Skip to content

Conversation

@renovate
Copy link
Contributor

@renovate renovate bot commented May 31, 2023

Mend Renovate logo banner

This PR contains the following updates:

Package Change Age Adoption Passing Confidence
com.graphql-java:graphql-java 20.3 -> 20.7 age adoption passing confidence

Release Notes

graphql-java/graphql-java (com.graphql-java:graphql-java)

v20.7: 20.7

This is a small bugfix release which includes a backport of PR #​3334, which fixes a type unwrapping bug.

What's Changed

Full Changelog: graphql-java/graphql-java@v20.6...v20.7

v20.6: 20.6

This 20.6 release includes a critical Guava fix.

The 20.5 release had a problem where Guava classes were not shaded due to a configuration error. Do not use version 20.5 and please use this version 20.6 instead.

What's Changed

Full Changelog: graphql-java/graphql-java@v20.5...v20.6

v20.5: 20.5

Do not use version 20.5. Please use version 20.6 instead.

Version 20.5 contains a problem where Guava files were not shaded due to a configuration error. This is fixed in 20.6.


This is a bugfix release which backports two default value fixes.

This release also updates Guava to keep security scanners happy. Some security scanners had incorrectly flagged an earlier patched version of Guava as still vulnerable to CVE-2023-2976. To avoid incorrect security alerts, we have updated Guava to a version that all scanners will accept as patched. More details in #​3279 and #​3263.

What's Changed

Full Changelog: graphql-java/graphql-java@v20.4...v20.5

v20.4: 20.4

This is a special release with only one commit: updating the version of Guava to 32.0.0 to address CVE-2023-2976.

graphql-java shades in selected classes of Guava. Although this library does not use any of the code described in the CVE, we received reports in #​3239 that the Guava POM inside the jar was incorrectly triggering security scanners. We'd prefer to keep those security scanners happy and upgrade the Guava version.

What's Changed

Full Changelog: graphql-java/graphql-java@v20.3...v20.4


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot changed the title Update dependency com.graphql-java:graphql-java to v20.3 Update dependency com.graphql-java:graphql-java to v20.3 - autoclosed May 31, 2023
@renovate renovate bot closed this May 31, 2023
@renovate renovate bot deleted the renovate/graphql.java branch May 31, 2023 19:33
@renovate renovate bot changed the title Update dependency com.graphql-java:graphql-java to v20.3 - autoclosed Update dependency com.graphql-java:graphql-java to v20.3 May 31, 2023
@renovate renovate bot reopened this May 31, 2023
@renovate renovate bot restored the renovate/graphql.java branch May 31, 2023 22:17
@renovate renovate bot changed the title Update dependency com.graphql-java:graphql-java to v20.3 Update dependency com.graphql-java:graphql-java to v20.3 - autoclosed Jun 2, 2023
@renovate renovate bot closed this Jun 2, 2023
@renovate renovate bot changed the title Update dependency com.graphql-java:graphql-java to v20.3 - autoclosed Update dependency com.graphql-java:graphql-java to v20.3 Jun 2, 2023
@renovate renovate bot reopened this Jun 2, 2023
@renovate renovate bot force-pushed the renovate/graphql.java branch from d327176 to 97f8e86 Compare June 2, 2023 04:14
@renovate renovate bot changed the title Update dependency com.graphql-java:graphql-java to v20.3 Update dependency com.graphql-java:graphql-java to v20.3 - autoclosed Jun 2, 2023
@renovate renovate bot closed this Jun 2, 2023
@renovate renovate bot deleted the renovate/graphql.java branch June 2, 2023 06:30
@renovate renovate bot changed the title Update dependency com.graphql-java:graphql-java to v20.3 - autoclosed Update dependency com.graphql-java:graphql-java to v20.3 Jun 8, 2023
@renovate renovate bot reopened this Jun 8, 2023
@renovate renovate bot restored the renovate/graphql.java branch June 8, 2023 09:23
@renovate renovate bot force-pushed the renovate/graphql.java branch from 97f8e86 to 455098b Compare June 8, 2023 09:23
@renovate renovate bot changed the title Update dependency com.graphql-java:graphql-java to v20.3 Update dependency com.graphql-java:graphql-java to v20.4 Jun 8, 2023
@renovate renovate bot force-pushed the renovate/graphql.java branch from 455098b to 07d718e Compare August 31, 2023 04:29
@renovate renovate bot changed the title Update dependency com.graphql-java:graphql-java to v20.4 Update dependency com.graphql-java:graphql-java to v20.5 Aug 31, 2023
@renovate renovate bot force-pushed the renovate/graphql.java branch from 07d718e to 03256f0 Compare September 4, 2023 09:02
@renovate renovate bot changed the title Update dependency com.graphql-java:graphql-java to v20.5 Update dependency com.graphql-java:graphql-java to v20.6 Sep 4, 2023
@renovate renovate bot changed the title Update dependency com.graphql-java:graphql-java to v20.6 Update dependency com.graphql-java:graphql-java to v20.7 Oct 24, 2023
@renovate renovate bot force-pushed the renovate/graphql.java branch from 03256f0 to c7d5fb8 Compare October 24, 2023 00:27
@donbeave donbeave merged commit a338371 into main Nov 17, 2023
@donbeave donbeave deleted the renovate/graphql.java branch November 17, 2023 15:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants