Skip to content

Bump the minor-and-patch group across 1 directory with 10 updates - #1464

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/minor-and-patch-753fc69234
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/gradle/minor-and-patch-753fc69234

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 3, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 10 updates in the / directory:

Package From To
org.springframework.modulith:spring-modulith-bom 2.1.0 2.1.1
net.bytebuddy:byte-buddy 1.18.11 1.18.14
net.bytebuddy:byte-buddy-agent 1.18.11 1.18.14
com.github.oshi:oshi-core 7.4.2 7.7.0
org.springdoc:springdoc-openapi-starter-webmvc-ui 3.0.3 3.1.1
com.azure:azure-data-tables 12.5.11 12.5.12
org.jsoup:jsoup 1.22.2 1.23.2
org.projectlombok:lombok 1.18.46 1.18.48
org.slf4j:slf4j-api 2.0.18 2.0.20
gradle-wrapper 9.6.1 9.8.0

Updates org.springframework.modulith:spring-modulith-bom from 2.1.0 to 2.1.1

Release notes

Sourced from org.springframework.modulith:spring-modulith-bom's releases.

2.1.1

💡 Improvements

  • Use Namastack version property in spring-modulith-events-core #1807

🪲 Bugs

  • Event externalization throws ClassCastException with event listener using ApplicationListener.forPayload(…) #1832
  • RabbitJackson2Configuration and RabbitJacksonConfiguration conflict when Jackson 2.x is on classpath (e.g. Eureka Client) #1830
  • Ambiguous violation message when referring to a non-exposed type in a module generally available for access #1827
  • ConcurrentModificationException in TestExecutionCondition when running tests with JUnit parallel class execution #1824
  • Typo in spring.modulith.events.staleness.check-interval configuration property #1822
  • Potential NullPointerException in FormattableType.of(…) for wildcard types #1806
  • Fix Testcontainers setup to ensure fresh containers for SQL databases #1802
  • MongoDB event publication tests use default localhost connection instead of Testcontainers #1755
  • Unbounded wildcard / type-variable generic parameters break FormattableType (NPE in DefaultObservedModule.render) #1754
  • Root module Flyway migrations are not executed during a test #1753

🔨 Dependency Upgrades

  • Upgrade to Spring Boot 4.1.1 #1820
  • Upgrade to Namastack Outbox 1.7.3 #1796, #1814
  • Upgrade to Spring Framework 7.0.9 #1813
  • Upgrade to Micrometer Tracing 1.7.1 #1812
  • Upgrade to jGit 7.7.1.202607240634-r #1797

❤️ Contributors

Thank you to all the contributors who worked on this release:

@​arendomoda, @​arimu1, @​char-yb, @​DragonFSKY, @​Hashim1999164, @​kalayciburak, @​seonwooj0810

Commits

Updates net.bytebuddy:byte-buddy from 1.18.11 to 1.18.14

Release notes

Sourced from net.bytebuddy:byte-buddy's releases.

Byte Buddy 1.18.14

  • Avoid exposure of the agent argument on the command line of the process that is spawned for an external attachment.
  • Avoid the resolution of symbolic links when the Gradle plugin deletes a folder recursively.
  • Limit the nesting depth that is accepted when parsing a generic type signature to avoid an exhaustion of the stack for a malformed class file.
  • Sign all deployed files using sigstore, in addition to the existing GPG signature.
  • Validate entry names when the Android plugin retains a file to avoid the propagation of path traversals.

Byte Buddy 1.18.13

  • Actually include the SBOM within the published artifacts.
  • Avoid propagation of path traversals that are contained in jar files which are copied without transformation.
  • Avoid repeated traversal of previously visited type hierarchies to improve performance.
  • Correct Kotlin support of the Gradle plugin to redirect the classes directory of a source set while retaining support for legacy Gradle versions.
  • Create Gradle tasks using Gradle's task registration API if available.

Byte Buddy 1.18.12

  • Automatically support Kotlin in Gradle plugin.
  • Add support for native attach on Windows for ARM64.
  • Correct JNA injector which accidentally created on based on Unsafe.
Changelog

Sourced from net.bytebuddy:byte-buddy's changelog.

14. September 2026: version 1.18.14

  • Avoid exposure of the agent argument on the command line of the process that is spawned for an external attachment.
  • Avoid the resolution of symbolic links when the Gradle plugin deletes a folder recursively.
  • Limit the nesting depth that is accepted when parsing a generic type signature to avoid an exhaustion of the stack for a malformed class file.
  • Sign all deployed files using sigstore, in addition to the existing GPG signature.
  • Validate entry names when the Android plugin retains a file to avoid the propagation of path traversals.

2. September 2026: version 1.18.13

  • Actually include the SBOM within the published artifacts.
  • Avoid propagation of path traversals that are contained in jar files which are copied without transformation.
  • Avoid repeated traversal of previously visited type hierarchies to improve performance.
  • Correct Kotlin support of the Gradle plugin to redirect the classes directory of a source set while retaining support for legacy Gradle versions.
  • Create Gradle tasks using Gradle's task registration API if available.

17. July 2026: version 1.18.12

  • Automatically support Kotlin in Gradle plugin.
  • Correct JNA injector which accidentally created on based on Unsafe.
  • Support dynamic attach on Windows ARM64 by shipping a native attach_hotspot_windows library for win32-aarch64.
Commits
  • 92846cb [publish] Releasing Byte Buddy 1.18.14
  • a8a9f14 [release] Release new version
  • b0fe006 Skip the signature creation for artifacts that are not deployed.
  • c610783 Resolve the signed POM file by the path of the project file.
  • caab321 Sign the deployed POM file and allow for a sigstore dry run.
  • c68a9c1 Supply the agent argument to the attacher process as an environment variable.
  • 3ac9ded Avoid symbolic link resolution on recursive deletion and validate Android ent...
  • 8dbae60 Sign deployed files using sigstore.
  • 5d83cd4 Disable semantic versioning check for protected constructor in abstract class...
  • 172e0f4 Move to method to apply suppression.
  • Additional commits viewable in compare view

Updates net.bytebuddy:byte-buddy-agent from 1.18.11 to 1.18.14

Release notes

Sourced from net.bytebuddy:byte-buddy-agent's releases.

Byte Buddy 1.18.14

  • Avoid exposure of the agent argument on the command line of the process that is spawned for an external attachment.
  • Avoid the resolution of symbolic links when the Gradle plugin deletes a folder recursively.
  • Limit the nesting depth that is accepted when parsing a generic type signature to avoid an exhaustion of the stack for a malformed class file.
  • Sign all deployed files using sigstore, in addition to the existing GPG signature.
  • Validate entry names when the Android plugin retains a file to avoid the propagation of path traversals.

Byte Buddy 1.18.13

  • Actually include the SBOM within the published artifacts.
  • Avoid propagation of path traversals that are contained in jar files which are copied without transformation.
  • Avoid repeated traversal of previously visited type hierarchies to improve performance.
  • Correct Kotlin support of the Gradle plugin to redirect the classes directory of a source set while retaining support for legacy Gradle versions.
  • Create Gradle tasks using Gradle's task registration API if available.

Byte Buddy 1.18.12

  • Automatically support Kotlin in Gradle plugin.
  • Add support for native attach on Windows for ARM64.
  • Correct JNA injector which accidentally created on based on Unsafe.
Changelog

Sourced from net.bytebuddy:byte-buddy-agent's changelog.

14. September 2026: version 1.18.14

  • Avoid exposure of the agent argument on the command line of the process that is spawned for an external attachment.
  • Avoid the resolution of symbolic links when the Gradle plugin deletes a folder recursively.
  • Limit the nesting depth that is accepted when parsing a generic type signature to avoid an exhaustion of the stack for a malformed class file.
  • Sign all deployed files using sigstore, in addition to the existing GPG signature.
  • Validate entry names when the Android plugin retains a file to avoid the propagation of path traversals.

2. September 2026: version 1.18.13

  • Actually include the SBOM within the published artifacts.
  • Avoid propagation of path traversals that are contained in jar files which are copied without transformation.
  • Avoid repeated traversal of previously visited type hierarchies to improve performance.
  • Correct Kotlin support of the Gradle plugin to redirect the classes directory of a source set while retaining support for legacy Gradle versions.
  • Create Gradle tasks using Gradle's task registration API if available.

17. July 2026: version 1.18.12

  • Automatically support Kotlin in Gradle plugin.
  • Correct JNA injector which accidentally created on based on Unsafe.
  • Support dynamic attach on Windows ARM64 by shipping a native attach_hotspot_windows library for win32-aarch64.
Commits
  • 92846cb [publish] Releasing Byte Buddy 1.18.14
  • a8a9f14 [release] Release new version
  • b0fe006 Skip the signature creation for artifacts that are not deployed.
  • c610783 Resolve the signed POM file by the path of the project file.
  • caab321 Sign the deployed POM file and allow for a sigstore dry run.
  • c68a9c1 Supply the agent argument to the attacher process as an environment variable.
  • 3ac9ded Avoid symbolic link resolution on recursive deletion and validate Android ent...
  • 8dbae60 Sign deployed files using sigstore.
  • 5d83cd4 Disable semantic versioning check for protected constructor in abstract class...
  • 172e0f4 Move to method to apply suppression.
  • Additional commits viewable in compare view

Updates com.github.oshi:oshi-core from 7.4.2 to 7.7.0

Release notes

Sourced from com.github.oshi:oshi-core's releases.

Release 7.7.0

New Features
  • #3745: The FFM implementation now reads NetBSD natively, through sysctl, getloadavg, _lwp_self and getrlimit, where it previously ran commands and parsed their output - @​dbwiddis.
  • #3709, #3757: Display.getCurrentMode() returns the mode a display is driven in: its logical and pixel resolution, refresh rate, rotation, and position on the desktop. Display.isBuiltIn() reports whether it is a built-in panel, and Display.isPrimary() whether it is the primary display. All three are available on Windows, macOS, and on Linux and the other UNIX platforms through X11 - @​ayonization, @​dbwiddis.
Bug Fixes and Improvements
  • #3723: Windows Sensors now reads CPU temperature, fan speed and voltage from the ROOT\LibreHardwareMonitor WMI namespace when the LibreHardwareMonitor application is running, in addition to the ROOT\OpenHardwareMonitor namespace it already read. Users running the maintained LibreHardwareMonitor previously got its GPU metrics but no CPU sensor data - @​dbwiddis.
  • #3727: The oshi.os.windows.ohm.disabled and oshi.os.windows.lhm.disabled configuration properties now skip the Open Hardware Monitor and Libre Hardware Monitor WMI namespaces, which OSHI otherwise queries on each sensor read until one returns data. The latter also covers GPU metrics - @​dbwiddis.
  • #3730: Fixed Sensors.getCpuVoltage() on Windows when using the voltage published by Open Hardware Monitor or LibreHardwareMonitor - @​dbwiddis.
  • #3742: NetworkParams.getRoutes() on NetBSD now reads the routing table from the kernel where the JNA native library is available - @​dbwiddis.
  • #3743: Fixed three HWDiskStore faults on NetBSD: read and write byte totals that could decrease between readings, a doubled getTransferTime(), and a 1-byte disk or 512-byte partition size where the size is unknown, which also affected OpenBSD - @​dbwiddis.
  • #3744: Fixed OSProcess naming on NetBSD: getPath() and getName() were truncated to seven characters, and where the kernel withholds a process's arguments, getCommandLine() returned ps's (command) placeholder and getName() kept its parentheses - @​dbwiddis.
  • #3754: OperatingSystem.getProcessId() and getThreadId() return 0 when the ID is unknown on every platform. On NetBSD without JNA, getThreadId() returned a Java thread ID, and on failure some implementations returned -1, which led getCurrentProcess() to return an arbitrary process on the BSDs, Solaris and AIX. getProcess() with a negative PID now returns null on Solaris and AIX - @​dbwiddis.

Full change log

Release 7.6.1

Bug Fixes and Improvements
  • #3710: Fix the bnd imports for oshi-core and oshi-core-ffm to make the JSpecify annotations optional, so both bundles resolve in an OSGi container without JSpecify - @​dbwiddis.

Full change log

Release 7.6.0

Maven Central Publication Change

The oshi-dist zip is no longer published to Maven Central; download it from the GitHub release instead.

New Features
  • #3652: oshi-metrics reports the OpenTelemetry reserved state for system.filesystem.usage and system.filesystem.utilization, alongside the existing used and free. The three states partition the filesystem, so the usage gauges sum to system.filesystem.limit and the utilization gauges sum to 1.0 - @​dbwiddis.
  • #3660, #3678: Display.getDevicePort() reports the port a display is attached to, and on systems with X RandR, Display.getOutputName() gives the name xrandr --output accepts for it - @​ayonization, @​dbwiddis.
Behavior Changes
  • #3705: OSDesktopWindow.getLocAndSize() returns a copy of the window's Rectangle and the constructor copies the one it is given, so the class honors the immutability its documentation promises. ApplicationInfo.getAdditionalInfo() returns an unmodifiable map. Code that wrote through either return value silently mutated OSHI's own state; it now has no effect, or throws UnsupportedOperationException for the map - @​dbwiddis.
  • #3705: UsbDevice.compareTo() breaks ties on the unique device ID, vendor ID, product ID and serial number after comparing names, and AbstractUsbDevice implements equals() and hashCode() over the same fields. Two distinct devices sharing a name previously compared equal, so a TreeSet or SortedSet of them kept only one. The ordering is now a default method on UsbDevice, so every implementation shares it - @​dbwiddis.
Bug Fixes and Improvements
  • #3651: OSFileStore now guarantees 0 <= getUsableSpace() <= getFreeSpace() <= getTotalSpace() on every platform. The three values are read by separate queries, so on a ZFS dataset or a swap-backed tmpfs they could previously contradict each other; they are now clamped downward to restore the ordering - @​dbwiddis.
  • #3657: Fix the TcpState for the FFM implementation of InternetProtocolStats.getConnections() on macOS and set the process cap from the kernel - @​dbwiddis.
  • #3661: Setting oshi.os.windows.hkeyperfdata to false now also skips the registry when fetching thread counters, matching its documented behavior and the existing handling for processes - @​dbwiddis.
  • #3662: Reading the processor description from the registry no longer throws when a value is missing. CentralProcessor.getFeatureFlags() on Windows now reports every processor feature IsProcessorFeaturePresent() accepts, matching the PF_ defines in winnt.h - @​dbwiddis.
  • #3665: NetworkParams.getRoutes() reads the routing table from the kernel through a NET_RT_DUMP sysctl on macOS, FreeBSD, DragonFly BSD and OpenBSD, rather than by running netstat twice - @​dbwiddis.
  • #3670: NetworkParams.getHostName() on Linux reads the kernel host name from /proc/sys/kernel/hostname in every backend, fixing the native-free implementation, which truncated a fully qualified name at the first dot and reported localhost when the name did not resolve - @​dbwiddis.
  • #3671: NetworkParams.getHostName() and getDomainName() report the empty-string sentinel when the local host name does not resolve, rather than the loopback address's localhost. NetBSD is the most affected platform, having no native host name query of its own - @​dbwiddis.

... (truncated)

Changelog

Sourced from com.github.oshi:oshi-core's changelog.

7.7.0 (2026-09-29)

New Features
  • #3745: The FFM implementation now reads NetBSD natively, through sysctl, getloadavg, _lwp_self and getrlimit, where it previously ran commands and parsed their output - @​dbwiddis.
  • #3709, #3757: Display.getCurrentMode() returns the mode a display is driven in: its logical and pixel resolution, refresh rate, rotation, and position on the desktop. Display.isBuiltIn() reports whether it is a built-in panel, and Display.isPrimary() whether it is the primary display. All three are available on Windows, macOS, and on Linux and the other UNIX platforms through X11 - @​ayonization, @​dbwiddis.
Bug Fixes and Improvements
  • #3723: Windows Sensors now reads CPU temperature, fan speed and voltage from the ROOT\LibreHardwareMonitor WMI namespace when the LibreHardwareMonitor application is running, in addition to the ROOT\OpenHardwareMonitor namespace it already read. Users running the maintained LibreHardwareMonitor previously got its GPU metrics but no CPU sensor data - @​dbwiddis.
  • #3727: The oshi.os.windows.ohm.disabled and oshi.os.windows.lhm.disabled configuration properties now skip the Open Hardware Monitor and Libre Hardware Monitor WMI namespaces, which OSHI otherwise queries on each sensor read until one returns data. The latter also covers GPU metrics - @​dbwiddis.
  • #3730: Fixed Sensors.getCpuVoltage() on Windows when using the voltage published by Open Hardware Monitor or LibreHardwareMonitor - @​dbwiddis.
  • #3742: NetworkParams.getRoutes() on NetBSD now reads the routing table from the kernel where the JNA native library is available - @​dbwiddis.
  • #3743: Fixed three HWDiskStore faults on NetBSD: read and write byte totals that could decrease between readings, a doubled getTransferTime(), and a 1-byte disk or 512-byte partition size where the size is unknown, which also affected OpenBSD - @​dbwiddis.
  • #3744: Fixed OSProcess naming on NetBSD: getPath() and getName() were truncated to seven characters, and where the kernel withholds a process's arguments, getCommandLine() returned ps's (command) placeholder and getName() kept its parentheses - @​dbwiddis.
  • #3754: OperatingSystem.getProcessId() and getThreadId() return 0 when the ID is unknown on every platform. On NetBSD without JNA, getThreadId() returned a Java thread ID, and on failure some implementations returned -1, which led getCurrentProcess() to return an arbitrary process on the BSDs, Solaris and AIX. getProcess() with a negative PID now returns null on Solaris and AIX - @​dbwiddis.

7.6.0 (2026-08-23), 7.6.1 (2026-09-01)

The oshi-dist zip is no longer published to Maven Central; download it from the GitHub release instead.

New Features
  • #3652: oshi-metrics reports the OpenTelemetry reserved state for system.filesystem.usage and system.filesystem.utilization, alongside the existing used and free. The three states partition the filesystem, so the usage gauges sum to system.filesystem.limit and the utilization gauges sum to 1.0 - @​dbwiddis.
  • #3660, #3678: Display.getDevicePort() reports the port a display is attached to, and on systems with X RandR, Display.getOutputName() gives the name xrandr --output accepts for it - @​ayonization, @​dbwiddis.
Behavior Changes
  • #3705: OSDesktopWindow.getLocAndSize() returns a copy of the window's Rectangle and the constructor copies the one it is given, so the class honors the immutability its documentation promises. ApplicationInfo.getAdditionalInfo() returns an unmodifiable map. Code that wrote through either return value silently mutated OSHI's own state; it now has no effect, or throws UnsupportedOperationException for the map - @​dbwiddis.
  • #3705: UsbDevice.compareTo() breaks ties on the unique device ID, vendor ID, product ID and serial number after comparing names, and AbstractUsbDevice implements equals() and hashCode() over the same fields. Two distinct devices sharing a name previously compared equal, so a TreeSet or SortedSet of them kept only one. The ordering is now a default method on UsbDevice, so every implementation shares it - @​dbwiddis.
Bug Fixes and Improvements
  • #3651: OSFileStore now guarantees 0 <= getUsableSpace() <= getFreeSpace() <= getTotalSpace() on every platform. The three values are read by separate queries, so on a ZFS dataset or a swap-backed tmpfs they could previously contradict each other; they are now clamped downward to restore the ordering - @​dbwiddis.
  • #3657: Fix the TcpState for the FFM implementation of InternetProtocolStats.getConnections() on macOS and set the process cap from the kernel - @​dbwiddis.
  • #3661: Setting oshi.os.windows.hkeyperfdata to false now also skips the registry when fetching thread counters, matching its documented behavior and the existing handling for processes - @​dbwiddis.
  • #3662: Reading the processor description from the registry no longer throws when a value is missing. CentralProcessor.getFeatureFlags() on Windows now reports every processor feature IsProcessorFeaturePresent() accepts, matching the PF_ defines in winnt.h - @​dbwiddis.
  • #3665: NetworkParams.getRoutes() reads the routing table from the kernel through a NET_RT_DUMP sysctl on macOS, FreeBSD, DragonFly BSD and OpenBSD, rather than by running netstat twice - @​dbwiddis.
  • #3670: NetworkParams.getHostName() on Linux reads the kernel host name from /proc/sys/kernel/hostname in every backend, fixing the native-free implementation, which truncated a fully qualified name at the first dot and reported localhost when the name did not resolve - @​dbwiddis.
  • #3671: NetworkParams.getHostName() and getDomainName() report the empty-string sentinel when the local host name does not resolve, rather than the loopback address's localhost. NetBSD is the most affected platform, having no native host name query of its own - @​dbwiddis.
  • #3672, #3674: CentralProcessor frequencies and PhysicalProcessor.getEfficiency() on Apple Silicon are correct regardless of call order and on the M4 and M5 generations. Frequencies previously fell back to a 2.4 GHz placeholder unless getProcessorIdentifier() happened to be called first, were reported a thousand times too low on the M4 and later, and a chip with more or fewer than two kinds of core was misclassified - @​dbwiddis.
  • #3675: CentralProcessor.getCurrentFreq() on Apple Silicon can report the frequency the hardware actually ran at, rather than a nominal maximum that never changes. Set oshi.os.mac.cpu.frequency.ioreport to true; it is opt-in because it holds a subscription to a private framework for the lifetime of the process - @​dbwiddis.
  • #3680: oshi-metrics reads a disk or network interface once per memoizer expiration window rather than once per meter, so a scrape makes one query where it previously made five or seven, and the meters of one device report the same reading. A rate computed across two of them, such as errors per packet, is now comparable - @​dbwiddis.
  • #3681: GpuStats.getGpuUtilization() on Linux reads NVIDIA GPU utilization from NVML. It previously read only the amdgpu/i915/xe sysfs paths, none of which the NVIDIA driver exposes, so an NVIDIA card always returned the -1 sentinel - @​Krillsson.
  • #3686: GpuStats.getGpuUtilization() on Windows reads NVIDIA utilization from NVML and AMD utilization from ADL, matching the source order of every other metric on the class. It previously ran only LibreHardwareMonitor and a PDH engine-tick delta, which needs two samples, so the first call returned the -1 sentinel - @​dbwiddis.
  • #3687: GpuStats.getSharedMemoryUsed() on Linux reports the amdgpu GTT memory in use rather than always returning -1, and GraphicsCard.getVRam() on an amdgpu card reports the driver's own figure rather than the memory BAR size parsed from lspci or lshw. Several GpuStats metrics on Linux also now return the -1 sentinel when the sysfs file behind them is absent; they previously reported 0, so a card whose hwmon directory omits power1_average read as drawing 0.0 W - @​dbwiddis.
  • #3698: OSProcess.getCurrentWorkingDirectory() on macOS returns the directory rather than an empty string in the FFM implementation, and NetworkParams.getDomainName() on macOS and the BSDs returns the canonical name rather than an empty string in both implementations - @​dbwiddis.

... (truncated)

Commits
  • fa2eb03 [maven-release-plugin] prepare release oshi-parent-7.7.0
  • 4471a73 7.7.0 Release
  • f9b03d0 Update vmactions/openbsd-vm digest to 5f7b2c9 (#3759)
  • 698d32a Update vmactions/openindiana-vm digest to d82e630 (#3760)
  • 5b4722a Update dependency com.puppycrawl.tools:checkstyle to v14.3.0 (#3761)
  • 0a4401b Update vmactions/netbsd-vm digest to c8a0d7d (#3758)
  • 171d674 Add isPrimary to the Display API (#3709)
  • b71fdfa Add Display.getCurrentMode() and isBuiltIn() (#3757)
  • 7ad5445 Update vmactions/freebsd-vm digest to a2f9a41 (#3756)
  • 726d2d0 Update vmactions/dragonflybsd-vm digest to 4ab776f (#3755)
  • Additional commits viewable in compare view

Updates org.springdoc:springdoc-openapi-starter-webmvc-ui from 3.0.3 to 3.1.1

Release notes

Sourced from org.springdoc:springdoc-openapi-starter-webmvc-ui's releases.

springdoc-openapi v3.1.1 released!

Security

  • GHSA-6f5m-mhjg-qwxq – MCP tool callbacks do not encode path parameters, allowing request retargeting
  • GHSA-4v2q-56v7-2cpw – MCP transport, admin and dashboard endpoints are exposed by default
  • GHSA-m4cg-mhpg-rh2r – MCP audit events record credentials and request/response bodies without redaction
  • GHSA-5f9r-4mc4-qh3c – Unbounded MCP pending-confirmation store allows memory exhaustion
  • GHSA-jcgg-59c8-w4wh – MCP request context in a ThreadLocal can leak headers between concurrent WebFlux requests
  • GHSA-rhhx-6j8h-8cvw – Unbounded per-locale OpenAPI cache allows memory exhaustion via Accept-Language
  • GHSA-c925-vm88-mpp9 – Scalar starters trust client-supplied forwarded headers and render from a shared mutable bean
  • CVE-2026-75838 – Cross-site scripting in the DOMPurify bundled with swagger-ui, addressed by upgrading swagger-ui to 5.32.14

Added

  • #3340 – Describe JsonNullable values without their Java wrapper
  • #3325 – Manage the swagger artifacts in springdoc-openapi-bom, so that modules holding only the annotations stay in lockstep
  • #3321 – Add springdoc.login-endpoint.username-example and springdoc.login-endpoint.password-example to document the Spring Security login endpoint

Changed

  • MCP is now opt-in. Set springdoc.ai.mcp.enabled=true, and springdoc.ai.mcp.dashboard-enabled=true for the dashboard
  • The Scalar starters no longer register forwarded-header handling. Set server.forward-headers-strategy=framework (or native) behind a trusted proxy
  • Add springdoc.cache.max-entries (default 100) to bound the per-locale OpenAPI cache
  • Add springdoc.ai.mcp.audit.redact (default true) to mask secrets in MCP audit events
  • Document that the MCP approval flow is a confirmation step, not an authorization control
  • Document the security policy and the release versioning scheme
  • #3351 – java.time.Duration, LocalTime and OffsetTime are now resolved by swagger-core instead of being forced to a bare string, so they carry a format (duration and partial-time respectively for the first two)
  • A property whose type only implements Set indirectly (LinkedHashSet, TreeSet, …) is now described with uniqueItems: true, following swagger-api/swagger-core#5265
  • Upgrade swagger-core to version 2.2.55
  • Upgrade swagger-ui to version 5.32.14

Fixed

  • #3328, #3337 – /v3/api-docs fails with a NullPointerException when spring-hateoas is on the classpath without HateoasProperties
  • #3314 – Json Processing Exception occurred is logged for every constrained parameter whose schema is not a JsonSchema
  • #3317 – An injected HttpHeaders parameter is described as a schema
  • #3332 – The properties a Kotlin entity inherits from an @Embeddable are missing from the Spring Data REST schemas
  • #3320 – @Order and Ordered ignored when applying customizers
  • #3319 – A Page nested in another schema is not replaced by PagedModel
  • #3313 – Springdoc auto-configurations rely on unspecified auto-configuration ordering
  • #3331 – Validation annotations declared inside Optional parameters are dropped
  • #3322 – Validation annotations on a container's type argument leak between parameters
  • #3315 – An OAS 3.1 JsonSchema cannot be cloned through JSON
  • #3300 – TYPE_USE annotations on @ParameterObject fields are not passed along
  • #3341 – Stabilize Spring Data Sort and Pageable schema property order
  • #3338 – Kotlin nullability interpretation of the Any? type
  • #3136 – A Spring Data REST association to a non-exported entity expands its @EmbeddedId and @MapsId fields recursively in the response schemas
  • The Spring Data REST response post-processing rewrote an association property in place, so the …Response refs could leak into the schema shared with the request body representation

New Contributors

... (truncated)

Changelog

Sourced from org.springdoc:springdoc-openapi-starter-webmvc-ui's changelog.

[3.1.1] - 2026-09-06

Security

  • GHSA-6f5m-mhjg-qwxq – MCP tool callbacks do not encode path parameters, allowing request retargeting
  • GHSA-4v2q-56v7-2cpw – MCP transport, admin and dashboard endpoints are exposed by default
  • GHSA-m4cg-mhpg-rh2r – MCP audit events record credentials and request/response bodies without redaction
  • GHSA-5f9r-4mc4-qh3c – Unbounded MCP pending-confirmation store allows memory exhaustion
  • GHSA-jcgg-59c8-w4wh – MCP request context in a ThreadLocal can leak headers between concurrent WebFlux requests
  • GHSA-rhhx-6j8h-8cvw – Unbounded per-locale OpenAPI cache allows memory exhaustion via Accept-Language
  • GHSA-c925-vm88-mpp9 – Scalar starters trust client-supplied forwarded headers and render from a shared mutable bean
  • CVE-2026-75838 – Cross-site scripting in the DOMPurify bundled with swagger-ui, addressed by upgrading swagger-ui to 5.32.14

Added

  • #3340 – Describe JsonNullable values without their Java wrapper
  • #3325 – Manage the swagger artifacts in springdoc-openapi-bom, so that modules holding only the annotations stay in lockstep
  • #3321 – Add springdoc.login-endpoint.username-example and springdoc.login-endpoint.password-example to document the Spring Security login endpoint

Changed

  • MCP is now opt-in. Set springdoc.ai.mcp.enabled=true, and springdoc.ai.mcp.dashboard-enabled=true for the dashboard
  • The Scalar starters no longer register forwarded-header handling. Set server.forward-headers-strategy=framework (or native) behind a trusted proxy
  • Add springdoc.cache.max-entries (default 100) to bound the per-locale OpenAPI cache
  • Add springdoc.ai.mcp.audit.redact (default true) to mask secrets in MCP audit events
  • Document that the MCP approval flow is a confirmation step, not an authorization control
  • Document the security policy and the release versioning scheme
  • #3351 – java.time.Duration, LocalTime and OffsetTime are now resolved by swagger-core instead of being forced to a bare string, so they carry a format (duration and partial-time respectively for the first two)
  • A property whose type only implements Set indirectly (LinkedHashSet, TreeSet, …) is now described with uniqueItems: true, following swagger-api/swagger-core#5265
  • Upgrade swagger-core to version 2.2.55
  • Upgrade swagger-ui to version 5.32.14

Fixed

  • #3328, #3337 – /v3/api-docs fails with a NullPointerException when spring-hateoas is on the classpath without HateoasProperties
  • #3314 – Json Processing Exception occurred is logged for every constrained parameter whose schema is not a JsonSchema
  • #3317 – An injected HttpHeaders parameter is described as a schema
  • #3332 – The properties a Kotlin entity inherits from an @Embeddable are missing from the Spring Data REST schemas
  • #3320 – @Order and Ordered ignored when applying customizers
  • #3319 – A Page nested in another schema is not replaced by PagedModel
  • #3313 – Springdoc auto-configurations rely on unspecified auto-configuration ordering
  • #3331 – Validation annotations declared inside Optional parameters are dropped
  • #3322 – Validation annotations on a container's type argument leak between parameters
  • #3315 – An OAS 3.1 JsonSchema cannot be cloned through JSON
  • #3300 – TYPE_USE annotations on @ParameterObject fields are not passed along
  • #3341 – Stabilize Spring Data Sort and Pageable schema property order
  • #3338 – Kotlin nullability interpretation of the Any? type
  • #3136 – A Spring Data REST association to a non-exported entity expands its @EmbeddedId and @MapsId fields recursively in the response schemas
  • The Spring Data REST response post-processing rewrote an association property in place, so the …Response refs could leak into the schema shared with the request body representation

... (truncated)

Commits
  • 1cc87a7 [maven-release-plugin] prepare release v3.1.1
  • 4e8ac26 docs: record the swagger-ui 5.32.14 upgrade as a security fix for 3.1.1
  • 958c79a Merge swagger-core 2.2.55 upgrade
  • cf7d7c7 Upgrade swagger-core to 2.2.55
  • 186adb3 Record the swagger-core 2.2.54 upgrade in the changelog
  • 2498ffb Merge pull request #3351 from Mattias-Sehlstedt/update-swagger-core
  • d78abd9 upgrade swagger-core from 2.2.53 to 2.2.54
  • 9f7f099 Rewrite a copy of a Spring Data REST association property
  • f47060e Record #3321 in the changelog and align the buildRequestBody indent
  • ccb2fc0 Merge pull request #3323 from Mattias-Sehlstedt/feature/3321-login-example-va...
  • Additional commits viewable in compare view

Updates com.azure:azure-data-tables from 12.5.11 to 12.5.12

Commits
  • c923efa Prepare patch release 20260818 (#50173)
  • c6b40a1 Add WireMock dependency version 2.35.2 to external dependencies
  • 8c93dca Increment package versions for commvaultcontentstore releases (#50171)
  • f3e1875 Configurations: 'specification/compute/resource-manager/Microsoft.Compute/Co...
  • d39ffca Prepare OTel AutoConfigure release v1.6.0 (#50167)
  • ac5a002 [AzureMonitorAutoConfigure] Validate ingestion and Live Metrics redirect targ...
  • 53e6420 Increment versions for core releases (#50152)
  • 168277b Update resources TypeSpec commit (#50164)
  • 6cc7989 Migrate resource manager resources generation to TypeSpec (#50111)
  • 645e30c Increment package versions for network auto-releases (

Bumps the minor-and-patch group with 10 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| [org.springframework.modulith:spring-modulith-bom](https://github.com/spring-projects/spring-modulith) | `2.1.0` | `2.1.1` |
| [net.bytebuddy:byte-buddy](https://github.com/raphw/byte-buddy) | `1.18.11` | `1.18.14` |
| [net.bytebuddy:byte-buddy-agent](https://github.com/raphw/byte-buddy) | `1.18.11` | `1.18.14` |
| [com.github.oshi:oshi-core](https://github.com/oshi/oshi) | `7.4.2` | `7.7.0` |
| [org.springdoc:springdoc-openapi-starter-webmvc-ui](https://github.com/springdoc/springdoc-openapi) | `3.0.3` | `3.1.1` |
| [com.azure:azure-data-tables](https://github.com/Azure/azure-sdk-for-java) | `12.5.11` | `12.5.12` |
| [org.jsoup:jsoup](https://github.com/jhy/jsoup) | `1.22.2` | `1.23.2` |
| [org.projectlombok:lombok](https://github.com/projectlombok/lombok) | `1.18.46` | `1.18.48` |
| org.slf4j:slf4j-api | `2.0.18` | `2.0.20` |
| [gradle-wrapper](https://github.com/gradle/gradle) | `9.6.1` | `9.8.0` |



Updates `org.springframework.modulith:spring-modulith-bom` from 2.1.0 to 2.1.1
- [Release notes](https://github.com/spring-projects/spring-modulith/releases)
- [Changelog](https://github.com/spring-projects/spring-modulith/blob/main/release-train-settings.xml)
- [Commits](spring-projects/spring-modulith@2.1.0...2.1.1)

Updates `net.bytebuddy:byte-buddy` from 1.18.11 to 1.18.14
- [Release notes](https://github.com/raphw/byte-buddy/releases)
- [Changelog](https://github.com/raphw/byte-buddy/blob/master/release-notes.md)
- [Commits](raphw/byte-buddy@byte-buddy-1.18.11...byte-buddy-1.18.14)

Updates `net.bytebuddy:byte-buddy-agent` from 1.18.11 to 1.18.14
- [Release notes](https://github.com/raphw/byte-buddy/releases)
- [Changelog](https://github.com/raphw/byte-buddy/blob/master/release-notes.md)
- [Commits](raphw/byte-buddy@byte-buddy-1.18.11...byte-buddy-1.18.14)

Updates `com.github.oshi:oshi-core` from 7.4.2 to 7.7.0
- [Release notes](https://github.com/oshi/oshi/releases)
- [Changelog](https://github.com/oshi/oshi/blob/master/CHANGELOG.md)
- [Commits](oshi/oshi@oshi-parent-7.4.2...oshi-parent-7.7.0)

Updates `org.springdoc:springdoc-openapi-starter-webmvc-ui` from 3.0.3 to 3.1.1
- [Release notes](https://github.com/springdoc/springdoc-openapi/releases)
- [Changelog](https://github.com/springdoc/springdoc-openapi/blob/main/CHANGELOG.md)
- [Commits](springdoc/springdoc-openapi@v3.0.3...v3.1.1)

Updates `com.azure:azure-data-tables` from 12.5.11 to 12.5.12
- [Release notes](https://github.com/Azure/azure-sdk-for-java/releases)
- [Commits](Azure/azure-sdk-for-java@com.azure+azure-data-tables_12.5.11...com.azure+azure-data-tables_12.5.12)

Updates `org.jsoup:jsoup` from 1.22.2 to 1.23.2
- [Release notes](https://github.com/jhy/jsoup/releases)
- [Changelog](https://github.com/jhy/jsoup/blob/master/CHANGES.md)
- [Commits](jhy/jsoup@jsoup-1.22.2...jsoup-1.23.2)

Updates `org.projectlombok:lombok` from 1.18.46 to 1.18.48
- [Changelog](https://github.com/projectlombok/lombok/blob/master/doc/changelog.markdown)
- [Commits](projectlombok/lombok@v1.18.46...v1.18.48)

Updates `org.slf4j:slf4j-api` from 2.0.18 to 2.0.20

Updates `gradle-wrapper` from 9.6.1 to 9.8.0
- [Release notes](https://github.com/gradle/gradle/releases)
- [Commits](gradle/gradle@v9.6.1...v9.8.0)

---
updated-dependencies:
- dependency-name: org.springframework.modulith:spring-modulith-bom
  dependency-version: 2.1.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: net.bytebuddy:byte-buddy
  dependency-version: 1.18.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: net.bytebuddy:byte-buddy-agent
  dependency-version: 1.18.14
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: com.github.oshi:oshi-core
  dependency-version: 7.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: org.springdoc:springdoc-openapi-starter-webmvc-ui
  dependency-version: 3.1.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: com.azure:azure-data-tables
  dependency-version: 12.5.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: org.jsoup:jsoup
  dependency-version: 1.23.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: org.projectlombok:lombok
  dependency-version: 1.18.48
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: org.slf4j:slf4j-api
  dependency-version: 2.0.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: gradle-wrapper
  dependency-version: 9.8.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Oct 3, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants