From 95d1382c4bced3fa31ecf34ee35abd210b760598 Mon Sep 17 00:00:00 2001
From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com>
Date: Tue, 30 Jul 2024 11:24:50 +0800
Subject: [PATCH] ORC-1750: Bump `protobuf-java` to 3.25.4
Bumps [com.google.protobuf:protobuf-java](https://github.com/protocolbuffers/protobuf) from 3.25.3 to 3.25.4.
Commits
e915ce2
Updating version.json and repo version numbers to: 25.4
6eb8b00
Merge pull request #17525 from protocolbuffers/fix-25.x-staleness
d491c4c
Merge branch '25.x' into fix-25.x-staleness
314fc8b
drop 2.7 in linux test (#17524)
eb1fdd3
fix targets
a5dadc3
update bazel to 6.3.2
c3b9b4f
backport staleness changes to 25.x
fb0520e
Merge pull request #17514 from protocolbuffers/cp-25
bdb1f75
Downgrade CMake to 3.29 to workaround Abseil issue.
165cf12
Check that size is non-negative when reading string or bytes in StreamDecoder.
- Additional commits viewable in compare view
Most Recent Ignore Conditions Applied to This Pull Request
| Dependency Name | Ignore Conditions |
| --- | --- |
| com.google.protobuf:protobuf-java | [>= 4.a, < 5] |
[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=com.google.protobuf:protobuf-java&package-manager=maven&previous-version=3.25.3&new-version=3.25.4)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores)
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `dependabot rebase`.
[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
---
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
- `dependabot rebase` will rebase this PR
- `dependabot recreate` will recreate this PR, overwriting any edits that have been made to it
- `dependabot merge` will merge this PR after your CI passes on it
- `dependabot squash and merge` will squash and merge this PR after your CI passes on it
- `dependabot cancel merge` will cancel a previously requested merge and block automerging
- `dependabot reopen` will reopen this PR if it is closed
- `dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
- `dependabot show ignore conditions` will show all of the ignore conditions of the specified dependency
- `dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
- `dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
- `dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Closes #1991 from dependabot[bot]/dependabot/maven/java/com.google.protobuf-protobuf-java-3.25.4.
Authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Signed-off-by: Shaoyun Chen
(cherry picked from commit 21a63806a8222dbee79f0476431133bcf147c04d)
Signed-off-by: Dongjoon Hyun
---
java/pom.xml | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/java/pom.xml b/java/pom.xml
index 04b960e2e1..3075d391d9 100644
--- a/java/pom.xml
+++ b/java/pom.xml
@@ -78,7 +78,7 @@
1.0.0
2024-08-11T21:58:47Z
- 3.25.3
+ 3.25.4
2.0.11
2.8.1
3.0.0-M5