build(deps): bump jetty-servlet from 9.4.27.v20200227 to 11.0.7 #33

Closed
dependabot[bot] wants to merge 1 commit from dependabot/gradle/org.eclipse.jetty-jetty-servlet-11.0.7 into helma-🐜
dependabot[bot] commented 2021-10-13 09:09:43 +00:00 (Migrated from github.com)

Bumps jetty-servlet from 9.4.27.v20200227 to 11.0.7.

Release notes

Sourced from jetty-servlet's releases.

11.0.7

Special Thanks to the following Eclipse Jetty community members

Changelog

Dependency Updates

  • #6788 - Bump conscrypt-openjdk-uber from 2.5.1 to 2.5.2
  • #6750 - Bump openwebbeans.version from 2.0.20 to 2.0.23
  • #6742 - Bump json-smart from 2.3 to 2.4.7
  • #6725 - Bump gson from 2.8.6 to 2.8.8
  • #6722 - Bump biz.aQute.bndlib from 5.2.0 to 5.3.0
  • #6717 - Bump bouncycastle.version from 1.62 to 1.69
  • #6712 - Bump jnr-unixsocket from 0.38.3 to 0.38.10
  • #6711 - Bump google-cloud-datastore from 1.105.0 to 2.1.0
  • #6705 - Bump hazelcast.version from 4.1 to 4.2.2
  • #6679 - Update to Apache Jasper 10.0.10

11.0.6

Changelog

  • This release resolves CVE-2021-34429
  • #6473 - Improve alias checking in PathResource
  • #6468 - Revert logic in Request.setMetaData & clear emptySegment on HttpUri.clear()
  • #6464 - Wrong files/lib definitions in certain *-capture.mod files?
  • #6447 - Deprecate support for UTF16 encoding in URIs
  • #6426 - Update to spifly 1.3.3
  • #6425 - Update to asm 9.1
  • #6418 - Bad and/or missing Require-Capability for osgi.serviceloader
  • #6410 - Ensure Jetty IO uses SocketAddress instead of InetSocketAddress
  • #6407 - Malformed scheme logical expression check in WebSocket ClientUpgradeRequest
  • #6394 - Review osgi manifests within Jetty 11
  • #6376 - Cleanups for SslClientCertAuthenticator.
  • #6375 - Always check XML Set elements with property attribute
  • #6353 - Rename EWYK The AdaptiveExecutionStrategy

11.0.5

Changelog

  • #6392 - Review accidental xml config changes
  • #6379 - Reduce contention in all ByteBufferPool implementations
  • #6354 - org.slfj dependency imports packages at 2.0
  • #6329 - Regression on graceful shutdown default in Jetty 10
  • #6302 - Treat empty path segments are ambiguous.
  • #4772 - Jetty WebSocket API onMessage annotation does not support partial messages.

... (truncated)

Commits
  • 389a358 Updating to version 11.0.7
  • 8bcd404 Fixing release script
  • abb7077 fix new module pom parent version
  • e78951b Merge branch 'jetty-10.0.x' into jetty-11.0.x
  • aaaa48c Issue #6403 - add an automatic generated maven deployable p2 site (#6404)
  • f8244fc Merged branch 'jetty-10.0.x' into 'jetty-11.0.x'.
  • 0412bdc Fixes #6938 - module-info.java file do not use the canonical order for the el...
  • 4011f1e merge jetty-10.0.x (#6945)
  • 51d44a3 use dependencyManagement for internal dependencies (#6940)
  • 0269117 Changed order of entries in module-info.java to be canonical
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
Bumps [jetty-servlet](https://github.com/eclipse/jetty.project) from 9.4.27.v20200227 to 11.0.7. <details> <summary>Release notes</summary> <p><em>Sourced from <a href="https://github.com/eclipse/jetty.project/releases">jetty-servlet's releases</a>.</em></p> <blockquote> <h2>11.0.7</h2> <h1>Special Thanks to the following Eclipse Jetty community members</h1> <ul> <li><a href="https://github.com/frode-carlsen"><code>@​frode-carlsen</code></a> (Frode Carlsen)</li> </ul> <h1>Changelog</h1> <ul> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6406">#6406</a> - Jetty Jaspi module not compatible with Jakarta EE 9 (Jakarta Authentication) (<a href="https://github.com/frode-carlsen"><code>@​frode-carlsen</code></a>)</li> </ul> <h1>Dependency Updates</h1> <ul> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6788">#6788</a> - Bump conscrypt-openjdk-uber from 2.5.1 to 2.5.2</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6750">#6750</a> - Bump openwebbeans.version from 2.0.20 to 2.0.23</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6742">#6742</a> - Bump json-smart from 2.3 to 2.4.7</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6725">#6725</a> - Bump gson from 2.8.6 to 2.8.8</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6722">#6722</a> - Bump biz.aQute.bndlib from 5.2.0 to 5.3.0</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6717">#6717</a> - Bump bouncycastle.version from 1.62 to 1.69</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6712">#6712</a> - Bump jnr-unixsocket from 0.38.3 to 0.38.10</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6711">#6711</a> - Bump google-cloud-datastore from 1.105.0 to 2.1.0</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6705">#6705</a> - Bump hazelcast.version from 4.1 to 4.2.2</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6679">#6679</a> - Update to Apache Jasper 10.0.10</li> </ul> <h2>11.0.6</h2> <h1>Changelog</h1> <ul> <li>This release resolves CVE-2021-34429</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6473">#6473</a> - Improve alias checking in PathResource</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6468">#6468</a> - Revert logic in Request.setMetaData &amp; clear emptySegment on HttpUri.clear()</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6464">#6464</a> - Wrong files/lib definitions in certain *-capture.mod files?</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6447">#6447</a> - Deprecate support for UTF16 encoding in URIs</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6426">#6426</a> - Update to spifly 1.3.3</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6425">#6425</a> - Update to asm 9.1</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6418">#6418</a> - Bad and/or missing Require-Capability for osgi.serviceloader</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6410">#6410</a> - Ensure Jetty IO uses SocketAddress instead of InetSocketAddress</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6407">#6407</a> - Malformed scheme logical expression check in WebSocket ClientUpgradeRequest</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6394">#6394</a> - Review osgi manifests within Jetty 11</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6376">#6376</a> - Cleanups for SslClientCertAuthenticator.</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6375">#6375</a> - Always check XML <code>Set</code> elements with <code>property</code> attribute</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6353">#6353</a> - Rename EWYK The AdaptiveExecutionStrategy</li> </ul> <h2>11.0.5</h2> <h1>Changelog</h1> <ul> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6392">#6392</a> - Review accidental xml config changes</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6379">#6379</a> - Reduce contention in all <code>ByteBufferPool</code> implementations</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6354">#6354</a> - org.slfj dependency imports packages at 2.0</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6329">#6329</a> - Regression on graceful shutdown default in Jetty 10</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6302">#6302</a> - Treat empty path segments are ambiguous.</li> <li><a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/4772">#4772</a> - Jetty WebSocket API onMessage annotation does not support partial messages.</li> </ul> <!-- raw HTML omitted --> </blockquote> <p>... (truncated)</p> </details> <details> <summary>Commits</summary> <ul> <li><a href="https://github.com/eclipse/jetty.project/commit/389a3587725d94cc2470ed06aa184c6e57fe9ce8"><code>389a358</code></a> Updating to version 11.0.7</li> <li><a href="https://github.com/eclipse/jetty.project/commit/8bcd4045d0d643433b52b1396078690d3574b33d"><code>8bcd404</code></a> Fixing release script</li> <li><a href="https://github.com/eclipse/jetty.project/commit/abb7077180c0e8293736cfef6a2255c13a734932"><code>abb7077</code></a> fix new module pom parent version</li> <li><a href="https://github.com/eclipse/jetty.project/commit/e78951bfebfbfcd32676f161991828275cf0f75c"><code>e78951b</code></a> Merge branch 'jetty-10.0.x' into jetty-11.0.x</li> <li><a href="https://github.com/eclipse/jetty.project/commit/aaaa48c5ccaae16fe1d09e95f4a72f4bba29b148"><code>aaaa48c</code></a> Issue <a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6403">#6403</a> - add an automatic generated maven deployable p2 site (<a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6404">#6404</a>)</li> <li><a href="https://github.com/eclipse/jetty.project/commit/f8244fc301c2dc9e73531910426641f0b0512be2"><code>f8244fc</code></a> Merged branch 'jetty-10.0.x' into 'jetty-11.0.x'.</li> <li><a href="https://github.com/eclipse/jetty.project/commit/0412bdc3d980cc758abbc6fc06166b221598939e"><code>0412bdc</code></a> Fixes <a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6938">#6938</a> - module-info.java file do not use the canonical order for the el...</li> <li><a href="https://github.com/eclipse/jetty.project/commit/4011f1e71e9efd30a2ccde8302c21252fb9995c9"><code>4011f1e</code></a> merge jetty-10.0.x (<a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6945">#6945</a>)</li> <li><a href="https://github.com/eclipse/jetty.project/commit/51d44a3401e9d3efdb94aabcbf0964d7e8e4b78a"><code>51d44a3</code></a> use dependencyManagement for internal dependencies (<a href="https://github-redirect.dependabot.com/eclipse/jetty.project/issues/6940">#6940</a>)</li> <li><a href="https://github.com/eclipse/jetty.project/commit/02691171d500175ac47fedf00a712eeb62dff67c"><code>0269117</code></a> Changed order of entries in module-info.java to be canonical</li> <li>Additional commits viewable in <a href="https://github.com/eclipse/jetty.project/compare/jetty-9.4.27.v20200227...jetty-11.0.7">compare view</a></li> </ul> </details> <br /> [![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=org.eclipse.jetty:jetty-servlet&package-manager=gradle&previous-version=9.4.27.v20200227&new-version=11.0.7)](https://docs.github.com/en/github/managing-security-vulnerabilities/about-dependabot-security-updates#about-compatibility-scores) Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`. [//]: # (dependabot-automerge-start) [//]: # (dependabot-automerge-end) --- <details> <summary>Dependabot commands and options</summary> <br /> You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot ignore this major version` will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this minor version` will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) - `@dependabot ignore this dependency` will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself) </details>
p3k commented 2021-12-11 17:06:56 +00:00 (Migrated from github.com)

@dependabot ignore this major version

@dependabot ignore this major version
dependabot[bot] commented 2021-12-11 17:06:59 +00:00 (Migrated from github.com)

OK, I won't notify you about version 11.x.x again, unless you re-open this PR or update to a 11.x.x release yourself.

OK, I won't notify you about version 11.x.x again, unless you re-open this PR or update to a 11.x.x release yourself.

Pull request closed

Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: antville/helma#33
No description provided.