Skip to content

Bump the minor-and-patch group across 1 directory with 16 updates - #22

Merged
maximkr merged 1 commit into
mainfrom
dependabot/gradle/minor-and-patch-8cc327413f
Aug 12, 2026
Merged

Bump the minor-and-patch group across 1 directory with 16 updates#22
maximkr merged 1 commit into
mainfrom
dependabot/gradle/minor-and-patch-8cc327413f

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 12, 2026

Copy link
Copy Markdown
Contributor

Bumps the minor-and-patch group with 10 updates in the / directory:

Package From To
org.slf4j:slf4j-api 2.0.12 2.0.18
ch.qos.logback:logback-classic 1.4.14 1.6.1
org.freemarker:freemarker 2.3.33 2.3.34
org.apache.lucene:lucene-core 7.6.0 7.7.3
org.quartz-scheduler:quartz 2.3.2 2.5.2
com.mchange:c3p0 0.9.5.5 0.14.1
org.postgresql:postgresql 42.7.7 42.7.13
commons-codec:commons-codec 1.17.0 1.22.1
com.palantir.git-version 4.0.0 4.3.0
gradle-wrapper 9.0.0 9.7.0

Updates org.slf4j:slf4j-api from 2.0.12 to 2.0.18

Updates ch.qos.logback:logback-classic from 1.4.14 to 1.6.1

Release notes

Sourced from ch.qos.logback:logback-classic's releases.

Logback 1.6.1

2026-07-28 Release of logback version 1.6.1

• In TimeBasedRollingPolicy, when the file option is set, the intermediate file renamed before asynchronous compression now receives the target archive name without the compression suffix (e.g. .gz, .zip, .xz). Previously it used a nanotime-based .tmp suffix. This makes the file easier to identify if compression fails during rollover. (See also the following paragraph.)

• On GZ, ZIP, or XZ compression failure, the original (uncompressed) log file is no longer deleted. Compression strategies now delete the source file only after successful compression and emit a warning that the original was left intact.

• ConsoleAppender with now probes JLine's org.jline.jansi.AnsiConsole first and falls back to the legacy FuseSource org.fusesource.jansi.AnsiConsole class. This keeps ANSI coloring working after Jansi moved under the JLine project. The optional org.jline:jansi-core artifact is declared as a dependency alongside the existing FuseSource jansi dependency. A preferredJansiClassName property was added for tests. This issue was reported in issues/1043 by seonwoo_jung who also provided the relevant PR.

• LayoutWrappingEncoder now reports an error at start() when no layout is set and guards encode() against a null layout. Previously, a missing layout (for example after an ignored // branch) allowed the encoder to start and then fail with a NullPointerException on every event, resulting in silent log loss. This issue was reported in issues/1046 by seonwoo_jung who also provided the relevant PR.

• FileCollisionAnalyser now detects file collisions involving nested appenders of SiftingAppender. When the nested file or fileNamePattern does not textually reference the discriminator key (e.g. ${userId}), a warning is issued at configuration time naming the appender, the key, and the shared target. This closes a gap where statically declared file appenders were checked but sifted nested appenders were not. This enhancement was contributed in [PR #1041](qos-ch/logback#1041) by seonwoo_jung.

• More defensive handling in SyslogOutputStream and SyslogAppenderBase: the close() method now ensures that resources are closed, writes and flushes check that the underlying resources are in a valid state and fallback to no-op otherwise.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit 57759f433000a133088ef0441038963134437fbd associated with the tag v_1.6.1. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

• See https://logback.qos.ch/news.html#1.6.1 for the original text.

Logback 1.6.0

2026-07-23 Release of logback version 1.6.0

• Removed certain deprecated variables, methods, and classes. For the list of removed members see release_1.6.0.txt.

• In AsyncAppenderBase, the put(ILoggingEvent) method now has the protected modifier to allow access from derived classes. This change was requested by Thomas Skjølberg in pr#1053.

• Bump SLF4J dependency to version 2.0.18.

See also the overview of the 1.6.x series.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit b07adf36019b51a10f824fdd94009985c587b1d3 associated with the tag v_1.6.0. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Logback 1.5.38

2026-07-09 Release of logback version 1.5.38

• In HardenedObjectInputStream, fixed a typo preventing Throwable objects from being white-filtered. This issue was reported in [PR #1045](qos-ch/logback#1045) by t0rchwo0d.

• A bitwise identical binary of this version can be reproduced by building from source code at commit d04984a41fce42977466f45a2f076f0ee5cc4207 associated with the tag v_1.5.38. Release built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Logback 1.5.37

2026-06-26 Release of logback version 1.5.37

  1. • Given the numerous vulnerabilities related to conditional configuration processing based on the evaluation of Java expressions using the Janino library, support for such expressions has been removed. Users are offered the an online migration service or the <condition> element introduced in version 1.5.20. See the relevant documentation for more details.

• A bitwise identical binary of this version can be reproduced by building from source code at commit c1df7f522e648eec7b4ef6a12c8758fec0f00048 associated with the tag v_1.5.37. Release built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Logback 1.5.36

2026-06-25 Release of logback version 1.5.36

• The 'condition' attribute in <if> elements now reject certain references that are associated with ACE attacks. This issue was reported by "yulate" (yulate531@gmail.com.com) and registered as CVE-2026-13006. Please note that version 1.5.37 provides the full fix to this vulnerability.

... (truncated)

Commits
  • 57759f4 prepare release 1.6.1
  • 175f99f fix imports
  • 4b8773e add compressionFailureLeavesOriginalFileIntact test for XZ compression
  • cafaf11 do not delete original file if compression fails
  • ee50125 let the temporary file before compression be target file without the .gz or ....
  • 5626acc minor refactoring
  • d97da4f minor refactoring
  • 159c045 more defensive coding in SyslogOutputStream and in SyslogAppenderBase
  • 9427d6b slight refactoring for clarity
  • 79c4179 slight refactoring
  • Additional commits viewable in compare view

Updates ch.qos.logback:logback-core from 1.4.14 to 1.6.1

Release notes

Sourced from ch.qos.logback:logback-core's releases.

Logback 1.6.1

2026-07-28 Release of logback version 1.6.1

• In TimeBasedRollingPolicy, when the file option is set, the intermediate file renamed before asynchronous compression now receives the target archive name without the compression suffix (e.g. .gz, .zip, .xz). Previously it used a nanotime-based .tmp suffix. This makes the file easier to identify if compression fails during rollover. (See also the following paragraph.)

• On GZ, ZIP, or XZ compression failure, the original (uncompressed) log file is no longer deleted. Compression strategies now delete the source file only after successful compression and emit a warning that the original was left intact.

• ConsoleAppender with now probes JLine's org.jline.jansi.AnsiConsole first and falls back to the legacy FuseSource org.fusesource.jansi.AnsiConsole class. This keeps ANSI coloring working after Jansi moved under the JLine project. The optional org.jline:jansi-core artifact is declared as a dependency alongside the existing FuseSource jansi dependency. A preferredJansiClassName property was added for tests. This issue was reported in issues/1043 by seonwoo_jung who also provided the relevant PR.

• LayoutWrappingEncoder now reports an error at start() when no layout is set and guards encode() against a null layout. Previously, a missing layout (for example after an ignored // branch) allowed the encoder to start and then fail with a NullPointerException on every event, resulting in silent log loss. This issue was reported in issues/1046 by seonwoo_jung who also provided the relevant PR.

• FileCollisionAnalyser now detects file collisions involving nested appenders of SiftingAppender. When the nested file or fileNamePattern does not textually reference the discriminator key (e.g. ${userId}), a warning is issued at configuration time naming the appender, the key, and the shared target. This closes a gap where statically declared file appenders were checked but sifted nested appenders were not. This enhancement was contributed in [PR #1041](qos-ch/logback#1041) by seonwoo_jung.

• More defensive handling in SyslogOutputStream and SyslogAppenderBase: the close() method now ensures that resources are closed, writes and flushes check that the underlying resources are in a valid state and fallback to no-op otherwise.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit 57759f433000a133088ef0441038963134437fbd associated with the tag v_1.6.1. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

• See https://logback.qos.ch/news.html#1.6.1 for the original text.

Logback 1.6.0

2026-07-23 Release of logback version 1.6.0

• Removed certain deprecated variables, methods, and classes. For the list of removed members see release_1.6.0.txt.

• In AsyncAppenderBase, the put(ILoggingEvent) method now has the protected modifier to allow access from derived classes. This change was requested by Thomas Skjølberg in pr#1053.

• Bump SLF4J dependency to version 2.0.18.

See also the overview of the 1.6.x series.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit b07adf36019b51a10f824fdd94009985c587b1d3 associated with the tag v_1.6.0. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Logback 1.5.38

2026-07-09 Release of logback version 1.5.38

• In HardenedObjectInputStream, fixed a typo preventing Throwable objects from being white-filtered. This issue was reported in [PR #1045](qos-ch/logback#1045) by t0rchwo0d.

• A bitwise identical binary of this version can be reproduced by building from source code at commit d04984a41fce42977466f45a2f076f0ee5cc4207 associated with the tag v_1.5.38. Release built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Logback 1.5.37

2026-06-26 Release of logback version 1.5.37

  1. • Given the numerous vulnerabilities related to conditional configuration processing based on the evaluation of Java expressions using the Janino library, support for such expressions has been removed. Users are offered the an online migration service or the <condition> element introduced in version 1.5.20. See the relevant documentation for more details.

• A bitwise identical binary of this version can be reproduced by building from source code at commit c1df7f522e648eec7b4ef6a12c8758fec0f00048 associated with the tag v_1.5.37. Release built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Logback 1.5.36

2026-06-25 Release of logback version 1.5.36

• The 'condition' attribute in <if> elements now reject certain references that are associated with ACE attacks. This issue was reported by "yulate" (yulate531@gmail.com.com) and registered as CVE-2026-13006. Please note that version 1.5.37 provides the full fix to this vulnerability.

... (truncated)

Commits
  • 57759f4 prepare release 1.6.1
  • 175f99f fix imports
  • 4b8773e add compressionFailureLeavesOriginalFileIntact test for XZ compression
  • cafaf11 do not delete original file if compression fails
  • ee50125 let the temporary file before compression be target file without the .gz or ....
  • 5626acc minor refactoring
  • d97da4f minor refactoring
  • 159c045 more defensive coding in SyslogOutputStream and in SyslogAppenderBase
  • 9427d6b slight refactoring for clarity
  • 79c4179 slight refactoring
  • Additional commits viewable in compare view

Updates org.slf4j:jcl-over-slf4j from 2.0.12 to 2.0.18

Updates org.slf4j:log4j-over-slf4j from 2.0.12 to 2.0.18

Updates org.freemarker:freemarker from 2.3.33 to 2.3.34

Updates org.apache.lucene:lucene-core from 7.6.0 to 7.7.3

Updates org.apache.lucene:lucene-analyzers-common from 7.6.0 to 7.7.3

Updates org.apache.lucene:lucene-highlighter from 7.6.0 to 7.7.3

Updates org.apache.lucene:lucene-queryparser from 7.6.0 to 7.7.3

Updates org.quartz-scheduler:quartz from 2.3.2 to 2.5.2

Release notes

Sourced from org.quartz-scheduler:quartz's releases.

Quartz 2.5.2

This is a bug-fix and dependency upgrade release of the 2.5.x line.

All changes/updates:

Completed Issues

Jars can be found on Maven Central:
quartz.jar quartz-jobs.jar

Quartz 2.5.1

This is a bug-fix and dependency upgrade release of the 2.5.x line.

All changes/updates:

Completed Issues

Jars can be found on Maven Central:
quartz.jar quartz-jobs.jar

Quartz 2.5.0

Most Significant Changes This Release (over 2.4.0):

[!IMPORTANT]
BREAKING CHANGE: Move to Jakarta namespace

[!IMPORTANT]
BREAKING CHANGE: Move to JDK 11

All changes/updates:

Open Issues

Completed Issues

Quartz 2.4.1

This is a bug-fix and dependency upgrade release of the 2.4.x line.

All changes/updates:

Completed Issues

Jars can be found on Maven Central:
quartz.jar quartz-jobs.jar

Quartz 2.4.0

Most Significant Changes This Release:

... (truncated)

Commits
  • ed52d39 Set quartzVersion to 2.5.2
  • 4406ab0 Merge pull request #1426 from mprins/patch-1
  • a73dab0 Merge pull request #1424 from jhouserizer/fix1420
  • ed6fb43 Fix interval calculation for hourly triggers
  • 8853377 fix #1420, issue with nearest weekday expressions
  • 9307232 Merge pull request #1414 from quartz-scheduler/dependabot/gradle/main/commons...
  • d0500cf build(deps): bump commons-io:commons-io from 2.20.0 to 2.21.0
  • a745be8 Merge pull request #1423 from jhouserizer/fix1422_use_nvarchar_for_sqlserver
  • b9e92c3 Change SQL Server DDL to use NVARCHAR instead of VARCHAR for perf reasons, se...
  • 86f1e12 Merge pull request #1411 from rydenius/jorgen/case-insensitive-postgresql
  • Additional commits viewable in compare view

Updates com.mchange:c3p0 from 0.9.5.5 to 0.14.1

Changelog

Sourced from com.mchange:c3p0's changelog.

    -- Reorganize the build, which previously was basically a direct port of an ancient ant
 build, into a build that is reliable, much simpler, and respects the mill-build philosophy.
 (With a lot of help from claude.ai, this one.)
    -- The Statement cache was clearing parameters and batches, but otherwise not resetting
       Statement state that may have been modified by prior users' activity. We now carefully
       either reset mutated Statement state, or refuse to re-cache on operations that change
       state in ways we can't reverse. Many thanks to Fredrik Jeppsson for calling attention
       to this issue!

c3p0-0.14.1 -- Modify c3p0 to use new BeanInfoGen functionality, restoring compatability with Java [7,11). -- Modify BeanInfoGen to (optionally but by default) cache descriptors rather than regenerating for each call to an introspection method. -- Modify BeanInfoGen to log items skipped from descriptors due to API incompatibility. -- Modify BeanInfoGen to generate BeanInfo classes in which properties/events/methods that existed in the JVM under which they were generated and built, but do not exist under the runtime JVM are tolerate, simply omitted at runtime from BeanInfo descriptors. This fixes compatability with Java environments before Java 11, under whose API c3p0 and mchange-commons-java are currently built. (Thanks to Vlad Skarzhevskyy, @​skarzhevskyy on GitHub, for calling attention to this issue.) c3p0-0.14.0 -- Update to mill 1.1.6 and fix broken support for reproducible builds via the SOURCE_DATE_EPOCH environment variable. -- Generate explicit BeanInfo classes for c3p0-defined concrete DataSource and ConnectionPoolDataSource implementations, which exclude "connection" and/or "pooledConnection" from introspected bean properties, in order to preclude attacks such as those described here: https://mogwailabs.de/en/blog/2023/04/look-mama-no-templatesimpl/ -- Enforce a deterministic ordering on methods produced by the code generator DelegatorGenerator, in order to keep builds including such generated classes reproducible. (mchange-commons-java and c3p0 subclass) -- Define BeanInfoGen, a code-generation utility that defines explicit BeanInfo classes for what otherwise would have been introspected via JavaBean naming conventions, but that permits properties to be excluded from such introspection. (mchange-commons-java) -- JavaBeanObjectFactory now enforces a whitelist of classes it is willing to construct from References that call upon it. That whitelist is defined by new config parameter com.mchange.v2.naming.referenceableJavaBeanClassWhitelist (mchange-commons-java) -- Define false-biased config security key com.mchange.v2.naming.allowIndirectSerializationViaReference, disabling by default indirect serialization/deserialization of Referenceable but otherwise not serializable objects by serializing their references. This is a clever mechanism, but rarely used, and a place where attackers might smuggle a malicious reference. (mchange-commons-java) c3p0-0.13.0 -- Ensure sessions are marked as endRequest() is called prior to check-in, to eliminate race between DBMS cleanup and checkout by a new client. Thanks Krrish (ota0912 on github). -- Take generic JavaBeanObjectFactory out of the whitelist of object factories, com.mchange.v2.naming.objectFactoryWhitelist, mchange-commons-java ReferenceableUtils is willing to dereference. Only C3P0JavaBeanObjectFactory should be used. -- Modify C3P0JavaBeanObjectFactory to use C3P0JavaBeanReferencePropertyOverrider. -- Modify the JavaBeanReferenceMaker employed by c3p0 beans to use C3P0JavaBeanReferencePropertyOverrider -- Define C3P0JavaBeanReferencePropertyOverrider, supporting the serialization and deserialization of user-defined config key value pairs (the 'extensions' property) -- Add support for extensions, in the form of JavaBeanReferencePropertyOverrider, that allow javax.naming.Referenceable JavaBeans that include non-String, non-coerceable-to-string,

... (truncated)

Commits
  • 9084ab6 Update versions for mchange-commons-java 0.6.1, c3p0-0.14.1 final.
  • 6579705 Add release notes for 0.14.1, update CHANGELOG.
  • 8b58820 Use new functionality in BeanInfoGen, don't suppress caching (ie cache BeanIn...
  • 993b9c2 Bump version to 0.14.1-SNAPSHOT, mchange-commons-java version to 0.6.1-SNAPSHOT.
  • 931fd53 Update test console scala version, versions for mchange-commons-java 0.6.0 fi...
  • 76cff33 Extremely minor tweaks to tests.
  • d35e3b1 Wrote release notes for 0.14.0.
  • 50c128a Update CHANGELOG for 0.14.0, README.md fixes.
  • d7ae528 Update README.md to track changes to the test.runClasspath task, when explain...
  • 2607761 Update README.md for 0.14.0, add to brief note re security fixes, describe re...
  • Additional commits viewable in compare view

Updates org.postgresql:postgresql from 42.7.7 to 42.7.13

Release notes

Sourced from org.postgresql:postgresql's releases.

v42.7.13

Changes

  • docs: add 42.7.13 release changelog @​davecramer (#4270)
  • Adjust EditorConfig für Makefile @​BaumiCoder (#4279)
  • fix(scram): fail closed on channel-binding downgrade (no scram bump) @​vlsi (#4272)
  • Bump pgjdbc version from 42.7.12 to 42.7.13 @​davecramer (#4269)
  • chore: remove test-anorm-sbt module and its disabled CI wiring @​vlsi (#4261)
  • refactor(test-gss): convert to Java/JUnit 5 submodule of the main build @​vlsi (#4166)
  • ci: derive PG test versions from a Renovate-managed maxPgVersion @​vlsi (#4218)
  • feat(insert): cap reWriteBatchedInserts by the protocol limit, not 128 @​vlsi (#4207)
  • refactor(metadata): derive getPrimaryKeys from pg_constraint.conkey @​vlsi (#4202)
  • fix(protocol): defer flushes until response processing @​vlsi (#4196)
  • fix(build): resolve the Temurin 8 test toolchain by vendor @​vlsi (#4257)
  • build: include multi-release source sets in the JaCoCo coverage report @​vlsi (#4256)
  • fix(ci): read java_vendor before overwriting java_distribution @​vlsi (#4255)
  • ci: generate the whole matrix in one batch, coverage job included @​vlsi (#4253)
  • ci: pass CODECOV_TOKEN so protected-branch coverage uploads succeed @​vlsi (#4254)
  • ci: collect coverage on one pinned job @​vlsi (#4245)
  • ci: apply -DqueryTimeout from the matrix query_timeout axis @​vlsi (#4246)
  • ci: make Codecov project and patch statuses informational @​vlsi (#4244)
  • fix(build): restore JaCoCo XML report so Codecov receives coverage @​vlsi (#4240)
  • test(replication): shrink big-transaction inserts to avoid CI timeouts @​vlsi (#4243)
  • update maintainers @​davecramer (#4222)
  • test: add hermetic test for localSocketAddress @​vlsi (#4224)
  • docs(translation): clean up leftover German header in ja.po @​vlsi (#4206)
  • Update ja.po @​davecramer (#2004)
  • test: add PostgreSQL 18 to the CI test matrix @​vlsi (#4198)
  • test: silence expected SSPI warning stack trace in SSPIClientWaffleTest @​vlsi (#4197)
  • fix(ssl): build PKIX trust anchors without a KeyStore so FIPS-mode JVMs can load sslrootcert @​vlsi (#4193)
  • test: fix flaky sentLocationEqualToLastReceiveLSN replication test @​vlsi (#4175)
  • build: promote MethodCanBeStatic to error level @​vlsi (#4172)
  • Fix PGInterval.setSeconds to reject out of range and NaN values @​sehrope (#4194)
  • Replace connectThreadFactory with connectExecutor @​sehrope (#4165)
  • Fix deleting temp file when spooling large stream to disk in StreamWrapper @​sehrope (#4190)
  • chore: Add top level /scratch to gitignore @​sehrope (#4164)
  • refactor: favour composition over inheritance for Driver.ConnectTask @​vlsi (#4160)
  • Fix NumberParser.getFastLong(...) handling of overlong values @​sehrope (#4163)
  • build: produce a multi-release jar from reduced-pom.xml on Java 11+ @​vlsi (#4157)
  • Add connectThreadFactory and refactor Driver to use FutureTask for loginTimeout connection attempts @​sehrope (#4120)
  • test: verify custom properties reach socket factory @​vlsi (#4125)
  • test: fix LazyCleanerTest timeouts for the lingering Java 8 cleanup thread @​vlsi (#4122)
  • test: stabilise StatementTest.fastCloses on Windows @​vlsi (#4121)
  • fix: append default non-proxy hosts when socksNonProxyHosts is set @​davecramer (#4045)
  • test: budget terminating Sync in BatchDeadlockTest small-RETURNING branch @​vlsi (#4116)
  • test: make message assertions locale-independent @​vlsi (#4113)
  • build: drop xgettext default keywords; regenerate translations @​vlsi (#4100)
  • ci: opt-in scheduled workflows via ENABLE_SCHEDULED_JOBS repo variable @​vlsi (#4085)
  • Avoid direct java.lang.management dependency in maxResultBuffer parser @​mblakley-casana (#4069)
  • fix: restore pre-describe for generated-key batches @​bilalshehata (#4014)

... (truncated)

Changelog

Sourced from org.postgresql:postgresql's changelog.

[42.7.13] (2026-07-06)

Added

  • feat: invalidate the prepared-statement cache when the server reports a search_path change via GUC_REPORT (PostgreSQL 18+), so cached plans are no longer used against the wrong schema [PR #4259](pgjdbc/pgjdbc#4259)
  • feat: reWriteBatchedInserts now merges up to 32768 rows into one multi-values INSERT (bounded by the 65535 bind-parameter limit on the extended protocol) instead of capping at 128, which speeds up batches of few-column rows. The new reWriteBatchedInsertsSize connection property lowers that cap when set; the default of 0 uses that maximum. [PR #4207](pgjdbc/pgjdbc#4207)
  • feat: invalidate the prepared-statement cache after CREATE/DROP/ALTER so callers no longer trip on "cached plan must not change result type" without opting into autosave=ALWAYS. Controlled by the new flushCacheOnDdl connection property (default true); set to false for the prior behaviour. [PR #4067](pgjdbc/pgjdbc#4067)
  • feat: add connectExecutor connection property to customize the Executor used to run the worker task that performs the connection attempt when loginTimeout is in effect. The value is the fully qualified name of a class implementing java.util.concurrent.Executor. With a null value, the default, the driver retains the prior behavior of running the connection attempt on a daemon thread named "PostgreSQL JDBC driver connection thread". The executor must run the task on a thread other than the caller's. Running the attempt on a named thread lets applications that monitor driver-created threads identify it. [PR #4165](pgjdbc/pgjdbc#4165)
  • feat: add classLoaderStrategy connection property to control which classloaders the driver searches when loading a class named by a connection property, for example socketFactory. The default driver-first now falls back to the thread context classloader when the driver's classloader cannot resolve the class, which fixes class loading in non-flat class paths such as Quarkus and OSGi. Set driver to keep the previous driver-classloader-only behaviour, or context-first to prefer the thread context classloader [Issue #2112](pgjdbc/pgjdbc#2112) [PR #4167](pgjdbc/pgjdbc#4167)
  • feat: add OID constants for geometric arrays, RECORD, and refcursor [PR #4220](pgjdbc/pgjdbc#4220)
  • feat: LargeObject BlobInputStream now skips by seeking instead of reading, and the driver exposes the server version so it can select the 64-bit large-object API where available [PR #4204](pgjdbc/pgjdbc#4204)

Changed

  • refactor: the worker that runs the connection attempt under loginTimeout is now a FutureTask (ConnectTask) instead of the hand-rolled ConnectThread. When the caller hits the timeout, the task is now cancelled with cancel(true), which interrupts the worker thread rather than letting it run to completion. This makes the connection attempt interruptible, so loginTimeout can stop a slow connection attempt instead of leaking a thread. As before, a connection that the worker still manages to establish after the caller gives up is closed by the worker so that it does not leak. There are no public API changes and this should only lead to faster background resource cleanup for connections that time out. [PR #4120](pgjdbc/pgjdbc#4120)
  • chore: PGXAConnection.ConnectionHandler now rejects setAutoCommit(false) and setSavepoint(...) during an active XA branch, in addition to the long-rejected setAutoCommit(true) / commit() / rollback(). The setSavepoint rejection was already meant to be in place but the guard misspelled the method name as setSavePoint, so savepoints silently went through. Both changes bring the proxy in line with JTA 1.2 §3.4. [PR #4114](pgjdbc/pgjdbc#4114)
  • chore: commitPrepared / rollback-of-prepared now return XAER_RMFAIL instead of XAER_RMERR when the underlying connection is left in a non-idle TransactionState. Transaction managers (Geronimo, Narayana, Atomikos) treat XAER_RMFAIL as retryable on a fresh XAResource; the prepared transaction is no longer abandoned. [PR #4114](pgjdbc/pgjdbc#4114)
  • refactor: derive getPrimaryKeys from pg_constraint.conkey [PR #4202](pgjdbc/pgjdbc#4202)

Fixed

  • fix: the published GitHub release now ships the released postgresql-<version>.jar and its detached PGP signature, taken from the same signed build that is uploaded to Maven Central, instead of a leftover SNAPSHOT jar [Issue #3812](pgjdbc/pgjdbc#3812) [PR #3814](pgjdbc/pgjdbc#3814)
  • fix: simplify the Statement#cancel state machine by dropping the redundant CANCELLED state. killTimerTask now waits for the state to return to IDLE directly, which removes a spin-forever case when more than one thread observes the cancel completing [PR #1827](pgjdbc/pgjdbc#1827).
  • perf: defer simple-query flushes until the driver reads the response, allowing BEGIN and the following query to share a network flush [Issue #3894](pgjdbc/pgjdbc#3894) [PR #4196](pgjdbc/pgjdbc#4196)
  • fix: reWriteBatchedInserts no longer throws IllegalArgumentException when batching a parameterless INSERT (for example INSERT INTO t VALUES (1, 2)) of 256 rows or more [PR #4207](pgjdbc/pgjdbc#4207)
  • fix: a comment before CALL in a CallableStatement no longer hides the native call, so OUT parameter registration works for /* comment */ call proc(?, ?) and similar. Parser.modifyJdbcCall now skips leading whitespace and SQL comments (both -- and /* */) before the call, tolerates a trailing comment after a { ... } escape, and no longer adds a spurious comma when moving an OUT parameter into a call whose arguments are only a comment [Issue #2538](pgjdbc/pgjdbc#2538) [PR #4209](pgjdbc/pgjdbc#4209)
  • fix: PreparedStatement.toString() no longer throws for a bytea value supplied as text via PGobject. Hex-format values (\x...) are validated and rendered as a bytea literal, and escape-format values are quoted and cast like any other literal [Issue #3757](pgjdbc/pgjdbc#3757) [PR #4201](pgjdbc/pgjdbc#4201)
  • fix: the driver no longer nulls the contextClassLoader of shared ForkJoinPool.commonPool() worker threads, which previously left unrelated tasks on those threads running with a null classloader [Issue #4155](pgjdbc/pgjdbc#4155) [PR #4156](pgjdbc/pgjdbc#4156)
  • fix: PgResultSet#getCharacterStream wraps String in a StringReader [PR #4063](pgjdbc/pgjdbc#4063)
  • fix: PGXAConnection no longer saves and restores the underlying connection's JDBC autoCommit flag. All XA-protocol SQL (BEGIN, PREPARE TRANSACTION, COMMIT, ROLLBACK, COMMIT PREPARED, ROLLBACK PREPARED, the recover() SELECT) is sent through QUERY_SUPPRESS_BEGIN, so the caller's autoCommit value is invariant across every XAResource call. Fixes the "2nd phase commit must be issued using an idle connection" failure during recovery on managed datasources that pool connections with autoCommit=false (TomEE, WildFly, WebSphere Liberty) [PR #4114](pgjdbc/pgjdbc#4114)
  • fix: PGXAConnection.prepare() now mutates XA state only after PREPARE TRANSACTION succeeds. A failed PREPARE previously left the driver thinking the branch was already prepared, so the follow-up rollback(xid) tried ROLLBACK PREPARED against a non-existent gid and returned XAER_RMERR. Transaction managers (Narayana) escalated this to HeuristicMixedException. With the fix, rollback(xid) takes the active-branch path and issues a plain ROLLBACK, which the server accepts cleanly. Fixes [Issue #3153](pgjdbc/pgjdbc#3153), [Issue #3123](pgjdbc/pgjdbc#3123). [PR #4114](pgjdbc/pgjdbc#4114)
  • fix: an updatable result set over an unqualified table name is now classified using only the table visible through search_path. When two schemas held a table with the same name and the same primary or unique index name but a different set of key columns, the driver took the union of both schemas' columns, so the result set could be wrongly rejected as not updatable [PR #4214](pgjdbc/pgjdbc#4214). Supersedes [PR #3400](pgjdbc/pgjdbc#3400).
  • fix: LargeObject.close() now flushes a buffered output stream before marking the object closed, so closing a large object without an explicit flush() no longer drops buffered writes. The flush runs while the object is still open (it calls back into LargeObject.write()), and lo_close always runs afterward; a failure from lo_close no longer masks an earlier flush error, and the transaction is not committed when the flush failed [Issue #4247](pgjdbc/pgjdbc#4247) [PR #4248](pgjdbc/pgjdbc#4248).
  • fix: reject empty timestamp, timestamptz, and date text with a clear SQLException (SQLState 22007) instead of an ArrayIndexOutOfBoundsException [PR #4278](pgjdbc/pgjdbc#4278)
  • fix: return null CHAR_OCTET_LENGTH for non-character columns [PR #4231](pgjdbc/pgjdbc#4231)
  • fix: honor scale in ResultSet.getBigDecimal(int, int) [PR #4211](pgjdbc/pgjdbc#4211)
  • fix: support java.time values in an updatable ResultSet updateRow() / insertRow() [PR #3848](pgjdbc/pgjdbc#3848)
  • fix: improve batching when the RETURNING clause contains varchar or numeric types [PR #4014](pgjdbc/pgjdbc#4014)
  • fix: correct estimatedReceiveBufferBytes accounting after a forced Sync [PR #4014](pgjdbc/pgjdbc#4014)
  • fix: avoid creating a transient ResultSet for describe-statement purposes, and restore the pre-describe path for generated-key batches [PR #4014](pgjdbc/pgjdbc#4014)
  • fix: add an explicit failure message when a multi-statement command executes in a batch [PR #4014](pgjdbc/pgjdbc#4014)
  • fix: detect search_path changes case-insensitively [PR #4216](pgjdbc/pgjdbc#4216)
  • fix: auto-detect the SSL key format instead of relying on the .key extension [PR #3946](pgjdbc/pgjdbc#3946)
  • fix: build PKIX trust anchors without a KeyStore so FIPS JVMs work [PR #4193](pgjdbc/pgjdbc#4193)
  • fix: use gssResponseTimeout rather than sslResponseTimeout for GSS connections [PR #4076](pgjdbc/pgjdbc#4076)
  • fix: skip the autosave savepoint for SET LOCAL / SET SESSION TRANSACTION [PR #4203](pgjdbc/pgjdbc#4203)
  • fix: do not throw AssertionError from BatchResultHandler on a closed connection [PR #4187](pgjdbc/pgjdbc#4187)
  • fix: reject SQL_TSI_FRAC_SECOND with an explicit, explained error [PR #4229](pgjdbc/pgjdbc#4229)
  • fix: reject a null URL in Driver.acceptsURL with a clear NullPointerException [PR #4205](pgjdbc/pgjdbc#4205)
  • fix: reject overlong inputs in NumberParser.getFastLong instead of silently wrapping [PR #4163](pgjdbc/pgjdbc#4163)
  • fix: reject out-of-range and NaN values in PGInterval.setSeconds [PR #4194](pgjdbc/pgjdbc#4194)
  • fix: close the socket when PgConnection setup fails after connect [PR #4161](pgjdbc/pgjdbc#4161)
  • fix: keep the LazyCleanerImpl cleanup task alive across a transient empty queue [PR #4038](pgjdbc/pgjdbc#4038)

... (truncated)

Commits
  • 3297557 docs: add 42.7.13 release changelog (#4270)
  • d93d370 style: apply Autostyle to docs/ and .github/
  • 2e05ff9 build: check docs/ and .github/ formatting with Autostyle
  • b4a6087 Adjust EditorConfig für Makefiles
  • 725cebb fix(jdbc): reject empty timestamp/timestamptz text with a clear error
  • 23a1b0d fix(scram): fail closed on channel-binding downgrade (no scram bump)
  • 0b4077a Bump pgjdbc version from 42.7.12 to 42.7.13 (#4269)
  • 394800a fix: flush LargeObject output stream before marking closed (#4248)
  • 83780f1 Maintain consistency with the use of the word maintainer vs comitter (#4234)
  • d42cad5 fix(jdbc): classify updatable result set by search_path visibility
  • Additional commits viewable in compare view

Updates commons-codec:commons-codec from 1.17.0 to 1.22.1

Changelog

Sourced from commons-codec:commons-codec's changelog.

Apache Commons Codec 1.22.1 Release Notes

The Apache Commons Codec team is pleased to announce the release of Apache Commons Codec 1.22.1.

The Apache Commons Codec component contains encoders and decoders for formats such as Base16, Base32, Base64, digest, and Hexadecimal. In addition to these widely used encoders and decoders, the codec package also maintains a collection of phonetic encoding utilities.

This is a feature and maintenance release. Java 8 or later is required.

Fixed Bugs

  • CODEC-344: Base64.Builder.setEncodeTable(byte...) accepts invalid custom alphabets. Thanks to Ruiqi Dong, Gary Gregory.
  • CODEC-340: Base58.Builder.setEncodeTable(byte...) is ignored when encoding and decoding. Thanks to Ruiqi Dong, Gary Gregory.
  • CODEC-342: Base32.Builder.setEncodeTable(byte...) can create a codec that cannot decode its own output. Thanks to Ruiqi Dong, Gary Gregory.
  • CODEC-343: Base32.Builder.setHexDecodeTable(boolean) sets the encode table to a decode lookup table. Thanks to Ruiqi Dong, Gary Gregory.
  • CODEC-341: Base16.Builder.setEncodeTable(byte...) can create a codec that cannot decode its own output. Thanks to Ruiqi Dong, Gary Gregory.
  • CODEC-339: URLCodec.encodeUrl(BitSet, byte[]) allows custom safe sets to emit URL encoding control characters. Thanks to Ruiqi Dong, Gary Gregory.
  • CODEC-338: PercentCodec loses literal '+' when plusForSpace is enabled. Thanks to Ruiqi Dong, Gary Gregory.
  • CODEC-337: Digest ALL reuses System.in, so only the first algorithm sees the real input (#431). Thanks to Ruiqi Dong, Gary Gregory.
  •         Fix Base64.toIntegerBytes(BigInteger) for zero edge case ([#441](https://github.com/apache/commons-codec/issues/441)). Thanks to Gary Gregory.
    
  •         Add messages when throwing NullPointerException. Thanks to Gary Gregory.
    
  •         Add messages when throwing NullPointerException. Thanks to Gary Gregory.
    
  •         StringEncoderComparator.StringEncoderComparator(StringEncoder) now fails fast on null input. Thanks to Gary Gregory.
    

Changes

  •         Bump org.ap...
    

    Description has been truncated

Bumps the minor-and-patch group with 10 updates in the / directory:

| Package | From | To |
| --- | --- | --- |
| org.slf4j:slf4j-api | `2.0.12` | `2.0.18` |
| [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) | `1.4.14` | `1.6.1` |
| org.freemarker:freemarker | `2.3.33` | `2.3.34` |
| org.apache.lucene:lucene-core | `7.6.0` | `7.7.3` |
| [org.quartz-scheduler:quartz](https://github.com/quartz-scheduler/quartz) | `2.3.2` | `2.5.2` |
| [com.mchange:c3p0](https://github.com/swaldman/c3p0) | `0.9.5.5` | `0.14.1` |
| [org.postgresql:postgresql](https://github.com/pgjdbc/pgjdbc) | `42.7.7` | `42.7.13` |
| [commons-codec:commons-codec](https://github.com/apache/commons-codec) | `1.17.0` | `1.22.1` |
| com.palantir.git-version | `4.0.0` | `4.3.0` |
| [gradle-wrapper](https://github.com/gradle/gradle) | `9.0.0` | `9.7.0` |



Updates `org.slf4j:slf4j-api` from 2.0.12 to 2.0.18

Updates `ch.qos.logback:logback-classic` from 1.4.14 to 1.6.1
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.4.14...v_1.6.1)

Updates `ch.qos.logback:logback-core` from 1.4.14 to 1.6.1
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.4.14...v_1.6.1)

Updates `org.slf4j:jcl-over-slf4j` from 2.0.12 to 2.0.18

Updates `org.slf4j:log4j-over-slf4j` from 2.0.12 to 2.0.18

Updates `org.freemarker:freemarker` from 2.3.33 to 2.3.34

Updates `org.apache.lucene:lucene-core` from 7.6.0 to 7.7.3

Updates `org.apache.lucene:lucene-analyzers-common` from 7.6.0 to 7.7.3

Updates `org.apache.lucene:lucene-highlighter` from 7.6.0 to 7.7.3

Updates `org.apache.lucene:lucene-queryparser` from 7.6.0 to 7.7.3

Updates `org.quartz-scheduler:quartz` from 2.3.2 to 2.5.2
- [Release notes](https://github.com/quartz-scheduler/quartz/releases)
- [Commits](quartz-scheduler/quartz@v2.3.2...v2.5.2)

Updates `com.mchange:c3p0` from 0.9.5.5 to 0.14.1
- [Changelog](https://github.com/swaldman/c3p0/blob/0.15.x/CHANGELOG)
- [Commits](swaldman/c3p0@c3p0-0.9.5.5...v0.14.1)

Updates `org.postgresql:postgresql` from 42.7.7 to 42.7.13
- [Release notes](https://github.com/pgjdbc/pgjdbc/releases)
- [Changelog](https://github.com/pgjdbc/pgjdbc/blob/master/CHANGELOG.md)
- [Commits](pgjdbc/pgjdbc@REL42.7.7...REL42.7.13)

Updates `commons-codec:commons-codec` from 1.17.0 to 1.22.1
- [Changelog](https://github.com/apache/commons-codec/blob/master/RELEASE-NOTES.txt)
- [Commits](apache/commons-codec@rel/commons-codec-1.17.0...rel/commons-codec-1.22.1)

Updates `com.palantir.git-version` from 4.0.0 to 4.3.0

Updates `gradle-wrapper` from 9.0.0 to 9.7.0
- [Release notes](https://github.com/gradle/gradle/releases)
- [Commits](gradle/gradle@v9.0.0...v9.7.0)

---
updated-dependencies:
- dependency-name: org.slf4j:slf4j-api
  dependency-version: 2.0.18
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: ch.qos.logback:logback-classic
  dependency-version: 1.6.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: ch.qos.logback:logback-core
  dependency-version: 1.6.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: org.slf4j:jcl-over-slf4j
  dependency-version: 2.0.18
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: org.slf4j:log4j-over-slf4j
  dependency-version: 2.0.18
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: org.freemarker:freemarker
  dependency-version: 2.3.34
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: org.apache.lucene:lucene-core
  dependency-version: 7.7.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: org.apache.lucene:lucene-analyzers-common
  dependency-version: 7.7.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: org.apache.lucene:lucene-highlighter
  dependency-version: 7.7.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: org.apache.lucene:lucene-queryparser
  dependency-version: 7.7.3
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: org.quartz-scheduler:quartz
  dependency-version: 2.5.2
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: com.mchange:c3p0
  dependency-version: 0.14.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: org.postgresql:postgresql
  dependency-version: 42.7.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: minor-and-patch
- dependency-name: commons-codec:commons-codec
  dependency-version: 1.22.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: com.palantir.git-version
  dependency-version: 4.3.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
- dependency-name: gradle-wrapper
  dependency-version: 9.7.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Aug 12, 2026
@maximkr
maximkr merged commit e3960d7 into main Aug 12, 2026
5 checks passed
@maximkr
maximkr deleted the dependabot/gradle/minor-and-patch-8cc327413f branch August 12, 2026 10:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant