chore(deps): bump org.slf4j:slf4j-nop from 1.7.34 to 2.0.18 - #54
Open
dependabot[bot] wants to merge 1 commit into
Open
chore(deps): bump org.slf4j:slf4j-nop from 1.7.34 to 2.0.18#54dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps org.slf4j:slf4j-nop from 1.7.34 to 2.0.18. --- updated-dependencies: - dependency-name: org.slf4j:slf4j-nop dependency-version: 2.0.18 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <support@github.com>
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
There was a problem hiding this comment.
Dependabot review: org.slf4j:slf4j-nop 1.7.34 → 2.0.18
Verdict: safe to merge. ✅
Scope & usage
slf4j-nop(and the transitively bumpedslf4j-api) are test-only — the lockfile places both ontestCompileClasspath/testRuntimeClasspathonly. Nothing is added tocompileClasspath/runtimeClasspath, so this does not affect anything shipped to SDK consumers.- A full-repo search for
slf4j/Logger/LoggerFactory/org.slf4jreturns zero matches in any.javafile.slf4j-nopis used purely as a no-op SLF4J binding to suppress "no SLF4J providers found" warnings emitted by test-scoped libraries (wiremock-jre8, jetty, httpclient5, etc.).
Major-version (1.7.x → 2.0.x) compatibility
- The notable change across this major bump is provider discovery moving from the static binder (
org.slf4j.impl.StaticLoggerBinder) to aServiceLoader-based mechanism (org.slf4j.spi.SLF4JServiceProvider). Becauseslf4j-apiandslf4j-nopare upgraded in lockstep (both 2.0.18), the new mechanism is satisfied. slf4j-nopis the only binding on the classpath (no logback / slf4j-simple / log4j-slf4j), so there is no double-binding conflict. slf4j-api 2.0.x remains backward compatible for callers compiled against 1.7, so transitive libraries still log correctly (into the no-op).- The lockfile line
empty=annotationProcessor,signatures,testAnnotationProcessor(addedsignatures) is benign normalization: thesigningplugin'ssignaturesconfiguration resolves to no dependencies and was simply recorded during lockfile regeneration.
Build/test verification
./gradlew :lib:compileTestJavasucceeds.- All 106 non-E2E tests pass on this branch.
- 15 E2E tests (
EndToEndTests.*) fail, but they fail identically onmasterprior to this change (121 completed / 15 failed in both cases). Their failure is a static-initializerExceptionInInitializerErrorfrom constructing a realEvervaultclient withoutTEST_EV_APP_ID/TEST_EV_API_KEYand network access — pre-existing and unrelated to this dependency bump.
No source or build changes were required.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps org.slf4j:slf4j-nop from 1.7.34 to 2.0.18.
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)