Skip to content

Bump the alldependencies group across 1 directory with 31 updates - #1979

Open
dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/gradle/alldependencies-40f842c238
Open

dependabot[bot] wants to merge 1 commit into
developfrom
dependabot/gradle/alldependencies-40f842c238

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 28, 2026 •

Copy link
Copy Markdown
Contributor

Bumps the alldependencies group with 31 updates in the / directory:

Package From To
org.openapi.generator 7.15.0 7.25.0
org.slf4j:slf4j-api 2.0.17 2.0.20
org.slf4j:jul-to-slf4j 2.0.17 2.0.20
org.slf4j:jul-to-slf4j 2.0.17 2.0.20
ch.qos.logback:logback-classic 1.5.34 1.6.5
io.opentelemetry.instrumentation:opentelemetry-logback-mdc-1.0 2.29.0-alpha 2.31.1-alpha
io.opentelemetry:opentelemetry-api 1.63.0 1.66.0
io.opentelemetry:opentelemetry-sdk 1.63.0 1.66.0
io.opentelemetry:opentelemetry-exporter-logging 1.63.0 1.66.0
io.opentelemetry:opentelemetry-sdk 1.63.0 1.66.0
io.opentelemetry:opentelemetry-exporter-logging 1.63.0 1.66.0
io.opentelemetry.instrumentation:opentelemetry-instrumentation-api 2.29.0 2.31.1
com.google.errorprone:error_prone_annotations 2.15.0 2.50.0
io.swagger.core.v3:swagger-core 2.2.23 2.2.55
io.dropwizard.metrics:metrics-core 4.2.12 4.2.40
io.dropwizard.metrics:metrics-servlets 4.2.12 4.2.40
io.dropwizard.metrics:metrics-servlets 4.2.12 4.2.40
io.prometheus:prometheus-metrics-instrumentation-dropwizard 1.6.1 1.9.0
io.prometheus:prometheus-metrics-exporter-servlet-javax 1.6.1 1.9.0
io.prometheus:prometheus-metrics-exporter-servlet-javax 1.6.1 1.9.0
com.fasterxml.jackson.core:jackson-databind 2.22.2 2.22.3
com.fasterxml.jackson.dataformat:jackson-dataformat-csv 2.22.2 2.22.3
com.fasterxml.jackson.datatype:jackson-datatype-jsr310 2.22.2 2.22.3
com.fasterxml.jackson.dataformat:jackson-dataformat-xml 2.22.2 2.22.3
com.fasterxml.jackson.datatype:jackson-datatype-jdk8 2.22.2 2.22.3
com.fasterxml.jackson.dataformat:jackson-dataformat-csv 2.22.2 2.22.3
com.fasterxml.jackson.datatype:jackson-datatype-jsr310 2.22.2 2.22.3
com.fasterxml.jackson.dataformat:jackson-dataformat-xml 2.22.2 2.22.3
com.fasterxml.jackson.datatype:jackson-datatype-jdk8 2.22.2 2.22.3
io.jsonwebtoken:jjwt-api 0.11.5 0.13.0
io.jsonwebtoken:jjwt-jackson 0.11.5 0.13.0
io.jsonwebtoken:jjwt-impl 0.11.5 0.13.0
io.jsonwebtoken:jjwt-jackson 0.11.5 0.13.0
io.jsonwebtoken:jjwt-impl 0.11.5 0.13.0
com.adobe.testing:s3mock-testcontainers 5.2.2 5.2.3
com.oracle.database.jdbc:ojdbc11 23.26.1.0.0 23.26.3.0.0
org.freemarker:freemarker 2.3.32 2.3.35
com.github.javaparser:javaparser-core 3.26.2 3.28.2
com.github.javaparser:javaparser-symbol-solver-core 3.26.2 3.28.2
com.github.javaparser:javaparser-symbol-solver-core 3.26.2 3.28.2
org.apache.tomcat.embed:tomcat-embed-core 9.0.121 9.0.122
org.apache.tomcat.embed:tomcat-embed-jasper 9.0.121 9.0.122
org.apache.tomcat:tomcat-jdbc 9.0.121 9.0.122
org.apache.tomcat.embed:tomcat-embed-jasper 9.0.121 9.0.122
org.apache.tomcat:tomcat-jdbc 9.0.121 9.0.122

Updates org.openapi.generator from 7.15.0 to 7.25.0

Updates org.slf4j:slf4j-api from 2.0.17 to 2.0.20

Updates org.slf4j:jul-to-slf4j from 2.0.17 to 2.0.20

Updates org.slf4j:jul-to-slf4j from 2.0.17 to 2.0.20

Updates ch.qos.logback:logback-classic from 1.5.34 to 1.6.5

Release notes

Sourced from ch.qos.logback:logback-classic's releases.

Logback 1.6.5

2026-09-30 Release of logback version 1.6.5

• Fixed a vulnerability CVE-2026-104721 closely related to CVE-2026-19880. The fix in version 1.6.3, which strips forward and backward slashes from MDC values, was insufficient. An MDC value could still contain relative path components such as .., variable references such as /, or characters that are special in file name patterns and email addresses. This latest vulnerability was found and reported by François Martin (GitHub: @​martinfrancois, https://github.com/martinfrancois).

MDCBasedDiscriminator, used by SiftingAppender, now rejects MDC values instead of stripping characters from them. An MDC value is rejected if it is empty, if it is longer than 64 characters, if it contains the sequence .., or if it contains any of the following characters: / \ $ { } [ ] ( ) | ? * + % , @. When an MDC value is rejected, the discriminator returns the value of its DefaultValue property. A warning is emitted for each rejected value. These warnings are rate-limited.

• When compression is enabled, TimeBasedRollingPolicy and SizeAndTimeBasedRollingPolicy now also remove old log files that were never compressed, for example because the application was not running at rollover time. Previously, such files were ignored by maxHistory and accumulated indefinitely. This issue was discussed in discussions/1032. See TimeBasedRollingPolicy.

• SimpleInvocationGate, deprecated in version 1.6.3, is now marked for removal. Use FixedIntervalInvocationGate instead.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit d1b829dcdb9fd98511c64401beb1419a9c9384aa associated with the tag v_1.6.5. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Logback 1.6.4

2026-09-24 Release of logback version 1.6.4

• Variable substitution is again applied to the scan attribute of the <configuration> element. The scanning refactoring in version 1.5.27 had dropped substitution, so values such as ${logback.scan.enabled:-true} were no longer resolved. As before version 1.5.27, an unrecognized non-empty value turns scanning on. The same substitution now applies to the scan attribute of <propertiesConfigurator>. This regression was reported in issues/1065 by vaibhavjain2.

• OutputStreamAppender and FileAppender now handle stateful encoders. The Encoder interface has a new default method called isStateful(), which returns false. An encoder that keeps state between calls to encode() can return true. For such encoders, the appender holds its write lock while encoding and while writing, so the output of concurrent appends cannot interleave. Stateless encoders still encode outside the lock, so their performance does not change. Existing encoders need no changes.

• Several race conditions in OutputStreamAppender and FileAppender were fixed. The appender is now marked started and the encoder header is written while the same lock is held, so a concurrent append can no longer write an event before the header. After acquiring the lock, the appender checks again whether it has been stopped, so no event is written after the footer. In prudent mode, FileAppender now encodes and writes each event while holding the lock.

• Fixed a data race on the logger count in LoggerContext. Loggers are created under the lock of their parent logger, so loggers with different parents could be created at the same time and increments of the shared counter could be lost. As a result, LoggerContext.size() could return a value lower than the actual number of loggers. The counter is now an AtomicInteger. This issue was reported in issues/1038 by hcantunc. The fix was contributed in PR #1055 by seonwoo_jung.

• TimeBasedRollingPolicy now supports half-day periods. Date patterns with the AM/PM marker, for example %d{yyyy-MM-dd-a}, used to be detected as daily and rolled over only at midnight. They now roll over at both 00:00 and 12:00. This issue was reported in issues/976 by shakthifuture. The fix was contributed in PR #1051 by seonwoo_jung. See TimeBasedRollingPolicy.

• If org.jline.jansi.AnsiConsole cannot be found on the class path, JansiConsoleAppender now emits warnings that explain how to add org.jline:jansi-core and then writes to the plain console stream. See codes.html#missingJlineJansi.

• The unused ch.qos.logback.classic.util.LogbackMDCAdapterSimple class was removed. LogbackMDCAdapter remains the default MDC adapter.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit 07d291ca0d280bc5da934ec9ff5f1da634fd7937 associated with the tag v_1.6.4. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Full Changelog: qos-ch/logback@v_1.6.3...v_1.6.4

Logback 1.6.3

2026-08-14 Release of logback version 1.6.3

  • In response CVE-2026-19880, MDCBasedDiscriminator (used by SiftingAppender) now strips forward and backward slashes (/, \) from MDC values before they are used as discriminating keys. This prevents path segments from escaping into destinations controlled by an attacker. When sanitisation actually changes a value, a warning is emitted; the warning is rate-limited (a small batch, then a lull of about ten minutes).

  • Colour console support is split out into a dedicated JansiConsoleAppender. It wraps stdout or stderr with Jansi so ANSI escape sequences (for example coloured patterns) render correctly on terminals that need it, notably Windows. Prefer this class over the older path described next. See the appenders documentation.

  • The withJansi property on ConsoleAppender is deprecated. Existing configurations that still set <withJansi>true</withJansi> continue to work for compatibility, but new setups should use JansiConsoleAppender instead.

  • ConsoleAppender no longer treats the process console as an exclusive resource: stopping it does not close System.out / System.err. JansiConsoleAppender pairs each AnsiConsole.systemInstall() with systemUninstall() on stop, so repeated start/stop cycles do not leave Jansi installed or tear down streams shared with the rest of the JVM. Related behavior is covered by tests for issues/1063.

  • Invocation throttling helpers were reworked: SimpleInvocationGate is renamed FixedIntervalInvocationGate, and BatchedFixedIntervalInvocationGate allows a short burst of invocations before applying a fixed lull. The sanitisation warning above uses the batched gate.

  • The JPMS module-info for logback-core now exports the ch.qos.logback.core.property package, which had been missing from the module descriptor.

... (truncated)

Commits
  • d1b829d prepare release 1.6.5
  • 065b9b2 enhance protectin against mischievious MDC values in MDCBasedDiscriminator
  • b69beab complete commit in relation to discussion_1032
  • 7266c0b fix intermittently failing SocketAppenderMessageLossTest rest condition
  • a633bb0 fix intermittently failing SocketAppenderMessageLossTest rest condition
  • 2bc5bcc renamed tbrp and eclosingTBRP, other minor changes
  • 2cd8762 fix typo in AGENTS.md
  • 647846c fix errors when running tests under intellij IDEA
  • 1048917 removed ConsoleCharsetPropertyDefiner.java
  • 39b5002 added 'since' and 'forRemoval' attributes to SimpleInvocationGate @​Deprecatio...
  • Additional commits viewable in compare view

Updates io.opentelemetry.instrumentation:opentelemetry-logback-mdc-1.0 from 2.29.0-alpha to 2.31.1-alpha

Release notes

Sourced from io.opentelemetry.instrumentation:opentelemetry-logback-mdc-1.0's releases.

Version 2.31.0

This release targets the OpenTelemetry SDK 1.65.0.

Note that many artifacts have the -alpha suffix attached to their version number, reflecting that they will continue to have breaking changes. Please see VERSIONING.md for more details.

⚠️ Breaking changes to non-stable APIs

  • Remove the deprecated ConfigPropertiesBackedConfigProvider and its create(ConfigProperties) compatibility API from the declarative config bridge. (#19305)
  • Stop exposing opentelemetry-instrumentation-api-incubator on library instrumentation compile classpaths. (#19612)

🚫 Deprecations

  • Deprecate otel.instrumentation.experimental.span-suppression-strategy in favor of Experimental.setSpanSuppressionStrategy(...). (#19180)
  • Deprecate HostIdResource.REGISTRY_QUERY in favor of the absolute-path reg.exe lookup used by HostIdResource. (#19293)
  • Deprecate MessageOperation in favor of MessagingOperationType, and the MessageOperation overloads of MessagingAttributesExtractor, MessagingConsumerMetrics, MessagingProducerMetrics, MessagingSpanKindExtractor, and MessagingSpanNameExtractor in favor of the corresponding MessagingOperationType APIs. (#19357)
  • Deprecate otel.traces.exporter=zipkin in favor of otel.traces.exporter=otlp, and otel.exporter.zipkin.endpoint in favor of otel.exporter.otlp.traces.endpoint. (#19400)
  • Deprecate OpenTelemetryMeterRegistryBuilder#setMicrometerHistogramGaugesEnabled(boolean) in favor of Experimental#setMicrometerHistogramGaugesEnabled(OpenTelemetryMeterRegistryBuilder, boolean). (#19404)
  • Deprecate legacy gRPC metadata, messaging header, and servlet request-parameter capture properties and APIs in favor of selector-based .included / .excluded configuration and IncludeExclude APIs. (#19494, #19522, #19523, #19638)
  • Deprecate otel.instrumentation.runtime-telemetry.experimental.prefer-jfr in favor of otel.instrumentation.runtime-telemetry.experimental.jfr-metrics.included, and setPreferJfrMetrics(...) in favor of setJfrMetrics(RuntimeTelemetryBuilder, IncludeExclude). (#19495)
  • Deprecate boolean and capture-list configuration for MDC/context data, map messages, key-value pairs, logger context, Logstash markers, and structured arguments in favor of .included / .excluded selectors and IncludeExclude APIs. (#19519, #19520, #19521, #19599, #19600, #19605, #19609, #19610)
  • Deprecate the declarative configuration field general.semconv_stability.opt_in in favor of general.stability_opt_in_list, and general.sanitization.url.sensitive_query_parameters/development in favor of general.sanitization.url.sensitive_query_parameters. (#19561)
  • Deprecate otel.instrumentation.graphql.add-operation-name-to-span-name.enabled in favor of otel.instrumentation.graphql.operation-name-in-span-name.enabled, and otel.instrumentation.runtime-telemetry.package-emitter.enabled / jars-per-second in favor of otel.instrumentation.runtime-telemetry.experimental.package-emitter.enabled / jars-per-second. (#19573)
  • Deprecate captured request and response header builder methods across HTTP library instrumentations in favor of selector-based requestHeaders(IncludeExclude) and responseHeaders(IncludeExclude) APIs. (#19598, #19601, #19602, #19603, #19604, #19606, #19607, #19608)
  • Deprecate otel.instrumentation.micrometer.histogram-gauges.enabled in favor of otel.instrumentation.micrometer.experimental.histogram-gauges.enabled. (#19613)

🌟 New javaagent instrumentation

  • Add Apache Commons Pool 2 instrumentation for object pool metrics. (#19091)
  • Add Apache HBase client 1.0 javaagent instrumentation. (#19243)
  • Add Redisson connection pool metrics for 3.26+. (#19392)
  • Add support for OpenTelemetry API 1.65 incubator metrics in the Java agent. (#19456)
  • Add Tomcat DBCP 8.0 javaagent instrumentation for database pool metrics. (#19472)

📈 Enhancements

  • Add opt-in OSGi bundle metadata for selected instrumentation, API, and SDK extension artifacts so they can be consumed directly in OSGi runtimes. (#18995)
  • Add cassandra.compaction.progress.completed and cassandra.compaction.progress.size gauges for in-flight Cassandra compactions. (#19290)
  • Preview the upcoming 3.0 messaging semantic conventions behind otel.semconv-stability.opt-in=messaging across AWS SQS and Lambda, JMS, Kafka, NATS, Pulsar, RabbitMQ, RocketMQ, Spring Integration, and Spring messaging instrumentations. (#19347, #19348, #19349, #19350, #19351, #19353, #19354, #19355, #19356, #19476, #19477, #19478, #19479, #19480, #19481, #19482, #19486, #19487, #19499, #19500, #19504, #19505, #19507, #19508, #19535, #19544, #19565, #19567, #19639, #19640)
  • Under the upcoming 3.0 RPC semantic conventions behind otel.semconv-stability.opt-in=rpc, Dubbo requests to unknown services emit server spans even when decoding fails before DubboProtocol.getInvoker(), and record the original method in rpc.method_original. (#16668)
  • Log4j context data now includes baggage.* entries even when there is no current span. (#19378)
  • When otel.instrumentation.common.v3-preview=true, the Micrometer bridge no longer exports .max gauges for Timer and DistributionSummary. (#19397)
  • Add the IncludeExclude selector API to opentelemetry-instrumentation-api for matching strings against included and excluded glob patterns. (#19451)
  • Emit Cassandra driver 3 consistency, coordinator, page size, idempotence, and speculative execution attributes. (#19629)
  • Expand the upcoming 3.0 database semantic conventions behind otel.semconv-stability.opt-in=database, including operation names, namespaces, collection names, operation parameters, batch telemetry, and error types for Couchbase, Redis clients, Elasticsearch, R2DBC, JDBC, ClickHouse, MongoDB, and HBase. (#19616, #19623, #19664, #19665, #19668, #19670, #19704, #19705, #19706, #19707, #19708)
  • Add otel.instrumentation.influxdb.query-sanitization.enabled to control InfluxDB query sanitization, taking precedence over otel.instrumentation.common.db.query-sanitization.enabled. (#19703)

🛠️ Bug fixes

  • Use stable database-derived metric names for unnamed Alibaba Druid, c3p0, Tomcat JDBC, HikariCP, and Vibur connection pools. (#19108, #19159, #19173, #19470, #19471)
  • Apache DBCP 2.0 metrics now register when the pool starts even without JMX registration, and they unregister on close(). (#19160)

... (truncated)

Changelog

Sourced from io.opentelemetry.instrumentation:opentelemetry-logback-mdc-1.0's changelog.

Changelog

Unreleased

⚠️ Breaking changes to non-stable APIs

  • Remove deprecated setCapturedRequestHeaders and setCapturedResponseHeaders methods from Ktor 1.0 configuration, and the capturedRequestHeaders and capturedResponseHeaders overloads from Ktor 2.0/3.0 builders. Use requestHeaders and responseHeaders with IncludeExclude selectors instead. Selector patterns interpret * and ? as wildcards rather than literal header-name characters.
  • Rename Ktor 1.0 configuration methods to match Ktor 2.0/3.0: setRequestHeaders to requestHeaders, setResponseHeaders to responseHeaders, setKnownMethods to knownMethods, addAttributesExtractor to attributesExtractor, setSpanNameExtractorCustomizer to spanNameExtractor, setStatusExtractor to spanStatusExtractor, and setSpanKindExtractor to spanKindExtractor. Parameter types and behavior are unchanged.
  • Rename setOpenTelemetry to openTelemetry in Ktor 1.0 configuration and Ktor 2.0/3.0 client and server builders. The parameter type and initialization behavior are unchanged.
  • Remove the deprecated OpenTelemetryMeterRegistryBuilder#setMicrometerHistogramGaugesEnabled(boolean). Use Experimental#setMicrometerHistogramGaugesEnabled(OpenTelemetryMeterRegistryBuilder, boolean) instead.

Version 2.32.0 (2026-10-03)

This release targets the OpenTelemetry SDK 1.66.0.

Note that many artifacts have the -alpha suffix attached to their version number, reflecting that they will continue to have breaking changes. Please see VERSIONING.md for more details.

⚠️ Breaking changes to non-stable APIs

  • Remove the deprecated HostIdResource.REGISTRY_QUERY constant. (#19778)
  • The ExperimentalJmxMetricHandler SPI now requires implementations to provide getMetricNames(). (#19781)
  • Add the required isRequestStreaming(REQUEST) method to GenAiAttributesGetter. (#19879)
  • The experimental java.common.messaging.headers/development YAML selector no longer configures header capture. Use java.common.messaging.headers instead. (#20260)

🚫 Deprecations

  • Deprecate otel.jmx.target.system in favor of otel.jmx.metrics.experimental.included. (#19783)
  • Deprecate otel.instrumentation.elasticsearch.capture-search-query. It will be removed in 3.0, when search query bodies are always captured. There is no replacement.

... (truncated)

Commits

Updates io.opentelemetry:opentelemetry-api from 1.63.0 to 1.66.0

Release notes

Sourced from io.opentelemetry:opentelemetry-api's releases.

Version 1.66.0

API

  • Fix Baggage.fromContext() and Baggage.fromContextOrNull() to handle a null context (#8667)
  • Do not percent-encode W3C baggage metadata (#8682)
  • Fix ArrayIndexOutOfBoundsException in OtelEncodingUtils for invalid hex characters (#8748)

SDK

Traces

  • Record processed spans before export completes and reject new spans on shutdown in SpanProcessor self-observability instrumentation (#8735)

Metrics

  • Improve explicit bucket histogram contention performance (#8717)

Logs

  • Record processed logs before export completes and reject new logs on shutdown in LogRecordProcessor self-observability instrumentation (#8698)

Exporters

  • OTLP: Respect Retry-After in OTLP HTTP senders (#8633)
  • OTLP: Add setEnabledProtocols option to OTLP HTTP exporter builders (#8610)
  • OTLP: Reject mixing keyManager and sslContext in TlsConfigHelper (#8710)
  • OTLP: Fix OkHttpGrpcSender mTLS when using the platform default trust store (#8758)
  • OTLP: Suppress instrumentation of exporter requests in JdkHttpSender (#8757)
  • OTLP: Accept RFC 1123 hostnames in EndpointUtil.validateEndpoint for OkHttp senders (#8746)
  • OTLP: Include the number of affected items in exporter error logging (#8780)
  • OTLP: Add toString to OtlpJsonLogging{Span,Metric,LogRecord}Exporter (#8725)
  • OTLP Profiles: Improve JFR export example and align LinkData null-element handling with the spec (#8349)
  • Prometheus: Remove default host log warning in PrometheusHttpServerBuilder (#8679)
  • Prometheus: Align UCUM byte unit conversions with the specification table (#8752)

Extensions

  • BREAKING Declarative config: Rename generated model POJO setters from with<Prop> to set<Prop> (#8742)
  • Declarative config: Resolve experimental properties on stable APIs in generated model POJOs (#8654)
  • Declarative config: Fix inverted scope_info_enabled and target_info_enabled flags in the Prometheus component provider (#8750)
  • Declarative config: Support output_stream in otlp_file/development (#8676)
  • Incubator: Add toString to ComposableAnnotatingSampler (#8645)

Project tooling

  • Remediate zizmor findings in GitHub Actions workflows (#8592)

🙇 Thank you

This release was possible thanks to the following contributors who shared their brilliant ideas and awesome pull requests:

... (truncated)

Changelog

Sourced from io.opentelemetry:opentelemetry-api's changelog.

Version 1.66.0 (2026-09-11)

API

  • Fix Baggage.fromContext() and Baggage.fromContextOrNull() to handle a null context (#8667)
  • Do not percent-encode W3C baggage metadata (#8682)
  • Fix ArrayIndexOutOfBoundsException in OtelEncodingUtils for invalid hex characters (#8748)

SDK

Traces

  • Record processed spans before export completes and reject new spans on shutdown in SpanProcessor self-observability instrumentation (#8735)

Metrics

  • Improve explicit bucket histogram contention performance (#8717)

Logs

  • Record processed logs before export completes and reject new logs on shutdown in LogRecordProcessor self-observability instrumentation (#8698)

Exporters

  • OTLP: Respect Retry-After in OTLP HTTP senders (#8633)
  • OTLP: Add setEnabledProtocols option to OTLP HTTP exporter builders (#8610)
  • OTLP: Reject mixing keyManager and sslContext in TlsConfigHelper (#8710)
  • OTLP: Fix OkHttpGrpcSender mTLS when using the platform default trust store (#8758)
  • OTLP: Suppress instrumentation of exporter requests in JdkHttpSender (#8757)
  • OTLP: Accept RFC 1123 hostnames in EndpointUtil.validateEndpoint for OkHttp senders (#8746)
  • OTLP: Include the number of affected items in exporter error logging (#8780)
  • OTLP: Add toString to OtlpJsonLogging{Span,Metric,LogRecord}Exporter (#8725)
  • OTLP Profiles: Improve JFR export example and align LinkData null-element handling with the spec (#8349)

... (truncated)

Commits
  • 300a358 [release/v1.66.x] Prepare release 1.66.0 (#8799)
  • dd71106 Prepare for 1.66.0 release (#8795)
  • 9284265 Manual 1.65.0 post release (#8794)
  • 10c7338 Align UCUM byte unit conversions with the specification table (#8752)
  • bf1a64c Accept RFC 1123 hostnames in EndpointUtil.validateEndpoint (#8746)
  • ab72956 Add number of affected items to Exporter error logging (#8780)
  • 275fe92 Update dependency com.squareup.wire:wire-bom to v7 (#8793)
  • 050f481 Remove unused parameter from B3 propagation integration tests (#8791)
  • 8d7bd65 Improve explicit histogram contention performance (#8717)
  • 2c880d9 Rename inverted grpc detection test in GrpcJavaOtlpIntegrationTest (#8790)
  • Additional commits viewable in compare view

Updates io.opentelemetry:opentelemetry-sdk from 1.63.0 to 1.66.0

Release notes

Sourced from io.opentelemetry:opentelemetry-sdk's releases.

Version 1.66.0

API

  • Fix Baggage.fromContext() and Baggage.fromContextOrNull() to handle a null context (#8667)
  • Do not percent-encode W3C baggage metadata (#8682)
  • Fix ArrayIndexOutOfBoundsException in OtelEncodingUtils for invalid hex characters (#8748)

SDK

Traces

  • Record processed spans before export completes and reject new spans on shutdown in SpanProcessor self-observability instrumentation (#8735)

Metrics

  • Improve explicit bucket histogram contention performance (#8717)

Logs

  • Record processed logs before export completes and reject new logs on shutdown in LogRecordProcessor self-observability instrumentation (#8698)

Exporters

  • OTLP: Respect Retry-After in OTLP HTTP senders (#8633)
  • OTLP: Add setEnabledProtocols option to OTLP HTTP exporter builders (#8610)
  • OTLP: Reject mixing keyManager and sslContext in TlsConfigHelper (#8710)
  • OTLP: Fix OkHttpGrpcSender mTLS when using the platform default trust store (#8758)
  • OTLP: Suppress instrumentation of exporter requests in JdkHttpSender (#8757)
  • OTLP: Accept RFC 1123 hostnames in EndpointUtil.validateEndpoint for OkHttp senders (#8746)
  • OTLP: Include the number of affected items in exporter error logging (#8780)
  • OTLP: Add toString to OtlpJsonLogging{Span,Metric,LogRecord}Exporter (#8725)
  • OTLP Profiles: Improve JFR export example and align LinkData null-element handling with the spec (#8349)
  • Prometheus: Remove default host log warning in PrometheusHttpServerBuilder (#8679)
  • Prometheus: Align UCUM byte unit conversions with the specification table (#8752)

Extensions

  • BREAKING Declarative config: Rename generated model POJO setters from with<Prop> to set<Prop> (#8742)
  • Declarative config: Resolve experimental properties on stable APIs in generated model POJOs (#8654)
  • Declarative config: Fix inverted scope_info_enabled and target_info_enabled flags in the Prometheus component provider (#8750)
  • Declarative config: Support output_stream in otlp_file/development (#8676)
  • Incubator: Add toString to ComposableAnnotatingSampler (#8645)

Project tooling

  • Remediate zizmor findings in GitHub Actions workflows (#8592)

🙇 Thank you

This release was possible thanks to the following contributors who shared their brilliant ideas and awesome pull requests:

... (truncated)

Changelog

Sourced from io.opentelemetry:opentelemetry-sdk's changelog.

Version 1.66.0 (2026-09-11)

API

  • Fix Baggage.fromContext() and Baggage.fromContextOrNull() to handle a null context (#8667)
  • Do not percent-encode W3C baggage metadata (#8682)
  • Fix ArrayIndexOutOfBoundsException in OtelEncodingUtils for invalid hex characters (#8748)

SDK

Traces

  • Record processed spans before export completes and reject new spans on shutdown in SpanProcessor self-observability instrumentation (#8735)

Metrics

  • Improve explicit bucket histogram contention performance (#8717)

Logs

  • Record processed logs before export completes and reject new logs on shutdown in LogRecordProcessor self-observability instrumentation (#8698)

Exporters

  • OTLP: Respect Retry-After in OTLP HTTP senders (#8633)
  • OTLP: Add setEnabledProtocols option to OTLP HTTP exporter builders (#8610)
  • OTLP: Reject mixing keyManager and sslContext in TlsConfigHelper (#8710)
  • OTLP: Fix OkHttpGrpcSender mTLS when using the platform default trust store (#8758)
  • OTLP: Suppress instrumentation of exporter requests in JdkHttpSender (#8757)
  • OTLP: Accept RFC 1123 hostnames in EndpointUtil.validateEndpoint for OkHttp senders (#8746)
  • OTLP: Include the number of affected items in exporter error logging (#8780)
  • OTLP: Add toString to OtlpJsonLogging{Span,Metric,LogRecord}Exporter (#8725)
  • OTLP Profiles: Improve JFR export example and align LinkData null-element handling with the spec (#8349)

... (truncated)

Commits
  • 300a358 [release/v1.66.x] Prepare release 1.66.0 (#8799)
  • dd71106 Prepare for 1.66.0 release (#8795)
  • 9284265 Manual 1.65.0 post release (#8794)
  • 10c7338 Align UCUM byte unit conversions with the specification table (#8752)
  • bf1a64c Accept RFC 1123 hostnames in EndpointUtil.validateEndpoint (#8746)
  • ab72956 Add number of affected items to Exporter error logging (#8780)
  • 275fe92 Update dependency com.squareup.wire:wire-bom to v7 (#8793)
  • 050f481 Remove unused parameter from B3 propagation integration tests (#8791)
  • 8d7bd65 Improve explicit histogram contention performance (#8717)
  • 2c880d9 Rename inverted grpc detection test in GrpcJavaOtlpIntegrationTest (#8790)
  • Additional commits viewable in compare view

Updates io.opentelemetry:opentelemetry-exporter-logging from 1.63.0 to 1.66.0

Release notes

Sourced from io.opentelemetry:opentelemetry-exporter-logging's releases.

Version 1.66.0

API

  • Fix Baggage.fromContext() and Baggage.fromContextOrNull() to handle a null context (#8667)
  • Do not percent-encode W3C baggage metadata (#8682)
  • Fix ArrayIndexOutOfBoundsException in OtelEncodingUtils for invalid hex characters (#8748)

SDK

Traces

  • Record processed spans before export completes and reject new spans on shutdown in SpanProcessor self-observability instrumentation (#8735)

Metrics

  • Improve explicit bucket histogram contention performance (#8717)

Logs

  • Record processed logs before export completes and reject new logs on shutdown in LogRecordProcessor self-observability instrumentation (#8698)

Exporters

  • OTLP: Respect Retry-After in OTLP HTTP senders (#8633)
  • OTLP: Add setEnabledProtocols option to OTLP HTTP exporter builders (#8610)
  • OTLP: Reject mixing keyManager and sslContext in TlsConfigHelper (#8710)
  • OTLP: Fix OkHttpGrpcSender mTLS when using the platform default trust store (#8758)
  • OTLP: Suppress instrumentation of exporter requests in JdkHttpSender (#8757)
  • OTLP: Accept RFC 1123 hostnames in EndpointUtil.validateEndpoint for OkHttp senders (#8746)
  • OTLP: Include the number of affected items in exporter error logging (#8780)
  • OTLP: Add toString to OtlpJsonLogging{Span,Metric,LogRecord}Exporter (#8725)
  • OTLP Profiles: Improve JFR export example and align LinkData null-element handling with the spec (#8349)
  • Prometheus: Remove default host log warning in PrometheusHttpServerBuilder (#8679)
  • Prometheus: Align UCUM byte unit conversions with the specification table (#8752)

Extensions

  • BREAKING Declarative config: Rename generated model POJO setters from with<Prop> to set<Prop> (#8742)
  • Declarative config: Resolve experimental properties on stable APIs in generated model POJOs (#8654)
  • Declarative config: Fix inverted scope_info_enabled and Description has been truncated

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Sep 28, 2026
Bumps the alldependencies group with 31 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| org.openapi.generator | `7.15.0` | `7.25.0` |
| org.slf4j:slf4j-api | `2.0.17` | `2.0.20` |
| org.slf4j:jul-to-slf4j | `2.0.17` | `2.0.20` |
| org.slf4j:jul-to-slf4j | `2.0.17` | `2.0.20` |
| [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) | `1.5.34` | `1.6.5` |
| [io.opentelemetry.instrumentation:opentelemetry-logback-mdc-1.0](https://github.com/open-telemetry/opentelemetry-java-instrumentation) | `2.29.0-alpha` | `2.31.1-alpha` |
| [io.opentelemetry:opentelemetry-api](https://github.com/open-telemetry/opentelemetry-java) | `1.63.0` | `1.66.0` |
| [io.opentelemetry:opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-java) | `1.63.0` | `1.66.0` |
| [io.opentelemetry:opentelemetry-exporter-logging](https://github.com/open-telemetry/opentelemetry-java) | `1.63.0` | `1.66.0` |
| [io.opentelemetry:opentelemetry-sdk](https://github.com/open-telemetry/opentelemetry-java) | `1.63.0` | `1.66.0` |
| [io.opentelemetry:opentelemetry-exporter-logging](https://github.com/open-telemetry/opentelemetry-java) | `1.63.0` | `1.66.0` |
| [io.opentelemetry.instrumentation:opentelemetry-instrumentation-api](https://github.com/open-telemetry/opentelemetry-java-instrumentation) | `2.29.0` | `2.31.1` |
| [com.google.errorprone:error_prone_annotations](https://github.com/google/error-prone) | `2.15.0` | `2.50.0` |
| [io.swagger.core.v3:swagger-core](https://github.com/swagger-api/swagger-core) | `2.2.23` | `2.2.55` |
| [io.dropwizard.metrics:metrics-core](https://github.com/dropwizard/metrics) | `4.2.12` | `4.2.40` |
| [io.dropwizard.metrics:metrics-servlets](https://github.com/dropwizard/metrics) | `4.2.12` | `4.2.40` |
| [io.dropwizard.metrics:metrics-servlets](https://github.com/dropwizard/metrics) | `4.2.12` | `4.2.40` |
| io.prometheus:prometheus-metrics-instrumentation-dropwizard | `1.6.1` | `1.9.0` |
| io.prometheus:prometheus-metrics-exporter-servlet-javax | `1.6.1` | `1.9.0` |
| io.prometheus:prometheus-metrics-exporter-servlet-javax | `1.6.1` | `1.9.0` |
| [com.fasterxml.jackson.core:jackson-databind](https://github.com/FasterXML/jackson-databind) | `2.22.2` | `2.22.3` |
| [com.fasterxml.jackson.dataformat:jackson-dataformat-csv](https://github.com/FasterXML/jackson-dataformats-text) | `2.22.2` | `2.22.3` |
| com.fasterxml.jackson.datatype:jackson-datatype-jsr310 | `2.22.2` | `2.22.3` |
| [com.fasterxml.jackson.dataformat:jackson-dataformat-xml](https://github.com/FasterXML/jackson-dataformat-xml) | `2.22.2` | `2.22.3` |
| com.fasterxml.jackson.datatype:jackson-datatype-jdk8 | `2.22.2` | `2.22.3` |
| [com.fasterxml.jackson.dataformat:jackson-dataformat-csv](https://github.com/FasterXML/jackson-dataformats-text) | `2.22.2` | `2.22.3` |
| com.fasterxml.jackson.datatype:jackson-datatype-jsr310 | `2.22.2` | `2.22.3` |
| [com.fasterxml.jackson.dataformat:jackson-dataformat-xml](https://github.com/FasterXML/jackson-dataformat-xml) | `2.22.2` | `2.22.3` |
| com.fasterxml.jackson.datatype:jackson-datatype-jdk8 | `2.22.2` | `2.22.3` |
| [io.jsonwebtoken:jjwt-api](https://github.com/jwtk/jjwt) | `0.11.5` | `0.13.0` |
| io.jsonwebtoken:jjwt-jackson | `0.11.5` | `0.13.0` |
| [io.jsonwebtoken:jjwt-impl](https://github.com/jwtk/jjwt) | `0.11.5` | `0.13.0` |
| io.jsonwebtoken:jjwt-jackson | `0.11.5` | `0.13.0` |
| [io.jsonwebtoken:jjwt-impl](https://github.com/jwtk/jjwt) | `0.11.5` | `0.13.0` |
| com.adobe.testing:s3mock-testcontainers | `5.2.2` | `5.2.3` |
| com.oracle.database.jdbc:ojdbc11 | `23.26.1.0.0` | `23.26.3.0.0` |
| org.freemarker:freemarker | `2.3.32` | `2.3.35` |
| [com.github.javaparser:javaparser-core](https://github.com/javaparser/javaparser) | `3.26.2` | `3.28.2` |
| [com.github.javaparser:javaparser-symbol-solver-core](https://github.com/javaparser/javaparser) | `3.26.2` | `3.28.2` |
| [com.github.javaparser:javaparser-symbol-solver-core](https://github.com/javaparser/javaparser) | `3.26.2` | `3.28.2` |
| org.apache.tomcat.embed:tomcat-embed-core | `9.0.121` | `9.0.122` |
| org.apache.tomcat.embed:tomcat-embed-jasper | `9.0.121` | `9.0.122` |
| org.apache.tomcat:tomcat-jdbc | `9.0.121` | `9.0.122` |
| org.apache.tomcat.embed:tomcat-embed-jasper | `9.0.121` | `9.0.122` |
| org.apache.tomcat:tomcat-jdbc | `9.0.121` | `9.0.122` |



Updates `org.openapi.generator` from 7.15.0 to 7.25.0

Updates `org.slf4j:slf4j-api` from 2.0.17 to 2.0.20

Updates `org.slf4j:jul-to-slf4j` from 2.0.17 to 2.0.20

Updates `org.slf4j:jul-to-slf4j` from 2.0.17 to 2.0.20

Updates `ch.qos.logback:logback-classic` from 1.5.34 to 1.6.5
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.5.34...v_1.6.5)

Updates `io.opentelemetry.instrumentation:opentelemetry-logback-mdc-1.0` from 2.29.0-alpha to 2.31.1-alpha
- [Release notes](https://github.com/open-telemetry/opentelemetry-java-instrumentation/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-java-instrumentation/blob/main/CHANGELOG.md)
- [Commits](https://github.com/open-telemetry/opentelemetry-java-instrumentation/commits)

Updates `io.opentelemetry:opentelemetry-api` from 1.63.0 to 1.66.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-java/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-java/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-java@v1.63.0...v1.66.0)

Updates `io.opentelemetry:opentelemetry-sdk` from 1.63.0 to 1.66.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-java/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-java/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-java@v1.63.0...v1.66.0)

Updates `io.opentelemetry:opentelemetry-exporter-logging` from 1.63.0 to 1.66.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-java/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-java/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-java@v1.63.0...v1.66.0)

Updates `io.opentelemetry:opentelemetry-sdk` from 1.63.0 to 1.66.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-java/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-java/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-java@v1.63.0...v1.66.0)

Updates `io.opentelemetry:opentelemetry-exporter-logging` from 1.63.0 to 1.66.0
- [Release notes](https://github.com/open-telemetry/opentelemetry-java/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-java/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-java@v1.63.0...v1.66.0)

Updates `io.opentelemetry.instrumentation:opentelemetry-instrumentation-api` from 2.29.0 to 2.31.1
- [Release notes](https://github.com/open-telemetry/opentelemetry-java-instrumentation/releases)
- [Changelog](https://github.com/open-telemetry/opentelemetry-java-instrumentation/blob/main/CHANGELOG.md)
- [Commits](open-telemetry/opentelemetry-java-instrumentation@v2.29.0...v2.31.1)

Updates `com.google.errorprone:error_prone_annotations` from 2.15.0 to 2.50.0
- [Release notes](https://github.com/google/error-prone/releases)
- [Commits](google/error-prone@v2.15.0...v2.50.0)

Updates `io.swagger.core.v3:swagger-core` from 2.2.23 to 2.2.55
- [Release notes](https://github.com/swagger-api/swagger-core/releases)
- [Changelog](https://github.com/swagger-api/swagger-core/blob/master/CHANGELOG.md)
- [Commits](swagger-api/swagger-core@v2.2.23...v2.2.55)

Updates `io.dropwizard.metrics:metrics-core` from 4.2.12 to 4.2.40
- [Release notes](https://github.com/dropwizard/metrics/releases)
- [Commits](dropwizard/metrics@v4.2.12...v4.2.40)

Updates `io.dropwizard.metrics:metrics-servlets` from 4.2.12 to 4.2.40
- [Release notes](https://github.com/dropwizard/metrics/releases)
- [Commits](dropwizard/metrics@v4.2.12...v4.2.40)

Updates `io.dropwizard.metrics:metrics-servlets` from 4.2.12 to 4.2.40
- [Release notes](https://github.com/dropwizard/metrics/releases)
- [Commits](dropwizard/metrics@v4.2.12...v4.2.40)

Updates `io.prometheus:prometheus-metrics-instrumentation-dropwizard` from 1.6.1 to 1.9.0

Updates `io.prometheus:prometheus-metrics-exporter-servlet-javax` from 1.6.1 to 1.9.0

Updates `io.prometheus:prometheus-metrics-exporter-servlet-javax` from 1.6.1 to 1.9.0

Updates `com.fasterxml.jackson.core:jackson-databind` from 2.22.2 to 2.22.3
- [Commits](FasterXML/jackson-databind@jackson-databind-2.22.2...jackson-databind-2.22.3)

Updates `com.fasterxml.jackson.dataformat:jackson-dataformat-csv` from 2.22.2 to 2.22.3
- [Commits](FasterXML/jackson-dataformats-text@jackson-dataformats-text-2.22.2...jackson-dataformats-text-2.22.3)

Updates `com.fasterxml.jackson.datatype:jackson-datatype-jsr310` from 2.22.2 to 2.22.3

Updates `com.fasterxml.jackson.dataformat:jackson-dataformat-xml` from 2.22.2 to 2.22.3
- [Commits](FasterXML/jackson-dataformat-xml@jackson-dataformat-xml-2.22.2...jackson-dataformat-xml-2.22.3)

Updates `com.fasterxml.jackson.datatype:jackson-datatype-jdk8` from 2.22.2 to 2.22.3

Updates `com.fasterxml.jackson.dataformat:jackson-dataformat-csv` from 2.22.2 to 2.22.3
- [Commits](FasterXML/jackson-dataformats-text@jackson-dataformats-text-2.22.2...jackson-dataformats-text-2.22.3)

Updates `com.fasterxml.jackson.datatype:jackson-datatype-jsr310` from 2.22.2 to 2.22.3

Updates `com.fasterxml.jackson.dataformat:jackson-dataformat-xml` from 2.22.2 to 2.22.3
- [Commits](FasterXML/jackson-dataformat-xml@jackson-dataformat-xml-2.22.2...jackson-dataformat-xml-2.22.3)

Updates `com.fasterxml.jackson.datatype:jackson-datatype-jdk8` from 2.22.2 to 2.22.3

Updates `io.jsonwebtoken:jjwt-api` from 0.11.5 to 0.13.0
- [Release notes](https://github.com/jwtk/jjwt/releases)
- [Changelog](https://github.com/jwtk/jjwt/blob/main/CHANGELOG.md)
- [Commits](jwtk/jjwt@0.11.5...0.13.0)

Updates `io.jsonwebtoken:jjwt-jackson` from 0.11.5 to 0.13.0

Updates `io.jsonwebtoken:jjwt-impl` from 0.11.5 to 0.13.0
- [Release notes](https://github.com/jwtk/jjwt/releases)
- [Changelog](https://github.com/jwtk/jjwt/blob/main/CHANGELOG.md)
- [Commits](jwtk/jjwt@0.11.5...0.13.0)

Updates `io.jsonwebtoken:jjwt-jackson` from 0.11.5 to 0.13.0

Updates `io.jsonwebtoken:jjwt-impl` from 0.11.5 to 0.13.0
- [Release notes](https://github.com/jwtk/jjwt/releases)
- [Changelog](https://github.com/jwtk/jjwt/blob/main/CHANGELOG.md)
- [Commits](jwtk/jjwt@0.11.5...0.13.0)

Updates `com.adobe.testing:s3mock-testcontainers` from 5.2.2 to 5.2.3

Updates `com.oracle.database.jdbc:ojdbc11` from 23.26.1.0.0 to 23.26.3.0.0

Updates `org.freemarker:freemarker` from 2.3.32 to 2.3.35

Updates `com.github.javaparser:javaparser-core` from 3.26.2 to 3.28.2
- [Release notes](https://github.com/javaparser/javaparser/releases)
- [Changelog](https://github.com/javaparser/javaparser/blob/master/changelog.md)
- [Commits](javaparser/javaparser@javaparser-parent-3.26.2...javaparser-parent-3.28.2)

Updates `com.github.javaparser:javaparser-symbol-solver-core` from 3.26.2 to 3.28.2
- [Release notes](https://github.com/javaparser/javaparser/releases)
- [Changelog](https://github.com/javaparser/javaparser/blob/master/changelog.md)
- [Commits](javaparser/javaparser@javaparser-parent-3.26.2...javaparser-parent-3.28.2)

Updates `com.github.javaparser:javaparser-symbol-solver-core` from 3.26.2 to 3.28.2
- [Release notes](https://github.com/javaparser/javaparser/releases)
- [Changelog](https://github.com/javaparser/javaparser/blob/master/changelog.md)
- [Commits](javaparser/javaparser@javaparser-parent-3.26.2...javaparser-parent-3.28.2)

Updates `org.apache.tomcat.embed:tomcat-embed-core` from 9.0.121 to 9.0.122

Updates `org.apache.tomcat.embed:tomcat-embed-jasper` from 9.0.121 to 9.0.122

Updates `org.apache.tomcat:tomcat-jdbc` from 9.0.121 to 9.0.122

Updates `org.apache.tomcat.embed:tomcat-embed-jasper` from 9.0.121 to 9.0.122

Updates `org.apache.tomcat:tomcat-jdbc` from 9.0.121 to 9.0.122

---
updated-dependencies:
- dependency-name: ch.qos.logback:logback-classic
  dependency-version: 1.6.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: alldependencies
- dependency-name: com.adobe.testing:s3mock-testcontainers
  dependency-version: 5.2.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: alldependencies
- dependency-name: com.fasterxml.jackson.core:jackson-databind
  dependency-version: 2.22.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: alldependencies
- dependency-name: com.fasterxml.jackson.dataformat:jackson-dataformat-csv
  dependency-version: 2.22.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: alldependencies
- dependency-name: com.fasterxml.jackson.dataformat:jackson-dataformat-csv
  dependency-version: 2.22.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: alldependencies
- dependency-name: com.fasterxml.jackson.dataformat:jackson-dataformat-xml
  dependency-version: 2.22.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: alldependencies
- dependency-name: com.fasterxml.jackson.dataformat:jackson-dataformat-xml
  dependency-version: 2.22.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: alldependencies
- dependency-name: com.fasterxml.jackson.datatype:jackson-datatype-jdk8
  dependency-version: 2.22.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: alldependencies
- dependency-name: com.fasterxml.jackson.datatype:jackson-datatype-jdk8
  dependency-version: 2.22.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: alldependencies
- dependency-name: com.fasterxml.jackson.datatype:jackson-datatype-jsr310
  dependency-version: 2.22.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: alldependencies
- dependency-name: com.fasterxml.jackson.datatype:jackson-datatype-jsr310
  dependency-version: 2.22.3
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: alldependencies
- dependency-name: com.github.javaparser:javaparser-core
  dependency-version: 3.28.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: alldependencies
- dependency-name: com.github.javaparser:javaparser-symbol-solver-core
  dependency-version: 3.28.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: alldependencies
- dependency-name: com.github.javaparser:javaparser-symbol-solver-core
  dependency-version: 3.28.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: alldependencies
- dependency-name: com.google.errorprone:error_prone_annotations
  dependency-version: 2.50.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: alldependencies
- dependency-name: com.oracle.database.jdbc:ojdbc11
  dependency-version: 23.26.3.0.0
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: alldependencies
- dependency-name: io.dropwizard.metrics:metrics-core
  dependency-version: 4.2.40
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: alldependencies
- dependency-name: io.dropwizard.metrics:metrics-servlets
  dependency-version: 4.2.40
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: alldependencies
- dependency-name: io.dropwizard.metrics:metrics-servlets
  dependency-version: 4.2.40
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: alldependencies
- dependency-name: io.jsonwebtoken:jjwt-api
  dependency-version: 0.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: alldependencies
- dependency-name: io.jsonwebtoken:jjwt-impl
  dependency-version: 0.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: alldependencies
- dependency-name: io.jsonwebtoken:jjwt-impl
  dependency-version: 0.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: alldependencies
- dependency-name: io.jsonwebtoken:jjwt-jackson
  dependency-version: 0.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: alldependencies
- dependency-name: io.jsonwebtoken:jjwt-jackson
  dependency-version: 0.13.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: alldependencies
- dependency-name: io.opentelemetry.instrumentation:opentelemetry-instrumentation-api
  dependency-version: 2.31.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: alldependencies
- dependency-name: io.opentelemetry.instrumentation:opentelemetry-logback-mdc-1.0
  dependency-version: 2.31.1-alpha
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: alldependencies
- dependency-name: io.opentelemetry:opentelemetry-api
  dependency-version: 1.66.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: alldependencies
- dependency-name: io.opentelemetry:opentelemetry-exporter-logging
  dependency-version: 1.66.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: alldependencies
- dependency-name: io.opentelemetry:opentelemetry-exporter-logging
  dependency-version: 1.66.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: alldependencies
- dependency-name: io.opentelemetry:opentelemetry-sdk
  dependency-version: 1.66.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: alldependencies
- dependency-name: io.opentelemetry:opentelemetry-sdk
  dependency-version: 1.66.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: alldependencies
- dependency-name: io.prometheus:prometheus-metrics-exporter-servlet-javax
  dependency-version: 1.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: alldependencies
- dependency-name: io.prometheus:prometheus-metrics-exporter-servlet-javax
  dependency-version: 1.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: alldependencies
- dependency-name: io.prometheus:prometheus-metrics-instrumentation-dropwizard
  dependency-version: 1.9.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: alldependencies
- dependency-name: io.swagger.core.v3:swagger-core
  dependency-version: 2.2.55
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: alldependencies
- dependency-name: org.apache.tomcat.embed:tomcat-embed-core
  dependency-version: 9.0.122
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: alldependencies
- dependency-name: org.apache.tomcat.embed:tomcat-embed-jasper
  dependency-version: 9.0.122
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: alldependencies
- dependency-name: org.apache.tomcat.embed:tomcat-embed-jasper
  dependency-version: 9.0.122
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: alldependencies
- dependency-name: org.apache.tomcat:tomcat-jdbc
  dependency-version: 9.0.122
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: alldependencies
- dependency-name: org.apache.tomcat:tomcat-jdbc
  dependency-version: 9.0.122
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: alldependencies
- dependency-name: org.freemarker:freemarker
  dependency-version: 2.3.35
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: alldependencies
- dependency-name: org.openapi.generator
  dependency-version: 7.25.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: alldependencies
- dependency-name: org.slf4j:jul-to-slf4j
  dependency-version: 2.0.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: alldependencies
- dependency-name: org.slf4j:jul-to-slf4j
  dependency-version: 2.0.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: alldependencies
- dependency-name: org.slf4j:slf4j-api
  dependency-version: 2.0.20
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: alldependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/gradle/alldependencies-40f842c238 branch from 7a09803 to 4a40e57 Compare October 5, 2026 06:32

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update Java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants