Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Resolve open backend dependabots #15903

Merged
merged 48 commits into from
Sep 24, 2024
Merged

Conversation

thetaurean
Copy link
Collaborator

@thetaurean thetaurean commented Sep 17, 2024

This PR resolves a collection of dependabots, 23 in total.

Test Steps:

  1. Run test suites

Changes

  • Dependencies updated (see commit messages or linked issues for which)

Checklist

Testing

  • Tested locally?
  • Ran ./prime test or ./gradlew testSmoke against local Docker ReportStream container?

Linked Issues

dependabot bot and others added 30 commits August 25, 2024 08:14
Bumps [plugin.spring](https://github.com/JetBrains/kotlin) from 2.0.0 to 2.0.20.
- [Release notes](https://github.com/JetBrains/kotlin/releases)
- [Changelog](https://github.com/JetBrains/kotlin/blob/v2.0.20/ChangeLog.md)
- [Commits](JetBrains/kotlin@v2.0.0...v2.0.20)

---
updated-dependencies:
- dependency-name: plugin.spring
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps org.apache.commons:commons-compress from 1.26.2 to 1.27.1.

---
updated-dependencies:
- dependency-name: org.apache.commons:commons-compress
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps org.apache.commons:commons-compress from 1.26.2 to 1.27.1.

---
updated-dependencies:
- dependency-name: org.apache.commons:commons-compress
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [org.yaml:snakeyaml](https://bitbucket.org/snakeyaml/snakeyaml) from 2.2 to 2.3.
- [Commits](https://bitbucket.org/snakeyaml/snakeyaml/branches/compare/snakeyaml-2.3..snakeyaml-2.2)

---
updated-dependencies:
- dependency-name: org.yaml:snakeyaml
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [com.avast.gradle.docker-compose](https://github.com/avast/gradle-docker-compose-plugin) from 0.17.7 to 0.17.8.
- [Release notes](https://github.com/avast/gradle-docker-compose-plugin/releases)
- [Commits](avast/gradle-docker-compose-plugin@0.17.7...0.17.8)

---
updated-dependencies:
- dependency-name: com.avast.gradle.docker-compose
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps org.apache.commons:commons-lang3 from 3.15.0 to 3.17.0.

---
updated-dependencies:
- dependency-name: org.apache.commons:commons-lang3
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [com.googlecode.libphonenumber:libphonenumber](https://github.com/google/libphonenumber) from 8.13.42 to 8.13.45.
- [Release notes](https://github.com/google/libphonenumber/releases)
- [Changelog](https://github.com/google/libphonenumber/blob/master/making-metadata-changes.md)
- [Commits](google/libphonenumber@v8.13.42...v8.13.45)

---
updated-dependencies:
- dependency-name: com.googlecode.libphonenumber:libphonenumber
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps the log4j group with 5 updates in the /prime-router directory:

| Package | From | To |
| --- | --- | --- |
| org.apache.logging.log4j:log4j-api | `2.23.1` | `2.24.0` |
| org.apache.logging.log4j:log4j-core | `2.23.1` | `2.24.0` |
| org.apache.logging.log4j:log4j-slf4j2-impl | `2.23.1` | `2.24.0` |
| org.apache.logging.log4j:log4j-layout-template-json | `2.23.1` | `2.24.0` |
| [org.apache.logging.log4j:log4j-api-kotlin](https://github.com/apache/logging-log4j-kotlin) | `1.4.0` | `1.5.0` |



Updates `org.apache.logging.log4j:log4j-api` from 2.23.1 to 2.24.0

Updates `org.apache.logging.log4j:log4j-core` from 2.23.1 to 2.24.0

Updates `org.apache.logging.log4j:log4j-slf4j2-impl` from 2.23.1 to 2.24.0

Updates `org.apache.logging.log4j:log4j-layout-template-json` from 2.23.1 to 2.24.0

Updates `org.apache.logging.log4j:log4j-api-kotlin` from 1.4.0 to 1.5.0
- [Release notes](https://github.com/apache/logging-log4j-kotlin/releases)
- [Commits](apache/logging-log4j-kotlin@rel/1.4.0...rel/1.5.0)

---
updated-dependencies:
- dependency-name: org.apache.logging.log4j:log4j-api
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: log4j
- dependency-name: org.apache.logging.log4j:log4j-core
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: log4j
- dependency-name: org.apache.logging.log4j:log4j-slf4j2-impl
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: log4j
- dependency-name: org.apache.logging.log4j:log4j-layout-template-json
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: log4j
- dependency-name: org.apache.logging.log4j:log4j-api-kotlin
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: log4j
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps the swagger group in /prime-router with 2 updates: io.swagger.core.v3:swagger-jaxrs2 and io.swagger.core.v3.swagger-gradle-plugin.


Updates `io.swagger.core.v3:swagger-jaxrs2` from 2.2.22 to 2.2.23

Updates `io.swagger.core.v3.swagger-gradle-plugin` from 2.2.22 to 2.2.23

---
updated-dependencies:
- dependency-name: io.swagger.core.v3:swagger-jaxrs2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: swagger
- dependency-name: io.swagger.core.v3.swagger-gradle-plugin
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: swagger
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps the flyway group with 3 updates in the /prime-router directory: org.flywaydb:flyway-database-postgresql, [org.flywaydb:flyway-core](https://github.com/flyway/flyway) and org.flywaydb.flyway.


Updates `org.flywaydb:flyway-database-postgresql` from 10.17.0 to 10.18.0

Updates `org.flywaydb:flyway-core` from 10.17.0 to 10.18.0
- [Release notes](https://github.com/flyway/flyway/releases)
- [Commits](flyway/flyway@flyway-10.17.0...flyway-10.18.0)

Updates `org.flywaydb.flyway` from 10.17.0 to 10.18.0

---
updated-dependencies:
- dependency-name: org.flywaydb:flyway-database-postgresql
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: flyway
- dependency-name: org.flywaydb:flyway-core
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: flyway
- dependency-name: org.flywaydb.flyway
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: flyway
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps the azurecore group in /prime-router with 2 updates: [com.azure:azure-core](https://github.com/Azure/azure-sdk-for-java) and [com.azure:azure-core-http-netty](https://github.com/Azure/azure-sdk-for-java).


Updates `com.azure:azure-core` from 1.51.0 to 1.52.0
- [Release notes](https://github.com/Azure/azure-sdk-for-java/releases)
- [Commits](Azure/azure-sdk-for-java@azure-core_1.51.0...azure-core_1.52.0)

Updates `com.azure:azure-core-http-netty` from 1.15.3 to 1.15.4
- [Release notes](https://github.com/Azure/azure-sdk-for-java/releases)
- [Commits](Azure/azure-sdk-for-java@azure-core-http-netty_1.15.3...azure-core-http-netty_1.15.4)

---
updated-dependencies:
- dependency-name: com.azure:azure-core
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: azurecore
- dependency-name: com.azure:azure-core-http-netty
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: azurecore
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [com.squareup.okio:okio](https://github.com/square/okio) from 3.9.0 to 3.9.1.
- [Release notes](https://github.com/square/okio/releases)
- [Changelog](https://github.com/square/okio/blob/master/CHANGELOG.md)
- [Commits](square/okio@parent-3.9.0...3.9.1)

---
updated-dependencies:
- dependency-name: com.squareup.okio:okio
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [com.azure:azure-identity](https://github.com/Azure/azure-sdk-for-java) from 1.13.2 to 1.13.3.
- [Release notes](https://github.com/Azure/azure-sdk-for-java/releases)
- [Commits](Azure/azure-sdk-for-java@azure-identity_1.13.2...azure-identity_1.13.3)

---
updated-dependencies:
- dependency-name: com.azure:azure-identity
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [com.nimbusds:nimbus-jose-jwt](https://bitbucket.org/connect2id/nimbus-jose-jwt) from 9.40 to 9.41.1.
- [Changelog](https://bitbucket.org/connect2id/nimbus-jose-jwt/src/master/CHANGELOG.txt)
- [Commits](https://bitbucket.org/connect2id/nimbus-jose-jwt/branches/compare/9.41.1..9.40)

---
updated-dependencies:
- dependency-name: com.nimbusds:nimbus-jose-jwt
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [org.jetbrains.kotlinx:kotlinx-coroutines-core](https://github.com/Kotlin/kotlinx.coroutines) from 1.8.1 to 1.9.0.
- [Release notes](https://github.com/Kotlin/kotlinx.coroutines/releases)
- [Changelog](https://github.com/Kotlin/kotlinx.coroutines/blob/master/CHANGES.md)
- [Commits](Kotlin/kotlinx.coroutines@1.8.1...1.9.0)

---
updated-dependencies:
- dependency-name: org.jetbrains.kotlinx:kotlinx-coroutines-core
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [org.jetbrains.kotlinx:kotlinx-coroutines-reactor](https://github.com/Kotlin/kotlinx.coroutines) from 1.8.1 to 1.9.0.
- [Release notes](https://github.com/Kotlin/kotlinx.coroutines/releases)
- [Changelog](https://github.com/Kotlin/kotlinx.coroutines/blob/master/CHANGES.md)
- [Commits](Kotlin/kotlinx.coroutines@1.8.1...1.9.0)

---
updated-dependencies:
- dependency-name: org.jetbrains.kotlinx:kotlinx-coroutines-reactor
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
…g.jetbrains.kotlinx-kotlinx-coroutines-reactor-1.9.0' into platform/thetaurean/mass-dependabots
…rg.jetbrains.kotlinx-kotlinx-coroutines-core-1.9.0' into platform/thetaurean/mass-dependabots
…om.nimbusds-nimbus-jose-jwt-9.41.1' into platform/thetaurean/mass-dependabots
…om.azure-azure-identity-1.13.3' into platform/thetaurean/mass-dependabots
…om.squareup.okio-okio-3.9.1' into platform/thetaurean/mass-dependabots
…zurecore-6f1bdbd9e8' into platform/thetaurean/mass-dependabots
…lyway-fbe6211fcc' into platform/thetaurean/mass-dependabots
…om.googlecode.libphonenumber-libphonenumber-8.13.45' into platform/thetaurean/mass-dependabots
…og4j-a2630dd90b' into platform/thetaurean/mass-dependabots
…che.commons-commons-lang3-3.17.0' into platform/thetaurean/mass-dependabots
…om.avast.gradle.docker-compose-0.17.8' into platform/thetaurean/mass-dependabots
…rg.yaml-snakeyaml-2.3' into platform/thetaurean/mass-dependabots
…wagger-22debd9e4a' into platform/thetaurean/mass-dependabots
…che.commons-commons-compress-1.27.1' into platform/thetaurean/mass-dependabots
dependabot bot and others added 5 commits September 17, 2024 16:58
Bumps [com.github.doyaaaaaken:kotlin-csv-jvm](https://github.com/doyaaaaaken/kotlin-csv) from 1.9.3 to 1.10.0.
- [Release notes](https://github.com/doyaaaaaken/kotlin-csv/releases)
- [Commits](jsoizo/kotlin-csv@1.9.3...1.10.0)

---
updated-dependencies:
- dependency-name: com.github.doyaaaaaken:kotlin-csv-jvm
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps `jacksonVersion` from 2.17.1 to 2.17.2.

Updates `com.fasterxml.jackson.dataformat:jackson-dataformat-yaml` from 2.17.1 to 2.17.2
- [Commits](FasterXML/jackson-dataformats-text@jackson-dataformats-text-2.17.1...jackson-dataformats-text-2.17.2)

Updates `com.fasterxml.jackson.core:jackson-databind` from 2.17.1 to 2.17.2
- [Commits](https://github.com/FasterXML/jackson/commits)

---
updated-dependencies:
- dependency-name: com.fasterxml.jackson.dataformat:jackson-dataformat-yaml
  dependency-type: direct:production
  update-type: version-update:semver-patch
- dependency-name: com.fasterxml.jackson.core:jackson-databind
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
…5703)

Bumps azure-storage/azurite from 3.31.0 to 3.32.0.

---
updated-dependencies:
- dependency-name: azure-storage/azurite
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
@thetaurean thetaurean force-pushed the platform/thetaurean/mass-dependabots branch from 741160e to e1207fb Compare September 17, 2024 21:01
@thetaurean thetaurean requested a review from a team as a code owner September 17, 2024 21:01
snesm
snesm previously requested changes Sep 18, 2024
submissions/build.gradle.kts Outdated Show resolved Hide resolved
@snesm snesm self-requested a review September 20, 2024 15:22
@snesm snesm dismissed their stale review September 20, 2024 15:25

corrected by removing PR from this list.

Bumps [com.googlecode.libphonenumber:libphonenumber](https://github.com/google/libphonenumber) from 8.13.42 to 8.13.46.
- [Release notes](https://github.com/google/libphonenumber/releases)
- [Changelog](https://github.com/google/libphonenumber/blob/master/making-metadata-changes.md)
- [Commits](google/libphonenumber@v8.13.42...v8.13.46)

---
updated-dependencies:
- dependency-name: com.googlecode.libphonenumber:libphonenumber
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [org.springframework.boot](https://github.com/spring-projects/spring-boot) from 3.3.2 to 3.3.4.
- [Release notes](https://github.com/spring-projects/spring-boot/releases)
- [Commits](spring-projects/spring-boot@v3.3.2...v3.3.4)

---
updated-dependencies:
- dependency-name: org.springframework.boot
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <[email protected]>
…om.googlecode.libphonenumber-libphonenumber-8.13.46' into platform/thetaurean/mass-dependabots
Copy link

sonarcloud bot commented Sep 24, 2024

@thetaurean thetaurean merged commit e5cd452 into master Sep 24, 2024
22 checks passed
@thetaurean thetaurean deleted the platform/thetaurean/mass-dependabots branch September 24, 2024 17:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file java Pull requests that update Java code platform Platform Team security Work Type label to flag work related to security
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants