Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump spring-core from 5.3.26 to 5.3.27 #3018

Merged

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Apr 13, 2023

Bumps spring-core from 5.3.26 to 5.3.27.

Release notes

Sourced from spring-core's releases.

v5.3.27

⭐ New Features

  • Limit string concatenation in SpEL expressions #30331
  • Limit SpEL expression length #30329
  • Disable variable assignment in SimpleEvaluationContext #30327
  • Introduce StringUtils.truncate() #30291
  • Introduce ObjectUtils.nullSafeConciseToString() #30287
  • Make HttpComponentsHeadersAdapter#getFirst nullable #30269

🐞 Bug Fixes

  • Fix regression in ReactorServerHttpRequest related to IPV6 Zone id with "%" #30314
  • SSE breaks with indenting serializer in WebMvc.fn #30302
  • Increase max regex length in SpEL expressions #30298
  • NullPointerException on timeout in HttpComponentsClientHttpConnector when using Apache HttpComponents #30246
  • Wrong MockRestRequestMatchers.header() method in spring-test being invoked (JDK issue?) #30235
  • TypeNotPresentException: org/springframework/cglib/proxy/NoOp not present on Java 17 #30228
  • Refine generic type management in AbstractMessageWriterResultHandler #30215
  • MvcUriComponentsBuilder.fromMethodCall breaks for controller with CharSequence return type #30212
  • Handle all exceptions for stored proc output param retrieval in SharedEntityManagerCreator #30164

πŸ“” Documentation

  • Fix @PathVariable reference documentation code snippets #30258
  • Fix example in Javadoc for @EnableWebSocket #30187
  • Fix anchor in link to "Web on Reactive Stack" chapter #30163

πŸ”¨ Dependency Upgrades

  • Upgrade to Reactor 2020.0.31 #30315
Commits
  • 08bc1a0 Release v5.3.27
  • 6bfb94a Disable variable assignment in SimpleEvaluationContext
  • ebc8265 Limit SpEL expression length
  • 8645746 Limit string concatenation in SpEL expressions
  • be129dc Change max regex length in SpEL expressions to 1000
  • 8bb1b3e Upgrade to Netty 4.1.91 and Checkstyle 10.9.3
  • 6abd822 Upgrade to Reactor 2020.0.31
  • 1c43a4c Fix regression in ReactorServerHttpRequest
  • 423f221 Remove flaky assertion to fix build on JDK 17
  • 0bad69d Fix SSE with indenting serializer in WebMvc.fn
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [spring-core](https://github.com/spring-projects/spring-framework) from 5.3.26 to 5.3.27.
- [Release notes](https://github.com/spring-projects/spring-framework/releases)
- [Commits](spring-projects/spring-framework@v5.3.26...v5.3.27)

---
updated-dependencies:
- dependency-name: org.springframework:spring-core
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added the dependabot: Maven A dependency upgrade for Maven raised by Dependabot label Apr 13, 2023
@github-actions
Copy link

github-actions bot commented Apr 13, 2023

JUnit test results

βŸβ€„4β€ˆ009 files  Β±0β€‚β€ƒβŸβ€„4β€ˆ009 suites  Β±0   1m 12s ⏱️ +13s
19β€ˆ411 tests Β±0  19β€ˆ367 βœ”οΈ Β±0  44 πŸ’€ Β±0  0 ❌ Β±0 
19β€ˆ499 runs  Β±0  19β€ˆ455 βœ”οΈ Β±0  44 πŸ’€ Β±0  0 ❌ Β±0 

Results for commit f9b05df. ± Comparison against base commit 410bb5a.

This pull request removes 1188 and adds 1080 tests. Note that renamed tests count towards both.


  

  b
  -1000000000-01-01T00:00:00Z
  07:10
  07:10Z
  07:23
  07:23Z
  2017-03-08T07:10
  2017-03-08T07:10-05:00[America/New_York]
…
AbstractTemporalAssert isCloseTo ‑ should fail if actual is null (ArgumentsAccessor)[1] org.assertj.core.api.InstantAssert@1, org.assertj.core.api.InstantAssert@1, org.assertj.core.data.TemporalUnitWithinOffset@51, 2017-03-12T07:12:00Z, 2017-03-12T07:12:00Z, 2017-03-08T07:10:00Z, 2017-03-08T07:10:00Z, 
Expecting actual:
  2017-03-12T07:10:00Z
to be close to:
  2017-03-08T07:10:00Z
within 50 Hours but difference was 96 Hours, null
AbstractTemporalAssert isCloseTo ‑ should fail if actual is null (ArgumentsAccessor)[2] org.assertj.core.api.InstantAssert@1, org.assertj.core.api.InstantAssert@1, org.assertj.core.data.TemporalUnitWithinOffset@21, 2017-03-12T07:10:00.001Z, 2017-03-12T07:10:00.001Z, -1000000000-01-01T00:00:00Z, -1000000000-01-01T00:00:00Z, 
Expecting actual:
  2017-03-12T07:10:00Z
to be close to:
  -1000000000-01-01T00:00:00Z
within 2 Millis but difference was PT8765837682367H10M, null
AbstractTemporalAssert isCloseTo ‑ should fail if actual is null (ArgumentsAccessor)[3] org.assertj.core.api.LocalDateTimeAssert@1, org.assertj.core.api.LocalDateTimeAssert@1, org.assertj.core.data.TemporalUnitWithinOffset@51, 2017-03-10T07:12, 2017-03-10T07:12:00, 2017-03-08T07:10, 2017-03-08T07:10:00, 
Expecting actual:
  2017-03-12T07:10
to be close to:
  2017-03-08T07:10
within 50 Hours but difference was 96 Hours, null
AbstractTemporalAssert isCloseTo ‑ should fail if actual is null (ArgumentsAccessor)[4] org.assertj.core.api.LocalDateAssert@1, org.assertj.core.api.LocalDateAssert@1, org.assertj.core.data.TemporalUnitWithinOffset@22, 2017-03-10, 2017-03-10, 2017-03-27, 2017-03-27, 
Expecting actual:
  2017-03-12
to be close to:
  2017-03-27
within 3 Days but difference was 15 Days, org.assertj.core.data.TemporalUnitWithinOffset@20
AbstractTemporalAssert isCloseTo ‑ should fail if actual is null (ArgumentsAccessor)[5] org.assertj.core.api.LocalTimeAssert@1, org.assertj.core.api.LocalTimeAssert@1, org.assertj.core.data.TemporalUnitWithinOffset@24, 07:12, 07:12:00, 07:23, 07:23:00, 
Expecting actual:
  07:10
to be close to:
  07:23
within 5 Minutes but difference was 13 Minutes, org.assertj.core.data.TemporalUnitWithinOffset@20
AbstractTemporalAssert isCloseTo ‑ should fail if actual is null (ArgumentsAccessor)[6] org.assertj.core.api.OffsetDateTimeAssert@1, org.assertj.core.api.OffsetDateTimeAssert@1, org.assertj.core.data.TemporalUnitWithinOffset@29, 2017-03-12T07:12Z, 2017-03-12T07:12:00Z, 2017-03-12T07:23Z, 2017-03-12T07:23:00Z, 
Expecting actual:
  2017-03-12T07:10Z
to be close to:
  2017-03-12T07:23Z
within 10 Minutes but difference was 13 Minutes, null
AbstractTemporalAssert isCloseTo ‑ should fail if actual is null (ArgumentsAccessor)[7] org.assertj.core.api.ZonedDateTimeAssert@1, org.assertj.core.api.ZonedDateTimeAssert@1, org.assertj.core.data.TemporalUnitLessThanOffset@7e, 2017-03-10T07:12-05:00[America/New_York], 2017-03-10T07:12:00-05:00[America/New_York], 2017-03-08T07:10-05:00[America/New_York], 2017-03-08T07:10:00-05:00[America/New_York], 
Expecting actual:
  2017-03-12T07:10-04:00[America/New_York]
to be close to:
  2017-03-08T07:10-05:00[America/New_York]
by less than 95 Hours but difference was 95 Hours, null
AbstractTemporalAssert isCloseTo ‑ should fail if actual is null (ArgumentsAccessor)[8] org.assertj.core.api.OffsetTimeAssert@1, org.assertj.core.api.OffsetTimeAssert@1, org.assertj.core.data.TemporalUnitWithinOffset@21, 07:12Z, 07:12:00Z, 07:23Z, 07:23:00Z, 
Expecting actual:
  07:10Z
to be close to:
  07:23Z
within 2 Minutes but difference was 13 Minutes, org.assertj.core.data.TemporalUnitWithinOffset@20
AbstractTemporalAssert isCloseTo ‑ should fail if offset parameter is null (ArgumentsAccessor)[1] org.assertj.core.api.InstantAssert@1, org.assertj.core.api.InstantAssert@1, org.assertj.core.data.TemporalUnitWithinOffset@51, 2017-03-12T07:12:00Z, 2017-03-12T07:12:00Z, 2017-03-08T07:10:00Z, 2017-03-08T07:10:00Z, 
Expecting actual:
  2017-03-12T07:10:00Z
to be close to:
  2017-03-08T07:10:00Z
within 50 Hours but difference was 96 Hours, null
AbstractTemporalAssert isCloseTo ‑ should fail if offset parameter is null (ArgumentsAccessor)[2] org.assertj.core.api.InstantAssert@1, org.assertj.core.api.InstantAssert@1, org.assertj.core.data.TemporalUnitWithinOffset@21, 2017-03-12T07:10:00.001Z, 2017-03-12T07:10:00.001Z, -1000000000-01-01T00:00:00Z, -1000000000-01-01T00:00:00Z, 
Expecting actual:
  2017-03-12T07:10:00Z
to be close to:
  -1000000000-01-01T00:00:00Z
within 2 Millis but difference was PT8765837682367H10M, null
…

♻️ This comment has been updated with latest results.

@scordio scordio merged commit 15b9679 into main Apr 13, 2023
@scordio scordio deleted the dependabot/maven/org.springframework-spring-core-5.3.27 branch April 13, 2023 22:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependabot: Maven A dependency upgrade for Maven raised by Dependabot
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

1 participant