Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump org.apache.commons:commons-lang3 from 3.14.0 to 3.15.0 #41962

Merged

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jul 17, 2024

Bumps org.apache.commons:commons-lang3 from 3.14.0 to 3.15.0.

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps org.apache.commons:commons-lang3 from 3.14.0 to 3.15.0.

---
updated-dependencies:
- dependency-name: org.apache.commons:commons-lang3
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added the area/dependencies Pull requests that update a dependency file label Jul 17, 2024
@quarkus-bot quarkus-bot bot added the area/devtools Issues/PR related to maven, gradle, platform and cli tooling/plugins label Jul 17, 2024
Copy link

quarkus-bot bot commented Jul 18, 2024

Status for workflow Quarkus CI

This is the status report for running Quarkus CI on commit 47aad8d.

✅ The latest workflow run for the pull request has completed successfully.

It should be safe to merge provided you have a look at the other checks in the summary.

You can consult the Develocity build scans.

@gsmet gsmet merged commit d20cd23 into main Jul 18, 2024
52 checks passed
@quarkus-bot quarkus-bot bot added this to the 3.14 - main milestone Jul 18, 2024
@dependabot dependabot bot deleted the dependabot/maven/org.apache.commons-commons-lang3-3.15.0 branch July 18, 2024 06:39
@gsmet gsmet modified the milestones: 3.14 - main, 3.13.0 Jul 22, 2024
@famod
Copy link
Member

famod commented Aug 16, 2024

@gsmet I'd like to point out that this update brings a nasty surprise: https://issues.apache.org/jira/browse/LANG-1748

This entropy issue has hit my project (on Quarkus 3.13.2) on a late stage (but luckily before production).

I'm not entirely sure whether lang3 3.17.0 wil fix it and I haven't checked whether the folks over at liquibase are planning any counter measures, but I wanted to drop an early note here.

famod added a commit to famod/quarkus that referenced this pull request Aug 16, 2024
famod added a commit to famod/quarkus that referenced this pull request Aug 16, 2024
gsmet pushed a commit to gsmet/quarkus that referenced this pull request Aug 19, 2024
gsmet pushed a commit to gsmet/quarkus that referenced this pull request Aug 20, 2024
danielsoro pushed a commit to danielsoro/quarkus that referenced this pull request Sep 20, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
area/dependencies Pull requests that update a dependency file area/devtools Issues/PR related to maven, gradle, platform and cli tooling/plugins kind/component-upgrade
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants