Skip to content

chore(deps): bump the maven-dependencies group with 25 updates - #2848

Merged
lprimak merged 1 commit into
2.xfrom
dependabot/maven/2.x/maven-dependencies-337e9caf20
Aug 2, 2026
Merged

chore(deps): bump the maven-dependencies group with 25 updates#2848
lprimak merged 1 commit into
2.xfrom
dependabot/maven/2.x/maven-dependencies-337e9caf20

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 1, 2026

Copy link
Copy Markdown
Contributor

Bumps the maven-dependencies group with 30 updates:

Package From To
org.apache.groovy:groovy-all 4.0.32 4.0.33
org.apache.groovy:groovy 4.0.32 4.0.33
net.bytebuddy:byte-buddy 1.18.10 1.18.11
net.bytebuddy:byte-buddy-agent 1.18.10 1.18.11
org.apache.logging.log4j:log4j-slf4j2-impl 2.26.0 2.26.1
org.apache.logging.log4j:log4j-core-test 2.26.0 2.26.1
org.apache.logging.log4j:log4j-api 2.26.0 2.26.1
org.apache.logging.log4j:log4j-core 2.26.0 2.26.1
org.apache.logging.log4j:log4j-jul 2.26.0 2.26.1
org.apache.logging.log4j:log4j-to-slf4j 2.26.0 2.26.1
ch.qos.logback:logback-core 1.5.37 1.6.1
ch.qos.logback:logback-classic 1.5.37 1.6.1
org.bouncycastle:bcprov-jdk18on 1.84 1.85
org.apache.maven.plugins:maven-help-plugin 3.5.1 3.5.2
org.codehaus.gmavenplus:gmavenplus-plugin 5.0.0 5.1.0
com.mycila:license-maven-plugin 5.0.0 5.1.1
org.apache.tomcat.embed:tomcat-embed-core 9.0.119 9.0.120
org.apache.tomcat.embed:tomcat-embed-el 9.0.119 9.0.120
org.apache.tomcat.embed:tomcat-embed-websocket 9.0.119 9.0.120
org.apache.tomcat:tomcat-jaspic-api 9.0.119 9.0.120
org.apache.tomcat:tomcat-catalina 9.0.119 9.0.120
org.omnifaces:omnifaces 3.14.21 3.14.23
io.openliberty.tools:liberty-maven-plugin 3.12.0 3.12.1
org.apache.tomcat.embed:tomcat-embed-core 10.1.56 10.1.57
org.apache.tomcat.embed:tomcat-embed-el 10.1.56 10.1.57
org.apache.tomcat.embed:tomcat-embed-websocket 10.1.56 10.1.57
org.apache.tomcat:tomcat-jaspic-api 10.1.56 10.1.57
org.apache.tomcat:tomcat-catalina 10.1.56 10.1.57
org.apache.tomcat:tomcat-jasper 10.1.56 10.1.57
org.apache.tomcat:tomcat-jasper-el 10.1.56 10.1.57

Updates org.apache.groovy:groovy-all from 4.0.32 to 4.0.33

Commits

Updates org.apache.groovy:groovy from 4.0.32 to 4.0.33

Commits

Updates org.apache.groovy:groovy from 4.0.32 to 4.0.33

Commits

Updates net.bytebuddy:byte-buddy from 1.18.10 to 1.18.11

Release notes

Sourced from net.bytebuddy:byte-buddy's releases.

Byte Buddy 1.18.11

  • Add SBOM to published artifacts.
  • Check for traversable paths injected into class files as a rather hypothetical attack vector.
Changelog

Sourced from net.bytebuddy:byte-buddy's changelog.

2. July 2026: version 1.18.11

  • Add SBOM to published artifacts.
  • Check for traversable paths injected into class files as a rather hypothetical attack vector.
Commits
  • 88dd0a3 [publish] Releasing Byte Buddy 1.18.11
  • 46fcade [release] Release new version
  • 6a68de6 Prevent path traversal from crafted type names when writing class files to fo...
  • 9ba4ab6 Pin ClusterFuzzLite base image and actions by hash.
  • dd4f81e Add SBOM to build.
  • 7dd9a0d Update internal Byte Buddy and release notes
  • d6b3e15 [publish] Start next development iteration 1.18.11-SNAPSHOT
  • See full diff in compare view

Updates net.bytebuddy:byte-buddy-agent from 1.18.10 to 1.18.11

Release notes

Sourced from net.bytebuddy:byte-buddy-agent's releases.

Byte Buddy 1.18.11

  • Add SBOM to published artifacts.
  • Check for traversable paths injected into class files as a rather hypothetical attack vector.
Changelog

Sourced from net.bytebuddy:byte-buddy-agent's changelog.

2. July 2026: version 1.18.11

  • Add SBOM to published artifacts.
  • Check for traversable paths injected into class files as a rather hypothetical attack vector.
Commits
  • 88dd0a3 [publish] Releasing Byte Buddy 1.18.11
  • 46fcade [release] Release new version
  • 6a68de6 Prevent path traversal from crafted type names when writing class files to fo...
  • 9ba4ab6 Pin ClusterFuzzLite base image and actions by hash.
  • dd4f81e Add SBOM to build.
  • 7dd9a0d Update internal Byte Buddy and release notes
  • d6b3e15 [publish] Start next development iteration 1.18.11-SNAPSHOT
  • See full diff in compare view

Updates net.bytebuddy:byte-buddy-agent from 1.18.10 to 1.18.11

Release notes

Sourced from net.bytebuddy:byte-buddy-agent's releases.

Byte Buddy 1.18.11

  • Add SBOM to published artifacts.
  • Check for traversable paths injected into class files as a rather hypothetical attack vector.
Changelog

Sourced from net.bytebuddy:byte-buddy-agent's changelog.

2. July 2026: version 1.18.11

  • Add SBOM to published artifacts.
  • Check for traversable paths injected into class files as a rather hypothetical attack vector.
Commits
  • 88dd0a3 [publish] Releasing Byte Buddy 1.18.11
  • 46fcade [release] Release new version
  • 6a68de6 Prevent path traversal from crafted type names when writing class files to fo...
  • 9ba4ab6 Pin ClusterFuzzLite base image and actions by hash.
  • dd4f81e Add SBOM to build.
  • 7dd9a0d Update internal Byte Buddy and release notes
  • d6b3e15 [publish] Start next development iteration 1.18.11-SNAPSHOT
  • See full diff in compare view

Updates org.apache.logging.log4j:log4j-slf4j2-impl from 2.26.0 to 2.26.1

Updates org.apache.logging.log4j:log4j-core-test from 2.26.0 to 2.26.1

Updates org.apache.logging.log4j:log4j-api from 2.26.0 to 2.26.1

Updates org.apache.logging.log4j:log4j-core from 2.26.0 to 2.26.1

Updates org.apache.logging.log4j:log4j-jul from 2.26.0 to 2.26.1

Updates org.apache.logging.log4j:log4j-to-slf4j from 2.26.0 to 2.26.1

Updates org.apache.logging.log4j:log4j-core-test from 2.26.0 to 2.26.1

Updates ch.qos.logback:logback-core from 1.5.37 to 1.6.1

Release notes

Sourced from ch.qos.logback:logback-core's releases.

Logback 1.6.1

2026-07-28 Release of logback version 1.6.1

• In TimeBasedRollingPolicy, when the file option is set, the intermediate file renamed before asynchronous compression now receives the target archive name without the compression suffix (e.g. .gz, .zip, .xz). Previously it used a nanotime-based .tmp suffix. This makes the file easier to identify if compression fails during rollover. (See also the following paragraph.)

• On GZ, ZIP, or XZ compression failure, the original (uncompressed) log file is no longer deleted. Compression strategies now delete the source file only after successful compression and emit a warning that the original was left intact.

• ConsoleAppender with now probes JLine's org.jline.jansi.AnsiConsole first and falls back to the legacy FuseSource org.fusesource.jansi.AnsiConsole class. This keeps ANSI coloring working after Jansi moved under the JLine project. The optional org.jline:jansi-core artifact is declared as a dependency alongside the existing FuseSource jansi dependency. A preferredJansiClassName property was added for tests. This issue was reported in issues/1043 by seonwoo_jung who also provided the relevant PR.

• LayoutWrappingEncoder now reports an error at start() when no layout is set and guards encode() against a null layout. Previously, a missing layout (for example after an ignored // branch) allowed the encoder to start and then fail with a NullPointerException on every event, resulting in silent log loss. This issue was reported in issues/1046 by seonwoo_jung who also provided the relevant PR.

• FileCollisionAnalyser now detects file collisions involving nested appenders of SiftingAppender. When the nested file or fileNamePattern does not textually reference the discriminator key (e.g. ${userId}), a warning is issued at configuration time naming the appender, the key, and the shared target. This closes a gap where statically declared file appenders were checked but sifted nested appenders were not. This enhancement was contributed in [PR #1041](qos-ch/logback#1041) by seonwoo_jung.

• More defensive handling in SyslogOutputStream and SyslogAppenderBase: the close() method now ensures that resources are closed, writes and flushes check that the underlying resources are in a valid state and fallback to no-op otherwise.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit 57759f433000a133088ef0441038963134437fbd associated with the tag v_1.6.1. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

• See https://logback.qos.ch/news.html#1.6.1 for the original text.

Logback 1.6.0

2026-07-23 Release of logback version 1.6.0

• Removed certain deprecated variables, methods, and classes. For the list of removed members see release_1.6.0.txt.

• In AsyncAppenderBase, the put(ILoggingEvent) method now has the protected modifier to allow access from derived classes. This change was requested by Thomas Skjølberg in pr#1053.

• Bump SLF4J dependency to version 2.0.18.

See also the overview of the 1.6.x series.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit b07adf36019b51a10f824fdd94009985c587b1d3 associated with the tag v_1.6.0. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Logback 1.5.38

2026-07-09 Release of logback version 1.5.38

• In HardenedObjectInputStream, fixed a typo preventing Throwable objects from being white-filtered. This issue was reported in [PR #1045](qos-ch/logback#1045) by t0rchwo0d.

• A bitwise identical binary of this version can be reproduced by building from source code at commit d04984a41fce42977466f45a2f076f0ee5cc4207 associated with the tag v_1.5.38. Release built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Commits
  • 57759f4 prepare release 1.6.1
  • 175f99f fix imports
  • 4b8773e add compressionFailureLeavesOriginalFileIntact test for XZ compression
  • cafaf11 do not delete original file if compression fails
  • ee50125 let the temporary file before compression be target file without the .gz or ....
  • 5626acc minor refactoring
  • d97da4f minor refactoring
  • 159c045 more defensive coding in SyslogOutputStream and in SyslogAppenderBase
  • 9427d6b slight refactoring for clarity
  • 79c4179 slight refactoring
  • Additional commits viewable in compare view

Updates ch.qos.logback:logback-classic from 1.5.37 to 1.6.1

Release notes

Sourced from ch.qos.logback:logback-classic's releases.

Logback 1.6.1

2026-07-28 Release of logback version 1.6.1

• In TimeBasedRollingPolicy, when the file option is set, the intermediate file renamed before asynchronous compression now receives the target archive name without the compression suffix (e.g. .gz, .zip, .xz). Previously it used a nanotime-based .tmp suffix. This makes the file easier to identify if compression fails during rollover. (See also the following paragraph.)

• On GZ, ZIP, or XZ compression failure, the original (uncompressed) log file is no longer deleted. Compression strategies now delete the source file only after successful compression and emit a warning that the original was left intact.

• ConsoleAppender with now probes JLine's org.jline.jansi.AnsiConsole first and falls back to the legacy FuseSource org.fusesource.jansi.AnsiConsole class. This keeps ANSI coloring working after Jansi moved under the JLine project. The optional org.jline:jansi-core artifact is declared as a dependency alongside the existing FuseSource jansi dependency. A preferredJansiClassName property was added for tests. This issue was reported in issues/1043 by seonwoo_jung who also provided the relevant PR.

• LayoutWrappingEncoder now reports an error at start() when no layout is set and guards encode() against a null layout. Previously, a missing layout (for example after an ignored // branch) allowed the encoder to start and then fail with a NullPointerException on every event, resulting in silent log loss. This issue was reported in issues/1046 by seonwoo_jung who also provided the relevant PR.

• FileCollisionAnalyser now detects file collisions involving nested appenders of SiftingAppender. When the nested file or fileNamePattern does not textually reference the discriminator key (e.g. ${userId}), a warning is issued at configuration time naming the appender, the key, and the shared target. This closes a gap where statically declared file appenders were checked but sifted nested appenders were not. This enhancement was contributed in [PR #1041](qos-ch/logback#1041) by seonwoo_jung.

• More defensive handling in SyslogOutputStream and SyslogAppenderBase: the close() method now ensures that resources are closed, writes and flushes check that the underlying resources are in a valid state and fallback to no-op otherwise.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit 57759f433000a133088ef0441038963134437fbd associated with the tag v_1.6.1. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

• See https://logback.qos.ch/news.html#1.6.1 for the original text.

Logback 1.6.0

2026-07-23 Release of logback version 1.6.0

• Removed certain deprecated variables, methods, and classes. For the list of removed members see release_1.6.0.txt.

• In AsyncAppenderBase, the put(ILoggingEvent) method now has the protected modifier to allow access from derived classes. This change was requested by Thomas Skjølberg in pr#1053.

• Bump SLF4J dependency to version 2.0.18.

See also the overview of the 1.6.x series.

• A bit-wise identical binary of this version can be reproduced by building from source code at commit b07adf36019b51a10f824fdd94009985c587b1d3 associated with the tag v_1.6.0. The release was built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Logback 1.5.38

2026-07-09 Release of logback version 1.5.38

• In HardenedObjectInputStream, fixed a typo preventing Throwable objects from being white-filtered. This issue was reported in [PR #1045](qos-ch/logback#1045) by t0rchwo0d.

• A bitwise identical binary of this version can be reproduced by building from source code at commit d04984a41fce42977466f45a2f076f0ee5cc4207 associated with the tag v_1.5.38. Release built using Java "21" 2023-10-17 LTS build 21.0.1.+12-LTS-29 under Linux Debian 11.6.

Commits
  • 57759f4 prepare release 1.6.1
  • 175f99f fix imports
  • 4b8773e add compressionFailureLeavesOriginalFileIntact test for XZ compression
  • cafaf11 do not delete original file if compression fails
  • ee50125 let the temporary file before compression be target file without the .gz or ....
  • 5626acc minor refactoring
  • d97da4f minor refactoring
  • 159c045 more defensive coding in SyslogOutputStream and in SyslogAppenderBase
  • 9427d6b slight refactoring for clarity
  • 79c4179 slight refactoring
  • Additional commits viewable in compare view

Updates org.apache.logging.log4j:log4j-api from 2.26.0 to 2.26.1

Updates org.apache.logging.log4j:log4j-core from 2.26.0 to 2.26.1

Updates org.apache.logging.log4j:log4j-jul from 2.26.0 to 2.26.1

Updates org.apache.logging.log4j:log4j-to-slf4j from 2.26.0 to 2.26.1

Updates org.bouncycastle:bcprov-jdk18on from 1.84 to 1.85

Changelog

Sourced from org.bouncycastle:bcprov-jdk18on's changelog.

... (truncated)

Commits

Updates org.apache.maven.plugins:maven-help-plugin from 3.5.1 to 3.5.2

Release notes

Sourced from org.apache.maven.plugins:maven-help-plugin's releases.

3.5.2

🚀 New features and improvements

🐛 Bug Fixes

📝 Documentation updates

👻 Maintenance

🔧 Build

📦 Dependency updates

Commits
  • bdefec3 [maven-release-plugin] prepare release maven-help-plugin-3.5.2
  • b45833f Update site descriptor to 2.0.0 (#377)
  • 943dd09 [maven-release-plugin] prepare for next development iteration
  • 8a495be [maven-release-plugin] prepare release maven-help-plugin-3.5.2
  • 3ec573e Configure project for ATR (#376)
  • edff852 Add more goals to help plugin (self documenting any Maven version) (#374)
  • 2976b29 Fix issue 367 (#372)
  • 394ea1b Bump org.apache.maven.plugins:maven-plugins from 48 to 49 (#375)
  • 2c155b2 revert broken IT updates from #344
  • 1e716e1 Use version properties in IT (#368)
  • Additional commits viewable in compare view

Updates org.codehaus.gmavenplus:gmavenplus-plugin from 5.0.0 to 5.1.0

Release notes

Sourced from org.codehaus.gmavenplus:gmavenplus-plugin's releases.

5.1.0

Bugs

  • fix: Use Maven source-root removal APIs (#341)
  • Drop warnings about missing dependencies down to debug (#390)

Enhancements

  • Add to Java 25 enum LanguageLevel by @​jonesbusy in #346
  • feat: Honor compiler release for Groovy bytecode (#387)

Potentially breaking changes

None.

Notes

None.

New Contributors

Full Changelog

groovy/GMavenPlus@5.0.0...5.1.0

Commits
  • 33ac4f5 [maven-release-plugin] prepare release 5.1.0
  • fadc578 Merge pull request #391 from groovy/adjust-dependency-logging
  • 2180de9 Drop warnings about missing dependencies down to debug (closes #390)
  • 3991ff8 Merge pull request #389 from groovy/feat/honor-compiler-release
  • 3d29b11 feat: Honor compiler release for Groovy bytecode (closes #387)
  • b7bb980 build: Bump version
  • 5622987 doc: Update redeploy instructions
  • 0951225 doc: Add a skill for updating everything
  • e510e45 doc: Add a skill for updating everything
  • aec8eb1 doc: Update developer documentation
  • Additional commits viewable in compare view

Updates com.mycila:license-maven-plugin from 5.0.0 to 5.1.1

Release notes

Sourced from com.mycila:license-maven-plugin's releases.

v5.1.1

What's Changed

Full Changelog: mathieucarbou/license-maven-plugin@v5.1.0...v5.1.1

v5.1.0

What's Changed

... (truncated)

Commits
  • 602a083 [maven-release-plugin] prepare release v5.1.1
  • 590c91f Merge pull request #1078 from mathieucarbou/revert-1077-fix/git
  • b485d43 Revert "fix(git): follow renames across merges in copyright creation year (#b...
  • ce2cb81 Rolback to 5.0.0 for now
  • d0e644e Doc update
  • f80e1b7 [maven-release-plugin] prepare for next development iteration
  • f26d4bd [maven-release-plugin] prepare release v5.1.0
  • 6ca1342 Fix release process
  • a082fc1 [maven-release-plugin] rollback the release of v5.1.0
  • 7049b92 Fix release process
  • Additional commits viewable in compare view

Updates org.apache.tomcat.embed:tomcat-embed-core from 9.0.119 to 9.0.120

Updates org.apache.tomcat.embed:tomcat-embed-el from 9.0.119 to 9.0.120

Updates org.apache.tomcat.embed:tomcat-embed-websocket from 9.0.119 to 9.0.120

Updates org.apache.tomcat:tomcat-jaspic-api from 9.0.119 to 9.0.120

Updates org.apache.tomcat:tomcat-catalina from 9.0.119 to 9.0.120

Updates org.apache.tomcat.embed:tomcat-embed-el from 9.0.119 to 9.0.120

Updates org.apache.tomcat.embed:tomcat-embed-websocket from 9.0.119 to 9.0.120

Updates org.omnifaces:omnifaces from 3.14.21 to 3.14.23

Commits

Updates org.apache.tomcat:tomcat-jaspic-api from 9.0.119 to 9.0.120

Updates org.apache.tomcat:tomcat-catalina from 9.0.119 to 9.0.120

Updates io.openliberty.tools:liberty-maven-plugin from 3.12.0 to 3.12.1

Release notes

Sourced from io.openliberty.tools:liberty-maven-plugin's releases.

Liberty Maven Plug-in 3.12.1

Version 3.12.1 of the Liberty Maven Plugin is a minor release with new features and fixes.

New Features

See the commit log for the full set of the changes since the previous release.

The Liberty Maven Plugin 3.12.1 release is available on the Maven Central repository.

Commits
  • d8fc175 [maven-release-plugin] prepare release liberty-maven-3.12.1
  • 3fa940d Merge pull request #2059 from venmanyarun/3.x_common_update
  • 8aee01d changing workflow
  • ec53c28 changing ci.common version
  • ec8040e Merge pull request #2045 from sajeerzeji/feature/GH2044-compiler-args-support
  • 1185966 Fixed the test failure by adding a delay in the test
  • c216630 Merge pull request #2047 from venmanyarun/test_jdk_semetu_test
  • a56d05f changing test jdk to semeru instead of temurin
  • dec0a52 Fixed compiler options logging to check for non-empty list before logging rec...
  • 13d6257 Workflow reverted
  • Additional commits viewable in compare view

Updates org.apache.tomcat.embed:tomcat-embed-core from 10.1.56 to 10.1.57

Updates org.apache.tomcat.embed:tomcat-embed-el from 10.1.56 to 10.1.57

Updates org.apache.tomcat.embed:tomcat-embed-websocket from 10.1.56 to 10.1.57

Updates org.apache.tomcat:tomcat-jaspic-api from 10.1.56 to 10.1.57

Updates org.apache.tomcat:tomcat-catalina from 10.1.56 to 10.1.57

Updates org.apache.tomcat:tomcat-jasper from 10.1.56 to 10.1.57

Updates org.apache.tomcat:tomcat-jasper-el from 10.1.56 to 10.1.57

Updates org.apache.tomcat:tomcat-jasper-el from 10.1.56 to 10.1.57

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the maven-dependencies group with 30 updates:

| Package | From | To |
| --- | --- | --- |
| [org.apache.groovy:groovy-all](https://github.com/apache/groovy) | `4.0.32` | `4.0.33` |
| [org.apache.groovy:groovy](https://github.com/apache/groovy) | `4.0.32` | `4.0.33` |
| [net.bytebuddy:byte-buddy](https://github.com/raphw/byte-buddy) | `1.18.10` | `1.18.11` |
| [net.bytebuddy:byte-buddy-agent](https://github.com/raphw/byte-buddy) | `1.18.10` | `1.18.11` |
| org.apache.logging.log4j:log4j-slf4j2-impl | `2.26.0` | `2.26.1` |
| org.apache.logging.log4j:log4j-core-test | `2.26.0` | `2.26.1` |
| org.apache.logging.log4j:log4j-api | `2.26.0` | `2.26.1` |
| org.apache.logging.log4j:log4j-core | `2.26.0` | `2.26.1` |
| org.apache.logging.log4j:log4j-jul | `2.26.0` | `2.26.1` |
| org.apache.logging.log4j:log4j-to-slf4j | `2.26.0` | `2.26.1` |
| [ch.qos.logback:logback-core](https://github.com/qos-ch/logback) | `1.5.37` | `1.6.1` |
| [ch.qos.logback:logback-classic](https://github.com/qos-ch/logback) | `1.5.37` | `1.6.1` |
| [org.bouncycastle:bcprov-jdk18on](https://github.com/bcgit/bc-java) | `1.84` | `1.85` |
| [org.apache.maven.plugins:maven-help-plugin](https://github.com/apache/maven-help-plugin) | `3.5.1` | `3.5.2` |
| [org.codehaus.gmavenplus:gmavenplus-plugin](https://github.com/groovy/GMavenPlus) | `5.0.0` | `5.1.0` |
| [com.mycila:license-maven-plugin](https://github.com/mathieucarbou/license-maven-plugin) | `5.0.0` | `5.1.1` |
| org.apache.tomcat.embed:tomcat-embed-core | `9.0.119` | `9.0.120` |
| org.apache.tomcat.embed:tomcat-embed-el | `9.0.119` | `9.0.120` |
| org.apache.tomcat.embed:tomcat-embed-websocket | `9.0.119` | `9.0.120` |
| org.apache.tomcat:tomcat-jaspic-api | `9.0.119` | `9.0.120` |
| org.apache.tomcat:tomcat-catalina | `9.0.119` | `9.0.120` |
| [org.omnifaces:omnifaces](https://github.com/omnifaces/omnifaces) | `3.14.21` | `3.14.23` |
| [io.openliberty.tools:liberty-maven-plugin](https://github.com/OpenLiberty/ci.maven) | `3.12.0` | `3.12.1` |
| org.apache.tomcat.embed:tomcat-embed-core | `10.1.56` | `10.1.57` |
| org.apache.tomcat.embed:tomcat-embed-el | `10.1.56` | `10.1.57` |
| org.apache.tomcat.embed:tomcat-embed-websocket | `10.1.56` | `10.1.57` |
| org.apache.tomcat:tomcat-jaspic-api | `10.1.56` | `10.1.57` |
| org.apache.tomcat:tomcat-catalina | `10.1.56` | `10.1.57` |
| org.apache.tomcat:tomcat-jasper | `10.1.56` | `10.1.57` |
| org.apache.tomcat:tomcat-jasper-el | `10.1.56` | `10.1.57` |


Updates `org.apache.groovy:groovy-all` from 4.0.32 to 4.0.33
- [Commits](https://github.com/apache/groovy/commits)

Updates `org.apache.groovy:groovy` from 4.0.32 to 4.0.33
- [Commits](https://github.com/apache/groovy/commits)

Updates `org.apache.groovy:groovy` from 4.0.32 to 4.0.33
- [Commits](https://github.com/apache/groovy/commits)

Updates `net.bytebuddy:byte-buddy` from 1.18.10 to 1.18.11
- [Release notes](https://github.com/raphw/byte-buddy/releases)
- [Changelog](https://github.com/raphw/byte-buddy/blob/master/release-notes.md)
- [Commits](raphw/byte-buddy@byte-buddy-1.18.10...byte-buddy-1.18.11)

Updates `net.bytebuddy:byte-buddy-agent` from 1.18.10 to 1.18.11
- [Release notes](https://github.com/raphw/byte-buddy/releases)
- [Changelog](https://github.com/raphw/byte-buddy/blob/master/release-notes.md)
- [Commits](raphw/byte-buddy@byte-buddy-1.18.10...byte-buddy-1.18.11)

Updates `net.bytebuddy:byte-buddy-agent` from 1.18.10 to 1.18.11
- [Release notes](https://github.com/raphw/byte-buddy/releases)
- [Changelog](https://github.com/raphw/byte-buddy/blob/master/release-notes.md)
- [Commits](raphw/byte-buddy@byte-buddy-1.18.10...byte-buddy-1.18.11)

Updates `org.apache.logging.log4j:log4j-slf4j2-impl` from 2.26.0 to 2.26.1

Updates `org.apache.logging.log4j:log4j-core-test` from 2.26.0 to 2.26.1

Updates `org.apache.logging.log4j:log4j-api` from 2.26.0 to 2.26.1

Updates `org.apache.logging.log4j:log4j-core` from 2.26.0 to 2.26.1

Updates `org.apache.logging.log4j:log4j-jul` from 2.26.0 to 2.26.1

Updates `org.apache.logging.log4j:log4j-to-slf4j` from 2.26.0 to 2.26.1

Updates `org.apache.logging.log4j:log4j-core-test` from 2.26.0 to 2.26.1

Updates `ch.qos.logback:logback-core` from 1.5.37 to 1.6.1
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.5.37...v_1.6.1)

Updates `ch.qos.logback:logback-classic` from 1.5.37 to 1.6.1
- [Release notes](https://github.com/qos-ch/logback/releases)
- [Commits](qos-ch/logback@v_1.5.37...v_1.6.1)

Updates `org.apache.logging.log4j:log4j-api` from 2.26.0 to 2.26.1

Updates `org.apache.logging.log4j:log4j-core` from 2.26.0 to 2.26.1

Updates `org.apache.logging.log4j:log4j-jul` from 2.26.0 to 2.26.1

Updates `org.apache.logging.log4j:log4j-to-slf4j` from 2.26.0 to 2.26.1

Updates `org.bouncycastle:bcprov-jdk18on` from 1.84 to 1.85
- [Changelog](https://github.com/bcgit/bc-java/blob/main/docs/releasenotes.html)
- [Commits](https://github.com/bcgit/bc-java/commits)

Updates `org.apache.maven.plugins:maven-help-plugin` from 3.5.1 to 3.5.2
- [Release notes](https://github.com/apache/maven-help-plugin/releases)
- [Commits](apache/maven-help-plugin@maven-help-plugin-3.5.1...maven-help-plugin-3.5.2)

Updates `org.codehaus.gmavenplus:gmavenplus-plugin` from 5.0.0 to 5.1.0
- [Release notes](https://github.com/groovy/GMavenPlus/releases)
- [Commits](groovy/GMavenPlus@5.0.0...5.1.0)

Updates `com.mycila:license-maven-plugin` from 5.0.0 to 5.1.1
- [Release notes](https://github.com/mathieucarbou/license-maven-plugin/releases)
- [Changelog](https://github.com/mathieucarbou/license-maven-plugin/blob/master/docs/releases.md)
- [Commits](mathieucarbou/license-maven-plugin@v5.0.0...v5.1.1)

Updates `org.apache.tomcat.embed:tomcat-embed-core` from 9.0.119 to 9.0.120

Updates `org.apache.tomcat.embed:tomcat-embed-el` from 9.0.119 to 9.0.120

Updates `org.apache.tomcat.embed:tomcat-embed-websocket` from 9.0.119 to 9.0.120

Updates `org.apache.tomcat:tomcat-jaspic-api` from 9.0.119 to 9.0.120

Updates `org.apache.tomcat:tomcat-catalina` from 9.0.119 to 9.0.120

Updates `org.apache.tomcat.embed:tomcat-embed-el` from 9.0.119 to 9.0.120

Updates `org.apache.tomcat.embed:tomcat-embed-websocket` from 9.0.119 to 9.0.120

Updates `org.omnifaces:omnifaces` from 3.14.21 to 3.14.23
- [Commits](https://github.com/omnifaces/omnifaces/commits)

Updates `org.apache.tomcat:tomcat-jaspic-api` from 9.0.119 to 9.0.120

Updates `org.apache.tomcat:tomcat-catalina` from 9.0.119 to 9.0.120

Updates `io.openliberty.tools:liberty-maven-plugin` from 3.12.0 to 3.12.1
- [Release notes](https://github.com/OpenLiberty/ci.maven/releases)
- [Commits](OpenLiberty/ci.maven@liberty-maven-3.12.0...liberty-maven-3.12.1)

Updates `org.apache.tomcat.embed:tomcat-embed-core` from 10.1.56 to 10.1.57

Updates `org.apache.tomcat.embed:tomcat-embed-el` from 10.1.56 to 10.1.57

Updates `org.apache.tomcat.embed:tomcat-embed-websocket` from 10.1.56 to 10.1.57

Updates `org.apache.tomcat:tomcat-jaspic-api` from 10.1.56 to 10.1.57

Updates `org.apache.tomcat:tomcat-catalina` from 10.1.56 to 10.1.57

Updates `org.apache.tomcat:tomcat-jasper` from 10.1.56 to 10.1.57

Updates `org.apache.tomcat:tomcat-jasper-el` from 10.1.56 to 10.1.57

Updates `org.apache.tomcat:tomcat-jasper-el` from 10.1.56 to 10.1.57

---
updated-dependencies:
- dependency-name: org.apache.groovy:groovy-all
  dependency-version: 4.0.33
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.groovy:groovy
  dependency-version: 4.0.33
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.groovy:groovy
  dependency-version: 4.0.33
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: net.bytebuddy:byte-buddy
  dependency-version: 1.18.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: net.bytebuddy:byte-buddy-agent
  dependency-version: 1.18.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: net.bytebuddy:byte-buddy-agent
  dependency-version: 1.18.11
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.logging.log4j:log4j-slf4j2-impl
  dependency-version: 2.26.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.logging.log4j:log4j-core-test
  dependency-version: 2.26.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.logging.log4j:log4j-api
  dependency-version: 2.26.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.logging.log4j:log4j-core
  dependency-version: 2.26.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.logging.log4j:log4j-jul
  dependency-version: 2.26.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.logging.log4j:log4j-to-slf4j
  dependency-version: 2.26.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.logging.log4j:log4j-core-test
  dependency-version: 2.26.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: ch.qos.logback:logback-core
  dependency-version: 1.6.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: ch.qos.logback:logback-classic
  dependency-version: 1.6.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: org.apache.logging.log4j:log4j-api
  dependency-version: 2.26.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.logging.log4j:log4j-core
  dependency-version: 2.26.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.logging.log4j:log4j-jul
  dependency-version: 2.26.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.logging.log4j:log4j-to-slf4j
  dependency-version: 2.26.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.bouncycastle:bcprov-jdk18on
  dependency-version: '1.85'
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: org.apache.maven.plugins:maven-help-plugin
  dependency-version: 3.5.2
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.codehaus.gmavenplus:gmavenplus-plugin
  dependency-version: 5.1.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: com.mycila:license-maven-plugin
  dependency-version: 5.1.1
  dependency-type: direct:development
  update-type: version-update:semver-minor
  dependency-group: maven-dependencies
- dependency-name: org.apache.tomcat.embed:tomcat-embed-core
  dependency-version: 9.0.120
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.tomcat.embed:tomcat-embed-el
  dependency-version: 9.0.120
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.tomcat.embed:tomcat-embed-websocket
  dependency-version: 9.0.120
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.tomcat:tomcat-jaspic-api
  dependency-version: 9.0.120
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.tomcat:tomcat-catalina
  dependency-version: 9.0.120
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.tomcat.embed:tomcat-embed-el
  dependency-version: 9.0.120
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.tomcat.embed:tomcat-embed-websocket
  dependency-version: 9.0.120
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.omnifaces:omnifaces
  dependency-version: 3.14.23
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.tomcat:tomcat-jaspic-api
  dependency-version: 9.0.120
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.tomcat:tomcat-catalina
  dependency-version: 9.0.120
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: io.openliberty.tools:liberty-maven-plugin
  dependency-version: 3.12.1
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.tomcat.embed:tomcat-embed-core
  dependency-version: 10.1.57
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.tomcat.embed:tomcat-embed-el
  dependency-version: 10.1.57
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.tomcat.embed:tomcat-embed-websocket
  dependency-version: 10.1.57
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.tomcat:tomcat-jaspic-api
  dependency-version: 10.1.57
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.tomcat:tomcat-catalina
  dependency-version: 10.1.57
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.tomcat:tomcat-jasper
  dependency-version: 10.1.57
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.tomcat:tomcat-jasper-el
  dependency-version: 10.1.57
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
- dependency-name: org.apache.tomcat:tomcat-jasper-el
  dependency-version: 10.1.57
  dependency-type: direct:development
  update-type: version-update:semver-patch
  dependency-group: maven-dependencies
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update Java code labels Aug 1, 2026
@github-actions github-actions Bot added xml and removed java Pull requests that update Java code labels Aug 1, 2026
@lprimak
lprimak merged commit 37d1ef7 into 2.x Aug 2, 2026
29 checks passed
@dependabot
dependabot Bot deleted the dependabot/maven/2.x/maven-dependencies-337e9caf20 branch August 2, 2026 12:34
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file xml

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant