Bump org.jacoco:jacoco-maven-plugin from 0.8.14 to 0.8.15 - #174
Open
dependabot[bot] wants to merge 1 commit into
Open
Bump org.jacoco:jacoco-maven-plugin from 0.8.14 to 0.8.15#174dependabot[bot] wants to merge 1 commit into
dependabot[bot] wants to merge 1 commit into
Conversation
Bumps [org.jacoco:jacoco-maven-plugin](https://github.com/jacoco/jacoco) from 0.8.14 to 0.8.15. - [Release notes](https://github.com/jacoco/jacoco/releases) - [Commits](jacoco/jacoco@v0.8.14...v0.8.15) --- updated-dependencies: - dependency-name: org.jacoco:jacoco-maven-plugin dependency-version: 0.8.15 dependency-type: direct:development update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com>
senzingdevops
approved these changes
Jun 26, 2026
senzingdevops
left a comment
There was a problem hiding this comment.
Automated: approving this pull request because it includes a patch update
🤖 Claude Code ReviewCode ReviewSummary: This PR is a single-line dependency version bump of Code Quality
Testing
Documentation
Security
Verdict: APPROVE. This is a routine, low-risk dependency update. JaCoCo 0.8.15 is a patch/minor release with no breaking changes expected. No action required beyond confirming CI passes.Automated code review analyzing defects and coding standards |
3 tasks
barrycaceres
added a commit
that referenced
this pull request
Aug 5, 2026
* Prepare 1.0.2 release: dependency rollup and Trivy CVE fixes Security patch release. Addresses 10 HIGH-severity CVEs flagged by Trivy on the 1.0.1 baseline and rolls up the currently-open Maven dependency dependabot PRs into a single change. GitHub Actions workflow dependabot PRs (setup-java, cache, checkout) are handled separately. - Bumped project version from 1.0.1 to 1.0.2 in pom.xml. - Updated Dockerfile REFRESHED_AT to 2026-08-04 and Version labels to 1.0.2 (both builder and final stages). Consumer-facing dependency updates (compile/runtime scope): - Updated com.fasterxml.jackson/jackson-bom from 2.21.3 to 2.22.0 (PR #167; addresses GHSA-r7wm-3cxj-wff9 in jackson-core, and CVE-2026-54512 and CVE-2026-54513 in jackson-databind). - Updated io.netty/netty-bom from 4.2.15.Final to 4.2.16.Final (not in a dependabot PR; addresses CVE-2026-59901 in netty-codec-compression, CVE-2026-55851 in netty-codec-haproxy, CVE-2026-55831/CVE-2026-55833/CVE-2026-56745 in netty-codec-http, and CVE-2026-56819 in netty-codec-http2). - Updated com.linecorp.armeria/armeria-bom from 1.39.0 to 1.39.1 (PR #173). - Updated org.xerial/sqlite-jdbc from 3.53.1.0 to 3.53.2.0 (PR #172). Build-only updates: - Updated org.jacoco/jacoco-maven-plugin from 0.8.14 to 0.8.15 (PR #174). - Updated com.github.spotbugs/spotbugs-maven-plugin from 4.9.8.3 to 4.9.8.4 (PR #175). Closes #167, #172, #173, #174, #175. * Fix Trivy postgresql CVE; bump sz-sdk to 4.4.0; advance submodule Addresses the three CI failure classes on this PR: 1. Trivy Scan Dependencies (1 remaining HIGH CVE after the earlier jackson/netty bumps): added a dependencyManagement override for org.postgresql/postgresql to 42.7.12 to fix CVE-2026-54291 (SCRAM authentication DoS in pgjdbc). postgresql is transitive from data-mart-replicator 2.0.1; the override can be removed when data-mart-replicator upgrades past 42.7.11. 2. maven-*-staging-v4 (6 jobs) compile errors in the sz-sdk-java submodule's RepositoryManager.java (setDefaultConfigID(Long), getConfig(long, StringBuffer), etc. cannot be found): caused by the JNI-modernization cutover on the sz-sdk-java main branch (commits #356 and #361) that changed the NativeConfigManager / NativeConfig interface signatures. Advanced the sz-sdk-java submodule pointer from tag 4.3.0 to origin/main (b8c0f7a) so the submodule's test code matches the modernized JNI in staging-v4. 3. Bumped the com.senzing/sz-sdk range from [4.3.0, ...) to [4.4.0, ...) to match the modernized SDK API. This is a transitional bump — until Senzing SDK 4.4.0 is published to Maven Central, production-v4 CI builds will fail to resolve the dependency. staging-v4 resolves against the pre-release SDK. Additional pom.xml change: - Loosened the RUNTIME_SENZING_VERSION static-block strip regex in the copy-install-utilities maven-replacer-plugin execution (static \{ → static\s*\{) to match the reformatted upstream ("static\n{"). The verify-install-utilities-strip antrun guardrail fired on the initial build attempt, demonstrating that the guardrail added in 1.0.0 correctly catches upstream API drift. Test results: - mvn clean install -Pcheckstyle -DskipTests=true : BUILD SUCCESS - mvn test : 2,125 tests run, 0 failures, 0 errors, 0 skipped - dependency:tree confirms postgresql 42.7.12, jackson 2.22.0, netty-codec-* 4.2.16.Final * Revert release-related version bumps — this is a maintenance PR This PR is a maintenance change on main to clear the dependabot backlog and address Trivy CVE findings — not a release. Reverting the release-related bumps: - pom.xml: version 1.0.2 → 1.0.1 (unchanged from main baseline). - Dockerfile: Version labels 1.0.2 → 1.0.1 and REFRESHED_AT 2026-08-04 → 2026-06-19 (unchanged from main; Dockerfile now has zero delta from main). - CHANGELOG.md: renamed the [1.0.2] - 2026-08-04 section to [Unreleased] and reworded the introductory blurb accordingly. The version tag and release date will be added when Senzing SDK 4.4.0 ships and this can be cut as 1.0.2.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps org.jacoco:jacoco-maven-plugin from 0.8.14 to 0.8.15.
Release notes
Sourced from org.jacoco:jacoco-maven-plugin's releases.
Commits
6c5260aPrepare release v0.8.155c05141Transfer of execution data through socket should use buffered stream (#2089)ab5efa9Remove from Azure Pipelines all builds except with JDK 5 and JDK EA (#2148)5f6ea38Use Windows 2025 image in GitHub Actions (#2130)35a8af2Use Renovate instead of Dependabot for updates of ASM (#2137)85b8ddfUpgrade ASM to 9.10.1 (#2134)2988647AgentModule should use ClassLoader of agent instead of SystemClassLoader (#1651)75a4e31Add filter for Kotlin@JvmExposeBoxed(#1944)691fa1dUse Renovate instead of Dependabot for updates of GitHub Actions (#2132)3e18f17Require at least JDK 21 for build (#2128)You can trigger a rebase of this PR by commenting
@dependabot rebase.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
@dependabot rebasewill rebase this PR@dependabot recreatewill recreate this PR, overwriting any edits that have been made to it@dependabot show <dependency name> ignore conditionswill show all of the ignore conditions of the specified dependency@dependabot ignore this major versionwill close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this minor versionwill close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)@dependabot ignore this dependencywill close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)