From daa36da77b762a09eccb649859c3a57f1b986256 Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Tue, 28 Nov 2023 05:38:10 +0000 Subject: [PATCH 01/16] Update dependency org.glassfish.jaxb:jaxb-runtime to v2.3.9 --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index aa328c319b1..b9e3e187e9d 100644 --- a/pom.xml +++ b/pom.xml @@ -34,7 +34,7 @@ 2.13.4.2 1.3.2 2.3.1 - 2.3.8 + 2.3.9 1.1.1 9.4.53.v20231009 From 47666737d4779a9430561104bc8351a8cbd41754 Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Tue, 28 Nov 2023 05:44:02 +0000 Subject: [PATCH 02/16] Update pdfbox-version to v2.0.30 --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index aa328c319b1..7f1a2703a6c 100644 --- a/pom.xml +++ b/pom.xml @@ -39,7 +39,7 @@ 9.4.53.v20231009 2.20.0 - 2.0.29 + 2.0.30 1.19.0 1.7.36 2.5.0 From 8ed5b6d22c8aec9a045170445b49b7595e251d67 Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Tue, 28 Nov 2023 05:51:40 +0000 Subject: [PATCH 03/16] Update dependency commons-cli:commons-cli to v1.6.0 --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index aa328c319b1..11ad45fcc8f 100644 --- a/pom.xml +++ b/pom.xml @@ -1451,7 +1451,7 @@ commons-cli commons-cli - 1.5.0 + 1.6.0 commons-codec From 2736b0e5d57336fa2ea0743847b1bf75f3460a1f Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Tue, 28 Nov 2023 05:52:16 +0000 Subject: [PATCH 04/16] Update dependency com.opencsv:opencsv to v5.9 --- dspace-api/pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/dspace-api/pom.xml b/dspace-api/pom.xml index 547be787e4c..395729649cf 100644 --- a/dspace-api/pom.xml +++ b/dspace-api/pom.xml @@ -784,7 +784,7 @@ com.opencsv opencsv - 5.7.1 + 5.9 From 178fc9e92bb77dfd310c20587bc126c8fdf05f50 Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Tue, 28 Nov 2023 05:52:20 +0000 Subject: [PATCH 05/16] Update dependency commons-io:commons-io to v2.15.0 --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index aa328c319b1..03db113d0c8 100644 --- a/pom.xml +++ b/pom.xml @@ -1489,7 +1489,7 @@ commons-io commons-io - 2.13.0 + 2.15.0 org.apache.commons From 603bad7978db2013cc8ccc64d42d305e3017ce33 Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Tue, 28 Nov 2023 06:24:36 +0000 Subject: [PATCH 06/16] Update log4j.version to v2.22.0 --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index c22f40400cf..8de85fe0b66 100644 --- a/pom.xml +++ b/pom.xml @@ -38,7 +38,7 @@ 1.1.1 9.4.53.v20231009 - 2.20.0 + 2.22.0 2.0.30 1.19.0 1.7.36 From 9e84b049e5b013f5df2c7fe9f95502f48b4911e0 Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Tue, 28 Nov 2023 06:33:06 +0000 Subject: [PATCH 07/16] Update dependency com.fasterxml:classmate to v1.6.0 --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index 5f6646795ad..b8187ebf6f9 100644 --- a/pom.xml +++ b/pom.xml @@ -1746,7 +1746,7 @@ com.fasterxml classmate - 1.5.1 + 1.6.0 com.fasterxml.jackson.core From ef560e4f03944f14c327c7218edf4d6a73e30d5a Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Tue, 28 Nov 2023 08:13:14 +0000 Subject: [PATCH 08/16] Update dependency org.xmlunit:xmlunit-core to v2.9.1 --- dspace-api/pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/dspace-api/pom.xml b/dspace-api/pom.xml index 395729649cf..2bf551319b8 100644 --- a/dspace-api/pom.xml +++ b/dspace-api/pom.xml @@ -896,7 +896,7 @@ org.xmlunit xmlunit-core - 2.8.0 + 2.9.1 test From a4bdd34802f90abd447d680bc41b6fbdb468059d Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Tue, 28 Nov 2023 08:16:05 +0000 Subject: [PATCH 09/16] Update dependency com.maxmind.geoip2:geoip2 to v2.17.0 --- dspace-api/pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/dspace-api/pom.xml b/dspace-api/pom.xml index 395729649cf..fc8754555d3 100644 --- a/dspace-api/pom.xml +++ b/dspace-api/pom.xml @@ -620,7 +620,7 @@ com.maxmind.geoip2 geoip2 - 2.11.0 + 2.17.0 org.apache.ant From d4985e9af80dd03b40baa98a1897203c79668ac9 Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Tue, 28 Nov 2023 09:06:03 +0000 Subject: [PATCH 10/16] Update netty monorepo to v4.1.101.Final --- dspace-api/pom.xml | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/dspace-api/pom.xml b/dspace-api/pom.xml index aa37c706752..ececf009851 100644 --- a/dspace-api/pom.xml +++ b/dspace-api/pom.xml @@ -861,32 +861,32 @@ io.netty netty-buffer - 4.1.94.Final + 4.1.101.Final io.netty netty-transport - 4.1.94.Final + 4.1.101.Final io.netty netty-transport-native-unix-common - 4.1.94.Final + 4.1.101.Final io.netty netty-common - 4.1.94.Final + 4.1.101.Final io.netty netty-handler - 4.1.94.Final + 4.1.101.Final io.netty netty-codec - 4.1.94.Final + 4.1.101.Final org.apache.velocity From 921157806fc9be7a5fe4fbb09cbc3f2c56918b13 Mon Sep 17 00:00:00 2001 From: Alan Orth Date: Wed, 29 Nov 2023 08:33:39 +0300 Subject: [PATCH 11/16] pom.xml: update Spring MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit We need to keep Spring Framework, Spring Boot, and Spring Security versions updated together: - Spring Framework: 5.3.28→5.3.31 - Spring Boot: 2.7.13→2.7.18 - Spring Security: 5.7.9→5.7.11 --- pom.xml | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/pom.xml b/pom.xml index 7339d12943d..3a062367a8d 100644 --- a/pom.xml +++ b/pom.xml @@ -19,9 +19,9 @@ 11 - 5.3.28 - 2.7.13 - 5.7.9 + 5.3.31 + 2.7.18 + 5.7.11 5.6.15.Final 6.2.5.Final 42.6.0 From 6f3d0d37a58407a992af69a96c485839c9442120 Mon Sep 17 00:00:00 2001 From: Alan Orth Date: Wed, 29 Nov 2023 10:01:27 +0300 Subject: [PATCH 12/16] pom.xml: update spotbugs and spotbugs-maven-plugin MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Update to latest versions: - spotbugs v4.1.2→v4.8.1 - spotbugs-maven-plugin v4.0.4→v4.8.1.0 These are not run in CI and seem to only run manually when asked, ie via maven: $ mvn spotbugs:spotbugs --- pom.xml | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/pom.xml b/pom.xml index 3a062367a8d..6b500e5ffcd 100644 --- a/pom.xml +++ b/pom.xml @@ -294,7 +294,7 @@ com.github.spotbugs spotbugs-maven-plugin - 4.0.4 + 4.8.1.0 Max Low @@ -304,7 +304,7 @@ com.github.spotbugs spotbugs - 4.1.2 + 4.8.1 From 5c027d9fa0b5b8603b7f98ee866be87fc8dee2a8 Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Wed, 29 Nov 2023 07:07:13 +0000 Subject: [PATCH 13/16] Update dependency org.apache.ant:ant to v1.10.14 --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index 6b500e5ffcd..3eeff2f28c6 100644 --- a/pom.xml +++ b/pom.xml @@ -1336,7 +1336,7 @@ org.apache.ant ant - 1.10.13 + 1.10.14 org.apache.jena From fb3a8a6624d359e19c73f302f57a0bc01cb9e1ac Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Wed, 29 Nov 2023 07:24:40 +0000 Subject: [PATCH 14/16] Update json-path.version to v2.8.0 --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index 6b500e5ffcd..7526c91e27b 100644 --- a/pom.xml +++ b/pom.xml @@ -48,7 +48,7 @@ - 2.6.0 + 2.8.0 7.9 From 324b139bf9a056a2108d4de2c6ef8608d91eb578 Mon Sep 17 00:00:00 2001 From: Alan Orth Date: Wed, 29 Nov 2023 12:46:35 +0300 Subject: [PATCH 15/16] Update hamcrest to v2.2 Due to changes in hamcrest packaging we only need the main artifact now, but we add hamcrest-core (which is an empty pom) so it doesn't get pulled in by other deps. Last, the hamcrest docs recommend that we put hamcrest first so that we don't have dependency convergence issues from junit. See: https://hamcrest.org/JavaHamcrest/distributables --- dspace-api/pom.xml | 2 +- dspace-oai/pom.xml | 2 +- dspace-server-webapp/pom.xml | 2 +- dspace/modules/additions/pom.xml | 2 +- pom.xml | 16 ++++++++-------- 5 files changed, 12 insertions(+), 12 deletions(-) diff --git a/dspace-api/pom.xml b/dspace-api/pom.xml index ececf009851..f81341837b2 100644 --- a/dspace-api/pom.xml +++ b/dspace-api/pom.xml @@ -528,7 +528,7 @@ org.hamcrest - hamcrest-all + hamcrest test diff --git a/dspace-oai/pom.xml b/dspace-oai/pom.xml index b900ebe88de..db8b55c79b5 100644 --- a/dspace-oai/pom.xml +++ b/dspace-oai/pom.xml @@ -156,7 +156,7 @@ org.hamcrest - hamcrest-all + hamcrest compile diff --git a/dspace-server-webapp/pom.xml b/dspace-server-webapp/pom.xml index 29457ff540b..05148dc73cc 100644 --- a/dspace-server-webapp/pom.xml +++ b/dspace-server-webapp/pom.xml @@ -498,7 +498,7 @@ org.hamcrest - hamcrest-all + hamcrest test diff --git a/dspace/modules/additions/pom.xml b/dspace/modules/additions/pom.xml index 922e0f0fe51..54d4dea25cd 100644 --- a/dspace/modules/additions/pom.xml +++ b/dspace/modules/additions/pom.xml @@ -273,7 +273,7 @@ org.hamcrest - hamcrest-core + hamcrest test diff --git a/pom.xml b/pom.xml index 7a1af6e6b41..6faa709066d 100644 --- a/pom.xml +++ b/pom.xml @@ -1661,21 +1661,21 @@ - junit - junit - 4.13.2 + org.hamcrest + hamcrest + 2.2 test org.hamcrest - hamcrest-all - 1.3 + hamcrest-core + 2.2 test - org.hamcrest - hamcrest-core - 1.3 + junit + junit + 4.13.2 test From 9407e304a58c12a60b44cad41ab493dd962b7def Mon Sep 17 00:00:00 2001 From: "renovate[bot]" <29139614+renovate[bot]@users.noreply.github.com> Date: Wed, 29 Nov 2023 13:42:12 +0000 Subject: [PATCH 16/16] Update dependency com.github.spotbugs:spotbugs to v4.8.2 --- pom.xml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/pom.xml b/pom.xml index 6faa709066d..a63ae872084 100644 --- a/pom.xml +++ b/pom.xml @@ -304,7 +304,7 @@ com.github.spotbugs spotbugs - 4.8.1 + 4.8.2