Skip to content

NIFI-15762 - Bump Log4J to 2.25.4, GCP SDK to 26.79.0, AWS SDK to 2.42.23, and others#11069

Merged
exceptionfactory merged 2 commits intoapache:mainfrom
pvillard31:NIFI-15762
Mar 30, 2026
Merged

NIFI-15762 - Bump Log4J to 2.25.4, GCP SDK to 26.79.0, AWS SDK to 2.42.23, and others#11069
exceptionfactory merged 2 commits intoapache:mainfrom
pvillard31:NIFI-15762

Conversation

@pvillard31
Copy link
Copy Markdown
Contributor

@pvillard31 pvillard31 commented Mar 29, 2026

Summary

NIFI-15762 - Bump Log4J to 2.25.4, GCP SDK to 26.79.0, AWS SDK to 2.42.23, and others

Tracking

Please complete the following tracking steps prior to pull request creation.

Issue Tracking

Pull Request Tracking

  • Pull Request title starts with Apache NiFi Jira issue number, such as NIFI-00000
  • Pull Request commit message starts with Apache NiFi Jira issue number, as such NIFI-00000
  • Pull request contains commits signed with a registered key indicating Verified status

Pull Request Formatting

  • Pull Request based on current revision of the main branch
  • Pull Request refers to a feature branch with one commit containing changes

Verification

Please indicate the verification steps performed prior to pull request creation.

Build

  • Build completed using ./mvnw clean install -P contrib-check
    • JDK 21
    • JDK 25

Licensing

  • New dependencies are compatible with the Apache License 2.0 according to the License Policy
  • New dependencies are documented in applicable LICENSE and NOTICE files

Documentation

  • Documentation formatting appears as expected in rendered files

…2.23, and others

- Spotbugs Maven Plugin from 4.9.8.2 to 4.9.8.3 - https://github.com/spotbugs/spotbugs-maven-plugin/releases/tag/spotbugs-maven-plugin-4.9.8.3
- LZ4 Java from 1.10.1 to 1.10.4 - https://github.com/yawkat/lz4-java/releases/tag/v1.10.4
- Brotli4J from 1.20.0 to 1.21.0 - https://github.com/hyperxpro/Brotli4j/releases/tag/v1.21.0
- GCP SDK BOM from 26.78.0 to 26.79.0 - https://github.com/googleapis/java-cloud-bom/releases/tag/v26.79.0
- AWS SDK BOM from 2.42.21 to 2.42.23 - https://github.com/aws/aws-sdk-java-v2/blob/master/CHANGELOG.md
- Neo4J Driver from 6.0.3 to 6.0.4 - https://github.com/neo4j/neo4j-java-driver/releases/tag/6.0.4
- HiveMQ MQTT Client from 1.3.12 to 1.3.13 - https://github.com/hivemq/hivemq-mqtt-client/releases/tag/v1.3.13
- Wire from 6.1.0 to 6.2.0 - https://square.github.io/wire/changelog/#version-620
- Camel Salesforce from 4.18.0 to 4.18.1 - https://github.com/apache/camel/releases/tag/camel-4.18.1
- QuestDB from 9.3.3 to 9.3.4 - https://github.com/questdb/questdb/releases/tag/9.3.4
- Jackson 3 from 3.1.0 to 3.1.1 - https://github.com/FasterXML/jackson/wiki/Jackson-Release-3.1.1
- Log4J2 from 2.25.3 to 2.25.4 - https://github.com/apache/logging-log4j2/releases/tag/rel%2F2.25.4
- Nimbus OAuth2 OIDC from 11.35 to 11.36 - https://bitbucket.org/connect2id/oauth-2.0-sdk-with-openid-connect-extensions/src/master/CHANGELOG.txt
- PMD from 7.22.0 to 7.23.0 - https://github.com/pmd/pmd/releases/tag/pmd_releases%2F7.23.0

Signed-off-by: Pierre Villard <pierre.villard.fr@gmail.com>
@pvillard31 pvillard31 added the dependencies Pull requests that update a dependency file label Mar 29, 2026
@pvillard31
Copy link
Copy Markdown
Contributor Author

Reverting brotli4j version change and filed hyperxpro/Brotli4j#246

@exceptionfactory exceptionfactory merged commit 31c1bd4 into apache:main Mar 30, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants