Skip to content

Bump the maven-patch-updates group across 1 directory with 4 updates - #48

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/maven-patch-updates-34623b3651
Open

dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/maven/maven-patch-updates-34623b3651

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 6, 2026

Copy link
Copy Markdown
Contributor

Bumps the maven-patch-updates group with 4 updates in the / directory: com.networknt:json-schema-validator, org.bouncycastle:bcpkix-fips, org.openapitools:jackson-databind-nullable and org.jruby:jruby-core.

Updates com.networknt:json-schema-validator from 3.0.7 to 3.0.8

Release notes

Sourced from com.networknt:json-schema-validator's releases.

3.0.8- 2026-09-30

Added

Changed

  • Expose Error.isCustomMessage() to identify messages supplied by the schema through the configured error message keyword, while preserving the existing Error constructor's binary compatibility and JSON serialization format. (680d7b3, f8c7659)
  • Reject leading or interior empty labels and names consisting only of label separators in the idn-hostname format (#1274) Thanks @​dngr2
  • Allow apostrophes in uri-template literals (#1275) Thanks @​dngr2
  • Honor PathType when formatting schema locations in DiscriminatorValidator exceptions (#1281) Thanks @​youdie006
  • Resolve the OpenAPI nullable keyword through allOf/oneOf/anyOf, if/then/else and $ref/$dynamicRef/$recursiveRef ancestors, to any depth and in any order. nullable on a schema composed through these keywords now applies to the value they describe, for both the type and enum keywords (#1278, #1279, #1283) Thanks @​tomakehurst
  • nullable on a container no longer applies to the values described by its properties, items and additionalProperties subschemas. Previously a nullable container made its children accept null. Schemas relying on that must declare nullable on the child itself. (#1283) Thanks @​tomakehurst
  • oneOf no longer requires exactly one matching branch when the value is null and a nullable ancestor permits it. Every branch accepts null in that case, so {"nullable": true, "oneOf": [ ... ]} previously reported that more than one branch matched. Branch errors are still reported when no branch matches. (#1283) Thanks @​tomakehurst
  • nullable no longer applies inside a not subschema, so {"nullable": true, "not": {"type": "string"}} now accepts null where it previously reported a not error. (#1283) Thanks @​tomakehurst
  • With typeLoose enabled, the empty string no longer satisfies an enum on a nullable schema. null was previously held in the accepted set and compared as text, where it renders as the empty string, so {"enum": ["a"], "nullable": true} accepted "". Only an actual null is accepted now. (#1283) Thanks @​tomakehurst
  • A nullable declared alongside $ref is now ignored at the root of an OpenAPI 3.0 schema as it already was elsewhere, so {"$ref": "...", "nullable": true} rejects null. Siblings of a Reference Object are ignored in OpenAPI 3.0. (#1283) Thanks @​tomakehurst
  • Add regression coverage for YAML .nan, .inf and -.inf values producing validation type errors instead of parser exceptions with Jackson 3.2.1 (#1228, #1282) Thanks @​patpatpat123
  • Upgrade SLF4J from 2.0.17 to 2.0.19 and the test dependency Logback from 1.5.22 to 1.6.3. (759445b, 3d9971d, 2575a02)
  • Upgrade Maven Surefire and Surefire Report from 3.5.4 to 3.6.0, and the Central Publishing Maven plugin from 0.7.0 to 0.11.0. (f26327c, 4649209)
  • Upgrade the benchmark workflow to actions/checkout@v7 and actions/setup-java@v6. (6f5d6c1)
Changelog

Sourced from com.networknt:json-schema-validator's changelog.

Change Log

All notable changes to this project will be documented in this file.

This format is based on Keep a Changelog.

This project does not adhere to Semantic Versioning and minor version changes can have incompatible API changes. These incompatible API changes will largely affect those who have custom validator or walker implementations. Those who just use the library to validate using the standard JSON Schema Draft specifications may not need changes.

[Unreleased]

Added

  • Opt-in ExecutionConfig.maxEvaluationSteps and maxEvaluationDepth limits for validation and schema walking, including walking without assertions. Exhaustion throws ValidationLimitExceededException instead of returning a partial validity result. Both limits default to unlimited; they bound admitted evaluation steps and schema frames, not work inside a keyword. (#1276)

Changed

  • Unlimited validation/walking bypasses execution counters and keeps the original recursion frame structure. During an active limited execution, reentrant convenience calls share the budget and the caller's evaluation path; unlimited calls retain their legacy root-path initialization.
  • Exhausted contexts reject public errors/annotation access. Walk listeners can inspect ExecutionContext.isEvaluationAborted() and getEvaluationAbort() during cleanup; an empty error slice after abort is not a validity verdict. Subclass builders supporting limits must use the protected builder constructor or forward both limits explicitly, since the legacy seven-argument constructor remains unlimited.

3.0.8- 2026-09-30

Added

Changed

  • Expose Error.isCustomMessage() to identify messages supplied by the schema through the configured error message keyword, while preserving the existing Error constructor's binary compatibility and JSON serialization format. (680d7b3, f8c7659)
  • Reject leading or interior empty labels and names consisting only of label separators in the idn-hostname format (#1274) Thanks @​dngr2
  • Allow apostrophes in uri-template literals (#1275) Thanks @​dngr2
  • Honor PathType when formatting schema locations in DiscriminatorValidator exceptions (#1281) Thanks @​youdie006
  • Resolve the OpenAPI nullable keyword through allOf/oneOf/anyOf, if/then/else and $ref/$dynamicRef/$recursiveRef ancestors, to any depth and in any order. nullable on a schema composed through these keywords now applies to the value they describe, for both the type and enum keywords (#1278, #1279, #1283) Thanks @​tomakehurst
  • nullable on a container no longer applies to the values described by its properties, items and additionalProperties subschemas. Previously a nullable container made its children accept null. Schemas relying on that must declare nullable on the child itself. (#1283) Thanks @​tomakehurst
  • oneOf no longer requires exactly one matching branch when the value is null and a nullable ancestor permits it. Every branch accepts null in that case, so {"nullable": true, "oneOf": [ ... ]} previously reported that more than one branch matched. Branch errors are still reported when no branch matches. (#1283) Thanks @​tomakehurst
  • nullable no longer applies inside a not subschema, so {"nullable": true, "not": {"type": "string"}} now accepts null where it previously reported a not error. (#1283) Thanks @​tomakehurst
  • With typeLoose enabled, the empty string no longer satisfies an enum on a nullable schema. null was previously held in the accepted set and compared as text, where it renders as the empty string, so {"enum": ["a"], "nullable": true} accepted "". Only an actual null is accepted now. (#1283) Thanks @​tomakehurst
  • A nullable declared alongside $ref is now ignored at the root of an OpenAPI 3.0 schema as it already was elsewhere, so {"$ref": "...", "nullable": true} rejects null. Siblings of a Reference Object are ignored in OpenAPI 3.0. (#1283) Thanks @​tomakehurst
  • Add regression coverage for YAML .nan, .inf and -.inf values producing validation type errors instead of parser exceptions with Jackson 3.2.1 (#1228, #1282) Thanks @​patpatpat123
  • Upgrade SLF4J from 2.0.17 to 2.0.19 and the test dependency Logback from 1.5.22 to 1.6.3. (759445b, 3d9971d, 2575a02)
  • Upgrade Maven Surefire and Surefire Report from 3.5.4 to 3.6.0, and the Central Publishing Maven plugin from 0.7.0 to 0.11.0. (f26327c, 4649209)
  • Upgrade the benchmark workflow to actions/checkout@v7 and actions/setup-java@v6. (6f5d6c1)

3.0.7- 2026-08-20

Added

Changed

3.0.6- 2026-07-07

... (truncated)

Commits
  • 12596e6 upgrade to 3.0.8 and update changelog
  • 759445b upgrade slf4j to 2.0.19 from 2.0.17
  • f26327c upgrade maven-surefire to 3.6.0
  • 2575a02 upgrade logback to 1.6.3 from 1.5.37
  • 3d9971d upgrade logback to 1.5.37
  • 6f5d6c1 upgrade actions/checkout
  • 4649209 upgrade central-publishing-maven to 0.11.0 from 0.7.0
  • dc11f65 Port the nullable ancestor walk from the 2.x branch (#1283)
  • 3c433c4 Add YAML non-finite number regression test for #1228 (#1282)
  • 81efb27 Honor PathType when formatting DiscriminatorValidator schema locations (#1281)
  • Additional commits viewable in compare view

Updates org.bouncycastle:bcpkix-fips from 2.1.12 to 2.1.13

Updates org.openapitools:jackson-databind-nullable from 0.2.11 to 0.2.12

Release notes

Sourced from org.openapitools:jackson-databind-nullable's releases.

v0.2.12 released

Highlights

  • New mapBlankStringToNull option on both modules: with it on, a blank string for a non-String JsonNullable reads as of(null) instead of undefined() (#186, thanks @​Thorsrud22, and @​krangerich for the first version in #126).
  • Character, CharSequence and deserializers you register yourself now get the empty string instead of undefined() (#187, fixes #26 and #46). Two cases behave differently from 0.2.11: a wrapper deserializer that neither extends DelegatingDeserializer nor overrides getDelegatee() is judged by its own class, so the deserializer it wraps can now throw on ""; and a subclass of FromStringDeserializer now reads "" as of(null). Content converters (@JsonDeserialize(contentConverter = ...)) still don't see "". Thanks @​Thorsrud22 for testing it past the suite.
  • Docs: module-path registration on Java 17+ (#188) and what NON_NULL does in the usage example (#190).
  • CI runs on JDK 17, 21 and 25 (#171), and CreatorTest is back on (#170), thanks @​davidpavlovschi.

What's Changed

New Contributors

Full Changelog: OpenAPITools/jackson-databind-nullable@v0.2.11...v0.2.12

Commits
  • be5bf95 0.2.12 release (#194)
  • c7bdbe1 Let Character, CharSequence and custom deserializers see empty strings (#187)
  • 649a6c1 Bump the minor-and-patch group across 1 directory with 3 updates (#193)
  • e3a82e4 README: say what NON_NULL does in the usage example (#190)
  • 0c11b11 Bump actions/setup-java from 5.7.0 to 6.0.1 (#189)
  • ff408fc README: remove the 'looking for maintainers' banner (#191)
  • c045fea Add mapBlankStringToNull option to JsonNullableModule and JsonNullableJackson...
  • 2d290ce Document module-path registration on Java 17+ (#188)
  • 24fccd8 Keep major GitHub Actions updates out of the group (#185)
  • 9f2a81c Group dependabot updates to reduce PR noise (#182)
  • Additional commits viewable in compare view

Updates org.jruby:jruby-core from 10.1.1.0 to 10.1.2.0

Release notes

Sourced from org.jruby:jruby-core's releases.

JRuby 10.1.2.0

The JRuby community is pleased to announce the release of JRuby 10.1.2.0.

JRuby 10.1.x targets Ruby 4.0 compatibility.

Thank you to our contributors this release, you help keep JRuby moving forward! [@​aminmansuri], [@​drzaiusx11], [@​evaniainbrooks], [@​gillesbergerp], [@​jcharaoui], [@​jwils], [@​kares], [@​lloeki], [@​makenowjust], [@​nobu], [@​sampokuokkanen], [@​shugo]

Notable Changes

Compatibility

Performance

  • Fixed a regression in startup time on MacOS by properly loading native JNR subsystem. #9690
  • Improve performance of Ruby subclasses of Java classes. #9619, #9557
  • Improve performance of autoloads overridden by an actual require. #9677

Standard Library

  • Update to jar-dependencies 0.6.1 using mima for dependency resolution instead of the ruby-maven gem. #9515, #9720
  • Update default and bundled standard library gems. #9705

Default gems

  • erb 6.0.7
  • error_highligh 0.7.2
  • ffi 1.17.4
  • io-console 0.9.4
  • ipaddr 1.2.9
  • json 2.21.2
  • net-protocol 0.4.0
  • pp 0.6.4
  • psych 5.5.0
  • resolv 0.8.0
  • strscan 3.1.8
  • syntax_suggest 3.0.0
  • timeout 0.6.1
  • win32-registry 0.1.2

Bundled gems

  • bigdecimal 4.1.2 (ruby parts only)
  • csv 3.3.6
  • minitest 5.27.0

... (truncated)

Commits
  • 36cf8bb Version 10.1.2.0 updated for release
  • 0e6e01b Merge pull request #9720 from headius/jar_deps_0.6.1
  • 528c114 Update jar-dependencies to 0.6.1
  • b7268d0 Merge remote-tracking branch 'origin/jruby-10.0'
  • 6718ce1 Move AOT cache skip into the example block in GH-9319 regression spec
  • 9bca2f8 Avoid timing-sensitive sleep(250) in TestRubyThread tests
  • f5ea9a2 Merge pull request #9716 from aminmansuri/fix-io-npe-on-concurrent-close
  • 7aaeb92 Move AOT cache skip into the example block in GH-9319 regression spec
  • 99d93c8 Avoid timing-sensitive sleep(250) in TestRubyThread tests
  • 203eb0a Read the IO fd field once for fileno and tty?
  • Additional commits viewable in compare view

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the maven-patch-updates group with 4 updates in the / directory: [com.networknt:json-schema-validator](https://github.com/networknt/json-schema-validator), org.bouncycastle:bcpkix-fips, [org.openapitools:jackson-databind-nullable](https://github.com/OpenAPITools/jackson-databind-nullable) and [org.jruby:jruby-core](https://github.com/jruby/jruby).


Updates `com.networknt:json-schema-validator` from 3.0.7 to 3.0.8
- [Release notes](https://github.com/networknt/json-schema-validator/releases)
- [Changelog](https://github.com/networknt/json-schema-validator/blob/master/CHANGELOG.md)
- [Commits](networknt/json-schema-validator@3.0.7...3.0.8)

Updates `org.bouncycastle:bcpkix-fips` from 2.1.12 to 2.1.13

Updates `org.openapitools:jackson-databind-nullable` from 0.2.11 to 0.2.12
- [Release notes](https://github.com/OpenAPITools/jackson-databind-nullable/releases)
- [Commits](OpenAPITools/jackson-databind-nullable@v0.2.11...v0.2.12)

Updates `org.jruby:jruby-core` from 10.1.1.0 to 10.1.2.0
- [Release notes](https://github.com/jruby/jruby/releases)
- [Commits](jruby/jruby@10.1.1.0...10.1.2.0)

---
updated-dependencies:
- dependency-name: com.networknt:json-schema-validator
  dependency-version: 3.0.8
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-patch-updates
- dependency-name: org.bouncycastle:bcpkix-fips
  dependency-version: 2.1.13
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-patch-updates
- dependency-name: org.openapitools:jackson-databind-nullable
  dependency-version: 0.2.12
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-patch-updates
- dependency-name: org.jruby:jruby-core
  dependency-version: 10.1.2.0
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: maven-patch-updates
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file java Pull requests that update java code labels Oct 6, 2026
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

PR: #48
Mode: squash
Topic: GH-policy-parent-48
Change-Ids:
I01f1a1ae26b256035af4b542e58e81582c27a6d9
Digest: 6e2a4318825e
GitHub-Hash: 4759585bdd52eaef

Note: This metadata is also included in the Gerrit commit message for reconciliation.

@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

Change raised in Gerrit by GitHub2Gerrit: https://gerrit.onap.org/r/c/policy/parent/+/148077

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file java Pull requests that update java code

Development

Successfully merging this pull request may close these issues.

0 participants