Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Bump spring-framework-bom from 5.3.20 to 5.3.21 #6664

Merged

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jun 15, 2022

Proposed changelog entries

  • Bump spring-framework-bom from 5.3.20 to 5.3.21

Dependabot section

Bumps spring-framework-bom from 5.3.20 to 5.3.21.

Release notes

Sourced from spring-framework-bom's releases.

v5.3.21

⭐ New Features

  • Expose ThreadPoolTaskExecutor queue size and capacity for metrics #28583
  • Lazily initialize DataSize.PATTERN #28560
  • MockMvcWebTestClient forces HTTP POST for multipart requests #28545
  • Support for CGLIB BeanCopier utility on JDK 17 #28530
  • Allow changes to org.springframework.web log category at runtime #28477

🐞 Bug Fixes

  • Avoid eager instantiation of non-singleton FactoryBean in getBeanNamesForType #28616
  • ObjectToObjectConverter doesn't consider return type of static methods #28609
  • Charset for input stream ignored in Jaxb2XmlDecoder #28599
  • Support RouterFunction ordering in Spring MVC #28595
  • Always construct new exception on error in DefaultWebClient #28550
  • HierarchicalUriComponents::getPort() throws NumberFormatException with invalid port in URI #28521
  • Cannot serve static resources with spaces from "file:" location when using PathPattern and UrlPathHelper is set to not decode #27791

📔 Documentation

  • Fix code sample for nested router functions #28603
  • Fix Kotlin example for @Required #28590
  • Fix Kotlin example for dependency injection with static factory method #28589
  • Update documentation regarding nested test class support #28579
  • Update reference docs to use PropertySourcesPlaceholderConfigurer #28572
  • Fix typo in webflux.adoc #28542
  • Fix Javadoc for DatabaseClient #28520
  • CachingConnectionFactory with WebLogic JMS not caching producers nor consumers #28500
  • Fix Kotlin example for static factory method #28399

🔨 Dependency Upgrades

  • Upgrade to Reactor 2020.0.20 #28612

❤️ Contributors

We'd like to thank all the contributors who worked on this release!

Commits
  • fcfb168 Release v5.3.21
  • c75da7b Upgrade to Reactor 2020.0.20
  • eeac150 Polish contribution
  • 0ce9516 Avoid eager instantiation of non-singleton FactoryBean in getBeanNamesForType
  • e47cc44 Polish DefaultListableBeanFactoryTests
  • 57db73d Upgrade to Tomcat 9.0.64, Jackson 2.12.7, Apache Johnzon 1.2.18, OpenPDF 1.3....
  • d7be1e0 Polishing
  • 30c873b Move NestedServletExceptionTests to spring-web module
  • e72b0a0 Document limitations for MessageProducer/Consumer caching with WebLogic JMS
  • f8b41c1 Consistent support for setContextClass in CGLIB beans package
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [spring-framework-bom](https://github.com/spring-projects/spring-framework) from 5.3.20 to 5.3.21.
- [Release notes](https://github.com/spring-projects/spring-framework/releases)
- [Commits](spring-projects/spring-framework@v5.3.20...v5.3.21)

---
updated-dependencies:
- dependency-name: org.springframework:spring-framework-bom
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Jun 15, 2022
@timja timja added the ready-for-merge The PR is ready to go, and it will be merged soon if there is no negative feedback label Jun 16, 2022
@timja
Copy link
Member

timja commented Jun 16, 2022

This PR is now ready for merge, after ~24 hours, we will merge it if there's no negative feedback.

Thanks!

@timja timja added the skip-changelog Should not be shown in the changelog label Jun 16, 2022
@basil
Copy link
Member

basil commented Jun 16, 2022

This is an upgrade of a production library, not a build or test library, so I could see an argument for including it in the Jenkins changelog, linking to the upstream changelog. That is what I have done in the recent past for other Spring Framework and Spring Security library upgrades at least. Though these upgrades generally do not contain any changes that are of impact to Jenkins users, I think it sends a positive message to the Jenkins community that we are staying up-to-date with library upgrades for major components.

@timja
Copy link
Member

timja commented Jun 16, 2022

Feel free to add it.

@basil
Copy link
Member

basil commented Jun 16, 2022

Feel free to add it.

If and when I am interested in adding it, I will do so. Thanks!

@basil
Copy link
Member

basil commented Jun 22, 2022

I am removing the skip-changelog label because this is an upgrade to a major production (not test) library that I think should be mentioned in the changelog. I am removing the ready-for-merge label because per the maintainer checklist, "before the changes are marked as ready-for-merge, […] Proposed changelog entries are accurate, human-readable, and in the imperative mood."

@basil basil removed ready-for-merge The PR is ready to go, and it will be merged soon if there is no negative feedback skip-changelog Should not be shown in the changelog labels Jun 22, 2022
@timja timja added the ready-for-merge The PR is ready to go, and it will be merged soon if there is no negative feedback label Jun 22, 2022
@timja timja merged commit c52001b into master Jun 22, 2022
@timja timja deleted the dependabot/maven/org.springframework-spring-framework-bom-5.3.21 branch June 22, 2022 22:21
@timja
Copy link
Member

timja commented Jun 22, 2022

I am removing the skip-changelog label because this is an upgrade to a major production (not test) library that I think should be mentioned in the changelog. I am removing the ready-for-merge label because per the maintainer checklist, "before the changes are marked as ready-for-merge, […] Proposed changelog entries are accurate, human-readable, and in the imperative mood."

it would have been far less effort for you to add yourself than type and link that.

basil pushed a commit to basil/jenkins that referenced this pull request Jun 24, 2022
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file java Pull requests that update Java code ready-for-merge The PR is ready to go, and it will be merged soon if there is no negative feedback
Projects
None yet
2 participants