Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Dependabot 20221201a #7211

Merged
merged 47 commits into from
Dec 2, 2022
Merged

Dependabot 20221201a #7211

merged 47 commits into from
Dec 2, 2022

Conversation

planetf1
Copy link
Member

@planetf1 planetf1 commented Dec 1, 2022

Description

Dependabot updates for Dec 2022

Related Issue(s)

Testing

Release Notes & Documentation

Additional notes

When reviewing the PRs prior to merge:

  • All spring 3.x related updates were rejected -- We will move to spring3 in release 4
  • slf4j 2.x rejected known issues due to spring
  • logback 3.x/4.x rejected - dependency issues

We expect these all to be resolved in v4

Bumps [maven-install-plugin](https://github.com/apache/maven-install-plugin) from 3.0.1 to 3.1.0.
- [Release notes](https://github.com/apache/maven-install-plugin/releases)
- [Commits](apache/maven-install-plugin@maven-install-plugin-3.0.1...maven-install-plugin-3.1.0)

---
updated-dependencies:
- dependency-name: org.apache.maven.plugins:maven-install-plugin
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps `spotbugs-maven.version` from 4.7.2.0 to 4.7.3.0.

Updates `spotbugs` from 4.7.2.0 to 4.7.3.0

Updates `spotbugs-maven-plugin` from 4.7.2.0 to 4.7.3.0
- [Release notes](https://github.com/spotbugs/spotbugs-maven-plugin/releases)
- [Commits](spotbugs/spotbugs-maven-plugin@spotbugs-maven-plugin-4.7.2.0...spotbugs-maven-plugin-4.7.3.0)

---
updated-dependencies:
- dependency-name: com.github.spotbugs:spotbugs
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: com.github.spotbugs:spotbugs-maven-plugin
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps [protobuf-java](https://github.com/protocolbuffers/protobuf) from 3.21.9 to 3.21.10.
- [Release notes](https://github.com/protocolbuffers/protobuf/releases)
- [Changelog](https://github.com/protocolbuffers/protobuf/blob/main/generate_changelog.py)
- [Commits](protocolbuffers/protobuf@v3.21.9...v3.21.10)

---
updated-dependencies:
- dependency-name: com.google.protobuf:protobuf-java
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps [classgraph](https://github.com/classgraph/classgraph) from 4.8.149 to 4.8.151.
- [Release notes](https://github.com/classgraph/classgraph/releases)
- [Commits](classgraph/classgraph@classgraph-4.8.149...classgraph-4.8.151)

---
updated-dependencies:
- dependency-name: io.github.classgraph:classgraph
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps tomcat-embed-core from 9.0.68 to 9.0.69.

---
updated-dependencies:
- dependency-name: org.apache.tomcat.embed:tomcat-embed-core
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps [chronicle-bom](https://github.com/OpenHFT/OpenHFT) from 2.24ea7 to 2.24ea16.
- [Release notes](https://github.com/OpenHFT/OpenHFT/releases)
- [Commits](https://github.com/OpenHFT/OpenHFT/commits)

---
updated-dependencies:
- dependency-name: net.openhft:chronicle-bom
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps [jnr-posix](https://github.com/jnr/jnr-posix) from 3.1.15 to 3.1.16.
- [Release notes](https://github.com/jnr/jnr-posix/releases)
- [Commits](jnr/jnr-posix@jnr-posix-3.1.15...jnr-posix-3.1.16)

---
updated-dependencies:
- dependency-name: com.github.jnr:jnr-posix
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps [openlineage-java](https://github.com/OpenLineage/OpenLineage) from 0.15.1 to 0.17.0.
- [Release notes](https://github.com/OpenLineage/OpenLineage/releases)
- [Changelog](https://github.com/OpenLineage/OpenLineage/blob/main/CHANGELOG.md)
- [Commits](OpenLineage/OpenLineage@0.15.1...0.17.0)

---
updated-dependencies:
- dependency-name: io.openlineage:openlineage-java
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps [dependency-check-maven](https://github.com/jeremylong/DependencyCheck) from 7.3.0 to 7.3.2.
- [Release notes](https://github.com/jeremylong/DependencyCheck/releases)
- [Changelog](https://github.com/jeremylong/DependencyCheck/blob/main/RELEASE_NOTES.md)
- [Commits](jeremylong/DependencyCheck@v7.3.0...v7.3.2)

---
updated-dependencies:
- dependency-name: org.owasp:dependency-check-maven
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps jackson-datatype-jdk8 from 2.13.4 to 2.14.1.

---
updated-dependencies:
- dependency-name: com.fasterxml.jackson.datatype:jackson-datatype-jdk8
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps `swagger.version` from 2.2.6 to 2.2.7.

Updates `swagger-annotations` from 2.2.6 to 2.2.7

Updates `swagger-models` from 2.2.6 to 2.2.7

---
updated-dependencies:
- dependency-name: io.swagger.core.v3:swagger-annotations
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: io.swagger.core.v3:swagger-models
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps [springdoc-openapi-ui](https://github.com/springdoc/springdoc-openapi) from 1.6.12 to 1.6.13.
- [Release notes](https://github.com/springdoc/springdoc-openapi/releases)
- [Changelog](https://github.com/springdoc/springdoc-openapi/blob/master/CHANGELOG.md)
- [Commits](springdoc/springdoc-openapi@v1.6.12...v1.6.13)

---
updated-dependencies:
- dependency-name: org.springdoc:springdoc-openapi-ui
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps `jackson.version` from 2.13.4 to 2.14.1.

Updates `jackson-annotations` from 2.13.4 to 2.14.1
- [Release notes](https://github.com/FasterXML/jackson/releases)
- [Commits](https://github.com/FasterXML/jackson/commits)

Updates `jackson-core` from 2.13.4 to 2.14.1
- [Release notes](https://github.com/FasterXML/jackson-core/releases)
- [Commits](FasterXML/jackson-core@jackson-core-2.13.4...jackson-core-2.14.1)

Updates `jackson-dataformat-yaml` from 2.13.4 to 2.14.1
- [Release notes](https://github.com/FasterXML/jackson-dataformats-text/releases)
- [Commits](FasterXML/jackson-dataformats-text@jackson-dataformats-text-2.13.4...jackson-dataformats-text-2.14.1)

Updates `jackson-datatype-jsr310` from 2.13.4 to 2.14.1

---
updated-dependencies:
- dependency-name: com.fasterxml.jackson.core:jackson-annotations
  dependency-type: direct:production
  update-type: version-update:semver-minor
- dependency-name: com.fasterxml.jackson.core:jackson-core
  dependency-type: direct:development
  update-type: version-update:semver-minor
- dependency-name: com.fasterxml.jackson.dataformat:jackson-dataformat-yaml
  dependency-type: direct:production
  update-type: version-update:semver-minor
- dependency-name: com.fasterxml.jackson.datatype:jackson-datatype-jsr310
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps `httpcore.version` from 4.4.15 to 4.4.16.

Updates `httpcore` from 4.4.15 to 4.4.16

Updates `httpcore-nio` from 4.4.15 to 4.4.16

Updates `httpcore-osgi` from 4.4.15 to 4.4.16

---
updated-dependencies:
- dependency-name: org.apache.httpcomponents:httpcore
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: org.apache.httpcomponents:httpcore-nio
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: org.apache.httpcomponents:httpcore-osgi
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps swagger-annotations from 2.2.6 to 2.2.7.

---
updated-dependencies:
- dependency-name: io.swagger.core.v3:swagger-annotations
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps [chronicle-bom](https://github.com/OpenHFT/OpenHFT) from 2.24ea7 to 2.24ea16.
- [Release notes](https://github.com/OpenHFT/OpenHFT/releases)
- [Commits](https://github.com/OpenHFT/OpenHFT/commits)

---
updated-dependencies:
- dependency-name: net.openhft:chronicle-bom
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps com.github.psxpaul.execfork from 0.2.0 to 0.2.1.

---
updated-dependencies:
- dependency-name: com.github.psxpaul.execfork
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps de.jjohannes.java-ecosystem-capabilities from 0.6 to 0.8.

---
updated-dependencies:
- dependency-name: de.jjohannes.java-ecosystem-capabilities
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps `mockito.version` from 4.8.1 to 4.9.0.

Updates `mockito-core` from 4.8.1 to 4.9.0
- [Release notes](https://github.com/mockito/mockito/releases)
- [Commits](mockito/mockito@v4.8.1...v4.9.0)

Updates `mockito-inline` from 4.8.1 to 4.9.0
- [Release notes](https://github.com/mockito/mockito/releases)
- [Commits](mockito/mockito@v4.8.1...v4.9.0)

Updates `mockito-junit-jupiter` from 4.8.1 to 4.9.0
- [Release notes](https://github.com/mockito/mockito/releases)
- [Commits](mockito/mockito@v4.8.1...v4.9.0)

---
updated-dependencies:
- dependency-name: org.mockito:mockito-core
  dependency-type: direct:production
  update-type: version-update:semver-minor
- dependency-name: org.mockito:mockito-inline
  dependency-type: direct:production
  update-type: version-update:semver-minor
- dependency-name: org.mockito:mockito-junit-jupiter
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps [jnr-posix](https://github.com/jnr/jnr-posix) from 3.1.15 to 3.1.16.
- [Release notes](https://github.com/jnr/jnr-posix/releases)
- [Commits](jnr/jnr-posix@jnr-posix-3.1.15...jnr-posix-3.1.16)

---
updated-dependencies:
- dependency-name: com.github.jnr:jnr-posix
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps [micrometer-registry-prometheus](https://github.com/micrometer-metrics/micrometer) from 1.9.5 to 1.10.2.
- [Release notes](https://github.com/micrometer-metrics/micrometer/releases)
- [Commits](micrometer-metrics/micrometer@v1.9.5...v1.10.2)

---
updated-dependencies:
- dependency-name: io.micrometer:micrometer-registry-prometheus
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps [com.autonomousapps.dependency-analysis](https://github.com/autonomousapps/dependency-analysis-android-gradle-plugin) from 1.13.1 to 1.17.0.
- [Release notes](https://github.com/autonomousapps/dependency-analysis-android-gradle-plugin/releases)
- [Changelog](https://github.com/autonomousapps/dependency-analysis-android-gradle-plugin/blob/main/CHANGELOG.md)
- [Commits](autonomousapps/dependency-analysis-gradle-plugin@v1.13.1...v1.17.0)

---
updated-dependencies:
- dependency-name: com.autonomousapps.dependency-analysis
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps [protobuf-java](https://github.com/protocolbuffers/protobuf) from 3.21.9 to 3.21.10.
- [Release notes](https://github.com/protocolbuffers/protobuf/releases)
- [Changelog](https://github.com/protocolbuffers/protobuf/blob/main/generate_changelog.py)
- [Commits](protocolbuffers/protobuf@v3.21.9...v3.21.10)

---
updated-dependencies:
- dependency-name: com.google.protobuf:protobuf-java
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps `mockitoVersion` from 4.8.1 to 4.9.0.

Updates `mockito-core` from 4.8.1 to 4.9.0
- [Release notes](https://github.com/mockito/mockito/releases)
- [Commits](mockito/mockito@v4.8.1...v4.9.0)

Updates `mockito-junit-jupiter` from 4.8.1 to 4.9.0
- [Release notes](https://github.com/mockito/mockito/releases)
- [Commits](mockito/mockito@v4.8.1...v4.9.0)

Updates `mockito-inline` from 4.8.1 to 4.9.0
- [Release notes](https://github.com/mockito/mockito/releases)
- [Commits](mockito/mockito@v4.8.1...v4.9.0)

---
updated-dependencies:
- dependency-name: org.mockito:mockito-core
  dependency-type: direct:production
  update-type: version-update:semver-minor
- dependency-name: org.mockito:mockito-junit-jupiter
  dependency-type: direct:production
  update-type: version-update:semver-minor
- dependency-name: org.mockito:mockito-inline
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps [classgraph](https://github.com/classgraph/classgraph) from 4.8.149 to 4.8.151.
- [Release notes](https://github.com/classgraph/classgraph/releases)
- [Commits](classgraph/classgraph@classgraph-4.8.149...classgraph-4.8.151)

---
updated-dependencies:
- dependency-name: io.github.classgraph:classgraph
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps jackson-datatype-jdk8 from 2.13.4 to 2.14.1.

---
updated-dependencies:
- dependency-name: com.fasterxml.jackson.datatype:jackson-datatype-jdk8
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps [jackson-databind](https://github.com/FasterXML/jackson) from 2.13.4.2 to 2.14.1.
- [Release notes](https://github.com/FasterXML/jackson/releases)
- [Commits](https://github.com/FasterXML/jackson/commits)

---
updated-dependencies:
- dependency-name: com.fasterxml.jackson.core:jackson-databind
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps [jackson-databind](https://github.com/FasterXML/jackson) from 2.13.4.2 to 2.14.1.
- [Release notes](https://github.com/FasterXML/jackson/releases)
- [Commits](https://github.com/FasterXML/jackson/commits)

---
updated-dependencies:
- dependency-name: com.fasterxml.jackson.core:jackson-databind
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps `micrometer-registry-prometheus.version` from 1.9.5 to 1.10.2.

Updates `micrometer-core` from 1.9.5 to 1.10.2
- [Release notes](https://github.com/micrometer-metrics/micrometer/releases)
- [Commits](micrometer-metrics/micrometer@v1.9.5...v1.10.2)

Updates `micrometer-registry-prometheus` from 1.9.5 to 1.10.2
- [Release notes](https://github.com/micrometer-metrics/micrometer/releases)
- [Commits](micrometer-metrics/micrometer@v1.9.5...v1.10.2)

---
updated-dependencies:
- dependency-name: io.micrometer:micrometer-core
  dependency-type: direct:production
  update-type: version-update:semver-minor
- dependency-name: io.micrometer:micrometer-registry-prometheus
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps `httpcoreVersion` from 4.4.15 to 4.4.16.

Updates `httpcore` from 4.4.15 to 4.4.16

Updates `httpcore-nio` from 4.4.15 to 4.4.16

Updates `httpcore-osgi` from 4.4.15 to 4.4.16

---
updated-dependencies:
- dependency-name: org.apache.httpcomponents:httpcore
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: org.apache.httpcomponents:httpcore-nio
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: org.apache.httpcomponents:httpcore-osgi
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps `elasticsearch.version` from 8.5.0 to 8.5.2.

Updates `elasticsearch-rest-client` from 8.5.0 to 8.5.2
- [Release notes](https://github.com/elastic/elasticsearch/releases)
- [Changelog](https://github.com/elastic/elasticsearch/blob/main/CHANGELOG.md)
- [Commits](elastic/elasticsearch@v8.5.0...v8.5.2)

Updates `elasticsearch-java` from 8.5.0 to 8.5.2
- [Release notes](https://github.com/elastic/elasticsearch-java/releases)
- [Changelog](https://github.com/elastic/elasticsearch-java/blob/main/CHANGELOG.md)
- [Commits](elastic/elasticsearch-java@v8.5.0...v8.5.2)

Updates `elasticsearch` from 8.5.0 to 8.5.2
- [Release notes](https://github.com/elastic/elasticsearch/releases)
- [Changelog](https://github.com/elastic/elasticsearch/blob/main/CHANGELOG.md)
- [Commits](elastic/elasticsearch@v8.5.0...v8.5.2)

Updates `elasticsearch-x-content` from 8.5.0 to 8.5.2
- [Release notes](https://github.com/elastic/elasticsearch/releases)
- [Changelog](https://github.com/elastic/elasticsearch/blob/main/CHANGELOG.md)
- [Commits](elastic/elasticsearch@v8.5.0...v8.5.2)

---
updated-dependencies:
- dependency-name: org.elasticsearch.client:elasticsearch-rest-client
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: co.elastic.clients:elasticsearch-java
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: org.elasticsearch:elasticsearch
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: org.elasticsearch:elasticsearch-x-content
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps [maven-dependency-plugin](https://github.com/apache/maven-dependency-plugin) from 3.3.0 to 3.4.0.
- [Release notes](https://github.com/apache/maven-dependency-plugin/releases)
- [Commits](apache/maven-dependency-plugin@maven-dependency-plugin-3.3.0...maven-dependency-plugin-3.4.0)

---
updated-dependencies:
- dependency-name: org.apache.maven.plugins:maven-dependency-plugin
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps `netty.version` from 4.1.84.Final to 4.1.85.Final.

Updates `netty-all` from 4.1.84.Final to 4.1.85.Final
- [Release notes](https://github.com/netty/netty/releases)
- [Commits](netty/netty@netty-4.1.84.Final...netty-4.1.85.Final)

Updates `netty-buffer` from 4.1.84.Final to 4.1.85.Final
- [Release notes](https://github.com/netty/netty/releases)
- [Commits](netty/netty@netty-4.1.84.Final...netty-4.1.85.Final)

Updates `netty-codec` from 4.1.84.Final to 4.1.85.Final
- [Release notes](https://github.com/netty/netty/releases)
- [Commits](netty/netty@netty-4.1.84.Final...netty-4.1.85.Final)

Updates `netty-common` from 4.1.84.Final to 4.1.85.Final
- [Release notes](https://github.com/netty/netty/releases)
- [Commits](netty/netty@netty-4.1.84.Final...netty-4.1.85.Final)

Updates `netty-handler` from 4.1.84.Final to 4.1.85.Final
- [Release notes](https://github.com/netty/netty/releases)
- [Commits](netty/netty@netty-4.1.84.Final...netty-4.1.85.Final)

Updates `netty-resolver` from 4.1.84.Final to 4.1.85.Final
- [Release notes](https://github.com/netty/netty/releases)
- [Commits](netty/netty@netty-4.1.84.Final...netty-4.1.85.Final)

Updates `netty-transport` from 4.1.84.Final to 4.1.85.Final
- [Release notes](https://github.com/netty/netty/releases)
- [Commits](netty/netty@netty-4.1.84.Final...netty-4.1.85.Final)

---
updated-dependencies:
- dependency-name: io.netty:netty-all
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: io.netty:netty-buffer
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: io.netty:netty-codec
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: io.netty:netty-common
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: io.netty:netty-handler
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: io.netty:netty-resolver
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: io.netty:netty-transport
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps `tomcatVersion` from 9.0.68 to 9.0.69.

Updates `tomcat-embed-core` from 9.0.68 to 9.0.69

Updates `tomcat-coyote` from 9.0.68 to 9.0.69

---
updated-dependencies:
- dependency-name: org.apache.tomcat.embed:tomcat-embed-core
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: org.apache.tomcat:tomcat-coyote
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps `elasticsearchVersion` from 8.5.0 to 8.5.2.

Updates `elasticsearch` from 8.5.0 to 8.5.2
- [Release notes](https://github.com/elastic/elasticsearch/releases)
- [Changelog](https://github.com/elastic/elasticsearch/blob/main/CHANGELOG.md)
- [Commits](elastic/elasticsearch@v8.5.0...v8.5.2)

Updates `elasticsearch-rest-client` from 8.5.0 to 8.5.2
- [Release notes](https://github.com/elastic/elasticsearch/releases)
- [Changelog](https://github.com/elastic/elasticsearch/blob/main/CHANGELOG.md)
- [Commits](elastic/elasticsearch@v8.5.0...v8.5.2)

Updates `elasticsearch-java` from 8.5.0 to 8.5.2
- [Release notes](https://github.com/elastic/elasticsearch-java/releases)
- [Changelog](https://github.com/elastic/elasticsearch-java/blob/main/CHANGELOG.md)
- [Commits](elastic/elasticsearch-java@v8.5.0...v8.5.2)

---
updated-dependencies:
- dependency-name: org.elasticsearch:elasticsearch
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: org.elasticsearch.client:elasticsearch-rest-client
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: co.elastic.clients:elasticsearch-java
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps [springdoc-openapi-ui](https://github.com/springdoc/springdoc-openapi) from 1.6.12 to 1.6.13.
- [Release notes](https://github.com/springdoc/springdoc-openapi/releases)
- [Changelog](https://github.com/springdoc/springdoc-openapi/blob/master/CHANGELOG.md)
- [Commits](springdoc/springdoc-openapi@v1.6.12...v1.6.13)

---
updated-dependencies:
- dependency-name: org.springdoc:springdoc-openapi-ui
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps [openlineage-java](https://github.com/OpenLineage/OpenLineage) from 0.15.1 to 0.17.0.
- [Release notes](https://github.com/OpenLineage/OpenLineage/releases)
- [Changelog](https://github.com/OpenLineage/OpenLineage/blob/main/CHANGELOG.md)
- [Commits](OpenLineage/OpenLineage@0.15.1...0.17.0)

---
updated-dependencies:
- dependency-name: io.openlineage:openlineage-java
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps `nettyVersion` from 4.1.84.Final to 4.1.85.Final.

Updates `netty-handler` from 4.1.84.Final to 4.1.85.Final
- [Release notes](https://github.com/netty/netty/releases)
- [Commits](netty/netty@netty-4.1.84.Final...netty-4.1.85.Final)

Updates `netty-common` from 4.1.84.Final to 4.1.85.Final
- [Release notes](https://github.com/netty/netty/releases)
- [Commits](netty/netty@netty-4.1.84.Final...netty-4.1.85.Final)

Updates `netty-buffer` from 4.1.84.Final to 4.1.85.Final
- [Release notes](https://github.com/netty/netty/releases)
- [Commits](netty/netty@netty-4.1.84.Final...netty-4.1.85.Final)

Updates `netty-codec` from 4.1.84.Final to 4.1.85.Final
- [Release notes](https://github.com/netty/netty/releases)
- [Commits](netty/netty@netty-4.1.84.Final...netty-4.1.85.Final)

Updates `netty-all` from 4.1.84.Final to 4.1.85.Final
- [Release notes](https://github.com/netty/netty/releases)
- [Commits](netty/netty@netty-4.1.84.Final...netty-4.1.85.Final)

Updates `netty-transport` from 4.1.84.Final to 4.1.85.Final
- [Release notes](https://github.com/netty/netty/releases)
- [Commits](netty/netty@netty-4.1.84.Final...netty-4.1.85.Final)

Updates `netty-resolver` from 4.1.84.Final to 4.1.85.Final
- [Release notes](https://github.com/netty/netty/releases)
- [Commits](netty/netty@netty-4.1.84.Final...netty-4.1.85.Final)

---
updated-dependencies:
- dependency-name: io.netty:netty-handler
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: io.netty:netty-common
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: io.netty:netty-buffer
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: io.netty:netty-codec
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: io.netty:netty-all
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: io.netty:netty-transport
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: io.netty:netty-resolver
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps [lycheeverse/lychee-action](https://github.com/lycheeverse/lychee-action) from 1.5.1 to 1.5.4.
- [Release notes](https://github.com/lycheeverse/lychee-action/releases)
- [Commits](lycheeverse/lychee-action@v1.5.1...v1.5.4)

---
updated-dependencies:
- dependency-name: lycheeverse/lychee-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Bumps library/alpine from 3.16.2 to 3.17.0.

---
updated-dependencies:
- dependency-name: library/alpine
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
@planetf1
Copy link
Member Author

planetf1 commented Dec 2, 2022

Dependency check fails with:

[INFO] --- maven-enforcer-plugin:3.1.0:enforce (enforce-versions) @ server-chassis-spring ---
Downloading from 1-MavenCentral: https://repo1.maven.org/maven2/jakarta/servlet/jakarta.servlet-api/4.0.4/jakarta.servlet-api-4.0.4.pom
Downloaded from 1-MavenCentral: https://repo1.maven.org/maven2/jakarta/servlet/jakarta.servlet-api/4.0.4/jakarta.servlet-api-4.0.4.pom (17 kB at 180 kB/s)
Downloading from 1-MavenCentral: https://repo1.maven.org/maven2/org/eclipse/jdt/org.eclipse.jdt.annotation/2.2.700/org.eclipse.jdt.annotation-2.2.700.pom
Downloaded from 1-MavenCentral: https://repo1.maven.org/maven2/org/eclipse/jdt/org.eclipse.jdt.annotation/2.2.700/org.eclipse.jdt.annotation-2.2.700.pom (1.7 kB at 18 kB/s)
[ERROR] Rule 5: org.apache.maven.plugins.enforcer.RequireUpperBoundDeps failed with message:
Failed while enforcing RequireUpperBoundDeps. The error(s) are [
Require upper bound dependencies error for ch.qos.logback:logback-classic:1.2.11 paths to dependency are:
+-org.odpi.egeria:server-chassis-spring:3.15-SNAPSHOT
  +-ch.qos.logback:logback-classic:1.2.11
and
+-org.odpi.egeria:server-chassis-spring:3.15-SNAPSHOT
  +-org.springframework.boot:spring-boot-starter-actuator:2.7.5
    +-org.springframework.boot:spring-boot-starter:2.7.5
      +-org.springframework.boot:spring-boot-starter-logging:2.7.5
        +-ch.qos.logback:logback-classic:1.2.11 (managed) <-- ch.qos.logback:logback-classic:1.2.11
and
+-org.odpi.egeria:server-chassis-spring:3.15-SNAPSHOT
  +-org.springdoc:springdoc-openapi-ui:1.6.13
    +-org.springdoc:springdoc-openapi-webmvc-core:1.6.13
      +-org.springdoc:springdoc-openapi-common:1.6.13
        +-io.swagger.core.v3:swagger-core:2.2.7
          +-ch.qos.logback:logback-classic:1.2.11 (managed) <-- ch.qos.logback:logback-classic:1.4.4
,
Require upper bound dependencies error for ch.qos.logback:logback-core:1.2.11 paths to dependency are:
+-org.odpi.egeria:server-chassis-spring:3.15-SNAPSHOT
  +-ch.qos.logback:logback-core:1.2.11
and
+-org.odpi.egeria:server-chassis-spring:3.15-SNAPSHOT
  +-ch.qos.logback:logback-classic:1.2.11
    +-ch.qos.logback:logback-core:1.2.11 (managed) <-- ch.qos.logback:logback-core:1.2.11
and
+-org.odpi.egeria:server-chassis-spring:3.15-SNAPSHOT
  +-org.springdoc:springdoc-openapi-ui:1.6.13
    +-org.springdoc:springdoc-openapi-webmvc-core:1.6.13
      +-org.springdoc:springdoc-openapi-common:1.6.13
        +-io.swagger.core.v3:swagger-core:2.2.7
          +-ch.qos.logback:logback-core:1.2.11 (managed) <-- ch.qos.logback:logback-core:1.4.4
]

This reverts commit d94aa17.

Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
@planetf1
Copy link
Member Author

planetf1 commented Dec 2, 2022

Swagger 2.4.7 is upgrading to logback 1.4.4 which causes other dependency issues with spring -- this will be resolved in java 17/version 4 build. Reverting the swagger updates

This reverts commit d80b851.

Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
This reverts commit d80b851.

Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
This reverts commit e91f078.

Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
This reverts commit 268517e.

Signed-off-by: Nigel Jones <nigel.l.jones+git@gmail.com>
@planetf1 planetf1 merged commit 692e791 into odpi:main Dec 2, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant