Skip to content

Bump org.jacoco:jacoco-maven-plugin from 0.8.14 to 0.8.15 - #174

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/org.jacoco-jacoco-maven-plugin-0.8.15
Open

Bump org.jacoco:jacoco-maven-plugin from 0.8.14 to 0.8.15#174
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/maven/org.jacoco-jacoco-maven-plugin-0.8.15

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 26, 2026

Copy link
Copy Markdown
Contributor

Bumps org.jacoco:jacoco-maven-plugin from 0.8.14 to 0.8.15.

Release notes

Sourced from org.jacoco:jacoco-maven-plugin's releases.

0.8.15

New Features

  • JaCoCo now officially supports Java 26 (GitHub #2076).
  • Experimental support for Java 27 class files (GitHub #2004).
  • Compatibility methods generated by Kotlin compiler for functions defined in interfaces are filtered out during generation of report (GitHub #1905).
  • Compatibility methods generated by Kotlin compiler for exposed boxed inline value classes (JvmExposeBoxed annotation) are filtered out during generation of report (GitHub #1944).
  • Methods generated by the Kotlin compiler for functions with JvmStatic annotation are filtered out during generation of report (GitHub #2097).
  • Improved filtering of bytecode generated by Kotlin compiler for when expressions and statements with kotlin.String subject where first branch condition contains string with largest hash (GitHub #2098).
  • Part of bytecode that javac versions from 24 to 26 generate for switch statements and expressions with selector expression of type java.lang.String inside lambdas is filtered out during generation of report (GitHub #2023).
  • Improved performance of Kotlin files analysis by parsing SMAPs only once per class (GitHub #2114).
  • For better performance agent output methods tcpclient and tcpserver use BufferedOutputStream to write execution data to socket. Maven plugin, Ant tasks, CLI, API usage examples, and ExecDumpClient API use BufferedInputStream to read execution data from socket. Third-party integrations should do the same to benefit from this change in agent (GitHub #2089).

Fixed bugs

  • Fixed processing of Kotlin SMAP in synthetic classes (GitHub #1985).
  • Multiple JaCoCo runtimes within one JVM writing to the same output file should not cause data corruption when running on JDK versions from 6 to 10 affected by JDK-8166253 (GitHub #2065, #2074).
  • For better performance agent writes to output file via BufferedOutputStream, this fixes regression introduced in version 0.6.2 (GitHub #2073).
  • Fixed NullPointerException when JaCoCo agent is loaded by non system class loader, for example when loaded by JBoss Modules (GitHub #1651).

Non-functional Changes

  • JaCoCo now depends on ASM 9.10.1 (GitHub #2134).
Commits
  • 6c5260a Prepare release v0.8.15
  • 5c05141 Transfer of execution data through socket should use buffered stream (#2089)
  • ab5efa9 Remove from Azure Pipelines all builds except with JDK 5 and JDK EA (#2148)
  • 5f6ea38 Use Windows 2025 image in GitHub Actions (#2130)
  • 35a8af2 Use Renovate instead of Dependabot for updates of ASM (#2137)
  • 85b8ddf Upgrade ASM to 9.10.1 (#2134)
  • 2988647 AgentModule should use ClassLoader of agent instead of SystemClassLoader (#1651)
  • 75a4e31 Add filter for Kotlin @JvmExposeBoxed (#1944)
  • 691fa1d Use Renovate instead of Dependabot for updates of GitHub Actions (#2132)
  • 3e18f17 Require at least JDK 21 for build (#2128)
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Note
Automatic rebases have been disabled on this pull request as it has been open for over 30 days.

Bumps [org.jacoco:jacoco-maven-plugin](https://github.com/jacoco/jacoco) from 0.8.14 to 0.8.15.
- [Release notes](https://github.com/jacoco/jacoco/releases)
- [Commits](jacoco/jacoco@v0.8.14...v0.8.15)

---
updated-dependencies:
- dependency-name: org.jacoco:jacoco-maven-plugin
  dependency-version: 0.8.15
  dependency-type: direct:development
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot requested a review from a team as a code owner June 26, 2026 10:42
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java labels Jun 26, 2026

@senzingdevops senzingdevops left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Automated: approving this pull request because it includes a patch update

@github-actions
github-actions Bot enabled auto-merge (squash) June 26, 2026 10:43
@github-actions

Copy link
Copy Markdown

🤖 Claude Code Review

Code Review

Summary: This PR is a single-line dependency version bump of org.jacoco:jacoco-maven-plugin from 0.8.14 to 0.8.15 in pom.xml. This appears to be a Dependabot automated update.


Code Quality

  • Style guide: No style concerns for a version bump.
  • No commented-out code: None present.
  • Meaningful variable names: N/A.
  • DRY principle: N/A.
  • Defects: No logic changes; version bump only. No bugs, race conditions, or security issues introduced.
  • CLAUDE.md: No concerns. JaCoCo is referenced under the jacoco Maven profile and this change is consistent with how the plugin is used.

Testing

  • Unit/integration tests: N/A for a dependency version bump.
  • Test coverage: Not impacted — JaCoCo is a test reporting tool, not production code.

Documentation

  • README/API docs: No updates needed.
  • Inline comments: N/A.
  • ⚠️ CHANGELOG.md: No CHANGELOG update is included. Dependency bumps are typically omitted from changelogs in this project (Dependabot pattern), which is acceptable — but worth confirming against project convention.
  • Markdown formatting: N/A.

Security

  • No hardcoded credentials.
  • No license files (.lic / AQAAAD) checked in.
  • No sensitive data.

Verdict: APPROVE. This is a routine, low-risk dependency update. JaCoCo 0.8.15 is a patch/minor release with no breaking changes expected. No action required beyond confirming CI passes.

Automated code review analyzing defects and coding standards

barrycaceres added a commit that referenced this pull request Aug 5, 2026
* Prepare 1.0.2 release: dependency rollup and Trivy CVE fixes

Security patch release. Addresses 10 HIGH-severity CVEs flagged by
Trivy on the 1.0.1 baseline and rolls up the currently-open Maven
dependency dependabot PRs into a single change. GitHub Actions
workflow dependabot PRs (setup-java, cache, checkout) are handled
separately.

- Bumped project version from 1.0.1 to 1.0.2 in pom.xml.
- Updated Dockerfile REFRESHED_AT to 2026-08-04 and Version labels to
  1.0.2 (both builder and final stages).

Consumer-facing dependency updates (compile/runtime scope):

- Updated com.fasterxml.jackson/jackson-bom from 2.21.3 to 2.22.0
  (PR #167; addresses GHSA-r7wm-3cxj-wff9 in jackson-core, and
  CVE-2026-54512 and CVE-2026-54513 in jackson-databind).
- Updated io.netty/netty-bom from 4.2.15.Final to 4.2.16.Final
  (not in a dependabot PR; addresses CVE-2026-59901 in
  netty-codec-compression, CVE-2026-55851 in netty-codec-haproxy,
  CVE-2026-55831/CVE-2026-55833/CVE-2026-56745 in netty-codec-http,
  and CVE-2026-56819 in netty-codec-http2).
- Updated com.linecorp.armeria/armeria-bom from 1.39.0 to 1.39.1
  (PR #173).
- Updated org.xerial/sqlite-jdbc from 3.53.1.0 to 3.53.2.0 (PR #172).

Build-only updates:

- Updated org.jacoco/jacoco-maven-plugin from 0.8.14 to 0.8.15
  (PR #174).
- Updated com.github.spotbugs/spotbugs-maven-plugin from 4.9.8.3 to
  4.9.8.4 (PR #175).

Closes #167, #172, #173, #174, #175.

* Fix Trivy postgresql CVE; bump sz-sdk to 4.4.0; advance submodule

Addresses the three CI failure classes on this PR:

1. Trivy Scan Dependencies (1 remaining HIGH CVE after the earlier
   jackson/netty bumps): added a dependencyManagement override for
   org.postgresql/postgresql to 42.7.12 to fix CVE-2026-54291 (SCRAM
   authentication DoS in pgjdbc). postgresql is transitive from
   data-mart-replicator 2.0.1; the override can be removed when
   data-mart-replicator upgrades past 42.7.11.

2. maven-*-staging-v4 (6 jobs) compile errors in the sz-sdk-java
   submodule's RepositoryManager.java (setDefaultConfigID(Long),
   getConfig(long, StringBuffer), etc. cannot be found): caused by
   the JNI-modernization cutover on the sz-sdk-java main branch
   (commits #356 and #361) that changed the NativeConfigManager /
   NativeConfig interface signatures. Advanced the sz-sdk-java
   submodule pointer from tag 4.3.0 to origin/main (b8c0f7a) so the
   submodule's test code matches the modernized JNI in staging-v4.

3. Bumped the com.senzing/sz-sdk range from [4.3.0, ...) to
   [4.4.0, ...) to match the modernized SDK API. This is a
   transitional bump — until Senzing SDK 4.4.0 is published to Maven
   Central, production-v4 CI builds will fail to resolve the
   dependency. staging-v4 resolves against the pre-release SDK.

Additional pom.xml change:

- Loosened the RUNTIME_SENZING_VERSION static-block strip regex in
  the copy-install-utilities maven-replacer-plugin execution
  (static \{ → static\s*\{) to match the reformatted upstream
  ("static\n{"). The verify-install-utilities-strip antrun guardrail
  fired on the initial build attempt, demonstrating that the guardrail
  added in 1.0.0 correctly catches upstream API drift.

Test results:

- mvn clean install -Pcheckstyle -DskipTests=true : BUILD SUCCESS
- mvn test : 2,125 tests run, 0 failures, 0 errors, 0 skipped
- dependency:tree confirms postgresql 42.7.12, jackson 2.22.0,
  netty-codec-* 4.2.16.Final

* Revert release-related version bumps — this is a maintenance PR

This PR is a maintenance change on main to clear the dependabot
backlog and address Trivy CVE findings — not a release. Reverting
the release-related bumps:

- pom.xml: version 1.0.2 → 1.0.1 (unchanged from main baseline).
- Dockerfile: Version labels 1.0.2 → 1.0.1 and REFRESHED_AT
  2026-08-04 → 2026-06-19 (unchanged from main; Dockerfile now has
  zero delta from main).
- CHANGELOG.md: renamed the [1.0.2] - 2026-08-04 section to
  [Unreleased] and reworded the introductory blurb accordingly.
  The version tag and release date will be added when Senzing SDK
  4.4.0 ships and this can be cut as 1.0.2.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants