dependabot[bot] opened a new pull request, #15726:
URL: https://github.com/apache/dubbo/pull/15726

   Bumps [com.hazelcast:hazelcast](https://github.com/hazelcast/hazelcast) from 
3.12.13 to 5.2.5.
   <details>
   <summary>Release notes</summary>
   <p><em>Sourced from <a 
href="https://github.com/hazelcast/hazelcast/releases";>com.hazelcast:hazelcast's
 releases</a>.</em></p>
   <blockquote>
   <h2>v5.2.5</h2>
   <p>This document lists the enhancements and fixed issues for the Hazelcast 
Platform 5.2.5 release. The numbers in the square brackets refer to the issues 
and pull requests in Hazelcast's GitHub repository.</p>
   <h2>Enhancements</h2>
   <ul>
   <li>Improved the permission checks in the file connectors by adding a method 
that returns the permissions required to resolve field names. <a 
href="https://redirect.github.com/hazelcast/hazelcast/issues/25674";>#25674</a></li>
   <li>Updated the versions of following dependencies:
   ** Snappy to 1.1.10.5
   ** gRPC to 1.59
   ** Netty to 4.1.100.Final
   ** Elasticsearch to 7.17.13
   ** Everit JSON Schema to 1.14.3
   <a 
href="https://redirect.github.com/hazelcast/hazelcast/issues/24866";>#24866</a>, 
<a 
href="https://redirect.github.com/hazelcast/hazelcast/issues/25820";>#25820</a>, 
<a 
href="https://redirect.github.com/hazelcast/hazelcast/issues/25708";>#25708</a>, 
<a 
href="https://redirect.github.com/hazelcast/hazelcast/issues/25729";>#25729</a>, 
<a 
href="https://redirect.github.com/hazelcast/hazelcast/issues/25775";>#25775</a></li>
   </ul>
   <h2>Fixes</h2>
   <ul>
   <li>Fixed an issue where the entry listeners for Replicated Maps were 
checking the Map permissions instead of the Replicated Map permissions. <a 
href="https://redirect.github.com/hazelcast/hazelcast/issues/25971";>#25971</a></li>
   <li>Fixed an issue where the map entries' metadata, such as time-to-live and 
expiration, was not replicated correctly over WAN after updating existing 
entries. <a 
href="https://redirect.github.com/hazelcast/hazelcast/issues/25506";>#25506</a></li>
   <li>Fixed an issue where there was a difference between the elapsed clock 
time and elapsed total time when listening to migration events. <a 
href="https://redirect.github.com/hazelcast/hazelcast/issues/25066";>#25066</a></li>
   <li>Fixed an issue where the member list was not updated after a cluster 
failover scenario. <a 
href="https://redirect.github.com/hazelcast/hazelcast/issues/24944";>#24944</a></li>
   <li>Renamed the service port for Hazelcast clusters deployed in Kubernetes 
environments to hazelcast. The previous name, 
<code>hazelcast-service-port</code>, caused member auto-discovery for embedded 
deployments to fail. <a 
href="https://redirect.github.com/hazelcast/hazelcast/issues/24841";>#24841</a></li>
   <li>Fixed an issue where Hazelcast was sending empty map interceptor 
information to the members that are newly joined to the cluster; it was causing 
eager map initializations. <a 
href="https://redirect.github.com/hazelcast/hazelcast/issues/24669";>#24669</a></li>
   </ul>
   <h2>Removed/Deprecated Features</h2>
   <ul>
   <li>Removed the evaluation tool (for trying out Platform 5.x features for 
IMDG 3.x users) and the relevant IMDG 3.x JAR libraries from Hazelcast Platform 
distributions. <a 
href="https://redirect.github.com/hazelcast/hazelcast/issues/25697";>#25697</a></li>
   </ul>
   <h2>Contributors</h2>
   <p>We would like to thank the contributors from our open source community
   who worked on this release:</p>
   <ul>
   <li><a href="https://github.com/azotcsit";>Aleksei Zotov</a></li>
   </ul>
   <h2>v5.2.4</h2>
   <p>This document lists the enhancements and fixed issues for the Hazelcast 
Platform 5.2.4 release. The numbers in the square brackets refer to the issues 
and pull requests in Hazelcast's GitHub repository 
(github.com/hazelcast/hazelcast).</p>
   <h2>Enhancements</h2>
   <ul>
   <li>Updated the version of <code>jackson-core</code> dependency to 2.15.2. 
<a 
href="https://redirect.github.com/hazelcast/hazelcast/issues/24730";>#24730</a></li>
   <li>Hazelcast was sending requests to Kubernetes API when deploying an 
application with embedded Hazelcast and <code>service-dns</code> (DNS lookup 
mode) specified to a Kubernetes cluster. This was causing the requests to be 
unsuccessful and the application not to start. This mechanism has been improved 
by creating Kubernetes client only for the DNS lookup mode. <a 
href="https://redirect.github.com/hazelcast/hazelcast/issues/24045";>#24045</a></li>
   </ul>
   <h2>Fixes</h2>
   <ul>
   <li>Fixed an issue where some of the members in a Hazelcast cluster deployed 
on Kubernetes (as a statefulset) shut down with en exception in a delayed 
manner. <a 
href="https://redirect.github.com/hazelcast/hazelcast/issues/24709";>#24709</a></li>
   <li>Fixed an issue where Jet job snapshots could be prematurely deleted 
after a restart of a cluster, having lossless restart enabled. <a 
href="https://redirect.github.com/hazelcast/hazelcast/issues/24576";>#24576</a></li>
   <li>Fixed an issue where the SELECT COUNT(DISTINCT COLUMN) query for maps 
was producing incorrect results. <a 
href="https://redirect.github.com/hazelcast/hazelcast/issues/24490";>#24490</a></li>
   <li>Fixed various issues in [Health Monitor] including incorrect metric 
names. <a 
href="https://redirect.github.com/hazelcast/hazelcast/issues/24634";>#24634</a></li>
   <li>Fixed an issue where the REST calls were failing for Hazelcast clusters 
with TLS v1.3 configured, and deployed on Kubernetes. <a 
href="https://redirect.github.com/hazelcast/hazelcast/issues/24624";>#24624</a></li>
   <li>Fixed an issue where SQL statements were failing when a class (to 
determine the fields of a key/value pair) no longer exists but the mapping is 
still valid. <a 
href="https://redirect.github.com/hazelcast/hazelcast/issues/24043";>#24043</a></li>
   </ul>
   <!-- raw HTML omitted -->
   </blockquote>
   <p>... (truncated)</p>
   </details>
   <details>
   <summary>Commits</summary>
   <ul>
   <li><a 
href="https://github.com/hazelcast/hazelcast/commit/8b1bd72a87ad7072c9eb1dd639cb953dba7831ad";><code>8b1bd72</code></a>
 Upgrade version to 5.2.5</li>
   <li><a 
href="https://github.com/hazelcast/hazelcast/commit/c4f388d0baf10a9a468aa1719f3f618f89715666";><code>c4f388d</code></a>
 Adding OS RN for 5.2.5 (<a 
href="https://redirect.github.com/hazelcast/hazelcast/issues/827";>#827</a>)</li>
   <li><a 
href="https://github.com/hazelcast/hazelcast/commit/0c3b54d1addac075e0325df68b66c43ca4799229";><code>0c3b54d</code></a>
 Best-effort fix for merging metadata over WAN after merge rejection [5.2.5] 
(...</li>
   <li><a 
href="https://github.com/hazelcast/hazelcast/commit/1eec447afaff529381e8cf8af07b368b2665883c";><code>1eec447</code></a>
 Extend permission checks in MessageTasks and add a test coverage [HZ-2090] 
[5...</li>
   <li><a 
href="https://github.com/hazelcast/hazelcast/commit/e394e3d09ff1c2a078c0ae0d2ee019db4cdc8406";><code>e394e3d</code></a>
 Fix K8s service port [CN-894] [5.2.5] (<a 
href="https://redirect.github.com/hazelcast/hazelcast/issues/797";>#797</a>)</li>
   <li><a 
href="https://github.com/hazelcast/hazelcast/commit/06a10be6ee00b0c1a1da2933243311bc93cef350";><code>06a10be</code></a>
 [BACKPORT] Do not try to connect to the old member list after the cluster 
cha...</li>
   <li><a 
href="https://github.com/hazelcast/hazelcast/commit/1239695c774ef7c1eb4fdc3e33f97e2761ddd578";><code>1239695</code></a>
 Make MigrationListener timers use wall-clock not CPU time 
[5.2.5][HZ-2651][HZ...</li>
   <li><a 
href="https://github.com/hazelcast/hazelcast/commit/39395483b68ba63fb945685a52f2ebb239de2ce7";><code>3939548</code></a>
 Correctly WAN replicate IMap metadata when updating existing records (<a 
href="https://redirect.github.com/hazelcast/hazelcast/issues/6514";>#6514</a>) 
...</li>
   <li><a 
href="https://github.com/hazelcast/hazelcast/commit/6c471c17b69d43ba05e7894efd855ca3e53e8519";><code>6c471c1</code></a>
 Use MapContainer to filter maps to be cleaned up when migrating off a 
partiti...</li>
   <li><a 
href="https://github.com/hazelcast/hazelcast/commit/366fad925b467de7d4d022bc47cba73900ae2e49";><code>366fad9</code></a>
 Bump <code>grpc</code> to mitigate CVE-2023-44487 [5.2.5]</li>
   <li>Additional commits viewable in <a 
href="https://github.com/hazelcast/hazelcast/compare/v3.12.13...v5.2.5";>compare 
view</a></li>
   </ul>
   </details>
   <br />
   
   
   [![Dependabot compatibility 
score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.hazelcast:hazelcast&package-manager=maven&previous-version=3.12.13&new-version=5.2.5)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
   
   Dependabot will resolve any conflicts with this PR as long as you don't 
alter it yourself. You can also trigger a rebase manually by commenting 
`@dependabot rebase`.
   
   [//]: # (dependabot-automerge-start)
   [//]: # (dependabot-automerge-end)
   
   ---
   
   <details>
   <summary>Dependabot commands and options</summary>
   <br />
   
   You can trigger Dependabot actions by commenting on this PR:
   - `@dependabot rebase` will rebase this PR
   - `@dependabot recreate` will recreate this PR, overwriting any edits that 
have been made to it
   - `@dependabot merge` will merge this PR after your CI passes on it
   - `@dependabot squash and merge` will squash and merge this PR after your CI 
passes on it
   - `@dependabot cancel merge` will cancel a previously requested merge and 
block automerging
   - `@dependabot reopen` will reopen this PR if it is closed
   - `@dependabot close` will close this PR and stop Dependabot recreating it. 
You can achieve the same result by closing it manually
   - `@dependabot show <dependency name> ignore conditions` will show all of 
the ignore conditions of the specified dependency
   - `@dependabot ignore this major version` will close this PR and stop 
Dependabot creating any more for this major version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this minor version` will close this PR and stop 
Dependabot creating any more for this minor version (unless you reopen the PR 
or upgrade to it yourself)
   - `@dependabot ignore this dependency` will close this PR and stop 
Dependabot creating any more for this dependency (unless you reopen the PR or 
upgrade to it yourself)
   You can disable automated security fix PRs for this repo from the [Security 
Alerts page](https://github.com/apache/dubbo/network/alerts).
   
   </details>


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to