary>Commits</summary>
   <ul>
   <li>See full diff in <a 
href="https://github.com/apache/groovy/commits";>compare view</a></li>
   </ul>
   </details>
   <br />
   
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore <dependency name> major version` will close this group 
update PR and stop Dependabot creating any more for the specific dependency's 
major version (unless you unignore this specific dependency's major version or 
upgrade to it yourself)
   - `@dependabot ignore <dependency name> minor version` will close this group 
update PR and stop Dependabot creating any more for the specific dependency's 
minor version (unless you unignore this specific dependency's minor version or 
upgrade to it yourself)
   - `@dependabot ignore <dependency name>` will close this group update PR and 
stop Dependabot creating any more for the specific dependency (unless you 
unignore this specific dependency or upgrade to it yourself)
   - `@dependabot unignore <dependency name>` will remove all of the ignore 
conditions of the specified dependency
   - `@dependabot unignore <dependency name> <ignore condition>` will remove 
the ignore condition of the specified dependency and ignore conditions
   
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to