Skip to content

chore(deps): bump org.slf4j:slf4j-nop from 1.7.34 to 2.0.18 - #54

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/gradle/org.slf4j-slf4j-nop-2.0.18
Open

chore(deps): bump org.slf4j:slf4j-nop from 1.7.34 to 2.0.18#54
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/gradle/org.slf4j-slf4j-nop-2.0.18

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 23, 2026

Copy link
Copy Markdown
Contributor

Bumps org.slf4j:slf4j-nop from 1.7.34 to 2.0.18.

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps org.slf4j:slf4j-nop from 1.7.34 to 2.0.18.

---
updated-dependencies:
- dependency-name: org.slf4j:slf4j-nop
  dependency-version: 2.0.18
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Jul 23, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner July 23, 2026 06:25
@dependabot dependabot Bot added the java Pull requests that update java code label Jul 23, 2026
@socket-security

Copy link
Copy Markdown

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatedmaven/​org.slf4j/​slf4j-nop@​1.7.34 ⏵ 2.0.1810010090100100

View full report

@ev-vaultkeeper ev-vaultkeeper Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Dependabot review: org.slf4j:slf4j-nop 1.7.34 → 2.0.18

Verdict: safe to merge.

Scope & usage

  • slf4j-nop (and the transitively bumped slf4j-api) are test-only — the lockfile places both on testCompileClasspath/testRuntimeClasspath only. Nothing is added to compileClasspath/runtimeClasspath, so this does not affect anything shipped to SDK consumers.
  • A full-repo search for slf4j / Logger / LoggerFactory / org.slf4j returns zero matches in any .java file. slf4j-nop is used purely as a no-op SLF4J binding to suppress "no SLF4J providers found" warnings emitted by test-scoped libraries (wiremock-jre8, jetty, httpclient5, etc.).

Major-version (1.7.x → 2.0.x) compatibility

  • The notable change across this major bump is provider discovery moving from the static binder (org.slf4j.impl.StaticLoggerBinder) to a ServiceLoader-based mechanism (org.slf4j.spi.SLF4JServiceProvider). Because slf4j-api and slf4j-nop are upgraded in lockstep (both 2.0.18), the new mechanism is satisfied.
  • slf4j-nop is the only binding on the classpath (no logback / slf4j-simple / log4j-slf4j), so there is no double-binding conflict. slf4j-api 2.0.x remains backward compatible for callers compiled against 1.7, so transitive libraries still log correctly (into the no-op).
  • The lockfile line empty=annotationProcessor,signatures,testAnnotationProcessor (added signatures) is benign normalization: the signing plugin's signatures configuration resolves to no dependencies and was simply recorded during lockfile regeneration.

Build/test verification

  • ./gradlew :lib:compileTestJava succeeds.
  • All 106 non-E2E tests pass on this branch.
  • 15 E2E tests (EndToEndTests.*) fail, but they fail identically on master prior to this change (121 completed / 15 failed in both cases). Their failure is a static-initializer ExceptionInInitializerError from constructing a real Evervault client without TEST_EV_APP_ID/TEST_EV_API_KEY and network access — pre-existing and unrelated to this dependency bump.

No source or build changes were required.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Development

Successfully merging this pull request may close these issues.

0 participants