Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Oct 24, 2025

Bumps org.springframework.boot:spring-boot-dependencies from 3.4.9 to 3.4.11.

Release notes

Sourced from org.springframework.boot:spring-boot-dependencies's releases.

v3.4.11

🐞 Bug Fixes

  • In an uber war, value of the Sbom-Location manifest attribute does not match the SBOM's actual location #47735
  • Homebrew formula for the CLI should use libexec #47696
  • When virtual threads are enabled, embedded Jetty does not use recommended virtual thread configuration #47690
  • ClientHttpRequestFactoryRuntimeHints is missing timeout methods with Duration overloads #47675
  • OnBeanCondition no longer correctly finds annotations on scoped target proxy beans #47633
  • JavaVersion doesn't work reliably in native-image #47619
  • In an uber war, value of the Sbom-Location manifest attribute does not match the SBOM's actual location #47408
  • LiquibaseEndpoint always uses defaultSchema instead of liquibaseSchema #47300
  • Signed jar verification fails when nested in an uber war running on an Oracle JVM #47284
  • Bitnami legacy images are not automatically detected #46983

📔 Documentation

  • Dependency management for Maven AntRun Plugin is missing changelog link #47732
  • Developing Your First Spring Boot Application has outdated tools #47699
  • Include deprecated configuration properties in the reference documentation #47622
  • Aggregated Javadoc should link to the proper version of JakartaEE #47592
  • Use non-deprecated syntax to configure sourceCompatibility #47339
  • Fix link to Framework's @Bean annotation #47329
  • Update managed dependency version override examples in documentation #47304

🔨 Dependency Upgrades

  • Upgrade to ActiveMQ 6.1.8 #47766
  • Upgrade to Angus Mail 2.0.5 #47506
  • Upgrade to Classmate 1.7.1 #47507
  • Upgrade to Glassfish JAXB 4.0.6 #47508
  • Upgrade to Groovy 4.0.29 #47711
  • Upgrade to Hibernate 6.6.33.Final #47509
  • Upgrade to HttpCore5 5.3.6 #47510
  • Upgrade to Jakarta Mail 2.1.5 #47511
  • Upgrade to Jakarta XML Bind 4.0.4 #47237
  • Upgrade to Jaybird 5.0.10.java11 #47513
  • Upgrade to Jetty 12.0.29 #47726
  • Upgrade to Jetty Reactive HTTPClient 4.0.12 #47514
  • Upgrade to jOOQ 3.19.27 #47516
  • Upgrade to Logback 1.5.20 #47712
  • Upgrade to Lombok 1.18.42 #47518
  • Upgrade to Micrometer 1.14.12 #47446
  • Upgrade to Micrometer Tracing 1.4.11 #47447
  • Upgrade to MSSQL JDBC 12.8.2.jre11 #47607
  • Upgrade to Netty 4.1.128.Final #47647
  • Upgrade to Postgresql 42.7.8 #47519
  • Upgrade to Pulsar 3.3.9 #47520
  • Upgrade to R2DBC H2 1.0.1.RELEASE #47727
  • Upgrade to R2DBC Postgresql 1.0.8.RELEASE #47521
  • Upgrade to Reactor Bom 2024.0.11 #47448

... (truncated)

Commits
  • 2ab8820 Release v3.4.11
  • 4525a0c Merge pull request #47284 from DKARAGODIN
  • 43d91ae Write signature files to uber wars for Oracle Java 17 verification
  • b361a1f Upgrade to Spring Batch 5.2.4
  • 9238928 Upgrade to ActiveMQ 6.1.8
  • c249d95 Omit properties deprecated at error level from new appendix
  • 92e61fd Merge pull request #47416 from dependabot[bot]
  • ba27452 Polish "Bump gradle/actions from 4.4.4 to 5.0.0"
  • f44def3 Bump gradle/actions from 4.4.4 to 5.0.0
  • 67c25d9 Upgrade to Spring Integration 6.4.8
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [org.springframework.boot:spring-boot-dependencies](https://github.com/spring-projects/spring-boot) from 3.4.9 to 3.4.11.
- [Release notes](https://github.com/spring-projects/spring-boot/releases)
- [Commits](spring-projects/spring-boot@v3.4.9...v3.4.11)

---
updated-dependencies:
- dependency-name: org.springframework.boot:spring-boot-dependencies
  dependency-version: 3.4.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants